git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v3 01/10] doc: define unambiguous type mappings across C and Rust

From
Ezekiel Newren via GitGitGadget <gitgitgadget@gmail.com>
Date
Nov 11, 2025, 19:42 UTC
Message-ID
<e5d084d340e874be52e7c3b056ada15ab5557877.1762890152.git.gitgitgadget@gmail.com>
In-Reply-To
<pull.2070.v3.git.git.1762890152.gitgitgadget@gmail.com>
From: Ezekiel Newren <ezekielnewren@gmail.com>

Document other nuances with crossing the FFI boundary. Other language mappings may be added in the future.

Signed-off-by: Ezekiel Newren <ezekielnewren@gmail.com>
---
 Documentation/Makefile                        |   1 +
 Documentation/technical/meson.build           |   1 +
 .../technical/unambiguous-types.adoc          | 239 ++++++++++++++++++
 3 files changed, 241 insertions(+)
 create mode 100644 Documentation/technical/unambiguous-types.adoc
diff --git a/Documentation/Makefile b/Documentation/Makefile
index 04e9e10b27..bc1adb2d9d 100644
--- a/Documentation/Makefile
+++ b/Documentation/Makefile
@@ -142,6 +142,7 @@ TECH_DOCS += technical/shallow
 TECH_DOCS += technical/sparse-checkout
 TECH_DOCS += technical/sparse-index
 TECH_DOCS += technical/trivial-merge
+TECH_DOCS += technical/unambiguous-types
 TECH_DOCS += technical/unit-tests
 SP_ARTICLES += $(TECH_DOCS)
 SP_ARTICLES += technical/api-index
diff --git a/Documentation/technical/meson.build b/Documentation/technical/meson.build
index be698ef22a..89a6e26821 100644
--- a/Documentation/technical/meson.build
+++ b/Documentation/technical/meson.build
@@ -32,6 +32,7 @@ articles = [
   'sparse-checkout.adoc',
   'sparse-index.adoc',
   'trivial-merge.adoc',
+  'unambiguous-types.adoc',
   'unit-tests.adoc',
 ]
 
diff --git a/Documentation/technical/unambiguous-types.adoc b/Documentation/technical/unambiguous-types.adoc
new file mode 100644
index 0000000000..6bca39209b
--- /dev/null
+++ b/Documentation/technical/unambiguous-types.adoc
@@ -0,0 +1,239 @@
+= Unambiguous types
+
+Most of these mappings are obvious, but there are some nuances and gotchas with
+Rust FFI (Foreign Function Interface).
+
+This document defines clear, one-to-one mappings between primitive types in C,
+Rust (and possible other languages in the future). Its purpose is to eliminate
+ambiguity in type widths, signedness, and binary representation across
+platforms and languages.
+
+For Git, the only header required to use these unambiguous types in C is
+`git-compat-util.h`.
+
+== Boolean types
+[cols="1,1", options="header"]
+|===
+| C Type | Rust Type
+| bool^1^       | bool
+|===
+
+== Integer types
+
+In C, `<stdint.h>` (or an equivalent) must be included.
+
+[cols="1,1", options="header"]
+|===
+| C Type | Rust Type
+| uint8_t    | u8
+| uint16_t   | u16
+| uint32_t   | u32
+| uint64_t   | u64
+
+| int8_t     | i8
+| int16_t    | i16
+| int32_t    | i32
+| int64_t    | i64
+|===
+
+== Floating-point types
+
+Rust requires IEEE-754 semantics.
+In C, that is typically true, but not guaranteed by the standard.
+
+[cols="1,1", options="header"]
+|===
+| C Type | Rust Type
+| float^2^      | f32
+| double^2^     | f64
+|===
+
+== Size types
+
+These types represent pointer-sized integers and are typically defined in
+`<stddef.h>` or an equivalent header.
+
+Size types should be used any time pointer arithmetic is performed e.g.
+indexing an array, describing the number of elements in memory, etc...
+
+[cols="1,1", options="header"]
+|===
+| C Type | Rust Type
+| size_t^3^     | usize
+| ptrdiff_t^3^  | isize
+|===
+
+== Character types
+
+This is where C and Rust don't have a clean one-to-one mapping.
+
+C comparison problem: While the sign of `char` is implementation defined, it's
+also signless (neither signed nor unsigned). When building with
+`make DEVELOPER=1` it will complain about a "differ in signedness" when `char`
+is compared with `uint8_t` or `int8_t`.
