]> dgit.raspbian.org Git - dovecot.git/commitdiff
[PATCH 5/5] lib: Add comments about memory allocations and string functions preservin...
authorTimo Sirainen <timo.sirainen@open-xchange.com>
Wed, 3 Jun 2026 21:14:51 +0000 (21:14 +0000)
committerNoah Meyerhans <noahm@debian.org>
Wed, 16 Sep 2026 19:06:35 +0000 (15:06 -0400)
Gbp-Pq: Name 0005-lib-Add-comments-about-memory-allocations-and-string.patch

src/lib/data-stack.h
src/lib/imem.h
src/lib/mempool.h
src/lib/strfuncs.h

index 7ff66c4ef4c2fc66cb1cd1d6395efae8d3dc6b26..e0febe494f5efede637f89c9cb34b4cb4647a349 100644 (file)
       overflows.
 */
 
+/* All data stack allocations - t_malloc(), t_malloc0(), t_buffer_get(),
+   t_try_realloc() etc. - preserve errno. It is therefore safe to allocate
+   temporary memory between a failing syscall and reading errno (or
+   formatting "%m"). */
+
 #ifndef STATIC_CHECKER
 typedef unsigned int data_stack_frame_t;
 #else
index ed8c2eb58187581592725f5faa70d14961c2b585..6635bc018a483bd8856b9c39617de258a9c29c23 100644 (file)
@@ -3,6 +3,9 @@
 
 /* For easy allocation of memory from default memory pool. */
 
+/* Like all pool allocations, i_malloc()/i_realloc()/i_free() and the
+   i_strdup*() helpers preserve errno (see mempool.h). */
+
 extern pool_t default_pool;
 
 #define i_new(type, count) p_new(default_pool, type, count)
index 3b9872cb207ba2f4e70add14fecf413092695afd..37ecff4c7c9c0d3f8703a5f3ba06b48573bd08ac 100644 (file)
    zeroed, it will cost only a few CPU cycles and may well save some debug
    time. */
 
+/* All pool memory operations - p_malloc(), p_realloc(), p_free() and the
+   p_new()/p_strdup*() helpers built on them - preserve errno. This means an
+   allocation between a failing syscall and reading errno (e.g. when building
+   an error string with "%m") will not clobber errno. The same guarantee holds
+   for the t_* (data stack) and i_* (default pool) allocators. */
+
 typedef struct pool *pool_t;
 
 struct pool_vfuncs {
index f48021a9a1aae69865ef51adc6503fce9d4dca5e..b59c8b53f816c8e24b7ad36d4166d432a1fc6793 100644 (file)
@@ -13,6 +13,13 @@ extern const char *const empty_str_array[];
 int i_snprintf(char *dest, size_t max_chars, const char *format, ...)
        ATTR_FORMAT(3, 4);
 
+/* The p_/t_/i_ strdup, strconcat and *printf helpers below preserve errno.
+   So this pattern is safe - errno still refers to the failed syscall when
+   "%m" is expanded:
+
+     if (syscall(...) < 0)
+             error = t_strdup_printf("syscall() failed: %m"); */
+
 char *p_strdup(pool_t pool, const char *str) ATTR_MALLOC;
 void *p_memdup(pool_t pool, const void *data, size_t size) ATTR_MALLOC;
 /* return NULL if str = "" */