reftable/basics: handle allocation failures in `reftable_calloc()`

Handle allocation failures in `reftable_calloc()`. While at it, remove our use of `st_mult()` that would cause us to die on an overflow. From the caller's point of view there is not much of a difference between arguments that are too large to be multiplied and a request that is too big to handle by the allocator: in both cases the allocation cannot be fulfilled. And in neither of these cases do we want the reftable library to die. While we could use `unsigned_mult_overflows()` to handle the overflow gracefully, we instead open-code it to further our goal of converting the reftable codebase to become a standalone library that can be reused by external projects. Signed-off-by: Patrick Steinhardt <ps@pks.im> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Patrick Steinhardt committed Oct 2, 2024 at 12:55 UTC 6593e147d3992eb52cb53b6f8a09dc3e10f79613
1 file changed +10 -3
reftable/basics.c
+10 -3
@@ -37,9 +37,16 @@ void reftable_free(void *p)
37
38 void *reftable_calloc(size_t nelem, size_t elsize)
39 {
40 - size_t sz = st_mult(nelem, elsize);
41 - void *p = reftable_malloc(sz);
42 - memset(p, 0, sz);
40 + void *p;
41 +
42 + if (nelem && elsize > SIZE_MAX / nelem)
43 + return NULL;
44 +
45 + p = reftable_malloc(nelem * elsize);
46 + if (!p)
47 + return NULL;
48 +
49 + memset(p, 0, nelem * elsize);
50 return p;
51 }
52