+
+Rust's `char` type is an unsigned 32-bit integer that is used to describe
+Unicode code points. Even though a C `char` is the same width as `u8`, `char`
+should be converted to u8 where it is describing bytes in memory. If a C
+`char` is not describing bytes, then it should be converted to a more accurate
+unambiguous type. The reason for mentioning Unicode here is because of how &str
+is defined in Rust and how to create a &str from &[u8]. Rust assumes that &str
+is a correctly encoded utf-8 string, i.e. text in memory. Where as a C `char`
+makes no assumption about the bytes that it is representing.
+
+```
+let raw_bytes = b"abc\n";
+let result = std::str::from_utf8(raw_bytes);
+if let Ok(line) = result {
+    // do something with text
+}
+```
+
+While you could specify `char` in the C code and `u8` in Rust code, it's not as
+clear what the appropriate type is, but it would work across the FFI boundary.
+However, the bigger problem comes from code generation tools like cbindgen and
+bindgen. When cbindgen sees u8 in Rust it will generate uint8_t on the C side
+which will cause differ in signedness warnings/errors. Similarly if bindgen
+sees `char` on the C side it will generate `std::ffi::c_char` which has its own
+problems.
+
+=== Notes
+^1^ This is only true if stdbool.h (or equivalent) is used. +
+^2^ C does not enforce IEEE-754 compatibility, but Rust expects it. If the
+platform/arch for C does not follow IEEE-754 then this equivalence does not
+hold. Also, it's assumed that `float` is 32 bits and `double` is 64, but
+there may be a strange platform/arch where even this isn't true. +
+^3^ C also defines uintptr_t, ssize_t and intptr_t, but these types are
+discouraged for FFI purposes. For functions like `read()` and `write()` ssize_t
+should be cast to a different, and unambiguous, type before being passed over
+the FFI boundary. +
+
+== Problems with std::ffi::c_* types in Rust
+TL;DR: In practice, Rust's `c_*` types aren't guaranteed to match C types for
+all possible C compilers, platforms, or architectures, because Rust only
+ensures correctness of C types on officially supported targets. These
+definitions have changed over time to match more targets which means that the
+c_* definitions will differ based on which Rust version Git chooses to use.
+
+Current list of safe, Rust side, FFI types in Git: +
+
+* `c_void`
+* `CStr`
+* `CString`
+
+Even then, they should be used sparingly, and only where the semantics match
+exactly.
+
+The std::os::raw::c_* directly inherits the problems of core::ffi, which
+changes over time and seems to make a best guess at the correct definition for
+a given platform/target. This probably isn't a problem for all other platforms
+that Rust supports currently, but can anyone say that Rust got it right for all
+C compilers of all platforms/targets?
+
+To give an example: c_long is defined in
+footnote:[https://doc.rust-lang.org/1.63.0/src/core/ffi/mod.rs.html#175-189[c_long in 1.63.0]]
+footnote:[https://doc.rust-lang.org/1.89.0/src/core/ffi/primitives.rs.html#135-151[c_long in 1.89.0]]
+
+=== Rust version 1.63.0
+
+```
+mod c_long_definition {
+    cfg_if! {
+        if #[cfg(all(target_pointer_width = "64", not(windows)))] {
+            pub type c_long = i64;
+            pub type NonZero_c_long = crate::num::NonZeroI64;
+            pub type c_ulong = u64;
+            pub type NonZero_c_ulong = crate::num::NonZeroU64;
+        } else {
+            // The minimal size of `long` in the C standard is 32 bits
+            pub type c_long = i32;
+            pub type NonZero_c_long = crate::num::NonZeroI32;
+            pub type c_ulong = u32;
+            pub type NonZero_c_ulong = crate::num::NonZeroU32;
+        }
+    }
+}
+```
+
+=== Rust version 1.89.0
+
+```
+mod c_long_definition {
+    crate::cfg_select! {
+        any(
+            all(target_pointer_width = "64", not(windows)),
+            // wasm32 Linux ABI uses 64-bit long
+            all(target_arch = "wasm32", target_os = "linux")
+        ) => {
+            pub(super) type c_long = i64;
+            pub(super) type c_ulong = u64;
+        }
+        _ => {
+            // The minimal size of `long` in the C standard is 32 bits
+            pub(super) type c_long = i32;
+            pub(super) type c_ulong = u32;
+        }
+    }
+}
+```
+
+Even for the cases where C types are correctly mapped to Rust types via
+std::ffi::c_* there are still problems. Let's take c_char for example. On some
+platforms it's u8 on others it's i8.
+
+=== Subtraction underflow in debug mode
+
+The following code will panic in debug on platforms that define c_char as u8,
+but won't if it's an i8.
+
+```
+let mut x: std::ffi::c_char = 0;
+x -= 1;
+```
+
+=== Inconsistent shift behavior
+
+`x` will be 0xC0 for platforms that use i8, but will be 0x40 where it's u8.
+
+```
+let mut x: std::ffi::c_char = 0x80;
+x >>= 1;
+```
+
+=== Equality fails to compile on some platforms
+
+The following will not compile on platforms that define c_char as i8, but will
+if it's u8. You can cast x e.g. `assert_eq!(x as u8, b'a');`, but then you get
+a warning on platforms that use u8 and a clean compilation where i8 is used.
+
+```
+let mut x: std::ffi::c_char = 0x61;
+assert_eq!(x, b'a');
+```
+
+== Enum types
+Rust enum types should not be used as FFI types. Rust enum types are more like
+C union types than C enum's. For something like:
+
+```
+#[repr(C, u8)]
+enum Fruit {
+    Apple,
+    Banana,
+    Cherry,
+}
+```
+
+It's easy enough to make sure the Rust enum matches what C would expect, but a
+more complex type like.
+
+```
+enum HashResult {
+    SHA1([u8; 20]),
+    SHA256([u8; 32]),
+}
+```
+
+The Rust compiler has to add a discriminant to the enum to distinguish between
+the variants. The width, location, and values for that discriminant is up to
+the Rust compiler and is not ABI stable.
-- 
gitgitgadget
Previous: Ezekiel Newren via GitGitGadgetNext: Junio C Hamano
Message 62 of 118 in “Xdiff cleanup part2”
  1. 0/9 Xdiff cleanup part2Ezekiel Newren via GitGitGadget, Oct 15, 2025
  2. 1/9 xdiff: use ssize_t for dstart/dend, make them last in xdfile_tEzekiel Newren via GitGitGadget, Oct 15, 2025
  3. Phillip WoodOct 21, 2025
  4. Junio C HamanoOct 21, 2025
  5. Ezekiel NewrenOct 22, 2025
  6. Junio C HamanoOct 22, 2025
  7. Ezekiel NewrenOct 22, 2025
  8. 2/9 xdiff: make xrecord_t.ptr a uint8_t instead of charEzekiel Newren via GitGitGadget, Oct 15, 2025
  9. Kristoffer HaugsbakkOct 16, 2025
  10. Patrick SteinhardtOct 21, 2025
  11. Ezekiel NewrenOct 22, 2025
  12. Phillip WoodOct 21, 2025
  13. Junio C HamanoOct 21, 2025
  14. Phillip WoodOct 22, 2025
  15. Ezekiel NewrenOct 22, 2025
  16. 3/9 xdiff: use size_t for xrecord_t.sizeEzekiel Newren via GitGitGadget, Oct 15, 2025
  17. 4/9 xdiff: use unambiguous types in xdl_hash_record()Ezekiel Newren via GitGitGadget, Oct 15, 2025
  18. Patrick SteinhardtOct 21, 2025
  19. Ezekiel NewrenOct 22, 2025
  20. Patrick SteinhardtOct 23, 2025
  21. 5/9 xdiff: split xrecord_t.ha into line_hash and minimal_perfect_hashEzekiel Newren via GitGitGadget, Oct 15, 2025
  22. Ezekiel NewrenOct 20, 2025
  23. Junio C HamanoOct 21, 2025
  24. Patrick SteinhardtOct 21, 2025
  25. Phillip WoodOct 21, 2025
  26. Chris TorekOct 21, 2025
  27. Ezekiel NewrenOct 22, 2025
  28. 6/9 xdiff: make xdfile_t.nrec a size_t instead of longEzekiel Newren via GitGitGadget, Oct 15, 2025
  29. 7/9 xdiff: make xdfile_t.nreff a size_t instead of longEzekiel Newren via GitGitGadget, Oct 15, 2025
  30. 8/9 xdiff: change rindex from long to size_t in xdfile_tEzekiel Newren via GitGitGadget, Oct 15, 2025
  31. Patrick SteinhardtOct 21, 2025
  32. Ezekiel NewrenOct 22, 2025
  33. Patrick SteinhardtOct 23, 2025
  34. 9/9 xdiff: rename rindex -> reference_indexEzekiel Newren via GitGitGadget, Oct 15, 2025
  35. Junio C HamanoOct 15, 2025
  36. Phillip WoodOct 21, 2025
  37. Junio C HamanoOct 21, 2025
  38. 00/10 Xdiff cleanup part2Ezekiel Newren via GitGitGadget, Oct 29, 2025
  39. 01/10 doc: define unambiguous type mappings across C and RustEzekiel Newren via GitGitGadget, Oct 29, 2025
  40. Phillip WoodNov 6, 2025
  41. Ezekiel NewrenNov 6, 2025
  42. Phillip WoodNov 9, 2025
  43. 02/10 xdiff: use ssize_t for dstart/dend, make them last in xdfile_tEzekiel Newren via GitGitGadget, Oct 29, 2025
  44. Phillip WoodNov 6, 2025
  45. Ezekiel NewrenNov 6, 2025
  46. 03/10 xdiff: make xrecord_t.ptr a uint8_t instead of charEzekiel Newren via GitGitGadget, Oct 29, 2025
  47. Phillip WoodNov 6, 2025
  48. Ezekiel NewrenNov 6, 2025
  49. Phillip WoodNov 6, 2025
  50. Ezekiel NewrenNov 6, 2025
  51. 04/10 xdiff: use size_t for xrecord_t.sizeEzekiel Newren via GitGitGadget, Oct 29, 2025
  52. 05/10 xdiff: use unambiguous types in xdl_hash_record()Ezekiel Newren via GitGitGadget, Oct 29, 2025
  53. 06/10 xdiff: split xrecord_t.ha into line_hash and minimal_perfect_hashEzekiel Newren via GitGitGadget, Oct 29, 2025
  54. Phillip WoodNov 6, 2025
  55. Ezekiel NewrenNov 6, 2025
  56. 07/10 xdiff: make xdfile_t.nrec a size_t instead of longEzekiel Newren via GitGitGadget, Oct 29, 2025
  57. 08/10 xdiff: make xdfile_t.nreff a size_t instead of longEzekiel Newren via GitGitGadget, Oct 29, 2025
  58. 09/10 xdiff: change rindex from long to size_t in xdfile_tEzekiel Newren via GitGitGadget, Oct 29, 2025
  59. 10/10 xdiff: rename rindex -> reference_indexEzekiel Newren via GitGitGadget, Oct 29, 2025
  60. Junio C HamanoOct 30, 2025
  61. 00/10 Xdiff cleanup part2Ezekiel Newren via GitGitGadget, Nov 11, 2025
  62. 01/10 doc: define unambiguous type mappings across C and RustEzekiel Newren via GitGitGadget, Nov 11, 2025
  63. Junio C HamanoNov 11, 2025
  64. Junio C HamanoNov 11, 2025
  65. 02/10 xdiff: use ptrdiff_t for dstart/dendEzekiel Newren via GitGitGadget, Nov 11, 2025
  66. Junio C HamanoNov 11, 2025
  67. 03/10 xdiff: make xrecord_t.ptr a uint8_t instead of charEzekiel Newren via GitGitGadget, Nov 11, 2025
  68. Junio C HamanoNov 11, 2025
  69. 04/10 xdiff: use size_t for xrecord_t.sizeEzekiel Newren via GitGitGadget, Nov 11, 2025
  70. Junio C HamanoNov 11, 2025
  71. Ezekiel NewrenNov 14, 2025
  72. Junio C HamanoNov 14, 2025
  73. 05/10 xdiff: use unambiguous types in xdl_hash_record()Ezekiel Newren via GitGitGadget, Nov 11, 2025
  74. 06/10 xdiff: split xrecord_t.ha into line_hash and minimal_perfect_hashEzekiel Newren via GitGitGadget, Nov 11, 2025
  75. Junio C HamanoNov 11, 2025
  76. Ezekiel NewrenNov 14, 2025
  77. Junio C HamanoNov 14, 2025
  78. 07/10 xdiff: make xdfile_t.nrec a size_t instead of longEzekiel Newren via GitGitGadget, Nov 11, 2025
  79. 08/10 xdiff: make xdfile_t.nreff a size_t instead of longEzekiel Newren via GitGitGadget, Nov 11, 2025
  80. 09/10 xdiff: change rindex from long to size_t in xdfile_tEzekiel Newren via GitGitGadget, Nov 11, 2025
  81. 10/10 xdiff: rename rindex -> reference_indexEzekiel Newren via GitGitGadget, Nov 11, 2025
  82. Junio C HamanoNov 11, 2025
  83. Ezekiel NewrenNov 14, 2025
  84. 00/10 Xdiff cleanup part2Ezekiel Newren via GitGitGadget, Nov 14, 2025
  85. 01/10 doc: define unambiguous type mappings across C and RustEzekiel Newren via GitGitGadget, Nov 14, 2025
  86. Ramsay JonesNov 15, 2025
  87. Ben KnobleNov 15, 2025
  88. Ramsay JonesNov 15, 2025
  89. Junio C HamanoNov 15, 2025
  90. D. Ben KnobleNov 15, 2025
  91. Junio C HamanoNov 15, 2025
  92. Junio C HamanoNov 17, 2025
  93. Ramsay JonesNov 17, 2025
  94. 02/10 xdiff: use ptrdiff_t for dstart/dendEzekiel Newren via GitGitGadget, Nov 14, 2025
  95. 03/10 xdiff: make xrecord_t.ptr a uint8_t instead of charEzekiel Newren via GitGitGadget, Nov 14, 2025
  96. Junio C HamanoNov 15, 2025
  97. Ezekiel NewrenNov 18, 2025
  98. 04/10 xdiff: use size_t for xrecord_t.sizeEzekiel Newren via GitGitGadget, Nov 14, 2025
  99. 05/10 xdiff: use unambiguous types in xdl_hash_record()Ezekiel Newren via GitGitGadget, Nov 14, 2025
  100. 06/10 xdiff: split xrecord_t.ha into line_hash and minimal_perfect_hashEzekiel Newren via GitGitGadget, Nov 14, 2025
  101. 07/10 xdiff: make xdfile_t.nrec a size_t instead of longEzekiel Newren via GitGitGadget, Nov 14, 2025
  102. 08/10 xdiff: make xdfile_t.nreff a size_t instead of longEzekiel Newren via GitGitGadget, Nov 14, 2025
  103. 09/10 xdiff: change rindex from long to size_t in xdfile_tEzekiel Newren via GitGitGadget, Nov 14, 2025
  104. 10/10 xdiff: rename rindex -> reference_indexEzekiel Newren via GitGitGadget, Nov 14, 2025
  105. 00/10 Xdiff cleanup part2Ezekiel Newren via GitGitGadget, Nov 18, 2025
  106. 01/10 doc: define unambiguous type mappings across C and RustEzekiel Newren via GitGitGadget, Nov 18, 2025
  107. Ramsay JonesNov 18, 2025
  108. Junio C HamanoNov 19, 2025
  109. 02/10 xdiff: use ptrdiff_t for dstart/dendEzekiel Newren via GitGitGadget, Nov 18, 2025
  110. 03/10 xdiff: make xrecord_t.ptr a uint8_t instead of charEzekiel Newren via GitGitGadget, Nov 18, 2025
  111. 04/10 xdiff: use size_t for xrecord_t.sizeEzekiel Newren via GitGitGadget, Nov 18, 2025
  112. 05/10 xdiff: use unambiguous types in xdl_hash_record()Ezekiel Newren via GitGitGadget, Nov 18, 2025
  113. 06/10 xdiff: split xrecord_t.ha into line_hash and minimal_perfect_hashEzekiel Newren via GitGitGadget, Nov 18, 2025
  114. 07/10 xdiff: make xdfile_t.nrec a size_t instead of longEzekiel Newren via GitGitGadget, Nov 18, 2025
  115. 08/10 xdiff: make xdfile_t.nreff a size_t instead of longEzekiel Newren via GitGitGadget, Nov 18, 2025
  116. 09/10 xdiff: change rindex from long to size_t in xdfile_tEzekiel Newren via GitGitGadget, Nov 18, 2025
  117. 10/10 xdiff: rename rindex -> reference_indexEzekiel Newren via GitGitGadget, Nov 18, 2025
  118. Junio C HamanoNov 18, 2025

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.