[PATCH] rust: drm: ioctl: wrap `Device::from_raw` in an `unsafe` block

From: spidermana

Date: Wed Oct 07 2026 - 17:20:51 EST


`declare_drm_ioctls!` generates an `unsafe extern "C" fn` per ioctl. Inside
it, four unsafe operations are performed, while the call to `Device::from_raw()` relies on the enclosing
`unsafe fn` body instead.

Both forms are legal, but the kernel builds all Rust code with `-Dunsafe_op_in_unsafe_fn`, which asks for the explicit block.
The lint does not fire here because the macro is defined in the `kernel` crate and expanded in the
driver crates, and rustc suppresses lints for code coming from another crate's macro.

The patch is to wrap the call in an unsafe block, keeping the existing SAFETY comment. No functional change.

Signed-off-by: spidermana <xuyiwen14@xxxxxxxxx>
---
rust/kernel/drm/ioctl.rs | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/rust/kernel/drm/ioctl.rs b/rust/kernel/drm/ioctl.rs
index 64af9eacc306..5a2e2f4f0e91 100644
--- a/rust/kernel/drm/ioctl.rs
+++ b/rust/kernel/drm/ioctl.rs
@@ -152,7 +152,7 @@ macro_rules! declare_drm_ioctls {
// dev/file match the current driver these ioctls are being declared
// for, and it's not clear how to enforce this within the type system.
let dev: &$crate::drm::device::Device<_, $crate::drm::Ioctl> =
- $crate::drm::device::Device::from_raw(raw_dev);
+ unsafe { $crate::drm::device::Device::from_raw(raw_dev) };

// Type-inference anchor: the closure is never called but ties `dev`'s
// type to `$func`'s first parameter, which the compiler cannot infer
--
2.43.0