git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 6/6] do not discard const: the ugly truth

From
Jeff King <peff@peff.net>
Date
Mar 26, 2026, 17:42 UTC
Message-ID
<20260326174204.GC2447148@coredump.intra.peff.net>
In-Reply-To
<fe9c86af4825a81b2618ae8ffc8be12300058af2.1774537954.git.git@grubix.eu>
On Thu, Mar 26, 2026 at 04:22:52PM +0100, Michael J Gruber wrote:
> ISOC23 reveals that we mutate argv strings in place. Confess to this
> with explicit casts.
Collin and I looked at this one a bit in the earlier thread:
  https://lore.kernel.org/git/e6f7e2eddbc9aef1c21f661420a4b8cb9cd8e2c1.1770095829.git.collin.funk1@gmail.com/

I think it is technically legal to mutate argv strings (which is why this doesn't segfault now), though I think we would prefer to treat them as conceptually const. You do get a segfault with:

  handle_revision_arg("..HEAD", &revs, 0, 0);

which we fortunately never do (we do pass string literals, but never with a range operator).

IMHO the right solution here is to teach the revision-parser not to touch the incoming buffers. We do it only to tie off strings, which can mostly be replaced with xmemdupz(). That's slightly less efficient, but I don't think it would be measurable (it's one allocation that tends to happen a handful of times per program execution, and the rest of the parsing is going to allocate things like commit structs anyway).

I have some patches in that direction, but I haven't gotten around to polishing them yet.

-Peff
Previous: Junio C HamanoNext: Jeff King
Message 6 of 24 in “ISOC23: quell warnings on discarding const”
  1. 0/6 ISOC23: quell warnings on discarding constMichael J Gruber, Mar 26, 2026
  2. 5/6 do not discard const: keep signatureMichael J Gruber, Mar 26, 2026
  3. Junio C HamanoMar 26, 2026
  4. 6/6 do not discard const: the ugly truthMichael J Gruber, Mar 26, 2026
  5. Junio C HamanoMar 26, 2026
  6. Jeff KingMar 26, 2026
  7. 0/4 fix const issues in revision parserJeff King, Mar 26, 2026
  8. 1/4 revision: make handle_dotdot() interface less confusingJeff King, Mar 26, 2026
  9. Junio C HamanoMar 26, 2026
  10. Jeff KingMar 26, 2026
  11. Junio C HamanoMar 27, 2026
  12. 2/4 rev-parse: simplify dotdot parsingJeff King, Mar 26, 2026
  13. 3/4 revision: avoid writing to const string for parent marksJeff King, Mar 26, 2026
  14. 4/4 rev-parse: avoid writing to const string for parent marksJeff King, Mar 26, 2026
  15. 1/6 do not discard const: the simple casesMichael J Gruber, Mar 26, 2026
  16. Jeff KingMar 26, 2026
  17. Junio C HamanoMar 26, 2026
  18. config: store allocated string in non-const pointerJeff King, Mar 26, 2026
  19. 4/6 do not discard const: declare const where we stay constMichael J Gruber, Mar 26, 2026
  20. 2/6 do not discard const: make git-compat-util ISOC23-likeMichael J Gruber, Mar 26, 2026
  21. 3/6 do not discard const: adjust to non-const data typesMichael J Gruber, Mar 26, 2026
  22. Junio C HamanoMar 26, 2026
  23. D. Ben KnobleMar 26, 2026
  24. Michael J GruberMar 27, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.