From: Timo Sirainen Date: Wed, 3 Jun 2026 21:14:51 +0000 (+0000) Subject: [PATCH 5/5] lib: Add comments about memory allocations and string functions preservin... X-Git-Tag: archive/raspbian/1%2.4.1+dfsg1-6+rpi1+deb13u7^2~96 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=555147d5366ebefddd6f9159621415597da62135;p=dovecot.git [PATCH 5/5] lib: Add comments about memory allocations and string functions preserving errno Gbp-Pq: Name 0005-lib-Add-comments-about-memory-allocations-and-string.patch --- diff --git a/src/lib/data-stack.h b/src/lib/data-stack.h index 7ff66c4..e0febe4 100644 --- a/src/lib/data-stack.h +++ b/src/lib/data-stack.h @@ -31,6 +31,11 @@ overflows. */ +/* All data stack allocations - t_malloc(), t_malloc0(), t_buffer_get(), + t_try_realloc() etc. - preserve errno. It is therefore safe to allocate + temporary memory between a failing syscall and reading errno (or + formatting "%m"). */ + #ifndef STATIC_CHECKER typedef unsigned int data_stack_frame_t; #else diff --git a/src/lib/imem.h b/src/lib/imem.h index ed8c2eb..6635bc0 100644 --- a/src/lib/imem.h +++ b/src/lib/imem.h @@ -3,6 +3,9 @@ /* For easy allocation of memory from default memory pool. */ +/* Like all pool allocations, i_malloc()/i_realloc()/i_free() and the + i_strdup*() helpers preserve errno (see mempool.h). */ + extern pool_t default_pool; #define i_new(type, count) p_new(default_pool, type, count) diff --git a/src/lib/mempool.h b/src/lib/mempool.h index 3b9872c..37ecff4 100644 --- a/src/lib/mempool.h +++ b/src/lib/mempool.h @@ -19,6 +19,12 @@ zeroed, it will cost only a few CPU cycles and may well save some debug time. */ +/* All pool memory operations - p_malloc(), p_realloc(), p_free() and the + p_new()/p_strdup*() helpers built on them - preserve errno. This means an + allocation between a failing syscall and reading errno (e.g. when building + an error string with "%m") will not clobber errno. The same guarantee holds + for the t_* (data stack) and i_* (default pool) allocators. */ + typedef struct pool *pool_t; struct pool_vfuncs { diff --git a/src/lib/strfuncs.h b/src/lib/strfuncs.h index f48021a..b59c8b5 100644 --- a/src/lib/strfuncs.h +++ b/src/lib/strfuncs.h @@ -13,6 +13,13 @@ extern const char *const empty_str_array[]; int i_snprintf(char *dest, size_t max_chars, const char *format, ...) ATTR_FORMAT(3, 4); +/* The p_/t_/i_ strdup, strconcat and *printf helpers below preserve errno. + So this pattern is safe - errno still refers to the failed syscall when + "%m" is expanded: + + if (syscall(...) < 0) + error = t_strdup_printf("syscall() failed: %m"); */ + char *p_strdup(pool_t pool, const char *str) ATTR_MALLOC; void *p_memdup(pool_t pool, const void *data, size_t size) ATTR_MALLOC; /* return NULL if str = "" */