Linux PCI subsystem development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Danilo Krummrich" <dakr@kernel.org>
Cc: ojeda@kernel.org, linux-pci@vger.kernel.org
Subject: Re: [PATCH v4 17/27] rust: pci: make Bar lifetime-parameterized
Date: Fri, 22 May 2026 00:49:43 +0000	[thread overview]
Message-ID: <20260522004943.CDA7C1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260521233501.1191842-18-dakr@kernel.org>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [Critical] `Bar::into_devres` uses `unsafe { core::mem::transmute(self) }` to artificially erase the local `'a` borrow of the `Device`, which is unsound and causes a Use-After-Free during `Devres` destruction.
- [High] The `name` parameter in `iomap_region` and `iomap_region_sized` lacks a `'static` or device-bound lifetime constraint, allowing temporary strings to be passed and leading to a dangling pointer in the kernel's resource tree.
--

commit 00fb543eb5262d30a44ce3dd81c925a773732bd2
Author: Danilo Krummrich <dakr@kernel.org>

rust: pci: make Bar lifetime-parameterized

This patch parameterizes the lifetime of pci::Bar, tying its mapping
lifetime directly to the device. It changes iomap_region_sized to return
a Bar instead of a Devres, and adds an into_devres method to optionally
register it as a device-managed resource with a static lifetime.

> diff --git a/rust/kernel/pci/io.rs b/rust/kernel/pci/io.rs
[ ... ]
> @@ -219,11 +214,24 @@ unsafe fn do_release(pdev: &Device, ioptr: usize, num: i32) {
>  
>      fn release(&self) {
>          // SAFETY: The safety requirements are guaranteed by the type invariant of `self.pdev`.
> -        unsafe { Self::do_release(&self.pdev, self.io.addr(), self.num) };
> +        unsafe { Self::do_release(self.pdev, self.io.addr(), self.num) };
> +    }
> +
> +    /// Consume the `Bar` and register it as a device-managed resource.
> +    ///
> +    /// The returned `Devres<Bar<'static, SIZE>>` can outlive the original lifetime `'a`. Access
> +    /// to the BAR is revoked when the device is unbound.
> +    pub fn into_devres(self) -> Result<Devres<Bar<'static, SIZE>>> {
> +        // SAFETY: Casting to `'static` is sound because `Devres` guarantees the `Bar` does not
> +        // actually outlive the device -- access is revoked and the resource is released when the
> +        // device is unbound.
> +        let bar: Bar<'static, SIZE> = unsafe { core::mem::transmute(self) };

[Severity: Critical]
Is it safe to transmute this lifetime to 'static here?

Since Rust drops struct fields in declaration order, and Devres declares its
dev: ARef<Device> field before its inner: Arc<Inner<T>> data wrapper, dropping
a Devres<Bar<'static>> will decrement the Device refcount first.

If this was the last reference, the underlying C struct pci_dev could be
freed. When inner then drops, it triggers Bar::drop, which will access the now
dangling pdev pointer to call pci_release_region().

Could this lead to memory corruption during error paths or unbinding?

> +        let pdev = bar.pdev;
> +        Devres::new(pdev.as_ref(), bar)
>      }
>  }
[ ... ]
> @@ -252,17 +260,13 @@ impl Device<device::Bound> {
>      pub fn iomap_region_sized<'a, const SIZE: usize>(
>          &'a self,
>          bar: u32,
> -        name: &'a CStr,
> -    ) -> impl PinInit<Devres<Bar<SIZE>>, Error> + 'a {
> -        Devres::new(self.as_ref(), Bar::<SIZE>::new(self, bar, name))
> +        name: &CStr,

[Severity: High]
Does removing the 'a lifetime bound from the name parameter allow temporary
strings to be passed?

The underlying C function pci_request_region stores the provided string
pointer directly into the name field of the allocated struct resource
without making a copy.

If a caller passes a dynamically allocated temporary CString that drops after
this function returns, could accessing the kernel's resource tree (for example,
by reading /proc/iomem) dereference a freed string pointer?

> +    ) -> Result<Bar<'a, SIZE>> {
> +        Bar::new(self, bar, name)
>      }
>  
>      /// Maps an entire PCI BAR after performing a region-request on it.
> -    pub fn iomap_region<'a>(
> -        &'a self,
> -        bar: u32,
> -        name: &'a CStr,
> -    ) -> impl PinInit<Devres<Bar>, Error> + 'a {
> +    pub fn iomap_region<'a>(&'a self, bar: u32, name: &CStr) -> Result<Bar<'a>> {

[Severity: High]
This seems to have the same lifetime issue with the name parameter as
iomap_region_sized above.

