git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2 11/18] git-compat-util.h: introduce `u32_add()`

From
Patrick Steinhardt <ps@pks.im>
Date
Jan 21, 2026, 08:51 UTC
Message-ID
<aXCTkVpjJkTabx_0@pks.im>
In-Reply-To
<aWgwn2rk/qw+fRoA@nand.local>
On Wed, Jan 14, 2026 at 07:11:11PM -0500, Taylor Blau wrote:
Show 89 quoted lines
> On Wed, Jan 14, 2026 at 05:03:56PM -0500, Taylor Blau wrote:
> > As for removing u64_add(), that should be straightforward as well since
> > there is also a single caller. Let me know if you think that makes sense
> > to take up as part of this series, or if you would prefer it done
> > separately. I tend to prefer the latter, since the state after applying
> > the above is that we avoid adding any new callers.
> 
> This appears to be easy enough. The following applies on top of 'master'
> if you want to pick it up separately:
> 
> --- 8< ---
> 
> Subject: [PATCH] git-compat-util.h: drop u64_add(), u64_mult() helpers
> 
> The u64_add() and u64_mult() helper functions were introduced in
> b103881d4f4 (midx repack: avoid integer overflow on 32 bit systems,
> 2025-05-22) to implement overflow checks during a fixed-point
> calculation when estimating pack sizes in the MIDX writing code.
> 
> However, those functions call die() when either the addition or
> multiplication of their operands (depending on which function is being
> called) would cause an overflow. This does not allow the caller to
> provide a more detailed message, presenting the user with an opaque
> message like:
> 
>     fatal: uint64_t overflow: M * N
> 
> Let's discourage these opaque error messages by dropping these functions
> entirely and instead having the caller use unsigned_mult_overflows() or
> unsigned_add_overflows() themselves, providing the caller the
> opportunity to come up with their own die() message.
> 
> Suggested-by: Junio C Hamano <gitster@pobox.com>
> Signed-off-by: Taylor Blau <me@ttaylorr.com>
> ---
>  git-compat-util.h | 16 ----------------
>  midx-write.c      | 15 +++++++++++++--
>  2 files changed, 13 insertions(+), 18 deletions(-)
> 
> diff --git a/git-compat-util.h b/git-compat-util.h
> index b0673d1a450..24edd68c671 100644
> --- a/git-compat-util.h
> +++ b/git-compat-util.h
> @@ -641,22 +641,6 @@ static inline int cast_size_t_to_int(size_t a)
>  	return (int)a;
>  }
> 
> -static inline uint64_t u64_mult(uint64_t a, uint64_t b)
> -{
> -	if (unsigned_mult_overflows(a, b))
> -		die("uint64_t overflow: %"PRIuMAX" * %"PRIuMAX,
> -		    (uintmax_t)a, (uintmax_t)b);
> -	return a * b;
> -}
> -
> -static inline uint64_t u64_add(uint64_t a, uint64_t b)
> -{
> -	if (unsigned_add_overflows(a, b))
> -		die("uint64_t overflow: %"PRIuMAX" + %"PRIuMAX,
> -		    (uintmax_t)a, (uintmax_t)b);
> -	return a + b;
> -}
> -
>  /*
>   * Limit size of IO chunks, because huge chunks only cause pain.  OS X
>   * 64-bit is buggy, returning EINVAL if len >= INT_MAX; and even in
> diff --git a/midx-write.c b/midx-write.c
> index 87b97c70872..6006b6569c8 100644
> --- a/midx-write.c
> +++ b/midx-write.c
> @@ -1738,8 +1738,19 @@ static void fill_included_packs_batch(struct repository *r,
>  		 */
>  		expected_size = (uint64_t)pack_info[i].referenced_objects << 14;
>  		expected_size /= p->num_objects;
> -		expected_size = u64_mult(expected_size, p->pack_size);
> -		expected_size = u64_add(expected_size, 1u << 13) >> 14;
> +
> +		if (unsigned_mult_overflows(expected_size,
> +					    (uint64_t)p->pack_size))
> +			die(_("overflow during fixed-point multiply (%"PRIu64" "
> +			      "* %"PRIu64")"),
> +			    expected_size, (uint64_t)p->pack_size);
> +		expected_size = expected_size * p->pack_size;
> +
> +		if (unsigned_add_overflows(expected_size, 1u << 13))
> +			die(_("overflow during fixed-point rounding (%"PRIu64" "
> +			      " + %"PRIu64")"),
> +			    expected_size, (uint64_t)(1ul << 13));
> +		expected_size = (expected_size + (1u << 13)) >> 14;

One downside this pattern has is that we repeat the computation, which makes it easy to get it wrong or forget updating either the check or the computation.

I think ideally, we would have interfaces that combine the two approaches in `u64_mult()` and `unsigned_mult_overflows()`. Something like this for example:

    static intline bool u64_mult(uint64_t a, uint64_t b, uint64_t *out)
    {
        if (unsigned_mult_overflows(a, b))
            return false;
        *out = a * b;
        return true;
    }

This would let the caller handle the failure and is thus quite flexible, which results in the following code:

	if (!u64_mult(expected_size, (uint64_t)p->pack_size, &expected_size))
		die(_("overflow during fixed-point multiply (%"PRIu64" "
		      "* %"PRIu64")"), expected_size, (uint64_t)p->pack_size);
Patrick
Previous: Taylor BlauNext: Taylor Blau
Message 64 of 99 in “midx: incremental MIDX/bitmap layer compaction”
  1. 00/17 midx: incremental MIDX/bitmap layer compactionTaylor Blau, Dec 6, 2025
  2. 01/17 midx: mark `get_midx_checksum()` arguments as constTaylor Blau, Dec 6, 2025
  3. Patrick SteinhardtDec 8, 2025
  4. Taylor BlauDec 9, 2025
  5. 02/17 midx: split `get_midx_checksum()` by adding `get_midx_hash()`Taylor Blau, Dec 6, 2025
  6. Patrick SteinhardtDec 8, 2025
  7. Taylor BlauDec 9, 2025
  8. Taylor BlauDec 9, 2025
  9. Patrick SteinhardtDec 9, 2025
  10. Taylor BlauJan 13, 2026
  11. 03/17 builtin/multi-pack-index.c: make '--progress' a common optionTaylor Blau, Dec 6, 2025
  12. 04/17 git-multi-pack-index(1): remove non-existent incompatibilityTaylor Blau, Dec 6, 2025
  13. 05/17 git-multi-pack-index(1): align SYNOPSIS with 'git multi-pack-index -h'Taylor Blau, Dec 6, 2025
  14. 06/17 t/t5319-multi-pack-index.sh: fix copy-and-paste error in t5319.39Taylor Blau, Dec 6, 2025
  15. 07/17 midx-write.c: don't use `pack_perm` when assigning `bitmap_pos`Taylor Blau, Dec 6, 2025
  16. Patrick SteinhardtDec 8, 2025
  17. Taylor BlauDec 9, 2025
  18. 08/17 midx-write.c: introduce `struct write_midx_opts`Taylor Blau, Dec 6, 2025
  19. Patrick SteinhardtDec 8, 2025
  20. Taylor BlauDec 9, 2025
  21. 09/17 midx: do not require packs to be sorted in lexicographic orderTaylor Blau, Dec 6, 2025
  22. Patrick SteinhardtDec 8, 2025
  23. Taylor BlauDec 9, 2025
  24. Taylor BlauDec 9, 2025
  25. 10/17 git-compat-util.h: introduce `u32_add()`Taylor Blau, Dec 6, 2025
  26. Patrick SteinhardtDec 8, 2025
  27. Taylor BlauDec 9, 2025
  28. 11/17 midx-write.c: introduce `midx_pack_perm()` helperTaylor Blau, Dec 6, 2025
  29. 12/17 midx-write.c: extract `fill_pack_from_midx()`Taylor Blau, Dec 6, 2025
  30. 13/17 midx-write.c: enumerate `pack_int_id` values directlyTaylor Blau, Dec 6, 2025
  31. Patrick SteinhardtDec 8, 2025
  32. Taylor BlauDec 9, 2025
  33. 14/17 midx-write.c: factor fanout layering from `compute_sorted_entries()`Taylor Blau, Dec 6, 2025
  34. 15/17 t/helper/test-read-midx.c: plug memory leak when selecting layerTaylor Blau, Dec 6, 2025
  35. Patrick SteinhardtDec 8, 2025
  36. Taylor BlauDec 9, 2025
  37. 16/17 midx: implement MIDX compactionTaylor Blau, Dec 6, 2025
  38. Patrick SteinhardtDec 9, 2025
  39. Taylor BlauJan 13, 2026
  40. 17/17 midx: enable reachability bitmaps during MIDX compactionTaylor Blau, Dec 6, 2025
  41. Patrick SteinhardtDec 9, 2025
  42. Taylor BlauJan 13, 2026
  43. 00/18 midx: incremental MIDX/bitmap layer compactionTaylor Blau, Jan 14, 2026
  44. 01/18 midx: mark `get_midx_checksum()` arguments as constTaylor Blau, Jan 14, 2026
  45. 02/18 midx: rename `get_midx_checksum()` to `midx_get_checksum_hash()`Taylor Blau, Jan 14, 2026
  46. 03/18 midx: introduce `midx_get_checksum_hex()`Taylor Blau, Jan 14, 2026
  47. 04/18 builtin/multi-pack-index.c: make '--progress' a common optionTaylor Blau, Jan 14, 2026
  48. 05/18 git-multi-pack-index(1): remove non-existent incompatibilityTaylor Blau, Jan 14, 2026
  49. 06/18 git-multi-pack-index(1): align SYNOPSIS with 'git multi-pack-index -h'Taylor Blau, Jan 14, 2026
  50. 07/18 t/t5319-multi-pack-index.sh: fix copy-and-paste error in t5319.39Taylor Blau, Jan 14, 2026
  51. 08/18 midx-write.c: don't use `pack_perm` when assigning `bitmap_pos`Taylor Blau, Jan 14, 2026
  52. Junio C HamanoJan 14, 2026
  53. Taylor BlauJan 14, 2026
  54. 09/18 midx-write.c: introduce `struct write_midx_opts`Taylor Blau, Jan 14, 2026
  55. 10/18 midx: do not require packs to be sorted in lexicographic orderTaylor Blau, Jan 14, 2026
  56. Junio C HamanoJan 14, 2026
  57. Taylor BlauJan 14, 2026
  58. Patrick SteinhardtJan 27, 2026
  59. Taylor BlauFeb 24, 2026
  60. 11/18 git-compat-util.h: introduce `u32_add()`Taylor Blau, Jan 14, 2026
  61. Junio C HamanoJan 14, 2026
  62. Taylor BlauJan 14, 2026
  63. Taylor BlauJan 15, 2026
  64. Patrick SteinhardtJan 21, 2026
  65. Taylor BlauJan 21, 2026
  66. rsbecker@nexbridge.comJan 22, 2026
  67. Junio C HamanoJan 22, 2026
  68. Jeff KingFeb 23, 2026
  69. Taylor BlauFeb 24, 2026
  70. 12/18 midx-write.c: introduce `midx_pack_perm()` helperTaylor Blau, Jan 14, 2026
  71. 13/18 midx-write.c: extract `fill_pack_from_midx()`Taylor Blau, Jan 14, 2026
  72. 14/18 midx-write.c: enumerate `pack_int_id` values directlyTaylor Blau, Jan 14, 2026
  73. 15/18 midx-write.c: factor fanout layering from `compute_sorted_entries()`Taylor Blau, Jan 14, 2026
  74. 16/18 t/helper/test-read-midx.c: plug memory leak when selecting layerTaylor Blau, Jan 14, 2026
  75. 17/18 midx: implement MIDX compactionTaylor Blau, Jan 14, 2026
  76. Patrick SteinhardtJan 27, 2026
  77. Taylor BlauJan 27, 2026
  78. 18/18 midx: enable reachability bitmaps during MIDX compactionTaylor Blau, Jan 14, 2026
  79. Junio C HamanoFeb 20, 2026
  80. Jeff KingFeb 23, 2026
  81. Taylor BlauFeb 24, 2026
  82. 00/17 midx: incremental MIDX/bitmap layer compactionTaylor Blau, Feb 24, 2026
  83. 01/17 midx: mark `get_midx_checksum()` arguments as constTaylor Blau, Feb 24, 2026
  84. 02/17 midx: rename `get_midx_checksum()` to `midx_get_checksum_hash()`Taylor Blau, Feb 24, 2026
  85. 03/17 midx: introduce `midx_get_checksum_hex()`Taylor Blau, Feb 24, 2026
  86. 04/17 builtin/multi-pack-index.c: make '--progress' a common optionTaylor Blau, Feb 24, 2026
  87. 05/17 git-multi-pack-index(1): remove non-existent incompatibilityTaylor Blau, Feb 24, 2026
  88. 06/17 git-multi-pack-index(1): align SYNOPSIS with 'git multi-pack-index -h'Taylor Blau, Feb 24, 2026
  89. 07/17 t/t5319-multi-pack-index.sh: fix copy-and-paste error in t5319.39Taylor Blau, Feb 24, 2026
  90. 08/17 midx-write.c: don't use `pack_perm` when assigning `bitmap_pos`Taylor Blau, Feb 24, 2026
  91. 09/17 midx-write.c: introduce `struct write_midx_opts`Taylor Blau, Feb 24, 2026
  92. 10/17 midx: do not require packs to be sorted in lexicographic orderTaylor Blau, Feb 24, 2026
  93. 11/17 midx-write.c: introduce `midx_pack_perm()` helperTaylor Blau, Feb 24, 2026
  94. 13/17 midx-write.c: enumerate `pack_int_id` values directlyTaylor Blau, Feb 24, 2026
  95. 14/17 midx-write.c: factor fanout layering from `compute_sorted_entries()`Taylor Blau, Feb 24, 2026
  96. 15/17 t/helper/test-read-midx.c: plug memory leak when selecting layerTaylor Blau, Feb 24, 2026
  97. 16/17 midx: implement MIDX compactionTaylor Blau, Feb 24, 2026
  98. 17/17 midx: enable reachability bitmaps during MIDX compactionTaylor Blau, Feb 24, 2026
  99. 12/17 midx-write.c: extract `fill_pack_from_midx()`Taylor Blau, Feb 24, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.