From: "Alexandre Courbot" <acourbot@nvidia.com>
To: "Gary Guo" <gary@garyguo.net>
Cc: "Alice Ryhl" <aliceryhl@google.com>,
"Daniel Almeida" <daniel.almeida@collabora.com>,
"Greg Kroah-Hartman" <gregkh@linuxfoundation.org>,
"Rafael J. Wysocki" <rafael@kernel.org>,
"Miguel Ojeda" <ojeda@kernel.org>,
"Boqun Feng" <boqun@kernel.org>,
"Björn Roy Baron" <bjorn3_gh@protonmail.com>,
"Benno Lossin" <lossin@kernel.org>,
"Andreas Hindborg" <a.hindborg@kernel.org>,
"Trevor Gross" <tmgross@umich.edu>,
"Bjorn Helgaas" <bhelgaas@google.com>,
"Krzysztof Wilczyński" <kwilczynski@kernel.org>,
"Abdiel Janulgue" <abdiel.janulgue@gmail.com>,
"Robin Murphy" <robin.murphy@arm.com>,
"David Airlie" <airlied@gmail.com>,
"Simona Vetter" <simona@ffwll.ch>,
"Danilo Krummrich" <dakr@kernel.org>,
driver-core@lists.linux.dev, rust-for-linux@vger.kernel.org,
linux-kernel@vger.kernel.org, linux-pci@vger.kernel.org,
nova-gpu@lists.linux.dev, dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v4 09/20] rust: io: use view types instead of addresses for `Io`
Date: Tue, 16 Jun 2026 23:05:55 +0900 [thread overview]
Message-ID: <DJAJ51781EOF.1Q2VTH6CQVXYD@nvidia.com> (raw)
In-Reply-To: <20260611-io_projection-v4-9-1f7224b02dcb@garyguo.net>
On Fri Jun 12, 2026 at 1:28 AM JST, Gary Guo wrote:
> Currently, `io_read` and `io_write` methods require the exact type of `Io`
> plus an address. This means that they need to be monomorphized for each
> different `Io` instance. This also means that multiple I/O implementors for
> the same I/O kind needs to duplicate implementation (e.g. `Mmio` and
> `MmioOwned`).
>
> Create a new `IoBackend` trait and define these operations on it instead.
> The operations are just going to receive a view type and operate on them.
> This has the additional advantage that the invariants can be moved from the
> trait (and guaranteed via `unsafe`) to type invariants on the canonical
> view types of the backends, so `io_read` and `io_write` can be safe.
>
> Note that view type is needed; addresses are insufficient in this
> designk, as they do not carry sufficient information. For example,
typo: design
> `ConfigSpace` needs `&pci::Device` in addition to the address.
>
> Signed-off-by: Gary Guo <gary@garyguo.net>
> ---
> rust/kernel/io.rs | 345 ++++++++++++++++++++++++++------------------------
> rust/kernel/pci/io.rs | 70 ++++++----
> 2 files changed, 224 insertions(+), 191 deletions(-)
>
> diff --git a/rust/kernel/io.rs b/rust/kernel/io.rs
> index 3ac8b396f5a7..e422a5ff2a5e 100644
> --- a/rust/kernel/io.rs
> +++ b/rust/kernel/io.rs
> @@ -244,6 +244,38 @@ const fn offset_valid<U>(base: usize, offset: usize, size: usize) -> bool {
> }
> }
>
> +/// I/O backends.
> +///
> +/// This is an abstract representation to be implemented by arbitrary I/O
> +/// backends (e.g. MMIO, PCI config space, etc.).
> +///
> +/// The base trait only defines the projection operations; which I/O methods are available depends
> +/// on which [`IoCapable<T>`] traits are implemented for the type. For example, for MMIO regions,
> +/// all widths (u8, u16, u32, and u64 on 64-bit systems) are typically supported. For PCI
> +/// configuration space, u8, u16, and u32 are supported but u64 is not.
> +///
> +/// This trait is separate from the `Io` trait as multiple different I/O types may share the same
> +/// operation.
> +pub trait IoBackend {
> + /// View type for this I/O backend.
> + type View<'a, T: ?Sized + KnownSize>: Io<'a, Backend = Self, Target = T>;
> +
> + /// Convert a `view` to a raw pointer for projection.
