From: "Derrick Stolee via GitGitGadget" <gitgitgadget@gmail.com>
To: git@vger.kernel.org
Cc: gitster@pobox.com, peff@peff.net, newren@gmail.com,
Derrick Stolee <stolee@gmail.com>,
Derrick Stolee <stolee@gmail.com>
Subject: [PATCH 3/6] wrapper: create safe_memory_limit_check()
Date: Fri, 18 Sep 2026 13:02:17 +0000 [thread overview]
Message-ID: <3b3c67243d200a42aa105981b64228e2cbb35a6c.1789736540.git.gitgitgadget@gmail.com> (raw)
In-Reply-To: <pull.2230.git.1789736540.gitgitgadget@gmail.com>
From: Derrick Stolee <stolee@gmail.com>
The existing memory_limit_check() is used in many places within wrapper.c,
but because it initializes the GIT_ALLOC_LIMIT environment variable _and_
can call die() when not in gentle mode, this method isn't appropriate for a
safe API.
Modify the implementation to be safe_memory_limit_check() and to keep
calling error() when there is an allocation problem. The original method
calls that version but will die() instead when failing and not gentle.
The one potential behavior change is that when git_alloc_limit is unset we
must assume SIZE_MAX instead of loading the environment variable. Since we
load this environment variable proactively in setup_environment(), this
should only matter for that brief window before setup_environment() and the
safe APIs that call this version. If such safe APIs are used in that window,
then they should allocate small enough amounts of memory to fit under any
reasonable values of GIT_ALLOC_LIMIT.
Signed-off-by: Derrick Stolee <stolee@gmail.com>
---
wrapper.c | 27 ++++++++++++++++++---------
1 file changed, 18 insertions(+), 9 deletions(-)
diff --git a/wrapper.c b/wrapper.c
index 3de6b21cc2..97a29bda75 100644
--- a/wrapper.c
+++ b/wrapper.c
@@ -30,22 +30,31 @@ void initialize_git_alloc_limit(void)
}
}
-static int memory_limit_check(size_t size, int gentle)
+static int safe_memory_limit_check(size_t size, int verbose)
{
- initialize_git_alloc_limit();
-
- if (size > git_alloc_limit) {
- if (gentle) {
+ size_t limit = git_alloc_limit ? git_alloc_limit : SIZE_MAX;
+ if (size > limit) {
+ if (verbose)
error("attempting to allocate %"PRIuMAX" over limit %"PRIuMAX,
(uintmax_t)size, (uintmax_t)git_alloc_limit);
- return -1;
- } else
- die("attempting to allocate %"PRIuMAX" over limit %"PRIuMAX,
- (uintmax_t)size, (uintmax_t)git_alloc_limit);
+ return -1;
}
return 0;
}
+static int memory_limit_check(size_t size, int gentle)
+{
+ int res;
+ initialize_git_alloc_limit();
+
+ res = safe_memory_limit_check(size, gentle);
+ if (res && !gentle) {
+ die("attempting to allocate %"PRIuMAX" over limit %"PRIuMAX,
+ (uintmax_t)size, (uintmax_t)git_alloc_limit);
+ }
+ return res;
+}
+
char *xstrdup(const char *str)
{
char *ret = strdup(str);
--
gitgitgadget
next prev parent reply other threads:[~2026-09-18 13:02 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-18 13:02 [PATCH 0/6] [RFC] Create a 'safe' strbuf API Derrick Stolee via GitGitGadget
2026-09-18 13:02 ` [PATCH 1/6] strbuf: add header for 'safe' API Derrick Stolee via GitGitGadget
2026-09-21 21:18 ` Junio C Hamano
2026-09-23 19:25 ` Mark C. Chu-Carroll
2026-09-23 20:14 ` Junio C Hamano
2026-09-18 13:02 ` [PATCH 2/6] wrapper: initialize GIT_ALLOC_LIMIT proactively Derrick Stolee via GitGitGadget
2026-09-18 13:02 ` Derrick Stolee via GitGitGadget [this message]
2026-09-21 21:24 ` [PATCH 3/6] wrapper: create safe_memory_limit_check() Junio C Hamano
2026-09-18 13:02 ` [PATCH 4/6] strbuf-safe: add sstrbuf_grow() Derrick Stolee via GitGitGadget
2026-09-21 21:29 ` Junio C Hamano
2026-09-18 13:02 ` [PATCH 5/6] json-writer: include strbuf-safe.h Derrick Stolee via GitGitGadget
2026-09-18 13:02 ` [PATCH 6/6] strbuf-safe: add init and release methods Derrick Stolee via GitGitGadget
2026-09-21 21:44 ` Junio C Hamano
2026-09-21 22:34 ` Junio C Hamano
2026-09-19 15:23 ` [PATCH 0/6] [RFC] Create a 'safe' strbuf API Phillip Wood
2026-09-23 19:46 ` Jeff King
2026-10-06 14:33 ` Derrick Stolee
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=3b3c67243d200a42aa105981b64228e2cbb35a6c.1789736540.git.gitgitgadget@gmail.com \
--to=gitgitgadget@gmail.com \
--cc=git@vger.kernel.org \
--cc=gitster@pobox.com \
--cc=newren@gmail.com \
--cc=peff@peff.net \
--cc=stolee@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox