git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2 6/9] list-objects-filter-options: make filter_spec a strbuf

From
Matthew DeVore <matvore@comcast.net>
Date
Jun 11, 2019, 18:44 UTC
Message-ID
<20190611184426.GB58112@comcast.net>
In-Reply-To
<xmqqtvcwkowx.fsf@gitster-ct.c.googlers.com>
On Tue, Jun 11, 2019 at 10:33:18AM -0700, Junio C Hamano wrote:
Show 14 quoted lines
> Matthew DeVore <matvore@comcast.net> writes:
> 
> >> convention, and it may even be a useful one (i.e. it allows you to
> >> calloc() a structure with an embedded strbuf in it and the "if
> >> .buf==NULL, call strbuf_init() lazily" can become an established
> >> pattern), but at the same time it feels a bit brittle.  
> >
> > Is it brittle because a strbuf may be initialized to non-zero memory, and so
> > the "if (buf.buf == NULL)" may evaluate to false, and then go on treating
> > garbage like a valid buffer?
> 
> It is brittle because callers are bound to forget doing "if
> (!x->buf.buf) lazy_init(&x->buf)" at some point, and blindly use an
> uninitialized x->buf.  Making sure x->buf is always initialized

A corallary proposition would be to make this particular strbuf a "struct strbuf *" rather than an inline strbuf. It should then be rather clear to users that it may be null. Then whoever allocates the memory can also do the strbuf_init one-liner. The free'ing logic of list_objects_filter_options then only becomes trivially more complicated than it was before. Does that sound like a good compromise to you?

Show 5 quoted lines
> before any caller touches is the only way to solve it, and as you
> said, there are two possible ways to make that happen.  One way that
> does not violate the current API contract is to make sure whoever
> allocates and/or initializes the surrounding struct that embeds a
> strbuf does strbuf_init(&x->buf) before any user sees the struct.

The thing I don't like about that is that the non-zeroness of its initialization percolates upward to whatever the top-level struct is, which means implementation details leak a lot. This seems quite brittle as well, since anyone can forget to initialize some struct in the nested line.

Show 9 quoted lines
> 
> Another would be to update strbuf API so that strbuf_init() does not
> even have to use slopbuf.  But that is a much larger change that
> potentially breaks existing users of strbuf API.  When you have a
> strbuf that has been prepared to be usable, the current API contract
> allows its users to expect buf.buf is never NULL, so they assume
> that they can safely write "if (!buf.buf)", so auditing strbuf.c and
> making sure a strbuf with buf==NULL gets lazily initialized is not
> enough.

That's true. I didn't think it matters in the case of filter_spec in particular, since users of list_objects_filter_options are supposed to use an accessor and not touch the strbuf directly, but looking at it like a more general API change, it seems risky.

Previous: Junio C HamanoNext: Matthew DeVore
Message 14 of 74 in “Filter combination”
  1. 0/9 Filter combinationMatthew DeVore, Jun 1, 2019
  2. 1/9 list-objects-filter: make API easier to useMatthew DeVore, Jun 1, 2019
  3. 2/9 list-objects-filter: put omits set in filter structMatthew DeVore, Jun 1, 2019
  4. 3/9 list-objects-filter-options: always supply *errbufMatthew DeVore, Jun 1, 2019
  5. 4/9 list-objects-filter: implement composite filtersMatthew DeVore, Jun 1, 2019
  6. Jeff HostetlerJun 3, 2019
  7. Matthew DeVoreJun 6, 2019
  8. Jeff HostetlerJun 7, 2019
  9. 5/9 list-objects-filter-options: move error check upMatthew DeVore, Jun 1, 2019
  10. 6/9 list-objects-filter-options: make filter_spec a strbufMatthew DeVore, Jun 1, 2019
  11. Junio C HamanoJun 10, 2019
  12. Matthew DeVoreJun 11, 2019
  13. Junio C HamanoJun 11, 2019
  14. Matthew DeVoreJun 11, 2019
  15. Matthew DeVoreJun 11, 2019
  16. Junio C HamanoJun 11, 2019
  17. Matthew DeVoreJun 12, 2019
  18. Matthew DeVoreJun 12, 2019
  19. 7/9 list-objects-filter-options: allow mult. --filterMatthew DeVore, Jun 1, 2019
  20. 8/9 list-objects-filter-options: clean up use of ALLOC_GROWMatthew DeVore, Jun 1, 2019
  21. Jacob KellerJun 3, 2019
  22. Matthew DeVoreJun 3, 2019
  23. Jacob KellerJun 4, 2019
  24. 9/9 list-objects-filter-options: make parser voidMatthew DeVore, Jun 1, 2019
  25. Jeff HostetlerJun 3, 2019
  26. 00/10 Filter combinationMatthew DeVore, Jun 13, 2019
  27. 01/10 list-objects-filter: make API easier to useMatthew DeVore, Jun 13, 2019
  28. 02/10 list-objects-filter: put omits set in filter structMatthew DeVore, Jun 13, 2019
  29. 03/10 list-objects-filter-options: always supply *errbufMatthew DeVore, Jun 13, 2019
  30. 04/10 list-objects-filter: implement composite filtersMatthew DeVore, Jun 13, 2019
  31. 05/10 list-objects-filter-options: move error check upMatthew DeVore, Jun 13, 2019
  32. 06/10 list-objects-filter-options: make filter_spec a string_listMatthew DeVore, Jun 13, 2019
  33. 07/10 strbuf: give URL-encoding API a char predicate fnMatthew DeVore, Jun 13, 2019
  34. 08/10 list-objects-filter-options: allow mult. --filterMatthew DeVore, Jun 13, 2019
  35. 09/10 list-objects-filter-options: clean up use of ALLOC_GROWMatthew DeVore, Jun 13, 2019
  36. 10/10 list-objects-filter-options: make parser voidMatthew DeVore, Jun 13, 2019
  37. Junio C HamanoJun 14, 2019
  38. 00/10 Filter combinationMatthew DeVore, Jun 15, 2019
  39. 01/10 list-objects-filter: make API easier to useMatthew DeVore, Jun 15, 2019
  40. Jonathan TanJun 21, 2019
  41. Matthew DeVoreJun 27, 2019
  42. 02/10 list-objects-filter: put omits set in filter structMatthew DeVore, Jun 15, 2019
  43. 03/10 list-objects-filter-options: always supply *errbufMatthew DeVore, Jun 15, 2019
  44. 04/10 list-objects-filter: implement composite filtersMatthew DeVore, Jun 15, 2019
  45. Johannes SchindelinJun 18, 2019
  46. Matthew DeVoreJun 18, 2019
  47. Johannes SchindelinJun 21, 2019
  48. Jonathan TanJun 22, 2019
  49. Matthew DeVoreJun 27, 2019
  50. 05/10 list-objects-filter-options: move error check upMatthew DeVore, Jun 15, 2019
  51. 06/10 list-objects-filter-options: make filter_spec a string_listMatthew DeVore, Jun 15, 2019
  52. Jonathan TanJun 22, 2019
  53. Matthew DeVoreJun 27, 2019
  54. 07/10 strbuf: give URL-encoding API a char predicate fnMatthew DeVore, Jun 15, 2019
  55. 08/10 list-objects-filter-options: allow mult. --filterMatthew DeVore, Jun 15, 2019
  56. 09/10 list-objects-filter-options: clean up use of ALLOC_GROWMatthew DeVore, Jun 15, 2019
  57. 10/10 list-objects-filter-options: make parser voidMatthew DeVore, Jun 15, 2019
  58. Jonathan TanJun 22, 2019
  59. Matthew DeVoreJun 27, 2019
  60. Matthew DeVoreJun 27, 2019
  61. Junio C HamanoJun 18, 2019
  62. 00/10 Filter combinationMatthew DeVore, Jun 27, 2019
  63. 01/10 list-objects-filter: encapsulate filter componentsMatthew DeVore, Jun 27, 2019
  64. 03/10 list-objects-filter-options: always supply *errbufMatthew DeVore, Jun 27, 2019
  65. 02/10 list-objects-filter: put omits set in filter structMatthew DeVore, Jun 27, 2019
  66. 04/10 list-objects-filter: implement composite filtersMatthew DeVore, Jun 27, 2019
  67. 05/10 list-objects-filter-options: move error check upMatthew DeVore, Jun 27, 2019
  68. 06/10 list-objects-filter-options: make filter_spec a string_listMatthew DeVore, Jun 27, 2019
  69. 07/10 strbuf: give URL-encoding API a char predicate fnMatthew DeVore, Jun 27, 2019
  70. 08/10 list-objects-filter-options: allow mult. --filterMatthew DeVore, Jun 27, 2019
  71. 09/10 list-objects-filter-options: clean up use of ALLOC_GROWMatthew DeVore, Jun 27, 2019
  72. 10/10 list-objects-filter-options: make parser voidMatthew DeVore, Jun 27, 2019
  73. Junio C HamanoJun 28, 2019
  74. Jonathan TanJun 28, 2019

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.