rust/kernel/safety.rs
Source file repositories/reference/linux-study-clean/rust/kernel/safety.rs
File Facts
- System
- Linux kernel
- Corpus path
rust/kernel/safety.rs- Extension
.rs- Size
- 1560 bytes
- Lines
- 54
- Domain
- Rust Kernel Layer
- Bucket
- Rust API Membrane
- Inferred role
- Rust Kernel Layer: implementation source
- Status
- source implementation candidate
Why This File Exists
Rust-side wrappers and abstractions around kernel C APIs, ownership contracts, allocation, synchronization, and module integration.
- Rust-side wrappers and abstractions around kernel C APIs, ownership contracts, allocation, synchronization, and module integration.
- Defines or uses C structs; map object ownership, embedded links, reference counts, and lock ownership.
Dependency Surface
- No C-style include directives detected by the generator.
Detected Declarations
- No top-level syscall, struct, function, initcall, or export declaration detected by the generator.
Annotated Snippet
// SPDX-License-Identifier: GPL-2.0
//! Safety related APIs.
/// Checks that a precondition of an unsafe function is followed.
///
/// The check is enabled at runtime if debug assertions (`CONFIG_RUST_DEBUG_ASSERTIONS`)
/// are enabled. Otherwise, this macro is a no-op.
///
/// # Examples
///
/// ```no_run
/// use kernel::unsafe_precondition_assert;
///
/// struct RawBuffer<T: Copy, const N: usize> {
/// data: [T; N],
/// }
///
/// impl<T: Copy, const N: usize> RawBuffer<T, N> {
/// /// # Safety
/// ///
/// /// The caller must ensure that `index` is less than `N`.
/// unsafe fn set_unchecked(&mut self, index: usize, value: T) {
/// unsafe_precondition_assert!(
/// index < N,
/// "RawBuffer::set_unchecked() requires index ({index}) < N ({N})"
/// );
///
/// // SAFETY: By the safety requirements of this function, `index` is valid.
/// unsafe {
/// *self.data.get_unchecked_mut(index) = value;
/// }
/// }
/// }
/// ```
///
/// # Panics
///
/// Panics if the expression is evaluated to [`false`] at runtime.
#[macro_export]
macro_rules! unsafe_precondition_assert {
($cond:expr $(,)?) => {
$crate::unsafe_precondition_assert!(@inner $cond, ::core::stringify!($cond))
};
($cond:expr, $($arg:tt)+) => {
$crate::unsafe_precondition_assert!(@inner $cond, $crate::prelude::fmt!($($arg)+))
};
(@inner $cond:expr, $msg:expr) => {
::core::debug_assert!($cond, "unsafe precondition violated: {}", $msg)
};
}
Annotation
- Atlas domain: Rust Kernel Layer / Rust API Membrane.
- Implementation status: source implementation candidate.
Implementation Notes
- This generated page is the file-by-file coverage layer; curated subsystem chapters should link here when they synthesize a multi-file control flow.
- Core OS pages should be promoted from atlas-only to deep-reviewed when they explain data structures, invariants, locking, lifecycle, and C implementation snippets.
- Driver-family pages are intentionally pattern-oriented unless they are part of the selected PCIe/NVMe representative device path.