diff options
author | Thomas Haller <thaller@redhat.com> | 2023-10-24 11:57:09 +0200 |
---|---|---|
committer | Pablo Neira Ayuso <pablo@netfilter.org> | 2023-11-09 12:40:59 +0100 |
commit | ffd6b4790a728bd879cc8e4532b54150febb58fa (patch) | |
tree | 2f59962fd5bc4387cbef794374aef29764a83d3e /include/nft.h | |
parent | d3b5b4b88c4d34bb0325fde0a6bf0a918ebfe55a (diff) |
src: add free_const() and use it instead of xfree()
Almost everywhere xmalloc() and friends is used instead of malloc().
This is almost everywhere paired with xfree().
xfree() has two problems. First, it brings the wrong notion that
xmalloc() should be paired with xfree(), as if xmalloc() would not use
the plain malloc() allocator. In practices, xfree() just wraps free(),
and it wouldn't make sense any other way. xfree() should go away. This
will be addressed in the next commit.
The problem addressed by this commit is that xfree() accepts a const
pointer. Paired with the practice of almost always using xfree() instead
of free(), all our calls to xfree() cast away constness of the pointer,
regardless whether that is necessary. Declaring a pointer as const
should help us to catch wrong uses. If the xfree() function always casts
aways const, the compiler doesn't help.
There are many places that rightly cast away const during free. But not
all of them. Add a free_const() macro, which is like free(), but accepts
const pointers. We should always make an intentional choice whether to
use free() or free_const(). Having a free_const() macro makes this very
common choice clearer, instead of adding a (void*) cast at many places.
Note that we now pair xmalloc() allocations with a free() call (instead
of xfree(). That inconsistency will be resolved in the next commit.
Signed-off-by: Thomas Haller <thaller@redhat.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'include/nft.h')
-rw-r--r-- | include/nft.h | 6 |
1 files changed, 6 insertions, 0 deletions
diff --git a/include/nft.h b/include/nft.h index 3c894e5b..a2d62dbf 100644 --- a/include/nft.h +++ b/include/nft.h @@ -9,4 +9,10 @@ #include <stdlib.h> #include <string.h> +/* Just free(), but casts to a (void*). This is for places where + * we have a const pointer that we know we want to free. We could just + * do the (void*) cast, but free_const() makes it clear that this is + * something we frequently need to do and it's intentional. */ +#define free_const(ptr) free((void *)(ptr)) + #endif /* NFTABLES_NFT_H */ |