* [PATCH 0/4] rust: pin-init: merge `__init` and `__pinned_init`
@ 2026-07-22 18:50 Gary Guo
2026-07-22 18:50 ` [PATCH 1/4] rust: pin-init: merge `__pinned_init` and `__init` Gary Guo
` (3 more replies)
0 siblings, 4 replies; 5+ messages in thread
From: Gary Guo @ 2026-07-22 18:50 UTC (permalink / raw)
To: Benno Lossin, Miguel Ojeda, Boqun Feng, Björn Roy Baron,
Andreas Hindborg, Alice Ryhl, Trevor Gross, Danilo Krummrich,
Daniel Almeida, Tamir Duberstein, Alexandre Courbot,
Onur Özkan
Cc: rust-for-linux, linux-kernel, Gary Guo
Currently we have `PinInit::__pinned_init` and `Init::__init` which has
slightly different safety requirement but are required to do the same
thing. Instead of having to duplicate impl everywhere, it's simpler to just
use `Init` as a marker trait that cancels out the pinning requirement on
`PinInit::__pinned_init`. This also simplifies code (and shorten the symbol
name) so `__init` can always be used.
Note that to pull off this change it needs a stage approach. The plan is:
* Patch 1 (the `__pinned_init` and `__init` merge) is to be taken this
cycle through pin-init tree; this preserves the `__pinned_init` method as
an alias for compatibility.
* Patch 2 can be taken via driver-core this cycle.
* Patch 3 (tree-wide changes) to be taken next cycle. I can split this
further up next cycle so this can be routed via various subsystems.
* Patch 4 (removal of `__pinned_init`) is to be taken via pin-init two
cycles after.
---
This might be an opportunity to rethink about the API. IIRC we use `__init`
initially to avoid conflicts because we have the blanket impl on `T` and
`Result<T, E>`.
Maybe we should get rid of the underscores and name it something more
proper, like `init_ptr`, or maybe add an extension trait to raw pointers
type so you can do
unsafe { raw_ptr.init(something_that_impls_pin_init) }
?
To: Benno Lossin <lossin@kernel.org>
To: Miguel Ojeda <ojeda@kernel.org>
To: Boqun Feng <boqun@kernel.org>
To: Björn Roy Baron <bjorn3_gh@protonmail.com>
To: Andreas Hindborg <a.hindborg@kernel.org>
To: Alice Ryhl <aliceryhl@google.com>
To: Trevor Gross <tmgross@umich.edu>
To: Danilo Krummrich <dakr@kernel.org>
To: Daniel Almeida <daniel.almeida@collabora.com>
To: Tamir Duberstein <tamird@kernel.org>
To: Alexandre Courbot <acourbot@nvidia.com>
To: Onur Özkan <work@onurozkan.dev>
Cc: rust-for-linux@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Signed-off-by: Gary Guo <gary@garyguo.net>
---
Gary Guo (4):
rust: pin-init: merge `__pinned_init` and `__init`
rust: devres: use `cast_pin_init` instead of manual reimplementation
rust: treewide: replace `__pinned_init` with `__init`
rust: pin-init: remove `__pinned_init` method for `cfg(kernel)`
rust/kernel/alloc/kbox.rs | 6 +-
rust/kernel/devres.rs | 6 +-
rust/kernel/drm/device.rs | 2 +-
rust/kernel/drm/gpuvm/va.rs | 2 +-
rust/kernel/drm/gpuvm/vm_bo.rs | 2 +-
rust/kernel/init.rs | 10 +--
rust/kernel/pwm.rs | 2 +-
rust/kernel/sync/arc.rs | 4 +-
rust/kernel/types.rs | 2 +-
rust/macros/module.rs | 2 +-
rust/pin-init/examples/mutex.rs | 2 +-
rust/pin-init/examples/static_init.rs | 9 +--
rust/pin-init/src/__internal.rs | 8 +-
rust/pin-init/src/alloc.rs | 6 +-
rust/pin-init/src/lib.rs | 147 ++++++++++++++--------------------
15 files changed, 85 insertions(+), 125 deletions(-)
---
base-commit: b4515cf4156356e8f4fe6e0fdc17f59adab9772f
change-id: 20260722-merge-init-3ed98519ec7f
Best regards,
--
Gary Guo <gary@garyguo.net>
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH 1/4] rust: pin-init: merge `__pinned_init` and `__init`
2026-07-22 18:50 [PATCH 0/4] rust: pin-init: merge `__init` and `__pinned_init` Gary Guo
@ 2026-07-22 18:50 ` Gary Guo
2026-07-22 18:50 ` [PATCH 2/4] rust: devres: use `cast_pin_init` instead of manual reimplementation Gary Guo
` (2 subsequent siblings)
3 siblings, 0 replies; 5+ messages in thread
From: Gary Guo @ 2026-07-22 18:50 UTC (permalink / raw)
To: Benno Lossin, Miguel Ojeda, Boqun Feng, Björn Roy Baron,
Andreas Hindborg, Alice Ryhl, Trevor Gross, Danilo Krummrich,
Daniel Almeida, Tamir Duberstein, Alexandre Courbot,
Onur Özkan
Cc: rust-for-linux, linux-kernel, Gary Guo
These functions have the same requirements and are also required to execute
the same code. Prevent duplication by merging them to the single function
and document the additional relaxation of `Init::__init` on both the merged
function and the safety requirement of `Init`.
