blob: a025e9165bda2ae6e45a42512aac9c1ca73fbc10 [file] [log] [blame]
Laurence Lundbladeb69cad72018-09-13 11:09:01 -07001/*==============================================================================
Laurence Lundbladed92a6162018-11-01 11:38:35 +07002 Copyright (c) 2016-2018, The Linux Foundation.
Laurence Lundbladeee851742020-01-08 08:37:05 -08003 Copyright (c) 2018-2020, Laurence Lundblade.
Laurence Lundbladed92a6162018-11-01 11:38:35 +07004 All rights reserved.
Laurence Lundblade3aee3a32018-12-17 16:17:45 -08005
Laurence Lundblade0dbc9172018-11-01 14:17:21 +07006Redistribution and use in source and binary forms, with or without
7modification, are permitted provided that the following conditions are
8met:
9 * Redistributions of source code must retain the above copyright
10 notice, this list of conditions and the following disclaimer.
11 * Redistributions in binary form must reproduce the above
12 copyright notice, this list of conditions and the following
13 disclaimer in the documentation and/or other materials provided
14 with the distribution.
15 * Neither the name of The Linux Foundation nor the names of its
16 contributors, nor the name "Laurence Lundblade" may be used to
17 endorse or promote products derived from this software without
18 specific prior written permission.
Laurence Lundblade3aee3a32018-12-17 16:17:45 -080019
Laurence Lundblade0dbc9172018-11-01 14:17:21 +070020THIS SOFTWARE IS PROVIDED "AS IS" AND ANY EXPRESS OR IMPLIED
21WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
22MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NON-INFRINGEMENT
23ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS
24BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
25CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
26SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
27BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
28WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE
29OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN
30IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
Laurence Lundbladeee851742020-01-08 08:37:05 -080031 =============================================================================*/
Laurence Lundblade624405d2018-09-18 20:10:47 -070032
Laurence Lundblade3aee3a32018-12-17 16:17:45 -080033
Laurence Lundblade844bb5c2020-03-01 17:27:25 -080034#include "qcbor/qcbor_encode.h"
Laurence Lundblade12d32c52018-09-19 11:25:27 -070035#include "ieee754.h"
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070036
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070037
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070038
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070039/*
Laurence Lundbladeee851742020-01-08 08:37:05 -080040 Nesting -- This tracks the nesting of maps and arrays.
41
42 The following functions and data type QCBORTrackNesting implement the
43 nesting management for encoding.
44
45 CBOR's two nesting types, arrays and maps, are tracked here. There is
46 a limit of QCBOR_MAX_ARRAY_NESTING to the number of arrays and maps
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070047 that can be nested in one encoding so the encoding context stays
48 small enough to fit on the stack.
Laurence Lundblade3aee3a32018-12-17 16:17:45 -080049
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070050 When an array / map is opened, pCurrentNesting points to the element
Laurence Lundbladeee851742020-01-08 08:37:05 -080051 in pArrays that records the type, start position and accumulates a
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070052 count of the number of items added. When closed the start position is
53 used to go back and fill in the type and number of items in the array
54 / map.
Laurence Lundblade3aee3a32018-12-17 16:17:45 -080055
Laurence Lundbladeee851742020-01-08 08:37:05 -080056 Encoded output can be just items like ints and strings that are not
57 part of any array / map. That is, the first thing encoded does not
58 have to be an array or a map.
59
60 QCBOR has a special feature to allow constructing bstr-wrapped CBOR
61 directly into the output buffer, so an extra buffer for it is not
62 needed. This is implemented as nesting with type
63 CBOR_MAJOR_TYPE_BYTE_STRING and uses this code. Bstr-wrapped CBOR is
64 used by COSE for data that is to be hashed.
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070065 */
66inline static void Nesting_Init(QCBORTrackNesting *pNesting)
67{
Laurence Lundbladeee851742020-01-08 08:37:05 -080068 // Assumes pNesting has been zeroed
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070069 pNesting->pCurrentNesting = &pNesting->pArrays[0];
70 // Implied CBOR array at the top nesting level. This is never returned,
71 // but makes the item count work correctly.
72 pNesting->pCurrentNesting->uMajorType = CBOR_MAJOR_TYPE_ARRAY;
73}
74
Laurence Lundblade29497c02020-07-11 15:44:03 -070075inline static uint8_t Nesting_Increase(QCBORTrackNesting *pNesting,
Laurence Lundblade2c40ab82018-12-30 14:20:29 -080076 uint8_t uMajorType,
77 uint32_t uPos)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070078{
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070079 if(pNesting->pCurrentNesting == &pNesting->pArrays[QCBOR_MAX_ARRAY_NESTING]) {
Laurence Lundbladeee851742020-01-08 08:37:05 -080080 // Trying to open one too many
Laurence Lundblade29497c02020-07-11 15:44:03 -070081 return QCBOR_ERR_ARRAY_NESTING_TOO_DEEP;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070082 } else {
83 pNesting->pCurrentNesting++;
84 pNesting->pCurrentNesting->uCount = 0;
85 pNesting->pCurrentNesting->uStart = uPos;
86 pNesting->pCurrentNesting->uMajorType = uMajorType;
Laurence Lundblade29497c02020-07-11 15:44:03 -070087 return QCBOR_SUCCESS;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070088 }
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070089}
90
91inline static void Nesting_Decrease(QCBORTrackNesting *pNesting)
92{
93 pNesting->pCurrentNesting--;
94}
95
Laurence Lundblade29497c02020-07-11 15:44:03 -070096inline static uint8_t Nesting_Increment(QCBORTrackNesting *pNesting)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -070097{
Laurence Lundbladedaefdec2020-11-02 20:22:03 -080098#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Laurence Lundblade1ef8b2d2018-12-14 23:13:34 -080099 if(1 >= QCBOR_MAX_ITEMS_IN_ARRAY - pNesting->pCurrentNesting->uCount) {
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700100 return QCBOR_ERR_ARRAY_TOO_LONG;
101 }
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800102#endif /* QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800103
Laurence Lundbladee6bcef12020-04-01 10:56:27 -0700104 pNesting->pCurrentNesting->uCount++;
Laurence Lundblade2c40ab82018-12-30 14:20:29 -0800105
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700106 return QCBOR_SUCCESS;
107}
108
109inline static uint16_t Nesting_GetCount(QCBORTrackNesting *pNesting)
110{
111 // The nesting count recorded is always the actual number of individiual
112 // data items in the array or map. For arrays CBOR uses the actual item
113 // count. For maps, CBOR uses the number of pairs. This function returns
114 // the number needed for the CBOR encoding, so it divides the number of
115 // items by two for maps to get the number of pairs. This implementation
116 // takes advantage of the map major type being one larger the array major
Laurence Lundblade2c40ab82018-12-30 14:20:29 -0800117 // type, hence uDivisor is either 1 or 2.
Laurence Lundblade2c40ab82018-12-30 14:20:29 -0800118
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800119 if(pNesting->pCurrentNesting->uMajorType == CBOR_MAJOR_TYPE_MAP) {
120 // Cast back to uint16_t after integer promotion for bit shift
121 return (uint16_t)(pNesting->pCurrentNesting->uCount >> 1);
122 } else {
123 return pNesting->pCurrentNesting->uCount;
124 }
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700125}
126
127inline static uint32_t Nesting_GetStartPos(QCBORTrackNesting *pNesting)
128{
129 return pNesting->pCurrentNesting->uStart;
130}
131
132inline static uint8_t Nesting_GetMajorType(QCBORTrackNesting *pNesting)
133{
134 return pNesting->pCurrentNesting->uMajorType;
135}
136
Laurence Lundbladeee851742020-01-08 08:37:05 -0800137inline static bool Nesting_IsInNest(QCBORTrackNesting *pNesting)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700138{
Laurence Lundbladeee851742020-01-08 08:37:05 -0800139 return pNesting->pCurrentNesting == &pNesting->pArrays[0] ? false : true;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700140}
141
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700142
143
144
145/*
Laurence Lundbladeee851742020-01-08 08:37:05 -0800146 Encoding of the major CBOR types is by these functions:
147
148 CBOR Major Type Public Function
149 0 QCBOREncode_AddUInt64()
150 0, 1 QCBOREncode_AddUInt64(), QCBOREncode_AddInt64()
151 2, 3 QCBOREncode_AddBuffer(), Also QCBOREncode_OpenMapOrArray(),
152 QCBOREncode_CloseMapOrArray()
153 4, 5 QCBOREncode_OpenMapOrArray(), QCBOREncode_CloseMapOrArray(),
154 QCBOREncode_OpenMapOrArrayIndefiniteLength(),
155 QCBOREncode_CloseMapOrArrayIndefiniteLength()
156 6 QCBOREncode_AddTag()
157 7 QCBOREncode_AddDouble(), QCBOREncode_AddType7()
158
159 Additionally, encoding of decimal fractions and bigfloats is by
160 QCBOREncode_AddExponentAndMantissa()
161*/
162
163/*
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700164 Error tracking plan -- Errors are tracked internally and not returned
Laurence Lundbladeee851742020-01-08 08:37:05 -0800165 until QCBOREncode_Finish is called. The CBOR errors are in me->uError.
Laurence Lundblade067035b2018-11-28 17:35:25 -0800166 UsefulOutBuf also tracks whether the buffer is full or not in its
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700167 context. Once either of these errors is set they are never
Laurence Lundblade241705e2018-12-30 18:56:14 -0800168 cleared. Only QCBOREncode_Init() resets them. Or said another way, they must
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700169 never be cleared or we'll tell the caller all is good when it is not.
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800170
Laurence Lundblade241705e2018-12-30 18:56:14 -0800171 Only one error code is reported by QCBOREncode_Finish() even if there are
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700172 multiple errors. The last one set wins. The caller might have to fix
173 one error to reveal the next one they have to fix. This is OK.
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800174
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700175 The buffer full error tracked by UsefulBuf is only pulled out of
176 UsefulBuf in Finish() so it is the one that usually wins. UsefulBuf
177 will never go off the end of the buffer even if it is called again
178 and again when full.
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800179
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700180 It is really tempting to not check for overflow on the count in the
181 number of items in an array. It would save a lot of code, it is
182 extremely unlikely that any one will every put 65,000 items in an
183 array, and the only bad thing that would happen is the CBOR would be
Laurence Lundblade241705e2018-12-30 18:56:14 -0800184 bogus.
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800185
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700186 Since this does not parse any input, you could in theory remove all
187 error checks in this code if you knew the caller called it
188 correctly. Maybe someday CDDL or some such language will be able to
189 generate the code to call this and the calling code would always be
Laurence Lundblade56230d12018-11-01 11:14:51 +0700190 correct. This could also automatically size some of the data
Laurence Lundblade241705e2018-12-30 18:56:14 -0800191 structures like array/map nesting resulting in some stack memory
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700192 savings.
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800193
Laurence Lundbladeee851742020-01-08 08:37:05 -0800194 The 8 errors returned here fall into three categories:
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800195
Laurence Lundblade067035b2018-11-28 17:35:25 -0800196 Sizes
Laurence Lundbladeee851742020-01-08 08:37:05 -0800197 QCBOR_ERR_BUFFER_TOO_LARGE -- Encoded output exceeded UINT32_MAX
198 QCBOR_ERR_BUFFER_TOO_SMALL -- Output buffer too small
199 QCBOR_ERR_ARRAY_NESTING_TOO_DEEP -- Nesting > QCBOR_MAX_ARRAY_NESTING1
200 QCBOR_ERR_ARRAY_TOO_LONG -- Too many things added to an array/map
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800201
Laurence Lundblade067035b2018-11-28 17:35:25 -0800202 Nesting constructed incorrectly
Laurence Lundbladeee851742020-01-08 08:37:05 -0800203 QCBOR_ERR_TOO_MANY_CLOSES -- More close calls than opens
204 QCBOR_ERR_CLOSE_MISMATCH -- Type of close does not match open
Laurence Lundblade067035b2018-11-28 17:35:25 -0800205 QCBOR_ERR_ARRAY_OR_MAP_STILL_OPEN -- Finish called without enough closes
Laurence Lundbladebb1062e2019-08-12 23:28:54 -0700206
207 Would generate not-well-formed CBOR
Laurence Lundbladea9489f82020-09-12 13:50:56 -0700208 QCBOR_ERR_ENCODE_UNSUPPORTED -- Simple type between 24 and 31
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700209 */
210
211
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700212/*
Laurence Lundblade844bb5c2020-03-01 17:27:25 -0800213 Public function for initialization. See qcbor/qcbor_encode.h
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700214 */
Laurence Lundblade2296db52018-09-14 18:08:39 -0700215void QCBOREncode_Init(QCBOREncodeContext *me, UsefulBuf Storage)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700216{
217 memset(me, 0, sizeof(QCBOREncodeContext));
Laurence Lundblade1ef8b2d2018-12-14 23:13:34 -0800218 UsefulOutBuf_Init(&(me->OutBuf), Storage);
219 Nesting_Init(&(me->nesting));
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700220}
221
222
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000223/*
Laurence Lundblade844bb5c2020-03-01 17:27:25 -0800224 Public function to encode a CBOR head. See qcbor/qcbor_encode.h
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700225 */
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000226UsefulBufC QCBOREncode_EncodeHead(UsefulBuf buffer,
227 uint8_t uMajorType,
228 uint8_t uMinLen,
229 uint64_t uArgument)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700230{
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000231 /**
232 All CBOR data items have a type and an "argument". The argument is
233 either the value of the item for integer types, the length of the
234 content for string, byte, array and map types, a tag for major type
235 6, and has several uses for major type 7.
236
237 This function encodes the type and the argument. There are several
238 encodings for the argument depending on how large it is and how it is
239 used.
240
241 Every encoding of the type and argument has at least one byte, the
242 "initial byte".
243
244 The top three bits of the initial byte are the major type for the
245 CBOR data item. The eight major types defined by the standard are
Laurence Lundblade844bb5c2020-03-01 17:27:25 -0800246 defined as CBOR_MAJOR_TYPE_xxxx in qcbor/qcbor_common.h.
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000247
248 The remaining five bits, known as "additional information", and
249 possibly more bytes encode the argument. If the argument is less than
250 24, then it is encoded entirely in the five bits. This is neat
251 because it allows you to encode an entire CBOR data item in 1 byte
252 for many values and types (integers 0-23, true, false, and tags).
253
254 If the argument is larger than 24, then it is encoded in 1,2,4 or 8
255 additional bytes, with the number of these bytes indicated by the
256 values of the 5 bits 24, 25, 25 and 27.
257
258 It is possible to encode a particular argument in many ways with this
259 representation. This implementation always uses the smallest
260 possible representation. This conforms with CBOR preferred encoding.
261
262 This function inserts them into the output buffer at the specified
263 position. AppendEncodedTypeAndNumber() appends to the end.
264
265 This function takes care of converting to network byte order.
266
267 This function is also used to insert floats and doubles. Before this
268 function is called the float or double must be copied into a
269 uint64_t. That is how they are passed in. They are then converted to
270 network byte order correctly. The uMinLen parameter makes sure that
271 even if all the digits of a half, float or double are 0 it is still
272 correctly encoded in 2, 4 or 8 bytes.
273 */
Laurence Lundbladee9b00322018-12-30 10:33:26 -0800274 /*
275 This code does endian conversion without hton or knowing the
Laurence Lundblade241705e2018-12-30 18:56:14 -0800276 endianness of the machine using masks and shifts. This avoids the
Laurence Lundbladee9b00322018-12-30 10:33:26 -0800277 dependency on hton and the mess of figuring out how to find the
278 machine's endianness.
Laurence Lundblade2c40ab82018-12-30 14:20:29 -0800279
Laurence Lundbladee9b00322018-12-30 10:33:26 -0800280 This is a good efficient implementation on little-endian machines.
281 A faster and small implementation is possible on big-endian
282 machines because CBOR/network byte order is big endian. However
283 big endian machines are uncommon.
Laurence Lundblade2c40ab82018-12-30 14:20:29 -0800284
Laurence Lundbladee9b00322018-12-30 10:33:26 -0800285 On x86, it is about 200 bytes instead of 500 bytes for the more
286 formal unoptimized code.
Laurence Lundblade2c40ab82018-12-30 14:20:29 -0800287
Laurence Lundbladee9b00322018-12-30 10:33:26 -0800288 This also does the CBOR preferred shortest encoding for integers
289 and is called to do endian conversion for floats.
Laurence Lundblade2c40ab82018-12-30 14:20:29 -0800290
Laurence Lundbladee9b00322018-12-30 10:33:26 -0800291 It works backwards from the LSB to the MSB as needed.
Laurence Lundblade2c40ab82018-12-30 14:20:29 -0800292
Laurence Lundbladee9b00322018-12-30 10:33:26 -0800293 Code Reviewers: THIS FUNCTION DOES POINTER MATH
294 */
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800295 /*
296 The type int is used here for several variables because of the way
297 integer promotion works in C for integer variables that are
298 uint8_t or uint16_t. The basic rule is that they will always be
299 promoted to int if they will fit. All of these integer variables
300 need only hold values less than 255 or are promoted from uint8_t,
301 so they will always fit into an int. Note that promotion is only
302 to unsigned int if the value won't fit into an int even if the
303 promotion is for an unsigned like uint8_t.
304
305 By declaring them int, there are few implicit conversions and fewer
306 casts needed. Code size is reduced a little. It also makes static
307 analyzers happier.
308
309 Note also that declaring them uint8_t won't stop integer wrap
310 around if the code is wrong. It won't make the code more correct.
311
312 https://stackoverflow.com/questions/46073295/implicit-type-promotion-rules
313 https://stackoverflow.com/questions/589575/what-does-the-c-standard-state-the-size-of-int-long-type-to-be
314 */
Laurence Lundbladeee851742020-01-08 08:37:05 -0800315
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000316 // Buffer must have room for the largest CBOR HEAD + one extra as the
317 // one extra is needed for this code to work as it does a pre-decrement.
318 if(buffer.len < QCBOR_HEAD_BUFFER_SIZE) {
319 return NULLUsefulBufC;
320 }
321
322 // Pointer to last valid byte in the buffer
323 uint8_t * const pBufferEnd = &((uint8_t *)buffer.ptr)[QCBOR_HEAD_BUFFER_SIZE-1];
324
325 // Point to the last byte and work backwards
326 uint8_t *pByte = pBufferEnd;
327 // The 5 bits in the initial byte that are not the major type
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800328 int nAdditionalInfo;
Laurence Lundblade2c40ab82018-12-30 14:20:29 -0800329
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800330 if(uMajorType > 10) {
331 uMajorType = uMajorType & 0x07;
332 nAdditionalInfo = 31;
333 } else
334/*
335#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDSX
Jan Jongboom5d827882019-08-07 12:51:15 +0200336 if (uMajorType == CBOR_MAJOR_NONE_TYPE_ARRAY_INDEFINITE_LEN) {
337 uMajorType = CBOR_MAJOR_TYPE_ARRAY;
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800338 nAdditionalInfo = LEN_IS_INDEFINITE;
Jan Jongboom5d827882019-08-07 12:51:15 +0200339 } else if (uMajorType == CBOR_MAJOR_NONE_TYPE_MAP_INDEFINITE_LEN) {
340 uMajorType = CBOR_MAJOR_TYPE_MAP;
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800341 nAdditionalInfo = LEN_IS_INDEFINITE;
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800342 } else
343#endif
344 */
345 if (uArgument < CBOR_TWENTY_FOUR && uMinLen == 0) {
Laurence Lundbladee9b00322018-12-30 10:33:26 -0800346 // Simple case where argument is < 24
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000347 nAdditionalInfo = (int)uArgument;
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800348#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000349 } else if (uMajorType == CBOR_MAJOR_TYPE_SIMPLE && uArgument == CBOR_SIMPLE_BREAK) {
Jan Jongboom4a93a662019-07-25 08:44:58 +0200350 // Break statement can be encoded in single byte too (0xff)
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800351 nAdditionalInfo = 31;
352#endif
Laurence Lundblade04a859b2018-12-11 12:13:02 -0800353 } else {
Laurence Lundbladee9b00322018-12-30 10:33:26 -0800354 /*
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000355 Encode argument in 1,2,4 or 8 bytes. Outer loop
356 runs once for 1 byte and 4 times for 8 bytes.
357 Inner loop runs 1, 2 or 4 times depending on
358 outer loop counter. This works backwards taking
359 8 bits off the argument being encoded at a time
360 until all bits from uNumber have been encoded
361 and the minimum encoding size is reached.
362 Minimum encoding size is for floating point
363 numbers with zero bytes.
Laurence Lundbladee9b00322018-12-30 10:33:26 -0800364 */
Laurence Lundblade04a859b2018-12-11 12:13:02 -0800365 static const uint8_t aIterate[] = {1,1,2,4};
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000366
367 // The parameter passed in is unsigned, but goes negative in the loop
368 // so it must be converted to a signed value.
369 int nMinLen = (int)uMinLen;
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800370 int i;
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000371 for(i = 0; uArgument || nMinLen > 0; i++) {
372 const int nIterations = (int)aIterate[i];
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800373 for(int j = 0; j < nIterations; j++) {
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000374 *--pByte = (uint8_t)(uArgument & 0xff);
375 uArgument = uArgument >> 8;
Laurence Lundblade04a859b2018-12-11 12:13:02 -0800376 }
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800377 nMinLen -= nIterations;
Laurence Lundblade04a859b2018-12-11 12:13:02 -0800378 }
Laurence Lundbladeee851742020-01-08 08:37:05 -0800379 // Additional info is the encoding of the number of additional
380 // bytes to encode argument.
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800381 nAdditionalInfo = LEN_IS_ONE_BYTE-1 + i;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700382 }
Laurence Lundbladef970f1d2018-12-14 01:44:23 -0800383
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800384 /*
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000385 This expression integer-promotes to type int. The code above in
386 function guarantees that nAdditionalInfo will never be larger than
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800387 0x1f. The caller may pass in a too-large uMajor type. The
388 conversion to unint8_t will cause an integer wrap around and
389 incorrect CBOR will be generated, but no security issue will
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000390 occur.
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800391 */
392 *--pByte = (uint8_t)((uMajorType << 5) + nAdditionalInfo);
393
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000394#ifdef EXTRA_ENCODE_HEAD_CHECK
395 /* This is a sanity check that can be turned on to verify the pointer
396 * math in this function is not going wrong. Turn it on and run the
397 * whole test suite to perform the check.
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800398 */
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000399 if(pBufferEnd - pByte > 9 || pBufferEnd - pByte < 1 || pByte < (uint8_t *)buffer.ptr) {
400 return NULLUsefulBufC;
401 }
402#endif
Laurence Lundbladec5fef682020-01-25 11:38:45 -0800403
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000404 // Length will not go negative because the loops run for at most 8 decrements
405 // of pByte, only one other decrement is made, and the array is sized
406 // for this.
407 return (UsefulBufC){pByte, (size_t)(pBufferEnd - pByte)};
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700408}
409
410
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000411/**
412 @brief Append the CBOR head, the major type and argument
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800413
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000414 @param me Encoder context.
415 @param uMajorType Major type to insert.
416 @param uArgument The argument (an integer value or a length).
417 @param uMinLen The minimum number of bytes for encoding the CBOR argument.
418
419 This formats the CBOR "head" and appends it to the output.
420 */
421static void AppendCBORHead(QCBOREncodeContext *me, uint8_t uMajorType, uint64_t uArgument, uint8_t uMinLen)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700422{
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000423 // A stack buffer large enough for a CBOR head
424 UsefulBuf_MAKE_STACK_UB (pBufferForEncodedHead, QCBOR_HEAD_BUFFER_SIZE);
425
426 UsefulBufC EncodedHead = QCBOREncode_EncodeHead(pBufferForEncodedHead,
427 uMajorType,
428 uMinLen,
429 uArgument);
430
431 /* No check for EncodedHead == NULLUsefulBufC is performed here to
432 * save object code. It is very clear that pBufferForEncodedHead
433 * is the correct size. If EncodedHead == NULLUsefulBufC then
434 * UsefulOutBuf_AppendUsefulBuf() will do nothing so there is
435 * no security hole introduced.
436 */
437
438 UsefulOutBuf_AppendUsefulBuf(&(me->OutBuf), EncodedHead);
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700439}
440
441
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000442/**
443 @brief Insert the CBOR head for a map, array or wrapped bstr
444
445 @param me QCBOR encoding context.
446 @param uMajorType One of CBOR_MAJOR_TYPE_XXXX.
447 @param uLen The length of the data item.
448
449 When an array, map or bstr was opened, nothing was done but note
450 the position. This function goes back to that position and inserts
451 the CBOR Head with the major type and length.
452 */
453static void InsertCBORHead(QCBOREncodeContext *me, uint8_t uMajorType, size_t uLen)
454{
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800455#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000456 if(me->uError == QCBOR_SUCCESS) {
457 if(!Nesting_IsInNest(&(me->nesting))) {
458 me->uError = QCBOR_ERR_TOO_MANY_CLOSES;
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800459 return;
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000460 } else if(Nesting_GetMajorType(&(me->nesting)) != uMajorType) {
461 me->uError = QCBOR_ERR_CLOSE_MISMATCH;
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800462 return;
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000463 }
464 }
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800465#endif /* QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
466 // A stack buffer large enough for a CBOR head
467 UsefulBuf_MAKE_STACK_UB (pBufferForEncodedHead,QCBOR_HEAD_BUFFER_SIZE);
468
469 UsefulBufC EncodedHead = QCBOREncode_EncodeHead(pBufferForEncodedHead,
470 uMajorType,
471 0,
472 uLen);
473
474 /* No check for EncodedHead == NULLUsefulBufC is performed here to
475 * save object code. It is very clear that pBufferForEncodedHead
476 * is the correct size. If EncodedHead == NULLUsefulBufC then
477 * UsefulOutBuf_InsertUsefulBuf() will do nothing so there is
478 * no security whole introduced.
479 */
480 UsefulOutBuf_InsertUsefulBuf(&(me->OutBuf),
481 EncodedHead,
482 Nesting_GetStartPos(&(me->nesting)));
483
484 Nesting_Decrease(&(me->nesting));
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000485}
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700486
Laurence Lundblade241705e2018-12-30 18:56:14 -0800487
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700488/*
Laurence Lundblade844bb5c2020-03-01 17:27:25 -0800489 Public functions for adding integers. See qcbor/qcbor_encode.h
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700490 */
Laurence Lundblade067035b2018-11-28 17:35:25 -0800491void QCBOREncode_AddUInt64(QCBOREncodeContext *me, uint64_t uValue)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700492{
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800493 AppendCBORHead(me, CBOR_MAJOR_TYPE_POSITIVE_INT, uValue, 0);
494
495#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Laurence Lundblade067035b2018-11-28 17:35:25 -0800496 if(me->uError == QCBOR_SUCCESS) {
Laurence Lundblade1ef8b2d2018-12-14 23:13:34 -0800497 me->uError = Nesting_Increment(&(me->nesting));
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700498 }
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800499#else
500 Nesting_Increment(&(me->nesting));
501#endif /* QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700502}
503
Laurence Lundblade56230d12018-11-01 11:14:51 +0700504
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700505/*
Laurence Lundblade844bb5c2020-03-01 17:27:25 -0800506 Public functions for adding unsigned. See qcbor/qcbor_encode.h
Laurence Lundblade067035b2018-11-28 17:35:25 -0800507 */
508void QCBOREncode_AddInt64(QCBOREncodeContext *me, int64_t nNum)
509{
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800510 uint8_t uMajorType;
511 uint64_t uValue;
512
513 if(nNum < 0) {
514 // In CBOR -1 encodes as 0x00 with major type negative int.
515 uValue = (uint64_t)(-nNum - 1);
516 uMajorType = CBOR_MAJOR_TYPE_NEGATIVE_INT;
517 } else {
518 uValue = (uint64_t)nNum;
519 uMajorType = CBOR_MAJOR_TYPE_POSITIVE_INT;
520 }
521 AppendCBORHead(me, uMajorType, uValue, 0);
522
523#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Laurence Lundblade067035b2018-11-28 17:35:25 -0800524 if(me->uError == QCBOR_SUCCESS) {
Laurence Lundblade1ef8b2d2018-12-14 23:13:34 -0800525 me->uError = Nesting_Increment(&(me->nesting));
Laurence Lundblade067035b2018-11-28 17:35:25 -0800526 }
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800527#else
528 Nesting_Increment(&(me->nesting));
529#endif /* QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
530
Laurence Lundblade067035b2018-11-28 17:35:25 -0800531}
532
533
534/*
Laurence Lundbladeda532272019-04-07 11:40:17 -0700535 Semi-private function. It is exposed to user of the interface, but
536 they will usually call one of the inline wrappers rather than this.
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800537
Laurence Lundblade844bb5c2020-03-01 17:27:25 -0800538 See qcbor/qcbor_encode.h
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800539
Laurence Lundbladeda532272019-04-07 11:40:17 -0700540 Does the work of adding actual strings bytes to the CBOR output (as
541 opposed to numbers and opening / closing aggregate types).
542
543 There are four use cases:
544 CBOR_MAJOR_TYPE_BYTE_STRING -- Byte strings
545 CBOR_MAJOR_TYPE_TEXT_STRING -- Text strings
546 CBOR_MAJOR_NONE_TYPE_RAW -- Already-encoded CBOR
547 CBOR_MAJOR_NONE_TYPE_BSTR_LEN_ONLY -- Special case
548
549 The first two add the type and length plus the actual bytes. The
550 third just adds the bytes as the type and length are presumed to be
551 in the bytes. The fourth just adds the type and length for the very
552 special case of QCBOREncode_AddBytesLenOnly().
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700553 */
Laurence Lundblade067035b2018-11-28 17:35:25 -0800554void QCBOREncode_AddBuffer(QCBOREncodeContext *me, uint8_t uMajorType, UsefulBufC Bytes)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700555{
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800556 // If it is not Raw CBOR, add the type and the length
557 if(uMajorType != CBOR_MAJOR_NONE_TYPE_RAW) {
558 uint8_t uRealMajorType = uMajorType;
559 if(uRealMajorType == CBOR_MAJOR_NONE_TYPE_BSTR_LEN_ONLY) {
560 uRealMajorType = CBOR_MAJOR_TYPE_BYTE_STRING;
561 }
562 AppendCBORHead(me, uRealMajorType, Bytes.len, 0);
563 }
564
565 if(uMajorType != CBOR_MAJOR_NONE_TYPE_BSTR_LEN_ONLY) {
566 // Actually add the bytes
567 UsefulOutBuf_AppendUsefulBuf(&(me->OutBuf), Bytes);
568 }
569
570 // Update the array counting if there is any nesting at all
571#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Laurence Lundblade241705e2018-12-30 18:56:14 -0800572 if(me->uError == QCBOR_SUCCESS) {
Laurence Lundblade1ef8b2d2018-12-14 23:13:34 -0800573 me->uError = Nesting_Increment(&(me->nesting));
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700574 }
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800575#else
576 Nesting_Increment(&(me->nesting));
577#endif /* QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700578}
579
Laurence Lundbladecafcfe12018-10-31 21:59:50 +0700580
Laurence Lundblade55a24832018-10-30 04:35:08 +0700581/*
Laurence Lundblade844bb5c2020-03-01 17:27:25 -0800582 Public functions for adding a tag. See qcbor/qcbor_encode.h
Laurence Lundblade55a24832018-10-30 04:35:08 +0700583 */
584void QCBOREncode_AddTag(QCBOREncodeContext *me, uint64_t uTag)
585{
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000586 AppendCBORHead(me, CBOR_MAJOR_TYPE_OPTIONAL, uTag, 0);
Laurence Lundblade55a24832018-10-30 04:35:08 +0700587}
588
589
Laurence Lundblade56230d12018-11-01 11:14:51 +0700590/*
Laurence Lundblade487930f2018-11-30 11:01:45 -0800591 Semi-private function. It is exposed to user of the interface,
592 but they will usually call one of the inline wrappers rather than this.
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800593
Laurence Lundblade844bb5c2020-03-01 17:27:25 -0800594 See header qcbor/qcbor_encode.h
Laurence Lundblade56230d12018-11-01 11:14:51 +0700595 */
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000596void QCBOREncode_AddType7(QCBOREncodeContext *me, uint8_t uMinLen, uint64_t uNum)
Laurence Lundblade55a24832018-10-30 04:35:08 +0700597{
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800598#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Laurence Lundblade487930f2018-11-30 11:01:45 -0800599 if(me->uError == QCBOR_SUCCESS) {
Laurence Lundbladebb1062e2019-08-12 23:28:54 -0700600 if(uNum >= CBOR_SIMPLEV_RESERVED_START && uNum <= CBOR_SIMPLEV_RESERVED_END) {
Laurence Lundbladea9489f82020-09-12 13:50:56 -0700601 me->uError = QCBOR_ERR_ENCODE_UNSUPPORTED;
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800602 return;
Laurence Lundbladebb1062e2019-08-12 23:28:54 -0700603 }
Laurence Lundblade487930f2018-11-30 11:01:45 -0800604 }
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800605#endif /* QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
606
607 // AppendHead() does endian swapping for the float / double
608 AppendCBORHead(me, CBOR_MAJOR_TYPE_SIMPLE, uNum, uMinLen);
609
610#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
611 if(me->uError == QCBOR_SUCCESS) {
612 me->uError = Nesting_Increment(&(me->nesting));
613 }
614#else
615 Nesting_Increment(&(me->nesting));
616#endif /* QCBOR_DISABLE_ENCODE_USAGE_GUARDS */
Laurence Lundblade55a24832018-10-30 04:35:08 +0700617}
618
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700619
Laurence Lundblade32f3e622020-07-13 20:35:11 -0700620/*
621 Public functions for adding a double. See qcbor/qcbor_encode.h
622*/
Laurence Lundbladeb275cdc2020-07-12 12:34:38 -0700623void QCBOREncode_AddDoubleNoPreferred(QCBOREncodeContext *me, double dNum)
