mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] rust: drm: ioctl: wrap `Device::from_raw` in an `unsafe` block
@ 2026-10-07 21:17 spidermana
  0 siblings, 0 replies; only message in thread
From: spidermana @ 2026-10-07 21:17 UTC (permalink / raw)
  To: Danilo Krummrich, Alice Ryhl, David Airlie, Simona Vetter, Miguel Ojeda
  Cc: spidermana, Boqun Feng, Gary Guo, Björn Roy Baron,
	Benno Lossin, Andreas Hindborg, Trevor Gross, Daniel Almeida,
	Tamir Duberstein, Alexandre Courbot, Onur Özkan, dri-devel,
	rust-for-linux, linux-kernel

`declare_drm_ioctls!` generates an `unsafe extern "C" fn` per ioctl. Inside
it, four unsafe operations are performed, while the call to `Device::from_raw()` relies on the enclosing
`unsafe fn` body instead.

Both forms are legal, but the kernel builds all Rust code with `-Dunsafe_op_in_unsafe_fn`, which asks for the explicit block.
The lint does not fire here because the macro is defined in the `kernel` crate and expanded in the
driver crates, and rustc suppresses lints for code coming from another crate's macro.

The patch is to wrap the call in an unsafe block, keeping the existing SAFETY comment. No functional change.

Signed-off-by: spidermana <xuyiwen14@gmail.com>
---
 rust/kernel/drm/ioctl.rs | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/rust/kernel/drm/ioctl.rs b/rust/kernel/drm/ioctl.rs
index 64af9eacc306..5a2e2f4f0e91 100644
--- a/rust/kernel/drm/ioctl.rs
+++ b/rust/kernel/drm/ioctl.rs
@@ -152,7 +152,7 @@ macro_rules! declare_drm_ioctls {
                             // dev/file match the current driver these ioctls are being declared
                             // for, and it's not clear how to enforce this within the type system.
                             let dev: &$crate::drm::device::Device<_, $crate::drm::Ioctl> =
-                                $crate::drm::device::Device::from_raw(raw_dev);
+                                unsafe { $crate::drm::device::Device::from_raw(raw_dev) };

                             // Type-inference anchor: the closure is never called but ties `dev`'s
                             // type to `$func`'s first parameter, which the compiler cannot infer
--
2.43.0

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-10-07 21:18 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-07 21:17 [PATCH] rust: drm: ioctl: wrap `Device::from_raw` in an `unsafe` block spidermana

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®