From: Claudio Fontana <cfontana@suse.de>
To: Mark Cave-Ayland <mark.cave-ayland@ilande.co.uk>,
qemu-devel@nongnu.org, peter.maydell@linaro.org
Subject: Re: [PATCH] utils/fifo8: change fatal errors from abort() to assert()
Date: Thu, 14 Jan 2021 11:15:47 +0100 [thread overview]
Message-ID: <10945f87-a43b-98c5-6f53-1042b3eb1311@suse.de> (raw)
In-Reply-To: <ec32506f-ec83-d166-f444-efa33e2867e9@ilande.co.uk>
On 1/14/21 10:58 AM, Mark Cave-Ayland wrote:
> On 14/01/2021 09:07, Claudio Fontana wrote:
>
>> On 1/14/21 9:33 AM, Mark Cave-Ayland wrote:
>>> Developer errors are better represented with assert() rather than abort().
>>
>> ... "also, make the tests more strict"
>>
>> I'd add this since the checks have been changed sometimes in the patch to be more strict.
>>
>> Reviewed-by: Claudio Fontana <cfontana@suse.de>
>
> Oh, that was not intentional on my part - I was aiming to keep the same logic but
> effectively invert the logic to keep the assert() happy. What did I miss?
Did I misunderstand? Comments below:
>
>
> ATB,
>
> Mark.
>
>>> Signed-off-by: Mark Cave-Ayland <mark.cave-ayland@ilande.co.uk>
>>> ---
>>> This was suggested by Peter during a discussion on IRC yesterday.
>>>
>>> ---
>>> util/fifo8.c | 16 ++++------------
>>> 1 file changed, 4 insertions(+), 12 deletions(-)
>>>
>>> diff --git a/util/fifo8.c b/util/fifo8.c
>>> index a5dd789ce5..d4d1c135e0 100644
>>> --- a/util/fifo8.c
>>> +++ b/util/fifo8.c
>>> @@ -31,9 +31,7 @@ void fifo8_destroy(Fifo8 *fifo)
>>>
>>> void fifo8_push(Fifo8 *fifo, uint8_t data)
>>> {
>>> - if (fifo->num == fifo->capacity) {
>>> - abort();
>>> - }
>>> + assert(fifo->num < fifo->capacity);
This changes the check effectively, the same logic would be in my view:
assert(fifo->num != fifo->capacity);
But I think your change actually makes sense.
>>> fifo->data[(fifo->head + fifo->num) % fifo->capacity] = data;
>>> fifo->num++;
>>> }
>>> @@ -42,9 +40,7 @@ void fifo8_push_all(Fifo8 *fifo, const uint8_t *data, uint32_t num)
>>> {
>>> uint32_t start, avail;
>>>
>>> - if (fifo->num + num > fifo->capacity) {
>>> - abort();
>>> - }
>>> + assert(fifo->num + num <= fifo->capacity);
>>>
>>> start = (fifo->head + fifo->num) % fifo->capacity;
>>>
>>> @@ -63,9 +59,7 @@ uint8_t fifo8_pop(Fifo8 *fifo)
>>> {
>>> uint8_t ret;
>>>
>>> - if (fifo->num == 0) {
>>> - abort();
>>> - }
>>> + assert(fifo->num > 0);
applying the exact same logic would be:
assert(fifo->num != 0);
but again, I think that the actual change is more expressive, and most likely is correct, just more strict.
>>> ret = fifo->data[fifo->head++];
>>> fifo->head %= fifo->capacity;
>>> fifo->num--;
>>> @@ -76,9 +70,7 @@ const uint8_t *fifo8_pop_buf(Fifo8 *fifo, uint32_t max, uint32_t *num)
>>> {
>>> uint8_t *ret;
>>>
>>> - if (max == 0 || max > fifo->num) {
>>> - abort();
>>> - }
>>> + assert(max > 0 && max <= fifo->num);
>>> *num = MIN(fifo->capacity - fifo->head, max);
>>> ret = &fifo->data[fifo->head];
>>> fifo->head += *num;
>>>
>>
>>
>
Ciao,
Claudio
next prev parent reply other threads:[~2021-01-14 10:16 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-01-14 8:33 [PATCH] utils/fifo8: change fatal errors from abort() to assert() Mark Cave-Ayland
2021-01-14 9:07 ` Claudio Fontana
2021-01-14 9:58 ` Mark Cave-Ayland
2021-01-14 10:15 ` Claudio Fontana [this message]
2021-01-14 11:06 ` Philippe Mathieu-Daudé
2021-01-21 9:50 ` Mark Cave-Ayland
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=10945f87-a43b-98c5-6f53-1042b3eb1311@suse.de \
--to=cfontana@suse.de \
--cc=mark.cave-ayland@ilande.co.uk \
--cc=peter.maydell@linaro.org \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).