1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
|
------------------------------------------------------------------------------
-- --
-- GNAT COMPILER COMPONENTS --
-- --
-- I N T E R F A C E S . C . S T R I N G S --
-- --
-- B o d y --
-- --
-- Copyright (C) 1992-2007, Free Software Foundation, Inc. --
-- --
-- GNAT is free software; you can redistribute it and/or modify it under --
-- terms of the GNU General Public License as published by the Free Soft- --
-- ware Foundation; either version 2, or (at your option) any later ver- --
-- sion. GNAT is distributed in the hope that it will be useful, but WITH- --
-- OUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY --
-- or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License --
-- for more details. You should have received a copy of the GNU General --
-- Public License distributed with GNAT; see file COPYING. If not, write --
-- to the Free Software Foundation, 51 Franklin Street, Fifth Floor, --
-- Boston, MA 02110-1301, USA. --
-- --
-- As a special exception, if other files instantiate generics from this --
-- unit, or you link this unit with other files to produce an executable, --
-- this unit does not by itself cause the resulting executable to be --
-- covered by the GNU General Public License. This exception does not --
-- however invalidate any other reasons why the executable file might be --
-- covered by the GNU Public License. --
-- --
-- GNAT was originally developed by the GNAT team at New York University. --
-- Extensive contributions were provided by Ada Core Technologies Inc. --
-- --
------------------------------------------------------------------------------
with System; use System;
with System.Storage_Elements; use System.Storage_Elements;
with Ada.Unchecked_Conversion;
package body Interfaces.C.Strings is
-- Note that the type chars_ptr has a pragma No_Strict_Aliasing in the
-- spec, to prevent any assumptions about aliasing for values of this type,
-- since arbitrary addresses can be converted, and it is quite likely that
-- this type will in fact be used for aliasing values of other types.
function To_chars_ptr is
new Ada.Unchecked_Conversion (Address, chars_ptr);
function To_Address is
new Ada.Unchecked_Conversion (chars_ptr, Address);
-----------------------
-- Local Subprograms --
-----------------------
function Peek (From : chars_ptr) return char;
pragma Inline (Peek);
-- Given a chars_ptr value, obtain referenced character
procedure Poke (Value : char; Into : chars_ptr);
pragma Inline (Poke);
-- Given a chars_ptr, modify referenced Character value
function "+" (Left : chars_ptr; Right : size_t) return chars_ptr;
pragma Inline ("+");
-- Address arithmetic on chars_ptr value
function Position_Of_Nul (Into : char_array) return size_t;
-- Returns position of the first Nul in Into or Into'Last + 1 if none
-- We can't use directly System.Memory because the categorization is not
-- compatible, so we directly import here the malloc and free routines.
function Memory_Alloc (Size : size_t) return chars_ptr;
pragma Import (C, Memory_Alloc, "__gnat_malloc");
procedure Memory_Free (Address : chars_ptr);
pragma Import (C, Memory_Free, "__gnat_free");
---------
-- "+" --
---------
function "+" (Left : chars_ptr; Right : size_t) return chars_ptr is
begin
return To_chars_ptr (To_Address (Left) + Storage_Offset (Right));
end "+";
----------
-- Free --
----------
procedure Free (Item : in out chars_ptr) is
begin
if Item = Null_Ptr then
return;
end if;
Memory_Free (Item);
Item := Null_Ptr;
end Free;
--------------------
-- New_Char_Array --
--------------------
function New_Char_Array (Chars : char_array) return chars_ptr is
Index : size_t;
Pointer : chars_ptr;
begin
-- Get index of position of null. If Index > Chars'Last,
-- nul is absent and must be added explicitly.
Index := Position_Of_Nul (Into => Chars);
Pointer := Memory_Alloc ((Index - Chars'First + 1));
-- If nul is present, transfer string up to and including nul
if Index <= Chars'Last then
Update (Item => Pointer,
Offset => 0,
Chars => Chars (Chars'First .. Index),
Check => False);
else
-- If original string has no nul, transfer whole string and add
-- terminator explicitly.
Update (Item => Pointer,
Offset => 0,
Chars => Chars,
Check => False);
Poke (nul, into => Pointer + size_t'(Chars'Length));
end if;
return Pointer;
end New_Char_Array;
----------------
-- New_String --
----------------
function New_String (Str : String) return chars_ptr is
begin
return New_Char_Array (To_C (Str));
end New_String;
----------
-- Peek --
----------
function Peek (From : chars_ptr) return char is
begin
return char (From.all);
end Peek;
----------
-- Poke --
----------
procedure Poke (Value : char; Into : chars_ptr) is
begin
Into.all := Character (Value);
end Poke;
---------------------
-- Position_Of_Nul --
---------------------
function Position_Of_Nul (Into : char_array) return size_t is
begin
for J in Into'Range loop
if Into (J) = nul then
return J;
end if;
end loop;
return Into'Last + 1;
end Position_Of_Nul;
------------
-- Strlen --
------------
function Strlen (Item : chars_ptr) return size_t is
Item_Index : size_t := 0;
begin
if Item = Null_Ptr then
raise Dereference_Error;
end if;
loop
if Peek (Item + Item_Index) = nul then
return Item_Index;
end if;
Item_Index := Item_Index + 1;
end loop;
end Strlen;
------------------
-- To_Chars_Ptr --
------------------
function To_Chars_Ptr
(Item : char_array_access;
Nul_Check : Boolean := False) return chars_ptr
is
begin
if Item = null then
return Null_Ptr;
elsif Nul_Check
and then Position_Of_Nul (Into => Item.all) > Item'Last
then
raise Terminator_Error;
else
return To_chars_ptr (Item (Item'First)'Address);
end if;
end To_Chars_Ptr;
------------
-- Update --
------------
procedure Update
(Item : chars_ptr;
Offset : size_t;
Chars : char_array;
Check : Boolean := True)
is
Index : chars_ptr := Item + Offset;
begin
if Check and then Offset + Chars'Length > Strlen (Item) then
raise Update_Error;
end if;
for J in Chars'Range loop
Poke (Chars (J), Into => Index);
Index := Index + size_t'(1);
end loop;
end Update;
procedure Update
(Item : chars_ptr;
Offset : size_t;
Str : String;
Check : Boolean := True)
is
begin
-- Note: in RM 95, the Append_Nul => False parameter is omitted. But
-- this has the unintended consequence of truncating the string after
-- an update. As discussed in Ada 2005 AI-242, this was unintended,
-- and should be corrected. Since this is a clear error, it seems
-- appropriate to apply the correction in Ada 95 mode as well.
Update (Item, Offset, To_C (Str, Append_Nul => False), Check);
end Update;
-----------
-- Value --
-----------
function Value (Item : chars_ptr) return char_array is
Result : char_array (0 .. Strlen (Item));
begin
if Item = Null_Ptr then
raise Dereference_Error;
end if;
-- Note that the following loop will also copy the terminating Nul
for J in Result'Range loop
Result (J) := Peek (Item + J);
end loop;
return Result;
end Value;
function Value
(Item : chars_ptr;
Length : size_t) return char_array
is
begin
if Item = Null_Ptr then
raise Dereference_Error;
end if;
-- ACATS cxb3010 checks that Constraint_Error gets raised when Length
-- is 0. Seems better to check that Length is not null before declaring
-- an array with size_t bounds of 0 .. Length - 1 anyway.
if Length = 0 then
raise Constraint_Error;
end if;
declare
Result : char_array (0 .. Length - 1);
begin
for J in Result'Range loop
Result (J) := Peek (Item + J);
if Result (J) = nul then
return Result (0 .. J);
end if;
end loop;
return Result;
end;
end Value;
function Value (Item : chars_ptr) return String is
begin
return To_Ada (Value (Item));
end Value;
function Value (Item : chars_ptr; Length : size_t) return String is
Result : char_array (0 .. Length);
begin
-- As per AI-00177, this is equivalent to:
-- To_Ada (Value (Item, Length) & nul);
if Item = Null_Ptr then
raise Dereference_Error;
end if;
for J in 0 .. Length - 1 loop
Result (J) := Peek (Item + J);
if Result (J) = nul then
return To_Ada (Result (0 .. J));
end if;
end loop;
Result (Length) := nul;
return To_Ada (Result);
end Value;
end Interfaces.C.Strings;
|