On Fri, Jun 23, 2023 at 04:09:46PM -0600, Jeffrey Hugo wrote: > Kees, would you please chime in and educate me here? I feel like I'm > missing something important here. The array_size() family will saturate at SIZE_MAX (rather than potentially wrapping around). No allocator can fulfil a 18446744073709551615 byte (18 exabyte) allocation. :) So the NULL return value will (hopefully) trigger an error path. -- Kees Cook