Commit 1908b5f0 authored by Jeremy Hannon's avatar Jeremy Hannon Committed by Reini Urban
Browse files

Return ESNOSPC for `(smax > dmax)` overflow check.

The following two error codes are defined in safe_lib_errno.h:
ESLEMAX - "length exceeds max"
ESNOSPC - "not enough space for s2"

However, we saw in the code that ESLEMAX error code was being returned for
cases where both `if (dmax > RSIZE_MAX_MEM)` and `if (smax > dmax)`.  The
first is an invalid input condition always and the second is an invalid
input condition dependent on whether there is enough space in the
destination buffer for the source data.  Therefore we think that the second
error condition should use error code ESNOSPC instead of ESLEMAX.

The reason we discovered this discrepancy is that we are trying to provide a
common C11AnnexK wrapper interface in our code, allowing use of
compiler-specific implementations by Microsoft, IAR, and Renesas, while
using this library for GCC.  However, we need to normalize the error codes
returned and the other libraries use only error codes EINVAL(22) and
ERANGE(34) instead of the more targeted error codes used by safeclib.

GNU defines EINVAL as "“Invalid argument.” This is used to indicate various
kinds of problems with passing the wrong argument to a library function."
GNU defines ERANGE as "“Numerical result out of range.” Used by mathematical
functions when the result value is not representable because of overflow or
underflow."

In our usage of safeclib we overwrite each error code in safe_lib_errno.h to
map to either EINVAL or ERANGE.  However, ESLEMAX causes problems because it
is used for both situations in the code.  Therefore we are proposing that
ESNOSPC 'no space' is more appropriate for the ERANGE situtations where
there's a possible overflow condition, and suggest a definition
clarification in safe_lib_errno.h that ESLEMAX is "length exceeds
RSIZE_MAX".  I know that safelib uses string- and memory-specific RSIZE_MAX
variables so we could be more exact and list those, but I thought this
description was acceptable and succinct.

The changes in this commit were co-authored with Arjun Gour, my coworker,
who has approved of submitting his work back to this open source library.
parent aef2b934
Supports Markdown
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment