From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-dl2-f42.google.com (mail-dl2-f42.google.com [74.125.229.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 25274568558 for ; Wed, 23 Sep 2026 20:31:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.229.170 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790195522; cv=none; b=IJH/13QMF11oj21mGTuDe47NlsxOojdkyLEhrQqtGBkS12ML/WgiokFodFxAd9GrT8/xXWO//OubKsRvQk8uHPVIXqeztqtELadZ+ZaTRuPIxkVMfxUsQVvESG9gUh7QmZ1qNZ+xF74QvBus0xdn8cVxqIq8A5UQz8oM7Dq5lG4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790195522; c=relaxed/simple; bh=lsgiFQR0W1RaDSUCFb03bBzHp12jvBbMgfMT0EHXOU0=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=dXryBWDtnVULdpiG5qCGImKqdB8sbJsgzVyuWqfjhrYDY+BSsP7AWWHl3iMnjmLH0iHASYfLzSsrSeaVsfuJYTuvoZa3pZU5VRu9A1DM/GfnQG9r5Z/SqNDOJVd0D97uiDAnqEAw36p9azhozXJJrm7vPnlFR+rKx6aU80p5PVk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=uci.edu; spf=pass smtp.mailfrom=uci.edu; dkim=pass (2048-bit key) header.d=uci.edu header.i=@uci.edu header.b=oz5pMRSA; arc=none smtp.client-ip=74.125.229.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=uci.edu Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=uci.edu Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=uci.edu header.i=@uci.edu header.b="oz5pMRSA" Received: by mail-dl2-f42.google.com with SMTP id a92af1059eb24-144ecebb6cbso611518c88.3 for ; Wed, 23 Sep 2026 13:31:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=uci.edu; s=google; t=1790195509; x=1790800309; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=rVIQWAnKN98ur25hclWfvj2q8SoQe7T1V/QGgzzXRDE=; b=oz5pMRSANSD2rT04xi0Ga0fDwbcW+o4DGgCerIZ1x+V2qDeEgLh7X1WcwerHDrzKAs lGiTMo1+LF2JnsQvPwOJQoJtvfPvY8c6Ti8NBCOIkcqEmn4FEvjDq0UeYcD2dLnVJPDY DjYopDDfneU50g+c5MG+4PHyophV53eksTZoNUtHxPNjjy38Rf7P5yKhhR9AS7ErBU/b 5mLc6cVAHXcL4/Oq93FiQuL8Ywg2SrAXKxbQFd3+IVw1PUThjxyquri1ATku3bFJaxbg 0rXpZgkSkHZg1siqA34lopbbD5ip4QlyFpLrO1LDARpBnIOCDdKMw/bRg4KjeHiz1hK8 duCQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790195509; x=1790800309; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=rVIQWAnKN98ur25hclWfvj2q8SoQe7T1V/QGgzzXRDE=; b=O92y8ZDoZy5cyBo6Sfff9gZIFo33w/cGiDfsqwTmBJ8y0kqlheVH/KzrVAd4gr5MNd TO2AQDhgFYWq3vSgFT22fwJxvygjFNgokHDjWk9dx1wsXQ6tRVtXgnrovHcY8NAFyso2 iT7ZlAE6LoXKQBWtbO2S4g3WLh+phMwKfN+DGt0zkp2/A7gae6epc7HUvd0DwAwGx/uh AY/CEdkLUTjEbvul37DrzNWgYUylT2Bos3pp9kUB25t/oM2uCAt1lscqYEakQUvdbxYb tieoccx3JRwBE5VF9gvOaDnb18+DgFJr+BWuT+CHNopUCNnJh1+saPXgDdiebE4hc6+Z Nmww== X-Forwarded-Encrypted: i=1; AKwUvByCjjsf0R0xkZjDa9SxsF+PHDP6L2ycy6/FCi4h36mnHjwqjZoVv45Dt498eDYNHXf6WcIMpDMNnXVWz8rt@vger.kernel.org X-Gm-Message-State: AFuF++mLr6MZipPTMpnTmc9KV+C4KRtptNC+Ag8q8aQ3ipUZ8rpUdMk2 me26SDzBjaxqXmipZprRCU0eQDAyJBEQCOdvkWf2G/IR+xtkiRrKz090/ktcEZBstyk= X-Gm-Gg: AYBFou3hr4AHMpMk2aVdkNshzgEGE/hQNu7hogQCW6+YeKe43CbaJwup0rz6jyCiH2/ iZvgQ3owbhH9qbGc1bZ5QXiUh+cWnx0Gqi0dN+SAHtPnwVy0OZ60PvupdeWOXVtLy7dYdoFSC14 1RyB6rhDYvrMA+Iajn8nf7gq6c4erzyPXJbznY3WvycSJJedWUhT8FaBGRxDlCzmOo1XrAK2q8N ROd+SkgvD3KWrwYh3bCjk3a8MTmFdAcBlB9Rny/l5NaZ78/HUEUJhb9DAfv8fTW9oxvPAyvzkvs tCb+AIrsd+xcxJ8dIX+C5O5d8cqcUD58M+snvwVSZRCDR2kNCTQ9axAEWjdZAFr+dZEOHRJ7QmF o1cPKQiarCLaltxS+WyllW0N/DtIkBbGFiw+Fug7s2Qa1TgpCmZjGz6g/4RNUuJhtdsB2IN12pY