From: "Gary Guo" <gary@garyguo.net>
To: "Andreas Hindborg" <a.hindborg@kernel.org>,
"Gary Guo" <gary@kernel.org>, "Miguel Ojeda" <ojeda@kernel.org>,
"Boqun Feng" <boqun@kernel.org>, "Gary Guo" <gary@garyguo.net>,
"Björn Roy Baron" <bjorn3_gh@protonmail.com>,
"Benno Lossin" <lossin@kernel.org>,
"Alice Ryhl" <aliceryhl@google.com>,
"Trevor Gross" <tmgross@umich.edu>,
"Danilo Krummrich" <dakr@kernel.org>,
"Daniel Almeida" <daniel.almeida@collabora.com>
Cc: <rust-for-linux@vger.kernel.org>, <driver-core@lists.linux.dev>,
<linux-kernel@vger.kernel.org>
Subject: Re: [PATCH 4/8] rust: io: add view type
Date: Thu, 02 Apr 2026 14:01:32 +0100 [thread overview]
Message-ID: <DHIOSVI47UIV.10SV1TCUTM9IE@garyguo.net> (raw)
In-Reply-To: <87h5q2y85c.fsf@t14s.mail-host-address-is-not-set>
On Thu Mar 26, 2026 at 2:31 PM GMT, Andreas Hindborg wrote:
> "Gary Guo" <gary@kernel.org> writes:
>
>> From: Gary Guo <gary@garyguo.net>
>>
>> The view may be created statically via I/O projection using `io_project!()`
>> macro to perform compile-time checks, or created by type-casting an
>> existing view type with `try_cast()` function, where the size and alignment
>> checks are performed at runtime.
>>
>> Signed-off-by: Gary Guo <gary@garyguo.net>
>> ---
>> rust/kernel/io.rs | 147 +++++++++++++++++++++++++++++++++++++++++++++-
>> 1 file changed, 146 insertions(+), 1 deletion(-)
>>
>> diff --git a/rust/kernel/io.rs b/rust/kernel/io.rs
>> index 72902a4a343d..8166e47f1381 100644
>> --- a/rust/kernel/io.rs
>> +++ b/rust/kernel/io.rs
>> @@ -7,7 +7,11 @@
>> use crate::{
>> bindings,
>> prelude::*,
>> - ptr::KnownSize, //
>> + ptr::KnownSize,
>> + transmute::{
>> + AsBytes,
>> + FromBytes, //
>> + }, //
>> };
>>
>> pub mod mem;
>> @@ -296,6 +300,13 @@ pub trait Io {
>> /// Type of this I/O region. For untyped I/O regions, [`Region`] type can be used.
>> type Type: ?Sized + KnownSize;
>>
>> + /// Get a [`View`] covering the entire region.
>> + #[inline]
>> + fn as_view(&self) -> View<'_, Self, Self::Type> {
>> + // SAFETY: Trivially satisfied.
>
> What might be trivial to you is not necessarily obvious to others.
> Please explain why we are satisfying safety requirements.
This is what language model produces:
Analysis: Io::as_view()
fn as_view(&self) -> View<'_, Self, Self::Type> {
// SAFETY: Trivially satisfied
unsafe { View::new_unchecked(self, self.as_ptr()) }
}
The View invariants are:
1. ptr is aligned for T
2. ptr has same provenance as io.as_ptr()
3. ptr.byte_offset_from(io.as_ptr()) is between 0 to KnownSize::size(io.as_ptr()) - KnownSize::size(ptr)
For as_view():
- ptr = self.as_ptr() which is Self::Type
- Invariant 1: self.as_ptr() should be aligned for Self::Type - assumed true from the Io trait
- Invariant 2: Same pointer, same provenance - trivially true
- Invariant 3: ptr.byte_offset_from(io.as_ptr()) = 0, and we need 0 <= size_io - size_ptr which is 0 <= 0, true
The safety comment "Trivially satisfied" is correct.
I think the verbosity here is really because we have the safety requirement
listed item by item, rather than just defining a new concept.
If we, for example, coin an idea of `IO valid pointers`, then we can just say
the `self.as_ptr()` is trivially I/O valid.
