From: Alice Ryhl <aliceryhl@google.com>
To: Andreas Hindborg <a.hindborg@kernel.org>
Cc: "Boqun Feng" <boqun.feng@gmail.com>,
"Miguel Ojeda" <ojeda@kernel.org>,
"Alex Gaynor" <alex.gaynor@gmail.com>,
"Gary Guo" <gary@garyguo.net>,
"Björn Roy Baron" <bjorn3_gh@protonmail.com>,
"Benno Lossin" <lossin@kernel.org>,
"Trevor Gross" <tmgross@umich.edu>,
"Danilo Krummrich" <dakr@kernel.org>,
"Jens Axboe" <axboe@kernel.dk>,
linux-block@vger.kernel.org, rust-for-linux@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH v2 03/14] rust: str: introduce `NullBorrowFormatter`
Date: Wed, 9 Jul 2025 13:23:05 +0000 [thread overview]
Message-ID: <aG5tObucycBg9dP1@google.com> (raw)
In-Reply-To: <20250708-rnull-up-v6-16-v2-3-ab93c0ff429b@kernel.org>
On Tue, Jul 08, 2025 at 09:44:58PM +0200, Andreas Hindborg wrote:
> Add `NullBorrowFormatter`, a formatter that writes a null terminated string
> to an array or slice buffer. Because this type needs to manage the trailing
> null marker, the existing formatters cannot be used to implement this type.
>
> Signed-off-by: Andreas Hindborg <a.hindborg@kernel.org>
> ---
> rust/kernel/str.rs | 59 ++++++++++++++++++++++++++++++++++++++++++++++++++++++
> 1 file changed, 59 insertions(+)
>
> diff --git a/rust/kernel/str.rs b/rust/kernel/str.rs
> index 78b2f95eb3171..05d79cf40c201 100644
> --- a/rust/kernel/str.rs
> +++ b/rust/kernel/str.rs
> @@ -860,6 +860,65 @@ fn deref_mut(&mut self) -> &mut Self::Target {
> }
> }
>
> +/// A mutable reference to a byte buffer where a string can be written into.
> +///
> +/// The buffer will be automatically null terminated after the last written character.
> +///
> +/// # Invariants
> +///
> +/// `buffer` is always null terminated.
> +pub(crate) struct NullBorrowFormatter<'a> {
> + buffer: &'a mut [u8],
> + pos: usize,
> +}
Do you need `pos`? Often I see this kind of code subslice `buffer`
instead.
> +impl<'a> NullBorrowFormatter<'a> {
> + /// Create a new [`Self`] instance.
> + pub(crate) fn new(buffer: &'a mut [u8]) -> Result<NullBorrowFormatter<'a>> {
> + *(buffer.first_mut().ok_or(EINVAL)?) = 0;
> +
> + // INVARIANT: We null terminated the buffer above.
> + Ok(Self { buffer, pos: 0 })
> + }
I would probably just use an Option for this constructor.
> + #[expect(dead_code)]
> + pub(crate) fn from_array<const N: usize>(
> + a: &'a mut [crate::ffi::c_char; N],
> + ) -> Result<NullBorrowFormatter<'a>> {
> + Self::new(
> + // SAFETY: the buffer of `a` is valid for read and write as `u8` for
> + // at least `N` bytes.
> + unsafe { core::slice::from_raw_parts_mut(a.as_mut_ptr().cast::<u8>(), N) },
> + )
> + }
Arrays automatically coerce to slices, so I don't think this is
necessary. You can just call `new`.
> + /// Return the position of the write pointer in the underlying buffer.
> + #[expect(dead_code)]
> + pub(crate) fn pos(&self) -> usize {
> + self.pos
> + }
You delete this function in one of the later patches, so it makes more
sense not to add it.
> +}
> +
> +impl Write for NullBorrowFormatter<'_> {
> + fn write_str(&mut self, s: &str) -> fmt::Result {
> + let bytes = s.as_bytes();
> + let len = bytes.len();
> +
> + // We want space for a null terminator
> + if self.pos + len > self.buffer.len() - 1 {
Integer overflow?
> + return Err(fmt::Error);
> + }
> +
> + self.buffer[self.pos..self.pos + len].copy_from_slice(bytes);
> + self.pos += len;
> +
> + // INVARIANT: The buffer is null terminated.
> + self.buffer[self.pos] = 0;
> +
> + Ok(())
> + }
> +}
> +
> /// An owned string that is guaranteed to have exactly one `NUL` byte, which is at the end.
> ///
> /// Used for interoperability with kernel APIs that take C strings.
>
> --
> 2.47.2
>
>
next prev parent reply other threads:[~2025-07-09 13:23 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-07-08 19:44 [PATCH v2 00/14] rnull: add configfs, remote completion to rnull Andreas Hindborg
2025-07-08 19:44 ` [PATCH v2 01/14] rust: str: normalize imports in `str.rs` Andreas Hindborg
2025-07-09 13:26 ` Alice Ryhl
2025-07-08 19:44 ` [PATCH v2 02/14] rust: str: introduce `BorrowFormatter` Andreas Hindborg
2025-07-09 13:14 ` Alice Ryhl
2025-07-09 15:11 ` Andreas Hindborg
2025-07-08 19:44 ` [PATCH v2 03/14] rust: str: introduce `NullBorrowFormatter` Andreas Hindborg
2025-07-09 13:23 ` Alice Ryhl [this message]
2025-07-09 15:49 ` Andreas Hindborg
2025-07-10 8:47 ` Alice Ryhl
2025-07-10 11:01 ` Andreas Hindborg
2025-07-08 19:44 ` [PATCH v2 04/14] rust: block: normalize imports for `gen_disk.rs` Andreas Hindborg
2025-07-09 13:26 ` Alice Ryhl
2025-07-08 19:45 ` [PATCH v2 05/14] rust: block: use `NullBorrowFormatter` Andreas Hindborg
2025-07-09 13:25 ` Alice Ryhl
2025-07-11 9:29 ` Andreas Hindborg
2025-07-11 10:02 ` Alice Ryhl
2025-07-08 19:45 ` [PATCH v2 06/14] rust: block: remove `RawWriter` Andreas Hindborg
2025-07-08 19:45 ` [PATCH v2 07/14] rust: block: remove trait bound from `mq::Request` definition Andreas Hindborg
2025-07-09 13:25 ` Alice Ryhl
2025-07-08 19:45 ` [PATCH v2 08/14] rust: block: add block related constants Andreas Hindborg
2025-07-08 19:45 ` [PATCH v2 09/14] rnull: move driver to separate directory Andreas Hindborg
2025-07-08 19:45 ` [PATCH v2 10/14] rnull: enable configuration via `configfs` Andreas Hindborg
2025-07-08 19:45 ` [PATCH v2 11/14] rust: block: add `GenDisk` private data support Andreas Hindborg
2025-07-08 19:45 ` [PATCH v2 12/14] rust: block: mq: fix spelling in a safety comment Andreas Hindborg
2025-07-08 19:45 ` [PATCH v2 13/14] rust: block: add remote completion to `Request` Andreas Hindborg
2025-07-08 19:45 ` [PATCH v2 14/14] rnull: add soft-irq completion support Andreas Hindborg
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aG5tObucycBg9dP1@google.com \
--to=aliceryhl@google.com \
--cc=a.hindborg@kernel.org \
--cc=alex.gaynor@gmail.com \
--cc=axboe@kernel.dk \
--cc=bjorn3_gh@protonmail.com \
--cc=boqun.feng@gmail.com \
--cc=dakr@kernel.org \
--cc=gary@garyguo.net \
--cc=linux-block@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=lossin@kernel.org \
--cc=ojeda@kernel.org \
--cc=rust-for-linux@vger.kernel.org \
--cc=tmgross@umich.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.