[PATCH v6 00/10] rust: add conversion derives and exhaustive From support
From: Kaiqi Guo
Date: Tue Sep 29 2026 - 10:02:18 EST
Nova register enums need conversions to and from integer fields. This
series adds Into and TryFrom derives and a shared convert helper, then
adds From for enums that cover every possible input value. Two Nova
register enums use the derives without changing their conversion results
or error types.
This continues Jesung Yang's work. The first five patches preserve his
authorship and implementation from the unpublished tryfrom-into-macro.v6
branch [1], rebased onto rust-next. Jesung has not formally posted this
v6 series. The remaining five patches fix test and name-resolution issues,
add exhaustive conversions, and exercise them in Nova. The last public
submission I found is v5 [2]; the v6 branch was announced in March [3].
The v6 numbering here follows that public submission history.
Alexandre requested an infallible Bounded-to-enum conversion when the enum
covers the entire field [4], referring to bounded_enum!'s compile-time
exhaustiveness check [5]. This version adds:
#[derive(kernel::macros::From, kernel::macros::Into)]
#[convert(Bounded<u8, 2>)]
enum Mode {
A = 0,
B = 1,
C = 2,
D = 3,
}
The direction-specific spelling is #[derive(From)] with #[from(...)].
>From also supplies the standard blanket TryFrom with Error = Infallible;
an explicit TryFrom derive for the same input would conflict with it.
The exhaustiveness proof reuses the existing per-discriminant range
assertions and Rust's rejection of duplicate discriminants. It checks
that the number of distinct variants equals the input domain size,
comparing spans to avoid overflowing a full-width cardinality. The
generated function compares all but the final variant, then returns that
variant. Missing values, gaps, and out-of-range discriminants fail at
compile time even without a call site. No panic or unsafe path is needed.
This count-based proof is a new implementation choice, rather than the
MAX.. match pattern suggested in the thread. Review of this choice and
the From/from spelling would be welcome. No new conversion trait or
Bounded abstraction is introduced.
Changes since the public v5:
- Preserve Jesung's shared convert helper and replacement of from_expr
with per-variant Bounded::new const-generic constructors.
- Preserve his separate private Into and TryFrom doctest patches.
- Rebase onto d266640c6c76, retaining the new ForLt/CovariantForLt macros.
- Correct repr(C) negative examples that still used structs, and make
the negative unsigned Bounded tests exercise conversion overflow.
- Add From/from and compile-pass/fail tests for exhaustive conversions.
- Reject generic arguments on primitive helper types and qualify generated
Result and Bounded backing-type names against local aliases.
- Migrate Architecture to TryFrom/Into and FalconCoreRevSubversion to
From/Into, preserving EINVAL and Infallible respectively.
Two earlier API questions remain deliberately visible for review:
- The absence of an explicit integer repr still defaults to isize.
- Helper arguments still override the repr-derived conversion type;
they do not add an extra implementation for that repr type.
These retain Jesung's v6 choices. TryFrom also retains Error/EINVAL;
context-specific errors remain the caller's responsibility. This series
does not change Chipset's ENODEV conversion or add a configurable error
API. Bounded constructor support is unchanged (up to 64-bit and pointer
width backing integers); primitive u128/i128 domains are checked too.
Validation on Debian arm64, Rust 1.85.1, LLVM 19.1.7, bindgen 0.71.1:
- Rust and drivers/gpu/nova-core.o builds passed.
- rusttest: 128 doctests passed, 4 existing examples ignored.
- rustfmtcheck, CLIPPY=1 builds, and rustdoc passed.
- rust/.kunitconfig under arm64 QEMU: 360 tests passed.
- Exhaustive before/after comparison of the actual Nova declarations:
Architecture 64/64 inputs identical (6 successes, 58 EINVAL), and
FalconCoreRevSubversion 4/4 identical, including round trips and the
Infallible error type.
- Separate negative-test probes checked the expected diagnostic for
missing values, gaps, overflow, and duplicate discriminants.
No NVIDIA hardware testing was performed. checkpatch reports no errors;
the preserved original patches retain a new-file MAINTAINERS reminder
and one 120-column doctest line warning. The five follow-up patches have
no checkpatch warnings. Previous review/test tags dropped by Jesung are
not restored, and no new review, test, or ack tags are claimed.
Base: rust-next d266640c6c760c9bc215bf5a3ece122ca488b6f5
[1] https://github.com/J3m3/linux/tree/2ea456bd5f26bd66c766b462a7d606d9842c208a
[2] https://lore.kernel.org/rust-for-linux/20260129-try-from-into-macro-v5-0-dd011008118c@xxxxxxxxx/
[3] https://lore.kernel.org/rust-for-linux/DH939HK0611M.22A8T9BJ3NG8@xxxxxxxxx/
[4] https://lore.kernel.org/rust-for-linux/DHHJCEG8BC47.2VC6GLDRRZH1B@xxxxxxxxxx/
[5] https://lore.kernel.org/rust-for-linux/DHHK2OJ6O83V.2MZNHRQYK21EU@xxxxxxxxxx/
--
This series is based on Jesung's five commits below, followed by five
separate continuation commits.
Jesung Yang (5):
rust: macros: add derive macro for `Into`
rust: macros: add derive macro for `TryFrom`
rust: macros: add `convert` helper attribute
rust: macros: add private doctests for `Into` derive macro
rust: macros: add private doctests for `TryFrom` derive macro
Kaiqi Guo (5):
rust: macros: exercise the intended conversion doctest failures
rust: macros: derive From for exhaustive enum conversions
rust: macros: test exhaustive conversion derives
rust: macros: validate and qualify conversion helper types
gpu: nova-core: use conversion derives for two register enums
drivers/gpu/nova-core/falcon.rs | 19 +-
drivers/gpu/nova-core/gpu.rs | 22 +-
rust/macros/convert.rs | 2093 +++++++++++++++++++++++++++++++
rust/macros/lib.rs | 522 +++++++-
4 files changed, 2633 insertions(+), 23 deletions(-)
create mode 100644 rust/macros/convert.rs
base-commit: d266640c6c760c9bc215bf5a3ece122ca488b6f5