lib/: Use the comma operator to perform lvalue conversion - #1491
Open
alejandro-colomar wants to merge 5 commits into
Open
lib/: Use the comma operator to perform lvalue conversion#1491alejandro-colomar wants to merge 5 commits into
alejandro-colomar wants to merge 5 commits into
Conversation
alejandro-colomar
marked this pull request as ready for review
January 10, 2026 23:28
alejandro-colomar
force-pushed
the
void0
branch
from
January 10, 2026 23:28
122133d to
9558736
Compare
alejandro-colomar
force-pushed
the
void0
branch
from
February 23, 2026 14:41
9558736 to
5732c14
Compare
alejandro-colomar
force-pushed
the
void0
branch
2 times, most recently
from
March 17, 2026 21:57
5a03c61 to
b7ab3f9
Compare
Compound literals are lvalues, and thus somewhat dangerous. Their address can be taken, and they can be assigned to. We were using statement expressions to perform lvalue conversion on compound literals, transforming them to rvalues, and thus removing their dangers. However, statement expressions are non-standard, and quite complex within the compiler, so it would be interesting to use simpler compiler features to achieve the same. The comma operator also performs lvalue conversion, and we can use a dummy (void)0 expression to introduce it. This is significantly simpler, and is more portable than the statement expression: it is valid all the way back to C99 (the comma operator and the (void)0 expression are portable to C89, but the compound literal is from C99). By using a simpler feature, we have a smaller risk of running into a compiler bug. Suggested-by: Martin Uecker <uecker@tugraz.at> Cc: Christopher Bazley <chris.bazley@arm.com> Cc: Kees Cook <kees@kernel.org> Cc: Richard Russon <rich@flatcap.org> Signed-off-by: Alejandro Colomar <alx@kernel.org>
This macro takes an lvalue, and performs lvalue conversion, resulting in an rvalue. Signed-off-by: Alejandro Colomar <alx@kernel.org>
This helps document why we use '(void)0' with the comma operator. Signed-off-by: Alejandro Colomar <alx@kernel.org>
This macro takes a pointer --usually, a void pointer--, and converts it to a pointer to T, implicitly. Signed-off-by: Alejandro Colomar <alx@kernel.org>
This helps document why we use compound literals. Signed-off-by: Alejandro Colomar <alx@kernel.org>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Compound literals are lvalues, and thus somewhat dangerous. Their address can be taken, and they can be assigned to.
We were using statement expressions to perform lvalue conversion on compound literals, transforming them to rvalues, and thus removing their dangers. However, statement expressions are non-standard, and quite complex within the compiler, so it would be interesting to use simpler compiler features to achieve the same.
The comma operator also performs lvalue conversion, and we can use a dummy (void)0 expression to introduce it. This is significantly simpler, and is more portable than the statement expression (it is valid all the way back to ANSI C89).
By using a simpler feature, we have a smaller risk of running into a compiler bug.
Suggested-by: @uecker
Cc: @chrisbazley
Cc: @kees
Cc: @flatcap
Revisions:
v1b
v1c
v1d
v1e
v1f
v2
v2b
v2c
v2d