Ruby 3.5.0dev (2025-02-20 revision 34098b669c0cbc024cd08e686891f1dfe0a10aaf)
memory.h
Go to the documentation of this file.
1#ifndef RBIMPL_MEMORY_H /*-*-C++-*-vi:se ft=cpp:*/
2#define RBIMPL_MEMORY_H
23#include "ruby/internal/config.h"
24
25#ifdef STDC_HEADERS
26# include <stddef.h>
27#endif
28
29#ifdef HAVE_STRING_H
30# include <string.h>
31#endif
32
33#ifdef HAVE_STDINT_H
34# include <stdint.h>
35#endif
36
37#ifdef HAVE_ALLOCA_H
38# include <alloca.h>
39#endif
40
41#if defined(_MSC_VER) && defined(_WIN64)
42# include <intrin.h>
43# if defined(_M_AMD64)
44# pragma intrinsic(_umul128)
45# endif
46# if defined(_M_ARM64)
47# pragma intrinsic(__umulh)
48# endif
49#endif
50
59#include "ruby/internal/cast.h"
64#include "ruby/internal/stdckdint.h"
66#include "ruby/backward/2/limits.h"
69#include "ruby/defines.h"
70
73/* Make alloca work the best possible way. */
74#if defined(alloca)
75# /* Take that. */
76#elif RBIMPL_HAS_BUILTIN(__builtin_alloca)
77# define alloca __builtin_alloca
78#elif defined(_AIX)
79# pragma alloca
80#elif defined(__cplusplus)
81extern "C" void *alloca(size_t);
82#else
83extern void *alloca();
84#endif
85
88#if defined(__DOXYGEN__)
96typedef uint128_t DSIZE_T;
97#elif defined(HAVE_INT128_T) && SIZEOF_SIZE_T <= 8
98# define DSIZE_T uint128_t
99#elif SIZEOF_SIZE_T * 2 <= SIZEOF_LONG_LONG
100# define DSIZE_T unsigned LONG_LONG
101#endif
102
110#ifdef C_ALLOCA
111# define RUBY_ALLOCV_LIMIT 0
112#else
113# define RUBY_ALLOCV_LIMIT 1024
114#endif
115
166#ifdef __GNUC__
167#define RB_GC_GUARD(v) \
168 (*__extension__ ({ \
169 volatile VALUE *rb_gc_guarded_ptr = &(v); \
170 __asm__("" : : "m"(rb_gc_guarded_ptr)); \
171 rb_gc_guarded_ptr; \
172 }))
173#elif defined _MSC_VER
174#define RB_GC_GUARD(v) (*rb_gc_guarded_ptr(&(v)))
175#else
176#define HAVE_RB_GC_GUARDED_PTR_VAL 1
177#define RB_GC_GUARD(v) (*rb_gc_guarded_ptr_val(&(v),(v)))
178#endif
179
180/* Casts needed because void* is NOT compatible with others in C++. */
181
199#define RB_ALLOC_N(type,n) RBIMPL_CAST((type *)ruby_xmalloc2((n), sizeof(type)))
200
213#define RB_ALLOC(type) RBIMPL_CAST((type *)ruby_xmalloc(sizeof(type)))
214
234#define RB_ZALLOC_N(type,n) RBIMPL_CAST((type *)ruby_xcalloc((n), sizeof(type)))
235
249#define RB_ZALLOC(type) (RB_ZALLOC_N(type, 1))
250
282#define RB_REALLOC_N(var,type,n) \
283 ((var) = RBIMPL_CAST((type *)ruby_xrealloc2((void *)(var), (n), sizeof(type))))
284
292#define ALLOCA_N(type,n) \
293 RBIMPL_CAST((type *)alloca(rbimpl_size_mul_or_raise(sizeof(type), (n))))
294
304#define RB_ALLOCV(v, n) \
305 ((n) < RUBY_ALLOCV_LIMIT ? \
306 ((v) = 0, alloca(n)) : \
307 rb_alloc_tmp_buffer(&(v), (n)))
308
336#define RB_ALLOCV_N(type, v, n) \
337 RBIMPL_CAST((type *) \
338 (((size_t)(n) < RUBY_ALLOCV_LIMIT / sizeof(type)) ? \
339 ((v) = 0, alloca((n) * sizeof(type))) : \
