From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-lf1-f44.google.com (mail-lf1-f44.google.com [209.85.167.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 508E53B8BC2 for ; Wed, 21 Jan 2026 19:14:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.167.44 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1769022896; cv=none; b=MarRCZ5uY0o2GjS6GoaMv/7dcGh08vkiD4sQ86BXgc6Nx4OosAK7RHlm+lmiRjzAS4mMfzIGOTKo2tqhJKQEAIsbCOQQCsT1he/+mcOeUMkgHrI+VqKduFbxJC9UJAEOzYFWH49KjFghQPDOJMLrF8Lc9DOKO9rjI9Ny3KO7w0w= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1769022896; c=relaxed/simple; bh=aJRtysccswB3GmdDSce+lpuj01tU0vpN4koKSrA7CWw=; h=Date:From:To:Cc:Subject:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=k/YiVk+lXe/EGrhIznsnVigop0pE6Tip//fM7SzqqQfeVrU1Fot2WcKOBVG12ajfgisMNqZx4BnXlAEiM8k0p0mLZq8NcDlvHwnSCxR1lm2T9dJPU9h/A4qcDp3Q7UtesnVKFn7u4BKZIb0KeBZl2+2EgVCxKxN2v84sxgN39bo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ZDFbEUAC; arc=none smtp.client-ip=209.85.167.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ZDFbEUAC" Received: by mail-lf1-f44.google.com with SMTP id 2adb3069b0e04-59dd4bec4ecso144745e87.0 for ; Wed, 21 Jan 2026 11:14:54 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1769022892; x=1769627692; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:subject:cc:to:from:date:from:to:cc:subject:date :message-id:reply-to; bh=Vr+UIc7zW1MlTBTbOjASE/j1Va3VjetLWpvwAjcFB+o=; b=ZDFbEUACEYJHsPYhert9ZIf4oguZ2nqxMwPYd6FEIKEZgzC7q8TCfx0Jz/yv3SoNed f4gtfxGpi80MeuyfQ1uAYOsIj1K+crAQqbYTy11qlOQ8u9qG0cqarda9+SyajKS/IgnL j7aXZJFo41KL0fhV+QTTRGaHrhIUzcbSq5TVmEt3WnoBo88AZacSN6+VXjZMsg6bj6iO x7GtZ+HgwBHD9fQdFz7XQgOfHaf0w88wz7rkNOt4kY2IxdhkHHW1Y5Nn2Gu1mQppMnmr 0gyDUxZFgRX2Qts1cRUSkMbwhNw2ruH/+ZrvS+N/xp+YHxYjPXCIaulkzhopAMRSYqjV 2W9g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1769022892; x=1769627692; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:subject:cc:to:from:date:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=Vr+UIc7zW1MlTBTbOjASE/j1Va3VjetLWpvwAjcFB+o=; b=p7EeuEDvQfQsk7Y1FJzf3AS0/aHnelke1L9OAVPmmHJNsfUji3GmcUKLha3a0ilxLh EmoLQkqKdAHsKZ8QDmPgDl5+zcRWgmHAk+QR1mk17z40W4U6KHTy7dgcqGa7A3mpium/ QKIel0WvOAUKCUH8PlLIw+PSg85jrbFlajEA75NJEw3E5Ed+Y0OzVNuoY4G+vMQJBC79 h2ih+xsTmAc31a/RF6dZbxCvTmvLBpi5Hswu3bBrbR0roPkSX2Mz2QUlMzHmcDABqmpD zm98vqB98NNhuRC0++c5mu79dZnwj2vC/KGiEH+TRW60h6lFYNytI6fuTxV5ks6k9+y7 nr1Q== X-Forwarded-Encrypted: i=1; AJvYcCUd8/hBkUzbv7AWu44vOx5+2/R895mjbWOUPVuRfUerUl6OqaK0rZkdU8gtqltmibfaXt18g/QZi3eQowE=@vger.kernel.org X-Gm-Message-State: AOJu0Yz3+jM7UlA+OVAgpDHDRT01egzlxZjxrd7ukSi0Gk46wG/Mc/UI iDsVRc8S/ilYghlSxu6m8oh5sgxaY4yfhk4pzAGdn1kjxAuc81WTwS6c X-Gm-Gg: AZuq6aLAwVV3ZYJN4oYNgAO1tEfH53Wg9CUC7y8RSiZKRldz3nOVm4s+iyZ4ezuB28x 40C2EzwE48eRsJ+HASbzpeJ3exna7se+27iuMDAp//b0R/fWoVSSbOdUki9ATFWIXPQCw+9X4ZD VPtbf2F+QEaC1+IvkIeNWA9fVKtscigyQzewtSPWFx7MiwIYm/JMmwP5L1GPg9HnOOfHOrhu3KH FG0tvjNa1mw/fAMB89rWYtbAPkIb51YcBrkr1fl3c7zsQDokxY2Z43wtw6cNRir65uRjYyhD4NQ UQ3EhXtgFXJXUZ+dfOVXseIGkhDrN+zLPKfmrtXbrHhHGEWALTkFhQ0t+ViyqtgfAMqp/4u0Os1 xAmuwuLDO8ioXdlyLuzlva6C9plOFO8StVpGIIAnRfwoep2JD/NFNWVR2L7D5L4N924dbpDJdrX eJGEqzt8Saf9+XMWCp02Cnu17tbR7nEPa92PObb79WV3q4MXD/5Cdn X-Received: by 2002:a05:6512:2c8b:b0:59d:d09d:95c6 with SMTP id 2adb3069b0e04-59dd09d96bdmr1105271e87.15.1769022891988; Wed, 21 Jan 2026 11:14:51 -0800 (PST) Received: from pumpkin (82-69-66-36.dsl.in-addr.zen.co.uk. [82.69.66.36]) by smtp.gmail.com with ESMTPSA id 2adb3069b0e04-59baf34d379sm4893436e87.23.2026.01.21.11.14.50 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 21 Jan 2026 11:14:51 -0800 (PST) Date: Wed, 21 Jan 2026 19:14:48 +0000 From: David Laight To: Vincent Mailhol Cc: Nathan Chancellor , Greg Kroah-Hartman , Thomas Gleixner , Peter Zijlstra , Ingo Molnar , Mathieu Desnoyers , Arnd Bergmann , linux-arch@vger.kernel.org, linux-kernel@vger.kernel.org, Yury Norov , Lucas De Marchi , Jani Nikula , Andy Shevchenko , Kees Cook , Andrew Morton Subject: Re: [PATCH next 11/14] bit: Strengthen compile-time tests in GENMASK() and BIT() Message-ID: <20260121191448.1dc59684@pumpkin> In-Reply-To: <1ed83fd2-575b-4b22-9a01-b3a2110af78f@kernel.org> References: <20260121145731.3623-1-david.laight.linux@gmail.com> <20260121145731.3623-12-david.laight.linux@gmail.com> <1ed83fd2-575b-4b22-9a01-b3a2110af78f@kernel.org> X-Mailer: Claws Mail 4.1.1 (GTK 3.24.38; arm-unknown-linux-gnueabihf) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit On Wed, 21 Jan 2026 19:43:07 +0100 Vincent Mailhol wrote: > On 21/01/2026 at 15:57, david.laight.linux@gmail.com wrote: > > From: David Laight > > > > The current checks in GENMASK/BIT (eg reversed high/low) only work > > for 'integer constant expressions' not 'compile-time constants'. > > This is true for const_true() and -Wshift-count-overflow/negative. > > While compile-time constants may be unusual, they can happen through > > function inlining. > > Did those new checks actually found any real problem in the code? This > adds a lot of complexity so I am not sure whether this is a winning > trade-off. Not in an x86-64 allmodconfig build. They might in a 32bit one where there have definitely been issues. > > > This isn't too bad with gcc, but if clang detects a negative/over-large > > shift it treats it as 'undefined behaviour' and silently discards all > > code that would use the result, so: > > int f(u32 x) {int n = 32; return x >> n; } > > generates a function that just contains a 'return' instruction. > > If 'n' was a variable that happened to be 32, most modern cpu mask > > the count - so would return 'x', some might return 0. > > But then, you only solve that shift problem for GENMASK() and > BIT(). Any other usage of the left/right shifts are not diagnosed > unless your check get copy pasted all over the place. > > I think that such a check belongs to a static analyzer. Speaking of > which: > > $ cat test.c > typedef unsigned int u32; > static int f(u32 x) {int n = 32; return x >> n; } > > $ sparse test.c > test.c:2:46: warning: shift too big (32) for type unsigned int$ cat test.c > > So here, I would rather keep relying on sparse rather that introducing > the W=c logic and all that macro complexity. I suspect the compiler test will find more than sparse. I liked getting that to work, but maybe it is OTT. But the W=c is more generally useful. As well as removing all the compile-time tests from GENMASK() and (in another patch FIELD_PREP()) which really do bloat the .i file, I'd like to add some new tests to min/max/clamp to try to get rid of the more dodgy (and likely buggy) cases without breaking everyone's build - just failing the W=1 builds is better. Using a separate flag means you can use W=ce to stop the build, doing a W=1e build is hopeless. David > > > Yours sincerely, > Vincent Mailhol