1 /*
2 * NDR data marshalling
3 *
4 * Copyright 2002 Greg Turner
5 * Copyright 2003-2006 CodeWeavers
6 *
7 * This library is free software; you can redistribute it and/or
8 * modify it under the terms of the GNU Lesser General Public
9 * License as published by the Free Software Foundation; either
10 * version 2.1 of the License, or (at your option) any later version.
11 *
12 * This library is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
15 * Lesser General Public License for more details.
16 *
17 * You should have received a copy of the GNU Lesser General Public
18 * License along with this library; if not, write to the Free Software
19 * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA
20 *
21 * TODO:
22 * - String structs
23 * - Byte count pointers
24 * - transmit_as/represent as
25 * - Multi-dimensional arrays
26 * - Conversion functions (NdrConvert)
27 * - Checks for integer addition overflow in user marshall functions
28 */
29
30 #include <stdarg.h>
31 #include <stdio.h>
32 #include <string.h>
33 #include <limits.h>
34
35 #include "windef.h"
36 #include "winbase.h"
37 #include "winerror.h"
38
39 #include "ndr_misc.h"
40 #include "rpcndr.h"
41
42 #include "wine/unicode.h"
43 #include "wine/rpcfc.h"
44
45 #include "wine/debug.h"
46
47 WINE_DEFAULT_DEBUG_CHANNEL(ole);
48
49 #if defined(__i386__)
50 # define LITTLE_ENDIAN_UINT32_WRITE(pchar, uint32) \
51 (*((UINT32 *)(pchar)) = (uint32))
52
53 # define LITTLE_ENDIAN_UINT32_READ(pchar) \
54 (*((UINT32 *)(pchar)))
55 #else
56 /* these would work for i386 too, but less efficient */
57 # define LITTLE_ENDIAN_UINT32_WRITE(pchar, uint32) \
58 (*(pchar) = LOBYTE(LOWORD(uint32)), \
59 *((pchar)+1) = HIBYTE(LOWORD(uint32)), \
60 *((pchar)+2) = LOBYTE(HIWORD(uint32)), \
61 *((pchar)+3) = HIBYTE(HIWORD(uint32)))
62
63 # define LITTLE_ENDIAN_UINT32_READ(pchar) \
64 (MAKELONG( \
65 MAKEWORD(*(pchar), *((pchar)+1)), \
66 MAKEWORD(*((pchar)+2), *((pchar)+3))))
67 #endif
68
69 #define BIG_ENDIAN_UINT32_WRITE(pchar, uint32) \
70 (*((pchar)+3) = LOBYTE(LOWORD(uint32)), \
71 *((pchar)+2) = HIBYTE(LOWORD(uint32)), \
72 *((pchar)+1) = LOBYTE(HIWORD(uint32)), \
73 *(pchar) = HIBYTE(HIWORD(uint32)))
74
75 #define BIG_ENDIAN_UINT32_READ(pchar) \
76 (MAKELONG( \
77 MAKEWORD(*((pchar)+3), *((pchar)+2)), \
78 MAKEWORD(*((pchar)+1), *(pchar))))
79
80 #ifdef NDR_LOCAL_IS_BIG_ENDIAN
81 # define NDR_LOCAL_UINT32_WRITE(pchar, uint32) \
82 BIG_ENDIAN_UINT32_WRITE(pchar, uint32)
83 # define NDR_LOCAL_UINT32_READ(pchar) \
84 BIG_ENDIAN_UINT32_READ(pchar)
85 #else
86 # define NDR_LOCAL_UINT32_WRITE(pchar, uint32) \
87 LITTLE_ENDIAN_UINT32_WRITE(pchar, uint32)
88 # define NDR_LOCAL_UINT32_READ(pchar) \
89 LITTLE_ENDIAN_UINT32_READ(pchar)
90 #endif
91
92 /* _Align must be the desired alignment,
93 * e.g. ALIGN_LENGTH(len, 4) to align on a dword boundary. */
94 #define ALIGNED_LENGTH(_Len, _Align) (((_Len)+(_Align)-1)&~((_Align)-1))
95 #define ALIGNED_POINTER(_Ptr, _Align) ((LPVOID)ALIGNED_LENGTH((ULONG_PTR)(_Ptr), _Align))
96 #define ALIGN_LENGTH(_Len, _Align) _Len = ALIGNED_LENGTH(_Len, _Align)
97 #define ALIGN_POINTER(_Ptr, _Align) _Ptr = ALIGNED_POINTER(_Ptr, _Align)
98 #define ALIGN_POINTER_CLEAR(_Ptr, _Align) \
99 do { \
100 memset((_Ptr), 0, ((_Align) - (ULONG_PTR)(_Ptr)) & ((_Align) - 1)); \
101 ALIGN_POINTER(_Ptr, _Align); \
102 } while(0)
103
104 #define STD_OVERFLOW_CHECK(_Msg) do { \
105 TRACE("buffer=%d/%d\n", _Msg->Buffer - (unsigned char *)_Msg->RpcMsg->Buffer, _Msg->BufferLength); \
106 if (_Msg->Buffer > (unsigned char *)_Msg->RpcMsg->Buffer + _Msg->BufferLength) \
107 ERR("buffer overflow %d bytes\n", _Msg->Buffer - ((unsigned char *)_Msg->RpcMsg->Buffer + _Msg->BufferLength)); \
108 } while (0)
109
110 #define NDR_POINTER_ID_BASE 0x20000
111 #define NDR_POINTER_ID(pStubMsg) (NDR_POINTER_ID_BASE + ((pStubMsg)->UniquePtrCount++) * 4)
112 #define NDR_TABLE_SIZE 128
113 #define NDR_TABLE_MASK 127
114
115 static unsigned char *WINAPI NdrBaseTypeMarshall(PMIDL_STUB_MESSAGE, unsigned char *, PFORMAT_STRING);
116 static unsigned char *WINAPI NdrBaseTypeUnmarshall(PMIDL_STUB_MESSAGE, unsigned char **, PFORMAT_STRING, unsigned char);
117 static void WINAPI NdrBaseTypeBufferSize(PMIDL_STUB_MESSAGE, unsigned char *, PFORMAT_STRING);
118 static void WINAPI NdrBaseTypeFree(PMIDL_STUB_MESSAGE, unsigned char *, PFORMAT_STRING);
119 static ULONG WINAPI NdrBaseTypeMemorySize(PMIDL_STUB_MESSAGE, PFORMAT_STRING);
120
121 static unsigned char *WINAPI NdrContextHandleMarshall(PMIDL_STUB_MESSAGE, unsigned char *, PFORMAT_STRING);
122 static void WINAPI NdrContextHandleBufferSize(PMIDL_STUB_MESSAGE, unsigned char *, PFORMAT_STRING);
123 static unsigned char *WINAPI NdrContextHandleUnmarshall(PMIDL_STUB_MESSAGE, unsigned char **, PFORMAT_STRING, unsigned char);
124
125 static unsigned char *WINAPI NdrRangeMarshall(PMIDL_STUB_MESSAGE,unsigned char *, PFORMAT_STRING);
126 static void WINAPI NdrRangeBufferSize(PMIDL_STUB_MESSAGE, unsigned char *, PFORMAT_STRING);
127 static ULONG WINAPI NdrRangeMemorySize(PMIDL_STUB_MESSAGE, PFORMAT_STRING);
128 static void WINAPI NdrRangeFree(PMIDL_STUB_MESSAGE, unsigned char *, PFORMAT_STRING);
129
130 static ULONG WINAPI NdrByteCountPointerMemorySize(PMIDL_STUB_MESSAGE, PFORMAT_STRING);
131
132 const NDR_MARSHALL NdrMarshaller[NDR_TABLE_SIZE] = {
133 0,
134 NdrBaseTypeMarshall, NdrBaseTypeMarshall, NdrBaseTypeMarshall,
135 NdrBaseTypeMarshall, NdrBaseTypeMarshall, NdrBaseTypeMarshall, NdrBaseTypeMarshall,
136 NdrBaseTypeMarshall, NdrBaseTypeMarshall, NdrBaseTypeMarshall, NdrBaseTypeMarshall,
137 NdrBaseTypeMarshall, NdrBaseTypeMarshall, NdrBaseTypeMarshall, NdrBaseTypeMarshall,
138 /* 0x10 */
139 NdrBaseTypeMarshall,
140 /* 0x11 */
141 NdrPointerMarshall, NdrPointerMarshall,
142 NdrPointerMarshall, NdrPointerMarshall,
143 /* 0x15 */
144 NdrSimpleStructMarshall, NdrSimpleStructMarshall,
145 NdrConformantStructMarshall, NdrConformantStructMarshall,
146 NdrConformantVaryingStructMarshall,
147 NdrComplexStructMarshall,
148 /* 0x1b */
149 NdrConformantArrayMarshall,
150 NdrConformantVaryingArrayMarshall,
151 NdrFixedArrayMarshall, NdrFixedArrayMarshall,
152 NdrVaryingArrayMarshall, NdrVaryingArrayMarshall,
153 NdrComplexArrayMarshall,
154 /* 0x22 */
155 NdrConformantStringMarshall, 0, 0,
156 NdrConformantStringMarshall,
157 NdrNonConformantStringMarshall, 0, 0, 0,
158 /* 0x2a */
159 NdrEncapsulatedUnionMarshall,
160 NdrNonEncapsulatedUnionMarshall,
161 NdrByteCountPointerMarshall,
162 NdrXmitOrRepAsMarshall, NdrXmitOrRepAsMarshall,
163 /* 0x2f */
164 NdrInterfacePointerMarshall,
165 /* 0x30 */
166 NdrContextHandleMarshall,
167 /* 0xb1 */
168 0, 0, 0,
169 NdrUserMarshalMarshall,
170 0, 0,
171 /* 0xb7 */
172 NdrRangeMarshall
173 };
174 const NDR_UNMARSHALL NdrUnmarshaller[NDR_TABLE_SIZE] = {
175 0,
176 NdrBaseTypeUnmarshall, NdrBaseTypeUnmarshall, NdrBaseTypeUnmarshall,
177 NdrBaseTypeUnmarshall, NdrBaseTypeUnmarshall, NdrBaseTypeUnmarshall, NdrBaseTypeUnmarshall,
178 NdrBaseTypeUnmarshall, NdrBaseTypeUnmarshall, NdrBaseTypeUnmarshall, NdrBaseTypeUnmarshall,
179 NdrBaseTypeUnmarshall, NdrBaseTypeUnmarshall, NdrBaseTypeUnmarshall, NdrBaseTypeUnmarshall,
180 /* 0x10 */
181 NdrBaseTypeUnmarshall,
182 /* 0x11 */
183 NdrPointerUnmarshall, NdrPointerUnmarshall,
184 NdrPointerUnmarshall, NdrPointerUnmarshall,
185 /* 0x15 */
186 NdrSimpleStructUnmarshall, NdrSimpleStructUnmarshall,
187 NdrConformantStructUnmarshall, NdrConformantStructUnmarshall,
188 NdrConformantVaryingStructUnmarshall,
189 NdrComplexStructUnmarshall,
190 /* 0x1b */
191 NdrConformantArrayUnmarshall,
192 NdrConformantVaryingArrayUnmarshall,
193 NdrFixedArrayUnmarshall, NdrFixedArrayUnmarshall,
194 NdrVaryingArrayUnmarshall, NdrVaryingArrayUnmarshall,
195 NdrComplexArrayUnmarshall,
196 /* 0x22 */
197 NdrConformantStringUnmarshall, 0, 0,
198 NdrConformantStringUnmarshall,
199 NdrNonConformantStringUnmarshall, 0, 0, 0,
200 /* 0x2a */
201 NdrEncapsulatedUnionUnmarshall,
202 NdrNonEncapsulatedUnionUnmarshall,
203 NdrByteCountPointerUnmarshall,
204 NdrXmitOrRepAsUnmarshall, NdrXmitOrRepAsUnmarshall,
205 /* 0x2f */
206 NdrInterfacePointerUnmarshall,
207 /* 0x30 */
208 NdrContextHandleUnmarshall,
209 /* 0xb1 */
210 0, 0, 0,
211 NdrUserMarshalUnmarshall,
212 0, 0,
213 /* 0xb7 */
214 NdrRangeUnmarshall
215 };
216 const NDR_BUFFERSIZE NdrBufferSizer[NDR_TABLE_SIZE] = {
217 0,
218 NdrBaseTypeBufferSize, NdrBaseTypeBufferSize, NdrBaseTypeBufferSize,
219 NdrBaseTypeBufferSize, NdrBaseTypeBufferSize, NdrBaseTypeBufferSize, NdrBaseTypeBufferSize,
220 NdrBaseTypeBufferSize, NdrBaseTypeBufferSize, NdrBaseTypeBufferSize, NdrBaseTypeBufferSize,
221 NdrBaseTypeBufferSize, NdrBaseTypeBufferSize, NdrBaseTypeBufferSize, NdrBaseTypeBufferSize,
222 /* 0x10 */
223 NdrBaseTypeBufferSize,
224 /* 0x11 */
225 NdrPointerBufferSize, NdrPointerBufferSize,
226 NdrPointerBufferSize, NdrPointerBufferSize,
227 /* 0x15 */
228 NdrSimpleStructBufferSize, NdrSimpleStructBufferSize,
229 NdrConformantStructBufferSize, NdrConformantStructBufferSize,
230 NdrConformantVaryingStructBufferSize,
231 NdrComplexStructBufferSize,
232 /* 0x1b */
233 NdrConformantArrayBufferSize,
234 NdrConformantVaryingArrayBufferSize,
235 NdrFixedArrayBufferSize, NdrFixedArrayBufferSize,
236 NdrVaryingArrayBufferSize, NdrVaryingArrayBufferSize,
237 NdrComplexArrayBufferSize,
238 /* 0x22 */
239 NdrConformantStringBufferSize, 0, 0,
240 NdrConformantStringBufferSize,
241 NdrNonConformantStringBufferSize, 0, 0, 0,
242 /* 0x2a */
243 NdrEncapsulatedUnionBufferSize,
244 NdrNonEncapsulatedUnionBufferSize,
245 NdrByteCountPointerBufferSize,
246 NdrXmitOrRepAsBufferSize, NdrXmitOrRepAsBufferSize,
247 /* 0x2f */
248 NdrInterfacePointerBufferSize,
249 /* 0x30 */
250 NdrContextHandleBufferSize,
251 /* 0xb1 */
252 0, 0, 0,
253 NdrUserMarshalBufferSize,
254 0, 0,
255 /* 0xb7 */
256 NdrRangeBufferSize
257 };
258 const NDR_MEMORYSIZE NdrMemorySizer[NDR_TABLE_SIZE] = {
259 0,
260 NdrBaseTypeMemorySize, NdrBaseTypeMemorySize, NdrBaseTypeMemorySize,
261 NdrBaseTypeMemorySize, NdrBaseTypeMemorySize, NdrBaseTypeMemorySize, NdrBaseTypeMemorySize,
262 NdrBaseTypeMemorySize, NdrBaseTypeMemorySize, NdrBaseTypeMemorySize, NdrBaseTypeMemorySize,
263 NdrBaseTypeMemorySize, NdrBaseTypeMemorySize, NdrBaseTypeMemorySize, NdrBaseTypeMemorySize,
264 /* 0x10 */
265 NdrBaseTypeMemorySize,
266 /* 0x11 */
267 NdrPointerMemorySize, NdrPointerMemorySize,
268 NdrPointerMemorySize, NdrPointerMemorySize,
269 /* 0x15 */
270 NdrSimpleStructMemorySize, NdrSimpleStructMemorySize,
271 NdrConformantStructMemorySize, NdrConformantStructMemorySize,
272 NdrConformantVaryingStructMemorySize,
273 NdrComplexStructMemorySize,
274 /* 0x1b */
275 NdrConformantArrayMemorySize,
276 NdrConformantVaryingArrayMemorySize,
277 NdrFixedArrayMemorySize, NdrFixedArrayMemorySize,
278 NdrVaryingArrayMemorySize, NdrVaryingArrayMemorySize,
279 NdrComplexArrayMemorySize,
280 /* 0x22 */
281 NdrConformantStringMemorySize, 0, 0,
282 NdrConformantStringMemorySize,
283 NdrNonConformantStringMemorySize, 0, 0, 0,
284 /* 0x2a */
285 NdrEncapsulatedUnionMemorySize,
286 NdrNonEncapsulatedUnionMemorySize,
287 NdrByteCountPointerMemorySize,
288 NdrXmitOrRepAsMemorySize, NdrXmitOrRepAsMemorySize,
289 /* 0x2f */
290 NdrInterfacePointerMemorySize,
291 /* 0x30 */
292 0,
293 /* 0xb1 */
294 0, 0, 0,
295 NdrUserMarshalMemorySize,
296 0, 0,
297 /* 0xb7 */
298 NdrRangeMemorySize
299 };
300 const NDR_FREE NdrFreer[NDR_TABLE_SIZE] = {
301 0,
302 NdrBaseTypeFree, NdrBaseTypeFree, NdrBaseTypeFree,
303 NdrBaseTypeFree, NdrBaseTypeFree, NdrBaseTypeFree, NdrBaseTypeFree,
304 NdrBaseTypeFree, NdrBaseTypeFree, NdrBaseTypeFree, NdrBaseTypeFree,
305 NdrBaseTypeFree, NdrBaseTypeFree, NdrBaseTypeFree, NdrBaseTypeFree,
306 /* 0x10 */
307 NdrBaseTypeFree,
308 /* 0x11 */
309 NdrPointerFree, NdrPointerFree,
310 NdrPointerFree, NdrPointerFree,
311 /* 0x15 */
312 NdrSimpleStructFree, NdrSimpleStructFree,
313 NdrConformantStructFree, NdrConformantStructFree,
314 NdrConformantVaryingStructFree,
315 NdrComplexStructFree,
316 /* 0x1b */
317 NdrConformantArrayFree,
318 NdrConformantVaryingArrayFree,
319 NdrFixedArrayFree, NdrFixedArrayFree,
320 NdrVaryingArrayFree, NdrVaryingArrayFree,
321 NdrComplexArrayFree,
322 /* 0x22 */
323 0, 0, 0,
324 0, 0, 0, 0, 0,
325 /* 0x2a */
326 NdrEncapsulatedUnionFree,
327 NdrNonEncapsulatedUnionFree,
328 0,
329 NdrXmitOrRepAsFree, NdrXmitOrRepAsFree,
330 /* 0x2f */
331 NdrInterfacePointerFree,
332 /* 0x30 */
333 0,
334 /* 0xb1 */
335 0, 0, 0,
336 NdrUserMarshalFree,
337 0, 0,
338 /* 0xb7 */
339 NdrRangeFree
340 };
341
342 typedef struct _NDR_MEMORY_LIST
343 {
344 ULONG magic;
345 ULONG size;
346 ULONG reserved;
347 struct _NDR_MEMORY_LIST *next;
348 } NDR_MEMORY_LIST;
349
350 #define MEML_MAGIC ('M' << 24 | 'E' << 16 | 'M' << 8 | 'L')
351
352 /***********************************************************************
353 * NdrAllocate [RPCRT4.@]
354 *
355 * Allocates a block of memory using pStubMsg->pfnAllocate.
356 *
357 * PARAMS
358 * pStubMsg [I/O] MIDL_STUB_MESSAGE structure.
359 * len [I] Size of memory block to allocate.
360 *
361 * RETURNS
362 * The memory block of size len that was allocated.
363 *
364 * NOTES
365 * The memory block is always 8-byte aligned.
366 * If the function is unable to allocate memory an ERROR_OUTOFMEMORY
367 * exception is raised.
