xref: /freebsd/contrib/mandoc/compat_recallocarray.c (revision 6d38604fc532a3fc060788e3ce40464b46047eaf)
1*6d38604fSBaptiste Daroussin /*	$Id: compat_recallocarray.c,v 1.2 2020/06/15 01:37:15 schwarze Exp $ */
2*6d38604fSBaptiste Daroussin /*	$OpenBSD: recallocarray.c,v 1.1 2017/03/06 18:44:21 otto Exp $	*/
361d06d6bSBaptiste Daroussin /*
4*6d38604fSBaptiste Daroussin  * Copyright (c) 2008, 2017 Otto Moerbeek <otto@drijf.net>
561d06d6bSBaptiste Daroussin  *
661d06d6bSBaptiste Daroussin  * Permission to use, copy, modify, and distribute this software for any
761d06d6bSBaptiste Daroussin  * purpose with or without fee is hereby granted, provided that the above
861d06d6bSBaptiste Daroussin  * copyright notice and this permission notice appear in all copies.
961d06d6bSBaptiste Daroussin  *
1061d06d6bSBaptiste Daroussin  * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
1161d06d6bSBaptiste Daroussin  * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
1261d06d6bSBaptiste Daroussin  * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
1361d06d6bSBaptiste Daroussin  * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
1461d06d6bSBaptiste Daroussin  * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
1561d06d6bSBaptiste Daroussin  * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
1661d06d6bSBaptiste Daroussin  * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
1761d06d6bSBaptiste Daroussin  */
18*6d38604fSBaptiste Daroussin #include "config.h"
1961d06d6bSBaptiste Daroussin 
2061d06d6bSBaptiste Daroussin #include <sys/types.h>
2161d06d6bSBaptiste Daroussin #include <errno.h>
2261d06d6bSBaptiste Daroussin #include <stdlib.h>
23*6d38604fSBaptiste Daroussin #include <stdint.h>
2461d06d6bSBaptiste Daroussin #include <string.h>
2561d06d6bSBaptiste Daroussin 
2661d06d6bSBaptiste Daroussin /*
2761d06d6bSBaptiste Daroussin  * This is sqrt(SIZE_MAX+1), as s1*s2 <= SIZE_MAX
2861d06d6bSBaptiste Daroussin  * if both s1 < MUL_NO_OVERFLOW and s2 < MUL_NO_OVERFLOW
2961d06d6bSBaptiste Daroussin  */
3061d06d6bSBaptiste Daroussin #define MUL_NO_OVERFLOW ((size_t)1 << (sizeof(size_t) * 4))
3161d06d6bSBaptiste Daroussin 
3261d06d6bSBaptiste Daroussin /*
3361d06d6bSBaptiste Daroussin  * Even though specified in POSIX, the PAGESIZE and PAGE_SIZE
3461d06d6bSBaptiste Daroussin  * macros have very poor portability.  Since we only use this
3561d06d6bSBaptiste Daroussin  * to avoid free() overhead for small shrinking, simply pick
3661d06d6bSBaptiste Daroussin  * an arbitrary number.
