* Re: [PATCH] arm_mpam: make the mon_sel guard conditional only
2026-10-03 12:12 [PATCH] arm_mpam: make the mon_sel guard conditional only Sasha Levin
@ 2026-10-03 21:14 ` Nathan Chancellor
2026-10-07 10:40 ` Andre Przywara
2026-10-08 9:17 ` Ben Horgan
2 siblings, 0 replies; 4+ messages in thread
From: Nathan Chancellor @ 2026-10-03 21:14 UTC (permalink / raw)
To: Sasha Levin
Cc: James Morse, Ben Horgan, Jonathan Cameron, Andre Przywara,
Gavin Shan, kernelci.org bot, Reinette Chatre, Fenghua Yu,
Nick Desaulniers, Bill Wendling, Justin Stitt, linux-arm-kernel,
linux-kernel, llvm
On Sat, Oct 03, 2026 at 08:12:48AM -0400, Sasha Levin wrote:
> Building arm64 allmodconfig with clang fails:
>
> drivers/resctrl/mpam_internal.h:207:7: error: ignoring return value
> of function declared with 'warn_unused_result' attribute
> [-Werror,-Wunused-result]
> 207 | mpam_mon_sel_lock(_T), mpam_mon_sel_unlock(_T));
>
> mpam_mon_sel_lock() is __must_check and can fail: for an MSC accessed
> through the MPAM-Fb firmware interface it returns false when called
> from a context that cannot sleep. The mon_sel guard was defined with
> DEFINE_GUARD(), which calls it unconditionally and discards the
> result, so a guard(mon_sel) user would carry on without the lock and
> release it on scope exit.
I wondered why we do not see the same warning with GCC since it seems
like it should also warn on the same construct...
> The unconditional guard only exists as the base for the conditional
> mon_sel_lock variant, which is the one actually used.
but this is why: GCC may not emit warnings for dead code due to some
warnings being emitted from the middle end after optimizations happen
but clang will always warn because its semantic analysis runs in the
front end before optimizations occur.
> Define mon_sel_lock directly as a conditional guard class instead, as
> posix-timers does for lock_timer: the constructor returns NULL when
> the lock cannot be taken, and the destructor only releases a lock
> that was taken. ACQUIRE(mon_sel_lock, ...) works as before, including
> ACQUIRE_ERR() returning -EBUSY on failure, and there is no
> unconditional variant left to misuse.
These macros make my head hurt but this seems correct to me (though not
enough to give a formal review tag).
> Reported-by: kernelci.org bot <bot@kernelci.org>
> Closes: https://d.kernelci.org/i/maestro:66f869ecbbb5b8592562ffd89f049c5ddf682547
> Closes: https://d.kernelci.org/i/maestro:647269216758644837afcaac8e67d8dbe713a0e2
> Fixes: 0db1715e4c9c ("arm_mpam: propagate MSC access errors for hw_probe functions")
> Assisted-by: LLM
> Signed-off-by: Sasha Levin <sashal@kernel.org>
Thanks, this fixes the build for me as well.
Tested-by: Nathan Chancellor <nathan@kernel.org> # build
> ---
> drivers/resctrl/mpam_internal.h | 7 ++++---
> 1 file changed, 4 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/resctrl/mpam_internal.h b/drivers/resctrl/mpam_internal.h
> index ee7c3953a9b6c..be1795b29aca2 100644
> --- a/drivers/resctrl/mpam_internal.h
> +++ b/drivers/resctrl/mpam_internal.h
> @@ -203,9 +203,10 @@ static inline int mpam_mon_sel_lock_init(struct device *dev,
> return devm_mutex_init(dev, &msc->mon_sel_mutex);
> }
>
> -DEFINE_GUARD(mon_sel, struct mpam_msc *,
> - mpam_mon_sel_lock(_T), mpam_mon_sel_unlock(_T));
> -DEFINE_GUARD_COND(mon_sel, _lock, mpam_mon_sel_lock(_T), _RET);
> +DEFINE_CLASS(mon_sel_lock, struct mpam_msc *,
> + _T ? mpam_mon_sel_unlock(_T) : (void)0,
> + mpam_mon_sel_lock(msc) ? msc : NULL, struct mpam_msc *msc);
> +DEFINE_CLASS_IS_COND_GUARD(mon_sel_lock);
>
> /* Bits for mpam features bitmaps */
> enum mpam_device_features {
> --
> 2.53.0
>
--
Cheers,
Nathan
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH] arm_mpam: make the mon_sel guard conditional only
2026-10-03 12:12 [PATCH] arm_mpam: make the mon_sel guard conditional only Sasha Levin
2026-10-03 21:14 ` Nathan Chancellor
@ 2026-10-07 10:40 ` Andre Przywara
2026-10-08 9:17 ` Ben Horgan
2 siblings, 0 replies; 4+ messages in thread
From: Andre Przywara @ 2026-10-07 10:40 UTC (permalink / raw)
To: Sasha Levin, James Morse, Ben Horgan, Nathan Chancellor,
Jonathan Cameron, Gavin Shan
Cc: kernelci.org bot, Reinette Chatre, Fenghua Yu, Nick Desaulniers,
Bill Wendling, Justin Stitt, linux-arm-kernel, linux-kernel,
llvm
Hi Sasha,
many thanks for doing this!
On 10/3/26 14:12, Sasha Levin wrote:
> Building arm64 allmodconfig with clang fails:
>
> drivers/resctrl/mpam_internal.h:207:7: error: ignoring return value
> of function declared with 'warn_unused_result' attribute
> [-Werror,-Wunused-result]
> 207 | mpam_mon_sel_lock(_T), mpam_mon_sel_unlock(_T));
Ooops, I indeed tested this only with GCC.
> mpam_mon_sel_lock() is __must_check and can fail: for an MSC accessed
> through the MPAM-Fb firmware interface it returns false when called
> from a context that cannot sleep. The mon_sel guard was defined with
> DEFINE_GUARD(), which calls it unconditionally and discards the
> result, so a guard(mon_sel) user would carry on without the lock and
> release it on scope exit. The unconditional guard only exists as the
> base for the conditional mon_sel_lock variant, which is the one
> actually used.
Yes, that was the idea I had to model this particular lock, though I
wasn't entirely happy with it, but didn't dare to create a whole new
class. Turns out my solution was not only slightly less elegant, but
also broken ;-) So many thanks for pointing this out and providing the
proper solution.
> Define mon_sel_lock directly as a conditional guard class instead, as
> posix-timers does for lock_timer: the constructor returns NULL when
> the lock cannot be taken, and the destructor only releases a lock
> that was taken. ACQUIRE(mon_sel_lock, ...) works as before, including
> ACQUIRE_ERR() returning -EBUSY on failure, and there is no
> unconditional variant left to misuse.
>
> Reported-by: kernelci.org bot <bot@kernelci.org>
> Closes: https://d.kernelci.org/i/maestro:66f869ecbbb5b8592562ffd89f049c5ddf682547
> Closes: https://d.kernelci.org/i/maestro:647269216758644837afcaac8e67d8dbe713a0e2
> Fixes: 0db1715e4c9c ("arm_mpam: propagate MSC access errors for hw_probe functions")
> Assisted-by: LLM
> Signed-off-by: Sasha Levin <sashal@kernel.org>
> ---
> drivers/resctrl/mpam_internal.h | 7 ++++---
> 1 file changed, 4 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/resctrl/mpam_internal.h b/drivers/resctrl/mpam_internal.h
> index ee7c3953a9b6c..be1795b29aca2 100644
> --- a/drivers/resctrl/mpam_internal.h
> +++ b/drivers/resctrl/mpam_internal.h
> @@ -203,9 +203,10 @@ static inline int mpam_mon_sel_lock_init(struct device *dev,
> return devm_mutex_init(dev, &msc->mon_sel_mutex);
> }
>
> -DEFINE_GUARD(mon_sel, struct mpam_msc *,
> - mpam_mon_sel_lock(_T), mpam_mon_sel_unlock(_T));
> -DEFINE_GUARD_COND(mon_sel, _lock, mpam_mon_sel_lock(_T), _RET);
> +DEFINE_CLASS(mon_sel_lock, struct mpam_msc *,
> + _T ? mpam_mon_sel_unlock(_T) : (void)0,
> + mpam_mon_sel_lock(msc) ? msc : NULL, struct mpam_msc *msc);
> +DEFINE_CLASS_IS_COND_GUARD(mon_sel_lock);
Ah, that's ... nice, I guess, though I share that headache argument with
Nathan ;-)
So that looks superficially right, but the details go a bit above my
head, although I tested it to both still work and to fix the LLVM build
error, so:
Tested-by: Andre Przywara <andre.przywara@arm.com>
Thanks,
Andre
>
> /* Bits for mpam features bitmaps */
> enum mpam_device_features {
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH] arm_mpam: make the mon_sel guard conditional only
2026-10-03 12:12 [PATCH] arm_mpam: make the mon_sel guard conditional only Sasha Levin
2026-10-03 21:14 ` Nathan Chancellor
2026-10-07 10:40 ` Andre Przywara
@ 2026-10-08 9:17 ` Ben Horgan
2 siblings, 0 replies; 4+ messages in thread
From: Ben Horgan @ 2026-10-08 9:17 UTC (permalink / raw)
To: Sasha Levin, James Morse, Nathan Chancellor, Jonathan Cameron,
Andre Przywara, Gavin Shan
Cc: kernelci.org bot, Reinette Chatre, Fenghua Yu, Nick Desaulniers,
Bill Wendling, Justin Stitt, linux-arm-kernel, linux-kernel,
llvm
Hi Sasha,
Thanks for the report and fix.
On 03/10/2026 13:12, Sasha Levin wrote:
> Building arm64 allmodconfig with clang fails:
>
> drivers/resctrl/mpam_internal.h:207:7: error: ignoring return value
> of function declared with 'warn_unused_result' attribute
> [-Werror,-Wunused-result]
> 207 | mpam_mon_sel_lock(_T), mpam_mon_sel_unlock(_T));
>
> mpam_mon_sel_lock() is __must_check and can fail: for an MSC accessed
> through the MPAM-Fb firmware interface it returns false when called
> from a context that cannot sleep. The mon_sel guard was defined with
> DEFINE_GUARD(), which calls it unconditionally and discards the
> result, so a guard(mon_sel) user would carry on without the lock and
> release it on scope exit. The unconditional guard only exists as the
> base for the conditional mon_sel_lock variant, which is the one
> actually used.
>
> Define mon_sel_lock directly as a conditional guard class instead, as
> posix-timers does for lock_timer: the constructor returns NULL when
> the lock cannot be taken, and the destructor only releases a lock
> that was taken. ACQUIRE(mon_sel_lock, ...) works as before, including
> ACQUIRE_ERR() returning -EBUSY on failure, and there is no
> unconditional variant left to misuse.
>
> Reported-by: kernelci.org bot <bot@kernelci.org>
> Closes: https://d.kernelci.org/i/maestro:66f869ecbbb5b8592562ffd89f049c5ddf682547
> Closes: https://d.kernelci.org/i/maestro:647269216758644837afcaac8e67d8dbe713a0e2
> Fixes: 0db1715e4c9c ("arm_mpam: propagate MSC access errors for hw_probe functions")
> Assisted-by: LLM
> Signed-off-by: Sasha Levin <sashal@kernel.org>
> ---
> drivers/resctrl/mpam_internal.h | 7 ++++---
> 1 file changed, 4 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/resctrl/mpam_internal.h b/drivers/resctrl/mpam_internal.h
> index ee7c3953a9b6c..be1795b29aca2 100644
> --- a/drivers/resctrl/mpam_internal.h
> +++ b/drivers/resctrl/mpam_internal.h
> @@ -203,9 +203,10 @@ static inline int mpam_mon_sel_lock_init(struct device *dev,
> return devm_mutex_init(dev, &msc->mon_sel_mutex);
> }
>
> -DEFINE_GUARD(mon_sel, struct mpam_msc *,
> - mpam_mon_sel_lock(_T), mpam_mon_sel_unlock(_T));
> -DEFINE_GUARD_COND(mon_sel, _lock, mpam_mon_sel_lock(_T), _RET);
> +DEFINE_CLASS(mon_sel_lock, struct mpam_msc *,
> + _T ? mpam_mon_sel_unlock(_T) : (void)0,
Could this line be an if statement? That looks to be common in other
users of DEFINE_CLASS().
if (_T) mpam_mon_sel_unlock(_T)
Thanks,
Ben
> + mpam_mon_sel_lock(msc) ? msc : NULL, struct mpam_msc *msc);
> +DEFINE_CLASS_IS_COND_GUARD(mon_sel_lock);
>
> /* Bits for mpam features bitmaps */
> enum mpam_device_features {
^ permalink raw reply [flat|nested] 4+ messages in thread