Coverage Report

Created: 2025-08-29 06:03

/src/nanopb/pb_common.c
Line
Count
Source (jump to first uncovered line)
1
/* pb_common.c: Common support functions for pb_encode.c and pb_decode.c.
2
 *
3
 * 2014 Petteri Aimonen <jpa@kapsi.fi>
4
 */
5
6
#include "pb_common.h"
7
8
static bool load_descriptor_values(pb_field_iter_t *iter)
9
4.65M
{
10
4.65M
    uint32_t word0;
11
4.65M
    uint32_t data_offset;
12
4.65M
    int_least8_t size_offset;
13
14
4.65M
    if (iter->index >= iter->descriptor->field_count)
15
230k
        return false;
16
17
4.42M
    word0 = PB_PROGMEM_READU32(iter->descriptor->field_info[iter->field_info_index]);
18
4.42M
    iter->type = (pb_type_t)((word0 >> 8) & 0xFF);
19
20
4.42M
    switch(word0 & 3)
21
4.42M
    {
22
801k
        case 0: {
23
            /* 1-word format */
24
801k
            iter->array_size = 1;
25
801k
            iter->tag = (pb_size_t)((word0 >> 2) & 0x3F);
26
801k
            size_offset = (int_least8_t)((word0 >> 24) & 0x0F);
27
801k
            data_offset = (word0 >> 16) & 0xFF;
28
801k
            iter->data_size = (pb_size_t)((word0 >> 28) & 0x0F);
29
801k
            break;
30
0
        }
31
32
3.01M
        case 1: {
33
            /* 2-word format */
34
3.01M
            uint32_t word1 = PB_PROGMEM_READU32(iter->descriptor->field_info[iter->field_info_index + 1]);
35
36
3.01M
            iter->array_size = (pb_size_t)((word0 >> 16) & 0x0FFF);
37
3.01M
            iter->tag = (pb_size_t)(((word0 >> 2) & 0x3F) | ((word1 >> 28) << 6));
38
3.01M
            size_offset = (int_least8_t)((word0 >> 28) & 0x0F);
39
3.01M
            data_offset = word1 & 0xFFFF;
40
3.01M
            iter->data_size = (pb_size_t)((word1 >> 16) & 0x0FFF);
41
3.01M
            break;
42
0
        }
43
44
468k
        case 2: {
45
            /* 4-word format */
46
468k
            uint32_t word1 = PB_PROGMEM_READU32(iter->descriptor->field_info[iter->field_info_index + 1]);
47
468k
            uint32_t word2 = PB_PROGMEM_READU32(iter->descriptor->field_info[iter->field_info_index + 2]);
48
468k
            uint32_t word3 = PB_PROGMEM_READU32(iter->descriptor->field_info[iter->field_info_index + 3]);
49
50
468k
            iter->array_size = (pb_size_t)(word0 >> 16);
51
468k
            iter->tag = (pb_size_t)(((word0 >> 2) & 0x3F) | ((word1 >> 8) << 6));
52
468k
            size_offset = (int_least8_t)(word1 & 0xFF);
53
468k
            data_offset = word2;
54
468k
            iter->data_size = (pb_size_t)word3;
55
468k
            break;
56
0
        }
57
58
143k
        default: {
59
            /* 8-word format */
60
143k
            uint32_t word1 = PB_PROGMEM_READU32(iter->descriptor->field_info[iter->field_info_index + 1]);
61
143k
            uint32_t word2 = PB_PROGMEM_READU32(iter->descriptor->field_info[iter->field_info_index + 2]);
62
143k
            uint32_t word3 = PB_PROGMEM_READU32(iter->descriptor->field_info[iter->field_info_index + 3]);
63
143k
            uint32_t word4 = PB_PROGMEM_READU32(iter->descriptor->field_info[iter->field_info_index + 4]);
64
65
143k
            iter->array_size = (pb_size_t)word4;
66
143k
            iter->tag = (pb_size_t)(((word0 >> 2) & 0x3F) | ((word1 >> 8) << 6));
67
143k
            size_offset = (int_least8_t)(word1 & 0xFF);
68
143k
            data_offset = word2;
69
143k
            iter->data_size = (pb_size_t)word3;
70
143k
            break;
71
0
        }
72
4.42M
    }
73
74
4.42M
    if (!iter->message)
75
0
    {
76
        /* Avoid doing arithmetic on null pointers, it is undefined */
77
0
        iter->pField = NULL;
78
0
        iter->pSize = NULL;
79
0
    }
80
4.42M
    else
81
4.42M
    {
82
4.42M
        iter->pField = (char*)iter->message + data_offset;
83
84
4.42M
        if (size_offset)
85
742k
        {
86
742k
            iter->pSize = (char*)iter->pField - size_offset;
87
742k
        }
88
3.68M
        else if (PB_HTYPE(iter->type) == PB_HTYPE_REPEATED &&
89
3.68M
                 (PB_ATYPE(iter->type) == PB_ATYPE_STATIC ||
90
54.8k
                  PB_ATYPE(iter->type) == PB_ATYPE_POINTER))
91
54.8k
        {
92
            /* Fixed count array */
93
54.8k
            iter->pSize = &iter->array_size;
94
54.8k
        }
95
3.63M
        else
96
3.63M
        {
97
3.63M
            iter->pSize = NULL;
98
3.63M
        }
99
100
4.42M
        if (PB_ATYPE(iter->type) == PB_ATYPE_POINTER && iter->pField != NULL)
101
4.23M
        {
102
4.23M
            iter->pData = *(void**)iter->pField;
103
4.23M
        }
104
188k
        else
105
188k
        {
106
188k
            iter->pData = iter->pField;
107
188k
        }
108
4.42M
    }
109
110
4.42M
    if (PB_LTYPE_IS_SUBMSG(iter->type))
111
521k
    {
112
521k
        iter->submsg_desc = iter->descriptor->submsg_info[iter->submessage_index];
113
521k
    }
114
3.90M
    else
115
3.90M
    {
116
3.90M
        iter->submsg_desc = NULL;
117
3.90M
    }
118
119
4.42M
    return true;
120
4.42M
}
121
122
static void advance_iterator(pb_field_iter_t *iter)
123
13.3M
{
124
13.3M
    iter->index++;
125
126
13.3M
    if (iter->index >= iter->descriptor->field_count)
127
649k
    {
128
        /* Restart */
129
649k
        iter->index = 0;
130
649k
        iter->field_info_index = 0;
131
649k
        iter->submessage_index = 0;
132
649k
        iter->required_field_index = 0;
133
649k
    }
134
12.7M
    else
135
12.7M
    {
136
        /* Increment indexes based on previous field type.
137
         * All field info formats have the following fields:
138
         * - lowest 2 bits tell the amount of words in the descriptor (2^n words)
139
         * - bits 2..7 give the lowest bits of tag number.
140
         * - bits 8..15 give the field type.
141
         */
142
12.7M
        uint32_t prev_descriptor = PB_PROGMEM_READU32(iter->descriptor->field_info[iter->field_info_index]);
143
12.7M
        pb_type_t prev_type = (prev_descriptor >> 8) & 0xFF;
144
12.7M
        pb_size_t descriptor_len = (pb_size_t)(1 << (prev_descriptor & 3));
145
146
        /* Add to fields.
147
         * The cast to pb_size_t is needed to avoid -Wconversion warning.
148
         * Because the data is is constants from generator, there is no danger of overflow.
149
         */
150
12.7M
        iter->field_info_index = (pb_size_t)(iter->field_info_index + descriptor_len);
151
12.7M
        iter->required_field_index = (pb_size_t)(iter->required_field_index + (PB_HTYPE(prev_type) == PB_HTYPE_REQUIRED));
152
12.7M
        iter->submessage_index = (pb_size_t)(iter->submessage_index + PB_LTYPE_IS_SUBMSG(prev_type));
153
12.7M
    }
154
13.3M
}
155
156
bool pb_field_iter_begin(pb_field_iter_t *iter, const pb_msgdesc_t *desc, void *message)
157
687k
{
158
687k
    memset(iter, 0, sizeof(*iter));
159
160
687k
    iter->descriptor = desc;
161
687k
    iter->message = message;
162
163
687k
    return load_descriptor_values(iter);
164
687k
}
165
166
bool pb_field_iter_begin_extension(pb_field_iter_t *iter, pb_extension_t *extension)
167
83.9k
{
168
83.9k
    const pb_msgdesc_t *msg = (const pb_msgdesc_t*)extension->type->arg;
169
83.9k
    bool status;
170
171
83.9k
    uint32_t word0 = PB_PROGMEM_READU32(msg->field_info[0]);
172
83.9k
    if (PB_ATYPE(word0 >> 8) == PB_ATYPE_POINTER)
173
0
    {
174
        /* For pointer extensions, the pointer is stored directly
175
         * in the extension structure. This avoids having an extra
176
         * indirection. */
177
0
        status = pb_field_iter_begin(iter, msg, &extension->dest);
178
0
    }
179
83.9k
    else
180
83.9k
    {
181
83.9k
        status = pb_field_iter_begin(iter, msg, extension->dest);
182
83.9k
    }
183
184
83.9k
    iter->pSize = &extension->found;
185
83.9k
    return status;
186
83.9k
}
187
188
bool pb_field_iter_next(pb_field_iter_t *iter)
189
2.99M
{
190
2.99M
    advance_iterator(iter);
191
2.99M
    (void)load_descriptor_values(iter);
192
2.99M
    return iter->index != 0;
193
2.99M
}
194
195
bool pb_field_iter_find(pb_field_iter_t *iter, uint32_t tag)
196
30.6M
{
197
30.6M
    if (iter->tag == tag)
198
29.1M
    {
199
29.1M
        return true; /* Nothing to do, correct field already. */
200
29.1M
    }
201
1.44M
    else if (tag > iter->descriptor->largest_tag)
202
557k
    {
203
557k
        return false;
204
557k
    }
205
883k
    else
206
883k
    {
207
883k
        pb_size_t start = iter->index;
208
883k
        uint32_t fieldinfo;
209
210
883k
        if (tag < iter->tag)
211
211k
        {
212
            /* Fields are in tag number order, so we know that tag is between
213
             * 0 and our start position. Setting index to end forces
214
             * advance_iterator() call below to restart from beginning. */
215
211k
            iter->index = iter->descriptor->field_count;
216
211k
        }
217
218
883k
        do
219
10.2M
        {
220
            /* Advance iterator but don't load values yet */
221
10.2M
            advance_iterator(iter);
222
223
            /* Do fast check for tag number match */
224
10.2M
            fieldinfo = PB_PROGMEM_READU32(iter->descriptor->field_info[iter->field_info_index]);
225
226
10.2M
            if (((fieldinfo >> 2) & 0x3F) == (tag & 0x3F))
227
912k
            {
228
                /* Good candidate, check further */
229
912k
                (void)load_descriptor_values(iter);
230
231
912k
                if (iter->tag == tag &&
232
912k
                    PB_LTYPE(iter->type) != PB_LTYPE_EXTENSION)
233
826k
                {
234
                    /* Found it */
235
826k
                    return true;
236
826k
                }
237
912k
            }
238
10.2M
        } while (iter->index != start);
239
240
        /* Searched all the way back to start, and found nothing. */
241
57.5k
        (void)load_descriptor_values(iter);
242
57.5k
        return false;
243
883k
    }
244
30.6M
}
245
246
bool pb_field_iter_find_extension(pb_field_iter_t *iter)
247
10.3k
{
248
10.3k
    if (PB_LTYPE(iter->type) == PB_LTYPE_EXTENSION)
249
0
    {
250
0
        return true;
251
0
    }
252
10.3k
    else
253
10.3k
    {
254
10.3k
        pb_size_t start = iter->index;
255
10.3k
        uint32_t fieldinfo;
256
257
10.3k
        do
258
117k
        {
259
            /* Advance iterator but don't load values yet */
260
117k
            advance_iterator(iter);
261
262
            /* Do fast check for field type */
263
117k
            fieldinfo = PB_PROGMEM_READU32(iter->descriptor->field_info[iter->field_info_index]);
264
265
117k
            if (PB_LTYPE((fieldinfo >> 8) & 0xFF) == PB_LTYPE_EXTENSION)
266
3.55k
            {
267
3.55k
                return load_descriptor_values(iter);
268
3.55k
            }
269
117k
        } while (iter->index != start);
270
271
        /* Searched all the way back to start, and found nothing. */
272
6.83k
        (void)load_descriptor_values(iter);
273
6.83k
        return false;
274
10.3k
    }
275
10.3k
}
276
277
static void *pb_const_cast(const void *p)
278
220k
{
279
    /* Note: this casts away const, in order to use the common field iterator
280
     * logic for both encoding and decoding. The cast is done using union
281
     * to avoid spurious compiler warnings. */
282
220k
    union {
283
220k
        void *p1;
284
220k
        const void *p2;
285
220k
    } t;
286
220k
    t.p2 = p;
287
220k
    return t.p1;
288
220k
}
289
290
bool pb_field_iter_begin_const(pb_field_iter_t *iter, const pb_msgdesc_t *desc, const void *message)
291
217k
{
292
217k
    return pb_field_iter_begin(iter, desc, pb_const_cast(message));
293
217k
}
294
295
bool pb_field_iter_begin_extension_const(pb_field_iter_t *iter, const pb_extension_t *extension)
296
2.66k
{
297
2.66k
    return pb_field_iter_begin_extension(iter, (pb_extension_t*)pb_const_cast(extension));
298
2.66k
}
299
300
bool pb_default_field_callback(pb_istream_t *istream, pb_ostream_t *ostream, const pb_field_t *field)
301
0
{
302
0
    if (field->data_size == sizeof(pb_callback_t))
303
0
    {
304
0
        pb_callback_t *pCallback = (pb_callback_t*)field->pData;
305
306
0
        if (pCallback != NULL)
307
0
        {
308
0
            if (istream != NULL && pCallback->funcs.decode != NULL)
309
0
            {
310
0
                return pCallback->funcs.decode(istream, field, &pCallback->arg);
311
0
            }
312
313
0
            if (ostream != NULL && pCallback->funcs.encode != NULL)
314
0
            {
315
0
                return pCallback->funcs.encode(ostream, field, &pCallback->arg);
316
0
            }
317
0
        }
318
0
    }
319
320
0
    return true; /* Success, but didn't do anything */
321
322
0
}
323
324
#ifdef PB_VALIDATE_UTF8
325
326
/* This function checks whether a string is valid UTF-8 text.
327
 *
328
 * Algorithm is adapted from https://www.cl.cam.ac.uk/~mgk25/ucs/utf8_check.c
329
 * Original copyright: Markus Kuhn <http://www.cl.cam.ac.uk/~mgk25/> 2005-03-30
330
 * Licensed under "Short code license", which allows use under MIT license or
331
 * any compatible with it.
332
 */
333
334
bool pb_validate_utf8(const char *str)
335
{
336
    const pb_byte_t *s = (const pb_byte_t*)str;
337
    while (*s)
338
    {
339
        if (*s < 0x80)
340
        {
341
            /* 0xxxxxxx */
342
            s++;
343
        }
344
        else if ((s[0] & 0xe0) == 0xc0)
345
        {
346
            /* 110XXXXx 10xxxxxx */
347
            if ((s[1] & 0xc0) != 0x80 ||
348
                (s[0] & 0xfe) == 0xc0)                        /* overlong? */
349
                return false;
350
            else
351
                s += 2;
352
        }
353
        else if ((s[0] & 0xf0) == 0xe0)
354
        {
355
            /* 1110XXXX 10Xxxxxx 10xxxxxx */
356
            if ((s[1] & 0xc0) != 0x80 ||
357
                (s[2] & 0xc0) != 0x80 ||
358
                (s[0] == 0xe0 && (s[1] & 0xe0) == 0x80) ||    /* overlong? */
359
                (s[0] == 0xed && (s[1] & 0xe0) == 0xa0) ||    /* surrogate? */
360
                (s[0] == 0xef && s[1] == 0xbf &&
361
                (s[2] & 0xfe) == 0xbe))                 /* U+FFFE or U+FFFF? */
362
                return false;
363
            else
364
                s += 3;
365
        }
366
        else if ((s[0] & 0xf8) == 0xf0)
367
        {
368
            /* 11110XXX 10XXxxxx 10xxxxxx 10xxxxxx */
369
            if ((s[1] & 0xc0) != 0x80 ||
370
                (s[2] & 0xc0) != 0x80 ||
371
                (s[3] & 0xc0) != 0x80 ||
372
                (s[0] == 0xf0 && (s[1] & 0xf0) == 0x80) ||    /* overlong? */
373
                (s[0] == 0xf4 && s[1] > 0x8f) || s[0] > 0xf4) /* > U+10FFFF? */
374
                return false;
375
            else
376
                s += 4;
377
        }
378
        else
379
        {
380
            return false;
381
        }
382
    }
383
384
    return true;
385
}
386
387
#endif
388