> + fn as_ptr<'a, T: ?Sized + KnownSize>(view: Self::View<'a, T>) -> *mut T;
Same as the previous patch, this pointer is not necessarily
dereferencable (e.g. for `pci::ConfigSpace`). This should probably be
mentioned, or maybe we can use a newtype to prevent dereferencing?
> +
> + /// Project `view` to its subregion indicated by `ptr`.
> + ///
> + /// If input `view` is valid, returned view must also be valid.
> + ///
> + /// # Safety
> + ///
> + /// `ptr` must be a projection of `Self::as_ptr(view)`.
> + unsafe fn project_view<'a, T: ?Sized + KnownSize, U: ?Sized + KnownSize>(
> + view: Self::View<'a, T>,
> + ptr: *mut U,
> + ) -> Self::View<'a, U>;
> +}
> +
> /// Trait indicating that an I/O backend supports operations of a certain type and providing an
> /// implementation for these operations.
> ///
> @@ -252,22 +284,12 @@ const fn offset_valid<U>(base: usize, offset: usize, size: usize) -> bool {
> /// For example, a PCI configuration space may implement `IoCapable<u8>`, `IoCapable<u16>`,
> /// and `IoCapable<u32>`, but not `IoCapable<u64>`, while an MMIO region on a 64-bit
> /// system might implement all four.
> -pub trait IoCapable<T> {
> - /// Performs an I/O read of type `T` at `address` and returns the result.
> - ///
> - /// # Safety
> - ///
> - /// - The range `[address..address + size_of::<T>()]` must be within the bounds of `Self`.
> - /// - `address` must be aligned.
> - unsafe fn io_read(self, address: usize) -> T;
> +pub trait IoCapable<T>: IoBackend {
> + /// Performs an I/O read of type `T` at `view` and returns the result.
> + fn io_read<'a>(view: Self::View<'a, T>) -> T;
>
> - /// Performs an I/O write of `value` at `address`.
> - ///
> - /// # Safety
> - ///
> - /// - The range `[address..address + size_of::<T>()]` must be within the bounds of `Self`.
> - /// - `address` must be aligned.
> - unsafe fn io_write(self, value: T, address: usize);
> + /// Performs an I/O write of `value` at `view`.
> + fn io_write<'a>(view: Self::View<'a, T>, value: T);
> }
>
> /// Describes a given I/O location: its offset, width, and type to convert the raw value from and
> @@ -319,56 +341,54 @@ fn offset(self) -> usize {
> /// Types implementing this trait (e.g. MMIO BARs or PCI config regions)
> /// can perform I/O operations on regions of memory.
> ///
> -/// This is an abstract representation to be implemented by arbitrary I/O
> -/// backends (e.g. MMIO, PCI config space, etc.).
> -///
> /// The [`Io`] trait provides:
> -/// - Base address and size information
> +/// - Method to convert into [`IoBackend::View`].
> /// - Helper methods for offset validation and address calculation
> /// - Fallible (runtime checked) accessors for different data widths
> ///
> -/// Which I/O methods are available depends on which [`IoCapable<T>`] traits
> -/// are implemented for the type.
> -///
> -/// # Examples
> -///
> -/// For MMIO regions, all widths (u8, u16, u32, and u64 on 64-bit systems) are typically
> -/// supported. For PCI configuration space, u8, u16, and u32 are supported but u64 is not.
> -pub trait Io: Copy {
> +/// Which I/O methods are available depends on the associated [`IoBackend`] implementation.
> +pub trait Io<'a>: Copy {
> + /// Type that defines all I/O operations.
> + type Backend: IoBackend;
> +
> /// Type of this I/O region. For untyped regions, [`Region`] can be used.
> type Target: ?Sized + KnownSize;
>
> - /// Returns the base address of this mapping.
> - fn addr(self) -> usize;
> -
> - /// Returns the maximum size of this mapping.
> - fn maxsize(self) -> usize;
> + /// Return a view that covers the full region.
> + fn as_view(self) -> <Self::Backend as IoBackend>::View<'a, Self::Target>;
>
> - /// Returns the absolute I/O address for a given `offset`,
> - /// performing compile-time bound checks.
> + /// Returns a view for a given `offset`, performing compile-time bound checks.
> // Always inline to optimize out error path of `build_assert`.
> #[inline(always)]
> - fn io_addr_assert<U>(self, offset: usize) -> usize {
> - // We cannot check alignment with `offset_valid` using `self.addr()`. So set 0 for it and
> + fn io_addr_assert<U>(self, offset: usize) -> <Self::Backend as IoBackend>::View<'a, U> {
Since this doesn't return an address anymore, should it be renamed?
> + // We cannot check alignment with `offset_valid` using `ptr.addr()`. So set 0 for it and
> // ensure alignment by checking that the alignment of `U` is smaller or equal to the
> // alignment of `Self::Target`.
> const_assert!(Alignment::of::<U>().as_usize() <= Self::Target::MIN_ALIGN.as_usize());
> build_assert!(offset_valid::<U>(0, offset, Self::Target::MIN_SIZE));
>
> - self.addr() + offset
> + let view = self.as_view();
> + let ptr = Self::Backend::as_ptr(view);
> + let projected_ptr = ptr.cast::<U>().wrapping_byte_add(offset);
> + // SAFETY: `offset_valid` checks for size and alignment and therefore `projected_ptr` is a
> + // valid projection.
> + unsafe { Self::Backend::project_view(view, projected_ptr) }
> }
>
> - /// Returns the absolute I/O address for a given `offset`,
> - /// performing runtime bound checks.
> + /// Returns a view for a given `offset`, performing runtime bound checks.
> #[inline]
> - fn io_addr<U>(self, offset: usize) -> Result<usize> {
> - if !offset_valid::<U>(self.addr(), offset, self.maxsize()) {
> + fn io_addr<U>(self, offset: usize) -> Result<<Self::Backend as IoBackend>::View<'a, U>> {
Same here.
And potentially, a more serious issue: `io_addr_assert` and `io_addr`
remain part of `Io`, which is a public trait. They only verify size and
alignment for `U`, not whether a projection of `U` at `offset` is
structurally valid. AFAICT this remains that way by the end of the
series, so users are able to call `io_addr*` to create and use invalid
projections.
Moving `io_addr*` out of the trait and into local helpers should be
enough to close that loophole.
Also, (and not entirely sure of it because I haven't completely wrapped
my head around the issue yet), we might need to seal or otherwise
restrict `IoLoc` so external code cannot create arbitrary
implementations that allow invalid projections.
next prev parent reply other threads:[~2026-06-16 14:06 UTC|newest]
Thread overview: 62+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-11 16:28 [PATCH v4 00/20] rust: I/O type generalization and projection Gary Guo
2026-06-11 16:28 ` [PATCH v4 01/20] rust: io: add dynamically-sized `Region` type Gary Guo
2026-06-13 10:05 ` Miguel Ojeda
2026-06-15 4:03 ` Alexandre Courbot
2026-06-15 10:05 ` Gary Guo
2026-06-15 11:47 ` Miguel Ojeda
2026-06-11 16:28 ` [PATCH v4 02/20] rust: io: add missing safety requirement in `IoCapable` methods Gary Guo
2026-06-15 4:28 ` Alexandre Courbot
2026-06-15 10:13 ` Gary Guo
2026-06-15 14:10 ` Alexandre Courbot
2026-06-11 16:28 ` [PATCH v4 03/20] rust: io: restrict untyped IO access and `register!` to `Region` Gary Guo
2026-06-15 5:17 ` Alexandre Courbot
2026-06-15 10:22 ` Gary Guo
2026-06-11 16:28 ` [PATCH v4 04/20] rust: io: implement `Io` on reference types instead Gary Guo
2026-06-11 17:07 ` sashiko-bot
