All of lore.kernel.org
 help / color / mirror / Atom feed
From: Dmytro Prokopchuk1 <dmytro_prokopchuk1@epam.com>
To: Nicola Vetrini <nicola.vetrini@bugseng.com>
Cc: "Jan Beulich" <jbeulich@suse.com>,
	"consulting@bugseng.com" <consulting@bugseng.com>,
	"Anthony PERARD" <anthony.perard@vates.tech>,
	"Michal Orzel" <michal.orzel@amd.com>,
	"Julien Grall" <julien@xen.org>,
	"Roger Pau Monné" <roger.pau@citrix.com>,
	"Stefano Stabellini" <sstabellini@kernel.org>,
	"Bertrand Marquis" <bertrand.marquis@arm.com>,
	"Volodymyr Babchuk" <Volodymyr_Babchuk@epam.com>,
	"xen-devel@lists.xenproject.org" <xen-devel@lists.xenproject.org>,
	"Andrew Cooper" <andrew.cooper3@citrix.com>
Subject: Re: [PATCH] misra: deviate explicit cast for Rule 11.1
Date: Mon, 28 Jul 2025 18:58:27 +0000	[thread overview]
Message-ID: <efcda932-633b-4140-b869-e22d552b3aea@epam.com> (raw)
In-Reply-To: <a5781ddf-d353-470b-a072-1e0b4e6931dd@epam.com>



On 7/28/25 21:03, Dmytro Prokopchuk wrote:
> 
> 
> On 7/28/25 20:43, Nicola Vetrini wrote:
>> On 2025-07-28 12:49, Andrew Cooper wrote:
>>> On 28/07/2025 10:56 am, Jan Beulich wrote:
>>>> On 27.07.2025 22:27, Dmytro Prokopchuk1 wrote:
>>>>> Explicitly cast 'halt_this_cpu' when passing it
>>>>> to 'smp_call_function' to match the required
>>>>> function pointer type '(void (*)(void *info))'.
>>>>>
>>>>> Document and justify a MISRA C R11.1 deviation
>>>>> (explicit cast).
>>>>>
>>>>> Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@epam.com>
>>>> All you talk about is the rule that you violate by adding a cast. 
>>>> But what is
>>>> the problem you're actually trying to resolve by adding a cast?
>>>>
>>>>> --- a/xen/arch/arm/shutdown.c
>>>>> +++ b/xen/arch/arm/shutdown.c
>>>>> @@ -25,7 +25,8 @@ void machine_halt(void)
>>>>>      watchdog_disable();
>>>>>      console_start_sync();
>>>>>      local_irq_enable();
>>>>> -    smp_call_function(halt_this_cpu, NULL, 0);
>>>>> +    /* SAF-15-safe */
>>>>> +    smp_call_function((void (*)(void *))halt_this_cpu, NULL, 0);
>>>> Now this is the kind of cast that is very dangerous. The function's 
>>>> signature
>>>> changing will go entirely unnoticed (by the compiler) with such a 
>>>> cast in place.
>>>
>>> I agree.  This code is *far* safer in practice without the cast, than
>>> with it.
>>>
>>>> If Misra / Eclair are unhappy about such an extra (benign here) 
>>>> attribute, I'd
>>>> be interested to know what their suggestion is to deal with the 
>>>> situation
>>>> without making the code worse (as in: more risky). I first thought 
>>>> about having
>>>> a new helper function that then simply chains to halt_this_cpu(), 
>>>> yet that
>>>> would result in a function which can't return, but has no noreturn 
>>>> attribute.
>>>
>>> I guess that Eclair cannot know what an arbitrary attribute does and
>>> whether it impacts the ABI, but it would be lovely if Eclair could be
>>> told "noreturn is a safe attribute to differ on"?
>>>
>>
>> I'm convinced it can do that. Perhaps something like
>>
>> -config=MC3A2.R11.1,casts+={safe, 
>> "kind(bitcast)&&to(type(pointer(inner(return(builtin(void))&&all_param(1, pointer(builtin(void)))))))&&from(expr(skip(!syntactic(), ref(property(noreturn)))))"}
>>
>> which is a mess but decodes to that, more or less.
>>
>> I haven't tested it yet, though, but on a toy example [1] it works.
>>
>> [1]
>> void __attribute__((noreturn)) f(void *p) {
>>    __builtin_abort();
>> }
>>
>> void g(int x, void (*fp)(void *p)) {
>>    if (x < 3) {
>>      f((void*)x);
>>    }
>> }
>>
>> int main(int argc, char **argv) {
>>    g(argc, f);
>>    return 0;
>> }
>>
> Thanks, Nicola.
> I will check this.
> 
> Dmytro.
It works.
The violation "non-compliant cast: implicit cast from `void(*)(void*)' 
to `void(*)(void*)'" is gone.

Dmytro


  reply	other threads:[~2025-07-28 18:58 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-07-27 20:27 [PATCH] misra: deviate explicit cast for Rule 11.1 Dmytro Prokopchuk1
2025-07-28  9:56 ` Jan Beulich
2025-07-28 10:49   ` Andrew Cooper
2025-07-28 17:43     ` Nicola Vetrini
2025-07-28 18:03       ` Dmytro Prokopchuk1
2025-07-28 18:58         ` Dmytro Prokopchuk1 [this message]
2025-07-28 19:17           ` Nicola Vetrini
2025-07-29  7:26             ` Jan Beulich
2025-07-29 11:03               ` Nicola Vetrini
2025-07-28 13:09   ` Dmytro Prokopchuk1
2025-07-28 13:23     ` Jan Beulich

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=efcda932-633b-4140-b869-e22d552b3aea@epam.com \
    --to=dmytro_prokopchuk1@epam.com \
    --cc=Volodymyr_Babchuk@epam.com \
    --cc=andrew.cooper3@citrix.com \
    --cc=anthony.perard@vates.tech \
    --cc=bertrand.marquis@arm.com \
    --cc=consulting@bugseng.com \
    --cc=jbeulich@suse.com \
    --cc=julien@xen.org \
    --cc=michal.orzel@amd.com \
    --cc=nicola.vetrini@bugseng.com \
    --cc=roger.pau@citrix.com \
    --cc=sstabellini@kernel.org \
    --cc=xen-devel@lists.xenproject.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.