Perhaps, for this case, we can use the "projection trivially satisfy the
invariants" that I've already mentioned in the doc, and just write
// SAFETY: This is an empty projection, so it trivially satisfies the
// invariant.
?
Best,
Gary
>
> Otherwise looks good, with the above fixed, please add:
>
> Reviewed-by: Andreas Hindborg <a.hindborg@kernel.org>
>
> Best regards,
> Andreas Hindborg
next prev parent reply other threads:[~2026-04-02 13:01 UTC|newest]
Thread overview: 36+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <OxgMwl1EcYLh4AqdBa-FaFap0ODNxpID-Hnns6odQVjvPTXqh6VoXM01bZmoVkAOF_5udNfKuCP8YJoW4UE5Fg==@protonmail.internalid>
2026-03-23 15:37 ` [PATCH 0/8] I/O type generalization and projection Gary Guo
2026-03-23 15:37 ` [PATCH 1/8] rust: io: generalize `MmioRaw` to pointer to arbitrary type Gary Guo
2026-03-26 12:53 ` Andreas Hindborg
2026-03-26 14:31 ` Gary Guo
2026-03-23 15:37 ` [PATCH 2/8] rust: io: generalize `Mmio` " Gary Guo
2026-03-26 13:04 ` Andreas Hindborg
2026-03-26 14:32 ` Gary Guo
2026-03-26 18:23 ` Andreas Hindborg
2026-04-02 12:57 ` Gary Guo
2026-04-04 18:57 ` Miguel Ojeda
2026-04-05 14:55 ` Alexandre Courbot
2026-04-05 23:21 ` Gary Guo
2026-04-06 4:00 ` Alexandre Courbot
2026-03-23 15:37 ` [PATCH 3/8] rust: io: use pointer types instead of address Gary Guo
2026-03-26 14:20 ` Andreas Hindborg
2026-03-26 14:35 ` Gary Guo
2026-03-27 10:11 ` Miguel Ojeda
2026-04-05 14:56 ` Alexandre Courbot
2026-04-05 15:00 ` Danilo Krummrich
2026-04-06 3:49 ` Alexandre Courbot
2026-03-23 15:37 ` [PATCH 4/8] rust: io: add view type Gary Guo
2026-03-26 14:31 ` Andreas Hindborg
2026-04-02 13:01 ` Gary Guo [this message]
2026-03-23 15:37 ` [PATCH 5/8] rust: dma: add methods to unsafely create reference from subview Gary Guo
2026-03-26 14:37 ` Andreas Hindborg
2026-03-26 14:44 ` Gary Guo
2026-03-23 15:37 ` [PATCH 6/8] rust: io: add `read_val` and `write_val` function on I/O view Gary Guo
2026-03-27 8:21 ` Andreas Hindborg
2026-03-27 12:19 ` Gary Guo
2026-03-23 15:37 ` [PATCH 7/8] gpu: nova-core: use I/O projection for cleaner encapsulation Gary Guo
2026-03-23 15:38 ` [PATCH 8/8] rust: dma: drop `dma_read!` and `dma_write!` API Gary Guo
2026-03-27 8:25 ` Andreas Hindborg
2026-03-25 11:11 ` [PATCH 0/8] I/O type generalization and projection Andreas Hindborg
2026-03-25 11:19 ` Miguel Ojeda
2026-04-05 15:01 ` Alexandre Courbot
2026-04-05 23:17 ` Gary Guo
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DHIOSVI47UIV.10SV1TCUTM9IE@garyguo.net \
--to=gary@garyguo.net \
--cc=a.hindborg@kernel.org \
--cc=aliceryhl@google.com \
--cc=bjorn3_gh@protonmail.com \
--cc=boqun@kernel.org \
--cc=dakr@kernel.org \
--cc=daniel.almeida@collabora.com \
--cc=driver-core@lists.linux.dev \
--cc=gary@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=lossin@kernel.org \
--cc=ojeda@kernel.org \
--cc=rust-for-linux@vger.kernel.org \
--cc=tmgross@umich.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox