Back to home page

EIC code displayed by LXR

 
 

    


Warning, file /include/upb/wire/decode.h was not indexed or was modified since last indexation (in which case cross-reference links may be missing, inaccurate or erroneous).

0001 // Protocol Buffers - Google's data interchange format
0002 // Copyright 2023 Google LLC.  All rights reserved.
0003 //
0004 // Use of this source code is governed by a BSD-style
0005 // license that can be found in the LICENSE file or at
0006 // https://developers.google.com/open-source/licenses/bsd
0007 
0008 // upb_decode: parsing into a upb_Message using a upb_MiniTable.
0009 
0010 #ifndef UPB_WIRE_DECODE_H_
0011 #define UPB_WIRE_DECODE_H_
0012 
0013 #include <stddef.h>
0014 #include <stdint.h>
0015 
0016 #include "upb/mem/arena.h"
0017 #include "upb/message/message.h"
0018 #include "upb/mini_table/extension_registry.h"
0019 #include "upb/mini_table/message.h"
0020 
0021 // Must be last.
0022 #include "upb/port/def.inc"
0023 
0024 #ifdef __cplusplus
0025 extern "C" {
0026 #endif
0027 
0028 // LINT.IfChange
0029 enum {
0030   /* If set, strings and unknown fields will alias the input buffer instead of
0031    * copying into the arena. */
0032   kUpb_DecodeOption_AliasString = 1,
0033 
0034   /* If set, the parse will return failure if any message is missing any
0035    * required fields when the message data ends.  The parse will still continue,
0036    * and the failure will only be reported at the end.
0037    *
0038    * IMPORTANT CAVEATS:
0039    *
0040    * 1. This can throw a false positive failure if an incomplete message is seen
0041    *    on the wire but is later completed when the sub-message occurs again.
0042    *    For this reason, a second pass is required to verify a failure, to be
0043    *    truly robust.
0044    *
0045    * 2. This can return a false success if you are decoding into a message that
0046    *    already has some sub-message fields present.  If the sub-message does
0047    *    not occur in the binary payload, we will never visit it and discover the
0048    *    incomplete sub-message.  For this reason, this check is only useful for
0049    *    implementing ParseFromString() semantics.  For MergeFromString(), a
0050    *    post-parse validation step will always be necessary. */
0051   kUpb_DecodeOption_CheckRequired = 2,
0052 
0053   /* EXPERIMENTAL:
0054    *
0055    * If set, the parser will allow parsing of sub-message fields that were not
0056    * previously linked using upb_MiniTable_SetSubMessage().  The data will be
0057    * parsed into an internal "empty" message type that cannot be accessed
0058    * directly, but can be later promoted into the true message type if the
0059    * sub-message fields are linked at a later time.
0060    *
0061    * Users should set this option if they intend to perform dynamic tree shaking
0062    * and promoting using the interfaces in message/promote.h.  If this option is
0063    * enabled, it is important that the resulting messages are only accessed by
0064    * code that is aware of promotion rules:
0065    *
0066    * 1. Message pointers in upb_Message, upb_Array, and upb_Map are represented
0067    *    by a tagged pointer upb_TaggedMessagePointer.  The tag indicates whether
0068    *    the message uses the internal "empty" type.
0069    *
0070    * 2. Any code *reading* these message pointers must test whether the "empty"
0071    *    tag bit is set, using the interfaces in mini_table/types.h.  However
0072    *    writing of message pointers should always use plain upb_Message*, since
0073    *    users are not allowed to create "empty" messages.
0074    *
0075    * 3. It is always safe to test whether a field is present or test the array
0076    *    length; these interfaces will reflect that empty messages are present,
0077    *    even though their data cannot be accessed without promoting first.
0078    *
0079    * 4. If a message pointer is indeed tagged as empty, the message may not be
0080    *    accessed directly, only promoted through the interfaces in
0081    *    message/promote.h.
0082    *
0083    * 5. Tagged/empty messages may never be created by the user.  They may only
0084    *    be created by the parser or the message-copying logic in message/copy.h.
0085    */
0086   kUpb_DecodeOption_ExperimentalAllowUnlinked = 4,
0087 
0088   /* EXPERIMENTAL:
0089    *
0090    * If set, decoding will enforce UTF-8 validation for string fields, even for
0091    * proto2 or fields with `features.utf8_validation = NONE`. Normally, only
0092    * proto3 string fields will be validated for UTF-8. Decoding will return
0093    * kUpb_DecodeStatus_BadUtf8 for non-UTF-8 strings, which is the same behavior
0094    * as non-UTF-8 proto3 string fields.
0095    */
0096   kUpb_DecodeOption_AlwaysValidateUtf8 = 8,
0097 
0098   /* EXPERIMENTAL:
0099    *
0100    * If set, the fasttable decoder will not be used. */
0101   kUpb_DecodeOption_DisableFastTable = 16,
0102 };
0103 // LINT.ThenChange(//depot/google3/third_party/protobuf/rust/upb.rs:decode_status)
0104 
0105 UPB_INLINE uint32_t upb_DecodeOptions_MaxDepth(uint16_t depth) {
0106   return (uint32_t)depth << 16;
0107 }
0108 
0109 uint16_t upb_DecodeOptions_GetEffectiveMaxDepth(uint32_t options);
0110 
0111 // Enforce an upper bound on recursion depth.
0112 UPB_INLINE int upb_Decode_LimitDepth(uint32_t decode_options, uint32_t limit) {
0113   uint32_t max_depth = upb_DecodeOptions_GetEffectiveMaxDepth(decode_options);
0114   if (max_depth > limit) max_depth = limit;
0115   return upb_DecodeOptions_MaxDepth(max_depth) | (decode_options & 0xffff);
0116 }
0117 
0118 // LINT.IfChange
0119 typedef enum {
0120   kUpb_DecodeStatus_Ok = 0,
0121   kUpb_DecodeStatus_Malformed = 1,    // Wire format was corrupt
0122   kUpb_DecodeStatus_OutOfMemory = 2,  // Arena alloc failed
0123   kUpb_DecodeStatus_BadUtf8 = 3,      // String field had bad UTF-8
0124   kUpb_DecodeStatus_MaxDepthExceeded =
0125       4,  // Exceeded upb_DecodeOptions_MaxDepth
0126 
0127   // kUpb_DecodeOption_CheckRequired failed (see above), but the parse otherwise
0128   // succeeded.
0129   kUpb_DecodeStatus_MissingRequired = 5,
0130 
0131   // Unlinked sub-message field was present, but
0132   // kUpb_DecodeOptions_ExperimentalAllowUnlinked was not specified in the list
0133   // of options.
0134   kUpb_DecodeStatus_UnlinkedSubMessage = 6,
0135 } upb_DecodeStatus;
0136 // LINT.ThenChange(//depot/google3/third_party/protobuf/rust/upb.rs:decode_status)
0137 
0138 UPB_API upb_DecodeStatus upb_Decode(const char* buf, size_t size,
0139                                     upb_Message* msg, const upb_MiniTable* mt,
0140                                     const upb_ExtensionRegistry* extreg,
0141                                     int options, upb_Arena* arena);
0142 
0143 // Same as upb_Decode but with a varint-encoded length prepended.
0144 // On success 'num_bytes_read' will be set to the how many bytes were read,
0145 // on failure the contents of num_bytes_read is undefined.
0146 UPB_API upb_DecodeStatus upb_DecodeLengthPrefixed(
0147     const char* buf, size_t size, upb_Message* msg, size_t* num_bytes_read,
0148     const upb_MiniTable* mt, const upb_ExtensionRegistry* extreg, int options,
0149     upb_Arena* arena);
0150 
0151 // For testing: decode with tracing.
0152 UPB_API upb_DecodeStatus upb_DecodeWithTrace(
0153     const char* buf, size_t size, upb_Message* msg, const upb_MiniTable* mt,
0154     const upb_ExtensionRegistry* extreg, int options, upb_Arena* arena,
0155     char* trace_buf, size_t trace_size);
0156 
0157 // Utility function for wrapper languages to get an error string from a
0158 // upb_DecodeStatus.
0159 UPB_API const char* upb_DecodeStatus_String(upb_DecodeStatus status);
0160 #ifdef __cplusplus
0161 } /* extern "C" */
0162 #endif
0163 
0164 #include "upb/port/undef.inc"
0165 
0166 #endif /* UPB_WIRE_DECODE_H_ */