git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH 3/6] wrapper: create safe_memory_limit_check()

From
Derrick Stolee via GitGitGadget <gitgitgadget@gmail.com>
Date
Sep 18, 2026, 13:02 UTC
Message-ID
<3b3c67243d200a42aa105981b64228e2cbb35a6c.1789736540.git.gitgitgadget@gmail.com>
In-Reply-To
<pull.2230.git.1789736540.gitgitgadget@gmail.com>
From: Derrick Stolee <stolee@gmail.com>

The existing memory_limit_check() is used in many places within wrapper.c, but because it initializes the GIT_ALLOC_LIMIT environment variable _and_ can call die() when not in gentle mode, this method isn't appropriate for a safe API.

Modify the implementation to be safe_memory_limit_check() and to keep calling error() when there is an allocation problem. The original method calls that version but will die() instead when failing and not gentle.

The one potential behavior change is that when git_alloc_limit is unset we must assume SIZE_MAX instead of loading the environment variable. Since we load this environment variable proactively in setup_environment(), this should only matter for that brief window before setup_environment() and the safe APIs that call this version. If such safe APIs are used in that window, then they should allocate small enough amounts of memory to fit under any reasonable values of GIT_ALLOC_LIMIT.

Signed-off-by: Derrick Stolee <stolee@gmail.com>
---
 wrapper.c | 27 ++++++++++++++++++---------
 1 file changed, 18 insertions(+), 9 deletions(-)
diff --git a/wrapper.c b/wrapper.c
index 3de6b21cc2..97a29bda75 100644
--- a/wrapper.c
+++ b/wrapper.c
@@ -30,22 +30,31 @@ void initialize_git_alloc_limit(void)
 	}
 }
 
-static int memory_limit_check(size_t size, int gentle)
+static int safe_memory_limit_check(size_t size, int verbose)
 {
-	initialize_git_alloc_limit();
-
-	if (size > git_alloc_limit) {
-		if (gentle) {
+	size_t limit = git_alloc_limit ? git_alloc_limit : SIZE_MAX;
+	if (size > limit) {
+		if (verbose)
 			error("attempting to allocate %"PRIuMAX" over limit %"PRIuMAX,
 			      (uintmax_t)size, (uintmax_t)git_alloc_limit);
-			return -1;
-		} else
-			die("attempting to allocate %"PRIuMAX" over limit %"PRIuMAX,
-			    (uintmax_t)size, (uintmax_t)git_alloc_limit);
+		return -1;
 	}
 	return 0;
 }
 
+static int memory_limit_check(size_t size, int gentle)
+{
+	int res;
+	initialize_git_alloc_limit();
+
+	res = safe_memory_limit_check(size, gentle);
+	if (res && !gentle) {
+		die("attempting to allocate %"PRIuMAX" over limit %"PRIuMAX,
+		    (uintmax_t)size, (uintmax_t)git_alloc_limit);
+	}
+	return res;
+}
+
 char *xstrdup(const char *str)
 {
 	char *ret = strdup(str);
-- 
gitgitgadget
Previous: Derrick Stolee via GitGitGadgetNext: Junio C Hamano
Message 7 of 17 in “[RFC] Create a 'safe' strbuf API”
  1. 0/6 [RFC] Create a 'safe' strbuf APIDerrick Stolee via GitGitGadget, Sep 18, 2026
  2. 1/6 strbuf: add header for 'safe' APIDerrick Stolee via GitGitGadget, Sep 18, 2026
  3. Junio C HamanoSep 21, 2026
  4. Mark C. Chu-CarrollSep 23, 2026
  5. Junio C HamanoSep 23, 2026
  6. 2/6 wrapper: initialize GIT_ALLOC_LIMIT proactivelyDerrick Stolee via GitGitGadget, Sep 18, 2026
  7. 3/6 wrapper: create safe_memory_limit_check()Derrick Stolee via GitGitGadget, Sep 18, 2026
  8. Junio C HamanoSep 21, 2026
  9. 4/6 strbuf-safe: add sstrbuf_grow()Derrick Stolee via GitGitGadget, Sep 18, 2026
  10. Junio C HamanoSep 21, 2026
  11. 5/6 json-writer: include strbuf-safe.hDerrick Stolee via GitGitGadget, Sep 18, 2026
  12. 6/6 strbuf-safe: add init and release methodsDerrick Stolee via GitGitGadget, Sep 18, 2026
  13. Junio C HamanoSep 21, 2026
  14. Junio C HamanoSep 21, 2026
  15. Phillip WoodSep 19, 2026
  16. Jeff KingSep 23, 2026
  17. Derrick StoleeOct 6, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.