340 rb_alloc_tmp_buffer2(&(v), (n), sizeof(type))))
341
349#define RB_ALLOCV_END(v) rb_free_tmp_buffer(&(v))
350
360#define MEMZERO(p,type,n) memset((p), 0, rbimpl_size_mul_or_raise(sizeof(type), (n)))
361
372#define MEMCPY(p1,p2,type,n) ruby_nonempty_memcpy((p1), (p2), rbimpl_size_mul_or_raise(sizeof(type), (n)))
373
384#define MEMMOVE(p1,p2,type,n) memmove((p1), (p2), rbimpl_size_mul_or_raise(sizeof(type), (n)))
385
397#define MEMCMP(p1,p2,type,n) memcmp((p1), (p2), rbimpl_size_mul_or_raise(sizeof(type), (n)))
398
399#define ALLOC_N RB_ALLOC_N
400#define ALLOC RB_ALLOC
401#define ZALLOC_N RB_ZALLOC_N
402#define ZALLOC RB_ZALLOC
403#define REALLOC_N RB_REALLOC_N
404#define ALLOCV RB_ALLOCV
405#define ALLOCV_N RB_ALLOCV_N
406#define ALLOCV_END RB_ALLOCV_END
419struct rbimpl_size_mul_overflow_tag {
420 bool left;
421 size_t right;
422};
423
440void *rb_alloc_tmp_buffer(volatile VALUE *store, long len);
441
463void *rb_alloc_tmp_buffer_with_count(volatile VALUE *store, size_t len,size_t count);
464
476void rb_free_tmp_buffer(volatile VALUE *store);
477
489void ruby_malloc_size_overflow(size_t x, size_t y);
490
501void ruby_malloc_add_size_overflow(size_t x, size_t y);
502
503#ifdef HAVE_RB_GC_GUARDED_PTR_VAL
504volatile VALUE *rb_gc_guarded_ptr_val(volatile VALUE *ptr, VALUE val);
505#endif
507
508#ifdef _MSC_VER
509# pragma optimize("", off)
510
520static inline volatile VALUE *
521rb_gc_guarded_ptr(volatile VALUE *ptr)
522{
523 return ptr;
524}
525
526# pragma optimize("", on)
527#endif
528
542static inline int
543rb_mul_size_overflow(size_t a, size_t b, size_t max, size_t *c)
544{
545#ifdef DSIZE_T
546 RB_GNUC_EXTENSION DSIZE_T da, db, c2;
547 da = a;
548 db = b;
549 c2 = da * db;
550 if (c2 > max) return 1;
551 *c = RBIMPL_CAST((size_t)c2);
552#else
553 if (b != 0 && a > max / b) return 1;
554 *c = a * b;
555#endif
556 return 0;
557}
558
559#if defined(__DOXYGEN__)
561#elif RBIMPL_COMPILER_SINCE(GCC, 7, 0, 0)
562RBIMPL_ATTR_CONSTEXPR(CXX14) /* https://gcc.gnu.org/bugzilla/show_bug.cgi?id=70507 */
563#elif RBIMPL_COMPILER_SINCE(Clang, 7, 0, 0)
564RBIMPL_ATTR_CONSTEXPR(CXX14) /* https://bugs.llvm.org/show_bug.cgi?id=37633 */
565#endif
583static inline struct rbimpl_size_mul_overflow_tag
584rbimpl_size_mul_overflow(size_t x, size_t y)
585{
586 struct rbimpl_size_mul_overflow_tag ret = { false, 0, };
587
588#if defined(ckd_mul)
589 ret.left = ckd_mul(&ret.right, x, y);
590
591#elif RBIMPL_HAS_BUILTIN(__builtin_mul_overflow)
592 ret.left = __builtin_mul_overflow(x, y, &ret.right);
593
594#elif defined(DSIZE_T)
595 RB_GNUC_EXTENSION DSIZE_T dx = x;
596 RB_GNUC_EXTENSION DSIZE_T dy = y;
597 RB_GNUC_EXTENSION DSIZE_T dz = dx * dy;
598 ret.left = dz > SIZE_MAX;
599 ret.right = RBIMPL_CAST((size_t)dz);
600
601#elif defined(_MSC_VER) && defined(_M_AMD64)
602 unsigned __int64 dp = 0;
603 unsigned __int64 dz = _umul128(x, y, &dp);
604 ret.left = RBIMPL_CAST((bool)dp);
605 ret.right = RBIMPL_CAST((size_t)dz);
606
607#elif defined(_MSC_VER) && defined(_M_ARM64)
608 ret.left = __umulh(x, y) != 0;
609 ret.right = x * y;
610
611#else
612 /* https://wiki.sei.cmu.edu/confluence/display/c/INT30-C.+Ensure+that+unsigned+integer+operations+do+not+wrap */
613 ret.left = (y != 0) && (x > SIZE_MAX / y);
614 ret.right = x * y;
615#endif
616
617 return ret;
618}
619
635static inline size_t
636rbimpl_size_mul_or_raise(size_t x, size_t y)
637{
638 struct rbimpl_size_mul_overflow_tag size =
639 rbimpl_size_mul_overflow(x, y);
640
641 if (RB_LIKELY(! size.left)) {
642 return size.right;
643 }
644 else {
645 ruby_malloc_size_overflow(x, y);
647 }
648}
649
650#if defined(__DOXYGEN__)
652#elif RBIMPL_COMPILER_SINCE(GCC, 7, 0, 0)
653RBIMPL_ATTR_CONSTEXPR(CXX14) /* https://gcc.gnu.org/bugzilla/show_bug.cgi?id=70507 */
654#elif RBIMPL_COMPILER_SINCE(Clang, 7, 0, 0)
655RBIMPL_ATTR_CONSTEXPR(CXX14) /* https://bugs.llvm.org/show_bug.cgi?id=37633 */
656#endif
671static inline struct rbimpl_size_mul_overflow_tag
672rbimpl_size_add_overflow(size_t x, size_t y)
673{
674 struct rbimpl_size_mul_overflow_tag ret = { false, 0, };
675
676#if defined(ckd_add)
677 ret.left = ckd_add(&ret.right, x, y);
678
679#elif RBIMPL_HAS_BUILTIN(__builtin_add_overflow)
680 ret.left = __builtin_add_overflow(x, y, &ret.right);
681
682#elif defined(DSIZE_T)
683 RB_GNUC_EXTENSION DSIZE_T dx = x;
684 RB_GNUC_EXTENSION DSIZE_T dy = y;
685 RB_GNUC_EXTENSION DSIZE_T dz = dx + dy;
686 ret.left = dz > SIZE_MAX;
687 ret.right = (size_t)dz;
688
689#else
690 ret.right = x + y;
691 ret.left = ret.right < y;
692
693#endif
694
695 return ret;
696}
697
710static inline size_t
711rbimpl_size_add_or_raise(size_t x, size_t y)
712{
713 struct rbimpl_size_mul_overflow_tag size =
714 rbimpl_size_add_overflow(x, y);
715
716 if (RB_LIKELY(!size.left)) {
717 return size.right;
718 }
719 else {
720 ruby_malloc_add_size_overflow(x, y);
722 }
723}
724
739static inline void *
740rb_alloc_tmp_buffer2(volatile VALUE *store, long count, size_t elsize)
741{
742 const size_t total_size = rbimpl_size_mul_or_raise(RBIMPL_CAST((size_t)count), elsize);
743 const size_t cnt = (total_size + sizeof(VALUE) - 1) / sizeof(VALUE);
744 return rb_alloc_tmp_buffer_with_count(store, total_size, cnt);
745}
746
751/* At least since 2004, glibc's <string.h> annotates memcpy to be
752 * __attribute__((__nonnull__(1, 2))). However it is safe to pass NULL to the
753 * source pointer, if n is 0. Let's wrap memcpy. */
754static inline void *
755ruby_nonempty_memcpy(void *dest, const void *src, size_t n)
756{
757 if (n) {
758 return memcpy(dest, src, n);
759 }
760 else {
761 return dest;
762 }
763}
765
766#endif /* RBIMPL_MEMORY_H */
Defines RBIMPL_ATTR_ALLOC_SIZE.
#define RBIMPL_ATTR_ALLOC_SIZE(tuple)
Wraps (or simulates) __attribute__((alloc_size))
Definition alloc_size.h:29
Defines ASSUME / RB_LIKELY / UNREACHABLE.
Defines old LONG_LONG.
Defines RBIMPL_ATTR_CONST.
#define RBIMPL_ATTR_CONST()
Wraps (or simulates) __attribute__((const))
Definition const.h:36
RBIMPL_ATTR_CONSTEXPR.
#define RBIMPL_ATTR_CONSTEXPR(_)
Wraps (or simulates) C++11 constexpr.
Definition constexpr.h:74
Tweaking visibility of C variables/functions.
#define RBIMPL_SYMBOL_EXPORT_END()
Counterpart of RBIMPL_SYMBOL_EXPORT_BEGIN.
Definition dllexport.h:74
#define RBIMPL_SYMBOL_EXPORT_BEGIN()
Shortcut macro equivalent to RUBY_SYMBOL_EXPORT_BEGIN extern "C" {.
Definition dllexport.h:65
#define RB_GNUC_EXTENSION
This is expanded to nothing for non-GCC compilers.
Definition defines.h:89
Defines RBIMPL_HAS_BUILTIN.
int len
Length of the buffer.
Definition io.h:8
#define RBIMPL_UNREACHABLE_RETURN(_)
Wraps (or simulates) __builtin_unreachable.
Definition assume.h:48
Defines RBIMPL_ALIGNAS / RBIMPL_ALIGNOF.
static void * rb_alloc_tmp_buffer2(volatile VALUE *store, long count, size_t elsize)
This is an implementation detail of RB_ALLOCV_N().
Definition memory.h:740
static int rb_mul_size_overflow(size_t a, size_t b, size_t max, size_t *c)
Definition memory.h:543
Defines RBIMPL_ATTR_NOALIAS.
#define RBIMPL_ATTR_NOALIAS()
Wraps (or simulates) __declspec((noalias))
Definition noalias.h:66
Defines RBIMPL_ATTR_NONNULL.
#define RBIMPL_ATTR_NONNULL(list)
Wraps (or simulates) __attribute__((nonnull))
Definition nonnull.h:30
Defines RBIMPL_ATTR_NORETURN.
#define RBIMPL_ATTR_NORETURN()
Wraps (or simulates) [[noreturn]]
Definition noreturn.h:38
#define inline
Old Visual Studio versions do not support the inline keyword, so we need to define it to be __inline.
Definition defines.h:91
Defines RBIMPL_ATTR_RESTRICT.
#define RBIMPL_ATTR_RESTRICT()
Wraps (or simulates) __declspec(restrict)
Definition restrict.h:41
Defines RBIMPL_ATTR_RETURNS_NONNULL.
#define RBIMPL_ATTR_RETURNS_NONNULL()
Wraps (or simulates) __attribute__((returns_nonnull))
C99 shim for <stdbool.h>
uintptr_t VALUE
Type that represents a Ruby object.
Definition value.h:40
Declares ruby_xmalloc().