|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [PATCH] misra: deviate C library-style functions from Misra C:2012 rule 11.8
bsearch(), memchr(), memchr_inv(), strchr(), strpbrk(), strrchr() and strstr() all accept a const pointer/object but return a non-const pointer to the matched element or byte, matching their standard C library interfaces. The const qualifier is deliberately stripped so that callers searching a non-const object get back a mutable pointer to it. Fixing this would require changing the public API, so document these uses as deviations instead. Update docs/misra/rules.rst to note that this class of double-use library functions is deviated on a per-function basis. Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@xxxxxxxx> --- Test CI pipeline: https://gitlab.com/xen-project/people/dimaprkp4k/xen/-/pipelines/2892411430 --- automation/eclair_analysis/ECLAIR/deviations.ecl | 9 +++++++++ docs/misra/deviations.rst | 9 +++++++++ docs/misra/rules.rst | 5 ++++- 3 files changed, 22 insertions(+), 1 deletion(-) diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl b/automation/eclair_analysis/ECLAIR/deviations.ecl index 33d508a2fb..0b87bd1d6f 100644 --- a/automation/eclair_analysis/ECLAIR/deviations.ecl +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl @@ -445,6 +445,15 @@ write or not" -config=MC3A2.R11.8,reports+={safe,"any_area(any_loc(text(^.*__hvm_copy.*HVMCOPY_to_guest doesn't modify.*$)))"} -doc_end +-doc_begin="Functions bsearch(), memchr(), memchr_inv(), strchr(), strpbrk(), +strrchr() and strstr() accept a const pointer/object and return a non-const +pointer to the matched element or byte, matching their standard C library +interfaces. The const qualifier is deliberately stripped so that callers +searching a non-const object get back a mutable pointer. This use is deemed +safe." +-config=MC3A2.R11.8,reports+={safe,"any_area(any_loc(file(^xen/include/xen/bsearch\\.h|xen/lib/memchr\\.c|xen/lib/memchr_inv\\.c|xen/lib/strchr\\.c|xen/lib/strpbrk\\.c|xen/lib/strrchr\\.c|xen/lib/strstr\\.c$)))"} +-doc_end + -doc_begin="This construct is used to check if the type is scalar, and for this purpose the use of 0 as a null pointer constant is deliberate." -config=MC3A2.R11.9,reports+={deliberate, "any_area(any_loc(any_exp(macro(^__ACCESS_ONCE$))))" } diff --git a/docs/misra/deviations.rst b/docs/misra/deviations.rst index b048309596..e3ad3545bc 100644 --- a/docs/misra/deviations.rst +++ b/docs/misra/deviations.rst @@ -427,6 +427,15 @@ Deviations related to MISRA C:2012 Rules: readability. - Tagged as `safe` for ECLAIR. + * - R11.8 + - Functions bsearch(), memchr(), memchr_inv(), strchr(), strpbrk(), + strrchr() and strstr() accept a const pointer/object and return a + non-const pointer to the matched element or byte, matching their + standard C library interfaces. The const qualifier is deliberately + stripped so that callers searching a non-const object get back a + mutable pointer. This use is deemed safe. + - Tagged as `safe` for ECLAIR. + * - R11.9 - __ACCESS_ONCE uses an integer, which happens to be zero, as a compile time check. The typecheck uses a cast. The usage of zero or other diff --git a/docs/misra/rules.rst b/docs/misra/rules.rst index c9bbab6c08..644e897558 100644 --- a/docs/misra/rules.rst +++ b/docs/misra/rules.rst @@ -469,7 +469,10 @@ maintainers if you want to suggest a change. * - `Rule 11.8 <https://gitlab.com/MISRA/MISRA-C/MISRA-C-2012/Example-Suite/-/blob/master/R_11_08.c>`_ - Required - A cast shall not remove any const or volatile qualification from the type pointed to by a pointer - - + - Some standard C library-style functions are inherently double-use, + accepting a const argument and returning a non-const pointer into + it so that callers searching a non-const object get back a + mutable pointer. Such uses are deviated on a per-function basis. * - `Rule 11.9 <https://gitlab.com/MISRA/MISRA-C/MISRA-C-2012/Example-Suite/-/blob/master/R_11_09.c>`_ - Required -- 2.43.0
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |