[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH 2/6] Fix annotations on some parameters


  • To: win-pv-devel@xxxxxxxxxxxxxxxxxxxx
  • From: Césaire Mounah <cesaire.mounah@xxxxxxxxxx>
  • Date: Tue, 29 Sep 2026 19:05:09 +0200
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=vates.tech header.i="@vates.tech" header.h="From:Subject:Date:Message-ID:To:Cc:MIME-Version:Content-Type:In-Reply-To:References:Feedback-ID"
  • Cc: Césaire Mounah <cesaire.mounah@xxxxxxxxxx>
  • Delivery-date: Tue, 29 Sep 2026 17:05:59 +0000
  • Feedback-id: default:8631fc262581453bbf619ec5b2062170:Sweego
  • List-id: Developer list for the Windows PV Drivers subproject <win-pv-devel.lists.xenproject.org>

_In_ declares read-only data.  Several parameters were annotated _In_
although the callee writes through them; corrected per SAL 2.0 [1].
The annotation describes the pointed-to data, not the pointer, so
none of these were visible on inspection: the pointer variable itself
is never reassigned in any of them.

Found by temporarily const-qualifying the pointee of every _In_
pointer parameter and letting the compiler reject the writes (C2166,
and C4090 where const was laundered through a local).

[1] 
https://learn.microsoft.com/en-us/cpp/code-quality/best-practices-and-examples-sal

Assisted-by: Claude/Opus-4
Signed-off-by: Césaire Mounah <cesaire.mounah@xxxxxxxxxx>
---
 src/xenhid/fdo.c    |  2 +-
 src/xenhid/string.c |  2 +-
 src/xenhid/util.h   | 20 ++++++++++----------
 3 files changed, 12 insertions(+), 12 deletions(-)

diff --git a/src/xenhid/fdo.c b/src/xenhid/fdo.c
index c6160e5..b021dbd 100644
--- a/src/xenhid/fdo.c
+++ b/src/xenhid/fdo.c
@@ -249,7 +249,7 @@ __FdoGetDevicePowerState(
 
 static FORCEINLINE PANSI_STRING
 __FdoMultiSzToUpcaseAnsi(
-    _In_ PCHAR      Buffer
+    _Inout_ PCHAR   Buffer
 )
 {
     PANSI_STRING    Ansi;
diff --git a/src/xenhid/string.c b/src/xenhid/string.c
index b75e249..b3f0305 100644
--- a/src/xenhid/string.c
+++ b/src/xenhid/string.c
@@ -53,7 +53,7 @@ __StringPut(
 
 static PCHAR
 FormatNumber(
-    _In_ PCHAR      Buffer,
+    _Inout_ PCHAR   Buffer,
     _In_ ULONGLONG  Value,
     _In_ UCHAR      Base,
     _In_ BOOLEAN    UpperCase
diff --git a/src/xenhid/util.h b/src/xenhid/util.h
index 0281490..66282d6 100644
--- a/src/xenhid/util.h
+++ b/src/xenhid/util.h
@@ -108,12 +108,12 @@ __CpuId(
 
 static FORCEINLINE LONG
 __InterlockedAdd(
-    _In_ LONG   *Value,
-    _In_ LONG   Delta
+    _Inout_ LONG    *Value,
+    _In_ LONG       Delta
     )
 {
-    LONG        New;
-    LONG        Old;
+    LONG            New;
+    LONG            Old;
 
     do {
         Old = *Value;
@@ -125,12 +125,12 @@ __InterlockedAdd(
 
 static FORCEINLINE LONG
 __InterlockedSubtract(
-    _In_ LONG   *Value,
-    _In_ LONG   Delta
+    _Inout_ LONG    *Value,
+    _In_ LONG       Delta
     )
 {
-    LONG        New;
-    LONG        Old;
+    LONG            New;
+    LONG            Old;
 
     do {
         Old = *Value;
@@ -267,7 +267,7 @@ __FreePages(
 
 static FORCEINLINE PCHAR
 __strtok_r(
-    _In_ PCHAR      Buffer,
+    _Inout_ PCHAR   Buffer,
     _In_ PCHAR      Delimiter,
     _Inout_ PCHAR   *Context
     )
@@ -305,7 +305,7 @@ __strtok_r(
 
 static FORCEINLINE PWCHAR
 __wcstok_r(
-    _In_ PWCHAR     Buffer,
+    _Inout_ PWCHAR  Buffer,
     _In_ PWCHAR     Delimiter,
     _Inout_ PWCHAR  *Context
     )
-- 
2.55.0.windows.5



--
Césaire Mounah | Vates Windows Guest Tools Engineer

XCP-ng & Xen Orchestra - Vates solutions

web: https://vates.tech

 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.