NVIDIA GPU driver infrastructure
 help / color / mirror / Atom feed
From: Yury Norov <ynorov@nvidia.com>
To: Danilo Krummrich <dakr@kernel.org>
Cc: "Gary Guo" <gary@garyguo.net>,
	"Eliot Courtney" <ecourtney@nvidia.com>,
	"Alice Ryhl" <aliceryhl@google.com>,
	"Burak Emir" <burak.emir@gmail.com>,
	"Yury Norov" <yury.norov@gmail.com>,
	"Miguel Ojeda" <ojeda@kernel.org>,
	"Boqun Feng" <boqun@kernel.org>,
	"Björn Roy Baron" <bjorn3_gh@protonmail.com>,
	"Benno Lossin" <lossin@kernel.org>,
	"Andreas Hindborg" <a.hindborg@kernel.org>,
	"Trevor Gross" <tmgross@umich.edu>,
	"Daniel Almeida" <daniel.almeida@collabora.com>,
	"Tamir Duberstein" <tamird@kernel.org>,
	"Alexandre Courbot" <acourbot@nvidia.com>,
	"Onur Özkan" <work@onurozkan.dev>,
	"David Airlie" <airlied@gmail.com>,
	"Simona Vetter" <simona@ffwll.ch>,
	"Greg Kroah-Hartman" <gregkh@linuxfoundation.org>,
	"John Hubbard" <jhubbard@nvidia.com>,
	"Alistair Popple" <apopple@nvidia.com>,
	"Timur Tabi" <ttabi@nvidia.com>, "Zhi Wang" <zhiw@nvidia.com>,
	rust-for-linux@vger.kernel.org, linux-kernel@vger.kernel.org,
	nova-gpu@lists.linux.dev, dri-devel@lists.freedesktop.org,
	dri-devel <dri-devel-bounces@lists.freedesktop.org>
Subject: Re: [PATCH v5 5/5] gpu: nova-core: add ChannelIdPool
Date: Mon, 17 Aug 2026 18:40:16 -0400	[thread overview]
Message-ID: <aoON0FepAUw1b003@yury> (raw)
In-Reply-To: <DKRA0IU4WVW1.3AOKCY38VHTKZ@kernel.org>

On Mon, Aug 17, 2026 at 04:08:09PM +0200, Danilo Krummrich wrote:
> On Mon Aug 17, 2026 at 3:02 PM CEST, Gary Guo wrote:
> > Now, with `NonZero` or `Bounded`, we are doing none of that. The only thing here
> > is that there is a range restriction. Other than the value restriction
> > themselves, they carry no other semantic meanings. How you interpret these types
> > still fully depend on the API that accepts them. Therefore, it is very common
> > that you'd be using these with literals, and it becomes an ergnomic pain.
> 
> I agree that NonZero and Bounded are on the weaker end of the argument. But
> there's still the flexibility argument.
> 
> The API itself, i.e. alloc_area(), does not need to bother with how the value is
> checked. I.e. is it a runtime check, compile or build time check, or is it even
> unchecked (or panicking) because we can derive the invariant from another type.
> 
> > Personally I value ergnomics higher than possibility of misuse if latter can
> > be easily mitigated otherwise (in this case, by WARN_ON or just support
> > zero-sized alloc).
> 
> Both is not a mitigation IMO.
> 
> WARN_ON() is does not prevent misuse of the API in the first place and in case
> the value comes from userspace even introduces a vulnerability.
> 
> Making zero a valid argument simply ignores the problem or just moves it
> elsewhere, e.g. where the caller has to validate the returned type instead, i.e.
> the ChannelIdArea. IOW, we'd remove the invariant ChannelIdArea carries.

Let's get back to roots, maybe?

The kernel functions don't check parameters, with the very few
exceptions, because the kernel trusts itself.

What are those exceptions?

1. strnlen(char *s, unsigned count). Here the 'count' hard-stops
traversing the array 's' in case it's not null-terminated. Why?
Because c-string is the bad data structure, and it's a very common,
very well known vulnerability of C strings to have them not
null-terminated. It brings tons of troubles, that's why.

GENMASK(hi, lo) falls into the same category, for example. People
always think of it as GENMASK(lo, hi). Bad design...

2. FIELD_PREP(mask, val) checks mask for being dense and wide enough to
fit the val. It's a very basic operation, has 0 cost and implemented at
compile time. In fact, FIELD_PREP() is a compile-time macro. The
corresponding run-time field_prep() doesn't check for any consistency.

3. int pin_user_pages_fast(...) 
   {
        if (!is_valid_gup_args(pages, NULL, &gup_flags, FOLL_PIN))
                return -EINVAL;
        return gup_fast_fallback(start, nr_pages, gup_flags, pages);
   }

It's not a validator per se, like nr_pages == 0. It's rather a
consistency checker.

