[PATCH 3/4] rust: list: document safety of List::remove
From: Cian McGuire
Date: Fri Jul 24 2026 - 17:57:49 EST
The call to `ListLinks::fields(T::view_links(item))` in `List::remove`
had its SAFETY comment left as "TODO.". This call chains two separate
safety requirements that need to be discharged together.
`view_links` requires its pointer argument to point at a valid value.
`item` is a `&T`, and Rust's reference guarantees mean it is always a
valid, non-dangling pointer to a live value of type `T`, so this is
satisfied without needing anything beyond ordinary reference validity
(`view_links`'s own doc comment notes it "need not be in an `Arc`", to
head off the assumption that anything more is required here).
`fields` requires its pointer argument to be dereferenceable. The
pointer returned by `view_links` is guaranteed dereferenceable by its
own documented guarantees: it is either the pointer from a preceding
`prepare_to_insert` call, which itself must point at a valid value, or
it points at a read-only `ListLinks` with null fields. Either way,
`fields`'s requirement is satisfied.
Suggested-by: Miguel Ojeda <ojeda@xxxxxxxxxx>
Link: https://github.com/Rust-for-Linux/linux/issues/351
Signed-off-by: Cian McGuire <cianmcguire167@xxxxxxxxx>
---
rust/kernel/list.rs | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/rust/kernel/list.rs b/rust/kernel/list.rs
index 406e3a028c55..22b497eb10c0 100644
--- a/rust/kernel/list.rs
+++ b/rust/kernel/list.rs
@@ -599,7 +599,12 @@ pub fn pop_front(&mut self) -> Option<ListArc<T, ID>> {
///
/// `item` must not be in a different linked list (with the same id).
pub unsafe fn remove(&mut self, item: &T) -> Option<ListArc<T, ID>> {
- // SAFETY: TODO.
+ // SAFETY: `item` is a `&T`, and Rust's reference guarantees mean it is always a valid,
+ // non-dangling pointer to a live value of type `T`, satisfying `view_links`'s safety
+ // requirement. The pointer `view_links` returns is guaranteed dereferenceable by its own
+ // documented guarantees: it's either the pointer from a preceding `prepare_to_insert`
+ // call, which itself must point at a valid value, or it points at a read-only
+ // `ListLinks` with null fields. Either way, `fields`'s safety requirement is satisfied.
let mut item = unsafe { ListLinks::fields(T::view_links(item)) };
// SAFETY: The user provided a reference, and reference are never dangling.
//
--
2.55.0