Coverage Report

Created: 2026-09-28 07:09

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/nanopb/pb_decode.c
Line
Count
Source
1
/* pb_decode.c -- decode a protobuf using minimal resources
2
 *
3
 * 2011 Petteri Aimonen <jpa@kapsi.fi>
4
 */
5
6
/* Use the GCC warn_unused_result attribute to check that all return values
7
 * are propagated correctly. On other compilers, gcc before 3.4.0 and iar
8
 * before 9.40.1 just ignore the annotation.
9
 */
10
#if (defined(__GNUC__) && ((__GNUC__ > 3) || (__GNUC__ == 3 && __GNUC_MINOR__ >= 4))) || \
11
    (defined(__IAR_SYSTEMS_ICC__) && (__VER__ >= 9040001))
12
    #define checkreturn __attribute__((warn_unused_result))
13
#else
14
    #define checkreturn
15
#endif
16
17
#include "pb.h"
18
#include "pb_decode.h"
19
#include "pb_common.h"
20
21
/**************************************
22
 * Declarations internal to this file *
23
 **************************************/
24
25
static bool checkreturn buf_read(pb_istream_t *stream, pb_byte_t *buf, size_t count);
26
static bool checkreturn read_raw_value(pb_istream_t *stream, pb_wire_type_t wire_type, pb_byte_t *buf, size_t *size);
27
static bool checkreturn decode_basic_field(pb_istream_t *stream, pb_wire_type_t wire_type, pb_field_iter_t *field);
28
static bool checkreturn decode_static_field(pb_istream_t *stream, pb_wire_type_t wire_type, pb_field_iter_t *field);
29
static bool checkreturn decode_pointer_field(pb_istream_t *stream, pb_wire_type_t wire_type, pb_field_iter_t *field);
30
static bool checkreturn decode_callback_field(pb_istream_t *stream, pb_wire_type_t wire_type, pb_field_iter_t *field);
31
static bool checkreturn decode_field(pb_istream_t *stream, pb_wire_type_t wire_type, pb_field_iter_t *field);
32
static bool checkreturn default_extension_decoder(pb_istream_t *stream, pb_extension_t *extension, uint32_t tag, pb_wire_type_t wire_type);
33
static bool checkreturn decode_extension(pb_istream_t *stream, uint32_t tag, pb_wire_type_t wire_type, pb_extension_t *extension);
34
static bool pb_field_set_to_default(pb_field_iter_t *field);
35
static bool pb_message_set_to_defaults(pb_field_iter_t *iter);
36
static bool checkreturn pb_dec_bool(pb_istream_t *stream, const pb_field_iter_t *field);
37
static bool checkreturn pb_dec_varint(pb_istream_t *stream, const pb_field_iter_t *field);
38
static bool checkreturn pb_dec_bytes(pb_istream_t *stream, const pb_field_iter_t *field);
39
static bool checkreturn pb_dec_string(pb_istream_t *stream, const pb_field_iter_t *field);
40
static bool checkreturn pb_dec_submessage(pb_istream_t *stream, const pb_field_iter_t *field);
41
static bool checkreturn pb_dec_fixed_length_bytes(pb_istream_t *stream, const pb_field_iter_t *field);
42
static bool checkreturn pb_skip_varint(pb_istream_t *stream);
43
static bool checkreturn pb_skip_string(pb_istream_t *stream);
44
45
#ifdef PB_ENABLE_MALLOC
46
static bool checkreturn allocate_field(pb_istream_t *stream, void *pData, size_t data_size, size_t array_size);
47
static void initialize_pointer_field(void *pItem, pb_field_iter_t *field);
48
static bool checkreturn pb_release_union_field(pb_istream_t *stream, pb_field_iter_t *field);
49
static void pb_release_single_field(pb_field_iter_t *field);
50
#endif
51
52
#ifdef PB_WITHOUT_64BIT
53
#define pb_int64_t int32_t
54
#define pb_uint64_t uint32_t
55
#else
56
32.8M
#define pb_int64_t int64_t
57
20.1M
#define pb_uint64_t uint64_t
58
#endif
59
60
typedef struct {
61
    uint32_t bitfield[(PB_MAX_REQUIRED_FIELDS + 31) / 32];
62
} pb_fields_seen_t;
63
64
/*******************************
65
 * pb_istream_t implementation *
66
 *******************************/
67
68
static bool checkreturn buf_read(pb_istream_t *stream, pb_byte_t *buf, size_t count)
69
87.1M
{
70
87.1M
    const pb_byte_t *source = (const pb_byte_t*)stream->state;
71
87.1M
    stream->state = (pb_byte_t*)stream->state + count;
72
    
73
87.1M
    if (buf != NULL)
74
86.9M
    {
75
86.9M
        memcpy(buf, source, count * sizeof(pb_byte_t));
76
86.9M
    }
77
    
78
87.1M
    return true;
79
87.1M
}
80
81
bool checkreturn pb_read(pb_istream_t *stream, pb_byte_t *buf, size_t count)
82
2.43M
{
83
2.43M
    if (count == 0)
84
334k
        return true;
85
86
2.09M
#ifndef PB_BUFFER_ONLY
87
2.09M
  if (buf == NULL && stream->callback != buf_read)
88
114k
  {
89
    /* Skip input bytes */
90
114k
    pb_byte_t tmp[16];
91
249k
    while (count > 16)
92
134k
    {
93
134k
      if (!pb_read(stream, tmp, 16))
94
0
        return false;
95
      
96
134k
      count -= 16;
97
134k
    }
98
    
99
114k
    return pb_read(stream, tmp, count);
100
114k
  }
101
1.98M
#endif
102
103
1.98M
    if (stream->bytes_left < count)
104
115
        PB_RETURN_ERROR(stream, "end-of-stream");
105
    
106
1.98M
#ifndef PB_BUFFER_ONLY
107
1.98M
    if (!stream->callback(stream, buf, count))
108
0
        PB_RETURN_ERROR(stream, "io error");
109
#else
110
    if (!buf_read(stream, buf, count))
111
        return false;
112
#endif
113
    
114
1.98M
    if (stream->bytes_left < count)
115
0
        stream->bytes_left = 0;
116
1.98M
    else
117
1.98M
        stream->bytes_left -= count;
118
119
1.98M
    return true;
120
1.98M
}
121
122
/* Read a single byte from input stream. buf may not be NULL.
123
 * This is an optimization for the varint decoding. */
124
static bool checkreturn pb_readbyte(pb_istream_t *stream, pb_byte_t *buf)
125
120M
{
126
120M
    if (stream->bytes_left == 0)
127
204
        PB_RETURN_ERROR(stream, "end-of-stream");
128
129
120M
#ifndef PB_BUFFER_ONLY
130
120M
    if (!stream->callback(stream, buf, 1))
131
2.06k
        PB_RETURN_ERROR(stream, "io error");
132
#else
133
    *buf = *(const pb_byte_t*)stream->state;
134
    stream->state = (pb_byte_t*)stream->state + 1;
135
#endif
136
137
120M
    stream->bytes_left--;
138
    
139
120M
    return true;    
140
120M
}
141
142
pb_istream_t pb_istream_from_buffer(const pb_byte_t *buf, size_t msglen)
143
7.03k
{
144
7.03k
    pb_istream_t stream;
145
    /* Cast away the const from buf without a compiler error.  We are
146
     * careful to use it only in a const manner in the callbacks.
147
     */
148
7.03k
    union {
149
7.03k
        void *state;
150
7.03k
        const void *c_state;
151
7.03k
    } state;
152
#ifdef PB_BUFFER_ONLY
153
    stream.callback = NULL;
154
#else
155
7.03k
    stream.callback = &buf_read;
156
7.03k
#endif
157
7.03k
    state.c_state = buf;
158
7.03k
    stream.state = state.state;
159
7.03k
    stream.bytes_left = msglen;
160
7.03k
#ifndef PB_NO_ERRMSG
161
7.03k
    stream.errmsg = NULL;
162
7.03k
#endif
163
#ifdef PB_MESSAGE_NESTING_MAX
164
    stream.depth = 0;
165
#endif
166
7.03k
    return stream;
167
7.03k
}
168
169
170
/********************
171
 * Helper functions *
172
 ********************/
173
174
bool checkreturn pb_decode_varint32(pb_istream_t *stream, uint32_t *dest)
175
48.9M
{
176
48.9M
    pb_byte_t byte;
177
48.9M
    uint32_t result;
178
    
179
48.9M
    if (!pb_readbyte(stream, &byte))
180
2.16k
    {
181
2.16k
        return false;
182
2.16k
    }
183
    
184
48.9M
    if ((byte & 0x80) == 0)
185
27.6M
    {
186
        /* Quick case, 1 byte value */
187
27.6M
        result = byte;
188
27.6M
    }
189
21.2M
    else
190
21.2M
    {
191
        /* Multibyte case */
192
21.2M
        uint_fast8_t bitpos = 7;
193
21.2M
        result = byte & 0x7F;
194
        
195
21.2M
        do
196
21.3M
        {
197
21.3M
            if (!pb_readbyte(stream, &byte))
198
52
                return false;
199
            
200
21.3M
            if (bitpos >= 32)
201
6.51k
            {
202
                /* Note: The varint could have trailing 0x80 bytes, or 0xFF for negative. */
203
6.51k
                pb_byte_t sign_extension = (bitpos < 63) ? 0xFF : 0x01;
204
6.51k
                bool valid_extension = ((byte & 0x7F) == 0x00 ||
205
3.80k
                         ((result >> 31) != 0 && byte == sign_extension));
206
207
6.51k
                if (bitpos >= 64 || !valid_extension)
208
70
                {
209
70
                    PB_RETURN_ERROR(stream, "varint overflow");
210
70
                }
211
6.51k
            }
212
21.3M
            else if (bitpos == 28)
213
7.92k
            {
214
7.92k
                if ((byte & 0x70) != 0 && (byte & 0x78) != 0x78)
215
20
                {
216
20
                    PB_RETURN_ERROR(stream, "varint overflow");
217
20
                }
218
7.90k
                result |= (uint32_t)(byte & 0x0F) << bitpos;
219
7.90k
            }
220
21.3M
            else
221
21.3M
            {
222
21.3M
                result |= (uint32_t)(byte & 0x7F) << bitpos;
223
21.3M
            }
224
21.3M
            bitpos = (uint_fast8_t)(bitpos + 7);
225
21.3M
        } while (byte & 0x80);
226
21.2M
   }
227
   
228
48.9M
   *dest = result;
229
48.9M
   return true;
230
48.9M
}
231
232
#ifndef PB_WITHOUT_64BIT
233
bool checkreturn pb_decode_varint(pb_istream_t *stream, uint64_t *dest)
234
18.2M
{
235
18.2M
    pb_byte_t byte;
236
18.2M
    uint_fast8_t bitpos = 0;
237
18.2M
    uint64_t result = 0;
238
    
239
18.2M
    do
240
50.4M
    {
241
50.4M
        if (!pb_readbyte(stream, &byte))
242
50
            return false;
243
244
50.4M
        if (bitpos >= 63 && (byte & 0xFE) != 0)
245
33
            PB_RETURN_ERROR(stream, "varint overflow");
246
247
50.4M
        result |= (uint64_t)(byte & 0x7F) << bitpos;
248
50.4M
        bitpos = (uint_fast8_t)(bitpos + 7);
249
50.4M
    } while (byte & 0x80);
250
    
251
18.2M
    *dest = result;
252
18.2M
    return true;
253
18.2M
}
254
#endif
255
256
bool checkreturn pb_skip_varint(pb_istream_t *stream)
257
147k
{
258
147k
    pb_byte_t byte;
259
147k
    do
260
311k
    {
261
311k
        if (!pb_read(stream, &byte, 1))
262
25
            return false;
263
311k
    } while (byte & 0x80);
264
147k
    return true;
265
147k
}
266
267
bool checkreturn pb_skip_string(pb_istream_t *stream)
268
134k
{
269
134k
    uint32_t length;
270
134k
    if (!pb_decode_varint32(stream, &length))
271
17
        return false;
272
    
273
134k
    if ((size_t)length != length)
274
0
    {
275
0
        PB_RETURN_ERROR(stream, "size too large");
276
0
    }
277
278
134k
    return pb_read(stream, NULL, (size_t)length);
279
134k
}
280
281
bool checkreturn pb_decode_tag(pb_istream_t *stream, pb_wire_type_t *wire_type, uint32_t *tag, bool *eof)
282
24.8M
{
283
24.8M
    uint32_t temp;
284
24.8M
    *eof = false;
285
24.8M
    *wire_type = (pb_wire_type_t) 0;
286
24.8M
    *tag = 0;
287
288
24.8M
    if (stream->bytes_left == 0)
289
1.85M
    {
290
1.85M
        *eof = true;
291
1.85M
        return false;
292
1.85M
    }
293
294
22.9M
    if (!pb_decode_varint32(stream, &temp))
295
2.16k
    {
296
2.16k
#ifndef PB_BUFFER_ONLY
297
        /* Workaround for issue #1017
298
         *
299
         * Callback streams don't set bytes_left to 0 on eof until after being called by pb_decode_varint32,
300
         * which results in "io error" being raised. This contrasts the behavior of buffer streams who raise
301
         * no error on eof as bytes_left is already 0 on entry. This causes legitimate errors (e.g. missing
302
         * required fields) to be incorrectly reported by callback streams.
303
         */
304
2.16k
        if (stream->callback != buf_read && stream->bytes_left == 0)
305
2.06k
        {
306
2.06k
#ifndef PB_NO_ERRMSG
307
2.06k
            if (strcmp(stream->errmsg, "io error") == 0)
308
2.06k
                stream->errmsg = NULL;
309
2.06k
#endif
310
2.06k
            *eof = true;
311
2.06k
        }
312
2.16k
#endif
313
2.16k
        return false;
314
2.16k
    }
315
    
316
22.9M
    *tag = temp >> 3;
317
22.9M
    *wire_type = (pb_wire_type_t)(temp & 7);
318
22.9M
    return true;
319
22.9M
}
320
321
bool checkreturn pb_skip_field(pb_istream_t *stream, pb_wire_type_t wire_type)
322
584k
{
323
584k
    switch (wire_type)
324
584k
    {
325
147k
        case PB_WT_VARINT: return pb_skip_varint(stream);
326
79.3k
        case PB_WT_64BIT: return pb_read(stream, NULL, 8);
327
134k
        case PB_WT_STRING: return pb_skip_string(stream);
328
224k
        case PB_WT_32BIT: return pb_read(stream, NULL, 4);
329
0
  case PB_WT_PACKED: 
330
            /* Calling pb_skip_field with a PB_WT_PACKED is an error.
331
             * Explicitly handle this case and fallthrough to default to avoid
332
             * compiler warnings.
333
             */
334
47
        default: PB_RETURN_ERROR(stream, "invalid wire_type");
335
584k
    }
336
584k
}
337
338
/* Read a raw value to buffer, for the purpose of passing it to callback as
339
 * a substream. Size is maximum size on call, and actual size on return.
340
 */
341
static bool checkreturn read_raw_value(pb_istream_t *stream, pb_wire_type_t wire_type, pb_byte_t *buf, size_t *size)
342
0
{
343
0
    size_t max_size = *size;
344
0
    switch (wire_type)
345
0
    {
346
0
        case PB_WT_VARINT:
347
0
            *size = 0;
348
0
            do
349
0
            {
350
0
                (*size)++;
351
0
                if (*size > max_size)
352
0
                    PB_RETURN_ERROR(stream, "varint overflow");
353
354
0
                if (!pb_read(stream, buf, 1))
355
0
                    return false;
356
0
            } while (*buf++ & 0x80);
357
0
            return true;
358
            
359
0
        case PB_WT_64BIT:
360
0
            *size = 8;
361
0
            return pb_read(stream, buf, 8);
362
        
363
0
        case PB_WT_32BIT:
364
0
            *size = 4;
365
0
            return pb_read(stream, buf, 4);
366
        
367
0
        case PB_WT_STRING:
368
            /* Calling read_raw_value with a PB_WT_STRING is an error.
369
             * Explicitly handle this case and fallthrough to default to avoid
370
             * compiler warnings.
371
             */
372
373
0
  case PB_WT_PACKED: 
374
            /* Calling read_raw_value with a PB_WT_PACKED is an error.
375
             * Explicitly handle this case and fallthrough to default to avoid
376
             * compiler warnings.
377
             */
378
379
0
        default: PB_RETURN_ERROR(stream, "invalid wire_type");
380
0
    }
381
0
}
382
383
/* Decode string length from stream and return a substream with limited length.
384
 * Remember to close the substream using pb_close_string_substream().
385
 */
386
bool checkreturn pb_make_string_substream(pb_istream_t *stream, pb_istream_t *substream)
387
1.88M
{
388
1.88M
    uint32_t size;
389
1.88M
    if (!pb_decode_varint32(stream, &size))
390
50
        return false;
391
    
392
1.88M
    *substream = *stream;
393
1.88M
    if (substream->bytes_left < size)
394
67
        PB_RETURN_ERROR(stream, "parent stream too short");
395
    
396
#ifdef PB_MESSAGE_NESTING_MAX
397
    substream->depth++;
398
    if (substream->depth > PB_MESSAGE_NESTING_MAX)
399
        PB_RETURN_ERROR(stream, "max depth");
400
#endif
401
402
1.88M
    substream->bytes_left = (size_t)size;
403
1.88M
    stream->bytes_left -= (size_t)size;
404
1.88M
    return true;
405
1.88M
}
406
407
bool checkreturn pb_close_string_substream(pb_istream_t *stream, pb_istream_t *substream)
408
1.88M
{
409
1.88M
    if (substream->bytes_left) {
410
85
        if (!pb_read(substream, NULL, substream->bytes_left))
411
0
            return false;
412
85
    }
413
414
1.88M
    stream->state = substream->state;
415
416
1.88M
#ifndef PB_NO_ERRMSG
417
1.88M
    stream->errmsg = substream->errmsg;
418
1.88M
#endif
419
1.88M
    return true;
420
1.88M
}
421
422
/*************************
423
 * Decode a single field *
424
 *************************/
425
426
static bool checkreturn decode_basic_field(pb_istream_t *stream, pb_wire_type_t wire_type, pb_field_iter_t *field)
427
44.3M
{
428
44.3M
    switch (PB_LTYPE(field->type))
429
44.3M
    {
430
5.68M
        case PB_LTYPE_BOOL:
431
5.68M
            if (wire_type != PB_WT_VARINT && wire_type != PB_WT_PACKED)
432
8
                PB_RETURN_ERROR(stream, "wrong wire type");
433
434
5.68M
            return pb_dec_bool(stream, field);
435
436
14.4M
        case PB_LTYPE_VARINT:
437
16.2M
        case PB_LTYPE_UVARINT:
438
18.2M
        case PB_LTYPE_SVARINT:
439
18.2M
            if (wire_type != PB_WT_VARINT && wire_type != PB_WT_PACKED)
440
26
                PB_RETURN_ERROR(stream, "wrong wire type");
441
442
18.2M
            return pb_dec_varint(stream, field);
443
444
252k
        case PB_LTYPE_FIXED32:
445
252k
            if (wire_type != PB_WT_32BIT && wire_type != PB_WT_PACKED)
446
15
                PB_RETURN_ERROR(stream, "wrong wire type");
447
448
252k
            return pb_decode_fixed32(stream, field->pData);
449
450
87.5k
        case PB_LTYPE_FIXED64:
451
87.5k
            if (wire_type != PB_WT_64BIT && wire_type != PB_WT_PACKED)
452
9
                PB_RETURN_ERROR(stream, "wrong wire type");
453
454
#ifdef PB_CONVERT_DOUBLE_FLOAT
455
            if (field->data_size == sizeof(float))
456
            {
457
                return pb_decode_double_as_float(stream, (float*)field->pData);
458
            }
459
#endif
460
461
#ifdef PB_WITHOUT_64BIT
462
            PB_RETURN_ERROR(stream, "invalid data_size");
463
#else
464
87.5k
            return pb_decode_fixed64(stream, field->pData);
465
0
#endif
466
467
251k
        case PB_LTYPE_BYTES:
468
251k
            if (wire_type != PB_WT_STRING)
469
5
                PB_RETURN_ERROR(stream, "wrong wire type");
470
471
251k
            return pb_dec_bytes(stream, field);
472
473
63.2k
        case PB_LTYPE_STRING:
474
63.2k
            if (wire_type != PB_WT_STRING)
475
11
                PB_RETURN_ERROR(stream, "wrong wire type");
476
477
63.2k
            return pb_dec_string(stream, field);
478
479
1.84M
        case PB_LTYPE_SUBMESSAGE:
480
1.84M
        case PB_LTYPE_SUBMSG_W_CB:
481
1.84M
            if (wire_type != PB_WT_STRING)
482
12
                PB_RETURN_ERROR(stream, "wrong wire type");
483
484
1.84M
            return pb_dec_submessage(stream, field);
485
486
17.9M
        case PB_LTYPE_FIXED_LENGTH_BYTES:
487
17.9M
            if (wire_type != PB_WT_STRING)
488
5
                PB_RETURN_ERROR(stream, "wrong wire type");
489
490
17.9M
            return pb_dec_fixed_length_bytes(stream, field);
491
492
0
        default:
493
0
            PB_RETURN_ERROR(stream, "invalid field type");
494
44.3M
    }
495
44.3M
}
496
497
static bool checkreturn decode_static_field(pb_istream_t *stream, pb_wire_type_t wire_type, pb_field_iter_t *field)
498
16.9k
{
499
16.9k
    switch (PB_HTYPE(field->type))
500
16.9k
    {
501
0
        case PB_HTYPE_REQUIRED:
502
0
            return decode_basic_field(stream, wire_type, field);
503
            
504
0
        case PB_HTYPE_OPTIONAL:
505
0
            if (field->pSize != NULL)
506
0
                *(bool*)field->pSize = true;
507
0
            return decode_basic_field(stream, wire_type, field);
508
    
509
0
        case PB_HTYPE_REPEATED:
510
0
            if (wire_type == PB_WT_STRING
511
0
                && PB_LTYPE(field->type) <= PB_LTYPE_LAST_PACKABLE)
512
0
            {
513
                /* Packed array */
514
0
                bool status = true;
515
0
                pb_istream_t substream;
516
0
                pb_size_t *size = (pb_size_t*)field->pSize;
517
0
                field->pData = (char*)field->pField + field->data_size * (*size);
518
519
0
                if (!pb_make_string_substream(stream, &substream))
520
0
                    return false;
521
522
0
                while (substream.bytes_left > 0 && *size < field->array_size)
523
0
                {
524
0
                    if (!decode_basic_field(&substream, PB_WT_PACKED, field))
525
0
                    {
526
0
                        status = false;
527
0
                        break;
528
0
                    }
529
0
                    (*size)++;
530
0
                    field->pData = (char*)field->pData + field->data_size;
531
0
                }
532
533
0
                if (substream.bytes_left != 0)
534
0
                    PB_RETURN_ERROR(stream, "array overflow");
535
0
                if (!pb_close_string_substream(stream, &substream))
536
0
                    return false;
537
538
0
                return status;
539
0
            }
540
0
            else
541
0
            {
542
                /* Repeated field */
543
0
                pb_size_t *size = (pb_size_t*)field->pSize;
544
0
                field->pData = (char*)field->pField + field->data_size * (*size);
545
546
0
                if ((*size)++ >= field->array_size)
547
0
                    PB_RETURN_ERROR(stream, "array overflow");
548
549
0
                return decode_basic_field(stream, wire_type, field);
550
0
            }
551
552
16.9k
        case PB_HTYPE_ONEOF:
553
16.9k
            if (PB_LTYPE_IS_SUBMSG(field->type) &&
554
16.9k
                *(pb_size_t*)field->pSize != field->tag)
555
12.0k
            {
556
                /* We memset to zero so that any callbacks are set to NULL.
557
                 * This is because the callbacks might otherwise have values
558
                 * from some other union field.
559
                 * If callbacks are needed inside oneof field, use .proto
560
                 * option submsg_callback to have a separate callback function
561
                 * that can set the fields before submessage is decoded.
562
                 * pb_dec_submessage() will set any default values. */
563
12.0k
                memset(field->pData, 0, (size_t)field->data_size);
564
565
                /* Set default values for the submessage fields. */
566
12.0k
                if (field->submsg_desc->default_value != NULL ||
567
12.0k
                    field->submsg_desc->field_callback != NULL ||
568
12.0k
                    field->submsg_desc->submsg_info[0] != NULL)
569
0
                {
570
0
                    pb_field_iter_t submsg_iter;
571
0
                    if (pb_field_iter_begin(&submsg_iter, field->submsg_desc, field->pData))
572
0
                    {
573
0
                        if (!pb_message_set_to_defaults(&submsg_iter))
574
0
                            PB_RETURN_ERROR(stream, "failed to set defaults");
575
0
                    }
576
0
                }
577
12.0k
            }
578
16.9k
            *(pb_size_t*)field->pSize = field->tag;
579
580
16.9k
            return decode_basic_field(stream, wire_type, field);
581
582
0
        default:
583
0
            PB_RETURN_ERROR(stream, "invalid field type");
584
16.9k
    }
585
16.9k
}
586
587
#ifdef PB_ENABLE_MALLOC
588
/* Allocate storage for the field and store the pointer at iter->pData.
589
 * array_size is the number of entries to reserve in an array.
590
 * Zero size is not allowed, use pb_free() for releasing.
591
 */
592
static bool checkreturn allocate_field(pb_istream_t *stream, void *pData, size_t data_size, size_t array_size)
593
23.7M
{    
594
23.7M
    void *ptr = *(void**)pData;
595
    
596
23.7M
    if (data_size == 0 || array_size == 0)
597
0
        PB_RETURN_ERROR(stream, "invalid size");
598
    
599
#ifdef __AVR__
600
    /* Workaround for AVR libc bug 53284: http://savannah.nongnu.org/bugs/?53284
601
     * Realloc to size of 1 byte can cause corruption of the malloc structures.
602
     */
603
    if (data_size == 1 && array_size == 1)
604
    {
605
        data_size = 2;
606
    }
607
#endif
608
609
    /* Check for multiplication overflows.
610
     * This code avoids the costly division if the sizes are small enough.
611
     * Multiplication is safe as long as only half of bits are set
612
     * in either multiplicand.
613
     */
614
23.7M
    {
615
23.7M
        const size_t check_limit = (size_t)1 << (sizeof(size_t) * 4);
616
23.7M
        if (data_size >= check_limit || array_size >= check_limit)
617
0
        {
618
0
            const size_t size_max = (size_t)-1;
619
0
            if (size_max / array_size < data_size)
620
0
            {
621
0
                PB_RETURN_ERROR(stream, "size too large");
622
0
            }
623
0
        }
624
23.7M
    }
625
    
626
    /* Allocate new or expand previous allocation */
627
    /* Note: on failure the old pointer will remain in the structure,
628
     * the message must be freed by caller also on error return. */
629
23.7M
    ptr = pb_realloc(ptr, array_size * data_size);
630
23.7M
    if (ptr == NULL)
631
0
        PB_RETURN_ERROR(stream, "realloc failed");
632
    
633
23.7M
    *(void**)pData = ptr;
634
23.7M
    return true;
635
23.7M
}
636
637
/* Clear a newly allocated item in case it contains a pointer, or is a submessage. */
638
static void initialize_pointer_field(void *pItem, pb_field_iter_t *field)
639
44.3M
{
640
44.3M
    if (PB_LTYPE(field->type) == PB_LTYPE_STRING ||
641
44.2M
        PB_LTYPE(field->type) == PB_LTYPE_BYTES)
642
292k
    {
643
292k
        *(void**)pItem = NULL;
644
292k
    }
645
44.0M
    else if (PB_LTYPE_IS_SUBMSG(field->type))
646
1.82M
    {
647
        /* We memset to zero so that any callbacks are set to NULL.
648
         * Default values will be set by pb_dec_submessage(). */
649
1.82M
        memset(pItem, 0, field->data_size);
650
1.82M
    }
651
44.3M
}
652
#endif
653
654
static bool checkreturn decode_pointer_field(pb_istream_t *stream, pb_wire_type_t wire_type, pb_field_iter_t *field)
655
22.3M
{
656
#ifndef PB_ENABLE_MALLOC
657
    PB_UNUSED(wire_type);
658
    PB_UNUSED(field);
659
    PB_RETURN_ERROR(stream, "no malloc support");
660
#else
661
22.3M
    switch (PB_HTYPE(field->type))
662
22.3M
    {
663
0
        case PB_HTYPE_REQUIRED:
664
1.83M
        case PB_HTYPE_OPTIONAL:
665
1.86M
        case PB_HTYPE_ONEOF:
666
1.86M
            if (PB_LTYPE_IS_SUBMSG(field->type) && *(void**)field->pField != NULL)
667
21.5k
            {
668
                /* Duplicate field, have to release the old allocation first. */
669
                /* FIXME: Does this work correctly for oneofs? */
670
21.5k
                pb_release_single_field(field);
671
21.5k
            }
672
        
673
1.86M
            if (PB_HTYPE(field->type) == PB_HTYPE_ONEOF)
674
34.3k
            {
675
34.3k
                *(pb_size_t*)field->pSize = field->tag;
676
34.3k
            }
677
678
1.86M
            if (PB_LTYPE(field->type) == PB_LTYPE_STRING ||
679
1.84M
                PB_LTYPE(field->type) == PB_LTYPE_BYTES)
680
23.1k
            {
681
                /* pb_dec_string and pb_dec_bytes handle allocation themselves */
682
23.1k
                field->pData = field->pField;
683
23.1k
                return decode_basic_field(stream, wire_type, field);
684
23.1k
            }
685
1.84M
            else
686
1.84M
            {
687
1.84M
                if (!allocate_field(stream, field->pField, field->data_size, 1))
688
0
                    return false;
689
                
690
1.84M
                field->pData = *(void**)field->pField;
691
1.84M
                initialize_pointer_field(field->pData, field);
692
1.84M
                return decode_basic_field(stream, wire_type, field);
693
1.84M
            }
694
    
695
20.5M
        case PB_HTYPE_REPEATED:
696
20.5M
            if (wire_type == PB_WT_STRING
697
20.0M
                && PB_LTYPE(field->type) <= PB_LTYPE_LAST_PACKABLE)
698
38.6k
            {
699
                /* Packed array, multiple items come in at once. */
700
38.6k
                bool status = true;
701
38.6k
                pb_size_t *size = (pb_size_t*)field->pSize;
702
38.6k
                size_t allocated_size = *size;
703
38.6k
                pb_istream_t substream;
704
                
705
38.6k
                if (!pb_make_string_substream(stream, &substream))
706
33
                    return false;
707
                
708
22.0M
                while (substream.bytes_left)
709
21.9M
                {
710
21.9M
                    if (*size == PB_SIZE_MAX)
711
7
                    {
712
7
#ifndef PB_NO_ERRMSG
713
7
                        stream->errmsg = "too many array entries";
714
7
#endif
715
7
                        status = false;
716
7
                        break;
717
7
                    }
718
719
21.9M
                    if ((size_t)*size + 1 > allocated_size)
720
1.14M
                    {
721
                        /* Allocate more storage. This tries to guess the
722
                         * number of remaining entries. Round the division
723
                         * upwards. */
724
1.14M
                        size_t remain = (substream.bytes_left - 1) / field->data_size + 1;
725
1.14M
                        if (remain < PB_SIZE_MAX - allocated_size)
726
107k
                            allocated_size += remain;
727
1.04M
                        else
728
1.04M
                            allocated_size += 1;
729
                        
730
1.14M
                        if (!allocate_field(&substream, field->pField, field->data_size, allocated_size))
731
0
                        {
732
0
                            status = false;
733
0
                            break;
734
0
                        }
735
1.14M
                    }
736
737
                    /* Decode the array entry */
738
21.9M
                    field->pData = *(char**)field->pField + field->data_size * (*size);
739
21.9M
                    if (field->pData == NULL)
740
0
                    {
741
                        /* Shouldn't happen, but satisfies static analyzers */
742
0
                        status = false;
743
0
                        break;
744
0
                    }
745
21.9M
                    initialize_pointer_field(field->pData, field);
746
21.9M
                    if (!decode_basic_field(&substream, PB_WT_PACKED, field))
747
76
                    {
748
76
                        status = false;
749
76
                        break;
750
76
                    }
751
                    
752
21.9M
                    (*size)++;
753
21.9M
                }
754
38.6k
                if (!pb_close_string_substream(stream, &substream))
755
0
                    return false;
756
                
757
38.6k
                return status;
758
38.6k
            }
759
20.4M
            else
760
20.4M
            {
761
                /* Normal repeated field, i.e. only one item at a time. */
762
20.4M
                pb_size_t *size = (pb_size_t*)field->pSize;
763
764
20.4M
                if (*size == PB_SIZE_MAX)
765
3
                    PB_RETURN_ERROR(stream, "too many array entries");
766
                
767
20.4M
                if (!allocate_field(stream, field->pField, field->data_size, (size_t)(*size + 1)))
768
0
                    return false;
769
            
770
20.4M
                field->pData = *(char**)field->pField + field->data_size * (*size);
771
20.4M
                (*size)++;
772
20.4M
                initialize_pointer_field(field->pData, field);
773
20.4M
                return decode_basic_field(stream, wire_type, field);
774
20.4M
            }
775
776
0
        default:
777
0
            PB_RETURN_ERROR(stream, "invalid field type");
778
22.3M
    }
779
22.3M
#endif
780
22.3M
}
781
782
static bool checkreturn decode_callback_field(pb_istream_t *stream, pb_wire_type_t wire_type, pb_field_iter_t *field)
783
0
{
784
    /* Clear any data that may have been decoded for another oneof field
785
     * that has come before this callback field.
786
     */
787
0
    if (PB_HTYPE(field->type) == PB_HTYPE_ONEOF)
788
0
    {
789
0
        if (*(pb_size_t*)field->pSize != 0 && *(pb_size_t*)field->pSize != field->tag)
790
0
        {
791
0
            memset(field->pData, 0, (size_t)field->data_size);
792
0
        }
793
0
        *(pb_size_t*)field->pSize = field->tag;
794
0
    }
795
796
0
    if (!field->descriptor->field_callback)
797
0
        return pb_skip_field(stream, wire_type);
798
799
0
    if (wire_type == PB_WT_STRING)
800
0
    {
801
0
        pb_istream_t substream;
802
0
        size_t prev_bytes_left;
803
        
804
0
        if (!pb_make_string_substream(stream, &substream))
805
0
            return false;
806
807
        /* If the callback field is inside a submsg, first call the submsg_callback which
808
         * should set the decoder for the callback field. */
809
0
        if (PB_LTYPE(field->type) == PB_LTYPE_SUBMSG_W_CB && field->pSize != NULL) {
810
0
            pb_callback_t* callback;
811
0
            *(pb_size_t*)field->pSize = field->tag;
812
0
            callback = (pb_callback_t*)field->pSize - 1;
813
814
0
            if (callback->funcs.decode)
815
0
            {
816
0
                if (!callback->funcs.decode(&substream, field, &callback->arg)) {
817
0
                    PB_SET_ERROR(stream, substream.errmsg ? substream.errmsg : "submsg callback failed");
818
0
                    return false;
819
0
                }
820
0
            }
821
0
        }
822
        
823
0
        do
824
0
        {
825
0
            prev_bytes_left = substream.bytes_left;
826
0
            if (!field->descriptor->field_callback(&substream, NULL, field))
827
0
            {
828
0
                PB_SET_ERROR(stream, substream.errmsg ? substream.errmsg : "callback failed");
829
0
                return false;
830
0
            }
831
0
        } while (substream.bytes_left > 0 && substream.bytes_left < prev_bytes_left);
832
        
833
0
        if (!pb_close_string_substream(stream, &substream))
834
0
            return false;
835
836
0
        return true;
837
0
    }
838
0
    else
839
0
    {
840
        /* Copy the single scalar value to stack.
841
         * This is required so that we can limit the stream length,
842
         * which in turn allows to use same callback for packed and
843
         * not-packed fields. */
844
0
        pb_istream_t substream;
845
0
        pb_byte_t buffer[10];
846
0
        size_t size = sizeof(buffer);
847
        
848
0
        if (!read_raw_value(stream, wire_type, buffer, &size))
849
0
            return false;
850
0
        substream = pb_istream_from_buffer(buffer, size);
851
        
852
0
        return field->descriptor->field_callback(&substream, NULL, field);
853
0
    }
854
0
}
855
856
static bool checkreturn decode_field(pb_istream_t *stream, pb_wire_type_t wire_type, pb_field_iter_t *field)
857
22.4M
{
858
22.4M
#ifdef PB_ENABLE_MALLOC
859
    /* When decoding an oneof field, check if there is old data that must be
860
     * released first. */
861
22.4M
    if (PB_HTYPE(field->type) == PB_HTYPE_ONEOF)
862
51.3k
    {
863
51.3k
        if (!pb_release_union_field(stream, field))
864
0
            return false;
865
51.3k
    }
866
22.4M
#endif
867
868
22.4M
    switch (PB_ATYPE(field->type))
869
22.4M
    {
870
16.9k
        case PB_ATYPE_STATIC:
871
16.9k
            return decode_static_field(stream, wire_type, field);
872
        
873
22.3M
        case PB_ATYPE_POINTER:
874
22.3M
            return decode_pointer_field(stream, wire_type, field);
875
        
876
0
        case PB_ATYPE_CALLBACK:
877
0
            return decode_callback_field(stream, wire_type, field);
878
        
879
0
        default:
880
0
            PB_RETURN_ERROR(stream, "invalid field type");
881
22.4M
    }
882
22.4M
}
883
884
/* Default handler for extension fields. Expects to have a pb_msgdesc_t
885
 * pointer in the extension->type->arg field, pointing to a message with
886
 * only one field in it.  */
887
static bool checkreturn default_extension_decoder(pb_istream_t *stream,
888
    pb_extension_t *extension, uint32_t tag, pb_wire_type_t wire_type)
889
0
{
890
0
    pb_field_iter_t iter;
891
892
0
    if (!pb_field_iter_begin_extension(&iter, extension))
893
0
        PB_RETURN_ERROR(stream, "invalid extension");
894
895
0
    if (iter.tag != tag || !iter.message)
896
0
        return true;
897
898
0
    extension->found = true;
899
0
    return decode_field(stream, wire_type, &iter);
900
0
}
901
902
/* Try to decode an unknown field as an extension field. Tries each extension
903
 * decoder in turn, until one of them handles the field or loop ends. */
904
static bool checkreturn decode_extension(pb_istream_t *stream,
905
    uint32_t tag, pb_wire_type_t wire_type, pb_extension_t *extension)
906
0
{
907
0
    size_t pos = stream->bytes_left;
908
    
909
0
    while (extension != NULL && pos == stream->bytes_left)
910
0
    {
911
0
        bool status;
912
0
        if (extension->type->decode)
913
0
            status = extension->type->decode(stream, extension, tag, wire_type);
914
0
        else
915
0
            status = default_extension_decoder(stream, extension, tag, wire_type);
916
917
0
        if (!status)
918
0
            return false;
919
        
920
0
        extension = extension->next;
921
0
    }
922
    
923
0
    return true;
924
0
}
925
926
/* Initialize message fields to default values, recursively */
927
static bool pb_field_set_to_default(pb_field_iter_t *field)
928
5.81M
{
929
5.81M
    pb_type_t type;
930
5.81M
    type = field->type;
931
932
5.81M
    if (PB_LTYPE(type) == PB_LTYPE_EXTENSION)
933
0
    {
934
0
        pb_extension_t *ext = *(pb_extension_t* const *)field->pData;
935
0
        while (ext != NULL)
936
0
        {
937
0
            pb_field_iter_t ext_iter;
938
0
            if (pb_field_iter_begin_extension(&ext_iter, ext))
939
0
            {
940
0
                ext->found = false;
941
0
                if (!pb_message_set_to_defaults(&ext_iter))
942
0
                    return false;
943
0
            }
944
0
            ext = ext->next;
945
0
        }
946
0
    }
947
5.81M
    else if (PB_ATYPE(type) == PB_ATYPE_STATIC)
948
9.10k
    {
949
9.10k
        bool init_data = true;
950
9.10k
        if (PB_HTYPE(type) == PB_HTYPE_OPTIONAL && field->pSize != NULL)
951
0
        {
952
            /* Set has_field to false. Still initialize the optional field
953
             * itself also. */
954
0
            *(bool*)field->pSize = false;
955
0
        }
956
9.10k
        else if (PB_HTYPE(type) == PB_HTYPE_REPEATED ||
957
9.10k
                 PB_HTYPE(type) == PB_HTYPE_ONEOF)
958
9.10k
        {
959
            /* REPEATED: Set array count to 0, no need to initialize contents.
960
               ONEOF: Set which_field to 0. */
961
9.10k
            *(pb_size_t*)field->pSize = 0;
962
9.10k
            init_data = false;
963
9.10k
        }
964
965
9.10k
        if (init_data)
966
0
        {
967
0
            if (PB_LTYPE_IS_SUBMSG(field->type) &&
968
0
                (field->submsg_desc->default_value != NULL ||
969
0
                 field->submsg_desc->field_callback != NULL ||
970
0
                 field->submsg_desc->submsg_info[0] != NULL))
971
0
            {
972
                /* Initialize submessage to defaults.
973
                 * Only needed if it has default values
974
                 * or callback/submessage fields. */
975
0
                pb_field_iter_t submsg_iter;
976
0
                if (pb_field_iter_begin(&submsg_iter, field->submsg_desc, field->pData))
977
0
                {
978
0
                    if (!pb_message_set_to_defaults(&submsg_iter))
979
0
                        return false;
980
0
                }
981
0
            }
982
0
            else
983
0
            {
984
                /* Initialize to zeros */
985
0
                memset(field->pData, 0, (size_t)field->data_size);
986
0
            }
987
0
        }
988
9.10k
    }
989
5.80M
    else if (PB_ATYPE(type) == PB_ATYPE_POINTER)
990
5.80M
    {
991
        /* Initialize the pointer to NULL. */
992
5.80M
        *(void**)field->pField = NULL;
993
994
        /* Initialize array count to 0. */
995
5.80M
        if (PB_HTYPE(type) == PB_HTYPE_REPEATED ||
996
5.63M
            PB_HTYPE(type) == PB_HTYPE_ONEOF)
997
191k
        {
998
191k
            *(pb_size_t*)field->pSize = 0;
999
191k
        }
1000
5.80M
    }
1001
0
    else if (PB_ATYPE(type) == PB_ATYPE_CALLBACK)
1002
0
    {
1003
        /* Don't overwrite callback */
1004
0
    }
1005
1006
5.81M
    return true;
1007
5.81M
}
1008
1009
static bool pb_message_set_to_defaults(pb_field_iter_t *iter)
1010
1.79M
{
1011
1.79M
    pb_istream_t defstream = PB_ISTREAM_EMPTY;
1012
1.79M
    uint32_t tag = 0;
1013
1.79M
    pb_wire_type_t wire_type = PB_WT_VARINT;
1014
1.79M
    bool eof;
1015
1016
1.79M
    if (iter->descriptor->default_value)
1017
0
    {
1018
0
        defstream = pb_istream_from_buffer(iter->descriptor->default_value, (size_t)-1);
1019
0
        if (!pb_decode_tag(&defstream, &wire_type, &tag, &eof))
1020
0
            return false;
1021
0
    }
1022
1023
1.79M
    do
1024
5.81M
    {
1025
5.81M
        if (!pb_field_set_to_default(iter))
1026
0
            return false;
1027
1028
5.81M
        if (tag != 0 && iter->tag == tag)
1029
0
        {
1030
            /* We have a default value for this field in the defstream */
1031
0
            if (!decode_field(&defstream, wire_type, iter))
1032
0
                return false;
1033
0
            if (!pb_decode_tag(&defstream, &wire_type, &tag, &eof))
1034
0
                return false;
1035
1036
0
            if (iter->pSize)
1037
0
                *(bool*)iter->pSize = false;
1038
0
        }
1039
5.81M
    } while (pb_field_iter_next(iter));
1040
1041
1.79M
    return true;
1042
1.79M
}
1043
1044
/*********************
1045
 * Decode all fields *
1046
 *********************/
1047
1048
static bool checkreturn pb_decode_inner(pb_istream_t *stream, const pb_msgdesc_t *fields, void *dest_struct, unsigned int flags)
1049
1.85M
{
1050
    /* If the message contains extension fields, the extension handlers
1051
     * are called when tag number is >= extension_range_start. This precheck
1052
     * is just for speed, and the handlers will check for precise match.
1053
     */
1054
1.85M
    uint32_t extension_range_start = 0;
1055
1.85M
    pb_extension_t *extensions = NULL;
1056
1057
    /* 'fixed_count_field' and 'fixed_count_size' track position of a repeated fixed
1058
     * count field. This can only handle _one_ repeated fixed count field that
1059
     * is unpacked and unordered among other (non repeated fixed count) fields.
1060
     */
1061
1.85M
    pb_size_t fixed_count_field = PB_SIZE_MAX;
1062
1.85M
    pb_size_t fixed_count_size = 0;
1063
1.85M
    pb_size_t fixed_count_total_size = 0;
1064
1065
    /* Tag and wire type of next field from the input stream */
1066
1.85M
    uint32_t tag;
1067
1.85M
    pb_wire_type_t wire_type;
1068
1.85M
    bool eof;
1069
1070
    /* Track presence of required fields */
1071
1.85M
    pb_fields_seen_t fields_seen = {{0, 0}};
1072
1.85M
    const uint32_t allbits = ~(uint32_t)0;
1073
1074
    /* Descriptor for the structure field matching the tag decoded from stream */
1075
1.85M
    pb_field_iter_t iter;
1076
1077
1.85M
    if (pb_field_iter_begin(&iter, fields, dest_struct))
1078
1.80M
    {
1079
1.80M
        if ((flags & PB_DECODE_NOINIT) == 0)
1080
1.79M
        {
1081
1.79M
            if (!pb_message_set_to_defaults(&iter))
1082
0
                PB_RETURN_ERROR(stream, "failed to set defaults");
1083
1.79M
        }
1084
1.80M
    }
1085
1086
24.8M
    while (pb_decode_tag(stream, &wire_type, &tag, &eof))
1087
22.9M
    {
1088
22.9M
        if (tag == 0)
1089
43
        {
1090
43
          if (flags & PB_DECODE_NULLTERMINATED)
1091
0
          {
1092
0
            eof = true;
1093
0
            break;
1094
0
          }
1095
43
          else
1096
43
          {
1097
43
            PB_RETURN_ERROR(stream, "zero tag");
1098
43
          }
1099
43
        }
1100
1101
22.9M
        if (!pb_field_iter_find(&iter, tag) || PB_LTYPE(iter.type) == PB_LTYPE_EXTENSION)
1102
584k
        {
1103
            /* No match found, check if it matches an extension. */
1104
584k
            if (extension_range_start == 0)
1105
5.26k
            {
1106
5.26k
                if (pb_field_iter_find_extension(&iter))
1107
0
                {
1108
0
                    extensions = *(pb_extension_t* const *)iter.pData;
1109
0
                    extension_range_start = iter.tag;
1110
0
                }
1111
1112
5.26k
                if (!extensions)
1113
5.26k
                {
1114
5.26k
                    extension_range_start = (uint32_t)-1;
1115
5.26k
                }
1116
5.26k
            }
1117
1118
584k
            if (tag >= extension_range_start)
1119
0
            {
1120
0
                size_t pos = stream->bytes_left;
1121
1122
0
                if (!decode_extension(stream, tag, wire_type, extensions))
1123
0
                    return false;
1124
1125
0
                if (pos != stream->bytes_left)
1126
0
                {
1127
                    /* The field was handled */
1128
0
                    continue;
1129
0
                }
1130
0
            }
1131
1132
            /* No match found, skip data */
1133
584k
            if (!pb_skip_field(stream, wire_type))
1134
158
                return false;
1135
584k
            continue;
1136
584k
        }
1137
1138
        /* If a repeated fixed count field was found, get size from
1139
         * 'fixed_count_field' as there is no counter contained in the struct.
1140
         */
1141
22.4M
        if (PB_HTYPE(iter.type) == PB_HTYPE_REPEATED && iter.pSize == &iter.array_size)
1142
0
        {
1143
0
            if (fixed_count_field != iter.index) {
1144
                /* If the new fixed count field does not match the previous one,
1145
                 * check that the previous one is NULL or that it finished
1146
                 * receiving all the expected data.
1147
                 */
1148
0
                if (fixed_count_field != PB_SIZE_MAX &&
1149
0
                    fixed_count_size != fixed_count_total_size)
1150
0
                {
1151
0
                    PB_RETURN_ERROR(stream, "wrong size for fixed count field");
1152
0
                }
1153
1154
0
                fixed_count_field = iter.index;
1155
0
                fixed_count_size = 0;
1156
0
                fixed_count_total_size = iter.array_size;
1157
0
            }
1158
1159
0
            iter.pSize = &fixed_count_size;
1160
0
        }
1161
1162
22.4M
        if (PB_HTYPE(iter.type) == PB_HTYPE_REQUIRED
1163
0
            && iter.required_field_index < PB_MAX_REQUIRED_FIELDS)
1164
0
        {
1165
0
            uint32_t tmp = ((uint32_t)1 << (iter.required_field_index & 31));
1166
0
            fields_seen.bitfield[iter.required_field_index >> 5] |= tmp;
1167
0
        }
1168
1169
22.4M
        if (!decode_field(stream, wire_type, &iter))
1170
763
            return false;
1171
22.4M
    }
1172
1173
1.85M
    if (!eof)
1174
96
    {
1175
        /* pb_decode_tag() returned error before end of stream */
1176
96
        return false;
1177
96
    }
1178
1179
    /* Check that all elements of the last decoded fixed count field were present. */
1180
1.85M
    if (fixed_count_field != PB_SIZE_MAX &&
1181
0
        fixed_count_size != fixed_count_total_size)
1182
0
    {
1183
0
        PB_RETURN_ERROR(stream, "wrong size for fixed count field");
1184
0
    }
1185
1186
    /* Check that all required fields were present. */
1187
1.85M
    {
1188
1.85M
        pb_size_t req_field_count = iter.descriptor->required_field_count;
1189
1190
1.85M
        if (req_field_count > 0)
1191
0
        {
1192
0
            pb_size_t i;
1193
1194
0
            if (req_field_count > PB_MAX_REQUIRED_FIELDS)
1195
0
                req_field_count = PB_MAX_REQUIRED_FIELDS;
1196
1197
            /* Check the whole words */
1198
0
            for (i = 0; i < (req_field_count >> 5); i++)
1199
0
            {
1200
0
                if (fields_seen.bitfield[i] != allbits)
1201
0
                    PB_RETURN_ERROR(stream, "missing required field");
1202
0
            }
1203
1204
            /* Check the remaining bits (if any) */
1205
0
            if ((req_field_count & 31) != 0)
1206
0
            {
1207
0
                if (fields_seen.bitfield[req_field_count >> 5] !=
1208
0
                    (allbits >> (uint_least8_t)(32 - (req_field_count & 31))))
1209
0
                {
1210
0
                    PB_RETURN_ERROR(stream, "missing required field");
1211
0
                }
1212
0
            }
1213
0
        }
1214
1.85M
    }
1215
1216
1.85M
    return true;
1217
1.85M
}
1218
1219
bool checkreturn pb_decode_ex(pb_istream_t *stream, const pb_msgdesc_t *fields, void *dest_struct, unsigned int flags)
1220
9.10k
{
1221
9.10k
    bool status;
1222
1223
9.10k
    if ((flags & PB_DECODE_DELIMITED) == 0)
1224
9.10k
    {
1225
9.10k
      status = pb_decode_inner(stream, fields, dest_struct, flags);
1226
9.10k
    }
1227
0
    else
1228
0
    {
1229
0
      pb_istream_t substream;
1230
0
      if (!pb_make_string_substream(stream, &substream))
1231
0
        return false;
1232
1233
0
      status = pb_decode_inner(&substream, fields, dest_struct, flags);
1234
1235
0
      if (!pb_close_string_substream(stream, &substream))
1236
0
        status = false;
1237
0
    }
1238
    
1239
9.10k
#ifdef PB_ENABLE_MALLOC
1240
9.10k
    if (!status)
1241
1.02k
        pb_release(fields, dest_struct);
1242
9.10k
#endif
1243
    
1244
9.10k
    return status;
1245
9.10k
}
1246
1247
bool checkreturn pb_decode(pb_istream_t *stream, const pb_msgdesc_t *fields, void *dest_struct)
1248
3.94k
{
1249
3.94k
    return pb_decode_ex(stream, fields, dest_struct, 0);
1250
3.94k
}
1251
1252
#ifdef PB_ENABLE_MALLOC
1253
/* Given an oneof field, if there has already been a field inside this oneof,
1254
 * release it before overwriting with a different one. */
1255
static bool pb_release_union_field(pb_istream_t *stream, pb_field_iter_t *field)
1256
51.3k
{
1257
51.3k
    pb_field_iter_t old_field = *field;
1258
51.3k
    pb_size_t old_tag = *(pb_size_t*)field->pSize; /* Previous which_ value */
1259
51.3k
    pb_size_t new_tag = field->tag; /* New which_ value */
1260
1261
51.3k
    if (old_tag == 0)
1262
1.30k
        return true; /* Ok, no old data in union */
1263
1264
50.0k
    if (old_tag == new_tag)
1265
15.9k
        return true; /* Ok, old data is of same type => merge */
1266
1267
    /* Release old data. The find can fail if the message struct contains
1268
     * invalid data. */
1269
34.1k
    if (!pb_field_iter_find(&old_field, old_tag))
1270
0
        PB_RETURN_ERROR(stream, "invalid union tag");
1271
1272
34.1k
    pb_release_single_field(&old_field);
1273
1274
34.1k
    if (PB_ATYPE(field->type) == PB_ATYPE_POINTER)
1275
22.4k
    {
1276
        /* Initialize the pointer to NULL to make sure it is valid
1277
         * even in case of error return. */
1278
22.4k
        *(void**)field->pField = NULL;
1279
22.4k
        field->pData = NULL;
1280
22.4k
    }
1281
1282
34.1k
    return true;
1283
34.1k
}
1284
1285
static void pb_release_single_field(pb_field_iter_t *field)
1286
5.91M
{
1287
5.91M
    pb_type_t type;
1288
5.91M
    type = field->type;
1289
1290
5.91M
    if (PB_HTYPE(type) == PB_HTYPE_ONEOF)
1291
73.0k
    {
1292
73.0k
        if (*(pb_size_t*)field->pSize != field->tag)
1293
26.5k
            return; /* This is not the current field in the union */
1294
73.0k
    }
1295
1296
    /* Release anything contained inside an extension or submsg.
1297
     * This has to be done even if the submsg itself is statically
1298
     * allocated. */
1299
5.88M
    if (PB_LTYPE(type) == PB_LTYPE_EXTENSION)
1300
0
    {
1301
        /* Release fields from all extensions in the linked list */
1302
0
        pb_extension_t *ext = *(pb_extension_t**)field->pData;
1303
0
        while (ext != NULL)
1304
0
        {
1305
0
            pb_field_iter_t ext_iter;
1306
0
            if (pb_field_iter_begin_extension(&ext_iter, ext))
1307
0
            {
1308
0
                pb_release_single_field(&ext_iter);
1309
0
            }
1310
0
            ext = ext->next;
1311
0
        }
1312
0
    }
1313
5.88M
    else if (PB_LTYPE_IS_SUBMSG(type) && PB_ATYPE(type) != PB_ATYPE_CALLBACK)
1314
103k
    {
1315
        /* Release fields in submessage or submsg array */
1316
103k
        pb_size_t count = 1;
1317
        
1318
103k
        if (PB_ATYPE(type) == PB_ATYPE_POINTER)
1319
91.4k
        {
1320
91.4k
            field->pData = *(void**)field->pField;
1321
91.4k
        }
1322
12.0k
        else
1323
12.0k
        {
1324
12.0k
            field->pData = field->pField;
1325
12.0k
        }
1326
        
1327
103k
        if (PB_HTYPE(type) == PB_HTYPE_REPEATED)
1328
18.5k
        {
1329
18.5k
            count = *(pb_size_t*)field->pSize;
1330
1331
18.5k
            if (PB_ATYPE(type) == PB_ATYPE_STATIC && count > field->array_size)
1332
0
            {
1333
                /* Protect against corrupted _count fields */
1334
0
                count = field->array_size;
1335
0
            }
1336
18.5k
        }
1337
        
1338
103k
        if (field->pData)
1339
60.7k
        {
1340
1.90M
            for (; count > 0; count--)
1341
1.84M
            {
1342
1.84M
                pb_release(field->submsg_desc, field->pData);
1343
1.84M
                field->pData = (char*)field->pData + field->data_size;
1344
1.84M
            }
1345
60.7k
        }
1346
103k
    }
1347
    
1348
5.88M
    if (PB_ATYPE(type) == PB_ATYPE_POINTER)
1349
5.87M
    {
1350
5.87M
        if (PB_HTYPE(type) == PB_HTYPE_REPEATED &&
1351
176k
            (PB_LTYPE(type) == PB_LTYPE_STRING ||
1352
167k
             PB_LTYPE(type) == PB_LTYPE_BYTES))
1353
18.5k
        {
1354
            /* Release entries in repeated string or bytes array */
1355
18.5k
            void **pItem = *(void***)field->pField;
1356
18.5k
            pb_size_t count = *(pb_size_t*)field->pSize;
1357
310k
            for (; count > 0; count--)
1358
292k
            {
1359
292k
                pb_free(*pItem);
1360
292k
                *pItem++ = NULL;
1361
292k
            }
1362
18.5k
        }
1363
        
1364
5.87M
        if (PB_HTYPE(type) == PB_HTYPE_REPEATED)
1365
176k
        {
1366
            /* We are going to release the array, so set the size to 0 */
1367
176k
            *(pb_size_t*)field->pSize = 0;
1368
176k
        }
1369
        
1370
        /* Release main pointer */
1371
5.87M
        pb_free(*(void**)field->pField);
1372
5.87M
        *(void**)field->pField = NULL;
1373
5.87M
    }
1374
5.88M
}
1375
1376
void pb_release(const pb_msgdesc_t *fields, void *dest_struct)
1377
1.84M
{
1378
1.84M
    pb_field_iter_t iter;
1379
    
1380
1.84M
    if (!dest_struct)
1381
0
        return; /* Ignore NULL pointers, similar to free() */
1382
1383
1.84M
    if (!pb_field_iter_begin(&iter, fields, dest_struct))
1384
45.7k
        return; /* Empty message type */
1385
    
1386
1.80M
    do
1387
5.85M
    {
1388
5.85M
        pb_release_single_field(&iter);
1389
5.85M
    } while (pb_field_iter_next(&iter));
1390
1.80M
}
1391
#else
1392
void pb_release(const pb_msgdesc_t *fields, void *dest_struct)
1393
{
1394
    /* Nothing to release without PB_ENABLE_MALLOC. */
1395
    PB_UNUSED(fields);
1396
    PB_UNUSED(dest_struct);
1397
}
1398
#endif
1399
1400
/* Field decoders */
1401
1402
bool pb_decode_bool(pb_istream_t *stream, bool *dest)
1403
5.68M
{
1404
5.68M
    uint32_t value;
1405
5.68M
    if (!pb_decode_varint32(stream, &value))
1406
58
        return false;
1407
1408
5.68M
    *(bool*)dest = (value != 0);
1409
5.68M
    return true;
1410
5.68M
}
1411
1412
bool pb_decode_svarint(pb_istream_t *stream, pb_int64_t *dest)
1413
1.95M
{
1414
1.95M
    pb_uint64_t value;
1415
1.95M
    if (!pb_decode_varint(stream, &value))
1416
25
        return false;
1417
    
1418
1.95M
    if (value & 1)
1419
196k
        *dest = (pb_int64_t)(~(value >> 1));
1420
1.76M
    else
1421
1.76M
        *dest = (pb_int64_t)(value >> 1);
1422
    
1423
1.95M
    return true;
1424
1.95M
}
1425
1426
bool pb_decode_fixed32(pb_istream_t *stream, void *dest)
1427
252k
{
1428
252k
    union {
1429
252k
        uint32_t fixed32;
1430
252k
        pb_byte_t bytes[4];
1431
252k
    } u;
1432
1433
252k
    if (!pb_read(stream, u.bytes, 4))
1434
9
        return false;
1435
1436
252k
#if defined(PB_LITTLE_ENDIAN_8BIT) && PB_LITTLE_ENDIAN_8BIT == 1
1437
    /* fast path - if we know that we're on little endian, assign directly */
1438
252k
    *(uint32_t*)dest = u.fixed32;
1439
#else
1440
    *(uint32_t*)dest = ((uint32_t)u.bytes[0] << 0) |
1441
                       ((uint32_t)u.bytes[1] << 8) |
1442
                       ((uint32_t)u.bytes[2] << 16) |
1443
                       ((uint32_t)u.bytes[3] << 24);
1444
#endif
1445
252k
    return true;
1446
252k
}
1447
1448
#ifndef PB_WITHOUT_64BIT
1449
bool pb_decode_fixed64(pb_istream_t *stream, void *dest)
1450
87.5k
{
1451
87.5k
    union {
1452
87.5k
        uint64_t fixed64;
1453
87.5k
        pb_byte_t bytes[8];
1454
87.5k
    } u;
1455
1456
87.5k
    if (!pb_read(stream, u.bytes, 8))
1457
12
        return false;
1458
1459
87.5k
#if defined(PB_LITTLE_ENDIAN_8BIT) && PB_LITTLE_ENDIAN_8BIT == 1
1460
    /* fast path - if we know that we're on little endian, assign directly */
1461
87.5k
    *(uint64_t*)dest = u.fixed64;
1462
#else
1463
    *(uint64_t*)dest = ((uint64_t)u.bytes[0] << 0) |
1464
                       ((uint64_t)u.bytes[1] << 8) |
1465
                       ((uint64_t)u.bytes[2] << 16) |
1466
                       ((uint64_t)u.bytes[3] << 24) |
1467
                       ((uint64_t)u.bytes[4] << 32) |
1468
                       ((uint64_t)u.bytes[5] << 40) |
1469
                       ((uint64_t)u.bytes[6] << 48) |
1470
                       ((uint64_t)u.bytes[7] << 56);
1471
#endif
1472
87.5k
    return true;
1473
87.5k
}
1474
#endif
1475
1476
static bool checkreturn pb_dec_bool(pb_istream_t *stream, const pb_field_iter_t *field)
1477
5.68M
{
1478
5.68M
    return pb_decode_bool(stream, (bool*)field->pData);
1479
5.68M
}
1480
1481
static bool checkreturn pb_dec_varint(pb_istream_t *stream, const pb_field_iter_t *field)
1482
18.2M
{
1483
18.2M
    if (PB_LTYPE(field->type) == PB_LTYPE_UVARINT)
1484
1.79M
    {
1485
1.79M
        pb_uint64_t value, clamped;
1486
1.79M
        if (!pb_decode_varint(stream, &value))
1487
23
            return false;
1488
1489
        /* Cast to the proper field size, while checking for overflows */
1490
1.79M
        if (field->data_size == sizeof(pb_uint64_t))
1491
1.56M
            clamped = *(pb_uint64_t*)field->pData = value;
1492
233k
        else if (field->data_size == sizeof(uint32_t))
1493
233k
            clamped = *(uint32_t*)field->pData = (uint32_t)value;
1494
0
        else if (field->data_size == sizeof(uint_least16_t))
1495
0
            clamped = *(uint_least16_t*)field->pData = (uint_least16_t)value;
1496
0
        else if (field->data_size == sizeof(uint_least8_t))
1497
0
            clamped = *(uint_least8_t*)field->pData = (uint_least8_t)value;
1498
0
        else
1499
0
            PB_RETURN_ERROR(stream, "invalid data_size");
1500
1501
1.79M
        if (clamped != value)
1502
63
            PB_RETURN_ERROR(stream, "integer too large");
1503
1504
1.79M
        return true;
1505
1.79M
    }
1506
16.4M
    else
1507
16.4M
    {
1508
16.4M
        pb_uint64_t value;
1509
16.4M
        pb_int64_t svalue;
1510
16.4M
        pb_int64_t clamped;
1511
1512
16.4M
        if (PB_LTYPE(field->type) == PB_LTYPE_SVARINT)
1513
1.95M
        {
1514
1.95M
            if (!pb_decode_svarint(stream, &svalue))
1515
25
                return false;
1516
1.95M
        }
1517
14.4M
        else
1518
14.4M
        {
1519
14.4M
            if (!pb_decode_varint(stream, &value))
1520
35
                return false;
1521
1522
            /* See issue 97: Google's C++ protobuf allows negative varint values to
1523
            * be cast as int32_t, instead of the int64_t that should be used when
1524
            * encoding. Nanopb versions before 0.2.5 had a bug in encoding. In order to
1525
            * not break decoding of such messages, we cast <=32 bit fields to
1526
            * int32_t first to get the sign correct.
1527
            */
1528
14.4M
            if (field->data_size == sizeof(pb_int64_t))
1529
307k
                svalue = (pb_int64_t)value;
1530
14.1M
            else
1531
14.1M
                svalue = (int32_t)value;
1532
14.4M
        }
1533
1534
        /* Cast to the proper field size, while checking for overflows */
1535
16.4M
        if (field->data_size == sizeof(pb_int64_t))
1536
1.89M
            clamped = *(pb_int64_t*)field->pData = svalue;
1537
14.5M
        else if (field->data_size == sizeof(int32_t))
1538
14.5M
            clamped = *(int32_t*)field->pData = (int32_t)svalue;
1539
0
        else if (field->data_size == sizeof(int_least16_t))
1540
0
            clamped = *(int_least16_t*)field->pData = (int_least16_t)svalue;
1541
0
        else if (field->data_size == sizeof(int_least8_t))
1542
0
            clamped = *(int_least8_t*)field->pData = (int_least8_t)svalue;
1543
0
        else
1544
0
            PB_RETURN_ERROR(stream, "invalid data_size");
1545
1546
16.4M
        if (clamped != svalue)
1547
51
            PB_RETURN_ERROR(stream, "integer too large");
1548
1549
16.4M
        return true;
1550
16.4M
    }
1551
18.2M
}
1552
1553
static bool checkreturn pb_dec_bytes(pb_istream_t *stream, const pb_field_iter_t *field)
1554
251k
{
1555
251k
    uint32_t size;
1556
251k
    size_t alloc_size;
1557
251k
    pb_bytes_array_t *dest;
1558
    
1559
251k
    if (!pb_decode_varint32(stream, &size))
1560
14
        return false;
1561
    
1562
251k
    if (size > PB_SIZE_MAX)
1563
31
        PB_RETURN_ERROR(stream, "bytes overflow");
1564
    
1565
251k
    alloc_size = PB_BYTES_ARRAY_T_ALLOCSIZE(size);
1566
251k
    if (size > alloc_size)
1567
0
        PB_RETURN_ERROR(stream, "size too large");
1568
    
1569
251k
    if (PB_ATYPE(field->type) == PB_ATYPE_POINTER)
1570
251k
    {
1571
#ifndef PB_ENABLE_MALLOC
1572
        PB_RETURN_ERROR(stream, "no malloc support");
1573
#else
1574
251k
        if (stream->bytes_left < size)
1575
44
            PB_RETURN_ERROR(stream, "end-of-stream");
1576
1577
251k
        if (!allocate_field(stream, field->pData, alloc_size, 1))
1578
0
            return false;
1579
251k
        dest = *(pb_bytes_array_t**)field->pData;
1580
251k
#endif
1581
251k
    }
1582
0
    else
1583
0
    {
1584
0
        if (alloc_size > field->data_size)
1585
0
            PB_RETURN_ERROR(stream, "bytes overflow");
1586
0
        dest = (pb_bytes_array_t*)field->pData;
1587
0
    }
1588
1589
251k
    dest->size = (pb_size_t)size;
1590
251k
    return pb_read(stream, dest->bytes, (size_t)size);
1591
251k
}
1592
1593
static bool checkreturn pb_dec_string(pb_istream_t *stream, const pb_field_iter_t *field)
1594
63.2k
{
1595
63.2k
    uint32_t size;
1596
63.2k
    size_t alloc_size;
1597
63.2k
    pb_byte_t *dest = (pb_byte_t*)field->pData;
1598
1599
63.2k
    if (!pb_decode_varint32(stream, &size))
1600
8
        return false;
1601
1602
63.2k
    if (size == (uint32_t)-1)
1603
2
        PB_RETURN_ERROR(stream, "size too large");
1604
1605
    /* Space for null terminator */
1606
63.2k
    alloc_size = (size_t)(size + 1);
1607
1608
63.2k
    if (alloc_size < size)
1609
0
        PB_RETURN_ERROR(stream, "size too large");
1610
1611
63.2k
    if (PB_ATYPE(field->type) == PB_ATYPE_POINTER)
1612
63.2k
    {
1613
#ifndef PB_ENABLE_MALLOC
1614
        PB_RETURN_ERROR(stream, "no malloc support");
1615
#else
1616
63.2k
        if (stream->bytes_left < size)
1617
60
            PB_RETURN_ERROR(stream, "end-of-stream");
1618
1619
63.1k
        if (!allocate_field(stream, field->pData, alloc_size, 1))
1620
0
            return false;
1621
63.1k
        dest = *(pb_byte_t**)field->pData;
1622
63.1k
#endif
1623
63.1k
    }
1624
0
    else
1625
0
    {
1626
0
        if (alloc_size > field->data_size)
1627
0
            PB_RETURN_ERROR(stream, "string overflow");
1628
0
    }
1629
    
1630
63.1k
    dest[size] = 0;
1631
1632
63.1k
    if (!pb_read(stream, dest, (size_t)size))
1633
0
        return false;
1634
1635
#ifdef PB_VALIDATE_UTF8
1636
    if (!pb_validate_utf8((const char*)dest))
1637
        PB_RETURN_ERROR(stream, "invalid utf8");
1638
#endif
1639
1640
63.1k
    return true;
1641
63.1k
}
1642
1643
static bool checkreturn pb_dec_submessage(pb_istream_t *stream, const pb_field_iter_t *field)
1644
1.84M
{
1645
1.84M
    bool status = true;
1646
1.84M
    bool submsg_consumed = false;
1647
1.84M
    pb_istream_t substream;
1648
1649
1.84M
    if (!pb_make_string_substream(stream, &substream))
1650
84
        return false;
1651
    
1652
1.84M
    if (field->submsg_desc == NULL)
1653
0
        PB_RETURN_ERROR(stream, "invalid field descriptor");
1654
    
1655
    /* Submessages can have a separate message-level callback that is called
1656
     * before decoding the message. Typically it is used to set callback fields
1657
     * inside oneofs. */
1658
1.84M
    if (PB_LTYPE(field->type) == PB_LTYPE_SUBMSG_W_CB && field->pSize != NULL)
1659
0
    {
1660
        /* Message callback is stored right before pSize. */
1661
0
        pb_callback_t *callback = (pb_callback_t*)field->pSize - 1;
1662
0
        if (callback->funcs.decode)
1663
0
        {
1664
0
            status = callback->funcs.decode(&substream, field, &callback->arg);
1665
1666
0
            if (substream.bytes_left == 0)
1667
0
            {
1668
0
                submsg_consumed = true;
1669
0
            }
1670
0
        }
1671
0
    }
1672
1673
    /* Now decode the submessage contents */
1674
1.84M
    if (status && !submsg_consumed)
1675
1.84M
    {
1676
1.84M
        unsigned int flags = 0;
1677
1678
        /* Static required/optional fields are already initialized by top-level
1679
         * pb_decode(), no need to initialize them again. */
1680
1.84M
        if (PB_ATYPE(field->type) == PB_ATYPE_STATIC &&
1681
16.9k
            PB_HTYPE(field->type) != PB_HTYPE_REPEATED)
1682
16.9k
        {
1683
16.9k
            flags = PB_DECODE_NOINIT;
1684
16.9k
        }
1685
1686
1.84M
        status = pb_decode_inner(&substream, field->submsg_desc, field->pData, flags);
1687
1.84M
    }
1688
    
1689
1.84M
    if (!pb_close_string_substream(stream, &substream))
1690
0
        return false;
1691
1692
1.84M
    return status;
1693
1.84M
}
1694
1695
static bool checkreturn pb_dec_fixed_length_bytes(pb_istream_t *stream, const pb_field_iter_t *field)
1696
17.9M
{
1697
17.9M
    uint32_t size;
1698
1699
17.9M
    if (!pb_decode_varint32(stream, &size))
1700
1
        return false;
1701
1702
17.9M
    if (size > PB_SIZE_MAX)
1703
32
        PB_RETURN_ERROR(stream, "bytes overflow");
1704
1705
17.9M
    if (size == 0)
1706
17.1M
    {
1707
        /* As a special case, treat empty bytes string as all zeros for fixed_length_bytes. */
1708
17.1M
        memset(field->pData, 0, (size_t)field->data_size);
1709
17.1M
        return true;
1710
17.1M
    }
1711
1712
779k
    if (size != field->data_size)
1713
43
        PB_RETURN_ERROR(stream, "incorrect fixed length bytes size");
1714
1715
779k
    return pb_read(stream, (pb_byte_t*)field->pData, (size_t)field->data_size);
1716
779k
}
1717
1718
#ifdef PB_CONVERT_DOUBLE_FLOAT
1719
bool pb_decode_double_as_float(pb_istream_t *stream, float *dest)
1720
{
1721
    uint_least8_t sign;
1722
    int exponent;
1723
    uint32_t mantissa;
1724
    uint64_t value;
1725
    union { float f; uint32_t i; } out;
1726
1727
    if (!pb_decode_fixed64(stream, &value))
1728
        return false;
1729
1730
    /* Decompose input value */
1731
    sign = (uint_least8_t)((value >> 63) & 1);
1732
    exponent = (int)((value >> 52) & 0x7FF) - 1023;
1733
    mantissa = (value >> 28) & 0xFFFFFF; /* Highest 24 bits */
1734
1735
    /* Figure if value is in range representable by floats. */
1736
    if (exponent == 1024)
1737
    {
1738
        /* Special value */
1739
        exponent = 128;
1740
        mantissa >>= 1;
1741
        /* Preserve NaN if its payload was lost when narrowing the mantissa. */
1742
        if (mantissa == 0 && (uint32_t)value != 0)
1743
            mantissa = 1;
1744
    }
1745
    else
1746
    {
1747
        if (exponent > 127)
1748
        {
1749
            /* Too large, convert to infinity */
1750
            exponent = 128;
1751
            mantissa = 0;
1752
        }
1753
        else if (exponent < -150)
1754
        {
1755
            /* Too small, convert to zero */
1756
            exponent = -127;
1757
            mantissa = 0;
1758
        }
1759
        else if (exponent < -126)
1760
        {
1761
            /* Denormalized */
1762
            mantissa |= 0x1000000;
1763
            mantissa >>= (-126 - exponent);
1764
            exponent = -127;
1765
        }
1766
1767
        /* Round off mantissa */
1768
        mantissa = (mantissa + 1) >> 1;
1769
1770
        /* Check if mantissa went over 2.0 */
1771
        if (mantissa & 0x800000)
1772
        {
1773
            exponent += 1;
1774
            mantissa &= 0x7FFFFF;
1775
            mantissa >>= 1;
1776
        }
1777
    }
1778
1779
    /* Combine fields */
1780
    out.i = mantissa;
1781
    out.i |= (uint32_t)(exponent + 127) << 23;
1782
    out.i |= (uint32_t)sign << 31;
1783
1784
    *dest = out.f;
1785
    return true;
1786
}
1787
#endif