* [XEN PATCH v2 0/3] address violation of MISRA C Rule 5.5
@ 2025-07-09 21:38 Dmytro Prokopchuk1
2025-07-09 21:38 ` [XEN PATCH v2 1/3] iommu: " Dmytro Prokopchuk1
` (3 more replies)
0 siblings, 4 replies; 23+ messages in thread
From: Dmytro Prokopchuk1 @ 2025-07-09 21:38 UTC (permalink / raw)
To: xen-devel@lists.xenproject.org
Cc: Dmytro Prokopchuk1, Jan Beulich, Roger Pau Monné,
Stefano Stabellini, Julien Grall, Bertrand Marquis, Michal Orzel,
Andrew Cooper, Anthony PERARD, Nicola Vetrini, Doug Goldstein
This patch series eliminates/deviates MISRA C Rule 5.5 violations for ARM64.
Thread discussion:
https://patchew.org/Xen/cover.1751659393.git.dmytro._5Fprokopchuk1@epam.com/
Changes in v2:
- fixed code alignment in "device-tree: address violation of MISRA C Rule 5.5"
- updated commit message in "iommu: address violation of MISRA C Rule 5.5"
- other patches were squashed and MISRA rule was deviated
Dmytro Prokopchuk (3):
iommu: address violation of MISRA C Rule 5.5
device-tree: address violation of MISRA C Rule 5.5
eclair: add deviations of MISRA C Rule 5.5
automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++
docs/misra/deviations.rst | 8 ++++++++
xen/common/device-tree/domain-build.c | 13 ++++++-------
xen/include/xen/fdt-domain-build.h | 4 ++--
xen/include/xen/iommu.h | 2 ++
5 files changed, 26 insertions(+), 9 deletions(-)
--
2.43.0
^ permalink raw reply [flat|nested] 23+ messages in thread
* [XEN PATCH v2 1/3] iommu: address violation of MISRA C Rule 5.5
2025-07-09 21:38 [XEN PATCH v2 0/3] address violation of MISRA C Rule 5.5 Dmytro Prokopchuk1
@ 2025-07-09 21:38 ` Dmytro Prokopchuk1
2025-07-10 8:21 ` Jan Beulich
2025-07-09 21:38 ` [XEN PATCH v2 2/3] device-tree: " Dmytro Prokopchuk1
` (2 subsequent siblings)
3 siblings, 1 reply; 23+ messages in thread
From: Dmytro Prokopchuk1 @ 2025-07-09 21:38 UTC (permalink / raw)
To: xen-devel@lists.xenproject.org
Cc: Dmytro Prokopchuk1, Jan Beulich, Roger Pau Monné
Address a violation of MISRA C:2012 Rule 5.5:
"Identifiers shall be distinct from macro names".
Reports for service MC3A2.R5.5:
xen/drivers/passthrough/iommu.c: non-compliant macro 'iommu_quarantine'
xen/include/xen/iommu.h: non-compliant variable 'iommu_quarantine'
There is a clash between function name and macro.
Add an 'extern' declaration for 'iommu_quarantine'
under the same preprocessor condition (#ifdef CONFIG_HAS_PCI).
This ensures that the declaration is consistent
and only exposed when CONFIG_HAS_PCI is defined.
Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com>
---
xen/include/xen/iommu.h | 2 ++
1 file changed, 2 insertions(+)
diff --git a/xen/include/xen/iommu.h b/xen/include/xen/iommu.h
index 3205e49990..57f338e2a0 100644
--- a/xen/include/xen/iommu.h
+++ b/xen/include/xen/iommu.h
@@ -53,7 +53,9 @@ static inline bool dfn_eq(dfn_t x, dfn_t y)
extern bool iommu_enable, iommu_enabled;
extern bool force_iommu, iommu_verbose;
/* Boolean except for the specific purposes of drivers/passthrough/iommu.c. */
+#ifdef CONFIG_HAS_PCI
extern uint8_t iommu_quarantine;
+#endif /* CONFIG_HAS_PCI */
#else
#define iommu_enabled false
#endif
--
2.43.0
^ permalink raw reply related [flat|nested] 23+ messages in thread
* [XEN PATCH v2 2/3] device-tree: address violation of MISRA C Rule 5.5
2025-07-09 21:38 [XEN PATCH v2 0/3] address violation of MISRA C Rule 5.5 Dmytro Prokopchuk1
2025-07-09 21:38 ` [XEN PATCH v2 1/3] iommu: " Dmytro Prokopchuk1
@ 2025-07-09 21:38 ` Dmytro Prokopchuk1
2025-07-09 21:38 ` [XEN PATCH v2 3/3] eclair: add deviations " Dmytro Prokopchuk1
2025-07-09 21:55 ` [XEN PATCH v2 0/3] address violation " Dmytro Prokopchuk1
3 siblings, 0 replies; 23+ messages in thread
From: Dmytro Prokopchuk1 @ 2025-07-09 21:38 UTC (permalink / raw)
To: xen-devel@lists.xenproject.org
Cc: Dmytro Prokopchuk1, Stefano Stabellini, Julien Grall,
Bertrand Marquis, Michal Orzel, Andrew Cooper, Anthony PERARD,
Jan Beulich, Roger Pau Monné
Address a violation of MISRA C:2012 Rule 5.5:
"Identifiers shall be distinct from macro names".
Reports for service MC3A2.R5.5:
xen/include/xen/fdt-domain-build.h: non-compliant parameter 'copy_to_guest'
xen/include/xen/guest_access.h: non-compliant macro 'copy_to_guest'
Rename 'copy_to_guest' function parameter to 'cb' for compliance.
No functional changes.
Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com>
Reviewed-by: Stefano Stabellini <sstabellini@kernel.org>
---
xen/common/device-tree/domain-build.c | 13 ++++++-------
xen/include/xen/fdt-domain-build.h | 4 ++--
2 files changed, 8 insertions(+), 9 deletions(-)
diff --git a/xen/common/device-tree/domain-build.c b/xen/common/device-tree/domain-build.c
index e6d7b8961e..4eea095e49 100644
--- a/xen/common/device-tree/domain-build.c
+++ b/xen/common/device-tree/domain-build.c
@@ -336,7 +336,7 @@ void __init allocate_memory(struct domain *d, struct kernel_info *kinfo)
}
void __init dtb_load(struct kernel_info *kinfo,
- copy_to_guest_phys_cb copy_to_guest)
+ copy_to_guest_phys_cb cb)
{
unsigned long left;
@@ -344,9 +344,9 @@ void __init dtb_load(struct kernel_info *kinfo,
kinfo->d, kinfo->dtb_paddr,
kinfo->dtb_paddr + fdt_totalsize(kinfo->fdt));
- left = copy_to_guest(kinfo->d, kinfo->dtb_paddr,
- kinfo->fdt,
- fdt_totalsize(kinfo->fdt));
+ left = cb(kinfo->d, kinfo->dtb_paddr,
+ kinfo->fdt,
+ fdt_totalsize(kinfo->fdt));
if ( left != 0 )
panic("Unable to copy the DTB to %pd memory (left = %lu bytes)\n",
@@ -355,7 +355,7 @@ void __init dtb_load(struct kernel_info *kinfo,
}
void __init initrd_load(struct kernel_info *kinfo,
- copy_to_guest_phys_cb copy_to_guest)
+ copy_to_guest_phys_cb cb)
{
const struct boot_module *mod = kinfo->initrd;
paddr_t load_addr = kinfo->initrd_paddr;
@@ -398,8 +398,7 @@ void __init initrd_load(struct kernel_info *kinfo,
if ( !initrd )
panic("Unable to map the %pd initrd\n", kinfo->d);
- res = copy_to_guest(kinfo->d, load_addr,
- initrd, len);
+ res = cb(kinfo->d, load_addr, initrd, len);
if ( res != 0 )
panic("Unable to copy the initrd in the %pd memory\n", kinfo->d);
diff --git a/xen/include/xen/fdt-domain-build.h b/xen/include/xen/fdt-domain-build.h
index 45981dbec0..3a20623cf5 100644
--- a/xen/include/xen/fdt-domain-build.h
+++ b/xen/include/xen/fdt-domain-build.h
@@ -50,10 +50,10 @@ typedef unsigned long (*copy_to_guest_phys_cb)(struct domain *d,
unsigned int len);
void initrd_load(struct kernel_info *kinfo,
- copy_to_guest_phys_cb copy_to_guest);
+ copy_to_guest_phys_cb cb);
void dtb_load(struct kernel_info *kinfo,
- copy_to_guest_phys_cb copy_to_guest);
+ copy_to_guest_phys_cb cb);
int find_unallocated_memory(const struct kernel_info *kinfo,
const struct membanks *mem_banks[],
--
2.43.0
^ permalink raw reply related [flat|nested] 23+ messages in thread
* [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5
2025-07-09 21:38 [XEN PATCH v2 0/3] address violation of MISRA C Rule 5.5 Dmytro Prokopchuk1
2025-07-09 21:38 ` [XEN PATCH v2 1/3] iommu: " Dmytro Prokopchuk1
2025-07-09 21:38 ` [XEN PATCH v2 2/3] device-tree: " Dmytro Prokopchuk1
@ 2025-07-09 21:38 ` Dmytro Prokopchuk1
2025-07-11 2:17 ` Stefano Stabellini
2025-07-11 8:28 ` Nicola Vetrini
2025-07-09 21:55 ` [XEN PATCH v2 0/3] address violation " Dmytro Prokopchuk1
3 siblings, 2 replies; 23+ messages in thread
From: Dmytro Prokopchuk1 @ 2025-07-09 21:38 UTC (permalink / raw)
To: xen-devel@lists.xenproject.org
Cc: Dmytro Prokopchuk1, Nicola Vetrini, Doug Goldstein,
Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel,
Jan Beulich, Julien Grall, Roger Pau Monné
MISRA C Rule 5.5 states that: "Identifiers shall
be distinct from macro names".
Update ECLAIR configuration to deviate:
- clashes in 'xen/include/xen/bitops.h';
- clashes in 'xen/include/xen/irq.h';
- clashes in 'xen/common/grant_table.c'.
Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com>
---
automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++
docs/misra/deviations.rst | 8 ++++++++
2 files changed, 16 insertions(+)
diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl b/automation/eclair_analysis/ECLAIR/deviations.ecl
index e8f513fbc5..a5d7b00094 100644
--- a/automation/eclair_analysis/ECLAIR/deviations.ecl
+++ b/automation/eclair_analysis/ECLAIR/deviations.ecl
@@ -117,6 +117,14 @@ it defines would (in the common case) be already defined. Peer reviewed by the c
-config=MC3A2.R5.5,reports+={deliberate, "any_area(decl(kind(function))||any_loc(macro(name(memcpy||memset||memmove))))&&any_area(any_loc(file(^xen/common/libelf/libelf-private\\.h$)))"}
-doc_end
+-doc_begin="Clashes between function names and macros are deliberate for bitops functions, pirq_cleanup_check, update_gnttab_par and parse_gnttab_limit functions
+and needed to have a function-like macro that acts as a wrapper for the function to be called. Before calling the function,
+the macro adds additional checks or adjusts the number of parameters depending on the configuration."
+-config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
+-config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/irq\\.h$))&&context(name(pirq_cleanup_check)&&kind(function)))"}
+-config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/common/grant_table\\.c$))&&context(name(update_gnttab_par||parse_gnttab_limit)&&kind(function)))"}
+-doc_end
+
-doc_begin="The type \"ret_t\" is deliberately defined multiple times,
depending on the guest."
-config=MC3A2.R5.6,reports+={deliberate,"any_area(any_loc(text(^.*ret_t.*$)))"}
diff --git a/docs/misra/deviations.rst b/docs/misra/deviations.rst
index 0d56d45b66..fe05e4062e 100644
--- a/docs/misra/deviations.rst
+++ b/docs/misra/deviations.rst
@@ -142,6 +142,14 @@ Deviations related to MISRA C:2012 Rules:
memmove.
- Tagged as `deliberate` for ECLAIR.
+ * - R5.5
+ - Clashes between function names and macros are deliberate for bitops functions,
+ pirq_cleanup_check, update_gnttab_par and parse_gnttab_limit functions and needed
+ to have a function-like macro that acts as a wrapper for the function to be
+ called. Before calling the function, the macro adds additional checks or
+ adjusts the number of parameters depending on the configuration.
+ - Tagged as `deliberate` for ECLAIR.
+
* - R5.6
- The type ret_t is deliberately defined multiple times depending on the
type of guest to service.
--
2.43.0
^ permalink raw reply related [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 0/3] address violation of MISRA C Rule 5.5
2025-07-09 21:38 [XEN PATCH v2 0/3] address violation of MISRA C Rule 5.5 Dmytro Prokopchuk1
` (2 preceding siblings ...)
2025-07-09 21:38 ` [XEN PATCH v2 3/3] eclair: add deviations " Dmytro Prokopchuk1
@ 2025-07-09 21:55 ` Dmytro Prokopchuk1
3 siblings, 0 replies; 23+ messages in thread
From: Dmytro Prokopchuk1 @ 2025-07-09 21:55 UTC (permalink / raw)
To: xen-devel@lists.xenproject.org
Cc: Jan Beulich, Roger Pau Monné, Stefano Stabellini,
Julien Grall, Bertrand Marquis, Michal Orzel, Andrew Cooper,
Anthony PERARD, Nicola Vetrini, Doug Goldstein
CI tests:
https://gitlab.com/xen-project/people/dimaprkp4k/xen/-/pipelines/1917527911
On 7/10/25 00:38, Dmytro Prokopchuk1 wrote:
> This patch series eliminates/deviates MISRA C Rule 5.5 violations for ARM64.
>
> Thread discussion:
> https://patchew.org/Xen/cover.1751659393.git.dmytro._5Fprokopchuk1@epam.com/
>
> Changes in v2:
> - fixed code alignment in "device-tree: address violation of MISRA C Rule 5.5"
> - updated commit message in "iommu: address violation of MISRA C Rule 5.5"
> - other patches were squashed and MISRA rule was deviated
>
> Dmytro Prokopchuk (3):
> iommu: address violation of MISRA C Rule 5.5
> device-tree: address violation of MISRA C Rule 5.5
> eclair: add deviations of MISRA C Rule 5.5
>
> automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++
> docs/misra/deviations.rst | 8 ++++++++
> xen/common/device-tree/domain-build.c | 13 ++++++-------
> xen/include/xen/fdt-domain-build.h | 4 ++--
> xen/include/xen/iommu.h | 2 ++
> 5 files changed, 26 insertions(+), 9 deletions(-)
>
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 1/3] iommu: address violation of MISRA C Rule 5.5
2025-07-09 21:38 ` [XEN PATCH v2 1/3] iommu: " Dmytro Prokopchuk1
@ 2025-07-10 8:21 ` Jan Beulich
2025-07-10 9:44 ` Dmytro Prokopchuk1
0 siblings, 1 reply; 23+ messages in thread
From: Jan Beulich @ 2025-07-10 8:21 UTC (permalink / raw)
To: Dmytro Prokopchuk1; +Cc: Roger Pau Monné, xen-devel@lists.xenproject.org
On 09.07.2025 23:38, Dmytro Prokopchuk1 wrote:
> Address a violation of MISRA C:2012 Rule 5.5:
> "Identifiers shall be distinct from macro names".
>
> Reports for service MC3A2.R5.5:
> xen/drivers/passthrough/iommu.c: non-compliant macro 'iommu_quarantine'
> xen/include/xen/iommu.h: non-compliant variable 'iommu_quarantine'
>
> There is a clash between function name and macro.
> Add an 'extern' declaration for 'iommu_quarantine'
> under the same preprocessor condition (#ifdef CONFIG_HAS_PCI).
Perhaps s/Add an/Put the/ or some such? You don't add any declaration,
after all.
> This ensures that the declaration is consistent
> and only exposed when CONFIG_HAS_PCI is defined.
>
> Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com>
With some suitable adjustment (happy to make while committing as long as
you agree):
Reviewed-by: Jan Beulich <jbeulich@suse.com>
Jan
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 1/3] iommu: address violation of MISRA C Rule 5.5
2025-07-10 8:21 ` Jan Beulich
@ 2025-07-10 9:44 ` Dmytro Prokopchuk1
2025-07-10 9:47 ` Dmytro Prokopchuk1
0 siblings, 1 reply; 23+ messages in thread
From: Dmytro Prokopchuk1 @ 2025-07-10 9:44 UTC (permalink / raw)
To: Jan Beulich; +Cc: Roger Pau Monné, xen-devel@lists.xenproject.org
Yes, sure. I'll update commit message.
Thanks!
On 7/10/25 11:21, Jan Beulich wrote:
> On 09.07.2025 23:38, Dmytro Prokopchuk1 wrote:
>> Address a violation of MISRA C:2012 Rule 5.5:
>> "Identifiers shall be distinct from macro names".
>>
>> Reports for service MC3A2.R5.5:
>> xen/drivers/passthrough/iommu.c: non-compliant macro 'iommu_quarantine'
>> xen/include/xen/iommu.h: non-compliant variable 'iommu_quarantine'
>>
>> There is a clash between function name and macro.
>> Add an 'extern' declaration for 'iommu_quarantine'
>> under the same preprocessor condition (#ifdef CONFIG_HAS_PCI).
>
> Perhaps s/Add an/Put the/ or some such? You don't add any declaration,
> after all.
>
>> This ensures that the declaration is consistent
>> and only exposed when CONFIG_HAS_PCI is defined.
>>
>> Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com>
>
> With some suitable adjustment (happy to make while committing as long as
> you agree):
> Reviewed-by: Jan Beulich <jbeulich@suse.com>
>
> Jan
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 1/3] iommu: address violation of MISRA C Rule 5.5
2025-07-10 9:44 ` Dmytro Prokopchuk1
@ 2025-07-10 9:47 ` Dmytro Prokopchuk1
0 siblings, 0 replies; 23+ messages in thread
From: Dmytro Prokopchuk1 @ 2025-07-10 9:47 UTC (permalink / raw)
To: Jan Beulich; +Cc: Roger Pau Monné, xen-devel@lists.xenproject.org
Jan, I don't mind, you can adjust it.
Please, go ahead.
On 7/10/25 12:44, Dmytro Prokopchuk wrote:
> Yes, sure. I'll update commit message.
> Thanks!
>
> On 7/10/25 11:21, Jan Beulich wrote:
>> On 09.07.2025 23:38, Dmytro Prokopchuk1 wrote:
>>> Address a violation of MISRA C:2012 Rule 5.5:
>>> "Identifiers shall be distinct from macro names".
>>>
>>> Reports for service MC3A2.R5.5:
>>> xen/drivers/passthrough/iommu.c: non-compliant macro 'iommu_quarantine'
>>> xen/include/xen/iommu.h: non-compliant variable 'iommu_quarantine'
>>>
>>> There is a clash between function name and macro.
>>> Add an 'extern' declaration for 'iommu_quarantine'
>>> under the same preprocessor condition (#ifdef CONFIG_HAS_PCI).
>>
>> Perhaps s/Add an/Put the/ or some such? You don't add any declaration,
>> after all.
>>
>>> This ensures that the declaration is consistent
>>> and only exposed when CONFIG_HAS_PCI is defined.
>>>
>>> Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com>
>>
>> With some suitable adjustment (happy to make while committing as long as
>> you agree):
>> Reviewed-by: Jan Beulich <jbeulich@suse.com>
>>
>> Jan
>
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5
2025-07-09 21:38 ` [XEN PATCH v2 3/3] eclair: add deviations " Dmytro Prokopchuk1
@ 2025-07-11 2:17 ` Stefano Stabellini
2025-07-11 8:28 ` Nicola Vetrini
1 sibling, 0 replies; 23+ messages in thread
From: Stefano Stabellini @ 2025-07-11 2:17 UTC (permalink / raw)
To: Dmytro Prokopchuk1
Cc: xen-devel@lists.xenproject.org, Nicola Vetrini, Doug Goldstein,
Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel,
Jan Beulich, Julien Grall, Roger Pau Monné
On Wed, 9 Jul 2025, Dmytro Prokopchuk1 wrote:
> MISRA C Rule 5.5 states that: "Identifiers shall
> be distinct from macro names".
>
> Update ECLAIR configuration to deviate:
> - clashes in 'xen/include/xen/bitops.h';
> - clashes in 'xen/include/xen/irq.h';
> - clashes in 'xen/common/grant_table.c'.
>
> Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com>
Hi Dmytro,
I tried to apply the patch and run a pipeline but it only results clean
on ARM but not on x86. There are 2087 outstanding violations:
https://gitlab.com/xen-project/people/sstabellini/xen/-/pipelines/1919889048
https://saas.eclairit.com:3787/fs/var/local/eclair/xen-project.ecdf/xen-project/people/sstabellini/xen/ECLAIR_normal/ppp1-1/X86_64/10644506983/PROJECT.ecd;/by_service/MC3A2.R5.5.html#{%22select%22:true,%22selection%22:{%22hiddenAreaKinds%22:[],%22hiddenSubareaKinds%22:[],%22show%22:false,%22selector%22:{%22enabled%22:true,%22negated%22:true,%22kind%22:0,%22domain%22:%22kind%22,%22inputs%22:[{%22enabled%22:true,%22text%22:%22violation%22}]}}}
Jan, Andrew, Roger,
About half of them are from bitops.h which could be deviated the same
way xen/include/xen/bitops.h is deviated in this patch.
xen/arch/x86/include/asm/x86_64/page.h:virt_to_maddr could be deviated
too.
I don't know how to handle the rest or even how to configure the
deviation in Eclair. These are the results with those two deviations
added:
https://saas.eclairit.com:3787/fs/var/local/eclair/xen-project.ecdf/xen-project/people/sstabellini/xen/ECLAIR_normal/ppp1-2/X86_64/10644744316/PROJECT.ecd;/by_service/MC3A2.R5.5.html#{%22select%22:true,%22selection%22:{%22hiddenAreaKinds%22:[],%22hiddenSubareaKinds%22:[],%22show%22:false,%22selector%22:{%22enabled%22:true,%22negated%22:true,%22kind%22:0,%22domain%22:%22kind%22,%22inputs%22:[{%22enabled%22:true,%22text%22:%22violation%22}]}}}
We only have 49 left. Any suggestions on how to handle them so that we
can mark the rule as "clean" and stop future regressions in the CI
loop?
> ---
> automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++
> docs/misra/deviations.rst | 8 ++++++++
> 2 files changed, 16 insertions(+)
>
> diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl b/automation/eclair_analysis/ECLAIR/deviations.ecl
> index e8f513fbc5..a5d7b00094 100644
> --- a/automation/eclair_analysis/ECLAIR/deviations.ecl
> +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl
> @@ -117,6 +117,14 @@ it defines would (in the common case) be already defined. Peer reviewed by the c
> -config=MC3A2.R5.5,reports+={deliberate, "any_area(decl(kind(function))||any_loc(macro(name(memcpy||memset||memmove))))&&any_area(any_loc(file(^xen/common/libelf/libelf-private\\.h$)))"}
> -doc_end
>
> +-doc_begin="Clashes between function names and macros are deliberate for bitops functions, pirq_cleanup_check, update_gnttab_par and parse_gnttab_limit functions
> +and needed to have a function-like macro that acts as a wrapper for the function to be called. Before calling the function,
> +the macro adds additional checks or adjusts the number of parameters depending on the configuration."
> +-config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
> +-config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/irq\\.h$))&&context(name(pirq_cleanup_check)&&kind(function)))"}
> +-config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/common/grant_table\\.c$))&&context(name(update_gnttab_par||parse_gnttab_limit)&&kind(function)))"}
> +-doc_end
> +
> -doc_begin="The type \"ret_t\" is deliberately defined multiple times,
> depending on the guest."
> -config=MC3A2.R5.6,reports+={deliberate,"any_area(any_loc(text(^.*ret_t.*$)))"}
> diff --git a/docs/misra/deviations.rst b/docs/misra/deviations.rst
> index 0d56d45b66..fe05e4062e 100644
> --- a/docs/misra/deviations.rst
> +++ b/docs/misra/deviations.rst
> @@ -142,6 +142,14 @@ Deviations related to MISRA C:2012 Rules:
> memmove.
> - Tagged as `deliberate` for ECLAIR.
>
> + * - R5.5
> + - Clashes between function names and macros are deliberate for bitops functions,
> + pirq_cleanup_check, update_gnttab_par and parse_gnttab_limit functions and needed
> + to have a function-like macro that acts as a wrapper for the function to be
> + called. Before calling the function, the macro adds additional checks or
> + adjusts the number of parameters depending on the configuration.
> + - Tagged as `deliberate` for ECLAIR.
> +
> * - R5.6
> - The type ret_t is deliberately defined multiple times depending on the
> type of guest to service.
> --
> 2.43.0
>
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5
2025-07-09 21:38 ` [XEN PATCH v2 3/3] eclair: add deviations " Dmytro Prokopchuk1
2025-07-11 2:17 ` Stefano Stabellini
@ 2025-07-11 8:28 ` Nicola Vetrini
2025-07-12 1:13 ` Stefano Stabellini
1 sibling, 1 reply; 23+ messages in thread
From: Nicola Vetrini @ 2025-07-11 8:28 UTC (permalink / raw)
To: Dmytro Prokopchuk1
Cc: xen-devel, Doug Goldstein, Stefano Stabellini, Andrew Cooper,
Anthony PERARD, Michal Orzel, Jan Beulich, Julien Grall,
Roger Pau Monné
On 2025-07-09 23:38, Dmytro Prokopchuk1 wrote:
> MISRA C Rule 5.5 states that: "Identifiers shall
> be distinct from macro names".
>
> Update ECLAIR configuration to deviate:
> - clashes in 'xen/include/xen/bitops.h';
> - clashes in 'xen/include/xen/irq.h';
> - clashes in 'xen/common/grant_table.c'.
>
> Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com>
> ---
> automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++
> docs/misra/deviations.rst | 8 ++++++++
> 2 files changed, 16 insertions(+)
>
> diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl
> b/automation/eclair_analysis/ECLAIR/deviations.ecl
> index e8f513fbc5..a5d7b00094 100644
> --- a/automation/eclair_analysis/ECLAIR/deviations.ecl
> +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl
> @@ -117,6 +117,14 @@ it defines would (in the common case) be already
> defined. Peer reviewed by the c
> -config=MC3A2.R5.5,reports+={deliberate,
> "any_area(decl(kind(function))||any_loc(macro(name(memcpy||memset||memmove))))&&any_area(any_loc(file(^xen/common/libelf/libelf-private\\.h$)))"}
> -doc_end
>
> +-doc_begin="Clashes between function names and macros are deliberate
> for bitops functions, pirq_cleanup_check, update_gnttab_par and
> parse_gnttab_limit functions
> +and needed to have a function-like macro that acts as a wrapper for
> the function to be called. Before calling the function,
> +the macro adds additional checks or adjusts the number of parameters
> depending on the configuration."
> +-config=MC3A2.R5.5,reports+={deliberate,
> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
Bitops violations are not inside "xen/include/xen/bitops.h", but rather
"xen/arch/x86/include/asm/bitops.h"
> +-config=MC3A2.R5.5,reports+={deliberate,
> "any_area(all_loc(file(^xen/include/xen/irq\\.h$))&&context(name(pirq_cleanup_check)&&kind(function)))"}
I would rather do (untested)
-config=MC3A2.R5.5,reports+={deliberate,
"all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
> +-config=MC3A2.R5.5,reports+={deliberate,
> "any_area(all_loc(file(^xen/common/grant_table\\.c$))&&context(name(update_gnttab_par||parse_gnttab_limit)&&kind(function)))"}
> +-doc_end
> +
same as above
> -doc_begin="The type \"ret_t\" is deliberately defined multiple times,
> depending on the guest."
>
> -config=MC3A2.R5.6,reports+={deliberate,"any_area(any_loc(text(^.*ret_t.*$)))"}
> diff --git a/docs/misra/deviations.rst b/docs/misra/deviations.rst
> index 0d56d45b66..fe05e4062e 100644
> --- a/docs/misra/deviations.rst
> +++ b/docs/misra/deviations.rst
> @@ -142,6 +142,14 @@ Deviations related to MISRA C:2012 Rules:
> memmove.
> - Tagged as `deliberate` for ECLAIR.
>
> + * - R5.5
> + - Clashes between function names and macros are deliberate for
> bitops functions,
> + pirq_cleanup_check, update_gnttab_par and parse_gnttab_limit
> functions and needed
> + to have a function-like macro that acts as a wrapper for the
> function to be
> + called. Before calling the function, the macro adds additional
> checks or
> + adjusts the number of parameters depending on the
> configuration.
> + - Tagged as `deliberate` for ECLAIR.
> +
> * - R5.6
> - The type ret_t is deliberately defined multiple times depending
> on the
> type of guest to service.
--
Nicola Vetrini, B.Sc.
Software Engineer
BUGSENG (https://bugseng.com)
LinkedIn: https://www.linkedin.com/in/nicola-vetrini-a42471253
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5
2025-07-11 8:28 ` Nicola Vetrini
@ 2025-07-12 1:13 ` Stefano Stabellini
2025-07-12 7:45 ` Nicola Vetrini
2025-07-14 7:55 ` Jan Beulich
0 siblings, 2 replies; 23+ messages in thread
From: Stefano Stabellini @ 2025-07-12 1:13 UTC (permalink / raw)
To: Nicola Vetrini
Cc: Dmytro Prokopchuk1, xen-devel, Doug Goldstein, Stefano Stabellini,
Andrew Cooper, Anthony PERARD, Michal Orzel, Jan Beulich,
Julien Grall, Roger Pau Monné
On Fri, 11 Jul 2025, Nicola Vetrini wrote:
> On 2025-07-09 23:38, Dmytro Prokopchuk1 wrote:
> > MISRA C Rule 5.5 states that: "Identifiers shall
> > be distinct from macro names".
> >
> > Update ECLAIR configuration to deviate:
> > - clashes in 'xen/include/xen/bitops.h';
> > - clashes in 'xen/include/xen/irq.h';
> > - clashes in 'xen/common/grant_table.c'.
> >
> > Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com>
> > ---
> > automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++
> > docs/misra/deviations.rst | 8 ++++++++
> > 2 files changed, 16 insertions(+)
> >
> > diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl
> > b/automation/eclair_analysis/ECLAIR/deviations.ecl
> > index e8f513fbc5..a5d7b00094 100644
> > --- a/automation/eclair_analysis/ECLAIR/deviations.ecl
> > +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl
> > @@ -117,6 +117,14 @@ it defines would (in the common case) be already
> > defined. Peer reviewed by the c
> > -config=MC3A2.R5.5,reports+={deliberate,
> > "any_area(decl(kind(function))||any_loc(macro(name(memcpy||memset||memmove))))&&any_area(any_loc(file(^xen/common/libelf/libelf-private\\.h$)))"}
> > -doc_end
> >
> > +-doc_begin="Clashes between function names and macros are deliberate for
> > bitops functions, pirq_cleanup_check, update_gnttab_par and
> > parse_gnttab_limit functions
> > +and needed to have a function-like macro that acts as a wrapper for the
> > function to be called. Before calling the function,
> > +the macro adds additional checks or adjusts the number of parameters
> > depending on the configuration."
> > +-config=MC3A2.R5.5,reports+={deliberate,
> > "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
>
> Bitops violations are not inside "xen/include/xen/bitops.h", but rather
> "xen/arch/x86/include/asm/bitops.h"
>
> > +-config=MC3A2.R5.5,reports+={deliberate,
> > "any_area(all_loc(file(^xen/include/xen/irq\\.h$))&&context(name(pirq_cleanup_check)&&kind(function)))"}
>
> I would rather do (untested)
>
> -config=MC3A2.R5.5,reports+={deliberate,
> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
>
> > +-config=MC3A2.R5.5,reports+={deliberate,
> > "any_area(all_loc(file(^xen/common/grant_table\\.c$))&&context(name(update_gnttab_par||parse_gnttab_limit)&&kind(function)))"}
> > +-doc_end
> > +
>
> same as above
>
Thanks Nicola! The following deviations are enough and sufficient to
zero violations on both ARM and x86:
-config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
-config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/bitops\\.h$)))"}
-config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat\\.c$)))"}
-config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat/.*$)))"}
-config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/x86_emulate/.*$)))"}
-config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/genapic\\.h$)))"}
-config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"}
-config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"}
-config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
-config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(virt_to_maddr))||macro(name(virt_to_maddr)))"}
-config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_px_pminfo))||macro(name(set_px_pminfo)))"}
-config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_cx_pminfo))||macro(name(set_cx_pminfo)))"}
-config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"}
-config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_to_guest_ll))||macro(name(copy_to_guest_ll)))"}
-config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_from_guest_ll))||macro(name(copy_from_guest_ll)))"}
-config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(edd_put_string))||macro(name(edd_put_string)))"}
-config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"}
-config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(page_list_entry))||macro(name(page_list_entry)))"}
-config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_physdev_op))||macro(name(do_physdev_op)))"}
-config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_platform_op))||macro(name(do_platform_op)))"}
Jan, are you OK with it?
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5
2025-07-12 1:13 ` Stefano Stabellini
@ 2025-07-12 7:45 ` Nicola Vetrini
2025-07-14 7:55 ` Jan Beulich
1 sibling, 0 replies; 23+ messages in thread
From: Nicola Vetrini @ 2025-07-12 7:45 UTC (permalink / raw)
To: Stefano Stabellini
Cc: Dmytro Prokopchuk1, xen-devel, Doug Goldstein, Stefano Stabellini,
Andrew Cooper, Anthony PERARD, Michal Orzel, Jan Beulich,
Julien Grall, Roger Pau Monné
On 2025-07-12 03:13, Stefano Stabellini wrote:
> On Fri, 11 Jul 2025, Nicola Vetrini wrote:
>> On 2025-07-09 23:38, Dmytro Prokopchuk1 wrote:
>> > MISRA C Rule 5.5 states that: "Identifiers shall
>> > be distinct from macro names".
>> >
>> > Update ECLAIR configuration to deviate:
>> > - clashes in 'xen/include/xen/bitops.h';
>> > - clashes in 'xen/include/xen/irq.h';
>> > - clashes in 'xen/common/grant_table.c'.
>> >
>> > Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com>
>> > ---
>> > automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++
>> > docs/misra/deviations.rst | 8 ++++++++
>> > 2 files changed, 16 insertions(+)
>> >
>> > diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl
>> > b/automation/eclair_analysis/ECLAIR/deviations.ecl
>> > index e8f513fbc5..a5d7b00094 100644
>> > --- a/automation/eclair_analysis/ECLAIR/deviations.ecl
>> > +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl
>> > @@ -117,6 +117,14 @@ it defines would (in the common case) be already
>> > defined. Peer reviewed by the c
>> > -config=MC3A2.R5.5,reports+={deliberate,
>> > "any_area(decl(kind(function))||any_loc(macro(name(memcpy||memset||memmove))))&&any_area(any_loc(file(^xen/common/libelf/libelf-private\\.h$)))"}
>> > -doc_end
>> >
>> > +-doc_begin="Clashes between function names and macros are deliberate for
>> > bitops functions, pirq_cleanup_check, update_gnttab_par and
>> > parse_gnttab_limit functions
>> > +and needed to have a function-like macro that acts as a wrapper for the
>> > function to be called. Before calling the function,
>> > +the macro adds additional checks or adjusts the number of parameters
>> > depending on the configuration."
>> > +-config=MC3A2.R5.5,reports+={deliberate,
>> > "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
>>
>> Bitops violations are not inside "xen/include/xen/bitops.h", but
>> rather
>> "xen/arch/x86/include/asm/bitops.h"
>>
>> > +-config=MC3A2.R5.5,reports+={deliberate,
>> > "any_area(all_loc(file(^xen/include/xen/irq\\.h$))&&context(name(pirq_cleanup_check)&&kind(function)))"}
>>
>> I would rather do (untested)
>>
>> -config=MC3A2.R5.5,reports+={deliberate,
>> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
>>
>> > +-config=MC3A2.R5.5,reports+={deliberate,
>> > "any_area(all_loc(file(^xen/common/grant_table\\.c$))&&context(name(update_gnttab_par||parse_gnttab_limit)&&kind(function)))"}
>> > +-doc_end
>> > +
>>
>> same as above
>>
>
> Thanks Nicola! The following deviations are enough and sufficient to
> zero violations on both ARM and x86:
>
> -config=MC3A2.R5.5,reports+={deliberate,
> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "any_area(all_loc(file(^xen/arch/x86/include/asm/bitops\\.h$)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "any_area(all_loc(file(^.*/compat\\.c$)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "any_area(all_loc(file(^.*/compat/.*$)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "any_area(all_loc(file(^xen/arch/x86/x86_emulate/.*$)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "any_area(all_loc(file(^xen/arch/x86/include/asm/genapic\\.h$)))"}
Thinking a bit more about it, this deviation is perhaps a bit too wide,
though in this case it's probably fine. Probably what is actually wanted
is "all_area(all_loc(...))" . This ensures that the decl area and the
macro area of the report are in the same file, which is almost always
the case for deliberate shadowing. If that turns out to be too strict,
then we may do "all_area(any_loc(...))", ensuring that at least there is
a loc for the macro and decl in that file.
> -config=MC3A2.R5.5,reports+={deliberate,
> "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "all_area(decl(name(virt_to_maddr))||macro(name(virt_to_maddr)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "all_area(decl(name(set_px_pminfo))||macro(name(set_px_pminfo)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "all_area(decl(name(set_cx_pminfo))||macro(name(set_cx_pminfo)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "all_area(decl(name(copy_to_guest_ll))||macro(name(copy_to_guest_ll)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "all_area(decl(name(copy_from_guest_ll))||macro(name(copy_from_guest_ll)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "all_area(decl(name(edd_put_string))||macro(name(edd_put_string)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "all_area(decl(name(page_list_entry))||macro(name(page_list_entry)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "all_area(decl(name(do_physdev_op))||macro(name(do_physdev_op)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "all_area(decl(name(do_platform_op))||macro(name(do_platform_op)))"}
>
> Jan, are you OK with it?
--
Nicola Vetrini, B.Sc.
Software Engineer
BUGSENG (https://bugseng.com)
LinkedIn: https://www.linkedin.com/in/nicola-vetrini-a42471253
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5
2025-07-12 1:13 ` Stefano Stabellini
2025-07-12 7:45 ` Nicola Vetrini
@ 2025-07-14 7:55 ` Jan Beulich
2025-07-15 9:46 ` Dmytro Prokopchuk1
1 sibling, 1 reply; 23+ messages in thread
From: Jan Beulich @ 2025-07-14 7:55 UTC (permalink / raw)
To: Stefano Stabellini
Cc: Dmytro Prokopchuk1, xen-devel, Doug Goldstein, Stefano Stabellini,
Andrew Cooper, Anthony PERARD, Michal Orzel, Julien Grall,
Roger Pau Monné, Nicola Vetrini
On 12.07.2025 03:13, Stefano Stabellini wrote:
> On Fri, 11 Jul 2025, Nicola Vetrini wrote:
>> On 2025-07-09 23:38, Dmytro Prokopchuk1 wrote:
>>> MISRA C Rule 5.5 states that: "Identifiers shall
>>> be distinct from macro names".
>>>
>>> Update ECLAIR configuration to deviate:
>>> - clashes in 'xen/include/xen/bitops.h';
>>> - clashes in 'xen/include/xen/irq.h';
>>> - clashes in 'xen/common/grant_table.c'.
>>>
>>> Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com>
>>> ---
>>> automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++
>>> docs/misra/deviations.rst | 8 ++++++++
>>> 2 files changed, 16 insertions(+)
>>>
>>> diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl
>>> b/automation/eclair_analysis/ECLAIR/deviations.ecl
>>> index e8f513fbc5..a5d7b00094 100644
>>> --- a/automation/eclair_analysis/ECLAIR/deviations.ecl
>>> +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl
>>> @@ -117,6 +117,14 @@ it defines would (in the common case) be already
>>> defined. Peer reviewed by the c
>>> -config=MC3A2.R5.5,reports+={deliberate,
>>> "any_area(decl(kind(function))||any_loc(macro(name(memcpy||memset||memmove))))&&any_area(any_loc(file(^xen/common/libelf/libelf-private\\.h$)))"}
>>> -doc_end
>>>
>>> +-doc_begin="Clashes between function names and macros are deliberate for
>>> bitops functions, pirq_cleanup_check, update_gnttab_par and
>>> parse_gnttab_limit functions
>>> +and needed to have a function-like macro that acts as a wrapper for the
>>> function to be called. Before calling the function,
>>> +the macro adds additional checks or adjusts the number of parameters
>>> depending on the configuration."
>>> +-config=MC3A2.R5.5,reports+={deliberate,
>>> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
>>
>> Bitops violations are not inside "xen/include/xen/bitops.h", but rather
>> "xen/arch/x86/include/asm/bitops.h"
>>
>>> +-config=MC3A2.R5.5,reports+={deliberate,
>>> "any_area(all_loc(file(^xen/include/xen/irq\\.h$))&&context(name(pirq_cleanup_check)&&kind(function)))"}
>>
>> I would rather do (untested)
>>
>> -config=MC3A2.R5.5,reports+={deliberate,
>> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
>>
>>> +-config=MC3A2.R5.5,reports+={deliberate,
>>> "any_area(all_loc(file(^xen/common/grant_table\\.c$))&&context(name(update_gnttab_par||parse_gnttab_limit)&&kind(function)))"}
>>> +-doc_end
>>> +
>>
>> same as above
>>
>
> Thanks Nicola! The following deviations are enough and sufficient to
> zero violations on both ARM and x86:
>
> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/bitops\\.h$)))"}
> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat\\.c$)))"}
> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat/.*$)))"}
> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/x86_emulate/.*$)))"}
> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/genapic\\.h$)))"}
> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"}
> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"}
> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(virt_to_maddr))||macro(name(virt_to_maddr)))"}
> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_px_pminfo))||macro(name(set_px_pminfo)))"}
> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_cx_pminfo))||macro(name(set_cx_pminfo)))"}
> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"}
> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_to_guest_ll))||macro(name(copy_to_guest_ll)))"}
> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_from_guest_ll))||macro(name(copy_from_guest_ll)))"}
> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(edd_put_string))||macro(name(edd_put_string)))"}
> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"}
> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(page_list_entry))||macro(name(page_list_entry)))"}
> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_physdev_op))||macro(name(do_physdev_op)))"}
> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_platform_op))||macro(name(do_platform_op)))"}
>
> Jan, are you OK with it?
For many of them the scope (all_area) looks to be far too wide, especially
for about everything involved in compat handling. I can only repeat that I
think that we would be (far) better off not having wider than necessary
deviations.
There are others which I may not understand, e.g. the genapic.h one. IOW I
further think that such a change would need to come with a fair bit of
explanation / justification.
Jan
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5
2025-07-14 7:55 ` Jan Beulich
@ 2025-07-15 9:46 ` Dmytro Prokopchuk1
2025-07-15 10:01 ` Jan Beulich
0 siblings, 1 reply; 23+ messages in thread
From: Dmytro Prokopchuk1 @ 2025-07-15 9:46 UTC (permalink / raw)
To: Jan Beulich, Stefano Stabellini
Cc: xen-devel@lists.xenproject.org, Doug Goldstein,
Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel,
Julien Grall, Roger Pau Monné, Nicola Vetrini
Hi Jan and Stefano.
Could we proceed with ARM deviations only so far?
I understand Stefano's preferences, but it can unblock me to address
next ARM violations.
BR, Dmytro.
On 7/14/25 10:55, Jan Beulich wrote:
> On 12.07.2025 03:13, Stefano Stabellini wrote:
>> On Fri, 11 Jul 2025, Nicola Vetrini wrote:
>>> On 2025-07-09 23:38, Dmytro Prokopchuk1 wrote:
>>>> MISRA C Rule 5.5 states that: "Identifiers shall
>>>> be distinct from macro names".
>>>>
>>>> Update ECLAIR configuration to deviate:
>>>> - clashes in 'xen/include/xen/bitops.h';
>>>> - clashes in 'xen/include/xen/irq.h';
>>>> - clashes in 'xen/common/grant_table.c'.
>>>>
>>>> Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com>
>>>> ---
>>>> automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++
>>>> docs/misra/deviations.rst | 8 ++++++++
>>>> 2 files changed, 16 insertions(+)
>>>>
>>>> diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl
>>>> b/automation/eclair_analysis/ECLAIR/deviations.ecl
>>>> index e8f513fbc5..a5d7b00094 100644
>>>> --- a/automation/eclair_analysis/ECLAIR/deviations.ecl
>>>> +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl
>>>> @@ -117,6 +117,14 @@ it defines would (in the common case) be already
>>>> defined. Peer reviewed by the c
>>>> -config=MC3A2.R5.5,reports+={deliberate,
>>>> "any_area(decl(kind(function))||any_loc(macro(name(memcpy||memset||memmove))))&&any_area(any_loc(file(^xen/common/libelf/libelf-private\\.h$)))"}
>>>> -doc_end
>>>>
>>>> +-doc_begin="Clashes between function names and macros are deliberate for
>>>> bitops functions, pirq_cleanup_check, update_gnttab_par and
>>>> parse_gnttab_limit functions
>>>> +and needed to have a function-like macro that acts as a wrapper for the
>>>> function to be called. Before calling the function,
>>>> +the macro adds additional checks or adjusts the number of parameters
>>>> depending on the configuration."
>>>> +-config=MC3A2.R5.5,reports+={deliberate,
>>>> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
>>>
>>> Bitops violations are not inside "xen/include/xen/bitops.h", but rather
>>> "xen/arch/x86/include/asm/bitops.h"
>>>
>>>> +-config=MC3A2.R5.5,reports+={deliberate,
>>>> "any_area(all_loc(file(^xen/include/xen/irq\\.h$))&&context(name(pirq_cleanup_check)&&kind(function)))"}
>>>
>>> I would rather do (untested)
>>>
>>> -config=MC3A2.R5.5,reports+={deliberate,
>>> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
>>>
>>>> +-config=MC3A2.R5.5,reports+={deliberate,
>>>> "any_area(all_loc(file(^xen/common/grant_table\\.c$))&&context(name(update_gnttab_par||parse_gnttab_limit)&&kind(function)))"}
>>>> +-doc_end
>>>> +
>>>
>>> same as above
>>>
>>
>> Thanks Nicola! The following deviations are enough and sufficient to
>> zero violations on both ARM and x86:
>>
>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/bitops\\.h$)))"}
>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat\\.c$)))"}
>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat/.*$)))"}
>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/x86_emulate/.*$)))"}
>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/genapic\\.h$)))"}
>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"}
>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"}
>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(virt_to_maddr))||macro(name(virt_to_maddr)))"}
>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_px_pminfo))||macro(name(set_px_pminfo)))"}
>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_cx_pminfo))||macro(name(set_cx_pminfo)))"}
>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"}
>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_to_guest_ll))||macro(name(copy_to_guest_ll)))"}
>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_from_guest_ll))||macro(name(copy_from_guest_ll)))"}
>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(edd_put_string))||macro(name(edd_put_string)))"}
>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"}
>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(page_list_entry))||macro(name(page_list_entry)))"}
>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_physdev_op))||macro(name(do_physdev_op)))"}
>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_platform_op))||macro(name(do_platform_op)))"}
>>
>> Jan, are you OK with it?
>
> For many of them the scope (all_area) looks to be far too wide, especially
> for about everything involved in compat handling. I can only repeat that I
> think that we would be (far) better off not having wider than necessary
> deviations.
>
> There are others which I may not understand, e.g. the genapic.h one. IOW I
> further think that such a change would need to come with a fair bit of
> explanation / justification.
>
> Jan
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5
2025-07-15 9:46 ` Dmytro Prokopchuk1
@ 2025-07-15 10:01 ` Jan Beulich
2025-07-15 10:07 ` Dmytro Prokopchuk1
0 siblings, 1 reply; 23+ messages in thread
From: Jan Beulich @ 2025-07-15 10:01 UTC (permalink / raw)
To: Dmytro Prokopchuk1
Cc: xen-devel@lists.xenproject.org, Doug Goldstein,
Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel,
Julien Grall, Roger Pau Monné, Nicola Vetrini,
Stefano Stabellini
On 15.07.2025 11:46, Dmytro Prokopchuk1 wrote:
> Could we proceed with ARM deviations only so far?
> I understand Stefano's preferences, but it can unblock me to address
> next ARM violations.
Hmm, ...
> On 7/14/25 10:55, Jan Beulich wrote:
>> On 12.07.2025 03:13, Stefano Stabellini wrote:
>>> On Fri, 11 Jul 2025, Nicola Vetrini wrote:
>>>> On 2025-07-09 23:38, Dmytro Prokopchuk1 wrote:
>>>>> MISRA C Rule 5.5 states that: "Identifiers shall
>>>>> be distinct from macro names".
>>>>>
>>>>> Update ECLAIR configuration to deviate:
>>>>> - clashes in 'xen/include/xen/bitops.h';
>>>>> - clashes in 'xen/include/xen/irq.h';
>>>>> - clashes in 'xen/common/grant_table.c'.
>>>>>
>>>>> Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com>
>>>>> ---
>>>>> automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++
>>>>> docs/misra/deviations.rst | 8 ++++++++
>>>>> 2 files changed, 16 insertions(+)
>>>>>
>>>>> diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl
>>>>> b/automation/eclair_analysis/ECLAIR/deviations.ecl
>>>>> index e8f513fbc5..a5d7b00094 100644
>>>>> --- a/automation/eclair_analysis/ECLAIR/deviations.ecl
>>>>> +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl
>>>>> @@ -117,6 +117,14 @@ it defines would (in the common case) be already
>>>>> defined. Peer reviewed by the c
>>>>> -config=MC3A2.R5.5,reports+={deliberate,
>>>>> "any_area(decl(kind(function))||any_loc(macro(name(memcpy||memset||memmove))))&&any_area(any_loc(file(^xen/common/libelf/libelf-private\\.h$)))"}
>>>>> -doc_end
>>>>>
>>>>> +-doc_begin="Clashes between function names and macros are deliberate for
>>>>> bitops functions, pirq_cleanup_check, update_gnttab_par and
>>>>> parse_gnttab_limit functions
>>>>> +and needed to have a function-like macro that acts as a wrapper for the
>>>>> function to be called. Before calling the function,
>>>>> +the macro adds additional checks or adjusts the number of parameters
>>>>> depending on the configuration."
>>>>> +-config=MC3A2.R5.5,reports+={deliberate,
>>>>> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
>>>>
>>>> Bitops violations are not inside "xen/include/xen/bitops.h", but rather
>>>> "xen/arch/x86/include/asm/bitops.h"
>>>>
>>>>> +-config=MC3A2.R5.5,reports+={deliberate,
>>>>> "any_area(all_loc(file(^xen/include/xen/irq\\.h$))&&context(name(pirq_cleanup_check)&&kind(function)))"}
>>>>
>>>> I would rather do (untested)
>>>>
>>>> -config=MC3A2.R5.5,reports+={deliberate,
>>>> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
>>>>
>>>>> +-config=MC3A2.R5.5,reports+={deliberate,
>>>>> "any_area(all_loc(file(^xen/common/grant_table\\.c$))&&context(name(update_gnttab_par||parse_gnttab_limit)&&kind(function)))"}
>>>>> +-doc_end
>>>>> +
>>>>
>>>> same as above
>>>>
>>>
>>> Thanks Nicola! The following deviations are enough and sufficient to
>>> zero violations on both ARM and x86:
>>>
>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/bitops\\.h$)))"}
>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat\\.c$)))"}
>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat/.*$)))"}
>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/x86_emulate/.*$)))"}
>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/genapic\\.h$)))"}
>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"}
>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"}
>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(virt_to_maddr))||macro(name(virt_to_maddr)))"}
>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_px_pminfo))||macro(name(set_px_pminfo)))"}
>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_cx_pminfo))||macro(name(set_cx_pminfo)))"}
>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"}
>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_to_guest_ll))||macro(name(copy_to_guest_ll)))"}
>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_from_guest_ll))||macro(name(copy_from_guest_ll)))"}
>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(edd_put_string))||macro(name(edd_put_string)))"}
>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"}
>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(page_list_entry))||macro(name(page_list_entry)))"}
>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_physdev_op))||macro(name(do_physdev_op)))"}
>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_platform_op))||macro(name(do_platform_op)))"}
... in here, which of them are Arm-only?
Jan
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5
2025-07-15 10:01 ` Jan Beulich
@ 2025-07-15 10:07 ` Dmytro Prokopchuk1
2025-07-15 10:39 ` Jan Beulich
2025-07-15 10:50 ` Jan Beulich
0 siblings, 2 replies; 23+ messages in thread
From: Dmytro Prokopchuk1 @ 2025-07-15 10:07 UTC (permalink / raw)
To: Jan Beulich
Cc: xen-devel@lists.xenproject.org, Doug Goldstein,
Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel,
Julien Grall, Roger Pau Monné, Nicola Vetrini,
Stefano Stabellini
ARM only are:
-config=MC3A2.R5.5,reports+={deliberate,
"any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
-config=MC3A2.R5.5,reports+={deliberate,
"all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"}
-config=MC3A2.R5.5,reports+={deliberate,
"all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"}
-config=MC3A2.R5.5,reports+={deliberate,
"all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
Dmytro.
On 7/15/25 13:01, Jan Beulich wrote:
> On 15.07.2025 11:46, Dmytro Prokopchuk1 wrote:
>> Could we proceed with ARM deviations only so far?
>> I understand Stefano's preferences, but it can unblock me to address
>> next ARM violations.
>
> Hmm, ...
>
>> On 7/14/25 10:55, Jan Beulich wrote:
>>> On 12.07.2025 03:13, Stefano Stabellini wrote:
>>>> On Fri, 11 Jul 2025, Nicola Vetrini wrote:
>>>>> On 2025-07-09 23:38, Dmytro Prokopchuk1 wrote:
>>>>>> MISRA C Rule 5.5 states that: "Identifiers shall
>>>>>> be distinct from macro names".
>>>>>>
>>>>>> Update ECLAIR configuration to deviate:
>>>>>> - clashes in 'xen/include/xen/bitops.h';
>>>>>> - clashes in 'xen/include/xen/irq.h';
>>>>>> - clashes in 'xen/common/grant_table.c'.
>>>>>>
>>>>>> Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com>
>>>>>> ---
>>>>>> automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++
>>>>>> docs/misra/deviations.rst | 8 ++++++++
>>>>>> 2 files changed, 16 insertions(+)
>>>>>>
>>>>>> diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl
>>>>>> b/automation/eclair_analysis/ECLAIR/deviations.ecl
>>>>>> index e8f513fbc5..a5d7b00094 100644
>>>>>> --- a/automation/eclair_analysis/ECLAIR/deviations.ecl
>>>>>> +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl
>>>>>> @@ -117,6 +117,14 @@ it defines would (in the common case) be already
>>>>>> defined. Peer reviewed by the c
>>>>>> -config=MC3A2.R5.5,reports+={deliberate,
>>>>>> "any_area(decl(kind(function))||any_loc(macro(name(memcpy||memset||memmove))))&&any_area(any_loc(file(^xen/common/libelf/libelf-private\\.h$)))"}
>>>>>> -doc_end
>>>>>>
>>>>>> +-doc_begin="Clashes between function names and macros are deliberate for
>>>>>> bitops functions, pirq_cleanup_check, update_gnttab_par and
>>>>>> parse_gnttab_limit functions
>>>>>> +and needed to have a function-like macro that acts as a wrapper for the
>>>>>> function to be called. Before calling the function,
>>>>>> +the macro adds additional checks or adjusts the number of parameters
>>>>>> depending on the configuration."
>>>>>> +-config=MC3A2.R5.5,reports+={deliberate,
>>>>>> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
>>>>>
>>>>> Bitops violations are not inside "xen/include/xen/bitops.h", but rather
>>>>> "xen/arch/x86/include/asm/bitops.h"
>>>>>
>>>>>> +-config=MC3A2.R5.5,reports+={deliberate,
>>>>>> "any_area(all_loc(file(^xen/include/xen/irq\\.h$))&&context(name(pirq_cleanup_check)&&kind(function)))"}
>>>>>
>>>>> I would rather do (untested)
>>>>>
>>>>> -config=MC3A2.R5.5,reports+={deliberate,
>>>>> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
>>>>>
>>>>>> +-config=MC3A2.R5.5,reports+={deliberate,
>>>>>> "any_area(all_loc(file(^xen/common/grant_table\\.c$))&&context(name(update_gnttab_par||parse_gnttab_limit)&&kind(function)))"}
>>>>>> +-doc_end
>>>>>> +
>>>>>
>>>>> same as above
>>>>>
>>>>
>>>> Thanks Nicola! The following deviations are enough and sufficient to
>>>> zero violations on both ARM and x86:
>>>>
>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/bitops\\.h$)))"}
>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat\\.c$)))"}
>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat/.*$)))"}
>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/x86_emulate/.*$)))"}
>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/genapic\\.h$)))"}
>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"}
>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"}
>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(virt_to_maddr))||macro(name(virt_to_maddr)))"}
>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_px_pminfo))||macro(name(set_px_pminfo)))"}
>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_cx_pminfo))||macro(name(set_cx_pminfo)))"}
>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"}
>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_to_guest_ll))||macro(name(copy_to_guest_ll)))"}
>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_from_guest_ll))||macro(name(copy_from_guest_ll)))"}
>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(edd_put_string))||macro(name(edd_put_string)))"}
>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"}
>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(page_list_entry))||macro(name(page_list_entry)))"}
>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_physdev_op))||macro(name(do_physdev_op)))"}
>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_platform_op))||macro(name(do_platform_op)))"}
>
> ... in here, which of them are Arm-only?
>
> Jan
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5
2025-07-15 10:07 ` Dmytro Prokopchuk1
@ 2025-07-15 10:39 ` Jan Beulich
2025-07-15 10:45 ` Dmytro Prokopchuk1
2025-07-15 10:50 ` Jan Beulich
1 sibling, 1 reply; 23+ messages in thread
From: Jan Beulich @ 2025-07-15 10:39 UTC (permalink / raw)
To: Dmytro Prokopchuk1
Cc: xen-devel@lists.xenproject.org, Doug Goldstein,
Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel,
Julien Grall, Roger Pau Monné, Nicola Vetrini,
Stefano Stabellini
On 15.07.2025 12:07, Dmytro Prokopchuk1 wrote:
> ARM only are:
> -config=MC3A2.R5.5,reports+={deliberate,
> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
Hmm, I'd call these "common code" ones, but I guess you meant "anything that
would make Arm clean".
As an aside - please don't top-post.
Jan
> On 7/15/25 13:01, Jan Beulich wrote:
>> On 15.07.2025 11:46, Dmytro Prokopchuk1 wrote:
>>> Could we proceed with ARM deviations only so far?
>>> I understand Stefano's preferences, but it can unblock me to address
>>> next ARM violations.
>>
>> Hmm, ...
>>
>>> On 7/14/25 10:55, Jan Beulich wrote:
>>>> On 12.07.2025 03:13, Stefano Stabellini wrote:
>>>>> On Fri, 11 Jul 2025, Nicola Vetrini wrote:
>>>>>> On 2025-07-09 23:38, Dmytro Prokopchuk1 wrote:
>>>>>>> MISRA C Rule 5.5 states that: "Identifiers shall
>>>>>>> be distinct from macro names".
>>>>>>>
>>>>>>> Update ECLAIR configuration to deviate:
>>>>>>> - clashes in 'xen/include/xen/bitops.h';
>>>>>>> - clashes in 'xen/include/xen/irq.h';
>>>>>>> - clashes in 'xen/common/grant_table.c'.
>>>>>>>
>>>>>>> Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com>
>>>>>>> ---
>>>>>>> automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++
>>>>>>> docs/misra/deviations.rst | 8 ++++++++
>>>>>>> 2 files changed, 16 insertions(+)
>>>>>>>
>>>>>>> diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl
>>>>>>> b/automation/eclair_analysis/ECLAIR/deviations.ecl
>>>>>>> index e8f513fbc5..a5d7b00094 100644
>>>>>>> --- a/automation/eclair_analysis/ECLAIR/deviations.ecl
>>>>>>> +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl
>>>>>>> @@ -117,6 +117,14 @@ it defines would (in the common case) be already
>>>>>>> defined. Peer reviewed by the c
>>>>>>> -config=MC3A2.R5.5,reports+={deliberate,
>>>>>>> "any_area(decl(kind(function))||any_loc(macro(name(memcpy||memset||memmove))))&&any_area(any_loc(file(^xen/common/libelf/libelf-private\\.h$)))"}
>>>>>>> -doc_end
>>>>>>>
>>>>>>> +-doc_begin="Clashes between function names and macros are deliberate for
>>>>>>> bitops functions, pirq_cleanup_check, update_gnttab_par and
>>>>>>> parse_gnttab_limit functions
>>>>>>> +and needed to have a function-like macro that acts as a wrapper for the
>>>>>>> function to be called. Before calling the function,
>>>>>>> +the macro adds additional checks or adjusts the number of parameters
>>>>>>> depending on the configuration."
>>>>>>> +-config=MC3A2.R5.5,reports+={deliberate,
>>>>>>> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
>>>>>>
>>>>>> Bitops violations are not inside "xen/include/xen/bitops.h", but rather
>>>>>> "xen/arch/x86/include/asm/bitops.h"
>>>>>>
>>>>>>> +-config=MC3A2.R5.5,reports+={deliberate,
>>>>>>> "any_area(all_loc(file(^xen/include/xen/irq\\.h$))&&context(name(pirq_cleanup_check)&&kind(function)))"}
>>>>>>
>>>>>> I would rather do (untested)
>>>>>>
>>>>>> -config=MC3A2.R5.5,reports+={deliberate,
>>>>>> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
>>>>>>
>>>>>>> +-config=MC3A2.R5.5,reports+={deliberate,
>>>>>>> "any_area(all_loc(file(^xen/common/grant_table\\.c$))&&context(name(update_gnttab_par||parse_gnttab_limit)&&kind(function)))"}
>>>>>>> +-doc_end
>>>>>>> +
>>>>>>
>>>>>> same as above
>>>>>>
>>>>>
>>>>> Thanks Nicola! The following deviations are enough and sufficient to
>>>>> zero violations on both ARM and x86:
>>>>>
>>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
>>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/bitops\\.h$)))"}
>>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat\\.c$)))"}
>>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat/.*$)))"}
>>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/x86_emulate/.*$)))"}
>>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/genapic\\.h$)))"}
>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"}
>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"}
>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(virt_to_maddr))||macro(name(virt_to_maddr)))"}
>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_px_pminfo))||macro(name(set_px_pminfo)))"}
>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_cx_pminfo))||macro(name(set_cx_pminfo)))"}
>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"}
>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_to_guest_ll))||macro(name(copy_to_guest_ll)))"}
>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_from_guest_ll))||macro(name(copy_from_guest_ll)))"}
>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(edd_put_string))||macro(name(edd_put_string)))"}
>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"}
>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(page_list_entry))||macro(name(page_list_entry)))"}
>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_physdev_op))||macro(name(do_physdev_op)))"}
>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_platform_op))||macro(name(do_platform_op)))"}
>>
>> ... in here, which of them are Arm-only?
>>
>> Jan
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5
2025-07-15 10:39 ` Jan Beulich
@ 2025-07-15 10:45 ` Dmytro Prokopchuk1
0 siblings, 0 replies; 23+ messages in thread
From: Dmytro Prokopchuk1 @ 2025-07-15 10:45 UTC (permalink / raw)
To: Jan Beulich
Cc: xen-devel@lists.xenproject.org, Doug Goldstein,
Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel,
Julien Grall, Roger Pau Monné, Nicola Vetrini,
Stefano Stabellini
On 7/15/25 13:39, Jan Beulich wrote:
> On 15.07.2025 12:07, Dmytro Prokopchuk1 wrote:
>> ARM only are:
>> -config=MC3A2.R5.5,reports+={deliberate,
>> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
>> -config=MC3A2.R5.5,reports+={deliberate,
>> "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"}
>> -config=MC3A2.R5.5,reports+={deliberate,
>> "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"}
>> -config=MC3A2.R5.5,reports+={deliberate,
>> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
>
> Hmm, I'd call these "common code" ones, but I guess you meant "anything that
> would make Arm clean".
>
> As an aside - please don't top-post.
>
> Jan
>
Yes, you are right. I meant "make ARM clean".
Sorry for inconvenience.
Dmytro.
>> On 7/15/25 13:01, Jan Beulich wrote:
>>> On 15.07.2025 11:46, Dmytro Prokopchuk1 wrote:
>>>> Could we proceed with ARM deviations only so far?
>>>> I understand Stefano's preferences, but it can unblock me to address
>>>> next ARM violations.
>>>
>>> Hmm, ...
>>>
>>>> On 7/14/25 10:55, Jan Beulich wrote:
>>>>> On 12.07.2025 03:13, Stefano Stabellini wrote:
>>>>>> On Fri, 11 Jul 2025, Nicola Vetrini wrote:
>>>>>>> On 2025-07-09 23:38, Dmytro Prokopchuk1 wrote:
>>>>>>>> MISRA C Rule 5.5 states that: "Identifiers shall
>>>>>>>> be distinct from macro names".
>>>>>>>>
>>>>>>>> Update ECLAIR configuration to deviate:
>>>>>>>> - clashes in 'xen/include/xen/bitops.h';
>>>>>>>> - clashes in 'xen/include/xen/irq.h';
>>>>>>>> - clashes in 'xen/common/grant_table.c'.
>>>>>>>>
>>>>>>>> Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com>
>>>>>>>> ---
>>>>>>>> automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++
>>>>>>>> docs/misra/deviations.rst | 8 ++++++++
>>>>>>>> 2 files changed, 16 insertions(+)
>>>>>>>>
>>>>>>>> diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl
>>>>>>>> b/automation/eclair_analysis/ECLAIR/deviations.ecl
>>>>>>>> index e8f513fbc5..a5d7b00094 100644
>>>>>>>> --- a/automation/eclair_analysis/ECLAIR/deviations.ecl
>>>>>>>> +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl
>>>>>>>> @@ -117,6 +117,14 @@ it defines would (in the common case) be already
>>>>>>>> defined. Peer reviewed by the c
>>>>>>>> -config=MC3A2.R5.5,reports+={deliberate,
>>>>>>>> "any_area(decl(kind(function))||any_loc(macro(name(memcpy||memset||memmove))))&&any_area(any_loc(file(^xen/common/libelf/libelf-private\\.h$)))"}
>>>>>>>> -doc_end
>>>>>>>>
>>>>>>>> +-doc_begin="Clashes between function names and macros are deliberate for
>>>>>>>> bitops functions, pirq_cleanup_check, update_gnttab_par and
>>>>>>>> parse_gnttab_limit functions
>>>>>>>> +and needed to have a function-like macro that acts as a wrapper for the
>>>>>>>> function to be called. Before calling the function,
>>>>>>>> +the macro adds additional checks or adjusts the number of parameters
>>>>>>>> depending on the configuration."
>>>>>>>> +-config=MC3A2.R5.5,reports+={deliberate,
>>>>>>>> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
>>>>>>>
>>>>>>> Bitops violations are not inside "xen/include/xen/bitops.h", but rather
>>>>>>> "xen/arch/x86/include/asm/bitops.h"
>>>>>>>
>>>>>>>> +-config=MC3A2.R5.5,reports+={deliberate,
>>>>>>>> "any_area(all_loc(file(^xen/include/xen/irq\\.h$))&&context(name(pirq_cleanup_check)&&kind(function)))"}
>>>>>>>
>>>>>>> I would rather do (untested)
>>>>>>>
>>>>>>> -config=MC3A2.R5.5,reports+={deliberate,
>>>>>>> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
>>>>>>>
>>>>>>>> +-config=MC3A2.R5.5,reports+={deliberate,
>>>>>>>> "any_area(all_loc(file(^xen/common/grant_table\\.c$))&&context(name(update_gnttab_par||parse_gnttab_limit)&&kind(function)))"}
>>>>>>>> +-doc_end
>>>>>>>> +
>>>>>>>
>>>>>>> same as above
>>>>>>>
>>>>>>
>>>>>> Thanks Nicola! The following deviations are enough and sufficient to
>>>>>> zero violations on both ARM and x86:
>>>>>>
>>>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
>>>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/bitops\\.h$)))"}
>>>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat\\.c$)))"}
>>>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat/.*$)))"}
>>>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/x86_emulate/.*$)))"}
>>>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/genapic\\.h$)))"}
>>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"}
>>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"}
>>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
>>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(virt_to_maddr))||macro(name(virt_to_maddr)))"}
>>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_px_pminfo))||macro(name(set_px_pminfo)))"}
>>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_cx_pminfo))||macro(name(set_cx_pminfo)))"}
>>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"}
>>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_to_guest_ll))||macro(name(copy_to_guest_ll)))"}
>>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_from_guest_ll))||macro(name(copy_from_guest_ll)))"}
>>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(edd_put_string))||macro(name(edd_put_string)))"}
>>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"}
>>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(page_list_entry))||macro(name(page_list_entry)))"}
>>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_physdev_op))||macro(name(do_physdev_op)))"}
>>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_platform_op))||macro(name(do_platform_op)))"}
>>>
>>> ... in here, which of them are Arm-only?
>>>
>>> Jan
>
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5
2025-07-15 10:07 ` Dmytro Prokopchuk1
2025-07-15 10:39 ` Jan Beulich
@ 2025-07-15 10:50 ` Jan Beulich
2025-07-16 16:04 ` Dmytro Prokopchuk1
1 sibling, 1 reply; 23+ messages in thread
From: Jan Beulich @ 2025-07-15 10:50 UTC (permalink / raw)
To: Dmytro Prokopchuk1
Cc: xen-devel@lists.xenproject.org, Doug Goldstein,
Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel,
Julien Grall, Roger Pau Monné, Nicola Vetrini,
Stefano Stabellini
On 15.07.2025 12:07, Dmytro Prokopchuk1 wrote:
> ARM only are:
> -config=MC3A2.R5.5,reports+={deliberate,
> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
This one's probably fine.
> -config=MC3A2.R5.5,reports+={deliberate,
> "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"}
These two look too broad: They're affecting common/grant_table.c only, aren't
they?
> -config=MC3A2.R5.5,reports+={deliberate,
> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
This one also looks overly broad, but it's perhaps unavoidable to be that way.
Jan
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5
2025-07-15 10:50 ` Jan Beulich
@ 2025-07-16 16:04 ` Dmytro Prokopchuk1
2025-07-16 16:20 ` Jan Beulich
2025-07-16 16:52 ` Nicola Vetrini
0 siblings, 2 replies; 23+ messages in thread
From: Dmytro Prokopchuk1 @ 2025-07-16 16:04 UTC (permalink / raw)
To: Jan Beulich
Cc: xen-devel@lists.xenproject.org, Doug Goldstein,
Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel,
Julien Grall, Roger Pau Monné, Nicola Vetrini,
Stefano Stabellini
On 7/15/25 13:50, Jan Beulich wrote:
> On 15.07.2025 12:07, Dmytro Prokopchuk1 wrote:
>> ARM only are:
>> -config=MC3A2.R5.5,reports+={deliberate,
>> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
>
> This one's probably fine.
