xref: /freebsd/crypto/openssh/openbsd-compat/recallocarray.c (revision 4f52dfbb8d6c4d446500c5b097e3806ec219fbd4)
1*4f52dfbbSDag-Erling Smørgrav /*	$OpenBSD: recallocarray.c,v 1.1 2017/03/06 18:44:21 otto Exp $	*/
2*4f52dfbbSDag-Erling Smørgrav /*
3*4f52dfbbSDag-Erling Smørgrav  * Copyright (c) 2008, 2017 Otto Moerbeek <otto@drijf.net>
4*4f52dfbbSDag-Erling Smørgrav  *
5*4f52dfbbSDag-Erling Smørgrav  * Permission to use, copy, modify, and distribute this software for any
6*4f52dfbbSDag-Erling Smørgrav  * purpose with or without fee is hereby granted, provided that the above
7*4f52dfbbSDag-Erling Smørgrav  * copyright notice and this permission notice appear in all copies.
8*4f52dfbbSDag-Erling Smørgrav  *
9*4f52dfbbSDag-Erling Smørgrav  * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
10*4f52dfbbSDag-Erling Smørgrav  * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
11*4f52dfbbSDag-Erling Smørgrav  * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
12*4f52dfbbSDag-Erling Smørgrav  * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
13*4f52dfbbSDag-Erling Smørgrav  * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
14*4f52dfbbSDag-Erling Smørgrav  * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
15*4f52dfbbSDag-Erling Smørgrav  * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
16*4f52dfbbSDag-Erling Smørgrav  */
17*4f52dfbbSDag-Erling Smørgrav 
18*4f52dfbbSDag-Erling Smørgrav /* OPENBSD ORIGINAL: lib/libc/stdlib/recallocarray.c */
19*4f52dfbbSDag-Erling Smørgrav 
20*4f52dfbbSDag-Erling Smørgrav #include "includes.h"
21*4f52dfbbSDag-Erling Smørgrav #ifndef HAVE_RECALLOCARRAY
22*4f52dfbbSDag-Erling Smørgrav 
23*4f52dfbbSDag-Erling Smørgrav #include <errno.h>
24*4f52dfbbSDag-Erling Smørgrav #include <stdlib.h>
25*4f52dfbbSDag-Erling Smørgrav #ifdef HAVE_STDINT_H
26*4f52dfbbSDag-Erling Smørgrav #include <stdint.h>
27*4f52dfbbSDag-Erling Smørgrav #endif
28*4f52dfbbSDag-Erling Smørgrav #include <string.h>
29*4f52dfbbSDag-Erling Smørgrav #include <unistd.h>
30*4f52dfbbSDag-Erling Smørgrav 
31*4f52dfbbSDag-Erling Smørgrav /*
32*4f52dfbbSDag-Erling Smørgrav  * This is sqrt(SIZE_MAX+1), as s1*s2 <= SIZE_MAX
33*4f52dfbbSDag-Erling Smørgrav  * if both s1 < MUL_NO_OVERFLOW and s2 < MUL_NO_OVERFLOW
34*4f52dfbbSDag-Erling Smørgrav  */
35*4f52dfbbSDag-Erling Smørgrav #define MUL_NO_OVERFLOW ((size_t)1 << (sizeof(size_t) * 4))
36*4f52dfbbSDag-Erling Smørgrav 
37*4f52dfbbSDag-Erling Smørgrav void *
recallocarray(void * ptr,size_t oldnmemb,size_t newnmemb,size_t size)38*4f52dfbbSDag-Erling Smørgrav recallocarray(void *ptr, size_t oldnmemb, size_t newnmemb, size_t size)
39*4f52dfbbSDag-Erling Smørgrav {
40*4f52dfbbSDag-Erling Smørgrav 	size_t oldsize, newsize;
41*4f52dfbbSDag-Erling Smørgrav 	void *newptr;
42*4f52dfbbSDag-Erling Smørgrav 
43*4f52dfbbSDag-Erling Smørgrav 	if (ptr == NULL)
44*4f52dfbbSDag-Erling Smørgrav 		return calloc(newnmemb, size);
45*4f52dfbbSDag-Erling Smørgrav 
46*4f52dfbbSDag-Erling Smørgrav 	if ((newnmemb >= MUL_NO_OVERFLOW || size >= MUL_NO_OVERFLOW) &&
47*4f52dfbbSDag-Erling Smørgrav 	    newnmemb > 0 && SIZE_MAX / newnmemb < size) {
48*4f52dfbbSDag-Erling Smørgrav 		errno = ENOMEM;
49*4f52dfbbSDag-Erling Smørgrav 		return NULL;
50*4f52dfbbSDag-Erling Smørgrav 	}
51*4f52dfbbSDag-Erling Smørgrav 	newsize = newnmemb * size;
52*4f52dfbbSDag-Erling Smørgrav 
53*4f52dfbbSDag-Erling Smørgrav 	if ((oldnmemb >= MUL_NO_OVERFLOW || size >= MUL_NO_OVERFLOW) &&
54*4f52dfbbSDag-Erling Smørgrav 	    oldnmemb > 0 && SIZE_MAX / oldnmemb < size) {
55*4f52dfbbSDag-Erling Smørgrav 		errno = EINVAL;
56*4f52dfbbSDag-Erling Smørgrav 		return NULL;
57*4f52dfbbSDag-Erling Smørgrav 	}
58*4f52dfbbSDag-Erling Smørgrav 	oldsize = oldnmemb * size;
59*4f52dfbbSDag-Erling Smørgrav 
60*4f52dfbbSDag-Erling Smørgrav 	/*
61*4f52dfbbSDag-Erling Smørgrav 	 * Don't bother too much if we're shrinking just a bit,
62*4f52dfbbSDag-Erling Smørgrav 	 * we do not shrink for series of small steps, oh well.
63*4f52dfbbSDag-Erling Smørgrav 	 */
64*4f52dfbbSDag-Erling Smørgrav 	if (newsize <= oldsize) {
65*4f52dfbbSDag-Erling Smørgrav 		size_t d = oldsize - newsize;
66*4f52dfbbSDag-Erling Smørgrav 
67*4f52dfbbSDag-Erling Smørgrav 		if (d < oldsize / 2 && d < (size_t)getpagesize()) {
68*4f52dfbbSDag-Erling Smørgrav 			memset((char *)ptr + newsize, 0, d);
69*4f52dfbbSDag-Erling Smørgrav 			return ptr;
70*4f52dfbbSDag-Erling Smørgrav 		}
71*4f52dfbbSDag-Erling Smørgrav 	}
72*4f52dfbbSDag-Erling Smørgrav 
73*4f52dfbbSDag-Erling Smørgrav 	newptr = malloc(newsize);
74*4f52dfbbSDag-Erling Smørgrav 	if (newptr == NULL)
75*4f52dfbbSDag-Erling Smørgrav 		return NULL;
76*4f52dfbbSDag-Erling Smørgrav 
77*4f52dfbbSDag-Erling Smørgrav 	if (newsize > oldsize) {
78*4f52dfbbSDag-Erling Smørgrav 		memcpy(newptr, ptr, oldsize);
79*4f52dfbbSDag-Erling Smørgrav 		memset((char *)newptr + oldsize, 0, newsize - oldsize);
80*4f52dfbbSDag-Erling Smørgrav 	} else
81*4f52dfbbSDag-Erling Smørgrav 		memcpy(newptr, ptr, newsize);
82*4f52dfbbSDag-Erling Smørgrav 
83*4f52dfbbSDag-Erling Smørgrav 	explicit_bzero(ptr, oldsize);
84*4f52dfbbSDag-Erling Smørgrav 	free(ptr);
85*4f52dfbbSDag-Erling Smørgrav 
86*4f52dfbbSDag-Erling Smørgrav 	return newptr;
87*4f52dfbbSDag-Erling Smørgrav }
88*4f52dfbbSDag-Erling Smørgrav /* DEF_WEAK(recallocarray); */
89*4f52dfbbSDag-Erling Smørgrav 
90*4f52dfbbSDag-Erling Smørgrav #endif /* HAVE_RECALLOCARRAY */
91