1da0d961cSdjm /*
2d3425be1Sdjm  * Copyright (c) 2014-2020 Pavel Kalvoda <me@pavelkalvoda.com>
3da0d961cSdjm  *
4da0d961cSdjm  * libcbor is free software; you can redistribute it and/or modify
5da0d961cSdjm  * it under the terms of the MIT license. See LICENSE for details.
6da0d961cSdjm  */
7da0d961cSdjm 
8da0d961cSdjm #include "memory_utils.h"
9da0d961cSdjm #include "cbor/common.h"
10da0d961cSdjm 
119e5c2ddcSdjm // TODO: Consider builtins
129e5c2ddcSdjm // (https://gcc.gnu.org/onlinedocs/gcc/Integer-Overflow-Builtins.html)
13da0d961cSdjm 
14da0d961cSdjm /** Highest on bit position */
_cbor_highest_bit(size_t number)159e5c2ddcSdjm size_t _cbor_highest_bit(size_t number) {
16da0d961cSdjm   size_t bit = 0;
17da0d961cSdjm   while (number != 0) {
18da0d961cSdjm     bit++;
19da0d961cSdjm     number >>= 1;
20da0d961cSdjm   }
21da0d961cSdjm 
22da0d961cSdjm   return bit;
23da0d961cSdjm }
24da0d961cSdjm 
_cbor_safe_to_multiply(size_t a,size_t b)259e5c2ddcSdjm bool _cbor_safe_to_multiply(size_t a, size_t b) {
26*4dcc46c4Sdjm   if (a <= 1 || b <= 1) return true;
27da0d961cSdjm   return _cbor_highest_bit(a) + _cbor_highest_bit(b) <= sizeof(size_t) * 8;
28da0d961cSdjm }
29da0d961cSdjm 
_cbor_safe_to_add(size_t a,size_t b)30*4dcc46c4Sdjm bool _cbor_safe_to_add(size_t a, size_t b) {
31*4dcc46c4Sdjm   // Unsigned integer overflow doesn't constitute UB
32*4dcc46c4Sdjm   size_t sum = a + b;
33*4dcc46c4Sdjm   return sum >= a && sum >= b;
34*4dcc46c4Sdjm }
35*4dcc46c4Sdjm 
_cbor_safe_signaling_add(size_t a,size_t b)36*4dcc46c4Sdjm size_t _cbor_safe_signaling_add(size_t a, size_t b) {
37*4dcc46c4Sdjm   if (a == 0 || b == 0) return 0;
38*4dcc46c4Sdjm   if (_cbor_safe_to_add(a, b)) return a + b;
39*4dcc46c4Sdjm   return 0;
40*4dcc46c4Sdjm }
41*4dcc46c4Sdjm 
_cbor_alloc_multiple(size_t item_size,size_t item_count)429e5c2ddcSdjm void* _cbor_alloc_multiple(size_t item_size, size_t item_count) {
43da0d961cSdjm   if (_cbor_safe_to_multiply(item_size, item_count)) {
44*4dcc46c4Sdjm     return _cbor_malloc(item_size * item_count);
45da0d961cSdjm   } else {
46da0d961cSdjm     return NULL;
47da0d961cSdjm   }
48da0d961cSdjm }
49da0d961cSdjm 
_cbor_realloc_multiple(void * pointer,size_t item_size,size_t item_count)509e5c2ddcSdjm void* _cbor_realloc_multiple(void* pointer, size_t item_size,
519e5c2ddcSdjm                              size_t item_count) {
52da0d961cSdjm   if (_cbor_safe_to_multiply(item_size, item_count)) {
53*4dcc46c4Sdjm     return _cbor_realloc(pointer, item_size * item_count);
54da0d961cSdjm   } else {
55da0d961cSdjm     return NULL;
56da0d961cSdjm   }
57da0d961cSdjm }
58