1da0d961cSdjm /*
2d3425be1Sdjm * Copyright (c) 2014-2020 Pavel Kalvoda <me@pavelkalvoda.com>
3da0d961cSdjm *
4da0d961cSdjm * libcbor is free software; you can redistribute it and/or modify
5da0d961cSdjm * it under the terms of the MIT license. See LICENSE for details.
6da0d961cSdjm */
7da0d961cSdjm
8da0d961cSdjm #include "memory_utils.h"
9da0d961cSdjm #include "cbor/common.h"
10da0d961cSdjm
119e5c2ddcSdjm // TODO: Consider builtins
129e5c2ddcSdjm // (https://gcc.gnu.org/onlinedocs/gcc/Integer-Overflow-Builtins.html)
13da0d961cSdjm
14da0d961cSdjm /** Highest on bit position */
_cbor_highest_bit(size_t number)159e5c2ddcSdjm size_t _cbor_highest_bit(size_t number) {
16da0d961cSdjm size_t bit = 0;
17da0d961cSdjm while (number != 0) {
18da0d961cSdjm bit++;
19da0d961cSdjm number >>= 1;
20da0d961cSdjm }
21da0d961cSdjm
22da0d961cSdjm return bit;
23da0d961cSdjm }
24da0d961cSdjm
_cbor_safe_to_multiply(size_t a,size_t b)259e5c2ddcSdjm bool _cbor_safe_to_multiply(size_t a, size_t b) {
26*4dcc46c4Sdjm if (a <= 1 || b <= 1) return true;
27da0d961cSdjm return _cbor_highest_bit(a) + _cbor_highest_bit(b) <= sizeof(size_t) * 8;
28da0d961cSdjm }
29da0d961cSdjm
_cbor_safe_to_add(size_t a,size_t b)30*4dcc46c4Sdjm bool _cbor_safe_to_add(size_t a, size_t b) {
31*4dcc46c4Sdjm // Unsigned integer overflow doesn't constitute UB
32*4dcc46c4Sdjm size_t sum = a + b;
33*4dcc46c4Sdjm return sum >= a && sum >= b;
34*4dcc46c4Sdjm }
35*4dcc46c4Sdjm
_cbor_safe_signaling_add(size_t a,size_t b)36*4dcc46c4Sdjm size_t _cbor_safe_signaling_add(size_t a, size_t b) {
37*4dcc46c4Sdjm if (a == 0 || b == 0) return 0;
38*4dcc46c4Sdjm if (_cbor_safe_to_add(a, b)) return a + b;
39*4dcc46c4Sdjm return 0;
40*4dcc46c4Sdjm }
41*4dcc46c4Sdjm
_cbor_alloc_multiple(size_t item_size,size_t item_count)429e5c2ddcSdjm void* _cbor_alloc_multiple(size_t item_size, size_t item_count) {
43da0d961cSdjm if (_cbor_safe_to_multiply(item_size, item_count)) {
44*4dcc46c4Sdjm return _cbor_malloc(item_size * item_count);
45da0d961cSdjm } else {
46da0d961cSdjm return NULL;
47da0d961cSdjm }
48da0d961cSdjm }
49da0d961cSdjm
_cbor_realloc_multiple(void * pointer,size_t item_size,size_t item_count)509e5c2ddcSdjm void* _cbor_realloc_multiple(void* pointer, size_t item_size,
519e5c2ddcSdjm size_t item_count) {
52da0d961cSdjm if (_cbor_safe_to_multiply(item_size, item_count)) {
53*4dcc46c4Sdjm return _cbor_realloc(pointer, item_size * item_count);
54da0d961cSdjm } else {
55da0d961cSdjm return NULL;
56da0d961cSdjm }
57da0d961cSdjm }
58