Re: [PATCH 02/12] rust: num: reject Bounded::shr overshifts at build time

From: Gary Guo

Date: Fri Aug 07 2026 - 15:15:38 EST


On Wed Aug 5, 2026 at 6:44 AM BST, Eliot Courtney wrote:
> Make `shr` reject shifts of at least the type's bit width at build
> time, instead of panicking or masking the shift amount at runtime.
>
> Signed-off-by: Eliot Courtney <ecourtney@xxxxxxxxxx>
> ---
> rust/kernel/num/bounded.rs | 1 +
> 1 file changed, 1 insertion(+)
>
> diff --git a/rust/kernel/num/bounded.rs b/rust/kernel/num/bounded.rs
> index dafe77782d79..f263107f001e 100644
> --- a/rust/kernel/num/bounded.rs
> +++ b/rust/kernel/num/bounded.rs
> @@ -485,6 +485,7 @@ pub fn cast<U>(self) -> Bounded<U, N>
> /// assert_eq!(v_shifted.get(), 0xff);
> /// ```
> pub fn shr<const SHIFT: u32, const RES: u32>(self) -> Bounded<T, RES> {
> + const { assert!(SHIFT < T::BITS) }

This should use const_assert!()

Best,
Gary

> const { assert!(RES + SHIFT >= N) }
>
> // SAFETY: We shift the value right by `SHIFT`, reducing the number of bits needed to