[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH] eclair: widen R11.1 noreturn cast deviation


  • To: "xen-devel@xxxxxxxxxxxxxxxxxxxx" <xen-devel@xxxxxxxxxxxxxxxxxxxx>
  • From: Dmytro Prokopchuk1 <dmytro_prokopchuk1@xxxxxxxx>
  • Date: Tue, 29 Sep 2026 09:48:41 +0000
  • Accept-language: en-US, uk-UA, ru-RU
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=epam.com; dmarc=pass action=none header.from=epam.com; dkim=pass header.d=epam.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=dF+r+n3AjReUdCAExrtgvlws/DD1uel99ehF0ITSJRI=; b=WWGT3fo8omwjiycjkyZof8mQy2QvoYOoZKebOCg2bvNK4EQeNRtbTGZB3mH3bfZvcdOarAZPEqeudB25gACd1CDfNv2yEcG22C0qib2JWmFje7R/o8tfEZAbKOZ8cm33jexj+CF+Zn4PH/2H4bjZn94ElK9uoI9JsQ6PMmb5cltcDoBWcaSqVohswyc9hCFBqbIWPLv7H+JoQhkc56hK4y9TFku8lP7LswPkj5ApLl1ByPYlu5z/ukGrae31KMqCfauFD4BBC4CfY9mUcvAktB0x8I6OQ+GfUY9C6MGz7/h22zQPK4h4GmQJEzvD/8YUe9XedAky1RiIkfki2iMBrQ==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=bVgenDrnfNQS+sZje/FcF8vTSIgs0sUovUqAsH18aoVru+scdcAfBqNqz8ZKh5PqJxKQnFArodYblZ6F1tt88L3bhKLERx4C33dHLAqowBvYY811GXUUgJlCQ+Ez0E3uLflVlwwPb8TuGSGdrQ/28OnZEm+FT4xaSP+e2Nd69XqPgzcTz3dldCXzrjIh+I4lMJrMxqmpqgix+Uwv64JXRm+aBzzeXHXOI3b2mGRCB/n3dB+oSWYZvoe8RYm/56T0IEhEL4Pqsqhj8gO4shoa0mGDWrToUc+r17ejeoxhM3hSqd5gQdlZdSte/jzmwNCeQUw7iM/q0fAZgNYxdkATMA==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=epam.com header.i="@epam.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:x-ms-exchange-senderadcheck"
  • Authentication-results: mx.microsoft.com 1; dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=epam.com;
  • Cc: Dmytro Prokopchuk1 <dmytro_prokopchuk1@xxxxxxxx>, Nicola Vetrini <nicola.vetrini@xxxxxxxxxxx>, Doug Goldstein <cardoe@xxxxxxxxxx>, Stefano Stabellini <sstabellini@xxxxxxxxxx>
  • Delivery-date: Tue, 29 Sep 2026 09:48:53 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>
  • Thread-index: AQHdT/e1WdmOtRNOG0e6Lpur+g94cQ==
  • Thread-topic: [PATCH] eclair: widen R11.1 noreturn cast deviation

The existing safe-cast rule for noreturn function pointers only
matched a void * parameter. Generalize it to also match unsigned int
and const struct cpu_user_regs *, so casts like gicv2_do_LPI to
do_LPI in gic-v2.c, and unexpected_machine_check to
mce_callbacks.handler in mce.c, are tagged safe without duplicating
the deviation.

Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@xxxxxxxx>
---
Test CI pipeline: 
https://gitlab.com/xen-project/people/dimaprkp4k/xen/-/pipelines/2892634720
---
 automation/eclair_analysis/ECLAIR/deviations.ecl | 10 ++++++----
 1 file changed, 6 insertions(+), 4 deletions(-)

diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl 
b/automation/eclair_analysis/ECLAIR/deviations.ecl
index 0b87bd1d6f..03116d236d 100644
--- a/automation/eclair_analysis/ECLAIR/deviations.ecl
+++ b/automation/eclair_analysis/ECLAIR/deviations.ecl
@@ -391,11 +391,13 @@ constant expressions are required.\""
 }
 -doc_end
 
--doc_begin="The conversion from 'void noreturn (*)(void *)' to 'void (*)(void 
*)' is safe
-because the semantics of the 'noreturn' attribute do not alter the calling 
convention or behavior of the resulting code."
+-doc_begin="The conversion from 'void noreturn (*)(void *)', 'void noreturn 
(*)(unsigned int)' or
+'void noreturn (*)(const struct cpu_user_regs *)' to the corresponding 
non-noreturn function
+pointer type is safe because the semantics of the 'noreturn' attribute do not 
alter the calling
+convention or behavior of the resulting code."
 -config=MC3A2.R11.1,casts+={safe,
-  "kind(bitcast)&&to(type(pointer(inner(return(builtin(void))&&all_param(1, 
pointer(builtin(void)))))))&&from(expr(skip(!syntactic(),
-   ref(property(noreturn)))))"} 
+  "kind(bitcast)&&to(type(pointer(inner(return(builtin(void))&&all_param(1, 
pointer(builtin(void))||builtin(unsigned int)||pointer(^struct 
cpu_user_regs$))))))&&from(expr(skip(!syntactic(),
+   ref(property(noreturn)))))"}
 -doc_end
 
 -doc_begin="The conversion from a pointer to an incomplete type to unsigned 
long does not lose any information, provided that the target type has enough 
bits to store it."
-- 
2.43.0



 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.