0
  "   9ˆl–Ým_J*j"Tâ�jàš¸ )‹FÿËƒh¹ÀÎ      9auto
     ;ˆÉË„yïÊÀÎ *ì    ;/* SPDX-License-Identifier: GPL-2.0 */
#ifndef _LINUX_MINMAX_H
#define _LINUX_MINMAX_H

#include <linux/build_bug.h>
#include <linux/compiler.h>
#include <linux/const.h>
#include <linux/types.h>

/*
 * min()/max()/clamp() macros must accomplish three things:
 *
 * - Avoid multiple evaluations of the arguments (so side-effects like
 *   "x++" happen only once) when non-constant.
 * - Retain result as a constant expressions when called with only
 *   constant expressions (to avoid tripping VLA warnings in stack
 *   allocation usage).
 * - Perform signed v unsigned type-checking (to generate compile
 *   errors instead of nasty runtime surprises).
 * - Unsigned char/short are always promoted to signed int and can be
 *   compared against signed or unsigned arguments.
 * - Unsigned arguments can be compared against non-negative signed constants.
 * - Comparison of a signed argument against an unsigned constant fails
 *   even if the constant is below __INT_MAX__ and could be cast to int.
 */
#define __typecheck(x, y) \
	(!!(sizeof((typeof(x) *)1 == (typeof(y) *)1)))

/*
 * __sign_use for integer expressions:
 *   bit #0 set if ok for unsigned comparisons
 *   bit #1 set if ok for signed comparisons
 *
 * In particular, statically non-negative signed integer
 * expressions are ok for both.
 *
 * NOTE! Unsigned types smaller than 'int' are implicitly
 * converted to 'int' in expressions, and are accepted for
 * signed conversions for now. This is debatable.
 *
 * Note that 'x' is the original expression, and 'ux' is
 * the unique variable that contains the value.
 *
 * We use 'ux' for pure type checking, and 'x' for when
 * we need to look at the value (but without evaluating
 * it for side effects! Careful to only ever evaluate it
 * with sizeof() or __builtin_constant_p() etc).
 *
 * Pointers end up being checked by the normal C type
 * rules at the actual comparison, and these expressions
 * only need to be careful to not cause warnings for
 * pointer use.
 */
#define __signed_type_use(x,ux) (2+__is_nonneg(x,ux))
#define __unsigned_type_use(x,ux) (1+2*(sizeof(ux)<4))
#define __sign_use(x,ux) (is_signed_type(typeof(ux))? \
	__signed_type_use(x,ux):__unsigned_type_use(x,ux))

/*
 * To avoid warnings about casting pointers to integers
 * of different sizes, we need that special sign type.
 *
 * On 64-bit we can just always use 'long', since any
 * integer or pointer type can just be cast to that.
 *
 * This does not work for 128-bit signed integers since
 * the cast would truncate them, but we do not use s128
 * types in the kernel (we do use 'u128', but they will
 * be handled by the !is_signed_type() case).
 *
 * NOTE! The cast is there only to avoid any warnings
 * from when values that aren't signed integer types.
 */
#ifdef CONFIG_64BIT
  #define __signed_type(ux) long
#else
  #define __signed_type(ux) typeof(__builtin_choose_expr(sizeof(ux)>4,1LL,1L))
#endif
#define __is_nonneg(x,ux) statically_true((__signed_type(ux))(x)>=0)

#define __types_ok(x,y,ux,uy) \
	(__sign_use(x,ux) & __sign_use(y,uy))

#define __types_ok3(x,y,z,ux,uy,uz) \
	(__sign_use(x,ux) & __sign_use(y,uy) & __sign_use(z,uz))

#define __cmp_op_min <
#define __cmp_op_max >

#define __cmp(op, x, y)	((x) __cmp_op_##op (y) ? (x) : (y))

#define __cmp_once_unique(op, type, x, y, ux, uy) \
	({ type ux = (x); type uy = (y); __cmp(op, ux, uy); })

#define __cmp_once(op, type, x, y) \
	__cmp_once_unique(op, type, x, y, __UNIQUE_ID(x_), __UNIQUE_ID(y_))

#define __careful_cmp_once(op, x, y, ux, uy) ({		\
	__auto_type ux = (x); __auto_type uy = (y);	\
	BUILD_BUG_ON_MSG(!__types_ok(x,y,ux,uy),	\
		#op"("#x", "#y") signedness error");	\
	__cmp(op, ux, uy); })

#define __careful_cmp(op, x, y) \
	__careful_cmp_once(op, x, y, __UNIQUE_ID(x_), __UNIQUE_ID(y_))

#define __clamp(val, lo, hi)	\
	((val) >= (hi) ? (hi) : ((val) <= (lo) ? (lo) : (val)))

#define __clamp_once(val, lo, hi, uval, ulo, uhi) ({				\
	__auto_type uval = (val);						\
	__auto_type ulo = (lo);							\
	__auto_typ