mirror of
https://github.com/torvalds/linux.git
synced 2026-09-22 04:34:03 +02:00
rust: num: reject Bounded::shr overshifts at build time
Make `shr` reject shifts of at least the type's bit width at build
time, instead of panicking or masking the shift amount at runtime.
[ This implies we can break the type invariant, which in turn means
we can trigger UB via `Deref`, e.g.:
rust_kernel: panicked at rust/kernel/num/bounded.rs:528:22:
unsafe precondition(s) violated: hint::unreachable_unchecked must never be reached
- Miguel ]
Signed-off-by: Eliot Courtney <ecourtney@nvidia.com>
Acked-by: Alexandre Courbot <acourbot@nvidia.com>
Reviewed-by: Gary Guo <gary@garyguo.net>
Reviewed-by: Danilo Krummrich <dakr@kernel.org>
Cc: stable@vger.kernel.org
Fixes: c59a2d14cd ("rust: num: add `shr` and `shl` methods to `Bounded`")
Link: https://patch.msgid.link/20260810-pramin-split-v2-2-65a00b3c7309@nvidia.com
Signed-off-by: Miguel Ojeda <ojeda@kernel.org>
This commit is contained in:
parent
119b598467
commit
223aa25aee
|
|
@ -485,6 +485,7 @@ pub fn cast<U>(self) -> Bounded<U, N>
|
|||
/// assert_eq!(v_shifted.get(), 0xff);
|
||||
/// ```
|
||||
pub fn shr<const SHIFT: u32, const RES: u32>(self) -> Bounded<T, RES> {
|
||||
const_assert!(SHIFT < T::BITS);
|
||||
const_assert!(RES + SHIFT >= N);
|
||||
|
||||
// SAFETY: We shift the value right by `SHIFT`, reducing the number of bits needed to
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user