mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Dirk Behme <dirk.behme@de.bosch.com>
To: "Benno Lossin" <lossin@kernel.org>,
	"Greg KH" <gregkh@linuxfoundation.org>,
	"Simona Vetter" <simona.vetter@ffwll.ch>,
	"Miguel Ojeda" <ojeda@kernel.org>,
	"Alex Gaynor" <alex.gaynor@gmail.com>,
	"Boqun Feng" <boqun.feng@gmail.com>,
	"Gary Guo" <gary@garyguo.net>,
	"Björn Roy Baron" <bjorn3_gh@protonmail.com>,
	"Andreas Hindborg" <a.hindborg@kernel.org>,
	"Alice Ryhl" <aliceryhl@google.com>,
	"Trevor Gross" <tmgross@umich.edu>,
	"Danilo Krummrich" <dakr@kernel.org>
Cc: Benno Lossin <benno.lossin@proton.me>,
	<rust-for-linux@vger.kernel.org>, <linux-kernel@vger.kernel.org>
Subject: Re: [RFC PATCH v4 3/4] rust: validate: add `Validate` trait
Date: Thu, 4 Sep 2025 08:48:12 +0200	[thread overview]
Message-ID: <55ad62f0-759d-48db-a8b2-6ca0b34380c0@de.bosch.com> (raw)
In-Reply-To: <20250814124424.516191-4-lossin@kernel.org>

On 14/08/2025 14:44, Benno Lossin wrote:
> From: Benno Lossin <benno.lossin@proton.me>
> 
> Introduce the `Validate<Input>` trait and functions to validate
> `Untrusted<T>` using said trait. This allows one to access the inner
> value of `Untrusted<T>` via `validate{,_ref,_mut}` functions which
> subsequently delegate the validation to user-implemented `Validate`
> trait.
> 
> The `Validate` trait is the only entry point for validation code, making
> it easy to spot where data is being validated.
> 
> The reason for restricting the types that can be inputs to
> `Validate::validate` is to be able to have the `validate...` functions
> on `Untrusted`. This is also the reason for the suggestions in the
> `Usage in API Design` section in the commit that introduced
> `Untrusted<T>`.
> 
> Signed-off-by: Benno Lossin <benno.lossin@proton.me>


While experimenting with this I was looking for an example how to use
`Validate::validate`. For example, illustrating how the "very bad idea"
read_bytes_from_network() example from patch 2/4 could be done correctly
with these patches would be nice.

Just to illustrate what I'm thinking about see [1].

Thanks!

Dirk

[1]

diff --git a/rust/kernel/validate.rs b/rust/kernel/validate.rs
index 2a582a572aa5e..688ccd541712a 100644
--- a/rust/kernel/validate.rs
+++ b/rust/kernel/validate.rs
@@ -82,6 +82,7 @@
 /// Here too the reason is that `KVec<Untrusted<u8>>` is more
restrictive compared to
 /// `Untrusted<KVec<u8>>`.
 #[repr(transparent)]
+#[derive(Copy, Clone)]
 pub struct Untrusted<T: ?Sized>(T);

 impl<T: ?Sized> Untrusted<T> {
@@ -201,6 +202,49 @@ impl<'a, T: ?Sized> Sealed for &'a mut Untrusted<T> {}
 /// Care must be taken when implementing this trait, as unprotected
access to unvalidated data is
 /// given to the [`Validate::validate`] function. The implementer must
ensure that the data is only
 /// used for logic after successful validation.
+///
+/// # Examples
+///
+///```
+/// # use kernel::validate::{Untrusted, Validate};
+///
+/// struct TrustedIndex(u8);
+/// struct TrustedData(u8);
+///
+/// # fn read_bytes_from_network() -> KBox<Untrusted<[u8]>> {
+/// #    Box::new(Untrusted::new([1, 0]),
kernel::alloc::flags::GFP_KERNEL).unwrap()
+/// # }
+/// impl Validate<Untrusted<u8>> for TrustedIndex {
+///     type Err = Error;
+///
+///     fn validate(raw: u8) -> Result<Self, Self::Err> {
+///         if raw != 1 {
+///             pr_err!("Invalid index: {}\n", raw);
+///             return Err(EINVAL);
+///         }
+///         Ok(TrustedIndex(raw))
+///     }
+/// }
+///
+/// impl Validate<Untrusted<u8>> for TrustedData {
+///     type Err = Error;
+///
+///     fn validate(raw: u8) -> Result<Self, Self::Err> {
+///         // All raw data values are valid
+///         Ok(TrustedData(raw))
+///     }
+/// }
+///
+/// fn example() -> Result{
+///    let rawbytes = read_bytes_from_network();
+///    let index = rawbytes[0].validate::<TrustedIndex>()?;
+///    let data =
rawbytes[usize::from(index.0)].validate::<TrustedData>()?;
+///    assert_eq!(data.0, 0);
+///    Ok(())
+/// }
+/// # example()?;
+/// # Ok::<(), Error>(())
+/// ```
 pub trait Validate<Input: ValidateInput>: Sized {
     /// Validation error.
     type Err;

  reply	other threads:[~2025-09-04  6:48 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20250814124424.516191-1-lossin@kernel.org>
2025-08-14 12:44 ` [PATCH v4 1/4] rust: transmute: add `cast_slice[_mut]` functions Benno Lossin
2025-08-14 12:44 ` [PATCH v4 2/4] rust: create basic untrusted data API Benno Lossin
2025-08-29  5:23   ` Dirk Behme
2025-08-14 12:44 ` [RFC PATCH v4 3/4] rust: validate: add `Validate` trait Benno Lossin
2025-09-04  6:48   ` Dirk Behme [this message]
2025-08-14 12:44 ` [RFC PATCH v4 4/4] rust: iov: use untrusted data API Benno Lossin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=55ad62f0-759d-48db-a8b2-6ca0b34380c0@de.bosch.com \
    --to=dirk.behme@de.bosch.com \
    --cc=a.hindborg@kernel.org \
    --cc=alex.gaynor@gmail.com \
    --cc=aliceryhl@google.com \
    --cc=benno.lossin@proton.me \
    --cc=bjorn3_gh@protonmail.com \
    --cc=boqun.feng@gmail.com \
    --cc=dakr@kernel.org \
    --cc=gary@garyguo.net \
    --cc=gregkh@linuxfoundation.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lossin@kernel.org \
    --cc=ojeda@kernel.org \
    --cc=rust-for-linux@vger.kernel.org \
    --cc=simona.vetter@ffwll.ch \
    --cc=tmgross@umich.edu \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®