From: "Benno Lossin" <lossin@kernel.org>
To: "Alice Ryhl" <aliceryhl@google.com>,
"Danilo Krummrich" <dakr@kernel.org>
Cc: "Matthew Maurer" <mmaurer@google.com>,
<rust-for-linux@vger.kernel.org>, <linux-kernel@vger.kernel.org>
Subject: Re: [PATCH v5 3/7] rust: alloc: add Vec::push_within_capacity
Date: Wed, 07 May 2025 13:35:46 +0200 [thread overview]
Message-ID: <D9PWBFMQRL0P.1UGCE5V5SSBLZ@kernel.org> (raw)
In-Reply-To: <20250502-vec-methods-v5-3-06d20ad9366f@google.com>
On Fri May 2, 2025 at 3:19 PM CEST, Alice Ryhl wrote:
> This introduces a new method called `push_within_capacity` for appending
> to a vector without attempting to allocate if the capacity is full. Rust
> Binder will use this in various places to safely push to a vector while
> holding a spinlock.
>
> The implementation is moved to a push_within_capacity_unchecked method.
> This is preferred over having push() call push_within_capacity()
> followed by an unwrap_unchecked() for simpler unsafe.
>
> Panics in the kernel are best avoided when possible, so an error is
> returned if the vector does not have sufficient capacity. An error type
> is used rather than just returning Result<(),T> to make it more
> convenient for callers (i.e. they can use ? or unwrap).
>
> Signed-off-by: Alice Ryhl <aliceryhl@google.com>
One small nit below, with or without:
Reviewed-by: Benno Lossin <lossin@kernel.org>
[...]
> + /// Appends an element to the back of the [`Vec`] instance without reallocating.
> + ///
> + /// # Safety
> + ///
> + /// The length must be less than the capacity.
I would have written:
- `self.len() < self.capacity()`
---
Cheers,
Benno
> + pub unsafe fn push_within_capacity_unchecked(&mut self, v: T) {
> let spare = self.spare_capacity_mut();
>
> - // SAFETY: The call to `reserve` was successful so the spare capacity is at least 1.
> + // SAFETY: By the safety requirements, `spare` is non-empty.
> unsafe { spare.get_unchecked_mut(0) }.write(v);
>
> // SAFETY: We just initialised the first spare entry, so it is safe to increase the length
> - // by 1. We also know that the new length is <= capacity because of the previous call to
> - // `reserve` above.
> + // by 1. We also know that the new length is <= capacity because the caller guarantees that
> + // the length is less than the capacity at the beginning of this function.
> unsafe { self.inc_len(1) };
> - Ok(())
> }
>
> /// Removes the last element from a vector and returns it, or `None` if it is empty.
next prev parent reply other threads:[~2025-05-07 11:35 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-05-02 13:19 [PATCH v5 0/7] Additional methods for Vec Alice Ryhl
2025-05-02 13:19 ` [PATCH v5 1/7] rust: alloc: add Vec::clear Alice Ryhl
2025-05-02 13:19 ` [PATCH v5 2/7] rust: alloc: add Vec::pop Alice Ryhl
2025-05-07 11:32 ` Benno Lossin
2025-05-02 13:19 ` [PATCH v5 3/7] rust: alloc: add Vec::push_within_capacity Alice Ryhl
2025-05-02 14:07 ` Greg KH
2025-05-02 14:25 ` Alice Ryhl
2025-05-03 11:50 ` Danilo Krummrich
2025-05-07 11:35 ` Benno Lossin [this message]
2025-05-02 13:19 ` [PATCH v5 4/7] rust: alloc: add Vec::drain_all Alice Ryhl
2025-05-07 11:37 ` Benno Lossin
2025-05-02 13:19 ` [PATCH v5 5/7] rust: alloc: add Vec::retain Alice Ryhl
2025-05-07 11:40 ` Benno Lossin
2025-05-02 13:19 ` [PATCH v5 6/7] rust: alloc: add Vec::remove Alice Ryhl
2025-05-03 11:44 ` Danilo Krummrich
2025-05-07 5:30 ` Alexandre Courbot
2025-05-07 5:32 ` Alexandre Courbot
2025-05-07 6:32 ` [PATCH v5 6/7] rust: alloc: add Vec::remove' Alice Ryhl
2025-05-07 11:44 ` [PATCH v5 6/7] rust: alloc: add Vec::remove Benno Lossin
2025-05-08 9:50 ` Alice Ryhl
2025-05-02 13:19 ` [PATCH v5 7/7] rust: alloc: add Vec::insert_within_capacity Alice Ryhl
2025-05-07 11:46 ` Benno Lossin
2025-05-02 14:08 ` [PATCH v5 0/7] Additional methods for Vec Greg KH
2025-05-07 16:46 ` Danilo Krummrich
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=D9PWBFMQRL0P.1UGCE5V5SSBLZ@kernel.org \
--to=lossin@kernel.org \
--cc=aliceryhl@google.com \
--cc=dakr@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mmaurer@google.com \
--cc=rust-for-linux@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.