Repository navigation
Reset string array size when allocation fails in init (backport #593) - #594
Merged
Merged
Conversation
Signed-off-by: leoca <[email protected]> (cherry picked from commit bf78574)
ahcorde
approved these changes
Sep 15, 2026
Contributor
|
Pulls: #594 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
rcutils_string_array_init()writes the requested size into the array before it tries to allocate:When the allocation fails, the function returns
RCUTILS_RET_BAD_ALLOCbut leavessizeset to the requested count whiledatastaysNULL. The array then advertises entries that cannot be read. A caller that checks the return value is fine, but one that inspects the array afterwards — or passes it to code that iterates0..size— walks a null pointer.This PR sets
sizeback to0on that error path, so a failed init leaves the array exactly asrcutils_get_zero_initialized_string_array()would.Fixes # (no issue filed; found while reading the allocation failure paths)
Is this user-facing behavior change?
Only on the failure path. On success nothing changes. After a failed
rcutils_string_array_init()the array is now consistently empty (data == NULL,size == 0) instead of reporting a non-zero size with no backing storage, andrcutils_string_array_fini()on it returnsRCUTILS_RET_OK.Did you use Generative AI?
Yes. Claude Opus 5, through Claude Code, found the inconsistent error path, wrote the one-line change in
src/string_array.c, wrote theinit_alloc_failure_leaves_array_emptytest intest/test_string_array.cpp, and drafted this description. The build and test verification below was run afterwards and is reported exactly as the container printed it.Additional Information
Verification. My earlier note said I had no ROS 2 workspace on this machine. That is now done, in the official
ros:rolling-ros-baseimage with the test dependencies (osrf_testing_tools_cpp,performance_test_fixture) installed byrosdep. Environment: Ubuntu 26.04.1, ROS 2 Rolling, gcc 15.2.0, cmake 4.2.3. Base:a4cba34onrolling.With this change applied,
colcon build --packages-select rcutilssucceeds and the test file passes:Then I reverted only
src/string_array.c, keeping the new test, rebuilt, and it fails on currentrolling:The array reports three entries after an allocation that never happened. The other four tests in the file pass on both sides.
This is an automatic backport of pull request #593 done by [Mergify](https://mergify.com).