git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 1/6] strbuf: add header for 'safe' API

From
Junio C Hamano <gitster@pobox.com>
Date
Sep 21, 2026, 21:18 UTC
Message-ID
<xmqq4ifimhfr.fsf@gitster.g>
In-Reply-To
<b1779709120adc9c1df40c7210481d6bed9791c5.1789736540.git.gitgitgadget@gmail.com>
"Derrick Stolee via GitGitGadget" <gitgitgadget@gmail.com> writes:
Show 12 quoted lines
> +/*
> + * NOTE FOR STRBUF DEVELOPERS
> + *
> + * strbuf is a low-level primitive; as such it should interact only
> + * with other low-level primitives. Do not introduce new functions
> + * which interact with higher-level APIs.
> + *
> + * This header file specifically conatins the "safe" API surface for
> + * working with strbufs. The implementations of these methods avoid
> + * using die() and other exits. Thus, these methods are appropriate
> + * for use within lower-level APIs such as trace2.
> + */

I have to wonder if this is somewhat backwards, in that the longer term goal for us should be to make most of the service routines like strbuf, string_list, csum_file, etc., free of die() and be "safe".

A recent trend under the label "libification" is to make the use of the_repository more explicit and pass a "struct repository *" as a parameter instead more widely throughout the code flow, but it would be equally if not more useful change to expand the "safe" API surface so that callers of more service routines take responsibility to act on errors.

And picking strbuf as the first instance of such generic service library certainly is a good idea. Its interface is well defined.

We may want to rename functions that _happen_ to use a strbuf to return their results but otherwise has nothing to do with strbuf away from strbuf_ prefix (strbuf_realpath() etc. in abspath.h are prime examples) as part of this first step, though.

Previous: Derrick Stolee via GitGitGadgetNext: Mark C. Chu-Carroll
Message 3 of 17 in “[RFC] Create a 'safe' strbuf API”
  1. 0/6 [RFC] Create a 'safe' strbuf APIDerrick Stolee via GitGitGadget, Sep 18, 2026
  2. 1/6 strbuf: add header for 'safe' APIDerrick Stolee via GitGitGadget, Sep 18, 2026
  3. Junio C HamanoSep 21, 2026
  4. Mark C. Chu-CarrollSep 23, 2026
  5. Junio C HamanoSep 23, 2026
  6. 2/6 wrapper: initialize GIT_ALLOC_LIMIT proactivelyDerrick Stolee via GitGitGadget, Sep 18, 2026
  7. 3/6 wrapper: create safe_memory_limit_check()Derrick Stolee via GitGitGadget, Sep 18, 2026
  8. Junio C HamanoSep 21, 2026
  9. 4/6 strbuf-safe: add sstrbuf_grow()Derrick Stolee via GitGitGadget, Sep 18, 2026
  10. Junio C HamanoSep 21, 2026
  11. 5/6 json-writer: include strbuf-safe.hDerrick Stolee via GitGitGadget, Sep 18, 2026
  12. 6/6 strbuf-safe: add init and release methodsDerrick Stolee via GitGitGadget, Sep 18, 2026
  13. Junio C HamanoSep 21, 2026
  14. Junio C HamanoSep 21, 2026
  15. Phillip WoodSep 19, 2026
  16. Jeff KingSep 23, 2026
  17. Derrick StoleeOct 6, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.