1e9bf778aSBaptiste Daroussin /* $Id: compat_recallocarray.c,v 1.2 2020/06/15 01:37:15 schwarze Exp $ */
2e9bf778aSBaptiste Daroussin /* $OpenBSD: recallocarray.c,v 1.1 2017/03/06 18:44:21 otto Exp $ */
375b6c55cSBaptiste Daroussin /*
4e9bf778aSBaptiste Daroussin * Copyright (c) 2008, 2017 Otto Moerbeek <otto@drijf.net>
575b6c55cSBaptiste Daroussin *
675b6c55cSBaptiste Daroussin * Permission to use, copy, modify, and distribute this software for any
775b6c55cSBaptiste Daroussin * purpose with or without fee is hereby granted, provided that the above
875b6c55cSBaptiste Daroussin * copyright notice and this permission notice appear in all copies.
975b6c55cSBaptiste Daroussin *
1075b6c55cSBaptiste Daroussin * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
1175b6c55cSBaptiste Daroussin * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
1275b6c55cSBaptiste Daroussin * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
1375b6c55cSBaptiste Daroussin * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
1475b6c55cSBaptiste Daroussin * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
1575b6c55cSBaptiste Daroussin * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
1675b6c55cSBaptiste Daroussin * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
1775b6c55cSBaptiste Daroussin */
18e9bf778aSBaptiste Daroussin #include "config.h"
1975b6c55cSBaptiste Daroussin
2075b6c55cSBaptiste Daroussin #include <sys/types.h>
2175b6c55cSBaptiste Daroussin #include <errno.h>
2275b6c55cSBaptiste Daroussin #include <stdlib.h>
23e9bf778aSBaptiste Daroussin #include <stdint.h>
2475b6c55cSBaptiste Daroussin #include <string.h>
2575b6c55cSBaptiste Daroussin
2675b6c55cSBaptiste Daroussin /*
2775b6c55cSBaptiste Daroussin * This is sqrt(SIZE_MAX+1), as s1*s2 <= SIZE_MAX
2875b6c55cSBaptiste Daroussin * if both s1 < MUL_NO_OVERFLOW and s2 < MUL_NO_OVERFLOW
2975b6c55cSBaptiste Daroussin */
3075b6c55cSBaptiste Daroussin #define MUL_NO_OVERFLOW ((size_t)1 << (sizeof(size_t) * 4))
3175b6c55cSBaptiste Daroussin
3275b6c55cSBaptiste Daroussin /*
3375b6c55cSBaptiste Daroussin * Even though specified in POSIX, the PAGESIZE and PAGE_SIZE
3475b6c55cSBaptiste Daroussin * macros have very poor portability. Since we only use this
3575b6c55cSBaptiste Daroussin * to avoid free() overhead for small shrinking, simply pick
3675b6c55cSBaptiste Daroussin * an arbitrary number.
3775b6c55cSBaptiste Daroussin */
38e9bf778aSBaptiste Daroussin #define getpagesize() (1UL << 12)
3975b6c55cSBaptiste Daroussin
4075b6c55cSBaptiste Daroussin
4175b6c55cSBaptiste Daroussin void *
recallocarray(void * ptr,size_t oldnmemb,size_t newnmemb,size_t size)4275b6c55cSBaptiste Daroussin recallocarray(void *ptr, size_t oldnmemb, size_t newnmemb, size_t size)
4375b6c55cSBaptiste Daroussin {
4475b6c55cSBaptiste Daroussin size_t oldsize, newsize;
4575b6c55cSBaptiste Daroussin void *newptr;
4675b6c55cSBaptiste Daroussin
4775b6c55cSBaptiste Daroussin if (ptr == NULL)
4875b6c55cSBaptiste Daroussin return calloc(newnmemb, size);
4975b6c55cSBaptiste Daroussin
5075b6c55cSBaptiste Daroussin if ((newnmemb >= MUL_NO_OVERFLOW || size >= MUL_NO_OVERFLOW) &&
5175b6c55cSBaptiste Daroussin newnmemb > 0 && SIZE_MAX / newnmemb < size) {
5275b6c55cSBaptiste Daroussin errno = ENOMEM;
5375b6c55cSBaptiste Daroussin return NULL;
5475b6c55cSBaptiste Daroussin }
5575b6c55cSBaptiste Daroussin newsize = newnmemb * size;
5675b6c55cSBaptiste Daroussin
5775b6c55cSBaptiste Daroussin if ((oldnmemb >= MUL_NO_OVERFLOW || size >= MUL_NO_OVERFLOW) &&
5875b6c55cSBaptiste Daroussin oldnmemb > 0 && SIZE_MAX / oldnmemb < size) {
5975b6c55cSBaptiste Daroussin errno = EINVAL;
6075b6c55cSBaptiste Daroussin return NULL;
6175b6c55cSBaptiste Daroussin }
6275b6c55cSBaptiste Daroussin oldsize = oldnmemb * size;
6375b6c55cSBaptiste Daroussin
6475b6c55cSBaptiste Daroussin /*
6575b6c55cSBaptiste Daroussin * Don't bother too much if we're shrinking just a bit,
6675b6c55cSBaptiste Daroussin * we do not shrink for series of small steps, oh well.
6775b6c55cSBaptiste Daroussin */
6875b6c55cSBaptiste Daroussin if (newsize <= oldsize) {
6975b6c55cSBaptiste Daroussin size_t d = oldsize - newsize;
7075b6c55cSBaptiste Daroussin
71e9bf778aSBaptiste Daroussin if (d < oldsize / 2 && d < getpagesize()) {
7275b6c55cSBaptiste Daroussin memset((char *)ptr + newsize, 0, d);
7375b6c55cSBaptiste Daroussin return ptr;
7475b6c55cSBaptiste Daroussin }
7575b6c55cSBaptiste Daroussin }
7675b6c55cSBaptiste Daroussin
7775b6c55cSBaptiste Daroussin newptr = malloc(newsize);
7875b6c55cSBaptiste Daroussin if (newptr == NULL)
7975b6c55cSBaptiste Daroussin return NULL;
8075b6c55cSBaptiste Daroussin
8175b6c55cSBaptiste Daroussin if (newsize > oldsize) {
8275b6c55cSBaptiste Daroussin memcpy(newptr, ptr, oldsize);
8375b6c55cSBaptiste Daroussin memset((char *)newptr + oldsize, 0, newsize - oldsize);
8475b6c55cSBaptiste Daroussin } else
8575b6c55cSBaptiste Daroussin memcpy(newptr, ptr, newsize);
8675b6c55cSBaptiste Daroussin
8775b6c55cSBaptiste Daroussin /*
8875b6c55cSBaptiste Daroussin * At this point, the OpenBSD implementation calls
8975b6c55cSBaptiste Daroussin * explicit_bzero() on the old memory before it is
9075b6c55cSBaptiste Daroussin * freed. Since explicit_bzero() is hard to implement
9175b6c55cSBaptiste Daroussin * portably and we don't handle confidential data in
9275b6c55cSBaptiste Daroussin * mandoc in the first place, simply free the memory
9375b6c55cSBaptiste Daroussin * without clearing it.
9475b6c55cSBaptiste Daroussin */
9575b6c55cSBaptiste Daroussin
9675b6c55cSBaptiste Daroussin free(ptr);
9775b6c55cSBaptiste Daroussin
9875b6c55cSBaptiste Daroussin return newptr;
9975b6c55cSBaptiste Daroussin }
100