freenode
Kernel & Low-Level

Kernel pin-init adds safe sibling-field self-references

Gary Guo’s series lets pinned Rust structs borrow between fields without allocation, landing advanced variance tools under a tight-use agreement.

Gary Guo has sent a large series that adds safe self-referential fields to the Linux kernel’s pin-init Rust crate. One field of a pinned struct can now borrow from a sibling without heap allocation, something driver authors need and Rust has historically made hard to express without unsafe code or extra layers of indirection.

Pin-init already forces the struct to stay pinned for the duration of initialization. That pinning contract is what makes the new feature workable without the allocation tricks common in userspace crates. The simple path is ergonomic: name a lifetime after the field being borrowed and the macro machinery wires the relationship. More demanding types can mark how they capture those field lifetimes (covariant or invariant) and introduce existential lifetimes so invariant bounds do not leak into every caller’s public API.

Those advanced pieces are not theoretical. DRM’s jobqueue needs the variance annotations, and Nova’s command-queue type needs existential lifetimes. After discussion at Linux Plumbers Conference, maintainers agreed to upstream the full set in one go rather than stage a minimal subset first, but to confine advanced usage to those pre-agreed callers so the blast radius stays small if the design later needs rework. Guo had already presented the soundness case at Kangrejos.

The generated code enforces drop-order consistency and variance expectations at compile time, so a field that borrows another cannot outlive what it depends on, and implied bounds cannot silently reverse that relationship. Shared and mutable sibling borrows are both supported; mutable targets are kept off ordinary field access and projection paths so aliasing rules hold. Non-covariant fields are reachable through closure-based accessors that avoid forcing covariance.

Full documentation is deferred to a later cycle once real in-tree use settles the patterns. Benno Lossin has acked substantial parts of the series. Broader test coverage lives in Guo’s out-of-tree pull request for now.