From 3ad1b1220151ad9cb9e79b52e10d8facb9dfc79d Mon Sep 17 00:00:00 2001 From: Mattias Andrée Date: Sun, 30 Aug 2015 15:03:08 +0200 Subject: add slibc-alloc.h MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Mattias Andrée --- include/slibc-alloc.h | 78 +++++++++++++++++++++++++++++++++++++++++++++++++++ src/slibc-alloc.c | 50 +++++++++++++++++++++++++++++++++ 2 files changed, 128 insertions(+) create mode 100644 include/slibc-alloc.h create mode 100644 src/slibc-alloc.c diff --git a/include/slibc-alloc.h b/include/slibc-alloc.h new file mode 100644 index 0000000..4453fc6 --- /dev/null +++ b/include/slibc-alloc.h @@ -0,0 +1,78 @@ +/** + * slibc — Yet another C library + * Copyright © 2015 Mattias Andrée (maandree@member.fsf.org) + * + * This program is free software: you can redistribute it and/or modify + * it under the terms of the GNU General Public License as published by + * the Free Software Foundation, either version 3 of the License, or + * (at your option) any later version. + * + * This program is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with this program. If not, see . + */ +#ifndef _SLIBC_ALLOC_H +#define _SLIBC_ALLOC_H +#ifndef _PORTABLE_SOURCE +#include + + + +#define __NEED_size_t +#include + + +/** + * This function is identical to `free`, except it is guaranteed not to + * override the memory segment with zeroes before freeing the allocation. + * + * @param segment The memory segment to free. + */ +void fast_free(void*); + +/** + * This function is identical to `free`, except it is guaranteed to + * override the memory segment with zeroes before freeing the allocation. + * + * @param segment The memory segment to free. + */ +void secure_free(void*); + +/** + * This function returns the allocation size of + * a memory segment. + * + * `p = malloc(n), allocsize(p)` will return `n`. + * + * @param segment The memory segment. + * @return The size of the memory segment, 0 on error. + * + * @throws EINVAL If `segment` is `NULL`. + * @throws EFAULT If `segment` is not a pointer to an allocation + * on the heap, or was not allocated with a function + * implemented in slibc. + */ +size_t allocsize(void*); /* TODO not implemented */ + + +/** + * This macro calls `fast_free` and then sets the pointer to `NULL`, + * so that another attempt to free the segment will not crash the process. + */ +#define FAST_FREE(segment) (fast_free(segment), (segment) = NULL); + +/** + * This macro calls `secure_free` and then sets the pointer to `NULL`, + * so that another attempt to free the segment will not crash the process. + */ +#define SECURE_FREE(segment) (secure_free(segment), (segment) = NULL); + + + +#endif +#endif + diff --git a/src/slibc-alloc.c b/src/slibc-alloc.c new file mode 100644 index 0000000..a29b188 --- /dev/null +++ b/src/slibc-alloc.c @@ -0,0 +1,50 @@ +/** + * slibc — Yet another C library + * Copyright © 2015 Mattias Andrée (maandree@member.fsf.org) + * + * This program is free software: you can redistribute it and/or modify + * it under the terms of the GNU General Public License as published by + * the Free Software Foundation, either version 3 of the License, or + * (at your option) any later version. + * + * This program is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with this program. If not, see . + */ +#include +#include +#include + + + +/** + * This function is identical to `free`, except it is guaranteed not to + * override the memory segment with zeroes before freeing the allocation. + * + * @param segment The memory segment to free. + */ +void fast_free(void* segment) +{ + free(segment); +} + + +/** + * This function is identical to `free`, except it is guaranteed to + * override the memory segment with zeroes before freeing the allocation. + * + * @param segment The memory segment to free. + */ +void secure_free(void* segment) +{ + if (segment) + { + explicit_bzero(segment, allocsize(segment)); + free(segment); + } +} + -- cgit v1.2.3-70-g09d2