I don't think that alloc(size, align) matches one of the above. The
underlying bitmap is not as bad as C string, the alloc_area() is not
a compile-time macro, and NonZero<0>() doesn't look like a complex
cross-validation.

From maintenance perspective, I don't think it's even possible to pass
0 into the alloc_area(), so that it slips through the reviewers
attention. NonZero<0>() is a pure complication for absolutely no
reason.

Again, any kernel API trusts it's caller. It holds for assembler,
for C, and I don't see any reason why it shouldn't hold for Rust.

Rust is more restrictive to undefined behavior. Having that in mind,
we may want to prevent the known undef. But that should never become
a part of the API. And undef isn't the case for alloc(0) - instead
of making non-zero 'size' a part of API contract, we must make the
function behavior well defined for this case. kmalloc(0), for example,
returns ZERO_SIZE_PTR. The pool.alloc_area(0) may return None, and
probably trigger some warning.

The underlying bitmap_find_next_zero_area_of(0) doesn't behave well, so
Rust wrapper should take care of it. pool.alloc_area() doesn't call
the C function directly, it calls the wrapper. The problem must be
already resolved at this level.

Thanks,
Yury

  parent reply	other threads:[~2026-08-17 22:40 UTC|newest]

Thread overview: 37+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-12  8:51 [PATCH v5 0/5] rust: Add support for reserving of ranges of IDs Eliot Courtney
2026-08-12  8:51 ` [PATCH v5 1/5] rust: bitmap: use function-level cfg on kunit test Eliot Courtney
2026-08-12 22:23   ` Yury Norov
2026-08-12  8:51 ` [PATCH v5 2/5] rust: bitmap: restrict bitmap length to at most i32::MAX Eliot Courtney
2026-08-12 19:44   ` Yury Norov
2026-08-12  8:51 ` [PATCH v5 3/5] rust: bitmap: add contiguous area operations Eliot Courtney
2026-08-12 20:31   ` Yury Norov
2026-08-13  7:27     ` Eliot Courtney
2026-08-12  8:51 ` [PATCH v5 4/5] rust: id_pool: add contiguous area allocation Eliot Courtney
2026-08-12 21:16   ` Yury Norov
2026-08-13  7:29     ` Eliot Courtney
2026-08-12  8:51 ` [PATCH v5 5/5] gpu: nova-core: add ChannelIdPool Eliot Courtney
2026-08-12 22:18   ` Yury Norov
2026-08-13  7:31     ` Eliot Courtney
2026-08-13 18:32       ` Yury Norov
2026-08-13 20:20         ` Miguel Ojeda
2026-08-13 20:48         ` Danilo Krummrich
2026-08-13 20:58           ` Gary Guo
2026-08-13 21:38             ` John Hubbard
2026-08-13 21:44               ` Yury Norov
2026-08-13 21:53                 ` John Hubbard
2026-08-13 21:03           ` Yury Norov
2026-08-14  2:14             ` Eliot Courtney
2026-08-14  4:54               ` Eliot Courtney
2026-08-14  9:08                 ` Yury Norov
2026-08-14 14:53                   ` Yury Norov
2026-08-17  7:03                     ` Eliot Courtney
2026-08-17 10:54                       ` Gary Guo
2026-08-17 11:18                         ` Danilo Krummrich
2026-08-17 11:49                           ` Eliot Courtney
2026-08-17 12:16                             ` Danilo Krummrich
2026-08-17 12:37                               ` Eliot Courtney
2026-08-17 13:02                               ` Gary Guo
2026-08-17 14:08                                 ` Danilo Krummrich
2026-08-17 21:36                                   ` Burak Emir
2026-08-17 22:40                                   ` Yury Norov [this message]
2026-08-17 20:20                       ` Yury Norov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=aoON0FepAUw1b003@yury \
    --to=ynorov@nvidia.com \
    --cc=a.hindborg@kernel.org \
    --cc=acourbot@nvidia.com \
    --cc=airlied@gmail.com \
    --cc=aliceryhl@google.com \
    --cc=apopple@nvidia.com \
    --cc=bjorn3_gh@protonmail.com \
    --cc=boqun@kernel.org \
    --cc=burak.emir@gmail.com \
    --cc=dakr@kernel.org \
    --cc=daniel.almeida@collabora.com \
    --cc=dri-devel-bounces@lists.freedesktop.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=ecourtney@nvidia.com \
    --cc=gary@garyguo.net \
    --cc=gregkh@linuxfoundation.org \
    --cc=jhubbard@nvidia.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lossin@kernel.org \
    --cc=nova-gpu@lists.linux.dev \
    --cc=ojeda@kernel.org \
    --cc=rust-for-linux@vger.kernel.org \
    --cc=simona@ffwll.ch \
    --cc=tamird@kernel.org \
    --cc=tmgross@umich.edu \
    --cc=ttabi@nvidia.com \
    --cc=work@onurozkan.dev \
    --cc=yury.norov@gmail.com \
    --cc=zhiw@nvidia.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox