reftable/basics: ban standard allocator functions

The reftable library uses pluggable allocators, which means that we shouldn't ever use the standard allocator functions. But it is an easy mistake to make to accidentally use e.g. free(3P) instead of the reftable-specific `reftable_free()` function, and we do not have any mechanism to detect this misuse right now. Introduce a couple of macros that ban the standard allocators, similar to how we do it in "banned.h". Note that we do not ban the following two classes of functions: - Macros like `FREE_AND_NULL()` or `REALLOC_ARRAY()`. As those expand to code that contains already-banned functions we'd get a compiler error even without banning those macros explicitly. - Git-specific allocators like `xmalloc()` and friends. The primary reason is that there are simply too many of them, so we're rather aiming for best effort here. Furthermore, the eventual goal is to make them unavailable in the reftable library place by not pulling them in via "git-compat-utils.h" anymore. Signed-off-by: Patrick Steinhardt <ps@pks.im> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Patrick Steinhardt committed Oct 2, 2024 at 12:56 UTC 35730302e995337766805299fa1128c1b9d8988c
2 files changed +15
reftable/basics.c
+1
@@ -6,6 +6,7 @@ license that can be found in the LICENSE file or at
6 https://developers.google.com/open-source/licenses/bsd
7 */
8
9 +#define REFTABLE_ALLOW_BANNED_ALLOCATORS
10 #include "basics.h"
11 #include "reftable-basics.h"
12
reftable/basics.h
+14
@@ -73,6 +73,20 @@ char *reftable_strdup(const char *str);
73 } while (0)
74 #define REFTABLE_FREE_AND_NULL(p) do { reftable_free(p); (p) = NULL; } while (0)
75
76 +#ifndef REFTABLE_ALLOW_BANNED_ALLOCATORS
77 +# define REFTABLE_BANNED(func) use_reftable_##func##_instead
78 +# undef malloc
79 +# define malloc(sz) REFTABLE_BANNED(malloc)
80 +# undef realloc
81 +# define realloc(ptr, sz) REFTABLE_BANNED(realloc)
82 +# undef free
83 +# define free(ptr) REFTABLE_BANNED(free)
84 +# undef calloc
85 +# define calloc(nelem, elsize) REFTABLE_BANNED(calloc)
86 +# undef strdup
87 +# define strdup(str) REFTABLE_BANNED(strdup)
88 +#endif
89 +
90 /* Find the longest shared prefix size of `a` and `b` */
91 struct strbuf;
92 int common_prefix_size(struct strbuf *a, struct strbuf *b);