Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 1 | /*============================================================================== |
Laurence Lundblade | d92a616 | 2018-11-01 11:38:35 +0700 | [diff] [blame] | 2 | Copyright (c) 2016-2018, The Linux Foundation. |
| 3 | Copyright (c) 2018, Laurence Lundblade. |
| 4 | All rights reserved. |
Laurence Lundblade | 624405d | 2018-09-18 20:10:47 -0700 | [diff] [blame] | 5 | |
Laurence Lundblade | 0dbc917 | 2018-11-01 14:17:21 +0700 | [diff] [blame] | 6 | Redistribution and use in source and binary forms, with or without |
| 7 | modification, are permitted provided that the following conditions are |
| 8 | met: |
| 9 | * Redistributions of source code must retain the above copyright |
| 10 | notice, this list of conditions and the following disclaimer. |
| 11 | * Redistributions in binary form must reproduce the above |
| 12 | copyright notice, this list of conditions and the following |
| 13 | disclaimer in the documentation and/or other materials provided |
| 14 | with the distribution. |
| 15 | * Neither the name of The Linux Foundation nor the names of its |
| 16 | contributors, nor the name "Laurence Lundblade" may be used to |
| 17 | endorse or promote products derived from this software without |
| 18 | specific prior written permission. |
Laurence Lundblade | 624405d | 2018-09-18 20:10:47 -0700 | [diff] [blame] | 19 | |
Laurence Lundblade | 0dbc917 | 2018-11-01 14:17:21 +0700 | [diff] [blame] | 20 | THIS SOFTWARE IS PROVIDED "AS IS" AND ANY EXPRESS OR IMPLIED |
| 21 | WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF |
| 22 | MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NON-INFRINGEMENT |
| 23 | ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS |
| 24 | BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR |
| 25 | CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF |
| 26 | SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR |
| 27 | BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, |
| 28 | WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE |
| 29 | OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN |
| 30 | IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
Laurence Lundblade | 624405d | 2018-09-18 20:10:47 -0700 | [diff] [blame] | 31 | ==============================================================================*/ |
| 32 | |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 33 | /*=================================================================================== |
| 34 | FILE: qcbor_encode.c |
| 35 | |
| 36 | DESCRIPTION: This file contains the implementation of QCBOR. |
| 37 | |
| 38 | EDIT HISTORY FOR FILE: |
| 39 | |
| 40 | This section contains comments describing changes made to the module. |
| 41 | Notice that changes are listed in reverse chronological order. |
| 42 | |
| 43 | when who what, where, why |
| 44 | -------- ---- --------------------------------------------------- |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 45 | 11/29/18 llundblade Rework to simpler handling of tags and labels. |
| 46 | 11/9/18 llundblade Error codes are now enums. |
| 47 | 11/1/18 llundblade Floating support. |
| 48 | 10/31/18 llundblade Switch to one license that is almost BSD-3. |
| 49 | 09/28/18 llundblade Added bstr wrapping feature for COSE implementation. |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 50 | 02/05/18 llundbla Works on CPUs which require integer alignment. |
| 51 | Requires new version of UsefulBuf. |
| 52 | 07/05/17 llundbla Add bstr wrapping of maps/arrays for COSE |
| 53 | 03/01/17 llundbla More data types |
| 54 | 11/13/16 llundbla Integrate most TZ changes back into github version. |
| 55 | 09/30/16 gkanike Porting to TZ. |
| 56 | 03/15/16 llundbla Initial Version. |
| 57 | |
| 58 | =====================================================================================*/ |
| 59 | |
| 60 | #include "qcbor.h" |
Laurence Lundblade | 12d32c5 | 2018-09-19 11:25:27 -0700 | [diff] [blame] | 61 | #include "ieee754.h" |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 62 | |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 63 | |
| 64 | /*...... This is a ruler that is 80 characters long...........................*/ |
| 65 | |
| 66 | |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 67 | /* |
| 68 | CBOR's two nesting types, arrays and maps, are tracked here. There is a |
| 69 | limit of QCBOR_MAX_ARRAY_NESTING to the number of arrays and maps |
| 70 | that can be nested in one encoding so the encoding context stays |
| 71 | small enough to fit on the stack. |
| 72 | |
| 73 | When an array / map is opened, pCurrentNesting points to the element |
| 74 | in pArrays that records the type, start position and accumluates a |
| 75 | count of the number of items added. When closed the start position is |
| 76 | used to go back and fill in the type and number of items in the array |
| 77 | / map. |
| 78 | |
| 79 | Encoded output be just items like ints and strings that are |
| 80 | not part of any array / map. That is, the first thing encoded |
| 81 | does not have to be an array or a map. |
| 82 | */ |
| 83 | inline static void Nesting_Init(QCBORTrackNesting *pNesting) |
| 84 | { |
| 85 | // assumes pNesting has been zeroed |
| 86 | pNesting->pCurrentNesting = &pNesting->pArrays[0]; |
| 87 | // Implied CBOR array at the top nesting level. This is never returned, |
| 88 | // but makes the item count work correctly. |
| 89 | pNesting->pCurrentNesting->uMajorType = CBOR_MAJOR_TYPE_ARRAY; |
| 90 | } |
| 91 | |
Laurence Lundblade | 30816f2 | 2018-11-10 13:40:22 +0700 | [diff] [blame] | 92 | inline static QCBORError Nesting_Increase(QCBORTrackNesting *pNesting, uint8_t uMajorType, uint32_t uPos) |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 93 | { |
Laurence Lundblade | 30816f2 | 2018-11-10 13:40:22 +0700 | [diff] [blame] | 94 | QCBORError nReturn = QCBOR_SUCCESS; |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 95 | |
| 96 | if(pNesting->pCurrentNesting == &pNesting->pArrays[QCBOR_MAX_ARRAY_NESTING]) { |
| 97 | // trying to open one too many |
| 98 | nReturn = QCBOR_ERR_ARRAY_NESTING_TOO_DEEP; |
| 99 | } else { |
| 100 | pNesting->pCurrentNesting++; |
| 101 | pNesting->pCurrentNesting->uCount = 0; |
| 102 | pNesting->pCurrentNesting->uStart = uPos; |
| 103 | pNesting->pCurrentNesting->uMajorType = uMajorType; |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 104 | } |
| 105 | return nReturn; |
| 106 | } |
| 107 | |
| 108 | inline static void Nesting_Decrease(QCBORTrackNesting *pNesting) |
| 109 | { |
| 110 | pNesting->pCurrentNesting--; |
| 111 | } |
| 112 | |
Laurence Lundblade | 30816f2 | 2018-11-10 13:40:22 +0700 | [diff] [blame] | 113 | inline static QCBORError Nesting_Increment(QCBORTrackNesting *pNesting, uint16_t uAmount) |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 114 | { |
| 115 | if(uAmount >= QCBOR_MAX_ITEMS_IN_ARRAY - pNesting->pCurrentNesting->uCount) { |
| 116 | return QCBOR_ERR_ARRAY_TOO_LONG; |
| 117 | } |
| 118 | |
| 119 | pNesting->pCurrentNesting->uCount += uAmount; |
| 120 | return QCBOR_SUCCESS; |
| 121 | } |
| 122 | |
| 123 | inline static uint16_t Nesting_GetCount(QCBORTrackNesting *pNesting) |
| 124 | { |
| 125 | // The nesting count recorded is always the actual number of individiual |
| 126 | // data items in the array or map. For arrays CBOR uses the actual item |
| 127 | // count. For maps, CBOR uses the number of pairs. This function returns |
| 128 | // the number needed for the CBOR encoding, so it divides the number of |
| 129 | // items by two for maps to get the number of pairs. This implementation |
| 130 | // takes advantage of the map major type being one larger the array major |
| 131 | // type, hence the subtraction returns either 1 or 2. |
| 132 | return pNesting->pCurrentNesting->uCount / (pNesting->pCurrentNesting->uMajorType - CBOR_MAJOR_TYPE_ARRAY+1); |
| 133 | } |
| 134 | |
| 135 | inline static uint32_t Nesting_GetStartPos(QCBORTrackNesting *pNesting) |
| 136 | { |
| 137 | return pNesting->pCurrentNesting->uStart; |
| 138 | } |
| 139 | |
| 140 | inline static uint8_t Nesting_GetMajorType(QCBORTrackNesting *pNesting) |
| 141 | { |
| 142 | return pNesting->pCurrentNesting->uMajorType; |
| 143 | } |
| 144 | |
| 145 | inline static int Nesting_IsInNest(QCBORTrackNesting *pNesting) |
| 146 | { |
| 147 | return pNesting->pCurrentNesting == &pNesting->pArrays[0] ? 0 : 1; |
| 148 | } |
| 149 | |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 150 | |
| 151 | |
| 152 | |
| 153 | /* |
| 154 | Error tracking plan -- Errors are tracked internally and not returned |
| 155 | until Finish is called. The CBOR errors are in me->uError. |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 156 | UsefulOutBuf also tracks whether the buffer is full or not in its |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 157 | context. Once either of these errors is set they are never |
| 158 | cleared. Only Init() resets them. Or said another way, they must |
| 159 | never be cleared or we'll tell the caller all is good when it is not. |
| 160 | |
| 161 | Only one error code is reported by Finish() even if there are |
| 162 | multiple errors. The last one set wins. The caller might have to fix |
| 163 | one error to reveal the next one they have to fix. This is OK. |
| 164 | |
| 165 | The buffer full error tracked by UsefulBuf is only pulled out of |
| 166 | UsefulBuf in Finish() so it is the one that usually wins. UsefulBuf |
| 167 | will never go off the end of the buffer even if it is called again |
| 168 | and again when full. |
| 169 | |
| 170 | It is really tempting to not check for overflow on the count in the |
| 171 | number of items in an array. It would save a lot of code, it is |
| 172 | extremely unlikely that any one will every put 65,000 items in an |
| 173 | array, and the only bad thing that would happen is the CBOR would be |
| 174 | bogus. Once we prove that is the only consequence, then we can make |
| 175 | the change. |
| 176 | |
| 177 | Since this does not parse any input, you could in theory remove all |
| 178 | error checks in this code if you knew the caller called it |
| 179 | correctly. Maybe someday CDDL or some such language will be able to |
| 180 | generate the code to call this and the calling code would always be |
Laurence Lundblade | 56230d1 | 2018-11-01 11:14:51 +0700 | [diff] [blame] | 181 | correct. This could also automatically size some of the data |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 182 | structures like array/map nesting resulting in some good memory |
| 183 | savings. |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 184 | |
| 185 | Errors returned here fall into three categories: |
| 186 | |
| 187 | Sizes |
| 188 | QCBOR_ERR_BUFFER_TOO_LARGE -- A buffer passed in > UINT32_MAX |
| 189 | QCBOR_ERR_BUFFER_TOO_SMALL -- output buffer too small |
| 190 | |
| 191 | QCBOR_ERR_ARRAY_NESTING_TOO_DEEP -- Too many opens without closes |
| 192 | QCBOR_ERR_ARRAY_TOO_LONG -- Too many things added to an array/map |
| 193 | |
| 194 | Nesting constructed incorrectly |
| 195 | QCBOR_ERR_TOO_MANY_CLOSES -- more close calls than opens |
| 196 | QCBOR_ERR_CLOSE_MISMATCH -- Type of close does not match open |
| 197 | QCBOR_ERR_ARRAY_OR_MAP_STILL_OPEN -- Finish called without enough closes |
| 198 | |
| 199 | Bad data |
| 200 | QCBOR_ERR_BAD_SIMPLE -- Simple value integer not valid |
| 201 | |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 202 | */ |
| 203 | |
| 204 | |
| 205 | |
| 206 | |
| 207 | /* |
| 208 | Public function for initialization. See header qcbor.h |
| 209 | */ |
Laurence Lundblade | 2296db5 | 2018-09-14 18:08:39 -0700 | [diff] [blame] | 210 | void QCBOREncode_Init(QCBOREncodeContext *me, UsefulBuf Storage) |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 211 | { |
| 212 | memset(me, 0, sizeof(QCBOREncodeContext)); |
Laurence Lundblade | 2296db5 | 2018-09-14 18:08:39 -0700 | [diff] [blame] | 213 | if(Storage.len > UINT32_MAX) { |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 214 | me->uError = QCBOR_ERR_BUFFER_TOO_LARGE; |
| 215 | } else { |
Laurence Lundblade | 2296db5 | 2018-09-14 18:08:39 -0700 | [diff] [blame] | 216 | UsefulOutBuf_Init(&(me->OutBuf), Storage); |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 217 | Nesting_Init(&(me->nesting)); |
| 218 | } |
| 219 | } |
| 220 | |
| 221 | |
| 222 | |
| 223 | |
| 224 | /* |
| 225 | All CBOR data items have a type and a number. The number is either |
| 226 | the value of the item for integer types, the length of the content |
| 227 | for string, byte, array and map types, a tag for major type 6, and |
| 228 | has serveral uses for major type 7. |
| 229 | |
| 230 | This function encodes the type and the number. There are several |
| 231 | encodings for the number depending on how large it is and how it is |
| 232 | used. |
| 233 | |
| 234 | Every encoding of the type and number has at least one byte, the |
| 235 | "initial byte". |
| 236 | |
| 237 | The top three bits of the initial byte are the major type for the |
| 238 | CBOR data item. The eight major types defined by the standard are |
| 239 | defined as CBOR_MAJOR_TYPE_xxxx in qcbor.h. |
| 240 | |
| 241 | The remaining five bits, known as "additional information", and |
| 242 | possibly more bytes encode the number. If the number is less than 24, |
| 243 | then it is encoded entirely in the five bits. This is neat because it |
| 244 | allows you to encode an entire CBOR data item in 1 byte for many |
| 245 | values and types (integers 0-23, true, false, and tags). |
| 246 | |
| 247 | If the number is larger than 24, then it is encoded in 1,2,4 or 8 |
| 248 | additional bytes, with the number of these bytes indicated by the |
| 249 | values of the 5 bits 24, 25, 25 and 27. |
| 250 | |
| 251 | It is possible to encode a particular number in many ways with this |
| 252 | representation. This implementation always uses the smallest |
| 253 | possible representation. This is also the suggestion made in the RFC |
| 254 | for cannonical CBOR. |
| 255 | |
| 256 | This function inserts them into the output buffer at the specified |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 257 | position. AppendEncodedTypeAndNumber() appends to the end. |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 258 | |
| 259 | This function takes care of converting to network byte order. |
| 260 | |
| 261 | This function is also used to insert floats and doubles. Before this |
| 262 | function is called the float or double must be copied into a |
| 263 | uint64_t. That is how they are passed in. They are then converted to |
| 264 | network byte order correctly. The uMinLen param makes sure that even |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 265 | if all the digits of a halft, float or double are 0 it is still correctly |
| 266 | encoded in 2, 4 or 8 bytes. |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 267 | |
| 268 | */ |
| 269 | static void InsertEncodedTypeAndNumber(QCBOREncodeContext *me, uint8_t uMajorType, size_t uMinLen, uint64_t uNumber, size_t uPos) |
| 270 | { |
| 271 | // No need to worry about integer overflow here because a) uMajorType is |
| 272 | // always generated internally, not by the caller, b) this is for CBOR |
| 273 | // _generation_, not parsing c) a mistake will result in bad CBOR generation, |
| 274 | // not a security vulnerability. |
Laurence Lundblade | 56230d1 | 2018-11-01 11:14:51 +0700 | [diff] [blame] | 275 | uMajorType <<= 5; |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 276 | |
| 277 | if(uNumber > 0xffffffff || uMinLen >= 8) { |
| 278 | UsefulOutBuf_InsertByte(&(me->OutBuf), uMajorType + LEN_IS_EIGHT_BYTES, uPos); |
| 279 | UsefulOutBuf_InsertUint64(&(me->OutBuf), (uint64_t)uNumber, uPos+1); |
| 280 | |
| 281 | } else if(uNumber > 0xffff || uMinLen >= 4) { |
| 282 | UsefulOutBuf_InsertByte(&(me->OutBuf), uMajorType + LEN_IS_FOUR_BYTES, uPos); |
| 283 | UsefulOutBuf_InsertUint32(&(me->OutBuf), (uint32_t)uNumber, uPos+1); |
| 284 | |
Laurence Lundblade | 12d32c5 | 2018-09-19 11:25:27 -0700 | [diff] [blame] | 285 | } else if (uNumber > 0xff || uMinLen>= 2) { |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 286 | // Between 0 and 65535 |
| 287 | UsefulOutBuf_InsertByte(&(me->OutBuf), uMajorType + LEN_IS_TWO_BYTES, uPos); |
| 288 | UsefulOutBuf_InsertUint16(&(me->OutBuf), (uint16_t)uNumber, uPos+1); |
| 289 | |
| 290 | } else if(uNumber >= 24) { |
| 291 | // Between 0 and 255, but only between 24 and 255 is ever encoded here |
| 292 | UsefulOutBuf_InsertByte(&(me->OutBuf), uMajorType + LEN_IS_ONE_BYTE, uPos); |
| 293 | UsefulOutBuf_InsertByte(&(me->OutBuf), (uint8_t)uNumber, uPos+1); |
| 294 | |
| 295 | } else { |
| 296 | // Between 0 and 23 |
| 297 | UsefulOutBuf_InsertByte(&(me->OutBuf), uMajorType + (uint8_t)uNumber, uPos); |
| 298 | } |
| 299 | } |
| 300 | |
| 301 | |
| 302 | /* |
| 303 | Append the type and number info to the end of the buffer. |
| 304 | |
| 305 | See InsertEncodedTypeAndNumber() function above for details |
| 306 | */ |
| 307 | inline static void AppendEncodedTypeAndNumber(QCBOREncodeContext *me, uint8_t uMajorType, uint64_t uNumber) |
| 308 | { |
| 309 | // An append is an insert at the end. |
| 310 | InsertEncodedTypeAndNumber(me, uMajorType, 0, uNumber, UsefulOutBuf_GetEndPosition(&(me->OutBuf))); |
| 311 | } |
| 312 | |
| 313 | |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 314 | /* |
| 315 | Internal function for adding floating point and simple |
| 316 | types to the encoded output. |
| 317 | */ |
| 318 | static void AppendType7(QCBOREncodeContext *me, size_t uSize, uint64_t uNum) |
| 319 | { |
| 320 | if(me->uError == QCBOR_SUCCESS) { |
| 321 | // This function call takes care of endian swapping for the float / double |
| 322 | InsertEncodedTypeAndNumber(me, |
| 323 | CBOR_MAJOR_TYPE_SIMPLE, // The major type for |
| 324 | // floats and doubles |
| 325 | uSize, // min size / tells |
| 326 | // encoder to do it right |
| 327 | uNum, // Bytes of the floating |
| 328 | // point number as a uint |
| 329 | UsefulOutBuf_GetEndPosition(&(me->OutBuf))); // end position for append |
| 330 | |
| 331 | me->uError = Nesting_Increment(&(me->nesting), 1); |
| 332 | } |
| 333 | } |
| 334 | |
| 335 | |
Laurence Lundblade | 55a2483 | 2018-10-30 04:35:08 +0700 | [diff] [blame] | 336 | |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 337 | |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 338 | /* |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 339 | Public functions for closing arrays and maps. See header qcbor.h |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 340 | */ |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 341 | void QCBOREncode_AddUInt64(QCBOREncodeContext *me, uint64_t uValue) |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 342 | { |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 343 | if(me->uError == QCBOR_SUCCESS) { |
| 344 | AppendEncodedTypeAndNumber(me, CBOR_MAJOR_TYPE_POSITIVE_INT, uValue); |
| 345 | me->uError = Nesting_Increment(&(me->nesting), 1); |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 346 | } |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 347 | } |
| 348 | |
Laurence Lundblade | 56230d1 | 2018-11-01 11:14:51 +0700 | [diff] [blame] | 349 | |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 350 | /* |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 351 | Public functions for closing arrays and maps. See header qcbor.h |
| 352 | */ |
| 353 | void QCBOREncode_AddInt64(QCBOREncodeContext *me, int64_t nNum) |
| 354 | { |
| 355 | if(me->uError == QCBOR_SUCCESS) { |
| 356 | uint8_t uMajorType; |
| 357 | uint64_t uValue; |
| 358 | |
| 359 | if(nNum < 0) { |
| 360 | uValue = (uint64_t)(-nNum - 1); // This is the way negative ints work in CBOR. -1 encodes as 0x00 with major type negative int. |
| 361 | uMajorType = CBOR_MAJOR_TYPE_NEGATIVE_INT; |
| 362 | } else { |
| 363 | uValue = (uint64_t)nNum; |
| 364 | uMajorType = CBOR_MAJOR_TYPE_POSITIVE_INT; |
| 365 | } |
| 366 | |
| 367 | AppendEncodedTypeAndNumber(me, uMajorType, uValue); |
| 368 | me->uError = Nesting_Increment(&(me->nesting), 1); |
| 369 | } |
| 370 | } |
| 371 | |
| 372 | |
| 373 | /* |
| 374 | Semi-private function. It is exposed to user of the interface, |
| 375 | but they will usually call one of the inline wrappers rather than this. |
| 376 | |
| 377 | See header qcbor.h |
| 378 | |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 379 | Does the work of adding some bytes to the CBOR output. Works for a |
| 380 | byte and text strings, which are the same in in CBOR though they have |
Laurence Lundblade | da3f082 | 2018-09-18 19:49:02 -0700 | [diff] [blame] | 381 | different major types. This is also used to insert raw |
| 382 | pre-encoded CBOR. |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 383 | */ |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 384 | void QCBOREncode_AddBuffer(QCBOREncodeContext *me, uint8_t uMajorType, UsefulBufC Bytes) |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 385 | { |
| 386 | if(Bytes.len >= UINT32_MAX) { |
Laurence Lundblade | 56230d1 | 2018-11-01 11:14:51 +0700 | [diff] [blame] | 387 | // This implementation doesn't allow buffers larger than UINT32_MAX. |
| 388 | // This is primarily because QCBORTrackNesting.pArrays[].uStart is |
| 389 | // an uint32 rather than size_t to keep the stack usage down. Also |
| 390 | // it is entirely impractical to create tokens bigger than 4GB in |
| 391 | // contiguous RAM |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 392 | me->uError = QCBOR_ERR_BUFFER_TOO_LARGE; |
| 393 | |
| 394 | } else { |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 395 | if(!me->uError) { |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 396 | // If it is not Raw CBOR, add the type and the length |
| 397 | if(uMajorType != CBOR_MAJOR_NONE_TYPE_RAW) { |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 398 | AppendEncodedTypeAndNumber(me, uMajorType, Bytes.len); |
Laurence Lundblade | 56230d1 | 2018-11-01 11:14:51 +0700 | [diff] [blame] | 399 | // The increment in uPos is to account for bytes added for |
| 400 | // type and number so the buffer being added goes to the |
| 401 | // right place |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 402 | } |
| 403 | |
| 404 | // Actually add the bytes |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 405 | UsefulOutBuf_AppendUsefulBuf(&(me->OutBuf), Bytes); |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 406 | |
| 407 | // Update the array counting if there is any nesting at all |
Laurence Lundblade | da3f082 | 2018-09-18 19:49:02 -0700 | [diff] [blame] | 408 | me->uError = Nesting_Increment(&(me->nesting), 1); |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 409 | } |
| 410 | } |
| 411 | } |
| 412 | |
Laurence Lundblade | cafcfe1 | 2018-10-31 21:59:50 +0700 | [diff] [blame] | 413 | |
Laurence Lundblade | 55a2483 | 2018-10-30 04:35:08 +0700 | [diff] [blame] | 414 | /* |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 415 | Public functions for closing arrays and maps. See header qcbor.h |
Laurence Lundblade | 55a2483 | 2018-10-30 04:35:08 +0700 | [diff] [blame] | 416 | */ |
| 417 | void QCBOREncode_AddTag(QCBOREncodeContext *me, uint64_t uTag) |
| 418 | { |
Laurence Lundblade | 55a2483 | 2018-10-30 04:35:08 +0700 | [diff] [blame] | 419 | AppendEncodedTypeAndNumber(me, CBOR_MAJOR_TYPE_OPTIONAL, uTag); |
| 420 | } |
| 421 | |
| 422 | |
Laurence Lundblade | 56230d1 | 2018-11-01 11:14:51 +0700 | [diff] [blame] | 423 | /* |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 424 | Public functions for closing arrays and maps. See header qcbor.h |
Laurence Lundblade | 56230d1 | 2018-11-01 11:14:51 +0700 | [diff] [blame] | 425 | */ |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 426 | void QCBOREncode_AddSimple(QCBOREncodeContext *pCtx, uint8_t uSimple) |
Laurence Lundblade | 55a2483 | 2018-10-30 04:35:08 +0700 | [diff] [blame] | 427 | { |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 428 | AppendType7(pCtx, 0, uSimple); |
Laurence Lundblade | 55a2483 | 2018-10-30 04:35:08 +0700 | [diff] [blame] | 429 | } |
| 430 | |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 431 | |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 432 | /* |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 433 | Public functions for closing arrays and maps. See header qcbor.h |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 434 | */ |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 435 | void QCBOREncode_AddDouble(QCBOREncodeContext *me, double dNum) |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 436 | { |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 437 | const IEEE754_union uNum = IEEE754_DoubleToSmallest(dNum); |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 438 | |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 439 | AppendType7(me, uNum.uSize, uNum.uValue); |
| 440 | } |
| 441 | |
| 442 | |
| 443 | /* |
| 444 | Semi-public function. It is exposed to user of the interface, |
| 445 | but they will usually call one of the inline wrappers rather than this. |
| 446 | |
| 447 | See header qcbor.h |
| 448 | */ |
| 449 | void QCBOREncode_OpenMapOrArray(QCBOREncodeContext *me, uint8_t uMajorType) |
| 450 | { |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 451 | // Add one item to the nesting level we are in for the new map or array |
| 452 | me->uError = Nesting_Increment(&(me->nesting), 1); |
| 453 | if(!me->uError) { |
| 454 | // Increase nesting level because this is a map or array |
| 455 | // Cast from size_t to uin32_t is safe because the UsefulOutBuf |
| 456 | // size is limited to UINT32_MAX in QCBOR_Init(). |
Laurence Lundblade | a954db9 | 2018-09-28 19:27:31 -0700 | [diff] [blame] | 457 | me->uError = Nesting_Increase(&(me->nesting), uMajorType, (uint32_t)UsefulOutBuf_GetEndPosition(&(me->OutBuf))); |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 458 | } |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 459 | } |
| 460 | |
| 461 | |
| 462 | /* |
Laurence Lundblade | cafcfe1 | 2018-10-31 21:59:50 +0700 | [diff] [blame] | 463 | Public functions for closing arrays and maps. See header qcbor.h |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 464 | */ |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 465 | void QCBOREncode_CloseMapOrArray(QCBOREncodeContext *me, uint8_t uMajorType, UsefulBufC *pWrappedCBOR) |
Laurence Lundblade | a954db9 | 2018-09-28 19:27:31 -0700 | [diff] [blame] | 466 | { |
| 467 | if(!me->uError) { |
| 468 | if(!Nesting_IsInNest(&(me->nesting))) { |
| 469 | me->uError = QCBOR_ERR_TOO_MANY_CLOSES; |
| 470 | } else if( Nesting_GetMajorType(&(me->nesting)) != uMajorType) { |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 471 | me->uError = QCBOR_ERR_CLOSE_MISMATCH; |
Laurence Lundblade | a954db9 | 2018-09-28 19:27:31 -0700 | [diff] [blame] | 472 | } else { |
Laurence Lundblade | 56230d1 | 2018-11-01 11:14:51 +0700 | [diff] [blame] | 473 | // When the array, map or bstr wrap was started, nothing was done |
| 474 | // except note the position of the start of it. This code goes back |
| 475 | // and inserts the actual CBOR array, map or bstr and its length. |
| 476 | // That means all the data that is in the array, map or wrapped |
| 477 | // needs to be slid to the right. This is done by UsefulOutBuf's |
| 478 | // insert function that is called from inside |
| 479 | // InsertEncodedTypeAndNumber() |
| 480 | const size_t uInsertPosition = Nesting_GetStartPos(&(me->nesting)); |
| 481 | const size_t uEndPosition = UsefulOutBuf_GetEndPosition(&(me->OutBuf)); |
| 482 | // This can't go negative because the UsefulOutBuf always only grows |
| 483 | // and never shrinks. UsefulOutBut itself also has defenses such that |
| 484 | // it won't write were it should not even if given hostile input lengths |
| 485 | const size_t uLenOfEncodedMapOrArray = uEndPosition - uInsertPosition; |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 486 | |
Laurence Lundblade | 56230d1 | 2018-11-01 11:14:51 +0700 | [diff] [blame] | 487 | // Length is number of bytes for a bstr and number of items a for map & array |
| 488 | const size_t uLength = uMajorType == CBOR_MAJOR_TYPE_BYTE_STRING ? |
Laurence Lundblade | a954db9 | 2018-09-28 19:27:31 -0700 | [diff] [blame] | 489 | uLenOfEncodedMapOrArray : Nesting_GetCount(&(me->nesting)); |
| 490 | |
| 491 | // Actually insert |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 492 | InsertEncodedTypeAndNumber(me, |
Laurence Lundblade | a954db9 | 2018-09-28 19:27:31 -0700 | [diff] [blame] | 493 | uMajorType, // major type bstr, array or map |
| 494 | 0, // no minimum length for encoding |
| 495 | uLength, // either len of bstr or num items in array or map |
| 496 | uInsertPosition); // position in out buffer |
| 497 | |
| 498 | // Return pointer and length to the enclosed encoded CBOR. The intended |
| 499 | // use is for it to be hashed (e.g., SHA-256) in a COSE implementation. |
| 500 | // This must be used right away, as the pointer and length go invalid |
| 501 | // on any subsequent calls to this function because of the |
| 502 | // InsertEncodedTypeAndNumber() call that slides data to the right. |
| 503 | if(pWrappedCBOR) { |
| 504 | UsefulBufC PartialResult = UsefulOutBuf_OutUBuf(&(me->OutBuf)); |
Laurence Lundblade | 56230d1 | 2018-11-01 11:14:51 +0700 | [diff] [blame] | 505 | size_t uBstrLen = UsefulOutBuf_GetEndPosition(&(me->OutBuf)) - uEndPosition; |
Laurence Lundblade | a954db9 | 2018-09-28 19:27:31 -0700 | [diff] [blame] | 506 | *pWrappedCBOR = UsefulBuf_Tail(PartialResult, uInsertPosition+uBstrLen); |
| 507 | } |
| 508 | Nesting_Decrease(&(me->nesting)); |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 509 | } |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 510 | } |
| 511 | } |
| 512 | |
| 513 | |
Laurence Lundblade | 56230d1 | 2018-11-01 11:14:51 +0700 | [diff] [blame] | 514 | |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 515 | /* |
| 516 | Public functions to finish and get the encoded result. See header qcbor.h |
| 517 | */ |
Laurence Lundblade | 30816f2 | 2018-11-10 13:40:22 +0700 | [diff] [blame] | 518 | QCBORError QCBOREncode_Finish(QCBOREncodeContext *me, UsefulBufC *pEncodedCBOR) |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 519 | { |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 520 | QCBORError uReturn = me->uError; |
| 521 | |
| 522 | if(uReturn != QCBOR_SUCCESS) { |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 523 | goto Done; |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 524 | } |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 525 | |
| 526 | if (Nesting_IsInNest(&(me->nesting))) { |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 527 | uReturn = QCBOR_ERR_ARRAY_OR_MAP_STILL_OPEN; |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 528 | goto Done; |
| 529 | } |
| 530 | |
| 531 | if(UsefulOutBuf_GetError(&(me->OutBuf))) { |
| 532 | // Stuff didn't fit in the buffer. |
Laurence Lundblade | 56230d1 | 2018-11-01 11:14:51 +0700 | [diff] [blame] | 533 | // This check catches this condition for all the appends and inserts |
| 534 | // so checks aren't needed when the appends and inserts are performed. |
| 535 | // And of course UsefulBuf will never overrun the input buffer given |
| 536 | // to it. No complex analysis of the error handling in this file is |
| 537 | // needed to know that is true. Just read the UsefulBuf code. |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 538 | uReturn = QCBOR_ERR_BUFFER_TOO_SMALL; |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 539 | goto Done; |
| 540 | } |
Laurence Lundblade | 2296db5 | 2018-09-14 18:08:39 -0700 | [diff] [blame] | 541 | |
Laurence Lundblade | da3f082 | 2018-09-18 19:49:02 -0700 | [diff] [blame] | 542 | *pEncodedCBOR = UsefulOutBuf_OutUBuf(&(me->OutBuf)); |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 543 | |
| 544 | Done: |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 545 | return uReturn; |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 546 | } |
| 547 | |
Laurence Lundblade | 0595e93 | 2018-11-02 22:22:47 +0700 | [diff] [blame] | 548 | |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 549 | /* |
| 550 | Public functions to finish and get the encoded result. See header qcbor.h |
| 551 | */ |
Laurence Lundblade | 30816f2 | 2018-11-10 13:40:22 +0700 | [diff] [blame] | 552 | QCBORError QCBOREncode_FinishGetSize(QCBOREncodeContext *me, size_t *puEncodedLen) |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 553 | { |
Laurence Lundblade | da3f082 | 2018-09-18 19:49:02 -0700 | [diff] [blame] | 554 | UsefulBufC Enc; |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 555 | |
Laurence Lundblade | 30816f2 | 2018-11-10 13:40:22 +0700 | [diff] [blame] | 556 | QCBORError nReturn = QCBOREncode_Finish(me, &Enc); |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 557 | |
| 558 | if(nReturn == QCBOR_SUCCESS) { |
Laurence Lundblade | da3f082 | 2018-09-18 19:49:02 -0700 | [diff] [blame] | 559 | *puEncodedLen = Enc.len; |
Laurence Lundblade | b69cad7 | 2018-09-13 11:09:01 -0700 | [diff] [blame] | 560 | } |
| 561 | |
| 562 | return nReturn; |
| 563 | } |
| 564 | |
| 565 | |
Laurence Lundblade | 067035b | 2018-11-28 17:35:25 -0800 | [diff] [blame^] | 566 | |
| 567 | |
| 568 | /* |
| 569 | Notes on the code |
| 570 | |
| 571 | CBOR Major Type Public Function |
| 572 | 0 QCBOREncode_AddUInt64 |
| 573 | 0, 1 QCBOREncode_AddUInt64, QCBOREncode_AddInt64 |
| 574 | 2, 3 QCBOREncode_AddBuffer, Also QCBOREncode_OpenMapOrArray |
| 575 | 4, 5 QCBOREncode_OpenMapOrArray |
| 576 | 6 QCBOREncode_AddTag |
| 577 | 7 QCBOREncode_AddDouble, QCBOREncode_AddSimple |
| 578 | |
| 579 | Object code sizes on X86 with LLVM compiler and -Os (Nov 27, 2018) |
| 580 | |
| 581 | _QCBOREncode_Init 84 |
| 582 | _QCBOREncode_AddUInt64 76 |
| 583 | _QCBOREncode_AddInt64 87 |
| 584 | _QCBOREncode_AddBuffer 131 |
| 585 | _QCBOREncode_AddSimple 30 |
| 586 | _AppendType7 83 |
| 587 | _QCBOREncode_OpenMapOrArray 89 |
| 588 | _QCBOREncode_CloseMapOrArray 181 |
| 589 | _InsertEncodedTypeAndNumber 480 |
| 590 | _QCBOREncode_Finish 72 |
| 591 | |
| 592 | Total is about 1.4KB (including FinishGetSize and AddTag and AddDouble) |
| 593 | |
| 594 | _InsertEncodedTypeAndNumber is large because a lot of UsefulBuf |
| 595 | code inlines into it including the conversion to network byte |
| 596 | order. This could be optimized to at least half the size, but |
| 597 | code would probably not be quite as clean. |
| 598 | |
| 599 | _QCBOREncode_CloseMapOrArray is larger because it has a lot |
| 600 | of nesting tracking to do and much of Nesting_ inlines |
| 601 | into it. It probably can't be reduced much. |
| 602 | |
| 603 | If the error returned by Nesting_Increment() can be ignored |
| 604 | because the limit is so high and the consequence of exceeding |
| 605 | is proved to be inconsequential, then a lot of if(me->uError) |
| 606 | instance can be removed, saving some code. |
| 607 | |
| 608 | */ |
| 609 | |
| 610 | |
| 611 | |
| 612 | |
| 613 | |
| 614 | |
| 615 | |
| 616 | |