|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [PATCH] eclair: widen R11.1 noreturn cast deviation
The existing safe-cast rule for noreturn function pointers only matched a void * parameter. Generalize it to also match unsigned int and const struct cpu_user_regs *, so casts like gicv2_do_LPI to do_LPI in gic-v2.c, and unexpected_machine_check to mce_callbacks.handler in mce.c, are tagged safe without duplicating the deviation. Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@xxxxxxxx> --- Test CI pipeline: https://gitlab.com/xen-project/people/dimaprkp4k/xen/-/pipelines/2892634720 --- automation/eclair_analysis/ECLAIR/deviations.ecl | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl b/automation/eclair_analysis/ECLAIR/deviations.ecl index 0b87bd1d6f..03116d236d 100644 --- a/automation/eclair_analysis/ECLAIR/deviations.ecl +++ b/automation/eclair_analysis/ECLAIR/deviations.ecl @@ -391,11 +391,13 @@ constant expressions are required.\"" } -doc_end --doc_begin="The conversion from 'void noreturn (*)(void *)' to 'void (*)(void *)' is safe -because the semantics of the 'noreturn' attribute do not alter the calling convention or behavior of the resulting code." +-doc_begin="The conversion from 'void noreturn (*)(void *)', 'void noreturn (*)(unsigned int)' or +'void noreturn (*)(const struct cpu_user_regs *)' to the corresponding non-noreturn function +pointer type is safe because the semantics of the 'noreturn' attribute do not alter the calling +convention or behavior of the resulting code." -config=MC3A2.R11.1,casts+={safe, - "kind(bitcast)&&to(type(pointer(inner(return(builtin(void))&&all_param(1, pointer(builtin(void)))))))&&from(expr(skip(!syntactic(), - ref(property(noreturn)))))"} + "kind(bitcast)&&to(type(pointer(inner(return(builtin(void))&&all_param(1, pointer(builtin(void))||builtin(unsigned int)||pointer(^struct cpu_user_regs$))))))&&from(expr(skip(!syntactic(), + ref(property(noreturn)))))"} -doc_end -doc_begin="The conversion from a pointer to an incomplete type to unsigned long does not lose any information, provided that the target type has enough bits to store it." -- 2.43.0
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |