From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([208.118.235.92]:54908) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1SEi9I-0002Kf-Dr for qemu-devel@nongnu.org; Mon, 02 Apr 2012 10:22:30 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1SEi9B-0007kw-Jx for qemu-devel@nongnu.org; Mon, 02 Apr 2012 10:22:23 -0400 Received: from mx1.redhat.com ([209.132.183.28]:42313) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1SEi9B-0007km-Bg for qemu-devel@nongnu.org; Mon, 02 Apr 2012 10:22:17 -0400 Date: Mon, 2 Apr 2012 15:22:11 +0100 From: "Daniel P. Berrange" Message-ID: <20120402142211.GH19259@redhat.com> References: <1333363816-1691-1-git-send-email-berrange@redhat.com> <1333363816-1691-9-git-send-email-berrange@redhat.com> <20120402121736.GC19259@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: Content-Transfer-Encoding: quoted-printable Subject: Re: [Qemu-devel] [PATCH 8/9] Add more format string warning flags Reply-To: "Daniel P. Berrange" List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Peter Maydell Cc: qemu-devel@nongnu.org On Mon, Apr 02, 2012 at 03:04:54PM +0100, Peter Maydell wrote: > On 2 April 2012 13:17, Daniel P. Berrange wrote: > > On Mon, Apr 02, 2012 at 01:13:56PM +0100, Peter Maydell wrote: > >> On 2 April 2012 11:50, Daniel P. Berrange wrot= e: > >> > +#if defined __GNUC__ > >> > +# define GCC_WARNINGS_SAVE =C2=A0 =C2=A0 =C2=A0_Pragma("GCC diagn= ostic push") > >> > +# define GCC_WARNINGS_RESTORE =C2=A0 _Pragma("GCC diagnostic pop"= ) > >> > +# define DO_PRAGMA(x) =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 _Pragma(= #x) > >> > +# define GCC_WARNINGS_IGNORE(x) DO_PRAGMA(GCC diagnostic ignored = x) > >> > +#else > >> > +# define GCC_WARNINGS_SAVE > >> > +# define GCC_WARNINGS_RESTORE > >> > +# define GCC_WARNINGS_IGNORE(x) > >> > +#endif > >> > >> Do these pragmas work on all versions of gcc that we support? > >> Google suggests that the push/pop ones are only gcc 4.6 or better, > >> for example. > > > > Hmm, the gcc info pages didn't mention any version constraints, but I= 'll > > investigate this >=20 > Having thought about it a little more, to be honest I'm not really > convinced that we should have these anyway. Better just to not enable > the format-nonliteral warning. (format-security should catch the cases > we care most about anyway, I think.) The -Wformat-security option can only catch problems if the format string is a literal. eg so it'd miss this: void foo(void) { int notastring =3D 1; const char *format =3D "String is %s"; sprintf(format, notastring); } There are a handful of places in QEMU which do that with non-trivial format strings & were easy to fix in this patch, which I think is a worthwhile improvement. The cases in the *-user/strace.c file though are not practical to fix, without significant re-design of the code in question. I'm fine if we just include those easy fixes, while leaving the actual warning flag disabled for now - someone can revisit later if desired. Daniel --=20 |: http://berrange.com -o- http://www.flickr.com/photos/dberrange= / :| |: http://libvirt.org -o- http://virt-manager.or= g :| |: http://autobuild.org -o- http://search.cpan.org/~danberr= / :| |: http://entangle-photo.org -o- http://live.gnome.org/gtk-vn= c :|