blob: 7d2f7fbb74ba5e2b5be72b888c1c801cdb975e2c [file] [log] [blame]
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001/*==============================================================================
Laurence Lundbladed92a6162018-11-01 11:38:35 +07002 Copyright (c) 2016-2018, The Linux Foundation.
Laurence Lundblade8e36f812024-01-26 10:59:29 -07003 Copyright (c) 2018-2024, Laurence Lundblade.
Máté Tóth-Pálef5f07a2021-09-17 19:31:37 +02004 Copyright (c) 2021, Arm Limited.
Laurence Lundbladed92a6162018-11-01 11:38:35 +07005 All rights reserved.
Laurence Lundblade3aee3a32018-12-17 16:17:45 -08006
Laurence Lundblade0dbc9172018-11-01 14:17:21 +07007Redistribution and use in source and binary forms, with or without
8modification, are permitted provided that the following conditions are
9met:
10 * Redistributions of source code must retain the above copyright
11 notice, this list of conditions and the following disclaimer.
12 * Redistributions in binary form must reproduce the above
13 copyright notice, this list of conditions and the following
14 disclaimer in the documentation and/or other materials provided
15 with the distribution.
16 * Neither the name of The Linux Foundation nor the names of its
17 contributors, nor the name "Laurence Lundblade" may be used to
18 endorse or promote products derived from this software without
19 specific prior written permission.
Laurence Lundblade3aee3a32018-12-17 16:17:45 -080020
Laurence Lundblade0dbc9172018-11-01 14:17:21 +070021THIS SOFTWARE IS PROVIDED "AS IS" AND ANY EXPRESS OR IMPLIED
22WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
23MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NON-INFRINGEMENT
24ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS
25BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
26CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
27SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
28BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
29WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE
30OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN
31IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
Laurence Lundbladeee851742020-01-08 08:37:05 -080032 =============================================================================*/
Laurence Lundblade624405d2018-09-18 20:10:47 -070033
Laurence Lundblade3aee3a32018-12-17 16:17:45 -080034
Laurence Lundblade844bb5c2020-03-01 17:27:25 -080035#include "qcbor/qcbor_encode.h"
Laurence Lundblade12d32c52018-09-19 11:25:27 -070036#include "ieee754.h"
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070037
Laurence Lundbladeeb3cdef2024-02-17 20:38:55 -080038#ifndef QCBOR_DISABLE_PREFERRED_FLOAT
39#include <math.h> /* Only for NAN definition */
40#endif /* ! QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
41
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070042
Laurence Lundblade1fa579b2020-11-25 00:31:37 -080043/**
44 * @file qcbor_encode.c
Laurence Lundblade3f1318a2021-01-04 18:26:44 -080045 *
Laurence Lundblade1fa579b2020-11-25 00:31:37 -080046 * The entire implementation of the QCBOR encoder.
47 */
48
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070049
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070050/*
Laurence Lundblade1fa579b2020-11-25 00:31:37 -080051 * == Nesting Tracking ==
52 *
53 * The following functions and data type QCBORTrackNesting implement
54 * the nesting management for encoding.
55 *
56 * CBOR's two nesting types, arrays and maps, are tracked here. There
57 * is a limit of QCBOR_MAX_ARRAY_NESTING to the number of arrays and
58 * maps that can be nested in one encoding so the encoding context
59 * stays small enough to fit on the stack.
60 *
61 * When an array/map is opened, pCurrentNesting points to the element
62 * in pArrays that records the type, start position and accumulates a
63 * count of the number of items added. When closed the start position
64 * is used to go back and fill in the type and number of items in the
65 * array/map.
66 *
67 * Encoded output can be a CBOR Sequence (RFC 8742) in which case
68 * there is no top-level array or map. It starts out with a string,
69 * integer or other non-aggregate type. It may have an array or map
70 * other than at the start, in which case that nesting is tracked
71 * here.
72 *
73 * QCBOR has a special feature to allow constructing byte string
74 * wrapped CBOR directly into the output buffer, so no extra buffer is
75 * needed for byte string wrapping. This is implemented as nesting
76 * with the type CBOR_MAJOR_TYPE_BYTE_STRING and is tracked here. Byte
77 * string wrapped CBOR is used by COSE for data that is to be hashed.
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070078 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -070079static void
Laurence Lundblade274ddef2022-05-17 09:12:23 -070080Nesting_Init(QCBORTrackNesting *pNesting)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070081{
Laurence Lundblade1fa579b2020-11-25 00:31:37 -080082 /* Assumes pNesting has been zeroed. */
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070083 pNesting->pCurrentNesting = &pNesting->pArrays[0];
Laurence Lundblade1fa579b2020-11-25 00:31:37 -080084 /* Implied CBOR array at the top nesting level. This is never
85 * returned, but makes the item count work correctly.
86 */
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070087 pNesting->pCurrentNesting->uMajorType = CBOR_MAJOR_TYPE_ARRAY;
88}
89
Laurence Lundblade8e36f812024-01-26 10:59:29 -070090static uint8_t
Laurence Lundblade274ddef2022-05-17 09:12:23 -070091Nesting_Increase(QCBORTrackNesting *pNesting,
Laurence Lundblade8e36f812024-01-26 10:59:29 -070092 const uint8_t uMajorType,
93 const uint32_t uPos)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070094{
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070095 if(pNesting->pCurrentNesting == &pNesting->pArrays[QCBOR_MAX_ARRAY_NESTING]) {
Laurence Lundblade29497c02020-07-11 15:44:03 -070096 return QCBOR_ERR_ARRAY_NESTING_TOO_DEEP;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070097 } else {
98 pNesting->pCurrentNesting++;
99 pNesting->pCurrentNesting->uCount = 0;
100 pNesting->pCurrentNesting->uStart = uPos;
101 pNesting->pCurrentNesting->uMajorType = uMajorType;
Laurence Lundblade29497c02020-07-11 15:44:03 -0700102 return QCBOR_SUCCESS;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700103 }
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700104}
105
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700106static void
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700107Nesting_Decrease(QCBORTrackNesting *pNesting)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700108{
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700109 if(pNesting->pCurrentNesting > &pNesting->pArrays[0]) {
110 pNesting->pCurrentNesting--;
111 }
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700112}
113
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700114static uint8_t
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700115Nesting_Increment(QCBORTrackNesting *pNesting)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700116{
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800117#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Laurence Lundblade1ef8b2d2018-12-14 23:13:34 -0800118 if(1 >= QCBOR_MAX_ITEMS_IN_ARRAY - pNesting->pCurrentNesting->uCount) {
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700119 return QCBOR_ERR_ARRAY_TOO_LONG;
120 }
Laurence Lundbladecbd7d132024-05-19 11:11:22 -0700121#endif /* !QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800122
Laurence Lundbladee6bcef12020-04-01 10:56:27 -0700123 pNesting->pCurrentNesting->uCount++;
Laurence Lundblade2c40ab82018-12-30 14:20:29 -0800124
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700125 return QCBOR_SUCCESS;
126}
127
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700128static void
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700129Nesting_Decrement(QCBORTrackNesting *pNesting)
Laurence Lundblade8d3b8552021-06-10 11:11:54 -0700130{
131 /* No error check for going below 0 here needed because this
132 * is only used by QCBOREncode_CancelBstrWrap() and it checks
133 * the nesting level before calling this. */
134 pNesting->pCurrentNesting->uCount--;
135}
136
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700137static uint16_t
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700138Nesting_GetCount(QCBORTrackNesting *pNesting)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700139{
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800140 /* The nesting count recorded is always the actual number of
141 * individual data items in the array or map. For arrays CBOR uses
142 * the actual item count. For maps, CBOR uses the number of pairs.
143 * This function returns the number needed for the CBOR encoding,
144 * so it divides the number of items by two for maps to get the
145 * number of pairs.
146 */
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800147 if(pNesting->pCurrentNesting->uMajorType == CBOR_MAJOR_TYPE_MAP) {
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800148 /* Cast back to uint16_t after integer promotion from bit shift */
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800149 return (uint16_t)(pNesting->pCurrentNesting->uCount >> 1);
150 } else {
151 return pNesting->pCurrentNesting->uCount;
152 }
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700153}
154
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700155static uint32_t
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700156Nesting_GetStartPos(QCBORTrackNesting *pNesting)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700157{
158 return pNesting->pCurrentNesting->uStart;
159}
160
Laurence Lundbladed8e1c512020-11-04 23:03:44 -0800161#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700162static uint8_t
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700163Nesting_GetMajorType(QCBORTrackNesting *pNesting)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700164{
165 return pNesting->pCurrentNesting->uMajorType;
166}
167
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700168static bool
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700169Nesting_IsInNest(QCBORTrackNesting *pNesting)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700170{
Laurence Lundbladeee851742020-01-08 08:37:05 -0800171 return pNesting->pCurrentNesting == &pNesting->pArrays[0] ? false : true;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700172}
Laurence Lundbladed8e1c512020-11-04 23:03:44 -0800173#endif /* QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700174
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700175
176
177
178/*
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800179 * == Major CBOR Types ==
180 *
181 * Encoding of the major CBOR types is by these functions:
182 *
Laurence Lundblade3f1318a2021-01-04 18:26:44 -0800183 * CBOR Major Type Public Function
184 * 0 QCBOREncode_AddUInt64()
185 * 0, 1 QCBOREncode_AddUInt64(), QCBOREncode_AddInt64()
186 * 2, 3 QCBOREncode_AddBuffer()
187 * 4, 5 QCBOREncode_OpenMapOrArray(), QCBOREncode_CloseMapOrArray(),
188 * QCBOREncode_OpenMapOrArrayIndefiniteLength(),
189 * QCBOREncode_CloseMapOrArrayIndefiniteLength()
190 * 6 QCBOREncode_AddTag()
191 * 7 QCBOREncode_AddDouble(), QCBOREncode_AddFloat(),
192 * QCBOREncode_AddDoubleNoPreferred(),
193 * QCBOREncode_AddFloatNoPreferred(), QCBOREncode_AddType7()
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800194 *
195 * Additionally, encoding of decimal fractions and bigfloats is by
196 * QCBOREncode_AddExponentAndMantissa() and byte strings that wrap
197 * encoded CBOR are handled by QCBOREncode_OpenMapOrArray() and
198 * QCBOREncode_CloseBstrWrap2().
199 *
200 *
201 * == Error Tracking Plan ==
202 *
203 * Errors are tracked internally and not returned until
204 * QCBOREncode_Finish() or QCBOREncode_GetErrorState() is called. The
205 * CBOR errors are in me->uError. UsefulOutBuf also tracks whether
206 * the buffer is full or not in its context. Once either of these
207 * errors is set they are never cleared. Only QCBOREncode_Init()
208 * resets them. Or said another way, they must never be cleared or
209 * we'll tell the caller all is good when it is not.
210 *
211 * Only one error code is reported by QCBOREncode_Finish() even if
212 * there are multiple errors. The last one set wins. The caller might
213 * have to fix one error to reveal the next one they have to fix.
214 * This is OK.
215 *
216 * The buffer full error tracked by UsefulBuf is only pulled out of
217 * UsefulBuf in QCBOREncode_Finish() so it is the one that usually
218 * wins. UsefulBuf will never go off the end of the buffer even if it
219 * is called again and again when full.
220 *
221 * QCBOR_DISABLE_ENCODE_USAGE_GUARDS disables about half of the error
222 * checks here to reduce code size by about 150 bytes leaving only the
223 * checks for size to avoid buffer overflow. If the calling code is
224 * completely correct, checks are completely unnecessary. For
225 * example, there is no need to check that all the opens are matched
226 * by a close.
227 *
228 * QCBOR_DISABLE_ENCODE_USAGE_GUARDS also disables the check for more
229 * than QCBOR_MAX_ITEMS_IN_ARRAY in an array. Since
230 * QCBOR_MAX_ITEMS_IN_ARRAY is very large (65,535) it is very unlikely
231 * to be reached. If it is reached, the count will wrap around to zero
232 * and CBOR that is not well formed will be produced, but there will
233 * be no buffers overrun and new security issues in the code.
234 *
235 * The 8 errors returned here fall into three categories:
236 *
237 * Sizes
238 * QCBOR_ERR_BUFFER_TOO_LARGE -- Encoded output exceeded UINT32_MAX
239 * QCBOR_ERR_BUFFER_TOO_SMALL -- Output buffer too small
240 * QCBOR_ERR_ARRAY_NESTING_TOO_DEEP -- Nesting > QCBOR_MAX_ARRAY_NESTING1
241 * QCBOR_ERR_ARRAY_TOO_LONG -- Too many items added to an array/map [1]
242 *
243 * Nesting constructed incorrectly
244 * QCBOR_ERR_TOO_MANY_CLOSES -- More close calls than opens [1]
245 * QCBOR_ERR_CLOSE_MISMATCH -- Type of close does not match open [1]
246 * QCBOR_ERR_ARRAY_OR_MAP_STILL_OPEN -- Finish called without enough closes [1]
247 *
248 * Would generate not-well-formed CBOR
249 * QCBOR_ERR_ENCODE_UNSUPPORTED -- Simple type between 24 and 31 [1]
250 *
251 * [1] indicated disabled by QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700252 */
253
254
Laurence Lundbladeeb3cdef2024-02-17 20:38:55 -0800255/* Forward declaration for reference in QCBOREncode_Init() */
256static void
257QCBOREncode_Private_CloseMapUnsorted(QCBOREncodeContext *pMe);
258
259
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700260/*
Laurence Lundbladeb9ccd6b2024-02-06 05:44:25 -0700261 * Public function for initialization. See qcbor/qcbor_encode.h
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700262 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700263void
264QCBOREncode_Init(QCBOREncodeContext *pMe, UsefulBuf Storage)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700265{
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700266 memset(pMe, 0, sizeof(QCBOREncodeContext));
267 UsefulOutBuf_Init(&(pMe->OutBuf), Storage);
268 Nesting_Init(&(pMe->nesting));
Laurence Lundbladeeb3cdef2024-02-17 20:38:55 -0800269 pMe->pfnCloseMap = QCBOREncode_Private_CloseMapUnsorted;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700270}
271
272
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000273/*
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800274 * Public function to encode a CBOR head. See qcbor/qcbor_encode.h
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700275 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700276UsefulBufC
277QCBOREncode_EncodeHead(UsefulBuf Buffer,
278 uint8_t uMajorType,
279 uint8_t uMinLen,
280 uint64_t uArgument)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700281{
Laurence Lundbladee9b00322018-12-30 10:33:26 -0800282 /*
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800283 * == Description of the CBOR Head ==
284 *
285 * The head of a CBOR data item
286 * +---+-----+ +--------+ +--------+ +--------+ +--------+
287 * |M T| A R G U M E N T . . . |
288 * +---+-----+ +--------+ +--------+ +--------+ ... +--------+
289 *
290 * Every CBOR data item has a "head". It is made up of the "major
291 * type" and the "argument".
292 *
293 * The major type indicates whether the data item is an integer,
294 * string, array or such. It is encoded in 3 bits giving it a range
295 * from 0 to 7. 0 indicates the major type is a positive integer,
296 * 1 a negative integer, 2 a byte string and so on.
297 *
298 * These 3 bits are the first part of the "initial byte" in a data
299 * item. Every data item has an initial byte, and some only have
300 * the initial byte.
301 *
302 * The argument is essentially a number between 0 and UINT64_MAX
303 * (18446744073709551615). This number is interpreted to mean
304 * different things for the different major types. For major type
305 * 0, a positive integer, it is value of the data item. For major
306 * type 2, a byte string, it is the length in bytes of the byte
307 * string. For major type 4, an array, it is the number of data
308 * items in the array.
309 *
310 * Special encoding is used so that the argument values less than
311 * 24 can be encoded very compactly in the same byte as the major
312 * type is encoded. When the lower 5 bits of the initial byte have
313 * a value less than 24, then that is the value of the argument.
314 *
315 * If the lower 5 bits of the initial byte are less than 24, then
316 * they are the value of the argument. This allows integer values 0
317 * - 23 to be CBOR encoded in just one byte.
318 *
319 * When the value of lower 5 bits are 24, 25, 26, or 27 the
320 * argument is encoded in 1, 2, 4 or 8 bytes following the initial
321 * byte in network byte order (bit endian). The cases when it is
322 * 28, 29 and 30 are reserved for future use. The value 31 is a
323 * special indicator for indefinite length strings, arrays and
324 * maps.
325 *
326 * The lower 5 bits are called the "additional information."
327 *
328 * Thus the CBOR head may be 1, 2, 3, 5 or 9 bytes long.
329 *
330 * It is legal in CBOR to encode the argument using any of these
331 * lengths even if it could be encoded in a shorter length. For
332 * example it is legal to encode a data item representing the
333 * positive integer 0 in 9 bytes even though it could be encoded in
334 * only 0. This is legal to allow for for very simple code or even
335 * hardware-only implementations that just output a register
336 * directly.
337 *
338 * CBOR defines preferred encoding as the encoding of the argument
339 * in the smallest number of bytes needed to encode it.
340 *
341 * This function takes the major type and argument as inputs and
342 * outputs the encoded CBOR head for them. It does conversion to
343 * network byte order. It implements CBOR preferred encoding,
344 * outputting the shortest representation of the argument.
345 *
346 * == Endian Conversion ==
347 *
348 * This code does endian conversion without hton() or knowing the
349 * endianness of the machine by using masks and shifts. This avoids
350 * the dependency on hton() and the mess of figuring out how to
351 * find the machine's endianness.
352 *
353 * This is a good efficient implementation on little-endian
354 * machines. A faster and smaller implementation is possible on
355 * big-endian machines because CBOR/network byte order is
356 * big-endian. However big-endian machines are uncommon.
357 *
358 * On x86, this is about 150 bytes instead of 500 bytes for the
359 * original, more formal unoptimized code.
360 *
361 * This also does the CBOR preferred shortest encoding for integers
362 * and is called to do endian conversion for floats.
363 *
364 * It works backwards from the least significant byte to the most
365 * significant byte.
366 *
367 * == Floating Point ==
368 *
369 * When the major type is 7 and the 5 lower bits have the values
370 * 25, 26 or 27, the argument is a floating-point number that is
371 * half, single or double-precision. Note that it is not the
372 * conversion from a floating-point value to an integer value like
373 * converting 0x00 to 0.00, it is the interpretation of the bits in
374 * the argument as an IEEE 754 float-point number.
375 *
376 * Floating-point numbers must be converted to network byte
377 * order. That is accomplished here by exactly the same code that
378 * converts integer arguments to network byte order.
379 *
380 * There is preferred encoding for floating-point numbers in CBOR,
381 * but it is very different than for integers and it is not
382 * implemented here. Half-precision is preferred to
383 * single-precision which is preferred to double-precision only if
384 * the conversion can be performed without loss of precision. Zero
385 * and infinity can always be converted to half-precision, without
386 * loss but 3.141592653589 cannot.
387 *
388 * The way this function knows to not do preferred encoding on the
389 * argument passed here when it is a floating point number is the
390 * uMinLen parameter. It should be 2, 4 or 8 for half, single and
391 * double precision floating point values. This prevents and the
392 * incorrect removal of leading zeros when encoding arguments that
393 * are floating-point numbers.
394 *
395 * == Use of Type int and Static Analyzers ==
396 *
397 * The type int is used here for several variables because of the
398 * way integer promotion works in C for variables that are uint8_t
399 * or uint16_t. The basic rule is that they will always be promoted
400 * to int if they will fit. These integer variables here need only
401 * hold values less than 255 so they will always fit into an int.
402 *
403 * Most of values stored are never negative, so one might think
404 * that unsigned int would be more correct than int. However the C
405 * integer promotion rules only promote to unsigned int if the
406 * result won't fit into an int even if the promotion is for an
407 * unsigned variable like uint8_t.
408 *
409 * By declaring these int, there are few implicit conversions and
410 * fewer casts needed. Code size is reduced a little. It makes
411 * static analyzers happier.
412 *
413 * Note also that declaring these uint8_t won't stop integer wrap
414 * around if the code is wrong. It won't make the code more
415 * correct.
416 *
417 * https://stackoverflow.com/questions/46073295/implicit-type-promotion-rules
418 * https://stackoverflow.com/questions/589575/what-does-the-c-standard-state-the-size-of-int-long-type-to-be
419 *
420 * Code Reviewers: THIS FUNCTION DOES POINTER MATH
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800421 */
Laurence Lundbladeee851742020-01-08 08:37:05 -0800422
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800423 /* The buffer must have room for the largest CBOR HEAD + one
424 * extra. The one extra is needed for this code to work as it does
425 * a pre-decrement.
426 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700427 if(Buffer.len < QCBOR_HEAD_BUFFER_SIZE) {
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000428 return NULLUsefulBufC;
429 }
430
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800431 /* Pointer to last valid byte in the buffer */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700432 uint8_t * const pBufferEnd = &((uint8_t *)Buffer.ptr)[QCBOR_HEAD_BUFFER_SIZE-1];
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000433
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800434 /* Point to the last byte and work backwards */
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000435 uint8_t *pByte = pBufferEnd;
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800436 /* The 5 bits in the initial byte that are not the major type */
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800437 int nAdditionalInfo;
Laurence Lundblade2c40ab82018-12-30 14:20:29 -0800438
Laurence Lundbladecbd7d132024-05-19 11:11:22 -0700439#ifndef QCBOR_DISABLE_INDEFINITE_LENGTH_ARRAYS
Laurence Lundblade8c858ab2020-11-02 19:53:49 -0800440 if(uMajorType > QCBOR_INDEFINITE_LEN_TYPE_MODIFIER) {
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800441 /* Special case for start & end of indefinite length */
Laurence Lundblade8c858ab2020-11-02 19:53:49 -0800442 uMajorType = uMajorType - QCBOR_INDEFINITE_LEN_TYPE_MODIFIER;
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800443 /* This takes advantage of design of CBOR where additional info
444 * is 31 for both opening and closing indefinite length
445 * maps and arrays.
446 */
447 #if CBOR_SIMPLE_BREAK != LEN_IS_INDEFINITE
448 #error additional info for opening array not the same as for closing
449 #endif
Laurence Lundblade8c858ab2020-11-02 19:53:49 -0800450 nAdditionalInfo = CBOR_SIMPLE_BREAK;
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800451
Laurence Lundbladecbd7d132024-05-19 11:11:22 -0700452 } else
453#endif /* !QCBOR_DISABLE_INDEFINITE_LENGTH_ARRAYS */
454 if (uArgument < CBOR_TWENTY_FOUR && uMinLen == 0) {
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800455 /* Simple case where argument is < 24 */
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000456 nAdditionalInfo = (int)uArgument;
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800457
Laurence Lundblade04a859b2018-12-11 12:13:02 -0800458 } else {
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800459 /* This encodes the argument in 1,2,4 or 8 bytes. The outer loop
460 * runs once for 1 byte and 4 times for 8 bytes. The inner loop
461 * runs 1, 2 or 4 times depending on outer loop counter. This
462 * works backwards shifting 8 bits off the argument being
463 * encoded at a time until all bits from uArgument have been
464 * encoded and the minimum encoding size is reached. Minimum
465 * encoding size is for floating-point numbers that have some
466 * zero-value bytes that must be output.
Laurence Lundbladee9b00322018-12-30 10:33:26 -0800467 */
Laurence Lundblade04a859b2018-12-11 12:13:02 -0800468 static const uint8_t aIterate[] = {1,1,2,4};
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000469
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800470 /* uMinLen passed in is unsigned, but goes negative in the loop
471 * so it must be converted to a signed value.
472 */
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000473 int nMinLen = (int)uMinLen;
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800474 int i;
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000475 for(i = 0; uArgument || nMinLen > 0; i++) {
476 const int nIterations = (int)aIterate[i];
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800477 for(int j = 0; j < nIterations; j++) {
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000478 *--pByte = (uint8_t)(uArgument & 0xff);
479 uArgument = uArgument >> 8;
Laurence Lundblade04a859b2018-12-11 12:13:02 -0800480 }
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800481 nMinLen -= nIterations;
Laurence Lundblade04a859b2018-12-11 12:13:02 -0800482 }
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800483
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800484 nAdditionalInfo = LEN_IS_ONE_BYTE-1 + i;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700485 }
Laurence Lundbladef970f1d2018-12-14 01:44:23 -0800486
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800487 /* This expression integer-promotes to type int. The code above in
488 * function guarantees that nAdditionalInfo will never be larger
489 * than 0x1f. The caller may pass in a too-large uMajor type. The
Laurence Lundblade11654912024-05-09 11:49:24 -0700490 * conversion to uint8_t will cause an integer wrap around and
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800491 * incorrect CBOR will be generated, but no security issue will
492 * occur.
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800493 */
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800494 const int nInitialByte = (uMajorType << 5) + nAdditionalInfo;
495 *--pByte = (uint8_t)nInitialByte;
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800496
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000497#ifdef EXTRA_ENCODE_HEAD_CHECK
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800498 /* This is a sanity check that can be turned on to verify the
499 * pointer math in this function is not going wrong. Turn it on and
500 * run the whole test suite to perform the check.
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800501 */
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000502 if(pBufferEnd - pByte > 9 || pBufferEnd - pByte < 1 || pByte < (uint8_t *)buffer.ptr) {
503 return NULLUsefulBufC;
504 }
Laurence Lundbladee2c893c2020-12-26 17:41:53 -0800505#endif /* EXTRA_ENCODE_HEAD_CHECK */
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800506
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800507 /* Length will not go negative because the loops run for at most 8 decrements
508 * of pByte, only one other decrement is made, and the array is sized
509 * for this.
510 */
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000511 return (UsefulBufC){pByte, (size_t)(pBufferEnd - pByte)};
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700512}
513
514
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000515/**
Laurence Lundbladecbd7d132024-05-19 11:11:22 -0700516 * @brief Increment item counter for maps and arrays.
517 *
518 * @param pMe QCBOR encoding context.
519 *
520 * This is mostly a separate function to make code more readable and
521 * to have fewer occurrences of #ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
522 */
523static void
524QCBOREncode_Private_IncrementMapOrArrayCount(QCBOREncodeContext *pMe)
525{
526#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
527 if(pMe->uError == QCBOR_SUCCESS) {
528 pMe->uError = Nesting_Increment(&(pMe->nesting));
529 }
530#else
531 (void)Nesting_Increment(&(pMe->nesting));
532#endif /* !QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
533}
534
535
536/**
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800537 * @brief Append the CBOR head, the major type and argument
538 *
Laurence Lundbladecbd7d132024-05-19 11:11:22 -0700539 * @param pMe Encoder context.
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800540 * @param uMajorType Major type to insert.
541 * @param uArgument The argument (an integer value or a length).
Laurence Lundbladeeb3cdef2024-02-17 20:38:55 -0800542 * @param uMinLen Minimum number of bytes for encoding the CBOR argument.
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800543 *
544 * This formats the CBOR "head" and appends it to the output.
Laurence Lundbladecbd7d132024-05-19 11:11:22 -0700545 *
546 * This also increments the array/map item counter in most cases.
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000547 */
Laurence Lundbladecbd7d132024-05-19 11:11:22 -0700548void
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700549QCBOREncode_Private_AppendCBORHead(QCBOREncodeContext *pMe,
550 const uint8_t uMajorType,
551 const uint64_t uArgument,
552 const uint8_t uMinLen)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700553{
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800554 /* A stack buffer large enough for a CBOR head */
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000555 UsefulBuf_MAKE_STACK_UB (pBufferForEncodedHead, QCBOR_HEAD_BUFFER_SIZE);
556
557 UsefulBufC EncodedHead = QCBOREncode_EncodeHead(pBufferForEncodedHead,
558 uMajorType,
559 uMinLen,
560 uArgument);
561
562 /* No check for EncodedHead == NULLUsefulBufC is performed here to
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800563 * save object code. It is very clear that pBufferForEncodedHead is
564 * the correct size. If EncodedHead == NULLUsefulBufC then
565 * UsefulOutBuf_AppendUsefulBuf() will do nothing so there is no
566 * security hole introduced.
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000567 */
568
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700569 UsefulOutBuf_AppendUsefulBuf(&(pMe->OutBuf), EncodedHead);
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700570
Laurence Lundbladecbd7d132024-05-19 11:11:22 -0700571 if(!(uMajorType & QCBOR_INDEFINITE_LEN_TYPE_MODIFIER || uMajorType == CBOR_MAJOR_TYPE_TAG)) {
572 /* Don't increment the map count for tag or break because that is
573 * not needed. Don't do it for indefinite-length arrays and maps
574 * because it is done elsewhere. This is never called for definite-length
575 * arrays and maps.
576 */
577 QCBOREncode_Private_IncrementMapOrArrayCount(pMe);
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700578 }
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700579}
580
Laurence Lundblade56230d12018-11-01 11:14:51 +0700581
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700582/*
Laurence Lundblade2d493002024-02-01 11:09:17 -0700583 * Public functions for adding negative integers. See qcbor/qcbor_encode.h
584 */
Laurence Lundbladeeb3cdef2024-02-17 20:38:55 -0800585void
586QCBOREncode_AddNegativeUInt64(QCBOREncodeContext *pMe, const uint64_t uValue)
Laurence Lundblade2d493002024-02-01 11:09:17 -0700587{
Laurence Lundbladeeb3cdef2024-02-17 20:38:55 -0800588#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
589 if(pMe->uMode >= QCBOR_ENCODE_MODE_DCBOR) {
590 /* Never allowed in dCBOR */
591 pMe->uError = QCBOR_ERR_NOT_PREFERRED;
592 return;
593 }
594
595 if(!(pMe->uAllow & QCBOR_ENCODE_ALLOW_65_BIG_NEG)) {
596 pMe->uError = QCBOR_ERR_NOT_ALLOWED;
597 return;
598 }
599#endif /* QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
600
Laurence Lundblade2d493002024-02-01 11:09:17 -0700601 QCBOREncode_Private_AppendCBORHead(pMe, CBOR_MAJOR_TYPE_NEGATIVE_INT, uValue, 0);
Laurence Lundblade2d493002024-02-01 11:09:17 -0700602}
603
604
605/*
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800606 * Public functions for adding signed integers. See qcbor/qcbor_encode.h
Laurence Lundblade067035b2018-11-28 17:35:25 -0800607 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700608void
609QCBOREncode_AddInt64(QCBOREncodeContext *pMe, const int64_t nNum)
Laurence Lundblade067035b2018-11-28 17:35:25 -0800610{
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800611 uint8_t uMajorType;
612 uint64_t uValue;
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800613
614 if(nNum < 0) {
Laurence Lundblade9c5c0ef2022-12-23 17:56:27 -0700615 /* In CBOR -1 encodes as 0x00 with major type negative int.
616 * First add one as a signed integer because that will not
Laurence Lundblade2d493002024-02-01 11:09:17 -0700617 * overflow. Then change the sign as needed for encoding (the
Laurence Lundblade9c5c0ef2022-12-23 17:56:27 -0700618 * opposite order, changing the sign and subtracting, can cause
Laurence Lundblade2d493002024-02-01 11:09:17 -0700619 * an overflow when encoding INT64_MIN). */
Laurence Lundblade9c5c0ef2022-12-23 17:56:27 -0700620 int64_t nTmp = nNum + 1;
621 uValue = (uint64_t)-nTmp;
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800622 uMajorType = CBOR_MAJOR_TYPE_NEGATIVE_INT;
623 } else {
624 uValue = (uint64_t)nNum;
625 uMajorType = CBOR_MAJOR_TYPE_POSITIVE_INT;
626 }
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700627 QCBOREncode_Private_AppendCBORHead(pMe, uMajorType, uValue, 0);
Laurence Lundblade067035b2018-11-28 17:35:25 -0800628}
629
630
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700631/**
632 * @brief Semi-private method to add a buffer full of bytes to encoded output.
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800633 *
Laurence Lundbladecbd7d132024-05-19 11:11:22 -0700634 * @param[in] pMe The encoding context to add the string to.
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700635 * @param[in] uMajorType The CBOR major type of the bytes.
636 * @param[in] Bytes The bytes to add.
637 *
Laurence Lundbladecbd7d132024-05-19 11:11:22 -0700638 * Called by inline functions to add text and byte strings.
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700639 *
Laurence Lundbladecbd7d132024-05-19 11:11:22 -0700640 * (This used to support QCBOREncode_AddEncoded() and
641 * QCBOREncode_AddBytesLenOnly(), but that was pulled out to make this
642 * smaller. This is one of the most used methods and they are some of
643 * the least used).
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700644 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700645void
646QCBOREncode_Private_AddBuffer(QCBOREncodeContext *pMe,
647 const uint8_t uMajorType,
648 const UsefulBufC Bytes)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700649{
Laurence Lundbladecbd7d132024-05-19 11:11:22 -0700650 QCBOREncode_Private_AppendCBORHead(pMe, uMajorType, Bytes.len, 0);
Laurence Lundblade15b93d42024-02-07 17:39:10 -0800651 UsefulOutBuf_AppendUsefulBuf(&(pMe->OutBuf), Bytes);
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700652}
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700653
Laurence Lundbladecafcfe12018-10-31 21:59:50 +0700654
Laurence Lundblade55a24832018-10-30 04:35:08 +0700655/*
Laurence Lundbladecbd7d132024-05-19 11:11:22 -0700656 * Public functions for adding raw encoded CBOR. See qcbor/qcbor_encode.h
Laurence Lundblade55a24832018-10-30 04:35:08 +0700657 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700658void
Laurence Lundbladecbd7d132024-05-19 11:11:22 -0700659QCBOREncode_AddEncoded(QCBOREncodeContext *pMe, const UsefulBufC Encoded)
Laurence Lundblade55a24832018-10-30 04:35:08 +0700660{
Laurence Lundbladecbd7d132024-05-19 11:11:22 -0700661 UsefulOutBuf_AppendUsefulBuf(&(pMe->OutBuf), Encoded);
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700662 QCBOREncode_Private_IncrementMapOrArrayCount(pMe);
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700663}
664
665
Laurence Lundbladeb275cdc2020-07-12 12:34:38 -0700666#ifndef QCBOR_DISABLE_PREFERRED_FLOAT
Laurence Lundblade8d9e0cd2024-05-25 18:12:19 -0700667/**
668 * @brief Semi-private method to add a double using preferred encoding.
669 *
670 * @param[in] pMe The encode context.
671 * @param[in] dNum The double to add.
672 *
673 * This converts the double to a float or half-precision if it can be done
674 * without a loss of precision. See QCBOREncode_AddDouble().
Laurence Lundbladebb1062e2019-08-12 23:28:54 -0700675 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700676void
Laurence Lundblade70fc1252024-05-31 10:57:28 -0700677QCBOREncode_Private_AddPreferredDouble(QCBOREncodeContext *pMe, double dNum)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700678{
Laurence Lundbladeeb3cdef2024-02-17 20:38:55 -0800679 IEEE754_union FloatResult;
680 bool bNoNaNPayload;
681 struct IEEE754_ToInt IntResult;
Laurence Lundblade2feb1e12020-07-15 03:50:45 -0700682
Laurence Lundbladeeb3cdef2024-02-17 20:38:55 -0800683#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Laurence Lundblade9b2ae8a2024-07-12 11:00:20 -0700684 if(IEEE754_DoubleHasNaNPayload(dNum) && !(pMe->uAllow & QCBOR_ENCODE_ALLOW_NAN_PAYLOAD)) {
Laurence Lundbladeeb3cdef2024-02-17 20:38:55 -0800685 pMe->uError = QCBOR_ERR_NOT_ALLOWED;
686 return;
687 }
688#endif /* ! QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
689
690 if(pMe->uMode == QCBOR_ENCODE_MODE_DCBOR) {
691 IntResult = IEEE754_DoubleToInt(dNum);
692 switch(IntResult.type) {
693 case IEEE754_ToInt_IS_INT:
694 QCBOREncode_AddInt64(pMe, IntResult.integer.is_signed);
695 return;
696 case IEEE754_ToInt_IS_UINT:
697 QCBOREncode_AddUInt64(pMe, IntResult.integer.un_signed);
698 return;
699 case IEEE754_ToInt_NaN:
700 dNum = NAN;
701 bNoNaNPayload = true;
702 break;
703 case IEEE754_ToInt_NO_CONVERSION:
704 bNoNaNPayload = true;
705 }
706 } else {
707 bNoNaNPayload = false;
708 }
709
710 FloatResult = IEEE754_DoubleToSmaller(dNum, true, bNoNaNPayload);
711
712 QCBOREncode_Private_AddType7(pMe, (uint8_t)FloatResult.uSize, FloatResult.uValue);
Laurence Lundbladeb275cdc2020-07-12 12:34:38 -0700713}
Laurence Lundblade9682a532020-06-06 18:33:04 -0700714
Laurence Lundbladeb275cdc2020-07-12 12:34:38 -0700715
Laurence Lundblade8d9e0cd2024-05-25 18:12:19 -0700716/**
717 * @brief Semi-private method to add a float using preferred encoding.
718 *
719 * @param[in] pMe The encode context.
720 * @param[in] fNum The float to add.
721 *
722 * This converts the float to a half-precision if it can be done
723 * without a loss of precision. See QCBOREncode_AddFloat().
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800724 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700725void
Laurence Lundblade70fc1252024-05-31 10:57:28 -0700726QCBOREncode_Private_AddPreferredFloat(QCBOREncodeContext *pMe, float fNum)
Laurence Lundbladeb275cdc2020-07-12 12:34:38 -0700727{
Laurence Lundbladeeb3cdef2024-02-17 20:38:55 -0800728 IEEE754_union FloatResult;
729 bool bNoNaNPayload;
730 struct IEEE754_ToInt IntResult;
Laurence Lundblade2feb1e12020-07-15 03:50:45 -0700731
Laurence Lundbladeeb3cdef2024-02-17 20:38:55 -0800732#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Laurence Lundblade9b2ae8a2024-07-12 11:00:20 -0700733 if(IEEE754_SingleHasNaNPayload(fNum) && !(pMe->uAllow & QCBOR_ENCODE_ALLOW_NAN_PAYLOAD)) {
Laurence Lundbladeeb3cdef2024-02-17 20:38:55 -0800734 pMe->uError = QCBOR_ERR_NOT_ALLOWED;
735 return;
736 }
737#endif /* ! QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
738
Laurence Lundbladeeb3cdef2024-02-17 20:38:55 -0800739 if(pMe->uMode == QCBOR_ENCODE_MODE_DCBOR) {
740 IntResult = IEEE754_SingleToInt(fNum);
741 switch(IntResult.type) {
742 case IEEE754_ToInt_IS_INT:
743 QCBOREncode_AddInt64(pMe, IntResult.integer.is_signed);
744 return;
745 case IEEE754_ToInt_IS_UINT:
746 QCBOREncode_AddUInt64(pMe, IntResult.integer.un_signed);
747 return;
748 case IEEE754_ToInt_NaN:
749 fNum = NAN;
750 bNoNaNPayload = true;
751 break;
752 case IEEE754_ToInt_NO_CONVERSION:
753 bNoNaNPayload = true;
754 }
755 } else {
756 bNoNaNPayload = false;
757 }
758
759 FloatResult = IEEE754_SingleToHalf(fNum, bNoNaNPayload);
760
761 QCBOREncode_Private_AddType7(pMe, (uint8_t)FloatResult.uSize, FloatResult.uValue);
Laurence Lundblade067035b2018-11-28 17:35:25 -0800762}
Laurence Lundblade8d9e0cd2024-05-25 18:12:19 -0700763#endif /* !QCBOR_DISABLE_PREFERRED_FLOAT */
Laurence Lundblade067035b2018-11-28 17:35:25 -0800764
Laurence Lundblade067035b2018-11-28 17:35:25 -0800765
766
Laurence Lundbladedd6e76e2021-03-10 01:54:01 -0700767#ifndef QCBOR_DISABLE_EXP_AND_MANTISSA
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700768/**
769 * @brief Semi-private method to add bigfloats and decimal fractions.
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800770 *
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700771 * @param[in] pMe The encoding context to add the value to.
772 * @param[in] uTag The type 6 tag indicating what this is to be.
773 * @param[in] BigNumMantissa Is @ref NULLUsefulBufC if mantissa is an
774 * @c int64_t or the actual big number mantissa
775 * if not.
776 * @param[in] bBigNumIsNegative This is @c true if the big number is negative.
777 * @param[in] nMantissa The @c int64_t mantissa if it is not a big number.
778 * @param[in] nExponent The exponent.
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800779 *
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700780 * This outputs either the @ref CBOR_TAG_DECIMAL_FRACTION or
781 * @ref CBOR_TAG_BIGFLOAT tag. if @c uTag is @ref CBOR_TAG_INVALID64,
782 * then this outputs the "borrowed" content format.
783 *
784 * The tag content output by this is an array with two members, the
785 * exponent and then the mantissa. The mantissa can be either a big
786 * number or an @c int64_t.
787 *
788 * This implementation cannot output an exponent further from 0 than
789 * @c INT64_MAX.
790 *
791 * To output a mantissa that is between INT64_MAX and UINT64_MAX from 0,
792 * it must be as a big number.
793 *
794 * Typically, QCBOREncode_AddDecimalFraction(), QCBOREncode_AddBigFloat(),
795 * QCBOREncode_AddDecimalFractionBigNum() or QCBOREncode_AddBigFloatBigNum()
796 * is called instead of this.
Laurence Lundblade59289e52019-12-30 13:44:37 -0800797 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700798void
799QCBOREncode_Private_AddExpMantissa(QCBOREncodeContext *pMe,
800 const uint64_t uTag,
801 const UsefulBufC BigNumMantissa,
802 const bool bBigNumIsNegative,
803 const int64_t nMantissa,
804 const int64_t nExponent)
Laurence Lundblade59289e52019-12-30 13:44:37 -0800805{
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800806 /* This is for encoding either a big float or a decimal fraction,
807 * both of which are an array of two items, an exponent and a
808 * mantissa. The difference between the two is that the exponent
809 * is base-2 for big floats and base-10 for decimal fractions, but
810 * that has no effect on the code here.
Laurence Lundbladeee851742020-01-08 08:37:05 -0800811 */
Laurence Lundbladeae66d3f2020-09-14 18:12:08 -0700812 if(uTag != CBOR_TAG_INVALID64) {
813 QCBOREncode_AddTag(pMe, uTag);
814 }
Laurence Lundblade59289e52019-12-30 13:44:37 -0800815 QCBOREncode_OpenArray(pMe);
816 QCBOREncode_AddInt64(pMe, nExponent);
817 if(!UsefulBuf_IsNULLC(BigNumMantissa)) {
818 if(bBigNumIsNegative) {
819 QCBOREncode_AddNegativeBignum(pMe, BigNumMantissa);
820 } else {
821 QCBOREncode_AddPositiveBignum(pMe, BigNumMantissa);
822 }
823 } else {
824 QCBOREncode_AddInt64(pMe, nMantissa);
825 }
826 QCBOREncode_CloseArray(pMe);
827}
Laurence Lundbladedd6e76e2021-03-10 01:54:01 -0700828#endif /* QCBOR_DISABLE_EXP_AND_MANTISSA */
Laurence Lundblade59289e52019-12-30 13:44:37 -0800829
830
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700831/**
832 * @brief Semi-private method to open a map, array or bstr-wrapped CBOR
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800833 *
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700834 * @param[in] pMe The context to add to.
835 * @param[in] uMajorType The major CBOR type to close
836 *
837 * Call QCBOREncode_OpenArray(), QCBOREncode_OpenMap() or
838 * QCBOREncode_BstrWrap() instead of this.
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700839 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700840void
841QCBOREncode_Private_OpenMapOrArray(QCBOREncodeContext *pMe,
842 const uint8_t uMajorType)
Laurence Lundblade067035b2018-11-28 17:35:25 -0800843{
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800844 /* Add one item to the nesting level we are in for the new map or array */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700845 QCBOREncode_Private_IncrementMapOrArrayCount(pMe);
Laurence Lundbladed39cd392019-01-11 18:17:38 -0800846
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800847 /* The offset where the length of an array or map will get written
848 * is stored in a uint32_t, not a size_t to keep stack usage
849 * smaller. This checks to be sure there is no wrap around when
850 * recording the offset. Note that on 64-bit machines CBOR larger
851 * than 4GB can be encoded as long as no array/map offsets occur
852 * past the 4GB mark, but the public interface says that the
853 * maximum is 4GB to keep the discussion simpler.
854 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700855 size_t uEndPosition = UsefulOutBuf_GetEndPosition(&(pMe->OutBuf));
Laurence Lundbladed39cd392019-01-11 18:17:38 -0800856
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800857 /* QCBOR_MAX_ARRAY_OFFSET is slightly less than UINT32_MAX so this
858 * code can run on a 32-bit machine and tests can pass on a 32-bit
859 * machine. If it was exactly UINT32_MAX, then this code would not
860 * compile or run on a 32-bit machine and an #ifdef or some machine
861 * size detection would be needed reducing portability.
862 */
Laurence Lundblade3e0a45c2020-11-05 11:12:04 -0800863 if(uEndPosition >= QCBOR_MAX_ARRAY_OFFSET) {
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700864 pMe->uError = QCBOR_ERR_BUFFER_TOO_LARGE;
Laurence Lundblade3e0a45c2020-11-05 11:12:04 -0800865
866 } else {
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800867 /* Increase nesting level because this is a map or array. Cast
868 * from size_t to uin32_t is safe because of check above.
869 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700870 pMe->uError = Nesting_Increase(&(pMe->nesting), uMajorType, (uint32_t)uEndPosition);
Laurence Lundblade1ef8b2d2018-12-14 23:13:34 -0800871 }
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700872}
873
Laurence Lundblade59289e52019-12-30 13:44:37 -0800874
Laurence Lundbladecbd7d132024-05-19 11:11:22 -0700875#ifndef QCBOR_DISABLE_INDEFINITE_LENGTH_ARRAYS
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700876/**
877 * @brief Semi-private method to open a map, array with indefinite length
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800878 *
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700879 * @param[in] pMe The context to add to.
880 * @param[in] uMajorType The major CBOR type to close
881 *
882 * Call QCBOREncode_OpenArrayIndefiniteLength() or
883 * QCBOREncode_OpenMapIndefiniteLength() instead of this.
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800884 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700885void
886QCBOREncode_Private_OpenMapOrArrayIndefiniteLength(QCBOREncodeContext *pMe,
887 const uint8_t uMajorType)
Jan Jongboom4a93a662019-07-25 08:44:58 +0200888{
Laurence Lundbladeeb3cdef2024-02-17 20:38:55 -0800889#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
890 if(pMe->uMode >= QCBOR_ENCODE_MODE_PREFERRED) {
891 pMe->uError = QCBOR_ERR_NOT_PREFERRED;
892 return;
893 }
894#endif /* ! QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800895 /* Insert the indefinite length marker (0x9f for arrays, 0xbf for maps) */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700896 QCBOREncode_Private_AppendCBORHead(pMe, uMajorType, 0, 0);
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800897
898 /* Call the definite-length opener just to do the bookkeeping for
899 * nesting. It will record the position of the opening item in the
900 * encoded output but this is not used when closing this open.
901 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700902 QCBOREncode_Private_OpenMapOrArray(pMe, uMajorType);
Jan Jongboom4a93a662019-07-25 08:44:58 +0200903}
Laurence Lundbladecbd7d132024-05-19 11:11:22 -0700904#endif
905
906
907/**
908 * @brief Check for errors when decreasing nesting.
909 *
910 * @param pMe QCBOR encoding context.
911 * @param uMajorType The major type of the nesting.
912 *
913 * Check that there is no previous error, that there is actually some
914 * nesting and that the major type of the opening of the nesting
915 * matches the major type of the nesting being closed.
916 *
917 * This is called when closing maps, arrays, byte string wrapping and
918 * open/close of byte strings.
919 */
920static bool
921QCBOREncode_Private_CheckDecreaseNesting(QCBOREncodeContext *pMe,
922 const uint8_t uMajorType)
923{
924#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
925 if(pMe->uError != QCBOR_SUCCESS) {
926 return true;
927 }
928
929 if(!Nesting_IsInNest(&(pMe->nesting))) {
930 pMe->uError = QCBOR_ERR_TOO_MANY_CLOSES;
931 return true;
932 }
933
934 if(Nesting_GetMajorType(&(pMe->nesting)) != uMajorType) {
935 pMe->uError = QCBOR_ERR_CLOSE_MISMATCH;
936 return true;
937 }
938
939#else /* !QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
940 /* None of these checks are performed if the encode guards are
941 * turned off as they all relate to correct calling.
942 *
943 * Turning off all these checks does not turn off any checking for
944 * buffer overflows or pointer issues.
945 */
946
947 (void)uMajorType;
948 (void)pMe;
949#endif /* !QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
950
951 return false;
952}
953
954
955/**
956 * @brief Insert the CBOR head for a map, array or wrapped bstr
957 *
958 * @param pMe QCBOR encoding context.
959 * @param uMajorType One of CBOR_MAJOR_TYPE_XXXX.
960 * @param uLen The length of the data item.
961 *
962 * When an array, map or bstr was opened, nothing was done but note
963 * the position. This function goes back to that position and inserts
964 * the CBOR Head with the major type and length.
965 */
966static void
967QCBOREncode_Private_CloseAggregate(QCBOREncodeContext *pMe,
968 uint8_t uMajorType,
969 size_t uLen)
970{
971 if(QCBOREncode_Private_CheckDecreaseNesting(pMe, uMajorType)) {
972 return;
973 }
974
975 if(uMajorType == CBOR_MAJOR_NONE_TYPE_OPEN_BSTR) {
976 uMajorType = CBOR_MAJOR_TYPE_BYTE_STRING;
977 }
978
979 /* A stack buffer large enough for a CBOR head (9 bytes) */
980 UsefulBuf_MAKE_STACK_UB(pBufferForEncodedHead, QCBOR_HEAD_BUFFER_SIZE);
981
982 UsefulBufC EncodedHead = QCBOREncode_EncodeHead(pBufferForEncodedHead,
983 uMajorType,
984 0,
985 uLen);
986
987 /* No check for EncodedHead == NULLUsefulBufC is performed here to
988 * save object code. It is very clear that pBufferForEncodedHead is
989 * the correct size. If EncodedHead == NULLUsefulBufC then
990 * UsefulOutBuf_InsertUsefulBuf() will do nothing so there is no
991 * security hole introduced.
992 */
993 UsefulOutBuf_InsertUsefulBuf(&(pMe->OutBuf),
994 EncodedHead,
995 Nesting_GetStartPos(&(pMe->nesting)));
996
997 Nesting_Decrease(&(pMe->nesting));
998}
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700999
Laurence Lundbladeee851742020-01-08 08:37:05 -08001000
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001001/**
Laurence Lundbladeeb3cdef2024-02-17 20:38:55 -08001002 * @brief Semi-private method to close a map, array or bstr wrapped CBOR.
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001003 *
1004 * @param[in] pMe The context to add to.
1005 * @param[in] uMajorType The major CBOR type to close.
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001006 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001007void
1008QCBOREncode_Private_CloseMapOrArray(QCBOREncodeContext *pMe,
1009 const uint8_t uMajorType)
Laurence Lundbladea954db92018-09-28 19:27:31 -07001010{
Laurence Lundbladecbd7d132024-05-19 11:11:22 -07001011 QCBOREncode_Private_CloseAggregate(pMe, uMajorType, Nesting_GetCount(&(pMe->nesting)));
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +00001012}
Laurence Lundblade3aee3a32018-12-17 16:17:45 -08001013
Laurence Lundblade3aee3a32018-12-17 16:17:45 -08001014
Laurence Lundbladeeb3cdef2024-02-17 20:38:55 -08001015/**
1016 * @brief Private method to close a map without sorting.
1017 *
1018 * @param[in] pMe The encode context with map to close.
1019 *
1020 * See QCBOREncode_SerializationCDE() implemention for explantion for why
1021 * this exists in this form.
1022 */
1023static void
1024QCBOREncode_Private_CloseMapUnsorted(QCBOREncodeContext *pMe)
1025{
1026 QCBOREncode_Private_CloseMapOrArray(pMe, CBOR_MAJOR_TYPE_MAP);
1027}
1028
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001029
1030/**
1031 * @brief Decode a CBOR item head.
1032 *
1033 * @param[in] pUInBuf UsefulInputBuf to read from.
1034 * @param[out] pnMajorType Major type of decoded head.
1035 * @param[out] puArgument Argument of decoded head.
1036 * @param[out] pnAdditionalInfo Additional info from decoded head.
1037 *
1038 * @return SUCCESS if a head was decoded
1039 * HIT_END if there were not enough bytes to decode a head
1040 * UNSUPPORTED if the decoded item is not one that is supported
1041 *
1042 * This is copied from qcbor_decode.c rather than referenced. This
1043 * makes the core decoder 60 bytes smaller because it gets inlined.
1044 * It would not get inlined if it was referenced. It is important to
1045 * make the core decoder as small as possible. The copy here does make
1046 * map sorting 200 bytes bigger, but map sorting is rarely used in
1047 * environments that need small object code. It would also make
1048 * qcbor_encode.c depend on qcbor_decode.c
1049 *
1050 * This is also super stable and tested. It implements the very
1051 * well-defined part of CBOR that will never change. So this won't
1052 * change.
1053 */
1054static QCBORError
1055QCBOREncodePriv_DecodeHead(UsefulInputBuf *pUInBuf,
1056 int *pnMajorType,
1057 uint64_t *puArgument,
1058 int *pnAdditionalInfo)
1059{
1060 QCBORError uReturn;
1061
1062 /* Get the initial byte that every CBOR data item has and break it
1063 * down. */
1064 const int nInitialByte = (int)UsefulInputBuf_GetByte(pUInBuf);
1065 const int nTmpMajorType = nInitialByte >> 5;
1066 const int nAdditionalInfo = nInitialByte & 0x1f;
1067
1068 /* Where the argument accumulates */
1069 uint64_t uArgument;
1070
1071 if(nAdditionalInfo >= LEN_IS_ONE_BYTE && nAdditionalInfo <= LEN_IS_EIGHT_BYTES) {
1072 /* Need to get 1,2,4 or 8 additional argument bytes. Map
1073 * LEN_IS_ONE_BYTE..LEN_IS_EIGHT_BYTES to actual length.
1074 */
1075 static const uint8_t aIterate[] = {1,2,4,8};
1076
1077 /* Loop getting all the bytes in the argument */
1078 uArgument = 0;
1079 for(int i = aIterate[nAdditionalInfo - LEN_IS_ONE_BYTE]; i; i--) {
1080 /* This shift and add gives the endian conversion. */
1081 uArgument = (uArgument << 8) + UsefulInputBuf_GetByte(pUInBuf);
1082 }
1083 } else if(nAdditionalInfo >= ADDINFO_RESERVED1 && nAdditionalInfo <= ADDINFO_RESERVED3) {
1084 /* The reserved and thus-far unused additional info values */
1085 uReturn = QCBOR_ERR_UNSUPPORTED;
1086 goto Done;
1087 } else {
1088 /* Less than 24, additional info is argument or 31, an
1089 * indefinite-length. No more bytes to get.
1090 */
1091 uArgument = (uint64_t)nAdditionalInfo;
1092 }
1093
1094 if(UsefulInputBuf_GetError(pUInBuf)) {
1095 uReturn = QCBOR_ERR_HIT_END;
1096 goto Done;
1097 }
1098
1099 /* All successful if arrived here. */
1100 uReturn = QCBOR_SUCCESS;
1101 *pnMajorType = nTmpMajorType;
1102 *puArgument = uArgument;
1103 *pnAdditionalInfo = nAdditionalInfo;
1104
1105Done:
1106 return uReturn;
1107}
1108
1109
1110/**
1111 * @brief Consume the next item from a UsefulInputBuf.
1112 *
1113 * @param[in] pInBuf UsefulInputBuf from which to consume item.
1114 *
1115 * Recursive, but stack usage is light and encoding depth limit
1116 */
1117static QCBORError
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001118QCBOR_Private_ConsumeNext(UsefulInputBuf *pInBuf)
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001119{
1120 int nMajor;
1121 uint64_t uArgument;
1122 int nAdditional;
1123 uint16_t uItemCount;
1124 uint16_t uMul;
1125 uint16_t i;
1126 QCBORError uCBORError;
1127
1128 uCBORError = QCBOREncodePriv_DecodeHead(pInBuf, &nMajor, &uArgument, &nAdditional);
1129 if(uCBORError != QCBOR_SUCCESS) {
1130 return uCBORError;
1131 }
1132
1133 uMul = 1;
1134
1135 switch(nMajor) {
1136 case CBOR_MAJOR_TYPE_POSITIVE_INT: /* Major type 0 */
1137 case CBOR_MAJOR_TYPE_NEGATIVE_INT: /* Major type 1 */
1138 break;
1139
1140 case CBOR_MAJOR_TYPE_SIMPLE:
1141 return uArgument == CBOR_SIMPLE_BREAK ? 1 : 0;
1142 break;
1143
1144 case CBOR_MAJOR_TYPE_BYTE_STRING:
1145 case CBOR_MAJOR_TYPE_TEXT_STRING:
1146 if(nAdditional == LEN_IS_INDEFINITE) {
1147 /* Segments of indefinite length */
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001148 while(QCBOR_Private_ConsumeNext(pInBuf) == 0);
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001149 }
1150 (void)UsefulInputBuf_GetBytes(pInBuf, uArgument);
1151 break;
1152
1153 case CBOR_MAJOR_TYPE_TAG:
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001154 QCBOR_Private_ConsumeNext(pInBuf);
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001155 break;
1156
1157 case CBOR_MAJOR_TYPE_MAP:
1158 uMul = 2;
1159 /* Fallthrough */
1160 case CBOR_MAJOR_TYPE_ARRAY:
1161 uItemCount = (uint16_t)uArgument * uMul;
1162 if(nAdditional == LEN_IS_INDEFINITE) {
1163 uItemCount = UINT16_MAX;
1164 }
1165 for(i = uItemCount; i > 0; i--) {
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001166 if(QCBOR_Private_ConsumeNext(pInBuf)) {
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001167 /* End of indefinite length */
1168 break;
1169 }
1170 }
1171 break;
1172 }
1173
1174 return QCBOR_SUCCESS;
1175}
1176
1177
1178/**
Laurence Lundbladedee0d4e2024-03-03 13:46:33 -07001179 * @brief Decoded next item to get its lengths.
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001180 *
1181 * Decode the next item in map no matter what type it is. It works
1182 * recursively when an item is a map or array It returns offset just
1183 * past the item decoded or zero there are no more items in the output
1184 * buffer.
1185 *
1186 * This doesn't distinguish between end of the input and an error
1187 * because it is used to decode stuff we encoded into a buffer, not
1188 * stuff that came in from outside. We still want a check for safety
1189 * in case of bugs here, but it is OK to report end of input on error.
1190 */
Laurence Lundbladedee0d4e2024-03-03 13:46:33 -07001191struct ItemLens {
1192 uint32_t uLabelLen;
1193 uint32_t uItemLen;
1194};
1195
1196static struct ItemLens
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001197QCBOREncode_Private_DecodeNextInMap(QCBOREncodeContext *pMe, uint32_t uStart)
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001198{
Laurence Lundbladedee0d4e2024-03-03 13:46:33 -07001199 UsefulInputBuf InBuf;
1200 UsefulBufC EncodedMapBytes;
1201 QCBORError uCBORError;
1202 struct ItemLens Result;
1203
1204 Result.uLabelLen = 0;
1205 Result.uItemLen = 0;
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001206
1207 EncodedMapBytes = UsefulOutBuf_OutUBufOffset(&(pMe->OutBuf), uStart);
1208 if(UsefulBuf_IsNULLC(EncodedMapBytes)) {
Laurence Lundbladedee0d4e2024-03-03 13:46:33 -07001209 return Result;
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001210 }
1211
1212 UsefulInputBuf_Init(&InBuf, EncodedMapBytes);
1213
1214 /* This is always used on maps, so consume two, the label and the value */
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001215 uCBORError = QCBOR_Private_ConsumeNext(&InBuf);
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001216 if(uCBORError) {
Laurence Lundbladedee0d4e2024-03-03 13:46:33 -07001217 return Result;
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001218 }
1219
1220 /* Cast is safe because this is QCBOR which limits sizes to UINT32_MAX */
Laurence Lundbladedee0d4e2024-03-03 13:46:33 -07001221 Result.uLabelLen = (uint32_t)UsefulInputBuf_Tell(&InBuf);
1222
1223 uCBORError = QCBOR_Private_ConsumeNext(&InBuf);
1224 if(uCBORError) {
1225 Result.uLabelLen = 0;
1226 return Result;
1227 }
1228
1229 Result.uItemLen = (uint32_t)UsefulInputBuf_Tell(&InBuf);
1230
1231 /* Cast is safe because this is QCBOR which limits sizes to UINT32_MAX */
1232 return Result;
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001233}
1234
1235
1236/**
1237 * @brief Sort items lexographically by encoded labels.
1238 *
1239 * @param[in] pMe Encoding context.
1240 * @param[in] uStart Offset in outbuf of first item for sorting.
1241 *
1242 * This reaches into the UsefulOutBuf in the encoding context and
1243 * sorts encoded CBOR items. The byte offset start of the items is at
1244 * @c uStart and it goes to the end of valid bytes in the
1245 * UsefulOutBuf.
1246 */
1247static void
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001248QCBOREncode_Private_SortMap(QCBOREncodeContext *pMe, uint32_t uStart)
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001249{
Laurence Lundbladedee0d4e2024-03-03 13:46:33 -07001250 bool bSwapped;
1251 int nComparison;
1252 uint32_t uStart1;
1253 uint32_t uStart2;
1254 struct ItemLens Lens1;
1255 struct ItemLens Lens2;
1256
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001257
1258 if(pMe->uError != QCBOR_SUCCESS) {
1259 return;
1260 }
1261
1262 /* Bubble sort because the sizes of all the items are not the
1263 * same. It works with adjacent pairs so the swap is not too
1264 * difficult even though sizes are different.
1265 *
1266 * While bubble sort is n-squared, it seems OK here because n will
1267 * usually be small and the comparison and swap functions aren't
1268 * too CPU intensive.
1269 *
1270 * Another approach would be to have an array of offsets to the
1271 * items. However this requires memory allocation and the swap
1272 * operation for quick sort or such is complicated because the item
1273 * sizes are not the same and overlap may occur in the bytes being
1274 * swapped.
1275 */
Laurence Lundbladedee0d4e2024-03-03 13:46:33 -07001276 do { /* Loop until nothing was swapped */
1277 Lens1 = QCBOREncode_Private_DecodeNextInMap(pMe, uStart);
1278 if(Lens1.uLabelLen == 0) {
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001279 /* It's an empty map. Nothing to do. */
1280 break;
1281 }
1282 uStart1 = uStart;
Laurence Lundbladedee0d4e2024-03-03 13:46:33 -07001283 uStart2 = uStart1 + Lens1.uItemLen;
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001284 bSwapped = false;
1285
1286 while(1) {
Laurence Lundbladedee0d4e2024-03-03 13:46:33 -07001287 Lens2 = QCBOREncode_Private_DecodeNextInMap(pMe, uStart2);
1288 if(Lens2.uLabelLen == 0) {
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001289 break;
1290 }
1291
Laurence Lundbladedee0d4e2024-03-03 13:46:33 -07001292 nComparison = UsefulOutBuf_Compare(&(pMe->OutBuf),
1293 uStart1, Lens1.uLabelLen,
1294 uStart2, Lens2.uLabelLen);
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001295 if(nComparison < 0) {
Laurence Lundbladedee0d4e2024-03-03 13:46:33 -07001296 UsefulOutBuf_Swap(&(pMe->OutBuf), uStart1, uStart2, uStart2 + Lens2.uItemLen);
1297 uStart1 = uStart1 + Lens2.uItemLen; /* item 2 now in position of item 1 */
1298 /* Lens1 is still valid as Lens1 for the next loop */
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001299 bSwapped = true;
Laurence Lundbladedee0d4e2024-03-03 13:46:33 -07001300 } else if(nComparison > 0) {
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001301 uStart1 = uStart2;
Laurence Lundbladedee0d4e2024-03-03 13:46:33 -07001302 Lens1 = Lens2;
1303 } else /* nComparison == 0 */ {
1304 pMe->uError = QCBOR_ERR_DUPLICATE_LABEL;
1305 return;
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001306 }
Laurence Lundbladedee0d4e2024-03-03 13:46:33 -07001307 uStart2 = uStart2 + Lens2.uItemLen;
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001308 }
1309 } while(bSwapped);
1310}
1311
1312
1313/*
1314 * Public functions for closing sorted maps. See qcbor/qcbor_encode.h
1315 */
Laurence Lundbladedee0d4e2024-03-03 13:46:33 -07001316void
1317QCBOREncode_CloseAndSortMap(QCBOREncodeContext *pMe)
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001318{
1319 uint32_t uStart;
1320
1321 /* The Header for the map we are about to sort hasn't been
1322 * inserted yet, so uStart is the position of the first item
1323 * and the end out the UsefulOutBuf data is the end of the
1324 * items we are about to sort.
1325 */
1326 uStart = Nesting_GetStartPos(&(pMe->nesting));
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001327 QCBOREncode_Private_SortMap(pMe, uStart);
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001328
Laurence Lundblade70fc1252024-05-31 10:57:28 -07001329 QCBOREncode_Private_CloseAggregate(pMe, CBOR_MAJOR_TYPE_MAP, Nesting_GetCount(&(pMe->nesting)));
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001330}
1331
1332
Laurence Lundbladed3f07842024-06-19 13:05:07 -07001333#ifndef QCBOR_DISABLE_INDEFINITE_LENGTH_ARRAYS
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001334/*
1335 * Public functions for closing sorted maps. See qcbor/qcbor_encode.h
1336 */
Laurence Lundbladedee0d4e2024-03-03 13:46:33 -07001337void
1338QCBOREncode_CloseAndSortMapIndef(QCBOREncodeContext *pMe)
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001339{
1340 uint32_t uStart;
1341
1342 uStart = Nesting_GetStartPos(&(pMe->nesting));
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001343 QCBOREncode_Private_SortMap(pMe, uStart);
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001344
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001345 QCBOREncode_Private_CloseMapOrArrayIndefiniteLength(pMe, CBOR_MAJOR_NONE_TYPE_MAP_INDEFINITE_LEN);
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001346}
Laurence Lundbladed3f07842024-06-19 13:05:07 -07001347#endif /* ! QCBOR_DISABLE_INDEFINITE_LENGTH_ARRAYS */
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001348
1349
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +00001350/*
Laurence Lundblade1fa579b2020-11-25 00:31:37 -08001351 * Public functions for closing bstr wrapping. See qcbor/qcbor_encode.h
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +00001352 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001353void
1354QCBOREncode_CloseBstrWrap2(QCBOREncodeContext *pMe,
1355 const bool bIncludeCBORHead,
1356 UsefulBufC *pWrappedCBOR)
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +00001357{
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001358 const size_t uInsertPosition = Nesting_GetStartPos(&(pMe->nesting));
1359 const size_t uEndPosition = UsefulOutBuf_GetEndPosition(&(pMe->OutBuf));
Laurence Lundblade3aee3a32018-12-17 16:17:45 -08001360
Laurence Lundblade1fa579b2020-11-25 00:31:37 -08001361 /* This subtraction can't go negative because the UsefulOutBuf
1362 * always only grows and never shrinks. UsefulOutBut itself also
1363 * has defenses such that it won't write where it should not even
1364 * if given incorrect input lengths.
1365 */
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +00001366 const size_t uBstrLen = uEndPosition - uInsertPosition;
1367
Laurence Lundblade1fa579b2020-11-25 00:31:37 -08001368 /* Actually insert */
Laurence Lundbladecbd7d132024-05-19 11:11:22 -07001369 QCBOREncode_Private_CloseAggregate(pMe, CBOR_MAJOR_TYPE_BYTE_STRING, uBstrLen);
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +00001370
1371 if(pWrappedCBOR) {
Laurence Lundblade1fa579b2020-11-25 00:31:37 -08001372 /* Return pointer and length to the enclosed encoded CBOR. The
1373 * intended use is for it to be hashed (e.g., SHA-256) in a COSE
1374 * implementation. This must be used right away, as the pointer
1375 * and length go invalid on any subsequent calls to this
1376 * function because there might be calls to
1377 * InsertEncodedTypeAndNumber() that slides data to the right.
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +00001378 */
1379 size_t uStartOfNew = uInsertPosition;
1380 if(!bIncludeCBORHead) {
Laurence Lundblade1fa579b2020-11-25 00:31:37 -08001381 /* Skip over the CBOR head to just get the inserted bstr */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001382 const size_t uNewEndPosition = UsefulOutBuf_GetEndPosition(&(pMe->OutBuf));
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +00001383 uStartOfNew += uNewEndPosition - uEndPosition;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001384 }
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001385 const UsefulBufC PartialResult = UsefulOutBuf_OutUBuf(&(pMe->OutBuf));
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +00001386 *pWrappedCBOR = UsefulBuf_Tail(PartialResult, uStartOfNew);
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001387 }
1388}
1389
Laurence Lundbladeee851742020-01-08 08:37:05 -08001390
Jan Jongboom4a93a662019-07-25 08:44:58 +02001391/*
Laurence Lundblade8d3b8552021-06-10 11:11:54 -07001392 * Public function for canceling a bstr wrap. See qcbor/qcbor_encode.h
1393 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001394void
1395QCBOREncode_CancelBstrWrap(QCBOREncodeContext *pMe)
Laurence Lundblade8d3b8552021-06-10 11:11:54 -07001396{
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001397 if(QCBOREncode_Private_CheckDecreaseNesting(pMe, CBOR_MAJOR_TYPE_BYTE_STRING)) {
Laurence Lundblade274ddef2022-05-17 09:12:23 -07001398 return;
1399 }
1400
Laurence Lundblade8d3b8552021-06-10 11:11:54 -07001401#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Laurence Lundblade274ddef2022-05-17 09:12:23 -07001402 const size_t uCurrent = UsefulOutBuf_GetEndPosition(&(pMe->OutBuf));
1403 if(pMe->nesting.pCurrentNesting->uStart != uCurrent) {
1404 pMe->uError = QCBOR_ERR_CANNOT_CANCEL;
1405 return;
Laurence Lundblade8d3b8552021-06-10 11:11:54 -07001406 }
1407 /* QCBOREncode_CancelBstrWrap() can't correctly undo
1408 * QCBOREncode_BstrWrapInMap() or QCBOREncode_BstrWrapInMapN(). It
1409 * can't undo the labels they add. It also doesn't catch the error
1410 * of using it this way. QCBOREncode_CancelBstrWrap() is used
1411 * infrequently and the the result is incorrect CBOR, not a
1412 * security hole, so no extra code or state is added to handle this
1413 * condition.
1414 */
1415#endif /* QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
1416
1417 Nesting_Decrease(&(pMe->nesting));
1418 Nesting_Decrement(&(pMe->nesting));
1419}
1420
1421
1422/*
Laurence Lundbladeb24faef2022-04-26 11:03:08 -06001423 * Public function for opening a byte string. See qcbor/qcbor_encode.h
1424 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001425void
1426QCBOREncode_OpenBytes(QCBOREncodeContext *pMe, UsefulBuf *pPlace)
Laurence Lundbladeb24faef2022-04-26 11:03:08 -06001427{
1428 *pPlace = UsefulOutBuf_GetOutPlace(&(pMe->OutBuf));
Laurence Lundbladeb24faef2022-04-26 11:03:08 -06001429#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Paul Liétar79789772022-07-26 20:33:18 +01001430 uint8_t uMajorType = Nesting_GetMajorType(&(pMe->nesting));
1431 if(uMajorType == CBOR_MAJOR_NONE_TYPE_OPEN_BSTR) {
Laurence Lundblade716d10c2024-02-07 16:54:42 -08001432 /* It's OK to nest a byte string in any type but
1433 * another open byte string. */
Paul Liétar79789772022-07-26 20:33:18 +01001434 pMe->uError = QCBOR_ERR_OPEN_BYTE_STRING;
1435 return;
1436 }
Laurence Lundbladeb24faef2022-04-26 11:03:08 -06001437#endif /* QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
1438
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001439 QCBOREncode_Private_OpenMapOrArray(pMe, CBOR_MAJOR_NONE_TYPE_OPEN_BSTR);
Laurence Lundbladeb24faef2022-04-26 11:03:08 -06001440}
1441
1442
1443/*
1444 * Public function for closing a byte string. See qcbor/qcbor_encode.h
1445 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001446void
1447QCBOREncode_CloseBytes(QCBOREncodeContext *pMe, const size_t uAmount)
Laurence Lundbladeb24faef2022-04-26 11:03:08 -06001448{
1449 UsefulOutBuf_Advance(&(pMe->OutBuf), uAmount);
1450 if(UsefulOutBuf_GetError(&(pMe->OutBuf))) {
1451 /* Advance too far. Normal off-end error handling in effect here. */
1452 return;
1453 }
1454
Laurence Lundbladecbd7d132024-05-19 11:11:22 -07001455 QCBOREncode_Private_CloseAggregate(pMe, CBOR_MAJOR_NONE_TYPE_OPEN_BSTR, uAmount);
Laurence Lundbladeb24faef2022-04-26 11:03:08 -06001456}
1457
1458
Laurence Lundbladecbd7d132024-05-19 11:11:22 -07001459#ifndef QCBOR_DISABLE_INDEFINITE_LENGTH_ARRAYS
1460
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001461/**
1462 * @brief Semi-private method to close a map, array with indefinite length
1463 *
1464 * @param[in] pMe The context to add to.
1465 * @param[in] uMajorType The major CBOR type to close.
1466 *
1467 * Call QCBOREncode_CloseArrayIndefiniteLength() or
1468 * QCBOREncode_CloseMapIndefiniteLength() instead of this.
Jan Jongboom4a93a662019-07-25 08:44:58 +02001469 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001470void
1471QCBOREncode_Private_CloseMapOrArrayIndefiniteLength(QCBOREncodeContext *pMe,
1472 const uint8_t uMajorType)
Jan Jongboom4a93a662019-07-25 08:44:58 +02001473{
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001474 if(QCBOREncode_Private_CheckDecreaseNesting(pMe, uMajorType)) {
Laurence Lundblade274ddef2022-05-17 09:12:23 -07001475 return;
Jan Jongboom4a93a662019-07-25 08:44:58 +02001476 }
Laurence Lundbladedaefdec2020-11-02 20:22:03 -08001477
Laurence Lundblade1fa579b2020-11-25 00:31:37 -08001478 /* Append the break marker (0xff for both arrays and maps) */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001479 QCBOREncode_Private_AppendCBORHead(pMe, CBOR_MAJOR_NONE_TYPE_SIMPLE_BREAK, CBOR_SIMPLE_BREAK, 0);
Laurence Lundblade274ddef2022-05-17 09:12:23 -07001480 Nesting_Decrease(&(pMe->nesting));
Jan Jongboom4a93a662019-07-25 08:44:58 +02001481}
Laurence Lundbladecbd7d132024-05-19 11:11:22 -07001482#endif
Jan Jongboom4a93a662019-07-25 08:44:58 +02001483
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001484
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001485/*
Laurence Lundblade8d3b8552021-06-10 11:11:54 -07001486 * Public function to finish and get the encoded result. See qcbor/qcbor_encode.h
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001487 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001488QCBORError
1489QCBOREncode_Finish(QCBOREncodeContext *pMe, UsefulBufC *pEncodedCBOR)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001490{
Laurence Lundbladef2f0c3f2024-04-12 13:01:54 -07001491 if(QCBOREncode_GetErrorState(pMe) != QCBOR_SUCCESS) {
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001492 goto Done;
Laurence Lundblade067035b2018-11-28 17:35:25 -08001493 }
Laurence Lundblade3aee3a32018-12-17 16:17:45 -08001494
Laurence Lundbladedaefdec2020-11-02 20:22:03 -08001495#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001496 if(Nesting_IsInNest(&(pMe->nesting))) {
Laurence Lundbladef2f0c3f2024-04-12 13:01:54 -07001497 pMe->uError = QCBOR_ERR_ARRAY_OR_MAP_STILL_OPEN;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001498 goto Done;
1499 }
Laurence Lundbladee2c893c2020-12-26 17:41:53 -08001500#endif /* QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
Laurence Lundblade3aee3a32018-12-17 16:17:45 -08001501
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001502 *pEncodedCBOR = UsefulOutBuf_OutUBuf(&(pMe->OutBuf));
Laurence Lundblade3aee3a32018-12-17 16:17:45 -08001503
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001504Done:
Laurence Lundbladef2f0c3f2024-04-12 13:01:54 -07001505 return pMe->uError;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001506}
1507
Laurence Lundblade0595e932018-11-02 22:22:47 +07001508
Laurence Lundblade067035b2018-11-28 17:35:25 -08001509/*
Laurence Lundblade1fa579b2020-11-25 00:31:37 -08001510 * Public functions to get size of the encoded result. See qcbor/qcbor_encode.h
Laurence Lundblade067035b2018-11-28 17:35:25 -08001511 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001512QCBORError
1513QCBOREncode_FinishGetSize(QCBOREncodeContext *pMe, size_t *puEncodedLen)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001514{
Laurence Lundbladeda3f0822018-09-18 19:49:02 -07001515 UsefulBufC Enc;
Laurence Lundblade3aee3a32018-12-17 16:17:45 -08001516
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001517 QCBORError nReturn = QCBOREncode_Finish(pMe, &Enc);
Laurence Lundblade3aee3a32018-12-17 16:17:45 -08001518
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001519 if(nReturn == QCBOR_SUCCESS) {
Laurence Lundbladeda3f0822018-09-18 19:49:02 -07001520 *puEncodedLen = Enc.len;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001521 }
Laurence Lundblade3aee3a32018-12-17 16:17:45 -08001522
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001523 return nReturn;
1524}