Re: RFC: __attribute_alloc_size__ on allocation functions (BZ#23741)

On 11/9/18 10:36 AM, Zack Weinberg wrote:
> On Fri, Nov 9, 2018 at 10:11 AM Adhemerval Zanella
> <> wrote:
>> BZ#23741 suggests glibc adds gcc __attribute_alloc_size__ on malloc functions
>> so asking allocation larger than PTRDIFF_MAX emits a warning that the value
>> exceeds maximum object size.
> I think it makes sense to add the annotations and disallow allocations
> larger than PTRDIFF_MAX for malloc and its family, but *not* for mmap,
> brk, sbrk, and any other hypothetical system memory-allocation
> primitives (IIRC Mach has something else) because those are not
> necessarily used to allocate "objects" in the sense of the C standard,
> and we know from other cases that people don't like it when glibc's
> system call wrappers impose restrictions that the bare system call
> doesn't.

I tend to agree. I think the PTRDIFF_MAX limit for malloc only is OK.
I wonder if we can't take advantage of that and gain some bits out
of SIZE|AMP in the chunk header for other uses.


