On Sun Sep 20, 2026 at 2:13 PM CEST, Lorenzo Delgado wrote:
> `ResourceSize` is a bare type alias for `resource_size_t`, so it
> inherits every integer operation and `as` cast. That allows operations
> that make no sense for the size of a hardware resource, such as mixing
> it with unrelated integers or truncating it with a cast.
>
> Wrap it in a `#[repr(transparent)]` newtype so each conversion at a
> boundary is explicit. The representation is unchanged, so this is
> ABI-identical; only the spelling at the FFI boundary changes. Provide
> `from_raw`/`into_raw`, `From` in both directions, and a fallible
> `TryFrom<ResourceSize> for usize`. On 64-bit, where `resource_size_t`
> is a `u64`, also implement `FromSafeCastArch<ResourceSize> for usize`,
> so code that is specific to 64-bit can keep the conversion infallible.

This looks good now, but it makes me notice that dma_len() shouldn't return
ResourceSize in the first place.

The length of a single SG segment is bounded by max_segment_size, which is also
unsigned int.

So, I think we should change dma_len() to just return u32 (I'm also fine with a
new type, but it might be slighly overkill).

I'd usually pick this patch regardless and leave that for a follow-up, as it is
a separate issue. But if we change dma_len() first, we only have to update tyr
once, whereas if change it after we end up touching nova and tyr twice.

Thanks,
Danilo

Reply via email to