nuttx/libs/libc/stdlib/lib_bsearch.c
Marco Casaroli 43694933ce libc, sched: Resolve FDPIC descriptors at module callback entry points.
The base firmware and an FDPIC module disagree about what a function
pointer is.  Firmware is not built FDPIC, so to it a pointer is a code
address and it branches there.  A module passes the address of a two word
descriptor instead, because its code and data are placed independently and
a bare code address would leave the callee unable to find its own data.  A
firmware routine that takes a callback therefore branches into the
module's data segment and faults.

So the ten entry points that can be handed a callback by a module resolve
the descriptor before storing or branching to it: qsort, bsearch,
pthread_create, signal, sigaction, task_create and task_create_with_stack,
task_spawn, pthread_once, scandir, and mq_notify and timer_create with
SIGEV_THREAD.

Which one resolves matters as much as that one does.  Resolving twice would
take an already resolved code address for a descriptor and read two words
from the instruction stream, so each pointer is resolved exactly once, at
the outermost point that sees it.  signal() passes its argument through
untouched because sigaction() and then nxsig_action() will resolve it,
which covers a module calling sigaction() directly as well.  qsort() is
split so that the public entry resolves and the recursive implementation
does not.  scandir() resolves its filter but not its comparison function,
which it hands to qsort().

Whether a caller is a module at all is asked of the PIC base register,
which up_initial_state() sets only for a task that has a D-Space.  A plain
kernel task therefore reads zero and is left alone.

SIGEV_THREAD is the case the register cannot answer, because the callback
runs later on a work queue worker that carries no module's base at all.
The base is captured instead when the notification is registered, in the
module's own context, and installed around the call.

All of it is behind CONFIG_FDPIC, which defaults off.  Built for
mps3-an547:picostest both ways; with it off the entry points compile to
what they were.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-25 10:46:48 -03:00

148 lines
6.5 KiB
C

/****************************************************************************
* libs/libc/stdlib/lib_bsearch.c
*
* SPDX-License-Identifier: BSD-3-Clause
* SPDX-FileCopyrightText: 1990 The Regents of the University of California.
* SPDX-FileCopyrightText: 1993 The Regents of the University of California.
* All rights reserved.
*
* Redistribution and use in source and binary forms, with or without
* modification, are permitted provided that the following conditions
* are met:
* 1. Redistributions of source code must retain the above copyright
* notice, this list of conditions and the following disclaimer.
* 2. Redistributions in binary form must reproduce the above copyright
* notice, this list of conditions and the following disclaimer in the
* documentation and/or other materials provided with the distribution.
* 3. Neither the name of the University nor the names of its contributors
* may be used to endorse or promote products derived from this software
* without specific prior written permission.
*
* THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
* ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
* ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
* FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
* DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
* OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
* HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
* LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
* SUCH DAMAGE.
*
****************************************************************************/
/****************************************************************************
* Included Files
****************************************************************************/
#include <stdlib.h>
#ifdef CONFIG_FDPIC
# include <nuttx/fdpic.h>
#endif
#include <assert.h>
/****************************************************************************
* Public Functions
****************************************************************************/
/****************************************************************************
* Name: bsearch
*
* Description:
* The bsearch() function will search an array of nel objects, the initial
* element of which is pointed to by 'base', for an element that matches
* the object pointed to by 'key'. The size of each element in the array
* is specified by 'width'. If the nel argument has the value zero, the
* comparison function pointed to by 'compar' will not be called and no
* match will be found.
*
* The comparison function pointed to by 'compar' will be called with two
* arguments that point to the 'key' object and to an array element, in
* that order.
*
* The application will ensure that the comparison function pointed to by
* 'compar 'does not alter the contents of the array. The implementation
* may reorder elements of the array between calls to the comparison
* function, but will not alter the contents of any individual element.
*
* The implementation will ensure that the first argument is always a
* pointer to the 'key'.
*
* When the same objects (consisting of width bytes, irrespective of their
* current positions in the array) are passed more than once to the
* comparison function, the results will be consistent with one another.
* That is, the same object will always compare the same way with the key.
*
* The application will ensure that the function returns an integer less
* than, equal to, or greater than 0 if the key object is considered,
* respectively, to be less than, to match, or to be greater than the
* array element. The application will ensure that the array consists of
* all the elements that compare less than, all the elements that compare
* equal to, and all the elements that compare greater than the key
* object, in that order.
*
* (Based on description from OpenGroup.org).
*
* Returned Value:
* The bsearch() function will return a pointer to a matching member of
* the array, or a null pointer if no match is found. If two or more
* members compare equal, which member is returned is unspecified.
*
* Notes from the NetBSD version:
* The code below is a bit sneaky. After a comparison fails, we divide
* the work in half by moving either left or right. If 'lim' is odd,
* moving left simply involves halving 'lim': e.g., when 'lim' is 5 we
* look at item 2, so we change 'lim' to 2 so that we will look at items
* 0 & 1. If 'lim' is even, the same applies. If 'lim' is odd, moving
* right again involves halving 'lim', this time moving the base up one
* item past 'middle': e.g., when 'lim' is 5 we change base to item 3 and
* make 'lim' 2 so that we will look at items 3 and 4. If 'lim' is
* even, however, we have to shrink it by one before halving: e.g.,
* when 'lim' is 4, we still looked at item 2, so we have to make 'lim'
* 3, then halve, obtaining 1, so that we will only look at item 3.
*
****************************************************************************/
FAR void *bsearch(FAR const void *key, FAR const void *base, size_t nel,
size_t width, CODE int (*compar)(FAR const void *,
FAR const void *))
{
FAR const void *middle; /* Current entry being tested */
FAR const char *lower; /* The lower limit of the search region */
size_t lim; /* The number of elements in the region */
int cmp; /* Boolean comparison result */
DEBUGASSERT(key != NULL);
DEBUGASSERT(base != NULL || nel == 0);
DEBUGASSERT(compar != NULL);
#ifdef CONFIG_FDPIC
/* See qsort(): an FDPIC caller passes a descriptor, not a code address */
compar = (CODE int (*)(FAR const void *, FAR const void *))
fdpic_callback((FAR void *)compar);
#endif
for (lim = nel, lower = (const char *)base; lim != 0; lim >>= 1)
{
middle = lower + (lim >> 1) * width;
cmp = (*compar)(key, middle);
if (cmp == 0)
{
return (FAR void *)middle;
}
if (cmp > 0)
{
/* key > middle: move right (else move left) */
lower = (FAR const char *)middle + width;
lim--;
}
}
return NULL;
}