Team Ai
Modelpublic

AryaWu/sqlite

sourceHugging Faceupdated 10mo agoView on Hugging Face
0likes
malloc.c921 linesDownload Raw Back to src
1/*2** 2001 September 153**4** The author disclaims copyright to this source code.  In place of5** a legal notice, here is a blessing:6**7**    May you do good and not evil.8**    May you find forgiveness for yourself and forgive others.9**    May you share freely, never taking more than you give.10**11*************************************************************************12**13** Memory allocation functions used throughout sqlite.14*/15#include "sqliteInt.h"16#include <stdarg.h>17 18/*19** Attempt to release up to n bytes of non-essential memory currently20** held by SQLite. An example of non-essential memory is memory used to21** cache database pages that are not currently in use.22*/23int sqlite3_release_memory(int n){24#ifdef SQLITE_ENABLE_MEMORY_MANAGEMENT25  return sqlite3PcacheReleaseMemory(n);26#else27  /* IMPLEMENTATION-OF: R-34391-24921 The sqlite3_release_memory() routine28  ** is a no-op returning zero if SQLite is not compiled with29  ** SQLITE_ENABLE_MEMORY_MANAGEMENT. */30  UNUSED_PARAMETER(n);31  return 0;32#endif33}34 35/*36** Default value of the hard heap limit.  0 means "no limit".37*/38#ifndef SQLITE_MAX_MEMORY39# define SQLITE_MAX_MEMORY 040#endif41 42/*43** State information local to the memory allocation subsystem.44*/45static SQLITE_WSD struct Mem0Global {46  sqlite3_mutex *mutex;         /* Mutex to serialize access */47  sqlite3_int64 alarmThreshold; /* The soft heap limit */48  sqlite3_int64 hardLimit;      /* The hard upper bound on memory */49 50  /*51  ** True if heap is nearly "full" where "full" is defined by the52  ** sqlite3_soft_heap_limit() setting.53  */54  int nearlyFull;55} mem0 = { 0, SQLITE_MAX_MEMORY, SQLITE_MAX_MEMORY, 0 };56 57#define mem0 GLOBAL(struct Mem0Global, mem0)58 59/*60** Return the memory allocator mutex. sqlite3_status() needs it.61*/62sqlite3_mutex *sqlite3MallocMutex(void){63  return mem0.mutex;64}65 66#ifndef SQLITE_OMIT_DEPRECATED67/*68** Deprecated external interface.  It used to set an alarm callback69** that was invoked when memory usage grew too large.  Now it is a70** no-op.71*/72int sqlite3_memory_alarm(73  void(*xCallback)(void *pArg, sqlite3_int64 used,int N),74  void *pArg,75  sqlite3_int64 iThreshold76){77  (void)xCallback;78  (void)pArg;79  (void)iThreshold;80  return SQLITE_OK;81}82#endif83 84/*85** Set the soft heap-size limit for the library.  An argument of86** zero disables the limit.  A negative argument is a no-op used to87** obtain the return value.88**89** The return value is the value of the heap limit just before this90** interface was called.91**92** If the hard heap limit is enabled, then the soft heap limit cannot93** be disabled nor raised above the hard heap limit.94*/95sqlite3_int64 sqlite3_soft_heap_limit64(sqlite3_int64 n){96  sqlite3_int64 priorLimit;97  sqlite3_int64 excess;98  sqlite3_int64 nUsed;99#ifndef SQLITE_OMIT_AUTOINIT100  int rc = sqlite3_initialize();101  if( rc ) return -1;102#endif103  sqlite3_mutex_enter(mem0.mutex);104  priorLimit = mem0.alarmThreshold;105  if( n<0 ){106    sqlite3_mutex_leave(mem0.mutex);107    return priorLimit;108  }109  if( mem0.hardLimit>0 && (n>mem0.hardLimit || n==0) ){110    n = mem0.hardLimit;111  }112  mem0.alarmThreshold = n;113  nUsed = sqlite3StatusValue(SQLITE_STATUS_MEMORY_USED);114  AtomicStore(&mem0.nearlyFull, n>0 && n<=nUsed);115  sqlite3_mutex_leave(mem0.mutex);116  excess = sqlite3_memory_used() - n;117  if( excess>0 ) sqlite3_release_memory((int)(excess & 0x7fffffff));118  return priorLimit;119}120void sqlite3_soft_heap_limit(int n){121  if( n<0 ) n = 0;122  sqlite3_soft_heap_limit64(n);123}124 125/*126** Set the hard heap-size limit for the library. An argument of zero127** disables the hard heap limit.  A negative argument is a no-op used128** to obtain the return value without affecting the hard heap limit.129**130** The return value is the value of the hard heap limit just prior to131** calling this interface.132**133** Setting the hard heap limit will also activate the soft heap limit134** and constrain the soft heap limit to be no more than the hard heap135** limit.136*/137sqlite3_int64 sqlite3_hard_heap_limit64(sqlite3_int64 n){138  sqlite3_int64 priorLimit;139#ifndef SQLITE_OMIT_AUTOINIT140  int rc = sqlite3_initialize();141  if( rc ) return -1;142#endif143  sqlite3_mutex_enter(mem0.mutex);144  priorLimit = mem0.hardLimit;145  if( n>=0 ){146    mem0.hardLimit = n;147    if( n<mem0.alarmThreshold || mem0.alarmThreshold==0 ){148      mem0.alarmThreshold = n;149    }150  }151  sqlite3_mutex_leave(mem0.mutex);152  return priorLimit;153}154 155 156/*157** Initialize the memory allocation subsystem.158*/159int sqlite3MallocInit(void){160  int rc;161  if( sqlite3GlobalConfig.m.xMalloc==0 ){162    sqlite3MemSetDefault();163  }164  mem0.mutex = sqlite3MutexAlloc(SQLITE_MUTEX_STATIC_MEM);165  if( sqlite3GlobalConfig.pPage==0 || sqlite3GlobalConfig.szPage<512166      || sqlite3GlobalConfig.nPage<=0 ){167    sqlite3GlobalConfig.pPage = 0;168    sqlite3GlobalConfig.szPage = 0;169  }170  rc = sqlite3GlobalConfig.m.xInit(sqlite3GlobalConfig.m.pAppData);171  if( rc!=SQLITE_OK ) memset(&mem0, 0, sizeof(mem0));172  return rc;173}174 175/*176** Return true if the heap is currently under memory pressure - in other177** words if the amount of heap used is close to the limit set by178** sqlite3_soft_heap_limit().179*/180int sqlite3HeapNearlyFull(void){181  return AtomicLoad(&mem0.nearlyFull);182}183 184/*185** Deinitialize the memory allocation subsystem.186*/187void sqlite3MallocEnd(void){188  if( sqlite3GlobalConfig.m.xShutdown ){189    sqlite3GlobalConfig.m.xShutdown(sqlite3GlobalConfig.m.pAppData);190  }191  memset(&mem0, 0, sizeof(mem0));192}193 194/*195** Return the amount of memory currently checked out.196*/197sqlite3_int64 sqlite3_memory_used(void){198  sqlite3_int64 res, mx;199  sqlite3_status64(SQLITE_STATUS_MEMORY_USED, &res, &mx, 0);200  return res;201}202 203/*204** Return the maximum amount of memory that has ever been205** checked out since either the beginning of this process206** or since the most recent reset.207*/208sqlite3_int64 sqlite3_memory_highwater(int resetFlag){209  sqlite3_int64 res, mx;210  sqlite3_status64(SQLITE_STATUS_MEMORY_USED, &res, &mx, resetFlag);211  return mx;212}213 214/*215** Trigger the alarm 216*/217static void sqlite3MallocAlarm(int nByte){218  if( mem0.alarmThreshold<=0 ) return;219  sqlite3_mutex_leave(mem0.mutex);220  sqlite3_release_memory(nByte);221  sqlite3_mutex_enter(mem0.mutex);222}223 224#ifdef SQLITE_DEBUG225/*226** This routine is called whenever an out-of-memory condition is seen,227** It's only purpose to to serve as a breakpoint for gdb or similar228** code debuggers when working on out-of-memory conditions, for example229** caused by PRAGMA hard_heap_limit=N.230*/231static SQLITE_NOINLINE void test_oom_breakpoint(u64 n){232  static u64 nOomFault = 0;233  nOomFault += n;234  /* The assert() is never reached in a human lifetime.  It  is here mostly235  ** to prevent code optimizers from optimizing out this function. */236  assert( (nOomFault>>32) < 0xffffffff );237}238#else239# define test_oom_breakpoint(X)   /* No-op for production builds */240#endif241 242/*243** Do a memory allocation with statistics and alarms.  Assume the244** lock is already held.245*/246static void mallocWithAlarm(int n, void **pp){247  void *p;248  int nFull;249  assert( sqlite3_mutex_held(mem0.mutex) );250  assert( n>0 );251 252  /* In Firefox (circa 2017-02-08), xRoundup() is remapped to an internal253  ** implementation of malloc_good_size(), which must be called in debug254  ** mode and specifically when the DMD "Dark Matter Detector" is enabled255  ** or else a crash results.  Hence, do not attempt to optimize out the256  ** following xRoundup() call. */257  nFull = sqlite3GlobalConfig.m.xRoundup(n);258 259  sqlite3StatusHighwater(SQLITE_STATUS_MALLOC_SIZE, n);260  if( mem0.alarmThreshold>0 ){261    sqlite3_int64 nUsed = sqlite3StatusValue(SQLITE_STATUS_MEMORY_USED);262    if( nUsed >= mem0.alarmThreshold - nFull ){263      AtomicStore(&mem0.nearlyFull, 1);264      sqlite3MallocAlarm(nFull);265      if( mem0.hardLimit ){266        nUsed = sqlite3StatusValue(SQLITE_STATUS_MEMORY_USED);267        if( nUsed >= mem0.hardLimit - nFull ){268          test_oom_breakpoint(1);269          *pp = 0;270          return;271        }272      }273    }else{274      AtomicStore(&mem0.nearlyFull, 0);275    }276  }277  p = sqlite3GlobalConfig.m.xMalloc(nFull);278#ifdef SQLITE_ENABLE_MEMORY_MANAGEMENT279  if( p==0 && mem0.alarmThreshold>0 ){280    sqlite3MallocAlarm(nFull);281    p = sqlite3GlobalConfig.m.xMalloc(nFull);282  }283#endif284  if( p ){285    nFull = sqlite3MallocSize(p);286    sqlite3StatusUp(SQLITE_STATUS_MEMORY_USED, nFull);287    sqlite3StatusUp(SQLITE_STATUS_MALLOC_COUNT, 1);288  }289  *pp = p;290}291 292/*293** Maximum size of any single memory allocation.294**295** This is not a limit on the total amount of memory used.  This is296** a limit on the size parameter to sqlite3_malloc() and sqlite3_realloc().297**298** The upper bound is slightly less than 2GiB:  0x7ffffeff == 2,147,483,391299** This provides a 256-byte safety margin for defense against 32-bit 300** signed integer overflow bugs when computing memory allocation sizes.301** Paranoid applications might want to reduce the maximum allocation size302** further for an even larger safety margin.  0x3fffffff or 0x0fffffff303** or even smaller would be reasonable upper bounds on the size of a memory304** allocations for most applications.305*/306#ifndef SQLITE_MAX_ALLOCATION_SIZE307# define SQLITE_MAX_ALLOCATION_SIZE  2147483391308#endif309#if SQLITE_MAX_ALLOCATION_SIZE>2147483391310# error Maximum size for SQLITE_MAX_ALLOCATION_SIZE is 2147483391311#endif312 313/*314** Allocate memory.  This routine is like sqlite3_malloc() except that it315** assumes the memory subsystem has already been initialized.316*/317void *sqlite3Malloc(u64 n){318  void *p;319  if( n==0 || n>SQLITE_MAX_ALLOCATION_SIZE ){320    p = 0;321  }else if( sqlite3GlobalConfig.bMemstat ){322    sqlite3_mutex_enter(mem0.mutex);323    mallocWithAlarm((int)n, &p);324    sqlite3_mutex_leave(mem0.mutex);325  }else{326    p = sqlite3GlobalConfig.m.xMalloc((int)n);327  }328  assert( EIGHT_BYTE_ALIGNMENT(p) );  /* IMP: R-11148-40995 */329  return p;330}331 332/*333** This version of the memory allocation is for use by the application.334** First make sure the memory subsystem is initialized, then do the335** allocation.336*/337void *sqlite3_malloc(int n){338#ifndef SQLITE_OMIT_AUTOINIT339  if( sqlite3_initialize() ) return 0;340#endif341  return n<=0 ? 