>
>> -config=MC3A2.R5.5,reports+={deliberate,
>> "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"}
>> -config=MC3A2.R5.5,reports+={deliberate,
>> "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"}
>
> These two look too broad: They're affecting common/grant_table.c only, aren't
> they?
>
>> -config=MC3A2.R5.5,reports+={deliberate,
>> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
>
> This one also looks overly broad, but it's perhaps unavoidable to be that way.
>
> Jan
Hi Jan.
Those deviations can be narrowed (specifying file name):
-config=MC3A2.R5.5,reports+={deliberate,
"any_area(any_loc(file(^xen/include/xen/bitops\\.h$)) &&
macro(name(__test_and_set_bit||__test_and_clear_bit||__test_and_change_bit||test_bit)))"}
-config=MC3A2.R5.5,reports+={deliberate,
"any_area(any_loc(file(^xen/common/grant_table\\.c$))&¯o(name(update_gnttab_par||parse_gnttab_limit)))"}
-config=MC3A2.R5.5,reports+={deliberate,
"any_area(any_loc(file(^xen/include/xen/irq\\.h$))&¯o(name(pirq_cleanup_check)))"}
Are you OK with it?
Dmytro.
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5
2025-07-16 16:04 ` Dmytro Prokopchuk1
@ 2025-07-16 16:20 ` Jan Beulich
2025-07-16 16:52 ` Nicola Vetrini
1 sibling, 0 replies; 23+ messages in thread
From: Jan Beulich @ 2025-07-16 16:20 UTC (permalink / raw)
To: Dmytro Prokopchuk1
Cc: xen-devel@lists.xenproject.org, Doug Goldstein,
Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel,
Julien Grall, Roger Pau Monné, Nicola Vetrini,
Stefano Stabellini
On 16.07.2025 18:04, Dmytro Prokopchuk1 wrote:
>
>
> On 7/15/25 13:50, Jan Beulich wrote:
>> On 15.07.2025 12:07, Dmytro Prokopchuk1 wrote:
>>> ARM only are:
>>> -config=MC3A2.R5.5,reports+={deliberate,
>>> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
>>
>> This one's probably fine.
>>
>>> -config=MC3A2.R5.5,reports+={deliberate,
>>> "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"}
>>> -config=MC3A2.R5.5,reports+={deliberate,
>>> "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"}
>>
>> These two look too broad: They're affecting common/grant_table.c only, aren't
>> they?
>>
>>> -config=MC3A2.R5.5,reports+={deliberate,
>>> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
>>
>> This one also looks overly broad, but it's perhaps unavoidable to be that way.
>
> Those deviations can be narrowed (specifying file name):
>
> -config=MC3A2.R5.5,reports+={deliberate,
> "any_area(any_loc(file(^xen/include/xen/bitops\\.h$)) &&
> macro(name(__test_and_set_bit||__test_and_clear_bit||__test_and_change_bit||test_bit)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "any_area(any_loc(file(^xen/common/grant_table\\.c$))&¯o(name(update_gnttab_par||parse_gnttab_limit)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "any_area(any_loc(file(^xen/include/xen/irq\\.h$))&¯o(name(pirq_cleanup_check)))"}
>
> Are you OK with it?
This looks acceptable to me, yes.
Jan
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5
2025-07-16 16:04 ` Dmytro Prokopchuk1
2025-07-16 16:20 ` Jan Beulich
@ 2025-07-16 16:52 ` Nicola Vetrini
2025-07-16 18:03 ` Dmytro Prokopchuk1
1 sibling, 1 reply; 23+ messages in thread
From: Nicola Vetrini @ 2025-07-16 16:52 UTC (permalink / raw)
To: Dmytro Prokopchuk1
Cc: Jan Beulich, xen-devel, Doug Goldstein, Stefano Stabellini,
Andrew Cooper, Anthony PERARD, Michal Orzel, Julien Grall,
Roger Pau Monné, Stefano Stabellini
On 2025-07-16 18:04, Dmytro Prokopchuk1 wrote:
> On 7/15/25 13:50, Jan Beulich wrote:
>> On 15.07.2025 12:07, Dmytro Prokopchuk1 wrote:
>>> ARM only are:
>>> -config=MC3A2.R5.5,reports+={deliberate,
>>> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
>>
>> This one's probably fine.
>>
>>> -config=MC3A2.R5.5,reports+={deliberate,
>>> "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"}
>>> -config=MC3A2.R5.5,reports+={deliberate,
>>> "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"}
>>
>> These two look too broad: They're affecting common/grant_table.c only,
>> aren't
>> they?
>>
>>> -config=MC3A2.R5.5,reports+={deliberate,
>>> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"}
>>
>> This one also looks overly broad, but it's perhaps unavoidable to be
>> that way.
>>
>> Jan
>
> Hi Jan.
>
> Those deviations can be narrowed (specifying file name):
>
> -config=MC3A2.R5.5,reports+={deliberate,
> "any_area(any_loc(file(^xen/include/xen/bitops\\.h$)) &&
> macro(name(__test_and_set_bit||__test_and_clear_bit||__test_and_change_bit||test_bit)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "any_area(any_loc(file(^xen/common/grant_table\\.c$))&¯o(name(update_gnttab_par||parse_gnttab_limit)))"}
> -config=MC3A2.R5.5,reports+={deliberate,
> "any_area(any_loc(file(^xen/include/xen/irq\\.h$))&¯o(name(pirq_cleanup_check)))"}
>
> Are you OK with it?
>
s/any_loc/all_loc/ ? I don't expect these reports to have locations
outside those header files, so this should have the same effect but with
a narrower deviation.
> Dmytro.
--
Nicola Vetrini, B.Sc.
Software Engineer
BUGSENG (https://bugseng.com)
LinkedIn: https://www.linkedin.com/in/nicola-vetrini-a42471253
^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5
2025-07-16 16:52 ` Nicola Vetrini
@ 2025-07-16 18:03 ` Dmytro Prokopchuk1
0 siblings, 0 replies; 23+ messages in thread
From: Dmytro Prokopchuk1 @ 2025-07-16 18:03 UTC (permalink / raw)
To: Nicola Vetrini
Cc: Jan Beulich, xen-devel@lists.xenproject.org, Doug Goldstein,
Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel,
Julien Grall, Roger Pau Monné, Stefano Stabellini
On 7/16/25 19:52, Nicola Vetrini wrote:
> On 2025-07-16 18:04, Dmytro Prokopchuk1 wrote:
>> On 7/15/25 13:50, Jan Beulich wrote:
>>> On 15.07.2025 12:07, Dmytro Prokopchuk1 wrote:
>>>> ARM only are:
>>>> -config=MC3A2.R5.5,reports+={deliberate,
>>>> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"}
>>>
>>> This one's probably fine.
>>>
>>>> -config=MC3A2.R5.5,reports+={deliberate,
>>>> "all_area(decl(name(parse_gnttab_limit))||
>>>> macro(name(parse_gnttab_limit)))"}
>>>> -config=MC3A2.R5.5,reports+={deliberate,
>>>> "all_area(decl(name(update_gnttab_par))||
>>>> macro(name(update_gnttab_par)))"}
>>>
>>> These two look too broad: They're affecting common/grant_table.c
>>> only, aren't
>>> they?
>>>
>>>> -config=MC3A2.R5.5,reports+={deliberate,
>>>> "all_area(decl(name(pirq_cleanup_check))||
>>>> macro(name(pirq_cleanup_check)))"}
>>>
>>> This one also looks overly broad, but it's perhaps unavoidable to be
>>> that way.
>>>
>>> Jan
>>
>> Hi Jan.
>>
>> Those deviations can be narrowed (specifying file name):
>>
>> -config=MC3A2.R5.5,reports+={deliberate,
>> "any_area(any_loc(file(^xen/include/xen/bitops\\.h$)) &&
>> macro(name(__test_and_set_bit||__test_and_clear_bit||
>> __test_and_change_bit||test_bit)))"}
>> -config=MC3A2.R5.5,reports+={deliberate,
>> "any_area(any_loc(file(^xen/common/grant_table\
>> \.c$))&¯o(name(update_gnttab_par||parse_gnttab_limit)))"}
>> -config=MC3A2.R5.5,reports+={deliberate,
>> "any_area(any_loc(file(^xen/include/xen/irq\
>> \.h$))&¯o(name(pirq_cleanup_check)))"}
>>
>> Are you OK with it?
>>
>
> s/any_loc/all_loc/ ? I don't expect these reports to have locations
> outside those header files, so this should have the same effect but with
> a narrower deviation.
Thanks, Nicola.
I updated my patch.
>
>> Dmytro.
>
^ permalink raw reply [flat|nested] 23+ messages in thread
end of thread, other threads:[~2025-07-16 18:04 UTC | newest]
Thread overview: 23+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-07-09 21:38 [XEN PATCH v2 0/3] address violation of MISRA C Rule 5.5 Dmytro Prokopchuk1
2025-07-09 21:38 ` [XEN PATCH v2 1/3] iommu: " Dmytro Prokopchuk1
2025-07-10 8:21 ` Jan Beulich
2025-07-10 9:44 ` Dmytro Prokopchuk1
2025-07-10 9:47 ` Dmytro Prokopchuk1
2025-07-09 21:38 ` [XEN PATCH v2 2/3] device-tree: " Dmytro Prokopchuk1
2025-07-09 21:38 ` [XEN PATCH v2 3/3] eclair: add deviations " Dmytro Prokopchuk1
2025-07-11 2:17 ` Stefano Stabellini
2025-07-11 8:28 ` Nicola Vetrini
2025-07-12 1:13 ` Stefano Stabellini
2025-07-12 7:45 ` Nicola Vetrini
2025-07-14 7:55 ` Jan Beulich
2025-07-15 9:46 ` Dmytro Prokopchuk1
2025-07-15 10:01 ` Jan Beulich
2025-07-15 10:07 ` Dmytro Prokopchuk1
2025-07-15 10:39 ` Jan Beulich
2025-07-15 10:45 ` Dmytro Prokopchuk1
2025-07-15 10:50 ` Jan Beulich
2025-07-16 16:04 ` Dmytro Prokopchuk1
2025-07-16 16:20 ` Jan Beulich
2025-07-16 16:52 ` Nicola Vetrini
2025-07-16 18:03 ` Dmytro Prokopchuk1
2025-07-09 21:55 ` [XEN PATCH v2 0/3] address violation " Dmytro Prokopchuk1
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.