1 
2 /* pngpread.c - read a png file in push mode
3  *
4  * Last changed in libpng 1.6.24 [August 4, 2016]
5  * Copyright (c) 1998-2002,2004,2006-2016 Glenn Randers-Pehrson
6  * (Version 0.96 Copyright (c) 1996, 1997 Andreas Dilger)
7  * (Version 0.88 Copyright (c) 1995, 1996 Guy Eric Schalnat, Group 42, Inc.)
8  *
9  * This code is released under the libpng license.
10  * For conditions of distribution and use, see the disclaimer
11  * and license in png.h
12  */
13 
14 #include "pngpriv.h"
15 
16 #ifdef PNG_PROGRESSIVE_READ_SUPPORTED
17 
18 /* Push model modes */
19 #define PNG_READ_SIG_MODE   0
20 #define PNG_READ_CHUNK_MODE 1
21 #define PNG_READ_IDAT_MODE  2
22 #define PNG_READ_tEXt_MODE  4
23 #define PNG_READ_zTXt_MODE  5
24 #define PNG_READ_DONE_MODE  6
25 #define PNG_READ_iTXt_MODE  7
26 #define PNG_ERROR_MODE      8
27 
28 #define PNG_PUSH_SAVE_BUFFER_IF_FULL \
29 if (png_ptr->push_length + 4 > png_ptr->buffer_size) \
30    { png_push_save_buffer(png_ptr); return; }
31 #define PNG_PUSH_SAVE_BUFFER_IF_LT(N) \
32 if (png_ptr->buffer_size < N) \
33    { png_push_save_buffer(png_ptr); return; }
34 
35 void PNGAPI
png_process_data(png_structrp png_ptr,png_inforp info_ptr,png_bytep buffer,png_size_t buffer_size)36 png_process_data(png_structrp png_ptr, png_inforp info_ptr,
37     png_bytep buffer, png_size_t buffer_size)
38 {
39    if (png_ptr == NULL || info_ptr == NULL)
40       return;
41 
42    png_push_restore_buffer(png_ptr, buffer, buffer_size);
43 
44    while (png_ptr->buffer_size)
45    {
46       png_process_some_data(png_ptr, info_ptr);
47    }
48 }
49 
50 png_size_t PNGAPI
png_process_data_pause(png_structrp png_ptr,int save)51 png_process_data_pause(png_structrp png_ptr, int save)
52 {
53    if (png_ptr != NULL)
54    {
55       /* It's easiest for the caller if we do the save; then the caller doesn't
56        * have to supply the same data again:
57        */
58       if (save != 0)
59          png_push_save_buffer(png_ptr);
60       else
61       {
62          /* This includes any pending saved bytes: */
63          png_size_t remaining = png_ptr->buffer_size;
64          png_ptr->buffer_size = 0;
65 
66          /* So subtract the saved buffer size, unless all the data
67           * is actually 'saved', in which case we just return 0
68           */
69          if (png_ptr->save_buffer_size < remaining)
70             return remaining - png_ptr->save_buffer_size;
71       }
72    }
73 
74    return 0;
75 }
76 
77 png_uint_32 PNGAPI
png_process_data_skip(png_structrp png_ptr)78 png_process_data_skip(png_structrp png_ptr)
79 {
80 /* TODO: Deprecate and remove this API.
81  * Somewhere the implementation of this seems to have been lost,
82  * or abandoned.  It was only to support some internal back-door access
83  * to png_struct) in libpng-1.4.x.
84  */
85    png_app_warning(png_ptr,
86 "png_process_data_skip is not implemented in any current version of libpng");
87    return 0;
88 }
89 
90 /* What we do with the incoming data depends on what we were previously
91  * doing before we ran out of data...
92  */
93 void /* PRIVATE */
png_process_some_data(png_structrp png_ptr,png_inforp info_ptr)94 png_process_some_data(png_structrp png_ptr, png_inforp info_ptr)
95 {
96    if (png_ptr == NULL)
97       return;
98 
99    switch (png_ptr->process_mode)
100    {
101       case PNG_READ_SIG_MODE:
102       {
103          png_push_read_sig(png_ptr, info_ptr);
104          break;
105       }
106 
107       case PNG_READ_CHUNK_MODE:
108       {
109          png_push_read_chunk(png_ptr, info_ptr);
110          break;
111       }
112 
113       case PNG_READ_IDAT_MODE:
114       {
115          png_push_read_IDAT(png_ptr);
116          break;
117       }
118 
119       default:
120       {
121          png_ptr->buffer_size = 0;
122          break;
123       }
124    }
125 }
126 
127 /* Read any remaining signature bytes from the stream and compare them with
128  * the correct PNG signature.  It is possible that this routine is called
129  * with bytes already read from the signature, either because they have been
130  * checked by the calling application, or because of multiple calls to this
131  * routine.