>          self.iomap_region_sized::<0>(bar, name)
>      }
>

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260521233501.1191842-1-dakr@kernel.org?part=17

  reply	other threads:[~2026-05-22  0:49 UTC|newest]

Thread overview: 63+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-05-21 23:34 [PATCH v4 00/27] rust: device: Higher-Ranked Lifetime Types for device drivers Danilo Krummrich
2026-05-21 23:34 ` [PATCH v4 01/27] rust: alloc: remove `'static` bound on `ForeignOwnable` Danilo Krummrich
2026-05-22  0:13   ` sashiko-bot
2026-05-21 23:34 ` [PATCH v4 02/27] rust: driver: move 'static bounds to constructor Danilo Krummrich
2026-05-21 23:34 ` [PATCH v4 03/27] rust: driver: decouple driver private data from driver type Danilo Krummrich
2026-05-21 23:56   ` sashiko-bot
2026-05-21 23:34 ` [PATCH v4 04/27] rust: driver core: drop drvdata before devres release Danilo Krummrich
2026-05-22  0:10   ` sashiko-bot
2026-05-21 23:34 ` [PATCH v4 05/27] rust: pci: implement Sync for Device<Bound> Danilo Krummrich
2026-05-21 23:34 ` [PATCH v4 06/27] rust: platform: " Danilo Krummrich
2026-05-21 23:34 ` [PATCH v4 07/27] rust: auxiliary: " Danilo Krummrich
2026-05-21 23:34 ` [PATCH v4 08/27] rust: usb: " Danilo Krummrich
2026-05-22  0:16   ` sashiko-bot
2026-05-21 23:34 ` [PATCH v4 09/27] rust: device: " Danilo Krummrich
2026-05-21 23:34 ` [PATCH v4 10/27] rust: device: make Core and CoreInternal lifetime-parameterized Danilo Krummrich
2026-05-25  4:21   ` Eliot Courtney
2026-05-25 11:02   ` Alexandre Courbot
2026-05-21 23:34 ` [PATCH v4 11/27] rust: pci: make Driver trait lifetime-parameterized Danilo Krummrich
2026-05-22  0:14   ` sashiko-bot
2026-05-21 23:34 ` [PATCH v4 12/27] rust: platform: " Danilo Krummrich
2026-05-21 23:34 ` [PATCH v4 13/27] rust: auxiliary: " Danilo Krummrich
2026-05-21 23:34 ` [PATCH v4 14/27] rust: usb: " Danilo Krummrich
2026-05-22  0:23   ` sashiko-bot
2026-05-25  4:31   ` Eliot Courtney
2026-05-21 23:34 ` [PATCH v4 15/27] rust: i2c: " Danilo Krummrich
2026-05-21 23:34 ` [PATCH v4 16/27] rust: driver: update module documentation for GAT-based Data type Danilo Krummrich
2026-05-21 23:34 ` [PATCH v4 17/27] rust: pci: make Bar lifetime-parameterized Danilo Krummrich
2026-05-22  0:49   ` sashiko-bot [this message]
2026-05-25  4:37   ` Eliot Courtney
2026-05-25 11:40     ` Gary Guo
2026-05-25 12:05       ` Danilo Krummrich
2026-05-25 11:10   ` Alexandre Courbot
2026-05-25 11:12     ` Alexandre Courbot
2026-05-21 23:34 ` [PATCH v4 18/27] rust: io: make IoMem and ExclusiveIoMem lifetime-parameterized Danilo Krummrich
2026-05-22  0:45   ` sashiko-bot
2026-05-25 13:10   ` Alexandre Courbot
2026-05-21 23:34 ` [PATCH v4 19/27] samples: rust: rust_driver_pci: use HRT lifetime for Bar Danilo Krummrich
2026-05-22  1:27   ` sashiko-bot
2026-05-25 13:55   ` Alexandre Courbot
2026-05-21 23:34 ` [PATCH v4 20/27] gpu: nova-core: separate driver type from driver data Danilo Krummrich
2026-05-25  4:40   ` Eliot Courtney
2026-05-25 14:11   ` Alexandre Courbot
2026-05-21 23:34 ` [PATCH v4 21/27] rust: types: add `ForLt` trait for higher-ranked lifetime support Danilo Krummrich
2026-05-22  0:31   ` sashiko-bot
2026-05-23 15:46   ` Danilo Krummrich
2026-05-25 12:31     ` Eliot Courtney
2026-05-21 23:34 ` [PATCH v4 22/27] rust: auxiliary: generalize Registration over ForLt Danilo Krummrich
2026-05-22  0:49   ` sashiko-bot
2026-05-25  6:03   ` Eliot Courtney
2026-05-25 14:42   ` Alexandre Courbot
2026-05-21 23:34 ` [PATCH v4 23/27] samples: rust: rust_driver_auxiliary: showcase lifetime-bound registration data Danilo Krummrich
2026-05-25 14:48   ` Alexandre Courbot
2026-05-21 23:34 ` [PATCH REF v4 24/27] gpu: nova-core: use lifetime for Bar Danilo Krummrich
2026-05-22  1:28   ` sashiko-bot
2026-05-26  2:10   ` Alexandre Courbot
2026-05-26  5:48     ` Alexandre Courbot
2026-05-21 23:34 ` [PATCH REF v4 25/27] gpu: nova-core: unregister sysmem flush page from Drop Danilo Krummrich
2026-05-22  0:47   ` sashiko-bot
2026-05-21 23:34 ` [PATCH REF v4 26/27] gpu: nova-core: replace ARef<Device> with &'bound Device in SysmemFlush Danilo Krummrich
2026-05-22  0:46   ` sashiko-bot
2026-05-21 23:34 ` [PATCH REF v4 27/27] gpu: drm: tyr: use lifetime for IoMem Danilo Krummrich
2026-05-22  0:42   ` sashiko-bot
2026-05-22 10:14 ` [PATCH v4 00/27] rust: device: Higher-Ranked Lifetime Types for device drivers Greg KH

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260522004943.CDA7C1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dakr@kernel.org \
    --cc=linux-pci@vger.kernel.org \
    --cc=ojeda@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox