From: sashiko-bot@kernel.org
To: "Gary Guo" <gary@garyguo.net>
Cc: dri-devel@lists.freedesktop.org,
"Alexandre Courbot" <acourbot@nvidia.com>,
ojeda@kernel.org, linux-pci@vger.kernel.org,
"Danilo Krummrich" <dakr@kernel.org>
Subject: Re: [PATCH v4 13/20] rust: io: add projection macro and methods
Date: Thu, 11 Jun 2026 18:14:17 +0000 [thread overview]
Message-ID: <20260611181418.1052D1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260611-io_projection-v4-13-1f7224b02dcb@garyguo.net>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] Deriving `FromBytes` on `Region<const SIZE: usize>` allows safe code to bypass the struct's documented `SIZE` invariant.
- [Low] Removal of trailing `//` on the vertical import block closing brace violates kernel Rust formatting rules.
--
commit 0616e76ffd1d8525b38835ead9f29afeae45c2ed
Author: Gary Guo <gary@garyguo.net>
Subject: Add an io_project!() macro allows projection from Io to a subview
This commit introduces an io_project!() macro that allows projection from Io
to a subview using compile-time checks. It also adds a try_cast() function
to perform size and alignment checks at runtime when type-casting is needed.
> diff --git a/rust/kernel/io.rs b/rust/kernel/io.rs
> index 470ee2ed9849..c7a9952af995 100644
> --- a/rust/kernel/io.rs
> +++ b/rust/kernel/io.rs
> @@ -14,7 +14,7 @@
> ptr::{
> Alignment,
> KnownSize, //
> - }, //
> + },
[Severity: Low]
This isn't a bug, but does removing the trailing // on the closing brace
violate the kernel Rust vertical import formatting rules? The coding
guidelines require this marker to prevent rustfmt from collapsing the
multi-line imports.
> };
>
> pub mod mem;
[ ... ]
> @@ -44,12 +44,12 @@
> /// This type can be used when an I/O region without known type information has a compile-time known
> /// minimum size (and a runtime known actual size).
> ///
> -/// This must be 4-byte aligned.
> -///
> /// # Invariants
> ///
> -/// Size of the region is at least as large as the `SIZE` generic parameter.
> +/// - Size of the region is at least as large as the `SIZE` generic parameter.
> +/// - Size of the region is multiple of 4.
> #[repr(C, align(4))]
> +#[derive(FromBytes)]
> pub struct Region<const SIZE: usize = 0> {
> inner: [u8],
> }
[Severity: High]
Does deriving FromBytes on Region allow safe code to bypass the documented
SIZE invariant?
By implementing zerocopy::FromBytes, safe code could use ref_from() to cast
any 4-byte aligned byte slice into a &Region. Since zerocopy only checks
that the slice length matches the dynamically computed layout size, which
for inner: [u8] is just the length of the slice, it appears safe code could
cast a 4-byte slice into a &Region<1024>.
Could this lead to out-of-bounds reads or writes if unsafe code
subsequently relies on the SIZE parameter for bounds checking?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260611-io_projection-v4-0-1f7224b02dcb@garyguo.net?part=13
next prev parent reply other threads:[~2026-06-11 18:14 UTC|newest]
Thread overview: 40+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-11 16:28 [PATCH v4 00/20] rust: I/O type generalization and projection Gary Guo
2026-06-11 16:28 ` [PATCH v4 01/20] rust: io: add dynamically-sized `Region` type Gary Guo
2026-06-11 16:28 ` [PATCH v4 02/20] rust: io: add missing safety requirement in `IoCapable` methods Gary Guo
2026-06-11 16:28 ` [PATCH v4 03/20] rust: io: restrict untyped IO access and `register!` to `Region` Gary Guo
2026-06-11 16:28 ` [PATCH v4 04/20] rust: io: implement `Io` on reference types instead Gary Guo
2026-06-11 17:07 ` sashiko-bot
2026-06-11 16:28 ` [PATCH v4 05/20] rust: io: generalize `MmioRaw` to pointer to arbitrary type Gary Guo
2026-06-11 17:15 ` sashiko-bot
2026-06-11 16:28 ` [PATCH v4 06/20] rust: io: rename `Mmio` to `MmioOwned` Gary Guo
2026-06-11 17:21 ` sashiko-bot
2026-06-11 16:28 ` [PATCH v4 07/20] rust: io: implement `Mmio` as view type Gary Guo
2026-06-11 17:31 ` sashiko-bot
2026-06-11 16:28 ` [PATCH v4 08/20] rust: pci: io: make `ConfigSpace` a view Gary Guo
2026-06-11 17:37 ` sashiko-bot
2026-06-11 16:28 ` [PATCH v4 09/20] rust: io: use view types instead of addresses for `Io` Gary Guo
2026-06-11 17:46 ` sashiko-bot
2026-06-11 16:28 ` [PATCH v4 10/20] rust: io: remove `MmioOwned` Gary Guo
2026-06-11 17:54 ` sashiko-bot
2026-06-11 16:28 ` [PATCH v4 11/20] rust: io: move `Io` methods to extension trait Gary Guo
2026-06-11 18:00 ` sashiko-bot
2026-06-11 16:28 ` [PATCH v4 12/20] rust: prelude: add `zerocopy{,_derive}::IntoBytes` Gary Guo
2026-06-11 18:01 ` sashiko-bot
2026-06-11 16:28 ` [PATCH v4 13/20] rust: io: add projection macro and methods Gary Guo
2026-06-11 18:14 ` sashiko-bot [this message]
2026-06-11 18:34 ` Gary Guo
2026-06-11 16:28 ` [PATCH v4 14/20] rust: io: add I/O backend for system memory with volatile access Gary Guo
2026-06-11 18:23 ` sashiko-bot
2026-06-11 16:28 ` [PATCH v4 15/20] rust: io: implement a view type for `Coherent` Gary Guo
2026-06-11 18:30 ` sashiko-bot
2026-06-11 16:28 ` [PATCH v4 16/20] rust: io: add `read_val` and `write_val` functions on `Io` Gary Guo
2026-06-11 18:37 ` sashiko-bot
2026-06-11 16:28 ` [PATCH v4 17/20] gpu: nova-core: use I/O projection for cleaner encapsulation Gary Guo
2026-06-11 18:47 ` sashiko-bot
2026-06-11 16:28 ` [PATCH v4 18/20] rust: dma: drop `dma_read!` and `dma_write!` API Gary Guo
2026-06-11 19:01 ` sashiko-bot
2026-06-11 16:28 ` [PATCH v4 19/20] rust: io: add copying methods Gary Guo
2026-06-11 19:11 ` sashiko-bot
2026-06-11 19:36 ` Gary Guo
2026-06-11 16:28 ` [PATCH v4 20/20] rust: io: implement `IoSysMap` Gary Guo
2026-06-11 19:13 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260611181418.1052D1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=acourbot@nvidia.com \
--cc=dakr@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=gary@garyguo.net \
--cc=linux-pci@vger.kernel.org \
--cc=ojeda@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox