Remix.run Logo
Why malloc always does more than I asked for?(ssenthilnathan3.github.io)
37 points by nathaah3 3 days ago | 26 comments
CodesInChaos 3 hours ago | parent | next [-]

Your bump allocator suffers from integer overflows turned into buffer overflows when the requested allocation is big enough:

  if (a->cursor + size > a->limit) return NULL; // out of memory
I'd rewrite it like this:

  if (size > a->limit - a->cursor) return NULL; // out of memory
matheusmoreira an hour ago | parent | next [-]

I used the compiler's __builtin_add_overflow in order to deal with that issue in my memory allocator. At this point I'm probably on track to replace every arithmetic operator in the entire codebase with those things.

dn3500 2 hours ago | parent | prev [-]

Your test is backwards. I would write it like this:

  if (size > a->limit - a->cursor) return NULL;
CodesInChaos 2 hours ago | parent [-]

You're right. Fixed.

phire 3 hours ago | parent | prev | next [-]

> so alloc() doesn’t just need to hand back a pointer. it needs to hand back a pointer that’s correctly aligned for whatever type the caller is about to store there.

Malloc doesn't know the required alignment (because has no idea what the type is, everything is cast through void). So all malloc implementations have a minimum alignment guarantee. Typically 16 bytes these days on x86, as that means even 128bit SSE values will end up aligned by default.

You couldn't go below the sizeof(void ) anyway, the backpointer needs to aligned too.

The padding only happens when you use memalign or aligned_malloc to specify a much larger alignment.

CodesInChaos 3 hours ago | parent [-]

There is no reason an allocation needs to contain any inline metadata. And even if it does, the allocator could choose to make it unalined, and pay the cost of an unalined access on de-allocation.

phire 3 hours ago | parent | next [-]

True.

But most C code out there assumes malloc will always return something that is at least aligned to sizeof(void *), it's very rare to see aligned_alloc. So how is your alloc allocation going to know when it can get away with a smaller alignment?

Even if you are on a cpu that doesn't fault on unaligned memory access, any malloc implementation that doesn't align by default will have serious disadvantages in any benchmarks. IMO, There is no good reason to use an unaligned backpointer.

CodesInChaos 2 hours ago | parent [-]

Yes, large allocations need to be aligned to `alignof(max_align_t)`. But small allocations could have a smaller alignment. For example a single byte allocation can actually be a single byte with no alignment, since types can't have an alignment larger than their size.

adrian_b an hour ago | parent | prev [-]

This is explained in TFA, where it is mentioned that you can replace inline metadata with a pointer to metadata (or an index), which may be unaligned, if necessary.

However, the pointer to metadata is not really necessary.

The associated metadata could be stored in a table, and the index of the metadata could be computed from the offset of the pointer returned by malloc to the start of the heap (possibly using a hash function).

The ancient versions of the Microsoft C/C++ compilers were using a malloc with inline metadata. I have no idea if they replaced this more recently.

pjmlp an hour ago | parent | prev | next [-]

Old magazines like The C/C++ Users' Journal and DDJ used to have ads for companies selling malloc()/free() replacement libraries, exactly because a single implementation isn't adequate to all scenarios.

drivebyhooting 3 hours ago | parent | prev | next [-]

Why bother with dynamic padding and a back pointer? That wastes at least 8 bytes.

You might as well always align to 8 bytes and make your header a multiple of 8.

jraph 2 hours ago | parent [-]

The back pointer could also be a 1 byte number giving the size of the padding.

lexicality 2 hours ago | parent | prev | next [-]

I'm a little confused. We start with

  [ Header ][ ...variable padding... ][ Back Pointer ][ User Memory ]
                                       ^ always exactly sizeof(void*)
                                         bytes before User Memory,
                                         no matter how much padding
                                         came before it
and then it says we don't need to align the back pointer and we end up with

  [ Header ][ Back Pointer ][ Padding ][ User Memory ]
without a clear explanation of how we now get to the back pointer if it's behind the variable alignment.
torh 2 hours ago | parent [-]

This puzzled me as well.

ncruces an hour ago | parent | prev | next [-]

I wrote this bump malloc that I use for very short lived Wasm modules: https://github.com/ncruces/wasm2go/blob/main/libc-gen/c/mall...

irenaeus 3 days ago | parent | prev | next [-]

I've read some allocator walkthroughs before but I thought that this line stood out:

"to get individual free() working, the allocator needs to remember something about every allocation it handed out. and that’s the moment metadata stops being optional."

That's just a very nice distillation of an important concept.

HexDecOctBin 4 hours ago | parent | next [-]

This becomes particularly important when the allocation and metadata cannot (or should not) be stored in the same address space. An example of this is allocating memory on GPUs.

The conventional approach for allocating memory on GPUs for games and other applications is to use a real-time allocator such as TLSF. However, it is not usually discussed that TLSF is real-time because it stores metadata in-band. It is possible to create a variant of TLSF that preserves its real-time properties while storing metadata out-of-band, but this requires careful consideration.

geocar 3 hours ago | parent | prev | next [-]

Oh? How do you think munmap does it?

If you can convince the caller to keep track of that metadata themselves you obviously don’t need to. That can be important.

Something I noticed is that _very often_ the code that is calling malloc(n) is keeping track of n somehow for its own reasons (bounds checking, grow/gap pointers, etc) so merging the value halves stack churn and it’s an easy win.

simiones 27 minutes ago | parent | next [-]

Well, even that doesn't really work, because optimized allocators typicallly don't allocate exactly the amount that you ask for, they allocate some larger chunk to help with both alignment and fragmentation.

So, most likely, there are two sizes in reality: the size of your user data that you care about; and the size of the memory chunk in which your user data resides, that free() cares about. So, unless you're willing to go for an API like this, you can't rely on the consumer:

  int* ptr_to_dest = NULL;
  size_t size = 10 * sizeof(int);
  size_t allocated = malloc(&ptr_to_dest, size);
  if (allocated <= 0 || !ptr_to_dest) {
    //handle allocation error
  }
  //... use ptr_to_dest, size
  free(ptr_to_dest, allocated); //careful not to pass size here!
xxs 2 hours ago | parent | prev | next [-]

> keep track of that metadata themselves you obviously don’t need to

likely it'd be perf. hit in most cases. They'd have to copy to the tail end (likely) of the allocated area. Or the start and offset the pointer, they'd need to know the size of the metadata and account for that, including aligning it.Hence, the tail feels 'nicer'

It's possible to manually use mmap and forgo malloc entirely, rolling your own arena manager.

byroot 3 hours ago | parent | prev [-]

That's why C23 introduce free_sized [0].

[0] https://en.cppreference.com/c/memory/free_sized

Someone 41 minutes ago | parent [-]

>> If you can convince the caller to keep track of that metadata themselves you obviously don’t need to. That can be important.

> That's why C23 introduce free_sized

Is it? C23 still has free, so there’s no guarantee callers wil use free_sized, so the allocator still has to be able to obtain a block’s size from a pointer.

Or do I overlook something?

lifthrasiir 3 hours ago | parent | prev | next [-]

In the other words, free() is a flawed API. :-)

adrian_b 29 minutes ago | parent [-]

Actually yes, the malloc/free API (inherited from the ALLOCATE and FREE statements of PL/I) is too simple.

The metadata that malloc always attaches to the allocated memory would normally be useful for the user (i.e. having access to values like the currently allocated size and the total size of the allocation).

Very frequently, the user must duplicate inside the allocated memory the same information that already exists in the metadata, wasting memory. Also time may be wasted with requests for reallocation, instead of just adjusting the currently allocated size, when this is sufficient.

With a better API, the metadata would have been visible for the user. Being hidden from the user is not a protection in a language like C, where using pointer arithmetic can trash any memory location. Being exposed as non-mutable would have been a better protection.

Moreover, a better metadata structure for malloc should have always included a reference count, to be handled automatically by the compiler, and the malloc/free functions should have been invoked only implicitly, never explicitly.

nathaah3 3 days ago | parent | prev [-]

glad you found it useful :)

iLoveOncall an hour ago | parent | prev [-]

Having to recode malloc and free from "scratch" in school was a great teaching experience and there's not a month since where I don't encounter something that I understand better thanks to that exercise.