From nobody Fri Sep 25 06:47:18 2026 Received: from mail-wm2-f12.google.com (mail-wm2-f12.google.com [74.125.225.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3F178277818 for ; Wed, 16 Sep 2026 01:15:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.140 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789521316; cv=none; b=Hp61CnVLCRyvo4AVvIKt79914xIjc7LiOnZqr23kOViTvwnDph7IMmUD89sKgcT5yPJSWY7JS1jmkAOV2TA4P7tYxpX6ebZJ5znsz/vMbbwuT9h9mm4+Qwk+w4L7j4/nzxiTVDJ29ij2JOze/H+TN5HRFSv352UksATSf/2yX2Y= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789521316; c=relaxed/simple; bh=1oHur9vEj+OaGrHshuKT+eDTAu8cXqL6ipLWH80GzPo=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=KxduVZsPPQBfZ28JEcIw2qEqejtm13I90+LD79IxHhb40jMJHqaAAsFd2PLLuAHyFUhmps5+dO038PwzQe5ppHN5ycejrHz4g0tjBUYsg8X7rtWRpgoNYESzay/7WVZvmSarMrhSWwiXf9O8g4Dff0JMNhmyHMe820+pMWqSc+g= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=sAXcBLNF; arc=none smtp.client-ip=74.125.225.140 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="sAXcBLNF" Received: by mail-wm2-f12.google.com with SMTP id 5b1f17b1804b1-49cd5462b69so2060505e9.1 for ; Tue, 15 Sep 2026 18:15:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789521311; x=1790126111; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=jnXDLK26KNZ+Nc8tc4KYaeGG7+wo+38IhWGefLy0ryc=; b=sAXcBLNF8mJ9yDJtXRLX2zVPFKNgN5+KR3ZA0BGPvB9GuDwmPW0M/ZWXPLacdfSBoQ soIGFj3p2SJpprt/WjtqqS9qg/BkbnoZS0NLIfUO+RCEEcal6KJ6ZW8SmOnmmSd9zNpF Y5GvJKpsNDBIaJZrFElsORrIyfpM2tKBul9Px60i3b5O4aj+WTJf4oxnz1xQ4AdL8o5o TuJp7vM64CRk8gg5KTD3E2DbWLohjzO023xdO/IcvLRChG9iHfG+cGHWdNIlzr9aMEB2 ggntOWtaUHx7n8blfT/nXMhbYNOeT/VWfUjxHm8qsLa0M68TEAQev71UG7O2eBE3Z+vh mNFw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789521311; x=1790126111; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=jnXDLK26KNZ+Nc8tc4KYaeGG7+wo+38IhWGefLy0ryc=; b=F3QgYnDVCzzoZCkoDEhNltuQXqRSWJFPFFHLHweluCm/xBUXR+m8khltiSspjNGfnG vudEAn0cZOCjsAH1ob732fkcGSY4lQ0r8D+27NHZFI8e4op+KTHIoY0HhX1hae7vtMBY 9m+hOSgVyscWwN3Ywxa2vNFgI3YL9vWO1OsNNKbCF3wweSvNV0z8jx4o7DgWQ6fUl+jj d7dspFMHhIihlxM2XzP5eWLMCd8PtQnE1yAtw3ovBjGypsw49Zxa8DjSQrjClBn2PwXv vyr0lLRrLm3uWZwHhBHez4qFNwrgn60YqWna8XtyCMI1kNEDay7M086A5L8YYobZznH3 hFwA== X-Forwarded-Encrypted: i=1; AKwUvBzATVw+YJaN5xo9HPA65bKYedY27jGuR4TajRgUX0CkwNoCX5GhYDCrQShrDKmmmMtyW33sSr4XWToD7dU=@vger.kernel.org X-Gm-Message-State: AFuF++l2IYrhzuiS4EVbJ4gxtsQJBpRqm4CR3Ww/VhxX29ocSN7ljir3 DhEyygUw/tdE03F2QeK25Lo9IgauWM+P35RHoHkn5qKPmnV8rP5FMeA2 X-Gm-Gg: AYBFou2VPjRzuA/ILu0fGPbLixjztsxzAxbyE6UEAZeKUhM4TD5lVzdEB7+vVI7Pwb3 8cvUEyCpFpmNMvEJWzEWgX3XURr3pOwKqsSW5Km58EGavynO9qnliz2NGuVHUyxn5506Au3ALpQ ixP9qxp37fZo8YPD0j57HoL/1qbrZpDgbwko1ZPu2fRMCfLFLv4ZU2IoROGPTzJjh/T96LHuJhA FJL6jyWQY/OsVGuhpaHhs7sQVetSYstuoBCM5CNtHvVXf9UyQfI/EJbMTc0Ru/xanbgQtZmw+dX Pr+1WAXtFnP8gdyJAPtSDp7G02b0bIRvUQ7fJBl2/LkBWn0yLxomLqGqkkMWg6OcoNLvDk+HDk2 BA+uoH9Kme95Gj7G4bmxHbu3DIAXnfaKKJqg4K1atrSkNQNm48X0V4VWDhoqpeCL6DxrGXJ/5Iy KaiXIVBMwMnthMQ7TUDoCMiGsRd/nuD5XPom2BBo9lbIO4LoBnBJWv33V5KhRpEahZ0XsWzT1Rq Eb0sZ+M4qRv/PDxj2f4fa0ujqboPNKHgM0G5LUW33T1iSL+swSPS5w1gMeX8FzJXA== X-Received: by 2002:a05:600c:3b97:b0:49e:6050:9fbe with SMTP id 5b1f17b1804b1-49ebcc010d5mr9739045e9.15.1789521311221; Tue, 15 Sep 2026 18:15:11 -0700 (PDT) Received: from moosama76.. ([156.193.15.50]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49e83fca34asm26367435e9.1.2026.09.15.18.15.