SAFE_ARRAY_SIZE() would return the size if there were no overflow and -1 on errors? We can't return zero on errors because there are a lot of places which do zero size allocations and it's valid. It seems ugly. I really think that's over thinking things. Let's just match kcalloc() exactly except without zeroing. The BUILD_BUG_ON() thing is an over complication as well. We haven't needed it for kcalloc(). The only impossible bit is picking the right name. regards, dan carpenter