The existing `__pinned_init` function is deprecated and kept for
compatibility for existing users. For `cfg(kernel)`, it is soft-deprecated
for now and will be removed when all users are migrated.
Signed-off-by: Gary Guo <gary@garyguo.net>
---
rust/pin-init/examples/mutex.rs | 2 +-
rust/pin-init/examples/static_init.rs | 9 +--
rust/pin-init/src/__internal.rs | 8 +-
rust/pin-init/src/alloc.rs | 6 +-
rust/pin-init/src/lib.rs | 146 +++++++++++++---------------------
5 files changed, 68 insertions(+), 103 deletions(-)
diff --git a/rust/pin-init/examples/mutex.rs b/rust/pin-init/examples/mutex.rs
index 882f3e23f5dd..8a3236c0c502 100644
--- a/rust/pin-init/examples/mutex.rs
+++ b/rust/pin-init/examples/mutex.rs
@@ -81,7 +81,7 @@ pub fn new(val: impl PinInit<T>) -> impl PinInit<Self> {
locked: Cell::new(false),
data <- unsafe {
pin_init_from_closure(|slot: *mut UnsafeCell<T>| {
- val.__pinned_init(slot.cast::<T>())
+ val.__init(slot.cast::<T>())
})
},
})
diff --git a/rust/pin-init/examples/static_init.rs b/rust/pin-init/examples/static_init.rs
index 58cd4241b78c..8e71556ffe85 100644
--- a/rust/pin-init/examples/static_init.rs
+++ b/rust/pin-init/examples/static_init.rs
@@ -59,7 +59,7 @@ fn deref(&self) -> &Self::Target {
println!("doing init");
let ptr = self.cell.get().cast::<T>();
match self.init.take() {
- Some(f) => unsafe { f.__pinned_init(ptr).unwrap() },
+ Some(f) => unsafe { f.__init(ptr).unwrap() },
None => unsafe { core::hint::unreachable_unchecked() },
}
self.present.set(true);
@@ -71,13 +71,10 @@ fn deref(&self) -> &Self::Target {
pub struct CountInit;
unsafe impl PinInit<CMutex<usize>> for CountInit {
- unsafe fn __pinned_init(
- self,
- slot: *mut CMutex<usize>,
- ) -> Result<(), core::convert::Infallible> {
+ unsafe fn __init(self, slot: *mut CMutex<usize>) -> Result<(), core::convert::Infallible> {
let init = CMutex::new(0);
std::thread::sleep(std::time::Duration::from_millis(1000));
- unsafe { init.__pinned_init(slot) }
+ unsafe { init.__init(slot) }
}
}
diff --git a/rust/pin-init/src/__internal.rs b/rust/pin-init/src/__internal.rs
index 56dc655e323e..ae9a0e68cd75 100644
--- a/rust/pin-init/src/__internal.rs
+++ b/rust/pin-init/src/__internal.rs
@@ -181,7 +181,7 @@ pub fn init<E>(self: Pin<&mut Self>, init: impl PinInit<T, E>) -> Result<Pin<&mu
unsafe { this.value.assume_init_drop() };
}
// SAFETY: The memory slot is valid and this type ensures that it will stay pinned.
- unsafe { init.__pinned_init(this.value.as_mut_ptr())? };
+ unsafe { init.__init(this.value.as_mut_ptr())? };
// INVARIANT: `this.value` is initialized above.
this.is_init = true;
// SAFETY: The slot is now pinned, since we will never give access to `&mut T`.
@@ -289,7 +289,7 @@ pub fn init<E>(self, init: impl PinInit<T, E>) -> Result<DropGuard<Pinned, T>, E
// - when `Err` is returned, we also propagate the error without touching `ptr`;
// also `self` is consumed so it cannot be touched further.
// - the drop guard will not hand out `&mut` (only `Pin<&mut T>`).
- unsafe { init.__pinned_init(self.ptr)? };
+ unsafe { init.__init(self.ptr)? };
// SAFETY:
// - `self.ptr` is valid, properly aligned and pinned per type invariant.
@@ -396,9 +396,9 @@ fn default() -> Self {
}
}
-// SAFETY: `__pinned_init` always fails, which is always okay.
+// SAFETY: `__init` always fails, which is always okay.
unsafe impl<T: ?Sized> PinInit<T, ()> for AlwaysFail<T> {
- unsafe fn __pinned_init(self, _slot: *mut T) -> Result<(), ()> {
+ unsafe fn __init(self, _slot: *mut T) -> Result<(), ()> {
Err(())
}
}
diff --git a/rust/pin-init/src/alloc.rs b/rust/pin-init/src/alloc.rs
index 5017f57442d8..641f4c7ce890 100644
--- a/rust/pin-init/src/alloc.rs
+++ b/rust/pin-init/src/alloc.rs
@@ -38,7 +38,7 @@ fn try_pin_init<E>(init: impl PinInit<T, E>) -> Result<Pin<Self>, E>
fn pin_init(init: impl PinInit<T>) -> Result<Pin<Self>, AllocError> {
// SAFETY: We delegate to `init` and only change the error type.
let init = unsafe {
- pin_init_from_closure(|slot| match init.__pinned_init(slot) {
+ pin_init_from_closure(|slot| match init.__init(slot) {
Ok(()) => Ok(()),
Err(i) => match i {},
})
@@ -109,7 +109,7 @@ fn try_pin_init<E>(init: impl PinInit<T, E>) -> Result<Pin<Self>, E>
let slot = slot.as_mut_ptr();
// SAFETY: When init errors/panics, slot will get deallocated but not dropped,
// slot is valid and will not be moved, because we pin it later.
- unsafe { init.__pinned_init(slot)? };
+ unsafe { init.__init(slot)? };
// SAFETY: All fields have been initialized and this is the only `Arc` to that data.
Ok(unsafe { Pin::new_unchecked(this.assume_init()) })
}
@@ -149,7 +149,7 @@ fn write_pin_init<E>(mut self, init: impl PinInit<T, E>) -> Result<Pin<Self::Ini
let slot = self.as_mut_ptr();
// SAFETY: When init errors/panics, slot will get deallocated but not dropped,
// slot is valid and will not be moved, because we pin it later.
- unsafe { init.__pinned_init(slot)? };
+ unsafe { init.__init(slot)? };
// SAFETY: All fields have been initialized.
Ok(unsafe { self.assume_init() }.into())
}
diff --git a/rust/pin-init/src/lib.rs b/rust/pin-init/src/lib.rs
index ef9f20b11034..354fbefcf80e 100644
--- a/rust/pin-init/src/lib.rs
+++ b/rust/pin-init/src/lib.rs
@@ -889,7 +889,7 @@ macro_rules! assert_pinned {
/// When implementing this trait you will need to take great care. Also there are probably very few
/// cases where a manual implementation is necessary. Use [`pin_init_from_closure`] where possible.
///
-/// The [`PinInit::__pinned_init`] function:
+/// The [`PinInit::__init`] function:
/// - returns `Ok(())` if it initialized every field of `slot`,
/// - returns `Err(err)` if it encountered an error and then cleaned `slot`, this means:
/// - `slot` can be deallocated without UB occurring,
@@ -909,6 +909,20 @@ macro_rules! assert_pinned {
#[cfg_attr(not(kernel), doc = "[`Box<T>`]: alloc::alloc::boxed::Box")]
#[must_use = "An initializer must be used in order to create its value."]
pub unsafe trait PinInit<T: ?Sized, E = Infallible>: Sized {
+ /// Alias of [`PinInit::__init`].
+ ///
+ /// New code should use `__init` instead.
+ ///
+ /// # Safety
+ ///
+ /// Same as `__init`.
+ #[inline(always)]
+ #[cfg_attr(not(kernel), deprecated = "use `__init` instead")]
+ unsafe fn __pinned_init(self, slot: *mut T) -> Result<(), E> {
+ // SAFETY: Per safety requirement.
+ unsafe { self.__init(slot) }
+ }
+
/// Initializes `slot`.
///
/// # Safety
@@ -917,7 +931,8 @@ pub unsafe trait PinInit<T: ?Sized, E = Infallible>: Sized {
/// - the caller does not touch `slot` when `Err` is returned, they are only permitted to
/// deallocate.
/// - `slot` will not move until it is dropped, i.e. it will be pinned.
- unsafe fn __pinned_init(self, slot: *mut T) -> Result<(), E>;
+ /// If `Self: Init<T, E>`, this requirement is cancelled and it may be moved.
+ unsafe fn __init(self, slot: *mut T) -> Result<(), E>;
/// First initializes the value using `self` then calls the function `f` with the initialized
/// value.
@@ -948,7 +963,7 @@ fn pin_chain<F>(self, f: F) -> ChainPinInit<Self, F, T, E>
/// An initializer returned by [`PinInit::pin_chain`].
pub struct ChainPinInit<I, F, T: ?Sized, E>(I, F, __internal::PhantomInvariant<(E, T)>);
-// SAFETY: The `__pinned_init` function is implemented such that it
+// SAFETY: The `__init` function is implemented such that it
// - returns `Ok(())` on successful initialization,
// - returns `Err(err)` on error and in this case `slot` will be dropped.
// - considers `slot` pinned.
@@ -957,8 +972,8 @@ unsafe impl<T: ?Sized, E, I, F> PinInit<T, E> for ChainPinInit<I, F, T, E>
I: PinInit<T, E>,
F: FnOnce(Pin<&mut T>) -> Result<(), E>,
{
- unsafe fn __pinned_init(self, slot: *mut T) -> Result<(), E> {
- // SAFETY: All requirements fulfilled since this function is `__pinned_init`.
+ unsafe fn __init(self, slot: *mut T) -> Result<(), E> {
+ // SAFETY: All requirements fulfilled since this function is `__init`.
let slot = unsafe { __internal::Slot::<__internal::Pinned, _>::new(slot) };
let mut guard = slot.init(self.0)?;
(self.1)(guard.let_binding())?;
@@ -980,19 +995,8 @@ unsafe fn __pinned_init(self, slot: *mut T) -> Result<(), E> {
/// When implementing this trait you will need to take great care. Also there are probably very few
/// cases where a manual implementation is necessary. Use [`init_from_closure`] where possible.
///
-/// The [`Init::__init`] function:
-/// - returns `Ok(())` if it initialized every field of `slot`,
-/// - returns `Err(err)` if it encountered an error and then cleaned `slot`, this means:
-/// - `slot` can be deallocated without UB occurring,
-/// - `slot` does not need to be dropped,
-/// - `slot` is not partially initialized.
-/// - while constructing the `T` at `slot` it upholds the pinning invariants of `T`.
-///
-/// The `__pinned_init` function from the supertrait [`PinInit`] needs to execute the exact same
-/// code as `__init`.
-///
-/// Contrary to its supertype [`PinInit<T, E>`] the caller is allowed to
-/// move the pointee after initialization.
+/// The [`PinInit::__init`] function must work without the pinning requirement; the caller is
+/// allowed to move the pointee after initialization.
///
#[cfg_attr(
kernel,
@@ -1006,15 +1010,6 @@ unsafe fn __pinned_init(self, slot: *mut T) -> Result<(), E> {
#[cfg_attr(not(kernel), doc = "[`Box<T>`]: alloc::alloc::boxed::Box")]
#[must_use = "An initializer must be used in order to create its value."]
pub unsafe trait Init<T: ?Sized, E = Infallible>: PinInit<T, E> {
- /// Initializes `slot`.
- ///
- /// # Safety
- ///
- /// - `slot` is a valid pointer to uninitialized memory.
- /// - the caller does not touch `slot` when `Err` is returned, they are only permitted to
- /// deallocate.
- unsafe fn __init(self, slot: *mut T) -> Result<(), E>;
-
/// First initializes the value using `self` then calls the function `f` with the initialized
/// value.
///
@@ -1053,10 +1048,18 @@ fn chain<F>(self, f: F) -> ChainInit<Self, F, T, E>
/// An initializer returned by [`Init::chain`].
pub struct ChainInit<I, F, T: ?Sized, E>(I, F, __internal::PhantomInvariant<(E, T)>);
+// SAFETY: The `__init` function does not rely on the pinning requirement.
+unsafe impl<T: ?Sized, E, I, F> Init<T, E> for ChainInit<I, F, T, E>
+where
+ I: Init<T, E>,
+ F: FnOnce(&mut T) -> Result<(), E>,
+{
+}
+
// SAFETY: The `__init` function is implemented such that it
// - returns `Ok(())` on successful initialization,
// - returns `Err(err)` on error and in this case `slot` will be dropped.
-unsafe impl<T: ?Sized, E, I, F> Init<T, E> for ChainInit<I, F, T, E>
+unsafe impl<T: ?Sized, E, I, F> PinInit<T, E> for ChainInit<I, F, T, E>
where
I: Init<T, E>,
F: FnOnce(&mut T) -> Result<(), E>,
@@ -1071,44 +1074,28 @@ unsafe fn __init(self, slot: *mut T) -> Result<(), E> {
}
}
-// SAFETY: `__pinned_init` behaves exactly the same as `__init`.
-unsafe impl<T: ?Sized, E, I, F> PinInit<T, E> for ChainInit<I, F, T, E>
-where
- I: Init<T, E>,
- F: FnOnce(&mut T) -> Result<(), E>,
-{
- unsafe fn __pinned_init(self, slot: *mut T) -> Result<(), E> {
- // SAFETY: `__init` has less strict requirements compared to `__pinned_init`.
- unsafe { self.__init(slot) }
- }
-}
-
/// Implement `PinInit` and `Init` for closures.
///
/// It is unsafe to create this type, since the closure needs to fulfill the same safety
-/// requirement as the `__pinned_init`/`__init` functions.
+/// requirement as the `__init` functions.
struct InitClosure<F, T: ?Sized>(F, __internal::PhantomInvariant<T>);
-// SAFETY: While constructing the `InitClosure`, the user promised that it upholds the
-// `__init` invariants.
-unsafe impl<T: ?Sized, F, E> Init<T, E> for InitClosure<F, T>
-where
- F: FnOnce(*mut T) -> Result<(), E>,
+// SAFETY: When constructing via `init_from_closure`, the `__init` function does not rely on the
+// pinning requirement. When constructing via `pin_init_from_closure`, the opaque type prevents this
+// implementation from being visible.
+unsafe impl<T: ?Sized, F, E> Init<T, E> for InitClosure<F, T> where
+ F: FnOnce(*mut T) -> Result<(), E>
{
- #[inline]
- unsafe fn __init(self, slot: *mut T) -> Result<(), E> {
- (self.0)(slot)
- }
}
// SAFETY: While constructing the `InitClosure`, the user promised that it upholds the
-// `__pinned_init` invariants.
+// `__init` invariants.
unsafe impl<T: ?Sized, F, E> PinInit<T, E> for InitClosure<F, T>
where
F: FnOnce(*mut T) -> Result<(), E>,
{
#[inline]
- unsafe fn __pinned_init(self, slot: *mut T) -> Result<(), E> {
+ unsafe fn __init(self, slot: *mut T) -> Result<(), E> {
(self.0)(slot)
}
}
@@ -1160,7 +1147,7 @@ unsafe fn __pinned_init(self, slot: *mut T) -> Result<(), E> {
pub const unsafe fn cast_pin_init<T, U, E>(init: impl PinInit<T, E>) -> impl PinInit<U, E> {
// SAFETY: initialization delegated to a valid initializer. Cast is valid by function safety
// requirements.
- unsafe { pin_init_from_closure(|ptr: *mut U| init.__pinned_init(ptr.cast::<T>())) }
+ unsafe { pin_init_from_closure(|ptr: *mut U| init.__init(ptr.cast::<T>())) }
}
/// Changes the to be initialized type.
@@ -1195,7 +1182,7 @@ pub fn uninit<T, E>() -> impl Init<MaybeUninit<T>, E> {
F: FnMut(usize) -> I,
I: PinInit<T, E>,
{
- unsafe fn __pinned_init(mut self, slot: *mut [T; N]) -> Result<(), E> {
+ unsafe fn __init(mut self, slot: *mut [T; N]) -> Result<(), E> {
/// # Invariants
///
/// - `ptr[..num_init]` contains initialized elements of type `T`
@@ -1237,7 +1224,7 @@ fn drop(&mut self) {
// - If `Err` is touched, the subslot is not touched further, the guard will drop
// previously initialized elements only.
// - `slot` is pinned so is the subslot.
- unsafe { init.__pinned_init(&raw mut (*slot)[i]) }?;
+ unsafe { init.__init(&raw mut (*slot)[i]) }?;
}
// Dismiss the drop guard now that all elements are initialized.
@@ -1246,18 +1233,13 @@ fn drop(&mut self) {
}
}
-// SAFETY: Follows the `PinInit` impl. `__init` executes the same code as `__pinned_init`.
+// SAFETY: `I: Init` cancels out the pinning requirement on subslots, which is the only place in the
+// `__init` function that relies on `slot` being pinned.
unsafe impl<T, F, I, E, const N: usize> Init<[T; N], E> for ArrayInit<T, F>
where
F: FnMut(usize) -> I,
I: Init<T, E>,
{
- #[inline(always)]
- unsafe fn __init(self, slot: *mut [T; N]) -> Result<(), E> {
- // SAFETY: `I: Init` cancels out the pinning requirement on subslots. The other safety
- // requirements follow that of `__init`.
- unsafe { self.__pinned_init(slot) }
- }
}
/// Initializes an array by initializing each element via the provided initializer.
@@ -1336,13 +1318,13 @@ pub fn pin_init_scope<T, E, F, I>(make_init: F) -> impl PinInit<T, E>
{
// SAFETY:
// - If `make_init` returns `Err`, `Err` is returned and `slot` is completely uninitialized,
- // - If `make_init` returns `Ok`, safety requirement are fulfilled by `init.__pinned_init`.
- // - The safety requirements of `init.__pinned_init` are fulfilled, since it's being called
- // from an initializer.
+ // - If `make_init` returns `Ok`, safety requirement are fulfilled by `init.__init`.
+ // - The safety requirements of `init.__init` are fulfilled, since it's being called from an
+ // initializer.
unsafe {
pin_init_from_closure(move |slot: *mut T| -> Result<(), E> {
let init = make_init()?;
- init.__pinned_init(slot)
+ init.__init(slot)
})
}
}
@@ -1390,41 +1372,27 @@ pub fn init_scope<T, E, F, I>(make_init: F) -> impl Init<T, E>
}
}
-// SAFETY: the `__init` function always returns `Ok(())` and initializes every field of `slot`.
-unsafe impl<T> Init<T> for T {
- unsafe fn __init(self, slot: *mut T) -> Result<(), Infallible> {
- // SAFETY: `slot` is valid for writes by the safety requirements of this function.
- unsafe { slot.write(self) };
- Ok(())
- }
-}
+// SAFETY: The `__init` function does not rely on slot being pinned after it returns.
+unsafe impl<T> Init<T> for T {}
-// SAFETY: the `__pinned_init` function always returns `Ok(())` and initializes every field of
+// SAFETY: the `__init` function always returns `Ok(())` and initializes every field of
// `slot`. Additionally, all pinning invariants of `T` are upheld.
unsafe impl<T> PinInit<T> for T {
- unsafe fn __pinned_init(self, slot: *mut T) -> Result<(), Infallible> {
+ unsafe fn __init(self, slot: *mut T) -> Result<(), Infallible> {
// SAFETY: `slot` is valid for writes by the safety requirements of this function.
unsafe { slot.write(self) };
Ok(())
}
}
-// SAFETY: when the `__init` function returns with
-// - `Ok(())`, `slot` was initialized and all pinned invariants of `T` are upheld.
-// - `Err(err)`, slot was not written to.
-unsafe impl<T, E> Init<T, E> for Result<T, E> {
- unsafe fn __init(self, slot: *mut T) -> Result<(), E> {
- // SAFETY: `slot` is valid for writes by the safety requirements of this function.
- unsafe { slot.write(self?) };
- Ok(())
- }
-}
+// SAFETY: The `__init` function does not rely on slot being pinned after it returns.
+unsafe impl<T, E> Init<T, E> for Result<T, E> {}
-// SAFETY: when the `__pinned_init` function returns with
+// SAFETY: when the `__init` function returns with
// - `Ok(())`, `slot` was initialized and all pinned invariants of `T` are upheld.
// - `Err(err)`, slot was not written to.
unsafe impl<T, E> PinInit<T, E> for Result<T, E> {
- unsafe fn __pinned_init(self, slot: *mut T) -> Result<(), E> {
+ unsafe fn __init(self, slot: *mut T) -> Result<(), E> {
// SAFETY: `slot` is valid for writes by the safety requirements of this function.
unsafe { slot.write(self?) };
Ok(())
@@ -1467,7 +1435,7 @@ fn write_pin_init<E>(self, init: impl PinInit<T, E>) -> Result<Pin<Self::Initial
//
// The `'static` borrow guarantees the data will not be
// moved/invalidated until it gets dropped (which is never).
- unsafe { init.__pinned_init(slot)? };
+ unsafe { init.__init(slot)? };
// SAFETY: The above call initialized the memory.
Ok(Pin::static_mut(unsafe { self.assume_init_mut() }))
--
2.54.0
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [PATCH 2/4] rust: devres: use `cast_pin_init` instead of manual reimplementation
2026-07-22 18:50 [PATCH 0/4] rust: pin-init: merge `__init` and `__pinned_init` Gary Guo
2026-07-22 18:50 ` [PATCH 1/4] rust: pin-init: merge `__pinned_init` and `__init` Gary Guo
@ 2026-07-22 18:50 ` Gary Guo
2026-07-22 18:50 ` [PATCH 3/4] rust: treewide: replace `__pinned_init` with `__init` Gary Guo
2026-07-22 18:50 ` [PATCH 4/4] rust: pin-init: remove `__pinned_init` method for `cfg(kernel)` Gary Guo
3 siblings, 0 replies; 5+ messages in thread
From: Gary Guo @ 2026-07-22 18:50 UTC (permalink / raw)
To: Benno Lossin, Miguel Ojeda, Boqun Feng, Björn Roy Baron,
Andreas Hindborg, Alice Ryhl, Trevor Gross, Danilo Krummrich,
Daniel Almeida, Tamir Duberstein, Alexandre Courbot,
Onur Özkan
Cc: rust-for-linux, linux-kernel, Gary Guo
Remove the manual type-casting which is already available as
`cast_pin_init`.
Signed-off-by: Gary Guo <gary@garyguo.net>
---
rust/kernel/devres.rs | 6 +-----
1 file changed, 1 insertion(+), 5 deletions(-)
diff --git a/rust/kernel/devres.rs b/rust/kernel/devres.rs
index ebb5c19e851e..aecc8906de2c 100644
--- a/rust/kernel/devres.rs
+++ b/rust/kernel/devres.rs
@@ -435,11 +435,7 @@ pub unsafe fn new<'a, E>(
// SAFETY: The caller guarantees the data is valid for the device's full bound scope.
// Lifetimes do not affect layout, so F::Of<'a> and F::Of<'static> have identical
// representation; casting the slot pointer is sound.
- let data = unsafe {
- pin_init::pin_init_from_closure::<F::Of<'static>, E>(move |slot| {
- data.__pinned_init(slot.cast())
- })
- };
+ let data = unsafe { pin_init::cast_pin_init(data) };
Ok(Self(Devres::new(dev, data)?))
}
--
2.54.0
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [PATCH 3/4] rust: treewide: replace `__pinned_init` with `__init`
2026-07-22 18:50 [PATCH 0/4] rust: pin-init: merge `__init` and `__pinned_init` Gary Guo
2026-07-22 18:50 ` [PATCH 1/4] rust: pin-init: merge `__pinned_init` and `__init` Gary Guo
2026-07-22 18:50 ` [PATCH 2/4] rust: devres: use `cast_pin_init` instead of manual reimplementation Gary Guo
@ 2026-07-22 18:50 ` Gary Guo
2026-07-22 18:50 ` [PATCH 4/4] rust: pin-init: remove `__pinned_init` method for `cfg(kernel)` Gary Guo
3 siblings, 0 replies; 5+ messages in thread
From: Gary Guo @ 2026-07-22 18:50 UTC (permalink / raw)
To: Benno Lossin, Miguel Ojeda, Boqun Feng, Björn Roy Baron,
Andreas Hindborg, Alice Ryhl, Trevor Gross, Danilo Krummrich,
Daniel Almeida, Tamir Duberstein, Alexandre Courbot,
Onur Özkan
Cc: rust-for-linux, linux-kernel, Gary Guo
The `__pinned_init` is being merged with `__init` and is soft-deprecated
and is to be removed. Replace the users with `__init`.
Signed-off-by: Gary Guo <gary@garyguo.net>
---
rust/kernel/alloc/kbox.rs | 6 +++---
rust/kernel/drm/device.rs | 2 +-
rust/kernel/drm/gpuvm/va.rs | 2 +-
rust/kernel/drm/gpuvm/vm_bo.rs | 2 +-
rust/kernel/init.rs | 10 ++++------
rust/kernel/pwm.rs | 2 +-
rust/kernel/sync/arc.rs | 4 ++--
rust/kernel/types.rs | 2 +-
rust/macros/module.rs | 2 +-
9 files changed, 15 insertions(+), 17 deletions(-)
diff --git a/rust/kernel/alloc/kbox.rs b/rust/kernel/alloc/kbox.rs
index 35d1e015848d..78e929ed3382 100644
--- a/rust/kernel/alloc/kbox.rs
+++ b/rust/kernel/alloc/kbox.rs
@@ -372,13 +372,13 @@ pub fn pin_slice<Func, Item, E>(
// - `ptr` is a valid pointer to uninitialized memory.
// - `ptr` is not used if an error is returned.
// - `ptr` won't be moved until it is dropped, i.e. it is pinned.
- unsafe { init(i).__pinned_init(ptr)? };
+ unsafe { init(i).__init(ptr)? };
// SAFETY:
// - `i + 1 <= len`, hence we don't exceed the capacity, due to the call to
// `with_capacity()` above.
// - The new value at index buffer.len() + 1 is the only element being added here, and
- // it has been initialized above by `init(i).__pinned_init(ptr)`.
+ // it has been initialized above by `init(i).__init(ptr)`.
unsafe { buffer.inc_len(1) };
}
@@ -473,7 +473,7 @@ fn write_pin_init<E>(mut self, init: impl PinInit<T, E>) -> Result<Pin<Self::Ini
let slot = self.as_mut_ptr();
// SAFETY: When init errors/panics, slot will get deallocated but not dropped,
// slot is valid and will not be moved, because we pin it later.
- unsafe { init.__pinned_init(slot)? };
+ unsafe { init.__init(slot)? };
// SAFETY: All fields have been initialized.
Ok(unsafe { Box::assume_init(self) }.into())
}
diff --git a/rust/kernel/drm/device.rs b/rust/kernel/drm/device.rs
index f43c6887ad23..4eadfefbe9e5 100644
--- a/rust/kernel/drm/device.rs
+++ b/rust/kernel/drm/device.rs
@@ -239,7 +239,7 @@ pub fn new(
// SAFETY:
// - `raw_data` is a valid pointer to uninitialized memory.
// - `raw_data` will not move until it is dropped.
- unsafe { data.__pinned_init(raw_data) }.inspect_err(|_| {
+ unsafe { data.__init(raw_data) }.inspect_err(|_| {
// SAFETY: `__drm_dev_alloc()` was successful, hence `drm_dev` must be valid and the
// refcount must be non-zero.
unsafe { bindings::drm_dev_put(drm_dev) };
diff --git a/rust/kernel/drm/gpuvm/va.rs b/rust/kernel/drm/gpuvm/va.rs
index b108ec7aa1bc..12a3d613f523 100644
--- a/rust/kernel/drm/gpuvm/va.rs
+++ b/rust/kernel/drm/gpuvm/va.rs
@@ -124,7 +124,7 @@ pub fn new(flags: AllocFlags) -> Result<GpuVaAlloc<T>, AllocError> {
pub(super) fn prepare(mut self, va_data: impl PinInit<T::VaData>) -> *mut bindings::drm_gpuva {
let va_ptr = MaybeUninit::as_mut_ptr(&mut self.0);
// SAFETY: The `data` field is pinned.
- let Ok(()) = unsafe { va_data.__pinned_init(&raw mut (*va_ptr).data) };
+ let Ok(()) = unsafe { va_data.__init(&raw mut (*va_ptr).data) };
KBox::into_raw(self.0).cast()
}
}
diff --git a/rust/kernel/drm/gpuvm/vm_bo.rs b/rust/kernel/drm/gpuvm/vm_bo.rs
index a30f838c11b8..c7305e4c03da 100644
--- a/rust/kernel/drm/gpuvm/vm_bo.rs
+++ b/rust/kernel/drm/gpuvm/vm_bo.rs
@@ -190,7 +190,7 @@ pub(super) fn new(
};
let ptr = NonNull::new(raw_ptr).ok_or(AllocError)?;
// SAFETY: `ptr->data` is a valid pinned location.
- let Ok(()) = unsafe { value.__pinned_init(&raw mut (*raw_ptr).data) };
+ let Ok(()) = unsafe { value.__init(&raw mut (*raw_ptr).data) };
// INVARIANTS: We just created the vm_bo so it's absent from lists, and the data is valid
// as we just initialized it.
Ok(GpuVmBoAlloc(ptr))
diff --git a/rust/kernel/init.rs b/rust/kernel/init.rs
index 05a12e869a57..2afdccb67373 100644
--- a/rust/kernel/init.rs
+++ b/rust/kernel/init.rs
@@ -157,9 +157,8 @@ fn pin_init<E>(init: impl PinInit<T, E>, flags: Flags) -> error::Result<Self::Pi
Error: From<E>,
{
// SAFETY: We delegate to `init` and only change the error type.
- let init = unsafe {
- pin_init_from_closure(|slot| init.__pinned_init(slot).map_err(|e| Error::from(e)))
- };
+ let init =
+ unsafe { pin_init_from_closure(|slot| init.__init(slot).map_err(|e| Error::from(e))) };
Self::try_pin_init(init, flags)
}
@@ -175,9 +174,8 @@ fn init<E>(init: impl Init<T, E>, flags: Flags) -> error::Result<Self>
Error: From<E>,
{
// SAFETY: We delegate to `init` and only change the error type.
- let init = unsafe {
- init_from_closure(|slot| init.__pinned_init(slot).map_err(|e| Error::from(e)))
- };
+ let init =
+ unsafe { init_from_closure(|slot| init.__init(slot).map_err(|e| Error::from(e))) };
Self::try_init(init, flags)
}
}
diff --git a/rust/kernel/pwm.rs b/rust/kernel/pwm.rs
index 6c9d667009ef..ed051c1780a1 100644
--- a/rust/kernel/pwm.rs
+++ b/rust/kernel/pwm.rs
@@ -600,7 +600,7 @@ pub fn new<'a>(
let drvdata_ptr = unsafe { bindings::pwmchip_get_drvdata(c_chip_ptr) };
// SAFETY: We construct the `T` object in-place in the allocated private memory.
- unsafe { data.__pinned_init(drvdata_ptr.cast()) }.inspect_err(|_| {
+ unsafe { data.__init(drvdata_ptr.cast()) }.inspect_err(|_| {
// SAFETY: It is safe to call `pwmchip_put()` with a valid pointer obtained
// from `pwmchip_alloc()`. We will not use pointer after this.
unsafe { bindings::pwmchip_put(c_chip_ptr) }
diff --git a/rust/kernel/sync/arc.rs b/rust/kernel/sync/arc.rs
index 5ac4961b7cd2..c5200cc0bc51 100644
--- a/rust/kernel/sync/arc.rs
+++ b/rust/kernel/sync/arc.rs
@@ -727,7 +727,7 @@ fn write_pin_init<E>(mut self, init: impl PinInit<T, E>) -> Result<Pin<Self::Ini
let slot = self.as_mut_ptr();
// SAFETY: When init errors/panics, slot will get deallocated but not dropped,
// slot is valid and will not be moved, because we pin it later.
- unsafe { init.__pinned_init(slot)? };
+ unsafe { init.__init(slot)? };
// SAFETY: All fields have been initialized.
Ok(unsafe { self.assume_init() }.into())
}
@@ -810,7 +810,7 @@ pub fn pin_init_with<E>(
) -> core::result::Result<Pin<UniqueArc<T>>, E> {
// SAFETY: The supplied pointer is valid for initialization and we will later pin the value
// to ensure it does not move.
- match unsafe { init.__pinned_init(self.as_mut_ptr()) } {
+ match unsafe { init.__init(self.as_mut_ptr()) } {
// SAFETY: Initialization completed successfully.
Ok(()) => Ok(unsafe { self.assume_init() }.into()),
Err(err) => Err(err),
diff --git a/rust/kernel/types.rs b/rust/kernel/types.rs
index 699aabe01ee5..b769c80189df 100644
--- a/rust/kernel/types.rs
+++ b/rust/kernel/types.rs
@@ -426,7 +426,7 @@ fn pin_init<E>(slot: impl PinInit<T, E>) -> impl PinInit<Self, E> {
// - `ptr` is a valid pointer to uninitialized memory,
// - `slot` is not accessed on error,
// - `slot` is pinned in memory.
- unsafe { PinInit::<T, E>::__pinned_init(slot, ptr) }
+ unsafe { PinInit::<T, E>::__init(slot, ptr) }
})
}
}
diff --git a/rust/macros/module.rs b/rust/macros/module.rs
index 025323fb030d..a922103b7e35 100644
--- a/rust/macros/module.rs
+++ b/rust/macros/module.rs
@@ -622,7 +622,7 @@ unsafe fn __init() -> ::kernel::ffi::c_int {
// SAFETY: No data race, since `__MOD` can only be accessed by this module
// and there only `__init` and `__exit` access it. These functions are only
// called once and `__exit` cannot be called before or during `__init`.
- match unsafe { initer.__pinned_init(__MOD.as_mut_ptr()) } {
+ match unsafe { initer.__init(__MOD.as_mut_ptr()) } {
Ok(m) => 0,
Err(e) => e.to_errno(),
}
--
2.54.0
^ permalink raw reply related [flat|nested] 5+ messages in thread
* [PATCH 4/4] rust: pin-init: remove `__pinned_init` method for `cfg(kernel)`
2026-07-22 18:50 [PATCH 0/4] rust: pin-init: merge `__init` and `__pinned_init` Gary Guo
` (2 preceding siblings ...)
2026-07-22 18:50 ` [PATCH 3/4] rust: treewide: replace `__pinned_init` with `__init` Gary Guo
@ 2026-07-22 18:50 ` Gary Guo
3 siblings, 0 replies; 5+ messages in thread
From: Gary Guo @ 2026-07-22 18:50 UTC (permalink / raw)
To: Benno Lossin, Miguel Ojeda, Boqun Feng, Björn Roy Baron,
Andreas Hindborg, Alice Ryhl, Trevor Gross, Danilo Krummrich,
Daniel Almeida, Tamir Duberstein, Alexandre Courbot,
Onur Özkan
Cc: rust-for-linux, linux-kernel, Gary Guo
Remove `__pinned_init` for kernel configuration, with all users gone.
Still perserve it temporarily as deprecated so other users have time to
move off it.
Signed-off-by: Gary Guo <gary@garyguo.net>
---
rust/pin-init/src/lib.rs | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/rust/pin-init/src/lib.rs b/rust/pin-init/src/lib.rs
index 354fbefcf80e..c8c1d0184da4 100644
--- a/rust/pin-init/src/lib.rs
+++ b/rust/pin-init/src/lib.rs
@@ -917,7 +917,8 @@ pub unsafe trait PinInit<T: ?Sized, E = Infallible>: Sized {
///
/// Same as `__init`.
#[inline(always)]
- #[cfg_attr(not(kernel), deprecated = "use `__init` instead")]
+ #[cfg(not(kernel))]
+ #[deprecated = "use `__init` instead"]
unsafe fn __pinned_init(self, slot: *mut T) -> Result<(), E> {
// SAFETY: Per safety requirement.
unsafe { self.__init(slot) }
--
2.54.0
^ permalink raw reply related [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-07-22 18:50 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-22 18:50 [PATCH 0/4] rust: pin-init: merge `__init` and `__pinned_init` Gary Guo
2026-07-22 18:50 ` [PATCH 1/4] rust: pin-init: merge `__pinned_init` and `__init` Gary Guo
2026-07-22 18:50 ` [PATCH 2/4] rust: devres: use `cast_pin_init` instead of manual reimplementation Gary Guo
2026-07-22 18:50 ` [PATCH 3/4] rust: treewide: replace `__pinned_init` with `__init` Gary Guo
2026-07-22 18:50 ` [PATCH 4/4] rust: pin-init: remove `__pinned_init` method for `cfg(kernel)` Gary Guo
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox