From: Gary Guo <gary@garyguo.net>
To: "Benno Lossin" <lossin@kernel.org>,
"Miguel Ojeda" <ojeda@kernel.org>,
"Boqun Feng" <boqun@kernel.org>,
"Björn Roy Baron" <bjorn3_gh@protonmail.com>,
"Andreas Hindborg" <a.hindborg@kernel.org>,
"Alice Ryhl" <aliceryhl@google.com>,
"Trevor Gross" <tmgross@umich.edu>,
"Danilo Krummrich" <dakr@kernel.org>,
"Daniel Almeida" <daniel.almeida@collabora.com>,
"Tamir Duberstein" <tamird@kernel.org>,
"Alexandre Courbot" <acourbot@nvidia.com>,
"Onur Özkan" <work@onurozkan.dev>
Cc: linux-kernel@vger.kernel.org, rust-for-linux@vger.kernel.org,
Gary Guo <gary@garyguo.net>
Subject: [PATCH v2 07/20] rust: pin-init: internal: pin_data: check covariance of self-referential fields
Date: Thu, 08 Oct 2026 20:24:31 +0100 [thread overview]
Message-ID: <20261008-dev-selfref-v2-7-e280b3c8fba5@garyguo.net> (raw)
In-Reply-To: <20261008-dev-selfref-v2-0-e280b3c8fba5@garyguo.net>
We implicitly infer covariance for fields that self-references. This needs
to be checked to ensure that the fields are really covariant, so the rest
of expansion code can rely on this fact.
Signed-off-by: Gary Guo <gary@garyguo.net>
---
rust/pin-init/internal/src/pin_data.rs | 75 +++++++++++++++++++++++++++++++++-
rust/pin-init/internal/src/util.rs | 24 ++++++++++-
2 files changed, 96 insertions(+), 3 deletions(-)
diff --git a/rust/pin-init/internal/src/pin_data.rs b/rust/pin-init/internal/src/pin_data.rs
index ec0b1aeefe7f..6a29ec358c30 100644
--- a/rust/pin-init/internal/src/pin_data.rs
+++ b/rust/pin-init/internal/src/pin_data.rs
@@ -76,7 +76,6 @@ enum Variance {
}
/// Information about field lifetimes captured in a type.
-#[expect(unused)]
struct Capture {
variance: Variance,
/// Lifetime to be captured.
@@ -435,6 +434,7 @@ fn expand(
let unpin_impl = generate_unpin_impl(&info);
let drop_impl = generate_drop_impl(&info);
let drop_order_check = generate_drop_order_check(dcx, &info);
+ let variance_check = generate_variance_check(&info);
let projections = generate_projections(&info);
let the_pin_data = generate_the_pin_data(&info);
@@ -444,6 +444,7 @@ fn expand(
// outside.
const _: () = {
#drop_order_check
+ #variance_check
#projections
#the_pin_data
#unpin_impl
@@ -770,6 +771,78 @@ fn __drop_order_check #impl_generics_with_field_lt (
}
}
+/// Produce variance checks, so we can ensure that the variance of lifetimes captured by field types
+/// actually match our expectation.
+fn generate_variance_check(info: &StructInfo) -> TokenStream {
+ if !info.self_referential {
+ return quote!();
+ }
+
+ let mut checks = Vec::new();
+
+ for f in info.fields.iter() {
+ let covariant_captures: Vec<_> = f
+ .captures
+ .iter()
+ .filter(|b| b.variance == Variance::Covariant)
+ .map(|b| &b.lifetime)
+ .collect();
+ if covariant_captures.is_empty() {
+ continue;
+ }
+
+ let ident = f.member.as_ident();
+ // Use the span of type for better error message.
+ let span = f.field.ty.span().resolved_at(Span::mixed_site());
+
+ let other_field_lifetimes = Generics {
+ lt_token: None,
+ params: f
+ .captures
+ .iter()
+ .filter(|b| b.variance != Variance::Covariant)
+ .map(|b| GenericParam::Lifetime(LifetimeParam::new(b.lifetime.clone())))
+ .collect(),
+ gt_token: None,
+ where_clause: None,
+ };
+
+ let long = Lifetime::new("'__long", span);
+ let long_ty = f
+ .field
+ .ty
+ .replace_lifetimes(&covariant_captures, &vec![&long; covariant_captures.len()]);
+
+ let short = Lifetime::new("'__short", span);
+ let short_ty = f
+ .field
+ .ty
+ .replace_lifetimes(&covariant_captures, &vec![&short; covariant_captures.len()]);
+
+ let check_name = format_ident!("__{ident}_covariance", span = span);
+
+ // Add `<'__long: '__short, 'short>` as additional generics.
+ let covariance_check_generics = parse_quote!(<#long: #short, #short>);
+ let combined_generics = CombinedGenerics(vec![
+ &covariance_check_generics,
+ &other_field_lifetimes,
+ &info.struct_.generics,
+ ]);
+ let (combined_impl_generics, _, whr) = combined_generics.split_for_impl();
+
+ checks.push(quote_spanned!(span =>
+ // Emit a check to ensure the type is *really* covariant for soundness.
+ fn #check_name #combined_impl_generics (long: #long_ty) -> #short_ty #whr {
+ long
+ }
+ ));
+ }
+
+ quote!(
+ #(#checks)*
+ )
+}
+
fn generate_projections(info: &StructInfo) -> TokenStream {
let ItemStruct {
vis,
diff --git a/rust/pin-init/internal/src/util.rs b/rust/pin-init/internal/src/util.rs
index f19712a46a30..59054f5934fb 100644
--- a/rust/pin-init/internal/src/util.rs
+++ b/rust/pin-init/internal/src/util.rs
@@ -5,8 +5,8 @@
use proc_macro2::{Ident, TokenStream};
use quote::{format_ident, ToTokens};
use syn::{
- visit::Visit, Attribute, BoundLifetimes, GenericParam, Generics, Index, Lifetime, Member,
- Token, TypePath,
+ parse_quote, visit::Visit, Attribute, BoundLifetimes, GenericParam, Generics, Index, Lifetime,
+ Member, Token, Type, TypePath,
};
use crate::DiagCtxt;
@@ -386,3 +386,23 @@ fn visit_type_path(&mut self, ty: &'a TypePath) {
TypeParamVisitor(f)
}
}
+
+pub(crate) trait TypeExt {
+ fn replace_lifetimes(&self, needle: &[&Lifetime], replacement: &[&Lifetime]) -> Type;
+}
+
+impl TypeExt for Type {
+ fn replace_lifetimes(&self, needle: &[&Lifetime], replacement: &[&Lifetime]) -> Type {
+ if needle.is_empty() {
+ return self.clone();
+ }
+
+ parse_quote!(
+ <
+ for<#(#needle,)*> fn(#(&#needle (),)*) -> #self
+ as
+ ::pin_init::__internal::FnOutput<(#(&#replacement (),)*)>
+ >::Output
+ )
+ }
+}
--
2.54.0
next prev parent reply other threads:[~2026-10-08 19:26 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 19:24 [PATCH v2 00/20] rust: pin-init: create self references safely Gary Guo
2026-10-08 19:24 ` [PATCH v2 01/20] kbuild: rust: allow `clippy::comparison_chain` globally Gary Guo
2026-10-08 19:24 ` [PATCH v2 02/20] rust: pin-init: internal: pin_data: infer self-referential struct Gary Guo
2026-10-08 19:24 ` [PATCH v2 03/20] rust: pin-init: internal: pin_data: rewrite fields that borrow others Gary Guo
2026-10-08 19:24 ` [PATCH v2 04/20] rust: pin-init: internal: pin_data: pin borrowed fields with wrapper Gary Guo
2026-10-08 19:24 ` [PATCH v2 05/20] rust: pin-init: internal: pin_data: teach drop check about generics that cannot dangle Gary Guo
2026-10-08 19:24 ` [PATCH v2 06/20] rust: pin-init: internal: pin_data: self-referential drop order checks Gary Guo
2026-10-08 19:24 ` Gary Guo [this message]
2026-10-08 19:24 ` [PATCH v2 08/20] rust: pin-init: internal: pin_data: implement initialization of borrowed structs Gary Guo
2026-10-08 19:24 ` [PATCH v2 09/20] rust: pin-init: internal: pin_data: project self-referential fields Gary Guo
2026-10-08 19:24 ` [PATCH v2 10/20] rust: pin-init: internal: pin_data: add `with_project` method Gary Guo
2026-10-08 19:24 ` [PATCH v2 11/20] rust: pin-init: internal: pin_data: enable self-referential support Gary Guo
2026-10-08 19:24 ` [PATCH v2 12/20] rust: pin-init: internal: pin_data: allow lifetime to be shortened per field drop order Gary Guo
2026-10-08 19:24 ` [PATCH v2 13/20] rust: pin-init: internal: pin_data: parse explicit `#[borrowed]` annotation Gary Guo
2026-10-08 19:24 ` [PATCH v2 14/20] rust: pin-init: internal: pin_data: support mutable borrows Gary Guo
2026-10-08 19:24 ` [PATCH v2 15/20] rust: pin-init: internal: pin_data: parse explicit `#[uses]` annotation Gary Guo
2026-10-08 19:24 ` [PATCH v2 16/20] rust: pin-init: internal: pin_data: make field lifetime invariance imply type invariance Gary Guo
2026-10-08 19:24 ` [PATCH v2 17/20] rust: pin-init: internal: pin_data: complete invariant borrow support Gary Guo
2026-10-08 19:24 ` [PATCH v2 18/20] rust: pin-init: internal: pin_data: perform AST lifetime replacement if possible Gary Guo
2026-10-08 19:24 ` [PATCH v2 19/20] rust: pin-init: internal: pin_data: support shared projection Gary Guo
2026-10-08 19:24 ` [PATCH v2 20/20] rust: pin-init: internal: pin_data: support existential lifetimes Gary Guo
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261008-dev-selfref-v2-7-e280b3c8fba5@garyguo.net \
--to=gary@garyguo.net \
--cc=a.hindborg@kernel.org \
--cc=acourbot@nvidia.com \
--cc=aliceryhl@google.com \
--cc=bjorn3_gh@protonmail.com \
--cc=boqun@kernel.org \
--cc=dakr@kernel.org \
--cc=daniel.almeida@collabora.com \
--cc=linux-kernel@vger.kernel.org \
--cc=lossin@kernel.org \
--cc=ojeda@kernel.org \
--cc=rust-for-linux@vger.kernel.org \
--cc=tamird@kernel.org \
--cc=tmgross@umich.edu \
--cc=work@onurozkan.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®