stdio2.h 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404
  1. /* Checking macros for stdio functions.
  2. Copyright (C) 2004-2026 Free Software Foundation, Inc.
  3. This file is part of the GNU C Library.
  4. The GNU C Library is free software; you can redistribute it and/or
  5. modify it under the terms of the GNU Lesser General Public
  6. License as published by the Free Software Foundation; either
  7. version 2.1 of the License, or (at your option) any later version.
  8. The GNU C Library is distributed in the hope that it will be useful,
  9. but WITHOUT ANY WARRANTY; without even the implied warranty of
  10. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  11. Lesser General Public License for more details.
  12. You should have received a copy of the GNU Lesser General Public
  13. License along with the GNU C Library; if not, see
  14. <https://www.gnu.org/licenses/>. */
  15. #ifndef _BITS_STDIO2_H
  16. #define _BITS_STDIO2_H 1
  17. #ifndef _STDIO_H
  18. # error "Never include <bits/stdio2.h> directly; use <stdio.h> instead."
  19. #endif
  20. #ifdef __va_arg_pack
  21. __fortify_function int
  22. __NTH (sprintf (char *__restrict __s, const char *__restrict __fmt, ...))
  23. {
  24. return __builtin___sprintf_chk (__s, __USE_FORTIFY_LEVEL - 1,
  25. __glibc_objsize (__s), __fmt,
  26. __va_arg_pack ());
  27. }
  28. #elif __fortify_use_clang
  29. /* clang does not have __va_arg_pack, so defer to va_arg version. */
  30. __fortify_function_error_function __attribute_overloadable__ int
  31. __NTH (sprintf (__fortify_clang_overload_arg (char *, __restrict, __s),
  32. const char *__restrict __fmt, ...))
  33. {
  34. __gnuc_va_list __fortify_ap;
  35. __builtin_va_start (__fortify_ap, __fmt);
  36. int __r = __builtin___vsprintf_chk (__s, __USE_FORTIFY_LEVEL - 1,
  37. __glibc_objsize (__s), __fmt,
  38. __fortify_ap);
  39. __builtin_va_end (__fortify_ap);
  40. return __r;
  41. }
  42. #elif !defined __cplusplus
  43. # define sprintf(str, ...) \
  44. __builtin___sprintf_chk (str, __USE_FORTIFY_LEVEL - 1, \
  45. __glibc_objsize (str), __VA_ARGS__)
  46. #endif
  47. __fortify_function __attribute_overloadable__ int
  48. __NTH (vsprintf (__fortify_clang_overload_arg (char *, __restrict, __s),
  49. const char *__restrict __fmt, __gnuc_va_list __ap))
  50. {
  51. return __builtin___vsprintf_chk (__s, __USE_FORTIFY_LEVEL - 1,
  52. __glibc_objsize (__s), __fmt, __ap);
  53. }
  54. #if defined __USE_ISOC99 || defined __USE_UNIX98
  55. # ifdef __va_arg_pack
  56. __fortify_function int
  57. __NTH (snprintf (char *__restrict __s, size_t __n,
  58. const char *__restrict __fmt, ...))
  59. {
  60. return __builtin___snprintf_chk (__s, __n, __USE_FORTIFY_LEVEL - 1,
  61. __glibc_objsize (__s), __fmt,
  62. __va_arg_pack ());
  63. }
  64. # elif __fortify_use_clang
  65. /* clang does not have __va_arg_pack, so defer to va_arg version. */
  66. __fortify_function_error_function __attribute_overloadable__ int
  67. __NTH (snprintf (__fortify_clang_overload_arg (char *, __restrict, __s),
  68. size_t __n, const char *__restrict __fmt, ...))
  69. {
  70. __gnuc_va_list __fortify_ap;
  71. __builtin_va_start (__fortify_ap, __fmt);
  72. int __r = __builtin___vsnprintf_chk (__s, __n, __USE_FORTIFY_LEVEL - 1,
  73. __glibc_objsize (__s), __fmt,
  74. __fortify_ap);
  75. __builtin_va_end (__fortify_ap);
  76. return __r;
  77. }
  78. # elif !defined __cplusplus
  79. # define snprintf(str, len, ...) \
  80. __builtin___snprintf_chk (str, len, __USE_FORTIFY_LEVEL - 1, \
  81. __glibc_objsize (str), __VA_ARGS__)
  82. # endif
  83. __fortify_function __attribute_overloadable__ int
  84. __NTH (vsnprintf (__fortify_clang_overload_arg (char *, __restrict, __s),
  85. size_t __n, const char *__restrict __fmt,
  86. __gnuc_va_list __ap))
  87. __fortify_clang_warning (__fortify_clang_bos_static_lt (__n, __s),
  88. "call to vsnprintf may overflow the destination "
  89. "buffer")
  90. {
  91. return __builtin___vsnprintf_chk (__s, __n, __USE_FORTIFY_LEVEL - 1,
  92. __glibc_objsize (__s), __fmt, __ap);
  93. }
  94. #endif
  95. #if __USE_FORTIFY_LEVEL > 1
  96. # ifdef __va_arg_pack
  97. __fortify_function __nonnull ((1)) int
  98. fprintf (FILE *__restrict __stream, const char *__restrict __fmt, ...)
  99. {
  100. return __fprintf_chk (__stream, __USE_FORTIFY_LEVEL - 1, __fmt,
  101. __va_arg_pack ());
  102. }
  103. __fortify_function int
  104. printf (const char *__restrict __fmt, ...)
  105. {
  106. return __printf_chk (__USE_FORTIFY_LEVEL - 1, __fmt, __va_arg_pack ());
  107. }
  108. # elif __fortify_use_clang
  109. /* clang does not have __va_arg_pack, so defer to va_arg version. */
  110. __fortify_function_error_function __attribute_overloadable__ __nonnull ((1)) int
  111. fprintf (__fortify_clang_overload_arg (FILE *, __restrict, __stream),
  112. const char *__restrict __fmt, ...)
  113. {
  114. __gnuc_va_list __fortify_ap;
  115. __builtin_va_start (__fortify_ap, __fmt);
  116. int __r = __builtin___vfprintf_chk (__stream, __USE_FORTIFY_LEVEL - 1,
  117. __fmt, __fortify_ap);
  118. __builtin_va_end (__fortify_ap);
  119. return __r;
  120. }
  121. __fortify_function_error_function __attribute_overloadable__ int
  122. printf (__fortify_clang_overload_arg (const char *, __restrict, __fmt), ...)
  123. {
  124. __gnuc_va_list __fortify_ap;
  125. __builtin_va_start (__fortify_ap, __fmt);
  126. int __r = __builtin___vprintf_chk (__USE_FORTIFY_LEVEL - 1, __fmt,
  127. __fortify_ap);
  128. __builtin_va_end (__fortify_ap);
  129. return __r;
  130. }
  131. # elif !defined __cplusplus
  132. # define printf(...) \
  133. __printf_chk (__USE_FORTIFY_LEVEL - 1, __VA_ARGS__)
  134. # define fprintf(stream, ...) \
  135. __fprintf_chk (stream, __USE_FORTIFY_LEVEL - 1, __VA_ARGS__)
  136. # endif
  137. __fortify_function __attribute_overloadable__ int
  138. vprintf (__fortify_clang_overload_arg (const char *, __restrict, __fmt),
  139. __gnuc_va_list __ap)
  140. {
  141. #ifdef __USE_EXTERN_INLINES
  142. return __vfprintf_chk (stdout, __USE_FORTIFY_LEVEL - 1, __fmt, __ap);
  143. #else
  144. return __vprintf_chk (__USE_FORTIFY_LEVEL - 1, __fmt, __ap);
  145. #endif
  146. }
  147. __fortify_function __nonnull ((1)) int
  148. vfprintf (FILE *__restrict __stream,
  149. const char *__restrict __fmt, __gnuc_va_list __ap)
  150. {
  151. return __vfprintf_chk (__stream, __USE_FORTIFY_LEVEL - 1, __fmt, __ap);
  152. }
  153. # ifdef __USE_XOPEN2K8
  154. # ifdef __va_arg_pack
  155. __fortify_function int
  156. dprintf (int __fd, const char *__restrict __fmt, ...)
  157. {
  158. return __dprintf_chk (__fd, __USE_FORTIFY_LEVEL - 1, __fmt,
  159. __va_arg_pack ());
  160. }
  161. # elif __fortify_use_clang
  162. __fortify_function_error_function __attribute_overloadable__ int
  163. dprintf (int __fd, __fortify_clang_overload_arg (const char *, __restrict,
  164. __fmt), ...)
  165. {
  166. __gnuc_va_list __fortify_ap;
  167. __builtin_va_start (__fortify_ap, __fmt);
  168. int __r = __vdprintf_chk (__fd, __USE_FORTIFY_LEVEL - 1, __fmt,
  169. __fortify_ap);
  170. __builtin_va_end (__fortify_ap);
  171. return __r;
  172. }
  173. # elif !defined __cplusplus
  174. # define dprintf(fd, ...) \
  175. __dprintf_chk (fd, __USE_FORTIFY_LEVEL - 1, __VA_ARGS__)
  176. # endif
  177. __fortify_function int
  178. vdprintf (int __fd, const char *__restrict __fmt, __gnuc_va_list __ap)
  179. {
  180. return __vdprintf_chk (__fd, __USE_FORTIFY_LEVEL - 1, __fmt, __ap);
  181. }
  182. # endif
  183. # ifdef __USE_GNU
  184. # ifdef __va_arg_pack
  185. __fortify_function int
  186. __NTH (asprintf (char **__restrict __ptr, const char *__restrict __fmt, ...))
  187. {
  188. return __asprintf_chk (__ptr, __USE_FORTIFY_LEVEL - 1, __fmt,
  189. __va_arg_pack ());
  190. }
  191. __fortify_function int
  192. __NTH (__asprintf (char **__restrict __ptr, const char *__restrict __fmt,
  193. ...))
  194. {
  195. return __asprintf_chk (__ptr, __USE_FORTIFY_LEVEL - 1, __fmt,
  196. __va_arg_pack ());
  197. }
  198. __fortify_function int
  199. __NTH (obstack_printf (struct obstack *__restrict __obstack,
  200. const char *__restrict __fmt, ...))
  201. {
  202. return __obstack_printf_chk (__obstack, __USE_FORTIFY_LEVEL - 1, __fmt,
  203. __va_arg_pack ());
  204. }
  205. # elif __fortify_use_clang
  206. __fortify_function_error_function __attribute_overloadable__ int
  207. __NTH (asprintf (__fortify_clang_overload_arg (char **, __restrict, __ptr),
  208. const char *__restrict __fmt, ...))
  209. {
  210. __gnuc_va_list __fortify_ap;
  211. __builtin_va_start (__fortify_ap, __fmt);
  212. int __r = __vasprintf_chk (__ptr, __USE_FORTIFY_LEVEL - 1, __fmt,
  213. __fortify_ap);
  214. __builtin_va_end (__fortify_ap);
  215. return __r;
  216. }
  217. __fortify_function_error_function __attribute_overloadable__ int
  218. __NTH (__asprintf (__fortify_clang_overload_arg (char **, __restrict, __ptr),
  219. const char *__restrict __fmt, ...))
  220. {
  221. __gnuc_va_list __fortify_ap;
  222. __builtin_va_start (__fortify_ap, __fmt);
  223. int __r = __vasprintf_chk (__ptr, __USE_FORTIFY_LEVEL - 1, __fmt,
  224. __fortify_ap);
  225. __builtin_va_end (__fortify_ap);
  226. return __r;
  227. }
  228. __fortify_function_error_function __attribute_overloadable__ int
  229. __NTH (obstack_printf (__fortify_clang_overload_arg (struct obstack *,
  230. __restrict, __obstack),
  231. const char *__restrict __fmt, ...))
  232. {
  233. __gnuc_va_list __fortify_ap;
  234. __builtin_va_start (__fortify_ap, __fmt);
  235. int __r = __obstack_vprintf_chk (__obstack, __USE_FORTIFY_LEVEL - 1,
  236. __fmt, __fortify_ap);
  237. __builtin_va_end (__fortify_ap);
  238. return __r;
  239. }
  240. # elif !defined __cplusplus
  241. # define asprintf(ptr, ...) \
  242. __asprintf_chk (ptr, __USE_FORTIFY_LEVEL - 1, __VA_ARGS__)
  243. # define __asprintf(ptr, ...) \
  244. __asprintf_chk (ptr, __USE_FORTIFY_LEVEL - 1, __VA_ARGS__)
  245. # define obstack_printf(obstack, ...) \
  246. __obstack_printf_chk (obstack, __USE_FORTIFY_LEVEL - 1, __VA_ARGS__)
  247. # endif
  248. __fortify_function int
  249. __NTH (vasprintf (char **__restrict __ptr, const char *__restrict __fmt,
  250. __gnuc_va_list __ap))
  251. {
  252. return __vasprintf_chk (__ptr, __USE_FORTIFY_LEVEL - 1, __fmt, __ap);
  253. }
  254. __fortify_function int
  255. __NTH (obstack_vprintf (struct obstack *__restrict __obstack,
  256. const char *__restrict __fmt, __gnuc_va_list __ap))
  257. {
  258. return __obstack_vprintf_chk (__obstack, __USE_FORTIFY_LEVEL - 1, __fmt,
  259. __ap);
  260. }
  261. # endif
  262. #endif
  263. #if __GLIBC_USE (DEPRECATED_GETS)
  264. __fortify_function __wur __attribute_overloadable__ char *
  265. gets (__fortify_clang_overload_arg (char *, , __str))
  266. __fortify_clang_warning (__glibc_objsize (__str) == (size_t) -1,
  267. "please use fgets or getline instead, gets "
  268. "can not specify buffer size")
  269. {
  270. if (__glibc_objsize (__str) != (size_t) -1)
  271. return __gets_chk (__str, __glibc_objsize (__str));
  272. return __gets_warn (__str);
  273. }
  274. #endif
  275. __fortify_function __wur __fortified_attr_access (__write_only__, 1, 2)
  276. __nonnull ((3)) __attribute_overloadable__ char *
  277. fgets (__fortify_clang_overload_arg (char *, __restrict, __s), int __n,
  278. FILE *__restrict __stream)
  279. __fortify_clang_warning (__fortify_clang_bos_static_lt (__n, __s) && __n > 0,
  280. "fgets called with bigger size than length of "
  281. "destination buffer")
  282. {
  283. size_t __sz = __glibc_objsize (__s);
  284. if (__glibc_safe_or_unknown_len (__n, sizeof (char), __sz))
  285. return __fgets_alias (__s, __n, __stream);
  286. #if !__fortify_use_clang
  287. if (__glibc_unsafe_len (__n, sizeof (char), __sz))
  288. return __fgets_chk_warn (__s, __sz, __n, __stream);
  289. #endif
  290. return __fgets_chk (__s, __sz, __n, __stream);
  291. }
  292. __fortify_function __wur __nonnull ((4)) __attribute_overloadable__ size_t
  293. fread (__fortify_clang_overload_arg (void *, __restrict, __ptr),
  294. size_t __size, size_t __n, FILE *__restrict __stream)
  295. __fortify_clang_warning (__fortify_clang_bos0_static_lt (__size * __n, __ptr)
  296. && !__fortify_clang_mul_may_overflow (__size, __n),
  297. "fread called with bigger size * n than length "
  298. "of destination buffer")
  299. {
  300. size_t __sz = __glibc_objsize0 (__ptr);
  301. if (__glibc_safe_or_unknown_len (__n, __size, __sz))
  302. return __fread_alias (__ptr, __size, __n, __stream);
  303. #if !__fortify_use_clang
  304. if (__glibc_unsafe_len (__n, __size, __sz))
  305. return __fread_chk_warn (__ptr, __sz, __size, __n, __stream);
  306. #endif
  307. return __fread_chk (__ptr, __sz, __size, __n, __stream);
  308. }
  309. #ifdef __USE_GNU
  310. __fortify_function __wur __fortified_attr_access (__write_only__, 1, 2)
  311. __nonnull ((3)) __attribute_overloadable__ char *
  312. fgets_unlocked (__fortify_clang_overload_arg (char *, __restrict, __s),
  313. int __n, FILE *__restrict __stream)
  314. __fortify_clang_warning (__fortify_clang_bos_static_lt (__n, __s) && __n > 0,
  315. "fgets called with bigger size than length of "
  316. "destination buffer")
  317. {
  318. size_t __sz = __glibc_objsize (__s);
  319. if (__glibc_safe_or_unknown_len (__n, sizeof (char), __sz))
  320. return __fgets_unlocked_alias (__s, __n, __stream);
  321. #if !__fortify_use_clang
  322. if (__glibc_unsafe_len (__n, sizeof (char), __sz))
  323. return __fgets_unlocked_chk_warn (__s, __sz, __n, __stream);
  324. #endif
  325. return __fgets_unlocked_chk (__s, __sz, __n, __stream);
  326. }
  327. #endif
  328. #ifdef __USE_MISC
  329. # undef fread_unlocked
  330. __fortify_function __wur __nonnull ((4)) __attribute_overloadable__ size_t
  331. fread_unlocked (__fortify_clang_overload_arg0 (void *, __restrict, __ptr),
  332. size_t __size, size_t __n, FILE *__restrict __stream)
  333. __fortify_clang_warning (__fortify_clang_bos0_static_lt (__size * __n, __ptr)
  334. && !__fortify_clang_mul_may_overflow (__size, __n),
  335. "fread_unlocked called with bigger size * n than "
  336. "length of destination buffer")
  337. {
  338. size_t __sz = __glibc_objsize0 (__ptr);
  339. if (__glibc_safe_or_unknown_len (__n, __size, __sz))
  340. {
  341. # ifdef __USE_EXTERN_INLINES
  342. if (__builtin_constant_p (__size)
  343. && __builtin_constant_p (__n)
  344. && (__size | __n) < (((size_t) 1) << (8 * sizeof (size_t) / 2))
  345. && __size * __n <= 8)
  346. {
  347. size_t __cnt = __size * __n;
  348. char *__cptr = (char *) __ptr;
  349. if (__cnt == 0)
  350. return 0;
  351. for (; __cnt > 0; --__cnt)
  352. {
  353. int __c = getc_unlocked (__stream);
  354. if (__c == EOF)
  355. break;
  356. *__cptr++ = __c;
  357. }
  358. return (__cptr - (char *) __ptr) / __size;
  359. }
  360. # endif
  361. return __fread_unlocked_alias (__ptr, __size, __n, __stream);
  362. }
  363. # if !__fortify_use_clang
  364. if (__glibc_unsafe_len (__n, __size, __sz))
  365. return __fread_unlocked_chk_warn (__ptr, __sz, __size, __n, __stream);
  366. # endif
  367. return __fread_unlocked_chk (__ptr, __sz, __size, __n, __stream);
  368. }
  369. #endif
  370. #endif /* bits/stdio2.h. */