linux/Documentation
Linus Torvalds b079329b86 Rust changes for v7.2
Toolchain and infrastructure:
 
  - Introduce support for the 'zerocopy' library [1][2]:
 
        Fast, safe, compile error. Pick two.
 
        Zerocopy makes zero-cost memory manipulation effortless. We write
        `unsafe` so you don't have to.
 
    It essentially provides derivable traits (e.g. 'FromBytes') and
    macros (e.g. 'transmute!') for safely converting between byte
    sequences and other types. Having such support allows us to remove
    some 'unsafe' code.
 
    It is among the most downloaded Rust crates and it is also used by
    the Rust compiler itself.
 
    It is licensed under "BSD-2-Clause OR Apache-2.0 OR MIT".
 
    The crates are imported essentially as-is (only +2/-3 lines needed
    to be adapted), plus SPDX identifiers. Upstream has since added the
    SPDX identifiers as well as one of the tweaks at my request, thus
    reducing our future diffs on updates -- I keep the details in one of
    our usual live lists [3].
 
    In total, it is about ~39k lines added, ~32k without counting
    'benches/' which are just for documentation purposes.
 
    The series includes a few Kbuild and rust-analyzer improvements and
    an example patch using it in Nova, removing one 'unsafe impl'.
 
    I checked that the codegen of an isolated example function (similar
    to the Nova patch on top) is essentially identical. It also turns out
    that (for that particular case) the 'zerocopy' version, even with
    'debug-assertions' enabled, has no remaining panics, unlike a few in
    the current code (since the compiler can prove the remaining
    'ub_checks' statically).
 
    So their "fast, safe" does indeed check out -- at least in that case.
 
    Link: https://github.com/google/zerocopy [1]
    Link: https://docs.rs/zerocopy [2]
    Link: https://github.com/Rust-for-Linux/linux/issues/1239 [3]
 
  - Support AutoFDO. This allows Rust code to be profiled and optimized
    based on the profile. Tested with Rust Binder: ~13% slower without
    AutoFDO in the binderAddInts benchmark (using an app-launch benchmark
    for the profile).
 
  - Support Software Tag-Based KASAN.
 
    In addition, fix KASAN Kconfig by requiring Clang.
 
  - Add Kconfig options for each existing Rust KUnit test suite, such as
    'CONFIG_RUST_BITMAP_KUNIT_TEST'. They are placed within a new menu,
    'CONFIG_RUST_KUNIT_TESTS', in the new 'rust/kernel/Kconfig.test'
    file.
 
  - Support the upcoming Rust 1.98.0 release (expected 2026-08-20): lint
    cleanups and an unstable flag rename.
 
  - Disable 'rustdoc' documentation inlining for all prelude items, which
    bloats the generated documentation.
 
  - Ignore (in Git) and clean (in Kbuild) the (rarely) 'rustc'-generated
    '*.long-type-*.txt' files.
 
 'kernel' crate:
 
  - Add new 'bitfield' module with the 'bitfield!' macro (extracted from
    the existing 'register!' one), which declares integer types that are
    split into distinct bit fields of arbitrary length.
 
    Each field is a 'Bounded' of the appropriate bit width (ensuring
    values are properly validated and avoiding implicit data loss) and
    gets several generated getters and setters (infallible, 'const' and
    fallible) as well as associated constants ('_MASK', '_SHIFT' and
    '_RANGE'). It also supports fields that can be converted from/to
    custom types, either fallibly ('?=>') or infallibly ('=>').
 
    For instance:
 
        bitfield! {
            struct Rgb(u16) {
                15:11 blue;
                10:5 green;
                4:0 red;
            }
        }
 
        // Compile-time checks.
        let color = Rgb::zeroed().with_const_green::<0x1f>();
 
        assert_eq!(color.green(), 0x1f);
        assert_eq!(color.into_raw(), 0x1f << Rgb::GREEN_SHIFT);
 
    Add as well documentation and a test suite for it, as usual; and
    update the 'register!' macro to use it.
 
    It will be maintained by Alexandre Courbot (with Yury Norov as
    reviewer) under a new 'MAINTAINERS' entry: 'RUST [BITFIELD]'.
 
  - 'ptr' module: rework index projection syntax into keyworded syntax
    and introduce panicking variant.
 
    The keyword syntax ('build:', 'try:', 'panic:') is more explicit and
    paves the way of perhaps adding more flavors in the future, e.g. an
    'unsafe' index projection.
 
    For instance, projections now look like this:
 
        fn f(p: *const [u8; 32]) -> Result {
            // Ok, within bounds, checked at build time.
            project!(p, [build: 1]);
 
            // Build error.
            project!(p, [build: 128]);
 
            // `OutOfBound` runtime error (convertible to `ERANGE`).
            project!(p, [try: 128]);
 
            // Runtime panic.
            project!(p, [panic: 128]);
 
            Ok(())
        }
 
    Update as well the users, which now look like e.g.
 
        // Pointer to the first entry of the GSP message queue.
        let data = project!(self.0.as_ptr(), .gspq.msgq.data[build: 0]);
 
  - 'build_assert' module: make the module the home of its macros instead
    of rendering them twice.
 
  - 'sync' module: add 'UniqueArc::as_ptr()' associated function.
 
  - 'alloc' module:
 
     + Fix the 'Vec::reserve()' doctest to properly account for the
       existing vector length in the capacity assertion.
 
     + Fix an incorrect operator in the 'Vec::extend_with()' 'SAFETY'
       comment; add a doc test demonstrating basic usage and the
       zero-length case.
 
  - Clean imports across several modules to follow the "kernel vertical"
    import style in order to minimize conflicts.
 
 'pin-init' crate:
 
  - User visible changes:
 
     + Do not generate 'non_snake_case' warnings for identifiers that are
       syntactically just users of a field name. This would allow all
       '#[allow(non_snake_case)]' in nova-core to be removed, which Gary
       will send to the nova tree next cycle.
 
     + Filter non-cfg attributes out properly in derived structs. This
       improves pin-init compatibility with other derive macros.
 
     + Insert projection types' where clause properly.
 
  - Other changes:
 
     + Bump MSRV to 1.82, plus associated cleanups.
 
     + Overhaul how init slots are projected. The new approach is easier
       to justify with safety comments.
 
     + Mark more functions as inline, which should help mitigate the
       super-long symbol name issue due to lack of inlining.
 
 rust-analyzer:
 
  - Support '--envs' for passing env vars for crates like 'zerocopy'.
 
 'MAINTAINERS':
 
  - Add the following reviewers to the 'RUST' entry:
 
     + Daniel Almeida
     + Tamir Duberstein
     + Alexandre Courbot
     + Onur Özkan
 
    They have been involved in the Rust for Linux project for about
    7 collective years and bring expertise across several domains, which
    will be very useful to have around in the future.
 
    Thanks everyone for stepping up!
 
 And some other fixes, cleanups and improvements.
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEEPjU5OPd5QIZ9jqqOGXyLc2htIW0FAmovBQsACgkQGXyLc2ht
 IW0BGA//WT/3qZTOE0yNtjG2/VAgbi6onNQeUf/NWkgo0HmPx0AUsKaedbWLOkTK
 FYTj0XOb7XlTV6ryuDsYfbQUm8vNGI8HEGAxWJmSThrY0dqBgnKTWWeYUCaG1OEp
 OBjf3i1gGS9A7WUWrBijjyeOui+dvm3wXBdKFREqVn7cRDjYUYUw75ZZsUxTigZf
 pA/tW5GEmrQw5NmuNB8bLeQacwwIwDSfnnkxE6d+FDAOngwyM7IM9ENLvy5cl2Ui
 yVUkEpXvA8nnvy4MXQ5toIUbDGMFKJBpIL1GeDgMc7DQtDOxNFeBnBe9hrpfQr2L
 XgeyWDs3+QD5WdVkjCPJEVS2gGpVDYIRUJRRHitGp+g+WDZsTA8FKvjjJjPnvHE8
 WSdmhB3/EP40vkLoKKHTb1/vizeJ3io+ku52fZLemTJESe1vqzc9sTlZFQ4zpp09
 /KCAwF+43XEPA1ETbLZQ0Wx7hTz0wjHIbF45hDGOGuvcjFepdFsFVKsHxDDXqkiB
 AqsdIR5IGPeVOLWDvWlRRrZvPQNGkxhf5zc+Ah0TfYfN4kyBuoUkdOpS0mdYVb1y
 nAULtyDkw3Ty8ZDVXgpl+o99kX7ajbgmIhOW6SrvKt43k9YQJ7A3NnaLCuoM3zOf
 wYzy/HNNMkal+8NZ67kT20BceuHlGAY3awIM7NbRAGGt3taMtwo=
 =Setk
 -----END PGP SIGNATURE-----

Merge tag 'rust-7.2' of gitolite.kernel.org:pub/scm/linux/kernel/git/ojeda/linux

Pull Rust updates from Miguel Ojeda:
 "This one is big due to the vendoring of the `zerocopy` library, which
  allows us to replace a bunch of `unsafe` code dealing with conversions
  between byte sequences and other types with safe alternatives. More
  details on that below (and in its merge commit).

  Toolchain and infrastructure:

   - Introduce support for the 'zerocopy' library [1][2]:

         Fast, safe, compile error. Pick two.

         Zerocopy makes zero-cost memory manipulation effortless. We write
         `unsafe` so you don't have to.

     It essentially provides derivable traits (e.g. 'FromBytes') and
     macros (e.g. 'transmute!') for safely converting between byte
     sequences and other types. Having such support allows us to remove
     some 'unsafe' code.

     It is among the most downloaded Rust crates and it is also used by
     the Rust compiler itself.

     It is licensed under "BSD-2-Clause OR Apache-2.0 OR MIT".

     The crates are imported essentially as-is (only +2/-3 lines needed
     to be adapted), plus SPDX identifiers. Upstream has since added the
     SPDX identifiers as well as one of the tweaks at my request, thus
     reducing our future diffs on updates -- I keep the details in one
     of our usual live lists [3].

     In total, it is about ~39k lines added, ~32k without counting
     'benches/' which are just for documentation purposes.

     The series includes a few Kbuild and rust-analyzer improvements and
     an example patch using it in Nova, removing one 'unsafe impl'.

     I checked that the codegen of an isolated example function (similar
     to the Nova patch on top) is essentially identical. It also turns
     out that (for that particular case) the 'zerocopy' version, even
     with 'debug-assertions' enabled, has no remaining panics, unlike a
     few in the current code (since the compiler can prove the remaining
     'ub_checks' statically).

     So their "fast, safe" does indeed check out -- at least in that
     case.

   - Support AutoFDO. This allows Rust code to be profiled and optimized
     based on the profile. Tested with Rust Binder: ~13% slower without
     AutoFDO in the binderAddInts benchmark (using an app-launch
     benchmark for the profile).

   - Support Software Tag-Based KASAN.

     In addition, fix KASAN Kconfig by requiring Clang.

   - Add Kconfig options for each existing Rust KUnit test suite, such
     as 'CONFIG_RUST_BITMAP_KUNIT_TEST'.

     They are placed within a new menu, 'CONFIG_RUST_KUNIT_TESTS', in
     the new 'rust/kernel/Kconfig.test' file.

   - Support the upcoming Rust 1.98.0 release (expected 2026-08-20):
     lint cleanups and an unstable flag rename.

   - Disable 'rustdoc' documentation inlining for all prelude items,
     which bloats the generated documentation.

   - Ignore (in Git) and clean (in Kbuild) the (rarely) 'rustc'-generated
     '*.long-type-*.txt' files.

  'kernel' crate:

   - Add new 'bitfield' module with the 'bitfield!' macro (extracted
     from the existing 'register!' one), which declares integer types
     that are split into distinct bit fields of arbitrary length.

     Each field is a 'Bounded' of the appropriate bit width (ensuring
     values are properly validated and avoiding implicit data loss) and
     gets several generated getters and setters (infallible, 'const' and
     fallible) as well as associated constants ('_MASK', '_SHIFT' and
     '_RANGE'). It also supports fields that can be converted from/to
     custom types, either fallibly ('?=>') or infallibly ('=>').

     For instance:

         bitfield! {
             struct Rgb(u16) {
                 15:11 blue;
                 10:5 green;
                 4:0 red;
             }
         }

         // Compile-time checks.
         let color = Rgb::zeroed().with_const_green::<0x1f>();

         assert_eq!(color.green(), 0x1f);
         assert_eq!(color.into_raw(), 0x1f << Rgb::GREEN_SHIFT);

     Add as well documentation and a test suite for it, as usual; and
     update the 'register!' macro to use it.

     It will be maintained by Alexandre Courbot (with Yury Norov as
     reviewer) under a new 'MAINTAINERS' entry: 'RUST [BITFIELD]'.

   - 'ptr' module: rework index projection syntax into keyworded syntax
     and introduce panicking variant.

     The keyword syntax ('build:', 'try:', 'panic:') is more explicit
     and paves the way of perhaps adding more flavors in the future,
     e.g. an 'unsafe' index projection.

     For instance, projections now look like this:

         fn f(p: *const [u8; 32]) -> Result {
             // Ok, within bounds, checked at build time.
             project!(p, [build: 1]);

             // Build error.
             project!(p, [build: 128]);

             // `OutOfBound` runtime error (convertible to `ERANGE`).
             project!(p, [try: 128]);

             // Runtime panic.
             project!(p, [panic: 128]);

             Ok(())
         }

     Update as well the users, which now look like e.g.

         // Pointer to the first entry of the GSP message queue.
         let data = project!(self.0.as_ptr(), .gspq.msgq.data[build: 0]);

   - 'build_assert' module: make the module the home of its macros
     instead of rendering them twice.

   - 'sync' module: add 'UniqueArc::as_ptr()' associated function.

   - 'alloc' module:

       - Fix the 'Vec::reserve()' doctest to properly account for the
         existing vector length in the capacity assertion.

       - Fix an incorrect operator in the 'Vec::extend_with()' 'SAFETY'
         comment; add a doc test demonstrating basic usage and the
         zero-length case.

   - Clean imports across several modules to follow the "kernel
     vertical" import style in order to minimize conflicts.

  'pin-init' crate:

   - User visible changes:

       - Do not generate 'non_snake_case' warnings for identifiers that
         are syntactically just users of a field name. This would allow
         all '#[allow(non_snake_case)]' in nova-core to be removed,
         which Gary will send to the nova tree next cycle.

       - Filter non-cfg attributes out properly in derived structs. This
         improves pin-init compatibility with other derive macros.

       - Insert projection types' where clause properly.

   - Other changes:

       - Bump MSRV to 1.82, plus associated cleanups.

       - Overhaul how init slots are projected. The new approach is
         easier to justify with safety comments.

       - Mark more functions as inline, which should help mitigate the
         super-long symbol name issue due to lack of inlining.

  rust-analyzer:

   - Support '--envs' for passing env vars for crates like 'zerocopy'.

  'MAINTAINERS':

   - Add the following reviewers to the 'RUST' entry:
       - Daniel Almeida
       - Tamir Duberstein
       - Alexandre Courbot
       - Onur Özkan

     They have been involved in the Rust for Linux project for about 7
     collective years and bring expertise across several domains, which
     will be very useful to have around in the future.

     Thanks everyone for stepping up!

  And some other fixes, cleanups and improvements"

Link: https://github.com/google/zerocopy [1]
Link: https://docs.rs/zerocopy [2]
Link: https://github.com/Rust-for-Linux/linux/issues/1239 [3]

