Re: [PATCH v2 2/4] string-list: replace negative index encoding with "exact_match" parameter
- From
Jeff King <peff@peff.net>
- Date
- Oct 9, 2025, 05:55 UTC
- Message-ID
- <20251009055554.GD1614343@coredump.intra.peff.net>
- In-Reply-To
- <87jz16dux5.fsf@gmail.com>
On Tue, Oct 07, 2025 at 06:49:42PM -0700, Collin Funk wrote:
Show 18 quoted lines
> In GNU Coreutils and Gnulib we often use 'idx_t', which is a typedef to > the standard signed type 'ptrdiff_t', when we refer to allocation of > objects or indexes. > > The rational is written in the header file where it is defined [1]. > However, I want to highlight one part that I find most useful: > > * Security: Signed types can be checked for overflow via > '-fsanitize=undefined', but unsigned types cannot. > > On common platforms, you will never need to allocate more memory than > PTRDIFF_MAX anyways: > > $ numfmt --to=iec-i `echo $(((1 << 63) - 1))` > 8.0Ei > > I think that addresses Jeff's point that 'int' is too small, which I > agree with.
Yeah, absolutely. I do not love size_t (and certainly switching signed "int" to unsigned "size_t" is an easy way to introduce bugs when you cross the "0" boundary). I'd be very happy with everything using something like ptrdiff_t, and even hiding it behind idx_t or count_t or whatever.
-Peff