mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: JX <1239989762@qq.com>
To: Miguel Ojeda <ojeda@kernel.org>, Danilo Krummrich <dakr@kernel.org>
Cc: "Boqun Feng" <boqun@kernel.org>, "Gary Guo" <gary@garyguo.net>,
	"Björn Roy Baron" <bjorn3_gh@protonmail.com>,
	"Benno Lossin" <lossin@kernel.org>,
	"Andreas Hindborg" <a.hindborg@kernel.org>,
	"Alice Ryhl" <aliceryhl@google.com>,
	"Trevor Gross" <tmgross@umich.edu>,
	"Daniel Almeida" <daniel.almeida@collabora.com>,
	"Tamir Duberstein" <tamird@kernel.org>,
	"Alexandre Courbot" <acourbot@nvidia.com>,
	"Onur Özkan" <work@onurozkan.dev>,
	"Lorenzo Stoakes" <ljs@kernel.org>,
	"Vlastimil Babka" <vbabka@kernel.org>,
	"Liam R . Howlett" <liam@infradead.org>,
	"Uladzislau Rezki" <urezki@gmail.com>,
	rust-for-linux@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: [PATCH v2 2/2] rust: alloc: use unsafe_precondition_assert! in Vec length helpers
Date: Tue,  8 Sep 2026 17:26:24 +0800	[thread overview]
Message-ID: <tencent_DD87A0F7B21501AFDD1205B7FE797FF85F0A@qq.com> (raw)
In-Reply-To: <20260908092624.63350-1-1239989762@qq.com>

Vec::inc_len and Vec::dec_len are unsafe functions whose debug
assertions directly check their documented safety preconditions.

Use unsafe_precondition_assert! for these checks so violations are
identified as unsafe precondition failures. The inc_len use also keeps
the const-compatible macro path covered by kernel compilation.

Suggested-by: Miguel Ojeda <ojeda@kernel.org>
Link: https://github.com/Rust-for-Linux/linux/issues/1232
Signed-off-by: JX <1239989762@qq.com>
---
 rust/kernel/alloc/kvec.rs | 7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

diff --git a/rust/kernel/alloc/kvec.rs b/rust/kernel/alloc/kvec.rs
index c7546b9da4..9216a4a304 100644
--- a/rust/kernel/alloc/kvec.rs
+++ b/rust/kernel/alloc/kvec.rs
@@ -23,7 +23,8 @@
     page::{
         AsPageIter,
         PAGE_SIZE, //
-    }, //
+    },
+    unsafe_precondition_assert, //
 };
 
 use core::{
@@ -230,7 +231,7 @@ pub const fn len(&self) -> usize {
     #[inline]
     pub const unsafe fn inc_len(&mut self, additional: usize) {
         // Guaranteed by the type invariant to never underflow.
-        debug_assert!(additional <= self.capacity() - self.len());
+        unsafe_precondition_assert!(additional <= self.capacity() - self.len());
         // INVARIANT: By the safety requirements of this method this represents the exact number of
         // elements stored within `self`.
         self.len += additional;
@@ -245,7 +246,7 @@ pub const fn len(&self) -> usize {
     ///
     /// - `count` must be less than or equal to `self.len`.
     unsafe fn dec_len(&mut self, count: usize) -> &mut [T] {
-        debug_assert!(count <= self.len());
+        unsafe_precondition_assert!(count <= self.len());
         // INVARIANT: We relinquish ownership of the elements within the range `[self.len - count,
         // self.len)`, hence the updated value of `set.len` represents the exact number of elements
         // stored within `self`.
-- 
2.54.0



      parent reply	other threads:[~2026-09-08  9:26 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20260908080604.34070-1-1239989762@qq.com>
2026-09-08  8:06 ` [PATCH 1/2] rust: make unsafe_precondition_assert! const compatible JX
2026-09-08  8:06 ` [PATCH 2/2] rust: alloc: use unsafe_precondition_assert! in Vec length helpers JX
2026-09-08  9:26 ` [PATCH v2 0/2] rust: add unsafe precondition assertions to " JX
     [not found] ` <20260908092624.63350-1-1239989762@qq.com>
2026-09-08  9:26   ` [PATCH v2 1/2] rust: make unsafe_precondition_assert! const compatible JX
2026-09-08 19:59     ` Miguel Ojeda
2026-09-08  9:26   ` JX [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=tencent_DD87A0F7B21501AFDD1205B7FE797FF85F0A@qq.com \
    --to=1239989762@qq.com \
    --cc=a.hindborg@kernel.org \
    --cc=acourbot@nvidia.com \
    --cc=aliceryhl@google.com \
    --cc=bjorn3_gh@protonmail.com \
    --cc=boqun@kernel.org \
    --cc=dakr@kernel.org \
    --cc=daniel.almeida@collabora.com \
    --cc=gary@garyguo.net \
    --cc=liam@infradead.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=ljs@kernel.org \
    --cc=lossin@kernel.org \
    --cc=ojeda@kernel.org \
    --cc=rust-for-linux@vger.kernel.org \
    --cc=tamird@kernel.org \
    --cc=tmgross@umich.edu \
    --cc=urezki@gmail.com \
    --cc=vbabka@kernel.org \
    --cc=work@onurozkan.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®