blobmsg: add _len variants for all attribute checking methods
[project/libubox.git] / blobmsg.h
1 /*
2 * Copyright (C) 2010-2012 Felix Fietkau <nbd@openwrt.org>
3 *
4 * Permission to use, copy, modify, and/or distribute this software for any
5 * purpose with or without fee is hereby granted, provided that the above
6 * copyright notice and this permission notice appear in all copies.
7 *
8 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
9 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
10 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
11 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
12 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
13 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
14 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
15 */
16 #ifndef __BLOBMSG_H
17 #define __BLOBMSG_H
18
19 #include <stdarg.h>
20 #include "blob.h"
21
22 #define BLOBMSG_ALIGN 2
23 #define BLOBMSG_PADDING(len) (((len) + (1 << BLOBMSG_ALIGN) - 1) & ~((1 << BLOBMSG_ALIGN) - 1))
24
25 enum blobmsg_type {
26 BLOBMSG_TYPE_UNSPEC,
27 BLOBMSG_TYPE_ARRAY,
28 BLOBMSG_TYPE_TABLE,
29 BLOBMSG_TYPE_STRING,
30 BLOBMSG_TYPE_INT64,
31 BLOBMSG_TYPE_INT32,
32 BLOBMSG_TYPE_INT16,
33 BLOBMSG_TYPE_INT8,
34 BLOBMSG_TYPE_DOUBLE,
35 __BLOBMSG_TYPE_LAST,
36 BLOBMSG_TYPE_LAST = __BLOBMSG_TYPE_LAST - 1,
37 BLOBMSG_TYPE_BOOL = BLOBMSG_TYPE_INT8,
38 };
39
40 struct blobmsg_hdr {
41 uint16_t namelen;
42 uint8_t name[];
43 } __packed;
44
45 struct blobmsg_policy {
46 const char *name;
47 enum blobmsg_type type;
48 };
49
50 static inline int blobmsg_hdrlen(unsigned int namelen)
51 {
52 return BLOBMSG_PADDING(sizeof(struct blobmsg_hdr) + namelen + 1);
53 }
54
55 static inline void blobmsg_clear_name(struct blob_attr *attr)
56 {
57 struct blobmsg_hdr *hdr = (struct blobmsg_hdr *) blob_data(attr);
58 hdr->name[0] = 0;
59 }
60
61 static inline const char *blobmsg_name(const struct blob_attr *attr)
62 {
63 struct blobmsg_hdr *hdr = (struct blobmsg_hdr *) blob_data(attr);
64 return (const char *) hdr->name;
65 }
66
67 static inline int blobmsg_type(const struct blob_attr *attr)
68 {
69 return blob_id(attr);
70 }
71
72 static inline void *blobmsg_data(const struct blob_attr *attr)
73 {
74 struct blobmsg_hdr *hdr;
75 char *data;
76
77 if (!attr)
78 return NULL;
79
80 hdr = (struct blobmsg_hdr *) blob_data(attr);
81 data = (char *) blob_data(attr);
82
83 if (blob_is_extended(attr))
84 data += blobmsg_hdrlen(be16_to_cpu(hdr->namelen));
85
86 return data;
87 }
88
89 static inline size_t blobmsg_data_len(const struct blob_attr *attr)
90 {
91 uint8_t *start, *end;
92
93 if (!attr)
94 return 0;
95
96 start = (uint8_t *) blob_data(attr);
97 end = (uint8_t *) blobmsg_data(attr);
98
99 return blob_len(attr) - (end - start);
100 }
101
102 static inline size_t blobmsg_len(const struct blob_attr *attr)
103 {
104 return blobmsg_data_len(attr);
105 }
106
107 /*
108 * blobmsg_check_attr: validate a list of attributes
109 *
110 * This method may be used with trusted data only. Providing
111 * malformed blobs will cause out of bounds memory access.
112 */
113 bool blobmsg_check_attr(const struct blob_attr *attr, bool name);
114
115 /*
116 * blobmsg_check_attr_len: validate a list of attributes
117 *
118 * This method should be safer implementation of blobmsg_check_attr.
119 * It will limit all memory access performed on the blob to the
120 * range [attr, attr + len] (upper bound non inclusive) and is
121 * thus suited for checking of untrusted blob attributes.
122 */
123 bool blobmsg_check_attr_len(const struct blob_attr *attr, bool name, size_t len);
124
125 /*
126 * blobmsg_check_attr_list: validate a list of attributes
127 *
128 * This method may be used with trusted data only. Providing
129 * malformed blobs will cause out of bounds memory access.
130 */
131 bool blobmsg_check_attr_list(const struct blob_attr *attr, int type);
132
133 /*
134 * blobmsg_check_attr_list_len: validate a list of untrusted attributes
135 *
136 * This method should be safer implementation of blobmsg_check_attr_list.
137 * It will limit all memory access performed on the blob to the
138 * range [attr, attr + len] (upper bound non inclusive) and is
139 * thus suited for checking of untrusted blob attributes.
140 */
141 bool blobmsg_check_attr_list_len(const struct blob_attr *attr, int type, size_t len);
142
143 /*
144 * blobmsg_check_array: validate array/table and return size
145 *
146 * Checks if all elements of an array or table are valid and have
147 * the specified type. Returns the number of elements in the array
148 *
149 * This method may be used with trusted data only. Providing
150 * malformed blobs will cause out of bounds memory access.
151 */
152 int blobmsg_check_array(const struct blob_attr *attr, int type);
153
154 /*
155 * blobmsg_check_array_len: validate untrusted array/table and return size
156 *
157 * Checks if all elements of an array or table are valid and have
158 * the specified type. Returns the number of elements in the array.
159 *
160 * This method should be safer implementation of blobmsg_check_array.
161 * It will limit all memory access performed on the blob to the
162 * range [attr, attr + len] (upper bound non inclusive) and is
163 * thus suited for checking of untrusted blob attributes.
164 */
165 int blobmsg_check_array_len(const struct blob_attr *attr, int type, size_t len);
166
167 int blobmsg_parse(const struct blobmsg_policy *policy, int policy_len,
168 struct blob_attr **tb, void *data, unsigned int len);
169 int blobmsg_parse_array(const struct blobmsg_policy *policy, int policy_len,
170 struct blob_attr **tb, void *data, unsigned int len);
171
172 int blobmsg_add_field(struct blob_buf *buf, int type, const char *name,
173 const void *data, unsigned int len);
174
175 static inline int
176 blobmsg_add_double(struct blob_buf *buf, const char *name, double val)
177 {
178 union {
179 double d;
180 uint64_t u64;
181 } v;
182 v.d = val;
183 v.u64 = cpu_to_be64(v.u64);
184 return blobmsg_add_field(buf, BLOBMSG_TYPE_DOUBLE, name, &v.u64, 8);
185 }
186
187 static inline int
188 blobmsg_add_u8(struct blob_buf *buf, const char *name, uint8_t val)
189 {
190 return blobmsg_add_field(buf, BLOBMSG_TYPE_INT8, name, &val, 1);
191 }
192
193 static inline int
194 blobmsg_add_u16(struct blob_buf *buf, const char *name, uint16_t val)
195 {
196 val = cpu_to_be16(val);
197 return blobmsg_add_field(buf, BLOBMSG_TYPE_INT16, name, &val, 2);
198 }
199
200 static inline int
201 blobmsg_add_u32(struct blob_buf *buf, const char *name, uint32_t val)
202 {
203 val = cpu_to_be32(val);
204 return blobmsg_add_field(buf, BLOBMSG_TYPE_INT32, name, &val, 4);
205 }
206
207 static inline int
208 blobmsg_add_u64(struct blob_buf *buf, const char *name, uint64_t val)
209 {
210 val = cpu_to_be64(val);
211 return blobmsg_add_field(buf, BLOBMSG_TYPE_INT64, name, &val, 8);
212 }
213
214 static inline int
215 blobmsg_add_string(struct blob_buf *buf, const char *name, const char *string)
216 {
217 return blobmsg_add_field(buf, BLOBMSG_TYPE_STRING, name, string, strlen(string) + 1);
218 }
219
220 static inline int
221 blobmsg_add_blob(struct blob_buf *buf, struct blob_attr *attr)
222 {
223 return blobmsg_add_field(buf, blobmsg_type(attr), blobmsg_name(attr),
224 blobmsg_data(attr), blobmsg_data_len(attr));
225 }
226
227 void *blobmsg_open_nested(struct blob_buf *buf, const char *name, bool array);
228
229 static inline void *
230 blobmsg_open_array(struct blob_buf *buf, const char *name)
231 {
232 return blobmsg_open_nested(buf, name, true);
233 }
234
235 static inline void *
236 blobmsg_open_table(struct blob_buf *buf, const char *name)
237 {
238 return blobmsg_open_nested(buf, name, false);
239 }
240
241 static inline void
242 blobmsg_close_array(struct blob_buf *buf, void *cookie)
243 {
244 blob_nest_end(buf, cookie);
245 }
246
247 static inline void
248 blobmsg_close_table(struct blob_buf *buf, void *cookie)
249 {
250 blob_nest_end(buf, cookie);
251 }
252
253 static inline int blobmsg_buf_init(struct blob_buf *buf)
254 {
255 return blob_buf_init(buf, BLOBMSG_TYPE_TABLE);
256 }
257
258 static inline uint8_t blobmsg_get_u8(struct blob_attr *attr)
259 {
260 return *(uint8_t *) blobmsg_data(attr);
261 }
262
263 static inline bool blobmsg_get_bool(struct blob_attr *attr)
264 {
265 return *(uint8_t *) blobmsg_data(attr);
266 }
267
268 static inline uint16_t blobmsg_get_u16(struct blob_attr *attr)
269 {
270 return be16_to_cpu(*(uint16_t *) blobmsg_data(attr));
271 }
272
273 static inline uint32_t blobmsg_get_u32(struct blob_attr *attr)
274 {
275 return be32_to_cpu(*(uint32_t *) blobmsg_data(attr));
276 }
277
278 static inline uint64_t blobmsg_get_u64(struct blob_attr *attr)
279 {
280 uint32_t *ptr = (uint32_t *) blobmsg_data(attr);
281 uint64_t tmp = ((uint64_t) be32_to_cpu(ptr[0])) << 32;
282 tmp |= be32_to_cpu(ptr[1]);
283 return tmp;
284 }
285
286 static inline double blobmsg_get_double(struct blob_attr *attr)
287 {
288 union {
289 double d;
290 uint64_t u64;
291 } v;
292 v.u64 = blobmsg_get_u64(attr);
293 return v.d;
294 }
295
296 static inline char *blobmsg_get_string(struct blob_attr *attr)
297 {
298 if (!attr)
299 return NULL;
300
301 return (char *) blobmsg_data(attr);
302 }
303
304 void *blobmsg_alloc_string_buffer(struct blob_buf *buf, const char *name, unsigned int maxlen);
305 void *blobmsg_realloc_string_buffer(struct blob_buf *buf, unsigned int maxlen);
306 void blobmsg_add_string_buffer(struct blob_buf *buf);
307
308 int blobmsg_vprintf(struct blob_buf *buf, const char *name, const char *format, va_list arg);
309 int blobmsg_printf(struct blob_buf *buf, const char *name, const char *format, ...)
310 __attribute__((format(printf, 3, 4)));
311
312
313 /* blobmsg to json formatting */
314
315 #define blobmsg_for_each_attr(pos, attr, rem) \
316 for (rem = attr ? blobmsg_data_len(attr) : 0, \
317 pos = (struct blob_attr *) (attr ? blobmsg_data(attr) : NULL); \
318 rem >= sizeof(struct blob_attr) && (blob_pad_len(pos) <= rem) && \
319 (blob_pad_len(pos) >= sizeof(struct blob_attr)); \
320 rem -= blob_pad_len(pos), pos = blob_next(pos))
321
322 #define __blobmsg_for_each_attr(pos, attr, rem) \
323 for (pos = (struct blob_attr *) (attr ? blobmsg_data(attr) : NULL); \
324 rem >= sizeof(struct blob_attr) && (blob_pad_len(pos) <= rem) && \
325 (blob_pad_len(pos) >= sizeof(struct blob_attr)); \
326 rem -= blob_pad_len(pos), pos = blob_next(pos))
327
328 #endif