From e9b5aec65e7b7221394eeb845a3456c44676ce64 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Fr=C3=A9d=C3=A9ric=20Desbiens?= Date: Wed, 16 Sep 2026 09:55:24 -0400 Subject: [PATCH] Added MISRA build configurations to the ThreadX regression matrix (#747) TX_MISRA_ENABLE routes the kernel's pointer conversions, its memset and its stack check through the shim in common/src/tx_misra.c. No build configuration defined it, so that file was never compiled or tested, and the source the MISRA analysis runs against was not the source the suite exercises. Adding event tracing alongside it reaches a further region of the shim that neither macro alone compiles. Both defects found in this area were invisible for the same reason: #741 broke under TX_MISRA_ENABLE and #745 under both macros together, and neither combination was built anywhere. misra_build and misra_trace_build fill that gap. Two things had to give way for them. TX_POINTER_TO_ALIGN_TYPE_CONVERT exists only when TX_MISRA_ENABLE is absent, so threadx_test_port.h writes the conversion out rather than taking it from the API; it is test scaffolding storing a pointer in a word wide enough to hold one, not kernel source. And thread_transition and module_manager compile hand-picked common/src sources directly instead of linking the library, which is what lets them reach feature macros the library-per-configuration model cannot; under TX_MISRA_ENABLE those sources call into the shim, and pulling the shim in pulls its own callees after it. Neither directory exists to test the shim, so the MISRA configurations skip them. 100/100 tests pass in each of the two new configurations, against 105/105 in the existing five - the five not run are the four thread transition tests and the module manager test, exactly the two directories skipped. Build is 4 to 5 seconds and the suites 13 and 15 seconds, against 4 seconds and 9 to 17 for the configurations already there, so the tx job grows by roughly forty seconds. Assisted-by: Claude Code (Opus 5) --- test/tx/cmake/CMakeLists.txt | 33 +++++++++++++++++++++++--- test/tx/regression/threadx_test_port.h | 7 +++++- 2 files changed, 36 insertions(+), 4 deletions(-) diff --git a/test/tx/cmake/CMakeLists.txt b/test/tx/cmake/CMakeLists.txt index f8e902ef..2f9c9b9f 100644 --- a/test/tx/cmake/CMakeLists.txt +++ b/test/tx/cmake/CMakeLists.txt @@ -14,7 +14,8 @@ set(CMAKE_C_EXTENSIONS OFF) # Set build configurations set(BUILD_CONFIGURATIONS default_build_coverage disable_notify_callbacks_build - stack_checking_build stack_checking_rand_fill_build trace_build) + stack_checking_build stack_checking_rand_fill_build trace_build + misra_build misra_trace_build) set(CMAKE_CONFIGURATION_TYPES ${BUILD_CONFIGURATIONS} CACHE STRING "list of supported configuration types" FORCE) @@ -36,6 +37,21 @@ set(stack_checking_build TX_QUEUE_MESSAGE_MAX_SIZE=32 TX_ENABLE_STACK_CHECKING) set(stack_checking_rand_fill_build TX_QUEUE_MESSAGE_MAX_SIZE=32 TX_ENABLE_STACK_CHECKING TX_ENABLE_RANDOM_NUMBER_STACK_FILLING) set(trace_build TX_QUEUE_MESSAGE_MAX_SIZE=32 TX_ENABLE_EVENT_TRACE) +# TX_MISRA_ENABLE routes the kernel's pointer conversions, its memset and its +# stack check through the shim in common/src/tx_misra.c, which every +# configuration above compiles out entirely. It is also the source the MISRA +# analysis runs against, so without this the build that is analysed and the build +# that is tested are different builds of the same tree. +# +# The second adds event tracing, because the shim has a region behind +# TX_ENABLE_EVENT_TRACE that neither macro alone reaches. +# +# Both defects found here were invisible for the same reason: #741 broke under +# TX_MISRA_ENABLE and #745 under both macros together, and neither combination +# was built anywhere. +set(misra_build TX_QUEUE_MESSAGE_MAX_SIZE=32 TX_MISRA_ENABLE) +set(misra_trace_build TX_QUEUE_MESSAGE_MAX_SIZE=32 TX_MISRA_ENABLE TX_ENABLE_EVENT_TRACE) + add_compile_definitions( TX_REGRESSION_TEST TEST_STACK_SIZE_PRINTF=4096 @@ -68,12 +84,23 @@ add_subdirectory(samples) # beside regression on purpose: every branch in the current fix set adds an # add_subdirectory line immediately after regression, and putting a second one # there turns a set of clean merges into a set of one-line conflicts. -add_subdirectory(thread_transition) +# These two compile a hand-picked set of common/src sources directly instead of +# linking the threadx library, which is what lets them reach feature macros the +# library-per-configuration model cannot. That does not survive TX_MISRA_ENABLE: +# the kernel's TX_MEMSET and its conversions become calls into tx_misra.c, and +# pulling the shim into these targets pulls its own callees after it. Neither +# exists to test the shim, and the regression suite covers it, so the MISRA +# configurations skip them. +if(NOT ("TX_MISRA_ENABLE" IN_LIST ${CMAKE_BUILD_TYPE})) + add_subdirectory(thread_transition) +endif() # Host tests for the Module Manager. Listed after thread_transition for the reason # given above it: additions here are appended rather than inserted, so that branches # adding a directory of their own merge cleanly. -add_subdirectory(module_manager) +if(NOT ("TX_MISRA_ENABLE" IN_LIST ${CMAKE_BUILD_TYPE})) + add_subdirectory(module_manager) +endif() # Coverage # diff --git a/test/tx/regression/threadx_test_port.h b/test/tx/regression/threadx_test_port.h index b8502b4d..5d79c8e8 100644 --- a/test/tx/regression/threadx_test_port.h +++ b/test/tx/regression/threadx_test_port.h @@ -32,6 +32,11 @@ typedef ALIGN_TYPE TX_TEST_POINTER_WORD; -#define TX_TEST_STORE_POINTER(a, b) (a) = ((TX_TEST_POINTER_WORD) TX_POINTER_TO_ALIGN_TYPE_CONVERT(b)) +/* TX_POINTER_TO_ALIGN_TYPE_CONVERT is defined only when TX_MISRA_ENABLE is absent, + so the conversion is written out here rather than taken from the API. This is + test scaffolding storing a pointer in a word wide enough to hold one; it is not + kernel source and carries no MISRA obligation of its own. */ + +#define TX_TEST_STORE_POINTER(a, b) (a) = ((TX_TEST_POINTER_WORD) (ALIGN_TYPE) (b)) #endif