From: Derrick Stolee Date: Tue, 06 Oct 2026 14:37:05 GMT Subject: Re: [PATCH v3 0/7] trace2: stop allowing die() Message-ID: <77c35daa-1b28-4248-a203-3fd9c23de76a@gmail.com> In-Reply-To: On 8/31/2026 1:25 PM, Derrick Stolee via GitGitGadget wrote: > This starts with a new banned-die.h header file at the root of the repo and > including it from all trace2 API *.c files. It starts empty, but the later > patches will add one method at a time: > > * xsnprintf() : This is the original patch, but made more complete by > adding the method to banned-die.h. > * xstrdup() > * ALLOC_ARRAY() > * xstrfmt() > * ALLOC_GROW() > * xcalloc() > > During each patch, the goal was to have the trace2 logic be "as correct as > possible" when an allocation failure occurs. This may mean that we have > incomplete messages or dropped trace messages. This topic has sat idle for a while, in part because the protections attempted by this approach are incomplete and thus less exciting than I had hoped. My RFC for making strbuf and friends more robust was similarly unsatisfying [1] but there are some interesting ideas as to how this can be done differently. [1] https://lore.kernel.org/git/0f466dc6-f9c5-48ee-bb94-f3e8a951ee5d@gmail.com/ Thanks, -Stolee