|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [PATCH 04/12] x86: add noreturn in a few more places
On 29.08.2026 15:21, Nicola Vetrini wrote:
> On 2026-08-28 09:01, Jan Beulich wrote:
>> start_secondary(), do_double_fault(), play_dead(), and tboot_s3_error()
>> never return, so would better be annotated anyway. The
>> do_double_fault()
>> change needs accompanying by adjustments to entry_from_{pv,xen}(), as
>> Eclair then deems the "return" there as unreachable.
>>
>> context_switch() and continue_running() are odd: We can't
>> (unconditionally) add noreturn to their declarations, as Arm's variants
>> do
>> return. Put the attribute on x86'es definitions instead (the use of
>> unreachable() in reset_stack_and_call_ind() allows the compiler to
>> figure
>> that out itself, but Eclair wants the annotation in addition).
>>
>> Signed-off-by: Jan Beulich <jbeulich@xxxxxxxx>
>
> Reviewed-by: Nicola Vetrini <nicola.vetrini@xxxxxxxxxxx>
Thanks, yet Andrew's objection will need dealing with.
>> ---
>> entry_from_pv() wants the annotation only when PV=n, yet once added gcc
>> then warns about "return" being used in a "noreturn" function. Is there
>> any other approach to address this besides adding #ifdef inside the
>> function (i.e. replacing the !IS_ENABLED(CONFIG_PV) check that's
>> there)?
>
> Besides GCC's warning, this would violate MISRA C's Rule 17.9 ("A
> function declared with a _Noreturn function specifier shall not return
> to its caller")
> which is not (yet) adopted by Xen, as it comes with MISRA C:2012
> Amendment 3, whereas as you know Xen is based on MISRA C:2012 Amendment
> 2 rules.
> Besides this, perhaps an alternative could be something like this
> (untested):
>
> #define __noreturn_0
> #define __noreturn_1 __attribute__((noreturn))
>
> #define __noreturn_select(x) __noreturn_select_(x)
> #define __noreturn_select_(x) __noreturn_ ## x
>
> #define noreturn(cond) __noreturn_select(cond)
>
> assuming use sites such as noreturn(IS_ENABLED(CONFIG_FOO))
But how is
void asmlinkage noreturn(!IS_ENABLED(CONFIG_PV))
entry_from_pv(struct cpu_user_regs *regs)
(besides of course not being correct to use this way) different from
void asmlinkage
#ifndef CONFIG_PV
noreturn
#endif
entry_from_pv(struct cpu_user_regs *regs)
? We'd still end up with a "noreturn" function having "return" statements.
Jan
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |