* [XEN PATCH v2 0/3] address violation of MISRA C Rule 5.5
@ 2025-07-09 21:38 Dmytro Prokopchuk1
2025-07-09 21:38 ` [XEN PATCH v2 1/3] iommu: " Dmytro Prokopchuk1
` (3 more replies)
0 siblings, 4 replies; 23+ messages in thread
From: Dmytro Prokopchuk1 @ 2025-07-09 21:38 UTC (permalink / raw)
To: xen-devel@lists.xenproject.org
Cc: Dmytro Prokopchuk1, Jan Beulich, Roger Pau Monné,
Stefano Stabellini, Julien Grall, Bertrand Marquis, Michal Orzel,
Andrew Cooper, Anthony PERARD, Nicola Vetrini, Doug Goldstein
This patch series eliminates/deviates MISRA C Rule 5.5 violations for ARM64.
Thread discussion:
https://patchew.org/Xen/cover.1751659393.git.dmytro._5Fprokopchuk1@epam.com/
Changes in v2:
- fixed code alignment in "device-tree: address violation of MISRA C Rule 5.5"
- updated commit message in "iommu: address violation of MISRA C Rule 5.5"
- other patches were squashed and MISRA rule was deviated
Dmytro Prokopchuk (3):
iommu: address violation of MISRA C Rule 5.5
device-tree: address violation of MISRA C Rule 5.5
eclair: add deviations of MISRA C Rule 5.5
automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++
docs/misra/deviations.rst | 8 ++++++++
xen/common/device-tree/domain-build.c | 13 ++++++-------
xen/include/xen/fdt-domain-build.h | 4 ++--
xen/include/xen/iommu.h | 2 ++
5 files changed, 26 insertions(+), 9 deletions(-)
--
2.43.0
^ permalink raw reply [flat|nested] 23+ messages in thread* [XEN PATCH v2 1/3] iommu: address violation of MISRA C Rule 5.5 2025-07-09 21:38 [XEN PATCH v2 0/3] address violation of MISRA C Rule 5.5 Dmytro Prokopchuk1 @ 2025-07-09 21:38 ` Dmytro Prokopchuk1 2025-07-10 8:21 ` Jan Beulich 2025-07-09 21:38 ` [XEN PATCH v2 2/3] device-tree: " Dmytro Prokopchuk1 ` (2 subsequent siblings) 3 siblings, 1 reply; 23+ messages in thread From: Dmytro Prokopchuk1 @ 2025-07-09 21:38 UTC (permalink / raw) To: xen-devel@lists.xenproject.org Cc: Dmytro Prokopchuk1, Jan Beulich, Roger Pau Monné Address a violation of MISRA C:2012 Rule 5.5: "Identifiers shall be distinct from macro names". Reports for service MC3A2.R5.5: xen/drivers/passthrough/iommu.c: non-compliant macro 'iommu_quarantine' xen/include/xen/iommu.h: non-compliant variable 'iommu_quarantine' There is a clash between function name and macro. Add an 'extern' declaration for 'iommu_quarantine' under the same preprocessor condition (#ifdef CONFIG_HAS_PCI). This ensures that the declaration is consistent and only exposed when CONFIG_HAS_PCI is defined. Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com> --- xen/include/xen/iommu.h | 2 ++ 1 file changed, 2 insertions(+) diff --git a/xen/include/xen/iommu.h b/xen/include/xen/iommu.h index 3205e49990..57f338e2a0 100644 --- a/xen/include/xen/iommu.h +++ b/xen/include/xen/iommu.h @@ -53,7 +53,9 @@ static inline bool dfn_eq(dfn_t x, dfn_t y) extern bool iommu_enable, iommu_enabled; extern bool force_iommu, iommu_verbose; /* Boolean except for the specific purposes of drivers/passthrough/iommu.c. */ +#ifdef CONFIG_HAS_PCI extern uint8_t iommu_quarantine; +#endif /* CONFIG_HAS_PCI */ #else #define iommu_enabled false #endif -- 2.43.0 ^ permalink raw reply related [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 1/3] iommu: address violation of MISRA C Rule 5.5 2025-07-09 21:38 ` [XEN PATCH v2 1/3] iommu: " Dmytro Prokopchuk1 @ 2025-07-10 8:21 ` Jan Beulich 2025-07-10 9:44 ` Dmytro Prokopchuk1 0 siblings, 1 reply; 23+ messages in thread From: Jan Beulich @ 2025-07-10 8:21 UTC (permalink / raw) To: Dmytro Prokopchuk1; +Cc: Roger Pau Monné, xen-devel@lists.xenproject.org On 09.07.2025 23:38, Dmytro Prokopchuk1 wrote: > Address a violation of MISRA C:2012 Rule 5.5: > "Identifiers shall be distinct from macro names". > > Reports for service MC3A2.R5.5: > xen/drivers/passthrough/iommu.c: non-compliant macro 'iommu_quarantine' > xen/include/xen/iommu.h: non-compliant variable 'iommu_quarantine' > > There is a clash between function name and macro. > Add an 'extern' declaration for 'iommu_quarantine' > under the same preprocessor condition (#ifdef CONFIG_HAS_PCI). Perhaps s/Add an/Put the/ or some such? You don't add any declaration, after all. > This ensures that the declaration is consistent > and only exposed when CONFIG_HAS_PCI is defined. > > Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com> With some suitable adjustment (happy to make while committing as long as you agree): Reviewed-by: Jan Beulich <jbeulich@suse.com> Jan ^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 1/3] iommu: address violation of MISRA C Rule 5.5 2025-07-10 8:21 ` Jan Beulich @ 2025-07-10 9:44 ` Dmytro Prokopchuk1 2025-07-10 9:47 ` Dmytro Prokopchuk1 0 siblings, 1 reply; 23+ messages in thread From: Dmytro Prokopchuk1 @ 2025-07-10 9:44 UTC (permalink / raw) To: Jan Beulich; +Cc: Roger Pau Monné, xen-devel@lists.xenproject.org Yes, sure. I'll update commit message. Thanks! On 7/10/25 11:21, Jan Beulich wrote: > On 09.07.2025 23:38, Dmytro Prokopchuk1 wrote: >> Address a violation of MISRA C:2012 Rule 5.5: >> "Identifiers shall be distinct from macro names". >> >> Reports for service MC3A2.R5.5: >> xen/drivers/passthrough/iommu.c: non-compliant macro 'iommu_quarantine' >> xen/include/xen/iommu.h: non-compliant variable 'iommu_quarantine' >> >> There is a clash between function name and macro. >> Add an 'extern' declaration for 'iommu_quarantine' >> under the same preprocessor condition (#ifdef CONFIG_HAS_PCI). > > Perhaps s/Add an/Put the/ or some such? You don't add any declaration, > after all. > >> This ensures that the declaration is consistent >> and only exposed when CONFIG_HAS_PCI is defined. >> >> Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com> > > With some suitable adjustment (happy to make while committing as long as > you agree): > Reviewed-by: Jan Beulich <jbeulich@suse.com> > > Jan ^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 1/3] iommu: address violation of MISRA C Rule 5.5 2025-07-10 9:44 ` Dmytro Prokopchuk1 @ 2025-07-10 9:47 ` Dmytro Prokopchuk1 0 siblings, 0 replies; 23+ messages in thread From: Dmytro Prokopchuk1 @ 2025-07-10 9:47 UTC (permalink / raw) To: Jan Beulich; +Cc: Roger Pau Monné, xen-devel@lists.xenproject.org Jan, I don't mind, you can adjust it. Please, go ahead. On 7/10/25 12:44, Dmytro Prokopchuk wrote: > Yes, sure. I'll update commit message. > Thanks! > > On 7/10/25 11:21, Jan Beulich wrote: >> On 09.07.2025 23:38, Dmytro Prokopchuk1 wrote: >>> Address a violation of MISRA C:2012 Rule 5.5: >>> "Identifiers shall be distinct from macro names". >>> >>> Reports for service MC3A2.R5.5: >>> xen/drivers/passthrough/iommu.c: non-compliant macro 'iommu_quarantine' >>> xen/include/xen/iommu.h: non-compliant variable 'iommu_quarantine' >>> >>> There is a clash between function name and macro. >>> Add an 'extern' declaration for 'iommu_quarantine' >>> under the same preprocessor condition (#ifdef CONFIG_HAS_PCI). >> >> Perhaps s/Add an/Put the/ or some such? You don't add any declaration, >> after all. >> >>> This ensures that the declaration is consistent >>> and only exposed when CONFIG_HAS_PCI is defined. >>> >>> Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com> >> >> With some suitable adjustment (happy to make while committing as long as >> you agree): >> Reviewed-by: Jan Beulich <jbeulich@suse.com> >> >> Jan > ^ permalink raw reply [flat|nested] 23+ messages in thread
* [XEN PATCH v2 2/3] device-tree: address violation of MISRA C Rule 5.5 2025-07-09 21:38 [XEN PATCH v2 0/3] address violation of MISRA C Rule 5.5 Dmytro Prokopchuk1 2025-07-09 21:38 ` [XEN PATCH v2 1/3] iommu: " Dmytro Prokopchuk1 @ 2025-07-09 21:38 ` Dmytro Prokopchuk1 2025-07-09 21:38 ` [XEN PATCH v2 3/3] eclair: add deviations " Dmytro Prokopchuk1 2025-07-09 21:55 ` [XEN PATCH v2 0/3] address violation " Dmytro Prokopchuk1 3 siblings, 0 replies; 23+ messages in thread From: Dmytro Prokopchuk1 @ 2025-07-09 21:38 UTC (permalink / raw) To: xen-devel@lists.xenproject.org Cc: Dmytro Prokopchuk1, Stefano Stabellini, Julien Grall, Bertrand Marquis, Michal Orzel, Andrew Cooper, Anthony PERARD, Jan Beulich, Roger Pau Monné Address a violation of MISRA C:2012 Rule 5.5: "Identifiers shall be distinct from macro names". Reports for service MC3A2.R5.5: xen/include/xen/fdt-domain-build.h: non-compliant parameter 'copy_to_guest' xen/include/xen/guest_access.h: non-compliant macro 'copy_to_guest' Rename 'copy_to_guest' function parameter to 'cb' for compliance. No functional changes. Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com> Reviewed-by: Stefano Stabellini <sstabellini@kernel.org> --- xen/common/device-tree/domain-build.c | 13 ++++++------- xen/include/xen/fdt-domain-build.h | 4 ++-- 2 files changed, 8 insertions(+), 9 deletions(-) diff --git a/xen/common/device-tree/domain-build.c b/xen/common/device-tree/domain-build.c index e6d7b8961e..4eea095e49 100644 --- a/xen/common/device-tree/domain-build.c +++ b/xen/common/device-tree/domain-build.c @@ -336,7 +336,7 @@ void __init allocate_memory(struct domain *d, struct kernel_info *kinfo) } void __init dtb_load(struct kernel_info *kinfo, - copy_to_guest_phys_cb copy_to_guest) + copy_to_guest_phys_cb cb) { unsigned long left; @@ -344,9 +344,9 @@ void __init dtb_load(struct kernel_info *kinfo, kinfo->d, kinfo->dtb_paddr, kinfo->dtb_paddr + fdt_totalsize(kinfo->fdt)); - left = copy_to_guest(kinfo->d, kinfo->dtb_paddr, - kinfo->fdt, - fdt_totalsize(kinfo->fdt)); + left = cb(kinfo->d, kinfo->dtb_paddr, + kinfo->fdt, + fdt_totalsize(kinfo->fdt)); if ( left != 0 ) panic("Unable to copy the DTB to %pd memory (left = %lu bytes)\n", @@ -355,7 +355,7 @@ void __init dtb_load(struct kernel_info *kinfo, } void __init initrd_load(struct kernel_info *kinfo, - copy_to_guest_phys_cb copy_to_guest) + copy_to_guest_phys_cb cb) { const struct boot_module *mod = kinfo->initrd; paddr_t load_addr = kinfo->initrd_paddr; @@ -398,8 +398,7 @@ void __init initrd_load(struct kernel_info *kinfo, if ( !initrd ) panic("Unable to map the %pd initrd\n", kinfo->d); - res = copy_to_guest(kinfo->d, load_addr, - initrd, len); + res = cb(kinfo->d, load_addr, initrd, len); if ( res != 0 ) panic("Unable to copy the initrd in the %pd memory\n", kinfo->d); diff --git a/xen/include/xen/fdt-domain-build.h b/xen/include/xen/fdt-domain-build.h index 45981dbec0..3a20623cf5 100644 --- a/xen/include/xen/fdt-domain-build.h +++ b/xen/include/xen/fdt-domain-build.h @@ -50,10 +50,10 @@ typedef unsigned long (*copy_to_guest_phys_cb)(struct domain *d, unsigned int len); void initrd_load(struct kernel_info *kinfo, - copy_to_guest_phys_cb copy_to_guest); + copy_to_guest_phys_cb cb); void dtb_load(struct kernel_info *kinfo, - copy_to_guest_phys_cb copy_to_guest); + copy_to_guest_phys_cb cb); int find_unallocated_memory(const struct kernel_info *kinfo, const struct membanks *mem_banks[], -- 2.43.0 ^ permalink raw reply related [flat|nested] 23+ messages in thread
