[PATCH 03/20] rust: pin-init: internal: pin_data: rewrite fields that borrow others

From: Gary Guo

Date: Thu Oct 08 2026 - 08:28:29 EST


Fields that borrow other fields have lifetimes that are within the struct
and these are not part of the struct generics. Therefore, these fields need
to have their lifetime erased.

A naive implementation would be to replace their lifetimes with `'static`.
However, doing so is unsound for multiple reasons:
* Users may directly access such field with field access syntax, and get
exposed with wrong lifetime;
* Auto trait implementations will cause the struct to be implementing auto
traits when the type only implements the auto trait for specific
lifetime. This is similar to how specialization can be unsound if
specialized on lifetime.

Create a `Erase` type, which has `for<'a> fn(&'a ()) -> Foo<'a>` as generic
parameter. Internally, it uses a helper trait to resolve that to
`Foo<'static>`. The first issue is solved by not exposing any public
accessor on that type. The second issue is solved by add custom `Send` and
`Sync` implementations that requires `Send` to be implemented for all
lifetimes, thus closing the lifetime specialization hole. The actual
implementation is a bit more convoluted because it supports erasing
multiple lifetimes.

This is more or less a stable polyfill of the unstable `unsafe_binder`
feature, without `unsafe_binders`'s no drop glue requirement.

Signed-off-by: Gary Guo <gary@xxxxxxxxxxx>
---
rust/pin-init/internal/src/pin_data.rs | 16 +++++++
rust/pin-init/src/__internal.rs | 77 ++++++++++++++++++++++++++++++++++
2 files changed, 93 insertions(+)

diff --git a/rust/pin-init/internal/src/pin_data.rs b/rust/pin-init/internal/src/pin_data.rs
index cf6142cd656d..868701c9a986 100644
--- a/rust/pin-init/internal/src/pin_data.rs
+++ b/rust/pin-init/internal/src/pin_data.rs
@@ -417,6 +417,22 @@ fn generate_struct_def(info: &StructInfo) -> TokenStream {
ty,
} = &field.field;

+ let mut ty = ty.to_token_stream();
+
+ // Replace lifetime for self-referential fields.
+ if !field.captures.is_empty() {
+ // Build a chain `for<'a> fn(&'a ()) -> ... -> (Ty,)`. Such type will have a `EraseTy`
+ // implementation and thus may be used inside `Erased`.
+ ty = quote!((#ty,));
+
+ for borrow in field.captures.iter().rev() {
+ let lt = &borrow.lifetime;
+ ty = quote!(for<#lt> fn(&#lt()) -> #ty);
+ }
+
+ ty = quote!(::pin_init::__internal::Erase<#ty>);
+ };
+
quote! {
#(#attrs)* #vis #ident #colon_token #ty
}
diff --git a/rust/pin-init/src/__internal.rs b/rust/pin-init/src/__internal.rs
index cba53b8c3c94..80c5624d78c9 100644
--- a/rust/pin-init/src/__internal.rs
+++ b/rust/pin-init/src/__internal.rs
@@ -385,3 +385,80 @@ unsafe fn __init(self, _slot: *mut T) -> Result<(), ()> {
Err(())
}
}
+/// Polyfill of `FnOnce` trait to be able to reference output via associated type.
+pub trait FnOutput<Args> {
+ type Output;
+}
+
+macro_rules! impl_fn_output {
+ () => {};
+ ($ret:ident, $($arg:ident,)*) => {
+ impl<This, $ret, $($arg,)*> FnOutput<($($arg,)*)> for This
+ where
+ This: FnOnce($($arg,)*) -> $ret,
+ {
+ type Output = $ret;
+ }
+ impl_fn_output!($($arg,)*);
+ };
+}
+
+impl_fn_output!(A, B, C, D, E, F, G, H, I, J, K, L, M, N, O, P, Q, R, S, T, U,);
+
+/// Lifetime erasure facility.
+///
+/// Say we have `exists<'a, 'b> Foo<'a, 'b>` and we want to store it. There's no concrete
+/// lifetimes we can use, so we want to erase the lifetime.
+///
+/// Such erasure can be encoded as
+/// `Erased<for<'a> fn(&'a ()) -> for<'b> fn(&'b()) -> (Foo<'a, 'b>,)`.
+///
+/// This can be considered the stable version of Rust's `unsafe_binder` feature, without the
+/// no-drop-glue requirement.
+#[repr(transparent)]
+#[allow(private_bounds)]
+pub struct Erase<F: EraseLt>(F::Erased);
+
+/// Helper trait to resolve the erased lifetime.
+trait EraseLt {
+ type Erased;
+}
+
+impl<T> EraseLt for (T,) {
+ type Erased = T;
+}
+
+impl<T> EraseLt for T
+where
+ T: for<'a> FnOutput<(&'a (),), Output: EraseLt>,
+{
+ type Erased = <<T as FnOutput<(&'static (),)>>::Output as EraseLt>::Erased;
+}
+
+// The default `Send` and `Sync` are not sufficient, because one can use lifetime specialization to
+// implement `Send` or `Sync` for a concrete instance of lifetime. Use HRTB to ensure that the type
+// will only implement `Send` or `Sync` if it's implemented for *all* erased lifetimes.
+
+// SAFETY: Trivial, no lifetime to erase.
+unsafe impl<T: Send> Send for Erase<(T,)> {}
+
+// SAFETY: If we erased a lifetime, then the type needs to be `Send` for across *all* that
+// lifetimes.
+unsafe impl<F: EraseLt> Send for Erase<F>
+where
+ F: for<'a> FnOutput<(&'a (),), Output: EraseLt>,
+ for<'a> Erase<<F as FnOutput<(&'a (),)>>::Output>: Send,
+{
+}
+
+// SAFETY: Trivial, no lifetime to erase.
+unsafe impl<T: Sync> Sync for Erase<(T,)> {}
+
+// SAFETY: If we erased a lifetime, then the type needs to be `Send` for across *all* that
+// lifetimes.
+unsafe impl<F: EraseLt> Sync for Erase<F>
+where
+ F: for<'a> FnOutput<(&'a (),), Output: EraseLt>,
+ for<'a> Erase<<F as FnOutput<(&'a (),)>>::Output>: Sync,
+{
+}

--
2.54.0