0 : sqlite3Malloc(n);342}343void *sqlite3_malloc64(sqlite3_uint64 n){344#ifndef SQLITE_OMIT_AUTOINIT345  if( sqlite3_initialize() ) return 0;346#endif347  return sqlite3Malloc(n);348}349 350/*351** TRUE if p is a lookaside memory allocation from db352*/353#ifndef SQLITE_OMIT_LOOKASIDE354static int isLookaside(sqlite3 *db, const void *p){355  return SQLITE_WITHIN(p, db->lookaside.pStart, db->lookaside.pTrueEnd);356}357#else358#define isLookaside(A,B) 0359#endif360 361/*362** Return the size of a memory allocation previously obtained from363** sqlite3Malloc() or sqlite3_malloc().364*/365int sqlite3MallocSize(const void *p){366  assert( sqlite3MemdebugHasType(p, MEMTYPE_HEAP) );367  return sqlite3GlobalConfig.m.xSize((void*)p);368}369static int lookasideMallocSize(sqlite3 *db, const void *p){370#ifndef SQLITE_OMIT_TWOSIZE_LOOKASIDE    371  return p<db->lookaside.pMiddle ? db->lookaside.szTrue : LOOKASIDE_SMALL;372#else373  return db->lookaside.szTrue;374#endif  375}376int sqlite3DbMallocSize(sqlite3 *db, const void *p){377  assert( p!=0 );378#ifdef SQLITE_DEBUG379  if( db==0 ){380    assert( sqlite3MemdebugNoType(p, (u8)~MEMTYPE_HEAP) );381    assert( sqlite3MemdebugHasType(p, MEMTYPE_HEAP) );382  }else if( !isLookaside(db,p) ){383    assert( sqlite3MemdebugHasType(p, (MEMTYPE_LOOKASIDE|MEMTYPE_HEAP)) );384    assert( sqlite3MemdebugNoType(p, (u8)~(MEMTYPE_LOOKASIDE|MEMTYPE_HEAP)) );385  }386#endif387  if( db ){388    if( ((uptr)p)<(uptr)(db->lookaside.pTrueEnd) ){389#ifndef SQLITE_OMIT_TWOSIZE_LOOKASIDE390      if( ((uptr)p)>=(uptr)(db->lookaside.pMiddle) ){391        assert( sqlite3_mutex_held(db->mutex) );392        return LOOKASIDE_SMALL;393      }394#endif395      if( ((uptr)p)>=(uptr)(db->lookaside.pStart) ){396        assert( sqlite3_mutex_held(db->mutex) );397        return db->lookaside.szTrue;398      }399    }400  }401  return sqlite3GlobalConfig.m.xSize((void*)p);402}403sqlite3_uint64 sqlite3_msize(void *p){404  assert( sqlite3MemdebugNoType(p, (u8)~MEMTYPE_HEAP) );405  assert( sqlite3MemdebugHasType(p, MEMTYPE_HEAP) );406  return p ? sqlite3GlobalConfig.m.xSize(p) : 0;407}408 409/*410** Free memory previously obtained from sqlite3Malloc().411*/412void sqlite3_free(void *p){413  if( p==0 ) return;  /* IMP: R-49053-54554 */414  assert( sqlite3MemdebugHasType(p, MEMTYPE_HEAP) );415  assert( sqlite3MemdebugNoType(p, (u8)~MEMTYPE_HEAP) );416  if( sqlite3GlobalConfig.bMemstat ){417    sqlite3_mutex_enter(mem0.mutex);418    sqlite3StatusDown(SQLITE_STATUS_MEMORY_USED, sqlite3MallocSize(p));419    sqlite3StatusDown(SQLITE_STATUS_MALLOC_COUNT, 1);420    sqlite3GlobalConfig.m.xFree(p);421    sqlite3_mutex_leave(mem0.mutex);422  }else{423    sqlite3GlobalConfig.m.xFree(p);424  }425}426 427/*428** Add the size of memory allocation "p" to the count in429** *db->pnBytesFreed.430*/431static SQLITE_NOINLINE void measureAllocationSize(sqlite3 *db, void *p){432  *db->pnBytesFreed += sqlite3DbMallocSize(db,p);433}434 435/*436** Free memory that might be associated with a particular database437** connection.  Calling sqlite3DbFree(D,X) for X==0 is a harmless no-op.438** The sqlite3DbFreeNN(D,X) version requires that X be non-NULL.439*/440void sqlite3DbFreeNN(sqlite3 *db, void *p){441  assert( db==0 || sqlite3_mutex_held(db->mutex) );442  assert( p!=0 );443  if( db ){444    if( ((uptr)p)<(uptr)(db->lookaside.pEnd) ){445#ifndef SQLITE_OMIT_TWOSIZE_LOOKASIDE446      if( ((uptr)p)>=(uptr)(db->lookaside.pMiddle) ){447        LookasideSlot *pBuf = (LookasideSlot*)p;448        assert( db->pnBytesFreed==0 );449#ifdef SQLITE_DEBUG450        memset(p, 0xaa, LOOKASIDE_SMALL);  /* Trash freed content */451#endif452        pBuf->pNext = db->lookaside.pSmallFree;453        db->lookaside.pSmallFree = pBuf;454        return;455      }456#endif /* SQLITE_OMIT_TWOSIZE_LOOKASIDE */457      if( ((uptr)p)>=(uptr)(db->lookaside.pStart) ){458        LookasideSlot *pBuf = (LookasideSlot*)p;459        assert( db->pnBytesFreed==0 );460#ifdef SQLITE_DEBUG461        memset(p, 0xaa, db->lookaside.szTrue);  /* Trash freed content */462#endif463        pBuf->pNext = db->lookaside.pFree;464        db->lookaside.pFree = pBuf;465        return;466      }467    }468    if( db->pnBytesFreed ){469      measureAllocationSize(db, p);470      return;471    }472  }473  assert( sqlite3MemdebugHasType(p, (MEMTYPE_LOOKASIDE|MEMTYPE_HEAP)) );474  assert( sqlite3MemdebugNoType(p, (u8)~(MEMTYPE_LOOKASIDE|MEMTYPE_HEAP)) );475  assert( db!=0 || sqlite3MemdebugNoType(p, MEMTYPE_LOOKASIDE) );476  sqlite3MemdebugSetType(p, MEMTYPE_HEAP);477  sqlite3_free(p);478}479void sqlite3DbNNFreeNN(sqlite3 *db, void *p){480  assert( db!=0 );481  assert( sqlite3_mutex_held(db->mutex) );482  assert( p!=0 );483  if( ((uptr)p)<(uptr)(db->lookaside.pEnd) ){484#ifndef SQLITE_OMIT_TWOSIZE_LOOKASIDE485    if( ((uptr)p)>=(uptr)(db->lookaside.pMiddle) ){486      LookasideSlot *pBuf = (LookasideSlot*)p;487      assert( db->pnBytesFreed==0 );488#ifdef SQLITE_DEBUG489      memset(p, 0xaa, LOOKASIDE_SMALL);  /* Trash freed content */490#endif491      pBuf->pNext = db->lookaside.pSmallFree;492      db->lookaside.pSmallFree = pBuf;493      return;494    }495#endif /* SQLITE_OMIT_TWOSIZE_LOOKASIDE */496    if( ((uptr)p)>=(uptr)(db->lookaside.pStart) ){497      LookasideSlot *pBuf = (LookasideSlot*)p;498      assert( db->pnBytesFreed==0 );499#ifdef SQLITE_DEBUG500      memset(p, 0xaa, db->lookaside.szTrue);  /* Trash freed content */501#endif502      pBuf->pNext = db->lookaside.pFree;503      db->lookaside.pFree = pBuf;504      return;505    }506  }507  if( db->pnBytesFreed ){508    measureAllocationSize(db, p);509    return;510  }511  assert( sqlite3MemdebugHasType(p, (MEMTYPE_LOOKASIDE|MEMTYPE_HEAP)) );512  assert( sqlite3MemdebugNoType(p, (u8)~(MEMTYPE_LOOKASIDE|MEMTYPE_HEAP)) );513  sqlite3MemdebugSetType(p, MEMTYPE_HEAP);514  sqlite3_free(p);515}516void sqlite3DbFree(sqlite3 *db, void *p){517  assert( db==0 || sqlite3_mutex_held(db->mutex) );518  if( p ) sqlite3DbFreeNN(db, p);519}520 521/*522** Change the size of an existing memory allocation523*/524void *sqlite3Realloc(void *pOld, u64 nBytes){525  int nOld, nNew, nDiff;526  void *pNew;527  assert( sqlite3MemdebugHasType(pOld, MEMTYPE_HEAP) );528  assert( sqlite3MemdebugNoType(pOld, (u8)~MEMTYPE_HEAP) );529  if( pOld==0 ){530    return sqlite3Malloc(nBytes); /* IMP: R-04300-56712 */531  }532  if( nBytes==0 ){533    sqlite3_free(pOld); /* IMP: R-26507-47431 */534    return 0;535  }536  if( nBytes>=0x7fffff00 ){537    /* The 0x7ffff00 limit term is explained in comments on sqlite3Malloc() */538    return 0;539  }540  nOld = sqlite3MallocSize(pOld);541  /* IMPLEMENTATION-OF: R-46199-30249 SQLite guarantees that the second542  ** argument to xRealloc is always a value returned by a prior call to543  ** xRoundup. */544  nNew = sqlite3GlobalConfig.m.xRoundup((int)nBytes);545  if( nOld==nNew ){546    pNew = pOld;547  }else if( sqlite3GlobalConfig.bMemstat ){548    sqlite3_int64 nUsed;549    sqlite3_mutex_enter(mem0.mutex);550    sqlite3StatusHighwater(SQLITE_STATUS_MALLOC_SIZE, (int)nBytes);551    nDiff = nNew - nOld;552    if( nDiff>0 && (nUsed = sqlite3StatusValue(SQLITE_STATUS_MEMORY_USED)) >= 553          mem0.alarmThreshold-nDiff ){554      sqlite3MallocAlarm(nDiff);555      if( mem0.hardLimit>0 && nUsed >= mem0.hardLimit - nDiff ){556        sqlite3_mutex_leave(mem0.mutex);557        test_oom_breakpoint(1);558        return 0;559      }560    }561    pNew = sqlite3GlobalConfig.m.xRealloc(pOld, nNew);562#ifdef SQLITE_ENABLE_MEMORY_MANAGEMENT563    if( pNew==0 && mem0.alarmThreshold>0 ){564      sqlite3MallocAlarm((int)nBytes);565      pNew = sqlite3GlobalConfig.m.xRealloc(pOld, nNew);566    }567#endif568    if( pNew ){569      nNew = sqlite3MallocSize(pNew);570      sqlite3StatusUp(SQLITE_STATUS_MEMORY_USED, nNew-nOld);571    }572    sqlite3_mutex_leave(mem0.mutex);573  }else{574    pNew = sqlite3GlobalConfig.m.xRealloc(pOld, nNew);575  }576  assert( EIGHT_BYTE_ALIGNMENT(pNew) ); /* IMP: R-11148-40995 */577  return pNew;578}579 580/*581** The public interface to sqlite3Realloc.  