624{
Laurence Lundblade2feb1e12020-07-15 03:50:45 -0700625 QCBOREncode_AddType7(me,
626 sizeof(uint64_t),
627 UsefulBufUtil_CopyDoubleToUint64(dNum));
Laurence Lundbladeb275cdc2020-07-12 12:34:38 -0700628}
629
Laurence Lundblade32f3e622020-07-13 20:35:11 -0700630
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700631/*
Laurence Lundblade844bb5c2020-03-01 17:27:25 -0800632 Public functions for adding a double. See qcbor/qcbor_encode.h
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700633 */
Laurence Lundblade067035b2018-11-28 17:35:25 -0800634void QCBOREncode_AddDouble(QCBOREncodeContext *me, double dNum)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700635{
Laurence Lundbladeb275cdc2020-07-12 12:34:38 -0700636#ifndef QCBOR_DISABLE_PREFERRED_FLOAT
Laurence Lundblade067035b2018-11-28 17:35:25 -0800637 const IEEE754_union uNum = IEEE754_DoubleToSmallest(dNum);
Laurence Lundblade2feb1e12020-07-15 03:50:45 -0700638
Laurence Lundblade487930f2018-11-30 11:01:45 -0800639 QCBOREncode_AddType7(me, uNum.uSize, uNum.uValue);
Laurence Lundblade9682a532020-06-06 18:33:04 -0700640#else
Laurence Lundbladeb275cdc2020-07-12 12:34:38 -0700641 QCBOREncode_AddDoubleNoPreferred(me, dNum);
Laurence Lundblade9682a532020-06-06 18:33:04 -0700642#endif
Laurence Lundbladeb275cdc2020-07-12 12:34:38 -0700643}
Laurence Lundblade9682a532020-06-06 18:33:04 -0700644
Laurence Lundbladeb275cdc2020-07-12 12:34:38 -0700645
Laurence Lundblade32f3e622020-07-13 20:35:11 -0700646/*
647 Public functions for adding a float. See qcbor/qcbor_encode.h
648*/
Laurence Lundbladeb275cdc2020-07-12 12:34:38 -0700649void QCBOREncode_AddFloatNoPreferred(QCBOREncodeContext *me, float fNum)
650{
Laurence Lundblade2feb1e12020-07-15 03:50:45 -0700651 QCBOREncode_AddType7(me,
652 sizeof(uint32_t),
653 UsefulBufUtil_CopyFloatToUint32(fNum));
Laurence Lundblade9682a532020-06-06 18:33:04 -0700654}
655
656
657/*
Laurence Lundblade32f3e622020-07-13 20:35:11 -0700658 Public functions for adding a float. See qcbor/qcbor_encode.h
Laurence Lundblade9682a532020-06-06 18:33:04 -0700659 */
660void QCBOREncode_AddFloat(QCBOREncodeContext *me, float fNum)
661{
Laurence Lundbladeb275cdc2020-07-12 12:34:38 -0700662#ifndef QCBOR_DISABLE_PREFERRED_FLOAT
Laurence Lundblade9682a532020-06-06 18:33:04 -0700663 const IEEE754_union uNum = IEEE754_FloatToSmallest(fNum);
Laurence Lundblade2feb1e12020-07-15 03:50:45 -0700664
Laurence Lundblade9682a532020-06-06 18:33:04 -0700665 QCBOREncode_AddType7(me, uNum.uSize, uNum.uValue);
666#else
Laurence Lundbladeb275cdc2020-07-12 12:34:38 -0700667 QCBOREncode_AddFloatNoPreferred(me, fNum);
Laurence Lundblade9682a532020-06-06 18:33:04 -0700668#endif
Laurence Lundblade067035b2018-11-28 17:35:25 -0800669}
670
671
Laurence Lundblade59289e52019-12-30 13:44:37 -0800672#ifndef QCBOR_CONFIG_DISABLE_EXP_AND_MANTISSA
673/*
674 Semi-public function. It is exposed to the user of the interface, but
675 one of the inline wrappers will usually be called rather than this.
676
Laurence Lundblade844bb5c2020-03-01 17:27:25 -0800677 See qcbor/qcbor_encode.h
Laurence Lundblade45d5e482020-09-15 21:15:15 -0700678
679 Improvement: create another version of this that only
680 takes a big number mantissa and converts the output to
681 a type 0 or 1 integer when mantissa is small enough.
Laurence Lundblade59289e52019-12-30 13:44:37 -0800682 */
683void QCBOREncode_AddExponentAndMantissa(QCBOREncodeContext *pMe,
684 uint64_t uTag,
685 UsefulBufC BigNumMantissa,
686 bool bBigNumIsNegative,
687 int64_t nMantissa,
688 int64_t nExponent)
689{
Laurence Lundbladeee851742020-01-08 08:37:05 -0800690 /*
691 This is for encoding either a big float or a decimal fraction,
692 both of which are an array of two items, an exponent and a
693 mantissa. The difference between the two is that the exponent is
694 base-2 for big floats and base-10 for decimal fractions, but that
695 has no effect on the code here.
696 */
Laurence Lundbladeae66d3f2020-09-14 18:12:08 -0700697 if(uTag != CBOR_TAG_INVALID64) {
698 QCBOREncode_AddTag(pMe, uTag);
699 }
Laurence Lundblade59289e52019-12-30 13:44:37 -0800700 QCBOREncode_OpenArray(pMe);
701 QCBOREncode_AddInt64(pMe, nExponent);
702 if(!UsefulBuf_IsNULLC(BigNumMantissa)) {
703 if(bBigNumIsNegative) {
704 QCBOREncode_AddNegativeBignum(pMe, BigNumMantissa);
705 } else {
706 QCBOREncode_AddPositiveBignum(pMe, BigNumMantissa);
707 }
708 } else {
709 QCBOREncode_AddInt64(pMe, nMantissa);
710 }
711 QCBOREncode_CloseArray(pMe);
712}
713#endif /* QCBOR_CONFIG_DISABLE_EXP_AND_MANTISSA */
714
715
Laurence Lundblade067035b2018-11-28 17:35:25 -0800716/*
717 Semi-public function. It is exposed to user of the interface,
718 but they will usually call one of the inline wrappers rather than this.
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800719
Laurence Lundblade844bb5c2020-03-01 17:27:25 -0800720 See qcbor/qcbor_encode.h
Laurence Lundblade067035b2018-11-28 17:35:25 -0800721*/
722void QCBOREncode_OpenMapOrArray(QCBOREncodeContext *me, uint8_t uMajorType)
723{
Laurence Lundblade1ef8b2d2018-12-14 23:13:34 -0800724 // Add one item to the nesting level we are in for the new map or array
725 me->uError = Nesting_Increment(&(me->nesting));
Laurence Lundblade241705e2018-12-30 18:56:14 -0800726 if(me->uError == QCBOR_SUCCESS) {
Laurence Lundbladeee851742020-01-08 08:37:05 -0800727 /*
728 The offset where the length of an array or map will get written
729 is stored in a uint32_t, not a size_t to keep stack usage
730 smaller. This checks to be sure there is no wrap around when
731 recording the offset. Note that on 64-bit machines CBOR larger
732 than 4GB can be encoded as long as no array / map offsets occur
733 past the 4GB mark, but the public interface says that the
734 maximum is 4GB to keep the discussion simpler.
