All of lore.kernel.org
 help / color / mirror / Atom feed
From: Markus Armbruster <armbru@redhat.com>
To: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
Cc: qemu-devel@nongnu.org,  odaki@rsg.ci.i.u-tokyo.ac.jp,
	marcandre.lureau@redhat.com,  berrange@redhat.com,
	richard.henderson@linaro.org,
	 Jagannathan Raman <jag.raman@oracle.com>
Subject: Re: [PATCH v3 05/13] hw/remote/vfio-user: Clean up error reporting
Date: Fri, 26 Sep 2025 08:51:08 +0200	[thread overview]
Message-ID: <878qi1so4j.fsf@pond.sub.org> (raw)
In-Reply-To: <1a10e0d3-17fc-4ec9-aa4c-cdfed13988e6@yandex-team.ru> (Vladimir Sementsov-Ogievskiy's message of "Tue, 23 Sep 2025 13:14:23 +0300")

Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru> writes:

> On 23.09.25 12:09, Markus Armbruster wrote:
>> VFU_OBJECT_ERROR() reports the error with error_setg(&error_abort,
>> ...) when auto-shutdown is enabled, else with error_report().
>>
>> Issues:
>>
>> 1. The error is serious enough to warrant aborting the process when
>> auto-shutdown is enabled, yet harmless enough to permit carrying on
>> when it's disabled.  This makes no sense to me.
>>
>> 2. Like assert(), &error_abort is strictly for programming errors.  Is
>> this one?
>
> Brief look at the code make me think that, no it isn't.

So the use of &error_abort is wrong.

>>  Or should we exit(1) instead?
>>
>> 3. qapi/error.h advises "don't error_setg(&error_abort, ...), use
>> assert()."
>>
>> This patch addresses just 3.
>>
>> Cc: Jagannathan Raman <jag.raman@oracle.com>
>> Signed-off-by: Markus Armbruster <armbru@redhat.com>
>> ---
>>   hw/remote/vfio-user-obj.c | 9 +++------
>>   1 file changed, 3 insertions(+), 6 deletions(-)
>> diff --git a/hw/remote/vfio-user-obj.c b/hw/remote/vfio-user-obj.c
>> index ea6165ebdc..eb96982a3a 100644
>> --- a/hw/remote/vfio-user-obj.c
>> +++ b/hw/remote/vfio-user-obj.c
>> @@ -75,12 +75,9 @@ OBJECT_DECLARE_TYPE(VfuObject, VfuObjectClass, VFU_OBJECT)
>>    */
>>   #define VFU_OBJECT_ERROR(o, fmt, ...)                                     \
>>       {                                                                     \
>> -        if (vfu_object_auto_shutdown()) {                                 \
>> -            error_setg(&error_abort, (fmt), ## __VA_ARGS__);              \
>> -        } else {                                                          \
>> -            error_report((fmt), ## __VA_ARGS__);                          \
>> -        }                                                                 \
>> -    }                                                                     \
>> +        error_report((fmt), ## __VA_ARGS__);                              \
>> +        assert(!vfu_object_auto_shutdown());                              \
>
> Probably, it's only my feeling, but for me, assert() is really strictly bound
> to programming errors, more than abort(). Using abort() for errors which are
> not programming, but we can't handle them looks less confusing, i.e.
>
> if (vfu_object_auto_shutdown()) {
>     abort();
> }

assert(COND) is if (COND) abort() plus a message meant to help
developers.  Both are for programming errors.  If it isn't something
that needs debugging, why dump core?

But this particular error condition is *not* a programming error.  So

        assert(!vfu_object_auto_shutdown());

and

        if (vfu_object_auto_shutdown()) {
            abort();
        }

are both equally wrong.  However, the latter makes it easier to add a
FIXME comment:

        if (vfu_object_auto_shutdown()) {
            /*
             * FIXME This looks inappropriate.  The error is serious
             * enough programming error to warrant aborting the process
             * when auto-shutdown is enabled, yet harmless enough to
             * permit carrying on when it's disabled.  Makes no sense.
             */
            abort();
        }

The commit message would then need a tweak.  Perhaps

  Issues:

  1. The error is serious enough to warrant killing the process when
  auto-shutdown is enabled, yet harmless enough to permit carrying on
  when it's disabled.  This makes no sense to me.

  2. Like assert(), &error_abort is strictly for programming errors.  Is
  this one?  Vladimir Sementsov-Ogievskiy tells me it's not.

  3. qapi/error.h advises "don't error_setg(&error_abort, ...), use
  assert()."

  This patch addresses just 3.  It adds a FIXME comment for the other
  two.

Thoughts?

> Not really matter. Anyway:
>
> Reviewed-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>

Thanks!

>> +    }
>>     struct VfuObjectClass {
>>       ObjectClass parent_class;



  reply	other threads:[~2025-09-26  6:52 UTC|newest]

Thread overview: 28+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-09-23  9:09 [PATCH v3 00/13] Error reporting cleanup, a fix, and &error_warn removal Markus Armbruster
2025-09-23  9:09 ` [PATCH v3 01/13] monitor: Clean up HMP gdbserver error reporting Markus Armbruster
2025-09-23  9:54   ` Philippe Mathieu-Daudé
2025-09-23 11:08     ` Markus Armbruster
2025-09-23  9:09 ` [PATCH v3 02/13] tcg: Fix error reporting on mprotect() failure in tcg_region_init() Markus Armbruster
2025-09-23  9:41   ` Philippe Mathieu-Daudé
2025-09-23 11:16     ` Markus Armbruster
2025-09-23 12:40       ` Philippe Mathieu-Daudé
2025-09-23  9:09 ` [PATCH v3 03/13] hw/cxl: Convert cxl_fmws_link() to Error Markus Armbruster
2025-09-23  9:09 ` [PATCH v3 04/13] migration/cpr: Clean up error reporting in cpr_resave_fd() Markus Armbruster
2025-09-23  9:09 ` [PATCH v3 05/13] hw/remote/vfio-user: Clean up error reporting Markus Armbruster
2025-09-23  9:25   ` Philippe Mathieu-Daudé
2025-09-23 10:14   ` Vladimir Sementsov-Ogievskiy
2025-09-26  6:51     ` Markus Armbruster [this message]
2025-09-30  8:02       ` Vladimir Sementsov-Ogievskiy
2025-09-30  8:21         ` Markus Armbruster
2025-09-23  9:09 ` [PATCH v3 06/13] net/slirp: " Markus Armbruster
2025-09-23  9:09 ` [PATCH v3 07/13] ui/spice-core: " Markus Armbruster
2025-09-23  9:09 ` [PATCH v3 08/13] util/oslib-win32: Do not treat null @errp as &error_warn Markus Armbruster
2025-09-23  9:19   ` Philippe Mathieu-Daudé
2025-09-23  9:09 ` [PATCH v3 09/13] ui/pixman: Consistent error handling in qemu_pixman_shareable_free() Markus Armbruster
2025-09-23  9:09 ` [PATCH v3 10/13] ui/dbus: Clean up dbus_update_gl_cb() error checking Markus Armbruster
2025-09-23  9:21   ` Philippe Mathieu-Daudé
2025-09-23  9:09 ` [PATCH v3 11/13] ui/dbus: Consistent handling of texture mutex failure Markus Armbruster
2025-09-23  9:09 ` [PATCH v3 12/13] ivshmem-flat: Mark an instance of missing error handling FIXME Markus Armbruster
2025-09-23 10:22   ` Vladimir Sementsov-Ogievskiy
2025-09-23  9:10 ` [PATCH v3 13/13] error: Kill @error_warn Markus Armbruster
2025-09-24  1:29 ` [PATCH v3 00/13] Error reporting cleanup, a fix, and &error_warn removal Akihiko Odaki

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=878qi1so4j.fsf@pond.sub.org \
    --to=armbru@redhat.com \
    --cc=berrange@redhat.com \
    --cc=jag.raman@oracle.com \
    --cc=marcandre.lureau@redhat.com \
    --cc=odaki@rsg.ci.i.u-tokyo.ac.jp \
    --cc=qemu-devel@nongnu.org \
    --cc=richard.henderson@linaro.org \
    --cc=vsementsov@yandex-team.ru \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.