[PATCH] rust: num: seal Integer

From: Younes Akhouayri via B4 Relay

Date: Fri Sep 04 2026 - 22:18:18 EST


From: Younes Akhouayri <git@xxxxxxxxx>

Bounded relies on Integer implementations to describe primitive integer
semantics correctly. In particular, it uses Integer::BITS and Signedness
to justify unchecked operations.

Integer is currently safe and externally implementable, so an
implementation can violate those assumptions and make safe Bounded
operations reach undefined behavior.

Seal Integer so only the primitive implementations provided by the
kernel crate can satisfy it.

Fixes: 01e345e82ec3 ("rust: num: add Bounded integer wrapping type")
Closes: https://lore.kernel.org/rust-for-linux/CANiq72mOfR33s4y+Ueivd5NrC5yre+Pcp57ZOBz0msw9A4AP1Q@xxxxxxxxxxxxxx/
Cc: stable@xxxxxxxxxxxxxxx
Suggested-by: Miguel Ojeda <ojeda@xxxxxxxxxx>
Signed-off-by: Younes Akhouayri <git@xxxxxxxxx>
---
rust/kernel/num.rs | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)

diff --git a/rust/kernel/num.rs b/rust/kernel/num.rs
index dbe848e30efe..de589792a77a 100644
--- a/rust/kernel/num.rs
+++ b/rust/kernel/num.rs
@@ -15,9 +15,14 @@ pub enum Unsigned {}
/// Designates signed primitive types.
pub enum Signed {}

+mod private {
+ pub trait Sealed {}
+}
+
/// Describes core properties of integer types.
pub trait Integer:
- Sized
+ private::Sealed
+ + Sized
+ Copy
+ Clone
+ PartialEq
@@ -56,6 +61,8 @@ pub trait Integer:
macro_rules! impl_integer {
($($type:ty: $signedness:ty), *) => {
$(
+ impl private::Sealed for $type {}
+
impl Integer for $type {
type Signedness = $signedness;


---
base-commit: e510334fbaeaa016ac76d80b4c5f47611c5f7860
change-id: 20260903-feature-rust-num-seal-integer-a4262df429c6

Best regards,
--
Younes Akhouayri <git@xxxxxxxxx>