Coverage Report

Created: 2026-09-28 07:09

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/nanopb/pb_decode.c
Line
Count
Source
1
/* pb_decode.c -- decode a protobuf using minimal resources
2
 *
3
 * 2011 Petteri Aimonen <jpa@kapsi.fi>
4
 */
5
6
/* Use the GCC warn_unused_result attribute to check that all return values
7
 * are propagated correctly. On other compilers, gcc before 3.4.0 and iar
8
 * before 9.40.1 just ignore the annotation.
9
 */
10
#if (defined(__GNUC__) && ((__GNUC__ > 3) || (__GNUC__ == 3 && __GNUC_MINOR__ >= 4))) || \
11
    (defined(__IAR_SYSTEMS_ICC__) && (__VER__ >= 9040001))
12
    #define checkreturn __attribute__((warn_unused_result))
13
#else
14
    #define checkreturn
15
#endif
16
17
#include "pb.h"
18
#include "pb_decode.h"
19
#include "pb_common.h"
20
21
/**************************************
22
 * Declarations internal to this file *
23
 **************************************/
24
25
static bool checkreturn buf_read(pb_istream_t *stream, pb_byte_t *buf, size_t count);
26
static bool checkreturn read_raw_value(pb_istream_t *stream, pb_wire_type_t wire_type, pb_byte_t *buf, size_t *size);
27
static bool checkreturn decode_basic_field(pb_istream_t *stream, pb_wire_type_t wire_type, pb_field_iter_t *field);
28
static bool checkreturn decode_static_field(pb_istream_t *stream, pb_wire_type_t wire_type, pb_field_iter_t *field);
29
static bool checkreturn decode_pointer_field(pb_istream_t *stream, pb_wire_type_t wire_type, pb_field_iter_t *field);
30
static bool checkreturn decode_callback_field(pb_istream_t *stream, pb_wire_type_t wire_type, pb_field_iter_t *field);
31
static bool checkreturn decode_field(pb_istream_t *stream, pb_wire_type_t wire_type, pb_field_iter_t *field);
32
static bool checkreturn default_extension_decoder(pb_istream_t *stream, pb_extension_t *extension, uint32_t tag, pb_wire_type_t wire_type);
33
static bool checkreturn decode_extension(pb_istream_t *stream, uint32_t tag, pb_wire_type_t wire_type, pb_extension_t *extension);
34
static bool pb_field_set_to_default(pb_field_iter_t *field);
35
static bool pb_message_set_to_defaults(pb_field_iter_t *iter);
36
static bool checkreturn pb_dec_bool(pb_istream_t *stream, const pb_field_iter_t *field);
37
static bool checkreturn pb_dec_varint(pb_istream_t *stream, const pb_field_iter_t *field);
38
static bool checkreturn pb_dec_bytes(pb_istream_t *stream, const pb_field_iter_t *field);
39
static bool checkreturn pb_dec_string(pb_istream_t *stream, const pb_field_iter_t *field);
40
static bool checkreturn pb_dec_submessage(pb_istream_t *stream, const pb_field_iter_t *field);
41
static bool checkreturn pb_dec_fixed_length_bytes(pb_istream_t *stream, const pb_field_iter_t *field);
42
static bool checkreturn pb_skip_varint(pb_istream_t *stream);
43
static bool checkreturn pb_skip_string(pb_istream_t *stream);
44
45
#ifdef PB_ENABLE_MALLOC
46
static bool checkreturn allocate_field(pb_istream_t *stream, void *pData, size_t data_size, size_t array_size);
47
static void initialize_pointer_field(void *pItem, pb_field_iter_t *field);
48
static bool checkreturn pb_release_union_field(pb_istream_t *stream, pb_field_iter_t *field);
49
static void pb_release_single_field(pb_field_iter_t *field);
50
#endif
51
52
#ifdef PB_WITHOUT_64BIT
53
#define pb_int64_t int32_t
54
#define pb_uint64_t uint32_t
55
#else
56
68.8M
#define pb_int64_t int64_t
57
45.2M
#define pb_uint64_t uint64_t
58
#endif
59
60
typedef struct {
61
    uint32_t bitfield[(PB_MAX_REQUIRED_FIELDS + 31) / 32];
62
} pb_fields_seen_t;
63
64
/*******************************
65
 * pb_istream_t implementation *
66
 *******************************/
67
68
static bool checkreturn buf_read(pb_istream_t *stream, pb_byte_t *buf, size_t count)
69
196M
{
70
196M
    const pb_byte_t *source = (const pb_byte_t*)stream->state;
71
196M
    stream->state = (pb_byte_t*)stream->state + count;
72
    
73
196M
    if (buf != NULL)
74
195M
    {
75
195M
        memcpy(buf, source, count * sizeof(pb_byte_t));
76
195M
    }
77
    
78
196M
    return true;
79
196M
}
80
81
bool checkreturn pb_read(pb_istream_t *stream, pb_byte_t *buf, size_t count)
82
10.7M
{
83
10.7M
    if (count == 0)
84
1.43M
        return true;
85
86
9.35M
#ifndef PB_BUFFER_ONLY
87
9.35M
  if (buf == NULL && stream->callback != buf_read)
88
420k
  {
89
    /* Skip input bytes */
90
420k
    pb_byte_t tmp[16];
91
2.05M
    while (count > 16)
92
1.63M
    {
93
1.63M
      if (!pb_read(stream, tmp, 16))
94
2.86k
        return false;
95
      
96
1.63M
      count -= 16;
97
1.63M
    }
98
    
99
417k
    return pb_read(stream, tmp, count);
100
420k
  }
101
8.93M
#endif
102
103
8.93M
    if (stream->bytes_left < count)
104
2.38k
        PB_RETURN_ERROR(stream, "end-of-stream");
105
    
106
8.93M
#ifndef PB_BUFFER_ONLY
107
8.93M
    if (!stream->callback(stream, buf, count))
108
6.02k
        PB_RETURN_ERROR(stream, "io error");
109
#else
110
    if (!buf_read(stream, buf, count))
111
        return false;
112
#endif
113
    
114
8.92M
    if (stream->bytes_left < count)
115
0
        stream->bytes_left = 0;
116
8.92M
    else
117
8.92M
        stream->bytes_left -= count;
118
119
8.92M
    return true;
120
8.93M
}
121
122
/* Read a single byte from input stream. buf may not be NULL.
123
 * This is an optimization for the varint decoding. */
124
static bool checkreturn pb_readbyte(pb_istream_t *stream, pb_byte_t *buf)
125
271M
{
126
271M
    if (stream->bytes_left == 0)
127
5.68k
        PB_RETURN_ERROR(stream, "end-of-stream");
128
129
271M
#ifndef PB_BUFFER_ONLY
130
271M
    if (!stream->callback(stream, buf, 1))
131
11.4k
        PB_RETURN_ERROR(stream, "io error");
132
#else
133
    *buf = *(const pb_byte_t*)stream->state;
134
    stream->state = (pb_byte_t*)stream->state + 1;
135
#endif
136
137
271M
    stream->bytes_left--;
138
    
139
271M
    return true;    
140
271M
}
141
142
pb_istream_t pb_istream_from_buffer(const pb_byte_t *buf, size_t msglen)
143
242k
{
144
242k
    pb_istream_t stream;
145
    /* Cast away the const from buf without a compiler error.  We are
146
     * careful to use it only in a const manner in the callbacks.
147
     */
148
242k
    union {
149
242k
        void *state;
150
242k
        const void *c_state;
151
242k
    } state;
152
#ifdef PB_BUFFER_ONLY
153
    stream.callback = NULL;
154
#else
155
242k
    stream.callback = &buf_read;
156
242k
#endif
157
242k
    state.c_state = buf;
158
242k
    stream.state = state.state;
159
242k
    stream.bytes_left = msglen;
160
242k
#ifndef PB_NO_ERRMSG
161
242k
    stream.errmsg = NULL;
162
242k
#endif
163
#ifdef PB_MESSAGE_NESTING_MAX
164
    stream.depth = 0;
165
#endif
166
242k
    return stream;
167
242k
}
168
169
170
/********************
171
 * Helper functions *
172
 ********************/
173
174
bool checkreturn pb_decode_varint32(pb_istream_t *stream, uint32_t *dest)
175
134M
{
176
134M
    pb_byte_t byte;
177
134M
    uint32_t result;
178
    
179
134M
    if (!pb_readbyte(stream, &byte))
180
11.2k
    {
181
11.2k
        return false;
182
11.2k
    }
183
    
184
134M
    if ((byte & 0x80) == 0)
185
79.9M
    {
186
        /* Quick case, 1 byte value */
187
79.9M
        result = byte;
188
79.9M
    }
189
54.5M
    else
190
54.5M
    {
191
        /* Multibyte case */
192
54.5M
        uint_fast8_t bitpos = 7;
193
54.5M
        result = byte & 0x7F;
194
        
195
54.5M
        do
196
55.3M
        {
197
55.3M
            if (!pb_readbyte(stream, &byte))
198
4.41k
                return false;
199
            
200
55.3M
            if (bitpos >= 32)
201
39.6k
            {
202
                /* Note: The varint could have trailing 0x80 bytes, or 0xFF for negative. */
203
39.6k
                pb_byte_t sign_extension = (bitpos < 63) ? 0xFF : 0x01;
204
39.6k
                bool valid_extension = ((byte & 0x7F) == 0x00 ||
205
24.0k
                         ((result >> 31) != 0 && byte == sign_extension));
206
207
39.6k
                if (bitpos >= 64 || !valid_extension)
208
1.19k
                {
209
1.19k
                    PB_RETURN_ERROR(stream, "varint overflow");
210
1.19k
                }
211
39.6k
            }
212
55.3M
            else if (bitpos == 28)
213
53.2k
            {
214
53.2k
                if ((byte & 0x70) != 0 && (byte & 0x78) != 0x78)
215
490
                {
216
490
                    PB_RETURN_ERROR(stream, "varint overflow");
217
490
                }
218
52.7k
                result |= (uint32_t)(byte & 0x0F) << bitpos;
219
52.7k
            }
220
55.2M
            else
221
55.2M
            {
222
55.2M
                result |= (uint32_t)(byte & 0x7F) << bitpos;
223
55.2M
            }
224
55.3M
            bitpos = (uint_fast8_t)(bitpos + 7);
225
55.3M
        } while (byte & 0x80);
226
54.5M
   }
227
   
228
134M
   *dest = result;
229
134M
   return true;
230
134M
}
231
232
#ifndef PB_WITHOUT_64BIT
233
bool checkreturn pb_decode_varint(pb_istream_t *stream, uint64_t *dest)
234
38.7M
{
235
38.7M
    pb_byte_t byte;
236
38.7M
    uint_fast8_t bitpos = 0;
237
38.7M
    uint64_t result = 0;
238
    
239
38.7M
    do
240
81.3M
    {
241
81.3M
        if (!pb_readbyte(stream, &byte))
242
1.42k
            return false;
243
244
81.3M
        if (bitpos >= 63 && (byte & 0xFE) != 0)
245
287
            PB_RETURN_ERROR(stream, "varint overflow");
246
247
81.3M
        result |= (uint64_t)(byte & 0x7F) << bitpos;
248
81.3M
        bitpos = (uint_fast8_t)(bitpos + 7);
249
81.3M
    } while (byte & 0x80);
250
    
251
38.7M
    *dest = result;
252
38.7M
    return true;
253
38.7M
}
254
#endif
255
256
bool checkreturn pb_skip_varint(pb_istream_t *stream)
257
1.54M
{
258
1.54M
    pb_byte_t byte;
259
1.54M
    do
260
2.00M
    {
261
2.00M
        if (!pb_read(stream, &byte, 1))
262
614
            return false;
263
2.00M
    } while (byte & 0x80);
264
1.54M
    return true;
265
1.54M
}
266
267
bool checkreturn pb_skip_string(pb_istream_t *stream)
268
626k
{
269
626k
    uint32_t length;
270
626k
    if (!pb_decode_varint32(stream, &length))
271
480
        return false;
272
    
273
625k
    if ((size_t)length != length)
274
0
    {
275
0
        PB_RETURN_ERROR(stream, "size too large");
276
0
    }
277
278
625k
    return pb_read(stream, NULL, (size_t)length);
279
625k
}
280
281
bool checkreturn pb_decode_tag(pb_istream_t *stream, pb_wire_type_t *wire_type, uint32_t *tag, bool *eof)
282
74.2M
{
283
74.2M
    uint32_t temp;
284
74.2M
    *eof = false;
285
74.2M
    *wire_type = (pb_wire_type_t) 0;
286
74.2M
    *tag = 0;
287
288
74.2M
    if (stream->bytes_left == 0)
289
2.41M
    {
290
2.41M
        *eof = true;
291
2.41M
        return false;
292
2.41M
    }
293
294
71.8M
    if (!pb_decode_varint32(stream, &temp))
295
14.8k
    {
296
14.8k
#ifndef PB_BUFFER_ONLY
297
        /* Workaround for issue #1017
298
         *
299
         * Callback streams don't set bytes_left to 0 on eof until after being called by pb_decode_varint32,
300
         * which results in "io error" being raised. This contrasts the behavior of buffer streams who raise
301
         * no error on eof as bytes_left is already 0 on entry. This causes legitimate errors (e.g. missing
302
         * required fields) to be incorrectly reported by callback streams.
303
         */
304
14.8k
        if (stream->callback != buf_read && stream->bytes_left == 0)
305
12.1k
        {
306
12.1k
#ifndef PB_NO_ERRMSG
307
12.1k
            if (strcmp(stream->errmsg, "io error") == 0)
308
8.20k
                stream->errmsg = NULL;
309
12.1k
#endif
310
12.1k
            *eof = true;
311
12.1k
        }
312
14.8k
#endif
313
14.8k
        return false;
314
14.8k
    }
315
    
316
71.8M
    *tag = temp >> 3;
317
71.8M
    *wire_type = (pb_wire_type_t)(temp & 7);
318
71.8M
    return true;
319
71.8M
}
320
321
bool checkreturn pb_skip_field(pb_istream_t *stream, pb_wire_type_t wire_type)
322
3.10M
{
323
3.10M
    switch (wire_type)
324
3.10M
    {
325
1.54M
        case PB_WT_VARINT: return pb_skip_varint(stream);
326
394k
        case PB_WT_64BIT: return pb_read(stream, NULL, 8);
327
626k
        case PB_WT_STRING: return pb_skip_string(stream);
328
526k
        case PB_WT_32BIT: return pb_read(stream, NULL, 4);
329
0
  case PB_WT_PACKED: 
330
            /* Calling pb_skip_field with a PB_WT_PACKED is an error.
331
             * Explicitly handle this case and fallthrough to default to avoid
332
             * compiler warnings.
333
             */
334
2.83k
        default: PB_RETURN_ERROR(stream, "invalid wire_type");
335
3.10M
    }
336
3.10M
}
337
338
/* Read a raw value to buffer, for the purpose of passing it to callback as
339
 * a substream. Size is maximum size on call, and actual size on return.
340
 */
341
static bool checkreturn read_raw_value(pb_istream_t *stream, pb_wire_type_t wire_type, pb_byte_t *buf, size_t *size)
342
25.4k
{
343
25.4k
    size_t max_size = *size;
344
25.4k
    switch (wire_type)
345
25.4k
    {
346
16.7k
        case PB_WT_VARINT:
347
16.7k
            *size = 0;
348
16.7k
            do
349
34.0k
            {
350
34.0k
                (*size)++;
351
34.0k
                if (*size > max_size)
352
43
                    PB_RETURN_ERROR(stream, "varint overflow");
353
354
34.0k
                if (!pb_read(stream, buf, 1))
355
264
                    return false;
356
34.0k
            } while (*buf++ & 0x80);
357
16.4k
            return true;
358
            
359
5.73k
        case PB_WT_64BIT:
360
5.73k
            *size = 8;
361
5.73k
            return pb_read(stream, buf, 8);
362
        
363
2.77k
        case PB_WT_32BIT:
364
2.77k
            *size = 4;
365
2.77k
            return pb_read(stream, buf, 4);
366
        
367
0
        case PB_WT_STRING:
368
            /* Calling read_raw_value with a PB_WT_STRING is an error.
369
             * Explicitly handle this case and fallthrough to default to avoid
370
             * compiler warnings.
371
             */
372
373
0
  case PB_WT_PACKED: 
374
            /* Calling read_raw_value with a PB_WT_PACKED is an error.
375
             * Explicitly handle this case and fallthrough to default to avoid
376
             * compiler warnings.
377
             */
378
379
120
        default: PB_RETURN_ERROR(stream, "invalid wire_type");
380
25.4k
    }
381
25.4k
}
382
383
/* Decode string length from stream and return a substream with limited length.
384
 * Remember to close the substream using pb_close_string_substream().
385
 */
386
bool checkreturn pb_make_string_substream(pb_istream_t *stream, pb_istream_t *substream)
387
2.72M
{
388
2.72M
    uint32_t size;
389
2.72M
    if (!pb_decode_varint32(stream, &size))
390
1.19k
        return false;
391
    
392
2.72M
    *substream = *stream;
393
2.72M
    if (substream->bytes_left < size)
394
5.93k
        PB_RETURN_ERROR(stream, "parent stream too short");
395
    
396
#ifdef PB_MESSAGE_NESTING_MAX
397
    substream->depth++;
398
    if (substream->depth > PB_MESSAGE_NESTING_MAX)
399
        PB_RETURN_ERROR(stream, "max depth");
400
#endif
401
402
2.72M
    substream->bytes_left = (size_t)size;
403
2.72M
    stream->bytes_left -= (size_t)size;
404
2.72M
    return true;
405
2.72M
}
406
407
bool checkreturn pb_close_string_substream(pb_istream_t *stream, pb_istream_t *substream)
408
2.72M
{
409
2.72M
    if (substream->bytes_left) {
410
75.3k
        if (!pb_read(substream, NULL, substream->bytes_left))
411
3.78k
            return false;
412
75.3k
    }
413
414
2.71M
    stream->state = substream->state;
415
416
2.71M
#ifndef PB_NO_ERRMSG
417
2.71M
    stream->errmsg = substream->errmsg;
418
2.71M
#endif
419
2.71M
    return true;
420
2.72M
}
421
422
/*************************
423
 * Decode a single field *
424
 *************************/
425
426
static bool checkreturn decode_basic_field(pb_istream_t *stream, pb_wire_type_t wire_type, pb_field_iter_t *field)
427
102M
{
428
102M
    switch (PB_LTYPE(field->type))
429
102M
    {
430
10.1M
        case PB_LTYPE_BOOL:
431
10.1M
            if (wire_type != PB_WT_VARINT && wire_type != PB_WT_PACKED)
432
264
                PB_RETURN_ERROR(stream, "wrong wire type");
433
434
10.1M
            return pb_dec_bool(stream, field);
435
436
27.8M
        case PB_LTYPE_VARINT:
437
32.1M
        case PB_LTYPE_UVARINT:
438
38.7M
        case PB_LTYPE_SVARINT:
439
38.7M
            if (wire_type != PB_WT_VARINT && wire_type != PB_WT_PACKED)
440
1.28k
                PB_RETURN_ERROR(stream, "wrong wire type");
441
442
38.7M
            return pb_dec_varint(stream, field);
443
444
909k
        case PB_LTYPE_FIXED32:
445
909k
            if (wire_type != PB_WT_32BIT && wire_type != PB_WT_PACKED)
446
270
                PB_RETURN_ERROR(stream, "wrong wire type");
447
448
908k
            return pb_decode_fixed32(stream, field->pData);
449
450
728k
        case PB_LTYPE_FIXED64:
451
728k
            if (wire_type != PB_WT_64BIT && wire_type != PB_WT_PACKED)
452
300
                PB_RETURN_ERROR(stream, "wrong wire type");
453
454
#ifdef PB_CONVERT_DOUBLE_FLOAT
455
            if (field->data_size == sizeof(float))
456
            {
457
                return pb_decode_double_as_float(stream, (float*)field->pData);
458
            }
459
#endif
460
461
#ifdef PB_WITHOUT_64BIT
462
            PB_RETURN_ERROR(stream, "invalid data_size");
463
#else
464
728k
            return pb_decode_fixed64(stream, field->pData);
465
0
#endif
466
467
1.03M
        case PB_LTYPE_BYTES:
468
1.03M
            if (wire_type != PB_WT_STRING)
469
327
                PB_RETURN_ERROR(stream, "wrong wire type");
470
471
1.03M
            return pb_dec_bytes(stream, field);
472
473
494k
        case PB_LTYPE_STRING:
474
494k
            if (wire_type != PB_WT_STRING)
475
216
                PB_RETURN_ERROR(stream, "wrong wire type");
476
477
494k
            return pb_dec_string(stream, field);
478
479
2.37M
        case PB_LTYPE_SUBMESSAGE:
480
2.43M
        case PB_LTYPE_SUBMSG_W_CB:
481
2.43M
            if (wire_type != PB_WT_STRING)
482
362
                PB_RETURN_ERROR(stream, "wrong wire type");
483
484
2.43M
            return pb_dec_submessage(stream, field);
485
486
47.5M
        case PB_LTYPE_FIXED_LENGTH_BYTES:
487
47.5M
            if (wire_type != PB_WT_STRING)
488
62
                PB_RETURN_ERROR(stream, "wrong wire type");
489
490
47.5M
            return pb_dec_fixed_length_bytes(stream, field);
491
492
0
        default:
493
0
            PB_RETURN_ERROR(stream, "invalid field type");
494
102M
    }
495
102M
}
496
497
static bool checkreturn decode_static_field(pb_istream_t *stream, pb_wire_type_t wire_type, pb_field_iter_t *field)
498
13.1M
{
499
13.1M
    switch (PB_HTYPE(field->type))
500
13.1M
    {
501
7.16M
        case PB_HTYPE_REQUIRED:
502
7.16M
            return decode_basic_field(stream, wire_type, field);
503
            
504
5.67M
        case PB_HTYPE_OPTIONAL:
505
5.67M
            if (field->pSize != NULL)
506
801k
                *(bool*)field->pSize = true;
507
5.67M
            return decode_basic_field(stream, wire_type, field);
508
    
509
57.5k
        case PB_HTYPE_REPEATED:
510
57.5k
            if (wire_type == PB_WT_STRING
511
46.3k
                && PB_LTYPE(field->type) <= PB_LTYPE_LAST_PACKABLE)
512
19.3k
            {
513
                /* Packed array */
514
19.3k
                bool status = true;
515
19.3k
                pb_istream_t substream;
516
19.3k
                pb_size_t *size = (pb_size_t*)field->pSize;
517
19.3k
                field->pData = (char*)field->pField + field->data_size * (*size);
518
519
19.3k
                if (!pb_make_string_substream(stream, &substream))
520
370
                    return false;
521
522
84.0k
                while (substream.bytes_left > 0 && *size < field->array_size)
523
65.3k
                {
524
65.3k
                    if (!decode_basic_field(&substream, PB_WT_PACKED, field))
525
304
                    {
526
304
                        status = false;
527
304
                        break;
528
304
                    }
529
65.0k
                    (*size)++;
530
65.0k
                    field->pData = (char*)field->pData + field->data_size;
531
65.0k
                }
532
533
18.9k
                if (substream.bytes_left != 0)
534
352
                    PB_RETURN_ERROR(stream, "array overflow");
535
18.5k
                if (!pb_close_string_substream(stream, &substream))
536
0
                    return false;
537
538
18.5k
                return status;
539
18.5k
            }
540
38.2k
            else
541
38.2k
            {
542
                /* Repeated field */
543
38.2k
                pb_size_t *size = (pb_size_t*)field->pSize;
544
38.2k
                field->pData = (char*)field->pField + field->data_size * (*size);
545
546
38.2k
                if ((*size)++ >= field->array_size)
547
180
                    PB_RETURN_ERROR(stream, "array overflow");
548
549
38.0k
                return decode_basic_field(stream, wire_type, field);
550
38.2k
            }
551
552
277k
        case PB_HTYPE_ONEOF:
553
277k
            if (PB_LTYPE_IS_SUBMSG(field->type) &&
554
274k
                *(pb_size_t*)field->pSize != field->tag)
555
165k
            {
556
                /* We memset to zero so that any callbacks are set to NULL.
557
                 * This is because the callbacks might otherwise have values
558
                 * from some other union field.
559
                 * If callbacks are needed inside oneof field, use .proto
560
                 * option submsg_callback to have a separate callback function
561
                 * that can set the fields before submessage is decoded.
562
                 * pb_dec_submessage() will set any default values. */
563
165k
                memset(field->pData, 0, (size_t)field->data_size);
564
565
                /* Set default values for the submessage fields. */
566
165k
                if (field->submsg_desc->default_value != NULL ||
567
84.5k
                    field->submsg_desc->field_callback != NULL ||
568
84.5k
                    field->submsg_desc->submsg_info[0] != NULL)
569
80.8k
                {
570
80.8k
                    pb_field_iter_t submsg_iter;
571
80.8k
                    if (pb_field_iter_begin(&submsg_iter, field->submsg_desc, field->pData))
572
80.8k
                    {
573
80.8k
                        if (!pb_message_set_to_defaults(&submsg_iter))
574
0
                            PB_RETURN_ERROR(stream, "failed to set defaults");
575
80.8k
                    }
576
80.8k
                }
577
165k
            }
578
277k
            *(pb_size_t*)field->pSize = field->tag;
579
580
277k
            return decode_basic_field(stream, wire_type, field);
581
582
0
        default:
583
0
            PB_RETURN_ERROR(stream, "invalid field type");
584
13.1M
    }
585
13.1M
}
586
587
#ifdef PB_ENABLE_MALLOC
588
/* Allocate storage for the field and store the pointer at iter->pData.
589
 * array_size is the number of entries to reserve in an array.
590
 * Zero size is not allowed, use pb_free() for releasing.
591
 */
592
static bool checkreturn allocate_field(pb_istream_t *stream, void *pData, size_t data_size, size_t array_size)
593
58.1M
{    
594
58.1M
    void *ptr = *(void**)pData;
595
    
596
58.1M
    if (data_size == 0 || array_size == 0)
597
0
        PB_RETURN_ERROR(stream, "invalid size");
598
    
599
#ifdef __AVR__
600
    /* Workaround for AVR libc bug 53284: http://savannah.nongnu.org/bugs/?53284
601
     * Realloc to size of 1 byte can cause corruption of the malloc structures.
602
     */
603
    if (data_size == 1 && array_size == 1)
604
    {
605
        data_size = 2;
606
    }
607
#endif
608
609
    /* Check for multiplication overflows.
610
     * This code avoids the costly division if the sizes are small enough.
611
     * Multiplication is safe as long as only half of bits are set
612
     * in either multiplicand.
613
     */
614
58.1M
    {
615
58.1M
        const size_t check_limit = (size_t)1 << (sizeof(size_t) * 4);
616
58.1M
        if (data_size >= check_limit || array_size >= check_limit)
617
0
        {
618
0
            const size_t size_max = (size_t)-1;
619
0
            if (size_max / array_size < data_size)
620
0
            {
621
0
                PB_RETURN_ERROR(stream, "size too large");
622
0
            }
623
0
        }
624
58.1M
    }
625
    
626
    /* Allocate new or expand previous allocation */
627
    /* Note: on failure the old pointer will remain in the structure,
628
     * the message must be freed by caller also on error return. */
629
58.1M
    ptr = pb_realloc(ptr, array_size * data_size);
630
58.1M
    if (ptr == NULL)
631
274
        PB_RETURN_ERROR(stream, "realloc failed");
632
    
633
58.1M
    *(void**)pData = ptr;
634
58.1M
    return true;
635
58.1M
}
636
637
/* Clear a newly allocated item in case it contains a pointer, or is a submessage. */
638
static void initialize_pointer_field(void *pItem, pb_field_iter_t *field)
639
88.6M
{
640
88.6M
    if (PB_LTYPE(field->type) == PB_LTYPE_STRING ||
641
88.6M
        PB_LTYPE(field->type) == PB_LTYPE_BYTES)
642
967k
    {
643
967k
        *(void**)pItem = NULL;
644
967k
    }
645
87.7M
    else if (PB_LTYPE_IS_SUBMSG(field->type))
646
2.02M
    {
647
        /* We memset to zero so that any callbacks are set to NULL.
648
         * Default values will be set by pb_dec_submessage(). */
649
2.02M
        memset(pItem, 0, field->data_size);
650
2.02M
    }
651
88.6M
}
652
#endif
653
654
static bool checkreturn decode_pointer_field(pb_istream_t *stream, pb_wire_type_t wire_type, pb_field_iter_t *field)
655
55.2M
{
656
#ifndef PB_ENABLE_MALLOC
657
    PB_UNUSED(wire_type);
658
    PB_UNUSED(field);
659
    PB_RETURN_ERROR(stream, "no malloc support");
660
#else
661
55.2M
    switch (PB_HTYPE(field->type))
662
55.2M
    {
663
2.27M
        case PB_HTYPE_REQUIRED:
664
4.14M
        case PB_HTYPE_OPTIONAL:
665
4.20M
        case PB_HTYPE_ONEOF:
666
4.20M
            if (PB_LTYPE_IS_SUBMSG(field->type) && *(void**)field->pField != NULL)
667
73.2k
            {
668
                /* Duplicate field, have to release the old allocation first. */
669
                /* FIXME: Does this work correctly for oneofs? */
670
73.2k
                pb_release_single_field(field);
671
73.2k
            }
672
        
673
4.20M
            if (PB_HTYPE(field->type) == PB_HTYPE_ONEOF)
674
61.0k
            {
675
61.0k
                *(pb_size_t*)field->pSize = field->tag;
676
61.0k
            }
677
678
4.20M
            if (PB_LTYPE(field->type) == PB_LTYPE_STRING ||
679
4.05M
                PB_LTYPE(field->type) == PB_LTYPE_BYTES)
680
201k
            {
681
                /* pb_dec_string and pb_dec_bytes handle allocation themselves */
682
201k
                field->pData = field->pField;
683
201k
                return decode_basic_field(stream, wire_type, field);
684
201k
            }
685
4.00M
            else
686
4.00M
            {
687
4.00M
                if (!allocate_field(stream, field->pField, field->data_size, 1))
688
8
                    return false;
689
                
690
4.00M
                field->pData = *(void**)field->pField;
691
4.00M
                initialize_pointer_field(field->pData, field);
692
4.00M
                return decode_basic_field(stream, wire_type, field);
693
4.00M
            }
694
    
695
51.0M
        case PB_HTYPE_REPEATED:
696
51.0M
            if (wire_type == PB_WT_STRING
697
50.5M
                && PB_LTYPE(field->type) <= PB_LTYPE_LAST_PACKABLE)
698
136k
            {
699
                /* Packed array, multiple items come in at once. */
700
136k
                bool status = true;
701
136k
                pb_size_t *size = (pb_size_t*)field->pSize;
702
136k
                size_t allocated_size = *size;
703
136k
                pb_istream_t substream;
704
                
705
136k
                if (!pb_make_string_substream(stream, &substream))
706
132
                    return false;
707
                
708
33.9M
                while (substream.bytes_left)
709
33.8M
                {
710
33.8M
                    if (*size == PB_SIZE_MAX)
711
13
                    {
712
13
#ifndef PB_NO_ERRMSG
713
13
                        stream->errmsg = "too many array entries";
714
13
#endif
715
13
                        status = false;
716
13
                        break;
717
13
                    }
718
719
33.8M
                    if ((size_t)*size + 1 > allocated_size)
720
2.09M
                    {
721
                        /* Allocate more storage. This tries to guess the
722
                         * number of remaining entries. Round the division
723
                         * upwards. */
724
2.09M
                        size_t remain = (substream.bytes_left - 1) / field->data_size + 1;
725
2.09M
                        if (remain < PB_SIZE_MAX - allocated_size)
726
370k
                            allocated_size += remain;
727
1.72M
                        else
728
1.72M
                            allocated_size += 1;
729
                        
730
2.09M
                        if (!allocate_field(&substream, field->pField, field->data_size, allocated_size))
731
38
                        {
732
38
                            status = false;
733
38
                            break;
734
38
                        }
735
2.09M
                    }
736
737
                    /* Decode the array entry */
738
33.8M
                    field->pData = *(char**)field->pField + field->data_size * (*size);
739
33.8M
                    if (field->pData == NULL)
740
0
                    {
741
                        /* Shouldn't happen, but satisfies static analyzers */
742
0
                        status = false;
743
0
                        break;
744
0
                    }
745
33.8M
                    initialize_pointer_field(field->pData, field);
746
33.8M
                    if (!decode_basic_field(&substream, PB_WT_PACKED, field))
747
527
                    {
748
527
                        status = false;
749
527
                        break;
750
527
                    }
751
                    
752
33.8M
                    (*size)++;
753
33.8M
                }
754
135k
                if (!pb_close_string_substream(stream, &substream))
755
176
                    return false;
756
                
757
135k
                return status;
758
135k
            }
759
50.8M
            else
760
50.8M
            {
761
                /* Normal repeated field, i.e. only one item at a time. */
762
50.8M
                pb_size_t *size = (pb_size_t*)field->pSize;
763
764
50.8M
                if (*size == PB_SIZE_MAX)
765
4
                    PB_RETURN_ERROR(stream, "too many array entries");
766
                
767
50.8M
                if (!allocate_field(stream, field->pField, field->data_size, (size_t)(*size + 1)))
768
6
                    return false;
769
            
770
50.8M
                field->pData = *(char**)field->pField + field->data_size * (*size);
771
50.8M
                (*size)++;
772
50.8M
                initialize_pointer_field(field->pData, field);
773
50.8M
                return decode_basic_field(stream, wire_type, field);
774
50.8M
            }
775
776
0
        default:
777
0
            PB_RETURN_ERROR(stream, "invalid field type");
778
55.2M
    }
779
55.2M
#endif
780
55.2M
}
781
782
static bool checkreturn decode_callback_field(pb_istream_t *stream, pb_wire_type_t wire_type, pb_field_iter_t *field)
783
155k
{
784
    /* Clear any data that may have been decoded for another oneof field
785
     * that has come before this callback field.
786
     */
787
155k
    if (PB_HTYPE(field->type) == PB_HTYPE_ONEOF)
788
20.7k
    {
789
20.7k
        if (*(pb_size_t*)field->pSize != 0 && *(pb_size_t*)field->pSize != field->tag)
790
7.47k
        {
791
7.47k
            memset(field->pData, 0, (size_t)field->data_size);
792
7.47k
        }
793
20.7k
        *(pb_size_t*)field->pSize = field->tag;
794
20.7k
    }
795
796
155k
    if (!field->descriptor->field_callback)
797
0
        return pb_skip_field(stream, wire_type);
798
799
155k
    if (wire_type == PB_WT_STRING)
800
130k
    {
801
130k
        pb_istream_t substream;
802
130k
        size_t prev_bytes_left;
803
        
804
130k
        if (!pb_make_string_substream(stream, &substream))
805
1.13k
            return false;
806
807
        /* If the callback field is inside a submsg, first call the submsg_callback which
808
         * should set the decoder for the callback field. */
809
129k
        if (PB_LTYPE(field->type) == PB_LTYPE_SUBMSG_W_CB && field->pSize != NULL) {
810
0
            pb_callback_t* callback;
811
0
            *(pb_size_t*)field->pSize = field->tag;
812
0
            callback = (pb_callback_t*)field->pSize - 1;
813
814
0
            if (callback->funcs.decode)
815
0
            {
816
0
                if (!callback->funcs.decode(&substream, field, &callback->arg)) {
817
0
                    PB_SET_ERROR(stream, substream.errmsg ? substream.errmsg : "submsg callback failed");
818
0
                    return false;
819
0
                }
820
0
            }
821
0
        }
822
        
823
129k
        do
824
129k
        {
825
129k
            prev_bytes_left = substream.bytes_left;
826
129k
            if (!field->descriptor->field_callback(&substream, NULL, field))
827
0
            {
828
0
                PB_SET_ERROR(stream, substream.errmsg ? substream.errmsg : "callback failed");
829
0
                return false;
830
0
            }
831
129k
        } while (substream.bytes_left > 0 && substream.bytes_left < prev_bytes_left);
832
        
833
129k
        if (!pb_close_string_substream(stream, &substream))
834
115
            return false;
835
836
128k
        return true;
837
129k
    }
838
25.4k
    else
839
25.4k
    {
840
        /* Copy the single scalar value to stack.
841
         * This is required so that we can limit the stream length,
842
         * which in turn allows to use same callback for packed and
843
         * not-packed fields. */
844
25.4k
        pb_istream_t substream;
845
25.4k
        pb_byte_t buffer[10];
846
25.4k
        size_t size = sizeof(buffer);
847
        
848
25.4k
        if (!read_raw_value(stream, wire_type, buffer, &size))
849
697
            return false;
850
24.7k
        substream = pb_istream_from_buffer(buffer, size);
851
        
852
24.7k
        return field->descriptor->field_callback(&substream, NULL, field);
853
25.4k
    }
854
155k
}
855
856
static bool checkreturn decode_field(pb_istream_t *stream, pb_wire_type_t wire_type, pb_field_iter_t *field)
857
68.5M
{
858
#ifdef PB_ENABLE_MALLOC
859
    /* When decoding an oneof field, check if there is old data that must be
860
     * released first. */
861
56.7M
    if (PB_HTYPE(field->type) == PB_HTYPE_ONEOF)
862
134k
    {
863
134k
        if (!pb_release_union_field(stream, field))
864
0
            return false;
865
134k
    }
866
56.7M
#endif
867
868
68.5M
    switch (PB_ATYPE(field->type))
869
56.7M
    {
870
13.1M
        case PB_ATYPE_STATIC:
871
13.1M
            return decode_static_field(stream, wire_type, field);
872
        
873
55.2M
        case PB_ATYPE_POINTER:
874
55.2M
            return decode_pointer_field(stream, wire_type, field);
875
        
876
155k
        case PB_ATYPE_CALLBACK:
877
155k
            return decode_callback_field(stream, wire_type, field);
878
        
879
0
        default:
880
0
            PB_RETURN_ERROR(stream, "invalid field type");
881
56.7M
    }
882
56.7M
}
pb_decode.c:decode_field
Line
Count
Source
857
11.7M
{
858
#ifdef PB_ENABLE_MALLOC
859
    /* When decoding an oneof field, check if there is old data that must be
860
     * released first. */
861
    if (PB_HTYPE(field->type) == PB_HTYPE_ONEOF)
862
    {
863
        if (!pb_release_union_field(stream, field))
864
            return false;
865
    }
866
#endif
867
868
11.7M
    switch (PB_ATYPE(field->type))
869
11.7M
    {
870
11.7M
        case PB_ATYPE_STATIC:
871
11.7M
            return decode_static_field(stream, wire_type, field);
872
        
873
0
        case PB_ATYPE_POINTER:
874
0
            return decode_pointer_field(stream, wire_type, field);
875
        
876
76.6k
        case PB_ATYPE_CALLBACK:
877
76.6k
            return decode_callback_field(stream, wire_type, field);
878
        
879
0
        default:
880
            PB_RETURN_ERROR(stream, "invalid field type");
881
11.7M
    }
882
11.7M
}
pb_decode.c:decode_field
Line
Count
Source
857
56.7M
{
858
56.7M
#ifdef PB_ENABLE_MALLOC
859
    /* When decoding an oneof field, check if there is old data that must be
860
     * released first. */
861
56.7M
    if (PB_HTYPE(field->type) == PB_HTYPE_ONEOF)
862
134k
    {
863
134k
        if (!pb_release_union_field(stream, field))
864
0
            return false;
865
134k
    }
866
56.7M
#endif
867
868
56.7M
    switch (PB_ATYPE(field->type))
869
56.7M
    {
870
1.47M
        case PB_ATYPE_STATIC:
871
1.47M
            return decode_static_field(stream, wire_type, field);
872
        
873
55.2M
        case PB_ATYPE_POINTER:
874
55.2M
            return decode_pointer_field(stream, wire_type, field);
875
        
876
78.9k
        case PB_ATYPE_CALLBACK:
877
78.9k
            return decode_callback_field(stream, wire_type, field);
878
        
879
0
        default:
880
            PB_RETURN_ERROR(stream, "invalid field type");
881
56.7M
    }
882
56.7M
}
883
884
/* Default handler for extension fields. Expects to have a pb_msgdesc_t
885
 * pointer in the extension->type->arg field, pointing to a message with
886
 * only one field in it.  */
887
static bool checkreturn default_extension_decoder(pb_istream_t *stream,
888
    pb_extension_t *extension, uint32_t tag, pb_wire_type_t wire_type)
889
239k
{
890
239k
    pb_field_iter_t iter;
891
892
239k
    if (!pb_field_iter_begin_extension(&iter, extension))
893
0
        PB_RETURN_ERROR(stream, "invalid extension");
894
895
239k
    if (iter.tag != tag || !iter.message)
896
229k
        return true;
897
898
10.1k
    extension->found = true;
899
10.1k
    return decode_field(stream, wire_type, &iter);
900
239k
}
901
902
/* Try to decode an unknown field as an extension field. Tries each extension
903
 * decoder in turn, until one of them handles the field or loop ends. */
904
static bool checkreturn decode_extension(pb_istream_t *stream,
905
    uint32_t tag, pb_wire_type_t wire_type, pb_extension_t *extension)
906
239k
{
907
239k
    size_t pos = stream->bytes_left;
908
    
909
478k
    while (extension != NULL && pos == stream->bytes_left)
910
239k
    {
911
239k
        bool status;
912
239k
        if (extension->type->decode)
913
0
            status = extension->type->decode(stream, extension, tag, wire_type);
914
239k
        else
915
239k
            status = default_extension_decoder(stream, extension, tag, wire_type);
916
917
239k
        if (!status)
918
206
            return false;
919
        
920
239k
        extension = extension->next;
921
239k
    }
922
    
923
239k
    return true;
924
239k
}
925
926
/* Initialize message fields to default values, recursively */
927
static bool pb_field_set_to_default(pb_field_iter_t *field)
928
10.2M
{
929
10.2M
    pb_type_t type;
930
10.2M
    type = field->type;
931
932
10.2M
    if (PB_LTYPE(type) == PB_LTYPE_EXTENSION)
933
41.0k
    {
934
41.0k
        pb_extension_t *ext = *(pb_extension_t* const *)field->pData;
935
58.8k
        while (ext != NULL)
936
17.7k
        {
937
17.7k
            pb_field_iter_t ext_iter;
938
17.7k
            if (pb_field_iter_begin_extension(&ext_iter, ext))
939
17.7k
            {
940
17.7k
                ext->found = false;
941
17.7k
                if (!pb_message_set_to_defaults(&ext_iter))
942
0
                    return false;
943
17.7k
            }
944
17.7k
            ext = ext->next;
945
17.7k
        }
946
41.0k
    }
947
10.1M
    else if (PB_ATYPE(type) == PB_ATYPE_STATIC)
948
2.39M
    {
949
2.39M
        bool init_data = true;
950
2.39M
        if (PB_HTYPE(type) == PB_HTYPE_OPTIONAL && field->pSize != NULL)
951
584k
        {
952
            /* Set has_field to false. Still initialize the optional field
953
             * itself also. */
954
584k
            *(bool*)field->pSize = false;
955
584k
        }
956
1.81M
        else if (PB_HTYPE(type) == PB_HTYPE_REPEATED ||
957
1.33M
                 PB_HTYPE(type) == PB_HTYPE_ONEOF)
958
677k
        {
959
            /* REPEATED: Set array count to 0, no need to initialize contents.
960
               ONEOF: Set which_field to 0. */
961
677k
            *(pb_size_t*)field->pSize = 0;
962
677k
            init_data = false;
963
677k
        }
964
965
2.39M
        if (init_data)
966
1.71M
        {
967
1.71M
            if (PB_LTYPE_IS_SUBMSG(field->type) &&
968
197k
                (field->submsg_desc->default_value != NULL ||
969
129k
                 field->submsg_desc->field_callback != NULL ||
970
129k
                 field->submsg_desc->submsg_info[0] != NULL))
971
68.6k
            {
972
                /* Initialize submessage to defaults.
973
                 * Only needed if it has default values
974
                 * or callback/submessage fields. */
975
68.6k
                pb_field_iter_t submsg_iter;
976
68.6k
                if (pb_field_iter_begin(&submsg_iter, field->submsg_desc, field->pData))
977
68.6k
                {
978
68.6k
                    if (!pb_message_set_to_defaults(&submsg_iter))
979
0
                        return false;
980
68.6k
                }
981
68.6k
            }
982
1.65M
            else
983
1.65M
            {
984
                /* Initialize to zeros */
985
1.65M
                memset(field->pData, 0, (size_t)field->data_size);
986
1.65M
            }
987
1.71M
        }
988
2.39M
    }
989
7.76M
    else if (PB_ATYPE(type) == PB_ATYPE_POINTER)
990
7.47M
    {
991
        /* Initialize the pointer to NULL. */
992
7.47M
        *(void**)field->pField = NULL;
993
994
        /* Initialize array count to 0. */
995
7.47M
        if (PB_HTYPE(type) == PB_HTYPE_REPEATED ||
996
6.92M
            PB_HTYPE(type) == PB_HTYPE_ONEOF)
997
609k
        {
998
609k
            *(pb_size_t*)field->pSize = 0;
999
609k
        }
1000
7.47M
    }
1001
288k
    else if (PB_ATYPE(type) == PB_ATYPE_CALLBACK)
1002
288k
    {
1003
        /* Don't overwrite callback */
1004
288k
    }
1005
1006
10.2M
    return true;
1007
10.2M
}
1008
1009
static bool pb_message_set_to_defaults(pb_field_iter_t *iter)
1010
2.13M
{
1011
2.13M
    pb_istream_t defstream = PB_ISTREAM_EMPTY;
1012
2.13M
    uint32_t tag = 0;
1013
2.13M
    pb_wire_type_t wire_type = PB_WT_VARINT;
1014
2.13M
    bool eof;
1015
1016
2.13M
    if (iter->descriptor->default_value)
1017
177k
    {
1018
177k
        defstream = pb_istream_from_buffer(iter->descriptor->default_value, (size_t)-1);
1019
177k
        if (!pb_decode_tag(&defstream, &wire_type, &tag, &eof))
1020
0
            return false;
1021
177k
    }
1022
1023
2.13M
    do
1024
10.2M
    {
1025
10.2M
        if (!pb_field_set_to_default(iter))
1026
0
            return false;
1027
1028
10.2M
        if (tag != 0 && iter->tag == tag)
1029
998k
        {
1030
            /* We have a default value for this field in the defstream */
1031
998k
            if (!decode_field(&defstream, wire_type, iter))
1032
0
                return false;
1033
998k
            if (!pb_decode_tag(&defstream, &wire_type, &tag, &eof))
1034
0
                return false;
1035
1036
998k
            if (iter->pSize)
1037
524k
                *(bool*)iter->pSize = false;
1038
998k
        }
1039
10.2M
    } while (pb_field_iter_next(iter));
1040
1041
2.13M
    return true;
1042
2.13M
}
1043
1044
/*********************
1045
 * Decode all fields *
1046
 *********************/
1047
1048
static bool checkreturn pb_decode_inner(pb_istream_t *stream, const pb_msgdesc_t *fields, void *dest_struct, unsigned int flags)
1049
2.45M
{
1050
    /* If the message contains extension fields, the extension handlers
1051
     * are called when tag number is >= extension_range_start. This precheck
1052
     * is just for speed, and the handlers will check for precise match.
1053
     */
1054
2.45M
    uint32_t extension_range_start = 0;
1055
2.45M
    pb_extension_t *extensions = NULL;
1056
1057
    /* 'fixed_count_field' and 'fixed_count_size' track position of a repeated fixed
1058
     * count field. This can only handle _one_ repeated fixed count field that
1059
     * is unpacked and unordered among other (non repeated fixed count) fields.
1060
     */
1061
2.45M
    pb_size_t fixed_count_field = PB_SIZE_MAX;
1062
2.45M
    pb_size_t fixed_count_size = 0;
1063
2.45M
    pb_size_t fixed_count_total_size = 0;
1064
1065
    /* Tag and wire type of next field from the input stream */
1066
2.45M
    uint32_t tag;
1067
2.45M
    pb_wire_type_t wire_type;
1068
2.45M
    bool eof;
1069
1070
    /* Track presence of required fields */
1071
2.45M
    pb_fields_seen_t fields_seen = {{0, 0}};
1072
2.45M
    const uint32_t allbits = ~(uint32_t)0;
1073
1074
    /* Descriptor for the structure field matching the tag decoded from stream */
1075
2.45M
    pb_field_iter_t iter;
1076
1077
2.45M
    if (pb_field_iter_begin(&iter, fields, dest_struct))
1078
2.17M
    {
1079
2.17M
        if ((flags & PB_DECODE_NOINIT) == 0)
1080
1.96M
        {
1081
1.96M
            if (!pb_message_set_to_defaults(&iter))
1082
0
                PB_RETURN_ERROR(stream, "failed to set defaults");
1083
1.96M
        }
1084
2.17M
    }
1085
1086
73.0M
    while (pb_decode_tag(stream, &wire_type, &tag, &eof))
1087
70.6M
    {
1088
70.6M
        if (tag == 0)
1089
2.31k
        {
1090
2.31k
          if (flags & PB_DECODE_NULLTERMINATED)
1091
324
          {
1092
324
            eof = true;
1093
324
            break;
1094
324
          }
1095
1.98k
          else
1096
1.98k
          {
1097
1.98k
            PB_RETURN_ERROR(stream, "zero tag");
1098
1.98k
          }
1099
2.31k
        }
1100
1101
70.6M
        if (!pb_field_iter_find(&iter, tag) || PB_LTYPE(iter.type) == PB_LTYPE_EXTENSION)
1102
3.11M
        {
1103
            /* No match found, check if it matches an extension. */
1104
3.11M
            if (extension_range_start == 0)
1105
65.7k
            {
1106
65.7k
                if (pb_field_iter_find_extension(&iter))
1107
16.7k
                {
1108
16.7k
                    extensions = *(pb_extension_t* const *)iter.pData;
1109
16.7k
                    extension_range_start = iter.tag;
1110
16.7k
                }
1111
1112
65.7k
                if (!extensions)
1113
57.3k
                {
1114
57.3k
                    extension_range_start = (uint32_t)-1;
1115
57.3k
                }
1116
65.7k
            }
1117
1118
3.11M
            if (tag >= extension_range_start)
1119
239k
            {
1120
239k
                size_t pos = stream->bytes_left;
1121
1122
239k
                if (!decode_extension(stream, tag, wire_type, extensions))
1123
206
                    return false;
1124
1125
239k
                if (pos != stream->bytes_left)
1126
9.94k
                {
1127
                    /* The field was handled */
1128
9.94k
                    continue;
1129
9.94k
                }
1130
239k
            }
1131
1132
            /* No match found, skip data */
1133
3.10M
            if (!pb_skip_field(stream, wire_type))
1134
6.20k
                return false;
1135
3.09M
            continue;
1136
3.10M
        }
1137
1138
        /* If a repeated fixed count field was found, get size from
1139
         * 'fixed_count_field' as there is no counter contained in the struct.
1140
         */
1141
67.5M
        if (PB_HTYPE(iter.type) == PB_HTYPE_REPEATED && iter.pSize == &iter.array_size)
1142
7.79k
        {
1143
7.79k
            if (fixed_count_field != iter.index) {
1144
                /* If the new fixed count field does not match the previous one,
1145
                 * check that the previous one is NULL or that it finished
1146
                 * receiving all the expected data.
1147
                 */
1148
5.79k
                if (fixed_count_field != PB_SIZE_MAX &&
1149
3.04k
                    fixed_count_size != fixed_count_total_size)
1150
41
                {
1151
41
                    PB_RETURN_ERROR(stream, "wrong size for fixed count field");
1152
41
                }
1153
1154
5.75k
                fixed_count_field = iter.index;
1155
5.75k
                fixed_count_size = 0;
1156
5.75k
                fixed_count_total_size = iter.array_size;
1157
5.75k
            }
1158
1159
7.75k
            iter.pSize = &fixed_count_size;
1160
7.75k
        }
1161
1162
67.5M
        if (PB_HTYPE(iter.type) == PB_HTYPE_REQUIRED
1163
9.05M
            && iter.required_field_index < PB_MAX_REQUIRED_FIELDS)
1164
9.05M
        {
1165
9.05M
            uint32_t tmp = ((uint32_t)1 << (iter.required_field_index & 31));
1166
9.05M
            fields_seen.bitfield[iter.required_field_index >> 5] |= tmp;
1167
9.05M
        }
1168
1169
67.5M
        if (!decode_field(stream, wire_type, &iter))
1170
18.0k
            return false;
1171
67.5M
    }
1172
1173
2.43M
    if (!eof)
1174
2.69k
    {
1175
        /* pb_decode_tag() returned error before end of stream */
1176
2.69k
        return false;
1177
2.69k
    }
1178
1179
    /* Check that all elements of the last decoded fixed count field were present. */
1180
2.42M
    if (fixed_count_field != PB_SIZE_MAX &&
1181
2.13k
        fixed_count_size != fixed_count_total_size)
1182
130
    {
1183
130
        PB_RETURN_ERROR(stream, "wrong size for fixed count field");
1184
130
    }
1185
1186
    /* Check that all required fields were present. */
1187
2.42M
    {
1188
2.42M
        pb_size_t req_field_count = iter.descriptor->required_field_count;
1189
1190
2.42M
        if (req_field_count > 0)
1191
304k
        {
1192
304k
            pb_size_t i;
1193
1194
304k
            if (req_field_count > PB_MAX_REQUIRED_FIELDS)
1195
0
                req_field_count = PB_MAX_REQUIRED_FIELDS;
1196
1197
            /* Check the whole words */
1198
304k
            for (i = 0; i < (req_field_count >> 5); i++)
1199
0
            {
1200
0
                if (fields_seen.bitfield[i] != allbits)
1201
0
                    PB_RETURN_ERROR(stream, "missing required field");
1202
0
            }
1203
1204
            /* Check the remaining bits (if any) */
1205
304k
            if ((req_field_count & 31) != 0)
1206
304k
            {
1207
304k
                if (fields_seen.bitfield[req_field_count >> 5] !=
1208
304k
                    (allbits >> (uint_least8_t)(32 - (req_field_count & 31))))
1209
4.07k
                {
1210
4.07k
                    PB_RETURN_ERROR(stream, "missing required field");
1211
4.07k
                }
1212
304k
            }
1213
304k
        }
1214
2.42M
    }
1215
1216
2.42M
    return true;
1217
2.42M
}
1218
1219
bool checkreturn pb_decode_ex(pb_istream_t *stream, const pb_msgdesc_t *fields, void *dest_struct, unsigned int flags)
1220
15.3k
{
1221
15.3k
    bool status;
1222
1223
15.3k
    if ((flags & PB_DECODE_DELIMITED) == 0)
1224
15.3k
    {
1225
15.3k
      status = pb_decode_inner(stream, fields, dest_struct, flags);
1226
15.3k
    }
1227
0
    else
1228
0
    {
1229
0
      pb_istream_t substream;
1230
0
      if (!pb_make_string_substream(stream, &substream))
1231
0
        return false;
1232
1233
0
      status = pb_decode_inner(&substream, fields, dest_struct, flags);
1234
1235
0
      if (!pb_close_string_substream(stream, &substream))
1236
0
        status = false;
1237
0
    }
1238
    
1239
#ifdef PB_ENABLE_MALLOC
1240
    if (!status)
1241
        pb_release(fields, dest_struct);
1242
#endif
1243
    
1244
15.3k
    return status;
1245
15.3k
}
1246
1247
bool checkreturn pb_decode(pb_istream_t *stream, const pb_msgdesc_t *fields, void *dest_struct)
1248
18.6k
{
1249
18.6k
    return pb_decode_ex(stream, fields, dest_struct, 0);
1250
18.6k
}
1251
1252
#ifdef PB_ENABLE_MALLOC
1253
/* Given an oneof field, if there has already been a field inside this oneof,
1254
 * release it before overwriting with a different one. */
1255
static bool pb_release_union_field(pb_istream_t *stream, pb_field_iter_t *field)
1256
134k
{
1257
134k
    pb_field_iter_t old_field = *field;
1258
134k
    pb_size_t old_tag = *(pb_size_t*)field->pSize; /* Previous which_ value */
1259
134k
    pb_size_t new_tag = field->tag; /* New which_ value */
1260
1261
134k
    if (old_tag == 0)
1262
6.98k
        return true; /* Ok, no old data in union */
1263
1264
127k
    if (old_tag == new_tag)
1265
50.7k
        return true; /* Ok, old data is of same type => merge */
1266
1267
    /* Release old data. The find can fail if the message struct contains
1268
     * invalid data. */
1269
76.9k
    if (!pb_field_iter_find(&old_field, old_tag))
1270
0
        PB_RETURN_ERROR(stream, "invalid union tag");
1271
1272
76.9k
    pb_release_single_field(&old_field);
1273
1274
76.9k
    if (PB_ATYPE(field->type) == PB_ATYPE_POINTER)
1275
32.3k
    {
1276
        /* Initialize the pointer to NULL to make sure it is valid
1277
         * even in case of error return. */
1278
32.3k
        *(void**)field->pField = NULL;
1279
32.3k
        field->pData = NULL;
1280
32.3k
    }
1281
1282
76.9k
    return true;
1283
76.9k
}
1284
1285
static void pb_release_single_field(pb_field_iter_t *field)
1286
9.84M
{
1287
9.84M
    pb_type_t type;
1288
9.84M
    type = field->type;
1289
1290
9.84M
    if (PB_HTYPE(type) == PB_HTYPE_ONEOF)
1291
400k
    {
1292
400k
        if (*(pb_size_t*)field->pSize != field->tag)
1293
289k
            return; /* This is not the current field in the union */
1294
400k
    }
1295
1296
    /* Release anything contained inside an extension or submsg.
1297
     * This has to be done even if the submsg itself is statically
1298
     * allocated. */
1299
9.55M
    if (PB_LTYPE(type) == PB_LTYPE_EXTENSION)
1300
38.4k
    {
1301
        /* Release fields from all extensions in the linked list */
1302
38.4k
        pb_extension_t *ext = *(pb_extension_t**)field->pData;
1303
51.6k
        while (ext != NULL)
1304
13.1k
        {
1305
13.1k
            pb_field_iter_t ext_iter;
1306
13.1k
            if (pb_field_iter_begin_extension(&ext_iter, ext))
1307
13.1k
            {
1308
13.1k
                pb_release_single_field(&ext_iter);
1309
13.1k
            }
1310
13.1k
            ext = ext->next;
1311
13.1k
        }
1312
38.4k
    }
1313
9.51M
    else if (PB_LTYPE_IS_SUBMSG(type) && PB_ATYPE(type) != PB_ATYPE_CALLBACK)
1314
535k
    {
1315
        /* Release fields in submessage or submsg array */
1316
535k
        pb_size_t count = 1;
1317
        
1318
535k
        if (PB_ATYPE(type) == PB_ATYPE_POINTER)
1319
320k
        {
1320
320k
            field->pData = *(void**)field->pField;
1321
320k
        }
1322
215k
        else
1323
215k
        {
1324
215k
            field->pData = field->pField;
1325
215k
        }
1326
        
1327
535k
        if (PB_HTYPE(type) == PB_HTYPE_REPEATED)
1328
76.6k
        {
1329
76.6k
            count = *(pb_size_t*)field->pSize;
1330
1331
76.6k
            if (PB_ATYPE(type) == PB_ATYPE_STATIC && count > field->array_size)
1332
82
            {
1333
                /* Protect against corrupted _count fields */
1334
82
                count = field->array_size;
1335
82
            }
1336
76.6k
        }
1337
        
1338
535k
        if (field->pData)
1339
365k
        {
1340
2.58M
            for (; count > 0; count--)
1341
2.21M
            {
1342
2.21M
                pb_release(field->submsg_desc, field->pData);
1343
2.21M
                field->pData = (char*)field->pData + field->data_size;
1344
2.21M
            }
1345
365k
        }
1346
535k
    }
1347
    
1348
9.55M
    if (PB_ATYPE(type) == PB_ATYPE_POINTER)
1349
7.60M
    {
1350
7.60M
        if (PB_HTYPE(type) == PB_HTYPE_REPEATED &&
1351
563k
            (PB_LTYPE(type) == PB_LTYPE_STRING ||
1352
535k
             PB_LTYPE(type) == PB_LTYPE_BYTES))
1353
55.4k
        {
1354
            /* Release entries in repeated string or bytes array */
1355
55.4k
            void **pItem = *(void***)field->pField;
1356
55.4k
            pb_size_t count = *(pb_size_t*)field->pSize;
1357
1.02M
            for (; count > 0; count--)
1358
967k
            {
1359
967k
                pb_free(*pItem);
1360
967k
                *pItem++ = NULL;
1361
967k
            }
1362
55.4k
        }
1363
        
1364
7.60M
        if (PB_HTYPE(type) == PB_HTYPE_REPEATED)
1365
563k
        {
1366
            /* We are going to release the array, so set the size to 0 */
1367
563k
            *(pb_size_t*)field->pSize = 0;
1368
563k
        }
1369
        
1370
        /* Release main pointer */
1371
7.60M
        pb_free(*(void**)field->pField);
1372
7.60M
        *(void**)field->pField = NULL;
1373
7.60M
    }
1374
9.55M
}
1375
1376
void pb_release(const pb_msgdesc_t *fields, void *dest_struct)
1377
2.26M
{
1378
2.26M
    pb_field_iter_t iter;
1379
    
1380
2.26M
    if (!dest_struct)
1381
0
        return; /* Ignore NULL pointers, similar to free() */
1382
1383
2.26M
    if (!pb_field_iter_begin(&iter, fields, dest_struct))
1384
167k
        return; /* Empty message type */
1385
    
1386
2.09M
    do
1387
9.68M
    {
1388
9.68M
        pb_release_single_field(&iter);
1389
9.68M
    } while (pb_field_iter_next(&iter));
1390
2.09M
}
1391
#else
1392
void pb_release(const pb_msgdesc_t *fields, void *dest_struct)
1393
12.4k
{
1394
    /* Nothing to release without PB_ENABLE_MALLOC. */
1395
12.4k
    PB_UNUSED(fields);
1396
12.4k
    PB_UNUSED(dest_struct);
1397
12.4k
}
1398
#endif
1399
1400
/* Field decoders */
1401
1402
bool pb_decode_bool(pb_istream_t *stream, bool *dest)
1403
10.1M
{
1404
10.1M
    uint32_t value;
1405
10.1M
    if (!pb_decode_varint32(stream, &value))
1406
492
        return false;
1407
1408
10.1M
    *(bool*)dest = (value != 0);
1409
10.1M
    return true;
1410
10.1M
}
1411
1412
bool pb_decode_svarint(pb_istream_t *stream, pb_int64_t *dest)
1413
6.56M
{
1414
6.56M
    pb_uint64_t value;
1415
6.56M
    if (!pb_decode_varint(stream, &value))
1416
466
        return false;
1417
    
1418
6.56M
    if (value & 1)
1419
789k
        *dest = (pb_int64_t)(~(value >> 1));
1420
5.77M
    else
1421
5.77M
        *dest = (pb_int64_t)(value >> 1);
1422
    
1423
6.56M
    return true;
1424
6.56M
}
1425
1426
bool pb_decode_fixed32(pb_istream_t *stream, void *dest)
1427
908k
{
1428
908k
    union {
1429
908k
        uint32_t fixed32;
1430
908k
        pb_byte_t bytes[4];
1431
908k
    } u;
1432
1433
908k
    if (!pb_read(stream, u.bytes, 4))
1434
342
        return false;
1435
1436
908k
#if defined(PB_LITTLE_ENDIAN_8BIT) && PB_LITTLE_ENDIAN_8BIT == 1
1437
    /* fast path - if we know that we're on little endian, assign directly */
1438
908k
    *(uint32_t*)dest = u.fixed32;
1439
#else
1440
    *(uint32_t*)dest = ((uint32_t)u.bytes[0] << 0) |
1441
                       ((uint32_t)u.bytes[1] << 8) |
1442
                       ((uint32_t)u.bytes[2] << 16) |
1443
                       ((uint32_t)u.bytes[3] << 24);
1444
#endif
1445
908k
    return true;
1446
908k
}
1447
1448
#ifndef PB_WITHOUT_64BIT
1449
bool pb_decode_fixed64(pb_istream_t *stream, void *dest)
1450
728k
{
1451
728k
    union {
1452
728k
        uint64_t fixed64;
1453
728k
        pb_byte_t bytes[8];
1454
728k
    } u;
1455
1456
728k
    if (!pb_read(stream, u.bytes, 8))
1457
363
        return false;
1458
1459
728k
#if defined(PB_LITTLE_ENDIAN_8BIT) && PB_LITTLE_ENDIAN_8BIT == 1
1460
    /* fast path - if we know that we're on little endian, assign directly */
1461
728k
    *(uint64_t*)dest = u.fixed64;
1462
#else
1463
    *(uint64_t*)dest = ((uint64_t)u.bytes[0] << 0) |
1464
                       ((uint64_t)u.bytes[1] << 8) |
1465
                       ((uint64_t)u.bytes[2] << 16) |
1466
                       ((uint64_t)u.bytes[3] << 24) |
1467
                       ((uint64_t)u.bytes[4] << 32) |
1468
                       ((uint64_t)u.bytes[5] << 40) |
1469
                       ((uint64_t)u.bytes[6] << 48) |
1470
                       ((uint64_t)u.bytes[7] << 56);
1471
#endif
1472
728k
    return true;
1473
728k
}
1474
#endif
1475
1476
static bool checkreturn pb_dec_bool(pb_istream_t *stream, const pb_field_iter_t *field)
1477
10.1M
{
1478
10.1M
    return pb_decode_bool(stream, (bool*)field->pData);
1479
10.1M
}
1480
1481
static bool checkreturn pb_dec_varint(pb_istream_t *stream, const pb_field_iter_t *field)
1482
38.7M
{
1483
38.7M
    if (PB_LTYPE(field->type) == PB_LTYPE_UVARINT)
1484
4.29M
    {
1485
4.29M
        pb_uint64_t value, clamped;
1486
4.29M
        if (!pb_decode_varint(stream, &value))
1487
539
            return false;
1488
1489
        /* Cast to the proper field size, while checking for overflows */
1490
4.29M
        if (field->data_size == sizeof(pb_uint64_t))
1491
2.81M
            clamped = *(pb_uint64_t*)field->pData = value;
1492
1.48M
        else if (field->data_size == sizeof(uint32_t))
1493
1.43M
            clamped = *(uint32_t*)field->pData = (uint32_t)value;
1494
50.6k
        else if (field->data_size == sizeof(uint_least16_t))
1495
25.1k
            clamped = *(uint_least16_t*)field->pData = (uint_least16_t)value;
1496
25.5k
        else if (field->data_size == sizeof(uint_least8_t))
1497
25.5k
            clamped = *(uint_least8_t*)field->pData = (uint_least8_t)value;
1498
0
        else
1499
0
            PB_RETURN_ERROR(stream, "invalid data_size");
1500
1501
4.29M
        if (clamped != value)
1502
674
            PB_RETURN_ERROR(stream, "integer too large");
1503
1504
4.29M
        return true;
1505
4.29M
    }
1506
34.4M
    else
1507
34.4M
    {
1508
34.4M
        pb_uint64_t value;
1509
34.4M
        pb_int64_t svalue;
1510
34.4M
        pb_int64_t clamped;
1511
1512
34.4M
        if (PB_LTYPE(field->type) == PB_LTYPE_SVARINT)
1513
6.56M
        {
1514
6.56M
            if (!pb_decode_svarint(stream, &svalue))
1515
466
                return false;
1516
6.56M
        }
1517
27.8M
        else
1518
27.8M
        {
1519
27.8M
            if (!pb_decode_varint(stream, &value))
1520
705
                return false;
1521
1522
            /* See issue 97: Google's C++ protobuf allows negative varint values to
1523
            * be cast as int32_t, instead of the int64_t that should be used when
1524
            * encoding. Nanopb versions before 0.2.5 had a bug in encoding. In order to
1525
            * not break decoding of such messages, we cast <=32 bit fields to
1526
            * int32_t first to get the sign correct.
1527
            */
1528
27.8M
            if (field->data_size == sizeof(pb_int64_t))
1529
2.42M
                svalue = (pb_int64_t)value;
1530
25.4M
            else
1531
25.4M
                svalue = (int32_t)value;
1532
27.8M
        }
1533
1534
        /* Cast to the proper field size, while checking for overflows */
1535
34.4M
        if (field->data_size == sizeof(pb_int64_t))
1536
8.15M
            clamped = *(pb_int64_t*)field->pData = svalue;
1537
26.2M
        else if (field->data_size == sizeof(int32_t))
1538
26.1M
            clamped = *(int32_t*)field->pData = (int32_t)svalue;
1539
100k
        else if (field->data_size == sizeof(int_least16_t))
1540
49.9k
            clamped = *(int_least16_t*)field->pData = (int_least16_t)svalue;
1541
50.1k
        else if (field->data_size == sizeof(int_least8_t))
1542
50.1k
            clamped = *(int_least8_t*)field->pData = (int_least8_t)svalue;
1543
0
        else
1544
0
            PB_RETURN_ERROR(stream, "invalid data_size");
1545
1546
34.4M
        if (clamped != svalue)
1547
537
            PB_RETURN_ERROR(stream, "integer too large");
1548
1549
34.4M
        return true;
1550
34.4M
    }
1551
38.7M
}
1552
1553
static bool checkreturn pb_dec_bytes(pb_istream_t *stream, const pb_field_iter_t *field)
1554
64.1k
{
1555
64.1k
    uint32_t size;
1556
64.1k
    size_t alloc_size;
1557
64.1k
    pb_bytes_array_t *dest;
1558
    
1559
64.1k
    if (!pb_decode_varint32(stream, &size))
1560
4
        return false;
1561
    
1562
64.1k
    if (size > PB_SIZE_MAX)
1563
60
        PB_RETURN_ERROR(stream, "bytes overflow");
1564
    
1565
64.0k
    alloc_size = PB_BYTES_ARRAY_T_ALLOCSIZE(size);
1566
64.0k
    if (size > alloc_size)
1567
0
        PB_RETURN_ERROR(stream, "size too large");
1568
    
1569
64.0k
    if (PB_ATYPE(field->type) == PB_ATYPE_POINTER)
1570
0
    {
1571
0
#ifndef PB_ENABLE_MALLOC
1572
0
        PB_RETURN_ERROR(stream, "no malloc support");
1573
#else
1574
        if (stream->bytes_left < size)
1575
            PB_RETURN_ERROR(stream, "end-of-stream");
1576
1577
        if (!allocate_field(stream, field->pData, alloc_size, 1))
1578
            return false;
1579
        dest = *(pb_bytes_array_t**)field->pData;
1580
#endif
1581
0
    }
1582
64.0k
    else
1583
64.0k
    {
1584
64.0k
        if (alloc_size > field->data_size)
1585
117
            PB_RETURN_ERROR(stream, "bytes overflow");
1586
63.9k
        dest = (pb_bytes_array_t*)field->pData;
1587
63.9k
    }
1588
1589
63.9k
    dest->size = (pb_size_t)size;
1590
63.9k
    return pb_read(stream, dest->bytes, (size_t)size);
1591
64.0k
}
1592
1593
static bool checkreturn pb_dec_string(pb_istream_t *stream, const pb_field_iter_t *field)
1594
225k
{
1595
225k
    uint32_t size;
1596
225k
    size_t alloc_size;
1597
225k
    pb_byte_t *dest = (pb_byte_t*)field->pData;
1598
1599
225k
    if (!pb_decode_varint32(stream, &size))
1600
10
        return false;
1601
1602
225k
    if (size == (uint32_t)-1)
1603
3
        PB_RETURN_ERROR(stream, "size too large");
1604
1605
    /* Space for null terminator */
1606
225k
    alloc_size = (size_t)(size + 1);
1607
1608
225k
    if (alloc_size < size)
1609
0
        PB_RETURN_ERROR(stream, "size too large");
1610
1611
225k
    if (PB_ATYPE(field->type) == PB_ATYPE_POINTER)
1612
0
    {
1613
0
#ifndef PB_ENABLE_MALLOC
1614
0
        PB_RETURN_ERROR(stream, "no malloc support");
1615
#else
1616
        if (stream->bytes_left < size)
1617
            PB_RETURN_ERROR(stream, "end-of-stream");
1618
1619
        if (!allocate_field(stream, field->pData, alloc_size, 1))
1620
            return false;
1621
        dest = *(pb_byte_t**)field->pData;
1622
#endif
1623
0
    }
1624
225k
    else
1625
225k
    {
1626
225k
        if (alloc_size > field->data_size)
1627
179
            PB_RETURN_ERROR(stream, "string overflow");
1628
225k
    }
1629
    
1630
225k
    dest[size] = 0;
1631
1632
225k
    if (!pb_read(stream, dest, (size_t)size))
1633
12
        return false;
1634
1635
#ifdef PB_VALIDATE_UTF8
1636
    if (!pb_validate_utf8((const char*)dest))
1637
        PB_RETURN_ERROR(stream, "invalid utf8");
1638
#endif
1639
1640
225k
    return true;
1641
225k
}
1642
1643
static bool checkreturn pb_dec_submessage(pb_istream_t *stream, const pb_field_iter_t *field)
1644
2.43M
{
1645
2.43M
    bool status = true;
1646
2.43M
    bool submsg_consumed = false;
1647
2.43M
    pb_istream_t substream;
1648
1649
2.43M
    if (!pb_make_string_substream(stream, &substream))
1650
1.77k
        return false;
1651
    
1652
2.43M
    if (field->submsg_desc == NULL)
1653
0
        PB_RETURN_ERROR(stream, "invalid field descriptor");
1654
    
1655
    /* Submessages can have a separate message-level callback that is called
1656
     * before decoding the message. Typically it is used to set callback fields
1657
     * inside oneofs. */
1658
2.43M
    if (PB_LTYPE(field->type) == PB_LTYPE_SUBMSG_W_CB && field->pSize != NULL)
1659
58.4k
    {
1660
        /* Message callback is stored right before pSize. */
1661
58.4k
        pb_callback_t *callback = (pb_callback_t*)field->pSize - 1;
1662
58.4k
        if (callback->funcs.decode)
1663
58.4k
        {
1664
58.4k
            status = callback->funcs.decode(&substream, field, &callback->arg);
1665
1666
58.4k
            if (substream.bytes_left == 0)
1667
31.2k
            {
1668
31.2k
                submsg_consumed = true;
1669
31.2k
            }
1670
58.4k
        }
1671
58.4k
    }
1672
1673
    /* Now decode the submessage contents */
1674
2.43M
    if (status && !submsg_consumed)
1675
2.39M
    {
1676
2.39M
        unsigned int flags = 0;
1677
1678
        /* Static required/optional fields are already initialized by top-level
1679
         * pb_decode(), no need to initialize them again. */
1680
2.39M
        if (PB_ATYPE(field->type) == PB_ATYPE_STATIC &&
1681
376k
            PB_HTYPE(field->type) != PB_HTYPE_REPEATED)
1682
364k
        {
1683
364k
            flags = PB_DECODE_NOINIT;
1684
364k
        }
1685
1686
2.39M
        status = pb_decode_inner(&substream, field->submsg_desc, field->pData, flags);
1687
2.39M
    }
1688
    
1689
2.43M
    if (!pb_close_string_substream(stream, &substream))
1690
839
        return false;
1691
1692
2.42M
    return status;
1693
2.43M
}
1694
1695
static bool checkreturn pb_dec_fixed_length_bytes(pb_istream_t *stream, const pb_field_iter_t *field)
1696
47.5M
{
1697
47.5M
    uint32_t size;
1698
1699
47.5M
    if (!pb_decode_varint32(stream, &size))
1700
26
        return false;
1701
1702
47.5M
    if (size > PB_SIZE_MAX)
1703
224
        PB_RETURN_ERROR(stream, "bytes overflow");
1704
1705
47.5M
    if (size == 0)
1706
45.6M
    {
1707
        /* As a special case, treat empty bytes string as all zeros for fixed_length_bytes. */
1708
45.6M
        memset(field->pData, 0, (size_t)field->data_size);
1709
45.6M
        return true;
1710
45.6M
    }
1711
1712
1.89M
    if (size != field->data_size)
1713
335
        PB_RETURN_ERROR(stream, "incorrect fixed length bytes size");
1714
1715
1.89M
    return pb_read(stream, (pb_byte_t*)field->pData, (size_t)field->data_size);
1716
1.89M
}
1717
1718
#ifdef PB_CONVERT_DOUBLE_FLOAT
1719
bool pb_decode_double_as_float(pb_istream_t *stream, float *dest)
1720
{
1721
    uint_least8_t sign;
1722
    int exponent;
1723
    uint32_t mantissa;
1724
    uint64_t value;
1725
    union { float f; uint32_t i; } out;
1726
1727
    if (!pb_decode_fixed64(stream, &value))
1728
        return false;
1729
1730
    /* Decompose input value */
1731
    sign = (uint_least8_t)((value >> 63) & 1);
1732
    exponent = (int)((value >> 52) & 0x7FF) - 1023;
1733
    mantissa = (value >> 28) & 0xFFFFFF; /* Highest 24 bits */
1734
1735
    /* Figure if value is in range representable by floats. */
1736
    if (exponent == 1024)
1737
    {
1738
        /* Special value */
1739
        exponent = 128;
1740
        mantissa >>= 1;
1741
        /* Preserve NaN if its payload was lost when narrowing the mantissa. */
1742
        if (mantissa == 0 && (uint32_t)value != 0)
1743
            mantissa = 1;
1744
    }
1745
    else
1746
    {
1747
        if (exponent > 127)
1748
        {
1749
            /* Too large, convert to infinity */
1750
            exponent = 128;
1751
            mantissa = 0;
1752
        }
1753
        else if (exponent < -150)
1754
        {
1755
            /* Too small, convert to zero */
1756
            exponent = -127;
1757
            mantissa = 0;
1758
        }
1759
        else if (exponent < -126)
1760
        {
1761
            /* Denormalized */
1762
            mantissa |= 0x1000000;
1763
            mantissa >>= (-126 - exponent);
1764
            exponent = -127;
1765
        }
1766
1767
        /* Round off mantissa */
1768
        mantissa = (mantissa + 1) >> 1;
1769
1770
        /* Check if mantissa went over 2.0 */
1771
        if (mantissa & 0x800000)
1772
        {
1773
            exponent += 1;
1774
            mantissa &= 0x7FFFFF;
1775
            mantissa >>= 1;
1776
        }
1777
    }
1778
1779
    /* Combine fields */
1780
    out.i = mantissa;
1781
    out.i |= (uint32_t)(exponent + 127) << 23;
1782
    out.i |= (uint32_t)sign << 31;
1783
1784
    *dest = out.f;
1785
    return true;
1786
}
1787
#endif