1 /* pb_decode.c -- decode a protobuf using minimal resources
3 * 2011 Petteri Aimonen <jpa@kapsi.fi>
8 /* Verify that we remember to check all return values for proper error propagation */
9 #define checkreturn __attribute__((warn_unused_result))
15 #include "pb_decode.h"
18 typedef bool (*pb_decoder_t)(pb_istream_t *stream, const pb_field_t *field, void *dest) checkreturn;
20 /* --- Function pointers to field decoders ---
21 * Order in the array must match pb_action_t LTYPE numbering.
23 static const pb_decoder_t PB_DECODERS[PB_LTYPES_COUNT] = {
37 bool checkreturn pb_read(pb_istream_t *stream, uint8_t *buf, size_t count)
39 if (stream->bytes_left < count)
42 if (!stream->callback(stream, buf, count))
45 stream->bytes_left -= count;
49 static bool checkreturn buf_read(pb_istream_t *stream, uint8_t *buf, size_t count)
51 uint8_t *source = (uint8_t*)stream->state;
54 memcpy(buf, source, count);
56 stream->state = source + count;
60 pb_istream_t pb_istream_from_buffer(uint8_t *buf, size_t bufsize)
63 stream.callback = &buf_read;
65 stream.bytes_left = bufsize;
73 static bool checkreturn pb_decode_varint32(pb_istream_t *stream, uint32_t *dest)
76 bool status = pb_decode_varint(stream, &temp);
81 bool checkreturn pb_decode_varint(pb_istream_t *stream, uint64_t *dest)
87 while (bitpos < 64 && pb_read(stream, &byte, 1))
89 *dest |= (uint64_t)(byte & 0x7F) << bitpos;
99 bool checkreturn pb_skip_varint(pb_istream_t *stream)
104 if (!pb_read(stream, &byte, 1))
106 } while (byte & 0x80);
110 bool checkreturn pb_skip_string(pb_istream_t *stream)
113 if (!pb_decode_varint32(stream, &length))
116 return pb_read(stream, NULL, length);
119 /* Currently the wire type related stuff is kept hidden from
120 * callbacks. They shouldn't need it. It's better for performance
121 * to just assume the correct type and fail safely on corrupt message.
124 static bool checkreturn skip(pb_istream_t *stream, int wire_type)
128 case PB_WT_VARINT: return pb_skip_varint(stream);
129 case PB_WT_64BIT: return pb_read(stream, NULL, 8);
130 case PB_WT_STRING: return pb_skip_string(stream);
131 case PB_WT_32BIT: return pb_read(stream, NULL, 4);
132 default: return false;
136 /* Read a raw value to buffer, for the purpose of passing it to callback as
137 * a substream. Size is maximum size on call, and actual size on return.
139 static bool checkreturn read_raw_value(pb_istream_t *stream, pb_wire_type_t wire_type, uint8_t *buf, size_t *size)
141 size_t max_size = *size;
149 if (*size > max_size) return false;
150 if (!pb_read(stream, buf, 1)) return false;
151 } while (*buf++ & 0x80);
156 return pb_read(stream, buf, 8);
160 return pb_read(stream, buf, 4);
162 default: return false;
166 /* Decode string length from stream and return a substream with limited length */
167 static bool checkreturn make_string_substream(pb_istream_t *stream, pb_istream_t *substream)
170 if (!pb_decode_varint32(stream, &size))
173 *substream = *stream;
174 if (substream->bytes_left < size)
177 substream->bytes_left = size;
178 stream->bytes_left -= size;
182 /* Iterator for pb_field_t list */
184 const pb_field_t *start;
185 const pb_field_t *current;
190 } pb_field_iterator_t;
192 static void pb_field_init(pb_field_iterator_t *iter, const pb_field_t *fields, void *dest_struct)
194 iter->start = iter->current = fields;
195 iter->field_index = 0;
196 iter->pData = dest_struct + iter->current->data_offset;
197 iter->pSize = (char*)iter->pData + iter->current->size_offset;
198 iter->dest_struct = dest_struct;
201 static bool pb_field_next(pb_field_iterator_t *iter)
203 bool notwrapped = true;
204 size_t prev_size = iter->current->data_size;
206 if (PB_HTYPE(iter->current->type) == PB_HTYPE_ARRAY)
207 prev_size *= iter->current->array_size;
211 if (iter->current->tag == 0)
213 iter->current = iter->start;
214 iter->field_index = 0;
215 iter->pData = iter->dest_struct;
220 iter->pData = (char*)iter->pData + prev_size + iter->current->data_offset;
221 iter->pSize = (char*)iter->pData + iter->current->size_offset;
225 static bool checkreturn pb_field_find(pb_field_iterator_t *iter, int tag)
227 int start = iter->field_index;
230 if (iter->current->tag == tag)
233 } while (iter->field_index != start);
238 /*************************
239 * Decode a single field *
240 *************************/
242 static bool checkreturn decode_field(pb_istream_t *stream, int wire_type, pb_field_iterator_t *iter)
244 pb_decoder_t func = PB_DECODERS[PB_LTYPE(iter->current->type)];
246 switch (PB_HTYPE(iter->current->type))
248 case PB_HTYPE_REQUIRED:
249 return func(stream, iter->current, iter->pData);
251 case PB_HTYPE_OPTIONAL:
252 *(bool*)iter->pSize = true;
253 return func(stream, iter->current, iter->pData);
256 if (wire_type == PB_WT_STRING
257 && PB_LTYPE(iter->current->type) <= PB_LTYPE_LAST_PACKABLE)
260 size_t *size = (size_t*)iter->pSize;
261 pb_istream_t substream;
262 if (!make_string_substream(stream, &substream))
265 while (substream.bytes_left && *size < iter->current->array_size)
267 void *pItem = (uint8_t*)iter->pData + iter->current->data_size * (*size);
268 if (!func(&substream, iter->current, pItem))
272 return (substream.bytes_left == 0);
277 size_t *size = (size_t*)iter->pSize;
278 void *pItem = (uint8_t*)iter->pData + iter->current->data_size * (*size);
279 if (*size >= iter->current->array_size)
283 return func(stream, iter->current, pItem);
286 case PB_HTYPE_CALLBACK:
288 pb_callback_t *pCallback = (pb_callback_t*)iter->pData;
290 if (pCallback->funcs.decode == NULL)
291 return skip(stream, wire_type);
293 if (wire_type == PB_WT_STRING)
295 pb_istream_t substream;
297 if (!make_string_substream(stream, &substream))
300 while (substream.bytes_left)
302 if (!pCallback->funcs.decode(&substream, iter->current, pCallback->arg))
309 /* Copy the single scalar value to stack.