* tag 'rust-7.2' of gitolite.kernel.org:pub/scm/linux/kernel/git/ojeda/linux: (86 commits)
  MAINTAINERS: add Onur Özkan as Rust reviewer
  MAINTAINERS: add Alexandre Courbot as Rust reviewer
  MAINTAINERS: add Tamir Duberstein as Rust reviewer
  MAINTAINERS: add Daniel Almeida as Rust reviewer
  kbuild: rust: clean `zerocopy-derive` in `mrproper`
  rust: make `build_assert` module the home of related macros
  rust: str: clean unused import for Rust >= 1.98
  rust: str: use the "kernel vertical" imports style
  rust: aref: use the "kernel vertical" imports style
  rust: page: use the "kernel vertical" imports style
  gpu: nova-core: firmware: parse `FalconUCodeDescV2` via `zerocopy`
  rust: prelude: add `zerocopy{,_derive}::FromBytes`
  rust: zerocopy-derive: enable support in kbuild
  rust: zerocopy-derive: add `README.md`
  rust: zerocopy-derive: avoid generating non-ASCII identifiers
  rust: zerocopy-derive: add SPDX License Identifiers
  rust: zerocopy-derive: import crate
  rust: zerocopy: enable support in kbuild
  rust: zerocopy: add `README.md`
  rust: zerocopy: remove float `Display` support
  ...
2026-06-15 09:25:48 +05:30
..
ABI selinux: prune /sys/fs/selinux/user 2026-05-05 15:27:44 -04:00
accel
accounting
admin-guide RCU pull request for v7.2 2026-06-15 09:16:00 +05:30
arch Documentation/arch/x86: Hide clearcpuid= 2026-05-26 05:37:20 +02:00
block Documentation: ublk: address review comments for SHMEM_ZC docs 2026-04-09 19:10:44 -06:00
bpf docs/bpf: add missing fsession attach type to docs 2026-04-12 12:42:38 -07:00
cdrom
core-api mm.git review status for linus..mm-stable 2026-04-15 12:59:16 -07:00
cpu-freq
crypto crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks 2026-05-20 16:36:45 -07:00
dev-tools kconfig: Remove the architecture specific config for Propeller 2026-06-05 21:12:08 -07:00
devicetree dt-bindings: i2c: mux-gpio: name correct maintainer 2026-06-12 16:58:38 +02:00
doc-guide docs: kernel-doc.rst: document private: scope propagation 2026-03-22 15:02:29 -06:00
driver-api We've finally gotten rid of the struct clk_ops::round_rate() code after months 2026-04-21 08:33:26 -07:00
edac
fault-injection
fb
features RISC-V updates for v7.1 2026-04-24 10:00:37 -07:00
filesystems dentry memory safety stuff 2026-06-15 04:15:31 +05:30
firmware_class
firmware-guide
fpga
gpu DRM Rust changes for v7.1-rc1 2026-04-01 07:32:05 +10:00
hid Docs: hid: intel-ish-hid: make long URL usable 2026-04-09 08:40:41 -06:00
hwmon docs: hwmon: sy7636a: fix temperature sysfs attribute name 2026-05-14 15:48:57 -07:00
i2c
iio Docs: iio: ad7191 Correct clock configuration 2026-03-27 07:31:19 +00:00
images
infiniband RDMA/hfi1: Remove opa_vnic 2026-03-10 07:51:30 -04:00
input
kbuild kbuild: document generation of offset header files 2026-04-29 15:22:22 -07:00
kernel-hacking
leds
litmus-tests
livepatch
locking
maintainer
mhi
misc-devices
mm mm.git review status for linus..mm-stable 2026-04-15 12:59:16 -07:00
netlabel
netlink net/handshake: Pass negative errno through handshake_complete() 2026-05-28 13:35:31 +02:00
networking ethernet: 3c509: Update documentation to match MAINTAINERS 2026-05-21 08:28:56 -07:00
nvdimm
nvme
PCI pci-v7.1-changes 2026-04-15 14:41:21 -07:00
pcmcia
peci
power
process Kbuild / Kconfig changes for 7.2 2026-06-15 05:01:15 +05:30
RCU rcu-tasks: Document that RCU Tasks Trace grace periods now imply RCU grace periods 2026-03-30 15:48:14 -04:00
rust Documentation: rust: testing: add Kconfig guidance 2026-06-08 02:30:33 +02:00
scheduler sched_ext: Changes for v7.1 2026-04-15 10:54:24 -07:00
scsi
security ipe/stable-7.1 PR 20260413 2026-04-15 15:19:45 -07:00
sound ALSA: doc: cs35l56: Update path to HDA driver source 2026-05-15 08:53:34 +02:00
sphinx docs: pt_BR: Add initial Portuguese translation 2026-02-23 14:16:07 -07:00
sphinx-includes
sphinx-static docs: allow long links to wrap per character to prevent page overflow 2026-03-25 13:22:02 -06:00
spi
staging net: remove ax25 and amateur radio (hamradio) subsystem 2026-04-23 10:24:02 -07:00
sunrpc/xdr Documentation: Add the RPC language description of NLM version 4 2026-03-29 21:25:09 -04:00
target
tee
timers
tools RTLA patches for v7.1: 2026-04-15 17:48:24 -07:00
trace buffer: Remove submit_bh() 2026-06-04 10:28:10 +02:00
translations kbuild: Bump minimum version of LLVM for building the kernel to 17.0.1 2026-05-27 15:18:53 -07:00
usb
userspace-api rseq: Reenable performance optimizations conditionally 2026-05-06 17:40:27 +02:00
virt Documentation: kvm: update links in the references section of AMD Memory Encryption 2026-05-12 22:17:42 +02:00
w1
watchdog
wmi platform/wmi: Replace .no_notify_data with .min_event_size 2026-04-13 14:11:27 +03:00
.gitignore
.renames.txt Revert "drivers: net: 3com: 3c509: Remove this driver" 2026-05-21 08:28:56 -07:00
atomic_bitops.txt
atomic_t.txt
Changes
CodingStyle
conf.py docs: use logo.svg as favicon 2026-03-22 15:27:43 -06:00
docutils.conf
index.rst
Kconfig
Makefile
memory-barriers.txt
SubmittingPatches
subsystem-apis.rst net: remove ISDN subsystem and Bluetooth CMTP 2026-04-23 10:24:02 -07:00