On 2026/07/25 23:00, Marc-André Lureau wrote:
When compiled with -Og, gcc produces many false-positives
gcc (GCC) 16.1.1 20260515 (Red Hat 16.1.1-2).

We already use auto-var-init=zero, but better be explicit.

I'm kind of reluctant to describe it is more explicit and it is better. The variables causing the false positives do not contain a useful value until later assignments. Initializing them obscures the fact and suppresses useful warnings. This patch may serve as a workaround, but its scope should be minimized.

I think WITH_QEMU_LOCK_GUARD() should be fixed to explicitly tell that the block is unconditionally executed. Linux does so, for example:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=fcc22ac5baf06dd17193de44b60dbceea6461983

Signed-off-by: Marc-André Lureau <[email protected]>
---
  block/blkio.c                 |  4 ++--
  block/qcow2.c                 |  2 +-
  hw/cxl/cxl-host.c             |  2 +-
  hw/scsi/scsi-disk.c           |  2 +-
  hw/scsi/scsi-generic.c        |  4 ++--
  hw/scsi/virtio-scsi.c         |  2 +-
  io/net-listener.c             | 10 +++++-----
  target/i386/cpu.c             |  3 ++-
  target/i386/emulate/x86_mmu.c |  4 ++--
  9 files changed, 17 insertions(+), 16 deletions(-)

diff --git a/block/blkio.c b/block/blkio.c
index d2ba2a4d58dc..f7cb6e0b57d4 100644
--- a/block/blkio.c
+++ b/block/blkio.c
@@ -278,7 +278,7 @@ static bool blkio_completion_fd_poll(void *opaque)
  {
      BlockDriverState *bs = opaque;
      BDRVBlkioState *s = bs->opaque;
-    int ret;
+    int ret = -1;
/* Just in case we already fetched a completion */
      if (s->poll_completion.user_data != NULL) {
@@ -559,7 +559,7 @@ static bool blkio_register_buf(BlockDriverState *bs, void 
*host, size_t size,
      BDRVBlkioState *s = bs->opaque;
      struct blkio_mem_region region;
      BlkioMemRegionResult region_result;
-    int ret;
+    int ret = -1;
/*
       * Mapping memory regions conflicts with RAM discard (virtio-mem) when
diff --git a/block/qcow2.c b/block/qcow2.c
index 19271b10a49f..639593d737c8 100644
--- a/block/qcow2.c
+++ b/block/qcow2.c
@@ -838,7 +838,7 @@ static const char 
*overlap_bool_option_names[QCOW2_OL_MAX_BITNR] = {
  static void coroutine_fn cache_clean_timer(void *opaque)
  {
      BDRVQcow2State *s = opaque;
-    uint64_t wait_ns;
+    uint64_t wait_ns = 0;
WITH_QEMU_LOCK_GUARD(&s->lock) {
          wait_ns = s->cache_clean_interval * NANOSECONDS_PER_SECOND;
diff --git a/hw/cxl/cxl-host.c b/hw/cxl/cxl-host.c
index 7e744312f1d8..eba13c9e7cba 100644
--- a/hw/cxl/cxl-host.c
+++ b/hw/cxl/cxl-host.c
@@ -279,7 +279,7 @@ static void 
cxl_fmws_direct_passthrough_setup(CXLDirectPTState *state,
      MemoryRegion *mr = NULL;
      uint64_t vmr_size = 0, pmr_size = 0, offset = 0;
      MemoryRegion *direct_mr;
-    g_autofree char *direct_mr_name;
+    g_autofree char *direct_mr_name = NULL;

This fixes a real issue, not a false positive. An early return can trigger a cleanup on an uninitialized variable.

Regards,
Akihiko Odaki

      unsigned int idx = state->hdm_decoder_idx;
if (ct3d->hostvmem) {
diff --git a/hw/scsi/scsi-disk.c b/hw/scsi/scsi-disk.c
index 1b0cce128c5e..82dc75cb7d10 100644
--- a/hw/scsi/scsi-disk.c
+++ b/hw/scsi/scsi-disk.c
@@ -3263,7 +3263,7 @@ static bool scsi_disk_pr_state_needed(void *opaque)
  {
      SCSIDiskState *s = opaque;
      SCSIPRState *pr_state = &s->qdev.pr_state;
-    bool ret;
+    bool ret = false;
if (!s->qdev.migrate_pr) {
          return false;
diff --git a/hw/scsi/scsi-generic.c b/hw/scsi/scsi-generic.c
index 8999f3b72006..b044561ae2dd 100644
--- a/hw/scsi/scsi-generic.c
+++ b/hw/scsi/scsi-generic.c
@@ -553,8 +553,8 @@ bool scsi_generic_pr_state_preempt(SCSIDevice *s, Error 
**errp)
      SCSIPRState *pr_state = &s->pr_state;
      Error *local_err = NULL;
      bool check_stale_key = true;
-    uint64_t key;
-    uint8_t resv_type;
+    uint64_t key = 0;
+    uint8_t resv_type = 0;
/* Get the migrated PR state */
      WITH_QEMU_LOCK_GUARD(&pr_state->mutex) {
diff --git a/hw/scsi/virtio-scsi.c b/hw/scsi/virtio-scsi.c
index 6c7376801190..833f773d7f6c 100644
--- a/hw/scsi/virtio-scsi.c
+++ b/hw/scsi/virtio-scsi.c
@@ -1093,7 +1093,7 @@ static void virtio_scsi_push_event(VirtIOSCSI *s,
static void virtio_scsi_handle_event_vq(VirtIOSCSI *s, VirtQueue *vq)
  {
-    bool events_dropped;
+    bool events_dropped = false;
WITH_QEMU_LOCK_GUARD(&s->event_lock) {
          events_dropped = s->events_dropped;
diff --git a/io/net-listener.c b/io/net-listener.c
index 1fd0f6cb5ab8..8df19c35bd8f 100644
--- a/io/net-listener.c
+++ b/io/net-listener.c
@@ -54,11 +54,11 @@ static gboolean qio_net_listener_channel_func(QIOChannel 
*ioc,
                                                gpointer opaque)
  {
      QIONetListener *listener = QIO_NET_LISTENER(opaque);
-    QIOChannelSocket *sioc;
-    QIONetListenerClientFunc io_func;
-    gpointer io_data;
-    GMainContext *context;
-    AioContext *aio_context;
+    QIOChannelSocket *sioc = NULL;
+    QIONetListenerClientFunc io_func = NULL;
+    gpointer io_data = NULL;
+    GMainContext *context = NULL;
+    AioContext *aio_context = NULL;
sioc = qio_channel_socket_accept(QIO_CHANNEL_SOCKET(ioc),
                                       NULL);
diff --git a/target/i386/cpu.c b/target/i386/cpu.c
index 5805d33ab92d..e9759ab25077 100644
--- a/target/i386/cpu.c
+++ b/target/i386/cpu.c
@@ -7734,7 +7734,7 @@ static void x86_cpuid_get_avx10_version(Object *obj, 
Visitor *v,
  static bool x86_cpu_apply_avx10_features(X86CPU *cpu, uint8_t version,
                                           Error **errp)
  {
-    const AVX10VersionDefinition *def;
+    const AVX10VersionDefinition *def = NULL;
      CPUX86State *env = &cpu->env;
if (!version) {
@@ -7758,6 +7758,7 @@ static bool x86_cpu_apply_avx10_features(X86CPU *cpu, 
uint8_t version,
          }
      }
+ assert(def != NULL);
      if (def->version < version) {
          error_setg(errp, "avx10-version can be at most %d", def->version);
          return false;
diff --git a/target/i386/emulate/x86_mmu.c b/target/i386/emulate/x86_mmu.c
index 8d4371467fd7..c1cb385b3228 100644
--- a/target/i386/emulate/x86_mmu.c
+++ b/target/i386/emulate/x86_mmu.c
@@ -185,8 +185,8 @@ static MMUTranslateResult walk_gpt(CPUState *cpu, 
target_ulong addr, MMUTranslat
      int largeness = 0;
      target_ulong cr3 = x86_read_cr(cpu, 3);
      uint64_t page_mask = pae ? PAE_PTE_PAGE_MASK : LEGACY_PTE_PAGE_MASK;
-    MMUTranslateResult res;
-
+    MMUTranslateResult res = 0;
+
      memset(pt, 0, sizeof(*pt));
      top_level = gpt_top_level(cpu, pae);


Reply via email to