From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pg1-f172.google.com (mail-pg1-f172.google.com [209.85.215.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 88FFB2628D for ; Thu, 30 Apr 2026 00:49:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.172 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777510193; cv=none; b=Q7Uw0rOUhssclmh7ghcGj9OvQXu6gp/nYyuHw3yUaDM08KCYH2ht6fYOyxy11+FkuoDS27MPZUJmmH3dDpLi8Q1UugDOxBl/45JQ9objXrvy3yHOr5dTntwwF6lc8ymvCHq7gPE/vrcdKDlV5SmNJI6VnicK9FfO6lPdfTBjirI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777510193; c=relaxed/simple; bh=mKzrcvddoEBLoLAxv6IbWjadFKzrsk7xDstB8thFXC8=; h=From:To:Subject:Date:Message-ID:MIME-Version; b=e32za3oiBDp/9EshAXSBmRikLWiH8Kog/SqqXDqw0s305rplh2aI/F2SaFCb/YBTm+8hnQ51phhsFRKe3R/9ek5q5e5/1ars3apB2+Abzd3uS5dlPt5GRykBkVr4QubjKIyE+Ho8rYWLDB7Cu4qZg3jaJ434bl9uQAYgrg0H/rs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=JeDgeaif; arc=none smtp.client-ip=209.85.215.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="JeDgeaif" Received: by mail-pg1-f172.google.com with SMTP id 41be03b00d2f7-c795eacbeb0so112228a12.2 for ; Wed, 29 Apr 2026 17:49:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1777510192; x=1778114992; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:to :from:from:to:cc:subject:date:message-id:reply-to; bh=wVPXlO+qn0l+OSmwg7LhkgsAr5axNICfzufY4UApWCE=; b=JeDgeaifCZCdHJIrDZu2pWsv6gUQ5FVmHwv5YqPTCRtRdJHCcNPiyLPhPrFp4WsjoC jAbDO3yYGBBa6Jp7zwntdftXmxDsQ3p4V7N3GmqG0b5bfjoSecro0B8tokUXEjMepnXg MnEwq/LGft6rHmRuQ4qx1sNkSSZK3BKaU5mUZmsD1oOoHP/VKydcoTTk+w15TfDLFSrL dpAPBj/N6HhVZFyWbupw1LtsdduHO3wTCfL56X5k+Z0UfqJosM4lpAkLKCmMzFzJMENZ 7u/7wZ7WCTkikSwZXpujlY2v8oPCezDrUeLhpUT75TUJZILPj1I/WVJ07yWeEF448YKG WO2g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1777510192; x=1778114992; h=content-transfer-encoding:mime-version:message-id:date:subject:to :from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=wVPXlO+qn0l+OSmwg7LhkgsAr5axNICfzufY4UApWCE=; b=CQOhZyIib+2Ux/7BTXkvRN/7y+j1RWqIhFuKxoQsX/QbT1Bk9+TEbDFGkKFASSo5Pb VkNMwvl+6dlZF/Zmx3V9WwUW7SeUMZLgwP90lx7TW4Up3phBx1dM4KUPhXwAQnq9WdGw SdV1DEj8gfRTus7Z2bbE1c9XT1SWC0IR0rvHx3XkqPVlDmRwPmkY4+aCxrdsjA2Ziwsb ETUTkNLGCFKy7xF06L4B29scdcGQfZ0SXlraV8E4B68A84w2G+cnjpP08Exa6F+y0EHi UpScsV2oM5jmnuwTY7KBN3CxclGaPYuI2gXPRIpkEK8RD/nfdLW3PPFA05/JBdVqprBz 7dWA== X-Forwarded-Encrypted: i=1; AFNElJ98lfi/1KDJT3d1dYIyVnzgX3qHV4HDeeGzGhRArUF3ATaXZiR/08VivGnE9NidPa+xv8U7NAN44sI9XFw=@vger.kernel.org X-Gm-Message-State: AOJu0Ywn/AcWyDpIzFWBxSmf//pZ8bZ7KOJwpxaECYaSmHx7x9k7XDW5 YM/g9wzcRypKUFKG/caCCp9vpvQw+TcolbGKE8YUz7fQDWlWJTIZFlS4 X-Gm-Gg: AeBDieszwk8kQ3MzE7ctbQNfyphZFgbWaZUHGQj/wHhAJyvMc21ns/9yU86Wg2DfArI fUyLqukbLLZ7+wggUMd5HaIFH4T1K8cpOwBD9Kfgy/9ZnjuAlj/lA4dxbZkNGK5rPisLidDRtWb glsPL5ldiSSV4cNfiWnAIWsayM1h/CyhM54Ynd3gRfLu4M13sGB6jW2J5or48g3o5H9Sgjpvyt+ 3yDfn71k01YpNPq2D6DP9zXd02uepd0hTiIF5jbHs0cCo3oBQiumgouBNETQCnfbZzTWa62rC5f DqumZ7aIxQN4V9ftHU4nLQdZXCGoqXlNjgGR0LdHaV1tu8O6v64U+g6HNCVVOaLVrvM/CHOiwgT pY5LjpfDm6j03B+wvETC7phnLznfVuMy7uPaMkwYq99C+5JQrpvvhuFkRlBYxyGKRSqJx811iru HQZJZQm591hDfTIremvM0HrrXmdFj/T0dp3s//7FlmJMfuesxRLfA= X-Received: by 2002:a05:6a20:a11d:b0:3a2:dabf:feed with SMTP id adf61e73a8af0-3a3cf561bf0mr794737637.3.1777510191841; Wed, 29 Apr 2026 17:49:51 -0700 (PDT) Received: from Nighthawk.localdomain ([223.178.220.204]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-c7fd64f09fdsm3075997a12.17.2026.04.29.17.49.47 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 29 Apr 2026 17:49:51 -0700 (PDT) From: Sagar Taunk To: Miguel Ojeda , Boqun Feng , Gary Guo , =?UTF-8?q?Bj=C3=B6rn=20Roy=20Baron?= , Benno Lossin , Andreas Hindborg , Alice Ryhl , Trevor Gross , Danilo Krummrich , Tamir Duberstein , Sagar Taunk , Daniel Almeida , rust-for-linux@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH] rust: workqueue: replace SAFETY TODO for `WorkItemPointer` impl on `Pin>` Date: Thu, 30 Apr 2026 06:18:56 +0530 Message-ID: <20260430004857.38281-1-sagartaunk2@gmail.com> X-Mailer: git-send-email 2.54.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit The original implementation left a `SAFETY: TODO` comment on the `WorkItemPointer` implementation for `Pin>`. This patch documents the safety requirements that make this implementation sound. The safety argument relies on three guarantees: `__enqueue` strips the `Pin` wrapper via `Pin::into_inner_unchecked` and leaks the box via `KBox::into_raw`, producing a `*mut T` whose allocation remains live for the duration of the queued work; `work_container_of` safely reverses the `raw_get_work` offset arithmetic to recover the exact `*mut T` that `__enqueue` produced; and the workqueue guarantees `run` is called exactly once, making `KBox::from_raw` sound. Signed-off-by: Sagar Taunk --- rust/kernel/workqueue.rs | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/rust/kernel/workqueue.rs b/rust/kernel/workqueue.rs index 74c59f2b1c09..f31412fca303 100644 --- a/rust/kernel/workqueue.rs +++ b/rust/kernel/workqueue.rs @@ -881,7 +881,12 @@ unsafe impl RawDelayedWorkItem for Arc { } -// SAFETY: TODO. +// SAFETY: The `work_struct` pointer passed to `run` originates from `__enqueue`, +// which strips the `Pin` wrapper via `Pin::into_inner_unchecked()` and leaks the box +// via `KBox::into_raw()`, producing a `*mut T`. `work_container_of` then safely reverses +// the `raw_get_work` offset to recover that exact `*mut T`. The workqueue itself guarantees +// that `run` is called exactly once, so `KBox::from_raw()` correctly reclaims ownership +// of the leaked box. unsafe impl WorkItemPointer for Pin> where T: WorkItem, -- 2.54.0