git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 09/13] parse-options API: don't restrict OPT_SUBCOMMAND() to one *_fn type

From
Ævar Arnfjörð Bjarmason <avarab@gmail.com>
Date
Nov 5, 2022, 21:59 UTC
Message-ID
<221105.86sfixvxqk.gmgdl@evledraar.gmail.com>
In-Reply-To
<1b158749-44b1-34e0-5b52-1d3bfad9bc9a@dunelm.org.uk>
On Sat, Nov 05 2022, Phillip Wood wrote:
Show 88 quoted lines
> On 05/11/2022 13:52, Ævar Arnfjörð Bjarmason wrote:
>> On Sat, Nov 05 2022, René Scharfe wrote:
>> 
>>> Am 04.11.22 um 14:22 schrieb Ævar Arnfjörð Bjarmason:
>>>> diff --git a/parse-options.h b/parse-options.h
>>>> index b6ef86e0d15..61e3016c3fc 100644
>>>> --- a/parse-options.h
>>>> +++ b/parse-options.h
>>>> @@ -128,19 +128,24 @@ typedef int parse_opt_subcommand_fn(int argc, const char **argv,
>>>>    *			 the option takes optional argument.
>>>>    *
>>>>    * `callback`::
>>>> - *   pointer to the callback to use for OPTION_CALLBACK
>>>> + *   pointer to the callback to use for OPTION_CALLBACK and OPTION_SUBCOMMAND.
>>>>    *
>>>>    * `defval`::
>>>>    *   default value to fill (*->value) with for PARSE_OPT_OPTARG.
>>>>    *   OPTION_{BIT,SET_INT} store the {mask,integer} to put in the value when met.
>>>> + *   OPTION_SUBCOMMAND stores the pointer the function selected for
>>>> + *   the subcommand.
>>>> + *
>>>>    *   CALLBACKS can use it like they want.
>>>>    *
>>>>    * `ll_callback`::
>>>>    *   pointer to the callback to use for OPTION_LOWLEVEL_CALLBACK
>>>>    *
>>>>    * `subcommand_fn`::
>>>> - *   pointer to a function to use for OPTION_SUBCOMMAND.
>>>> - *   It will be put in value when the subcommand is given on the command line.
>>>> + *   pointer to the callback used with OPT_SUBCOMMAND() and
>>>> + *   OPT_SUBCOMMAND_F(). Internally we store the same value in
>>>> + *   `defval`. This is only here to give the OPT_SUBCOMMAND{,_F}()
>>>> + *   common case type safety.
>>>>    */
>>>>   struct option {
>>>>   	enum parse_opt_type type;
>>>> @@ -217,12 +222,24 @@ struct option {
>>>>   #define OPT_ALIAS(s, l, source_long_name) \
>>>>   	{ OPTION_ALIAS, (s), (l), (source_long_name) }
>>>>
>>>> +static inline int parse_options_pick_subcommand_cb(const struct option *option,
>>>> +						   const char *arg UNUSED,
>>>> +						   int unset UNUSED)
>>>> +{
>>>> +	parse_opt_subcommand_fn *fn = (parse_opt_subcommand_fn *)option->defval;
>>>> +	*(parse_opt_subcommand_fn **)option->value = fn;
>>>
>>> ->defval is of type intptr_t and ->value is a void pointer.  The result
>>> of converting a void pointer value to an intptr_t and back is a void
>>> pointer equal to the original pointer if I read 6.3.2.3 (Pointers,
>>> paragraphs 5 and 6) and 7.18.1.4 (Integer types capable of holding
>>> object pointers) in C99 correctly.
>>>
>>> 6.3.2.3 paragraph 8 says that casting between function pointers of
>>> different type is OK and you can get your original function pointer
>>> back and use it in a call if you convert it back to the right type.
>>>
>>> Casting between a function pointer and an object pointer is undefined,
>>> though.  They don't have to be of the same size, so a function pointer
>>> doesn't have to fit into an intptr_t.  I wouldn't be surprised if CHERI
>>> (https://www.cl.cam.ac.uk/research/security/ctsrd/cheri/) was an actual
>>> example of that.
>> I should have called this out explicitly. I think you're right as
>> far as
>> what you're summarizing goes.
>> To elaborate on it, paragraph 8 of 6.3.2.3 says:
>> 	A pointer to a function of one type may be converted to a
>> 	pointer to a function of another type and back again; the result
>> 	shall compare equal to the original pointer. If a converted
>> 	pointer is used to call a function whose type is not compatible
>> 	with the pointed-to type, the behavior is undefined.
>> And 7.18.1.4 says, when discussing (among other things) "intptr_t"
>> ("[such" added for clarity:
>> 	[...]any valid [such] pointer to void can be converted to this
>> 	type, then converted back to pointer to void, and the result
>> 	will compare equal to the original pointer:
>> But as you point out that doesn't say anything about whether a
>> pointer
>> to a function is a "valid .. pointer to void".
>> I think that's an "unportable" extension covered in "J.5 Common
>> extensions", specifically "J.5.7 Function pointer casts":
>> 	A pointer to an object or to void may be cast to a pointer to
>> a
>> 	function, allowing data to be invoked as a function
>
> This is a common extension, it is _not_ guaranteed by the standard and
> so still undefined behavior unless your compiler happens to have 
> implemented that extension.
Show 7 quoted lines
>> Thus, since the standard already establishes that valid "void *" and
>> "intptr_t" pointers can be cast'd back & forth, the J.5.7 bridges the
>> gap between the two saying a function pointer can be converted to
>> either.
>
> How does J.5.7 bridge the gap when compilers are not required to
> implement it?
I'm saying it bridges the gap in that explanation, i.e. reinforces that
the main standard body isn't referring to function pointer casts to void
* and intptr_t.
Show 6 quoted lines
>> Now, I may be missing something here, but I was under the impression
>> that "intptr_t" wasn't special in any way here, and that any casting of
>> a function pointer to either it or a "void *" was what was made portable
>> by "J.5.7"
>
> How is it made portable by an "unportable" extension?

I'm just repeating the terminology the standard uses: "The following extensions are widely used in many systems, but are not portable to all implementations".

Show 7 quoted lines
>> So I think aside from other concerns this should be safe to use, as
>> real-world data backing that up we've had a intptr_t converted to a
>> function pointer since v2.35.0: 5cb28270a1f (pack-objects: lazily set up
>> "struct rev_info", don't leak, 2022-03-28).
>
> Saying "it works so it is fine" is not a convincing argument that it
> is compliant with the standard. 

I was saying, among other things, that it's standardized by POSIX, so it's in the same category as ssize_t, not some hypothetical "happens to work" undefined behavior.

But we also make use of it already, so that gives us some real-world data on potential issues.

Previous: Phillip WoodNext: René Scharfe
Message 91 of 106 in “"git bisect run" strips "--log" from the list of arguments”
  1. Lukáš DoktorNov 4, 2022
  2. Jeff KingNov 4, 2022
  3. Đoàn Trần Công DanhNov 4, 2022
  4. Jeff KingNov 4, 2022
  5. Ævar Arnfjörð BjarmasonNov 4, 2022
  6. Jeff KingNov 4, 2022
  7. Ævar Arnfjörð BjarmasonNov 4, 2022
  8. SZEDER GáborNov 4, 2022
  9. Jeff KingNov 4, 2022
  10. 0/3 Convert git-bisect--helper to OPT_SUBCOMMANDĐoàn Trần Công Danh, Nov 4, 2022
  11. 1/3 bisect--helper: remove unused optionsĐoàn Trần Công Danh, Nov 4, 2022
  12. Jeff KingNov 4, 2022
  13. 2/3 bisect--helper: move all subcommands into their own functionsĐoàn Trần Công Danh, Nov 4, 2022
  14. Jeff KingNov 4, 2022
  15. Ævar Arnfjörð BjarmasonNov 4, 2022
  16. Đoàn Trần Công DanhNov 4, 2022
  17. 3/3 bisect--helper: parse subcommand with OPT_SUBCOMMANDĐoàn Trần Công Danh, Nov 4, 2022
  18. Jeff KingNov 4, 2022
  19. Ævar Arnfjörð BjarmasonNov 4, 2022
  20. Đoàn Trần Công DanhNov 4, 2022
  21. Ævar Arnfjörð BjarmasonNov 4, 2022
  22. 0/3 Convert git-bisect--helper to OPT_SUBCOMMANDĐoàn Trần Công Danh, Nov 5, 2022
  23. 1/3 bisect--helper: remove unused optionsĐoàn Trần Công Danh, Nov 5, 2022
  24. 3/3 bisect--helper: parse subcommand with OPT_SUBCOMMANDĐoàn Trần Công Danh, Nov 5, 2022
  25. 2/3 bisect--helper: move all subcommands into their own functionsĐoàn Trần Công Danh, Nov 5, 2022
  26. Đoàn Trần Công DanhNov 5, 2022
  27. 00/13 Turn git-bisect to be builtinĐoàn Trần Công Danh, Nov 5, 2022
  28. 01/13 bisect tests: test for v2.30.0 "bisect run" regressionsĐoàn Trần Công Danh, Nov 5, 2022
  29. Ævar Arnfjörð BjarmasonNov 7, 2022
  30. Đoàn Trần Công DanhNov 8, 2022
  31. 02/13 bisect: refactor bisect_run() to match CodingGuidelinesĐoàn Trần Công Danh, Nov 5, 2022
  32. 03/13 bisect--helper: pass arg[cv] down to do_bisect_runĐoàn Trần Công Danh, Nov 5, 2022
  33. 04/13 bisect: fix output regressions in v2.30.0Đoàn Trần Công Danh, Nov 5, 2022
  34. 05/13 bisect run: keep some of the post-v2.30.0 outputĐoàn Trần Công Danh, Nov 5, 2022
  35. Ævar Arnfjörð BjarmasonNov 7, 2022
  36. Đoàn Trần Công DanhNov 8, 2022
  37. Ævar Arnfjörð BjarmasonNov 8, 2022
  38. 06/13 bisect--helper: remove unused arguments from do_bisect_runĐoàn Trần Công Danh, Nov 5, 2022
  39. 07/13 bisect--helper: pretend we're real bisect when report errorĐoàn Trần Công Danh, Nov 5, 2022
  40. Ævar Arnfjörð BjarmasonNov 7, 2022
  41. 08/13 bisect test: test exit codes on bad usageĐoàn Trần Công Danh, Nov 5, 2022
  42. 09/13 bisect--helper: emit usage for "git bisect"Đoàn Trần Công Danh, Nov 5, 2022
  43. 10/13 bisect--helper: make `state` optionalĐoàn Trần Công Danh, Nov 5, 2022
  44. 11/13 bisect--helper: remove subcommand stateĐoàn Trần Công Danh, Nov 5, 2022
  45. Ævar Arnfjörð BjarmasonNov 7, 2022
  46. Đoàn Trần Công DanhNov 8, 2022
  47. 12/13 bisect--helper: log: allow arbitrary number of argumentsĐoàn Trần Công Danh, Nov 5, 2022
  48. 13/13 Turn `git bisect` into a full built-inĐoàn Trần Công Danh, Nov 5, 2022
  49. Taylor BlauNov 5, 2022
  50. 0/3 Convert git-bisect--helper to OPT_SUBCOMMANDĐoàn Trần Công Danh, Nov 10, 2022
  51. 1/3 bisect--helper: remove unused optionsĐoàn Trần Công Danh, Nov 10, 2022
  52. Ævar Arnfjörð BjarmasonNov 11, 2022
  53. 2/3 bisect--helper: move all subcommands into their own functionsĐoàn Trần Công Danh, Nov 10, 2022
  54. Ævar Arnfjörð BjarmasonNov 11, 2022
  55. 3/3 bisect--helper: parse subcommand with OPT_SUBCOMMANDĐoàn Trần Công Danh, Nov 10, 2022
  56. 00/11 Turn git-bisect to be builtinĐoàn Trần Công Danh, Nov 10, 2022
  57. 02/11 bisect: refactor bisect_run() to match CodingGuidelinesĐoàn Trần Công Danh, Nov 10, 2022
  58. 01/11 bisect tests: test for v2.30.0 "bisect run" regressionsĐoàn Trần Công Danh, Nov 10, 2022
  59. 03/11 bisect: fix output regressions in v2.30.0Đoàn Trần Công Danh, Nov 10, 2022
  60. 04/11 bisect run: keep some of the post-v2.30.0 outputĐoàn Trần Công Danh, Nov 10, 2022
  61. 05/11 bisect-run: verify_good: account for non-negative exit statusĐoàn Trần Công Danh, Nov 10, 2022
  62. 06/11 bisect--helper: identify as bisect when report errorĐoàn Trần Công Danh, Nov 10, 2022
  63. 07/11 bisect test: test exit codes on bad usageĐoàn Trần Công Danh, Nov 10, 2022
  64. 08/11 bisect--helper: emit usage for "git bisect"Đoàn Trần Công Danh, Nov 10, 2022
  65. 09/11 bisect--helper: handle states directlyĐoàn Trần Công Danh, Nov 10, 2022
  66. 10/11 bisect--helper: log: allow arbitrary number of argumentsĐoàn Trần Công Danh, Nov 10, 2022
  67. Ævar Arnfjörð BjarmasonNov 11, 2022
  68. 11/11 Turn `git bisect` into a full built-inĐoàn Trần Công Danh, Nov 10, 2022
  69. Ævar Arnfjörð BjarmasonNov 11, 2022
  70. Jeff KingNov 11, 2022
  71. Ævar Arnfjörð BjarmasonNov 11, 2022
  72. Taylor BlauNov 11, 2022
  73. Taylor BlauNov 15, 2022
  74. Jeff KingNov 15, 2022
  75. Taylor BlauNov 15, 2022
  76. Ævar Arnfjörð BjarmasonNov 11, 2022
  77. 00/13 bisect: v2.30.0 "run" regressions + make it built-inÆvar Arnfjörð Bjarmason, Nov 4, 2022
  78. 01/13 bisect tests: test for v2.30.0 "bisect run" regressionsÆvar Arnfjörð Bjarmason, Nov 4, 2022
  79. 02/13 bisect: refactor bisect_run() to match CodingGuidelinesÆvar Arnfjörð Bjarmason, Nov 4, 2022
  80. 04/13 bisect run: fix "--log" eating regression in v2.30.0Ævar Arnfjörð Bjarmason, Nov 4, 2022
  81. 03/13 bisect: fix output regressions in v2.30.0Ævar Arnfjörð Bjarmason, Nov 4, 2022
  82. 05/13 bisect run: keep some of the post-v2.30.0 outputÆvar Arnfjörð Bjarmason, Nov 4, 2022
  83. 06/13 bisect test: test exit codes on bad usageÆvar Arnfjörð Bjarmason, Nov 4, 2022
  84. 07/13 bisect--helper: emit usage for "git bisect"Ævar Arnfjörð Bjarmason, Nov 4, 2022
  85. 09/13 parse-options API: don't restrict OPT_SUBCOMMAND() to one *_fn typeÆvar Arnfjörð Bjarmason, Nov 4, 2022
  86. René ScharfeNov 5, 2022
  87. Đoàn Trần Công DanhNov 5, 2022
  88. Phillip WoodNov 5, 2022
  89. Ævar Arnfjörð BjarmasonNov 5, 2022
  90. Phillip WoodNov 5, 2022
  91. Ævar Arnfjörð BjarmasonNov 5, 2022
  92. René ScharfeNov 5, 2022
  93. Ævar Arnfjörð BjarmasonNov 5, 2022
  94. René ScharfeNov 6, 2022
  95. Ævar Arnfjörð BjarmasonNov 6, 2022
  96. René ScharfeNov 12, 2022
  97. Jeff KingNov 12, 2022
  98. Ævar Arnfjörð BjarmasonNov 12, 2022
  99. René ScharfeNov 13, 2022
  100. 08/13 bisect--helper: have all functions take state, argc, argv, prefixÆvar Arnfjörð Bjarmason, Nov 4, 2022
  101. 10/13 bisect--helper: remove dead --bisect-{next-check,autostart} codeÆvar Arnfjörð Bjarmason, Nov 4, 2022
  102. 11/13 bisect--helper: convert to OPT_SUBCOMMAND_CB()Ævar Arnfjörð Bjarmason, Nov 4, 2022
  103. 12/13 bisect--helper: make `state` optionalÆvar Arnfjörð Bjarmason, Nov 4, 2022
  104. 13/13 Turn `git bisect` into a full built-inÆvar Arnfjörð Bjarmason, Nov 4, 2022
  105. Taylor BlauNov 5, 2022
  106. Johannes SchindelinNov 10, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.