[PATCH v7 00/11] rust: add conversion derives and exhaustive From support
From: Kaiqi Guo
Date: Tue Sep 29 2026 - 20:28:11 EST
To: Jesung Yang <y.j3ms.n@xxxxxxxxx>,
Miguel Ojeda <ojeda@xxxxxxxxxx>,
Alexandre Courbot <acourbot@xxxxxxxxxx>,
Danilo Krummrich <dakr@xxxxxxxxxx>
Cc: rust-for-linux@xxxxxxxxxxxxxxx,
nova-gpu@xxxxxxxxxxxxxxx,
dri-devel@xxxxxxxxxxxxxxxxxxxxx,
linux-kernel@xxxxxxxxxxxxxxx,
Boqun Feng <boqun@xxxxxxxxxx>,
Gary Guo <gary@xxxxxxxxxxx>,
bjorn3_gh@xxxxxxxxxxxxxx,
Benno Lossin <lossin@xxxxxxxxxx>,
Andreas Hindborg <a.hindborg@xxxxxxxxxx>,
Alice Ryhl <aliceryhl@xxxxxxxxxx>,
Trevor Gross <tmgross@xxxxxxxxx>,
Daniel Almeida <daniel.almeida@xxxxxxxxxxxxx>,
Tamir Duberstein <tamird@xxxxxxxxxx>,
work@xxxxxxxxxxxxx,
David Airlie <airlied@xxxxxxxxx>,
Simona Vetter <simona@xxxxxxxx>,
Charalampos Mitrodimas <charmitro@xxxxxxxxxx>,
Shivam Kalra <shivamklr@xxxxxxx>
Nova register enums need conversions to and from integer fields. This
series adds Into and TryFrom derives and a shared convert helper, then
adds From for enums that cover every possible input value. Two Nova
register enums use the derives without changing their conversion results
or error types.
This continues Jesung Yang's work. The first five patches preserve his
authorship and implementation from the unpublished tryfrom-into-macro.v6
branch [1], rebased onto rust-next. Jesung's last public submission was
v5 [2]; the v6 branch was announced in March [3]. The remaining six
patches fix tests and name resolution, add exhaustive conversions, use
them in Nova, and address findings received during v6 review.
Alexandre requested an infallible Bounded-to-enum conversion when the enum
covers the entire field [4], referring to bounded_enum!'s compile-time
exhaustiveness check [5]. This version adds:
#[derive(kernel::macros::From, kernel::macros::Into)]
#[convert(Bounded<u8, 2>)]
enum Mode {
A = 0,
B = 1,
C = 2,
D = 3,
}
The direction-specific spelling is #[derive(From)] with #[from(...)].
>From also supplies the standard blanket TryFrom with Error = Infallible;
an explicit TryFrom derive for the same input would conflict with it.
The exhaustiveness proof reuses the existing per-discriminant range
assertions and Rust's rejection of duplicate discriminants. It checks
that the number of distinct variants equals the input domain size,
comparing spans to avoid overflowing a full-width cardinality. The
generated function compares all but the final variant, then returns that
variant. Missing values, gaps, and out-of-range discriminants fail at
compile time even without a call site. No panic or unsafe path is needed.
This count-based proof is a new implementation choice, rather than the
MAX.. match pattern suggested in the thread. Review of this choice and
the From/from spelling would be welcome. No new conversion trait or
Bounded abstraction is introduced.
Changes since v6:
- Format the new conversion doctest imports vertically.
- Avoid unused_variables and dead_code warnings for empty TryFrom enums.
- Allow generated fits() comparisons at 128-bit boundaries, where rustc
identifies a comparison against the type maximum as always true.
- Consume nested repr arguments such as #[repr(u8, align(4))], preserving
rustc's own validation of the attribute.
- Reject bool as a Bounded backing type in helper arguments.
- Add compile-pass and compile-fail regression doctests for these cases.
Two earlier API questions remain visible for review:
- The absence of an explicit integer repr still defaults to isize.
- Helper arguments still override the repr-derived conversion type;
they do not add an extra implementation for that repr type.
These retain Jesung's v6 choices. TryFrom also retains Error/EINVAL;
context-specific errors remain the caller's responsibility. This series
does not change Chipset's ENODEV conversion or add a configurable error
API. Bounded constructor support is unchanged (up to 64-bit and pointer
width backing integers); primitive u128/i128 domains are checked too.
Validation:
- The v6 code passed Rust and Nova builds, rusttest, rustfmtcheck,
CLIPPY=1 builds, rustdoc, and arm64 QEMU KUnit (360 tests).
- The v7 changes passed direct proc-macro compilation with rustc 1.97,
rustfmt --check, git diff --check, and checkpatch for patch 11.
- The preserved Jesung patches retain two existing checkpatch warnings: a
MAINTAINERS reminder on the new file and one long doctest attribute line.
- Direct -D warnings probes compiled and ran empty-enum TryFrom, u128
boundary conversion, and #[repr(u8, align(4))] Into; an invalid
Bounded<bool, 1> helper was rejected with the intended diagnostic.
- Full v7 kernel rusttest/rustfmtcheck could not run on this macOS host:
GNU Make 3.81 is installed, while the kernel requires version 4.0.
No NVIDIA hardware testing was performed. Previous review, test, or ack
tags are not claimed.
[1] https://github.com/J3m3/linux/tree/2ea456bd5f26bd66c766b462a7d606d9842c208a
[2] https://lore.kernel.org/rust-for-linux/20260129-try-from-into-macro-v5-0-dd011008118c@xxxxxxxxx/
[3] https://lore.kernel.org/rust-for-linux/DH939HK0611M.22A8T9BJ3NG8@xxxxxxxxx/
[4] https://lore.kernel.org/rust-for-linux/DHHJCEG8BC47.2VC6GLDRRZH1B@xxxxxxxxxx/
[5] https://lore.kernel.org/rust-for-linux/DHHK2OJ6O83V.2MZNHRQYK21EU@xxxxxxxxxx/
Jesung Yang (5):
rust: macros: add derive macro for `Into`
rust: macros: add derive macro for `TryFrom`
rust: macros: add `convert` helper attribute
rust: macros: add private doctests for `Into` derive macro
rust: macros: add private doctests for `TryFrom` derive macro
Kaiqi Guo (6):
rust: macros: exercise the intended conversion doctest failures
rust: macros: derive From for exhaustive enum conversions
rust: macros: test exhaustive conversion derives
rust: macros: validate and qualify conversion helper types
gpu: nova-core: use conversion derives for two register enums
rust: macros: address conversion derive review findings
drivers/gpu/nova-core/falcon.rs | 19 +-
drivers/gpu/nova-core/gpu.rs | 22 +-
rust/macros/convert.rs | 2180 +++++++++++++++++++++++++++++++
rust/macros/lib.rs | 522 +++++++-
4 files changed, 2720 insertions(+), 23 deletions(-)
create mode 100644 rust/macros/convert.rs
base-commit: d266640c6c760c9bc215bf5a3ece122ca488b6f5
--
2.50.1 (Apple Git-155)