mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v2] rust: num: seal Integer
@ 2026-09-05 15:16 Younes Akhouayri via B4 Relay
  2026-09-06  0:16 ` Alexandre Courbot
  2026-09-06  1:53 ` Miguel Ojeda
  0 siblings, 2 replies; 3+ messages in thread
From: Younes Akhouayri via B4 Relay @ 2026-09-05 15:16 UTC (permalink / raw)
  To: Alexandre Courbot, Yury Norov, Miguel Ojeda, Boqun Feng,
	Gary Guo, Björn Roy Baron, Benno Lossin, Andreas Hindborg,
	Alice Ryhl, Trevor Gross, Danilo Krummrich, Daniel Almeida,
	Tamir Duberstein, Onur Özkan
  Cc: rust-for-linux, linux-kernel, stable, Younes Akhouayri

From: Younes Akhouayri <git@younes.io>

Bounded relies on Integer implementations to describe primitive integer
semantics correctly. In particular, it uses Integer::BITS and Signedness
to justify unchecked operations.

Integer is currently safe and externally implementable, so an
implementation can violate those assumptions and make safe Bounded
operations reach undefined behavior.

For example, an Integer implementation for a u8 wrapper can report
BITS = 16. Safe code can then cast a Bounded<u16, 9> containing 256
to that wrapper. Its TryFrom<u16> implementation returns Err, and
Bounded::cast() calls unwrap_unchecked() on it, causing undefined
behavior.

Seal Integer so only the primitive implementations provided by the
kernel crate can satisfy it.

Fixes: 01e345e82ec3 ("rust: num: add Bounded integer wrapping type")
Reported-by: Miguel Ojeda <ojeda@kernel.org>
Closes: https://lore.kernel.org/rust-for-linux/CANiq72mOfR33s4y+Ueivd5NrC5yre+Pcp57ZOBz0msw9A4AP1Q@mail.gmail.com/
Cc: stable@vger.kernel.org
Suggested-by: Miguel Ojeda <ojeda@kernel.org>
Signed-off-by: Younes Akhouayri <git@younes.io>
---
Changes in v2:
- Explain how an incorrect Integer implementation can cause undefined behavior.
- Add the missing Reported-by trailer.
- Link to v1: https://patch.msgid.link/20260905-feature-rust-num-seal-integer-v1-1-83096115ad64@younes.io
---
 rust/kernel/num.rs | 9 ++++++++-
 1 file changed, 8 insertions(+), 1 deletion(-)

diff --git a/rust/kernel/num.rs b/rust/kernel/num.rs
index dbe848e30efe..de589792a77a 100644
--- a/rust/kernel/num.rs
+++ b/rust/kernel/num.rs
@@ -15,9 +15,14 @@ pub enum Unsigned {}
 /// Designates signed primitive types.
 pub enum Signed {}
 
+mod private {
+    pub trait Sealed {}
+}
+
 /// Describes core properties of integer types.
 pub trait Integer:
-    Sized
+    private::Sealed
+    + Sized
     + Copy
     + Clone
     + PartialEq
@@ -56,6 +61,8 @@ pub trait Integer:
 macro_rules! impl_integer {
     ($($type:ty: $signedness:ty), *) => {
         $(
+        impl private::Sealed for $type {}
+
         impl Integer for $type {
             type Signedness = $signedness;
 

---
base-commit: e510334fbaeaa016ac76d80b4c5f47611c5f7860
change-id: 20260903-feature-rust-num-seal-integer-a4262df429c6

Best regards,
--  
Younes Akhouayri <git@younes.io>



^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH v2] rust: num: seal Integer
  2026-09-05 15:16 [PATCH v2] rust: num: seal Integer Younes Akhouayri via B4 Relay
@ 2026-09-06  0:16 ` Alexandre Courbot
  2026-09-06  1:53 ` Miguel Ojeda
  1 sibling, 0 replies; 3+ messages in thread
From: Alexandre Courbot @ 2026-09-06  0:16 UTC (permalink / raw)
  To: Younes Akhouayri via B4 Relay
  Cc: git, Yury Norov, Miguel Ojeda, Boqun Feng, Gary Guo,
	Björn Roy Baron, Benno Lossin, Andreas Hindborg, Alice Ryhl,
	Trevor Gross, Danilo Krummrich, Daniel Almeida, Tamir Duberstein,
	Onur Özkan, rust-for-linux, linux-kernel, stable

On Sun Sep 6, 2026 at 12:16 AM JST, Younes Akhouayri via B4 Relay wrote:
> From: Younes Akhouayri <git@younes.io>
>
> Bounded relies on Integer implementations to describe primitive integer
> semantics correctly. In particular, it uses Integer::BITS and Signedness
> to justify unchecked operations.
>
> Integer is currently safe and externally implementable, so an
> implementation can violate those assumptions and make safe Bounded
> operations reach undefined behavior.
>
> For example, an Integer implementation for a u8 wrapper can report
> BITS = 16. Safe code can then cast a Bounded<u16, 9> containing 256
> to that wrapper. Its TryFrom<u16> implementation returns Err, and
> Bounded::cast() calls unwrap_unchecked() on it, causing undefined
> behavior.
>
> Seal Integer so only the primitive implementations provided by the
> kernel crate can satisfy it.
>
> Fixes: 01e345e82ec3 ("rust: num: add Bounded integer wrapping type")
> Reported-by: Miguel Ojeda <ojeda@kernel.org>
> Closes: https://lore.kernel.org/rust-for-linux/CANiq72mOfR33s4y+Ueivd5NrC5yre+Pcp57ZOBz0msw9A4AP1Q@mail.gmail.com/
> Cc: stable@vger.kernel.org
> Suggested-by: Miguel Ojeda <ojeda@kernel.org>
> Signed-off-by: Younes Akhouayri <git@younes.io>

Acked-by: Alexandre Courbot <acourbot@nvidia.com>

Thanks for taking care of this!

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH v2] rust: num: seal Integer
  2026-09-05 15:16 [PATCH v2] rust: num: seal Integer Younes Akhouayri via B4 Relay
  2026-09-06  0:16 ` Alexandre Courbot
@ 2026-09-06  1:53 ` Miguel Ojeda
  1 sibling, 0 replies; 3+ messages in thread
From: Miguel Ojeda @ 2026-09-06  1:53 UTC (permalink / raw)
  To: git
  Cc: Alexandre Courbot, Yury Norov, Miguel Ojeda, Boqun Feng,
	Gary Guo, Björn Roy Baron, Benno Lossin, Andreas Hindborg,
	Alice Ryhl, Trevor Gross, Danilo Krummrich, Daniel Almeida,
	Tamir Duberstein, Onur Özkan, rust-for-linux, linux-kernel,
	stable

On Sat, Sep 5, 2026 at 5:17 PM Younes Akhouayri via B4 Relay
<devnull+git.younes.io@kernel.org> wrote:
>
> From: Younes Akhouayri <git@younes.io>
>
> Bounded relies on Integer implementations to describe primitive integer
> semantics correctly. In particular, it uses Integer::BITS and Signedness
> to justify unchecked operations.
>
> Integer is currently safe and externally implementable, so an
> implementation can violate those assumptions and make safe Bounded
> operations reach undefined behavior.
>
> For example, an Integer implementation for a u8 wrapper can report
> BITS = 16. Safe code can then cast a Bounded<u16, 9> containing 256
> to that wrapper. Its TryFrom<u16> implementation returns Err, and
> Bounded::cast() calls unwrap_unchecked() on it, causing undefined
> behavior.
>
> Seal Integer so only the primitive implementations provided by the
> kernel crate can satisfy it.
>
> Fixes: 01e345e82ec3 ("rust: num: add Bounded integer wrapping type")
> Reported-by: Miguel Ojeda <ojeda@kernel.org>
> Closes: https://lore.kernel.org/rust-for-linux/CANiq72mOfR33s4y+Ueivd5NrC5yre+Pcp57ZOBz0msw9A4AP1Q@mail.gmail.com/
> Cc: stable@vger.kernel.org
> Suggested-by: Miguel Ojeda <ojeda@kernel.org>
> Signed-off-by: Younes Akhouayri <git@younes.io>

Applied to `rust-fixes` -- thanks everyone!

It would be nice to explain somewhere in the code why the trait is
sealed, especially if we rely on it for safety, but that can be
improved later.

Cheers,
Miguel

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-06  1:53 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-05 15:16 [PATCH v2] rust: num: seal Integer Younes Akhouayri via B4 Relay
2026-09-06  0:16 ` Alexandre Courbot
2026-09-06  1:53 ` Miguel Ojeda

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®