368 */
369 void * WINAPI NdrAllocate(MIDL_STUB_MESSAGE *pStubMsg, SIZE_T len)
370 {
371 SIZE_T aligned_len;
372 SIZE_T adjusted_len;
373 void *p;
374 NDR_MEMORY_LIST *mem_list;
375
376 aligned_len = ALIGNED_LENGTH(len, 8);
377 adjusted_len = aligned_len + sizeof(NDR_MEMORY_LIST);
378 /* check for overflow */
379 if (adjusted_len < len)
380 {
381 ERR("overflow of adjusted_len %ld, len %ld\n", adjusted_len, len);
382 RpcRaiseException(RPC_X_BAD_STUB_DATA);
383 }
384
385 p = pStubMsg->pfnAllocate(adjusted_len);
386 if (!p) RpcRaiseException(ERROR_OUTOFMEMORY);
387
388 mem_list = (NDR_MEMORY_LIST *)((char *)p + aligned_len);
389 mem_list->magic = MEML_MAGIC;
390 mem_list->size = aligned_len;
391 mem_list->reserved = 0;
392 mem_list->next = pStubMsg->pMemoryList;
393 pStubMsg->pMemoryList = mem_list;
394
395 TRACE("-- %p\n", p);
396 return p;
397 }
398
399 static void NdrFree(MIDL_STUB_MESSAGE *pStubMsg, unsigned char *Pointer)
400 {
401 TRACE("(%p, %p)\n", pStubMsg, Pointer);
402
403 pStubMsg->pfnFree(Pointer);
404 }
405
406 static inline BOOL IsConformanceOrVariancePresent(PFORMAT_STRING pFormat)
407 {
408 return (*(const ULONG *)pFormat != -1);
409 }
410
411 static PFORMAT_STRING ReadConformance(MIDL_STUB_MESSAGE *pStubMsg, PFORMAT_STRING pFormat)
412 {
413 ALIGN_POINTER(pStubMsg->Buffer, 4);
414 if (pStubMsg->Buffer + 4 > pStubMsg->BufferEnd)
415 RpcRaiseException(RPC_X_BAD_STUB_DATA);
416 pStubMsg->MaxCount = NDR_LOCAL_UINT32_READ(pStubMsg->Buffer);
417 pStubMsg->Buffer += 4;
418 TRACE("unmarshalled conformance is %ld\n", pStubMsg->MaxCount);
419 if (pStubMsg->fHasNewCorrDesc)
420 return pFormat+6;
421 else
422 return pFormat+4;
423 }
424
425 static inline PFORMAT_STRING ReadVariance(MIDL_STUB_MESSAGE *pStubMsg, PFORMAT_STRING pFormat, ULONG MaxValue)
426 {
427 if (pFormat && !IsConformanceOrVariancePresent(pFormat))
428 {
429 pStubMsg->Offset = 0;
430 pStubMsg->ActualCount = pStubMsg->MaxCount;
431 goto done;
432 }
433
434 ALIGN_POINTER(pStubMsg->Buffer, 4);
435 if (pStubMsg->Buffer + 8 > pStubMsg->BufferEnd)
436 RpcRaiseException(RPC_X_BAD_STUB_DATA);
437 pStubMsg->Offset = NDR_LOCAL_UINT32_READ(pStubMsg->Buffer);
438 pStubMsg->Buffer += 4;
439 TRACE("offset is %d\n", pStubMsg->Offset);
440 pStubMsg->ActualCount = NDR_LOCAL_UINT32_READ(pStubMsg->Buffer);
441 pStubMsg->Buffer += 4;
442 TRACE("variance is %d\n", pStubMsg->ActualCount);
443
444 if ((pStubMsg->ActualCount > MaxValue) ||
445 (pStubMsg->ActualCount + pStubMsg->Offset > MaxValue))
446 {
447 ERR("invalid array bound(s): ActualCount = %d, Offset = %d, MaxValue = %d\n",
448 pStubMsg->ActualCount, pStubMsg->Offset, MaxValue);
449 RpcRaiseException(RPC_S_INVALID_BOUND);
450 return NULL;
451 }
452
453 done:
454 if (pStubMsg->fHasNewCorrDesc)
455 return pFormat+6;
456 else
457 return pFormat+4;
458 }
459
460 /* writes the conformance value to the buffer */
461 static inline void WriteConformance(MIDL_STUB_MESSAGE *pStubMsg)
462 {
463 ALIGN_POINTER_CLEAR(pStubMsg->Buffer, 4);
464 if (pStubMsg->Buffer + 4 > (unsigned char *)pStubMsg->RpcMsg->Buffer + pStubMsg->BufferLength)
465 RpcRaiseException(RPC_X_BAD_STUB_DATA);
466 NDR_LOCAL_UINT32_WRITE(pStubMsg->Buffer, pStubMsg->MaxCount);
467 pStubMsg->Buffer += 4;
468 }
469
470 /* writes the variance values to the buffer */
471 static inline void WriteVariance(MIDL_STUB_MESSAGE *pStubMsg)
472 {
473 ALIGN_POINTER_CLEAR(pStubMsg->Buffer, 4);
474 if (pStubMsg->Buffer + 8 > (unsigned char *)pStubMsg->RpcMsg->Buffer + pStubMsg->BufferLength)
475 RpcRaiseException(RPC_X_BAD_STUB_DATA);
476 NDR_LOCAL_UINT32_WRITE(pStubMsg->Buffer, pStubMsg->Offset);
477 pStubMsg->Buffer += 4;
478 NDR_LOCAL_UINT32_WRITE(pStubMsg->Buffer, pStubMsg->ActualCount);
479 pStubMsg->Buffer += 4;
480 }
481
482 /* requests buffer space for the conformance value */
483 static inline void SizeConformance(MIDL_STUB_MESSAGE *pStubMsg)
484 {
485 ALIGN_LENGTH(pStubMsg->BufferLength, 4);
486 if (pStubMsg->BufferLength + 4 < pStubMsg->BufferLength)
487 RpcRaiseException(RPC_X_BAD_STUB_DATA);
488 pStubMsg->BufferLength += 4;
489 }
490
491 /* requests buffer space for the variance values */
492 static inline void SizeVariance(MIDL_STUB_MESSAGE *pStubMsg)
493 {
494 ALIGN_LENGTH(pStubMsg->BufferLength, 4);
495 if (pStubMsg->BufferLength + 8 < pStubMsg->BufferLength)
496 RpcRaiseException(RPC_X_BAD_STUB_DATA);
497 pStubMsg->BufferLength += 8;
498 }
499
500 PFORMAT_STRING ComputeConformanceOrVariance(
501 MIDL_STUB_MESSAGE *pStubMsg, unsigned char *pMemory,
502 PFORMAT_STRING pFormat, ULONG_PTR def, ULONG_PTR *pCount)
503 {
504 BYTE dtype = pFormat[0] & 0xf;
505 short ofs = *(const short *)&pFormat[2];
506 LPVOID ptr = NULL;
507 DWORD data = 0;
508
509 if (!IsConformanceOrVariancePresent(pFormat)) {
510 /* null descriptor */
511 *pCount = def;
512 goto finish_conf;
513 }
514
515 switch (pFormat[0] & 0xf0) {
516 case RPC_FC_NORMAL_CONFORMANCE:
517 TRACE("normal conformance, ofs=%d\n", ofs);
518 ptr = pMemory;
519 break;
520 case RPC_FC_POINTER_CONFORMANCE:
521 TRACE("pointer conformance, ofs=%d\n", ofs);
522 ptr = pStubMsg->Memory;
523 break;
524 case RPC_FC_TOP_LEVEL_CONFORMANCE:
525 TRACE("toplevel conformance, ofs=%d\n", ofs);
526 if (pStubMsg->StackTop) {
527 ptr = pStubMsg->StackTop;
528 }
529 else {
530 /* -Os mode, *pCount is already set */
531 goto finish_conf;
532 }
533 break;
534 case RPC_FC_CONSTANT_CONFORMANCE:
535 data = ofs | ((DWORD)pFormat[1] << 16);
536 TRACE("constant conformance, val=%d\n", data);
537 *pCount = data;
538 goto finish_conf;
539 case RPC_FC_TOP_LEVEL_MULTID_CONFORMANCE:
540 FIXME("toplevel multidimensional conformance, ofs=%d\n", ofs);
541 if (pStubMsg->StackTop) {
542 ptr = pStubMsg->StackTop;
543 }
544 else {
545 /* ? */
546 goto done_conf_grab;
547 }
548 break;
549 default:
550 FIXME("unknown conformance type %x\n", pFormat[0] & 0xf0);
551 }
552
553 switch (pFormat[1]) {
554 case RPC_FC_DEREFERENCE:
555 ptr = *(LPVOID*)((char *)ptr + ofs);
556 break;
557 case RPC_FC_CALLBACK:
558 {
559 unsigned char *old_stack_top = pStubMsg->StackTop;
560 pStubMsg->StackTop = ptr;
561
562 /* ofs is index into StubDesc->apfnExprEval */
563 TRACE("callback conformance into apfnExprEval[%d]\n", ofs);
564 pStubMsg->StubDesc->apfnExprEval[ofs](pStubMsg);
565
566 pStubMsg->StackTop = old_stack_top;
567
568 /* the callback function always stores the computed value in MaxCount */
569 *pCount = pStubMsg->MaxCount;
570 goto finish_conf;
571 }
572 default:
573 ptr = (char *)ptr + ofs;
574 break;
575 }
576
577 switch (dtype) {
578 case RPC_FC_LONG:
579 case RPC_FC_ULONG:
580 data = *(DWORD*)ptr;
581 break;
582 case RPC_FC_SHORT:
583 data = *(SHORT*)ptr;
584 break;
585 case RPC_FC_USHORT:
586 data = *(USHORT*)ptr;
587 break;
588 case RPC_FC_CHAR:
589 case RPC_FC_SMALL:
590 data = *(CHAR*)ptr;
591 break;
592 case RPC_FC_BYTE:
593 case RPC_FC_USMALL:
594 data = *(UCHAR*)ptr;
595 break;
596 default:
597 FIXME("unknown conformance data type %x\n", dtype);
598 goto done_conf_grab;
599 }
600 TRACE("dereferenced data type %x at %p, got %d\n", dtype, ptr, data);
601
602 done_conf_grab:
603 switch (pFormat[1]) {
604 case RPC_FC_DEREFERENCE: /* already handled */
605 case 0: /* no op */
606 *pCount = data;
607 break;
608 case RPC_FC_ADD_1:
609 *pCount = data + 1;
610 break;
611 case RPC_FC_SUB_1:
612 *pCount = data - 1;
613 break;
614 case RPC_FC_MULT_2:
615 *pCount = data * 2;
616 break;
617 case RPC_FC_DIV_2:
618 *pCount = data / 2;
619 break;
620 default:
621 FIXME("unknown conformance op %d\n", pFormat[1]);
622 goto finish_conf;
623 }
624
625 finish_conf:
626 TRACE("resulting conformance is %ld\n", *pCount);
627 if (pStubMsg->fHasNewCorrDesc)
628 return pFormat+6;
629 else
630 return pFormat+4;
631 }
632
633 static inline PFORMAT_STRING SkipConformance(PMIDL_STUB_MESSAGE pStubMsg,
634 PFORMAT_STRING pFormat)
635 {
636 if (IsConformanceOrVariancePresent(pFormat))
637 {
638 if (pStubMsg->fHasNewCorrDesc)
639 pFormat += 6;
640 else
641 pFormat += 4;
642 }
643 return pFormat;
644 }
645
646 /* multiply two numbers together, raising an RPC_S_INVALID_BOUND exception if
647 * the result overflows 32-bits */
648 static inline ULONG safe_multiply(ULONG a, ULONG b)
649 {
650 ULONGLONG ret = (ULONGLONG)a * b;
651 if (ret > 0xffffffff)
652 {
653 RpcRaiseException(RPC_S_INVALID_BOUND);
654 return 0;
655 }
656 return ret;
657 }
658
659 static inline void safe_buffer_increment(MIDL_STUB_MESSAGE *pStubMsg, ULONG size)
660 {
661 if ((pStubMsg->Buffer + size < pStubMsg->Buffer) || /* integer overflow of pStubMsg->Buffer */
662 (pStubMsg->Buffer + size > (unsigned char *)pStubMsg->RpcMsg->Buffer + pStubMsg->BufferLength))
663 RpcRaiseException(RPC_X_BAD_STUB_DATA);
664 pStubMsg->Buffer += size;
665 }
666
667 static inline void safe_buffer_length_increment(MIDL_STUB_MESSAGE *pStubMsg, ULONG size)
668 {
669 if (pStubMsg->BufferLength + size < pStubMsg->BufferLength) /* integer overflow of pStubMsg->BufferSize */
670 {
671 ERR("buffer length overflow - BufferLength = %u, size = %u\n",
672 pStubMsg->BufferLength, size);
673 RpcRaiseException(RPC_X_BAD_STUB_DATA);
674 }
675 pStubMsg->BufferLength += size;
676 }
677
678 /* copies data from the buffer, checking that there is enough data in the buffer
679 * to do so */
680 static inline void safe_copy_from_buffer(MIDL_STUB_MESSAGE *pStubMsg, void *p, ULONG size)
681 {
682 if ((pStubMsg->Buffer + size < pStubMsg->Buffer) || /* integer overflow of pStubMsg->Buffer */
683 (pStubMsg->Buffer + size > pStubMsg->BufferEnd))
684 {
685 ERR("buffer overflow - Buffer = %p, BufferEnd = %p, size = %u\n",
686 pStubMsg->Buffer, pStubMsg->BufferEnd, size);
687 RpcRaiseException(RPC_X_BAD_STUB_DATA);
688 }
689 if (p == pStubMsg->Buffer)
690 ERR("pointer is the same as the buffer\n");
691 memcpy(p, pStubMsg->Buffer, size);
692 pStubMsg->Buffer += size;
693 }
694
695 /* copies data to the buffer, checking that there is enough space to do so */
696 static inline void safe_copy_to_buffer(MIDL_STUB_MESSAGE *pStubMsg, const void *p, ULONG size)
697 {
698 if ((pStubMsg->Buffer + size < pStubMsg->Buffer) || /* integer overflow of pStubMsg->Buffer */
699 (pStubMsg->Buffer + size > (unsigned char *)pStubMsg->RpcMsg->Buffer + pStubMsg->BufferLength))
700 {
701 ERR("buffer overflow - Buffer = %p, BufferEnd = %p, size = %u\n",
702 pStubMsg->Buffer, (unsigned char *)pStubMsg->RpcMsg->Buffer + pStubMsg->BufferLength,
703 size);
704 RpcRaiseException(RPC_X_BAD_STUB_DATA);
705 }
706 memcpy(pStubMsg->Buffer, p, size);
707 pStubMsg->Buffer += size;
708 }
709
710 /* verify that string data sitting in the buffer is valid and safe to
711 * unmarshall */
712 static void validate_string_data(MIDL_STUB_MESSAGE *pStubMsg, ULONG bufsize, ULONG esize)
713 {
714 ULONG i;
715
716 /* verify the buffer is safe to access */
717 if ((pStubMsg->Buffer + bufsize < pStubMsg->Buffer) ||
718 (pStubMsg->Buffer + bufsize > pStubMsg->BufferEnd))
719 {
720 ERR("bufsize 0x%x exceeded buffer end %p of buffer %p\n", bufsize,
721 pStubMsg->BufferEnd, pStubMsg->Buffer);
722 RpcRaiseException(RPC_X_BAD_STUB_DATA);
723 }
724
725 /* strings must always have null terminating bytes */
726 if (bufsize < esize)
727 {
728 ERR("invalid string length of %d\n", bufsize / esize);
729 RpcRaiseException(RPC_S_INVALID_BOUND);
730 }
731
732 for (i = bufsize - esize; i < bufsize; i++)
733 if (pStubMsg->Buffer[i] != 0)
734 {
735 ERR("string not null-terminated at byte position %d, data is 0x%x\n",
736 i, pStubMsg->Buffer[i]);
737 RpcRaiseException(RPC_S_INVALID_BOUND);
738 }
739 }
740
741 static inline void dump_pointer_attr(unsigned char attr)
742 {
743 if (attr & RPC_FC_P_ALLOCALLNODES)
744 TRACE(" RPC_FC_P_ALLOCALLNODES");
745 if (attr & RPC_FC_P_DONTFREE)
746 TRACE(" RPC_FC_P_DONTFREE");
747 if (attr & RPC_FC_P_ONSTACK)
748 TRACE(" RPC_FC_P_ONSTACK");
749 if (attr & RPC_FC_P_SIMPLEPOINTER)
750 TRACE(" RPC_FC_P_SIMPLEPOINTER");
751 if (attr & RPC_FC_P_DEREF)
752 TRACE(" RPC_FC_P_DEREF");
753 TRACE("\n");
754 }
755
756 /***********************************************************************
757 * PointerMarshall [internal]
758 */
759 static void PointerMarshall(PMIDL_STUB_MESSAGE pStubMsg,
760 unsigned char *Buffer,
761 unsigned char *Pointer,
762 PFORMAT_STRING pFormat)
763 {
764 unsigned type = pFormat[0], attr = pFormat[1];
765 PFORMAT_STRING desc;
766 NDR_MARSHALL m;
767 ULONG pointer_id;
768 int pointer_needs_marshaling;
769
770 TRACE("(%p,%p,%p,%p)\n", pStubMsg, Buffer, Pointer, pFormat);
771 TRACE("type=0x%x, attr=", type); dump_pointer_attr(attr);
772 pFormat += 2;
773 if (attr & RPC_FC_P_SIMPLEPOINTER) desc = pFormat;
774 else desc = pFormat + *(const SHORT*)pFormat;
775
776 switch (type) {
777 case RPC_FC_RP: /* ref pointer (always non-null) */
778 if (!Pointer)
779 {
780 ERR("NULL ref pointer is not allowed\n");
781 RpcRaiseException(RPC_X_NULL_REF_POINTER);
782 }
783 pointer_needs_marshaling = 1;
784 break;
785 case RPC_FC_UP: /* unique pointer */
786 case RPC_FC_OP: /* object pointer - same as unique here */
787 if (Pointer)
788 pointer_needs_marshaling = 1;
789 else
790 pointer_needs_marshaling = 0;
791 pointer_id = Pointer ? NDR_POINTER_ID(pStubMsg) : 0;
792 TRACE("writing 0x%08x to buffer\n", pointer_id);
793 NDR_LOCAL_UINT32_WRITE(Buffer, pointer_id);
794 break;
795 case RPC_FC_FP:
796 pointer_needs_marshaling = !NdrFullPointerQueryPointer(
797 pStubMsg->FullPtrXlatTables, Pointer, 1, &pointer_id);
798 TRACE("writing 0x%08x to buffer\n", pointer_id);
799 NDR_LOCAL_UINT32_WRITE(Buffer, pointer_id);
800 break;
801 default:
802 FIXME("unhandled ptr type=%02x\n", type);
803 RpcRaiseException(RPC_X_BAD_STUB_DATA);
804 return;
805 }
806
807 TRACE("calling marshaller for type 0x%x\n", (int)*desc);
808
809 if (pointer_needs_marshaling) {
810 if (attr & RPC_FC_P_DEREF) {
811 Pointer = *(unsigned char**)Pointer;
812 TRACE("deref => %p\n", Pointer);
813 }
814 m = NdrMarshaller[*desc & NDR_TABLE_MASK];
815 if (m) m(pStubMsg, Pointer, desc);
816 else FIXME("no marshaller for data type=%02x\n", *desc);
817 }
818
819 STD_OVERFLOW_CHECK(pStubMsg);
820 }
821
822 /***********************************************************************
823 * PointerUnmarshall [internal]
824 */
825 static void PointerUnmarshall(PMIDL_STUB_MESSAGE pStubMsg,
826 unsigned char *Buffer,
827 unsigned char **pPointer,
828 unsigned char *pSrcPointer,
829 PFORMAT_STRING pFormat,
830 unsigned char fMustAlloc)
831 {
832 unsigned type = pFormat[0], attr = pFormat[1];
833 PFORMAT_STRING desc;
834 NDR_UNMARSHALL m;
835 DWORD pointer_id = 0;
836 int pointer_needs_unmarshaling;
837
838 TRACE("(%p,%p,%p,%p,%p,%d)\n", pStubMsg, Buffer, pPointer, pSrcPointer, pFormat, fMustAlloc);
839 TRACE("type=0x%x, attr=", type); dump_pointer_attr(attr);
840 pFormat += 2;
841 if (attr & RPC_FC_P_SIMPLEPOINTER) desc = pFormat;
842 else desc = pFormat + *(const SHORT*)pFormat;
843
844 switch (type) {
845 case RPC_FC_RP: /* ref pointer (always non-null) */
846 pointer_needs_unmarshaling = 1;
847 break;
848 case RPC_FC_UP: /* unique pointer */
849 pointer_id = NDR_LOCAL_UINT32_READ(Buffer);
850 TRACE("pointer_id is 0x%08x\n", pointer_id);
851 if (pointer_id)
852 pointer_needs_unmarshaling = 1;
853 else {
854 *pPointer = NULL;
855 pointer_needs_unmarshaling = 0;
856 }
857 break;
858 case RPC_FC_OP: /* object pointer - we must free data before overwriting it */
859 pointer_id = NDR_LOCAL_UINT32_READ(Buffer);
860 TRACE("pointer_id is 0x%08x\n", pointer_id);
861 if (!fMustAlloc && pSrcPointer)
862 {
863 FIXME("free object pointer %p\n", pSrcPointer);
864 fMustAlloc = TRUE;
865 }
866 if (pointer_id)
867 pointer_needs_unmarshaling = 1;
868 else
869 {
870 *pPointer = NULL;
871 pointer_needs_unmarshaling = 0;
872 }
873 break;
874 case RPC_FC_FP:
875 pointer_id = NDR_LOCAL_UINT32_READ(Buffer);
876 TRACE("pointer_id is 0x%08x\n", pointer_id);
877 pointer_needs_unmarshaling = !NdrFullPointerQueryRefId(
878 pStubMsg->FullPtrXlatTables, pointer_id, 1, (void **)pPointer);
879 break;
880 default:
881 FIXME("unhandled ptr type=%02x\n", type);
882 RpcRaiseException(RPC_X_BAD_STUB_DATA);
883 return;
884 }
885
886 if (pointer_needs_unmarshaling) {
887 unsigned char *base_ptr_val = *pPointer;
888 unsigned char **current_ptr = pPointer;
889 if (pStubMsg->IsClient) {
890 TRACE("client\n");
891 /* if we aren't forcing allocation of memory then try to use the existing
892 * (source) pointer to unmarshall the data into so that [in,out]
893 * parameters behave correctly. it doesn't matter if the parameter is
894 * [out] only since in that case the pointer will be NULL. we force
895 * allocation when the source pointer is NULL here instead of in the type
896 * unmarshalling routine for the benefit of the deref code below */
897 if (!fMustAlloc) {
898 if (pSrcPointer) {
899 TRACE("setting *pPointer to %p\n", pSrcPointer);
900 *pPointer = base_ptr_val = pSrcPointer;
901 } else
902 fMustAlloc = TRUE;
903 }
904 } else {
905 TRACE("server\n");
906 /* the memory in a stub is never initialised, so we have to work out here
907 * whether we have to initialise it so we can use the optimisation of
908 * setting the pointer to the buffer, if possible, or set fMustAlloc to
909 * TRUE. */
910 if (attr & RPC_FC_P_DEREF) {
911 fMustAlloc = TRUE;
912 } else {
913 base_ptr_val = NULL;
914 *current_ptr = NULL;
915 }
916 }
917
918 if (attr & RPC_FC_P_ALLOCALLNODES)
919 FIXME("RPC_FC_P_ALLOCALLNODES not implemented\n");
920
921 if (attr & RPC_FC_P_DEREF) {
922 if (fMustAlloc) {
923 base_ptr_val = NdrAllocate(pStubMsg, sizeof(void *));
924 *pPointer = base_ptr_val;
925 current_ptr = (unsigned char **)base_ptr_val;
926 } else
927 current_ptr = *(unsigned char***)current_ptr;
928 TRACE("deref => %p\n", current_ptr);
929 if (!fMustAlloc && !*current_ptr) fMustAlloc = TRUE;
930 }
931 m = NdrUnmarshaller[*desc & NDR_TABLE_MASK];
932 if (m) m(pStubMsg, current_ptr, desc, fMustAlloc);
933 else FIXME("no unmarshaller for data type=%02x\n", *desc);
934
935 if (type == RPC_FC_FP)
936 NdrFullPointerInsertRefId(pStubMsg->FullPtrXlatTables, pointer_id,
937 base_ptr_val);
938 }
939
940 TRACE("pointer=%p\n", *pPointer);
941 }
942
943 /***********************************************************************
944 * PointerBufferSize [internal]
945 */
946 static void PointerBufferSize(PMIDL_STUB_MESSAGE pStubMsg,
947 unsigned char *Pointer,
948 PFORMAT_STRING pFormat)
949 {
950 unsigned type = pFormat[0], attr = pFormat[1];
951 PFORMAT_STRING desc;
952 NDR_BUFFERSIZE m;
953 int pointer_needs_sizing;
954 ULONG pointer_id;
955
956 TRACE("(%p,%p,%p)\n", pStubMsg, Pointer, pFormat);
957 TRACE("type=0x%x, attr=", type); dump_pointer_attr(attr);
958 pFormat += 2;
959 if (attr & RPC_FC_P_SIMPLEPOINTER) desc = pFormat;
960 else desc = pFormat + *(const SHORT*)pFormat;
961
962 switch (type) {
963 case RPC_FC_RP: /* ref pointer (always non-null) */
964 if (!Pointer)
965 {
966 ERR("NULL ref pointer is not allowed\n");
967 RpcRaiseException(RPC_X_NULL_REF_POINTER);
968 }
969 break;
970 case RPC_FC_OP:
971 case RPC_FC_UP:
972 /* NULL pointer has no further representation */
973 if (!Pointer)
974 return;
975 break;
976 case RPC_FC_FP:
977 pointer_needs_sizing = !NdrFullPointerQueryPointer(
978 pStubMsg->FullPtrXlatTables, Pointer, 0, &pointer_id);
979 if (!pointer_needs_sizing)
980 return;
981 break;
982 default:
983 FIXME("unhandled ptr type=%02x\n", type);
984 RpcRaiseException(RPC_X_BAD_STUB_DATA);
985 return;
986 }
987
988 if (attr & RPC_FC_P_DEREF) {
989 Pointer = *(unsigned char**)Pointer;
990 TRACE("deref => %p\n", Pointer);
991 }
992
993 m = NdrBufferSizer[*desc & NDR_TABLE_MASK];
994 if (m) m(pStubMsg, Pointer, desc);
995 else FIXME("no buffersizer for data type=%02x\n", *desc);
996 }
997
998 /***********************************************************************
999 * PointerMemorySize [internal]
1000 */
1001 static unsigned long PointerMemorySize(PMIDL_STUB_MESSAGE pStubMsg,
1002 unsigned char *Buffer,
1003 PFORMAT_STRING pFormat)
1004 {
1005 unsigned type = pFormat[0], attr = pFormat[1];
1006 PFORMAT_STRING desc;
1007 NDR_MEMORYSIZE m;
1008 DWORD pointer_id = 0;
1009 int pointer_needs_sizing;
1010
1011 TRACE("(%p,%p,%p)\n", pStubMsg, Buffer, pFormat);
1012 TRACE("type=0x%x, attr=", type); dump_pointer_attr(attr);
1013 pFormat += 2;
1014 if (attr & RPC_FC_P_SIMPLEPOINTER) desc = pFormat;
1015 else desc = pFormat + *(const SHORT*)pFormat;
1016
1017 switch (type) {
1018 case RPC_FC_RP: /* ref pointer (always non-null) */
1019 pointer_needs_sizing = 1;
1020 break;
1021 case RPC_FC_UP: /* unique pointer */
1022 case RPC_FC_OP: /* object pointer - we must free data before overwriting it */
1023 pointer_id = NDR_LOCAL_UINT32_READ(Buffer);
1024 TRACE("pointer_id is 0x%08x\n", pointer_id);
1025 if (pointer_id)
1026 pointer_needs_sizing = 1;
1027 else
1028 pointer_needs_sizing = 0;
1029 break;
1030 case RPC_FC_FP:
1031 {
1032 void *pointer;
1033 pointer_id = NDR_LOCAL_UINT32_READ(Buffer);
1034 TRACE("pointer_id is 0x%08x\n", pointer_id);
1035 pointer_needs_sizing = !NdrFullPointerQueryRefId(
1036 pStubMsg->FullPtrXlatTables, pointer_id, 1, &pointer);
1037 break;
1038 }
1039 default:
1040 FIXME("unhandled ptr type=%02x\n", type);
1041 RpcRaiseException(RPC_X_BAD_STUB_DATA);
1042 return 0;
1043 }
1044
1045 if (attr & RPC_FC_P_DEREF) {
1046 TRACE("deref\n");
1047 }
1048
1049 if (pointer_needs_sizing) {
1050 m = NdrMemorySizer[*desc & NDR_TABLE_MASK];
1051 if (m) m(pStubMsg, desc);
1052 else FIXME("no memorysizer for data type=%02x\n", *desc);
1053 }
1054
1055 return pStubMsg->MemorySize;
1056 }
1057
1058 /***********************************************************************
1059 * PointerFree [internal]
1060 */
1061 static void PointerFree(PMIDL_STUB_MESSAGE pStubMsg,
1062 unsigned char *Pointer,
1063 PFORMAT_STRING pFormat)
1064 {
1065 unsigned type = pFormat[0], attr = pFormat[1];
1066 PFORMAT_STRING desc;
1067 NDR_FREE m;
1068 unsigned char *current_pointer = Pointer;
1069
1070 TRACE("(%p,%p,%p)\n", pStubMsg, Pointer, pFormat);
1071 TRACE("type=0x%x, attr=", type); dump_pointer_attr(attr);
1072 if (attr & RPC_FC_P_DONTFREE) return;
1073 pFormat += 2;
1074 if (attr & RPC_FC_P_SIMPLEPOINTER) desc = pFormat;
1075 else desc = pFormat + *(const SHORT*)pFormat;
1076
1077 if (!Pointer) return;
1078
1079 if (type == RPC_FC_FP) {
1080 int pointer_needs_freeing = NdrFullPointerFree(
1081 pStubMsg->FullPtrXlatTables, Pointer);
1082 if (!pointer_needs_freeing)
1083 return;
1084 }
1085
1086 if (attr & RPC_FC_P_DEREF) {
1087 current_pointer = *(unsigned char**)Pointer;
1088 TRACE("deref => %p\n", current_pointer);
1089 }
1090
1091 m = NdrFreer[*desc & NDR_TABLE_MASK];
1092 if (m) m(pStubMsg, current_pointer, desc);
1093
1094 /* this check stops us from trying to free buffer memory. we don't have to
1095 * worry about clients, since they won't call this function.
1096 * we don't have to check for the buffer being reallocated because
1097 * BufferStart and BufferEnd won't be reset when allocating memory for
1098 * sending the response. we don't have to check for the new buffer here as
1099 * it won't be used a type memory, only for buffer memory */
1100 if (Pointer >= pStubMsg->BufferStart && Pointer < pStubMsg->BufferEnd)
1101 goto notfree;
1102
1103 if (attr & RPC_FC_P_ONSTACK) {
1104 TRACE("not freeing stack ptr %p\n", Pointer);
1105 return;
1106 }
1107 TRACE("freeing %p\n", Pointer);
1108 NdrFree(pStubMsg, Pointer);
1109 return;
1110 notfree:
1111 TRACE("not freeing %p\n", Pointer);
1112 }
1113
1114 /***********************************************************************
1115 * EmbeddedPointerMarshall
1116 */
1117 static unsigned char * EmbeddedPointerMarshall(PMIDL_STUB_MESSAGE pStubMsg,
1118 unsigned char *pMemory,
1119 PFORMAT_STRING pFormat)
1120 {
1121 unsigned char *Mark = pStubMsg->BufferMark;
1122 unsigned rep, count, stride;
1123 unsigned i;
1124 unsigned char *saved_buffer = NULL;
1125
1126 TRACE("(%p,%p,%p)\n", pStubMsg, pMemory, pFormat);
1127
1128 if (*pFormat != RPC_FC_PP) return NULL;
1129 pFormat += 2;
1130
1131 if (pStubMsg->PointerBufferMark)
1132 {
1133 saved_buffer = pStubMsg->Buffer;
1134 pStubMsg->Buffer = pStubMsg->PointerBufferMark;
1135 pStubMsg->PointerBufferMark = NULL;
1136 }
1137
1138 while (pFormat[0] != RPC_FC_END) {
1139 switch (pFormat[0]) {
1140 default:
1141 FIXME("unknown repeat type %d\n", pFormat[0]);
1142 case RPC_FC_NO_REPEAT:
1143 rep = 1;
1144 stride = 0;
1145 count = 1;
1146 pFormat += 2;
1147 break;
1148 case RPC_FC_FIXED_REPEAT:
1149 rep = *(const WORD*)&pFormat[2];
1150 stride = *(const WORD*)&pFormat[4];
1151 count = *(const WORD*)&pFormat[8];
1152 pFormat += 10;
1153 break;
1154 case RPC_FC_VARIABLE_REPEAT:
1155 rep = (pFormat[1] == RPC_FC_VARIABLE_OFFSET) ? pStubMsg->ActualCount : pStubMsg->MaxCount;
1156 stride = *(const WORD*)&pFormat[2];
1157 count = *(const WORD*)&pFormat[6];
1158 pFormat += 8;
1159 break;
1160 }
1161 for (i = 0; i < rep; i++) {
1162 PFORMAT_STRING info = pFormat;
1163 unsigned char *membase = pMemory + (i * stride);
1164 unsigned char *bufbase = Mark + (i * stride);
1165 unsigned u;
1166
1167 for (u=0; u<count; u++,info+=8) {
1168 unsigned char *memptr = membase + *(const SHORT*)&info[0];
1169 unsigned char *bufptr = bufbase + *(const SHORT*)&info[2];
1170 unsigned char *saved_memory = pStubMsg->Memory;
1171
1172 pStubMsg->Memory = pMemory;
1173 PointerMarshall(pStubMsg, bufptr, *(unsigned char**)memptr, info+4);
1174 pStubMsg->Memory = saved_memory;
1175 }
1176 }
1177 pFormat += 8 * count;
1178 }
1179
1180 if (saved_buffer)
1181 {
1182 pStubMsg->PointerBufferMark = pStubMsg->Buffer;
1183 pStubMsg->Buffer = saved_buffer;
1184 }
1185
1186 STD_OVERFLOW_CHECK(pStubMsg);
1187
1188 return NULL;
1189 }
1190
1191 /***********************************************************************
1192 * EmbeddedPointerUnmarshall
1193 */
1194 static unsigned char * EmbeddedPointerUnmarshall(PMIDL_STUB_MESSAGE pStubMsg,
1195 unsigned char *pDstBuffer,
1196 unsigned char *pSrcMemoryPtrs,
1197 PFORMAT_STRING pFormat,
1198 unsigned char fMustAlloc)
1199 {
1200 unsigned char *Mark = pStubMsg->BufferMark;
1201 unsigned rep, count, stride;
1202 unsigned i;
1203 unsigned char *saved_buffer = NULL;
1204
1205 TRACE("(%p,%p,%p,%p,%d)\n", pStubMsg, pDstBuffer, pSrcMemoryPtrs, pFormat, fMustAlloc);
1206
1207 if (*pFormat != RPC_FC_PP) return NULL;
1208 pFormat += 2;
1209
1210 if (pStubMsg->PointerBufferMark)
1211 {
1212 saved_buffer = pStubMsg->Buffer;
1213 pStubMsg->Buffer = pStubMsg->PointerBufferMark;
1214 pStubMsg->PointerBufferMark = NULL;
1215 }
1216
1217 while (pFormat[0] != RPC_FC_END) {
1218 TRACE("pFormat[0] = 0x%x\n", pFormat[0]);
1219 switch (pFormat[0]) {
1220 default:
1221 FIXME("unknown repeat type %d\n", pFormat[0]);
1222 case RPC_FC_NO_REPEAT:
1223 rep = 1;
1224 stride = 0;
1225 count = 1;
1226 pFormat += 2;
1227 break;
1228 case RPC_FC_FIXED_REPEAT:
1229 rep = *(const WORD*)&pFormat[2];
1230 stride = *(const WORD*)&pFormat[4];
1231 count = *(const WORD*)&pFormat[8];
1232 pFormat += 10;
1233 break;
1234 case RPC_FC_VARIABLE_REPEAT:
1235 rep = (pFormat[1] == RPC_FC_VARIABLE_OFFSET) ? pStubMsg->ActualCount : pStubMsg->MaxCount;
1236 stride = *(const WORD*)&pFormat[2];
1237 count = *(const WORD*)&pFormat[6];
1238 pFormat += 8;
1239 break;
1240 }
1241 for (i = 0; i < rep; i++) {
1242 PFORMAT_STRING info = pFormat;
1243 unsigned char *bufdstbase = pDstBuffer + (i * stride);
1244 unsigned char *memsrcbase = pSrcMemoryPtrs + (i * stride);
1245 unsigned char *bufbase = Mark + (i * stride);
1246 unsigned u;
1247
1248 for (u=0; u<count; u++,info+=8) {
1249 unsigned char **bufdstptr = (unsigned char **)(bufdstbase + *(const SHORT*)&info[2]);
1250 unsigned char **memsrcptr = (unsigned char **)(memsrcbase + *(const SHORT*)&info[0]);
1251 unsigned char *bufptr = bufbase + *(const SHORT*)&info[2];
1252 PointerUnmarshall(pStubMsg, bufptr, bufdstptr, *memsrcptr, info+4, fMustAlloc);
1253 }
1254 }
1255 pFormat += 8 * count;
1256 }
1257
1258 if (saved_buffer)
1259 {
1260 pStubMsg->PointerBufferMark = pStubMsg->Buffer;
1261 pStubMsg->Buffer = saved_buffer;
1262 }
1263
1264 return NULL;
1265 }
1266
1267 /***********************************************************************
1268 * EmbeddedPointerBufferSize
1269 */
1270 static void EmbeddedPointerBufferSize(PMIDL_STUB_MESSAGE pStubMsg,
1271 unsigned char *pMemory,
1272 PFORMAT_STRING pFormat)
1273 {
1274 unsigned rep, count, stride;
1275 unsigned i;
1276 ULONG saved_buffer_length = 0;
1277
1278 TRACE("(%p,%p,%p)\n", pStubMsg, pMemory, pFormat);
1279
1280 if (pStubMsg->IgnoreEmbeddedPointers) return;
1281
1282 if (*pFormat != RPC_FC_PP) return;
1283 pFormat += 2;
1284
1285 if (pStubMsg->PointerLength)
1286 {
1287 saved_buffer_length = pStubMsg->BufferLength;
1288 pStubMsg->BufferLength = pStubMsg->PointerLength;
1289 pStubMsg->PointerLength = 0;
1290 }
1291
1292 while (pFormat[0] != RPC_FC_END) {
1293 switch (pFormat[0]) {
1294 default:
1295 FIXME("unknown repeat type %d\n", pFormat[0]);
1296 case RPC_FC_NO_REPEAT:
1297 rep = 1;
1298 stride = 0;
1299 count = 1;
1300 pFormat += 2;
1301 break;