3761d06d6bSBaptiste Daroussin  */
38*6d38604fSBaptiste Daroussin #define getpagesize()	(1UL << 12)
3961d06d6bSBaptiste Daroussin 
4061d06d6bSBaptiste Daroussin 
4161d06d6bSBaptiste Daroussin void *
recallocarray(void * ptr,size_t oldnmemb,size_t newnmemb,size_t size)4261d06d6bSBaptiste Daroussin recallocarray(void *ptr, size_t oldnmemb, size_t newnmemb, size_t size)
4361d06d6bSBaptiste Daroussin {
4461d06d6bSBaptiste Daroussin 	size_t oldsize, newsize;
4561d06d6bSBaptiste Daroussin 	void *newptr;
4661d06d6bSBaptiste Daroussin 
4761d06d6bSBaptiste Daroussin 	if (ptr == NULL)
4861d06d6bSBaptiste Daroussin 		return calloc(newnmemb, size);
4961d06d6bSBaptiste Daroussin 
5061d06d6bSBaptiste Daroussin 	if ((newnmemb >= MUL_NO_OVERFLOW || size >= MUL_NO_OVERFLOW) &&
5161d06d6bSBaptiste Daroussin 	    newnmemb > 0 && SIZE_MAX / newnmemb < size) {
5261d06d6bSBaptiste Daroussin 		errno = ENOMEM;
5361d06d6bSBaptiste Daroussin 		return NULL;
5461d06d6bSBaptiste Daroussin 	}
5561d06d6bSBaptiste Daroussin 	newsize = newnmemb * size;
5661d06d6bSBaptiste Daroussin 
5761d06d6bSBaptiste Daroussin 	if ((oldnmemb >= MUL_NO_OVERFLOW || size >= MUL_NO_OVERFLOW) &&
5861d06d6bSBaptiste Daroussin 	    oldnmemb > 0 && SIZE_MAX / oldnmemb < size) {
5961d06d6bSBaptiste Daroussin 		errno = EINVAL;
6061d06d6bSBaptiste Daroussin 		return NULL;
6161d06d6bSBaptiste Daroussin 	}
6261d06d6bSBaptiste Daroussin 	oldsize = oldnmemb * size;
6361d06d6bSBaptiste Daroussin 
6461d06d6bSBaptiste Daroussin 	/*
6561d06d6bSBaptiste Daroussin 	 * Don't bother too much if we're shrinking just a bit,
6661d06d6bSBaptiste Daroussin 	 * we do not shrink for series of small steps, oh well.
6761d06d6bSBaptiste Daroussin 	 */
6861d06d6bSBaptiste Daroussin 	if (newsize <= oldsize) {
6961d06d6bSBaptiste Daroussin 		size_t d = oldsize - newsize;
7061d06d6bSBaptiste Daroussin 
71*6d38604fSBaptiste Daroussin 		if (d < oldsize / 2 && d < getpagesize()) {
7261d06d6bSBaptiste Daroussin 			memset((char *)ptr + newsize, 0, d);
7361d06d6bSBaptiste Daroussin 			return ptr;
7461d06d6bSBaptiste Daroussin 		}
7561d06d6bSBaptiste Daroussin 	}
7661d06d6bSBaptiste Daroussin 
7761d06d6bSBaptiste Daroussin 	newptr = malloc(newsize);
7861d06d6bSBaptiste Daroussin 	if (newptr == NULL)
7961d06d6bSBaptiste Daroussin 		return NULL;
8061d06d6bSBaptiste Daroussin 
8161d06d6bSBaptiste Daroussin 	if (newsize > oldsize) {
8261d06d6bSBaptiste Daroussin 		memcpy(newptr, ptr, oldsize);
8361d06d6bSBaptiste Daroussin 		memset((char *)newptr + oldsize, 0, newsize - oldsize);
8461d06d6bSBaptiste Daroussin 	} else
8561d06d6bSBaptiste Daroussin 		memcpy(newptr, ptr, newsize);
8661d06d6bSBaptiste Daroussin 
8761d06d6bSBaptiste Daroussin 	/*
8861d06d6bSBaptiste Daroussin 	 * At this point, the OpenBSD implementation calls
8961d06d6bSBaptiste Daroussin 	 * explicit_bzero() on the old memory before it is
9061d06d6bSBaptiste Daroussin 	 * freed.  Since explicit_bzero() is hard to implement
9161d06d6bSBaptiste Daroussin 	 * portably and we don't handle confidential data in
9261d06d6bSBaptiste Daroussin 	 * mandoc in the first place, simply free the memory
9361d06d6bSBaptiste Daroussin 	 * without clearing it.
9461d06d6bSBaptiste Daroussin 	 */
9561d06d6bSBaptiste Daroussin 
9661d06d6bSBaptiste Daroussin 	free(ptr);
9761d06d6bSBaptiste Daroussin 
9861d06d6bSBaptiste Daroussin 	return newptr;
9961d06d6bSBaptiste Daroussin }
100