From: Andreas Hindborg <a.hindborg@kernel.org>
To: "Tamir Duberstein" <tamird@gmail.com>
Cc: "Miguel Ojeda" <ojeda@kernel.org>,
"Alex Gaynor" <alex.gaynor@gmail.com>,
"Boqun Feng" <boqun.feng@gmail.com>,
"Gary Guo" <gary@garyguo.net>,
=?utf-8?Q?Bj=C3=B6rn?= Roy Baron <bjorn3_gh@protonmail.com>,
"Benno Lossin" <benno.lossin@proton.me>,
"Alice Ryhl" <aliceryhl@google.com>,
"Trevor Gross" <tmgross@umich.edu>,
"Danilo Krummrich" <dakr@kernel.org>,
rust-for-linux@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH 1/5] rust: arc: use `NonNull::new_unchecked`
Date: Thu, 31 Oct 2024 09:27:43 +0100 [thread overview]
Message-ID: <87jzdopthc.fsf@kernel.org> (raw)
In-Reply-To: <20241030-borrow-mut-v1-1-8f0ceaf78eaf@gmail.com> (Tamir Duberstein's message of "Wed, 30 Oct 2024 16:46:38 -0400")
"Tamir Duberstein" <tamird@gmail.com> writes:
> There is no need to check (and panic on violations of) the safety
> requirements on `ForeignOwnable` functions. Avoiding the check is
> consistent with the implementation of `ForeignOwnable` for `Box`.
>
> Signed-off-by: Tamir Duberstein <tamird@gmail.com>
> ---
> rust/kernel/sync/arc.rs | 12 ++++++++----
> 1 file changed, 8 insertions(+), 4 deletions(-)
>
> diff --git a/rust/kernel/sync/arc.rs b/rust/kernel/sync/arc.rs
> index db9da352d588f65348aa7a5204abbb165b70197f..4857230bd8d410bcca97b2081c3ce2f617ee7921 100644
> --- a/rust/kernel/sync/arc.rs
> +++ b/rust/kernel/sync/arc.rs
> @@ -337,9 +337,9 @@ fn into_foreign(self) -> *const core::ffi::c_void {
> }
>
> unsafe fn borrow<'a>(ptr: *const core::ffi::c_void) -> ArcBorrow<'a, T> {
> - // By the safety requirement of this function, we know that `ptr` came from
> - // a previous call to `Arc::into_foreign`.
> - let inner = NonNull::new(ptr as *mut ArcInner<T>).unwrap();
> + // SAFETY: The safety requirements of this function ensure that `ptr` comes from a previous
> + // call to `Self::into_foreign`.
> + let inner = unsafe { NonNull::new_unchecked(ptr as _) };
Please use an explicit cast.
>
> // SAFETY: The safety requirements of `from_foreign` ensure that the object remains alive
> // for the lifetime of the returned value.
> @@ -347,10 +347,14 @@ unsafe fn borrow<'a>(ptr: *const core::ffi::c_void) -> ArcBorrow<'a, T> {
> }
>
> unsafe fn from_foreign(ptr: *const core::ffi::c_void) -> Self {
> + // SAFETY: The safety requirements of this function ensure that `ptr` comes from a previous
> + // call to `Self::into_foreign`.
> + let inner = unsafe { NonNull::new_unchecked(ptr as _) };
Please use an explicit cast.
> +
> // SAFETY: By the safety requirement of this function, we know that `ptr` came from
> // a previous call to `Arc::into_foreign`, which guarantees that `ptr` is valid and
> // holds a reference count increment that is transferrable to us.
> - unsafe { Self::from_inner(NonNull::new(ptr as _).unwrap()) }
> + unsafe { Self::from_inner(inner) }
> }
> }
Otherwise lgtm.
Best regards,
Andreas
next prev parent reply other threads:[~2024-10-31 8:50 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-10-30 20:46 [PATCH 0/5] rust: add improved version of `ForeignOwnable::borrow_mut` Tamir Duberstein
2024-10-30 20:46 ` [PATCH 1/5] rust: arc: use `NonNull::new_unchecked` Tamir Duberstein
2024-10-31 8:27 ` Andreas Hindborg [this message]
2024-10-31 11:50 ` Tamir Duberstein
2024-10-31 8:37 ` Alice Ryhl
2024-10-30 20:46 ` [PATCH 2/5] rust: types: avoid `as` casts, narrow unsafe scope Tamir Duberstein
2024-10-31 8:41 ` Andreas Hindborg
2024-10-31 11:50 ` Tamir Duberstein
2024-11-01 13:21 ` Andreas Hindborg
2024-11-04 21:19 ` Tamir Duberstein
2024-10-31 8:46 ` Alice Ryhl
2024-10-31 13:24 ` Tamir Duberstein
2024-10-30 20:46 ` [PATCH 3/5] rust: change `ForeignOwnable` pointer to mut Tamir Duberstein
2024-10-31 8:45 ` Andreas Hindborg
2024-10-31 8:53 ` Alice Ryhl
2024-10-30 20:46 ` [PATCH 4/5] rust: reorder `ForeignOwnable` items Tamir Duberstein
2024-10-31 8:46 ` Andreas Hindborg
2024-10-31 12:22 ` Tamir Duberstein
2024-10-31 12:40 ` Miguel Ojeda
2024-10-31 13:30 ` Tamir Duberstein
2024-11-01 13:24 ` Andreas Hindborg
2024-11-01 13:22 ` Andreas Hindborg
2024-10-30 20:46 ` [PATCH 5/5] rust: add improved version of `ForeignOwnable::borrow_mut` Tamir Duberstein
2024-10-31 8:50 ` Andreas Hindborg
2024-10-31 10:54 ` Alice Ryhl
2024-10-31 12:23 ` Tamir Duberstein
2024-10-31 12:27 ` Miguel Ojeda
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87jzdopthc.fsf@kernel.org \
--to=a.hindborg@kernel.org \
--cc=alex.gaynor@gmail.com \
--cc=aliceryhl@google.com \
--cc=benno.lossin@proton.me \
--cc=bjorn3_gh@protonmail.com \
--cc=boqun.feng@gmail.com \
--cc=dakr@kernel.org \
--cc=gary@garyguo.net \
--cc=linux-kernel@vger.kernel.org \
--cc=ojeda@kernel.org \
--cc=rust-for-linux@vger.kernel.org \
--cc=tamird@gmail.com \
--cc=tmgross@umich.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.