From d646a0efe7a8fa703977ff7e1124030da348220c Mon Sep 17 00:00:00 2001
From: Tristan Partin <tristan@partin.io>
Date: Wed, 7 Oct 2026 05:01:11 +0000
Subject: [PATCH v2] Add pg_attribute_returns_nonnull to various memory
 allocation functions

This function attribute tells the compiler that the function will never
return NULL. This allows the compiler to do better static analysis and
lets it optimize the caller given the non-NULL guarantee.

The attribute is placed in front of the declaration, rather than after
it, so that it can also expand to the MSVC annotation _Ret_notnull_,
which is only valid in that position.

Signed-off-by: Tristan Partin <tristan@partin.io>
---
 src/include/c.h                  | 13 +++++++++++++
 src/include/common/fe_memutils.h | 14 +++++++-------
 src/include/utils/palloc.h       | 24 ++++++++++++------------
 3 files changed, 32 insertions(+), 19 deletions(-)

diff --git a/src/include/c.h b/src/include/c.h
index 95e71d7e612..fd4a923500d 100644
--- a/src/include/c.h
+++ b/src/include/c.h
@@ -304,6 +304,19 @@ extern "C++"
 #define pg_attribute_nonnull(...)
 #endif
 
+/*
+ * pg_attribute_returns_nonnull means the function never returns NULL.  It
+ * must be placed in front of the declaration, which is where the MSVC
+ * annotation _Ret_notnull_ requires it to be.
+ */
+#if __has_attribute (returns_nonnull)
+#define pg_attribute_returns_nonnull __attribute__((returns_nonnull))
+#elif defined(_MSC_VER)
+#define pg_attribute_returns_nonnull _Ret_notnull_
+#else
+#define pg_attribute_returns_nonnull
+#endif
+
 /*
  * pg_attribute_target allows specifying different target options that the
  * function should be compiled with (e.g., for using special CPU instructions).
diff --git a/src/include/common/fe_memutils.h b/src/include/common/fe_memutils.h
index d5c6d37bb66..33a64ce20eb 100644
--- a/src/include/common/fe_memutils.h
+++ b/src/include/common/fe_memutils.h
@@ -34,11 +34,11 @@
  * "Safe" memory allocation functions --- these exit(1) on failure
  * (except pg_malloc_extended with MCXT_ALLOC_NO_OOM)
  */
-extern char *pg_strdup(const char *in);
+pg_attribute_returns_nonnull extern char *pg_strdup(const char *in);
 extern void *pg_malloc(size_t size);
 extern void *pg_malloc0(size_t size);
 extern void *pg_malloc_extended(size_t size, int flags);
-extern void *pg_realloc(void *ptr, size_t size);
+pg_attribute_returns_nonnull extern void *pg_realloc(void *ptr, size_t size);
 extern void pg_free(void *ptr);
 
 /*
@@ -49,7 +49,7 @@ extern Size mul_size(Size s1, Size s2);
 extern void *pg_malloc_mul(Size s1, Size s2);
 extern void *pg_malloc0_mul(Size s1, Size s2);
 extern void *pg_malloc_mul_extended(Size s1, Size s2, int flags);
-extern void *pg_realloc_mul(void *p, Size s1, Size s2);
+pg_attribute_returns_nonnull extern void *pg_realloc_mul(void *p, Size s1, Size s2);
 
 /*
  * Variants with easier notation and more type safety
@@ -75,17 +75,17 @@ extern void *pg_realloc_mul(void *p, Size s1, Size s2);
 #define pg_realloc_array(pointer, type, count) ((type *) pg_realloc_mul(pointer, sizeof(type), count))
 
 /* Equivalent functions, deliberately named the same as backend functions */
-extern char *pstrdup(const char *in);
-extern char *pnstrdup(const char *in, Size size);
+pg_attribute_returns_nonnull extern char *pstrdup(const char *in);
+pg_attribute_returns_nonnull extern char *pnstrdup(const char *in, Size size);
 extern void *palloc(Size size);
 extern void *palloc0(Size size);
 extern void *palloc_extended(Size size, int flags);
-extern void *repalloc(void *pointer, Size size);
+pg_attribute_returns_nonnull extern void *repalloc(void *pointer, Size size);
 extern void pfree(void *pointer);
 extern void *palloc_mul(Size s1, Size s2);
 extern void *palloc0_mul(Size s1, Size s2);
 extern void *palloc_mul_extended(Size s1, Size s2, int flags);
-extern void *repalloc_mul(void *p, Size s1, Size s2);
+pg_attribute_returns_nonnull extern void *repalloc_mul(void *p, Size s1, Size s2);
 
 #define palloc_object(type) ((type *) palloc(sizeof(type)))
 #define palloc0_object(type) ((type *) palloc0(sizeof(type)))
diff --git a/src/include/utils/palloc.h b/src/include/utils/palloc.h
index 0e934158b60..8436850c87e 100644
--- a/src/include/utils/palloc.h
+++ b/src/include/utils/palloc.h
@@ -68,15 +68,15 @@ extern PGDLLIMPORT MemoryContext CurrentMemoryContext;
 /*
  * Fundamental memory-allocation operations (more are in utils/memutils.h)
  */
-extern void *MemoryContextAlloc(MemoryContext context, Size size);
-extern void *MemoryContextAllocZero(MemoryContext context, Size size);
+pg_attribute_returns_nonnull extern void *MemoryContextAlloc(MemoryContext context, Size size);
+pg_attribute_returns_nonnull extern void *MemoryContextAllocZero(MemoryContext context, Size size);
 extern void *MemoryContextAllocExtended(MemoryContext context,
 										Size size, int flags);
 extern void *MemoryContextAllocAligned(MemoryContext context,
 									   Size size, Size alignto, int flags);
 
-extern void *palloc(Size size);
-extern void *palloc0(Size size);
+pg_attribute_returns_nonnull extern void *palloc(Size size);
+pg_attribute_returns_nonnull extern void *palloc0(Size size);
 extern void *palloc_extended(Size size, int flags);
 extern void *palloc_aligned(Size size, Size alignto, int flags);
 pg_nodiscard extern void *repalloc(void *pointer, Size size);
@@ -90,8 +90,8 @@ extern void pfree(void *pointer);
  */
 extern Size add_size(Size s1, Size s2);
 extern Size mul_size(Size s1, Size s2);
-extern void *palloc_mul(Size s1, Size s2);
-extern void *palloc0_mul(Size s1, Size s2);
+pg_attribute_returns_nonnull extern void *palloc_mul(Size s1, Size s2);
+pg_attribute_returns_nonnull extern void *palloc0_mul(Size s1, Size s2);
 extern void *palloc_mul_extended(Size s1, Size s2, int flags);
 pg_nodiscard extern void *repalloc_mul(void *p, Size s1, Size s2);
 pg_nodiscard extern void *repalloc_mul_extended(void *p, Size s1, Size s2,
@@ -123,7 +123,7 @@ pg_nodiscard extern void *repalloc_mul_extended(void *p, Size s1, Size s2,
 #define repalloc_array_extended(pointer, type, count, flags) ((type *) repalloc_mul_extended(pointer, sizeof(type), count, flags))
 
 /* Higher-limit allocators. */
-extern void *MemoryContextAllocHuge(MemoryContext context, Size size);
+pg_attribute_returns_nonnull extern void *MemoryContextAllocHuge(MemoryContext context, Size size);
 pg_nodiscard extern void *repalloc_huge(void *pointer, Size size);
 
 /*
@@ -154,14 +154,14 @@ extern void MemoryContextUnregisterResetCallback(MemoryContext context,
  * These are like standard strdup() except the copied string is
  * allocated in a context, not with malloc().
  */
-extern char *MemoryContextStrdup(MemoryContext context, const char *string);
-extern char *pstrdup(const char *in);
-extern char *pnstrdup(const char *in, Size len);
+pg_attribute_returns_nonnull extern char *MemoryContextStrdup(MemoryContext context, const char *string);
+pg_attribute_returns_nonnull extern char *pstrdup(const char *in);
+pg_attribute_returns_nonnull extern char *pnstrdup(const char *in, Size len);
 
-extern char *pchomp(const char *in);
+pg_attribute_returns_nonnull extern char *pchomp(const char *in);
 
 /* sprintf into a palloc'd buffer --- these are in psprintf.c */
-extern char *psprintf(const char *fmt, ...) pg_attribute_printf(1, 2);
+pg_attribute_returns_nonnull extern char *psprintf(const char *fmt, ...) pg_attribute_printf(1, 2);
 extern size_t pvsnprintf(char *buf, size_t len, const char *fmt, va_list args) pg_attribute_printf(3, 0);
 
 #endif							/* PALLOC_H */
-- 
Tristan Partin
https://tristan.partin.io

