and not get segmentation fault later (applies only to debug code).
Reality treatment for comments.
SCCS-vsn: lib/libc/stdlib/malloc.c 5.5
-static char sccsid[] = "@(#)malloc.c 5.4 (Berkeley) %G%";
+static char sccsid[] = "@(#)malloc.c 5.5 (Berkeley) %G%";
* This is a very fast storage allocator. It allocates blocks of a small
* number of different sizes, and keeps free lists of each size. Blocks that
* don't exactly fit are passed up to the next larger size. In this
* This is a very fast storage allocator. It allocates blocks of a small
* number of different sizes, and keeps free lists of each size. Blocks that
* don't exactly fit are passed up to the next larger size. In this
- * implementation, the available sizes are 2^n-4 (or 2^n-12) bytes long.
- * This is designed for use in a program that uses vast quantities of memory,
- * but bombs when it runs out.
+ * implementation, the available sizes are 2^n-4 (or 2^n-10) bytes long.
+ * This is designed for use in a virtual memory environment.
*/
#include <sys/types.h>
*/
#include <sys/types.h>
* contains a pointer to the next free block, and the bottom two bits must
* be zero. When in use, the first byte is set to MAGIC, and the second
* byte is the size index. The remaining bytes are for alignment.
* contains a pointer to the next free block, and the bottom two bits must
* be zero. When in use, the first byte is set to MAGIC, and the second
* byte is the size index. The remaining bytes are for alignment.
- * If range checking is enabled and the size of the block fits
- * in two bytes, then the top two bytes hold the size of the requested block
- * plus the range checking words, and the header word MINUS ONE.
+ * If range checking is enabled then a second word holds the size of the
+ * requested block, less 1, rounded up to a multiple of sizeof(RMAGIC).
+ * The order of elements is critical: ov_magic must overlay the low order
+ * bits of ov_next, and ov_magic can not be a valid ov_next bit pattern.
*/
union overhead {
union overhead *ov_next; /* when free */
struct {
*/
union overhead {
union overhead *ov_next; /* when free */
struct {
-#ifndef RCHECK
- u_char ovu_magic; /* magic number */
- u_char ovu_index; /* bucket # */
-#else
- u_int ovu_size; /* actual block size */
u_char ovu_magic; /* magic number */
u_char ovu_index; /* bucket # */
u_char ovu_magic; /* magic number */
u_char ovu_index; /* bucket # */
u_short ovu_rmagic; /* range magic number */
u_short ovu_rmagic; /* range magic number */
+ u_int ovu_size; /* actual block size */
#endif
} ovu;
#define ov_magic ovu.ovu_magic
#endif
} ovu;
#define ov_magic ovu.ovu_magic
* 2^30 bytes on a VAX, I think) or for a negative arg.
*/
sz = 1 << (bucket + 3);
* 2^30 bytes on a VAX, I think) or for a negative arg.
*/
sz = 1 << (bucket + 3);
+#ifdef DEBUG
+ ASSERT(sz > 0);
+#else
if (sz < pagesz) {
amt = pagesz;
nblks = amt / sz;
if (sz < pagesz) {
amt = pagesz;
nblks = amt / sz;
#endif
size = op->ov_index;
ASSERT(size < NBUCKETS);
#endif
size = op->ov_index;
ASSERT(size < NBUCKETS);
- op->ov_next = nextf[size];
+ op->ov_next = nextf[size]; /* also clobbers ov_magic */
nextf[size] = op;
#ifdef MSTATS
nmalloc[size]--;
nextf[size] = op;
#ifdef MSTATS
nmalloc[size]--;