2026-06-15 5:29 ` Alexandre Courbot
2026-06-11 16:28 ` [PATCH v4 05/20] rust: io: generalize `MmioRaw` to pointer to arbitrary type Gary Guo
2026-06-11 17:15 ` sashiko-bot
2026-06-15 8:04 ` Alexandre Courbot
2026-06-11 16:28 ` [PATCH v4 06/20] rust: io: rename `Mmio` to `MmioOwned` Gary Guo
2026-06-11 17:21 ` sashiko-bot
2026-06-15 8:09 ` Alexandre Courbot
2026-06-11 16:28 ` [PATCH v4 07/20] rust: io: implement `Mmio` as view type Gary Guo
2026-06-11 17:31 ` sashiko-bot
2026-06-15 14:52 ` Alexandre Courbot
2026-06-15 15:13 ` Gary Guo
2026-06-16 0:18 ` Alexandre Courbot
2026-06-16 11:12 ` Gary Guo
2026-06-16 14:22 ` Alexandre Courbot
2026-06-11 16:28 ` [PATCH v4 08/20] rust: pci: io: make `ConfigSpace` a view Gary Guo
2026-06-11 17:37 ` sashiko-bot
2026-06-16 6:34 ` Alexandre Courbot
2026-06-16 10:58 ` Gary Guo
2026-06-16 14:28 ` Alexandre Courbot
2026-06-11 16:28 ` [PATCH v4 09/20] rust: io: use view types instead of addresses for `Io` Gary Guo
2026-06-11 17:46 ` sashiko-bot
2026-06-16 14:05 ` Alexandre Courbot [this message]
2026-06-16 14:50 ` Gary Guo
2026-06-11 16:28 ` [PATCH v4 10/20] rust: io: remove `MmioOwned` Gary Guo
2026-06-11 17:54 ` sashiko-bot
2026-06-11 16:28 ` [PATCH v4 11/20] rust: io: move `Io` methods to extension trait Gary Guo
2026-06-11 18:00 ` sashiko-bot
2026-06-11 16:28 ` [PATCH v4 12/20] rust: prelude: add `zerocopy{,_derive}::IntoBytes` Gary Guo
2026-06-11 18:01 ` sashiko-bot
2026-06-11 16:28 ` [PATCH v4 13/20] rust: io: add projection macro and methods Gary Guo
2026-06-11 18:14 ` sashiko-bot
2026-06-11 18:34 ` Gary Guo
2026-06-11 16:28 ` [PATCH v4 14/20] rust: io: add I/O backend for system memory with volatile access Gary Guo
2026-06-11 18:23 ` sashiko-bot
2026-06-11 16:28 ` [PATCH v4 15/20] rust: io: implement a view type for `Coherent` Gary Guo
2026-06-11 18:30 ` sashiko-bot
2026-06-11 16:28 ` [PATCH v4 16/20] rust: io: add `read_val` and `write_val` functions on `Io` Gary Guo
2026-06-11 18:37 ` sashiko-bot
2026-06-11 16:28 ` [PATCH v4 17/20] gpu: nova-core: use I/O projection for cleaner encapsulation Gary Guo
2026-06-11 18:47 ` sashiko-bot
2026-06-11 16:28 ` [PATCH v4 18/20] rust: dma: drop `dma_read!` and `dma_write!` API Gary Guo
2026-06-11 19:01 ` sashiko-bot
2026-06-11 16:28 ` [PATCH v4 19/20] rust: io: add copying methods Gary Guo
2026-06-11 19:11 ` sashiko-bot
2026-06-11 19:36 ` Gary Guo
2026-06-11 16:28 ` [PATCH v4 20/20] rust: io: implement `IoSysMap` Gary Guo
2026-06-11 19:13 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DJAJ51781EOF.1Q2VTH6CQVXYD@nvidia.com \
--to=acourbot@nvidia.com \
--cc=a.hindborg@kernel.org \
--cc=abdiel.janulgue@gmail.com \
--cc=airlied@gmail.com \
--cc=aliceryhl@google.com \
--cc=bhelgaas@google.com \
--cc=bjorn3_gh@protonmail.com \
--cc=boqun@kernel.org \
--cc=dakr@kernel.org \
--cc=daniel.almeida@collabora.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=driver-core@lists.linux.dev \
--cc=gary@garyguo.net \
--cc=gregkh@linuxfoundation.org \
--cc=kwilczynski@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=lossin@kernel.org \
--cc=nova-gpu@lists.linux.dev \
--cc=ojeda@kernel.org \
--cc=rafael@kernel.org \
--cc=robin.murphy@arm.com \
--cc=rust-for-linux@vger.kernel.org \
--cc=simona@ffwll.ch \
--cc=tmgross@umich.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox