[PATCH] rust: security: replace `core::mem::zeroed` with `pin_init::zeroed`
From: Nils Lehnen <hidden>
Date: 2026-08-28 02:44:47
Also in:
lkml, rust-for-linux
Subsystem:
rust, security subsystem, the rest · Maintainers:
Miguel Ojeda, Paul Moore, James Morris, "Serge E. Hallyn", Linus Torvalds
From: Benno Lossin <lossin@kernel.org> All types in `bindings` implement `Zeroable` if they can, so use `pin_init::zeroed` instead of relying on `unsafe` code. If this ends up not compiling in the future, something in bindgen or on the C side changed and is most likely incorrect. Link: https://lore.kernel.org/r/20250814093046.2071971-8-lossin@kernel.org (local) Link: https://github.com/Rust-for-Linux/linux/issues/1189 Signed-off-by: Benno Lossin <lossin@kernel.org> Reviewed-by: Alexandre Courbot <acourbot@nvidia.com> Signed-off-by: Nils Lehnen <redacted> --- Resend of Benno's patch from the Zeroable series [1]: only patches 1, 2 and 11 of that series were applied, and the issue [2] asks for the rest to be re-sent. Rebased onto rust-next; it applied cleanly, and a defconfig build with CONFIG_RUST=y and CONFIG_SECURITY=y passes. Two equivalent one-off patches were posted earlier [3][4]; Miguel asked in [5] for a resend that keeps Benno's authorship, which this is. Cc'ing the LSM list per Paul's request on the original thread. [1] https://lore.kernel.org/r/20250814093046.2071971-1-lossin@kernel.org (local) [2] https://github.com/Rust-for-Linux/linux/issues/1189 [3] https://lore.kernel.org/r/20251129135657.36144-1-atharvd440@gmail.com (local) [4] https://lore.kernel.org/r/20260120083824.477339-8-sunke@kylinos.cn (local) [5] https://lore.kernel.org/r/CANiq72nJqFOR9vhPBfZUNrxU+M1HMV6wN9bN6i8e9rf_oOD2qw@mail.gmail.com (local) rust/kernel/security.rs | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/rust/kernel/security.rs b/rust/kernel/security.rs
index 9d271695265f..4dc3eba6ce84 100644
--- a/rust/kernel/security.rs
+++ b/rust/kernel/security.rs@@ -62,8 +62,7 @@ impl SecurityCtx { /// Get the security context given its id. #[inline] pub fn from_secid(secid: u32) -> Result<Self> { - // SAFETY: `struct lsm_context` can be initialized to all zeros. - let mut ctx: bindings::lsm_context = unsafe { core::mem::zeroed() }; + let mut ctx: bindings::lsm_context = pin_init::zeroed(); // SAFETY: Just a C FFI call. The pointer is valid for writes. to_result(unsafe { bindings::security_secid_to_secctx(secid, &mut ctx) })?;
base-commit: 73e3f0710014fe6d4ed98cfc02292f6121db7558 -- 2.43.0