From: "Benno Lossin" <lossin@kernel.org>
To: "Andreas Hindborg" <a.hindborg@kernel.org>,
"Miguel Ojeda" <ojeda@kernel.org>,
"Alex Gaynor" <alex.gaynor@gmail.com>,
"Boqun Feng" <boqun.feng@gmail.com>,
"Gary Guo" <gary@garyguo.net>,
"Björn Roy Baron" <bjorn3_gh@protonmail.com>,
"Alice Ryhl" <aliceryhl@google.com>,
"Masahiro Yamada" <masahiroy@kernel.org>,
"Nathan Chancellor" <nathan@kernel.org>,
"Luis Chamberlain" <mcgrof@kernel.org>,
"Danilo Krummrich" <dakr@kernel.org>,
"Nicolas Schier" <nicolas.schier@linux.dev>
Cc: "Trevor Gross" <tmgross@umich.edu>,
"Adam Bratschi-Kaye" <ark.email@gmail.com>,
<rust-for-linux@vger.kernel.org>, <linux-kernel@vger.kernel.org>,
<linux-kbuild@vger.kernel.org>,
"Petr Pavlu" <petr.pavlu@suse.com>,
"Sami Tolvanen" <samitolvanen@google.com>,
"Daniel Gomez" <da.gomez@samsung.com>,
"Simona Vetter" <simona.vetter@ffwll.ch>,
"Greg KH" <gregkh@linuxfoundation.org>,
"Fiona Behrens" <me@kloenk.dev>,
"Daniel Almeida" <daniel.almeida@collabora.com>,
<linux-modules@vger.kernel.org>
Subject: Re: [PATCH v14 1/7] rust: sync: add `OnceLock`
Date: Wed, 02 Jul 2025 17:07:12 +0200 [thread overview]
Message-ID: <DB1NVTWHU7BN.2WGPMAY9LQYNW@kernel.org> (raw)
In-Reply-To: <20250702-module-params-v3-v14-1-5b1cc32311af@kernel.org>
On Wed Jul 2, 2025 at 3:18 PM CEST, Andreas Hindborg wrote:
> Introduce the `OnceLock` type, a container that can only be written once.
> The container uses an internal atomic to synchronize writes to the internal
> value.
>
> Signed-off-by: Andreas Hindborg <a.hindborg@kernel.org>
> ---
> rust/kernel/sync.rs | 1 +
> rust/kernel/sync/once_lock.rs | 104 ++++++++++++++++++++++++++++++++++++++++++
> 2 files changed, 105 insertions(+)
>
> diff --git a/rust/kernel/sync.rs b/rust/kernel/sync.rs
> index c7c0e552bafe..f2ee07315091 100644
> --- a/rust/kernel/sync.rs
> +++ b/rust/kernel/sync.rs
> @@ -15,6 +15,7 @@
> mod condvar;
> pub mod lock;
> mod locked_by;
> +pub mod once_lock;
As Alice already said, we should reexport the type. And then make the
module private, no need to have `kernel::sync::OnceLock` and
`kernel::sync::once_lock::OnceLock`...
Also, I agree with the name change to `SetOnce` or something similar.
> pub mod poll;
> pub mod rcu;
>
> diff --git a/rust/kernel/sync/once_lock.rs b/rust/kernel/sync/once_lock.rs
> new file mode 100644
> index 000000000000..cd311bea3919
> --- /dev/null
> +++ b/rust/kernel/sync/once_lock.rs
> @@ -0,0 +1,104 @@
> +//! A container that can be initialized at most once.
> +
> +use super::atomic::ordering::Acquire;
> +use super::atomic::ordering::Release;
> +use super::atomic::Atomic;
> +use kernel::types::Opaque;
> +
> +/// A container that can be populated at most once. Thread safe.
> +///
> +/// Once the a [`OnceLock`] is populated, it remains populated by the same object for the
> +/// lifetime `Self`.
> +///
> +/// # Invariants
> +///
> +/// `init` tracks the state of the container:
> +///
> +/// - If the container is empty, `init` is `0`.
> +/// - If the container is mutably accessed, `init` is `1`.
I think we should swap the order and change the ifs to iffs:
- `init == 0` iff the container is empty.
- `init == 1` iff the container is being accessed mutably.
> +/// - If the container is populated and ready for shared access, `init` is `2`.
You also need that `init` is only increased and never decreases.
Otherwise you could read a `2` and then access the value, but `init`
changed under your nose to `0`.
Then the INVARIANT comments below also need to be updated.
> +///
> +/// # Example
> +///
> +/// ```
> +/// # use kernel::sync::once_lock::OnceLock;
> +/// let value = OnceLock::new();
> +/// assert_eq!(None, value.as_ref());
> +///
> +/// let status = value.populate(42u8);
> +/// assert_eq!(true, status);
> +/// assert_eq!(Some(&42u8), value.as_ref());
> +/// assert_eq!(Some(42u8), value.copy());
> +///
> +/// let status = value.populate(101u8);
> +/// assert_eq!(false, status);
> +/// assert_eq!(Some(&42u8), value.as_ref());
> +/// assert_eq!(Some(42u8), value.copy());
> +/// ```
> +pub struct OnceLock<T> {
> + init: Atomic<u32>,
> + value: Opaque<T>,
> +}
> +
> +impl<T> Default for OnceLock<T> {
> + fn default() -> Self {
> + Self::new()
> + }
> +}
> +
> +impl<T> OnceLock<T> {
> + /// Create a new [`OnceLock`].
> + ///
> + /// The returned instance will be empty.
> + pub const fn new() -> Self {
> + // INVARIANT: The container is empty and we set `init` to `0`.
> + Self {
> + value: Opaque::uninit(),
> + init: Atomic::new(0),
> + }
> + }
> +
> + /// Get a reference to the contained object.
> + ///
> + /// Returns [`None`] if this [`OnceLock`] is empty.
> + pub fn as_ref(&self) -> Option<&T> {
> + if self.init.load(Acquire) == 2 {
> + // SAFETY: As determined by the load above, the object is ready for shared access.
// SAFETY: By the safety requirements of `Self`, `self.init == 2` means that `self.value` contains
// a valid value.
> + Some(unsafe { &*self.value.get() })
> + } else {
> + None
> + }
> + }
> +
> + /// Populate the [`OnceLock`].
> + ///
> + /// Returns `true` if the [`OnceLock`] was successfully populated.
> + pub fn populate(&self, value: T) -> bool {
> + // INVARIANT: We obtain exclusive access to the contained allocation and write 1 to
> + // `init`.
> + if let Ok(0) = self.init.cmpxchg(0, 1, Acquire) {
> + // SAFETY: We obtained exclusive access to the contained object.
> + unsafe { core::ptr::write(self.value.get(), value) };
> + // INVARIANT: We release our exclusive access and transition the object to shared
> + // access.
> + self.init.store(2, Release);
> + true
> + } else {
> + false
> + }
> + }
> +}
> +
> +impl<T: Copy> OnceLock<T> {
> + /// Get a copy of the contained object.
> + ///
> + /// Returns [`None`] if the [`OnceLock`] is empty.
> + pub fn copy(&self) -> Option<T> {
> + if self.init.load(Acquire) == 2 {
> + // SAFETY: As determined by the load above, the object is ready for shared access.
> + Some(unsafe { *self.value.get() })
> + } else {
> + None
> + }
The impl can just be:
self.as_ref().copied()
Would it make sense for this function to take `self` instead & we make
the `OnceLock` also `Copy` if `T: Copy`? Maybe not...
> + }
> +}
You can move this method into the block above and just add `where T:
Copy` on the method.
---
Cheers,
Benno
next prev parent reply other threads:[~2025-07-02 15:07 UTC|newest]
Thread overview: 34+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-07-02 13:18 [PATCH v14 0/7] rust: extend `module!` macro with integer parameter support Andreas Hindborg
2025-07-02 13:18 ` [PATCH v14 1/7] rust: sync: add `OnceLock` Andreas Hindborg
2025-07-02 13:32 ` Alice Ryhl
2025-07-02 13:54 ` Andreas Hindborg
2025-07-02 14:50 ` Alice Ryhl
2025-07-03 7:51 ` Andreas Hindborg
2025-07-02 15:07 ` Benno Lossin [this message]
2025-07-02 15:27 ` Alice Ryhl
2025-07-02 15:40 ` Benno Lossin
2025-07-03 9:03 ` Andreas Hindborg
2025-07-03 9:42 ` Benno Lossin
2025-07-03 16:25 ` Andreas Hindborg
2025-07-03 20:41 ` Benno Lossin
2025-07-03 9:36 ` Wren Turkal
2025-07-03 16:41 ` Andreas Hindborg
2025-07-02 13:18 ` [PATCH v14 2/7] rust: str: add radix prefixed integer parsing functions Andreas Hindborg
2025-07-02 13:18 ` [PATCH v14 3/7] rust: introduce module_param module Andreas Hindborg
2025-07-02 15:21 ` Benno Lossin
2025-07-04 11:45 ` Andreas Hindborg
2025-07-06 20:00 ` Miguel Ojeda
2025-07-03 21:49 ` Danilo Krummrich
2025-07-04 7:29 ` Andreas Hindborg
2025-07-04 7:37 ` Andreas Hindborg
2025-07-04 9:59 ` Benno Lossin
2025-07-04 11:46 ` Andreas Hindborg
2025-07-02 13:18 ` [PATCH v14 4/7] rust: module: use a reference in macros::module::module Andreas Hindborg
2025-07-02 13:18 ` [PATCH v14 5/7] rust: module: update the module macro with module parameter support Andreas Hindborg
2025-07-02 15:38 ` Benno Lossin
2025-07-04 12:29 ` Andreas Hindborg
2025-07-04 12:48 ` Benno Lossin
2025-07-04 13:51 ` Andreas Hindborg
2025-07-04 14:00 ` Benno Lossin
2025-07-02 13:18 ` [PATCH v14 6/7] rust: samples: add a module parameter to the rust_minimal sample Andreas Hindborg
2025-07-02 13:18 ` [PATCH v14 7/7] modules: add rust modules files to MAINTAINERS Andreas Hindborg
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DB1NVTWHU7BN.2WGPMAY9LQYNW@kernel.org \
--to=lossin@kernel.org \
--cc=a.hindborg@kernel.org \
--cc=alex.gaynor@gmail.com \
--cc=aliceryhl@google.com \
--cc=ark.email@gmail.com \
--cc=bjorn3_gh@protonmail.com \
--cc=boqun.feng@gmail.com \
--cc=da.gomez@samsung.com \
--cc=dakr@kernel.org \
--cc=daniel.almeida@collabora.com \
--cc=gary@garyguo.net \
--cc=gregkh@linuxfoundation.org \
--cc=linux-kbuild@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-modules@vger.kernel.org \
--cc=masahiroy@kernel.org \
--cc=mcgrof@kernel.org \
--cc=me@kloenk.dev \
--cc=nathan@kernel.org \
--cc=nicolas.schier@linux.dev \
--cc=ojeda@kernel.org \
--cc=petr.pavlu@suse.com \
--cc=rust-for-linux@vger.kernel.org \
--cc=samitolvanen@google.com \
--cc=simona.vetter@ffwll.ch \
--cc=tmgross@umich.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.