From: Lorenzo Delgado <lnsdev@proton.me>
To: Danilo Krummrich <dakr@kernel.org>,
Alice Ryhl <aliceryhl@google.com>,
Alexandre Courbot <acourbot@nvidia.com>,
David Airlie <airlied@gmail.com>, Simona Vetter <simona@ffwll.ch>,
Daniel Almeida <daniel.almeida@collabora.com>,
Miguel Ojeda <ojeda@kernel.org>
Cc: "Boqun Feng" <boqun@kernel.org>, "Gary Guo" <gary@garyguo.net>,
"Björn Roy Baron" <bjorn3_gh@protonmail.com>,
"Benno Lossin" <lossin@kernel.org>,
"Andreas Hindborg" <a.hindborg@kernel.org>,
"Trevor Gross" <tmgross@umich.edu>,
"Tamir Duberstein" <tamird@kernel.org>,
"Onur Özkan" <work@onurozkan.dev>,
"Abdiel Janulgue" <abdiel.janulgue@gmail.com>,
"Robin Murphy" <robin.murphy@arm.com>,
rust-for-linux@vger.kernel.org, linux-kernel@vger.kernel.org,
driver-core@lists.linux.dev, dri-devel@lists.freedesktop.org,
nova-gpu@lists.linux.dev, "Lorenzo Delgado" <lnsdev@proton.me>
Subject: [PATCH v2] rust: io: convert ResourceSize into a transparent newtype
Date: Sun, 19 Jul 2026 20:09:49 +0000 [thread overview]
Message-ID: <20260719200945.687904-1-lnsdev@proton.me> (raw)
In-Reply-To: <20260712113602.389060-1-lnsdev@proton.me>
`ResourceSize` was a bare type alias for `resource_size_t`, so it
inherited every integer operation and `as` cast. That silently permits
operations that are meaningless for the size of a hardware resource:
mixing it with unrelated integers and truncating casts.
Wrap it in a `#[repr(transparent)]` newtype so each conversion at a
boundary becomes explicit and reviewable. The representation is
unchanged, so this is ABI-identical; only the spelling at the FFI
boundary changes. Provide the conversion surface `from_raw`/`into_raw`,
`From` in both directions, and a fallible `TryFrom<ResourceSize> for
usize` for checked narrowing. Update the two producers, `Resource::size`
and `SGEntry::dma_len`, and the `request_region` consumer. In nova-core,
add an `impl FromSafeCast<ResourceSize> for usize` so its page-count
conversion keeps the infallible `usize::from_safe_cast(sg_entry.dma_len())`
unchanged.
Suggested-by: Miguel Ojeda <ojeda@kernel.org>
Link: https://github.com/Rust-for-Linux/linux/issues/1203
Signed-off-by: Lorenzo Delgado <lnsdev@proton.me>
---
v2: keep the nova-core page-count conversion infallible, per review
(Danilo Krummrich). v1 changed it to a fallible
usize::try_from(sg_entry.dma_len())?; instead of touching the call
site, add an impl FromSafeCast<ResourceSize> for usize in nova-core's
num.rs, so drivers/gpu/nova-core/firmware/gsp.rs keeps
usize::from_safe_cast(sg_entry.dma_len()) unchanged. FromSafeCast is
to move to the kernel crate subsequently. io.rs is unchanged from v1.
v1: https://lore.kernel.org/r/20260712113602.389060-1-lnsdev@proton.me
drivers/gpu/nova-core/num.rs | 10 +++++
rust/kernel/io.rs | 73 ++++++++++++++++++++++++++++++++++--
rust/kernel/io/resource.rs | 6 +--
rust/kernel/scatterlist.rs | 2 +-
4 files changed, 83 insertions(+), 8 deletions(-)
diff --git a/drivers/gpu/nova-core/num.rs b/drivers/gpu/nova-core/num.rs
index 6eb174d136ab..7c0e878bbfb2 100644
--- a/drivers/gpu/nova-core/num.rs
+++ b/drivers/gpu/nova-core/num.rs
@@ -6,6 +6,7 @@
//! crate.
use kernel::{
+ io::ResourceSize,
macros::paste,
prelude::*, //
};
@@ -137,6 +138,15 @@ fn from_safe_cast(value: u64) -> Self {
}
}
+// A `resource_size_t` fits into a `usize` on 64-bit platforms, where a `usize` is a `u64` and a
+// `resource_size_t` is at most a `u64`. Delegates to the primitive impl for the underlying type.
+#[cfg(CONFIG_64BIT)]
+impl FromSafeCast<ResourceSize> for usize {
+ fn from_safe_cast(value: ResourceSize) -> Self {
+ Self::from_safe_cast(value.into_raw())
+ }
+}
+
/// Counterpart to the [`FromSafeCast`] trait, i.e. this trait is to [`FromSafeCast`] what [`Into`]
/// is to [`From`].
///
diff --git a/rust/kernel/io.rs b/rust/kernel/io.rs
index fcc7678fd9e3..ebf00b4536d6 100644
--- a/rust/kernel/io.rs
+++ b/rust/kernel/io.rs
@@ -6,9 +6,12 @@
use crate::{
bindings,
+ fmt,
prelude::*, //
};
+use core::num::TryFromIntError;
+
pub mod mem;
pub mod poll;
pub mod register;
@@ -25,11 +28,73 @@
/// `CONFIG_PHYS_ADDR_T_64BIT`, and it can be a u64 even on 32-bit architectures.
pub type PhysAddr = bindings::phys_addr_t;
-/// Resource Size type.
+/// Resource size type.
///
-/// This is a type alias to either `u32` or `u64` depending on the config option
-/// `CONFIG_PHYS_ADDR_T_64BIT`, and it can be a u64 even on 32-bit architectures.