yjHyN5U2FLnvZWmi0cM8tbTTD9WbhgiiYteMu8r1sEf0cIceeLLUxD8RiLkOtOAZqEHlHWjwJf8 i9WljP2injBq8KDmU0h8dD9XFIF8OAXdJN0N8Jq+TEJGg== X-Received: by 2002:a05:701b:4512:20b0:143:297d:21f5 with SMTP id a92af1059eb24-14503fc5fedmr228574c88.34.1790195508236; Wed, 23 Sep 2026 13:31:48 -0700 (PDT) Received: from guest1.. (charm.ics.uci.edu. [128.195.4.118]) by smtp.googlemail.com with ESMTPSA id a92af1059eb24-144f983c5a1sm13276486c88.7.2026.09.23.13.31.46 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 13:31:47 -0700 (PDT) From: Priya Bala Govindasamy To: mcgrof@kernel.org, petr.pavlu@suse.com, da.gomez@kernel.org, samitolvanen@google.com, ojeda@kernel.org Cc: atomlin@atomlin.com, boqun@kernel.org, gary@garyguo.net, bjorn3_gh@protonmail.com, lossin@kernel.org, a.hindborg@kernel.org, aliceryhl@google.com, tmgross@umich.edu, dakr@kernel.org, daniel.almeida@collabora.com, tamird@kernel.org, acourbot@nvidia.com, work@onurozkan.dev, linux-modules@vger.kernel.org, rust-for-linux@vger.kernel.org, stable@vger.kernel.org, ardalan@uci.edu, zhiyunq@cs.ucr.edu, dzueck@uci.edu, pgovind2@uci.edu Subject: [PATCH v2] rust: module_param: Fix potentially incorrect access of `SetOnce` Date: Wed, 23 Sep 2026 20:31:45 +0000 Message-Id: <20260923203145.18714-1-pgovind2@uci.edu> X-Mailer: git-send-email 2.34.1 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-modules@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit The `set_param` function casts `kernel_param.arg` to `*const SetOnce` But the Rust module macro in rust/macros/module.rs initializes `arg` with `#param_name.as_void_ptr()`, and `#param_name` is a `ModuleParamAccess`, not a `SetOnce`. ModuleParamAccess has default Rust layout but `set_param` accesses its first field SetOnce assuming it to be at offset 0. This is not guaranteed by Rust and could cause type confusion leading to data corruption. Fix this by casting `kernel_param.arg` to `ModuleParamAccess` and then accessing the `value: SetOnce` field. Fixes: 0b08fc292842 ("rust: introduce module_param module") Cc: stable@vger.kernel.org Reported-by: Dylan Zueck Assisted-by: LLM Suggested-by: Andreas Hindborg Signed-off-by: Priya Bala Govindasamy --- Changes in v2: - Split unsafe block into two separate unsafe operations - Add safety comments explaining the unsafe operations rust/kernel/module_param.rs | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/rust/kernel/module_param.rs b/rust/kernel/module_param.rs index f9a14765a926..1a2fcbf4a5b3 100644 --- a/rust/kernel/module_param.rs +++ b/rust/kernel/module_param.rs @@ -74,8 +74,13 @@ pub trait ModuleParam: Sized + Copy { crate::error::from_result(|| { let new_value = T::try_from_param_arg(arg)?; - // SAFETY: By function safety requirements, this access is safe. - let container = unsafe { &*((*param).__bindgen_anon_1.arg.cast::>()) }; + // SAFETY: By function safety requirements, `param` is valid for read. + let arg = unsafe { (*param).__bindgen_anon_1.arg }; + let param_access_ptr = arg.cast::>(); + // SAFETY: The `arg` field is initialized with a pointer to a `static ModuleAccessParam` by + // the rust module macro. Thus, the pointer is valid for use as a reference. + let param_access = unsafe { &*(param_access_ptr) }; + let container = ¶m_access.value; container .populate(new_value) -- 2.34.1