1*64c3fdb4Szrj /* $OpenBSD: recallocarray.c,v 1.1 2017/03/06 18:44:21 otto Exp $ */
2*64c3fdb4Szrj /*
3*64c3fdb4Szrj * Copyright (c) 2008, 2017 Otto Moerbeek <otto@drijf.net>
4*64c3fdb4Szrj *
5*64c3fdb4Szrj * Permission to use, copy, modify, and distribute this software for any
6*64c3fdb4Szrj * purpose with or without fee is hereby granted, provided that the above
7*64c3fdb4Szrj * copyright notice and this permission notice appear in all copies.
8*64c3fdb4Szrj *
9*64c3fdb4Szrj * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
10*64c3fdb4Szrj * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
11*64c3fdb4Szrj * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
12*64c3fdb4Szrj * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
13*64c3fdb4Szrj * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
14*64c3fdb4Szrj * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
15*64c3fdb4Szrj * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
16*64c3fdb4Szrj */
17*64c3fdb4Szrj
18*64c3fdb4Szrj #include <errno.h>
19*64c3fdb4Szrj #include <stdlib.h>
20*64c3fdb4Szrj #include <stdint.h>
21*64c3fdb4Szrj #include <string.h>
22*64c3fdb4Szrj #include <unistd.h>
23*64c3fdb4Szrj
24*64c3fdb4Szrj /*
25*64c3fdb4Szrj * This is sqrt(SIZE_MAX+1), as s1*s2 <= SIZE_MAX
26*64c3fdb4Szrj * if both s1 < MUL_NO_OVERFLOW and s2 < MUL_NO_OVERFLOW
27*64c3fdb4Szrj */
28*64c3fdb4Szrj #define MUL_NO_OVERFLOW ((size_t)1 << (sizeof(size_t) * 4))
29*64c3fdb4Szrj
30*64c3fdb4Szrj void *
recallocarray(void * ptr,size_t oldnmemb,size_t newnmemb,size_t size)31*64c3fdb4Szrj recallocarray(void *ptr, size_t oldnmemb, size_t newnmemb, size_t size)
32*64c3fdb4Szrj {
33*64c3fdb4Szrj size_t oldsize, newsize;
34*64c3fdb4Szrj void *newptr;
35*64c3fdb4Szrj
36*64c3fdb4Szrj if (ptr == NULL)
37*64c3fdb4Szrj return calloc(newnmemb, size);
38*64c3fdb4Szrj
39*64c3fdb4Szrj if ((newnmemb >= MUL_NO_OVERFLOW || size >= MUL_NO_OVERFLOW) &&
40*64c3fdb4Szrj newnmemb > 0 && SIZE_MAX / newnmemb < size) {
41*64c3fdb4Szrj errno = ENOMEM;
42*64c3fdb4Szrj return NULL;
43*64c3fdb4Szrj }
44*64c3fdb4Szrj newsize = newnmemb * size;
45*64c3fdb4Szrj
46*64c3fdb4Szrj if ((oldnmemb >= MUL_NO_OVERFLOW || size >= MUL_NO_OVERFLOW) &&
47*64c3fdb4Szrj oldnmemb > 0 && SIZE_MAX / oldnmemb < size) {
48*64c3fdb4Szrj errno = EINVAL;
49*64c3fdb4Szrj return NULL;
50*64c3fdb4Szrj }
51*64c3fdb4Szrj oldsize = oldnmemb * size;
52*64c3fdb4Szrj
53*64c3fdb4Szrj /*
54*64c3fdb4Szrj * Don't bother too much if we're shrinking just a bit,
55*64c3fdb4Szrj * we do not shrink for series of small steps, oh well.
56*64c3fdb4Szrj */
57*64c3fdb4Szrj if (newsize <= oldsize) {
58*64c3fdb4Szrj size_t d = oldsize - newsize;
59*64c3fdb4Szrj
60*64c3fdb4Szrj if (d < oldsize / 2 && d < (size_t)getpagesize()) {
61*64c3fdb4Szrj memset((char *)ptr + newsize, 0, d);
62*64c3fdb4Szrj return ptr;
63*64c3fdb4Szrj }
64*64c3fdb4Szrj }
65*64c3fdb4Szrj
66*64c3fdb4Szrj newptr = malloc(newsize);
67*64c3fdb4Szrj if (newptr == NULL)
68*64c3fdb4Szrj return NULL;
69*64c3fdb4Szrj
70*64c3fdb4Szrj if (newsize > oldsize) {
71*64c3fdb4Szrj memcpy(newptr, ptr, oldsize);
72*64c3fdb4Szrj memset((char *)newptr + oldsize, 0, newsize - oldsize);
73*64c3fdb4Szrj } else
74*64c3fdb4Szrj memcpy(newptr, ptr, newsize);
75*64c3fdb4Szrj
76*64c3fdb4Szrj explicit_bzero(ptr, oldsize);
77*64c3fdb4Szrj free(ptr);
78*64c3fdb4Szrj
79*64c3fdb4Szrj return newptr;
80*64c3fdb4Szrj }
81