blob: a2a944a070369b31b50bb4d76728dba21723a559 [file] [log] [blame]
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001/*==============================================================================
Laurence Lundbladed92a6162018-11-01 11:38:35 +07002 Copyright (c) 2016-2018, The Linux Foundation.
Laurence Lundblade8e36f812024-01-26 10:59:29 -07003 Copyright (c) 2018-2024, Laurence Lundblade.
Máté Tóth-Pálef5f07a2021-09-17 19:31:37 +02004 Copyright (c) 2021, Arm Limited.
Laurence Lundbladed92a6162018-11-01 11:38:35 +07005 All rights reserved.
Laurence Lundblade3aee3a32018-12-17 16:17:45 -08006
Laurence Lundblade0dbc9172018-11-01 14:17:21 +07007Redistribution and use in source and binary forms, with or without
8modification, are permitted provided that the following conditions are
9met:
10 * Redistributions of source code must retain the above copyright
11 notice, this list of conditions and the following disclaimer.
12 * Redistributions in binary form must reproduce the above
13 copyright notice, this list of conditions and the following
14 disclaimer in the documentation and/or other materials provided
15 with the distribution.
16 * Neither the name of The Linux Foundation nor the names of its
17 contributors, nor the name "Laurence Lundblade" may be used to
18 endorse or promote products derived from this software without
19 specific prior written permission.
Laurence Lundblade3aee3a32018-12-17 16:17:45 -080020
Laurence Lundblade0dbc9172018-11-01 14:17:21 +070021THIS SOFTWARE IS PROVIDED "AS IS" AND ANY EXPRESS OR IMPLIED
22WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
23MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NON-INFRINGEMENT
24ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS
25BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
26CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
27SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
28BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
29WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE
30OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN
31IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
Laurence Lundbladeee851742020-01-08 08:37:05 -080032 =============================================================================*/
Laurence Lundblade624405d2018-09-18 20:10:47 -070033
Laurence Lundblade3aee3a32018-12-17 16:17:45 -080034
Laurence Lundblade844bb5c2020-03-01 17:27:25 -080035#include "qcbor/qcbor_encode.h"
Laurence Lundblade12d32c52018-09-19 11:25:27 -070036#include "ieee754.h"
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070037
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070038
Laurence Lundblade1fa579b2020-11-25 00:31:37 -080039/**
40 * @file qcbor_encode.c
Laurence Lundblade3f1318a2021-01-04 18:26:44 -080041 *
Laurence Lundblade1fa579b2020-11-25 00:31:37 -080042 * The entire implementation of the QCBOR encoder.
43 */
44
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070045
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070046/*
Laurence Lundblade1fa579b2020-11-25 00:31:37 -080047 * == Nesting Tracking ==
48 *
49 * The following functions and data type QCBORTrackNesting implement
50 * the nesting management for encoding.
51 *
52 * CBOR's two nesting types, arrays and maps, are tracked here. There
53 * is a limit of QCBOR_MAX_ARRAY_NESTING to the number of arrays and
54 * maps that can be nested in one encoding so the encoding context
55 * stays small enough to fit on the stack.
56 *
57 * When an array/map is opened, pCurrentNesting points to the element
58 * in pArrays that records the type, start position and accumulates a
59 * count of the number of items added. When closed the start position
60 * is used to go back and fill in the type and number of items in the
61 * array/map.
62 *
63 * Encoded output can be a CBOR Sequence (RFC 8742) in which case
64 * there is no top-level array or map. It starts out with a string,
65 * integer or other non-aggregate type. It may have an array or map
66 * other than at the start, in which case that nesting is tracked
67 * here.
68 *
69 * QCBOR has a special feature to allow constructing byte string
70 * wrapped CBOR directly into the output buffer, so no extra buffer is
71 * needed for byte string wrapping. This is implemented as nesting
72 * with the type CBOR_MAJOR_TYPE_BYTE_STRING and is tracked here. Byte
73 * string wrapped CBOR is used by COSE for data that is to be hashed.
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070074 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -070075static void
Laurence Lundblade274ddef2022-05-17 09:12:23 -070076Nesting_Init(QCBORTrackNesting *pNesting)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070077{
Laurence Lundblade1fa579b2020-11-25 00:31:37 -080078 /* Assumes pNesting has been zeroed. */
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070079 pNesting->pCurrentNesting = &pNesting->pArrays[0];
Laurence Lundblade1fa579b2020-11-25 00:31:37 -080080 /* Implied CBOR array at the top nesting level. This is never
81 * returned, but makes the item count work correctly.
82 */
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070083 pNesting->pCurrentNesting->uMajorType = CBOR_MAJOR_TYPE_ARRAY;
84}
85
Laurence Lundblade8e36f812024-01-26 10:59:29 -070086static uint8_t
Laurence Lundblade274ddef2022-05-17 09:12:23 -070087Nesting_Increase(QCBORTrackNesting *pNesting,
Laurence Lundblade8e36f812024-01-26 10:59:29 -070088 const uint8_t uMajorType,
89 const uint32_t uPos)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070090{
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070091 if(pNesting->pCurrentNesting == &pNesting->pArrays[QCBOR_MAX_ARRAY_NESTING]) {
Laurence Lundblade29497c02020-07-11 15:44:03 -070092 return QCBOR_ERR_ARRAY_NESTING_TOO_DEEP;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070093 } else {
94 pNesting->pCurrentNesting++;
95 pNesting->pCurrentNesting->uCount = 0;
96 pNesting->pCurrentNesting->uStart = uPos;
97 pNesting->pCurrentNesting->uMajorType = uMajorType;
Laurence Lundblade29497c02020-07-11 15:44:03 -070098 return QCBOR_SUCCESS;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070099 }
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700100}
101
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700102static void
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700103Nesting_Decrease(QCBORTrackNesting *pNesting)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700104{
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700105 if(pNesting->pCurrentNesting > &pNesting->pArrays[0]) {
106 pNesting->pCurrentNesting--;
107 }
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700108}
109
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700110static uint8_t
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700111Nesting_Increment(QCBORTrackNesting *pNesting)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700112{
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800113#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Laurence Lundblade1ef8b2d2018-12-14 23:13:34 -0800114 if(1 >= QCBOR_MAX_ITEMS_IN_ARRAY - pNesting->pCurrentNesting->uCount) {
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700115 return QCBOR_ERR_ARRAY_TOO_LONG;
116 }
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800117#endif /* QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800118
Laurence Lundbladee6bcef12020-04-01 10:56:27 -0700119 pNesting->pCurrentNesting->uCount++;
Laurence Lundblade2c40ab82018-12-30 14:20:29 -0800120
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700121 return QCBOR_SUCCESS;
122}
123
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700124static void
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700125Nesting_Decrement(QCBORTrackNesting *pNesting)
Laurence Lundblade8d3b8552021-06-10 11:11:54 -0700126{
127 /* No error check for going below 0 here needed because this
128 * is only used by QCBOREncode_CancelBstrWrap() and it checks
129 * the nesting level before calling this. */
130 pNesting->pCurrentNesting->uCount--;
131}
132
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700133static uint16_t
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700134Nesting_GetCount(QCBORTrackNesting *pNesting)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700135{
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800136 /* The nesting count recorded is always the actual number of
137 * individual data items in the array or map. For arrays CBOR uses
138 * the actual item count. For maps, CBOR uses the number of pairs.
139 * This function returns the number needed for the CBOR encoding,
140 * so it divides the number of items by two for maps to get the
141 * number of pairs.
142 */
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800143 if(pNesting->pCurrentNesting->uMajorType == CBOR_MAJOR_TYPE_MAP) {
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800144 /* Cast back to uint16_t after integer promotion from bit shift */
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800145 return (uint16_t)(pNesting->pCurrentNesting->uCount >> 1);
146 } else {
147 return pNesting->pCurrentNesting->uCount;
148 }
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700149}
150
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700151static uint32_t
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700152Nesting_GetStartPos(QCBORTrackNesting *pNesting)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700153{
154 return pNesting->pCurrentNesting->uStart;
155}
156
Laurence Lundbladed8e1c512020-11-04 23:03:44 -0800157#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700158static uint8_t
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700159Nesting_GetMajorType(QCBORTrackNesting *pNesting)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700160{
161 return pNesting->pCurrentNesting->uMajorType;
162}
163
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700164static bool
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700165Nesting_IsInNest(QCBORTrackNesting *pNesting)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700166{
Laurence Lundbladeee851742020-01-08 08:37:05 -0800167 return pNesting->pCurrentNesting == &pNesting->pArrays[0] ? false : true;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700168}
Laurence Lundbladed8e1c512020-11-04 23:03:44 -0800169#endif /* QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700170
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700171
172
173
174/*
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800175 * == Major CBOR Types ==
176 *
177 * Encoding of the major CBOR types is by these functions:
178 *
Laurence Lundblade3f1318a2021-01-04 18:26:44 -0800179 * CBOR Major Type Public Function
180 * 0 QCBOREncode_AddUInt64()
181 * 0, 1 QCBOREncode_AddUInt64(), QCBOREncode_AddInt64()
182 * 2, 3 QCBOREncode_AddBuffer()
183 * 4, 5 QCBOREncode_OpenMapOrArray(), QCBOREncode_CloseMapOrArray(),
184 * QCBOREncode_OpenMapOrArrayIndefiniteLength(),
185 * QCBOREncode_CloseMapOrArrayIndefiniteLength()
186 * 6 QCBOREncode_AddTag()
187 * 7 QCBOREncode_AddDouble(), QCBOREncode_AddFloat(),
188 * QCBOREncode_AddDoubleNoPreferred(),
189 * QCBOREncode_AddFloatNoPreferred(), QCBOREncode_AddType7()
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800190 *
191 * Additionally, encoding of decimal fractions and bigfloats is by
192 * QCBOREncode_AddExponentAndMantissa() and byte strings that wrap
193 * encoded CBOR are handled by QCBOREncode_OpenMapOrArray() and
194 * QCBOREncode_CloseBstrWrap2().
195 *
196 *
197 * == Error Tracking Plan ==
198 *
199 * Errors are tracked internally and not returned until
200 * QCBOREncode_Finish() or QCBOREncode_GetErrorState() is called. The
201 * CBOR errors are in me->uError. UsefulOutBuf also tracks whether
202 * the buffer is full or not in its context. Once either of these
203 * errors is set they are never cleared. Only QCBOREncode_Init()
204 * resets them. Or said another way, they must never be cleared or
205 * we'll tell the caller all is good when it is not.
206 *
207 * Only one error code is reported by QCBOREncode_Finish() even if
208 * there are multiple errors. The last one set wins. The caller might
209 * have to fix one error to reveal the next one they have to fix.
210 * This is OK.
211 *
212 * The buffer full error tracked by UsefulBuf is only pulled out of
213 * UsefulBuf in QCBOREncode_Finish() so it is the one that usually
214 * wins. UsefulBuf will never go off the end of the buffer even if it
215 * is called again and again when full.
216 *
217 * QCBOR_DISABLE_ENCODE_USAGE_GUARDS disables about half of the error
218 * checks here to reduce code size by about 150 bytes leaving only the
219 * checks for size to avoid buffer overflow. If the calling code is
220 * completely correct, checks are completely unnecessary. For
221 * example, there is no need to check that all the opens are matched
222 * by a close.
223 *
224 * QCBOR_DISABLE_ENCODE_USAGE_GUARDS also disables the check for more
225 * than QCBOR_MAX_ITEMS_IN_ARRAY in an array. Since
226 * QCBOR_MAX_ITEMS_IN_ARRAY is very large (65,535) it is very unlikely
227 * to be reached. If it is reached, the count will wrap around to zero
228 * and CBOR that is not well formed will be produced, but there will
229 * be no buffers overrun and new security issues in the code.
230 *
231 * The 8 errors returned here fall into three categories:
232 *
233 * Sizes
234 * QCBOR_ERR_BUFFER_TOO_LARGE -- Encoded output exceeded UINT32_MAX
235 * QCBOR_ERR_BUFFER_TOO_SMALL -- Output buffer too small
236 * QCBOR_ERR_ARRAY_NESTING_TOO_DEEP -- Nesting > QCBOR_MAX_ARRAY_NESTING1
237 * QCBOR_ERR_ARRAY_TOO_LONG -- Too many items added to an array/map [1]
238 *
239 * Nesting constructed incorrectly
240 * QCBOR_ERR_TOO_MANY_CLOSES -- More close calls than opens [1]
241 * QCBOR_ERR_CLOSE_MISMATCH -- Type of close does not match open [1]
242 * QCBOR_ERR_ARRAY_OR_MAP_STILL_OPEN -- Finish called without enough closes [1]
243 *
244 * Would generate not-well-formed CBOR
245 * QCBOR_ERR_ENCODE_UNSUPPORTED -- Simple type between 24 and 31 [1]
246 *
247 * [1] indicated disabled by QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700248 */
249
250
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700251/*
Laurence Lundblade844bb5c2020-03-01 17:27:25 -0800252 Public function for initialization. See qcbor/qcbor_encode.h
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700253 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700254void
255QCBOREncode_Init(QCBOREncodeContext *pMe, UsefulBuf Storage)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700256{
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700257 memset(pMe, 0, sizeof(QCBOREncodeContext));
258 UsefulOutBuf_Init(&(pMe->OutBuf), Storage);
259 Nesting_Init(&(pMe->nesting));
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700260}
261
262
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000263/*
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800264 * Public function to encode a CBOR head. See qcbor/qcbor_encode.h
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700265 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700266UsefulBufC
267QCBOREncode_EncodeHead(UsefulBuf Buffer,
268 uint8_t uMajorType,
269 uint8_t uMinLen,
270 uint64_t uArgument)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700271{
Laurence Lundbladee9b00322018-12-30 10:33:26 -0800272 /*
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800273 * == Description of the CBOR Head ==
274 *
275 * The head of a CBOR data item
276 * +---+-----+ +--------+ +--------+ +--------+ +--------+
277 * |M T| A R G U M E N T . . . |
278 * +---+-----+ +--------+ +--------+ +--------+ ... +--------+
279 *
280 * Every CBOR data item has a "head". It is made up of the "major
281 * type" and the "argument".
282 *
283 * The major type indicates whether the data item is an integer,
284 * string, array or such. It is encoded in 3 bits giving it a range
285 * from 0 to 7. 0 indicates the major type is a positive integer,
286 * 1 a negative integer, 2 a byte string and so on.
287 *
288 * These 3 bits are the first part of the "initial byte" in a data
289 * item. Every data item has an initial byte, and some only have
290 * the initial byte.
291 *
292 * The argument is essentially a number between 0 and UINT64_MAX
293 * (18446744073709551615). This number is interpreted to mean
294 * different things for the different major types. For major type
295 * 0, a positive integer, it is value of the data item. For major
296 * type 2, a byte string, it is the length in bytes of the byte
297 * string. For major type 4, an array, it is the number of data
298 * items in the array.
299 *
300 * Special encoding is used so that the argument values less than
301 * 24 can be encoded very compactly in the same byte as the major
302 * type is encoded. When the lower 5 bits of the initial byte have
303 * a value less than 24, then that is the value of the argument.
304 *
305 * If the lower 5 bits of the initial byte are less than 24, then
306 * they are the value of the argument. This allows integer values 0
307 * - 23 to be CBOR encoded in just one byte.
308 *
309 * When the value of lower 5 bits are 24, 25, 26, or 27 the
310 * argument is encoded in 1, 2, 4 or 8 bytes following the initial
311 * byte in network byte order (bit endian). The cases when it is
312 * 28, 29 and 30 are reserved for future use. The value 31 is a
313 * special indicator for indefinite length strings, arrays and
314 * maps.
315 *
316 * The lower 5 bits are called the "additional information."
317 *
318 * Thus the CBOR head may be 1, 2, 3, 5 or 9 bytes long.
319 *
320 * It is legal in CBOR to encode the argument using any of these
321 * lengths even if it could be encoded in a shorter length. For
322 * example it is legal to encode a data item representing the
323 * positive integer 0 in 9 bytes even though it could be encoded in
324 * only 0. This is legal to allow for for very simple code or even
325 * hardware-only implementations that just output a register
326 * directly.
327 *
328 * CBOR defines preferred encoding as the encoding of the argument
329 * in the smallest number of bytes needed to encode it.
330 *
331 * This function takes the major type and argument as inputs and
332 * outputs the encoded CBOR head for them. It does conversion to
333 * network byte order. It implements CBOR preferred encoding,
334 * outputting the shortest representation of the argument.
335 *
336 * == Endian Conversion ==
337 *
338 * This code does endian conversion without hton() or knowing the
339 * endianness of the machine by using masks and shifts. This avoids
340 * the dependency on hton() and the mess of figuring out how to
341 * find the machine's endianness.
342 *
343 * This is a good efficient implementation on little-endian
344 * machines. A faster and smaller implementation is possible on
345 * big-endian machines because CBOR/network byte order is
346 * big-endian. However big-endian machines are uncommon.
347 *
348 * On x86, this is about 150 bytes instead of 500 bytes for the
349 * original, more formal unoptimized code.
350 *
351 * This also does the CBOR preferred shortest encoding for integers
352 * and is called to do endian conversion for floats.
353 *
354 * It works backwards from the least significant byte to the most
355 * significant byte.
356 *
357 * == Floating Point ==
358 *
359 * When the major type is 7 and the 5 lower bits have the values
360 * 25, 26 or 27, the argument is a floating-point number that is
361 * half, single or double-precision. Note that it is not the
362 * conversion from a floating-point value to an integer value like
363 * converting 0x00 to 0.00, it is the interpretation of the bits in
364 * the argument as an IEEE 754 float-point number.
365 *
366 * Floating-point numbers must be converted to network byte
367 * order. That is accomplished here by exactly the same code that
368 * converts integer arguments to network byte order.
369 *
370 * There is preferred encoding for floating-point numbers in CBOR,
371 * but it is very different than for integers and it is not
372 * implemented here. Half-precision is preferred to
373 * single-precision which is preferred to double-precision only if
374 * the conversion can be performed without loss of precision. Zero
375 * and infinity can always be converted to half-precision, without
376 * loss but 3.141592653589 cannot.
377 *
378 * The way this function knows to not do preferred encoding on the
379 * argument passed here when it is a floating point number is the
380 * uMinLen parameter. It should be 2, 4 or 8 for half, single and
381 * double precision floating point values. This prevents and the
382 * incorrect removal of leading zeros when encoding arguments that
383 * are floating-point numbers.
384 *
385 * == Use of Type int and Static Analyzers ==
386 *
387 * The type int is used here for several variables because of the
388 * way integer promotion works in C for variables that are uint8_t
389 * or uint16_t. The basic rule is that they will always be promoted
390 * to int if they will fit. These integer variables here need only
391 * hold values less than 255 so they will always fit into an int.
392 *
393 * Most of values stored are never negative, so one might think
394 * that unsigned int would be more correct than int. However the C
395 * integer promotion rules only promote to unsigned int if the
396 * result won't fit into an int even if the promotion is for an
397 * unsigned variable like uint8_t.
398 *
399 * By declaring these int, there are few implicit conversions and
400 * fewer casts needed. Code size is reduced a little. It makes
401 * static analyzers happier.
402 *
403 * Note also that declaring these uint8_t won't stop integer wrap
404 * around if the code is wrong. It won't make the code more
405 * correct.
406 *
407 * https://stackoverflow.com/questions/46073295/implicit-type-promotion-rules
408 * https://stackoverflow.com/questions/589575/what-does-the-c-standard-state-the-size-of-int-long-type-to-be
409 *
410 * Code Reviewers: THIS FUNCTION DOES POINTER MATH
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800411 */
Laurence Lundbladeee851742020-01-08 08:37:05 -0800412
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800413 /* The buffer must have room for the largest CBOR HEAD + one
414 * extra. The one extra is needed for this code to work as it does
415 * a pre-decrement.
416 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700417 if(Buffer.len < QCBOR_HEAD_BUFFER_SIZE) {
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000418 return NULLUsefulBufC;
419 }
420
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800421 /* Pointer to last valid byte in the buffer */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700422 uint8_t * const pBufferEnd = &((uint8_t *)Buffer.ptr)[QCBOR_HEAD_BUFFER_SIZE-1];
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000423
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800424 /* Point to the last byte and work backwards */
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000425 uint8_t *pByte = pBufferEnd;
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800426 /* The 5 bits in the initial byte that are not the major type */
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800427 int nAdditionalInfo;
Laurence Lundblade2c40ab82018-12-30 14:20:29 -0800428
Laurence Lundblade8c858ab2020-11-02 19:53:49 -0800429 if(uMajorType > QCBOR_INDEFINITE_LEN_TYPE_MODIFIER) {
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800430 /* Special case for start & end of indefinite length */
Laurence Lundblade8c858ab2020-11-02 19:53:49 -0800431 uMajorType = uMajorType - QCBOR_INDEFINITE_LEN_TYPE_MODIFIER;
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800432 /* This takes advantage of design of CBOR where additional info
433 * is 31 for both opening and closing indefinite length
434 * maps and arrays.
435 */
436 #if CBOR_SIMPLE_BREAK != LEN_IS_INDEFINITE
437 #error additional info for opening array not the same as for closing
438 #endif
Laurence Lundblade8c858ab2020-11-02 19:53:49 -0800439 nAdditionalInfo = CBOR_SIMPLE_BREAK;
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800440
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000441 } else if (uArgument < CBOR_TWENTY_FOUR && uMinLen == 0) {
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800442 /* Simple case where argument is < 24 */
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000443 nAdditionalInfo = (int)uArgument;
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800444
Laurence Lundblade04a859b2018-12-11 12:13:02 -0800445 } else {
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800446 /* This encodes the argument in 1,2,4 or 8 bytes. The outer loop
447 * runs once for 1 byte and 4 times for 8 bytes. The inner loop
448 * runs 1, 2 or 4 times depending on outer loop counter. This
449 * works backwards shifting 8 bits off the argument being
450 * encoded at a time until all bits from uArgument have been
451 * encoded and the minimum encoding size is reached. Minimum
452 * encoding size is for floating-point numbers that have some
453 * zero-value bytes that must be output.
Laurence Lundbladee9b00322018-12-30 10:33:26 -0800454 */
Laurence Lundblade04a859b2018-12-11 12:13:02 -0800455 static const uint8_t aIterate[] = {1,1,2,4};
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000456
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800457 /* uMinLen passed in is unsigned, but goes negative in the loop
458 * so it must be converted to a signed value.
459 */
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000460 int nMinLen = (int)uMinLen;
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800461 int i;
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000462 for(i = 0; uArgument || nMinLen > 0; i++) {
463 const int nIterations = (int)aIterate[i];
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800464 for(int j = 0; j < nIterations; j++) {
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000465 *--pByte = (uint8_t)(uArgument & 0xff);
466 uArgument = uArgument >> 8;
Laurence Lundblade04a859b2018-12-11 12:13:02 -0800467 }
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800468 nMinLen -= nIterations;
Laurence Lundblade04a859b2018-12-11 12:13:02 -0800469 }
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800470
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800471 nAdditionalInfo = LEN_IS_ONE_BYTE-1 + i;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700472 }
Laurence Lundbladef970f1d2018-12-14 01:44:23 -0800473
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800474 /* This expression integer-promotes to type int. The code above in
475 * function guarantees that nAdditionalInfo will never be larger
476 * than 0x1f. The caller may pass in a too-large uMajor type. The
477 * conversion to unint8_t will cause an integer wrap around and
478 * incorrect CBOR will be generated, but no security issue will
479 * occur.
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800480 */
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800481 const int nInitialByte = (uMajorType << 5) + nAdditionalInfo;
482 *--pByte = (uint8_t)nInitialByte;
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800483
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000484#ifdef EXTRA_ENCODE_HEAD_CHECK
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800485 /* This is a sanity check that can be turned on to verify the
486 * pointer math in this function is not going wrong. Turn it on and
487 * run the whole test suite to perform the check.
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800488 */
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000489 if(pBufferEnd - pByte > 9 || pBufferEnd - pByte < 1 || pByte < (uint8_t *)buffer.ptr) {
490 return NULLUsefulBufC;
491 }
Laurence Lundbladee2c893c2020-12-26 17:41:53 -0800492#endif /* EXTRA_ENCODE_HEAD_CHECK */
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800493
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800494 /* Length will not go negative because the loops run for at most 8 decrements
495 * of pByte, only one other decrement is made, and the array is sized
496 * for this.
497 */
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000498 return (UsefulBufC){pByte, (size_t)(pBufferEnd - pByte)};
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700499}
500
501
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000502/**
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800503 * @brief Append the CBOR head, the major type and argument
504 *
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700505 * @param pMe Encoder context.
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800506 * @param uMajorType Major type to insert.
507 * @param uArgument The argument (an integer value or a length).
508 * @param uMinLen The minimum number of bytes for encoding the CBOR argument.
509 *
510 * This formats the CBOR "head" and appends it to the output.
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000511 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700512static void
513QCBOREncode_Private_AppendCBORHead(QCBOREncodeContext *pMe,
514 const uint8_t uMajorType,
515 const uint64_t uArgument,
516 const uint8_t uMinLen)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700517{
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800518 /* A stack buffer large enough for a CBOR head */
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000519 UsefulBuf_MAKE_STACK_UB (pBufferForEncodedHead, QCBOR_HEAD_BUFFER_SIZE);
520
521 UsefulBufC EncodedHead = QCBOREncode_EncodeHead(pBufferForEncodedHead,
522 uMajorType,
523 uMinLen,
524 uArgument);
525
526 /* No check for EncodedHead == NULLUsefulBufC is performed here to
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800527 * save object code. It is very clear that pBufferForEncodedHead is
528 * the correct size. If EncodedHead == NULLUsefulBufC then
529 * UsefulOutBuf_AppendUsefulBuf() will do nothing so there is no
530 * security hole introduced.
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000531 */
532
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700533 UsefulOutBuf_AppendUsefulBuf(&(pMe->OutBuf), EncodedHead);
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700534}
535
536
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000537/**
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700538 * @brief Check for errors when decreasing nesting.
539 *
540 * @param pMe QCBOR encoding context.
541 * @param uMajorType The major type of the nesting.
542 *
543 * Check that there is no previous error, that there is actually some
544 * nesting and that the major type of the opening of the nesting
545 * matches the major type of the nesting being closed.
546 *
547 * This is called when closing maps, arrays, byte string wrapping and
548 * open/close of byte strings.
549 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700550static bool
551QCBOREncode_Private_CheckDecreaseNesting(QCBOREncodeContext *pMe,
552 const uint8_t uMajorType)
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700553{
554#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
555 if(pMe->uError != QCBOR_SUCCESS) {
556 return true;
557 }
558
559 if(!Nesting_IsInNest(&(pMe->nesting))) {
560 pMe->uError = QCBOR_ERR_TOO_MANY_CLOSES;
561 return true;
562 }
563
564 if(Nesting_GetMajorType(&(pMe->nesting)) != uMajorType) {
565 pMe->uError = QCBOR_ERR_CLOSE_MISMATCH;
566 return true;
567 }
568
569#else
570 /* None of these checks are performed if the encode guards are
571 * turned off as they all relate to correct calling.
572 *
573 * Turning off all these checks does not turn off any checking for
574 * buffer overflows or pointer issues.
575 */
576
577 (void)uMajorType;
578 (void)pMe;
579#endif
Laurence Lundbladed6e13022023-11-26 10:14:02 -0700580
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700581 return false;
582}
583
584
585/**
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800586 * @brief Insert the CBOR head for a map, array or wrapped bstr
587 *
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700588 * @param pMe QCBOR encoding context.
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800589 * @param uMajorType One of CBOR_MAJOR_TYPE_XXXX.
590 * @param uLen The length of the data item.
591 *
592 * When an array, map or bstr was opened, nothing was done but note
593 * the position. This function goes back to that position and inserts
594 * the CBOR Head with the major type and length.
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000595 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700596static void
597QCBOREncode_Private_InsertCBORHead(QCBOREncodeContext *pMe,
598 uint8_t uMajorType,
599 size_t uLen)
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000600{
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700601 if(QCBOREncode_Private_CheckDecreaseNesting(pMe, uMajorType)) {
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700602 return;
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000603 }
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700604
Laurence Lundbladeb24faef2022-04-26 11:03:08 -0600605 if(uMajorType == CBOR_MAJOR_NONE_TYPE_OPEN_BSTR) {
606 uMajorType = CBOR_MAJOR_TYPE_BYTE_STRING;
607 }
Laurence Lundbladed8e1c512020-11-04 23:03:44 -0800608
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700609 /* A stack buffer large enough for a CBOR head (9 bytes) */
Laurence Lundbladed8e1c512020-11-04 23:03:44 -0800610 UsefulBuf_MAKE_STACK_UB(pBufferForEncodedHead, QCBOR_HEAD_BUFFER_SIZE);
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800611
612 UsefulBufC EncodedHead = QCBOREncode_EncodeHead(pBufferForEncodedHead,
613 uMajorType,
614 0,
615 uLen);
616
617 /* No check for EncodedHead == NULLUsefulBufC is performed here to
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800618 * save object code. It is very clear that pBufferForEncodedHead is
619 * the correct size. If EncodedHead == NULLUsefulBufC then
620 * UsefulOutBuf_InsertUsefulBuf() will do nothing so there is no
Laurence Lundblade9e2f7082021-05-17 02:10:48 -0700621 * security hole introduced.
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800622 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700623 UsefulOutBuf_InsertUsefulBuf(&(pMe->OutBuf),
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800624 EncodedHead,
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700625 Nesting_GetStartPos(&(pMe->nesting)));
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800626
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700627 Nesting_Decrease(&(pMe->nesting));
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000628}
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700629
Laurence Lundblade241705e2018-12-30 18:56:14 -0800630
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800631/**
632 * @brief Increment item counter for maps and arrays.
633 *
634 * @param pMe QCBOR encoding context.
635 *
636 * This is mostly a separate function to make code more readable and
637 * to have fewer occurrences of #ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Laurence Lundblade3e0a45c2020-11-05 11:12:04 -0800638 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700639static void
640QCBOREncode_Private_IncrementMapOrArrayCount(QCBOREncodeContext *pMe)
Laurence Lundblade3e0a45c2020-11-05 11:12:04 -0800641{
642#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
643 if(pMe->uError == QCBOR_SUCCESS) {
644 pMe->uError = Nesting_Increment(&(pMe->nesting));
645 }
646#else
647 (void)Nesting_Increment(&(pMe->nesting));
648#endif /* QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
649}
650
651
652/*
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800653 * Public functions for adding unsigned integers. See qcbor/qcbor_encode.h
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700654 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700655void
656QCBOREncode_AddUInt64(QCBOREncodeContext *pMe, const uint64_t uValue)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700657{
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700658 QCBOREncode_Private_AppendCBORHead(pMe,
659 CBOR_MAJOR_TYPE_POSITIVE_INT,
660 uValue,
661 0);
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800662
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700663 QCBOREncode_Private_IncrementMapOrArrayCount(pMe);
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700664}
665
Laurence Lundblade56230d12018-11-01 11:14:51 +0700666
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700667/*
Laurence Lundblade2d493002024-02-01 11:09:17 -0700668 * Public functions for adding negative integers. See qcbor/qcbor_encode.h
669 */
670void QCBOREncode_AddNegativeUInt64(QCBOREncodeContext *pMe, const uint64_t uValue)
671{
672 // TODO: Error out in dCBOR mode
673 QCBOREncode_Private_AppendCBORHead(pMe, CBOR_MAJOR_TYPE_NEGATIVE_INT, uValue, 0);
674
675 QCBOREncode_Private_IncrementMapOrArrayCount(pMe);
676}
677
678
679/*
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800680 * Public functions for adding signed integers. See qcbor/qcbor_encode.h
Laurence Lundblade067035b2018-11-28 17:35:25 -0800681 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700682void
683QCBOREncode_AddInt64(QCBOREncodeContext *pMe, const int64_t nNum)
Laurence Lundblade067035b2018-11-28 17:35:25 -0800684{
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800685 uint8_t uMajorType;
686 uint64_t uValue;
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800687
688 if(nNum < 0) {
Laurence Lundblade9c5c0ef2022-12-23 17:56:27 -0700689 /* In CBOR -1 encodes as 0x00 with major type negative int.
690 * First add one as a signed integer because that will not
Laurence Lundblade2d493002024-02-01 11:09:17 -0700691 * overflow. Then change the sign as needed for encoding (the
Laurence Lundblade9c5c0ef2022-12-23 17:56:27 -0700692 * opposite order, changing the sign and subtracting, can cause
Laurence Lundblade2d493002024-02-01 11:09:17 -0700693 * an overflow when encoding INT64_MIN). */
Laurence Lundblade9c5c0ef2022-12-23 17:56:27 -0700694 int64_t nTmp = nNum + 1;
695 uValue = (uint64_t)-nTmp;
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800696 uMajorType = CBOR_MAJOR_TYPE_NEGATIVE_INT;
697 } else {
698 uValue = (uint64_t)nNum;
699 uMajorType = CBOR_MAJOR_TYPE_POSITIVE_INT;
700 }
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700701 QCBOREncode_Private_AppendCBORHead(pMe, uMajorType, uValue, 0);
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800702
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700703 QCBOREncode_Private_IncrementMapOrArrayCount(pMe);
Laurence Lundblade067035b2018-11-28 17:35:25 -0800704}
705
706
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700707/**
708 * @brief Semi-private method to add a buffer full of bytes to encoded output.
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800709 *
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700710 * @param[in] pMe The encoding context to add the integer to.
711 * @param[in] uMajorType The CBOR major type of the bytes.
712 * @param[in] Bytes The bytes to add.
713 *
714 * Use QCBOREncode_AddText() or QCBOREncode_AddBytes() or
715 * QCBOREncode_AddEncoded() instead. They are inline functions that
716 * call this and supply the correct major type. This function is
717 * public to make the inline functions work to keep the overall code
718 * size down and because the C language has no way to make it private.
719 *
720 * If this is called the major type should be @c CBOR_MAJOR_TYPE_TEXT_STRING,
721 * @c CBOR_MAJOR_TYPE_BYTE_STRING or @c CBOR_MAJOR_NONE_TYPE_RAW. The
722 * last one is special for adding already-encoded CBOR.
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800723 *
724 * This does the work of adding actual strings bytes to the CBOR
725 * output (as opposed to adding numbers and opening / closing
726 * aggregate types).
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800727
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800728 * There are four use cases:
729 * CBOR_MAJOR_TYPE_BYTE_STRING -- Byte strings
730 * CBOR_MAJOR_TYPE_TEXT_STRING -- Text strings
731 * CBOR_MAJOR_NONE_TYPE_RAW -- Already-encoded CBOR
732 * CBOR_MAJOR_NONE_TYPE_BSTR_LEN_ONLY -- Special case
733 *
734 * The first two add the head plus the actual bytes. The third just
735 * adds the bytes as the heas is presumed to be in the bytes. The
736 * fourth just adds the head for the very special case of
737 * QCBOREncode_AddBytesLenOnly().
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700738 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700739void
740QCBOREncode_Private_AddBuffer(QCBOREncodeContext *pMe,
741 const uint8_t uMajorType,
742 const UsefulBufC Bytes)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700743{
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800744 /* If it is not Raw CBOR, add the type and the length */
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800745 if(uMajorType != CBOR_MAJOR_NONE_TYPE_RAW) {
746 uint8_t uRealMajorType = uMajorType;
747 if(uRealMajorType == CBOR_MAJOR_NONE_TYPE_BSTR_LEN_ONLY) {
748 uRealMajorType = CBOR_MAJOR_TYPE_BYTE_STRING;
749 }
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700750 QCBOREncode_Private_AppendCBORHead(pMe, uRealMajorType, Bytes.len, 0);
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800751 }
752
753 if(uMajorType != CBOR_MAJOR_NONE_TYPE_BSTR_LEN_ONLY) {
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800754 /* Actually add the bytes */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700755 UsefulOutBuf_AppendUsefulBuf(&(pMe->OutBuf), Bytes);
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800756 }
757
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700758 QCBOREncode_Private_IncrementMapOrArrayCount(pMe);
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700759}
760
Laurence Lundbladecafcfe12018-10-31 21:59:50 +0700761
Laurence Lundblade55a24832018-10-30 04:35:08 +0700762/*
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800763 * Public functions for adding a tag. See qcbor/qcbor_encode.h
Laurence Lundblade55a24832018-10-30 04:35:08 +0700764 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700765void
766QCBOREncode_AddTag(QCBOREncodeContext *pMe, const uint64_t uTag)
Laurence Lundblade55a24832018-10-30 04:35:08 +0700767{
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700768 QCBOREncode_Private_AppendCBORHead(pMe, CBOR_MAJOR_TYPE_TAG, uTag, 0);
Laurence Lundblade55a24832018-10-30 04:35:08 +0700769}
770
771
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700772/**
773 * @brief Semi-private method to add simple types.
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800774 *
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700775 * @param[in] pMe The encoding context to add the simple value to.
776 * @param[in] uMinLen Minimum encoding size for uNum. Usually 0.
777 * @param[in] uNum One of CBOR_SIMPLEV_FALSE through _UNDEF or other.
778 *
779 * This is used to add simple types like true and false.
780 *
781 * Call QCBOREncode_AddBool(), QCBOREncode_AddNULL(),
782 * QCBOREncode_AddUndef() instead of this.
783 *
784 * This function can add simple values that are not defined by CBOR
785 * yet. This expansion point in CBOR should not be used unless they are
786 * standardized.
787 *
788 * Error handling is the same as QCBOREncode_AddInt64().
Laurence Lundblade56230d12018-11-01 11:14:51 +0700789 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700790void
791QCBOREncode_Private_AddType7(QCBOREncodeContext *pMe,
792 const uint8_t uMinLen,
793 const uint64_t uNum)
Laurence Lundblade55a24832018-10-30 04:35:08 +0700794{
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800795#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700796 if(pMe->uError == QCBOR_SUCCESS) {
Laurence Lundbladebb1062e2019-08-12 23:28:54 -0700797 if(uNum >= CBOR_SIMPLEV_RESERVED_START && uNum <= CBOR_SIMPLEV_RESERVED_END) {
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700798 pMe->uError = QCBOR_ERR_ENCODE_UNSUPPORTED;
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800799 return;
Laurence Lundbladebb1062e2019-08-12 23:28:54 -0700800 }
Laurence Lundblade487930f2018-11-30 11:01:45 -0800801 }
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800802#endif /* QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
803
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800804 /* AppendCBORHead() does endian swapping for the float / double */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700805 QCBOREncode_Private_AppendCBORHead(pMe, CBOR_MAJOR_TYPE_SIMPLE, uNum, uMinLen);
Laurence Lundblade3f1318a2021-01-04 18:26:44 -0800806
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700807 QCBOREncode_Private_IncrementMapOrArrayCount(pMe);
Laurence Lundblade55a24832018-10-30 04:35:08 +0700808}
809
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700810
Máté Tóth-Pálef5f07a2021-09-17 19:31:37 +0200811#ifndef USEFULBUF_DISABLE_ALL_FLOAT
Laurence Lundblade32f3e622020-07-13 20:35:11 -0700812/*
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800813 * Public functions for adding a double. See qcbor/qcbor_encode.h
814 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700815void
816QCBOREncode_AddDoubleNoPreferred(QCBOREncodeContext *pMe, const double dNum)
Laurence Lundbladeb275cdc2020-07-12 12:34:38 -0700817{
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700818 QCBOREncode_Private_AddType7(pMe,
819 sizeof(uint64_t),
820 UsefulBufUtil_CopyDoubleToUint64(dNum));
Laurence Lundbladeb275cdc2020-07-12 12:34:38 -0700821}
822
Laurence Lundblade32f3e622020-07-13 20:35:11 -0700823
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700824/*
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800825 * Public functions for adding a double. See qcbor/qcbor_encode.h
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700826 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700827void
828QCBOREncode_AddDouble(QCBOREncodeContext *pMe, const double dNum)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700829{
Laurence Lundbladeb275cdc2020-07-12 12:34:38 -0700830#ifndef QCBOR_DISABLE_PREFERRED_FLOAT
Laurence Lundblade83dbf5c2024-01-07 19:17:52 -0700831 const IEEE754_union uNum = IEEE754_DoubleToSmaller(dNum, true);
Laurence Lundblade2feb1e12020-07-15 03:50:45 -0700832
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700833 QCBOREncode_Private_AddType7(pMe, (uint8_t)uNum.uSize, uNum.uValue);
Laurence Lundbladee2c893c2020-12-26 17:41:53 -0800834#else /* QCBOR_DISABLE_PREFERRED_FLOAT */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700835 QCBOREncode_AddDoubleNoPreferred(pMe, dNum);
Laurence Lundbladee2c893c2020-12-26 17:41:53 -0800836#endif /* QCBOR_DISABLE_PREFERRED_FLOAT */
Laurence Lundbladeb275cdc2020-07-12 12:34:38 -0700837}
Laurence Lundblade9682a532020-06-06 18:33:04 -0700838
Laurence Lundbladeb275cdc2020-07-12 12:34:38 -0700839
Laurence Lundblade32f3e622020-07-13 20:35:11 -0700840/*
Laurence Lundbladed6e13022023-11-26 10:14:02 -0700841 * Public functions for adding a double. See qcbor/qcbor_encode.h
842 */
843void QCBOREncode_AddDoubleDeterministic(QCBOREncodeContext *me, double dNum)
844{
845 if(dNum <= (double)UINT64_MAX && dNum >= 0) {
846 uint64_t uNum = (uint64_t)dNum;
847 if((double)uNum == dNum) {
848 QCBOREncode_AddUInt64(me, uNum);
849 return;
850 }
851 /* Fall through */
852 } else if(dNum >= (double)INT64_MIN && dNum < 0) {
853 int64_t nNum = (int64_t)dNum;
854 if((double)nNum == dNum) {
855 QCBOREncode_AddInt64(me, nNum);
856 return;
857 }
858 /* Fall through */
859 }
860 //const IEEE754_union uNum = IEEE754_DoubleToSmallest(dNum);
861
862 //QCBOREncode_AddType7(me, uNum.uSize, uNum.uValue);
863}
864
865
866/*
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800867 * Public functions for adding a float. See qcbor/qcbor_encode.h
868 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700869void
870QCBOREncode_AddFloatNoPreferred(QCBOREncodeContext *pMe, const float fNum)
Laurence Lundbladeb275cdc2020-07-12 12:34:38 -0700871{
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700872 QCBOREncode_Private_AddType7(pMe,
873 sizeof(uint32_t),
874 UsefulBufUtil_CopyFloatToUint32(fNum));
Laurence Lundblade9682a532020-06-06 18:33:04 -0700875}
876
877
878/*
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800879 * Public functions for adding a float. See qcbor/qcbor_encode.h
Laurence Lundblade9682a532020-06-06 18:33:04 -0700880 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700881void
882QCBOREncode_AddFloat(QCBOREncodeContext *pMe, const float fNum)
Laurence Lundblade9682a532020-06-06 18:33:04 -0700883{
Laurence Lundbladeb275cdc2020-07-12 12:34:38 -0700884#ifndef QCBOR_DISABLE_PREFERRED_FLOAT
Laurence Lundblade83dbf5c2024-01-07 19:17:52 -0700885 const IEEE754_union uNum = IEEE754_SingleToHalf(fNum);
Laurence Lundblade2feb1e12020-07-15 03:50:45 -0700886
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700887 QCBOREncode_Private_AddType7(pMe, (uint8_t)uNum.uSize, uNum.uValue);
Laurence Lundbladee2c893c2020-12-26 17:41:53 -0800888#else /* QCBOR_DISABLE_PREFERRED_FLOAT */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700889 QCBOREncode_AddFloatNoPreferred(pMe, fNum);
Laurence Lundbladee2c893c2020-12-26 17:41:53 -0800890#endif /* QCBOR_DISABLE_PREFERRED_FLOAT */
Laurence Lundblade067035b2018-11-28 17:35:25 -0800891}
Máté Tóth-Pálef5f07a2021-09-17 19:31:37 +0200892#endif /* USEFULBUF_DISABLE_ALL_FLOAT */
Laurence Lundblade067035b2018-11-28 17:35:25 -0800893
894
Laurence Lundbladedd6e76e2021-03-10 01:54:01 -0700895#ifndef QCBOR_DISABLE_EXP_AND_MANTISSA
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700896/**
897 * @brief Semi-private method to add bigfloats and decimal fractions.
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800898 *
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700899 * @param[in] pMe The encoding context to add the value to.
900 * @param[in] uTag The type 6 tag indicating what this is to be.
901 * @param[in] BigNumMantissa Is @ref NULLUsefulBufC if mantissa is an
902 * @c int64_t or the actual big number mantissa
903 * if not.
904 * @param[in] bBigNumIsNegative This is @c true if the big number is negative.
905 * @param[in] nMantissa The @c int64_t mantissa if it is not a big number.
906 * @param[in] nExponent The exponent.
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800907 *
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700908 * This outputs either the @ref CBOR_TAG_DECIMAL_FRACTION or
909 * @ref CBOR_TAG_BIGFLOAT tag. if @c uTag is @ref CBOR_TAG_INVALID64,
910 * then this outputs the "borrowed" content format.
911 *
912 * The tag content output by this is an array with two members, the
913 * exponent and then the mantissa. The mantissa can be either a big
914 * number or an @c int64_t.
915 *
916 * This implementation cannot output an exponent further from 0 than
917 * @c INT64_MAX.
918 *
919 * To output a mantissa that is between INT64_MAX and UINT64_MAX from 0,
920 * it must be as a big number.
921 *
922 * Typically, QCBOREncode_AddDecimalFraction(), QCBOREncode_AddBigFloat(),
923 * QCBOREncode_AddDecimalFractionBigNum() or QCBOREncode_AddBigFloatBigNum()
924 * is called instead of this.
Laurence Lundblade59289e52019-12-30 13:44:37 -0800925 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700926void
927QCBOREncode_Private_AddExpMantissa(QCBOREncodeContext *pMe,
928 const uint64_t uTag,
929 const UsefulBufC BigNumMantissa,
930 const bool bBigNumIsNegative,
931 const int64_t nMantissa,
932 const int64_t nExponent)
Laurence Lundblade59289e52019-12-30 13:44:37 -0800933{
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800934 /* This is for encoding either a big float or a decimal fraction,
935 * both of which are an array of two items, an exponent and a
936 * mantissa. The difference between the two is that the exponent
937 * is base-2 for big floats and base-10 for decimal fractions, but
938 * that has no effect on the code here.
Laurence Lundbladeee851742020-01-08 08:37:05 -0800939 */
Laurence Lundbladeae66d3f2020-09-14 18:12:08 -0700940 if(uTag != CBOR_TAG_INVALID64) {
941 QCBOREncode_AddTag(pMe, uTag);
942 }
Laurence Lundblade59289e52019-12-30 13:44:37 -0800943 QCBOREncode_OpenArray(pMe);
944 QCBOREncode_AddInt64(pMe, nExponent);
945 if(!UsefulBuf_IsNULLC(BigNumMantissa)) {
946 if(bBigNumIsNegative) {
947 QCBOREncode_AddNegativeBignum(pMe, BigNumMantissa);
948 } else {
949 QCBOREncode_AddPositiveBignum(pMe, BigNumMantissa);
950 }
951 } else {
952 QCBOREncode_AddInt64(pMe, nMantissa);
953 }
954 QCBOREncode_CloseArray(pMe);
955}
Laurence Lundbladedd6e76e2021-03-10 01:54:01 -0700956#endif /* QCBOR_DISABLE_EXP_AND_MANTISSA */
Laurence Lundblade59289e52019-12-30 13:44:37 -0800957
958
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700959/**
960 * @brief Semi-private method to open a map, array or bstr-wrapped CBOR
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800961 *
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700962 * @param[in] pMe The context to add to.
963 * @param[in] uMajorType The major CBOR type to close
964 *
965 * Call QCBOREncode_OpenArray(), QCBOREncode_OpenMap() or
966 * QCBOREncode_BstrWrap() instead of this.
Laurence Lundblade274ddef2022-05-17 09:12:23 -0700967 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700968void
969QCBOREncode_Private_OpenMapOrArray(QCBOREncodeContext *pMe,
970 const uint8_t uMajorType)
Laurence Lundblade067035b2018-11-28 17:35:25 -0800971{
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800972 /* Add one item to the nesting level we are in for the new map or array */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700973 QCBOREncode_Private_IncrementMapOrArrayCount(pMe);
Laurence Lundbladed39cd392019-01-11 18:17:38 -0800974
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800975 /* The offset where the length of an array or map will get written
976 * is stored in a uint32_t, not a size_t to keep stack usage
977 * smaller. This checks to be sure there is no wrap around when
978 * recording the offset. Note that on 64-bit machines CBOR larger
979 * than 4GB can be encoded as long as no array/map offsets occur
980 * past the 4GB mark, but the public interface says that the
981 * maximum is 4GB to keep the discussion simpler.
982 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700983 size_t uEndPosition = UsefulOutBuf_GetEndPosition(&(pMe->OutBuf));
Laurence Lundbladed39cd392019-01-11 18:17:38 -0800984
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800985 /* QCBOR_MAX_ARRAY_OFFSET is slightly less than UINT32_MAX so this
986 * code can run on a 32-bit machine and tests can pass on a 32-bit
987 * machine. If it was exactly UINT32_MAX, then this code would not
988 * compile or run on a 32-bit machine and an #ifdef or some machine
989 * size detection would be needed reducing portability.
990 */
Laurence Lundblade3e0a45c2020-11-05 11:12:04 -0800991 if(uEndPosition >= QCBOR_MAX_ARRAY_OFFSET) {
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700992 pMe->uError = QCBOR_ERR_BUFFER_TOO_LARGE;
Laurence Lundblade3e0a45c2020-11-05 11:12:04 -0800993
994 } else {
Laurence Lundblade1fa579b2020-11-25 00:31:37 -0800995 /* Increase nesting level because this is a map or array. Cast
996 * from size_t to uin32_t is safe because of check above.
997 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -0700998 pMe->uError = Nesting_Increase(&(pMe->nesting), uMajorType, (uint32_t)uEndPosition);
Laurence Lundblade1ef8b2d2018-12-14 23:13:34 -0800999 }
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001000}
1001
Laurence Lundblade59289e52019-12-30 13:44:37 -08001002
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001003/**
1004 * @brief Semi-private method to open a map, array with indefinite length
Laurence Lundblade1fa579b2020-11-25 00:31:37 -08001005 *
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001006 * @param[in] pMe The context to add to.
1007 * @param[in] uMajorType The major CBOR type to close
1008 *
1009 * Call QCBOREncode_OpenArrayIndefiniteLength() or
1010 * QCBOREncode_OpenMapIndefiniteLength() instead of this.
Laurence Lundblade1fa579b2020-11-25 00:31:37 -08001011 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001012void
1013QCBOREncode_Private_OpenMapOrArrayIndefiniteLength(QCBOREncodeContext *pMe,
1014 const uint8_t uMajorType)
Jan Jongboom4a93a662019-07-25 08:44:58 +02001015{
Laurence Lundblade1fa579b2020-11-25 00:31:37 -08001016 /* Insert the indefinite length marker (0x9f for arrays, 0xbf for maps) */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001017 QCBOREncode_Private_AppendCBORHead(pMe, uMajorType, 0, 0);
Laurence Lundblade1fa579b2020-11-25 00:31:37 -08001018
1019 /* Call the definite-length opener just to do the bookkeeping for
1020 * nesting. It will record the position of the opening item in the
1021 * encoded output but this is not used when closing this open.
1022 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001023 QCBOREncode_Private_OpenMapOrArray(pMe, uMajorType);
Jan Jongboom4a93a662019-07-25 08:44:58 +02001024}
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001025
Laurence Lundbladeee851742020-01-08 08:37:05 -08001026
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001027/**
1028 * @brief Semi-private method to close a map, array or bstr wrapped CBOR
1029 *
1030 * @param[in] pMe The context to add to.
1031 * @param[in] uMajorType The major CBOR type to close.
1032 *
1033 * Call QCBOREncode_CloseArray() or QCBOREncode_CloseMap() instead of this.
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001034 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001035void
1036QCBOREncode_Private_CloseMapOrArray(QCBOREncodeContext *pMe,
1037 const uint8_t uMajorType)
Laurence Lundbladea954db92018-09-28 19:27:31 -07001038{
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001039 QCBOREncode_Private_InsertCBORHead(pMe, uMajorType, Nesting_GetCount(&(pMe->nesting)));
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +00001040}
Laurence Lundblade3aee3a32018-12-17 16:17:45 -08001041
Laurence Lundblade3aee3a32018-12-17 16:17:45 -08001042
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001043
1044/**
1045 * @brief Decode a CBOR item head.
1046 *
1047 * @param[in] pUInBuf UsefulInputBuf to read from.
1048 * @param[out] pnMajorType Major type of decoded head.
1049 * @param[out] puArgument Argument of decoded head.
1050 * @param[out] pnAdditionalInfo Additional info from decoded head.
1051 *
1052 * @return SUCCESS if a head was decoded
1053 * HIT_END if there were not enough bytes to decode a head
1054 * UNSUPPORTED if the decoded item is not one that is supported
1055 *
1056 * This is copied from qcbor_decode.c rather than referenced. This
1057 * makes the core decoder 60 bytes smaller because it gets inlined.
1058 * It would not get inlined if it was referenced. It is important to
1059 * make the core decoder as small as possible. The copy here does make
1060 * map sorting 200 bytes bigger, but map sorting is rarely used in
1061 * environments that need small object code. It would also make
1062 * qcbor_encode.c depend on qcbor_decode.c
1063 *
1064 * This is also super stable and tested. It implements the very
1065 * well-defined part of CBOR that will never change. So this won't
1066 * change.
1067 */
1068static QCBORError
1069QCBOREncodePriv_DecodeHead(UsefulInputBuf *pUInBuf,
1070 int *pnMajorType,
1071 uint64_t *puArgument,
1072 int *pnAdditionalInfo)
1073{
1074 QCBORError uReturn;
1075
1076 /* Get the initial byte that every CBOR data item has and break it
1077 * down. */
1078 const int nInitialByte = (int)UsefulInputBuf_GetByte(pUInBuf);
1079 const int nTmpMajorType = nInitialByte >> 5;
1080 const int nAdditionalInfo = nInitialByte & 0x1f;
1081
1082 /* Where the argument accumulates */
1083 uint64_t uArgument;
1084
1085 if(nAdditionalInfo >= LEN_IS_ONE_BYTE && nAdditionalInfo <= LEN_IS_EIGHT_BYTES) {
1086 /* Need to get 1,2,4 or 8 additional argument bytes. Map
1087 * LEN_IS_ONE_BYTE..LEN_IS_EIGHT_BYTES to actual length.
1088 */
1089 static const uint8_t aIterate[] = {1,2,4,8};
1090
1091 /* Loop getting all the bytes in the argument */
1092 uArgument = 0;
1093 for(int i = aIterate[nAdditionalInfo - LEN_IS_ONE_BYTE]; i; i--) {
1094 /* This shift and add gives the endian conversion. */
1095 uArgument = (uArgument << 8) + UsefulInputBuf_GetByte(pUInBuf);
1096 }
1097 } else if(nAdditionalInfo >= ADDINFO_RESERVED1 && nAdditionalInfo <= ADDINFO_RESERVED3) {
1098 /* The reserved and thus-far unused additional info values */
1099 uReturn = QCBOR_ERR_UNSUPPORTED;
1100 goto Done;
1101 } else {
1102 /* Less than 24, additional info is argument or 31, an
1103 * indefinite-length. No more bytes to get.
1104 */
1105 uArgument = (uint64_t)nAdditionalInfo;
1106 }
1107
1108 if(UsefulInputBuf_GetError(pUInBuf)) {
1109 uReturn = QCBOR_ERR_HIT_END;
1110 goto Done;
1111 }
1112
1113 /* All successful if arrived here. */
1114 uReturn = QCBOR_SUCCESS;
1115 *pnMajorType = nTmpMajorType;
1116 *puArgument = uArgument;
1117 *pnAdditionalInfo = nAdditionalInfo;
1118
1119Done:
1120 return uReturn;
1121}
1122
1123
1124/**
1125 * @brief Consume the next item from a UsefulInputBuf.
1126 *
1127 * @param[in] pInBuf UsefulInputBuf from which to consume item.
1128 *
1129 * Recursive, but stack usage is light and encoding depth limit
1130 */
1131static QCBORError
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001132QCBOR_Private_ConsumeNext(UsefulInputBuf *pInBuf)
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001133{
1134 int nMajor;
1135 uint64_t uArgument;
1136 int nAdditional;
1137 uint16_t uItemCount;
1138 uint16_t uMul;
1139 uint16_t i;
1140 QCBORError uCBORError;
1141
1142 uCBORError = QCBOREncodePriv_DecodeHead(pInBuf, &nMajor, &uArgument, &nAdditional);
1143 if(uCBORError != QCBOR_SUCCESS) {
1144 return uCBORError;
1145 }
1146
1147 uMul = 1;
1148
1149 switch(nMajor) {
1150 case CBOR_MAJOR_TYPE_POSITIVE_INT: /* Major type 0 */
1151 case CBOR_MAJOR_TYPE_NEGATIVE_INT: /* Major type 1 */
1152 break;
1153
1154 case CBOR_MAJOR_TYPE_SIMPLE:
1155 return uArgument == CBOR_SIMPLE_BREAK ? 1 : 0;
1156 break;
1157
1158 case CBOR_MAJOR_TYPE_BYTE_STRING:
1159 case CBOR_MAJOR_TYPE_TEXT_STRING:
1160 if(nAdditional == LEN_IS_INDEFINITE) {
1161 /* Segments of indefinite length */
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001162 while(QCBOR_Private_ConsumeNext(pInBuf) == 0);
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001163 }
1164 (void)UsefulInputBuf_GetBytes(pInBuf, uArgument);
1165 break;
1166
1167 case CBOR_MAJOR_TYPE_TAG:
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001168 QCBOR_Private_ConsumeNext(pInBuf);
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001169 break;
1170
1171 case CBOR_MAJOR_TYPE_MAP:
1172 uMul = 2;
1173 /* Fallthrough */
1174 case CBOR_MAJOR_TYPE_ARRAY:
1175 uItemCount = (uint16_t)uArgument * uMul;
1176 if(nAdditional == LEN_IS_INDEFINITE) {
1177 uItemCount = UINT16_MAX;
1178 }
1179 for(i = uItemCount; i > 0; i--) {
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001180 if(QCBOR_Private_ConsumeNext(pInBuf)) {
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001181 /* End of indefinite length */
1182 break;
1183 }
1184 }
1185 break;
1186 }
1187
1188 return QCBOR_SUCCESS;
1189}
1190
1191
1192/**
1193 * @brief Decoded next item to get its length.
1194 *
1195 * Decode the next item in map no matter what type it is. It works
1196 * recursively when an item is a map or array It returns offset just
1197 * past the item decoded or zero there are no more items in the output
1198 * buffer.
1199 *
1200 * This doesn't distinguish between end of the input and an error
1201 * because it is used to decode stuff we encoded into a buffer, not
1202 * stuff that came in from outside. We still want a check for safety
1203 * in case of bugs here, but it is OK to report end of input on error.
1204 */
1205static uint32_t
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001206QCBOREncode_Private_DecodeNextInMap(QCBOREncodeContext *pMe, uint32_t uStart)
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001207{
1208 UsefulInputBuf InBuf;
1209 UsefulBufC EncodedMapBytes;
1210 QCBORError uCBORError;
1211
1212 EncodedMapBytes = UsefulOutBuf_OutUBufOffset(&(pMe->OutBuf), uStart);
1213 if(UsefulBuf_IsNULLC(EncodedMapBytes)) {
1214 return 0;
1215 }
1216
1217 UsefulInputBuf_Init(&InBuf, EncodedMapBytes);
1218
1219 /* This is always used on maps, so consume two, the label and the value */
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001220 uCBORError = QCBOR_Private_ConsumeNext(&InBuf);
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001221 if(uCBORError) {
1222 return 0;
1223 }
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001224 uCBORError = QCBOR_Private_ConsumeNext(&InBuf);
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001225 if(uCBORError) {
1226 return 0;
1227 }
1228
1229 /* Cast is safe because this is QCBOR which limits sizes to UINT32_MAX */
1230 return (uint32_t)UsefulInputBuf_Tell(&InBuf);
1231}
1232
1233
1234/**
1235 * @brief Sort items lexographically by encoded labels.
1236 *
1237 * @param[in] pMe Encoding context.
1238 * @param[in] uStart Offset in outbuf of first item for sorting.
1239 *
1240 * This reaches into the UsefulOutBuf in the encoding context and
1241 * sorts encoded CBOR items. The byte offset start of the items is at
1242 * @c uStart and it goes to the end of valid bytes in the
1243 * UsefulOutBuf.
1244 */
1245static void
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001246QCBOREncode_Private_SortMap(QCBOREncodeContext *pMe, uint32_t uStart)
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001247{
1248 bool bSwapped;
1249 int nComparison;
1250 uint32_t uLen2;
1251 uint32_t uLen1;
1252 uint32_t uStart1;
1253 uint32_t uStart2;
1254
1255 if(pMe->uError != QCBOR_SUCCESS) {
1256 return;
1257 }
1258
1259 /* Bubble sort because the sizes of all the items are not the
1260 * same. It works with adjacent pairs so the swap is not too
1261 * difficult even though sizes are different.
1262 *
1263 * While bubble sort is n-squared, it seems OK here because n will
1264 * usually be small and the comparison and swap functions aren't
1265 * too CPU intensive.
1266 *
1267 * Another approach would be to have an array of offsets to the
1268 * items. However this requires memory allocation and the swap
1269 * operation for quick sort or such is complicated because the item
1270 * sizes are not the same and overlap may occur in the bytes being
1271 * swapped.
1272 */
1273 do {
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001274 uLen1 = QCBOREncode_Private_DecodeNextInMap(pMe, uStart);
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001275 if(uLen1 == 0) {
1276 /* It's an empty map. Nothing to do. */
1277 break;
1278 }
1279 uStart1 = uStart;
1280 uStart2 = uStart1 + uLen1;
1281 bSwapped = false;
1282
1283 while(1) {
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001284 uLen2 = QCBOREncode_Private_DecodeNextInMap(pMe, uStart2);
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001285 if(uLen2 == 0) {
1286 break;
1287 }
1288
1289 nComparison = UsefulOutBuf_Compare(&(pMe->OutBuf), uStart1, uStart2);
1290 if(nComparison < 0) {
1291 UsefulOutBuf_Swap(&(pMe->OutBuf), uStart1, uStart2, uStart2 + uLen2);
1292 uStart1 = uStart1 + uLen2;
1293 bSwapped = true;
1294 } else {
1295 uStart1 = uStart2;
1296 }
1297 uStart2 = uStart2 + uLen2;
1298 }
1299 } while(bSwapped);
1300}
1301
1302
1303/*
1304 * Public functions for closing sorted maps. See qcbor/qcbor_encode.h
1305 */
1306void QCBOREncode_CloseAndSortMap(QCBOREncodeContext *pMe)
1307{
1308 uint32_t uStart;
1309
1310 /* The Header for the map we are about to sort hasn't been
1311 * inserted yet, so uStart is the position of the first item
1312 * and the end out the UsefulOutBuf data is the end of the
1313 * items we are about to sort.
1314 */
1315 uStart = Nesting_GetStartPos(&(pMe->nesting));
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001316 QCBOREncode_Private_SortMap(pMe, uStart);
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001317
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001318 QCBOREncode_Private_InsertCBORHead(pMe, CBOR_MAJOR_TYPE_MAP, Nesting_GetCount(&(pMe->nesting)));
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001319}
1320
1321
1322/*
1323 * Public functions for closing sorted maps. See qcbor/qcbor_encode.h
1324 */
1325void QCBOREncode_CloseAndSortMapIndef(QCBOREncodeContext *pMe)
1326{
1327 uint32_t uStart;
1328
1329 uStart = Nesting_GetStartPos(&(pMe->nesting));
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001330 QCBOREncode_Private_SortMap(pMe, uStart);
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001331
Laurence Lundblade3b703b82024-01-27 20:17:20 -07001332 QCBOREncode_Private_CloseMapOrArrayIndefiniteLength(pMe, CBOR_MAJOR_NONE_TYPE_MAP_INDEFINITE_LEN);
Laurence Lundbladed6e13022023-11-26 10:14:02 -07001333}
1334
1335
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +00001336/*
Laurence Lundblade1fa579b2020-11-25 00:31:37 -08001337 * Public functions for closing bstr wrapping. See qcbor/qcbor_encode.h
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +00001338 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001339void
1340QCBOREncode_CloseBstrWrap2(QCBOREncodeContext *pMe,
1341 const bool bIncludeCBORHead,
1342 UsefulBufC *pWrappedCBOR)
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +00001343{
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001344 const size_t uInsertPosition = Nesting_GetStartPos(&(pMe->nesting));
1345 const size_t uEndPosition = UsefulOutBuf_GetEndPosition(&(pMe->OutBuf));
Laurence Lundblade3aee3a32018-12-17 16:17:45 -08001346
Laurence Lundblade1fa579b2020-11-25 00:31:37 -08001347 /* This subtraction can't go negative because the UsefulOutBuf
1348 * always only grows and never shrinks. UsefulOutBut itself also
1349 * has defenses such that it won't write where it should not even
1350 * if given incorrect input lengths.
1351 */
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +00001352 const size_t uBstrLen = uEndPosition - uInsertPosition;
1353
Laurence Lundblade1fa579b2020-11-25 00:31:37 -08001354 /* Actually insert */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001355 QCBOREncode_Private_InsertCBORHead(pMe, CBOR_MAJOR_TYPE_BYTE_STRING, uBstrLen);
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +00001356
1357 if(pWrappedCBOR) {
Laurence Lundblade1fa579b2020-11-25 00:31:37 -08001358 /* Return pointer and length to the enclosed encoded CBOR. The
1359 * intended use is for it to be hashed (e.g., SHA-256) in a COSE
1360 * implementation. This must be used right away, as the pointer
1361 * and length go invalid on any subsequent calls to this
1362 * function because there might be calls to
1363 * InsertEncodedTypeAndNumber() that slides data to the right.
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +00001364 */
1365 size_t uStartOfNew = uInsertPosition;
1366 if(!bIncludeCBORHead) {
Laurence Lundblade1fa579b2020-11-25 00:31:37 -08001367 /* Skip over the CBOR head to just get the inserted bstr */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001368 const size_t uNewEndPosition = UsefulOutBuf_GetEndPosition(&(pMe->OutBuf));
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +00001369 uStartOfNew += uNewEndPosition - uEndPosition;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001370 }
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001371 const UsefulBufC PartialResult = UsefulOutBuf_OutUBuf(&(pMe->OutBuf));
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +00001372 *pWrappedCBOR = UsefulBuf_Tail(PartialResult, uStartOfNew);
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001373 }
1374}
1375
Laurence Lundbladeee851742020-01-08 08:37:05 -08001376
Jan Jongboom4a93a662019-07-25 08:44:58 +02001377/*
Laurence Lundblade8d3b8552021-06-10 11:11:54 -07001378 * Public function for canceling a bstr wrap. See qcbor/qcbor_encode.h
1379 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001380void
1381QCBOREncode_CancelBstrWrap(QCBOREncodeContext *pMe)
Laurence Lundblade8d3b8552021-06-10 11:11:54 -07001382{
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001383 if(QCBOREncode_Private_CheckDecreaseNesting(pMe, CBOR_MAJOR_TYPE_BYTE_STRING)) {
Laurence Lundblade274ddef2022-05-17 09:12:23 -07001384 return;
1385 }
1386
Laurence Lundblade8d3b8552021-06-10 11:11:54 -07001387#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Laurence Lundblade274ddef2022-05-17 09:12:23 -07001388 const size_t uCurrent = UsefulOutBuf_GetEndPosition(&(pMe->OutBuf));
1389 if(pMe->nesting.pCurrentNesting->uStart != uCurrent) {
1390 pMe->uError = QCBOR_ERR_CANNOT_CANCEL;
1391 return;
Laurence Lundblade8d3b8552021-06-10 11:11:54 -07001392 }
1393 /* QCBOREncode_CancelBstrWrap() can't correctly undo
1394 * QCBOREncode_BstrWrapInMap() or QCBOREncode_BstrWrapInMapN(). It
1395 * can't undo the labels they add. It also doesn't catch the error
1396 * of using it this way. QCBOREncode_CancelBstrWrap() is used
1397 * infrequently and the the result is incorrect CBOR, not a
1398 * security hole, so no extra code or state is added to handle this
1399 * condition.
1400 */
1401#endif /* QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
1402
1403 Nesting_Decrease(&(pMe->nesting));
1404 Nesting_Decrement(&(pMe->nesting));
1405}
1406
1407
1408/*
Laurence Lundbladeb24faef2022-04-26 11:03:08 -06001409 * Public function for opening a byte string. See qcbor/qcbor_encode.h
1410 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001411void
1412QCBOREncode_OpenBytes(QCBOREncodeContext *pMe, UsefulBuf *pPlace)
Laurence Lundbladeb24faef2022-04-26 11:03:08 -06001413{
1414 *pPlace = UsefulOutBuf_GetOutPlace(&(pMe->OutBuf));
Laurence Lundbladeb24faef2022-04-26 11:03:08 -06001415#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Paul Liétar79789772022-07-26 20:33:18 +01001416 // TODO: is this right?
1417 uint8_t uMajorType = Nesting_GetMajorType(&(pMe->nesting));
1418 if(uMajorType == CBOR_MAJOR_NONE_TYPE_OPEN_BSTR) {
1419 pMe->uError = QCBOR_ERR_OPEN_BYTE_STRING;
1420 return;
1421 }
Laurence Lundbladeb24faef2022-04-26 11:03:08 -06001422#endif /* QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
1423
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001424 QCBOREncode_Private_OpenMapOrArray(pMe, CBOR_MAJOR_NONE_TYPE_OPEN_BSTR);
Laurence Lundbladeb24faef2022-04-26 11:03:08 -06001425}
1426
1427
1428/*
1429 * Public function for closing a byte string. See qcbor/qcbor_encode.h
1430 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001431void
1432QCBOREncode_CloseBytes(QCBOREncodeContext *pMe, const size_t uAmount)
Laurence Lundbladeb24faef2022-04-26 11:03:08 -06001433{
1434 UsefulOutBuf_Advance(&(pMe->OutBuf), uAmount);
1435 if(UsefulOutBuf_GetError(&(pMe->OutBuf))) {
1436 /* Advance too far. Normal off-end error handling in effect here. */
1437 return;
1438 }
1439
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001440 QCBOREncode_Private_InsertCBORHead(pMe, CBOR_MAJOR_NONE_TYPE_OPEN_BSTR, uAmount);
Laurence Lundbladeb24faef2022-04-26 11:03:08 -06001441}
1442
1443
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001444/**
1445 * @brief Semi-private method to close a map, array with indefinite length
1446 *
1447 * @param[in] pMe The context to add to.
1448 * @param[in] uMajorType The major CBOR type to close.
1449 *
1450 * Call QCBOREncode_CloseArrayIndefiniteLength() or
1451 * QCBOREncode_CloseMapIndefiniteLength() instead of this.
Jan Jongboom4a93a662019-07-25 08:44:58 +02001452 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001453void
1454QCBOREncode_Private_CloseMapOrArrayIndefiniteLength(QCBOREncodeContext *pMe,
1455 const uint8_t uMajorType)
Jan Jongboom4a93a662019-07-25 08:44:58 +02001456{
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001457 if(QCBOREncode_Private_CheckDecreaseNesting(pMe, uMajorType)) {
Laurence Lundblade274ddef2022-05-17 09:12:23 -07001458 return;
Jan Jongboom4a93a662019-07-25 08:44:58 +02001459 }
Laurence Lundbladedaefdec2020-11-02 20:22:03 -08001460
Laurence Lundblade1fa579b2020-11-25 00:31:37 -08001461 /* Append the break marker (0xff for both arrays and maps) */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001462 QCBOREncode_Private_AppendCBORHead(pMe, CBOR_MAJOR_NONE_TYPE_SIMPLE_BREAK, CBOR_SIMPLE_BREAK, 0);
Laurence Lundblade274ddef2022-05-17 09:12:23 -07001463 Nesting_Decrease(&(pMe->nesting));
Jan Jongboom4a93a662019-07-25 08:44:58 +02001464}
1465
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001466
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001467/*
Laurence Lundblade8d3b8552021-06-10 11:11:54 -07001468 * Public function to finish and get the encoded result. See qcbor/qcbor_encode.h
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001469 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001470QCBORError
1471QCBOREncode_Finish(QCBOREncodeContext *pMe, UsefulBufC *pEncodedCBOR)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001472{
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001473 QCBORError uReturn = QCBOREncode_GetErrorState(pMe);
Laurence Lundblade3aee3a32018-12-17 16:17:45 -08001474
Laurence Lundblade067035b2018-11-28 17:35:25 -08001475 if(uReturn != QCBOR_SUCCESS) {
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001476 goto Done;
Laurence Lundblade067035b2018-11-28 17:35:25 -08001477 }
Laurence Lundblade3aee3a32018-12-17 16:17:45 -08001478
Laurence Lundbladedaefdec2020-11-02 20:22:03 -08001479#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001480 if(Nesting_IsInNest(&(pMe->nesting))) {
Laurence Lundblade067035b2018-11-28 17:35:25 -08001481 uReturn = QCBOR_ERR_ARRAY_OR_MAP_STILL_OPEN;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001482 goto Done;
1483 }
Laurence Lundbladee2c893c2020-12-26 17:41:53 -08001484#endif /* QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
Laurence Lundblade3aee3a32018-12-17 16:17:45 -08001485
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001486 *pEncodedCBOR = UsefulOutBuf_OutUBuf(&(pMe->OutBuf));
Laurence Lundblade3aee3a32018-12-17 16:17:45 -08001487
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001488Done:
Laurence Lundblade067035b2018-11-28 17:35:25 -08001489 return uReturn;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001490}
1491
Laurence Lundblade0595e932018-11-02 22:22:47 +07001492
Laurence Lundblade067035b2018-11-28 17:35:25 -08001493/*
Laurence Lundblade1fa579b2020-11-25 00:31:37 -08001494 * Public functions to get size of the encoded result. See qcbor/qcbor_encode.h
Laurence Lundblade067035b2018-11-28 17:35:25 -08001495 */
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001496QCBORError
1497QCBOREncode_FinishGetSize(QCBOREncodeContext *pMe, size_t *puEncodedLen)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001498{
Laurence Lundbladeda3f0822018-09-18 19:49:02 -07001499 UsefulBufC Enc;
Laurence Lundblade3aee3a32018-12-17 16:17:45 -08001500
Laurence Lundblade8e36f812024-01-26 10:59:29 -07001501 QCBORError nReturn = QCBOREncode_Finish(pMe, &Enc);
Laurence Lundblade3aee3a32018-12-17 16:17:45 -08001502
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001503 if(nReturn == QCBOR_SUCCESS) {
Laurence Lundbladeda3f0822018-09-18 19:49:02 -07001504 *puEncodedLen = Enc.len;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001505 }
Laurence Lundblade3aee3a32018-12-17 16:17:45 -08001506
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001507 return nReturn;
1508}