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 15 Sep 2026 18:15:10 -0700 (PDT) From: Mohamed Osama To: rust-for-linux@vger.kernel.org Cc: linux-block@vger.kernel.org, linux-serial@vger.kernel.org, linux-kernel@vger.kernel.org, Mohamed Osama , Gary Guo Subject: [PATCH] rust: mem: add DropGuard Date: Wed, 16 Sep 2026 04:15:00 +0300 Message-ID: <20260916011500.529743-1-mohamed.osama189110@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Add a `DropGuard` type to the Rust kernel memory module for running cleanup code when a scope is left. `DropGuard` runs a `FnOnce` callback when dropped and provides `dismiss()` to take the wrapped value without running the callback. Replace the current `ScopeGuard` users in `gen_disk`, `serdev`, and `sync::lock` with `DropGuard`. Keep `ScopeGuard` since it is still used elsewhere. Add KUnit tests for cleanup on drop and `dismiss()`. Tested with: - `make LLVM=3D1 -j$(nproc)` - KUnit: 8 tests passed - `make LLVM=3D1 rustfmtcheck` - `git diff --check` - `checkpatch.pl` - `make LLVM=3D1 rustdoc` Suggested-by: Gary Guo Link: https://github.com/Rust-for-Linux/linux/issues/1255 Signed-off-by: Mohamed Osama --- rust/kernel/Kconfig.test | 10 +++ rust/kernel/block/mq/gen_disk.rs | 11 +-- rust/kernel/mem.rs | 116 +++++++++++++++++++++++++++++++ rust/kernel/serdev.rs | 8 +-- rust/kernel/sync/lock.rs | 5 +- 5 files changed, 138 insertions(+), 12 deletions(-) diff --git a/rust/kernel/Kconfig.test b/rust/kernel/Kconfig.test index e6a5c7a795f0..011c72f14e2c 100644 --- a/rust/kernel/Kconfig.test +++ b/rust/kernel/Kconfig.test @@ -33,6 +33,16 @@ config RUST_KVEC_KUNIT_TEST =20 If unsure, say N. =20 +config RUST_DROP_GUARD_KUNIT_TEST + bool "KUnit tests for Rust DropGuard API" if !KUNIT_ALL_TESTS + default KUNIT_ALL_TESTS + help + This option enables KUnit tests for the Rust DropGuard API. + These are only for development and testing, not for regular + kernel use cases. + + If unsure, say N. + config RUST_BITMAP_KUNIT_TEST bool "KUnit tests for Rust bitmap API" if !KUNIT_ALL_TESTS default KUNIT_ALL_TESTS diff --git a/rust/kernel/block/mq/gen_disk.rs b/rust/kernel/block/mq/gen_di= sk.rs index fc97dd873974..d9019fbbb361 100644 --- a/rust/kernel/block/mq/gen_disk.rs +++ b/rust/kernel/block/mq/gen_disk.rs @@ -10,11 +10,12 @@ block::mq::{Operations, TagSet}, error::{self, from_err_ptr, Result}, fmt::{self, Write}, + mem::DropGuard, prelude::*, static_lock_class, str::NullTerminatedFormatter, sync::Arc, - types::{ForeignOwnable, ScopeGuard}, + types::ForeignOwnable, }; =20 /// A builder for [`GenDisk`]. @@ -102,7 +103,7 @@ pub fn build( queue_data: T::QueueData, ) -> Result> { let data =3D queue_data.into_foreign(); - let recover_data =3D ScopeGuard::new(|| { + let recover_data =3D DropGuard::new((), |_| { // SAFETY: T::QueueData was created by the call to `into_forei= gn()` above drop(unsafe { T::QueueData::from_foreign(data) }); }); @@ -150,7 +151,7 @@ pub fn build( // SAFETY: `gendisk` is a valid pointer as we initialized it above unsafe { (*gendisk).fops =3D &TABLE }; =20 - let cleanup_failure =3D ScopeGuard::new_with_data((gendisk, data),= |(gendisk, data)| { + let cleanup_failure =3D DropGuard::new((gendisk, data), |(gendisk,= data)| { // SAFETY: `gendisk` came from `__blk_mq_alloc_disk()` above a= nd // has not been added to the VFS on this cleanup path. unsafe { bindings::put_disk(gendisk) }; @@ -161,7 +162,7 @@ pub fn build( =20 // The failure guard now owns both pieces of cleanup; the early gu= ard // must not run on this path anymore. - recover_data.dismiss(); + DropGuard::dismiss(recover_data); =20 let mut writer =3D NullTerminatedFormatter::new( // SAFETY: `gendisk` points to a valid and initialized instanc= e. We @@ -185,7 +186,7 @@ pub fn build( }, )?; =20 - cleanup_failure.dismiss(); + DropGuard::dismiss(cleanup_failure); =20 // INVARIANT: `gendisk` was initialized above. // INVARIANT: `gendisk` was added to the VFS via `device_add_disk`= above. diff --git a/rust/kernel/mem.rs b/rust/kernel/mem.rs index f2d4cdf87d00..e098675ea195 100644 --- a/rust/kernel/mem.rs +++ b/rust/kernel/mem.rs @@ -4,6 +4,88 @@ =20 use crate::prelude::*; =20 +use core::mem::ManuallyDrop; +use core::ops::{Deref, DerefMut}; + +/// Wraps a value and runs a closure when dropped. +/// +/// This is useful for running cleanup code when leaving a scope. +/// +/// The [`DropGuard::dismiss`] function can be used to take ownership of t= he wrapped +/// value without running the cleanup function. +#[doc(alias =3D "ScopeGuard")] +#[doc(alias =3D "defer")] +pub struct DropGuard +where + F: FnOnce(T), +{ + inner: ManuallyDrop, + f: ManuallyDrop, +} + +impl DropGuard +where + F: FnOnce(T), +{ + /// Creates a new `DropGuard`. + #[must_use] + pub fn new(inner: T, f: F) -> Self { + Self { + inner: ManuallyDrop::new(inner), + f: ManuallyDrop::new(f), + } + } + + /// Consumes the `DropGuard`, returning the wrapped value without + /// running the cleanup function. + pub fn dismiss(guard: Self) -> T { + let mut guard =3D ManuallyDrop::new(guard); + + // SAFETY: We have taken ownership of the guard and prevent its de= structor from running. + let value =3D unsafe { ManuallyDrop::take(&mut guard.inner) }; + + // SAFETY: We have taken ownership of the guard. + unsafe { ManuallyDrop::drop(&mut guard.f) }; + + value + } +} + +impl Deref for DropGuard +where + F: FnOnce(T), +{ + type Target =3D T; + + fn deref(&self) -> &T { + &self.inner + } +} + +impl DerefMut for DropGuard +where + F: FnOnce(T), +{ + fn deref_mut(&mut self) -> &mut T { + &mut self.inner + } +} + +impl