public inbox for rust-for-linux@vger.kernel.org
 help / color / mirror / Atom feed
From: "Gary Guo" <gary@garyguo.net>
To: "Andreas Hindborg" <a.hindborg@kernel.org>,
	"Gary Guo" <gary@kernel.org>, "Miguel Ojeda" <ojeda@kernel.org>,
	"Boqun Feng" <boqun@kernel.org>, "Gary Guo" <gary@garyguo.net>,
	"Björn Roy Baron" <bjorn3_gh@protonmail.com>,
	"Benno Lossin" <lossin@kernel.org>,
	"Alice Ryhl" <aliceryhl@google.com>,
	"Trevor Gross" <tmgross@umich.edu>,
	"Danilo Krummrich" <dakr@kernel.org>,
	"Daniel Almeida" <daniel.almeida@collabora.com>
Cc: <rust-for-linux@vger.kernel.org>, <driver-core@lists.linux.dev>,
	<linux-kernel@vger.kernel.org>
Subject: Re: [PATCH 4/8] rust: io: add view type
Date: Thu, 02 Apr 2026 14:01:32 +0100	[thread overview]
Message-ID: <DHIOSVI47UIV.10SV1TCUTM9IE@garyguo.net> (raw)
In-Reply-To: <87h5q2y85c.fsf@t14s.mail-host-address-is-not-set>

On Thu Mar 26, 2026 at 2:31 PM GMT, Andreas Hindborg wrote:
> "Gary Guo" <gary@kernel.org> writes:
>
>> From: Gary Guo <gary@garyguo.net>
>>
>> The view may be created statically via I/O projection using `io_project!()`
>> macro to perform compile-time checks, or created by type-casting an
>> existing view type with `try_cast()` function, where the size and alignment
>> checks are performed at runtime.
>>
>> Signed-off-by: Gary Guo <gary@garyguo.net>
>> ---
>>  rust/kernel/io.rs | 147 +++++++++++++++++++++++++++++++++++++++++++++-
>>  1 file changed, 146 insertions(+), 1 deletion(-)
>>
>> diff --git a/rust/kernel/io.rs b/rust/kernel/io.rs
>> index 72902a4a343d..8166e47f1381 100644
>> --- a/rust/kernel/io.rs
>> +++ b/rust/kernel/io.rs
>> @@ -7,7 +7,11 @@
>>  use crate::{
>>      bindings,
>>      prelude::*,
>> -    ptr::KnownSize, //
>> +    ptr::KnownSize,
>> +    transmute::{
>> +        AsBytes,
>> +        FromBytes, //
>> +    }, //
>>  };
>>
>>  pub mod mem;
>> @@ -296,6 +300,13 @@ pub trait Io {
>>      /// Type of this I/O region. For untyped I/O regions, [`Region`] type can be used.
>>      type Type: ?Sized + KnownSize;
>>
>> +    /// Get a [`View`] covering the entire region.
>> +    #[inline]
>> +    fn as_view(&self) -> View<'_, Self, Self::Type> {
>> +        // SAFETY: Trivially satisfied.
>
> What might be trivial to you is not necessarily obvious to others.
> Please explain why we are satisfying safety requirements.

This is what language model produces:

    Analysis: Io::as_view()
    
      fn as_view(&self) -> View<'_, Self, Self::Type> {
          // SAFETY: Trivially satisfied
          unsafe { View::new_unchecked(self, self.as_ptr()) }
      }
    
      The View invariants are:
      1. ptr is aligned for T
      2. ptr has same provenance as io.as_ptr()
      3. ptr.byte_offset_from(io.as_ptr()) is between 0 to KnownSize::size(io.as_ptr()) - KnownSize::size(ptr)
    
      For as_view():
      - ptr = self.as_ptr() which is Self::Type
      - Invariant 1: self.as_ptr() should be aligned for Self::Type - assumed true from the Io trait
      - Invariant 2: Same pointer, same provenance - trivially true
      - Invariant 3: ptr.byte_offset_from(io.as_ptr()) = 0, and we need 0 <= size_io - size_ptr which is 0 <= 0, true
    
      The safety comment "Trivially satisfied" is correct.

I think the verbosity here is really because we have the safety requirement
listed item by item, rather than just defining a new concept.

If we, for example, coin an idea of `IO valid pointers`, then we can just say
the `self.as_ptr()` is trivially I/O valid.

Perhaps, for this case, we can use the "projection trivially satisfy the
invariants" that I've already mentioned in the doc, and just write

    // SAFETY: This is an empty projection, so it trivially satisfies the
    // invariant.

?

Best,
Gary


>
> Otherwise looks good, with the above fixed, please add:
>
> Reviewed-by: Andreas Hindborg <a.hindborg@kernel.org>
>
> Best regards,
> Andreas Hindborg


  reply	other threads:[~2026-04-02 13:01 UTC|newest]

Thread overview: 36+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <OxgMwl1EcYLh4AqdBa-FaFap0ODNxpID-Hnns6odQVjvPTXqh6VoXM01bZmoVkAOF_5udNfKuCP8YJoW4UE5Fg==@protonmail.internalid>
2026-03-23 15:37 ` [PATCH 0/8] I/O type generalization and projection Gary Guo
2026-03-23 15:37   ` [PATCH 1/8] rust: io: generalize `MmioRaw` to pointer to arbitrary type Gary Guo
2026-03-26 12:53     ` Andreas Hindborg
2026-03-26 14:31       ` Gary Guo
2026-03-23 15:37   ` [PATCH 2/8] rust: io: generalize `Mmio` " Gary Guo
2026-03-26 13:04     ` Andreas Hindborg
2026-03-26 14:32       ` Gary Guo
2026-03-26 18:23         ` Andreas Hindborg
2026-04-02 12:57           ` Gary Guo
2026-04-04 18:57     ` Miguel Ojeda
2026-04-05 14:55     ` Alexandre Courbot
2026-04-05 23:21       ` Gary Guo
2026-04-06  4:00         ` Alexandre Courbot
2026-03-23 15:37   ` [PATCH 3/8] rust: io: use pointer types instead of address Gary Guo
2026-03-26 14:20     ` Andreas Hindborg
2026-03-26 14:35       ` Gary Guo
2026-03-27 10:11         ` Miguel Ojeda
2026-04-05 14:56     ` Alexandre Courbot
2026-04-05 15:00       ` Danilo Krummrich
2026-04-06  3:49         ` Alexandre Courbot
2026-03-23 15:37   ` [PATCH 4/8] rust: io: add view type Gary Guo
2026-03-26 14:31     ` Andreas Hindborg
2026-04-02 13:01       ` Gary Guo [this message]
2026-03-23 15:37   ` [PATCH 5/8] rust: dma: add methods to unsafely create reference from subview Gary Guo
2026-03-26 14:37     ` Andreas Hindborg
2026-03-26 14:44       ` Gary Guo
2026-03-23 15:37   ` [PATCH 6/8] rust: io: add `read_val` and `write_val` function on I/O view Gary Guo
2026-03-27  8:21     ` Andreas Hindborg
2026-03-27 12:19       ` Gary Guo
2026-03-23 15:37   ` [PATCH 7/8] gpu: nova-core: use I/O projection for cleaner encapsulation Gary Guo
2026-03-23 15:38   ` [PATCH 8/8] rust: dma: drop `dma_read!` and `dma_write!` API Gary Guo
2026-03-27  8:25     ` Andreas Hindborg
2026-03-25 11:11   ` [PATCH 0/8] I/O type generalization and projection Andreas Hindborg
2026-03-25 11:19     ` Miguel Ojeda
2026-04-05 15:01   ` Alexandre Courbot
2026-04-05 23:17     ` Gary Guo

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=DHIOSVI47UIV.10SV1TCUTM9IE@garyguo.net \
    --to=gary@garyguo.net \
    --cc=a.hindborg@kernel.org \
    --cc=aliceryhl@google.com \
    --cc=bjorn3_gh@protonmail.com \
    --cc=boqun@kernel.org \
    --cc=dakr@kernel.org \
    --cc=daniel.almeida@collabora.com \
    --cc=driver-core@lists.linux.dev \
    --cc=gary@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lossin@kernel.org \
    --cc=ojeda@kernel.org \
    --cc=rust-for-linux@vger.kernel.org \
    --cc=tmgross@umich.edu \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox