From: Jan Beulich <jbeulich@suse.com>
To: Dmytro Prokopchuk1 <dmytro_prokopchuk1@epam.com>
Cc: "Andrew Cooper" <andrew.cooper3@citrix.com>,
"Anthony PERARD" <anthony.perard@vates.tech>,
"Michal Orzel" <michal.orzel@amd.com>,
"Julien Grall" <julien@xen.org>,
"Roger Pau Monné" <roger.pau@citrix.com>,
"Stefano Stabellini" <sstabellini@kernel.org>,
"Bertrand Marquis" <bertrand.marquis@arm.com>,
"Volodymyr Babchuk" <Volodymyr_Babchuk@epam.com>,
"xen-devel@lists.xenproject.org" <xen-devel@lists.xenproject.org>,
"consulting@bugseng.com" <consulting@bugseng.com>
Subject: Re: [PATCH] misra: deviate explicit cast for Rule 11.1
Date: Mon, 28 Jul 2025 15:23:30 +0200 [thread overview]
Message-ID: <c412c163-e076-4513-8eca-6607534a8b1e@suse.com> (raw)
In-Reply-To: <c112f144-6f75-4f19-ac14-57d538ccc7ab@epam.com>
On 28.07.2025 15:09, Dmytro Prokopchuk1 wrote:
>
>
> On 7/28/25 12:56, Jan Beulich wrote:
>> On 27.07.2025 22:27, Dmytro Prokopchuk1 wrote:
>>> Explicitly cast 'halt_this_cpu' when passing it
>>> to 'smp_call_function' to match the required
>>> function pointer type '(void (*)(void *info))'.
>>>
>>> Document and justify a MISRA C R11.1 deviation
>>> (explicit cast).
>>>
>>> Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com>
>>
>> All you talk about is the rule that you violate by adding a cast. But what is
>> the problem you're actually trying to resolve by adding a cast?
>>
>>> --- a/xen/arch/arm/shutdown.c
>>> +++ b/xen/arch/arm/shutdown.c
>>> @@ -25,7 +25,8 @@ void machine_halt(void)
>>> watchdog_disable();
>>> console_start_sync();
>>> local_irq_enable();
>>> - smp_call_function(halt_this_cpu, NULL, 0);
>>> + /* SAF-15-safe */
>>> + smp_call_function((void (*)(void *))halt_this_cpu, NULL, 0);
>>
>> Now this is the kind of cast that is very dangerous. The function's signature
>> changing will go entirely unnoticed (by the compiler) with such a cast in place.
>>
>> If Misra / Eclair are unhappy about such an extra (benign here) attribute, I'd
>> be interested to know what their suggestion is to deal with the situation
>> without making the code worse (as in: more risky). I first thought about having
>> a new helper function that then simply chains to halt_this_cpu(), yet that
>> would result in a function which can't return, but has no noreturn attribute.
>>
>> Jan
>
> Yes, Misra doesn't like cast.
>
> Initially Misra reported about non-compliant implicit cast due to
> 'noreturn' attribute:
> smp_call_function(halt_this_cpu, NULL, 0);
>
> I thought that in this case explicit cast is better, telling compiler
> exact type.
> But, Misra reported about non-compliant c-style (explicit) cast.
> So, I decided to deviate explicit cast.
>
> I tried to write wrapper function to resolve this.
> Example:
> static void halt_this_cpu_2(void *arg)
> {
> halt_this_cpu(arg);
> }
> void machine_halt(void)
> {
> ...
> smp_call_function(halt_this_cpu_2, NULL, 0);
> ...
>
> Unfortunately new R2.1 violation was observed.
> "function definition `halt_this_cpu_2(void*)' (unit
> `xen/arch/arm/shutdown.c' with target `xen/arch/arm/shutdown.o') will
> never return"
>
> Maybe it's better to have such violation....instead of R11.1
> "non-compliant cast"
>
>
> I can remove cast and re-write deviation justification.
> Are you OK with that, Jan?
I expect so, as a temporary measure. In the longer run I would hope Eclair
can be adjusted to accept such cases without complaint.
Jan
prev parent reply other threads:[~2025-07-28 13:23 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-07-27 20:27 [PATCH] misra: deviate explicit cast for Rule 11.1 Dmytro Prokopchuk1
2025-07-28 9:56 ` Jan Beulich
2025-07-28 10:49 ` Andrew Cooper
2025-07-28 17:43 ` Nicola Vetrini
2025-07-28 18:03 ` Dmytro Prokopchuk1
2025-07-28 18:58 ` Dmytro Prokopchuk1
2025-07-28 19:17 ` Nicola Vetrini
2025-07-29 7:26 ` Jan Beulich
2025-07-29 11:03 ` Nicola Vetrini
2025-07-28 13:09 ` Dmytro Prokopchuk1
2025-07-28 13:23 ` Jan Beulich [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=c412c163-e076-4513-8eca-6607534a8b1e@suse.com \
--to=jbeulich@suse.com \
--cc=Volodymyr_Babchuk@epam.com \
--cc=andrew.cooper3@citrix.com \
--cc=anthony.perard@vates.tech \
--cc=bertrand.marquis@arm.com \
--cc=consulting@bugseng.com \
--cc=dmytro_prokopchuk1@epam.com \
--cc=julien@xen.org \
--cc=michal.orzel@amd.com \
--cc=roger.pau@citrix.com \
--cc=sstabellini@kernel.org \
--cc=xen-devel@lists.xenproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.