Re: [PATCH v2] drm/tyr: safely write GpuInfo to userspace
From: Deborah Brouwer
Date: Fri Sep 25 2026 - 12:35:51 EST
On Fri, Sep 25, 2026 at 11:29:07AM +0100, Gary Guo wrote:
> On Fri Sep 25, 2026 at 8:56 AM BST, Alice Ryhl wrote:
> > On Thu, Sep 24, 2026 at 7:22 PM Deborah Brouwer
> > <deborah.brouwer@xxxxxxxxxxxxx> wrote:
> >>
> >> Tyr creates the struct drm_panthor_gpu_info from the Panthor UAPI
> >> bindings. It initializes this struct by querying the gpu and then writes
> >> the struct into userspace memory faithfully byte-by-byte.
> >>
> >> Currently, the struct drm_panthor_gpu_info does not have any implicit
> >> padding, but if implicit padding were added in the future Rust does not
> >> guarantee that it would be initialized. Then when Tyr writes the struct
> >> back to userspace it could expose uninitialized kernel memory.
> >>
> >> Tyr implements the unsafe trait AsBytes for GpuInfo whereby the developer
> >> guarantees that struct drm_panthor_gpu_info does not include implicit
> >> padding, pointers, or interior mutability. This allows Tyr to safely copy
> >> the struct into userspace memory. However, relying on the unsafe trait
> >> AsBytes is fragile because if the Panthor UAPI changes, the SAFETY
> >> guarantees may no longer be accurate.
> >>
> >> Instead, use the derive macro `zerocopy_derive::most_traits` for struct
> >> drm_panthor_gpu_info. This macro will attempt to implement the zerocopy
> >> traits for struct drm_panthor_gpu_info. If the Panthor UAPI changes so
> >> that the traits IntoBytes or Immutable can no longer be implemented, Tyr
> >> will no longer compile.
> >>
> >> Signed-off-by: Deborah Brouwer <deborah.brouwer@xxxxxxxxxxxxx>
> >
> > So this looks good to me
> >
> > Reviewed-by: Alice Ryhl <aliceryhl@xxxxxxxxxx>
> >
> > but needs Miguel's ok since it modifies the Makefile. And I imagine he
> > may ask the commit to be split into two.
>
> FWIW I do think this should be two commits, one making Make changes and apply to
> both uapi and bindings, and the second adding the Tyr-specific parts.
I'll split the commit and send a v3.
>
> Best,
> Gary
>
>