Skip to content

lib/alloc/: mallocarray(): Define as a macro - #1708

Draft
alejandro-colomar wants to merge 6 commits into
shadow-maint:masterfrom
alejandro-colomar:mallocarray
Draft

lib/alloc/: mallocarray(): Define as a macro#1708
alejandro-colomar wants to merge 6 commits into
shadow-maint:masterfrom
alejandro-colomar:mallocarray

Conversation

@alejandro-colomar

@alejandro-colomar alejandro-colomar commented Jul 31, 2026

Copy link
Copy Markdown
Collaborator

Compound literals are lvalues, and thus somewhat dangerous.  Their
address can be taken, and they can be assigned to.

We were using statement expressions to perform lvalue conversion
on compound literals, transforming them to rvalues, and thus removing
their dangers.  However, statement expressions are non-standard, and
quite complex within the compiler, so it would be interesting to use
simpler compiler features to achieve the same.

The comma operator also performs lvalue conversion, and we can use
a dummy (void)0 expression to introduce it.  This is significantly
simpler, and is more portable than the statement expression: it is valid
all the way back to C99 (the comma operator and the (void)0 expression
are portable to C89, but the compound literal is from C99).

By using a simpler feature, we have a smaller risk of running into
a compiler bug.

Suggested-by: Martin Uecker <uecker@tugraz.at>
Cc: Christopher Bazley <chris.bazley@arm.com>
Cc: Kees Cook <kees@kernel.org>
Cc: Richard Russon <rich@flatcap.org>
Signed-off-by: Alejandro Colomar <alx@kernel.org>
This macro takes an lvalue, and performs lvalue conversion, resulting in
an rvalue.

Signed-off-by: Alejandro Colomar <alx@kernel.org>
This helps document why we use '(void)0' with the comma operator.

Signed-off-by: Alejandro Colomar <alx@kernel.org>
@alejandro-colomar alejandro-colomar self-assigned this Jul 31, 2026
@alejandro-colomar
alejandro-colomar marked this pull request as draft August 8, 2026 11:28
@alejandro-colomar
alejandro-colomar force-pushed the mallocarray branch 2 times, most recently from 6b81624 to ca6bb08 Compare August 8, 2026 11:49
This macro takes a pointer --usually, a void pointer--, and converts it
to a pointer to T, implicitly.

Signed-off-by: Alejandro Colomar <alx@kernel.org>
This helps document why we use compound literals.

Signed-off-by: Alejandro Colomar <alx@kernel.org>
It's much simpler.

Signed-off-by: Alejandro Colomar <alx@kernel.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant