1*e3723e1fSApple OSS Distributions // 2*e3723e1fSApple OSS Distributions // Copyright (c) 2019 Apple, Inc. All rights reserved. 3*e3723e1fSApple OSS Distributions // 4*e3723e1fSApple OSS Distributions // @APPLE_OSREFERENCE_LICENSE_HEADER_START@ 5*e3723e1fSApple OSS Distributions // 6*e3723e1fSApple OSS Distributions // This file contains Original Code and/or Modifications of Original Code 7*e3723e1fSApple OSS Distributions // as defined in and that are subject to the Apple Public Source License 8*e3723e1fSApple OSS Distributions // Version 2.0 (the 'License'). You may not use this file except in 9*e3723e1fSApple OSS Distributions // compliance with the License. The rights granted to you under the License 10*e3723e1fSApple OSS Distributions // may not be used to create, or enable the creation or redistribution of, 11*e3723e1fSApple OSS Distributions // unlawful or unlicensed copies of an Apple operating system, or to 12*e3723e1fSApple OSS Distributions // circumvent, violate, or enable the circumvention or violation of, any 13*e3723e1fSApple OSS Distributions // terms of an Apple operating system software license agreement. 14*e3723e1fSApple OSS Distributions // 15*e3723e1fSApple OSS Distributions // Please obtain a copy of the License at 16*e3723e1fSApple OSS Distributions // http://www.opensource.apple.com/apsl/ and read it before using this file. 17*e3723e1fSApple OSS Distributions // 18*e3723e1fSApple OSS Distributions // The Original Code and all software distributed under the License are 19*e3723e1fSApple OSS Distributions // distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER 20*e3723e1fSApple OSS Distributions // EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES, 21*e3723e1fSApple OSS Distributions // INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY, 22*e3723e1fSApple OSS Distributions // FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT. 23*e3723e1fSApple OSS Distributions // Please see the License for the specific language governing rights and 24*e3723e1fSApple OSS Distributions // limitations under the License. 25*e3723e1fSApple OSS Distributions // 26*e3723e1fSApple OSS Distributions // @APPLE_OSREFERENCE_LICENSE_HEADER_END@ 27*e3723e1fSApple OSS Distributions // 28*e3723e1fSApple OSS Distributions 29*e3723e1fSApple OSS Distributions #ifndef XNU_LIBKERN_LIBKERN_CXX_BOUNDED_ARRAY_REF_H 30*e3723e1fSApple OSS Distributions #define XNU_LIBKERN_LIBKERN_CXX_BOUNDED_ARRAY_REF_H 31*e3723e1fSApple OSS Distributions 32*e3723e1fSApple OSS Distributions #if !TAPI 33*e3723e1fSApple OSS Distributions 34*e3723e1fSApple OSS Distributions #if DRIVERKIT_FRAMEWORK_INCLUDE 35*e3723e1fSApple OSS Distributions #include <DriverKit/bounded_array.h> 36*e3723e1fSApple OSS Distributions #include <DriverKit/bounded_ptr.h> 37*e3723e1fSApple OSS Distributions #else 38*e3723e1fSApple OSS Distributions #include <libkern/c++/bounded_array.h> 39*e3723e1fSApple OSS Distributions #include <libkern/c++/bounded_ptr.h> 40*e3723e1fSApple OSS Distributions #endif /* DRIVERKIT_FRAMEWORK_INCLUDE */ 41*e3723e1fSApple OSS Distributions 42*e3723e1fSApple OSS Distributions #include <stddef.h> 43*e3723e1fSApple OSS Distributions #include <os/base.h> 44*e3723e1fSApple OSS Distributions 45*e3723e1fSApple OSS Distributions namespace libkern { 46*e3723e1fSApple OSS Distributions namespace bar_detail { 47*e3723e1fSApple OSS Distributions using nullptr_t = decltype(nullptr); 48*e3723e1fSApple OSS Distributions } 49*e3723e1fSApple OSS Distributions 50*e3723e1fSApple OSS Distributions // Represents a reference to a sequence of 0 or more elements consecutively in 51*e3723e1fSApple OSS Distributions // memory, i.e. a start pointer and a length. 52*e3723e1fSApple OSS Distributions // 53*e3723e1fSApple OSS Distributions // When elements of the sequence are accessed, `bounded_array_ref` ensures 54*e3723e1fSApple OSS Distributions // that those elements are in the bounds of the sequence (which are provided 55*e3723e1fSApple OSS Distributions // when the `bounded_array_ref` is constructed). 56*e3723e1fSApple OSS Distributions // 57*e3723e1fSApple OSS Distributions // This class does not own the underlying data. It is expected to be used in 58*e3723e1fSApple OSS Distributions // situations where the data resides in some other buffer, whose lifetime 59*e3723e1fSApple OSS Distributions // extends past that of the `bounded_array_ref`. For this reason, storing a 60*e3723e1fSApple OSS Distributions // `bounded_array_ref` adds the risk of a dangling pointer if the lifetime of 61*e3723e1fSApple OSS Distributions // the `bounded_array_ref` extends past that of the underlying data. 62*e3723e1fSApple OSS Distributions // 63*e3723e1fSApple OSS Distributions // `bounded_array_ref` is trivially copyable and it should be passed by value. 64*e3723e1fSApple OSS Distributions template <typename T, typename TrappingPolicy> 65*e3723e1fSApple OSS Distributions struct bounded_array_ref { 66*e3723e1fSApple OSS Distributions // Creates an empty `bounded_array_ref`. 67*e3723e1fSApple OSS Distributions // 68*e3723e1fSApple OSS Distributions // An empty `bounded_array_ref` does not reference anything, so its 69*e3723e1fSApple OSS Distributions // `data()` is null and its `size()` is 0. bounded_array_refbounded_array_ref70*e3723e1fSApple OSS Distributions explicit constexpr bounded_array_ref() noexcept : data_(nullptr), size_(0) 71*e3723e1fSApple OSS Distributions { 72*e3723e1fSApple OSS Distributions } 73*e3723e1fSApple OSS Distributions 74*e3723e1fSApple OSS Distributions // Creates a `bounded_array_ref` from a bounded pointer and a size. 75*e3723e1fSApple OSS Distributions // 76*e3723e1fSApple OSS Distributions // The resulting `bounded_array_ref` starts at the location where the 77*e3723e1fSApple OSS Distributions // pointer points, and has the given number of elements. All the elements 78*e3723e1fSApple OSS Distributions // must be in the bounds of the `bounded_ptr`, otherwise this constructor 79*e3723e1fSApple OSS Distributions // will trap. bounded_array_refbounded_array_ref80*e3723e1fSApple OSS Distributions explicit constexpr bounded_array_ref(bounded_ptr<T, TrappingPolicy> data, size_t n) 81*e3723e1fSApple OSS Distributions : data_(data.unsafe_discard_bounds()), size_(static_cast<uint32_t>(n)) 82*e3723e1fSApple OSS Distributions { 83*e3723e1fSApple OSS Distributions if (n != 0) { 84*e3723e1fSApple OSS Distributions data[n - 1]; // make sure the bounds are valid 85*e3723e1fSApple OSS Distributions // TODO: find a better way to do that 86*e3723e1fSApple OSS Distributions } 87*e3723e1fSApple OSS Distributions if (__improbable(n > UINT32_MAX)) { 88*e3723e1fSApple OSS Distributions TrappingPolicy::trap("bounded_array_ref: Can't construct from a size greater than UINT32_MAX"); 89*e3723e1fSApple OSS Distributions } 90*e3723e1fSApple OSS Distributions } 91*e3723e1fSApple OSS Distributions 92*e3723e1fSApple OSS Distributions // Creates a `bounded_array_ref` from a raw pointer and a size. 93*e3723e1fSApple OSS Distributions // 94*e3723e1fSApple OSS Distributions // The resulting `bounded_array_ref` starts at the location where the 95*e3723e1fSApple OSS Distributions // pointer points, and has the given number of elements. This constructor 96*e3723e1fSApple OSS Distributions // trusts that `n` elements are reachable from the given pointer. bounded_array_refbounded_array_ref97*e3723e1fSApple OSS Distributions explicit constexpr bounded_array_ref(T* data, size_t n) : data_(data), size_(static_cast<uint32_t>(n)) 98*e3723e1fSApple OSS Distributions { 99*e3723e1fSApple OSS Distributions if (__improbable(n > UINT32_MAX)) { 100*e3723e1fSApple OSS Distributions TrappingPolicy::trap("bounded_array_ref: Can't construct from a size greater than UINT32_MAX"); 101*e3723e1fSApple OSS Distributions } 102*e3723e1fSApple OSS Distributions } 103*e3723e1fSApple OSS Distributions 104*e3723e1fSApple OSS Distributions // Creates a `bounded_array_ref` from a `[first, last)` half-open range. 105*e3723e1fSApple OSS Distributions // 106*e3723e1fSApple OSS Distributions // The resulting `bounded_array_ref` starts at the location pointed-to by 107*e3723e1fSApple OSS Distributions // `first`, and contains `last - first` elements. The `[first, last)` 108*e3723e1fSApple OSS Distributions // half-open range must be a valid range, i.e. it must be the case that 109*e3723e1fSApple OSS Distributions // `first <= last`, otherwise the constructor traps. bounded_array_refbounded_array_ref110*e3723e1fSApple OSS Distributions explicit constexpr bounded_array_ref(T* first, T* last) : data_(first), size_(static_cast<uint32_t>(last - first)) 111*e3723e1fSApple OSS Distributions { 112*e3723e1fSApple OSS Distributions if (__improbable(first > last)) { 113*e3723e1fSApple OSS Distributions TrappingPolicy::trap("bounded_array_ref: The [first, last) constructor requires a valid range."); 114*e3723e1fSApple OSS Distributions } 115*e3723e1fSApple OSS Distributions if (__improbable(last - first > UINT32_MAX)) { 116*e3723e1fSApple OSS Distributions TrappingPolicy::trap("bounded_array_ref: Can't construct from a size greater than UINT32_MAX"); 117*e3723e1fSApple OSS Distributions } 118*e3723e1fSApple OSS Distributions } 119*e3723e1fSApple OSS Distributions 120*e3723e1fSApple OSS Distributions // Creates a `bounded_array_ref` from a `bounded_array`. 121*e3723e1fSApple OSS Distributions // 122*e3723e1fSApple OSS Distributions // The resulting `bounded_array_ref` starts at the first element of the 123*e3723e1fSApple OSS Distributions // `bounded_array`, and has the number of elements in the `bounded_array`. 124*e3723e1fSApple OSS Distributions template <size_t N> bounded_array_refbounded_array_ref125*e3723e1fSApple OSS Distributions constexpr bounded_array_ref(bounded_array<T, N, TrappingPolicy>& data) : data_(data.data()), size_(static_cast<uint32_t>(data.size())) 126*e3723e1fSApple OSS Distributions { 127*e3723e1fSApple OSS Distributions if (__improbable(data.size() > UINT32_MAX)) { 128*e3723e1fSApple OSS Distributions TrappingPolicy::trap("bounded_array_ref: Can't construct from a size greater than UINT32_MAX"); 129*e3723e1fSApple OSS Distributions } 130*e3723e1fSApple OSS Distributions } 131*e3723e1fSApple OSS Distributions 132*e3723e1fSApple OSS Distributions // Creates a `bounded_array_ref` from a C-style array. 133*e3723e1fSApple OSS Distributions // 134*e3723e1fSApple OSS Distributions // The resulting `bounded_array_ref` starts at the first element of the 135*e3723e1fSApple OSS Distributions // C-style array, and has the number of elements in that array. 