Re: [PATCH v2] drm/tyr: safely write GpuInfo to userspace

From: Gary Guo

Date: Fri Sep 25 2026 - 06:29:31 EST


On Fri Sep 25, 2026 at 8:56 AM BST, Alice Ryhl wrote:
> On Thu, Sep 24, 2026 at 7:22 PM Deborah Brouwer
> <deborah.brouwer@xxxxxxxxxxxxx> wrote:
>>
>> Tyr creates the struct drm_panthor_gpu_info from the Panthor UAPI
>> bindings. It initializes this struct by querying the gpu and then writes
>> the struct into userspace memory faithfully byte-by-byte.
>>
>> Currently, the struct drm_panthor_gpu_info does not have any implicit
>> padding, but if implicit padding were added in the future Rust does not
>> guarantee that it would be initialized. Then when Tyr writes the struct
>> back to userspace it could expose uninitialized kernel memory.
>>
>> Tyr implements the unsafe trait AsBytes for GpuInfo whereby the developer
>> guarantees that struct drm_panthor_gpu_info does not include implicit
>> padding, pointers, or interior mutability. This allows Tyr to safely copy
>> the struct into userspace memory. However, relying on the unsafe trait
>> AsBytes is fragile because if the Panthor UAPI changes, the SAFETY
>> guarantees may no longer be accurate.
>>
>> Instead, use the derive macro `zerocopy_derive::most_traits` for struct
>> drm_panthor_gpu_info. This macro will attempt to implement the zerocopy
>> traits for struct drm_panthor_gpu_info. If the Panthor UAPI changes so
>> that the traits IntoBytes or Immutable can no longer be implemented, Tyr
>> will no longer compile.
>>
>> Signed-off-by: Deborah Brouwer <deborah.brouwer@xxxxxxxxxxxxx>
>
> So this looks good to me
>
> Reviewed-by: Alice Ryhl <aliceryhl@xxxxxxxxxx>
>
> but needs Miguel's ok since it modifies the Makefile. And I imagine he
> may ask the commit to be split into two.

FWIW I do think this should be two commits, one making Make changes and apply to
both uapi and bindings, and the second adding the Tyr-specific parts.

Best,
Gary