From: "Daniel P. Berrangé" <berrange@redhat.com>
To: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Cc: "Arun Menon" <armenon@redhat.com>,
qemu-devel@nongnu.org, "Michael S. Tsirkin" <mst@redhat.com>,
"Marcel Apfelbaum" <marcel.apfelbaum@gmail.com>,
"Cornelia Huck" <cohuck@redhat.com>,
"Halil Pasic" <pasic@linux.ibm.com>,
"Eric Farman" <farman@linux.ibm.com>,
"Richard Henderson" <richard.henderson@linaro.org>,
"David Hildenbrand" <david@redhat.com>,
"Ilya Leoshkevich" <iii@linux.ibm.com>,
"Thomas Huth" <thuth@redhat.com>,
"Christian Borntraeger" <borntraeger@linux.ibm.com>,
"Paolo Bonzini" <pbonzini@redhat.com>,
"Fam Zheng" <fam@euphon.net>,
"Nicholas Piggin" <npiggin@gmail.com>,
"Daniel Henrique Barboza" <danielhb413@gmail.com>,
"Harsh Prateek Bora" <harshpb@linux.ibm.com>,
"Alex Williamson" <alex.williamson@redhat.com>,
"Cédric Le Goater" <clg@redhat.com>,
"Peter Xu" <peterx@redhat.com>, "Fabiano Rosas" <farosas@suse.de>,
"Hailiang Zhang" <zhanghailiang@xfusion.com>,
"Steve Sistare" <steven.sistare@oracle.com>,
qemu-s390x@nongnu.org, qemu-ppc@nongnu.org,
"Stefan Berger" <stefanb@linux.vnet.ibm.com>,
"Marc-André Lureau" <marcandre.lureau@redhat.com>,
"Alex Bennée" <alex.bennee@linaro.org>,
"Dmitry Osipenko" <dmitry.osipenko@collabora.com>,
"Matthew Rosato" <mjrosato@linux.ibm.com>
Subject: Re: [PATCH v5 09/23] migration: push Error **errp into ram_postcopy_incoming_init()
Date: Thu, 17 Jul 2025 18:02:09 +0100 [thread overview]
Message-ID: <aHkskfsMNVgjoV2y@redhat.com> (raw)
In-Reply-To: <c535b2b0-78d6-4afa-bd6a-d11159d3a952@rsg.ci.i.u-tokyo.ac.jp>
On Thu, Jul 17, 2025 at 12:34:21PM +0900, Akihiko Odaki wrote:
> On 2025/07/17 9:37, Arun Menon wrote:
> > This is an incremental step in converting vmstate loading
> > code to report error via Error objects instead of directly
> > printing it to console/monitor.
> > It is ensured that ram_postcopy_incoming_init() must report an error
> > in errp, in case of failure.
> >
> > Signed-off-by: Arun Menon <armenon@redhat.com>
> > ---
> > migration/postcopy-ram.c | 9 ++++++---
> > migration/postcopy-ram.h | 2 +-
> > migration/ram.c | 6 +++---
> > migration/ram.h | 2 +-
> > migration/savevm.c | 2 +-
> > 5 files changed, 12 insertions(+), 9 deletions(-)
> >
> > diff --git a/migration/postcopy-ram.c b/migration/postcopy-ram.c
> > index 45af9a361e8eacaad0fb217a5da2c5004416c1da..05617e5fbcad62226a54fe17d9f7d9a316baf1e4 100644
> > --- a/migration/postcopy-ram.c
> > +++ b/migration/postcopy-ram.c
> > @@ -681,6 +681,7 @@ out:
> > */
> > static int init_range(RAMBlock *rb, void *opaque)
> > {
> > + Error **errp = opaque;
> > const char *block_name = qemu_ram_get_idstr(rb);
> > void *host_addr = qemu_ram_get_host_addr(rb);
> > ram_addr_t offset = qemu_ram_get_offset(rb);
> > @@ -701,6 +702,8 @@ static int init_range(RAMBlock *rb, void *opaque)
> > * (Precopy will just overwrite this data, so doesn't need the discard)
> > */
> > if (ram_discard_range(block_name, 0, length)) {
> > + error_setg(errp, "failed to discard RAM block %s len=%zu",
> > + block_name, length);
> > return -1;
> > }
> > @@ -749,9 +752,9 @@ static int cleanup_range(RAMBlock *rb, void *opaque)
> > * postcopy later; must be called prior to any precopy.
> > * called from arch_init's similarly named ram_postcopy_incoming_init
> > */
> > -int postcopy_ram_incoming_init(MigrationIncomingState *mis)
> > +int postcopy_ram_incoming_init(MigrationIncomingState *mis, Error **errp)
> > {
> > - if (foreach_not_ignored_block(init_range, NULL)) {
> > + if (foreach_not_ignored_block(init_range, errp)) {
> > return -1;
> > }
> > @@ -1703,7 +1706,7 @@ bool postcopy_ram_supported_by_host(MigrationIncomingState *mis, Error **errp)
> > return false;
> > }
> > -int postcopy_ram_incoming_init(MigrationIncomingState *mis)
> > +int postcopy_ram_incoming_init(MigrationIncomingState *mis, Error **errp)
> > {
> > error_report("postcopy_ram_incoming_init: No OS support");
> > return -1;
> > diff --git a/migration/postcopy-ram.h b/migration/postcopy-ram.h
> > index 3852141d7e37ab18bada4b46c137fef0969d0070..ca19433b246893fa5105bcebffb442c58a9a4f48 100644
> > --- a/migration/postcopy-ram.h
> > +++ b/migration/postcopy-ram.h
> > @@ -30,7 +30,7 @@ int postcopy_ram_incoming_setup(MigrationIncomingState *mis);
> > * postcopy later; must be called prior to any precopy.
> > * called from ram.c's similarly named ram_postcopy_incoming_init
> > */
> > -int postcopy_ram_incoming_init(MigrationIncomingState *mis);
> > +int postcopy_ram_incoming_init(MigrationIncomingState *mis, Error **errp);
> > /*
> > * At the end of a migration where postcopy_ram_incoming_init was called.
> > diff --git a/migration/ram.c b/migration/ram.c
> > index 7208bc114fb5c366740db380ee6956a91b3871a0..8223183132dc0f558f45fbae3f4f832845730bd3 100644
> > --- a/migration/ram.c
> > +++ b/migration/ram.c
> > @@ -3708,7 +3708,7 @@ static int ram_load_cleanup(void *opaque)
> > /**
> > * ram_postcopy_incoming_init: allocate postcopy data structures
> > *
> > - * Returns 0 for success and negative if there was one error
> > + * Returns 0 for success and -1 if there was one error
>
> This is true but not relevant in this patch's goal.
>
> Besides, I'm not in favor of letting callers make an assumption on integer
> return values (i.e., let callers assume a particular integer value in the
> error conditions). It is subtle to make a mistake to return -errno while the
> documentation says it returns -1.
In general I would consider it bad practice to have an method
with "Error **errp" that also returns an errno. 95% of the time
the errno is just there as further info on the error scenario,
which "errp" obsoletes. Only in the rare cases where the caller
needs to take functional action based on errno values, is it
appropriate to contine returning '-errno'.
IOW, I'd consider this appropriate for the patch as is.
> I think a proper way to avoid bugs due to return values here is to change
> the type to bool, which ensures there are two possible values; that is a
> nice improvement but something that can be done later.
That doesn't guarantee avoidance of bugs, as bool values can be
assigned to & compared against integers.
> > diff --git a/migration/savevm.c b/migration/savevm.c
> > index d1edeaac5f2a5df2f6d94357388be807a938b2ef..8eba151a693b7f2dc58853292c92024288eae81e 100644
> > --- a/migration/savevm.c
> > +++ b/migration/savevm.c
> > @@ -1983,7 +1983,7 @@ static int loadvm_postcopy_handle_advise(MigrationIncomingState *mis,
> > return -1;
> > }
> > - if (ram_postcopy_incoming_init(mis)) {
> > + if (ram_postcopy_incoming_init(mis, NULL)) {
> > return -1;
> > }
This is a definite anti-pattern though as it treats positive return
values as errors, contrary to the documented API for both the old
and new code.
So change this to "< 0" while we're here.
With regards,
Daniel
--
|: https://berrange.com -o- https://www.flickr.com/photos/dberrange :|
|: https://libvirt.org -o- https://fstop138.berrange.com :|
|: https://entangle-photo.org -o- https://www.instagram.com/dberrange :|
next prev parent reply other threads:[~2025-07-17 19:40 UTC|newest]
Thread overview: 52+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-07-17 0:37 [PATCH v5 00/23] migration: propagate vTPM errors using Error objects Arun Menon
2025-07-17 0:37 ` [PATCH v5 01/23] migration: push Error **errp into vmstate_subsection_load() Arun Menon
2025-07-17 16:14 ` Daniel P. Berrangé
2025-07-17 0:37 ` [PATCH v5 02/23] migration: push Error **errp into vmstate_load_state() Arun Menon
2025-07-17 16:32 ` Daniel P. Berrangé
2025-07-18 16:27 ` Arun Menon
2025-07-17 0:37 ` [PATCH v5 03/23] migration: push Error **errp into qemu_loadvm_state_header() Arun Menon
2025-07-17 16:36 ` Daniel P. Berrangé
2025-07-17 0:37 ` [PATCH v5 04/23] migration: push Error **errp into vmstate_load() Arun Menon
2025-07-17 16:38 ` Daniel P. Berrangé
2025-07-17 0:37 ` [PATCH v5 05/23] migration: push Error **errp into qemu_loadvm_section_start_full() Arun Menon
2025-07-17 16:47 ` Daniel P. Berrangé
2025-07-17 0:37 ` [PATCH v5 06/23] migration: push Error **errp into qemu_loadvm_section_part_end() Arun Menon
2025-07-17 16:48 ` Daniel P. Berrangé
2025-07-17 0:37 ` [PATCH v5 07/23] migration: push Error **errp into loadvm_process_command() Arun Menon
2025-07-17 16:54 ` Daniel P. Berrangé
2025-07-17 17:17 ` Daniel P. Berrangé
2025-07-17 0:37 ` [PATCH v5 08/23] migration: push Error **errp into loadvm_handle_cmd_packaged() Arun Menon
2025-07-17 16:55 ` Daniel P. Berrangé
2025-07-17 0:37 ` [PATCH v5 09/23] migration: push Error **errp into ram_postcopy_incoming_init() Arun Menon
2025-07-17 3:34 ` Akihiko Odaki
2025-07-17 8:06 ` Arun Menon
2025-07-17 17:02 ` Daniel P. Berrangé [this message]
2025-07-18 4:28 ` Akihiko Odaki
2025-07-17 0:37 ` [PATCH v5 10/23] migration: push Error **errp into loadvm_postcopy_handle_advise() Arun Menon
2025-07-17 17:09 ` Daniel P. Berrangé
2025-07-17 0:37 ` [PATCH v5 11/23] migration: push Error **errp into loadvm_postcopy_handle_listen() Arun Menon
2025-07-17 17:11 ` Daniel P. Berrangé
2025-07-17 0:37 ` [PATCH v5 12/23] migration: push Error **errp into loadvm_postcopy_handle_run() Arun Menon
2025-07-17 17:13 ` Daniel P. Berrangé
2025-07-17 0:37 ` [PATCH v5 13/23] migration: push Error **errp into loadvm_postcopy_ram_handle_discard() Arun Menon
2025-07-17 0:37 ` [PATCH v5 14/23] migration: make loadvm_postcopy_handle_resume() void Arun Menon
2025-07-17 17:15 ` Daniel P. Berrangé
2025-07-17 0:37 ` [PATCH v5 15/23] migration: push Error **errp into loadvm_handle_recv_bitmap() Arun Menon
2025-07-17 17:18 ` Daniel P. Berrangé
2025-07-17 0:37 ` [PATCH v5 16/23] migration: push Error **errp into loadvm_process_enable_colo() Arun Menon
2025-07-17 3:26 ` Akihiko Odaki
2025-07-17 8:13 ` Arun Menon
2025-07-17 0:37 ` [PATCH v5 17/23] migration: push Error **errp into loadvm_postcopy_handle_switchover_start() Arun Menon
2025-07-17 17:20 ` Daniel P. Berrangé
2025-07-17 0:37 ` [PATCH v5 18/23] migration: push Error **errp into qemu_loadvm_state_main() Arun Menon
2025-07-17 17:25 ` Daniel P. Berrangé
2025-07-17 0:37 ` [PATCH v5 19/23] migration: push Error **errp into qemu_loadvm_state() Arun Menon
2025-07-17 17:28 ` Daniel P. Berrangé
2025-07-17 0:37 ` [PATCH v5 20/23] migration: push Error **errp into qemu_load_device_state() Arun Menon
2025-07-17 17:30 ` Daniel P. Berrangé
2025-07-17 0:37 ` [PATCH v5 21/23] migration: Capture error in postcopy_ram_listen_thread() Arun Menon
2025-07-17 17:33 ` Daniel P. Berrangé
2025-07-17 0:37 ` [PATCH v5 22/23] migration: Add error-parameterized function variants in VMSD struct Arun Menon
2025-07-17 17:36 ` Daniel P. Berrangé
2025-07-17 0:37 ` [PATCH v5 23/23] backends/tpm: Propagate vTPM error on migration failure Arun Menon
2025-07-17 17:37 ` Daniel P. Berrangé
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aHkskfsMNVgjoV2y@redhat.com \
--to=berrange@redhat.com \
--cc=alex.bennee@linaro.org \
--cc=alex.williamson@redhat.com \
--cc=armenon@redhat.com \
--cc=borntraeger@linux.ibm.com \
--cc=clg@redhat.com \
--cc=cohuck@redhat.com \
--cc=danielhb413@gmail.com \
--cc=david@redhat.com \
--cc=dmitry.osipenko@collabora.com \
--cc=fam@euphon.net \
--cc=farman@linux.ibm.com \
--cc=farosas@suse.de \
--cc=harshpb@linux.ibm.com \
--cc=iii@linux.ibm.com \
--cc=marcandre.lureau@redhat.com \
--cc=marcel.apfelbaum@gmail.com \
--cc=mjrosato@linux.ibm.com \
--cc=mst@redhat.com \
--cc=npiggin@gmail.com \
--cc=odaki@rsg.ci.i.u-tokyo.ac.jp \
--cc=pasic@linux.ibm.com \
--cc=pbonzini@redhat.com \
--cc=peterx@redhat.com \
--cc=qemu-devel@nongnu.org \
--cc=qemu-ppc@nongnu.org \
--cc=qemu-s390x@nongnu.org \
--cc=richard.henderson@linaro.org \
--cc=stefanb@linux.vnet.ibm.com \
--cc=steven.sistare@oracle.com \
--cc=thuth@redhat.com \
--cc=zhanghailiang@xfusion.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.