From: Jeff King Date: Thu, 09 Oct 2025 05:55:54 GMT Subject: Re: [PATCH v2 2/4] string-list: replace negative index encoding with "exact_match" parameter Message-ID: <20251009055554.GD1614343@coredump.intra.peff.net> In-Reply-To: <87jz16dux5.fsf@gmail.com> On Tue, Oct 07, 2025 at 06:49:42PM -0700, Collin Funk wrote: > In GNU Coreutils and Gnulib we often use 'idx_t', which is a typedef to > the standard signed type 'ptrdiff_t', when we refer to allocation of > objects or indexes. > > The rational is written in the header file where it is defined [1]. > However, I want to highlight one part that I find most useful: > > * Security: Signed types can be checked for overflow via > '-fsanitize=undefined', but unsigned types cannot. > > On common platforms, you will never need to allocate more memory than > PTRDIFF_MAX anyways: > > $ numfmt --to=iec-i `echo $(((1 << 63) - 1))` > 8.0Ei > > I think that addresses Jeff's point that 'int' is too small, which I > agree with. Yeah, absolutely. I do not love size_t (and certainly switching signed "int" to unsigned "size_t" is an easy way to introduce bugs when you cross the "0" boundary). I'd be very happy with everything using something like ptrdiff_t, and even hiding it behind idx_t or count_t or whatever. -Peff