136*e3723e1fSApple OSS Distributions template <size_t N> bounded_array_refbounded_array_ref137*e3723e1fSApple OSS Distributions constexpr bounded_array_ref(T (&array)[N]) : data_(array), size_(static_cast<uint32_t>(N)) 138*e3723e1fSApple OSS Distributions { 139*e3723e1fSApple OSS Distributions if (__improbable(N > UINT32_MAX)) { 140*e3723e1fSApple OSS Distributions TrappingPolicy::trap("bounded_array_ref: Can't construct from a size greater than UINT32_MAX"); 141*e3723e1fSApple OSS Distributions } 142*e3723e1fSApple OSS Distributions } 143*e3723e1fSApple OSS Distributions 144*e3723e1fSApple OSS Distributions constexpr 145*e3723e1fSApple OSS Distributions bounded_array_ref(bounded_array_ref const&) = default; 146*e3723e1fSApple OSS Distributions constexpr 147*e3723e1fSApple OSS Distributions bounded_array_ref(bounded_array_ref&& other) noexcept = default; 148*e3723e1fSApple OSS Distributions 149*e3723e1fSApple OSS Distributions constexpr bounded_array_ref& operator=(bounded_array_ref const&) = default; 150*e3723e1fSApple OSS Distributions constexpr bounded_array_ref& operator=(bounded_array_ref&& other) = default; 151*e3723e1fSApple OSS Distributions ~bounded_array_ref() = default; 152*e3723e1fSApple OSS Distributions 153*e3723e1fSApple OSS Distributions // Returns whether the `bounded_array_ref` points to a sequence or not. 154*e3723e1fSApple OSS Distributions // 155*e3723e1fSApple OSS Distributions // Note that pointing to a sequence at all is different from pointing to 156*e3723e1fSApple OSS Distributions // a valid sequence, or having a size of 0. If a `bounded_array_ref` 157*e3723e1fSApple OSS Distributions // points to a sequence (regardless of whether it is valid or whether 158*e3723e1fSApple OSS Distributions // the size of that sequence is 0), this operator will return true. 159*e3723e1fSApple OSS Distributions explicit 160*e3723e1fSApple OSS Distributions operator bool() const noexcept 161*e3723e1fSApple OSS Distributions { 162*e3723e1fSApple OSS Distributions return data_ != nullptr; 163*e3723e1fSApple OSS Distributions } 164*e3723e1fSApple OSS Distributions 165*e3723e1fSApple OSS Distributions using iterator = bounded_ptr<T, TrappingPolicy>; 166*e3723e1fSApple OSS Distributions 167*e3723e1fSApple OSS Distributions // The following methods allow obtaining iterators (i.e. cursors) to 168*e3723e1fSApple OSS Distributions // objects inside a `bounded_array_ref`. 169*e3723e1fSApple OSS Distributions // 170*e3723e1fSApple OSS Distributions // The iterators of a `bounded_array_ref` are `bounded_ptr`s, which know 171*e3723e1fSApple OSS Distributions // the bounds of the sequence and will trap when dereferenced outside 172*e3723e1fSApple OSS Distributions // of those bounds. 173*e3723e1fSApple OSS Distributions // 174*e3723e1fSApple OSS Distributions // `begin()` returns an iterator to the first element in the range, and 175*e3723e1fSApple OSS Distributions // `end()` returns an iterator to one-past-the-last element in the range. 176*e3723e1fSApple OSS Distributions // The `end()` iterator can't be dereferenced, since it is out of bounds. 177*e3723e1fSApple OSS Distributions // 178*e3723e1fSApple OSS Distributions // If the `bounded_array_ref` is empty, these methods will return null 179*e3723e1fSApple OSS Distributions // `bounded_ptr`s, which can be checked for equality but can't be 180*e3723e1fSApple OSS Distributions // dereferenced. 181*e3723e1fSApple OSS Distributions OS_ALWAYS_INLINE iterator beginbounded_array_ref182*e3723e1fSApple OSS Distributions begin() const noexcept 183*e3723e1fSApple OSS Distributions { 184*e3723e1fSApple OSS Distributions return iterator(data_, data_, data_ + size_); 185*e3723e1fSApple OSS Distributions } 186*e3723e1fSApple OSS Distributions iterator endbounded_array_ref187*e3723e1fSApple OSS Distributions end() const noexcept 188*e3723e1fSApple OSS Distributions { 189*e3723e1fSApple OSS Distributions return iterator(data_ + size_, data_, data_ + size_); 190*e3723e1fSApple OSS Distributions } 191*e3723e1fSApple OSS Distributions 192*e3723e1fSApple OSS Distributions // Returns the number of elements in the range referenced by the 193*e3723e1fSApple OSS Distributions // `bounded_array_ref`. 194*e3723e1fSApple OSS Distributions // 195*e3723e1fSApple OSS Distributions // This method returns `0` if the `bounded_array_ref` is null, since 196*e3723e1fSApple OSS Distributions // such an array ref behaves the same as an empty range. 197*e3723e1fSApple OSS Distributions constexpr size_t sizebounded_array_ref198*e3723e1fSApple OSS Distributions size() const noexcept 199*e3723e1fSApple OSS Distributions { 200*e3723e1fSApple OSS Distributions return size_; 201*e3723e1fSApple OSS Distributions } 202*e3723e1fSApple OSS Distributions 203*e3723e1fSApple OSS Distributions // This has the same behavior as size(), but is intended to avoid confusion 204*e3723e1fSApple OSS Distributions // about whether it is returning an array count or size in bytes. 205*e3723e1fSApple OSS Distributions constexpr size_t lengthbounded_array_ref206*e3723e1fSApple OSS Distributions length() const noexcept 207*e3723e1fSApple OSS Distributions { 208*e3723e1fSApple OSS Distributions return size_; 209*e3723e1fSApple OSS Distributions } 210*e3723e1fSApple OSS Distributions 211*e3723e1fSApple OSS Distributions // Returns a non-owning pointer to the underlying memory referenced by a 212*e3723e1fSApple OSS Distributions // `bounded_array_ref`. 213*e3723e1fSApple OSS Distributions // 214*e3723e1fSApple OSS Distributions // This method can be called even if the `bounded_array_ref` is null, in 215*e3723e1fSApple OSS Distributions // which case the returned pointer will be null. 216*e3723e1fSApple OSS Distributions constexpr T* databounded_array_ref217*e3723e1fSApple OSS Distributions data() const noexcept 218*e3723e1fSApple OSS Distributions { 219*e3723e1fSApple OSS Distributions return data_; 220*e3723e1fSApple OSS Distributions } 221*e3723e1fSApple OSS Distributions 222*e3723e1fSApple OSS Distributions // Access the n-th element of a `bounded_array_ref`. 223*e3723e1fSApple OSS Distributions // 224*e3723e1fSApple OSS Distributions // If `n` is out of the bounds of the sequence, this operation will 225*e3723e1fSApple OSS Distributions // trap. If the array ref is null, this operation will trap too. 226*e3723e1fSApple OSS Distributions // 227*e3723e1fSApple OSS Distributions // Design note: 228*e3723e1fSApple OSS Distributions // We voluntarily use a signed type to represent the index even though a 229*e3723e1fSApple OSS Distributions // negative index will always cause a trap. If we used an unsigned type, 230*e3723e1fSApple OSS Distributions // we could get an implicit conversion from signed to unsigned, which 231*e3723e1fSApple OSS Distributions // could silently wrap around. We think trapping early is more likely 232*e3723e1fSApple OSS Distributions // to be helpful in this situation. 233*e3723e1fSApple OSS Distributions OS_ALWAYS_INLINE T& 234*e3723e1fSApple OSS Distributions operator[](ptrdiff_t n) const 235*e3723e1fSApple OSS Distributions { 236*e3723e1fSApple OSS Distributions return begin()[n]; 237*e3723e1fSApple OSS Distributions } 238*e3723e1fSApple OSS Distributions 239*e3723e1fSApple OSS Distributions // Chop off the first `n` elements of the array, and keep `m` elements 240*e3723e1fSApple OSS Distributions // in the array. 241*e3723e1fSApple OSS Distributions // 242*e3723e1fSApple OSS Distributions // The resulting range can be described by `[beg + n, beg + n + m)`, where 243*e3723e1fSApple OSS Distributions // `beg` is the `begin()` of the range being sliced. This operation traps 244*e3723e1fSApple OSS Distributions // if `n + m` is larger than the number of elements in the array. 245*e3723e1fSApple OSS Distributions // 246*e3723e1fSApple OSS Distributions // Since `bounded_array_ref` checks (or assumes) that the range it is 247*e3723e1fSApple OSS Distributions // given on construction is within bounds and `slice()` checks that the 248*e3723e1fSApple OSS Distributions // produced slice is within the original range, it is impossible to create 249*e3723e1fSApple OSS Distributions // a `bounded_array_ref` that isn't a subset of a valid range using this 250*e3723e1fSApple OSS Distributions // function. 251*e3723e1fSApple OSS Distributions bounded_array_ref<T, TrappingPolicy> slicebounded_array_ref252*e3723e1fSApple OSS Distributions slice(size_t n, size_t m) const 253*e3723e1fSApple OSS Distributions { 254*e3723e1fSApple OSS Distributions uint32_t total; 255*e3723e1fSApple OSS Distributions if (__improbable(os_add_overflow(n, m, &total))) { 256*e3723e1fSApple OSS Distributions TrappingPolicy::trap("bounded_array_ref: n + m is larger than the size of any bounded_array_ref"); 257*e3723e1fSApple OSS Distributions } 258*e3723e1fSApple OSS Distributions if (__improbable(total > size())) { 259*e3723e1fSApple OSS Distributions TrappingPolicy::trap("bounded_array_ref: invalid slice provided, the indices are of bounds for the bounded_array_ref"); 260*e3723e1fSApple OSS Distributions } 261*e3723e1fSApple OSS Distributions return bounded_array_ref(data_ + n, m); 262*e3723e1fSApple OSS Distributions } 263*e3723e1fSApple OSS Distributions 264*e3723e1fSApple OSS Distributions private: 265*e3723e1fSApple OSS Distributions T* data_; 266*e3723e1fSApple OSS Distributions uint32_t size_; 267*e3723e1fSApple OSS Distributions }; 268*e3723e1fSApple OSS Distributions 269*e3723e1fSApple OSS Distributions // The comparison functions against `nullptr` all return whether the 270*e3723e1fSApple OSS Distributions // `bounded_array_ref` references a sequence or not. 271*e3723e1fSApple OSS Distributions template <typename T, typename P> 272*e3723e1fSApple OSS Distributions bool 273*e3723e1fSApple OSS Distributions operator==(bounded_array_ref<T, P> const& x, bar_detail::nullptr_t) 274*e3723e1fSApple OSS Distributions { 275*e3723e1fSApple OSS Distributions return !static_cast<bool>(x); 276*e3723e1fSApple OSS Distributions } 277*e3723e1fSApple OSS Distributions 278*e3723e1fSApple OSS Distributions template <typename T, typename P> 279*e3723e1fSApple OSS Distributions bool 280*e3723e1fSApple OSS Distributions operator!=(bounded_array_ref<T, P> const& x, bar_detail::nullptr_t) 281*e3723e1fSApple OSS Distributions { 282*e3723e1fSApple OSS Distributions return !(x == nullptr); 283*e3723e1fSApple OSS Distributions } 284*e3723e1fSApple OSS Distributions 285*e3723e1fSApple OSS Distributions template <typename T, typename P> 286*e3723e1fSApple OSS Distributions bool 287*e3723e1fSApple OSS Distributions operator==(bar_detail::nullptr_t, bounded_array_ref<T, P> const& x) 288*e3723e1fSApple OSS Distributions { 289*e3723e1fSApple OSS Distributions return x == nullptr; 290*e3723e1fSApple OSS Distributions } 291*e3723e1fSApple OSS Distributions 292*e3723e1fSApple OSS Distributions template <typename T, typename P> 293*e3723e1fSApple OSS Distributions bool 294*e3723e1fSApple OSS Distributions operator!=(bar_detail::nullptr_t, bounded_array_ref<T, P> const& x) 295*e3723e1fSApple OSS Distributions { 296*e3723e1fSApple OSS Distributions return x != nullptr; 297*e3723e1fSApple OSS Distributions } 298*e3723e1fSApple OSS Distributions } // end namespace libkern 299*e3723e1fSApple OSS Distributions 300*e3723e1fSApple OSS Distributions #endif /* !TAPI */ 301*e3723e1fSApple OSS Distributions 302*e3723e1fSApple OSS Distributions #endif // !XNU_LIBKERN_LIBKERN_CXX_BOUNDED_ARRAY_REF_H 303