* [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5 2025-07-09 21:38 [XEN PATCH v2 0/3] address violation of MISRA C Rule 5.5 Dmytro Prokopchuk1 2025-07-09 21:38 ` [XEN PATCH v2 1/3] iommu: " Dmytro Prokopchuk1 2025-07-09 21:38 ` [XEN PATCH v2 2/3] device-tree: " Dmytro Prokopchuk1 @ 2025-07-09 21:38 ` Dmytro Prokopchuk1 2025-07-11 2:17 ` Stefano Stabellini 2025-07-11 8:28 ` Nicola Vetrini 2025-07-09 21:55 ` [XEN PATCH v2 0/3] address violation " Dmytro Prokopchuk1 3 siblings, 2 replies; 23+ messages in thread From: Dmytro Prokopchuk1 @ 2025-07-09 21:38 UTC (permalink / raw) To: xen-devel@lists.xenproject.org Cc: Dmytro Prokopchuk1, Nicola Vetrini, Doug Goldstein, Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel, Jan Beulich, Julien Grall, Roger Pau Monné MISRA C Rule 5.5 states that: "Identifiers shall be distinct from macro names". Update ECLAIR configuration to deviate: - clashes in 'xen/include/xen/bitops.h'; - clashes in 'xen/include/xen/irq.h'; - clashes in 'xen/common/grant_table.c'. Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com> --- automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++ docs/misra/deviations.rst | 8 ++++++++ 2 files changed, 16 insertions(+) diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl b/automation/eclair_analysis/ECLAIR/deviations.ecl index e8f513fbc5..a5d7b00094 100644 --- a/automation/eclair_analysis/ECLAIR/deviations.ecl +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl @@ -117,6 +117,14 @@ it defines would (in the common case) be already defined. Peer reviewed by the c -config=MC3A2.R5.5,reports+={deliberate, "any_area(decl(kind(function))||any_loc(macro(name(memcpy||memset||memmove))))&&any_area(any_loc(file(^xen/common/libelf/libelf-private\\.h$)))"} -doc_end +-doc_begin="Clashes between function names and macros are deliberate for bitops functions, pirq_cleanup_check, update_gnttab_par and parse_gnttab_limit functions +and needed to have a function-like macro that acts as a wrapper for the function to be called. Before calling the function, +the macro adds additional checks or adjusts the number of parameters depending on the configuration." +-config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} +-config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/irq\\.h$))&&context(name(pirq_cleanup_check)&&kind(function)))"} +-config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/common/grant_table\\.c$))&&context(name(update_gnttab_par||parse_gnttab_limit)&&kind(function)))"} +-doc_end + -doc_begin="The type \"ret_t\" is deliberately defined multiple times, depending on the guest." -config=MC3A2.R5.6,reports+={deliberate,"any_area(any_loc(text(^.*ret_t.*$)))"} diff --git a/docs/misra/deviations.rst b/docs/misra/deviations.rst index 0d56d45b66..fe05e4062e 100644 --- a/docs/misra/deviations.rst +++ b/docs/misra/deviations.rst @@ -142,6 +142,14 @@ Deviations related to MISRA C:2012 Rules: memmove. - Tagged as `deliberate` for ECLAIR. + * - R5.5 + - Clashes between function names and macros are deliberate for bitops functions, + pirq_cleanup_check, update_gnttab_par and parse_gnttab_limit functions and needed + to have a function-like macro that acts as a wrapper for the function to be + called. Before calling the function, the macro adds additional checks or + adjusts the number of parameters depending on the configuration. + - Tagged as `deliberate` for ECLAIR. + * - R5.6 - The type ret_t is deliberately defined multiple times depending on the type of guest to service. -- 2.43.0 ^ permalink raw reply related [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5 2025-07-09 21:38 ` [XEN PATCH v2 3/3] eclair: add deviations " Dmytro Prokopchuk1 @ 2025-07-11 2:17 ` Stefano Stabellini 2025-07-11 8:28 ` Nicola Vetrini 1 sibling, 0 replies; 23+ messages in thread From: Stefano Stabellini @ 2025-07-11 2:17 UTC (permalink / raw) To: Dmytro Prokopchuk1 Cc: xen-devel@lists.xenproject.org, Nicola Vetrini, Doug Goldstein, Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel, Jan Beulich, Julien Grall, Roger Pau Monné On Wed, 9 Jul 2025, Dmytro Prokopchuk1 wrote: > MISRA C Rule 5.5 states that: "Identifiers shall > be distinct from macro names". > > Update ECLAIR configuration to deviate: > - clashes in 'xen/include/xen/bitops.h'; > - clashes in 'xen/include/xen/irq.h'; > - clashes in 'xen/common/grant_table.c'. > > Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com> Hi Dmytro, I tried to apply the patch and run a pipeline but it only results clean on ARM but not on x86. There are 2087 outstanding violations: https://gitlab.com/xen-project/people/sstabellini/xen/-/pipelines/1919889048 https://saas.eclairit.com:3787/fs/var/local/eclair/xen-project.ecdf/xen-project/people/sstabellini/xen/ECLAIR_normal/ppp1-1/X86_64/10644506983/PROJECT.ecd;/by_service/MC3A2.R5.5.html#{%22select%22:true,%22selection%22:{%22hiddenAreaKinds%22:[],%22hiddenSubareaKinds%22:[],%22show%22:false,%22selector%22:{%22enabled%22:true,%22negated%22:true,%22kind%22:0,%22domain%22:%22kind%22,%22inputs%22:[{%22enabled%22:true,%22text%22:%22violation%22}]}}} Jan, Andrew, Roger, About half of them are from bitops.h which could be deviated the same way xen/include/xen/bitops.h is deviated in this patch. xen/arch/x86/include/asm/x86_64/page.h:virt_to_maddr could be deviated too. I don't know how to handle the rest or even how to configure the deviation in Eclair. These are the results with those two deviations added: https://saas.eclairit.com:3787/fs/var/local/eclair/xen-project.ecdf/xen-project/people/sstabellini/xen/ECLAIR_normal/ppp1-2/X86_64/10644744316/PROJECT.ecd;/by_service/MC3A2.R5.5.html#{%22select%22:true,%22selection%22:{%22hiddenAreaKinds%22:[],%22hiddenSubareaKinds%22:[],%22show%22:false,%22selector%22:{%22enabled%22:true,%22negated%22:true,%22kind%22:0,%22domain%22:%22kind%22,%22inputs%22:[{%22enabled%22:true,%22text%22:%22violation%22}]}}} We only have 49 left. Any suggestions on how to handle them so that we can mark the rule as "clean" and stop future regressions in the CI loop? > --- > automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++ > docs/misra/deviations.rst | 8 ++++++++ > 2 files changed, 16 insertions(+) > > diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl b/automation/eclair_analysis/ECLAIR/deviations.ecl > index e8f513fbc5..a5d7b00094 100644 > --- a/automation/eclair_analysis/ECLAIR/deviations.ecl > +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl > @@ -117,6 +117,14 @@ it defines would (in the common case) be already defined. Peer reviewed by the c > -config=MC3A2.R5.5,reports+={deliberate, "any_area(decl(kind(function))||any_loc(macro(name(memcpy||memset||memmove))))&&any_area(any_loc(file(^xen/common/libelf/libelf-private\\.h$)))"} > -doc_end > > +-doc_begin="Clashes between function names and macros are deliberate for bitops functions, pirq_cleanup_check, update_gnttab_par and parse_gnttab_limit functions > +and needed to have a function-like macro that acts as a wrapper for the function to be called. Before calling the function, > +the macro adds additional checks or adjusts the number of parameters depending on the configuration." > +-config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} > +-config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/irq\\.h$))&&context(name(pirq_cleanup_check)&&kind(function)))"} > +-config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/common/grant_table\\.c$))&&context(name(update_gnttab_par||parse_gnttab_limit)&&kind(function)))"} > +-doc_end > + > -doc_begin="The type \"ret_t\" is deliberately defined multiple times, > depending on the guest." > -config=MC3A2.R5.6,reports+={deliberate,"any_area(any_loc(text(^.*ret_t.*$)))"} > diff --git a/docs/misra/deviations.rst b/docs/misra/deviations.rst > index 0d56d45b66..fe05e4062e 100644 > --- a/docs/misra/deviations.rst > +++ b/docs/misra/deviations.rst > @@ -142,6 +142,14 @@ Deviations related to MISRA C:2012 Rules: > memmove. > - Tagged as `deliberate` for ECLAIR. > > + * - R5.5 > + - Clashes between function names and macros are deliberate for bitops functions, > + pirq_cleanup_check, update_gnttab_par and parse_gnttab_limit functions and needed > + to have a function-like macro that acts as a wrapper for the function to be > + called. Before calling the function, the macro adds additional checks or > + adjusts the number of parameters depending on the configuration. > + - Tagged as `deliberate` for ECLAIR. > + > * - R5.6 > - The type ret_t is deliberately defined multiple times depending on the > type of guest to service. > -- > 2.43.0 > ^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5 2025-07-09 21:38 ` [XEN PATCH v2 3/3] eclair: add deviations " Dmytro Prokopchuk1 2025-07-11 2:17 ` Stefano Stabellini @ 2025-07-11 8:28 ` Nicola Vetrini 2025-07-12 1:13 ` Stefano Stabellini 1 sibling, 1 reply; 23+ messages in thread From: Nicola Vetrini @ 2025-07-11 8:28 UTC (permalink / raw) To: Dmytro Prokopchuk1 Cc: xen-devel, Doug Goldstein, Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel, Jan Beulich, Julien Grall, Roger Pau Monné On 2025-07-09 23:38, Dmytro Prokopchuk1 wrote: > MISRA C Rule 5.5 states that: "Identifiers shall > be distinct from macro names". > > Update ECLAIR configuration to deviate: > - clashes in 'xen/include/xen/bitops.h'; > - clashes in 'xen/include/xen/irq.h'; > - clashes in 'xen/common/grant_table.c'. > > Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com> > --- > automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++ > docs/misra/deviations.rst | 8 ++++++++ > 2 files changed, 16 insertions(+) > > diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl > b/automation/eclair_analysis/ECLAIR/deviations.ecl > index e8f513fbc5..a5d7b00094 100644 > --- a/automation/eclair_analysis/ECLAIR/deviations.ecl > +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl > @@ -117,6 +117,14 @@ it defines would (in the common case) be already > defined. Peer reviewed by the c > -config=MC3A2.R5.5,reports+={deliberate, > "any_area(decl(kind(function))||any_loc(macro(name(memcpy||memset||memmove))))&&any_area(any_loc(file(^xen/common/libelf/libelf-private\\.h$)))"} > -doc_end > > +-doc_begin="Clashes between function names and macros are deliberate > for bitops functions, pirq_cleanup_check, update_gnttab_par and > parse_gnttab_limit functions > +and needed to have a function-like macro that acts as a wrapper for > the function to be called. Before calling the function, > +the macro adds additional checks or adjusts the number of parameters > depending on the configuration." > +-config=MC3A2.R5.5,reports+={deliberate, > "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} Bitops violations are not inside "xen/include/xen/bitops.h", but rather "xen/arch/x86/include/asm/bitops.h" > +-config=MC3A2.R5.5,reports+={deliberate, > "any_area(all_loc(file(^xen/include/xen/irq\\.h$))&&context(name(pirq_cleanup_check)&&kind(function)))"} I would rather do (untested) -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} > +-config=MC3A2.R5.5,reports+={deliberate, > "any_area(all_loc(file(^xen/common/grant_table\\.c$))&&context(name(update_gnttab_par||parse_gnttab_limit)&&kind(function)))"} > +-doc_end > + same as above > -doc_begin="The type \"ret_t\" is deliberately defined multiple times, > depending on the guest." > > -config=MC3A2.R5.6,reports+={deliberate,"any_area(any_loc(text(^.*ret_t.*$)))"} > diff --git a/docs/misra/deviations.rst b/docs/misra/deviations.rst > index 0d56d45b66..fe05e4062e 100644 > --- a/docs/misra/deviations.rst > +++ b/docs/misra/deviations.rst > @@ -142,6 +142,14 @@ Deviations related to MISRA C:2012 Rules: > memmove. > - Tagged as `deliberate` for ECLAIR. > > + * - R5.5 > + - Clashes between function names and macros are deliberate for > bitops functions, > + pirq_cleanup_check, update_gnttab_par and parse_gnttab_limit > functions and needed > + to have a function-like macro that acts as a wrapper for the > function to be > + called. Before calling the function, the macro adds additional > checks or > + adjusts the number of parameters depending on the > configuration. > + - Tagged as `deliberate` for ECLAIR. > + > * - R5.6 > - The type ret_t is deliberately defined multiple times depending > on the > type of guest to service. -- Nicola Vetrini, B.Sc. Software Engineer BUGSENG (https://bugseng.com) LinkedIn: https://www.linkedin.com/in/nicola-vetrini-a42471253 ^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5 2025-07-11 8:28 ` Nicola Vetrini @ 2025-07-12 1:13 ` Stefano Stabellini 2025-07-12 7:45 ` Nicola Vetrini 2025-07-14 7:55 ` Jan Beulich 0 siblings, 2 replies; 23+ messages in thread From: Stefano Stabellini @ 2025-07-12 1:13 UTC (permalink / raw) To: Nicola Vetrini Cc: Dmytro Prokopchuk1, xen-devel, Doug Goldstein, Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel, Jan Beulich, Julien Grall, Roger Pau Monné On Fri, 11 Jul 2025, Nicola Vetrini wrote: > On 2025-07-09 23:38, Dmytro Prokopchuk1 wrote: > > MISRA C Rule 5.5 states that: "Identifiers shall > > be distinct from macro names". > > > > Update ECLAIR configuration to deviate: > > - clashes in 'xen/include/xen/bitops.h'; > > - clashes in 'xen/include/xen/irq.h'; > > - clashes in 'xen/common/grant_table.c'. > > > > Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com> > > --- > > automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++ > > docs/misra/deviations.rst | 8 ++++++++ > > 2 files changed, 16 insertions(+) > > > > diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl > > b/automation/eclair_analysis/ECLAIR/deviations.ecl > > index e8f513fbc5..a5d7b00094 100644 > > --- a/automation/eclair_analysis/ECLAIR/deviations.ecl > > +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl > > @@ -117,6 +117,14 @@ it defines would (in the common case) be already > > defined. Peer reviewed by the c > > -config=MC3A2.R5.5,reports+={deliberate, > > "any_area(decl(kind(function))||any_loc(macro(name(memcpy||memset||memmove))))&&any_area(any_loc(file(^xen/common/libelf/libelf-private\\.h$)))"} > > -doc_end > > > > +-doc_begin="Clashes between function names and macros are deliberate for > > bitops functions, pirq_cleanup_check, update_gnttab_par and > > parse_gnttab_limit functions > > +and needed to have a function-like macro that acts as a wrapper for the > > function to be called. Before calling the function, > > +the macro adds additional checks or adjusts the number of parameters > > depending on the configuration." > > +-config=MC3A2.R5.5,reports+={deliberate, > > "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} > > Bitops violations are not inside "xen/include/xen/bitops.h", but rather > "xen/arch/x86/include/asm/bitops.h" > > > +-config=MC3A2.R5.5,reports+={deliberate, > > "any_area(all_loc(file(^xen/include/xen/irq\\.h$))&&context(name(pirq_cleanup_check)&&kind(function)))"} > > I would rather do (untested) > > -config=MC3A2.R5.5,reports+={deliberate, > "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} > > > +-config=MC3A2.R5.5,reports+={deliberate, > > "any_area(all_loc(file(^xen/common/grant_table\\.c$))&&context(name(update_gnttab_par||parse_gnttab_limit)&&kind(function)))"} > > +-doc_end > > + > > same as above > Thanks Nicola! The following deviations are enough and sufficient to zero violations on both ARM and x86: -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/bitops\\.h$)))"} -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat\\.c$)))"} -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat/.*$)))"} -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/x86_emulate/.*$)))"} -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/genapic\\.h$)))"} -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"} -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"} -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(virt_to_maddr))||macro(name(virt_to_maddr)))"} -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_px_pminfo))||macro(name(set_px_pminfo)))"} -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_cx_pminfo))||macro(name(set_cx_pminfo)))"} -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"} -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_to_guest_ll))||macro(name(copy_to_guest_ll)))"} -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_from_guest_ll))||macro(name(copy_from_guest_ll)))"} -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(edd_put_string))||macro(name(edd_put_string)))"} -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"} -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(page_list_entry))||macro(name(page_list_entry)))"} -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_physdev_op))||macro(name(do_physdev_op)))"} -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_platform_op))||macro(name(do_platform_op)))"} Jan, are you OK with it? ^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5 2025-07-12 1:13 ` Stefano Stabellini @ 2025-07-12 7:45 ` Nicola Vetrini 2025-07-14 7:55 ` Jan Beulich 1 sibling, 0 replies; 23+ messages in thread From: Nicola Vetrini @ 2025-07-12 7:45 UTC (permalink / raw) To: Stefano Stabellini Cc: Dmytro Prokopchuk1, xen-devel, Doug Goldstein, Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel, Jan Beulich, Julien Grall, Roger Pau Monné On 2025-07-12 03:13, Stefano Stabellini wrote: > On Fri, 11 Jul 2025, Nicola Vetrini wrote: >> On 2025-07-09 23:38, Dmytro Prokopchuk1 wrote: >> > MISRA C Rule 5.5 states that: "Identifiers shall >> > be distinct from macro names". >> > >> > Update ECLAIR configuration to deviate: >> > - clashes in 'xen/include/xen/bitops.h'; >> > - clashes in 'xen/include/xen/irq.h'; >> > - clashes in 'xen/common/grant_table.c'. >> > >> > Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com> >> > --- >> > automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++ >> > docs/misra/deviations.rst | 8 ++++++++ >> > 2 files changed, 16 insertions(+) >> > >> > diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl >> > b/automation/eclair_analysis/ECLAIR/deviations.ecl >> > index e8f513fbc5..a5d7b00094 100644 >> > --- a/automation/eclair_analysis/ECLAIR/deviations.ecl >> > +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl >> > @@ -117,6 +117,14 @@ it defines would (in the common case) be already >> > defined. Peer reviewed by the c >> > -config=MC3A2.R5.5,reports+={deliberate, >> > "any_area(decl(kind(function))||any_loc(macro(name(memcpy||memset||memmove))))&&any_area(any_loc(file(^xen/common/libelf/libelf-private\\.h$)))"} >> > -doc_end >> > >> > +-doc_begin="Clashes between function names and macros are deliberate for >> > bitops functions, pirq_cleanup_check, update_gnttab_par and >> > parse_gnttab_limit functions >> > +and needed to have a function-like macro that acts as a wrapper for the >> > function to be called. Before calling the function, >> > +the macro adds additional checks or adjusts the number of parameters >> > depending on the configuration." >> > +-config=MC3A2.R5.5,reports+={deliberate, >> > "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} >> >> Bitops violations are not inside "xen/include/xen/bitops.h", but >> rather >> "xen/arch/x86/include/asm/bitops.h" >> >> > +-config=MC3A2.R5.5,reports+={deliberate, >> > "any_area(all_loc(file(^xen/include/xen/irq\\.h$))&&context(name(pirq_cleanup_check)&&kind(function)))"} >> >> I would rather do (untested) >> >> -config=MC3A2.R5.5,reports+={deliberate, >> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} >> >> > +-config=MC3A2.R5.5,reports+={deliberate, >> > "any_area(all_loc(file(^xen/common/grant_table\\.c$))&&context(name(update_gnttab_par||parse_gnttab_limit)&&kind(function)))"} >> > +-doc_end >> > + >> >> same as above >> > > Thanks Nicola! The following deviations are enough and sufficient to > zero violations on both ARM and x86: > > -config=MC3A2.R5.5,reports+={deliberate, > "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "any_area(all_loc(file(^xen/arch/x86/include/asm/bitops\\.h$)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "any_area(all_loc(file(^.*/compat\\.c$)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "any_area(all_loc(file(^.*/compat/.*$)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "any_area(all_loc(file(^xen/arch/x86/x86_emulate/.*$)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "any_area(all_loc(file(^xen/arch/x86/include/asm/genapic\\.h$)))"} Thinking a bit more about it, this deviation is perhaps a bit too wide, though in this case it's probably fine. Probably what is actually wanted is "all_area(all_loc(...))" . This ensures that the decl area and the macro area of the report are in the same file, which is almost always the case for deliberate shadowing. If that turns out to be too strict, then we may do "all_area(any_loc(...))", ensuring that at least there is a loc for the macro and decl in that file. > -config=MC3A2.R5.5,reports+={deliberate, > "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "all_area(decl(name(virt_to_maddr))||macro(name(virt_to_maddr)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "all_area(decl(name(set_px_pminfo))||macro(name(set_px_pminfo)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "all_area(decl(name(set_cx_pminfo))||macro(name(set_cx_pminfo)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "all_area(decl(name(copy_to_guest_ll))||macro(name(copy_to_guest_ll)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "all_area(decl(name(copy_from_guest_ll))||macro(name(copy_from_guest_ll)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "all_area(decl(name(edd_put_string))||macro(name(edd_put_string)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "all_area(decl(name(page_list_entry))||macro(name(page_list_entry)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "all_area(decl(name(do_physdev_op))||macro(name(do_physdev_op)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "all_area(decl(name(do_platform_op))||macro(name(do_platform_op)))"} > > Jan, are you OK with it? -- Nicola Vetrini, B.Sc. Software Engineer BUGSENG (https://bugseng.com) LinkedIn: https://www.linkedin.com/in/nicola-vetrini-a42471253 ^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5 2025-07-12 1:13 ` Stefano Stabellini 2025-07-12 7:45 ` Nicola Vetrini @ 2025-07-14 7:55 ` Jan Beulich 2025-07-15 9:46 ` Dmytro Prokopchuk1 1 sibling, 1 reply; 23+ messages in thread From: Jan Beulich @ 2025-07-14 7:55 UTC (permalink / raw) To: Stefano Stabellini Cc: Dmytro Prokopchuk1, xen-devel, Doug Goldstein, Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel, Julien Grall, Roger Pau Monné, Nicola Vetrini On 12.07.2025 03:13, Stefano Stabellini wrote: > On Fri, 11 Jul 2025, Nicola Vetrini wrote: >> On 2025-07-09 23:38, Dmytro Prokopchuk1 wrote: >>> MISRA C Rule 5.5 states that: "Identifiers shall >>> be distinct from macro names". >>> >>> Update ECLAIR configuration to deviate: >>> - clashes in 'xen/include/xen/bitops.h'; >>> - clashes in 'xen/include/xen/irq.h'; >>> - clashes in 'xen/common/grant_table.c'. >>> >>> Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com> >>> --- >>> automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++ >>> docs/misra/deviations.rst | 8 ++++++++ >>> 2 files changed, 16 insertions(+) >>> >>> diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl >>> b/automation/eclair_analysis/ECLAIR/deviations.ecl >>> index e8f513fbc5..a5d7b00094 100644 >>> --- a/automation/eclair_analysis/ECLAIR/deviations.ecl >>> +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl >>> @@ -117,6 +117,14 @@ it defines would (in the common case) be already >>> defined. Peer reviewed by the c >>> -config=MC3A2.R5.5,reports+={deliberate, >>> "any_area(decl(kind(function))||any_loc(macro(name(memcpy||memset||memmove))))&&any_area(any_loc(file(^xen/common/libelf/libelf-private\\.h$)))"} >>> -doc_end >>> >>> +-doc_begin="Clashes between function names and macros are deliberate for >>> bitops functions, pirq_cleanup_check, update_gnttab_par and >>> parse_gnttab_limit functions >>> +and needed to have a function-like macro that acts as a wrapper for the >>> function to be called. Before calling the function, >>> +the macro adds additional checks or adjusts the number of parameters >>> depending on the configuration." >>> +-config=MC3A2.R5.5,reports+={deliberate, >>> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} >> >> Bitops violations are not inside "xen/include/xen/bitops.h", but rather >> "xen/arch/x86/include/asm/bitops.h" >> >>> +-config=MC3A2.R5.5,reports+={deliberate, >>> "any_area(all_loc(file(^xen/include/xen/irq\\.h$))&&context(name(pirq_cleanup_check)&&kind(function)))"} >> >> I would rather do (untested) >> >> -config=MC3A2.R5.5,reports+={deliberate, >> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} >> >>> +-config=MC3A2.R5.5,reports+={deliberate, >>> "any_area(all_loc(file(^xen/common/grant_table\\.c$))&&context(name(update_gnttab_par||parse_gnttab_limit)&&kind(function)))"} >>> +-doc_end >>> + >> >> same as above >> > > Thanks Nicola! The following deviations are enough and sufficient to > zero violations on both ARM and x86: > > -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} > -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/bitops\\.h$)))"} > -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat\\.c$)))"} > -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat/.*$)))"} > -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/x86_emulate/.*$)))"} > -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/genapic\\.h$)))"} > -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"} > -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"} > -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} > -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(virt_to_maddr))||macro(name(virt_to_maddr)))"} > -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_px_pminfo))||macro(name(set_px_pminfo)))"} > -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_cx_pminfo))||macro(name(set_cx_pminfo)))"} > -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"} > -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_to_guest_ll))||macro(name(copy_to_guest_ll)))"} > -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_from_guest_ll))||macro(name(copy_from_guest_ll)))"} > -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(edd_put_string))||macro(name(edd_put_string)))"} > -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"} > -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(page_list_entry))||macro(name(page_list_entry)))"} > -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_physdev_op))||macro(name(do_physdev_op)))"} > -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_platform_op))||macro(name(do_platform_op)))"} > > Jan, are you OK with it? For many of them the scope (all_area) looks to be far too wide, especially for about everything involved in compat handling. I can only repeat that I think that we would be (far) better off not having wider than necessary deviations. There are others which I may not understand, e.g. the genapic.h one. IOW I further think that such a change would need to come with a fair bit of explanation / justification. Jan ^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5 2025-07-14 7:55 ` Jan Beulich @ 2025-07-15 9:46 ` Dmytro Prokopchuk1 2025-07-15 10:01 ` Jan Beulich 0 siblings, 1 reply; 23+ messages in thread From: Dmytro Prokopchuk1 @ 2025-07-15 9:46 UTC (permalink / raw) To: Jan Beulich, Stefano Stabellini Cc: xen-devel@lists.xenproject.org, Doug Goldstein, Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel, Julien Grall, Roger Pau Monné, Nicola Vetrini Hi Jan and Stefano. Could we proceed with ARM deviations only so far? I understand Stefano's preferences, but it can unblock me to address next ARM violations. BR, Dmytro. On 7/14/25 10:55, Jan Beulich wrote: > On 12.07.2025 03:13, Stefano Stabellini wrote: >> On Fri, 11 Jul 2025, Nicola Vetrini wrote: >>> On 2025-07-09 23:38, Dmytro Prokopchuk1 wrote: >>>> MISRA C Rule 5.5 states that: "Identifiers shall >>>> be distinct from macro names". >>>> >>>> Update ECLAIR configuration to deviate: >>>> - clashes in 'xen/include/xen/bitops.h'; >>>> - clashes in 'xen/include/xen/irq.h'; >>>> - clashes in 'xen/common/grant_table.c'. >>>> >>>> Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com> >>>> --- >>>> automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++ >>>> docs/misra/deviations.rst | 8 ++++++++ >>>> 2 files changed, 16 insertions(+) >>>> >>>> diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl >>>> b/automation/eclair_analysis/ECLAIR/deviations.ecl >>>> index e8f513fbc5..a5d7b00094 100644 >>>> --- a/automation/eclair_analysis/ECLAIR/deviations.ecl >>>> +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl >>>> @@ -117,6 +117,14 @@ it defines would (in the common case) be already >>>> defined. Peer reviewed by the c >>>> -config=MC3A2.R5.5,reports+={deliberate, >>>> "any_area(decl(kind(function))||any_loc(macro(name(memcpy||memset||memmove))))&&any_area(any_loc(file(^xen/common/libelf/libelf-private\\.h$)))"} >>>> -doc_end >>>> >>>> +-doc_begin="Clashes between function names and macros are deliberate for >>>> bitops functions, pirq_cleanup_check, update_gnttab_par and >>>> parse_gnttab_limit functions >>>> +and needed to have a function-like macro that acts as a wrapper for the >>>> function to be called. Before calling the function, >>>> +the macro adds additional checks or adjusts the number of parameters >>>> depending on the configuration." >>>> +-config=MC3A2.R5.5,reports+={deliberate, >>>> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} >>> >>> Bitops violations are not inside "xen/include/xen/bitops.h", but rather >>> "xen/arch/x86/include/asm/bitops.h" >>> >>>> +-config=MC3A2.R5.5,reports+={deliberate, >>>> "any_area(all_loc(file(^xen/include/xen/irq\\.h$))&&context(name(pirq_cleanup_check)&&kind(function)))"} >>> >>> I would rather do (untested) >>> >>> -config=MC3A2.R5.5,reports+={deliberate, >>> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} >>> >>>> +-config=MC3A2.R5.5,reports+={deliberate, >>>> "any_area(all_loc(file(^xen/common/grant_table\\.c$))&&context(name(update_gnttab_par||parse_gnttab_limit)&&kind(function)))"} >>>> +-doc_end >>>> + >>> >>> same as above >>> >> >> Thanks Nicola! The following deviations are enough and sufficient to >> zero violations on both ARM and x86: >> >> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} >> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/bitops\\.h$)))"} >> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat\\.c$)))"} >> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat/.*$)))"} >> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/x86_emulate/.*$)))"} >> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/genapic\\.h$)))"} >> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"} >> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"} >> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} >> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(virt_to_maddr))||macro(name(virt_to_maddr)))"} >> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_px_pminfo))||macro(name(set_px_pminfo)))"} >> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_cx_pminfo))||macro(name(set_cx_pminfo)))"} >> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"} >> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_to_guest_ll))||macro(name(copy_to_guest_ll)))"} >> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_from_guest_ll))||macro(name(copy_from_guest_ll)))"} >> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(edd_put_string))||macro(name(edd_put_string)))"} >> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"} >> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(page_list_entry))||macro(name(page_list_entry)))"} >> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_physdev_op))||macro(name(do_physdev_op)))"} >> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_platform_op))||macro(name(do_platform_op)))"} >> >> Jan, are you OK with it? > > For many of them the scope (all_area) looks to be far too wide, especially > for about everything involved in compat handling. I can only repeat that I > think that we would be (far) better off not having wider than necessary > deviations. > > There are others which I may not understand, e.g. the genapic.h one. IOW I > further think that such a change would need to come with a fair bit of > explanation / justification. > > Jan ^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5 2025-07-15 9:46 ` Dmytro Prokopchuk1 @ 2025-07-15 10:01 ` Jan Beulich 2025-07-15 10:07 ` Dmytro Prokopchuk1 0 siblings, 1 reply; 23+ messages in thread From: Jan Beulich @ 2025-07-15 10:01 UTC (permalink / raw) To: Dmytro Prokopchuk1 Cc: xen-devel@lists.xenproject.org, Doug Goldstein, Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel, Julien Grall, Roger Pau Monné, Nicola Vetrini, Stefano Stabellini On 15.07.2025 11:46, Dmytro Prokopchuk1 wrote: > Could we proceed with ARM deviations only so far? > I understand Stefano's preferences, but it can unblock me to address > next ARM violations. Hmm, ... > On 7/14/25 10:55, Jan Beulich wrote: >> On 12.07.2025 03:13, Stefano Stabellini wrote: >>> On Fri, 11 Jul 2025, Nicola Vetrini wrote: >>>> On 2025-07-09 23:38, Dmytro Prokopchuk1 wrote: >>>>> MISRA C Rule 5.5 states that: "Identifiers shall >>>>> be distinct from macro names". >>>>> >>>>> Update ECLAIR configuration to deviate: >>>>> - clashes in 'xen/include/xen/bitops.h'; >>>>> - clashes in 'xen/include/xen/irq.h'; >>>>> - clashes in 'xen/common/grant_table.c'. >>>>> >>>>> Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com> >>>>> --- >>>>> automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++ >>>>> docs/misra/deviations.rst | 8 ++++++++ >>>>> 2 files changed, 16 insertions(+) >>>>> >>>>> diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl >>>>> b/automation/eclair_analysis/ECLAIR/deviations.ecl >>>>> index e8f513fbc5..a5d7b00094 100644 >>>>> --- a/automation/eclair_analysis/ECLAIR/deviations.ecl >>>>> +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl >>>>> @@ -117,6 +117,14 @@ it defines would (in the common case) be already >>>>> defined. Peer reviewed by the c >>>>> -config=MC3A2.R5.5,reports+={deliberate, >>>>> "any_area(decl(kind(function))||any_loc(macro(name(memcpy||memset||memmove))))&&any_area(any_loc(file(^xen/common/libelf/libelf-private\\.h$)))"} >>>>> -doc_end >>>>> >>>>> +-doc_begin="Clashes between function names and macros are deliberate for >>>>> bitops functions, pirq_cleanup_check, update_gnttab_par and >>>>> parse_gnttab_limit functions >>>>> +and needed to have a function-like macro that acts as a wrapper for the >>>>> function to be called. Before calling the function, >>>>> +the macro adds additional checks or adjusts the number of parameters >>>>> depending on the configuration." >>>>> +-config=MC3A2.R5.5,reports+={deliberate, >>>>> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} >>>> >>>> Bitops violations are not inside "xen/include/xen/bitops.h", but rather >>>> "xen/arch/x86/include/asm/bitops.h" >>>> >>>>> +-config=MC3A2.R5.5,reports+={deliberate, >>>>> "any_area(all_loc(file(^xen/include/xen/irq\\.h$))&&context(name(pirq_cleanup_check)&&kind(function)))"} >>>> >>>> I would rather do (untested) >>>> >>>> -config=MC3A2.R5.5,reports+={deliberate, >>>> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} >>>> >>>>> +-config=MC3A2.R5.5,reports+={deliberate, >>>>> "any_area(all_loc(file(^xen/common/grant_table\\.c$))&&context(name(update_gnttab_par||parse_gnttab_limit)&&kind(function)))"} >>>>> +-doc_end >>>>> + >>>> >>>> same as above >>>> >>> >>> Thanks Nicola! The following deviations are enough and sufficient to >>> zero violations on both ARM and x86: >>> >>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} >>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/bitops\\.h$)))"} >>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat\\.c$)))"} >>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat/.*$)))"} >>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/x86_emulate/.*$)))"} >>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/genapic\\.h$)))"} >>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"} >>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"} >>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} >>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(virt_to_maddr))||macro(name(virt_to_maddr)))"} >>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_px_pminfo))||macro(name(set_px_pminfo)))"} >>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_cx_pminfo))||macro(name(set_cx_pminfo)))"} >>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"} >>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_to_guest_ll))||macro(name(copy_to_guest_ll)))"} >>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_from_guest_ll))||macro(name(copy_from_guest_ll)))"} >>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(edd_put_string))||macro(name(edd_put_string)))"} >>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"} >>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(page_list_entry))||macro(name(page_list_entry)))"} >>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_physdev_op))||macro(name(do_physdev_op)))"} >>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_platform_op))||macro(name(do_platform_op)))"} ... in here, which of them are Arm-only? Jan ^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5 2025-07-15 10:01 ` Jan Beulich @ 2025-07-15 10:07 ` Dmytro Prokopchuk1 2025-07-15 10:39 ` Jan Beulich 2025-07-15 10:50 ` Jan Beulich 0 siblings, 2 replies; 23+ messages in thread From: Dmytro Prokopchuk1 @ 2025-07-15 10:07 UTC (permalink / raw) To: Jan Beulich Cc: xen-devel@lists.xenproject.org, Doug Goldstein, Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel, Julien Grall, Roger Pau Monné, Nicola Vetrini, Stefano Stabellini ARM only are: -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"} -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"} -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} Dmytro. On 7/15/25 13:01, Jan Beulich wrote: > On 15.07.2025 11:46, Dmytro Prokopchuk1 wrote: >> Could we proceed with ARM deviations only so far? >> I understand Stefano's preferences, but it can unblock me to address >> next ARM violations. > > Hmm, ... > >> On 7/14/25 10:55, Jan Beulich wrote: >>> On 12.07.2025 03:13, Stefano Stabellini wrote: >>>> On Fri, 11 Jul 2025, Nicola Vetrini wrote: >>>>> On 2025-07-09 23:38, Dmytro Prokopchuk1 wrote: >>>>>> MISRA C Rule 5.5 states that: "Identifiers shall >>>>>> be distinct from macro names". >>>>>> >>>>>> Update ECLAIR configuration to deviate: >>>>>> - clashes in 'xen/include/xen/bitops.h'; >>>>>> - clashes in 'xen/include/xen/irq.h'; >>>>>> - clashes in 'xen/common/grant_table.c'. >>>>>> >>>>>> Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com> >>>>>> --- >>>>>> automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++ >>>>>> docs/misra/deviations.rst | 8 ++++++++ >>>>>> 2 files changed, 16 insertions(+) >>>>>> >>>>>> diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl >>>>>> b/automation/eclair_analysis/ECLAIR/deviations.ecl >>>>>> index e8f513fbc5..a5d7b00094 100644 >>>>>> --- a/automation/eclair_analysis/ECLAIR/deviations.ecl >>>>>> +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl >>>>>> @@ -117,6 +117,14 @@ it defines would (in the common case) be already >>>>>> defined. Peer reviewed by the c >>>>>> -config=MC3A2.R5.5,reports+={deliberate, >>>>>> "any_area(decl(kind(function))||any_loc(macro(name(memcpy||memset||memmove))))&&any_area(any_loc(file(^xen/common/libelf/libelf-private\\.h$)))"} >>>>>> -doc_end >>>>>> >>>>>> +-doc_begin="Clashes between function names and macros are deliberate for >>>>>> bitops functions, pirq_cleanup_check, update_gnttab_par and >>>>>> parse_gnttab_limit functions >>>>>> +and needed to have a function-like macro that acts as a wrapper for the >>>>>> function to be called. Before calling the function, >>>>>> +the macro adds additional checks or adjusts the number of parameters >>>>>> depending on the configuration." >>>>>> +-config=MC3A2.R5.5,reports+={deliberate, >>>>>> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} >>>>> >>>>> Bitops violations are not inside "xen/include/xen/bitops.h", but rather >>>>> "xen/arch/x86/include/asm/bitops.h" >>>>> >>>>>> +-config=MC3A2.R5.5,reports+={deliberate, >>>>>> "any_area(all_loc(file(^xen/include/xen/irq\\.h$))&&context(name(pirq_cleanup_check)&&kind(function)))"} >>>>> >>>>> I would rather do (untested) >>>>> >>>>> -config=MC3A2.R5.5,reports+={deliberate, >>>>> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} >>>>> >>>>>> +-config=MC3A2.R5.5,reports+={deliberate, >>>>>> "any_area(all_loc(file(^xen/common/grant_table\\.c$))&&context(name(update_gnttab_par||parse_gnttab_limit)&&kind(function)))"} >>>>>> +-doc_end >>>>>> + >>>>> >>>>> same as above >>>>> >>>> >>>> Thanks Nicola! The following deviations are enough and sufficient to >>>> zero violations on both ARM and x86: >>>> >>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} >>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/bitops\\.h$)))"} >>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat\\.c$)))"} >>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat/.*$)))"} >>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/x86_emulate/.*$)))"} >>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/genapic\\.h$)))"} >>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"} >>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"} >>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} >>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(virt_to_maddr))||macro(name(virt_to_maddr)))"} >>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_px_pminfo))||macro(name(set_px_pminfo)))"} >>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_cx_pminfo))||macro(name(set_cx_pminfo)))"} >>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"} >>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_to_guest_ll))||macro(name(copy_to_guest_ll)))"} >>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_from_guest_ll))||macro(name(copy_from_guest_ll)))"} >>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(edd_put_string))||macro(name(edd_put_string)))"} >>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"} >>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(page_list_entry))||macro(name(page_list_entry)))"} >>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_physdev_op))||macro(name(do_physdev_op)))"} >>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_platform_op))||macro(name(do_platform_op)))"} > > ... in here, which of them are Arm-only? > > Jan ^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5 2025-07-15 10:07 ` Dmytro Prokopchuk1 @ 2025-07-15 10:39 ` Jan Beulich 2025-07-15 10:45 ` Dmytro Prokopchuk1 2025-07-15 10:50 ` Jan Beulich 1 sibling, 1 reply; 23+ messages in thread From: Jan Beulich @ 2025-07-15 10:39 UTC (permalink / raw) To: Dmytro Prokopchuk1 Cc: xen-devel@lists.xenproject.org, Doug Goldstein, Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel, Julien Grall, Roger Pau Monné, Nicola Vetrini, Stefano Stabellini On 15.07.2025 12:07, Dmytro Prokopchuk1 wrote: > ARM only are: > -config=MC3A2.R5.5,reports+={deliberate, > "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} Hmm, I'd call these "common code" ones, but I guess you meant "anything that would make Arm clean". As an aside - please don't top-post. Jan > On 7/15/25 13:01, Jan Beulich wrote: >> On 15.07.2025 11:46, Dmytro Prokopchuk1 wrote: >>> Could we proceed with ARM deviations only so far? >>> I understand Stefano's preferences, but it can unblock me to address >>> next ARM violations. >> >> Hmm, ... >> >>> On 7/14/25 10:55, Jan Beulich wrote: >>>> On 12.07.2025 03:13, Stefano Stabellini wrote: >>>>> On Fri, 11 Jul 2025, Nicola Vetrini wrote: >>>>>> On 2025-07-09 23:38, Dmytro Prokopchuk1 wrote: >>>>>>> MISRA C Rule 5.5 states that: "Identifiers shall >>>>>>> be distinct from macro names". >>>>>>> >>>>>>> Update ECLAIR configuration to deviate: >>>>>>> - clashes in 'xen/include/xen/bitops.h'; >>>>>>> - clashes in 'xen/include/xen/irq.h'; >>>>>>> - clashes in 'xen/common/grant_table.c'. >>>>>>> >>>>>>> Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com> >>>>>>> --- >>>>>>> automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++ >>>>>>> docs/misra/deviations.rst | 8 ++++++++ >>>>>>> 2 files changed, 16 insertions(+) >>>>>>> >>>>>>> diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl >>>>>>> b/automation/eclair_analysis/ECLAIR/deviations.ecl >>>>>>> index e8f513fbc5..a5d7b00094 100644 >>>>>>> --- a/automation/eclair_analysis/ECLAIR/deviations.ecl >>>>>>> +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl >>>>>>> @@ -117,6 +117,14 @@ it defines would (in the common case) be already >>>>>>> defined. Peer reviewed by the c >>>>>>> -config=MC3A2.R5.5,reports+={deliberate, >>>>>>> "any_area(decl(kind(function))||any_loc(macro(name(memcpy||memset||memmove))))&&any_area(any_loc(file(^xen/common/libelf/libelf-private\\.h$)))"} >>>>>>> -doc_end >>>>>>> >>>>>>> +-doc_begin="Clashes between function names and macros are deliberate for >>>>>>> bitops functions, pirq_cleanup_check, update_gnttab_par and >>>>>>> parse_gnttab_limit functions >>>>>>> +and needed to have a function-like macro that acts as a wrapper for the >>>>>>> function to be called. Before calling the function, >>>>>>> +the macro adds additional checks or adjusts the number of parameters >>>>>>> depending on the configuration." >>>>>>> +-config=MC3A2.R5.5,reports+={deliberate, >>>>>>> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} >>>>>> >>>>>> Bitops violations are not inside "xen/include/xen/bitops.h", but rather >>>>>> "xen/arch/x86/include/asm/bitops.h" >>>>>> >>>>>>> +-config=MC3A2.R5.5,reports+={deliberate, >>>>>>> "any_area(all_loc(file(^xen/include/xen/irq\\.h$))&&context(name(pirq_cleanup_check)&&kind(function)))"} >>>>>> >>>>>> I would rather do (untested) >>>>>> >>>>>> -config=MC3A2.R5.5,reports+={deliberate, >>>>>> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} >>>>>> >>>>>>> +-config=MC3A2.R5.5,reports+={deliberate, >>>>>>> "any_area(all_loc(file(^xen/common/grant_table\\.c$))&&context(name(update_gnttab_par||parse_gnttab_limit)&&kind(function)))"} >>>>>>> +-doc_end >>>>>>> + >>>>>> >>>>>> same as above >>>>>> >>>>> >>>>> Thanks Nicola! The following deviations are enough and sufficient to >>>>> zero violations on both ARM and x86: >>>>> >>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} >>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/bitops\\.h$)))"} >>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat\\.c$)))"} >>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat/.*$)))"} >>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/x86_emulate/.