From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AE166313293 for ; Tue, 16 Dec 2025 10:13:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.52 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1765879988; cv=none; b=bUDLZDDkZauRFwJfxx6gNR0kNw15w4Kvf//7k7fTK39mqCOC6tVsrX5G7bNsYlIP0XB7fvR2qHbGZMPXZxnMfSsKHp/+KukHxudbB1vz223WRz0iPgI3TqdlUPz1W10OurwpjicU7StKwIfvCR2rtITfmm2j8M7wp15EWRqgGqQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1765879988; c=relaxed/simple; bh=YLAj/r2FEDKQLmYCBxCODquRps9KIGCQUgaQHAAdQys=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=WAOz5qBUmvtAbsi8GuL2l/NtY7VNp79GgOWee5NjpMzhSXKxPL6Tg/JQKzbPP7v2kBzOP9FX6haTCxOGqNC8iP0RknCSsbIgzmFpnQXj0krDOub+IzSOojMIqT+SPzITB3Y1ZbmfNPoWgCe2LFeUrnYVQ6vcDbvViYQ3M8B4qME= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=suse.com; spf=pass smtp.mailfrom=suse.com; dkim=pass (2048-bit key) header.d=suse.com header.i=@suse.com header.b=fL5Nytjf; arc=none smtp.client-ip=209.85.128.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=suse.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=suse.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=suse.com header.i=@suse.com header.b="fL5Nytjf" Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-47a80d4a065so27405735e9.2 for ; Tue, 16 Dec 2025 02:13:05 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=google; t=1765879984; x=1766484784; darn=vger.kernel.org; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date:from:to :cc:subject:date:message-id:reply-to; bh=YJzjGjsbvSF4rzkdIfKfsW7zFxLeDwbsXmmlktvfWtc=; b=fL5Nytjfejj/UEXnGji+fG2GqVpUaCjEqOoYyUOOW6sZdU3Lh/2FRNU4ooBpCe0AeV k0EJQw5LpuMU4hyPMfkV8f4qzaEDdAN89s7/9e6LZJI0xs/245jxM/YaBIsioy64bdLP JV+C1GUhLEsPSJkFg3JP/4ByJdaL4v26XzvwnVI4+jvkapYPniu4zYcDCP/+4NWnZPCb 6dRRo4KPyj9uhDw+FlLHJazr+L372Mu/cGZO5PWW1iJm7NCGfzG2Jb6qZpX8CZXfCQBi j1B8eNn0G76Ip4sEgoTSWN4DwazJrcwszd4mBBnM5Q52jzOByEYDujJ3Bkt+X8UrJJeo hHhw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1765879984; x=1766484784; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=YJzjGjsbvSF4rzkdIfKfsW7zFxLeDwbsXmmlktvfWtc=; b=CasmUWakXHgwNpwR8ct1Ol/Bw9NhO+nrECukdgNArV+hFCRSrO32RdVi/lYurY3Y+E mNzkj1S6mixEj/01Q/A0trwizLuGrCLmCd5dfyj8LiVFXBUvnJT5O6g0ZWj7inbb7X5E 2SlrJhEmgX0RGQB1HAGgAE8CJUh5KZa+K2we4xTmz0OrWOwFe0mlQt6ENPMxgRh+kYA7 tYJA11c7Ofe8kp9LaunKOXPq6QCKv1i9PuEBi+FfbOFKxI3vwDmzsJ3L3q3yEFqD6uXZ seHpv8hCDtTTx4oPJ587boh9A0JYTgLAAKdcAMB4XPGJE3c4bZ9WyzhdrmeBydcAUaXc 4BOw== X-Forwarded-Encrypted: i=1; AJvYcCXKefPVrBk8exKga3ILmXkBryvGyg8FxI8K3/V/GIHTRtwSudlmA6oxQZDlhhqV4HHYAeTvINPQ+apzI3E=@vger.kernel.org X-Gm-Message-State: AOJu0YwiF7OuDWU2oxf8Uv9URRZgLrg/vJMQ4vtoSyBbrpZIa75ucADN 5DhEuhSEIKyyCfkPYLB4SIT6J0jc9rzld7RRK8XvrvCkME9fjb8VVEBaRL5tNM17m0w= X-Gm-Gg: AY/fxX6uHbALdWMZ/nM6E2hNM/HrGG4oVb8N/+rUS5EmqLufdBrzMk1PLk1/qj0eLSe /GI633D5v+/xQgmRAks2MWqUVruGRV5bjXVE7ScrEWdqszHHYbUTCJHfSD14kRaS+yEPdyVJiaw lIPi8XxlV3eVFqGJwNeTWDI1oXQ/J6i5LcwiVPXs3yONpL3Z/IpNTgzh6gBG3MpdLqXOurZ3+kM Qp31yEeBRUFKgNzEYpfbOpAhO/IBTmirRaYtMYR4Yc7zhL6FY+V7pQhlbCPodkSpaYiPdaTb4Iq UuQ8WlLh9ZHPBul9lQRbngIEm2cidgDgLMcdPJ35L51mhkCIH9ICKICWlGXIHnWKwfW86jDxpgr eUGtmaDNGHa0SuJ/tgAS3UKjdTlkXYJnKyYIbdouDWwyO8uRfnBmaOiqko0JIKTWaogwqtmZNl4 +exTO615Dr3k6H7g== X-Google-Smtp-Source: AGHT+IHT98Uk/FnvpzqT+v55I0LtEgak7CyvE/0SRVkDp20MTWGrAR3AknHG2PZnf6r8+xJCDqQ2jg== X-Received: by 2002:a05:600c:800f:b0:471:1765:839c with SMTP id 5b1f17b1804b1-47a8f9068c3mr114272215e9.20.1765879983993; Tue, 16 Dec 2025 02:13:03 -0800 (PST) Received: from pathway.suse.cz ([176.114.240.130]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-47bd8eb1f26sm8597415e9.0.2025.12.16.02.13.03 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 16 Dec 2025 02:13:03 -0800 (PST) Date: Tue, 16 Dec 2025 11:13:01 +0100 From: Petr Mladek To: Tamir Duberstein Cc: Andy Shevchenko , Steven Rostedt , Rasmus Villemoes , Sergey Senozhatsky , Kees Cook , linux-kernel@vger.kernel.org, oe-kbuild-all@lists.linux.dev, kernel test robot Subject: Re: [PATCH] printf: add __printf attribute Message-ID: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: On Mon 2025-12-08 16:07:28, Tamir Duberstein wrote: > On Mon, Dec 8, 2025 at 9:06 AM Petr Mladek wrote: > > > > On Mon 2025-12-08 15:30:53, Andy Shevchenko wrote: > > > On Sun, Dec 07, 2025 at 08:32:53PM -0500, Tamir Duberstein wrote: > > > > On Sat, Dec 6, 2025 at 4:45 PM Andy Shevchenko > > > > wrote: > > > > > On Sat, Dec 06, 2025 at 02:57:48PM -0500, Tamir Duberstein wrote: > > > > > > On Sat, Dec 6, 2025 at 2:43 PM Andy Shevchenko > > > > > > wrote: > > > > > > > On Sat, Dec 06, 2025 at 12:52:53PM -0500, Tamir Duberstein wrote: > > > > > > > > On Sat, Dec 6, 2025 at 12:49 PM Andy Shevchenko > > > > > > > > wrote: > > > > > > > > > On Sat, Dec 06, 2025 at 12:13:34PM -0500, Tamir Duberstein wrote: > > > > > > > > > > On Sat, Dec 6, 2025 at 11:11 AM Andy Shevchenko > > > > > > > > > > wrote: > > > > > > > > > > > On Sat, Dec 06, 2025 at 08:19:09AM -0500, Tamir Duberstein wrote: > > > > > > ... > > > > > > > > > > > > > > > -static void > > > > > > > > > > > > +static void __printf(2, 3) > > > > > > > > > > > > > > > > > > > > > > 3?! > > > > > > > > > > > > > > > > > > > > > > I think it should be (2, 0). Yes, the both users call it with "%p..." in format > > > > > > > > > > > string, but the second parameter tells compiler to check the variadic > > > > > > > > > > > arguments, which are absent here. Changing 'const void *p' to '...' will align > > > > > > > > > > > it with the given __printf() attribute, but I don't know if this what we want. > > > > > > > > > > > > > > > > > > > > The second parameter is the first-to-check, it is not specific to > > > > > > > > > > variadic arguments. Using 0 means that no arguments are checkable, so > > > > > > > > > > the compiler only validates the format string itself and won’t > > > > > > > > > > diagnose mismatches with `p`. This works whether or not we later > > > > > > > > > > change `const void *p` to `...`. > > > > > > > > > > > > > > > > > > Yes, but this is fragile. As I explained it works only because we supply > > > > > > > > > the format string stuck to "%p", anything else will require reconsidering > > > > > > > > > the function prototypes. So, strictly speaking this should be (2, 0) if > > > > > > > > > we leave const void *p as is. > > > > > > > > > > > > > > > > > I believe this is not correct. As I said, 0 means "do not check > > > > > > > > arguments" so only the format string will be checked. See the existing > > > > > > > > uses of this annotation in this file: > > > > > > > > > > > > > > > > static void __printf(7, 0) > > > > > > > > do_test(struct kunit *kunittest, const char *file, const int line, int > > > > > > > > bufsize, const char *expect, > > > > > > > > int elen, const char *fmt, va_list ap) > > > > > > > > > > > > > > > > and > > > > > > > > > > > > > > > > static void __printf(6, 7) > > > > > > > > __test(struct kunit *kunittest, const char *file, const int line, > > > > > > > > const char *expect, int elen, > > > > > > > > const char *fmt, ...) > > > > > > > > > Since it doesn't make much sense to make this function variadic, I > > > > think the best we can do is a macro wrapper that combines this > > > > function with `no_printk`. Something like > > > > > > > > #define test_hashed(kunittest, fmt, p) \ > > > > do { \ > > > > if (0) \ > > > > no_printk(fmt, p); \ > > > > __test_hashed(kunittest, fmt, p);\ > > > > } while (0) > > > > > > > IMHO, this is is not worth it. test_hashed(kunittest, fmt, p) calls > > test(buf, fmt, p). It goes down to __test() which does the format > > check: > > > > static void __printf(6, 7) > > __test(struct kunit *kunittest, const char *file, const int line, const char *expect, int elen, > > const char *fmt, ...) > > > > > > > > That would give us better diagnostics, but is more complex (and more > > > > lines of code than just repeating this function's body twice, which > > > > would also give good diagnostics). I think the best thing to do is just > > > > to ignore the report that prompted me to look into this. Please let me > > > > know if you disagree. > > > > > > I think we may not ignore the report as it breaks builds in some cases. > > > As I said > > > > > > - __printf(2, 0) for now > > > > > > - and perhaps a comment on top to explain the clang approach that may cope > > > with fixed-argument functions for -Wformat (you can even put a link to that > > > LLVM discussion about the feature). > > > > I personally prefer this way. We just need to calm down the warning. > > The proper check is done by the nested test()... > > The nested `__test()` call cannot do the proper check because it cannot > see the format string. Right? IMHO, it does see the format string. It is defined the following way: static void __printf(6, 7) __test(struct kunit *kunittest, const char *file, const int line, const char *expect, int elen, const char *fmt, ...) #define test(expect, fmt, ...) \ __test(kunittest, __FILE__, __LINE__, expect, strlen(expect), fmt, ##__VA_ARGS__) static void test_hashed(struct kunit *kunittest, const char *fmt, const void *p) { char buf[PLAIN_BUF_SIZE]; plain_hash_to_buffer(kunittest, p, buf, PLAIN_BUF_SIZE); test(buf, fmt, p); } Now, let's get for example: test_hashed(kunittest, "%p", PTR_INVALID); it calls: test(buf, "%p", PTR_INVALID); which is exapnded to: __test(kunittest, file, line, buf, strlen(buf), "%p", PTR_INVALID) so, it gets the same printf arguments as the original test_hashed, namely: %p, PTR_INVALID Or do I miss anything, please? You might argue that it works by chance and that it might change in the future. But I have hard times to imagine it. test_hashed() is just a wrapper around "test()". The only purpose is to fill "buf" with the expected outcome. If any refactoring is needed in the future. The __printf() macros would need some refactoring as well. Best Regards, Petr