From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 72C05E7717F for ; Mon, 16 Dec 2024 07:26:47 +0000 (UTC) Received: from list by lists.xenproject.org with outflank-mailman.857548.1269777 (Exim 4.92) (envelope-from ) id 1tN5Us-0001uz-Np; Mon, 16 Dec 2024 07:26:30 +0000 X-Outflank-Mailman: Message body and most headers restored to incoming version Received: by outflank-mailman (output) from mailman id 857548.1269777; Mon, 16 Dec 2024 07:26:30 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1tN5Us-0001us-Kt; Mon, 16 Dec 2024 07:26:30 +0000 Received: by outflank-mailman (input) for mailman id 857548; Mon, 16 Dec 2024 07:26:30 +0000 Received: from se1-gles-flk1-in.inumbo.com ([94.247.172.50] helo=se1-gles-flk1.inumbo.com) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1tN5Ur-0001um-U1 for xen-devel@lists.xenproject.org; Mon, 16 Dec 2024 07:26:30 +0000 Received: from mail-wr1-x42f.google.com (mail-wr1-x42f.google.com [2a00:1450:4864:20::42f]) by se1-gles-flk1.inumbo.com (Halon) with ESMTPS id 0f6e0c21-bb7f-11ef-99a3-01e77a169b0f; Mon, 16 Dec 2024 08:26:26 +0100 (CET) Received: by mail-wr1-x42f.google.com with SMTP id ffacd0b85a97d-385e87b25f0so3066208f8f.0 for ; Sun, 15 Dec 2024 23:26:26 -0800 (PST) Received: from [10.156.60.236] (ip-037-024-206-209.um08.pools.vodafone-ip.de. [37.24.206.209]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-388c801b9ebsm7289392f8f.63.2024.12.15.23.26.25 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Sun, 15 Dec 2024 23:26:25 -0800 (PST) X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" X-Inumbo-ID: 0f6e0c21-bb7f-11ef-99a3-01e77a169b0f DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=google; t=1734333986; x=1734938786; darn=lists.xenproject.org; h=content-transfer-encoding:in-reply-to:autocrypt:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:from:to:cc:subject:date:message-id:reply-to; bh=nDClr30Lcr0vDyPEXxZa27XEpMaP8Hx/VJ+zjk+2fCw=; b=Sypy/C/Goujj6VMQymSnJO4VyGD8mipQ5VF24QHzaBaOv+ufmqlgWhsh69oxezbg0Q jR82ugkkLFpcAvRGLxA+WbbwL2PuAdbKjq5wjzn1XAzIVHT2w8OhDIQv8mKB17E/Br0f scvUPOq374O9/IjDsFoEepq2mKpRdQAOnYkZ61p1ExQe/x5k3HiKiNGVfydLpZgwaReg 8E1HZiTf8AlBuMeRHsKC/5oGfY7RP7/AEMHoZJ6xUywWuGEi3mZfBrKGsJAz98LFWS18 cSFhhDsjcjwvkg8MjlUO8uObqknnuVySnGtBlR3v5UEz/4QxsV97d3B2rngcyfXXvJif MkpQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1734333986; x=1734938786; h=content-transfer-encoding:in-reply-to:autocrypt:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=nDClr30Lcr0vDyPEXxZa27XEpMaP8Hx/VJ+zjk+2fCw=; b=dXL1F8YByY9VdbBwqeE7mv3s7RcwXEF9XYxrN2AR6rBtpoF8AZILsxLPBW3dL7ZvJX /2oVFbRDVulUw4BDmBGH+Pola5dLUVd17fqvO5oY84GzV5ZgyqFOW7Pr4D8LqR3WJ47d vZhSjh0ElUDVlSRbyr5GFpQE7FO5LXYcg9pInbb2xd0HLWLA1ZUzZnM00CzvIUO2IhMG ilwfFXK3A4r/YKNIU0VBsAET/75ffSob8IHK5QPc7/rZ8tZBYtrBCfswesdjOMZW2v/U tKCb/a3HcXh5XvqSgCkt4Cr5hgjifl63dmpN73DkyhQVQKB0l7n0D6oGuzc5Cg44Jqra fXgw== X-Forwarded-Encrypted: i=1; AJvYcCVo2H1WueF3Ckib0lWWKkJqlibZTmg6bhhmWjCKuPaGTb2lxC/+FVp9pmW1cH7X0eJMI/aKkD6PLFs=@lists.xenproject.org X-Gm-Message-State: AOJu0YwccEpYFmY/eEG2VE3tRYiqxgp9NpuUkpxRzmr7VkHjN3zCf1Uz MGJCU6ADwRsjh6SNMss3Z0Cy195SQ7CT3yYF4tS0doVVFa6KeFIExXKUGENFsA== X-Gm-Gg: ASbGncv7UznBgOLKe9DtiSikkVRMExHlYQOshlOAmyWSpKc6R2JEL4seEMdwnwCEw/I LfnApsnIDYVRMH6EizwRLeXmw2G8oXOMbjASzGYvNolW95xGTtFFB0HWSmiUL6FxCusiYv3tEcx kd3+jJTvB0TF4qyWQuhax/UkWm0W9X2WcVN0b3LUoa1lcK9qM8r0zjR2Iw35wT59p/4/eJPOGXB D/Ggwr0Lcrqg+Vu08ppqoODAdjBnN3sZUQpDefpn5hdR0Vo2oAk+YtbXjWf/C+N5WVYyD/80IVf /naCNNN6WBI9KQqwuqbjEhqbQBNUQX2mCG2QuyedMA== X-Google-Smtp-Source: AGHT+IE2ETw++RADhNZRp1rzYmqhN1PA3RVwPOsuldbu+tsijSK4uQka6P8cP3y6tUQAQxMCixwGgQ== X-Received: by 2002:a5d:584b:0:b0:386:3afc:14a7 with SMTP id ffacd0b85a97d-387887e24c5mr12553425f8f.7.1734333986113; Sun, 15 Dec 2024 23:26:26 -0800 (PST) Message-ID: <3beb2c10-0cde-48e4-841c-5addd324626d@suse.com> Date: Mon, 16 Dec 2024 08:26:28 +0100 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] xen: address violation of MISRA C Rule 11.1 To: alessandro.zucchelli@bugseng.com Cc: Stefano Stabellini , consulting@bugseng.com, Julien Grall , Bertrand Marquis , Michal Orzel , Volodymyr Babchuk , Andrew Cooper , =?UTF-8?Q?Roger_Pau_Monn=C3=A9?= , xen-devel@lists.xenproject.org References: <7debd63f3900bad62bcbcc03081e4c04e6099135.1733914487.git.alessandro.zucchelli@bugseng.com> <26600bb0-93af-45b5-a341-5771bad844a1@suse.com> <1ddb5bd7e8889da0e978bb1391072925@bugseng.com> Content-Language: en-US From: Jan Beulich Autocrypt: addr=jbeulich@suse.com; keydata= xsDiBFk3nEQRBADAEaSw6zC/EJkiwGPXbWtPxl2xCdSoeepS07jW8UgcHNurfHvUzogEq5xk hu507c3BarVjyWCJOylMNR98Yd8VqD9UfmX0Hb8/BrA+Hl6/DB/eqGptrf4BSRwcZQM32aZK 7Pj2XbGWIUrZrd70x1eAP9QE3P79Y2oLrsCgbZJfEwCgvz9JjGmQqQkRiTVzlZVCJYcyGGsD /0tbFCzD2h20ahe8rC1gbb3K3qk+LpBtvjBu1RY9drYk0NymiGbJWZgab6t1jM7sk2vuf0Py O9Hf9XBmK0uE9IgMaiCpc32XV9oASz6UJebwkX+zF2jG5I1BfnO9g7KlotcA/v5ClMjgo6Gl MDY4HxoSRu3i1cqqSDtVlt+AOVBJBACrZcnHAUSuCXBPy0jOlBhxPqRWv6ND4c9PH1xjQ3NP nxJuMBS8rnNg22uyfAgmBKNLpLgAGVRMZGaGoJObGf72s6TeIqKJo/LtggAS9qAUiuKVnygo 3wjfkS9A3DRO+SpU7JqWdsveeIQyeyEJ/8PTowmSQLakF+3fote9ybzd880fSmFuIEJldWxp Y2ggPGpiZXVsaWNoQHN1c2UuY29tPsJgBBMRAgAgBQJZN5xEAhsDBgsJCAcDAgQVAggDBBYC AwECHgECF4AACgkQoDSui/t3IH4J+wCfQ5jHdEjCRHj23O/5ttg9r9OIruwAn3103WUITZee e7Sbg12UgcQ5lv7SzsFNBFk3nEQQCACCuTjCjFOUdi5Nm244F+78kLghRcin/awv+IrTcIWF hUpSs1Y91iQQ7KItirz5uwCPlwejSJDQJLIS+QtJHaXDXeV6NI0Uef1hP20+y8qydDiVkv6l IreXjTb7DvksRgJNvCkWtYnlS3mYvQ9NzS9PhyALWbXnH6sIJd2O9lKS1Mrfq+y0IXCP10eS FFGg+Av3IQeFatkJAyju0PPthyTqxSI4lZYuJVPknzgaeuJv/2NccrPvmeDg6Coe7ZIeQ8Yj t0ARxu2xytAkkLCel1Lz1WLmwLstV30g80nkgZf/wr+/BXJW/oIvRlonUkxv+IbBM3dX2OV8 AmRv1ySWPTP7AAMFB/9PQK/VtlNUJvg8GXj9ootzrteGfVZVVT4XBJkfwBcpC/XcPzldjv+3 HYudvpdNK3lLujXeA5fLOH+Z/G9WBc5pFVSMocI71I8bT8lIAzreg0WvkWg5V2WZsUMlnDL9 mpwIGFhlbM3gfDMs7MPMu8YQRFVdUvtSpaAs8OFfGQ0ia3LGZcjA6Ik2+xcqscEJzNH+qh8V m5jjp28yZgaqTaRbg3M/+MTbMpicpZuqF4rnB0AQD12/3BNWDR6bmh+EkYSMcEIpQmBM51qM EKYTQGybRCjpnKHGOxG0rfFY1085mBDZCH5Kx0cl0HVJuQKC+dV2ZY5AqjcKwAxpE75MLFkr wkkEGBECAAkFAlk3nEQCGwwACgkQoDSui/t3IH7nnwCfcJWUDUFKdCsBH/E5d+0ZnMQi+G0A nAuWpQkjM1ASeQwSHEeAWPgskBQL In-Reply-To: <1ddb5bd7e8889da0e978bb1391072925@bugseng.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit On 13.12.2024 15:02, Alessandro Zucchelli wrote: > On 2024-12-13 11:08, Jan Beulich wrote: >> On 13.12.2024 01:53, Stefano Stabellini wrote: >>> On Thu, 12 Dec 2024, Jan Beulich wrote: >>>> On 12.12.2024 03:27, Stefano Stabellini wrote: >>>>> On Wed, 11 Dec 2024, Jan Beulich wrote: >>>>>> On 11.12.2024 12:02, Alessandro Zucchelli wrote: >>>>>>> Rule 11.1 states as following: "Conversions shall not be performed >>>>>>> between a pointer to a function and any other type". >>>>>>> >>>>>>> Functions "__machine_restart" and "__machine_halt" in >>>>>>> "x86/shutdown.c" >>>>>>> and "halt_this_cpu" in "arm/shutdown.c" are defined as noreturn >>>>>>> functions and subsequently passed as parameters to function calls. >>>>>>> This violates the rule in Clang, where the "noreturn" attribute is >>>>>>> considered part of the function"s type. >>>>>> >>>>>> I'm unaware of build issues with Clang, hence can you clarify how >>>>>> Clang's >>>>>> view comes into play here? In principle various attributes ought to >>>>>> be >>>>>> part of a function's type; iirc that's also the case for gcc. Yet >>>>>> how >>>>>> that matters to Eclair is still entirely unclear to me. >>>>>> >>>>>>> By removing the "noreturn" >>>>>>> attribbute and replacing it with uses of the ASSERT_UNREACHABLE >>>>>>> macro, >>>>>>> these violations are addressed. >>>>>> >>>>>> Papered over, I'd say. What about release builds, for example? >>>>>> >>>>>> Deleting the attribute also has a clear downside >>>>>> documentation-wise. If >>>>>> we really mean to remove them from what the compiler gets to see, I >>>>>> think >>>>>> we ought to still retain them in commented-out shape. >>>>> >>>>> Another option would be to #define noreturn to nothing for ECLAIR >>>>> builds ? >>>> >>>> That again would feel like papering over things. Plus I don't know if >>>> that's >>>> an option at all. >>> >>> What is "papering over" and what is a "nice solution" is often up to >>> the >>> personal opinions. >>> >>> From my point of view, Alessandro's patch doesn't make the code worse. >>> The ASSERT_UNREACHABLE solution is OK. I do agree with you that it >>> should not be required for us to remove "noreturn", but I don't think >>> we >>> have used it consistently anyway across the Xen codebase. >>> ASSERT_UNREACHABLE is also a form of documentation that the function >>> does not return. >>> >>> In conclusion, I think all three options are acceptable: >>> 1) this patch as is >>> 2) this patch plus /* noreturn */ as a comment >>> 3) #define noreturn to nothing just for ECLAIR builds >>> >>> I don't mind either way, maybe option 2) is the best compromise. >> >> The variant with least impact on what we currently have (generated code >> wise) is 3), though, which hence would be my preference (well, not >> exactly >> a preference, but the least bad one). > > Another option could be to encapsulate these function pointer casts as > follows: > #define REMOVE_NORETURN(x) (void(*)(void*))(x) > This approach allows us to retain the noreturn attribute and the > associated optimizations; > note that the encapsulating macro will need to be deviated then. And then have one such macro for every attribute that may need zapping? What if there are multiple? Any macro may do, yet which one to use would be unclear. What if only some attributes need zapping, and some need retaining? Jan