rust-for-linux.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Joel Fernandes <joelagnelf@nvidia.com>
To: Andrew Ballance <andrewjballance@gmail.com>
Cc: rust-for-linux@vger.kernel.org, linux-kernel@vger.kernel.org,
	John Hubbard <jhubbard@nvidia.com>,
	Alexandre Courbot <acourbot@nvidia.com>,
	Timur Tabi <ttabi@nvidia.com>,
	Alistair Popple <apopple@nvidia.com>,
	Miguel Ojeda <ojeda@kernel.org>
Subject: Re: Printing with overflow checks can cause modpost errors
Date: Tue, 16 Sep 2025 06:32:52 -0400	[thread overview]
Message-ID: <20250916103252.GA1660986@joelbox2> (raw)
In-Reply-To: <4940aa5a-18d0-4bcd-9125-80f5a9920627@gmail.com>

On Thu, Sep 11, 2025 at 11:08:17PM -0500, Andrew Ballance wrote:
> On 9/11/25 9:53 PM, Joel Fernandes wrote:
> > On Thu, Sep 11, 2025 at 07:27:26PM -0500, Andrew Ballance wrote:
> > > On Thu, Sep 11, 2025 at 05:31:57PM -0400, Joel Fernandes wrote:
> > > > Hello,
> > > > Recently some of have been running into modpost errors more frequently. Ahead
> > > > of Kangrejos, I am trying to study them, the one I looked at today is truly
> > > > weird, below are more details.
> > > > 
> > > > I narrowed it down to the print statement and specifically the FFI call to
> > > > printk bindings. This was first reported by Timur Tabi on CC.
> > > > 
> > > > With CONFIG_RUST_OVERFLOW_CHECKS=y and CONFIG_RUST_BUILD_ASSERT_ALLOW=y, the
> > > > following patch when applied to nova-core will fail to build with following
> > > > errors. The question is why does the overflow checking fail since the
> > > > arithmetic is valid, and why only during printing (and say not during the
> > > > call to write32).
> > > > 
> > > >    MODPOST Module.symvers
> > > > ERROR: modpost: "rust_build_error" [drivers/gpu/nova-core/nova_core.ko] undefined!
> > > > make[2]: *** [scripts/Makefile.modpost:147: Module.symvers] Error 1
> > > > make[1]: *** [/home/joelaf/repo/linux-nova-rm-call/Makefile:1961: modpost] Error 2
> > > > make: *** [Makefile:248: __sub-make] Error 2
> > > > 
> > > > Any comments or thoughts?
> > > > 
> > > 
> > > Io::write32 tries to do a bounds check at compile time and if it cannot
> > > be done it causes a build error. it looks like because a pointer to
> > > offset is passed across a ffi boundary, rustc makes no assumptions about
> > > the value of offset. so it cannot do the bounds check at compile time
> > > and causes a build error.
> > 
> > Are you saying this issue is related to iowrite32? I don't think so because
> > the issue does not happen if you comment out the pr_err in my example and
> > leave the write32 as it is. So it is something with the call to printk (FFI).
> > 
> > Why can't it assume the value of offset? All the values to compute it are
> > available at compile time right?
> > 
> > thanks,
> > 
> >   - Joel
> > 
> 
> This is a resend because I forgot to cc the mailing list.
> 
> it has to do with the FFI call. The value of offset can be found out at
> compile time, but because a pointer is passed through, the c side could
> theoretically change the value before write32 is called.
> The pointer passed is const so rustc should assume that the c side does
> not change offset, but looks like rustc does not do that.
> 
> as a test i created a version where a copy of offset is passed to printk
> instead of offset and it compiles.
> e.g:
> // SNIP
> let offset = <B as kernel::io::register::RegisterBase<$base>>::BASE
>     + Self::OFFSET
>     + (idx * Self::STRIDE);
> let offset_copy = offset;
> 
> pr_err!("{}", offset_copy);
> io.write32(self.0, offset);
> // SNIP

Andrew,
Thanks, I came to the same conclusion. After the first FFI call, the compiler
has to redo the overflow checking and cannot optimize it away. The issue does
not happen if either drop the print, or the io.write32, so it is their
combination that causes the issue.

So I guess how do we fix it? One crude way could be for the print macro to
alias its arguments automatically. But that does not fix the general problem
as it could occur with other FFI calls as well, not just printing.

thanks,

 - Joel


  parent reply	other threads:[~2025-09-16 10:32 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-09-11 21:31 Printing with overflow checks can cause modpost errors Joel Fernandes
2025-09-12  0:27 ` Andrew Ballance
2025-09-12  2:53   ` Joel Fernandes
2025-09-12  4:08     ` Andrew Ballance
2025-09-12  8:27       ` Miguel Ojeda
2025-09-12  9:45         ` Alice Ryhl
2025-09-12 10:08           ` Miguel Ojeda
2025-09-16 10:32       ` Joel Fernandes [this message]
2025-09-16 10:48         ` Joel Fernandes
2025-09-16 18:52           ` Joel Fernandes
2025-09-17 23:18             ` Timur Tabi

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250916103252.GA1660986@joelbox2 \
    --to=joelagnelf@nvidia.com \
    --cc=acourbot@nvidia.com \
    --cc=andrewjballance@gmail.com \
    --cc=apopple@nvidia.com \
    --cc=jhubbard@nvidia.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=ojeda@kernel.org \
    --cc=rust-for-linux@vger.kernel.org \
    --cc=ttabi@nvidia.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).