From: sashiko-bot@kernel.org
To: "Gary Guo" <gary@garyguo.net>
Cc: linux-pci@vger.kernel.org, "Danilo Krummrich" <dakr@kernel.org>,
dri-devel@lists.freedesktop.org, ojeda@kernel.org,
"Alexandre Courbot" <acourbot@nvidia.com>
Subject: Re: [PATCH 07/10] rust: io: add subregion method with compile-time check
Date: Tue, 21 Jul 2026 17:05:17 +0000 [thread overview]
Message-ID: <20260721170517.A74BF1F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260721-typed_register-v1-7-452d72b60262@garyguo.net>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] The `subregion` method incorrectly initializes the new subregion's runtime size using `ptr.len() - OFFSET` instead of `NEW_SIZE`, defeating encapsulation and enabling out-of-bounds MMIO accesses.
--
--- Patch [7]: [PATCH 07/10] rust: io: add subregion method with compile-time check ---
commit 3d97a4ac48567402f60659310de26681110a1c61
Author: Gary Guo <gary@garyguo.net>
rust: io: add subregion method with compile-time check
This commit adds a compile-time checked subregion helper function to Region.
This allows drivers to obtain a safely constrained subregion for relative
register access.
> diff --git a/rust/kernel/io.rs b/rust/kernel/io.rs
> index 0f8b166a6d3bb..f31d37c8a3d58 100644
> --- a/rust/kernel/io.rs
> +++ b/rust/kernel/io.rs
[ ... ]
> + /// Create a subregion with provided offset and size.
> + #[inline]
> + pub fn subregion<'a, const OFFSET: usize, const NEW_SIZE: usize, IO>(
> + io: IO,
> + ) -> <IO::Backend as IoBackend>::View<'a, Region<NEW_SIZE>>
> + where
> + IO: IoBase<'a, Target = Self>,
> + {
> + const_assert!(
> + OFFSET + NEW_SIZE <= SIZE && OFFSET.is_multiple_of(4) && NEW_SIZE.is_multiple_of(4)
> + );
> +
> + let view = io.as_view();
> + let ptr = IO::Backend::as_ptr(view) as *mut [u8];
> + let new_ptr = Region::ptr_from_raw_parts_mut(
> + ptr.cast::<u8>().wrapping_add(OFFSET),
> + ptr.len() - OFFSET,
[Severity: High]
Does this improperly initialize the new subregion's runtime size using
ptr.len() - OFFSET instead of NEW_SIZE?
If a parent driver creates a localized subregion specifying a NEW_SIZE and
delegates it to a sub-device driver, the sub-device could mistakenly execute
fallible MMIO operations beyond the intended NEW_SIZE.
Because the runtime dynamic bounds checking will evaluate against
ptr.len() - OFFSET instead of the constrained size, out-of-bounds accesses
would improperly succeed and could corrupt adjacent registers.
Should this be updated to pass NEW_SIZE to ptr_from_raw_parts_mut?
> + );
> +
> + // SAFETY: We have checked that the new region is a subregion and it is aligned, hence it is
> + // a valid projection.
> + unsafe { IO::Backend::project_view(view, new_ptr) }
> + }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260721-typed_register-v1-0-452d72b60262@garyguo.net?part=7
next prev parent reply other threads:[~2026-07-21 17:05 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-21 16:54 [PATCH 00/10] rust: io: make register bases typed and remove relative registers Gary Guo
2026-07-21 16:54 ` [PATCH 01/10] rust: io: register: allow explicit base type specification Gary Guo
2026-07-21 16:58 ` sashiko-bot
2026-07-21 16:54 ` [PATCH 02/10] gpu: nova-core: specify base type for registers Gary Guo
2026-07-21 16:59 ` sashiko-bot
2026-07-21 16:54 ` [PATCH 03/10] drm/tyr: " Gary Guo
2026-07-21 17:10 ` sashiko-bot
2026-07-21 16:54 ` [PATCH 04/10] samples: rust: pci: " Gary Guo
2026-07-21 17:03 ` sashiko-bot
2026-07-21 16:54 ` [PATCH 05/10] rust: io: register: make register have a typed base Gary Guo
2026-07-21 17:00 ` sashiko-bot
2026-07-21 16:54 ` [PATCH 06/10] rust: io: add static `cast()` method for views Gary Guo
2026-07-21 17:08 ` sashiko-bot
2026-07-21 16:54 ` [PATCH 07/10] rust: io: add subregion method with compile-time check Gary Guo
2026-07-21 17:05 ` sashiko-bot [this message]
2026-07-21 16:54 ` [PATCH 08/10] gpu: nova-core: use projection for PFALCON and PFALCON2 registers Gary Guo
2026-07-21 17:00 ` sashiko-bot
2026-07-21 16:54 ` [PATCH 09/10] gpu: nova-core: convert hshub0 from relative register to projection Gary Guo
2026-07-21 17:18 ` sashiko-bot
2026-07-21 16:54 ` [PATCH 10/10] rust: io: register: remove relative registers Gary Guo
2026-07-21 17:08 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260721170517.A74BF1F00A3A@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=acourbot@nvidia.com \
--cc=dakr@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=gary@garyguo.net \
--cc=linux-pci@vger.kernel.org \
--cc=ojeda@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.