-pub type ResourceSize = bindings::resource_size_t;
+/// This wraps either `u32` or `u64` depending on the config option
+/// `CONFIG_PHYS_ADDR_T_64BIT`, and it can be a `u64` even on 32-bit architectures.
+///
+/// # Examples
+///
+/// ```
+/// use kernel::io::ResourceSize;
+///
+/// let size = ResourceSize::from_raw(0x1000);
+/// assert_eq!(size.into_raw(), 0x1000);
+///
+/// // Round-trips through the raw C type.
+/// let raw: kernel::bindings::resource_size_t = size.into();
+/// assert_eq!(ResourceSize::from(raw), size);
+///
+/// // Fallible conversion to `usize` (can truncate on 32-bit).
+/// assert_eq!(usize::try_from(size)?, 0x1000);
+/// # Ok::<(), core::num::TryFromIntError>(())
+/// ```
+#[repr(transparent)]
+#[derive(Clone, Copy, PartialEq, Eq, PartialOrd, Ord)]
+pub struct ResourceSize(bindings::resource_size_t);
+
+impl ResourceSize {
+ /// Creates a resource size from the raw C type.
+ #[inline]
+ pub const fn from_raw(value: bindings::resource_size_t) -> Self {
+ Self(value)
+ }
+
+ /// Turns this resource size into the raw C type.
+ #[inline]
+ pub const fn into_raw(self) -> bindings::resource_size_t {
+ self.0
+ }
+}
+
+impl fmt::Debug for ResourceSize {
+ fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
+ write!(f, "{:#x}", self.0)
+ }
+}
+
+impl From<bindings::resource_size_t> for ResourceSize {
+ #[inline]
+ fn from(value: bindings::resource_size_t) -> Self {
+ Self::from_raw(value)
+ }
+}
+
+impl From<ResourceSize> for bindings::resource_size_t {
+ #[inline]
+ fn from(value: ResourceSize) -> Self {
+ value.into_raw()
+ }
+}
+
+impl TryFrom<ResourceSize> for usize {
+ type Error = TryFromIntError;
+
+ #[inline]
+ fn try_from(value: ResourceSize) -> Result<Self, Self::Error> {
+ Self::try_from(value.into_raw())
+ }
+}
/// Raw representation of an MMIO region.
///
diff --git a/rust/kernel/io/resource.rs b/rust/kernel/io/resource.rs
index 17b0c174cfc5..a33a416b289a 100644
--- a/rust/kernel/io/resource.rs
+++ b/rust/kernel/io/resource.rs
@@ -58,7 +58,7 @@ fn drop(&mut self) {
};
// SAFETY: Safe as per the invariant of `Region`.
- unsafe { release_fn(start, size) };
+ unsafe { release_fn(start, size.into_raw()) };
}
}
@@ -114,7 +114,7 @@ pub fn request_region(
bindings::__request_region(
self.0.get(),
start,
- size,
+ size.into_raw(),
name.as_char_ptr(),
flags.0 as c_int,
)
@@ -130,7 +130,7 @@ pub fn request_region(
pub fn size(&self) -> ResourceSize {
let inner = self.0.get();
// SAFETY: Safe as per the invariants of `Resource`.
- unsafe { bindings::resource_size(inner) }
+ ResourceSize::from_raw(unsafe { bindings::resource_size(inner) })
}
/// Returns the start address of the resource.
diff --git a/rust/kernel/scatterlist.rs b/rust/kernel/scatterlist.rs
index b83c468b5c63..5d67242befd8 100644
--- a/rust/kernel/scatterlist.rs
+++ b/rust/kernel/scatterlist.rs
@@ -93,7 +93,7 @@ pub fn dma_address(&self) -> dma::DmaAddress {
pub fn dma_len(&self) -> ResourceSize {
#[allow(clippy::useless_conversion)]
// SAFETY: `self.as_raw()` is a valid pointer to a `struct scatterlist`.
- unsafe { bindings::sg_dma_len(self.as_raw()) }.into()
+ ResourceSize::from_raw(unsafe { bindings::sg_dma_len(self.as_raw()) }.into())
}
}
base-commit: 7059bdf4f04a3e14f4fafb3ac35fdca913e3e21a
--
2.54.0
next prev parent reply other threads:[~2026-07-19 20:10 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-12 11:36 [PATCH] rust: io: convert ResourceSize into a transparent newtype Lorenzo Delgado
2026-07-16 21:45 ` Danilo Krummrich
2026-07-19 10:40 ` Lorenzo Delgado
2026-07-19 14:53 ` Danilo Krummrich
2026-07-19 20:53 ` Gary Guo
2026-07-19 20:09 ` Lorenzo Delgado [this message]
2026-07-19 20:17 ` [PATCH v2] " sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260719200945.687904-1-lnsdev@proton.me \
--to=lnsdev@proton.me \
--cc=a.hindborg@kernel.org \
--cc=abdiel.janulgue@gmail.com \
--cc=acourbot@nvidia.com \
--cc=airlied@gmail.com \
--cc=aliceryhl@google.com \
--cc=bjorn3_gh@protonmail.com \
--cc=boqun@kernel.org \
--cc=dakr@kernel.org \
--cc=daniel.almeida@collabora.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=driver-core@lists.linux.dev \
--cc=gary@garyguo.net \
--cc=linux-kernel@vger.kernel.org \
--cc=lossin@kernel.org \
--cc=nova-gpu@lists.linux.dev \
--cc=ojeda@kernel.org \
--cc=robin.murphy@arm.com \
--cc=rust-for-linux@vger.kernel.org \
--cc=simona@ffwll.ch \
--cc=tamird@kernel.org \
--cc=tmgross@umich.edu \
--cc=work@onurozkan.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.