| 1 | /* Safe automatic memory allocation. | 
|---|
| 2 | Copyright (C) 2003, 2006-2007, 2009-2022 Free Software Foundation, Inc. | 
|---|
| 3 | Written by Bruno Haible <bruno@clisp.org>, 2003, 2018. | 
|---|
| 4 |  | 
|---|
| 5 | This file is free software: you can redistribute it and/or modify | 
|---|
| 6 | it under the terms of the GNU Lesser General Public License as | 
|---|
| 7 | published by the Free Software Foundation; either version 2.1 of the | 
|---|
| 8 | License, or (at your option) any later version. | 
|---|
| 9 |  | 
|---|
| 10 | This file is distributed in the hope that it will be useful, | 
|---|
| 11 | but WITHOUT ANY WARRANTY; without even the implied warranty of | 
|---|
| 12 | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the | 
|---|
| 13 | GNU Lesser General Public License for more details. | 
|---|
| 14 |  | 
|---|
| 15 | You should have received a copy of the GNU Lesser General Public License | 
|---|
| 16 | along with this program.  If not, see <https://www.gnu.org/licenses/>.  */ | 
|---|
| 17 |  | 
|---|
| 18 | #define _GL_USE_STDLIB_ALLOC 1 | 
|---|
| 19 | #include <config.h> | 
|---|
| 20 |  | 
|---|
| 21 | /* Specification.  */ | 
|---|
| 22 | #include "malloca.h" | 
|---|
| 23 |  | 
|---|
| 24 | #include <stdckdint.h> | 
|---|
| 25 |  | 
|---|
| 26 | #include "idx.h" | 
|---|
| 27 |  | 
|---|
| 28 | /* The speed critical point in this file is freea() applied to an alloca() | 
|---|
| 29 | result: it must be fast, to match the speed of alloca().  The speed of | 
|---|
| 30 | mmalloca() and freea() in the other case are not critical, because they | 
|---|
| 31 | are only invoked for big memory sizes. | 
|---|
| 32 | Here we use a bit in the address as an indicator, an idea by OndÅej BÃlka. | 
|---|
| 33 | malloca() can return three types of pointers: | 
|---|
| 34 | - Pointers â¡ 0 mod 2*sa_alignment_max come from stack allocation. | 
|---|
| 35 | - Pointers â¡ sa_alignment_max mod 2*sa_alignment_max come from heap | 
|---|
| 36 | allocation. | 
|---|
| 37 | - NULL comes from a failed heap allocation.  */ | 
|---|
| 38 |  | 
|---|
| 39 | /* Type for holding very small pointer differences.  */ | 
|---|
| 40 | typedef unsigned char small_t; | 
|---|
| 41 | /* Verify that it is wide enough.  */ | 
|---|
| 42 | static_assert (2 * sa_alignment_max - 1 <= (small_t) -1); | 
|---|
| 43 |  | 
|---|
| 44 | void * | 
|---|
| 45 | mmalloca (size_t n) | 
|---|
| 46 | { | 
|---|
| 47 | #if HAVE_ALLOCA | 
|---|
| 48 | /* Allocate one more word, used to determine the address to pass to freea(), | 
|---|
| 49 | and room for the alignment â¡ sa_alignment_max mod 2*sa_alignment_max.  */ | 
|---|
| 50 | uintptr_t alignment2_mask = 2 * sa_alignment_max - 1; | 
|---|
| 51 | int plus = sizeof (small_t) + alignment2_mask; | 
|---|
| 52 | idx_t nplus; | 
|---|
| 53 | if (!ckd_add (&nplus, n, plus) && !xalloc_oversized (nplus, 1)) | 
|---|
| 54 | { | 
|---|
| 55 | char *mem = (char *) malloc (nplus); | 
|---|
| 56 |  | 
|---|
| 57 | if (mem != NULL) | 
|---|
| 58 | { | 
|---|
| 59 | uintptr_t umem = (uintptr_t)mem, umemplus; | 
|---|
| 60 | /* The ckd_add avoids signed integer overflow on | 
|---|
| 61 | theoretical platforms where UINTPTR_MAX <= INT_MAX.  */ | 
|---|
| 62 | ckd_add (&umemplus, umem, sizeof (small_t) + sa_alignment_max - 1); | 
|---|
| 63 | idx_t offset = ((umemplus & ~alignment2_mask) | 
|---|
| 64 | + sa_alignment_max - umem); | 
|---|
| 65 | void *vp = mem + offset; | 
|---|
| 66 | small_t *p = vp; | 
|---|
| 67 | /* Here p >= mem + sizeof (small_t), | 
|---|
| 68 | and p <= mem + sizeof (small_t) + 2 * sa_alignment_max - 1 | 
|---|
| 69 | hence p + n <= mem + nplus. | 
|---|
| 70 | So, the memory range [p, p+n) lies in the allocated memory range | 
|---|
| 71 | [mem, mem + nplus).  */ | 
|---|
| 72 | p[-1] = offset; | 
|---|
| 73 | /* p â¡ sa_alignment_max mod 2*sa_alignment_max.  */ | 
|---|
| 74 | return p; | 
|---|
| 75 | } | 
|---|
| 76 | } | 
|---|
| 77 | /* Out of memory.  */ | 
|---|
| 78 | return NULL; | 
|---|
| 79 | #else | 
|---|
| 80 | # if !MALLOC_0_IS_NONNULL | 
|---|
| 81 | if (n == 0) | 
|---|
| 82 | n = 1; | 
|---|
| 83 | # endif | 
|---|
| 84 | return malloc (n); | 
|---|
| 85 | #endif | 
|---|
| 86 | } | 
|---|
| 87 |  | 
|---|
| 88 | #if HAVE_ALLOCA | 
|---|
| 89 | void | 
|---|
| 90 | freea (void *p) | 
|---|
| 91 | { | 
|---|
| 92 | /* Check argument.  */ | 
|---|
| 93 | if ((uintptr_t) p & (sa_alignment_max - 1)) | 
|---|
| 94 | { | 
|---|
| 95 | /* p was not the result of a malloca() call.  Invalid argument.  */ | 
|---|
| 96 | abort (); | 
|---|
| 97 | } | 
|---|
| 98 | /* Determine whether p was a non-NULL pointer returned by mmalloca().  */ | 
|---|
| 99 | if ((uintptr_t) p & sa_alignment_max) | 
|---|
| 100 | { | 
|---|
| 101 | void *mem = (char *) p - ((small_t *) p)[-1]; | 
|---|
| 102 | free (mem); | 
|---|
| 103 | } | 
|---|
| 104 | } | 
|---|
| 105 | #endif | 
|---|
| 106 |  | 
|---|
| 107 | /* | 
|---|
| 108 | * Hey Emacs! | 
|---|
| 109 | * Local Variables: | 
|---|
| 110 | * coding: utf-8 | 
|---|
| 111 | * End: | 
|---|
| 112 | */ | 
|---|