[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH] misra: deviate C library-style functions from Misra C:2012 rule 11.8


  • To: "xen-devel@xxxxxxxxxxxxxxxxxxxx" <xen-devel@xxxxxxxxxxxxxxxxxxxx>
  • From: Dmytro Prokopchuk1 <dmytro_prokopchuk1@xxxxxxxx>
  • Date: Tue, 29 Sep 2026 09:03:01 +0000
  • Accept-language: en-US, uk-UA, ru-RU
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=epam.com; dmarc=pass action=none header.from=epam.com; dkim=pass header.d=epam.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=fafAK153eg918SSKENcO+oeH2Sl9Ie+i4cRFh2vgOvE=; b=ob2b87mRaUBokdTEMJju4vOea3TbFAbiYlLZl5uLrPWXd+P1mBJQ1cWmF99rSKqQ1CF4zmfz5+P6J9yCNwVe+hC4DsxvJVTSIKBOSfSjfHaO73DsHtrkVJY7L5R6Y2E2UucNG8J/OhWHowVGsuWhYu+nBIHYHFuRG+mp0L1o3MxGt5KmOORolbzGY3E+W4zswcpbNmD0sDay/MIeK8x2o/W1nILPjgkrMM53EUPyfDQJiorhnCClzrW+8KWUIh+pObOXHZq8r6BLQI1tqbp7AQ8B5B4fZOqpDFz3LuCkiAaZaQGSlkvB9zoVcQXCyp9PODjV40b5M3s8PkSAz5zyag==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=EvUkijEd+kAejbJXyTTLglW15fuOCveEXRSK/JMtgHmuQITRBvQ9pa6YhSnmWDAEfhtLA2NIDAI+6eYhdu5CUsxfd/FaKlz2ZRTzgKcn9TiYZf5L7uzlOyPPfOwkHMip0LPcCsipYdRAxrWnJgWIJRZozU7xIDVE3PGyGX03EI0SE097/7U8ESoRtFkia617zPLlgDMw/3YzX+e6ky6bELoWBAP1G6OdHmbyKNNW6EeFPegJIBy8DUauF1Whq88MH6ILVUFHmFNvnc59fkHxeO8sEAE4JjMfS4W+MXpUgyGIsb/IUiSie3SWOFOffYKsiies91ghDHIr3ykH2d2M2A==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=epam.com header.i="@epam.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:x-ms-exchange-senderadcheck"
  • Authentication-results: mx.microsoft.com 1; dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=epam.com;
  • Cc: Dmytro Prokopchuk1 <dmytro_prokopchuk1@xxxxxxxx>, Nicola Vetrini <nicola.vetrini@xxxxxxxxxxx>, Doug Goldstein <cardoe@xxxxxxxxxx>, Stefano Stabellini <sstabellini@xxxxxxxxxx>, Andrew Cooper <andrew.cooper3@xxxxxxxxxx>, Anthony PERARD <anthony.perard@xxxxxxxxxx>, Michal Orzel <michal.orzel@xxxxxxx>, Jan Beulich <jbeulich@xxxxxxxx>, Julien Grall <julien@xxxxxxx>, Roger Pau Monné <roger@xxxxxxxxxxxxxx>
  • Delivery-date: Tue, 29 Sep 2026 09:03:27 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>
  • Thread-index: AQHdT/FUuEZ9j2ZjeEWRZmF5vcrM7g==
  • Thread-topic: [PATCH] misra: deviate C library-style functions from Misra C:2012 rule 11.8

bsearch(), memchr(), memchr_inv(), strchr(), strpbrk(), strrchr() and
strstr() all accept a const pointer/object but return a non-const pointer
to the matched element or byte, matching their standard C library
interfaces. The const qualifier is deliberately stripped so that callers
searching a non-const object get back a mutable pointer to it. Fixing
this would require changing the public API, so document these uses as
deviations instead.

Update docs/misra/rules.rst to note that this class of double-use
library functions is deviated on a per-function basis.

Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@xxxxxxxx>
---
Test CI pipeline: 
https://gitlab.com/xen-project/people/dimaprkp4k/xen/-/pipelines/2892411430
---
 automation/eclair_analysis/ECLAIR/deviations.ecl | 9 +++++++++
 docs/misra/deviations.rst                        | 9 +++++++++
 docs/misra/rules.rst                             | 5 ++++-
 3 files changed, 22 insertions(+), 1 deletion(-)

diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl 
b/automation/eclair_analysis/ECLAIR/deviations.ecl
index 33d508a2fb..0b87bd1d6f 100644
--- a/automation/eclair_analysis/ECLAIR/deviations.ecl
+++ b/automation/eclair_analysis/ECLAIR/deviations.ecl
@@ -445,6 +445,15 @@ write or not"
 
-config=MC3A2.R11.8,reports+={safe,"any_area(any_loc(text(^.*__hvm_copy.*HVMCOPY_to_guest
 doesn't modify.*$)))"}
 -doc_end
 
+-doc_begin="Functions bsearch(), memchr(), memchr_inv(), strchr(), strpbrk(),
+strrchr() and strstr() accept a const pointer/object and return a non-const
+pointer to the matched element or byte, matching their standard C library
+interfaces. The const qualifier is deliberately stripped so that callers
+searching a non-const object get back a mutable pointer. This use is deemed
+safe."
+-config=MC3A2.R11.8,reports+={safe,"any_area(any_loc(file(^xen/include/xen/bsearch\\.h|xen/lib/memchr\\.c|xen/lib/memchr_inv\\.c|xen/lib/strchr\\.c|xen/lib/strpbrk\\.c|xen/lib/strrchr\\.c|xen/lib/strstr\\.c$)))"}
+-doc_end
+
 -doc_begin="This construct is used to check if the type is scalar, and for 
this purpose the use of 0 as a null pointer constant is deliberate."
 -config=MC3A2.R11.9,reports+={deliberate, 
"any_area(any_loc(any_exp(macro(^__ACCESS_ONCE$))))"
 }
diff --git a/docs/misra/deviations.rst b/docs/misra/deviations.rst
index b048309596..e3ad3545bc 100644
--- a/docs/misra/deviations.rst
+++ b/docs/misra/deviations.rst
@@ -427,6 +427,15 @@ Deviations related to MISRA C:2012 Rules:
        readability.
      - Tagged as `safe` for ECLAIR.
 
+   * - R11.8
+     - Functions bsearch(), memchr(), memchr_inv(), strchr(), strpbrk(),
+       strrchr() and strstr() accept a const pointer/object and return a
+       non-const pointer to the matched element or byte, matching their
+       standard C library interfaces. The const qualifier is deliberately
+       stripped so that callers searching a non-const object get back a
+       mutable pointer. This use is deemed safe.
+     - Tagged as `safe` for ECLAIR.
+
    * - R11.9
      - __ACCESS_ONCE uses an integer, which happens to be zero, as a
        compile time check. The typecheck uses a cast. The usage of zero or 
other
diff --git a/docs/misra/rules.rst b/docs/misra/rules.rst
index c9bbab6c08..644e897558 100644
--- a/docs/misra/rules.rst
+++ b/docs/misra/rules.rst
@@ -469,7 +469,10 @@ maintainers if you want to suggest a change.
    * - `Rule 11.8 
<https://gitlab.com/MISRA/MISRA-C/MISRA-C-2012/Example-Suite/-/blob/master/R_11_08.c>`_
      - Required
      - A cast shall not remove any const or volatile qualification from the 
type pointed to by a pointer
-     -
+     - Some standard C library-style functions are inherently double-use,
+       accepting a const argument and returning a non-const pointer into
+       it so that callers searching a non-const object get back a
+       mutable pointer. Such uses are deviated on a per-function basis.
 
    * - `Rule 11.9 
<https://gitlab.com/MISRA/MISRA-C/MISRA-C-2012/Example-Suite/-/blob/master/R_11_09.c>`_
      - Required
-- 
2.43.0



 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.