[PATCH 1/5] rust: pin-init: internal: make `__init_data` and `__pin_data` safe
From: Gary Guo
Date: Wed Sep 23 2026 - 15:26:34 EST
Remove the unsafe markers of `__init_data` and `__pin_data`. These methods
are for inference help and does not need to be unsafe.
The `HasInitData` cannot be implemented outside pin-init, so the `unsafe
trait` marker is not necessary.
Signed-off-by: Gary Guo <gary@xxxxxxxxxxx>
---
rust/pin-init/internal/src/init.rs | 3 +--
rust/pin-init/internal/src/pin_data.rs | 2 +-
rust/pin-init/src/__internal.rs | 11 +++++------
3 files changed, 7 insertions(+), 9 deletions(-)
diff --git a/rust/pin-init/internal/src/init.rs b/rust/pin-init/internal/src/init.rs
index 1d2db93dd33d..1957be83a196 100644
--- a/rust/pin-init/internal/src/init.rs
+++ b/rust/pin-init/internal/src/init.rs
@@ -312,8 +312,7 @@ fn assert_zeroable<T: ?::core::marker::Sized>(_: *mut T)
let field_check = make_field_check(&fields, init_kind, &path);
Ok(quote_spanned! { Span::mixed_site() => {
// Get the data about fields from the supplied type.
- // SAFETY: TODO
- let data = unsafe {
+ let data = {
use ::pin_init::__internal::#has_data_trait;
// Can't use `<#path as #has_data_trait>::#get_data`, since the user is able to omit
// generics (which need to be present with that syntax).
diff --git a/rust/pin-init/internal/src/pin_data.rs b/rust/pin-init/internal/src/pin_data.rs
index 8cd9bf139567..30d9b8b54d8a 100644
--- a/rust/pin-init/internal/src/pin_data.rs
+++ b/rust/pin-init/internal/src/pin_data.rs
@@ -538,7 +538,7 @@ unsafe impl #impl_generics ::pin_init::__internal::HasPinData for #struct_name #
type PinData = __ThePinData #ty_generics;
#[inline]
- unsafe fn __pin_data() -> Self::PinData {
+ fn __pin_data() -> Self::PinData {
__ThePinData { __phantom: ::pin_init::__internal::PhantomInvariant::new() }
}
}
diff --git a/rust/pin-init/src/__internal.rs b/rust/pin-init/src/__internal.rs
index 8e9fd18b993f..51f6b40daa9e 100644
--- a/rust/pin-init/src/__internal.rs
+++ b/rust/pin-init/src/__internal.rs
@@ -81,12 +81,12 @@ pub unsafe fn new() -> Self {
///
/// # Safety
///
-/// Only the `init` module is allowed to use this trait.
+/// `pin-init` relies on the correctness of the helper functions defined on `PinData`.
+/// Thus, only the `#[pin_data]` can implement this trait.
pub unsafe trait HasPinData {
type PinData;
- #[expect(clippy::missing_safety_doc)]
- unsafe fn __pin_data() -> Self::PinData;
+ fn __pin_data() -> Self::PinData;
}
/// This trait is automatically implemented for every type. It aims to provide the same type
@@ -98,8 +98,7 @@ pub unsafe trait HasPinData {
pub unsafe trait HasInitData {
type InitData;
- #[expect(clippy::missing_safety_doc)]
- unsafe fn __init_data() -> Self::InitData;
+ fn __init_data() -> Self::InitData;
}
pub struct AllData<T: ?Sized>(PhantomInvariant<T>);
@@ -129,7 +128,7 @@ unsafe impl<T: ?Sized> HasInitData for T {
type InitData = AllData<T>;
#[inline]
- unsafe fn __init_data() -> Self::InitData {
+ fn __init_data() -> Self::InitData {
AllData(PhantomInvariant::new())
}
}
--
2.54.0