refactor(protocol): guard session release, clarify Data.owner contract
Add a NULL guard to protocol_release_memory_for_session so it no-ops like the sibling session setters. Correct the Data.owner doc comment, which implied a non-zero protocol_charge always has an owner; document that owner may be NULL for uncharged/ownerless Data, that any such charge falls back to the bound session, and that a charged Data must not outlive its owning session. Note the lifetime contract on the release API too. Extend tests/test_protocol.c to cover destroying a charged Data with no session bound (the other half of the original bug) and to assert that data_create/data_create_reserve start with owner == NULL and protocol_charge == 0.
This commit is contained in:
@@ -41,6 +41,8 @@ static bool protocol_reserve_memory(ProtocolSession* session, size_t charge) {
|
||||
}
|
||||
|
||||
void protocol_release_memory_for_session(ProtocolSession* session, size_t charge) {
|
||||
if (!session)
|
||||
return;
|
||||
unsigned long long allocated = atomic_load(&session->total_allocated_bytes);
|
||||
while (true) {
|
||||
unsigned long long remaining = (unsigned long long)charge >= allocated ? 0 : allocated - charge;
|
||||
|
||||
Reference in New Issue
Block a user