Drop for DropGuard +where + F: FnOnce(T), +{ + fn drop(&mut self) { + // SAFETY: `DropGuard` is in the process of being dropped. + let inner =3D unsafe { ManuallyDrop::take(&mut self.inner) }; + + // SAFETY: `DropGuard` is in the process of being dropped. + let f =3D unsafe { ManuallyDrop::take(&mut self.f) }; + + f(inner); + } +} + /// Transmute between two types. /// /// Use this instead of [`core::mem::transmute`] when it is known that siz= es are identical but this @@ -232,3 +314,37 @@ unsafe impl AsReprMut for $signed {} // `usize` is not normalized to particular integer for portability. usize isize, } + +#[cfg(CONFIG_RUST_DROP_GUARD_KUNIT_TEST)] +#[macros::kunit_tests(rust_drop_guard)] +mod tests { + use super::*; + + #[test] + fn test_drop_runs_cleanup() { + let mut cleaned =3D false; + + { + let _guard =3D DropGuard::new(42, |value| { + assert_eq!(value, 42); + cleaned =3D true; + }); + } + + assert!(cleaned); + } + + #[test] + fn test_dismiss_returns_value_without_cleanup() { + let mut cleaned =3D false; + + let guard =3D DropGuard::new(42, |_| { + cleaned =3D true; + }); + + let value =3D DropGuard::dismiss(guard); + + assert_eq!(value, 42); + assert!(!cleaned); + } +} diff --git a/rust/kernel/serdev.rs b/rust/kernel/serdev.rs index 17ca504b7f8d..a400d241c2ad 100644 --- a/rust/kernel/serdev.rs +++ b/rust/kernel/serdev.rs @@ -13,6 +13,7 @@ to_result, VTABLE_DEFAULT_ERROR, // }, + mem::DropGuard, new_mutex, of, prelude::*, @@ -21,10 +22,7 @@ Mutex, // }, time::Jiffies, - types::{ - Opaque, - ScopeGuard, // - }, // + types::Opaque, // }; =20 use core::{ @@ -174,7 +172,7 @@ extern "C" fn probe_callback(sdev: *mut bindings::serde= v_device) -> kernel::ffi: }))?; // SAFETY: We just set drvdata to `PrivateData<'_, T>`. let private_data =3D unsafe { sdev.as_ref().drvdata_borrow::>() }; - let private_data =3D ScopeGuard::new_with_data(private_data, |= _| { + let private_data =3D DropGuard::new(private_data, |_| { // SAFETY: We just set drvdata to `PrivateData<'_, T>`. drop(unsafe { sdev.as_ref().drvdata_obtain::>() }); }); diff --git a/rust/kernel/sync/lock.rs b/rust/kernel/sync/lock.rs index 10b6b5e9b024..15f9cbe76c8d 100644 --- a/rust/kernel/sync/lock.rs +++ b/rust/kernel/sync/lock.rs @@ -7,8 +7,9 @@ =20 use super::LockClassKey; use crate::{ + mem::DropGuard, str::{CStr, CStrExt as _}, - types::{NotThreadSafe, Opaque, ScopeGuard}, + types::{NotThreadSafe, Opaque}, }; use core::{cell::UnsafeCell, marker::PhantomPinned, pin::Pin}; use pin_init::{pin_data, pin_init, PinInit, Wrapper}; @@ -242,7 +243,7 @@ pub(crate) fn do_unlocked(&mut self, cb: impl FnOnce= () -> U) -> U { // SAFETY: The caller owns the lock, so it is safe to unlock it. unsafe { B::unlock(self.lock.state.get(), &self.state) }; =20 - let _relock =3D ScopeGuard::new(|| + let _relock =3D DropGuard::new((), |_| // SAFETY: The lock was just unlocked above and is being r= elocked now. unsafe { B::relock(self.lock.state.get(), &mut self.state)= }); =20 --=20 2.43.0