3 ms·
If needed, you should zero memory on allocation succeeds, instead of zeroing it after it is freed.
by tapirl 2y ago
If needed, you should zero memory on allocation succeeds, instead of zeroing it after it is freed.
- alexchamberlain 2y agoGenerally, you 0 on free in secure environments to avoid leaking secrets from 1 section of knowledge to the next. ie a request may contain a password, which the next request should not have access to.
- tapirl 2y agoGood reason. But I think it is not the responsibility of memory allocators to do the zero work. It is what the application code should do.
- alexchamberlain 2y agoDepends where you draw the line. An arena allocator per request needs to be managed at least by an app framework, if not the application. It's all layers of abstraction, and one of those layers needs to 0 memory.
- tapirl 2y agoThe arena allocator implementation for general uses absolutely should not do the zero work. This is specific use case, which can be implemented in an app-specific custom allocator.
- alexchamberlain 2y agoThat's not what I said. My point was that an arena allocator has to be managed at a relatively high level. Similarly, an allocator responsible for 0 on free would be managed at a similar level. They are orthogonal concepts as you say, but there's no reason 0 on free can't be managed by an allocator.