Re: [PATCH v14 0/2] rust: Add safe pointer formatting support

Link Mauve <[email protected]>
Newsgroups org.kernel.vger.rust-for-linux
Message-ID <anWvyOP2rISjXkXn@desktop>
Hi,

This v14 indeed fixes things, my driver now always prints (ptrval) when
loaded the first time (I have to rmmod && modprobe it again for it to
display actual virtual addresses, not sure if I’m doing something wrong
here) instead of 0x(ptrval)!

Tested-by: Link Mauve <[email protected]>

On Fri, Aug 07, 2026 at 04:14:52PM +0800, Ke Sun wrote:
> This series fixes two issues with {:p} pointer formatting:
> - The impl_fmt_adapter_forward! macro destructures self into a local
>   variable, causing {:p} to print a stack address instead of the actual
>   pointer
> - Kernel address leak - {:p} prints raw pointer values, exposing kernel
>   address space layout
> 
> ---
> Changes in v14:
> - Use `%#0*p` for `0x` prefix and zero-padding (Gary); this also avoids
>   "0x(...)" for placeholder tokens like "(____ptrval____)" (Alice)
> - Simplify pointer impls per Gary
> - Link to v13: https://lore.kernel.org/r/[email protected]
> 
> Changes in v13:
> - Add NonNull<T> pointer formatting support
> - Add #[inline] to all Pointer impl methods
> - Support zero-padding format ({:0width$p})
> - Simplify SAFETY comments
> - Rewrite tests: remove NoHashPointersGuard - modifying
>   no_hash_pointers after boot panics since it's __ro_after_init; read
>   current value and branch instead; expand format coverage
> - Link to v12: https://lore.kernel.org/r/[email protected]
> 
> Changes in v12:
> - Split into 2 patches: fix {:p} printing stack addresses -> route {:p}
>   through HashedPtr
> - Test cleanup: NoHashPointersGuard RAII guard replaces raw
>   save/restore; mod expected consolidates 32/64-bit constants
> - Impl delegation: &T, &mut T, *mut T all forward to *const T (matching
>   core library conventions), replacing v11's blanket impl + macro
> - Link to v11: https://lore.kernel.org/r/[email protected]
> 
> Changes in v11:
> - Fix inaccurate or inappropriate descriptions in comments
> - Use as_char_ptr instead of as_ptr so that a *const u8 pointer is
>   always passed to scnprintf on all architectures
> - Per Tamir's suggestion, replace doctests with mod tests and adjust
>   test content to make the tests more meaningful
> - Remove the RawPtr wrapper type: it and HashedPtr use different
>   formatting mechanisms (HashedPtr uses scnprintf and pad; RawPtr would
>   call core's Pointer impl directly). This series focuses on fixing the
>   issue that without it {:p} would output the pointer's stack address,
>   and on using HashedPtr to safely format raw pointers and avoid leaking
>   kernel address space layout information
> - Link to v10: https://lore.kernel.org/r/[email protected]
> 
> Changes in v10:
> - Merge all patches into a single patch
> - Improve `kernel::fmt::Pointer` trait implementation
> Link to v9: https://lore.kernel.org/r/[email protected]
> 
> Changes in v9: https://lore.kernel.org/r/[email protected]
> - Refactor implementation to use Pointer trait and Adapter pattern
>   instead of exporting ptr_to_hashval() from lib/vsprintf.c. Use
>   scnprintf directly in Rust for pointer hashing, eliminating the
>   need for C function export
> - Move pointer wrapper types from rust/kernel/ptr.rs to
>   rust/kernel/fmt.rs
> - Split implementation into more granular patches: Pointer trait
>   foundation, HashedPtr type, raw pointer default behavior, and
>   RawPtr type
> - Remove documentation patch, integrate examples into code doctests
> - Simplify API and improve code organization following Display trait
>   pattern
> - Link to v8: https://lore.kernel.org/r/[email protected]
> 
> Changes in v8:
> - Remove RestrictedPtr (%pK) support: only export ptr_to_hashval() with
>   EXPORT_SYMBOL_NS_GPL using "RUST_INTERNAL" namespace, provide only two
>   pointer wrapper types (HashedPtr, RawPtr) for %p and %px
> - Change API from HashedPtr::from(ptr) to HashedPtr(ptr) for direct
>   construction
> - Link to v7: https://lore.kernel.org/r/[email protected]
> 
> Changes in v7:
> - Refactor kptr_restrict handling: extract kptr_restrict_value() from
>   restricted_pointer() in lib/vsprintf.c and export it for Rust use, and
>   improve RestrictedPtr::fmt() implementation to directly handle
>   kptr_restrict_value() return values (0, 1, 2, -1) for better code
>   clarity
> - Remove Debug derive from pointer wrapper types (HashedPtr,
>   RestrictedPtr, RawPtr)
> - Link to v6: https://lore.kernel.org/r/[email protected]
> 
> Changes in v6:
> - Fix placeholder formatting to use `f.pad()` instead of `f.write_str()`
>   in format_hashed_ptr(), ensuring width, alignment, and padding options
>   are correctly applied to PTR_PLACEHOLDER
> - Link to v5: https://lore.kernel.org/r/[email protected]
> 
> Changes in v5: https://lore.kernel.org/r/[email protected]
> - Format use statements in rust/kernel/ptr.rs and rust/kernel/fmt.rs
>   using kernel vertical style with alphabetical ordering
> - Remove unnecessary SAFETY comment in rust/kernel/ptr.rs (addressed
>   Clippy warning)
> - Update type ordering to alphabetical (HashedPtr, RawPtr,
>   RestrictedPtr) in fmt.rs macro invocation
> - Link to v4: https://lore.kernel.org/r/[email protected]
> 
> Changes in v4:
> - Use Pointer::fmt() instead of write!(f, "{:p}", ...) to preserve
>   formatting options (width, alignment, padding characters)
> - Improve code structure: reduce unsafe block scope, use early return
>   pattern
> - Add doctests with formatting option tests for all pointer wrapper
>   types
> - Enhance documentation with detailed formatting options section,
>   including examples for width, alignment, and padding
> - Fix RestrictedPtr example to use pr_info! instead of seq_print! in
>   docs
> - Link to v3: https://lore.kernel.org/r/[email protected]
> 
> Changes in v3:
> - Export ptr_to_hashval() from lib/vsprintf.c for Rust pointer hashing
> - Add three pointer wrapper types (HashedPtr, RestrictedPtr, RawPtr) in
>   rust/kernel/ptr.rs corresponding to %p, %pK, and %px
> - Make raw pointers automatically use HashedPtr when formatted with {:p}
> - Add documentation for pointer wrapper types
> - Link to v2: https://lore.kernel.org/r/[email protected]
> 
> Changes in v2:
> - Disabled {:p} raw pointer printing by default to prevent accidental
>   information leaks
> - Link to v1: https://lore.kernel.org/r/[email protected]
> 
> Signed-off-by: Ke Sun <[email protected]>
> 
> ---
> Ke Sun (2):
>       rust: fmt: fix {:p} printing stack addresses
>       rust: fmt: route {:p} through HashedPtr to prevent address leaks
> 
>  rust/kernel/fmt.rs | 173 ++++++++++++++++++++++++++++++++++++++++++++++++++++-
>  1 file changed, 171 insertions(+), 2 deletions(-)
> ---
> base-commit: 6946cd5d0aa4dd10a414ddcb7a10844fdb0ad345
> change-id: 20260512-hashedptr-22469b930113
> 
> Best regards,
> -- 
> Ke Sun <[email protected]>
> 
> 

-- 
Link Mauve
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.