From: "Gary Guo" <gary@garyguo.net>
To: git@younes.io, "Alexandre Courbot" <acourbot@nvidia.com>,
"Yury Norov" <yury.norov@gmail.com>,
"Miguel Ojeda" <ojeda@kernel.org>,
"Boqun Feng" <boqun@kernel.org>, "Gary Guo" <gary@garyguo.net>,
"Björn Roy Baron" <bjorn3_gh@protonmail.com>,
"Benno Lossin" <lossin@kernel.org>,
"Andreas Hindborg" <a.hindborg@kernel.org>,
"Alice Ryhl" <aliceryhl@google.com>,
"Trevor Gross" <tmgross@umich.edu>,
"Danilo Krummrich" <dakr@kernel.org>,
"Daniel Almeida" <daniel.almeida@collabora.com>,
"Tamir Duberstein" <tamird@kernel.org>,
"Onur Özkan" <work@onurozkan.dev>
Cc: <rust-for-linux@vger.kernel.org>, <linux-kernel@vger.kernel.org>,
<stable@vger.kernel.org>
Subject: Re: [PATCH] rust: num: seal Integer
Date: Sat, 05 Sep 2026 15:22:01 +0100 [thread overview]
Message-ID: <DL7G7HLTDOR3.3L6QJOQL43KP5@garyguo.net> (raw)
In-Reply-To: <20260905-feature-rust-num-seal-integer-v1-1-83096115ad64@younes.io>
On Sat Sep 5, 2026 at 3:17 AM BST, Younes Akhouayri via B4 Relay wrote:
> From: Younes Akhouayri <git@younes.io>
>
> Bounded relies on Integer implementations to describe primitive integer
> semantics correctly. In particular, it uses Integer::BITS and Signedness
> to justify unchecked operations.
>
> Integer is currently safe and externally implementable, so an
> implementation can violate those assumptions and make safe Bounded
> operations reach undefined behavior.
>
> Seal Integer so only the primitive implementations provided by the
> kernel crate can satisfy it.
>
> Fixes: 01e345e82ec3 ("rust: num: add Bounded integer wrapping type")
> Closes: https://lore.kernel.org/rust-for-linux/CANiq72mOfR33s4y+Ueivd5NrC5yre+Pcp57ZOBz0msw9A4AP1Q@mail.gmail.com/
> Cc: stable@vger.kernel.org
> Suggested-by: Miguel Ojeda <ojeda@kernel.org>
> Signed-off-by: Younes Akhouayri <git@younes.io>
> ---
> rust/kernel/num.rs | 9 ++++++++-
> 1 file changed, 8 insertions(+), 1 deletion(-)
>
> diff --git a/rust/kernel/num.rs b/rust/kernel/num.rs
> index dbe848e30efe..de589792a77a 100644
> --- a/rust/kernel/num.rs
> +++ b/rust/kernel/num.rs
> @@ -15,9 +15,14 @@ pub enum Unsigned {}
> /// Designates signed primitive types.
> pub enum Signed {}
>
> +mod private {
> + pub trait Sealed {}
> +}
I feel that it's time to add an attribute macro for sealing.
Yes, more macros :)
Best,
Gary
> +
> /// Describes core properties of integer types.
> pub trait Integer:
> - Sized
> + private::Sealed
> + + Sized
> + Copy
> + Clone
> + PartialEq
> @@ -56,6 +61,8 @@ pub trait Integer:
> macro_rules! impl_integer {
> ($($type:ty: $signedness:ty), *) => {
> $(
> + impl private::Sealed for $type {}
> +
> impl Integer for $type {
> type Signedness = $signedness;
>
>
> ---
> base-commit: e510334fbaeaa016ac76d80b4c5f47611c5f7860
> change-id: 20260903-feature-rust-num-seal-integer-a4262df429c6
>
> Best regards,
> --
> Younes Akhouayri <git@younes.io>
next prev parent reply other threads:[~2026-09-05 14:22 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-05 2:17 [PATCH] rust: num: seal Integer Younes Akhouayri via B4 Relay
2026-09-05 2:17 ` Younes Akhouayri
2026-09-05 14:12 ` Miguel Ojeda
2026-09-05 14:22 ` Gary Guo [this message]
2026-09-06 0:17 ` Alexandre Courbot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DL7G7HLTDOR3.3L6QJOQL43KP5@garyguo.net \
--to=gary@garyguo.net \
--cc=a.hindborg@kernel.org \
--cc=acourbot@nvidia.com \
--cc=aliceryhl@google.com \
--cc=bjorn3_gh@protonmail.com \
--cc=boqun@kernel.org \
--cc=dakr@kernel.org \
--cc=daniel.almeida@collabora.com \
--cc=git@younes.io \
--cc=linux-kernel@vger.kernel.org \
--cc=lossin@kernel.org \
--cc=ojeda@kernel.org \
--cc=rust-for-linux@vger.kernel.org \
--cc=stable@vger.kernel.org \
--cc=tamird@kernel.org \
--cc=tmgross@umich.edu \
--cc=work@onurozkan.dev \
--cc=yury.norov@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.