*$)))"} >>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/genapic\\.h$)))"} >>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"} >>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"} >>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} >>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(virt_to_maddr))||macro(name(virt_to_maddr)))"} >>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_px_pminfo))||macro(name(set_px_pminfo)))"} >>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_cx_pminfo))||macro(name(set_cx_pminfo)))"} >>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"} >>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_to_guest_ll))||macro(name(copy_to_guest_ll)))"} >>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_from_guest_ll))||macro(name(copy_from_guest_ll)))"} >>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(edd_put_string))||macro(name(edd_put_string)))"} >>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"} >>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(page_list_entry))||macro(name(page_list_entry)))"} >>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_physdev_op))||macro(name(do_physdev_op)))"} >>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_platform_op))||macro(name(do_platform_op)))"} >> >> ... in here, which of them are Arm-only? >> >> Jan ^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5 2025-07-15 10:39 ` Jan Beulich @ 2025-07-15 10:45 ` Dmytro Prokopchuk1 0 siblings, 0 replies; 23+ messages in thread From: Dmytro Prokopchuk1 @ 2025-07-15 10:45 UTC (permalink / raw) To: Jan Beulich Cc: xen-devel@lists.xenproject.org, Doug Goldstein, Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel, Julien Grall, Roger Pau Monné, Nicola Vetrini, Stefano Stabellini On 7/15/25 13:39, Jan Beulich wrote: > On 15.07.2025 12:07, Dmytro Prokopchuk1 wrote: >> ARM only are: >> -config=MC3A2.R5.5,reports+={deliberate, >> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} >> -config=MC3A2.R5.5,reports+={deliberate, >> "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"} >> -config=MC3A2.R5.5,reports+={deliberate, >> "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"} >> -config=MC3A2.R5.5,reports+={deliberate, >> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} > > Hmm, I'd call these "common code" ones, but I guess you meant "anything that > would make Arm clean". > > As an aside - please don't top-post. > > Jan > Yes, you are right. I meant "make ARM clean". Sorry for inconvenience. Dmytro. >> On 7/15/25 13:01, Jan Beulich wrote: >>> On 15.07.2025 11:46, Dmytro Prokopchuk1 wrote: >>>> Could we proceed with ARM deviations only so far? >>>> I understand Stefano's preferences, but it can unblock me to address >>>> next ARM violations. >>> >>> Hmm, ... >>> >>>> On 7/14/25 10:55, Jan Beulich wrote: >>>>> On 12.07.2025 03:13, Stefano Stabellini wrote: >>>>>> On Fri, 11 Jul 2025, Nicola Vetrini wrote: >>>>>>> On 2025-07-09 23:38, Dmytro Prokopchuk1 wrote: >>>>>>>> MISRA C Rule 5.5 states that: "Identifiers shall >>>>>>>> be distinct from macro names". >>>>>>>> >>>>>>>> Update ECLAIR configuration to deviate: >>>>>>>> - clashes in 'xen/include/xen/bitops.h'; >>>>>>>> - clashes in 'xen/include/xen/irq.h'; >>>>>>>> - clashes in 'xen/common/grant_table.c'. >>>>>>>> >>>>>>>> Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com> >>>>>>>> --- >>>>>>>> automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++ >>>>>>>> docs/misra/deviations.rst | 8 ++++++++ >>>>>>>> 2 files changed, 16 insertions(+) >>>>>>>> >>>>>>>> diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl >>>>>>>> b/automation/eclair_analysis/ECLAIR/deviations.ecl >>>>>>>> index e8f513fbc5..a5d7b00094 100644 >>>>>>>> --- a/automation/eclair_analysis/ECLAIR/deviations.ecl >>>>>>>> +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl >>>>>>>> @@ -117,6 +117,14 @@ it defines would (in the common case) be already >>>>>>>> defined. Peer reviewed by the c >>>>>>>> -config=MC3A2.R5.5,reports+={deliberate, >>>>>>>> "any_area(decl(kind(function))||any_loc(macro(name(memcpy||memset||memmove))))&&any_area(any_loc(file(^xen/common/libelf/libelf-private\\.h$)))"} >>>>>>>> -doc_end >>>>>>>> >>>>>>>> +-doc_begin="Clashes between function names and macros are deliberate for >>>>>>>> bitops functions, pirq_cleanup_check, update_gnttab_par and >>>>>>>> parse_gnttab_limit functions >>>>>>>> +and needed to have a function-like macro that acts as a wrapper for the >>>>>>>> function to be called. Before calling the function, >>>>>>>> +the macro adds additional checks or adjusts the number of parameters >>>>>>>> depending on the configuration." >>>>>>>> +-config=MC3A2.R5.5,reports+={deliberate, >>>>>>>> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} >>>>>>> >>>>>>> Bitops violations are not inside "xen/include/xen/bitops.h", but rather >>>>>>> "xen/arch/x86/include/asm/bitops.h" >>>>>>> >>>>>>>> +-config=MC3A2.R5.5,reports+={deliberate, >>>>>>>> "any_area(all_loc(file(^xen/include/xen/irq\\.h$))&&context(name(pirq_cleanup_check)&&kind(function)))"} >>>>>>> >>>>>>> I would rather do (untested) >>>>>>> >>>>>>> -config=MC3A2.R5.5,reports+={deliberate, >>>>>>> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} >>>>>>> >>>>>>>> +-config=MC3A2.R5.5,reports+={deliberate, >>>>>>>> "any_area(all_loc(file(^xen/common/grant_table\\.c$))&&context(name(update_gnttab_par||parse_gnttab_limit)&&kind(function)))"} >>>>>>>> +-doc_end >>>>>>>> + >>>>>>> >>>>>>> same as above >>>>>>> >>>>>> >>>>>> Thanks Nicola! The following deviations are enough and sufficient to >>>>>> zero violations on both ARM and x86: >>>>>> >>>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} >>>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/bitops\\.h$)))"} >>>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat\\.c$)))"} >>>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^.*/compat/.*$)))"} >>>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/x86_emulate/.*$)))"} >>>>>> -config=MC3A2.R5.5,reports+={deliberate, "any_area(all_loc(file(^xen/arch/x86/include/asm/genapic\\.h$)))"} >>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"} >>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"} >>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} >>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(virt_to_maddr))||macro(name(virt_to_maddr)))"} >>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_px_pminfo))||macro(name(set_px_pminfo)))"} >>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(set_cx_pminfo))||macro(name(set_cx_pminfo)))"} >>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"} >>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_to_guest_ll))||macro(name(copy_to_guest_ll)))"} >>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(copy_from_guest_ll))||macro(name(copy_from_guest_ll)))"} >>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(edd_put_string))||macro(name(edd_put_string)))"} >>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(cpu_has_amd_erratum))||macro(name(cpu_has_amd_erratum)))"} >>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(page_list_entry))||macro(name(page_list_entry)))"} >>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_physdev_op))||macro(name(do_physdev_op)))"} >>>>>> -config=MC3A2.R5.5,reports+={deliberate, "all_area(decl(name(do_platform_op))||macro(name(do_platform_op)))"} >>> >>> ... in here, which of them are Arm-only? >>> >>> Jan > ^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5 2025-07-15 10:07 ` Dmytro Prokopchuk1 2025-07-15 10:39 ` Jan Beulich @ 2025-07-15 10:50 ` Jan Beulich 2025-07-16 16:04 ` Dmytro Prokopchuk1 1 sibling, 1 reply; 23+ messages in thread From: Jan Beulich @ 2025-07-15 10:50 UTC (permalink / raw) To: Dmytro Prokopchuk1 Cc: xen-devel@lists.xenproject.org, Doug Goldstein, Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel, Julien Grall, Roger Pau Monné, Nicola Vetrini, Stefano Stabellini On 15.07.2025 12:07, Dmytro Prokopchuk1 wrote: > ARM only are: > -config=MC3A2.R5.5,reports+={deliberate, > "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} This one's probably fine. > -config=MC3A2.R5.5,reports+={deliberate, > "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"} These two look too broad: They're affecting common/grant_table.c only, aren't they? > -config=MC3A2.R5.5,reports+={deliberate, > "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} This one also looks overly broad, but it's perhaps unavoidable to be that way. Jan ^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5 2025-07-15 10:50 ` Jan Beulich @ 2025-07-16 16:04 ` Dmytro Prokopchuk1 2025-07-16 16:20 ` Jan Beulich 2025-07-16 16:52 ` Nicola Vetrini 0 siblings, 2 replies; 23+ messages in thread From: Dmytro Prokopchuk1 @ 2025-07-16 16:04 UTC (permalink / raw) To: Jan Beulich Cc: xen-devel@lists.xenproject.org, Doug Goldstein, Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel, Julien Grall, Roger Pau Monné, Nicola Vetrini, Stefano Stabellini On 7/15/25 13:50, Jan Beulich wrote: > On 15.07.2025 12:07, Dmytro Prokopchuk1 wrote: >> ARM only are: >> -config=MC3A2.R5.5,reports+={deliberate, >> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} > > This one's probably fine. > >> -config=MC3A2.R5.5,reports+={deliberate, >> "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"} >> -config=MC3A2.R5.5,reports+={deliberate, >> "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"} > > These two look too broad: They're affecting common/grant_table.c only, aren't > they? > >> -config=MC3A2.R5.5,reports+={deliberate, >> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} > > This one also looks overly broad, but it's perhaps unavoidable to be that way. > > Jan Hi Jan. Those deviations can be narrowed (specifying file name): -config=MC3A2.R5.5,reports+={deliberate, "any_area(any_loc(file(^xen/include/xen/bitops\\.h$)) && macro(name(__test_and_set_bit||__test_and_clear_bit||__test_and_change_bit||test_bit)))"} -config=MC3A2.R5.5,reports+={deliberate, "any_area(any_loc(file(^xen/common/grant_table\\.c$))&¯o(name(update_gnttab_par||parse_gnttab_limit)))"} -config=MC3A2.R5.5,reports+={deliberate, "any_area(any_loc(file(^xen/include/xen/irq\\.h$))&¯o(name(pirq_cleanup_check)))"} Are you OK with it? Dmytro. ^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5 2025-07-16 16:04 ` Dmytro Prokopchuk1 @ 2025-07-16 16:20 ` Jan Beulich 2025-07-16 16:52 ` Nicola Vetrini 1 sibling, 0 replies; 23+ messages in thread From: Jan Beulich @ 2025-07-16 16:20 UTC (permalink / raw) To: Dmytro Prokopchuk1 Cc: xen-devel@lists.xenproject.org, Doug Goldstein, Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel, Julien Grall, Roger Pau Monné, Nicola Vetrini, Stefano Stabellini On 16.07.2025 18:04, Dmytro Prokopchuk1 wrote: > > > On 7/15/25 13:50, Jan Beulich wrote: >> On 15.07.2025 12:07, Dmytro Prokopchuk1 wrote: >>> ARM only are: >>> -config=MC3A2.R5.5,reports+={deliberate, >>> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} >> >> This one's probably fine. >> >>> -config=MC3A2.R5.5,reports+={deliberate, >>> "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"} >>> -config=MC3A2.R5.5,reports+={deliberate, >>> "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"} >> >> These two look too broad: They're affecting common/grant_table.c only, aren't >> they? >> >>> -config=MC3A2.R5.5,reports+={deliberate, >>> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} >> >> This one also looks overly broad, but it's perhaps unavoidable to be that way. > > Those deviations can be narrowed (specifying file name): > > -config=MC3A2.R5.5,reports+={deliberate, > "any_area(any_loc(file(^xen/include/xen/bitops\\.h$)) && > macro(name(__test_and_set_bit||__test_and_clear_bit||__test_and_change_bit||test_bit)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "any_area(any_loc(file(^xen/common/grant_table\\.c$))&¯o(name(update_gnttab_par||parse_gnttab_limit)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "any_area(any_loc(file(^xen/include/xen/irq\\.h$))&¯o(name(pirq_cleanup_check)))"} > > Are you OK with it? This looks acceptable to me, yes. Jan ^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5 2025-07-16 16:04 ` Dmytro Prokopchuk1 2025-07-16 16:20 ` Jan Beulich @ 2025-07-16 16:52 ` Nicola Vetrini 2025-07-16 18:03 ` Dmytro Prokopchuk1 1 sibling, 1 reply; 23+ messages in thread From: Nicola Vetrini @ 2025-07-16 16:52 UTC (permalink / raw) To: Dmytro Prokopchuk1 Cc: Jan Beulich, xen-devel, Doug Goldstein, Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel, Julien Grall, Roger Pau Monné, Stefano Stabellini On 2025-07-16 18:04, Dmytro Prokopchuk1 wrote: > On 7/15/25 13:50, Jan Beulich wrote: >> On 15.07.2025 12:07, Dmytro Prokopchuk1 wrote: >>> ARM only are: >>> -config=MC3A2.R5.5,reports+={deliberate, >>> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} >> >> This one's probably fine. >> >>> -config=MC3A2.R5.5,reports+={deliberate, >>> "all_area(decl(name(parse_gnttab_limit))||macro(name(parse_gnttab_limit)))"} >>> -config=MC3A2.R5.5,reports+={deliberate, >>> "all_area(decl(name(update_gnttab_par))||macro(name(update_gnttab_par)))"} >> >> These two look too broad: They're affecting common/grant_table.c only, >> aren't >> they? >> >>> -config=MC3A2.R5.5,reports+={deliberate, >>> "all_area(decl(name(pirq_cleanup_check))||macro(name(pirq_cleanup_check)))"} >> >> This one also looks overly broad, but it's perhaps unavoidable to be >> that way. >> >> Jan > > Hi Jan. > > Those deviations can be narrowed (specifying file name): > > -config=MC3A2.R5.5,reports+={deliberate, > "any_area(any_loc(file(^xen/include/xen/bitops\\.h$)) && > macro(name(__test_and_set_bit||__test_and_clear_bit||__test_and_change_bit||test_bit)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "any_area(any_loc(file(^xen/common/grant_table\\.c$))&¯o(name(update_gnttab_par||parse_gnttab_limit)))"} > -config=MC3A2.R5.5,reports+={deliberate, > "any_area(any_loc(file(^xen/include/xen/irq\\.h$))&¯o(name(pirq_cleanup_check)))"} > > Are you OK with it? > s/any_loc/all_loc/ ? I don't expect these reports to have locations outside those header files, so this should have the same effect but with a narrower deviation. > Dmytro. -- Nicola Vetrini, B.Sc. Software Engineer BUGSENG (https://bugseng.com) LinkedIn: https://www.linkedin.com/in/nicola-vetrini-a42471253 ^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 3/3] eclair: add deviations of MISRA C Rule 5.5 2025-07-16 16:52 ` Nicola Vetrini @ 2025-07-16 18:03 ` Dmytro Prokopchuk1 0 siblings, 0 replies; 23+ messages in thread From: Dmytro Prokopchuk1 @ 2025-07-16 18:03 UTC (permalink / raw) To: Nicola Vetrini Cc: Jan Beulich, xen-devel@lists.xenproject.org, Doug Goldstein, Stefano Stabellini, Andrew Cooper, Anthony PERARD, Michal Orzel, Julien Grall, Roger Pau Monné, Stefano Stabellini On 7/16/25 19:52, Nicola Vetrini wrote: > On 2025-07-16 18:04, Dmytro Prokopchuk1 wrote: >> On 7/15/25 13:50, Jan Beulich wrote: >>> On 15.07.2025 12:07, Dmytro Prokopchuk1 wrote: >>>> ARM only are: >>>> -config=MC3A2.R5.5,reports+={deliberate, >>>> "any_area(all_loc(file(^xen/include/xen/bitops\\.h$)))"} >>> >>> This one's probably fine. >>> >>>> -config=MC3A2.R5.5,reports+={deliberate, >>>> "all_area(decl(name(parse_gnttab_limit))|| >>>> macro(name(parse_gnttab_limit)))"} >>>> -config=MC3A2.R5.5,reports+={deliberate, >>>> "all_area(decl(name(update_gnttab_par))|| >>>> macro(name(update_gnttab_par)))"} >>> >>> These two look too broad: They're affecting common/grant_table.c >>> only, aren't >>> they? >>> >>>> -config=MC3A2.R5.5,reports+={deliberate, >>>> "all_area(decl(name(pirq_cleanup_check))|| >>>> macro(name(pirq_cleanup_check)))"} >>> >>> This one also looks overly broad, but it's perhaps unavoidable to be >>> that way. >>> >>> Jan >> >> Hi Jan. >> >> Those deviations can be narrowed (specifying file name): >> >> -config=MC3A2.R5.5,reports+={deliberate, >> "any_area(any_loc(file(^xen/include/xen/bitops\\.h$)) && >> macro(name(__test_and_set_bit||__test_and_clear_bit|| >> __test_and_change_bit||test_bit)))"} >> -config=MC3A2.R5.5,reports+={deliberate, >> "any_area(any_loc(file(^xen/common/grant_table\ >> \.c$))&¯o(name(update_gnttab_par||parse_gnttab_limit)))"} >> -config=MC3A2.R5.5,reports+={deliberate, >> "any_area(any_loc(file(^xen/include/xen/irq\ >> \.h$))&¯o(name(pirq_cleanup_check)))"} >> >> Are you OK with it? >> > > s/any_loc/all_loc/ ? I don't expect these reports to have locations > outside those header files, so this should have the same effect but with > a narrower deviation. Thanks, Nicola. I updated my patch. > >> Dmytro. > ^ permalink raw reply [flat|nested] 23+ messages in thread
* Re: [XEN PATCH v2 0/3] address violation of MISRA C Rule 5.5 2025-07-09 21:38 [XEN PATCH v2 0/3] address violation of MISRA C Rule 5.5 Dmytro Prokopchuk1 ` (2 preceding siblings ...) 2025-07-09 21:38 ` [XEN PATCH v2 3/3] eclair: add deviations " Dmytro Prokopchuk1 @ 2025-07-09 21:55 ` Dmytro Prokopchuk1 3 siblings, 0 replies; 23+ messages in thread From: Dmytro Prokopchuk1 @ 2025-07-09 21:55 UTC (permalink / raw) To: xen-devel@lists.xenproject.org Cc: Jan Beulich, Roger Pau Monné, Stefano Stabellini, Julien Grall, Bertrand Marquis, Michal Orzel, Andrew Cooper, Anthony PERARD, Nicola Vetrini, Doug Goldstein CI tests: https://gitlab.com/xen-project/people/dimaprkp4k/xen/-/pipelines/1917527911 On 7/10/25 00:38, Dmytro Prokopchuk1 wrote: > This patch series eliminates/deviates MISRA C Rule 5.5 violations for ARM64. > > Thread discussion: > https://patchew.org/Xen/cover.1751659393.git.dmytro._5Fprokopchuk1@epam.com/ > > Changes in v2: > - fixed code alignment in "device-tree: address violation of MISRA C Rule 5.5" > - updated commit message in "iommu: address violation of MISRA C Rule 5.5" > - other patches were squashed and MISRA rule was deviated > > Dmytro Prokopchuk (3): > iommu: address violation of MISRA C Rule 5.5 > device-tree: address violation of MISRA C Rule 5.5 > eclair: add deviations of MISRA C Rule 5.5 > > automation/eclair_analysis/ECLAIR/deviations.ecl | 8 ++++++++ > docs/misra/deviations.rst | 8 ++++++++ > xen/common/device-tree/domain-build.c | 13 ++++++------- > xen/include/xen/fdt-domain-build.h | 4 ++-- > xen/include/xen/iommu.h | 2 ++ > 5 files changed, 26 insertions(+), 9 deletions(-) > ^ permalink raw reply [flat|nested] 23+ messages in thread
end of thread, other threads:[~2025-07-16 18:04 UTC | newest] Thread overview: 23+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2025-07-09 21:38 [XEN PATCH v2 0/3] address violation of MISRA C Rule 5.5 Dmytro Prokopchuk1 2025-07-09 21:38 ` [XEN PATCH v2 1/3] iommu: " Dmytro Prokopchuk1 2025-07-10 8:21 ` Jan Beulich 2025-07-10 9:44 ` Dmytro Prokopchuk1 2025-07-10 9:47 ` Dmytro Prokopchuk1 2025-07-09 21:38 ` [XEN PATCH v2 2/3] device-tree: " Dmytro Prokopchuk1 2025-07-09 21:38 ` [XEN PATCH v2 3/3] eclair: add deviations " Dmytro Prokopchuk1 2025-07-11 2:17 ` Stefano Stabellini 2025-07-11 8:28 ` Nicola Vetrini 2025-07-12 1:13 ` Stefano Stabellini 2025-07-12 7:45 ` Nicola Vetrini 2025-07-14 7:55 ` Jan Beulich 2025-07-15 9:46 ` Dmytro Prokopchuk1 2025-07-15 10:01 ` Jan Beulich 2025-07-15 10:07 ` Dmytro Prokopchuk1 2025-07-15 10:39 ` Jan Beulich 2025-07-15 10:45 ` Dmytro Prokopchuk1 2025-07-15 10:50 ` Jan Beulich 2025-07-16 16:04 ` Dmytro Prokopchuk1 2025-07-16 16:20 ` Jan Beulich 2025-07-16 16:52 ` Nicola Vetrini 2025-07-16 18:03 ` Dmytro Prokopchuk1 2025-07-09 21:55 ` [XEN PATCH v2 0/3] address violation " Dmytro Prokopchuk1
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.