Re: [PATCH v2 1/5] rust: pci: convert IrqVectorRegistration to a lifetime-managed owning type
From: Danilo Krummrich
Date: Wed Aug 12 2026 - 15:58:11 EST
On Wed Aug 12, 2026 at 9:01 PM CEST, Gary Guo wrote:
> On Wed Aug 12, 2026 at 7:47 PM BST, Danilo Krummrich wrote:
>> On Wed Aug 12, 2026 at 8:11 PM CEST, Gary Guo wrote:
>>> Well, I'd expect some drivers want to do `.vector(v).expect()` rather than just
>>> propagating the error if `v` is a constant that is less than `min_vecs`..
>>
>> This is nothing we want drivers to do; this API is only ever called from a
>> fallible context anyway and propagating costs nothing, but on the other hand, if
>> the driver gets it wrong, we'd BUG() the whole kernel for no value.
>
> Well, if you ask for an interrupt and got one, you'd better got one! If the case
> is actually "we'd BUG() the kernel", then it probably should because something
> is catastrophically wrong. I'd even consider `unwrap_unchecked` to be valid
> there and in my view `BUG()` is less damaging then UB.
If the driver calls vector().expect() on an index that is actually out of
bounds, because someone made a mistake, e.g. because min_vecs changed and people
forgot to update the code, then nothing went "catastrophically wrong" to a point
that we need to BUG() the whole kernel.
> I don't like the fact that we propagate error code because we can. Propagating
> error comes with a cost: it's one extra control flow that developer needs to
> consider; more code is generated because the destructors that's currently
> available still needs to be executed; and the code will have 0% coverage because
> it'd never occur as
>
> /// `dev` has an allocation of `count` interrupt vectors
>
> is the type invariant of `IrqVectorRegistration`.
I do not disagree; those points are all valid, but I think it is a case by case
question.
For drivers and in an already fallible cold path, I don't see a lot of value in
compromising on robustness against human mistakes for those reasons.
Quite some drivers are poorly maintained and patches don't receive a lot of
review before they are thrown in; Rust has a chance to significantly compensate
the downsides of a monolithic kernel by increasing the robustness of this
weakest part.
If we encourage drivers to use accessors that potentially end up in BUG() for
cases where it doesn't provide significant value, we may also diminish the
potential for additional robustness.