git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2 0/7] trace2: stop allowing die()

From
Derrick Stolee via GitGitGadget <gitgitgadget@gmail.com>
Date
Aug 25, 2026, 18:56 UTC
Message-ID
<pull.2178.v2.git.1787684181.gitgitgadget@gmail.com>
In-Reply-To
<pull.2178.git.1784131932489.gitgitgadget@gmail.com>

After v1 was posted, based on a concrete example of tracing leading to a recursive die() problem, more evidence has come up to imply that allocations are failing for some users more often. This is potentially an issue with the allocator chosen by Git for Windows, which is being discussed elsewhere.

But the conclusion is this: the trace2 API shouldn't call helpers that might call die(). It's too low-level for that.

In this v2, I have a much more robust approach to removing die() from the trace2 API.

This starts with a new banned-die.h header file at the root of the repo and including it from all trace2 API *.c files. It starts empty, but the later patches will add one method at a time:

 * xsnprintf() : This is the original patch, but made more complete by
   adding the method to banned-die.h.
 * xstrdup()
 * ALLOC_ARRAY()
 * xstrfmt()
 * ALLOC_GROW()
 * xcalloc()

During each patch, the goal was to have the trace2 logic be "as correct as possible" when an allocation failure occurs. This may mean that we have incomplete messages or dropped trace messages.

The focus here is that the trace2 API should never cause a process-ending failure, because those failures will trigger trace2 API calls while reporting the failure.

Thanks, -Stolee
Derrick Stolee (7):
  banned-die: create header for banning of functions
  trace2: tolerate failed timestamp formatting
  trace2: remove use of xstrdup()
  trace2: remove use of ALLOC_ARRAY()
  trace2: remove use of xstrfmt()
  trace2: remove use of ALLOC_GROW()
  trace2: remove use of xcalloc()
 banned-die.h            | 32 +++++++++++++++++
 trace2.c                | 51 ++++++++++++++++++++++++---
 trace2/tr2_cfg.c        |  1 +
 trace2/tr2_cmd_name.c   |  1 +
 trace2/tr2_ctr.c        | 11 +++++-
 trace2/tr2_dst.c        |  1 +
 trace2/tr2_sid.c        |  1 +
 trace2/tr2_sysenv.c     |  7 ++--
 trace2/tr2_tbuf.c       | 50 +++++++++++++++++++--------
 trace2/tr2_tgt_event.c  |  1 +
 trace2/tr2_tgt_normal.c |  1 +
 trace2/tr2_tgt_perf.c   |  1 +
 trace2/tr2_tls.c        | 76 +++++++++++++++++++++++++++++++++++++++--
 trace2/tr2_tls.h        |  7 ++++
 trace2/tr2_tmr.c        | 15 ++++++--
 15 files changed, 229 insertions(+), 27 deletions(-)
 create mode 100644 banned-die.h
base-commit: e9019fcafe0040228b8631c30f97ae1adb61bcdc
Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-2178%2Fderrickstolee%2Ftrace2-dont-die-v2
Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-2178/derrickstolee/trace2-dont-die-v2
Pull-Request: https://github.com/gitgitgadget/git/pull/2178
Range-diff vs v1:
 -:  ---------- > 1:  84634717e2 banned-die: create header for banning of functions
 1:  95c546bb3b ! 2:  bd45f46a34 trace2: tolerate failed timestamp formatting
     @@ Commit message
          triggering this problem in a loop as the 'atexit' event would be
          retriggered by the die().
      
     -    I could not determine the exact cause of why these errors started
     -    occuring in a bunch. My best guess is that these users are dogfooding an
     -    early operating system version that is more likely to fail in the
     -    gettimeofday() function and thus leaves the structures uninitialized and
     -    potentially violating the expected values.
     +    Based on other symptoms impacting users on the version reporting these
     +    failures, it is most likely that this is actually a failure to allocate
     +    memory, which is a specific symptom in Git for Windows. That fork uses a
     +    different library for its implementation of vsprintf() which allocates
     +    an array when seven or more positional arguments exist in the formatting
     +    string, such as this one.
      
     -    However, for full defense-in-depth I made several modifications:
     +    Ultimately, the trace2 machinery is so low-level that it should not rely on
     +    any helper functions that perform error handling with die(), as that can
     +    trigger issues that would then be traced, causing this kind of recursive
     +    loop.
     +
     +    These changes help remove any use of die() within this file:
      
          1. Both 'tv' and 'tm' structs are initialized with zero values, allowing
             an erroring gettimeofday() or gmtime_r() method to leave them
     @@ Commit message
          but they only die() on out-of-memory errors instead of formatting
          issues. I chose to leave those in place for now.
      
     +    Helped-by: Taylor Blau <ttaylorr@openai.com>
          Signed-off-by: Derrick Stolee <stolee@gmail.com>
      
     + ## banned-die.h ##
     +@@
     + #undef die
     + #define die banned(die)
     + 
     ++#undef xsnprintf
     ++#define xsnprintf(...) BANNED(xsnprintf)
     ++
     + #endif /* BANNED_DIE_H */
     +
       ## trace2/tr2_tbuf.c ##
      @@
       
 -:  ---------- > 3:  ec447a6a77 trace2: remove use of xstrdup()
 -:  ---------- > 4:  db6858d381 trace2: remove use of ALLOC_ARRAY()
 -:  ---------- > 5:  7f0bb405ad trace2: remove use of xstrfmt()
 -:  ---------- > 6:  120cf1967b trace2: remove use of ALLOC_GROW()
 -:  ---------- > 7:  c8fc195a2a trace2: remove use of xcalloc()
-- 
gitgitgadget
Previous: Junio C HamanoNext: Derrick Stolee via GitGitGadget
Message 9 of 43 in “trace2: tolerate failed timestamp formatting”
  1. trace2: tolerate failed timestamp formattingDerrick Stolee via GitGitGadget, Jul 15, 2026
  2. Taylor BlauJul 17, 2026
  3. Derrick StoleeJul 18, 2026
  4. Junio C HamanoJul 20, 2026
  5. Taylor BlauJul 20, 2026
  6. Junio C HamanoJul 29, 2026
  7. Derrick StoleeJul 31, 2026
  8. Junio C HamanoJul 31, 2026
  9. 0/7 trace2: stop allowing die()Derrick Stolee via GitGitGadget, Aug 25, 2026
  10. 1/7 banned-die: create header for banning of functionsDerrick Stolee via GitGitGadget, Aug 25, 2026
  11. Junio C HamanoAug 25, 2026
  12. Derrick StoleeAug 31, 2026
  13. Patrick SteinhardtAug 31, 2026
  14. Elijah NewrenAug 25, 2026
  15. Derrick StoleeAug 31, 2026
  16. Jeff KingAug 27, 2026
  17. Derrick StoleeAug 31, 2026
  18. 2/7 trace2: tolerate failed timestamp formattingDerrick Stolee via GitGitGadget, Aug 25, 2026
  19. 3/7 trace2: remove use of xstrdup()Derrick Stolee via GitGitGadget, Aug 25, 2026
  20. Elijah NewrenAug 25, 2026
  21. Derrick StoleeAug 31, 2026
  22. 4/7 trace2: remove use of ALLOC_ARRAY()Derrick Stolee via GitGitGadget, Aug 25, 2026
  23. 5/7 trace2: remove use of xstrfmt()Derrick Stolee via GitGitGadget, Aug 25, 2026
  24. Elijah NewrenAug 25, 2026
  25. Junio C HamanoAug 25, 2026
  26. Derrick StoleeAug 31, 2026
  27. 6/7 trace2: remove use of ALLOC_GROW()Derrick Stolee via GitGitGadget, Aug 25, 2026
  28. Elijah NewrenAug 25, 2026
  29. 7/7 trace2: remove use of xcalloc()Derrick Stolee via GitGitGadget, Aug 25, 2026
  30. Jeff KingAug 27, 2026
  31. Derrick StoleeAug 31, 2026
  32. Jeff KingSep 1, 2026
  33. Jeff KingSep 1, 2026
  34. Derrick StoleeSep 1, 2026
  35. 0/7 trace2: stop allowing die()Derrick Stolee via GitGitGadget, Aug 31, 2026
  36. 1/7 banned-die: create header for banning of functionsDerrick Stolee via GitGitGadget, Aug 31, 2026
  37. 2/7 trace2: tolerate failed timestamp formattingDerrick Stolee via GitGitGadget, Aug 31, 2026
  38. 3/7 trace2: remove use of xstrdup()Derrick Stolee via GitGitGadget, Aug 31, 2026
  39. 4/7 trace2: remove use of ALLOC_ARRAY()Derrick Stolee via GitGitGadget, Aug 31, 2026
  40. 5/7 trace2: remove use of xstrfmt()Derrick Stolee via GitGitGadget, Aug 31, 2026
  41. 6/7 trace2: remove use of ALLOC_GROW()Derrick Stolee via GitGitGadget, Aug 31, 2026
  42. 7/7 trace2: remove use of xcalloc()Derrick Stolee via GitGitGadget, Aug 31, 2026
  43. Derrick StoleeOct 6, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.