Re: Add returns_nonnull to infallible allocators

From: "Tristan Partin" <tristan(at)partin(dot)io>
To: "Peter Eisentraut" <peter(at)eisentraut(dot)org>
Cc: "pgsql-hackers" <pgsql-hackers(at)lists(dot)postgresql(dot)org>
Subject: Re: Add returns_nonnull to infallible allocators
Date: 2026-10-07 05:43:42
Message-ID: DLYD82FLQE7A.1SL6ZJDNM5Y7@partin.io
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

On Wed Oct 7, 2026 at 5:15 AM UTC, Tristan Partin wrote:
> On Tue Sep 29, 2026 at 6:49 AM UTC, Peter Eisentraut wrote:
>> On 06.07.26 20:11, Tristan Partin wrote:
>>> On Mon Jul 6, 2026 at 6:10 PM UTC, Tristan Partin wrote:
>>>> Postgres memory allocators, by default, ERROR out on memory allocation
>>>> failures. An ERROR leads to a longjmp, which means that the caller of
>>>> the allocator will never see a NULL return value. We can explicitly let
>>>> the compiler know about this behavior by adding the returns_nonnull
>>>> attribute to the allocators that follow this behavior. Postgres does
>>>> support _extended versions of some of the allocators that take a flaks
>>>> argument. The caller can provide the MCXT_ALLOC_NO_OOM flag to these
>>>> allocators to request that they return NULL on allocation failure
>>>> instead of ERROR-ing out. The _extended allocators cannot be marked as
>>>> returns_nonnull because of that.
>>>>
>>>> By using returns_nonnull, we can help the compiler to optimize call
>>>> sites.
>>
>> Your patch marks palloc_mul_extended() as pg_attribute_returns_nonnull,
>> which seems incorrect per the above description.
>
> Oops. Sorry about that. I must've not sent the most up to date version
> of the patch because I definitely didn't have that locally.
>
>> Also, per the discussion in the counted_by thread, lets put these new
>> attributes in their more correct position in front of the declaration.
>> (Note that several of these already use pg_nodiscard, which is also an
>> attribute.) That way we can also use the MSVC annotation _Ret_notnull_.
>
> Good points. See the revised attached patch. You definitely have a knack
> for knowing MSVC attributes. I'll have to try to keep those in mind.

Here is a v3 that adds missing annotations for the following functions
in palloc.h:

- repalloc
- repalloc0
- repalloc_mul
- repalloc_huge

And for fe_memutils.h:

- pg_malloc
- pg_malloc0
- pg_malloc_mul
- pg_malloc0_mul
- palloc
- palloc0
- palloc_mul
- palloc0_mul

--
Tristan Partin
PostgreSQL Contributors Team
AWS (https://aws.amazon.com)

Attachment Content-Type Size
v3-0001-Add-pg_attribute_returns_nonnull-to-various-memor.patch text/x-patch 9.1 KB

In response to

Browse pgsql-hackers by date

  From Date Subject
Next Message Richard Guo 2026-10-07 05:46:28 Re: ERROR: unsupported join alias expression
Previous Message Tristan Partin 2026-10-07 05:14:46 Re: Add returns_nonnull to infallible allocators