git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] strbuf: instate cleanup rule in case of non-memory errors

From
René Scharfe <rene.scharfe@lsrfire.ath.cx>
Date
Jan 6, 2009, 20:41 UTC
Message-ID
<4963C1EA.504@lsrfire.ath.cx>
In-Reply-To
<20090104122108.GC29325@artemis.corp>

Make all strbuf functions that can fail free() their memory on error if they have allocated it. They don't shrink buffers that have been grown, though.

This allows for easier error handling, as callers only need to call strbuf_release() if A) the command succeeded or B) if they would have had to do so anyway because they added something to the strbuf themselves.

Bonus hunk: document strbuf_readlink.
Signed-off-by: Rene Scharfe <rene.scharfe@lsrfire.ath.cx>
---
 Documentation/technical/api-strbuf.txt |   11 +++++++++--
 strbuf.c                               |   17 +++++++++++++----
 2 files changed, 22 insertions(+), 6 deletions(-)
diff --git a/Documentation/technical/api-strbuf.txt b/Documentation/technical/api-strbuf.txt
index a8ee2fe..9a4e3ea 100644
--- a/Documentation/technical/api-strbuf.txt
+++ b/Documentation/technical/api-strbuf.txt
@@ -133,8 +133,10 @@ Functions
 
 * Adding data to the buffer
 
-NOTE: All of these functions in this section will grow the buffer as
-      necessary.
+NOTE: All of the functions in this section will grow the buffer as necessary.
+If they fail for some reason other than memory shortage and the buffer hadn't
+been allocated before (i.e. the `struct strbuf` was set to `STRBUF_INIT`),
+then they will free() it.
 
 `strbuf_addch`::
 
@@ -235,6 +237,11 @@ same behaviour as well.
 	Read the contents of a file, specified by its path. The third argument
 	can be used to give a hint about the file size, to avoid reallocs.
 
+`strbuf_readlink`::
+
+	Read the target of a symbolic link, specified by its path.  The third
+	argument can be used to give a hint about the size, to avoid reallocs.
+
 `strbuf_getline`::
 
 	Read a line from a FILE* pointer. The second argument specifies the line
diff --git a/strbuf.c b/strbuf.c
index bdf4954..6ed0684 100644
--- a/strbuf.c
+++ b/strbuf.c
@@ -256,18 +256,21 @@ size_t strbuf_expand_dict_cb(struct strbuf *sb, const char *placeholder,
 size_t strbuf_fread(struct strbuf *sb, size_t size, FILE *f)
 {
 	size_t res;
+	size_t oldalloc = sb->alloc;
 
 	strbuf_grow(sb, size);
 	res = fread(sb->buf + sb->len, 1, size, f);
-	if (res > 0) {
+	if (res > 0)
 		strbuf_setlen(sb, sb->len + res);
-	}
+	else if (res < 0 && oldalloc == 0)
+		strbuf_release(sb);
 	return res;
 }
 
 ssize_t strbuf_read(struct strbuf *sb, int fd, size_t hint)
 {
 	size_t oldlen = sb->len;
+	size_t oldalloc = sb->alloc;
 
 	strbuf_grow(sb, hint ? hint : 8192);
 	for (;;) {
@@ -275,7 +278,10 @@ ssize_t strbuf_read(struct strbuf *sb, int fd, size_t hint)
 
 		cnt = xread(fd, sb->buf + sb->len, sb->alloc - sb->len - 1);
 		if (cnt < 0) {
-			strbuf_setlen(sb, oldlen);
+			if (oldalloc == 0)
+				strbuf_release(sb);
+			else
+				strbuf_setlen(sb, oldlen);
 			return -1;
 		}
 		if (!cnt)
@@ -292,6 +298,8 @@ ssize_t strbuf_read(struct strbuf *sb, int fd, size_t hint)
 
 int strbuf_readlink(struct strbuf *sb, const char *path, size_t hint)
 {
+	size_t oldalloc = sb->alloc;
+
 	if (hint < 32)
 		hint = 32;
 
@@ -311,7 +319,8 @@ int strbuf_readlink(struct strbuf *sb, const char *path, size_t hint)
 		/* .. the buffer was too small - try again */
 		hint *= 2;
 	}
-	strbuf_release(sb);
+	if (oldalloc == 0)
+		strbuf_release(sb);
 	return -1;
 }
 
-- 
1.6.1
Previous: Pierre HabouzitNext: Junio C Hamano
Message 32 of 33 in “Be careful about lstat()-vs-readlink()”
  1. 0/5 Be careful about lstat()-vs-readlink()Linus Torvalds, Dec 17, 2008
  2. 1/5 Add generic 'strbuf_readlink()' helper functionLinus Torvalds, Dec 17, 2008
  3. 2/5 Make 'ce_compare_link()' use the new 'strbuf_readlink()'Linus Torvalds, Dec 17, 2008
  4. 3/5 Make 'index_path()' use 'strbuf_readlink()'Linus Torvalds, Dec 17, 2008
  5. 4/5 Make 'diff_populate_filespec()' use the new 'strbuf_readlink()'Linus Torvalds, Dec 17, 2008
  6. 5/5 Make 'prepare_temp_file()' ignore st_size for symlinksLinus Torvalds, Dec 17, 2008
  7. 6/5 make_absolute_path(): check bounds when seeing an overlong symlinkJunio C Hamano, Dec 17, 2008
  8. 7/5 builtin-blame.c: use strbuf_readlink()Junio C Hamano, Dec 17, 2008
  9. 8/5 combine-diff.c: use strbuf_readlink()Junio C Hamano, Dec 17, 2008
  10. Linus TorvaldsDec 17, 2008
  11. Junio C HamanoDec 17, 2008
  12. Junio C HamanoDec 17, 2008
  13. Mark BurtonDec 18, 2008
  14. Linus TorvaldsDec 18, 2008
  15. René ScharfeDec 18, 2008
  16. Linus TorvaldsDec 18, 2008
  17. Olivier GalibertDec 18, 2008
  18. René ScharfeDec 18, 2008
  19. René ScharfeDec 18, 2008
  20. diff.c: fix pointer type warningRené Scharfe, Dec 19, 2008
  21. Junio C HamanoDec 19, 2008
  22. Junio C HamanoDec 17, 2008
  23. Jay SoffianDec 17, 2008
  24. Linus TorvaldsDec 17, 2008
  25. strbuf_readlink semantics update.Pierre Habouzit, Dec 23, 2008
  26. Pierre HabouzitDec 23, 2008
  27. Linus TorvaldsDec 23, 2008
  28. Pierre HabouzitDec 24, 2008
  29. René ScharfeDec 24, 2008
  30. Junio C HamanoDec 25, 2008
  31. Pierre HabouzitJan 4, 2009
  32. strbuf: instate cleanup rule in case of non-memory errorsRené Scharfe, Jan 6, 2009
  33. Junio C HamanoJan 7, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.