1302 case RPC_FC_FIXED_REPEAT:
1303 rep = *(const WORD*)&pFormat[2];
1304 stride = *(const WORD*)&pFormat[4];
1305 count = *(const WORD*)&pFormat[8];
1306 pFormat += 10;
1307 break;
1308 case RPC_FC_VARIABLE_REPEAT:
1309 rep = (pFormat[1] == RPC_FC_VARIABLE_OFFSET) ? pStubMsg->ActualCount : pStubMsg->MaxCount;
1310 stride = *(const WORD*)&pFormat[2];
1311 count = *(const WORD*)&pFormat[6];
1312 pFormat += 8;
1313 break;
1314 }
1315 for (i = 0; i < rep; i++) {
1316 PFORMAT_STRING info = pFormat;
1317 unsigned char *membase = pMemory + (i * stride);
1318 unsigned u;
1319
1320 for (u=0; u<count; u++,info+=8) {
1321 unsigned char *memptr = membase + *(const SHORT*)&info[0];
1322 unsigned char *saved_memory = pStubMsg->Memory;
1323
1324 pStubMsg->Memory = pMemory;
1325 PointerBufferSize(pStubMsg, *(unsigned char**)memptr, info+4);
1326 pStubMsg->Memory = saved_memory;
1327 }
1328 }
1329 pFormat += 8 * count;
1330 }
1331
1332 if (saved_buffer_length)
1333 {
1334 pStubMsg->PointerLength = pStubMsg->BufferLength;
1335 pStubMsg->BufferLength = saved_buffer_length;
1336 }
1337 }
1338
1339 /***********************************************************************
1340 * EmbeddedPointerMemorySize [internal]
1341 */
1342 static unsigned long EmbeddedPointerMemorySize(PMIDL_STUB_MESSAGE pStubMsg,
1343 PFORMAT_STRING pFormat)
1344 {
1345 unsigned char *Mark = pStubMsg->BufferMark;
1346 unsigned rep, count, stride;
1347 unsigned i;
1348 unsigned char *saved_buffer = NULL;
1349
1350 TRACE("(%p,%p)\n", pStubMsg, pFormat);
1351
1352 if (pStubMsg->IgnoreEmbeddedPointers) return 0;
1353
1354 if (pStubMsg->PointerBufferMark)
1355 {
1356 saved_buffer = pStubMsg->Buffer;
1357 pStubMsg->Buffer = pStubMsg->PointerBufferMark;
1358 pStubMsg->PointerBufferMark = NULL;
1359 }
1360
1361 if (*pFormat != RPC_FC_PP) return 0;
1362 pFormat += 2;
1363
1364 while (pFormat[0] != RPC_FC_END) {
1365 switch (pFormat[0]) {
1366 default:
1367 FIXME("unknown repeat type %d\n", pFormat[0]);
1368 case RPC_FC_NO_REPEAT:
1369 rep = 1;
1370 stride = 0;
1371 count = 1;
1372 pFormat += 2;
1373 break;
1374 case RPC_FC_FIXED_REPEAT:
1375 rep = *(const WORD*)&pFormat[2];
1376 stride = *(const WORD*)&pFormat[4];
1377 count = *(const WORD*)&pFormat[8];
1378 pFormat += 10;
1379 break;
1380 case RPC_FC_VARIABLE_REPEAT:
1381 rep = (pFormat[1] == RPC_FC_VARIABLE_OFFSET) ? pStubMsg->ActualCount : pStubMsg->MaxCount;
1382 stride = *(const WORD*)&pFormat[2];
1383 count = *(const WORD*)&pFormat[6];
1384 pFormat += 8;
1385 break;
1386 }
1387 for (i = 0; i < rep; i++) {
1388 PFORMAT_STRING info = pFormat;
1389 unsigned char *bufbase = Mark + (i * stride);
1390 unsigned u;
1391 for (u=0; u<count; u++,info+=8) {
1392 unsigned char *bufptr = bufbase + *(const SHORT*)&info[2];
1393 PointerMemorySize(pStubMsg, bufptr, info+4);
1394 }
1395 }
1396 pFormat += 8 * count;
1397 }
1398
1399 if (saved_buffer)
1400 {
1401 pStubMsg->PointerBufferMark = pStubMsg->Buffer;
1402 pStubMsg->Buffer = saved_buffer;
1403 }
1404
1405 return 0;
1406 }
1407
1408 /***********************************************************************
1409 * EmbeddedPointerFree [internal]
1410 */
1411 static void EmbeddedPointerFree(PMIDL_STUB_MESSAGE pStubMsg,
1412 unsigned char *pMemory,
1413 PFORMAT_STRING pFormat)
1414 {
1415 unsigned rep, count, stride;
1416 unsigned i;
1417
1418 TRACE("(%p,%p,%p)\n", pStubMsg, pMemory, pFormat);
1419 if (*pFormat != RPC_FC_PP) return;
1420 pFormat += 2;
1421
1422 while (pFormat[0] != RPC_FC_END) {
1423 switch (pFormat[0]) {
1424 default:
1425 FIXME("unknown repeat type %d\n", pFormat[0]);
1426 case RPC_FC_NO_REPEAT:
1427 rep = 1;
1428 stride = 0;
1429 count = 1;
1430 pFormat += 2;
1431 break;
1432 case RPC_FC_FIXED_REPEAT:
1433 rep = *(const WORD*)&pFormat[2];
1434 stride = *(const WORD*)&pFormat[4];
1435 count = *(const WORD*)&pFormat[8];
1436 pFormat += 10;
1437 break;
1438 case RPC_FC_VARIABLE_REPEAT:
1439 rep = (pFormat[1] == RPC_FC_VARIABLE_OFFSET) ? pStubMsg->ActualCount : pStubMsg->MaxCount;
1440 stride = *(const WORD*)&pFormat[2];
1441 count = *(const WORD*)&pFormat[6];
1442 pFormat += 8;
1443 break;
1444 }
1445 for (i = 0; i < rep; i++) {
1446 PFORMAT_STRING info = pFormat;
1447 unsigned char *membase = pMemory + (i * stride);
1448 unsigned u;
1449
1450 for (u=0; u<count; u++,info+=8) {
1451 unsigned char *memptr = membase + *(const SHORT*)&info[0];
1452 unsigned char *saved_memory = pStubMsg->Memory;
1453
1454 pStubMsg->Memory = pMemory;
1455 PointerFree(pStubMsg, *(unsigned char**)memptr, info+4);
1456 pStubMsg->Memory = saved_memory;
1457 }
1458 }
1459 pFormat += 8 * count;
1460 }
1461 }
1462
1463 /***********************************************************************
1464 * NdrPointerMarshall [RPCRT4.@]
1465 */
1466 unsigned char * WINAPI NdrPointerMarshall(PMIDL_STUB_MESSAGE pStubMsg,
1467 unsigned char *pMemory,
1468 PFORMAT_STRING pFormat)
1469 {
1470 unsigned char *Buffer;
1471
1472 TRACE("(%p,%p,%p)\n", pStubMsg, pMemory, pFormat);
1473
1474 /* Increment the buffer here instead of in PointerMarshall,
1475 * as that is used by embedded pointers which already handle the incrementing
1476 * the buffer, and shouldn't write any additional pointer data to the wire */
1477 if (*pFormat != RPC_FC_RP)
1478 {
1479 ALIGN_POINTER_CLEAR(pStubMsg->Buffer, 4);
1480 Buffer = pStubMsg->Buffer;
1481 safe_buffer_increment(pStubMsg, 4);
1482 }
1483 else
1484 Buffer = pStubMsg->Buffer;
1485
1486 PointerMarshall(pStubMsg, Buffer, pMemory, pFormat);
1487
1488 return NULL;
1489 }
1490
1491 /***********************************************************************
1492 * NdrPointerUnmarshall [RPCRT4.@]
1493 */
1494 unsigned char * WINAPI NdrPointerUnmarshall(PMIDL_STUB_MESSAGE pStubMsg,
1495 unsigned char **ppMemory,
1496 PFORMAT_STRING pFormat,
1497 unsigned char fMustAlloc)
1498 {
1499 unsigned char *Buffer;
1500
1501 TRACE("(%p,%p,%p,%d)\n", pStubMsg, ppMemory, pFormat, fMustAlloc);
1502
1503 if (*pFormat == RPC_FC_RP)
1504 {
1505 Buffer = pStubMsg->Buffer;
1506 /* Do the NULL ref pointer check here because embedded pointers can be
1507 * NULL if the type the pointer is embedded in was allocated rather than
1508 * being passed in by the client */
1509 if (pStubMsg->IsClient && !*ppMemory)
1510 {
1511 ERR("NULL ref pointer is not allowed\n");
1512 RpcRaiseException(RPC_X_NULL_REF_POINTER);
1513 }
1514 }
1515 else
1516 {
1517 /* Increment the buffer here instead of in PointerUnmarshall,
1518 * as that is used by embedded pointers which already handle the incrementing
1519 * the buffer, and shouldn't read any additional pointer data from the
1520 * buffer */
1521 ALIGN_POINTER(pStubMsg->Buffer, 4);
1522 Buffer = pStubMsg->Buffer;
1523 safe_buffer_increment(pStubMsg, 4);
1524 }
1525
1526 PointerUnmarshall(pStubMsg, Buffer, ppMemory, *ppMemory, pFormat, fMustAlloc);
1527
1528 return NULL;
1529 }
1530
1531 /***********************************************************************
1532 * NdrPointerBufferSize [RPCRT4.@]
1533 */
1534 void WINAPI NdrPointerBufferSize(PMIDL_STUB_MESSAGE pStubMsg,
1535 unsigned char *pMemory,
1536 PFORMAT_STRING pFormat)
1537 {
1538 TRACE("(%p,%p,%p)\n", pStubMsg, pMemory, pFormat);
1539
1540 /* Increment the buffer length here instead of in PointerBufferSize,
1541 * as that is used by embedded pointers which already handle the buffer
1542 * length, and shouldn't write anything more to the wire */
1543 if (*pFormat != RPC_FC_RP)
1544 {
1545 ALIGN_LENGTH(pStubMsg->BufferLength, 4);
1546 safe_buffer_length_increment(pStubMsg, 4);
1547 }
1548
1549 PointerBufferSize(pStubMsg, pMemory, pFormat);
1550 }
1551
1552 /***********************************************************************
1553 * NdrPointerMemorySize [RPCRT4.@]
1554 */
1555 ULONG WINAPI NdrPointerMemorySize(PMIDL_STUB_MESSAGE pStubMsg,
1556 PFORMAT_STRING pFormat)
1557 {
1558 /* unsigned size = *(LPWORD)(pFormat+2); */
1559 FIXME("(%p,%p): stub\n", pStubMsg, pFormat);
1560 PointerMemorySize(pStubMsg, pStubMsg->Buffer, pFormat);
1561 return 0;
1562 }
1563
1564 /***********************************************************************
1565 * NdrPointerFree [RPCRT4.@]
1566 */
1567 void WINAPI NdrPointerFree(PMIDL_STUB_MESSAGE pStubMsg,
1568 unsigned char *pMemory,
1569 PFORMAT_STRING pFormat)
1570 {
1571 TRACE("(%p,%p,%p)\n", pStubMsg, pMemory, pFormat);
1572 PointerFree(pStubMsg, pMemory, pFormat);
1573 }
1574
1575 /***********************************************************************
1576 * NdrSimpleTypeMarshall [RPCRT4.@]
1577 */
1578 void WINAPI NdrSimpleTypeMarshall( PMIDL_STUB_MESSAGE pStubMsg, unsigned char* pMemory,
1579 unsigned char FormatChar )
1580 {
1581 NdrBaseTypeMarshall(pStubMsg, pMemory, &FormatChar);
1582 }
1583
1584 /***********************************************************************
1585 * NdrSimpleTypeUnmarshall [RPCRT4.@]
1586 *
1587 * Unmarshall a base type.
1588 *
1589 * NOTES
1590 * Doesn't check that the buffer is long enough before copying, so the caller
1591 * should do this.
1592 */
1593 void WINAPI NdrSimpleTypeUnmarshall( PMIDL_STUB_MESSAGE pStubMsg, unsigned char* pMemory,
1594 unsigned char FormatChar )
1595 {
1596 #define BASE_TYPE_UNMARSHALL(type) \
1597 ALIGN_POINTER(pStubMsg->Buffer, sizeof(type)); \
1598 TRACE("pMemory: %p\n", pMemory); \
1599 *(type *)pMemory = *(type *)pStubMsg->Buffer; \
1600 pStubMsg->Buffer += sizeof(type);
1601
1602 switch(FormatChar)
1603 {
1604 case RPC_FC_BYTE:
1605 case RPC_FC_CHAR:
1606 case RPC_FC_SMALL:
1607 case RPC_FC_USMALL:
1608 BASE_TYPE_UNMARSHALL(UCHAR);
1609 TRACE("value: 0x%02x\n", *pMemory);
1610 break;
1611 case RPC_FC_WCHAR:
1612 case RPC_FC_SHORT:
1613 case RPC_FC_USHORT:
1614 BASE_TYPE_UNMARSHALL(USHORT);
1615 TRACE("value: 0x%04x\n", *(USHORT *)pMemory);
1616 break;
1617 case RPC_FC_LONG:
1618 case RPC_FC_ULONG:
1619 case RPC_FC_ERROR_STATUS_T:
1620 case RPC_FC_ENUM32:
1621 BASE_TYPE_UNMARSHALL(ULONG);
1622 TRACE("value: 0x%08x\n", *(ULONG *)pMemory);
1623 break;
1624 case RPC_FC_FLOAT:
1625 BASE_TYPE_UNMARSHALL(float);
1626 TRACE("value: %f\n", *(float *)pMemory);
1627 break;
1628 case RPC_FC_DOUBLE:
1629 BASE_TYPE_UNMARSHALL(double);
1630 TRACE("value: %f\n", *(double *)pMemory);
1631 break;
1632 case RPC_FC_HYPER:
1633 BASE_TYPE_UNMARSHALL(ULONGLONG);
1634 TRACE("value: %s\n", wine_dbgstr_longlong(*(ULONGLONG *)pMemory));
1635 break;
1636 case RPC_FC_ENUM16:
1637 ALIGN_POINTER(pStubMsg->Buffer, sizeof(USHORT));
1638 TRACE("pMemory: %p\n", pMemory);
1639 /* 16-bits on the wire, but int in memory */
1640 *(UINT *)pMemory = *(USHORT *)pStubMsg->Buffer;
1641 pStubMsg->Buffer += sizeof(USHORT);
1642 TRACE("value: 0x%08x\n", *(UINT *)pMemory);
1643 break;
1644 case RPC_FC_IGNORE:
1645 break;
1646 default:
1647 FIXME("Unhandled base type: 0x%02x\n", FormatChar);
1648 }
1649 #undef BASE_TYPE_UNMARSHALL
1650 }
1651
1652 /***********************************************************************
1653 * NdrSimpleStructMarshall [RPCRT4.@]
1654 */
1655 unsigned char * WINAPI NdrSimpleStructMarshall(PMIDL_STUB_MESSAGE pStubMsg,
1656 unsigned char *pMemory,
1657 PFORMAT_STRING pFormat)
1658 {
1659 unsigned size = *(const WORD*)(pFormat+2);
1660 TRACE("(%p,%p,%p)\n", pStubMsg, pMemory, pFormat);
1661
1662 ALIGN_POINTER_CLEAR(pStubMsg->Buffer, pFormat[1] + 1);
1663
1664 pStubMsg->BufferMark = pStubMsg->Buffer;
1665 safe_copy_to_buffer(pStubMsg, pMemory, size);
1666
1667 if (pFormat[0] != RPC_FC_STRUCT)
1668 EmbeddedPointerMarshall(pStubMsg, pMemory, pFormat+4);
1669
1670 return NULL;
1671 }
1672
1673 /***********************************************************************
1674 * NdrSimpleStructUnmarshall [RPCRT4.@]
1675 */
1676 unsigned char * WINAPI NdrSimpleStructUnmarshall(PMIDL_STUB_MESSAGE pStubMsg,
1677 unsigned char **ppMemory,
1678 PFORMAT_STRING pFormat,
1679 unsigned char fMustAlloc)
1680 {
1681 unsigned size = *(const WORD*)(pFormat+2);
1682 unsigned char *saved_buffer;
1683 TRACE("(%p,%p,%p,%d)\n", pStubMsg, ppMemory, pFormat, fMustAlloc);
1684
1685 ALIGN_POINTER(pStubMsg->Buffer, pFormat[1] + 1);
1686
1687 if (fMustAlloc)
1688 *ppMemory = NdrAllocate(pStubMsg, size);
1689 else
1690 {
1691 if (!pStubMsg->IsClient && !*ppMemory)
1692 /* for servers, we just point straight into the RPC buffer */
1693 *ppMemory = pStubMsg->Buffer;
1694 }
1695
1696 saved_buffer = pStubMsg->BufferMark = pStubMsg->Buffer;
1697 safe_buffer_increment(pStubMsg, size);
1698 if (pFormat[0] == RPC_FC_PSTRUCT)
1699 EmbeddedPointerUnmarshall(pStubMsg, saved_buffer, *ppMemory, pFormat+4, fMustAlloc);
1700
1701 TRACE("copying %p to %p\n", saved_buffer, *ppMemory);
1702 if (*ppMemory != saved_buffer)
1703 memcpy(*ppMemory, saved_buffer, size);
1704
1705 return NULL;
1706 }
1707
1708 /***********************************************************************
1709 * NdrSimpleStructBufferSize [RPCRT4.@]
1710 */
1711 void WINAPI NdrSimpleStructBufferSize(PMIDL_STUB_MESSAGE pStubMsg,
1712 unsigned char *pMemory,
1713 PFORMAT_STRING pFormat)
1714 {
1715 unsigned size = *(const WORD*)(pFormat+2);
1716 TRACE("(%p,%p,%p)\n", pStubMsg, pMemory, pFormat);
1717
1718 ALIGN_LENGTH(pStubMsg->BufferLength, pFormat[1] + 1);
1719
1720 safe_buffer_length_increment(pStubMsg, size);
1721 if (pFormat[0] != RPC_FC_STRUCT)
1722 EmbeddedPointerBufferSize(pStubMsg, pMemory, pFormat+4);
1723 }
1724
1725 /***********************************************************************
1726 * NdrSimpleStructMemorySize [RPCRT4.@]
1727 */
1728 ULONG WINAPI NdrSimpleStructMemorySize(PMIDL_STUB_MESSAGE pStubMsg,
1729 PFORMAT_STRING pFormat)
1730 {
1731 unsigned short size = *(const WORD *)(pFormat+2);
1732
1733 TRACE("(%p,%p)\n", pStubMsg, pFormat);
1734
1735 ALIGN_POINTER(pStubMsg->Buffer, pFormat[1] + 1);
1736 pStubMsg->MemorySize += size;
1737 safe_buffer_increment(pStubMsg, size);
1738
1739 if (pFormat[0] != RPC_FC_STRUCT)
1740 EmbeddedPointerMemorySize(pStubMsg, pFormat+4);
1741 return pStubMsg->MemorySize;
1742 }
1743
1744 /***********************************************************************
1745 * NdrSimpleStructFree [RPCRT4.@]
1746 */
1747 void WINAPI NdrSimpleStructFree(PMIDL_STUB_MESSAGE pStubMsg,
1748 unsigned char *pMemory,
1749 PFORMAT_STRING pFormat)
1750 {
1751 TRACE("(%p,%p,%p)\n", pStubMsg, pMemory, pFormat);
1752 if (pFormat[0] != RPC_FC_STRUCT)
1753 EmbeddedPointerFree(pStubMsg, pMemory, pFormat+4);
1754 }
1755
1756 /* Array helpers */
1757
1758 static inline void array_compute_and_size_conformance(
1759 unsigned char fc, PMIDL_STUB_MESSAGE pStubMsg, unsigned char *pMemory,
1760 PFORMAT_STRING pFormat)
1761 {
1762 switch (fc)
1763 {
1764 case RPC_FC_CARRAY:
1765 ComputeConformance(pStubMsg, pMemory, pFormat+4, 0);
1766 SizeConformance(pStubMsg);
1767 break;
1768 case RPC_FC_CVARRAY:
1769 pFormat = ComputeConformance(pStubMsg, pMemory, pFormat + 4, 0);
1770 pFormat = ComputeVariance(pStubMsg, pMemory, pFormat, 0);
1771 SizeConformance(pStubMsg);
1772 break;
1773 case RPC_FC_C_CSTRING:
1774 case RPC_FC_C_WSTRING:
1775 if (pFormat[0] == RPC_FC_C_CSTRING)
1776 {
1777 TRACE("string=%s\n", debugstr_a((const char *)pMemory));
1778 pStubMsg->ActualCount = strlen((const char *)pMemory)+1;
1779 }
1780 else
1781 {
1782 TRACE("string=%s\n", debugstr_w((LPCWSTR)pMemory));
1783 pStubMsg->ActualCount = strlenW((LPCWSTR)pMemory)+1;
1784 }
1785
1786 if (fc == RPC_FC_STRING_SIZED)
1787 pFormat = ComputeConformance(pStubMsg, pMemory, pFormat + 2, 0);
1788 else
1789 pStubMsg->MaxCount = pStubMsg->ActualCount;
1790
1791 SizeConformance(pStubMsg);
1792 break;
1793 default:
1794 ERR("unknown array format 0x%x\n", fc);
1795 RpcRaiseException(RPC_X_BAD_STUB_DATA);
1796 }
1797 }
1798
1799 static inline void array_buffer_size(
1800 unsigned char fc, PMIDL_STUB_MESSAGE pStubMsg, unsigned char *pMemory,
1801 PFORMAT_STRING pFormat, unsigned char fHasPointers)
1802 {
1803 DWORD size;
1804 DWORD esize;
1805 unsigned char alignment;
1806
1807 switch (fc)
1808 {
1809 case RPC_FC_CARRAY:
1810 esize = *(const WORD*)(pFormat+2);
1811 alignment = pFormat[1] + 1;
1812
1813 pFormat = SkipConformance(pStubMsg, pFormat + 4);
1814
1815 ALIGN_LENGTH(pStubMsg->BufferLength, alignment);
1816
1817 size = safe_multiply(esize, pStubMsg->MaxCount);
1818 /* conformance value plus array */
1819 safe_buffer_length_increment(pStubMsg, size);
1820
1821 if (fHasPointers)
1822 EmbeddedPointerBufferSize(pStubMsg, pMemory, pFormat);
1823 break;
1824 case RPC_FC_CVARRAY:
1825 esize = *(const WORD*)(pFormat+2);
1826 alignment = pFormat[1] + 1;
1827
1828 pFormat = SkipConformance(pStubMsg, pFormat + 4);
1829 pFormat = SkipConformance(pStubMsg, pFormat);
1830
1831 SizeVariance(pStubMsg);
1832
1833 ALIGN_LENGTH(pStubMsg->BufferLength, alignment);
1834
1835 size = safe_multiply(esize, pStubMsg->ActualCount);
1836 safe_buffer_length_increment(pStubMsg, size);
1837
1838 if (fHasPointers)
1839 EmbeddedPointerBufferSize(pStubMsg, pMemory, pFormat);
1840 break;
1841 case RPC_FC_C_CSTRING:
1842 case RPC_FC_C_WSTRING:
1843 if (fc == RPC_FC_C_CSTRING)
1844 esize = 1;
1845 else
1846 esize = 2;
1847
1848 SizeVariance(pStubMsg);
1849
1850 size = safe_multiply(esize, pStubMsg->ActualCount);
1851 safe_buffer_length_increment(pStubMsg, size);
1852 break;
1853 default:
1854 ERR("unknown array format 0x%x\n", fc);
1855 RpcRaiseException(RPC_X_BAD_STUB_DATA);
1856 }
1857 }
1858
1859 static inline void array_compute_and_write_conformance(
1860 unsigned char fc, PMIDL_STUB_MESSAGE pStubMsg, unsigned char *pMemory,
1861 PFORMAT_STRING pFormat)
1862 {
1863 switch (fc)
1864 {
1865 case RPC_FC_CARRAY:
1866 ComputeConformance(pStubMsg, pMemory, pFormat+4, 0);
1867 WriteConformance(pStubMsg);
1868 break;
1869 case RPC_FC_CVARRAY:
1870 pFormat = ComputeConformance(pStubMsg, pMemory, pFormat + 4, 0);
1871 pFormat = ComputeVariance(pStubMsg, pMemory, pFormat, 0);
1872 WriteConformance(pStubMsg);
1873 break;
1874 case RPC_FC_C_CSTRING:
1875 case RPC_FC_C_WSTRING:
1876 if (fc == RPC_FC_C_CSTRING)
1877 {
1878 TRACE("string=%s\n", debugstr_a((const char *)pMemory));
1879 pStubMsg->ActualCount = strlen((const char *)pMemory)+1;
1880 }
1881 else
1882 {
1883 TRACE("string=%s\n", debugstr_w((LPCWSTR)pMemory));
1884 pStubMsg->ActualCount = strlenW((LPCWSTR)pMemory)+1;
1885 }
1886 if (pFormat[1] == RPC_FC_STRING_SIZED)
1887 pFormat = ComputeConformance(pStubMsg, pMemory, pFormat + 2, 0);
1888 else
1889 pStubMsg->MaxCount = pStubMsg->ActualCount;
1890 pStubMsg->Offset = 0;
1891 WriteConformance(pStubMsg);
1892 break;
1893 default:
1894 ERR("unknown array format 0x%x\n", fc);
1895 RpcRaiseException(RPC_X_BAD_STUB_DATA);
1896 }
1897 }
1898
1899 static inline void array_write_variance_and_marshall(
1900 unsigned char fc, PMIDL_STUB_MESSAGE pStubMsg, unsigned char *pMemory,
1901 PFORMAT_STRING pFormat, unsigned char fHasPointers)
1902 {
1903 DWORD size;
1904 DWORD esize;
1905 unsigned char alignment;
1906
1907 switch (fc)
1908 {
1909 case RPC_FC_CARRAY:
1910 esize = *(const WORD*)(pFormat+2);
1911 alignment = pFormat[1] + 1;
1912
1913 pFormat = SkipConformance(pStubMsg, pFormat + 4);
1914
1915 ALIGN_POINTER_CLEAR(pStubMsg->Buffer, alignment);
1916
1917 size = safe_multiply(esize, pStubMsg->MaxCount);
1918 if (fHasPointers)
1919 pStubMsg->BufferMark = pStubMsg->Buffer;
1920 safe_copy_to_buffer(pStubMsg, pMemory, size);
1921
1922 if (fHasPointers)
1923 EmbeddedPointerMarshall(pStubMsg, pMemory, pFormat);
1924 break;
1925 case RPC_FC_CVARRAY:
1926 esize = *(const WORD*)(pFormat+2);
1927 alignment = pFormat[1] + 1;
1928
1929 /* conformance */
1930 pFormat = SkipConformance(pStubMsg, pFormat + 4);
1931 /* variance */
1932 pFormat = SkipConformance(pStubMsg, pFormat);
1933
1934 WriteVariance(pStubMsg);
1935
1936 ALIGN_POINTER_CLEAR(pStubMsg->Buffer, alignment);
1937
1938 size = safe_multiply(esize, pStubMsg->ActualCount);
1939
1940 if (fHasPointers)
1941 pStubMsg->BufferMark = pStubMsg->Buffer;
1942 safe_copy_to_buffer(pStubMsg, pMemory + pStubMsg->Offset, size);
1943
1944 if (fHasPointers)
1945 EmbeddedPointerMarshall(pStubMsg, pMemory, pFormat);
1946 break;
1947 case RPC_FC_C_CSTRING:
1948 case RPC_FC_C_WSTRING:
1949 if (fc == RPC_FC_C_CSTRING)
1950 esize = 1;
1951 else
1952 esize = 2;
1953
1954 WriteVariance(pStubMsg);
1955
1956 size = safe_multiply(esize, pStubMsg->ActualCount);
1957 safe_copy_to_buffer(pStubMsg, pMemory, size); /* the string itself */
1958 break;
1959 default:
1960 ERR("unknown array format 0x%x\n", fc);
1961 RpcRaiseException(RPC_X_BAD_STUB_DATA);
1962 }
1963 }
1964
1965 static inline ULONG array_read_conformance(
1966 unsigned char fc, PMIDL_STUB_MESSAGE pStubMsg, PFORMAT_STRING pFormat)
1967 {
1968 DWORD esize;
1969
1970 switch (fc)
1971 {
1972 case RPC_FC_CARRAY:
1973 esize = *(const WORD*)(pFormat+2);
1974 pFormat = ReadConformance(pStubMsg, pFormat+4);
1975 return safe_multiply(esize, pStubMsg->MaxCount);
1976 case RPC_FC_CVARRAY:
1977 esize = *(const WORD*)(pFormat+2);
1978 pFormat = ReadConformance(pStubMsg, pFormat+4);
1979 return safe_multiply(esize, pStubMsg->MaxCount);
1980 case RPC_FC_C_CSTRING:
1981 case RPC_FC_C_WSTRING:
1982 if (fc == RPC_FC_C_CSTRING)
1983 esize = 1;
1984 else
1985 esize = 2;
1986
1987 if (pFormat[1] == RPC_FC_STRING_SIZED)
1988 ReadConformance(pStubMsg, pFormat + 2);
1989 else
1990 ReadConformance(pStubMsg, NULL);
1991 return safe_multiply(esize, pStubMsg->MaxCount);
1992 default:
1993 ERR("unknown array format 0x%x\n", fc);
1994 RpcRaiseException(RPC_X_BAD_STUB_DATA);
1995 }
1996 }
1997
1998 static inline ULONG array_read_variance_and_unmarshall(
1999 unsigned char fc, PMIDL_STUB_MESSAGE pStubMsg, unsigned char **ppMemory,
2000 PFORMAT_STRING pFormat, unsigned char fMustAlloc,
2001 unsigned char fUseBufferMemoryServer, unsigned char fUnmarshall)
2002 {
2003 ULONG bufsize, memsize;
2004 WORD esize;
2005 unsigned char alignment;
2006 unsigned char *saved_buffer;
2007 ULONG offset;
2008
2009 switch (fc)
2010 {
2011 case RPC_FC_CARRAY:
2012 esize = *(const WORD*)(pFormat+2);
2013 alignment = pFormat[1] + 1;
2014
2015 bufsize = memsize = safe_multiply(esize, pStubMsg->MaxCount);
2016
2017 pFormat = SkipConformance(pStubMsg, pFormat + 4);
2018
2019 ALIGN_POINTER(pStubMsg->Buffer, alignment);
2020
2021 if (fUnmarshall)
2022 {
2023 if (fMustAlloc)
2024 *ppMemory = NdrAllocate(pStubMsg, memsize);
2025 else
2026 {
2027 if (fUseBufferMemoryServer && !pStubMsg->IsClient && !*ppMemory)
2028 /* for servers, we just point straight into the RPC buffer */
2029 *ppMemory = pStubMsg->Buffer;
2030 }
2031
2032 saved_buffer = pStubMsg->Buffer;
2033 safe_buffer_increment(pStubMsg, bufsize);
2034
2035 pStubMsg->BufferMark = saved_buffer;
2036 EmbeddedPointerUnmarshall(pStubMsg, saved_buffer, *ppMemory, pFormat, fMustAlloc);
2037
2038 TRACE("copying %p to %p\n", saved_buffer, *ppMemory);
2039 if (*ppMemory != saved_buffer)
2040 memcpy(*ppMemory, saved_buffer, bufsize);
2041 }
2042 return bufsize;
2043 case RPC_FC_CVARRAY:
2044 esize = *(const WORD*)(pFormat+2);
2045 alignment = pFormat[1] + 1;
2046
2047 pFormat = SkipConformance(pStubMsg, pFormat + 4);
2048
2049 pFormat = ReadVariance(pStubMsg, pFormat, pStubMsg->MaxCount);
2050
2051 ALIGN_POINTER(pStubMsg->Buffer, alignment);
2052
2053 bufsize = safe_multiply(esize, pStubMsg->ActualCount);
2054 memsize = safe_multiply(esize, pStubMsg->MaxCount);
2055
2056 if (fUnmarshall)
2057 {
2058 offset = pStubMsg->Offset;
2059
2060 if (!fMustAlloc && !*ppMemory)
2061 fMustAlloc = TRUE;
2062 if (fMustAlloc)
2063 *ppMemory = NdrAllocate(pStubMsg, memsize);
2064 saved_buffer = pStubMsg->Buffer;
2065 safe_buffer_increment(pStubMsg, bufsize);
2066
2067 pStubMsg->BufferMark = saved_buffer;
2068 EmbeddedPointerUnmarshall(pStubMsg, saved_buffer, *ppMemory, pFormat,
2069 fMustAlloc);
2070
2071 memcpy(*ppMemory + offset, saved_buffer, bufsize);
2072 }
2073 return bufsize;
2074 case RPC_FC_C_CSTRING:
2075 case RPC_FC_C_WSTRING:
2076 if (fc == RPC_FC_C_CSTRING)
2077 esize = 1;
2078 else
2079 esize = 2;
2080
2081 ReadVariance(pStubMsg, NULL, pStubMsg->MaxCount);
2082
2083 if (pFormat[1] != RPC_FC_STRING_SIZED && (pStubMsg->MaxCount != pStubMsg->ActualCount))
2084 {
2085 ERR("buffer size %d must equal memory size %ld for non-sized conformant strings\n",
2086 pStubMsg->ActualCount, pStubMsg->MaxCount);
2087 RpcRaiseException(RPC_S_INVALID_BOUND);
2088 }
2089 if (pStubMsg->Offset)
2090 {
2091 ERR("conformant strings can't have Offset (%d)\n", pStubMsg->Offset);
2092 RpcRaiseException(RPC_S_INVALID_BOUND);
2093 }
2094
2095 memsize = safe_multiply(esize, pStubMsg->MaxCount);
2096 bufsize = safe_multiply(esize, pStubMsg->ActualCount);
2097
2098 validate_string_data(pStubMsg, bufsize, esize);
2099
2100 if (fUnmarshall)
2101 {
2102 if (fMustAlloc)
2103 *ppMemory = NdrAllocate(pStubMsg, memsize);
2104 else
2105 {
2106 if (fUseBufferMemoryServer && !pStubMsg->IsClient &&
2107 !*ppMemory && (pStubMsg->MaxCount == pStubMsg->ActualCount))
2108 /* if the data in the RPC buffer is big enough, we just point
2109 * straight into it */
2110 *ppMemory = pStubMsg->Buffer;
2111 else if (!*ppMemory)
2112 *ppMemory = NdrAllocate(pStubMsg, memsize);
2113 }
2114
2115 if (*ppMemory == pStubMsg->Buffer)
2116 safe_buffer_increment(pStubMsg, bufsize);
2117 else
2118 safe_copy_from_buffer(pStubMsg, *ppMemory, bufsize);
2119
2120 if (*pFormat == RPC_FC_C_CSTRING)
2121 TRACE("string=%s\n", debugstr_a((char*)*ppMemory));
2122 else
2123 TRACE("string=%s\n", debugstr_w((LPWSTR)*ppMemory));
2124 }
2125 return bufsize;
2126 default:
2127 ERR("unknown array format 0x%x\n", fc);
2128 RpcRaiseException(RPC_X_BAD_STUB_DATA);
2129 }
2130 }
2131
2132 static inline void array_memory_size(
2133 unsigned char fc, PMIDL_STUB_MESSAGE pStubMsg, PFORMAT_STRING pFormat,
2134 unsigned char fHasPointers)
2135 {
2136 ULONG bufsize, memsize;
2137 DWORD esize;
2138 unsigned char alignment;
2139
2140 switch (fc)
2141 {
2142 case RPC_FC_CARRAY:
2143 esize = *(const WORD*)(pFormat+2);
2144 alignment = pFormat[1] + 1;
2145
2146 pFormat = SkipConformance(pStubMsg, pFormat + 4);
2147
2148 bufsize = memsize = safe_multiply(esize, pStubMsg->MaxCount);
2149 pStubMsg->MemorySize += memsize;
2150
2151 ALIGN_POINTER(pStubMsg->Buffer, alignment);
2152 if (fHasPointers)
2153 pStubMsg->BufferMark = pStubMsg->Buffer;
2154 safe_buffer_increment(pStubMsg, bufsize);
2155
2156 if (fHasPointers)
2157 EmbeddedPointerMemorySize(pStubMsg, pFormat);
2158 break;
2159 case RPC_FC_CVARRAY:
2160 esize = *(const WORD*)(pFormat+2);
2161 alignment = pFormat[1] + 1;
2162
2163 pFormat = SkipConformance(pStubMsg, pFormat + 4);
2164
2165 pFormat = ReadVariance(pStubMsg, pFormat, pStubMsg->MaxCount);
2166
2167 bufsize = safe_multiply(esize, pStubMsg->ActualCount);
2168 memsize = safe_multiply(esize, pStubMsg->MaxCount);
2169 pStubMsg->MemorySize += memsize;
2170
2171 ALIGN_POINTER(pStubMsg->Buffer, alignment);
2172 if (fHasPointers)
2173 pStubMsg->BufferMark = pStubMsg->Buffer;
2174 safe_buffer_increment(pStubMsg, bufsize);
2175
2176 if (fHasPointers)
2177 EmbeddedPointerMemorySize(pStubMsg, pFormat);
2178 break;
2179 case RPC_FC_C_CSTRING:
2180 case RPC_FC_C_WSTRING:
2181 if (fc == RPC_FC_C_CSTRING)
2182 esize = 1;
2183 else
2184 esize = 2;
2185
2186 ReadVariance(pStubMsg, NULL, pStubMsg->MaxCount);
2187
2188 if (pFormat[1] != RPC_FC_STRING_SIZED && (pStubMsg->MaxCount != pStubMsg->ActualCount))
2189 {
2190 ERR("buffer size %d must equal memory size %ld for non-sized conformant strings\n",
2191 pStubMsg->ActualCount, pStubMsg->MaxCount);
2192 RpcRaiseException(RPC_S_INVALID_BOUND);
2193 }
2194 if (pStubMsg->Offset)
2195 {
2196 ERR("conformant strings can't have Offset (%d)\n", pStubMsg->Offset);
2197 RpcRaiseException(RPC_S_INVALID_BOUND);
2198 }
2199
2200 memsize = safe_multiply(esize, pStubMsg->MaxCount);
2201 bufsize = safe_multiply(esize, pStubMsg->ActualCount);
2202
2203 validate_string_data(pStubMsg, bufsize, esize);
2204
2205 safe_buffer_increment(pStubMsg, bufsize);
2206 pStubMsg->MemorySize += memsize;
2207 break;
2208 default:
2209 ERR("unknown array format 0x%x\n", fc);
2210 RpcRaiseException(RPC_X_BAD_STUB_DATA);
2211 }
2212 }
2213
2214 static inline void array_free(
2215 unsigned char fc, PMIDL_STUB_MESSAGE pStubMsg,
2216 unsigned char *pMemory, PFORMAT_STRING pFormat, unsigned char fHasPointers)
2217 {
2218 switch (fc)
2219 {
2220 case RPC_FC_CARRAY:
2221 pFormat = ComputeConformance(pStubMsg, pMemory, pFormat+4, 0);
2222 if (fHasPointers)
2223 EmbeddedPointerFree(pStubMsg, pMemory, pFormat);
2224 break;
2225 case RPC_FC_CVARRAY:
2226 pFormat = ComputeConformance(pStubMsg, pMemory, pFormat+4, 0);
2227 pFormat = ComputeVariance(pStubMsg, pMemory, pFormat, 0);
2228 if (fHasPointers)
2229 EmbeddedPointerFree(pStubMsg, pMemory, pFormat);
2230 break;
2231 case RPC_FC_C_CSTRING:
2232 case RPC_FC_C_WSTRING:
2233 /* No embedded pointers so nothing to do */
2234 break;
2235 default:
2236 ERR("unknown array format 0x%x\n", fc);
2237 RpcRaiseException(RPC_X_BAD_STUB_DATA);
2238 }
2239 }
2240
2241 /*
2242 * NdrConformantString:
2243 *
2244 * What MS calls a ConformantString is, in DCE terminology,
2245 * a Varying-Conformant String.
2246 * [
2247 * maxlen: DWORD (max # of CHARTYPE characters, inclusive of '\0')
2248 * offset: DWORD (actual string data begins at (offset) CHARTYPE's
2249 * into unmarshalled string)
2250 * length: DWORD (# of CHARTYPE characters, inclusive of '\0')
2251 * [
2252 * data: CHARTYPE[maxlen]
2253 * ]
2254 * ], where CHARTYPE is the appropriate character type (specified externally)
2255 *
2256 */
2257
2258 /***********************************************************************
2259 * NdrConformantStringMarshall [RPCRT4.@]
2260 */
2261 unsigned char *WINAPI NdrConformantStringMarshall(MIDL_STUB_MESSAGE *pStubMsg,
2262 unsigned char *pszMessage, PFORMAT_STRING pFormat)
2263 {
2264 TRACE("(pStubMsg == ^%p, pszMessage == ^%p, pFormat == ^%p)\n", pStubMsg, pszMessage, pFormat);
2265
2266 if (pFormat[0] != RPC_FC_C_CSTRING && pFormat[0] != RPC_FC_C_WSTRING) {
2267 ERR("Unhandled string type: %#x\n", pFormat[0]);
2268 RpcRaiseException(RPC_X_BAD_STUB_DATA);
2269 }
2270
2271 /* allow compiler to optimise inline function by passing constant into
2272 * these functions */
2273 if (pFormat[0] == RPC_FC_C_CSTRING) {
2274 array_compute_and_write_conformance(RPC_FC_C_CSTRING, pStubMsg, pszMessage,
2275 pFormat);
2276 array_write_variance_and_marshall(RPC_FC_C_CSTRING, pStubMsg, pszMessage,
2277 pFormat, TRUE /* fHasPointers */);
2278 } else {
2279 array_compute_and_write_conformance(RPC_FC_C_WSTRING, pStubMsg, pszMessage,
2280 pFormat);
2281 array_write_variance_and_marshall(RPC_FC_C_WSTRING, pStubMsg, pszMessage,
2282 pFormat, TRUE /* fHasPointers */);
2283 }
2284
2285 return NULL;
2286 }
2287
2288 /***********************************************************************
2289 * NdrConformantStringBufferSize [RPCRT4.@]
2290 */
2291 void WINAPI NdrConformantStringBufferSize(PMIDL_STUB_MESSAGE pStubMsg,
2292 unsigned char* pMemory, PFORMAT_STRING pFormat)
2293 {
2294 TRACE("(pStubMsg == ^%p, pMemory == ^%p, pFormat == ^%p)\n", pStubMsg, pMemory, pFormat);
2295
2296 if (pFormat[0] != RPC_FC_C_CSTRING && pFormat[0] != RPC_FC_C_WSTRING) {
2297 ERR("Unhandled string type: %#x\n", pFormat[0]);
2298 RpcRaiseException(RPC_X_BAD_STUB_DATA);
2299 }
2300
2301 /* allow compiler to optimise inline function by passing constant into
2302 * these functions */
2303 if (pFormat[0] == RPC_FC_C_CSTRING) {
2304 array_compute_and_size_conformance(RPC_FC_C_CSTRING, pStubMsg, pMemory,
2305 pFormat);
2306 array_buffer_size(RPC_FC_C_CSTRING, pStubMsg, pMemory, pFormat,
2307 TRUE /* fHasPointers */);
2308 } else {
2309 array_compute_and_size_conformance(RPC_FC_C_WSTRING, pStubMsg, pMemory,
2310 pFormat);
2311 array_buffer_size(RPC_FC_C_WSTRING, pStubMsg, pMemory, pFormat,
2312 TRUE /* fHasPointers */);
2313 }
2314 }
2315
2316 /************************************************************************
2317 * NdrConformantStringMemorySize [RPCRT4.@]
2318 */
2319 ULONG WINAPI NdrConformantStringMemorySize( PMIDL_STUB_MESSAGE pStubMsg,
2320 PFORMAT_STRING pFormat )
2321 {
2322 TRACE("(pStubMsg == ^%p, pFormat == ^%p)\n", pStubMsg, pFormat);
2323
2324 if (pFormat[0] != RPC_FC_C_CSTRING && pFormat[0] != RPC_FC_C_WSTRING) {
2325 ERR("Unhandled string type: %#x\n", pFormat[0]);
2326 RpcRaiseException(RPC_X_BAD_STUB_DATA);
2327 }
2328
2329 /* allow compiler to optimise inline function by passing constant into
2330 * these functions */
2331 if (pFormat[0] == RPC_FC_C_CSTRING) {
2332 array_read_conformance(RPC_FC_C_CSTRING, pStubMsg, pFormat);
2333 array_memory_size(RPC_FC_C_CSTRING, pStubMsg, pFormat,
2334 TRUE /* fHasPointers */);
2335 } else {
2336 array_read_conformance(RPC_FC_C_WSTRING, pStubMsg, pFormat);
2337 array_memory_size(RPC_FC_C_WSTRING, pStubMsg, pFormat,
2338 TRUE /* fHasPointers */);
2339 }
2340
2341 return pStubMsg->MemorySize;
2342 }
2343
2344 /************************************************************************
2345 * NdrConformantStringUnmarshall [RPCRT4.@]
2346 */
2347 unsigned char *WINAPI NdrConformantStringUnmarshall( PMIDL_STUB_MESSAGE pStubMsg,
2348 unsigned char** ppMemory, PFORMAT_STRING pFormat, unsigned char fMustAlloc )
2349 {
2350 TRACE("(pStubMsg == ^%p, *pMemory == ^%p, pFormat == ^%p, fMustAlloc == %u)\n",
2351 pStubMsg, *ppMemory, pFormat, fMustAlloc);
2352
2353 if (pFormat[0] != RPC_FC_C_CSTRING && pFormat[0] != RPC_FC_C_WSTRING) {
2354 ERR("Unhandled string type: %#x\n", *pFormat);
2355 RpcRaiseException(RPC_X_BAD_STUB_DATA);
2356 }
2357
2358 /* allow compiler to optimise inline function by passing constant into
2359 * these functions */
2360 if (pFormat[0] == RPC_FC_C_CSTRING) {
2361 array_read_conformance(RPC_FC_C_CSTRING, pStubMsg, pFormat);
2362 array_read_variance_and_unmarshall(RPC_FC_C_CSTRING, pStubMsg, ppMemory,
2363 pFormat, fMustAlloc,
2364 TRUE /* fUseBufferMemoryServer */,
2365 TRUE /* fUnmarshall */);
2366 } else {
2367 array_read_conformance(RPC_FC_C_WSTRING, pStubMsg, pFormat);
2368 array_read_variance_and_unmarshall(RPC_FC_C_WSTRING, pStubMsg, ppMemory,
2369 pFormat, fMustAlloc,
2370 TRUE /* fUseBufferMemoryServer */,
2371 TRUE /* fUnmarshall */);
2372 }
2373
2374 return NULL;
2375 }
2376
2377 /***********************************************************************
2378 * NdrNonConformantStringMarshall [RPCRT4.@]
2379 */
2380 unsigned char * WINAPI NdrNonConformantStringMarshall(PMIDL_STUB_MESSAGE pStubMsg,
2381 unsigned char *pMemory,
2382 PFORMAT_STRING pFormat)
2383 {
2384 ULONG esize, size, maxsize;
2385
2386 TRACE("(pStubMsg == ^%p, pMemory == ^%p, pFormat == ^%p)\n", pStubMsg, pMemory, pFormat);
2387
2388 maxsize = *(USHORT *)&pFormat[2];
2389
2390 if (*pFormat == RPC_FC_CSTRING)
2391 {
2392 ULONG i;
2393 const char *str = (const char *)pMemory;
2394 for (i = 0; i < maxsize && *str; i++, str++)
2395 ;
2396 TRACE("string=%s\n", debugstr_an(str, i));
2397 pStubMsg->ActualCount = i + 1;
2398 esize = 1;
2399 }
2400 else if (*pFormat == RPC_FC_WSTRING)
2401 {
2402 ULONG i;
2403 const WCHAR *str = (const WCHAR *)pMemory;
2404 for (i = 0; i < maxsize && *str; i++, str++)
2405 ;
2406 TRACE("string=%s\n", debugstr_wn(str, i));
2407 pStubMsg->ActualCount = i + 1;
2408 esize = 2;
2409 }
2410 else
2411 {
2412 ERR("Unhandled string type: %#x\n", *pFormat);
2413 RpcRaiseException(RPC_X_BAD_STUB_DATA);
2414 }
2415
2416 pStubMsg->Offset = 0;
2417 WriteVariance(pStubMsg);
2418
2419 size = safe_multiply(esize, pStubMsg->ActualCount);
2420 safe_copy_to_buffer(pStubMsg, pMemory, size); /* the string itself */
2421
2422 return NULL;
2423 }
2424
2425 /***********************************************************************
2426 * NdrNonConformantStringUnmarshall [RPCRT4.@]
2427 */
2428 unsigned char * WINAPI NdrNonConformantStringUnmarshall(PMIDL_STUB_MESSAGE pStubMsg,
2429 unsigned char **ppMemory,
2430 PFORMAT_STRING pFormat,
2431 unsigned char fMustAlloc)
2432 {
2433 ULONG bufsize, memsize, esize, maxsize;
2434
2435 TRACE("(pStubMsg == ^%p, *pMemory == ^%p, pFormat == ^%p, fMustAlloc == %u)\n",
2436 pStubMsg, *ppMemory, pFormat, fMustAlloc);
2437
2438 maxsize = *(USHORT *)&pFormat[2];
2439
2440 ReadVariance(pStubMsg, NULL, maxsize);
2441 if (pStubMsg->Offset)
2442 {
2443 ERR("non-conformant strings can't have Offset (%d)\n", pStubMsg->Offset);
2444 RpcRaiseException(RPC_S_INVALID_BOUND);
2445 }
2446
2447 if (*pFormat == RPC_FC_CSTRING) esize = 1;
2448 else if (*pFormat == RPC_FC_WSTRING) esize = 2;
2449 else
2450 {
2451 ERR("Unhandled string type: %#x\n", *pFormat);
2452 RpcRaiseException(RPC_X_BAD_STUB_DATA);
2453 }
2454
2455 memsize = esize * maxsize;
2456 bufsize = safe_multiply(esize, pStubMsg->ActualCount);
2457
2458 validate_string_data(pStubMsg, bufsize, esize);
2459
2460 if (!fMustAlloc && !*ppMemory)
2461 fMustAlloc = TRUE;
2462 if (fMustAlloc)
2463 *ppMemory = NdrAllocate(pStubMsg, memsize);
2464
2465 safe_copy_from_buffer(pStubMsg, *ppMemory, bufsize);
2466
2467 if (*pFormat == RPC_FC_CSTRING) {
2468 TRACE("string=%s\n", debugstr_an((char*)*ppMemory, pStubMsg->ActualCount));
2469 }
2470 else if (*pFormat == RPC_FC_WSTRING) {
2471 TRACE("string=%s\n", debugstr_wn((LPWSTR)*ppMemory, pStubMsg->ActualCount));
2472 }
2473
2474 return NULL;
2475 }
2476
2477 /***********************************************************************
2478 * NdrNonConformantStringBufferSize [RPCRT4.@]
2479 */
2480 void WINAPI NdrNonConformantStringBufferSize(PMIDL_STUB_MESSAGE pStubMsg,
2481 unsigned char *pMemory,
2482 PFORMAT_STRING pFormat)
2483 {
2484 ULONG esize, maxsize;
2485
2486 TRACE("(pStubMsg == ^%p, pMemory == ^%p, pFormat == ^%p)\n", pStubMsg, pMemory, pFormat);
2487
2488 maxsize = *(USHORT *)&pFormat[2];
2489
2490 SizeVariance(pStubMsg);
2491
2492 if (*pFormat == RPC_FC_CSTRING)
2493 {
2494 ULONG i;
2495 const char *str = (const char *)pMemory;
2496 for (i = 0; i < maxsize && *str; i++, str++)
2497 ;
2498 TRACE("string=%s\n", debugstr_an(str, i));
2499 pStubMsg->ActualCount = i + 1;
2500 esize = 1;
2501 }
2502 else if (*pFormat == RPC_FC_WSTRING)
2503 {
2504 ULONG i;
2505 const WCHAR *str = (const WCHAR *)pMemory;
2506 for (i = 0; i < maxsize && *str; i++, str++)
2507 ;
2508 TRACE("string=%s\n", debugstr_wn(str, i));
2509 pStubMsg->ActualCount = i + 1;
2510 esize = 2;
2511 }
2512 else
2513 {
2514 ERR("Unhandled string type: %#x\n", *pFormat);
2515 RpcRaiseException(RPC_X_BAD_STUB_DATA);
2516 }
2517
2518 safe_buffer_length_increment(pStubMsg, safe_multiply(esize, pStubMsg->ActualCount));
2519 }
2520
2521 /***********************************************************************
2522 * NdrNonConformantStringMemorySize [RPCRT4.@]
2523 */
2524 ULONG WINAPI NdrNonConformantStringMemorySize(PMIDL_STUB_MESSAGE pStubMsg,
2525 PFORMAT_STRING pFormat)
2526 {
2527 ULONG bufsize, memsize, esize, maxsize;
2528
2529 TRACE("(pStubMsg == ^%p, pFormat == ^%p)\n", pStubMsg, pFormat);
2530
2531 maxsize = *(USHORT *)&pFormat[2];
2532
2533 ReadVariance(pStubMsg, NULL, maxsize);
2534
2535 if (pStubMsg->Offset)
2536 {
2537 ERR("non-conformant strings can't have Offset (%d)\n", pStubMsg->Offset);
2538 RpcRaiseException(RPC_S_INVALID_BOUND);
2539 }
2540
2541 if (*pFormat == RPC_FC_CSTRING) esize = 1;
2542 else if (*pFormat == RPC_FC_WSTRING) esize = 2;
2543 else
2544 {
2545 ERR("Unhandled string type: %#x\n", *pFormat);
2546 RpcRaiseException(RPC_X_BAD_STUB_DATA);
2547 }
2548
2549 memsize = esize * maxsize;
2550 bufsize = safe_multiply(esize, pStubMsg->ActualCount);
2551
2552 validate_string_data(pStubMsg, bufsize, esize);
2553
2554 safe_buffer_increment(pStubMsg, bufsize);
2555 pStubMsg->MemorySize += memsize;
2556
2557 return pStubMsg->MemorySize;
2558 }
2559
2560 /* Complex types */
2561
2562 #include "pshpack1.h"
2563 typedef struct
2564 {
2565 unsigned char type;
2566 unsigned char flags_type; /* flags in upper nibble, type in lower nibble */
2567 ULONG low_value;
2568 ULONG high_value;
2569 } NDR_RANGE;
2570 #include "poppack.h"
2571
2572 static unsigned long EmbeddedComplexSize(MIDL_STUB_MESSAGE *pStubMsg,
2573 PFORMAT_STRING pFormat)
2574 {
2575 switch (*pFormat) {
2576 case RPC_FC_STRUCT:
2577 case RPC_FC_PSTRUCT:
2578 case RPC_FC_CSTRUCT:
2579 case RPC_FC_BOGUS_STRUCT:
2580 case RPC_FC_SMFARRAY:
2581 case RPC_FC_SMVARRAY:
2582 case RPC_FC_CSTRING:
2583 return *(const WORD*)&pFormat[2];
2584 case RPC_FC_USER_MARSHAL:
2585 return *(const WORD*)&pFormat[4];
2586 case RPC_FC_RANGE: {
2587 switch (((const NDR_RANGE *)pFormat)->flags_type & 0xf) {
2588 case RPC_FC_BYTE:
2589 case RPC_FC_CHAR:
2590 case RPC_FC_SMALL:
2591 case RPC_FC_USMALL:
2592 return sizeof(UCHAR);
2593 case RPC_FC_WCHAR:
2594 case RPC_FC_SHORT:
2595 case RPC_FC_USHORT:
2596 return sizeof(USHORT);
2597 case RPC_FC_LONG:
2598 case RPC_FC_ULONG:
2599 case RPC_FC_ENUM32:
2600 return sizeof(ULONG);
2601 case RPC_FC_FLOAT:
2602 return sizeof(float);
2603 case RPC_FC_DOUBLE:
2604 return sizeof(double);
2605 case RPC_FC_HYPER:
2606 return sizeof(ULONGLONG);
2607 case RPC_FC_ENUM16:
2608 return sizeof(UINT);
2609 default:
2610 ERR("unknown type 0x%x\n", ((const NDR_RANGE *)pFormat)->flags_type & 0xf);
2611 RpcRaiseException(RPC_X_BAD_STUB_DATA);
2612 }
2613 }
2614 case RPC_FC_NON_ENCAPSULATED_UNION:
2615 pFormat += 2;
2616 if (pStubMsg->fHasNewCorrDesc)
2617 pFormat += 6;
2618 else
2619 pFormat += 4;
2620
2621 pFormat += *(const SHORT*)pFormat;
2622 return *(const SHORT*)pFormat;
2623 case RPC_FC_IP:
2624 return sizeof(void *);
2625 case RPC_FC_WSTRING:
2626 return *(const WORD*)&pFormat[2] * 2;
2627 default:
2628 FIXME("unhandled embedded type %02x\n", *pFormat);
2629 }
2630 return 0;
2631 }
2632
2633
2634 static unsigned long EmbeddedComplexMemorySize(PMIDL_STUB_MESSAGE pStubMsg,
2635 PFORMAT_STRING pFormat)
2636 {
2637 NDR_MEMORYSIZE m = NdrMemorySizer[*pFormat & NDR_TABLE_MASK];
2638
2639 if (!m)
2640 {
2641 FIXME("no memorysizer for data type=%02x\n", *pFormat);
2642 return 0;
2643 }
2644
2645 return m(pStubMsg, pFormat);
2646 }
2647
2648
2649 static unsigned char * ComplexMarshall(PMIDL_STUB_MESSAGE pStubMsg,
2650 unsigned char *pMemory,
2651 PFORMAT_STRING pFormat,
2652 PFORMAT_STRING pPointer)
2653 {
2654 PFORMAT_STRING desc;
2655 NDR_MARSHALL m;
2656 unsigned long size;
2657
2658 while (*pFormat != RPC_FC_END) {
2659 switch (*pFormat) {
2660 case RPC_FC_BYTE:
2661 case RPC_FC_CHAR:
2662 case RPC_FC_SMALL:
2663 case RPC_FC_USMALL:
2664 TRACE("byte=%d <= %p\n", *(WORD*)pMemory, pMemory);
2665 safe_copy_to_buffer(pStubMsg, pMemory, 1);
2666 pMemory += 1;
2667 break;
2668 case RPC_FC_WCHAR:
2669 case RPC_FC_SHORT:
2670 case RPC_FC_USHORT:
2671 TRACE("short=%d <= %p\n", *(WORD*)pMemory, pMemory);
2672 safe_copy_to_buffer(pStubMsg, pMemory, 2);
2673 pMemory += 2;
2674 break;
2675 case RPC_FC_ENUM16:
2676 TRACE("enum16=%d <= %p\n", *(DWORD*)pMemory, pMemory);
2677 if (32767 < *(DWORD*)pMemory)
2678 RpcRaiseException(RPC_X_ENUM_VALUE_OUT_OF_RANGE);
2679 safe_copy_to_buffer(pStubMsg, pMemory, 2);
2680 pMemory += 4;
2681 break;
2682 case RPC_FC_LONG:
2683 case RPC_FC_ULONG:
2684 case RPC_FC_ENUM32:
2685 TRACE("long=%d <= %p\n", *(DWORD*)pMemory, pMemory);
2686 safe_copy_to_buffer(pStubMsg, pMemory, 4);
2687 pMemory += 4;
2688 break;
2689 case RPC_FC_HYPER:
2690 TRACE("longlong=%s <= %p\n", wine_dbgstr_longlong(*(ULONGLONG*)pMemory), pMemory);
2691 safe_copy_to_buffer(pStubMsg, pMemory, 8);
2692 pMemory += 8;
2693 break;
2694 case RPC_FC_POINTER:
2695 {
2696 unsigned char *saved_buffer;
2697 int pointer_buffer_mark_set = 0;
2698 TRACE("pointer=%p <= %p\n", *(unsigned char**)pMemory, pMemory);
2699 TRACE("pStubMsg->Buffer before %p\n", pStubMsg->Buffer);
2700 if (*pPointer != RPC_FC_RP)
2701 ALIGN_POINTER_CLEAR(pStubMsg->Buffer, 4);
2702 saved_buffer = pStubMsg->Buffer;
2703 if (pStubMsg->PointerBufferMark)
2704 {
2705 pStubMsg->Buffer = pStubMsg->PointerBufferMark;
2706 pStubMsg->PointerBufferMark = NULL;
2707 pointer_buffer_mark_set = 1;
2708 }
2709 else if (*pPointer != RPC_FC_RP)
2710 safe_buffer_increment(pStubMsg, 4); /* for pointer ID */
2711 PointerMarshall(pStubMsg, saved_buffer, *(unsigned char**)pMemory, pPointer);
2712 if (pointer_buffer_mark_set)
2713 {
2714 STD_OVERFLOW_CHECK(pStubMsg);
2715 pStubMsg->PointerBufferMark = pStubMsg->Buffer;
2716 pStubMsg->Buffer = saved_buffer;
2717 if (*pPointer != RPC_FC_RP)
2718 safe_buffer_increment(pStubMsg, 4); /* for pointer ID */
2719 }
2720 TRACE("pStubMsg->Buffer after %p\n", pStubMsg->Buffer);
2721 pPointer += 4;
2722 pMemory += 4;
2723 break;
2724 }
2725 case RPC_FC_ALIGNM4:
2726 ALIGN_POINTER(pMemory, 4);
2727 break;
2728 case RPC_FC_ALIGNM8:
2729 ALIGN_POINTER(pMemory, 8);
2730 break;
2731 case RPC_FC_STRUCTPAD1:
2732 case RPC_FC_STRUCTPAD2:
2733 case RPC_FC_STRUCTPAD3:
2734 case RPC_FC_STRUCTPAD4:
2735 case RPC_FC_STRUCTPAD5:
2736 case RPC_FC_STRUCTPAD6:
2737 case RPC_FC_STRUCTPAD7:
2738 pMemory += *pFormat - RPC_FC_STRUCTPAD1 + 1;
2739 break;
2740 case RPC_FC_EMBEDDED_COMPLEX:
2741 pMemory += pFormat[1];
2742 pFormat += 2;
2743 desc = pFormat + *(const SHORT*)pFormat;
2744 size = EmbeddedComplexSize(pStubMsg, desc);
2745 TRACE("embedded complex (size=%ld) <= %p\n", size, pMemory);
2746 m = NdrMarshaller[*desc & NDR_TABLE_MASK];
2747 if (m)
2748 {
2749 /* for some reason interface pointers aren't generated as
2750 * RPC_FC_POINTER, but instead as RPC_FC_EMBEDDED_COMPLEX, yet
2751 * they still need the derefencing treatment that pointers are
2752 * given */
2753 if (*desc == RPC_FC_IP)
2754 m(pStubMsg, *(unsigned char **)pMemory, desc);
2755 else
2756 m(pStubMsg, pMemory, desc);
2757 }
2758 else FIXME("no marshaller for embedded type %02x\n", *desc);
2759 pMemory += size;
2760 pFormat += 2;
2761 continue;
2762 case RPC_FC_PAD:
2763 break;
2764 default:
2765 FIXME("unhandled format 0x%02x\n", *pFormat);
2766 }
2767 pFormat++;
2768 }
2769
2770 return pMemory;
2771 }
2772
2773 static unsigned char * ComplexUnmarshall(PMIDL_STUB_MESSAGE pStubMsg,
2774 unsigned char *pMemory,
2775 PFORMAT_STRING pFormat,
2776 PFORMAT_STRING pPointer,
2777 unsigned char fMustAlloc)
2778 {
2779 PFORMAT_STRING desc;
2780 NDR_UNMARSHALL m;
2781 unsigned long size;
2782
2783 while (*pFormat != RPC_FC_END) {
2784 switch (*pFormat) {
2785 case RPC_FC_BYTE:
2786 case RPC_FC_CHAR:
2787 case RPC_FC_SMALL:
2788 case RPC_FC_USMALL:
2789 safe_copy_from_buffer(pStubMsg, pMemory, 1);
2790 TRACE("byte=%d => %p\n", *(WORD*)pMemory, pMemory);
2791 pMemory += 1;
2792 break;
2793 case RPC_FC_WCHAR:
2794 case RPC_FC_SHORT:
2795 case RPC_FC_USHORT:
2796 safe_copy_from_buffer(pStubMsg, pMemory, 2);
2797 TRACE("short=%d => %p\n", *(WORD*)pMemory, pMemory);
2798 pMemory += 2;
2799 break;
2800 case RPC_FC_ENUM16:
2801 safe_copy_from_buffer(pStubMsg, pMemory, 2);
2802 *(DWORD*)pMemory &= 0xffff;
2803 TRACE("enum16=%d => %p\n", *(DWORD*)pMemory, pMemory);
2804 if (32767 < *(DWORD*)pMemory)
2805 RpcRaiseException(RPC_X_ENUM_VALUE_OUT_OF_RANGE);
2806 pMemory += 4;
2807 break;
2808 case RPC_FC_LONG:
2809 case RPC_FC_ULONG:
2810 case RPC_FC_ENUM32:
2811 safe_copy_from_buffer(pStubMsg, pMemory, 4);
2812 TRACE("long=%d => %p\n", *(DWORD*)pMemory, pMemory);
2813 pMemory += 4;
2814 break;
2815 case RPC_FC_HYPER:
2816 safe_copy_from_buffer(pStubMsg, pMemory, 8);
2817 TRACE("longlong=%s => %p\n", wine_dbgstr_longlong(*(ULONGLONG*)pMemory), pMemory);
2818 pMemory += 8;
2819 break;
2820 case RPC_FC_POINTER:
2821 {
2822 unsigned char *saved_buffer;
2823 int pointer_buffer_mark_set = 0;
2824 TRACE("pointer => %p\n", pMemory);
2825 if (*pPointer != RPC_FC_RP)
2826 ALIGN_POINTER(pStubMsg->Buffer, 4);
2827 saved_buffer = pStubMsg->Buffer;
2828 if (pStubMsg->PointerBufferMark)
2829 {
2830 pStubMsg->Buffer = pStubMsg->PointerBufferMark;
2831 pStubMsg->PointerBufferMark = NULL;
2832 pointer_buffer_mark_set = 1;
2833 }
2834 else if (*pPointer != RPC_FC_RP)
2835 safe_buffer_increment(pStubMsg, 4); /* for pointer ID */
2836
2837 PointerUnmarshall(pStubMsg, saved_buffer, (unsigned char**)pMemory, *(unsigned char**)pMemory, pPointer, fMustAlloc);
2838 if (pointer_buffer_mark_set)
2839 {
2840 STD_OVERFLOW_CHECK(pStubMsg);
2841 pStubMsg->PointerBufferMark = pStubMsg->Buffer;
2842 pStubMsg->Buffer = saved_buffer;
2843 if (*pPointer != RPC_FC_RP)
2844 safe_buffer_increment(pStubMsg, 4); /* for pointer ID */
2845 }
2846 pPointer += 4;
2847 pMemory += 4;
2848 break;
2849 }
2850 case RPC_FC_ALIGNM4:
2851 ALIGN_POINTER_CLEAR(pMemory, 4);
2852 break;
2853 case RPC_FC_ALIGNM8:
2854 ALIGN_POINTER_CLEAR(pMemory, 8);
2855 break;
2856 case RPC_FC_STRUCTPAD1:
2857 case RPC_FC_STRUCTPAD2:
2858 case RPC_FC_STRUCTPAD3:
2859 case RPC_FC_STRUCTPAD4:
2860 case RPC_FC_STRUCTPAD5:
2861 case RPC_FC_STRUCTPAD6:
2862 case RPC_FC_STRUCTPAD7:
2863 memset(pMemory, 0, *pFormat - RPC_FC_STRUCTPAD1 + 1);
2864 pMemory += *pFormat - RPC_FC_STRUCTPAD1 + 1;
2865 break;
2866 case RPC_FC_EMBEDDED_COMPLEX:
2867 pMemory += pFormat[1];
2868 pFormat += 2;
2869 desc = pFormat + *(const SHORT*)pFormat;
2870 size = EmbeddedComplexSize(pStubMsg, desc);
2871 TRACE("embedded complex (size=%ld) => %p\n", size, pMemory);
2872 if (fMustAlloc)
2873 /* we can't pass fMustAlloc=TRUE into the marshaller for this type
2874 * since the type is part of the memory block that is encompassed by
2875 * the whole complex type. Memory is forced to allocate when pointers
2876 * are set to NULL, so we emulate that part of fMustAlloc=TRUE by
2877 * clearing the memory we pass in to the unmarshaller */
2878 memset(pMemory, 0, size);
2879 m = NdrUnmarshaller[*desc & NDR_TABLE_MASK];
2880 if (m)
2881 {
2882 /* for some reason interface pointers aren't generated as
2883 * RPC_FC_POINTER, but instead as RPC_FC_EMBEDDED_COMPLEX, yet
2884 * they still need the derefencing treatment that pointers are
2885 * given */
2886 if (*desc == RPC_FC_IP)
2887 m(pStubMsg, (unsigned char **)pMemory, desc, FALSE);
2888 else
2889 m(pStubMsg, &pMemory, desc, FALSE);
2890 }
2891 else FIXME("no unmarshaller for embedded type %02x\n", *desc);
2892 pMemory += size;
2893 pFormat += 2;
2894 continue;
2895 case RPC_FC_PAD:
2896 break;
2897 default:
2898 FIXME("unhandled format %d\n", *pFormat);
2899 }
2900 pFormat++;
2901 }
2902
2903 return pMemory;
2904 }
2905
2906 static unsigned char * ComplexBufferSize(PMIDL_STUB_MESSAGE pStubMsg,
2907 unsigned char *pMemory,
2908 PFORMAT_STRING pFormat,
2909 PFORMAT_STRING pPointer)
2910 {
2911 PFORMAT_STRING desc;
2912 NDR_BUFFERSIZE m;
2913 unsigned long size;
2914
2915 while (*pFormat != RPC_FC_END) {
2916 switch (*pFormat) {
2917 case RPC_FC_BYTE:
2918 case RPC_FC_CHAR:
2919 case RPC_FC_SMALL:
2920 case RPC_FC_USMALL:
2921 safe_buffer_length_increment(pStubMsg, 1);
2922 pMemory += 1;
2923 break;
2924 case RPC_FC_WCHAR:
2925 case RPC_FC_SHORT:
2926 case RPC_FC_USHORT:
2927 safe_buffer_length_increment(pStubMsg, 2);
2928 pMemory += 2;
2929 break;
2930 case RPC_FC_ENUM16:
2931 safe_buffer_length_increment(pStubMsg, 2);
2932 pMemory += 4;
2933 break;
2934 case RPC_FC_LONG:
2935 case RPC_FC_ULONG:
2936 case RPC_FC_ENUM32:
2937 safe_buffer_length_increment(pStubMsg, 4);
2938 pMemory += 4;
2939 break;
2940 case RPC_FC_HYPER:
2941 safe_buffer_length_increment(pStubMsg, 8);
2942 pMemory += 8;
2943 break;
2944 case RPC_FC_POINTER:
2945 if (!pStubMsg->IgnoreEmbeddedPointers)
2946 {
2947 int saved_buffer_length = pStubMsg->BufferLength;
2948 pStubMsg->BufferLength = pStubMsg->PointerLength;
2949 pStubMsg->PointerLength = 0;
2950 if(!pStubMsg->BufferLength)
2951 ERR("BufferLength == 0??\n");
2952 PointerBufferSize(pStubMsg, *(unsigned char**)pMemory, pPointer);
2953 pStubMsg->PointerLength = pStubMsg->BufferLength;
2954 pStubMsg->BufferLength = saved_buffer_length;
2955 }
2956 if (*pPointer != RPC_FC_RP)
2957 {
2958 ALIGN_LENGTH(pStubMsg->BufferLength, 4);
2959 safe_buffer_length_increment(pStubMsg, 4);
2960 }
2961 pPointer += 4;
2962 pMemory += 4;
2963 break;
2964 case RPC_FC_ALIGNM4:
2965 ALIGN_POINTER(pMemory, 4);
2966 break;
2967 case RPC_FC_ALIGNM8:
2968 ALIGN_POINTER(pMemory, 8);
2969 break;
2970 case RPC_FC_STRUCTPAD1:
2971 case RPC_FC_STRUCTPAD2:
2972 case RPC_FC_STRUCTPAD3:
2973 case RPC_FC_STRUCTPAD4:
2974 case RPC_FC_STRUCTPAD5:
2975 case RPC_FC_STRUCTPAD6:
2976 case RPC_FC_STRUCTPAD7:
2977 pMemory += *pFormat - RPC_FC_STRUCTPAD1 + 1;
2978 break;
2979 case RPC_FC_EMBEDDED_COMPLEX:
2980 pMemory += pFormat[1];
2981 pFormat += 2;
2982 desc = pFormat + *(const SHORT*)pFormat;
2983 size = EmbeddedComplexSize(pStubMsg, desc);
2984 m = NdrBufferSizer[*desc & NDR_TABLE_MASK];
2985 if (m)
2986 {
2987 /* for some reason interface pointers aren't generated as
2988 * RPC_FC_POINTER, but instead as RPC_FC_EMBEDDED_COMPLEX, yet
2989 * they still need the derefencing treatment that pointers are
2990 * given */
2991 if (*desc == RPC_FC_IP)
2992 m(pStubMsg, *(unsigned char **)pMemory, desc);
2993 else
2994 m(pStubMsg, pMemory, desc);
2995 }
2996 else FIXME("no buffersizer for embedded type %02x\n", *desc);
2997 pMemory += size;
2998 pFormat += 2;
2999 continue;
3000 case RPC_FC_PAD:
3001 break;
3002 default:
3003 FIXME("unhandled format 0x%02x\n", *pFormat);
3004 }
3005 pFormat++;
3006 }
3007
3008 return pMemory;
3009 }
3010
3011 static unsigned char * ComplexFree(PMIDL_STUB_MESSAGE pStubMsg,
3012 unsigned char *pMemory,
3013 PFORMAT_STRING pFormat,
3014 PFORMAT_STRING pPointer)
3015 {
3016 PFORMAT_STRING desc;
3017 NDR_FREE m;
3018 unsigned long size;
3019
3020 while (*pFormat != RPC_FC_END) {
3021 switch (*pFormat) {
3022 case RPC_FC_BYTE:
3023 case RPC_FC_CHAR:
3024 case RPC_FC_SMALL:
3025 case RPC_FC_USMALL:
3026 pMemory += 1;
3027 break;
3028 case RPC_FC_WCHAR:
3029 case RPC_FC_SHORT:
3030 case RPC_FC_USHORT:
3031 pMemory += 2;
3032 break;
3033 case RPC_FC_LONG:
3034 case RPC_FC_ULONG:
3035 case RPC_FC_ENUM16:
3036 case RPC_FC_ENUM32:
3037 pMemory += 4;
3038 break;
3039 case RPC_FC_HYPER:
3040 pMemory += 8;
3041 break;
3042 case RPC_FC_POINTER:
3043 NdrPointerFree(pStubMsg, *(unsigned char**)pMemory, pPointer);
3044 pPointer += 4;
3045 pMemory += 4;
3046 break;
3047 case RPC_FC_ALIGNM4:
3048 ALIGN_POINTER(pMemory, 4);
3049 break;
3050 case RPC_FC_ALIGNM8:
3051 ALIGN_POINTER(pMemory, 8);
3052 break;
3053 case RPC_FC_STRUCTPAD1:
3054 case RPC_FC_STRUCTPAD2:
3055 case RPC_FC_STRUCTPAD3:
3056 case RPC_FC_STRUCTPAD4:
3057 case RPC_FC_STRUCTPAD5:
3058 case RPC_FC_STRUCTPAD6:
3059 case RPC_FC_STRUCTPAD7:
3060 pMemory += *pFormat - RPC_FC_STRUCTPAD1 + 1;
3061 break;
3062 case RPC_FC_EMBEDDED_COMPLEX:
3063 pMemory += pFormat[1];
3064 pFormat += 2;
3065 desc = pFormat + *(const SHORT*)pFormat;
3066 size = EmbeddedComplexSize(pStubMsg, desc);
3067 m = NdrFreer[*desc & NDR_TABLE_MASK];
3068 if (m)
3069 {
3070 /* for some reason interface pointers aren't generated as
3071 * RPC_FC_POINTER, but instead as RPC_FC_EMBEDDED_COMPLEX, yet
3072 * they still need the derefencing treatment that pointers are
3073 * given */
3074 if (*desc == RPC_FC_IP)
3075 m(pStubMsg, *(unsigned char **)pMemory, desc);
3076 else
3077 m(pStubMsg, pMemory, desc);
3078 }
3079 pMemory += size;
3080 pFormat += 2;
3081 continue;
3082 case RPC_FC_PAD:
3083 break;
3084 default:
3085 FIXME("unhandled format 0x%02x\n", *pFormat);
3086 }
3087 pFormat++;
3088 }
3089
3090 return pMemory;
3091 }
3092
3093 static unsigned long ComplexStructMemorySize(PMIDL_STUB_MESSAGE pStubMsg,
3094 PFORMAT_STRING pFormat,
3095 PFORMAT_STRING pPointer)
3096 {
3097 PFORMAT_STRING desc;
3098 unsigned long size = 0;
3099
3100 while (*pFormat != RPC_FC_END) {
3101 switch (*pFormat) {
3102 case RPC_FC_BYTE:
3103 case RPC_FC_CHAR:
3104 case RPC_FC_SMALL:
3105 case RPC_FC_USMALL:
3106 size += 1;
3107 safe_buffer_increment(pStubMsg, 1);
3108 break;
3109 case RPC_FC_WCHAR:
3110 case RPC_FC_SHORT:
3111 case RPC_FC_USHORT:
3112 size += 2;
3113 safe_buffer_increment(pStubMsg, 2);
3114 break;
3115 case RPC_FC_ENUM16:
3116 size += 4;
3117 safe_buffer_increment(pStubMsg, 2);
3118 break;
3119 case RPC_FC_LONG:
3120 case RPC_FC_ULONG:
3121 case RPC_FC_ENUM32:
3122 size += 4;
3123 safe_buffer_increment(pStubMsg, 4);
3124 break;
3125 case RPC_FC_HYPER:
3126 size += 8;
3127 safe_buffer_increment(pStubMsg, 8);
3128 break;
3129 case RPC_FC_POINTER:
3130 {
3131 unsigned char *saved_buffer;
3132 int pointer_buffer_mark_set = 0;
3133 if (*pPointer != RPC_FC_RP)
3134 ALIGN_POINTER(pStubMsg->Buffer, 4);
3135 saved_buffer = pStubMsg->Buffer;
3136 if (pStubMsg->PointerBufferMark)
3137 {
3138 pStubMsg->Buffer = pStubMsg->PointerBufferMark;
3139 pStubMsg->PointerBufferMark = NULL;
3140 pointer_buffer_mark_set = 1;
3141 }
3142 else if (*pPointer != RPC_FC_RP)
3143 safe_buffer_increment(pStubMsg, 4); /* for pointer ID */
3144
3145 if (!pStubMsg->IgnoreEmbeddedPointers)
3146 PointerMemorySize(pStubMsg, saved_buffer, pPointer);
3147 if (pointer_buffer_mark_set)
3148 {
3149 STD_OVERFLOW_CHECK(pStubMsg);
3150 pStubMsg->PointerBufferMark = pStubMsg->Buffer;
3151 pStubMsg->Buffer = saved_buffer;
3152 if (*pPointer != RPC_FC_RP)
3153 safe_buffer_increment(pStubMsg, 4); /* for pointer ID */
3154 }
3155 pPointer += 4;
3156 size += 4;
3157 break;
3158 }
3159 case RPC_FC_ALIGNM4:
3160 ALIGN_LENGTH(size, 4);
3161 break;
3162 case RPC_FC_ALIGNM8:
3163 ALIGN_LENGTH(size, 8);
3164 break;
3165 case RPC_FC_STRUCTPAD1:
3166 case RPC_FC_STRUCTPAD2:
3167 case RPC_FC_STRUCTPAD3:
3168 case RPC_FC_STRUCTPAD4:
3169 case RPC_FC_STRUCTPAD5:
3170 case RPC_FC_STRUCTPAD6:
3171 case RPC_FC_STRUCTPAD7:
3172 size += *pFormat - RPC_FC_STRUCTPAD1 + 1;
3173 break;
3174 case RPC_FC_EMBEDDED_COMPLEX:
3175 size += pFormat[1];
3176 pFormat += 2;
3177 desc = pFormat + *(const SHORT*)pFormat;
3178 size += EmbeddedComplexMemorySize(pStubMsg, desc);
3179 pFormat += 2;
3180 continue;
3181 case RPC_FC_PAD:
3182 break;
3183 default:
3184 FIXME("unhandled format 0x%02x\n", *pFormat);
3185 }
3186 pFormat++;
3187 }
3188
3189 return size;
3190 }
3191
3192 unsigned long ComplexStructSize(PMIDL_STUB_MESSAGE pStubMsg,
3193 PFORMAT_STRING pFormat)
3194 {
3195 PFORMAT_STRING desc;
3196 unsigned long size = 0;
3197
3198 while (*pFormat != RPC_FC_END) {
3199 switch (*pFormat) {
3200 case RPC_FC_BYTE:
3201 case RPC_FC_CHAR:
3202 case RPC_FC_SMALL:
3203 case RPC_FC_USMALL:
3204 size += 1;
3205 break;
3206 case RPC_FC_WCHAR:
3207 case RPC_FC_SHORT:
3208 case RPC_FC_USHORT:
3209 size += 2;
3210 break;
3211 case RPC_FC_LONG:
3212 case RPC_FC_ULONG:
3213 case RPC_FC_ENUM16:
3214 case RPC_FC_ENUM32:
3215 size += 4;
3216 break;
3217 case RPC_FC_HYPER:
3218 size += 8;
3219 break;
3220 case RPC_FC_POINTER:
3221 size += sizeof(void *);
3222 break;
3223 case RPC_FC_ALIGNM4:
3224 ALIGN_LENGTH(size, 4);
3225 break;
3226 case RPC_FC_ALIGNM8:
3227 ALIGN_LENGTH(size, 8);
3228 break;
3229 case RPC_FC_STRUCTPAD1:
3230 case RPC_FC_STRUCTPAD2:
3231 case RPC_FC_STRUCTPAD3:
3232 case RPC_FC_STRUCTPAD4:
3233 case RPC_FC_STRUCTPAD5:
3234 case RPC_FC_STRUCTPAD6:
3235 case RPC_FC_STRUCTPAD7:
3236 size += *pFormat - RPC_FC_STRUCTPAD1 + 1;
3237 break;
3238 case RPC_FC_EMBEDDED_COMPLEX:
3239 size += pFormat[1];
3240 pFormat += 2;
3241 desc = pFormat + *(const SHORT*)pFormat;
3242 size += EmbeddedComplexSize(pStubMsg, desc);
3243 pFormat += 2;
3244 continue;
3245 case RPC_FC_PAD:
3246 break;
3247 default:
3248 FIXME("unhandled format 0x%02x\n", *pFormat);
3249 }
3250 pFormat++;
3251 }
3252
3253 return size;
3254 }
3255
3256 /***********************************************************************
3257 * NdrComplexStructMarshall [RPCRT4.@]
3258 */
3259 unsigned char * WINAPI NdrComplexStructMarshall(PMIDL_STUB_MESSAGE pStubMsg,
3260 unsigned char *pMemory,
3261 PFORMAT_STRING pFormat)
3262 {
3263 PFORMAT_STRING conf_array = NULL;
3264 PFORMAT_STRING pointer_desc = NULL;
3265 unsigned char *OldMemory = pStubMsg->Memory;
3266 int pointer_buffer_mark_set = 0;
3267 ULONG count = 0;
3268 ULONG max_count = 0;
3269 ULONG offset = 0;
3270
3271 TRACE("(%p,%p,%p)\n", pStubMsg, pMemory, pFormat);
3272
3273 if (!pStubMsg->PointerBufferMark)
3274 {
3275 int saved_ignore_embedded = pStubMsg->IgnoreEmbeddedPointers;
3276 /* save buffer length */
3277 unsigned long saved_buffer_length = pStubMsg->BufferLength;
3278
3279 /* get the buffer pointer after complex array data, but before
3280 * pointer data */
3281 pStubMsg->BufferLength = pStubMsg->Buffer - (unsigned char *)pStubMsg->RpcMsg->Buffer;
3282 pStubMsg->IgnoreEmbeddedPointers = 1;
3283 NdrComplexStructBufferSize(pStubMsg, pMemory, pFormat);
3284 pStubMsg->IgnoreEmbeddedPointers = saved_ignore_embedded;
3285
3286 /* save it for use by embedded pointer code later */
3287 pStubMsg->PointerBufferMark = (unsigned char *)pStubMsg->RpcMsg->Buffer + pStubMsg->BufferLength;
3288 TRACE("difference = 0x%x\n", pStubMsg->PointerBufferMark - pStubMsg->Buffer);
3289 pointer_buffer_mark_set = 1;
3290
3291 /* restore the original buffer length */
3292 pStubMsg->BufferLength = saved_buffer_length;
3293 }
3294
3295 ALIGN_POINTER_CLEAR(pStubMsg->Buffer, pFormat[1] + 1);
3296
3297 pFormat += 4;
3298 if (*(const SHORT*)pFormat) conf_array = pFormat + *(const SHORT*)pFormat;
3299 pFormat += 2;
3300 if (*(const WORD*)pFormat) pointer_desc = pFormat + *(const WORD*)pFormat;
3301 pFormat += 2;
3302
3303 pStubMsg->Memory = pMemory;
3304
3305 if (conf_array)
3306 {
3307 unsigned long struct_size = ComplexStructSize(pStubMsg, pFormat);
3308 array_compute_and_write_conformance(conf_array[0], pStubMsg,
3309 pMemory + struct_size, conf_array);
3310 /* these could be changed in ComplexMarshall so save them for later */
3311 max_count = pStubMsg->MaxCount;
3312 count = pStubMsg->ActualCount;
3313 offset = pStubMsg->Offset;
3314 }
3315
3316 pMemory = ComplexMarshall(pStubMsg, pMemory, pFormat, pointer_desc);
3317
3318 if (conf_array)
3319 {
3320 pStubMsg->MaxCount = max_count;
3321 pStubMsg->ActualCount = count;
3322 pStubMsg->Offset = offset;
3323 array_write_variance_and_marshall(conf_array[0], pStubMsg, pMemory,
3324 conf_array, TRUE /* fHasPointers */);
3325 }
3326
3327 pStubMsg->Memory = OldMemory;
3328
3329 if (pointer_buffer_mark_set)
3330 {
3331 pStubMsg->Buffer = pStubMsg->PointerBufferMark;
3332 pStubMsg->PointerBufferMark = NULL;
3333 }
3334
3335 STD_OVERFLOW_CHECK(pStubMsg);
3336
3337 return NULL;
3338 }
3339
3340 /***********************************************************************
3341 * NdrComplexStructUnmarshall [RPCRT4.@]
3342 */
3343 unsigned char * WINAPI NdrComplexStructUnmarshall(PMIDL_STUB_MESSAGE pStubMsg,
3344 unsigned char **ppMemory,
3345 PFORMAT_STRING pFormat,
3346 unsigned char fMustAlloc)
3347 {
3348 unsigned size = *(const WORD*)(pFormat+2);
3349 PFORMAT_STRING conf_array = NULL;
3350 PFORMAT_STRING pointer_desc = NULL;
3351 unsigned char *pMemory;
3352 int pointer_buffer_mark_set = 0;
3353 ULONG count = 0;
3354 ULONG max_count = 0;
3355 ULONG offset = 0;
3356 ULONG array_size = 0;
3357
3358 TRACE("(%p,%p,%p,%d)\n", pStubMsg, ppMemory, pFormat, fMustAlloc);
3359
3360 if (!pStubMsg->PointerBufferMark)
3361 {
3362 int saved_ignore_embedded = pStubMsg->IgnoreEmbeddedPointers;
3363 /* save buffer pointer */
3364 unsigned char *saved_buffer = pStubMsg->Buffer;
3365
3366 /* get the buffer pointer after complex array data, but before
3367 * pointer data */
3368 pStubMsg->IgnoreEmbeddedPointers = 1;
3369 NdrComplexStructMemorySize(pStubMsg, pFormat);
3370 pStubMsg->IgnoreEmbeddedPointers = saved_ignore_embedded;
3371
3372 /* save it for use by embedded pointer code later */
3373 pStubMsg->PointerBufferMark = pStubMsg->Buffer;
3374 TRACE("difference = 0x%lx\n", (unsigned long)(pStubMsg->PointerBufferMark - saved_buffer));
3375 pointer_buffer_mark_set = 1;
3376
3377 /* restore the original buffer */
3378 pStubMsg->Buffer = saved_buffer;
3379 }
3380
3381 ALIGN_POINTER(pStubMsg->Buffer, pFormat[1] + 1);
3382
3383 pFormat += 4;
3384 if (*(const SHORT*)pFormat) conf_array = pFormat + *(const SHORT*)pFormat;
3385 pFormat += 2;
3386 if (*(const WORD*)pFormat) pointer_desc = pFormat + *(const WORD*)pFormat;
3387 pFormat += 2;
3388
3389 if (conf_array)
3390 {
3391 array_size = array_read_conformance(conf_array[0], pStubMsg, conf_array);
3392 size += array_size;
3393
3394 /* these could be changed in ComplexMarshall so save them for later */
3395 max_count = pStubMsg->MaxCount;
3396 count = pStubMsg->ActualCount;
3397 offset = pStubMsg->Offset;
3398 }
3399
3400 if (!fMustAlloc && !*ppMemory)
3401 fMustAlloc = TRUE;
3402 if (fMustAlloc)
3403 *ppMemory = NdrAllocate(pStubMsg, size);
3404
3405 pMemory = ComplexUnmarshall(pStubMsg, *ppMemory, pFormat, pointer_desc, fMustAlloc);
3406
3407 if (conf_array)
3408 {
3409 pStubMsg->MaxCount = max_count;
3410 pStubMsg->ActualCount = count;
3411 pStubMsg->Offset = offset;
3412 if (fMustAlloc)
3413 memset(pMemory, 0, array_size);
3414 array_read_variance_and_unmarshall(conf_array[0], pStubMsg, &pMemory,
3415 conf_array, FALSE,
3416 FALSE /* fUseBufferMemoryServer */,
3417 TRUE /* fUnmarshall */);
3418 }
3419
3420 if (pointer_buffer_mark_set)
3421 {
3422 pStubMsg->Buffer = pStubMsg->PointerBufferMark;
3423 pStubMsg->PointerBufferMark = NULL;
3424 }
3425
3426 return NULL;
3427 }
3428
3429 /***********************************************************************
3430 * NdrComplexStructBufferSize [RPCRT4.@]
3431 */
3432 void WINAPI NdrComplexStructBufferSize(PMIDL_STUB_MESSAGE pStubMsg,
3433 unsigned char *pMemory,
3434 PFORMAT_STRING pFormat)
3435 {
3436 PFORMAT_STRING conf_array = NULL;
3437 PFORMAT_STRING pointer_desc = NULL;
3438 unsigned char *OldMemory = pStubMsg->Memory;
3439 int pointer_length_set = 0;
3440 ULONG count = 0;
3441 ULONG max_count = 0;
3442 ULONG offset = 0;
3443
3444 TRACE("(%p,%p,%p)\n", pStubMsg, pMemory, pFormat);
3445
3446 ALIGN_LENGTH(pStubMsg->BufferLength, pFormat[1] + 1);
3447
3448 if(!pStubMsg->IgnoreEmbeddedPointers && !pStubMsg->PointerLength)
3449 {
3450 int saved_ignore_embedded = pStubMsg->IgnoreEmbeddedPointers;
3451 unsigned long saved_buffer_length = pStubMsg->BufferLength;
3452
3453 /* get the buffer length after complex struct data, but before
3454 * pointer data */
3455 pStubMsg->IgnoreEmbeddedPointers = 1;
3456 NdrComplexStructBufferSize(pStubMsg, pMemory, pFormat);
3457 pStubMsg->IgnoreEmbeddedPointers = saved_ignore_embedded;
3458
3459 /* save it for use by embedded pointer code later */
3460 pStubMsg->PointerLength = pStubMsg->BufferLength;
3461 pointer_length_set = 1;
3462 TRACE("difference = 0x%lx\n", pStubMsg->PointerLength - saved_buffer_length);
3463
3464 /* restore the original buffer length */
3465 pStubMsg->BufferLength = saved_buffer_length;
3466 }
3467
3468 pFormat += 4;
3469 if (*(const SHORT*)pFormat) conf_array = pFormat + *(const SHORT*)pFormat;
3470 pFormat += 2;
3471 if (*(const WORD*)pFormat) pointer_desc = pFormat + *(const WORD*)pFormat;
3472 pFormat += 2;
3473
3474 pStubMsg->Memory = pMemory;
3475
3476 if (conf_array)
3477 {
3478 unsigned long struct_size = ComplexStructSize(pStubMsg, pFormat);
3479 array_compute_and_size_conformance(conf_array[0], pStubMsg, pMemory + struct_size,
3480 conf_array);
3481
3482 /* these could be changed in ComplexMarshall so save them for later */
3483 max_count = pStubMsg->MaxCount;
3484 count = pStubMsg->ActualCount;
3485 offset = pStubMsg->Offset;
3486 }
3487
3488 pMemory = ComplexBufferSize(pStubMsg, pMemory, pFormat, pointer_desc);
3489
3490 if (conf_array)
3491 {
3492 pStubMsg->MaxCount = max_count;
3493 pStubMsg->ActualCount = count;
3494 pStubMsg->Offset = offset;
3495 array_buffer_size(conf_array[0], pStubMsg, pMemory, conf_array,
3496 TRUE /* fHasPointers */);
3497 }
3498
3499 pStubMsg->Memory = OldMemory;
3500
3501 if(pointer_length_set)
3502 {
3503 pStubMsg->BufferLength = pStubMsg->PointerLength;
3504 pStubMsg->PointerLength = 0;
3505 }
3506
3507 }
3508
3509 /***********************************************************************
3510 * NdrComplexStructMemorySize [RPCRT4.@]
3511 */
3512 ULONG WINAPI NdrComplexStructMemorySize(PMIDL_STUB_MESSAGE pStubMsg,
3513 PFORMAT_STRING pFormat)
3514 {
3515 unsigned size = *(const WORD*)(pFormat+2);
3516 PFORMAT_STRING conf_array = NULL;
3517 PFORMAT_STRING pointer_desc = NULL;
3518 ULONG count = 0;
3519 ULONG max_count = 0;
3520 ULONG offset = 0;
3521
3522 TRACE("(%p,%p)\n", pStubMsg, pFormat);
3523
3524 ALIGN_POINTER(pStubMsg->Buffer, pFormat[1] + 1);
3525
3526 pFormat += 4;
3527 if (*(const SHORT*)pFormat) conf_array = pFormat + *(const SHORT*)pFormat;
3528 pFormat += 2;
3529 if (*(const WORD*)pFormat) pointer_desc = pFormat + *(const WORD*)pFormat;
3530 pFormat += 2;
3531
3532 if (conf_array)
3533 {
3534 array_read_conformance(conf_array[0], pStubMsg, conf_array);
3535
3536 /* these could be changed in ComplexStructMemorySize so save them for
3537 * later */
3538 max_count = pStubMsg->MaxCount;
3539 count = pStubMsg->ActualCount;
3540 offset = pStubMsg->Offset;
3541 }
3542
3543 ComplexStructMemorySize(pStubMsg, pFormat, pointer_desc);
3544
3545 if (conf_array)
3546 {
3547 pStubMsg->MaxCount = max_count;
3548 pStubMsg->ActualCount = count;
3549 pStubMsg->Offset = offset;
3550 array_memory_size(conf_array[0], pStubMsg, conf_array,
3551 TRUE /* fHasPointers */);
3552 }
3553
3554 return size;
3555 }
3556
3557 /***********************************************************************
3558 * NdrComplexStructFree [RPCRT4.@]
3559 */
3560 void WINAPI NdrComplexStructFree(PMIDL_STUB_MESSAGE pStubMsg,
3561 unsigned char *pMemory,
3562 PFORMAT_STRING pFormat)
3563 {
3564 PFORMAT_STRING conf_array = NULL;
3565 PFORMAT_STRING pointer_desc = NULL;
3566 unsigned char *OldMemory = pStubMsg->Memory;
3567
3568 TRACE("(%p,%p,%p)\n", pStubMsg, pMemory, pFormat);
3569
3570 pFormat += 4;
3571 if (*(const SHORT*)pFormat) conf_array = pFormat + *(const SHORT*)pFormat;
3572 pFormat += 2;
3573 if (*(const WORD*)pFormat) pointer_desc = pFormat + *(const WORD*)pFormat;
3574 pFormat += 2;
3575
3576 pStubMsg->Memory = pMemory;
3577
3578 pMemory = ComplexFree(pStubMsg, pMemory, pFormat, pointer_desc);
3579
3580 if (conf_array)
3581 array_free(conf_array[0], pStubMsg, pMemory, conf_array,
3582 TRUE /* fHasPointers */);
3583