[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH] automation/eclair: generalize the noreturn function-pointer deviation


  • To: "xen-devel@xxxxxxxxxxxxxxxxxxxx" <xen-devel@xxxxxxxxxxxxxxxxxxxx>
  • From: Dmytro Prokopchuk1 <dmytro_prokopchuk1@xxxxxxxx>
  • Date: Mon, 5 Oct 2026 18:56:23 +0000
  • Accept-language: en-US, uk-UA, ru-RU
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=epam.com; dmarc=pass action=none header.from=epam.com; dkim=pass header.d=epam.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=gjpIctBI4RmCZYIcG2V/Hs4Wow7IW5zTz4571QN429E=; b=EN0ZxzhzcxOsqSmvGth5y18KReVPtYvaLIY3yZxnBwZM0q7LkZhlQX08aL/R+7yB6eZIpN8PaHlRhOJnLrzNhEtWLvgLACRv9IRbgLsdWb+Sku6DT6VOMcWx/587ng7IBAkaozIo3hqrDsItIMQCjLgwfS5TXyo7oyItgy0+U8yTBkbEAqQUSAYWNn9hJeTKmzUNpray64vWiAJydBTg5Squxj3nR8G4c6bATRvpQDRb0vuU4TscTU5UNgB4q5ldrZudVCFvUQPdCuniTOnmfEk+Lo9516awPZKTcgXqNfaCAG0/uvTMu77HZF0YgXrQ14TgEpgShl7uxnyLVgUDAg==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=GqmCEllBiFRyH6NQarpH73fcSgQaBnf6oTS8dvT9365ggspaQHar8QZtzSSK1JGNo6UqILIhuJkXfSC90nsITLtFKzx+22KlG7gOCjMvlHATnqqdMB5206tma81vCkac9wW/ADeenpEjmT9bSu0+sLjS+Cbe7MkPd8wxBQMF9hq+oIEiXJztuQV5vmXGMe/HWl7r2HAcSSt0lHidAmtn1K2AT2nrczEYxnTE9+Ox7fvBUeucamfNEhiAgiw8DPGlEjpSS3uWEtsN2/35dl8R7ZbHSnpAgmeMBHxAFuR+/3kX+UGgDKK8Xyv5eYIJl+J96UambM1S86mOUU9Jlx6ZsQ==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=epam.com header.i="@epam.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:x-ms-exchange-senderadcheck"
  • Authentication-results: mx.microsoft.com 1; dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=epam.com;
  • Cc: Dmytro Prokopchuk1 <dmytro_prokopchuk1@xxxxxxxx>, Nicola Vetrini <nicola.vetrini@xxxxxxxxxxx>, Doug Goldstein <cardoe@xxxxxxxxxx>, Stefano Stabellini <sstabellini@xxxxxxxxxx>, Andrew Cooper <andrew.cooper3@xxxxxxxxxx>, Anthony PERARD <anthony.perard@xxxxxxxxxx>, Michal Orzel <michal.orzel@xxxxxxx>, Jan Beulich <jbeulich@xxxxxxxx>, Julien Grall <julien@xxxxxxx>, Roger Pau Monné <roger@xxxxxxxxxxxxxx>
  • Delivery-date: Mon, 05 Oct 2026 18:56:43 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>
  • Thread-index: AQHdVPs3la7Yb/mPXkSleujSDB++zQ==
  • Thread-topic: [PATCH] automation/eclair: generalize the noreturn function-pointer deviation

The R11.1 safe cast only matched void noreturn (*)(void *). Accept any
noreturn function pointer converted to a compatible function pointer.
canonical() covers typeof destinations, and compatible_deep_unqualified
keeps the parameter and return types aligned.

