From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ed1-f74.google.com (mail-ed1-f74.google.com [209.85.208.74]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 91E8A361DD6 for ; Thu, 5 Feb 2026 08:19:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.74 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770279593; cv=none; b=AjSv1LWODLDmArqGAmpJgbU3HoCq2M47E4toirtqmSyq0rYXLSy+mDHDq+dAVyKydgc9JuvivOmKu2kkx2tWvol5oY3cPnThWRNLohCCwcESWPPo/Mvn+9m7x0ZQs8MYJ6Sk/S7ne+lO/ANsVDTVsUtdJMBOxTBAp4On2IrRMOg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770279593; c=relaxed/simple; bh=7Fst46cNuu1kQuRIBG7xiNUzZSPl1AXx0qqmTSYWW2o=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=MI2CUTkIVirEpqAf47u6yjfZ3Exb85lPeMI0g8NF/bUVZGJqdUFmo52NGXdxJ6p5/SHm+bCe6BDhH3fXy0PKV5mWjUoKDNw69iHIxNdIHyTW5aPbNpA9vdzOZZ57bVsJyT+7VRGtkWFhrS01JVXWFmLKzTA5vG29DXDCv0kCKoY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--aliceryhl.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=KEOXoMce; arc=none smtp.client-ip=209.85.208.74 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--aliceryhl.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="KEOXoMce" Received: by mail-ed1-f74.google.com with SMTP id 4fb4d7f45d1cf-659587815c2so990612a12.0 for ; Thu, 05 Feb 2026 00:19:52 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1770279591; x=1770884391; darn=vger.kernel.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:from:to:cc:subject:date:message-id:reply-to; bh=fxPcK36bK2rMabpnzCRfWnJSG7ZqPhcKrQTFDoZ0aKU=; b=KEOXoMceww6Lw8AB8CYloC1zX+IHmnVmWvw1lLlGpG6ONxYkyQGED1RhT5yg5F9IBs Pa0Gkn5cUrLHA7onC+d8QTer1JfK/HFEBwy8/nX7PqcRzuHE8AYtl0WTcESSJA8DDx0u Ue859r93bLqjDuwSmQ/DnAGvrEE6fof2h8QuxreL2fn37FBvMznZ+7Ne8OLrTjLOaPk2 A1xXOVKI2LjOfTgL+yjGKcUPf3h4lIRlED5Fpwf18tp8sQSIK/ESb5wP0cGEo4mtmo9J QedFfbOcKHdJnYq8YV470OOu6tRIDzYjNPeSGtsw1CSxYeHNPB308zj1Z+JKjVrSeNP3 ax6Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1770279591; x=1770884391; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=fxPcK36bK2rMabpnzCRfWnJSG7ZqPhcKrQTFDoZ0aKU=; b=qgIueprZg5xTFtluY0xtiP1UM7t0oRRWDyZrg6xz0MNp0GhW3BfirKLsDk0TPCTS84 ZRYdd6VO/GiSx3WfRp48wZ0uEpJ93BTLX/HMiYD/h5dnOTWuSRd+iyR8/zsynkBDsMNF bYJ/RG1wnQc6UrOYXHk4KoKcnOiV8bwydm81/Cy88C91yC5e14Kn6wgWp8snoJiU50q8 1RvvhZAOODpcSkJNz1WfFokHvDxOX4Z/fQVuJYZ+Q1zewRwChIzjise8yQYFzLCOybd1 QAlZ8znUmqXAt2Kg06sx3i8NU9mkR/G15yOvbR5fal0e2InrRy/lBgjRgqgd+Vbz10X+ Yd9A== X-Forwarded-Encrypted: i=1; AJvYcCX6vWwq7Lqp+IIprtyw58ZxiIw4PiFsunxgGGiJr2U3ZH+IBNBVRKODRhTfufJrG7PWjhMdx6gbQY8VhR0=@vger.kernel.org X-Gm-Message-State: AOJu0YxmGVEXJKAGkksnvQQI2RM+eQQ+5pchrQeBoV2YyopEBAMq6hp8 lw5SPi+E2ZjiU5MJz6ut3xtmk8xSW6gbCAKNlZXfD27JB2ocXbcADZNM0/RF9gV0dKHKb3XSB3u S6cfCGmFDzXeN5erRxQ== X-Received: from ejgi1.prod.google.com ([2002:a17:906:3c41:b0:b8d:7187:d449]) (user=aliceryhl job=prod-delivery.src-stubby-dispatcher) by 2002:a17:906:ef07:b0:b88:227e:3876 with SMTP id a640c23a62f3a-b8e9f0ef860mr409916266b.24.1770279590685; Thu, 05 Feb 2026 00:19:50 -0800 (PST) Date: Thu, 5 Feb 2026 08:19:49 +0000 In-Reply-To: <20260205042132.40772-1-muchamadcoirulanwar@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260205042132.40772-1-muchamadcoirulanwar@gmail.com> Message-ID: Subject: Re: [PATCH] rust: print: add safety comments for %pA formatting From: Alice Ryhl To: Muchamad Coirul Anwar Cc: ojeda@kernel.org, boqun@kernel.org, gary@garyguo.net, bjorn3_gh@protonmail.com, lossin@kernel.org, a.hindborg@kernel.org, tmgross@umich.edu, dakr@kernel.org, tamird@kernel.org, gregkh@linuxfoundation.org, fujita.tomonori@gmail.com, andrewjballance@gmail.com, rust-for-linux@vger.kernel.org, linux-kernel@vger.kernel.org Content-Type: text/plain; charset="utf-8" On Thu, Feb 05, 2026 at 11:21:32AM +0700, Muchamad Coirul Anwar wrote: > The safety comments in `rust_fmt_argument` and `call_printk` were > previously marked as TODO. > > This patch adds the missing safety documentation explaining why > dereferencing the pointers and calling the C `_printk` function > is safe in these contexts. It clarifies the contract between > `lib/vsprintf.c` and the Rust implementation regarding the `%pA` > format specifier. > > Signed-off-by: Muchamad Coirul Anwar > --- > rust/kernel/print.rs | 10 ++++++++-- > 1 file changed, 8 insertions(+), 2 deletions(-) > > diff --git a/rust/kernel/print.rs b/rust/kernel/print.rs > index 6fd84389a858..3e6ff8f42d95 100644 > --- a/rust/kernel/print.rs > +++ b/rust/kernel/print.rs > @@ -29,7 +29,11 @@ > use fmt::Write; > // SAFETY: The C contract guarantees that `buf` is valid if it's less than `end`. > let mut w = unsafe { RawFormatter::from_ptrs(buf.cast(), end.cast()) }; > - // SAFETY: TODO. > + // SAFETY: The C implementation of `vsprintf` (in `lib/vsprintf.c`) specifically > + // calls this function ONLY when processing the `%pA` format specifier. > + // On the Rust side (`call_printk`), we guarantee that `%pA` is always paired > + // with a valid pointer to `fmt::Arguments`. > + // Therefore, dereferencing `ptr` here is safe. There are multiple places that %pA is passed. For example, there is also seq_file.rs and probably more. Perhaps remove the reference to call_printk here? // SAFETY: The C implementation of `vsprintf` (in `lib/vsprintf.c`) specifically // calls this function ONLY when processing the `%pA` format specifier. // On the Rust side, we always pair `%pA` with a valid pointer to // `fmt::Arguments`. > let _ = w.write_fmt(unsafe { *ptr.cast::>() }); > w.pos().cast() > } > @@ -109,7 +113,9 @@ pub unsafe fn call_printk( > ) { > // `_printk` does not seem to fail in any path. > #[cfg(CONFIG_PRINTK)] > - // SAFETY: TODO. > + // SAFETY: The format string is constructed to use `%pA`, which corresponds to the > + // pointer to `fmt::Arguments` passed as the third argument. > + // Since `args` is a valid reference, casting it to a pointer is safe. > unsafe { > bindings::_printk( > format_string.as_ptr(), > -- > 2.50.0 >