From: Jan Beulich <jbeulich@suse.com>
To: Dmytro Prokopchuk1 <dmytro_prokopchuk1@epam.com>,
"consulting@bugseng.com" <consulting@bugseng.com>
Cc: "Andrew Cooper" <andrew.cooper3@citrix.com>,
"Anthony PERARD" <anthony.perard@vates.tech>,
"Michal Orzel" <michal.orzel@amd.com>,
"Julien Grall" <julien@xen.org>,
"Roger Pau Monné" <roger.pau@citrix.com>,
"Stefano Stabellini" <sstabellini@kernel.org>,
"Bertrand Marquis" <bertrand.marquis@arm.com>,
"Volodymyr Babchuk" <Volodymyr_Babchuk@epam.com>,
"xen-devel@lists.xenproject.org" <xen-devel@lists.xenproject.org>
Subject: Re: [PATCH] misra: deviate explicit cast for Rule 11.1
Date: Mon, 28 Jul 2025 11:56:25 +0200 [thread overview]
Message-ID: <093601d7-691a-48ee-a0f4-2e86a0f2015e@suse.com> (raw)
In-Reply-To: <181a03d5c7625d42c06cf9fa0cf48a9bc6825361.1753647875.git.dmytro_prokopchuk1@epam.com>
On 27.07.2025 22:27, Dmytro Prokopchuk1 wrote:
> Explicitly cast 'halt_this_cpu' when passing it
> to 'smp_call_function' to match the required
> function pointer type '(void (*)(void *info))'.
>
> Document and justify a MISRA C R11.1 deviation
> (explicit cast).
>
> Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com>
All you talk about is the rule that you violate by adding a cast. But what is
the problem you're actually trying to resolve by adding a cast?
> --- a/xen/arch/arm/shutdown.c
> +++ b/xen/arch/arm/shutdown.c
> @@ -25,7 +25,8 @@ void machine_halt(void)
> watchdog_disable();
> console_start_sync();
> local_irq_enable();
> - smp_call_function(halt_this_cpu, NULL, 0);
> + /* SAF-15-safe */
> + smp_call_function((void (*)(void *))halt_this_cpu, NULL, 0);
Now this is the kind of cast that is very dangerous. The function's signature
changing will go entirely unnoticed (by the compiler) with such a cast in place.
If Misra / Eclair are unhappy about such an extra (benign here) attribute, I'd
be interested to know what their suggestion is to deal with the situation
without making the code worse (as in: more risky). I first thought about having
a new helper function that then simply chains to halt_this_cpu(), yet that
would result in a function which can't return, but has no noreturn attribute.
Jan
next prev parent reply other threads:[~2025-07-28 9:57 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-07-27 20:27 [PATCH] misra: deviate explicit cast for Rule 11.1 Dmytro Prokopchuk1
2025-07-28 9:56 ` Jan Beulich [this message]
2025-07-28 10:49 ` Andrew Cooper
2025-07-28 17:43 ` Nicola Vetrini
2025-07-28 18:03 ` Dmytro Prokopchuk1
2025-07-28 18:58 ` Dmytro Prokopchuk1
2025-07-28 19:17 ` Nicola Vetrini
2025-07-29 7:26 ` Jan Beulich
2025-07-29 11:03 ` Nicola Vetrini
2025-07-28 13:09 ` Dmytro Prokopchuk1
2025-07-28 13:23 ` Jan Beulich
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=093601d7-691a-48ee-a0f4-2e86a0f2015e@suse.com \
--to=jbeulich@suse.com \
--cc=Volodymyr_Babchuk@epam.com \
--cc=andrew.cooper3@citrix.com \
--cc=anthony.perard@vates.tech \
--cc=bertrand.marquis@arm.com \
--cc=consulting@bugseng.com \
--cc=dmytro_prokopchuk1@epam.com \
--cc=julien@xen.org \
--cc=michal.orzel@amd.com \
--cc=roger.pau@citrix.com \
--cc=sstabellini@kernel.org \
--cc=xen-devel@lists.xenproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.