Re: [PATCH v5 01/20] rust: io: add dynamically-sized `Region` type

"Gary Guo" <[email protected]>
Newsgroups org.kernel.vger.linux-pwm,dev.linux.lists.driver-core,dev.linux.lists.nova-gpu,org.freedesktop.lists.dri-devel,org.kernel.vger.linux-kernel,org.kernel.vger.linux-pci,org.kernel.vger.rust-for-linux
Message-ID <[email protected]>
On Fri Jul 3, 2026 at 4:16 AM BST, Alexandre Courbot wrote:
> On Fri Jun 26, 2026 at 11:45 PM JST, Gary Guo wrote:
> <...>
>> diff --git a/rust/kernel/io.rs b/rust/kernel/io.rs
>> index fcc7678fd9e3..d1c5f0121994 100644
>> --- a/rust/kernel/io.rs
>> +++ b/rust/kernel/io.rs
>> @@ -6,7 +6,11 @@
>>  
>>  use crate::{
>>      bindings,
>> -    prelude::*, //
>> +    prelude::*,
>> +    ptr::{
>> +        Alignment,
>> +        KnownSize, //
>> +    }, //
>>  };
>>  
>>  pub mod mem;
>> @@ -31,6 +35,57 @@
>>  /// `CONFIG_PHYS_ADDR_T_64BIT`, and it can be a u64 even on 32-bit architectures.
>>  pub type ResourceSize = bindings::resource_size_t;
>>  
>> +/// Untyped I/O region.
>> +///
>> +/// This type can be used when an I/O region without known type information has a compile-time known
>> +/// minimum size (and a runtime known actual size).
>> +///
>> +/// # Invariants
>> +///
>> +/// - Size of the region is at least as large as the `SIZE` generic parameter.
>> +/// - Size of the region is multiple of 4.
>> +#[repr(C, align(4))]
>> +pub struct Region<const SIZE: usize = 0> {
>> +    inner: [u8],
>> +}
>> +
>> +impl<const SIZE: usize> Region<SIZE> {
>> +    /// Create a raw mutable pointer from given base address and size.
>> +    ///
>> +    /// `size` should be at least as large as the minimum size `SIZE`, and `base` and `size` should
>> +    /// be 4-byte aligned to uphold the type invariant.
>
> The second part of my comment on v4 was not relevant [1], but how about the
> "should -> must" proposal?

I think "should" is correct here. Most likely `size` satisfy the requirement,
but it's not UB or even logic error if `size` doesn't meet the requirement.

For example, it's okay to call this to get a raw pointer before performing
checks. As long as the pointer stays raw, it's not invalid.

Best,
Gary

>
> Regardless:
>
> Reviewed-by: Alexandre Courbot <[email protected]>
>
> [1] https://lore.kernel.org/all/[email protected]/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.