From: Alice Ryhl <alice@ryhl.io>
To: Benno Lossin <y86-dev@protonmail.com>
Cc: rust-for-linux@vger.kernel.org, linux-kernel@vger.kernel.org,
patches@lists.linux.dev, "Alice Ryhl" <aliceryhl@google.com>,
"Andreas Hindborg" <a.hindborg@samsung.com>,
"Miguel Ojeda" <ojeda@kernel.org>,
"Alex Gaynor" <alex.gaynor@gmail.com>,
"Wedson Almeida Filho" <wedsonaf@gmail.com>,
"Boqun Feng" <boqun.feng@gmail.com>,
"Gary Guo" <gary@garyguo.net>,
"Björn Roy Baron" <bjorn3_gh@protonmail.com>
Subject: Re: [PATCH v5 10/15] rust: init: add `stack_pin_init!` macro
Date: Mon, 3 Apr 2023 19:56:27 +0200 [thread overview]
Message-ID: <93225277-91a8-a1b5-abda-e936cd50d6a3@ryhl.io> (raw)
In-Reply-To: <20230403160511.174894-3-y86-dev@protonmail.com>
On 4/3/23 18:05, Benno Lossin wrote:
> The `stack_pin_init!` macro allows pin-initializing a value on the
> stack. It accepts a `impl PinInit<T, E>` to initialize a `T`. It allows
> propagating any errors via `?` or handling it normally via `match`.
>
> Signed-off-by: Benno Lossin <y86-dev@protonmail.com>
> Cc: Alice Ryhl <aliceryhl@google.com>
> Cc: Andreas Hindborg <a.hindborg@samsung.com>
> Cc: Gary Guo <gary@garyguo.net>
> ---
If you fix the issue below, then you may add
Reviewed-by: Alice Ryhl <aliceryhl@google.com>
> + /// Initializes the contents and returns the result.
> + #[inline]
> + pub fn init<E>(self: Pin<&mut Self>, init: impl PinInit<T, E>) -> Result<Pin<&mut T>, E> {
> + // SAFETY: We never move out of `this`.
> + let this = unsafe { Pin::into_inner_unchecked(self) };
> + // The value is currently initialized, so it needs to be dropped before we can reuse
> + // the memory (this is a safety guarantee of `Pin`).
> + if this.1 {
> + // SAFETY: `this.1` is true and we set it to false after this.
> + unsafe { this.0.assume_init_drop() };
> + this.1 = false;
> + }
This would double-free the value if `assume_init_drop` panics. I know
that we configure panics to abort the kernel, but someone could copy
this into another codebase and then they would have this issue.
You can fix it by setting `this.1` to false *before* calling
`assume_init_drop`.
next prev parent reply other threads:[~2023-04-03 17:57 UTC|newest]
Thread overview: 33+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-04-03 15:44 [PATCH v5 00/15] Rust pin-init API for pinned initialization of structs Benno Lossin
2023-04-03 15:44 ` [PATCH v5 01/15] rust: enable the `pin_macro` feature Benno Lossin
2023-04-03 17:55 ` Alice Ryhl
2023-04-04 13:11 ` Gary Guo
2023-04-03 15:44 ` [PATCH v5 02/15] rust: macros: add `quote!` macro Benno Lossin
2023-04-03 17:56 ` Alice Ryhl
2023-04-03 15:44 ` [PATCH v5 03/15] rust: sync: change error type of constructor functions Benno Lossin
2023-04-03 17:56 ` Alice Ryhl
2023-04-04 13:11 ` Gary Guo
2023-04-03 15:45 ` [PATCH v5 04/15] rust: sync: add `assume_init` to `UniqueArc` Benno Lossin
2023-04-03 15:45 ` [PATCH v5 05/15] rust: types: add `Opaque::raw_get` Benno Lossin
2023-04-03 15:45 ` [PATCH v5 06/15] rust: add pin-init API core Benno Lossin
2023-04-03 17:56 ` Alice Ryhl
2023-04-03 15:45 ` [PATCH v5 07/15] rust: init: add initialization macros Benno Lossin
2023-04-03 17:56 ` Alice Ryhl
2023-04-03 16:05 ` [PATCH v5 08/15] rust: init/sync: add `InPlaceInit` trait to pin-initialize smart pointers Benno Lossin
2023-04-03 17:56 ` Alice Ryhl
2023-04-04 13:15 ` Gary Guo
2023-04-03 16:05 ` [PATCH v5 09/15] rust: init: add `PinnedDrop` trait and macros Benno Lossin
2023-04-03 17:56 ` Alice Ryhl
2023-04-03 16:05 ` [PATCH v5 10/15] rust: init: add `stack_pin_init!` macro Benno Lossin
2023-04-03 17:56 ` Alice Ryhl [this message]
2023-04-03 16:05 ` [PATCH v5 11/15] rust: init: add `Zeroable` trait and `init::zeroed` function Benno Lossin
2023-04-03 17:56 ` Alice Ryhl
2023-04-03 19:20 ` Gary Guo
2023-04-04 13:24 ` Gary Guo
2023-04-03 16:05 ` [PATCH v5 12/15] rust: prelude: add `pin-init` API items to prelude Benno Lossin
2023-04-03 16:05 ` [PATCH v5 13/15] rust: types: add common init-helper functions for `Opaque` Benno Lossin
2023-04-03 16:05 ` [PATCH v5 14/15] rust: sync: reduce stack usage of `UniqueArc::try_new_uninit` Benno Lossin
2023-04-03 17:56 ` Alice Ryhl
2023-04-03 21:06 ` y86-dev
2023-04-04 13:25 ` Gary Guo
2023-04-03 16:06 ` [PATCH v5 15/15] rust: sync: add functions for initializing `UniqueArc<MaybeUninit<T>>` Benno Lossin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=93225277-91a8-a1b5-abda-e936cd50d6a3@ryhl.io \
--to=alice@ryhl.io \
--cc=a.hindborg@samsung.com \
--cc=alex.gaynor@gmail.com \
--cc=aliceryhl@google.com \
--cc=bjorn3_gh@protonmail.com \
--cc=boqun.feng@gmail.com \
--cc=gary@garyguo.net \
--cc=linux-kernel@vger.kernel.org \
--cc=ojeda@kernel.org \
--cc=patches@lists.linux.dev \
--cc=rust-for-linux@vger.kernel.org \
--cc=wedsonaf@gmail.com \
--cc=y86-dev@protonmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).