310 * This is required so that we can limit the stream length,
311 * which in turn allows to use same callback for packed and
312 * not-packed fields. */
313 pb_istream_t substream;
315 size_t size = sizeof(buffer);
317 if (!read_raw_value(stream, wire_type, buffer, &size))
319 substream = pb_istream_from_buffer(buffer, size);
321 return pCallback->funcs.decode(&substream, iter->current, pCallback->arg);
330 /*********************
331 * Decode all fields *
332 *********************/
334 bool checkreturn pb_decode(pb_istream_t *stream, const pb_field_t fields[], void *dest_struct)
336 uint32_t fields_seen = 0; /* Used to check for required fields */
337 pb_field_iterator_t iter;
340 pb_field_init(&iter, fields, dest_struct);
342 /* Initialize size/has fields and apply default values */
345 if (iter.current->tag == 0)
348 if (PB_HTYPE(iter.current->type) == PB_HTYPE_OPTIONAL)
350 *(bool*)iter.pSize = false;
352 /* Initialize to default value */
353 if (iter.current->ptr != NULL)
354 memcpy(iter.pData, iter.current->ptr, iter.current->data_size);
356 memset(iter.pData, 0, iter.current->data_size);
358 else if (PB_HTYPE(iter.current->type) == PB_HTYPE_ARRAY)
360 *(size_t*)iter.pSize = 0;
362 else if (PB_HTYPE(iter.current->type) == PB_HTYPE_REQUIRED)
364 memset(iter.pData, 0, iter.current->data_size);
366 } while (pb_field_next(&iter));
368 while (stream->bytes_left)
372 if (!pb_decode_varint32(stream, &temp))
374 if (stream->bytes_left == 0)
375 break; /* It was EOF */
377 return false; /* It was error */
381 break; /* Special feature: allow 0-terminated messages. */
384 wire_type = temp & 7;
386 if (!pb_field_find(&iter, tag))
388 /* No match found, skip data */
389 if (!skip(stream, wire_type))
394 fields_seen |= 1 << (iter.field_index & 31);
396 if (!decode_field(stream, wire_type, &iter))
400 /* Check that all required fields (mod 31) were present. */
401 for (i = 0; fields[i].tag != 0; i++)
403 if (PB_HTYPE(fields[i].type) == PB_HTYPE_REQUIRED &&
404 !(fields_seen & (1 << (i & 31))))
415 /* Copy destsize bytes from src so that values are casted properly.
416 * On little endian machine, copy first n bytes of src
417 * On big endian machine, copy last n bytes of src
418 * srcsize must always be larger than destsize
420 static void endian_copy(void *dest, void *src, size_t destsize, size_t srcsize)
422 #ifdef __BIG_ENDIAN__
423 memcpy(dest, (char*)src + (srcsize - destsize), destsize);
425 memcpy(dest, src, destsize);
429 bool checkreturn pb_dec_varint(pb_istream_t *stream, const pb_field_t *field, void *dest)
432 bool status = pb_decode_varint(stream, &temp);
433 endian_copy(dest, &temp, field->data_size, sizeof(temp));
437 bool checkreturn pb_dec_svarint(pb_istream_t *stream, const pb_field_t *field, void *dest)
440 bool status = pb_decode_varint(stream, &temp);
441 temp = (temp >> 1) ^ -(int64_t)(temp & 1);
442 endian_copy(dest, &temp, field->data_size, sizeof(temp));
446 bool checkreturn pb_dec_fixed(pb_istream_t *stream, const pb_field_t *field, void *dest)
448 #ifdef __BIG_ENDIAN__
449 uint8_t bytes[8] = {0};
450 bool status = pb_read(stream, bytes, field->data_size);
451 uint8_t bebytes[8] = {bytes[7], bytes[6], bytes[5], bytes[4],
452 bytes[3], bytes[2], bytes[1], bytes[0]};
453 endian_copy(dest, lebytes, field->data_size, 8);
456 return pb_read(stream, (uint8_t*)dest, field->data_size);
460 bool checkreturn pb_dec_bytes(pb_istream_t *stream, const pb_field_t *field, void *dest)
462 pb_bytes_array_t *x = (pb_bytes_array_t*)dest;
465 if (!pb_decode_varint32(stream, &temp))
469 if (x->size > field->data_size)
472 return pb_read(stream, x->bytes, x->size);
475 bool checkreturn pb_dec_string(pb_istream_t *stream, const pb_field_t *field, void *dest)
479 if (!pb_decode_varint32(stream, &size))
482 if (size > field->data_size - 1)
485 status = pb_read(stream, (uint8_t*)dest, size);
486 *((uint8_t*)dest + size) = 0;
490 bool checkreturn pb_dec_submessage(pb_istream_t *stream, const pb_field_t *field, void *dest)
492 pb_istream_t substream;
494 if (!make_string_substream(stream, &substream))
497 if (field->ptr == NULL)
500 return pb_decode(&substream, (pb_field_t*)field->ptr, dest);