Re: [PATCH] drm/tyr: safely write GpuInfo to userspace

From: Alice Ryhl

Date: Thu Sep 24 2026 - 06:33:38 EST


On Thu, Sep 24, 2026 at 2:21 AM Deborah Brouwer
<deborah.brouwer@xxxxxxxxxxxxx> wrote:
>
> Tyr creates the struct drm_panthor_gpu_info from the Panthor UAPI
> bindings. It initializes this struct by querying the gpu and then writes
> the struct into userspace memory faithfully byte-by-byte.
>
> Currently, the struct drm_panthor_gpu_info does not have any implicit
> padding, but if implicit padding were added in the future Rust does not
> guarantee that it would be initialized. Then when Tyr writes the struct
> back to userspace it could expose uninitialized kernel memory.
>
> Tyr implements the unsafe trait AsBytes for GpuInfo whereby the developer
> guarantees that struct drm_panthor_gpu_info does not include implicit
> padding, pointers, or interior mutability. This allows Tyr to safely copy
> the struct into userspace memory. However, relying on the unsafe trait
> AsBytes is fragile because if the Panthor UAPI changes, the SAFETY
> guarantees may no longer be accurate.
>
> Instead, use the macros provided by the zerocopy crate to safely derive
> the traits IntoBytes and Immutable for struct drm_panthor_gpu_info. This
> will cause a compile error if the Panthor UAPI changes in a way that the
> traits IntoBytes or Immutable can no longer be implemented.
>
> Signed-off-by: Deborah Brouwer <deborah.brouwer@xxxxxxxxxxxxx>

I checked it myself and per-type declarations are indeed needed. We
can't use most_traits for everything yet.

> diff --git a/rust/bindgen_parameters b/rust/bindgen_parameters
> index 8402b0c93545..65d913181eec 100644
> --- a/rust/bindgen_parameters
> +++ b/rust/bindgen_parameters
> @@ -71,3 +71,7 @@
> # Structs should implement `Zeroable` when all of their fields do.
> --with-derive-custom-struct .*=MaybeZeroable
> --with-derive-custom-union .*=MaybeZeroable
> +
> +# `drm_panthor_gpu_info` is copied byte-for-byte to userspace.
> +--with-derive-custom-struct '^drm_panthor_gpu_info$'=IntoBytes
> +--with-derive-custom-struct '^drm_panthor_gpu_info$'=Immutable

For this case, I think we should just do:

--with-derive-custom-struct
'^drm_panthor_gpu_info$'=zerocopy_derive::most_traits

That will automatically give us these two traits.

Alice