git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2] Make xmalloc and xrealloc thread-safe

From
Nicolas Pitre <nico@fluxnic.net>
Date
Apr 7, 2010, 02:57 UTC
Message-ID
<alpine.LFD.2.00.1004062152260.7232@xanadu.home>
In-Reply-To
<4c8ef71003270626y45685e69j28ccb8a8738b9083@mail.gmail.com>

By providing a hook for the routine responsible for trying to free some memory on malloc failure, we can ensure that the called routine is protected by the appropriate locks when threads are in play.

The obvious offender here was pack-objects which was calling xmalloc() within threads while release_pack_memory() is not thread safe.

To avoid a deadlock if try_to_free_from_threads() is called while read_lock is already locked within the same thread (may happen through the read_sha1_file() path), a simple mutex ownership is added. This could have been handled automatically with the PTHREAD_MUTEX_RECURSIVE type but the Windows pthread emulation would get much more complex.

Signed-off-by: Nicolas Pitre <nico@fluxnic.net>
---
On Sat, 27 Mar 2010, Fredrik Kuivinen wrote:
Show 11 quoted lines
> > +static void try_to_free_from_threads(size_t size)
> > +{
> > +       read_lock();
> > +       release_pack_memory(size, -1);
> > +       read_unlock();
> > +}
> > +
> 
> Will this really work in all cases? In the find_deltas -> try_delta ->
> read_sha1_file -> ... -> xmalloc call path, the mutex is already
> locked when we get to xmalloc.
So here's a fixed version.
diff --git a/builtin/pack-objects.c b/builtin/pack-objects.c
index 9780258..d3ac41f 100644
--- a/builtin/pack-objects.c
+++ b/builtin/pack-objects.c
@@ -1211,8 +1211,17 @@ static int delta_cacheable(unsigned long src_size, unsigned long trg_size,
 #ifndef NO_PTHREADS
 
 static pthread_mutex_t read_mutex;
-#define read_lock()		pthread_mutex_lock(&read_mutex)
-#define read_unlock()		pthread_mutex_unlock(&read_mutex)
+static pthread_t read_mutex_owner;
+#define read_lock() \
+	do { \
+		pthread_mutex_lock(&read_mutex); \
+		read_mutex_owner = pthread_self(); \
+	} while (0)
+#define read_unlock() \
+	do { \
+		memset(&read_mutex_owner, 0, sizeof(read_mutex_owner)); \
+		pthread_mutex_unlock(&read_mutex); \
+	} while (0)
 
 static pthread_mutex_t cache_mutex;
 #define cache_lock()		pthread_mutex_lock(&cache_mutex)
@@ -1522,6 +1531,16 @@ static void find_deltas(struct object_entry **list, unsigned *list_size,
 
 #ifndef NO_PTHREADS
 
+static void try_to_free_from_threads(size_t size)
+{
+	int self = pthread_equal(read_mutex_owner, pthread_self());
+	if (!self)
+		read_lock();
+	release_pack_memory(size, -1);
+	if (!self)
+		read_unlock();
+}
+
 /*
  * The main thread waits on the condition that (at least) one of the workers
  * has stopped working (which is indicated in the .working member of
@@ -1556,10 +1575,12 @@ static void init_threaded_search(void)
 	pthread_mutex_init(&cache_mutex, NULL);
 	pthread_mutex_init(&progress_mutex, NULL);
 	pthread_cond_init(&progress_cond, NULL);
+	set_try_to_free_routine(try_to_free_from_threads);
 }
 
 static void cleanup_threaded_search(void)
 {
+	set_try_to_free_routine(NULL);
 	pthread_cond_destroy(&progress_cond);
 	pthread_mutex_destroy(&read_mutex);
 	pthread_mutex_destroy(&cache_mutex);
diff --git a/git-compat-util.h b/git-compat-util.h
index b56c297..4ee8f86 100644
--- a/git-compat-util.h
+++ b/git-compat-util.h
@@ -357,6 +357,8 @@ static inline void *gitmempcpy(void *dest, const void *src, size_t n)
 
 extern void release_pack_memory(size_t, int);
 
+extern void set_try_to_free_routine(void (*routine)(size_t));
+
 extern char *xstrdup(const char *str);
 extern void *xmalloc(size_t size);
 extern void *xmallocz(size_t size);
diff --git a/wrapper.c b/wrapper.c
index 10a6750..58201b6 100644
--- a/wrapper.c
+++ b/wrapper.c
@@ -3,11 +3,23 @@
  */
 #include "cache.h"
 
+static void try_to_free_builtin(size_t size)
+{
+	release_pack_memory(size, -1);
+}
+
+static void (*try_to_free_routine)(size_t size) = try_to_free_builtin;
+
+void set_try_to_free_routine(void (*routine)(size_t))
+{
+	try_to_free_routine = (routine) ? routine : try_to_free_builtin;
+}
+
 char *xstrdup(const char *str)
 {
 	char *ret = strdup(str);
 	if (!ret) {
-		release_pack_memory(strlen(str) + 1, -1);
+		try_to_free_routine(strlen(str) + 1);
 		ret = strdup(str);
 		if (!ret)
 			die("Out of memory, strdup failed");
@@ -21,7 +33,7 @@ void *xmalloc(size_t size)
 	if (!ret && !size)
 		ret = malloc(1);
 	if (!ret) {
-		release_pack_memory(size, -1);
+		try_to_free_routine(size);
 		ret = malloc(size);
 		if (!ret && !size)
 			ret = malloc(1);
@@ -67,7 +79,7 @@ void *xrealloc(void *ptr, size_t size)
 	if (!ret && !size)
 		ret = realloc(ptr, 1);
 	if (!ret) {
-		release_pack_memory(size, -1);
+		try_to_free_routine(size);
 		ret = realloc(ptr, size);
 		if (!ret && !size)
 			ret = realloc(ptr, 1);
@@ -83,7 +95,7 @@ void *xcalloc(size_t nmemb, size_t size)
 	if (!ret && (!nmemb || !size))
 		ret = calloc(1, 1);
 	if (!ret) {
-		release_pack_memory(nmemb * size, -1);
+		try_to_free_routine(nmemb * size);
 		ret = calloc(nmemb, size);
 		if (!ret && (!nmemb || !size))
 			ret = calloc(1, 1);
Previous: Fredrik KuivinenNext: Shawn O. Pearce
Message 19 of 39 in “Make xmalloc and xrealloc thread-safe”
  1. 1/2 Make xmalloc and xrealloc thread-safeFredrik Kuivinen, Mar 23, 2010
  2. Shawn O. PearceMar 23, 2010
  3. Fredrik KuivinenMar 23, 2010
  4. Nicolas PitreMar 23, 2010
  5. Fredrik KuivinenMar 24, 2010
  6. Nicolas PitreMar 24, 2010
  7. Shawn PearceMar 24, 2010
  8. Junio C HamanoMar 24, 2010
  9. Nicolas PitreMar 24, 2010
  10. Shawn PearceMar 24, 2010
  11. Make xmalloc and xrealloc thread-safeNicolas Pitre, Mar 24, 2010
  12. Shawn O. PearceMar 24, 2010
  13. Nicolas PitreMar 24, 2010
  14. Junio C HamanoMar 24, 2010
  15. Junio C HamanoMar 24, 2010
  16. Fredrik KuivinenMar 27, 2010
  17. Nicolas PitreMar 27, 2010
  18. Fredrik KuivinenMar 31, 2010
  19. Make xmalloc and xrealloc thread-safeNicolas Pitre, Apr 7, 2010
  20. Shawn O. PearceApr 7, 2010
  21. Nicolas PitreApr 7, 2010
  22. Shawn PearceApr 7, 2010
  23. Nicolas PitreApr 7, 2010
  24. Shawn PearceApr 7, 2010
  25. Nicolas PitreApr 7, 2010
  26. Fredrik KuivinenApr 7, 2010
  27. Nicolas PitreApr 7, 2010
  28. Fredrik KuivinenApr 7, 2010
  29. Erik Faye-LundApr 7, 2010
  30. Nicolas PitreApr 7, 2010
  31. Sverre RabbelierApr 7, 2010
  32. Fredrik KuivinenApr 7, 2010
  33. Junio C HamanoApr 7, 2010
  34. Johannes SixtApr 7, 2010
  35. Thread-safe xmalloc and xrealloc needs a recursive mutexJohannes Sixt, Apr 8, 2010
  36. Fredrik KuivinenApr 8, 2010
  37. Junio C HamanoApr 7, 2010
  38. 2/2 Make sha1_to_hex thread-safeFredrik Kuivinen, Mar 23, 2010
  39. Johannes SixtMar 23, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.