33 releases

0.8.0 Sep 11, 2024
0.8.0-pre6 Jan 1, 2024
0.8.0-pre5 Dec 15, 2023
0.8.0-pre1 Nov 4, 2023
0.2.0 Nov 19, 2020

#448 in #no-alloc

Download history 307667/week @ 2024-07-29 307068/week @ 2024-08-05 306577/week @ 2024-08-12 354457/week @ 2024-08-19 339289/week @ 2024-08-26 318842/week @ 2024-09-02 320436/week @ 2024-09-09 284610/week @ 2024-09-16 319683/week @ 2024-09-23 323436/week @ 2024-09-30 325054/week @ 2024-10-07 364144/week @ 2024-10-14 355726/week @ 2024-10-21 353498/week @ 2024-10-28 341269/week @ 2024-11-04 369387/week @ 2024-11-11

1,440,607 downloads per month
Used in 512 crates (via bytecheck)

MIT license

34KB
715 lines

bytecheck

crates.io badge docs badge license badge

bytecheck is a memory validation framework for Rust.

Documentation

Example

use bytecheck::{CheckBytes, check_bytes, rancor::Failure};

#[derive(CheckBytes, Debug)]
#[repr(C)]
struct Test {
    a: u32,
    b: char,
    c: bool,
}

#[repr(C, align(4))]
struct Aligned<const N: usize>([u8; N]);

macro_rules! bytes {
    ($($byte:literal,)*) => {
        (&Aligned([$($byte,)*]).0 as &[u8]).as_ptr()
    };
    ($($byte:literal),*) => {
        bytes!($($byte,)*)
    };
}

// In this example, the architecture is assumed to be little-endian
#[cfg(target_endian = "little")]
unsafe {
    // These are valid bytes for a `Test`
    check_bytes::<Test, Failure>(
        bytes![
            0u8, 0u8, 0u8, 0u8,
            0x78u8, 0u8, 0u8, 0u8,
            1u8, 255u8, 255u8, 255u8,
        ].cast()
    ).unwrap();

    // Changing the bytes for the u32 is OK, any bytes are a valid u32
    check_bytes::<Test, Failure>(
        bytes![
            42u8, 16u8, 20u8, 3u8,
            0x78u8, 0u8, 0u8, 0u8,
            1u8, 255u8, 255u8, 255u8,
        ].cast()
    ).unwrap();

    // Characters outside the valid ranges are invalid
    check_bytes::<Test, Failure>(
        bytes![
            0u8, 0u8, 0u8, 0u8,
            0x00u8, 0xd8u8, 0u8, 0u8,
            1u8, 255u8, 255u8, 255u8,
        ].cast()
    ).unwrap_err();
    check_bytes::<Test, Failure>(
        bytes![
            0u8, 0u8, 0u8, 0u8,
            0x00u8, 0x00u8, 0x11u8, 0u8,
            1u8, 255u8, 255u8, 255u8,
        ].cast()
    ).unwrap_err();

    // 0 is a valid boolean value (false) but 2 is not
    check_bytes::<Test, Failure>(
        bytes![
            0u8, 0u8, 0u8, 0u8,
            0x78u8, 0u8, 0u8, 0u8,
            0u8, 255u8, 255u8, 255u8,
        ].cast()
    ).unwrap();
    check_bytes::<Test, Failure>(
        bytes![
            0u8, 0u8, 0u8, 0u8,
            0x78u8, 0u8, 0u8, 0u8,
            2u8, 255u8, 255u8, 255u8,
        ].cast()
    ).unwrap_err();
}

Dependencies

~230–670KB
~16K SLoC