[PATCH] binder: replace unsafe NewAllocation transmute with field move

From: Thorsten Blum

Date: Thu Oct 08 2026 - 05:42:22 EST


NewAllocation does not implement Drop and success() can return its
Allocation field directly. Also remove the now-unused transparent
representation.

Signed-off-by: Thorsten Blum <blum@xxxxxxxxxx>
---
drivers/android/binder/allocation.rs | 10 +++-------
1 file changed, 3 insertions(+), 7 deletions(-)

diff --git a/drivers/android/binder/allocation.rs b/drivers/android/binder/allocation.rs
index 165cb797eb1e..be405f2596ae 100644
--- a/drivers/android/binder/allocation.rs
+++ b/drivers/android/binder/allocation.rs
@@ -298,17 +298,13 @@ fn drop(&mut self) {
/// A wrapper around `Allocation` that is being created.
///
/// If the allocation is destroyed while wrapped in this wrapper, then the allocation will be
-/// considered to be part of a failed transaction. Successful transactions avoid that by calling
-/// `success`, which skips the destructor.
-#[repr(transparent)]
+/// considered to be part of a failed transaction. Successful transactions call `success` and
+/// store the returned `Allocation` in the new transaction.
pub(crate) struct NewAllocation(pub(crate) Allocation);

impl NewAllocation {
pub(crate) fn success(self) -> Allocation {
- // This skips the destructor.
- //
- // SAFETY: This type is `#[repr(transparent)]`, so the layout matches.
- unsafe { core::mem::transmute(self) }
+ self.0
}
}