735 */
Laurence Lundblade1ef8b2d2018-12-14 23:13:34 -0800736 size_t uEndPosition = UsefulOutBuf_GetEndPosition(&(me->OutBuf));
Laurence Lundbladed39cd392019-01-11 18:17:38 -0800737
Laurence Lundbladeee851742020-01-08 08:37:05 -0800738 /*
739 QCBOR_MAX_ARRAY_OFFSET is slightly less than UINT32_MAX so this
740 code can run on a 32-bit machine and tests can pass on a 32-bit
741 machine. If it was exactly UINT32_MAX, then this code would not
742 compile or run on a 32-bit machine and an #ifdef or some
743 machine size detection would be needed reducing portability.
744 */
Laurence Lundbladed39cd392019-01-11 18:17:38 -0800745 if(uEndPosition >= QCBOR_MAX_ARRAY_OFFSET) {
Laurence Lundblade1ef8b2d2018-12-14 23:13:34 -0800746 me->uError = QCBOR_ERR_BUFFER_TOO_LARGE;
Laurence Lundbladed39cd392019-01-11 18:17:38 -0800747
Laurence Lundblade1ef8b2d2018-12-14 23:13:34 -0800748 } else {
Laurence Lundbladeee851742020-01-08 08:37:05 -0800749 // Increase nesting level because this is a map or array. Cast
750 // from size_t to uin32_t is safe because of check above
Laurence Lundblade1ef8b2d2018-12-14 23:13:34 -0800751 me->uError = Nesting_Increase(&(me->nesting), uMajorType, (uint32_t)uEndPosition);
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700752 }
Laurence Lundblade1ef8b2d2018-12-14 23:13:34 -0800753 }
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700754}
755
Laurence Lundblade59289e52019-12-30 13:44:37 -0800756
Jan Jongboom4a93a662019-07-25 08:44:58 +0200757/*
758 Semi-public function. It is exposed to user of the interface,
759 but they will usually call one of the inline wrappers rather than this.
760
Laurence Lundblade844bb5c2020-03-01 17:27:25 -0800761 See qcbor/qcbor_encode.h
Jan Jongboom4a93a662019-07-25 08:44:58 +0200762*/
763void QCBOREncode_OpenMapOrArrayIndefiniteLength(QCBOREncodeContext *me, uint8_t uMajorType)
764{
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000765 // Insert the indefinite length marker (0x9f for arrays, 0xbf for maps)
766 AppendCBORHead(me, uMajorType, 0, 0);
767 // Call the definite-length opener just to do the bookkeeping for
768 // nesting. It will record the position of the opening item in
769 // the encoded output but this is not used when closing this open.
Jan Jongboom4a93a662019-07-25 08:44:58 +0200770 QCBOREncode_OpenMapOrArray(me, uMajorType);
771}
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700772
Laurence Lundbladeee851742020-01-08 08:37:05 -0800773
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700774/*
Laurence Lundblade844bb5c2020-03-01 17:27:25 -0800775 Public functions for closing arrays and maps. See qcbor/qcbor_encode.h
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700776 */
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000777void QCBOREncode_CloseMapOrArray(QCBOREncodeContext *me, uint8_t uMajorType)
Laurence Lundbladea954db92018-09-28 19:27:31 -0700778{
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000779 InsertCBORHead(me, uMajorType, Nesting_GetCount(&(me->nesting)));
780}
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800781
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800782
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000783/*
Laurence Lundblade844bb5c2020-03-01 17:27:25 -0800784 Public functions for closing bstr wrapping. See qcbor/qcbor_encode.h
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000785 */
786void QCBOREncode_CloseBstrWrap2(QCBOREncodeContext *me, bool bIncludeCBORHead, UsefulBufC *pWrappedCBOR)
787{
788 const size_t uInsertPosition = Nesting_GetStartPos(&(me->nesting));
789 const size_t uEndPosition = UsefulOutBuf_GetEndPosition(&(me->OutBuf));
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800790
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000791 // This can't go negative because the UsefulOutBuf always only grows
792 // and never shrinks. UsefulOutBut itself also has defenses such that
793 // it won't write where it should not even if given hostile input lengths.
794 const size_t uBstrLen = uEndPosition - uInsertPosition;
795
796 // Actually insert
797 InsertCBORHead(me, CBOR_MAJOR_TYPE_BYTE_STRING, uBstrLen);
798
799 if(pWrappedCBOR) {
800 /*
801 Return pointer and length to the enclosed encoded CBOR. The
802 intended use is for it to be hashed (e.g., SHA-256) in a COSE
803 implementation. This must be used right away, as the pointer
804 and length go invalid on any subsequent calls to this function
805 because there might be calls to InsertEncodedTypeAndNumber()
806 that slides data to the right.
807 */
808 size_t uStartOfNew = uInsertPosition;
809 if(!bIncludeCBORHead) {
810 // Skip over the CBOR head to just get the inserted bstr
811 const size_t uNewEndPosition = UsefulOutBuf_GetEndPosition(&(me->OutBuf));
812 uStartOfNew += uNewEndPosition - uEndPosition;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700813 }
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000814 const UsefulBufC PartialResult = UsefulOutBuf_OutUBuf(&(me->OutBuf));
815 *pWrappedCBOR = UsefulBuf_Tail(PartialResult, uStartOfNew);
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700816 }
817}
818
Laurence Lundbladeee851742020-01-08 08:37:05 -0800819
Jan Jongboom4a93a662019-07-25 08:44:58 +0200820/*
Laurence Lundblade844bb5c2020-03-01 17:27:25 -0800821 Public functions for closing arrays and maps. See qcbor/qcbor_encode.h
Jan Jongboom4a93a662019-07-25 08:44:58 +0200822 */
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000823void QCBOREncode_CloseMapOrArrayIndefiniteLength(QCBOREncodeContext *me, uint8_t uMajorType)
Jan Jongboom4a93a662019-07-25 08:44:58 +0200824{
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800825#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Jan Jongboom4a93a662019-07-25 08:44:58 +0200826 if(me->uError == QCBOR_SUCCESS) {
827 if(!Nesting_IsInNest(&(me->nesting))) {
828 me->uError = QCBOR_ERR_TOO_MANY_CLOSES;
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800829 return;
Jan Jongboom4a93a662019-07-25 08:44:58 +0200830 } else if(Nesting_GetMajorType(&(me->nesting)) != uMajorType) {
831 me->uError = QCBOR_ERR_CLOSE_MISMATCH;
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800832 return;
Jan Jongboom4a93a662019-07-25 08:44:58 +0200833 }
834 }
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800835#else
836 (void) uMajorType;
837#endif
838
839 // Append the break marker (0xff for both arrays and maps)
840 AppendCBORHead(me, CBOR_MAJOR_TYPE_SIMPLE, CBOR_SIMPLE_BREAK, 0);
841 Nesting_Decrease(&(me->nesting));
Jan Jongboom4a93a662019-07-25 08:44:58 +0200842}
843
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700844
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700845/*
Laurence Lundblade844bb5c2020-03-01 17:27:25 -0800846 Public functions to finish and get the encoded result. See qcbor/qcbor_encode.h
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700847 */
Laurence Lundblade30816f22018-11-10 13:40:22 +0700848QCBORError QCBOREncode_Finish(QCBOREncodeContext *me, UsefulBufC *pEncodedCBOR)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700849{
Laurence Lundbladef607a2a2019-07-05 21:25:25 -0700850 QCBORError uReturn = QCBOREncode_GetErrorState(me);
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800851
Laurence Lundblade067035b2018-11-28 17:35:25 -0800852 if(uReturn != QCBOR_SUCCESS) {
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700853 goto Done;
Laurence Lundblade067035b2018-11-28 17:35:25 -0800854 }
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800855
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800856#ifndef QCBOR_DISABLE_ENCODE_USAGE_GUARDS
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700857 if (Nesting_IsInNest(&(me->nesting))) {
Laurence Lundblade067035b2018-11-28 17:35:25 -0800858 uReturn = QCBOR_ERR_ARRAY_OR_MAP_STILL_OPEN;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700859 goto Done;
860 }
Laurence Lundbladedaefdec2020-11-02 20:22:03 -0800861#endif
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800862
Laurence Lundbladeda3f0822018-09-18 19:49:02 -0700863 *pEncodedCBOR = UsefulOutBuf_OutUBuf(&(me->OutBuf));
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800864
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700865Done:
Laurence Lundblade067035b2018-11-28 17:35:25 -0800866 return uReturn;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700867}
868
Laurence Lundblade0595e932018-11-02 22:22:47 +0700869
Laurence Lundblade067035b2018-11-28 17:35:25 -0800870/*
Laurence Lundblade844bb5c2020-03-01 17:27:25 -0800871 Public functions to finish and get the encoded result. See qcbor/qcbor_encode.h
Laurence Lundblade067035b2018-11-28 17:35:25 -0800872 */
Laurence Lundblade30816f22018-11-10 13:40:22 +0700873QCBORError QCBOREncode_FinishGetSize(QCBOREncodeContext *me, size_t *puEncodedLen)
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700874{
Laurence Lundbladeda3f0822018-09-18 19:49:02 -0700875 UsefulBufC Enc;
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800876
Laurence Lundblade30816f22018-11-10 13:40:22 +0700877 QCBORError nReturn = QCBOREncode_Finish(me, &Enc);
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800878
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700879 if(nReturn == QCBOR_SUCCESS) {
Laurence Lundbladeda3f0822018-09-18 19:49:02 -0700880 *puEncodedLen = Enc.len;
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700881 }
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800882
Laurence Lundbladeb69cad72018-09-13 11:09:01 -0700883 return nReturn;
884}
885
886
Laurence Lundblade067035b2018-11-28 17:35:25 -0800887
888
889/*
Laurence Lundbladec9f0fbc2020-02-07 10:48:33 +0000890Object code sizes on 64-bit x86 with GCC -Os Jan 2020. GCC compiles smaller
891than LLVM and optimizations have been made to decrease code size. Bigfloat,
892Decimal fractions and indefinite length encoding were added to increase code
893size. Bstr wrapping is now separate which means if you don't use it, it gets
894dead stripped.
895
896_QCBOREncode_EncodeHead 187
897_QCBOREncode_CloseBstrWrap2: 154
898_QCBOREncode_AddExponentAndMantissa: 144
899_QCBOREncode_AddBuffer 105
900_QCBOREncode_OpenMapOrArray 101
901_QCBOREncode_CloseMapOrArrayIndefiniteLength: 72
902_QCBOREncode_Finish 71
903_InsertCBORHead.part.0 66
904_QCBOREncode_CloseMapOrArray 64
905_QCBOREncode_AddType7 58
906_QCBOREncode_AddInt64 57
907_AppendCBORHead 54
908_QCBOREncode_AddUInt64 40
909_QCBOREncode_Init 38
910_Nesting_Increment.isra.0 36
911_QCBOREncode_FinishGetSize: 34
912_QCBOREncode_AddDouble: 26
913_QCBOREncode_AddTag: 15
914Total 1322
915Min_encode use case 776
916
917
Laurence Lundblade241705e2018-12-30 18:56:14 -0800918 Object code sizes on X86 with LLVM compiler and -Os (Dec 30, 2018)
Laurence Lundblade2c40ab82018-12-30 14:20:29 -0800919
Laurence Lundblade9c097392018-12-30 13:52:24 -0800920 _QCBOREncode_Init 69
Laurence Lundblade067035b2018-11-28 17:35:25 -0800921 _QCBOREncode_AddUInt64 76
922 _QCBOREncode_AddInt64 87
Laurence Lundblade1ef8b2d2018-12-14 23:13:34 -0800923 _QCBOREncode_AddBuffer 113
Laurence Lundbladef970f1d2018-12-14 01:44:23 -0800924 _QCBOREncode_AddTag 27
Laurence Lundblade9c097392018-12-30 13:52:24 -0800925 _QCBOREncode_AddType7 87
Laurence Lundbladef970f1d2018-12-14 01:44:23 -0800926 _QCBOREncode_AddDouble 36
Laurence Lundblade1ef8b2d2018-12-14 23:13:34 -0800927 _QCBOREncode_OpenMapOrArray 103
Laurence Lundblade067035b2018-11-28 17:35:25 -0800928 _QCBOREncode_CloseMapOrArray 181
Laurence Lundbladef970f1d2018-12-14 01:44:23 -0800929 _InsertEncodedTypeAndNumber 190
Laurence Lundblade067035b2018-11-28 17:35:25 -0800930 _QCBOREncode_Finish 72
Laurence Lundbladef970f1d2018-12-14 01:44:23 -0800931 _QCBOREncode_FinishGetSize 70
Laurence Lundblade2c40ab82018-12-30 14:20:29 -0800932
Laurence Lundbladef970f1d2018-12-14 01:44:23 -0800933 Total is about 1.1KB
Laurence Lundblade2c40ab82018-12-30 14:20:29 -0800934
Laurence Lundblade067035b2018-11-28 17:35:25 -0800935 _QCBOREncode_CloseMapOrArray is larger because it has a lot
936 of nesting tracking to do and much of Nesting_ inlines
937 into it. It probably can't be reduced much.
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800938
Laurence Lundblade067035b2018-11-28 17:35:25 -0800939 If the error returned by Nesting_Increment() can be ignored
940 because the limit is so high and the consequence of exceeding
941 is proved to be inconsequential, then a lot of if(me->uError)
942 instance can be removed, saving some code.
Laurence Lundblade3aee3a32018-12-17 16:17:45 -0800943
Laurence Lundblade067035b2018-11-28 17:35:25 -0800944 */