Class 14: Rust in the kernel¶
Date: 02.06.2026 Small assignment
Why Rust¶
While what Rust is, isn't a topic for this class, some basic knowledge about Rust and its use cases is still required to understand this class. To learn more about Rust itself you can attend Programming in Rust class or other classes that contain Rust like: Distributed systems.
What is the premise of Rust? Rust offers greater memory safety without costly overheads. It's not the only advantage, and it also has some disadvantages.
Memory safety is not just a claim. There are multiple reports of how Rust reduced the number of memory safety bugs and vulnerabilities. According to Google, their Rust code in Android results in 1000 times less memory bugs per line of code written. Some additional claim they make is lower rollback rate of the code and also... faster development.
Why should Linux care about it? In practice, around 70% of bugs in code, that lead to vulnerabilities come from memory related bugs: use after free, out of bounds writes or reads, null pointer de-referencing and others. Linux kernel is not free from those kind of bugs.
While the core parts of kernel may get quite scrutinized review process, drivers that come with Linux may get less attention during review process, and as a result may have a higher chance of letting bugs through.
Rust C interoperability¶
While internally Rust does not have a stable ABI, both when it comes to struct in memory representation, and function calling conventions, it does allows to manually create and call functions with C ABI, with just marginal inconvenience of needing to declare existence of those functions:
unsafe extern "C" {
fn snappy_max_compressed_length(source_length: size_t) -> size_t;
}
This also applies to structures:
#[repr(C)]
struct Foo {
a: u32,
b: u8,
}
To simplify this process even further, there exists a tool, called bindgen that automatically generates the declarations from the C headers. Linux uses it to generate bindings of internal APIs for use in Rust code.
Rust for Linux¶
Clang vs GCC¶
According to its own documentation:
The Linux kernel has always traditionally been compiled with GNU toolchains such as GCC and binutils.
From kbuild/llvm.rst
However the GCC creates assembly code as an intermediate representation (there is more going under the hood, but the important part is that it does not use LLVM). On the other hand, rustc uses LLVM as its IR. This means we cannot easily mix the code generated by GCC and Rust at the compilation time. (We can still mix Rust binaries with GCC binaries, since we have a stable ABI, see previous section).
This is where a support for Clang in the Linux kernel comes into play. The project of supporting Clang for compilation of the Linux code has started over 10 years ago, and around 2017 it was already at a stage where it could compile 4.4 and 4.9 LTS version of the Linux kernel. While the motivations for this project had nothing to do with Rust, Rust for Linux utilizes this support. Clang compiler uses LLVM as its intermediate representation. This means, the Rust and C code can be combined in the linking process.
About Rust¶
The project has started in 2020 as an experiment. Over the years the slow development process continued, and as of December 2025 this endeavour is no longer consider experimental.
Since Rust is quite a new language, it's actively developed, with some features already implemented, but not yet available in the stable release. Those features are known as unstable, since they may be reworked at any time. And Linux uses quite a lot of those features.
Drivers in Rust¶
Currently Rust is used inside the kernel only for the development of the drivers (modules). This was decided as part of the initial plan for the Rust adoption RFC. In the 6.18.5 version of the kernel there are already quite a few drivers present.
Some noteworthy drivers are:
Android Binder Driver. This is a driver that is responsible for inter-process communication on Android.
DRM Panic QR code generator. As the name suggests, it generates a QR code, when the kernel panics on a DRM error.
Nova GPU Driver. Open source driver for Nvidia GPU aiming to replace the Nouveau driver.
Small assignment¶
Compile and boot kernel with Rust support enabled.
This may require changes to the configuration file and installation of different compiler version.
Note: please enable support for the Rust on top of the changes from the second large assignment. Then try to find a definition of the task struct, and see how the changes you made in the large assignment are reflected in the generated binding.
Submit two files:
Generated binding file: ./rust/bindings/bindings_generated.rs
Short description of the steps you have done (including those unsuccessful)
and a brief comment on the task struct (in the context of your changes from large assignment).
Inside a description of the changes, provide also the output of the cat /proc/version command.
References¶
https://blog.google/security/rust-in-android-move-fast-fix-things/
https://www.chromium.org/Home/chromium-security/memory-safety/
Shameli-Sendi, Alireza. “Understanding Linux kernel vulnerabilities.” Journal of Computer Virology and Hacking Techniques 17 (2021): 265 - 278.
https://elixir.bootlin.com/linux/v6.18.5/source/rust/bindings/lib.rs
https://rustc-dev-guide.rust-lang.org/overview.html#code-generation
https://lore.kernel.org/lkml/20210414184604.23473-1-ojeda@kernel.org/