Signed-off-by: Dmytro Prokopchuk <dmytro_prokopchuk1@xxxxxxxx>
---

This patch tries to cover both of these:

1. eclair: widen R11.1 noreturn cast deviation
https://patchew.org/Xen/c6632dd805a119aca54b9d1ae2eea68ef9c1334c.1790674358.git.dmytro._5Fprokopchuk1@xxxxxxxx/

2. Eclair: relax "noreturn" function-pointer conversion deviation
https://patchew.org/Xen/6d212d60-5c0b-4909-996d-5d6a4906b7e1@xxxxxxxx/4cca58b6-b555-4064-aa26-5204dc4b99cc@xxxxxxxx/

Test CI pipeline:
https://gitlab.com/xen-project/people/dimaprkp4k/xen/-/pipelines/2914802667

The only one Rule11.1 violation remains, which is covered by this Jan's patch:
x86/kexec: address Misra rule 11.1 violation in machine_kexec_load()

---
 automation/eclair_analysis/ECLAIR/deviations.ecl | 9 +++++----
 docs/misra/deviations.rst                        | 8 ++++----
 docs/misra/rules.rst                             | 7 ++++---
 3 files changed, 13 insertions(+), 11 deletions(-)

diff --git a/automation/eclair_analysis/ECLAIR/deviations.ecl 
b/automation/eclair_analysis/ECLAIR/deviations.ecl
index 6cdb10a129..d89976a894 100644
--- a/automation/eclair_analysis/ECLAIR/deviations.ecl
+++ b/automation/eclair_analysis/ECLAIR/deviations.ecl
@@ -394,11 +394,12 @@ constant expressions are required.\""
 }
 -doc_end
 
--doc_begin="The conversion from 'void noreturn (*)(void *)' to 'void (*)(void 
*)' is safe
-because the semantics of the 'noreturn' attribute do not alter the calling 
convention or behavior of the resulting code."
+-doc_begin="The conversion from a noreturn function pointer to a function 
pointer
+with a compatible signature is safe because the semantics of the 'noreturn'
+attribute do not alter the calling convention or behavior of the resulting 
code."
 -config=MC3A2.R11.1,casts+={safe,
-  "kind(bitcast)&&to(type(pointer(inner(return(builtin(void))&&all_param(1, 
pointer(builtin(void)))))))&&from(expr(skip(!syntactic(),
-   ref(property(noreturn)))))"} 
+  
"kind(bitcast)&&to(type(canonical(__function_pointer_types)))&&from(expr(skip(!syntactic(),
+   ref(property(noreturn)))))&&relation(compatible_deep_unqualified)"}
 -doc_end
 
 -doc_begin="The conversion from a pointer to an incomplete type to unsigned 
long does not lose any information, provided that the target type has enough 
bits to store it."
diff --git a/docs/misra/deviations.rst b/docs/misra/deviations.rst
index 6bcc2adf95..ed7129b8dc 100644
--- a/docs/misra/deviations.rst
+++ b/docs/misra/deviations.rst
@@ -392,10 +392,10 @@ Deviations related to MISRA C:2012 Rules:
      - Tagged as `safe` for ECLAIR.
 
    * - R11.1
-     - The conversion from 'void noreturn (*)(...)' to 'void (*)(...)' is safe
-       because the semantics of the 'noreturn' attribute do not alter the 
calling
-       convention or behavior of the resulting code, parameters handling remain
-       consistent.
+     - The conversion from a noreturn function pointer to a function pointer
+       with a compatible signature is safe because the semantics of the
+       'noreturn' attribute do not alter the calling convention or behavior
+       of the resulting code.
      - Tagged as `safe` for ECLAIR.
 
    * - R11.2
diff --git a/docs/misra/rules.rst b/docs/misra/rules.rst
index a59cf1782e..bd288bba29 100644
--- a/docs/misra/rules.rst
+++ b/docs/misra/rules.rst
@@ -435,9 +435,10 @@ maintainers if you want to suggest a change.
        and any other type
      - All conversions to integer types are permitted if the destination
        type has enough bits to hold the entire value. Conversions to bool
-       and void* are permitted. Conversions from 'void noreturn (*)(...)'
-       to 'void (*)(...)' are permitted. Conversions from [unsigned] long
-       or '(void *)' to a function pointer are permitted.
+       and void* are permitted. Conversions from a noreturn function pointer
+       to a function pointer with a compatible signature are permitted.
+       Conversions from [unsigned] long or '(void *)' to a function pointer
+       are permitted.
        Example::
 
            unsigned long func_addr = (unsigned long)&some_function;
-- 
2.43.0



 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.