From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from [140.186.70.92] (port=47826 helo=eggs.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1OsD5k-0007u7-W4 for qemu-devel@nongnu.org; Sun, 05 Sep 2010 07:09:01 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.69) (envelope-from ) id 1OsBaU-00006l-7O for qemu-devel@nongnu.org; Sun, 05 Sep 2010 05:32:35 -0400 Received: from mx1.redhat.com ([209.132.183.28]:23086) by eggs.gnu.org with esmtp (Exim 4.69) (envelope-from ) id 1OsBaU-000060-06 for qemu-devel@nongnu.org; Sun, 05 Sep 2010 05:32:34 -0400 Date: Sun, 5 Sep 2010 12:26:36 +0300 From: "Michael S. Tsirkin" Message-ID: <20100905092636.GA17394@redhat.com> References: <20100905075403.GC16215@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline In-Reply-To: Content-Transfer-Encoding: quoted-printable Subject: [Qemu-devel] Re: [PATCH 1/5] Suppress some gcc warnings with -Wtype-limits List-Id: qemu-devel.nongnu.org List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Blue Swirl Cc: qemu-devel On Sun, Sep 05, 2010 at 09:06:10AM +0000, Blue Swirl wrote: > On Sun, Sep 5, 2010 at 7:54 AM, Michael S. Tsirkin wro= te: > > On Sat, Sep 04, 2010 at 05:21:24PM +0000, Blue Swirl wrote: > >> In the unsigned number space, the checks can be merged into one, > >> assuming that BLKDBG_EVEN_MAX is less than INT_MAX. Alternatively we > >> could have: > >> =A0- =A0 =A0if (event < 0 || event >=3D BLKDBG_EVENT_MAX) { > >> =A0+ =A0 =A0if ((int)event < 0 || event >=3D BLKDBG_EVENT_MAX) { > >> > >> This would also implement the check that the writer of this code was > >> trying to make. > >> The important thing to note is however is that the check as it is no= w > >> is not correct. > > > > I agree. But it seems to indicate a bigger problem. > > > > If we are trying to pass in a negative value, which is not one > > of enum values, using BlkDebugEvent as type is just confusing, > > we should just pass int instead. >=20 > AFAICT it's only possible to use the values listed in event_names in > blkdebug.c, other values are rejected. So the check should actually be > an assert() or it could even be removed. Sounds good. > >> >> How about adding assert(OMAP_EMIFS_BASE =3D=3D 0) and commenting = out the > >> >> check? Then if the value changes, the need to add the comparison = back > >> >> will be obvious. > >> > > >> > This would work but it's weird. =A0The thing is it's currently a c= orrect > >> > code and the check may be useless but it's the optimiser's task to > >> > remove it, not ours. =A0The compiler is not able to tell whether t= he > >> > check makes sense or nott, because the compiler only has access to > >> > preprocessed code. =A0So why should you let the compiler have anyt= hing > >> > to say on it. > >> > >> Good point. I'll try to invent something better. > > > > Use #pragma to supress the warning? Maybe we could wrap this in a mac= ro .. >=20 > Those lines may also desynch silently with changes to OMAP_EMIFS_BASE. >=20 > I think the assertion is still the best way, it ensures that something > will happen if OMAP_EMIFS_BASE changes. We could for example remove > OMAP_EMIFS_BASE entirely (it's only used for the check), but someone > adding a new define could still forget to adjust the check anyway. We could replace it with a macro #define OMAP_EMIFS_VALID(addr) ((target_phys_addr_t)addr < OMAP_EMIFF_BAS= E)=20 but all this does look artificial. And of course using type casts is always scary ... Would it help to have some inline functions that do the range checking co= rrectly? We have a couple of range helpers in pci.h, these could be moved out to range.h and we could add some more. As there act on u64 this will get the type limits mostly automatically right. --=20 MST