Make sure that the memory582** subsystem is initialized prior to invoking sqliteRealloc.583*/584void *sqlite3_realloc(void *pOld, int n){585#ifndef SQLITE_OMIT_AUTOINIT586  if( sqlite3_initialize() ) return 0;587#endif588  if( n<0 ) n = 0;  /* IMP: R-26507-47431 */589  return sqlite3Realloc(pOld, n);590}591void *sqlite3_realloc64(void *pOld, sqlite3_uint64 n){592#ifndef SQLITE_OMIT_AUTOINIT593  if( sqlite3_initialize() ) return 0;594#endif595  return sqlite3Realloc(pOld, n);596}597 598 599/*600** Allocate and zero memory.601*/ 602void *sqlite3MallocZero(u64 n){603  void *p = sqlite3Malloc(n);604  if( p ){605    memset(p, 0, (size_t)n);606  }607  return p;608}609 610/*611** Allocate and zero memory.  If the allocation fails, make612** the mallocFailed flag in the connection pointer.613*/614void *sqlite3DbMallocZero(sqlite3 *db, u64 n){615  void *p;616  testcase( db==0 );617  p = sqlite3DbMallocRaw(db, n);618  if( p ) memset(p, 0, (size_t)n);619  return p;620}621 622 623/* Finish the work of sqlite3DbMallocRawNN for the unusual and624** slower case when the allocation cannot be fulfilled using lookaside.625*/626static SQLITE_NOINLINE void *dbMallocRawFinish(sqlite3 *db, u64 n){627  void *p;628  assert( db!=0 );629  p = sqlite3Malloc(n);630  if( !p ) sqlite3OomFault(db);631  sqlite3MemdebugSetType(p, 632         (db->lookaside.bDisable==0) ? MEMTYPE_LOOKASIDE : MEMTYPE_HEAP);633  return p;634}635 636/*637** Allocate memory, either lookaside (if possible) or heap.  638** If the allocation fails, set the mallocFailed flag in639** the connection pointer.640**641** If db!=0 and db->mallocFailed is true (indicating a prior malloc642** failure on the same database connection) then always return 0.643** Hence for a particular database connection, once malloc starts644** failing, it fails consistently until mallocFailed is reset.645** This is an important assumption.  There are many places in the646** code that do things like this:647**648**         int *a = (int*)sqlite3DbMallocRaw(db, 100);649**         int *b = (int*)sqlite3DbMallocRaw(db, 200);650**         if( b ) a[10] = 9;651**652** In other words, if a subsequent malloc (ex: "b") worked, it is assumed653** that all prior mallocs (ex: "a") worked too.654**655** The sqlite3MallocRawNN() variant guarantees that the "db" parameter is656** not a NULL pointer.657*/658void *sqlite3DbMallocRaw(sqlite3 *db, u64 n){659  void *p;660  if( db ) return sqlite3DbMallocRawNN(db, n);661  p = sqlite3Malloc(n);662  sqlite3MemdebugSetType(p, MEMTYPE_HEAP);663  return p;664}665void *sqlite3DbMallocRawNN(sqlite3 *db, u64 n){666#ifndef SQLITE_OMIT_LOOKASIDE667  LookasideSlot *pBuf;668  assert( db!=0 );669  assert( sqlite3_mutex_held(db->mutex) );670  assert( db->pnBytesFreed==0 );671  if( n>db->lookaside.sz ){672    if( !db->lookaside.bDisable ){673      db->lookaside.anStat[1]++;      674    }else if( db->mallocFailed ){675      return 0;676    }677    return dbMallocRawFinish(db, n);678  }679#ifndef SQLITE_OMIT_TWOSIZE_LOOKASIDE680  if( n<=LOOKASIDE_SMALL ){681    if( (pBuf = db->lookaside.pSmallFree)!=0 ){682      db->lookaside.pSmallFree = pBuf->pNext;683      db->lookaside.anStat[0]++;684      return (void*)pBuf;685    }else if( (pBuf = db->lookaside.pSmallInit)!=0 ){686      db->lookaside.pSmallInit = pBuf->pNext;687      db->lookaside.anStat[0]++;688      return (void*)pBuf;689    }690  }691#endif692  if( (pBuf = db->lookaside.pFree)!=0 ){693    db->lookaside.pFree = pBuf->pNext;694    db->lookaside.anStat[0]++;695    return (void*)pBuf;696  }else if( (pBuf = db->lookaside.pInit)!=0 ){697    db->lookaside.pInit = pBuf->pNext;698    db->lookaside.anStat[0]++;699    return (void*)pBuf;700  }else{701    db->lookaside.anStat[2]++;702  }703#else704  assert( db!=0 );705  assert( sqlite3_mutex_held(db->mutex) );706  assert( db->pnBytesFreed==0 );707  if( db->mallocFailed ){708    return 0;709  }710#endif711  return dbMallocRawFinish(db, n);712}713 714/* Forward declaration */715static SQLITE_NOINLINE void *dbReallocFinish(sqlite3 *db, void *p, u64 n);716 717/*718** Resize the block of memory pointed to by p to n bytes. If the719** resize fails, set the mallocFailed flag in the connection object.720*/721void *sqlite3DbRealloc(sqlite3 *db, void *p, u64 n){722  assert( db!=0 );723  if( p==0 ) return sqlite3DbMallocRawNN(db, n);724  assert( sqlite3_mutex_held(db->mutex) );725  if( ((uptr)p)<(uptr)db->lookaside.pEnd ){726#ifndef SQLITE_OMIT_TWOSIZE_LOOKASIDE727    if( ((uptr)p)>=(uptr)db->lookaside.pMiddle ){728      if( n<=LOOKASIDE_SMALL ) return p;729    }else730#endif731    if( ((uptr)p)>=(uptr)db->lookaside.pStart ){732      if( n<=db->lookaside.szTrue ) return p;733    }734  }735  return dbReallocFinish(db, p, n);736}737static SQLITE_NOINLINE void *dbReallocFinish(sqlite3 *db, void *p, u64 n){738  void *pNew = 0;739  assert( db!=0 );740  assert( p!=0 );741  if( db->mallocFailed==0 ){742    if( isLookaside(db, p) ){743      pNew = sqlite3DbMallocRawNN(db, n);744      if( pNew ){745        memcpy(pNew, p, lookasideMallocSize(db, p));746        sqlite3DbFree(db, p);747      }748    }else{749      assert( sqlite3MemdebugHasType(p, (MEMTYPE_LOOKASIDE|MEMTYPE_HEAP)) );750      assert( sqlite3MemdebugNoType(p, (u8)~(MEMTYPE_LOOKASIDE|MEMTYPE_HEAP)) );751      sqlite3MemdebugSetType(p, MEMTYPE_HEAP);752      pNew = sqlite3Realloc(p, n);753      if( !pNew ){754        sqlite3OomFault(db);755      }756      sqlite3MemdebugSetType(pNew,757            (db->lookaside.bDisable==0 ? MEMTYPE_LOOKASIDE : MEMTYPE_HEAP));758    }759  }760  return pNew;761}762 763/*764** Attempt to reallocate p.  If the reallocation fails, then free p765** and set the mallocFailed flag in the database connection.766*/767void *sqlite3DbReallocOrFree(sqlite3 *db, void *p, u64 n){768  void *pNew;769  pNew = sqlite3DbRealloc(db, p, n);770  if( !pNew ){771    sqlite3DbFree(db, p);772  }773  return pNew;774}775 776/*777** Make a copy of a string in memory obtained from sqliteMalloc(). These 778** functions call sqlite3MallocRaw() directly instead of sqliteMalloc(). This779** is because when memory debugging is turned on, these two functions are 780** called via macros that record the current file and line number in the781** ThreadData structure.782*/783char *sqlite3DbStrDup(sqlite3 *db, const char *z){784  char *zNew;785  size_t n;786  if( z==0 ){787    return 0;788  }789  n = strlen(z) + 1;790  zNew = sqlite3DbMallocRaw(db, n);791  if( zNew ){792    memcpy(zNew, z, n);793  }794  return zNew;795}796char *sqlite3DbStrNDup(sqlite3 *db, const char *z, u64 n){797  char *zNew;798  assert( db!=0 );799  assert( z!=0 || n==0 );800  assert( (n&0x7fffffff)==n );801  zNew = z ? sqlite3DbMallocRawNN(db, n+1) : 0;802  if( zNew ){803    memcpy(zNew, z, (size_t)n);804    zNew[n] = 0;805  }806  return zNew;807}808 809/*810** The text between zStart and zEnd represents a phrase within a larger811** SQL statement.  Make a copy of this phrase in space obtained form812** sqlite3DbMalloc().  Omit leading and trailing whitespace.813*/814char *sqlite3DbSpanDup(sqlite3 *db, const char *zStart, const char *zEnd){815  int n;816#ifdef SQLITE_DEBUG817  /* Because of the way the parser works, the span is guaranteed to contain818  ** at least one non-space character */819  for(n=0; sqlite3Isspace(zStart[n]); n++){ assert( &zStart[n]<zEnd ); }820#endif821  while( sqlite3Isspace(zStart[0]) ) zStart++;822  n = (int)(zEnd - zStart);823  while( sqlite3Isspace(zStart[n-1]) ) n--;824  return sqlite3DbStrNDup(db, zStart, n);825}826 827/*828** Free any prior content in *pz and replace it with a copy of zNew.829*/830void sqlite3SetString(char **pz, sqlite3 *db, const char *zNew){831  char *z = sqlite3DbStrDup(db, zNew);832  sqlite3DbFree(db, *pz);833  *pz = z;834}835 836/*837** Call this routine to record the fact that an OOM (out-of-memory) error838** has happened.  This routine will set db->mallocFailed, and also839** temporarily disable the lookaside memory allocator and interrupt840** any running VDBEs.841**842** Always return a NULL pointer so that this routine can be invoked using843**844**      return sqlite3OomFault(db);845**846** and thereby avoid unnecessary stack frame allocations for the overwhelmingly847** common case where no OOM occurs.848*/849void *sqlite3OomFault(sqlite3 *db){850  if( db->mallocFailed==0 && db->bBenignMalloc==0 ){851    db->mallocFailed = 1;852    if( db->nVdbeExec>0 ){853      AtomicStore(&db->u1.isInterrupted, 1);854    }855    DisableLookaside;856    if( db->pParse ){857      Parse *pParse;858      sqlite3ErrorMsg(db->pParse, "out of memory");859      db->pParse->rc = SQLITE_NOMEM_BKPT;860      for(pParse=db->pParse->pOuterParse; pParse; pParse = pParse->pOuterParse){861        pParse->nErr++;862        pParse->rc = SQLITE_NOMEM;863      } 864    }865  }866  return 0;867}868 869/*870** This routine reactivates the memory allocator and clears the871** db->mallocFailed flag as necessary.872**873** The memory allocator is not restarted if there are running874** VDBEs.875*/876void sqlite3OomClear(sqlite3 *db){877  if( db->mallocFailed && db->nVdbeExec==0 ){878    db->mallocFailed = 0;879    AtomicStore(&db->u1.isInterrupted, 0);880    assert( db->lookaside.bDisable>0 );881    EnableLookaside;882  }883}884 885/*886** Take actions at the end of an API call to deal with error codes.887*/888static SQLITE_NOINLINE int apiHandleError(sqlite3 *db, int rc){889  if( db->mallocFailed || rc==SQLITE_IOERR_NOMEM ){890    sqlite3OomClear(db);891    sqlite3Error(db, SQLITE_NOMEM);892    return SQLITE_NOMEM_BKPT;893  }894  return rc & db->errMask;895}896 897/*898** This function must be called before exiting any API function (i.e. 899** returning control to the user) that has called sqlite3_malloc or900** sqlite3_realloc.901**902** The returned value is normally a copy of the second argument to this903** function. However, if a malloc() failure has occurred since the previous904** invocation SQLITE_NOMEM is returned instead. 905**906** If an OOM as occurred, then the connection error-code (the value907** returned by sqlite3_errcode()) is set to SQLITE_NOMEM.908*/909int sqlite3ApiExit(sqlite3* db, int rc){910  /* If the db handle must hold the connection handle mutex here.911  ** Otherwise the read (and possible write) of db->mallocFailed 912  ** is unsafe, as is the call to sqlite3Error().913  */914  assert( db!=0 );915  assert( sqlite3_mutex_held(db->mutex) );916  if( db->mallocFailed || rc ){917    return apiHandleError(db, rc);918  }919  return 0;920}921