132  */
133 void /* PRIVATE */
png_push_read_sig(png_structrp png_ptr,png_inforp info_ptr)134 png_push_read_sig(png_structrp png_ptr, png_inforp info_ptr)
135 {
136    png_size_t num_checked = png_ptr->sig_bytes, /* SAFE, does not exceed 8 */
137        num_to_check = 8 - num_checked;
138 
139    if (png_ptr->buffer_size < num_to_check)
140    {
141       num_to_check = png_ptr->buffer_size;
142    }
143 
144    png_push_fill_buffer(png_ptr, &(info_ptr->signature[num_checked]),
145        num_to_check);
146    png_ptr->sig_bytes = (png_byte)(png_ptr->sig_bytes + num_to_check);
147 
148    if (png_sig_cmp(info_ptr->signature, num_checked, num_to_check))
149    {
150       if (num_checked < 4 &&
151           png_sig_cmp(info_ptr->signature, num_checked, num_to_check - 4))
152          png_error(png_ptr, "Not a PNG file");
153 
154       else
155          png_error(png_ptr, "PNG file corrupted by ASCII conversion");
156    }
157    else
158    {
159       if (png_ptr->sig_bytes >= 8)
160       {
161          png_ptr->process_mode = PNG_READ_CHUNK_MODE;
162       }
163    }
164 }
165 
166 void /* PRIVATE */
png_push_read_chunk(png_structrp png_ptr,png_inforp info_ptr)167 png_push_read_chunk(png_structrp png_ptr, png_inforp info_ptr)
168 {
169    png_uint_32 chunk_name;
170 #ifdef PNG_HANDLE_AS_UNKNOWN_SUPPORTED
171    int keep; /* unknown handling method */
172 #endif
173 
174    /* First we make sure we have enough data for the 4-byte chunk name
175     * and the 4-byte chunk length before proceeding with decoding the
176     * chunk data.  To fully decode each of these chunks, we also make
177     * sure we have enough data in the buffer for the 4-byte CRC at the
178     * end of every chunk (except IDAT, which is handled separately).
179     */
180    if ((png_ptr->mode & PNG_HAVE_CHUNK_HEADER) == 0)
181    {
182       png_byte chunk_length[4];
183       png_byte chunk_tag[4];
184 
185       PNG_PUSH_SAVE_BUFFER_IF_LT(8)
186       png_push_fill_buffer(png_ptr, chunk_length, 4);
187       png_ptr->push_length = png_get_uint_31(png_ptr, chunk_length);
188       png_reset_crc(png_ptr);
189       png_crc_read(png_ptr, chunk_tag, 4);
190       png_ptr->chunk_name = PNG_CHUNK_FROM_STRING(chunk_tag);
191       png_check_chunk_name(png_ptr, png_ptr->chunk_name);
192       png_ptr->mode |= PNG_HAVE_CHUNK_HEADER;
193    }
194 
195    chunk_name = png_ptr->chunk_name;
196 
197    if (chunk_name == png_IDAT)
198    {
199       if ((png_ptr->mode & PNG_AFTER_IDAT) != 0)
200          png_ptr->mode |= PNG_HAVE_CHUNK_AFTER_IDAT;
201 
202       /* If we reach an IDAT chunk, this means we have read all of the
203        * header chunks, and we can start reading the image (or if this
204        * is called after the image has been read - we have an error).
205        */
206       if ((png_ptr->mode & PNG_HAVE_IHDR) == 0)
207          png_error(png_ptr, "Missing IHDR before IDAT");
208 
209       else if (png_ptr->color_type == PNG_COLOR_TYPE_PALETTE &&
210           (png_ptr->mode & PNG_HAVE_PLTE) == 0)
211          png_error(png_ptr, "Missing PLTE before IDAT");
212 
213       png_ptr->process_mode = PNG_READ_IDAT_MODE;
214 
215       if ((png_ptr->mode & PNG_HAVE_IDAT) != 0)
216          if ((png_ptr->mode & PNG_HAVE_CHUNK_AFTER_IDAT) == 0)
217             if (png_ptr->push_length == 0)
218                return;
219 
220       png_ptr->mode |= PNG_HAVE_IDAT;
221 
222       if ((png_ptr->mode & PNG_AFTER_IDAT) != 0)
223          png_benign_error(png_ptr, "Too many IDATs found");
224    }
225 
226    if (chunk_name == png_IHDR)
227    {
228       if (png_ptr->push_length != 13)
229          png_error(png_ptr, "Invalid IHDR length");
230 
231       PNG_PUSH_SAVE_BUFFER_IF_FULL
232       png_handle_IHDR(png_ptr, info_ptr, png_ptr->push_length);
233    }
234 
235    else if (chunk_name == png_IEND)
236    {
237       PNG_PUSH_SAVE_BUFFER_IF_FULL
238       png_handle_IEND(png_ptr, info_ptr, png_ptr->push_length);
239 
240       png_ptr->process_mode = PNG_READ_DONE_MODE;
241       png_push_have_end(png_ptr, info_ptr);
242    }
243 
244 #ifdef PNG_HANDLE_AS_UNKNOWN_SUPPORTED
245    else if ((keep = png_chunk_unknown_handling(png_ptr, chunk_name)) != 0)
246    {
247       PNG_PUSH_SAVE_BUFFER_IF_FULL
248       png_handle_unknown(png_ptr, info_ptr, png_ptr->push_length, keep);
249 
250       if (chunk_name == png_PLTE)
251          png_ptr->mode |= PNG_HAVE_PLTE;
252    }
253 #endif
254 
255    else if (chunk_name == png_PLTE)
256    {
257       PNG_PUSH_SAVE_BUFFER_IF_FULL
258       png_handle_PLTE(png_ptr, info_ptr, png_ptr->push_length);
259    }
260 
261    else if (chunk_name == png_IDAT)
262    {
263       png_ptr->idat_size = png_ptr->push_length;
264       png_ptr->process_mode = PNG_READ_IDAT_MODE;
265       png_push_have_info(png_ptr, info_ptr);
266       png_ptr->zstream.avail_out =
267           (uInt) PNG_ROWBYTES(png_ptr->pixel_depth,
268           png_ptr->iwidth) + 1;
269       png_ptr->zstream.next_out = png_ptr->row_buf;
270       return;
271    }
272 
273 #ifdef PNG_READ_gAMA_SUPPORTED
274    else if (png_ptr->chunk_name == png_gAMA)
275    {
276       PNG_PUSH_SAVE_BUFFER_IF_FULL
277       png_handle_gAMA(png_ptr, info_ptr, png_ptr->push_length);
278    }
279 
280 #endif
281 #ifdef PNG_READ_sBIT_SUPPORTED
282    else if (png_ptr->chunk_name == png_sBIT)
283    {
284       PNG_PUSH_SAVE_BUFFER_IF_FULL
285       png_handle_sBIT(png_ptr, info_ptr, png_ptr->push_length);
286    }
287 
288 #endif
289 #ifdef PNG_READ_cHRM_SUPPORTED
290    else if (png_ptr->chunk_name == png_cHRM)
291    {
292       PNG_PUSH_SAVE_BUFFER_IF_FULL
293       png_handle_cHRM(png_ptr, info_ptr, png_ptr->push_length);
294    }
295 
296 #endif
297 #ifdef PNG_READ_sRGB_SUPPORTED
298    else if (chunk_name == png_sRGB)
299    {
300       PNG_PUSH_SAVE_BUFFER_IF_FULL
301       png_handle_sRGB(png_ptr, info_ptr, png_ptr->push_length);
302    }
303 
304 #endif
305 #ifdef PNG_READ_iCCP_SUPPORTED
306    else if (png_ptr->chunk_name == png_iCCP)
307    {
308       PNG_PUSH_SAVE_BUFFER_IF_FULL
309       png_handle_iCCP(png_ptr, info_ptr, png_ptr->push_length);
310    }
311 
312 #endif
313 #ifdef PNG_READ_sPLT_SUPPORTED
314    else if (chunk_name == png_sPLT)
315    {
316       PNG_PUSH_SAVE_BUFFER_IF_FULL
317       png_handle_sPLT(png_ptr, info_ptr, png_ptr->push_length);
318    }
319 
320 #endif
321 #ifdef PNG_READ_tRNS_SUPPORTED
322    else if (chunk_name == png_tRNS)
323    {
324       PNG_PUSH_SAVE_BUFFER_IF_FULL
325       png_handle_tRNS(png_ptr, info_ptr, png_ptr->push_length);
326    }
327 
328 #endif
329 #ifdef PNG_READ_bKGD_SUPPORTED
330    else if (chunk_name == png_bKGD)
331    {
332       PNG_PUSH_SAVE_BUFFER_IF_FULL
333       png_handle_bKGD(png_ptr, info_ptr, png_ptr->push_length);
334    }
335 
336 #endif
337 #ifdef PNG_READ_hIST_SUPPORTED
338    else if (chunk_name == png_hIST)
339    {
340       PNG_PUSH_SAVE_BUFFER_IF_FULL
341       png_handle_hIST(png_ptr, info_ptr, png_ptr->push_length);
342    }
343 
344 #endif
345 #ifdef PNG_READ_pHYs_SUPPORTED
346    else if (chunk_name == png_pHYs)
347    {
348       PNG_PUSH_SAVE_BUFFER_IF_FULL
349       png_handle_pHYs(png_ptr, info_ptr, png_ptr->push_length);
350    }
351 
352 #endif
353 #ifdef PNG_READ_oFFs_SUPPORTED
354    else if (chunk_name == png_oFFs)
355    {
356       PNG_PUSH_SAVE_BUFFER_IF_FULL
357       png_handle_oFFs(png_ptr, info_ptr, png_ptr->push_length);
358    }
359 #endif
360 
361 #ifdef PNG_READ_pCAL_SUPPORTED
362    else if (chunk_name == png_pCAL)
363    {
364       PNG_PUSH_SAVE_BUFFER_IF_FULL
365       png_handle_pCAL(png_ptr, info_ptr, png_ptr->push_length);
366    }
367 
368 #endif
369 #ifdef PNG_READ_sCAL_SUPPORTED
370    else if (chunk_name == png_sCAL)
371    {
372       PNG_PUSH_SAVE_BUFFER_IF_FULL
373       png_handle_sCAL(png_ptr, info_ptr, png_ptr->push_length);
374    }
375 
376 #endif
377 #ifdef PNG_READ_tIME_SUPPORTED
378    else if (chunk_name == png_tIME)
379    {
380       PNG_PUSH_SAVE_BUFFER_IF_FULL
381       png_handle_tIME(png_ptr, info_ptr, png_ptr->push_length);
382    }
383 
384 #endif
385 #ifdef PNG_READ_tEXt_SUPPORTED
386    else if (chunk_name == png_tEXt)
387    {
388       PNG_PUSH_SAVE_BUFFER_IF_FULL
389       png_handle_tEXt(png_ptr, info_ptr, png_ptr->push_length);
390    }
391 
392 #endif
393 #ifdef PNG_READ_zTXt_SUPPORTED
394    else if (chunk_name == png_zTXt)
395    {
396       PNG_PUSH_SAVE_BUFFER_IF_FULL
397       png_handle_zTXt(png_ptr, info_ptr, png_ptr->push_length);
398    }
399 
400 #endif
401 #ifdef PNG_READ_iTXt_SUPPORTED
402    else if (chunk_name == png_iTXt)
403    {
404       PNG_PUSH_SAVE_BUFFER_IF_FULL
405       png_handle_iTXt(png_ptr, info_ptr, png_ptr->push_length);
406    }
407 #endif
408 
409    else
410    {
411       PNG_PUSH_SAVE_BUFFER_IF_FULL
412       png_handle_unknown(png_ptr, info_ptr, png_ptr->push_length,
413           PNG_HANDLE_CHUNK_AS_DEFAULT);
414    }
415 
416    png_ptr->mode &= ~PNG_HAVE_CHUNK_HEADER;
417 }
418 
419 void PNGCBAPI
png_push_fill_buffer(png_structp png_ptr,png_bytep buffer,png_size_t length)420 png_push_fill_buffer(png_structp png_ptr, png_bytep buffer, png_size_t length)
421 {
422    png_bytep ptr;
423 
424    if (png_ptr == NULL)
425       return;
426 
427    ptr = buffer;
428    if (png_ptr->save_buffer_size != 0)
429    {
430       png_size_t save_size;
431 
432       if (length < png_ptr->save_buffer_size)
433          save_size = length;
434 
435       else
436          save_size = png_ptr->save_buffer_size;
437 
438       memcpy(ptr, png_ptr->save_buffer_ptr, save_size);
439       length -= save_size;
440       ptr += save_size;
441       png_ptr->buffer_size -= save_size;
442       png_ptr->save_buffer_size -= save_size;
443       png_ptr->save_buffer_ptr += save_size;
444    }
445    if (length != 0 && png_ptr->current_buffer_size != 0)
446    {
447       png_size_t save_size;
448 
449       if (length < png_ptr->current_buffer_size)
450          save_size = length;
451 
452       else
453          save_size = png_ptr->current_buffer_size;
454 
455       memcpy(ptr, png_ptr->current_buffer_ptr, save_size);
456       png_ptr->buffer_size -= save_size;
457       png_ptr->current_buffer_size -= save_size;
458       png_ptr->current_buffer_ptr += save_size;
459    }
460 }
461 
462 void /* PRIVATE */
png_push_save_buffer(png_structrp png_ptr)463 png_push_save_buffer(png_structrp png_ptr)
464 {
465    if (png_ptr->save_buffer_size != 0)
466    {
467       if (png_ptr->save_buffer_ptr != png_ptr->save_buffer)
468       {
469          png_size_t i, istop;
470          png_bytep sp;
471          png_bytep dp;
472 
473          istop = png_ptr->save_buffer_size;
474          for (i = 0, sp = png_ptr->save_buffer_ptr, dp = png_ptr->save_buffer;
475              i < istop; i++, sp++, dp++)
476          {
477             *dp = *sp;
478          }
479       }
480    }
481    if (png_ptr->save_buffer_size + png_ptr->current_buffer_size >
482        png_ptr->save_buffer_max)
483    {
484       png_size_t new_max;
485       png_bytep old_buffer;
486 
487       if (png_ptr->save_buffer_size > PNG_SIZE_MAX -
488           (png_ptr->current_buffer_size + 256))
489       {
490          png_error(png_ptr, "Potential overflow of save_buffer");
491       }
492 
493       new_max = png_ptr->save_buffer_size + png_ptr->current_buffer_size + 256;
494       old_buffer = png_ptr->save_buffer;
495       png_ptr->save_buffer = (png_bytep)png_malloc_warn(png_ptr,
496           (png_size_t)new_max);
497 
498       if (png_ptr->save_buffer == NULL)
499       {
500          png_free(png_ptr, old_buffer);
501          png_error(png_ptr, "Insufficient memory for save_buffer");
502       }
503 
504       if (old_buffer)
505          memcpy(png_ptr->save_buffer, old_buffer, png_ptr->save_buffer_size);
506       else if (png_ptr->save_buffer_size)
507          png_error(png_ptr, "save_buffer error");
508       png_free(png_ptr, old_buffer);
509       png_ptr->save_buffer_max = new_max;
510    }
511    if (png_ptr->current_buffer_size)
512    {
513       memcpy(png_ptr->save_buffer + png_ptr->save_buffer_size,
514          png_ptr->current_buffer_ptr, png_ptr->current_buffer_size);
515       png_ptr->save_buffer_size += png_ptr->current_buffer_size;
516       png_ptr->current_buffer_size = 0;
517    }
518    png_ptr->save_buffer_ptr = png_ptr->save_buffer;
519    png_ptr->buffer_size = 0;
520 }
521 
522 void /* PRIVATE */
png_push_restore_buffer(png_structrp png_ptr,png_bytep buffer,png_size_t buffer_length)523 png_push_restore_buffer(png_structrp png_ptr, png_bytep buffer,
524     png_size_t buffer_length)
525 {
526    png_ptr->current_buffer = buffer;
527    png_ptr->current_buffer_size = buffer_length;
528    png_ptr->buffer_size = buffer_length + png_ptr->save_buffer_size;
529    png_ptr->current_buffer_ptr = png_ptr->current_buffer;
530 }
531 
532 void /* PRIVATE */
png_push_read_IDAT(png_structrp png_ptr)533 png_push_read_IDAT(png_structrp png_ptr)
534 {
535    if ((png_ptr->mode & PNG_HAVE_CHUNK_HEADER) == 0)
536    {
537       png_byte chunk_length[4];
538       png_byte chunk_tag[4];
539 
540       /* TODO: this code can be commoned up with the same code in push_read */
541       PNG_PUSH_SAVE_BUFFER_IF_LT(8)
542       png_push_fill_buffer(png_ptr, chunk_length, 4);
543       png_ptr->push_length = png_get_uint_31(png_ptr, chunk_length);
544       png_reset_crc(png_ptr);
545       png_crc_read(png_ptr, chunk_tag, 4);
546       png_ptr->chunk_name = PNG_CHUNK_FROM_STRING(chunk_tag);
547       png_ptr->mode |= PNG_HAVE_CHUNK_HEADER;
548 
549       if (png_ptr->chunk_name != png_IDAT)
550       {
551          png_ptr->process_mode = PNG_READ_CHUNK_MODE;
552 
553          if ((png_ptr->flags & PNG_FLAG_ZSTREAM_ENDED) == 0)
554             png_error(png_ptr, "Not enough compressed data");
555 
556          return;
557       }
558 
559       png_ptr->idat_size = png_ptr->push_length;
560    }
561 
562    if (png_ptr->idat_size != 0 && png_ptr->save_buffer_size != 0)
563    {
564       png_size_t save_size = png_ptr->save_buffer_size;
565       png_uint_32 idat_size = png_ptr->idat_size;
566 
567       /* We want the smaller of 'idat_size' and 'current_buffer_size', but they
568        * are of different types and we don't know which variable has the fewest
569        * bits.  Carefully select the smaller and cast it to the type of the
570        * larger - this cannot overflow.  Do not cast in the following test - it
571        * will break on either 16-bit or 64-bit platforms.
572        */
573       if (idat_size < save_size)
574          save_size = (png_size_t)idat_size;
575 
576       else
577          idat_size = (png_uint_32)save_size;
578 
579       png_calculate_crc(png_ptr, png_ptr->save_buffer_ptr, save_size);
580 
581       png_process_IDAT_data(png_ptr, png_ptr->save_buffer_ptr, save_size);
582 
583       png_ptr->idat_size -= idat_size;
584       png_ptr->buffer_size -= save_size;
585       png_ptr->save_buffer_size -= save_size;
586       png_ptr->save_buffer_ptr += save_size;
587    }
588 
589    if (png_ptr->idat_size != 0 && png_ptr->current_buffer_size != 0)
590    {
591       png_size_t save_size = png_ptr->current_buffer_size;
592       png_uint_32 idat_size = png_ptr->idat_size;
593 
594       /* We want the smaller of 'idat_size' and 'current_buffer_size', but they
595        * are of different types and we don't know which variable has the fewest
596        * bits.  Carefully select the smaller and cast it to the type of the
597        * larger - this cannot overflow.
598        */
599       if (idat_size < save_size)
600          save_size = (png_size_t)idat_size;
601 
602       else
603          idat_size = (png_uint_32)save_size;
604 
605       png_calculate_crc(png_ptr, png_ptr->current_buffer_ptr, save_size);
606 
607       png_process_IDAT_data(png_ptr, png_ptr->current_buffer_ptr, save_size);
608 
609       png_ptr->idat_size -= idat_size;
610       png_ptr->buffer_size -= save_size;
611       png_ptr->current_buffer_size -= save_size;
612       png_ptr->current_buffer_ptr += save_size;
613    }
614 
615    if (png_ptr->idat_size == 0)
616    {
617       PNG_PUSH_SAVE_BUFFER_IF_LT(4)
618       png_crc_finish(png_ptr, 0);
619       png_ptr->mode &= ~PNG_HAVE_CHUNK_HEADER;
620       png_ptr->mode |= PNG_AFTER_IDAT;
621       png_ptr->zowner = 0;
622    }
623 }
624 
625 void /* PRIVATE */
png_process_IDAT_data(png_structrp png_ptr,png_bytep buffer,png_size_t buffer_length)626 png_process_IDAT_data(png_structrp png_ptr, png_bytep buffer,
627     png_size_t buffer_length)
628 {
629    /* The caller checks for a non-zero buffer length. */
630    if (!(buffer_length > 0) || buffer == NULL)
631       png_error(png_ptr, "No IDAT data (internal error)");
632 
633    /* This routine must process all the data it has been given
634     * before returning, calling the row callback as required to
635     * handle the uncompressed results.
636     */
637    png_ptr->zstream.next_in = buffer;
638    /* TODO: WARNING: TRUNCATION ERROR: DANGER WILL ROBINSON: */
639    png_ptr->zstream.avail_in = (uInt)buffer_length;
640 
641    /* Keep going until the decompressed data is all processed
642     * or the stream marked as finished.
643     */
644    while (png_ptr->zstream.avail_in > 0 &&
645       (png_ptr->flags & PNG_FLAG_ZSTREAM_ENDED) == 0)
646    {
647       int ret;
648 
649       /* We have data for zlib, but we must check that zlib
650        * has someplace to put the results.  It doesn't matter
651        * if we don't expect any results -- it may be the input
652        * data is just the LZ end code.
653        */
654       if (!(png_ptr->zstream.avail_out > 0))
655       {
656          /* TODO: WARNING: TRUNCATION ERROR: DANGER WILL ROBINSON: */
657          png_ptr->zstream.avail_out = (uInt)(PNG_ROWBYTES(png_ptr->pixel_depth,
658              png_ptr->iwidth) + 1);
659 
660          png_ptr->zstream.next_out = png_ptr->row_buf;
661       }
662 
663       /* Using Z_SYNC_FLUSH here means that an unterminated
664        * LZ stream (a stream with a missing end code) can still
665        * be handled, otherwise (Z_NO_FLUSH) a future zlib
666        * implementation might defer output and therefore
667        * change the current behavior (see comments in inflate.c
668        * for why this doesn't happen at present with zlib 1.2.5).
669        */
670       ret = PNG_INFLATE(png_ptr, Z_SYNC_FLUSH);
671 
672       /* Check for any failure before proceeding. */
673       if (ret != Z_OK && ret != Z_STREAM_END)
674       {
675          /* Terminate the decompression. */
676          png_ptr->flags |= PNG_FLAG_ZSTREAM_ENDED;
677          png_ptr->zowner = 0;
678 
679          /* This may be a truncated stream (missing or
680           * damaged end code).  Treat that as a warning.
681           */
682          if (png_ptr->row_number >= png_ptr->num_rows ||
683              png_ptr->pass > 6)
684             png_warning(png_ptr, "Truncated compressed data in IDAT");
685 
686          else
687          {
688             if (ret == Z_DATA_ERROR)
689                png_benign_error(png_ptr, "IDAT: ADLER32 checksum mismatch");
690             else
691                png_error(png_ptr, "Decompression error in IDAT");
692          }
693 
694          /* Skip the check on unprocessed input */
695          return;
696       }
697 
698       /* Did inflate output any data? */
699       if (png_ptr->zstream.next_out != png_ptr->row_buf)
700       {
701          /* Is this unexpected data after the last row?
702           * If it is, artificially terminate the LZ output
703           * here.
704           */
705          if (png_ptr->row_number >= png_ptr->num_rows ||
706              png_ptr->pass > 6)
707          {
708             /* Extra data. */
709             png_warning(png_ptr, "Extra compressed data in IDAT");
710             png_ptr->flags |= PNG_FLAG_ZSTREAM_ENDED;
711             png_ptr->zowner = 0;
712 
713             /* Do no more processing; skip the unprocessed
714              * input check below.
715              */
716             return;
717          }
718 
719          /* Do we have a complete row? */
720          if (png_ptr->zstream.avail_out == 0)
721             png_push_process_row(png_ptr);
722       }
723 
724       /* And check for the end of the stream. */
725       if (ret == Z_STREAM_END)
726          png_ptr->flags |= PNG_FLAG_ZSTREAM_ENDED;
727    }
728 
729    /* All the data should have been processed, if anything
730     * is left at this point we have bytes of IDAT data
731     * after the zlib end code.
732     */
733    if (png_ptr->zstream.avail_in > 0)
734       png_warning(png_ptr, "Extra compression data in IDAT");
735 }
736 
737 void /* PRIVATE */
png_push_process_row(png_structrp png_ptr)738 png_push_process_row(png_structrp png_ptr)
739 {
740    /* 1.5.6: row_info moved out of png_struct to a local here. */
741    png_row_info row_info;
742 
743    row_info.width = png_ptr->iwidth; /* NOTE: width of current interlaced row */
744    row_info.color_type = png_ptr->color_type;
745    row_info.bit_depth = png_ptr->bit_depth;
746    row_info.channels = png_ptr->channels;
747    row_info.pixel_depth = png_ptr->pixel_depth;
748    row_info.rowbytes = PNG_ROWBYTES(row_info.pixel_depth, row_info.width);
749 
750    if (png_ptr->row_buf[0] > PNG_FILTER_VALUE_NONE)
751    {
752       if (png_ptr->row_buf[0] < PNG_FILTER_VALUE_LAST)
753          png_read_filter_row(png_ptr, &row_info, png_ptr->row_buf + 1,
754             png_ptr->prev_row + 1, png_ptr->row_buf[0]);
755       else
756          png_error(png_ptr, "bad adaptive filter value");
757    }
758 
759    /* libpng 1.5.6: the following line was copying png_ptr->rowbytes before
760     * 1.5.6, while the buffer really is this big in current versions of libpng
761     * it may not be in the future, so this was changed just to copy the
762     * interlaced row count:
763     */
764    memcpy(png_ptr->prev_row, png_ptr->row_buf, row_info.rowbytes + 1);
765 
766 #ifdef PNG_READ_TRANSFORMS_SUPPORTED
767    if (png_ptr->transformations != 0)
768       png_do_read_transformations(png_ptr, &row_info);
769 #endif
770 
771    /* The transformed pixel depth should match the depth now in row_info. */
772    if (png_ptr->transformed_pixel_depth == 0)
773    {
774       png_ptr->transformed_pixel_depth = row_info.pixel_depth;
775       if (row_info.pixel_depth > png_ptr->maximum_pixel_depth)
776          png_error(png_ptr, "progressive row overflow");
777    }
778 
779    else if (png_ptr->transformed_pixel_depth != row_info.pixel_depth)
780       png_error(png_ptr, "internal progressive row size calculation error");
781 
782 
783 #ifdef PNG_READ_INTERLACING_SUPPORTED
784    /* Expand interlaced rows to full size */
785    if (png_ptr->interlaced != 0 &&
786        (png_ptr->transformations & PNG_INTERLACE) != 0)
787    {
788       if (png_ptr->pass < 6)
789          png_do_read_interlace(&row_info, png_ptr->row_buf + 1, png_ptr->pass,
790              png_ptr->transformations);
791 
792       switch (png_ptr->pass)
793       {
794          case 0:
795          {
796             int i;
797             for (i = 0; i < 8 && png_ptr->pass == 0; i++)
798             {
799                png_push_have_row(png_ptr, png_ptr->row_buf + 1);
800                png_read_push_finish_row(png_ptr); /* Updates png_ptr->pass */
801             }
802 
803             if (png_ptr->pass == 2) /* Pass 1 might be empty */
804             {
805                for (i = 0; i < 4 && png_ptr->pass == 2; i++)
806                {
807                   png_push_have_row(png_ptr, NULL);
808                   png_read_push_finish_row(png_ptr);
809                }
810             }
811 
812             if (png_ptr->pass == 4 && png_ptr->height <= 4)
813             {
814                for (i = 0; i < 2 && png_ptr->pass == 4; i++)
815                {
816                   png_push_have_row(png_ptr, NULL);
817                   png_read_push_finish_row(png_ptr);
818                }
819             }
820 
821             if (png_ptr->pass == 6 && png_ptr->height <= 4)
822             {
823                 png_push_have_row(png_ptr, NULL);
824                 png_read_push_finish_row(png_ptr);
825             }
826 
827             break;
828          }
829 
830          case 1:
831          {
832             int i;
833             for (i = 0; i < 8 && png_ptr->pass == 1; i++)
834             {
835                png_push_have_row(png_ptr, png_ptr->row_buf + 1);
836                png_read_push_finish_row(png_ptr);
837             }
838 
839             if (png_ptr->pass == 2) /* Skip top 4 generated rows */
840             {
841                for (i = 0; i < 4 && png_ptr->pass == 2; i++)
842                {
843                   png_push_have_row(png_ptr, NULL);
844                   png_read_push_finish_row(png_ptr);
845                }
846             }
847 
848             break;
849          }
850 
851          case 2:
852          {
853             int i;
854 
855             for (i = 0; i < 4 && png_ptr->pass == 2; i++)
856             {
857                png_push_have_row(png_ptr, png_ptr->row_buf + 1);
858                png_read_push_finish_row(png_ptr);
859             }
860 
861             for (i = 0; i < 4 && png_ptr->pass == 2; i++)
862             {
863                png_push_have_row(png_ptr, NULL);
864                png_read_push_finish_row(png_ptr);
865             }
866 
867             if (png_ptr->pass == 4) /* Pass 3 might be empty */
868             {
869                for (i = 0; i < 2 && png_ptr->pass == 4; i++)
870                {
871                   png_push_have_row(png_ptr, NULL);
872                   png_read_push_finish_row(png_ptr);
873                }
874             }
875 
876             break;
877          }
878 
879          case 3:
880          {
881             int i;
882 
883             for (i = 0; i < 4 && png_ptr->pass == 3; i++)
884             {
885                png_push_have_row(png_ptr, png_ptr->row_buf + 1);
886                png_read_push_finish_row(png_ptr);
887             }
888 
889             if (png_ptr->pass == 4) /* Skip top two generated rows */
890             {
891                for (i = 0; i < 2 && png_ptr->pass == 4; i++)
892                {
893                   png_push_have_row(png_ptr, NULL);
894                   png_read_push_finish_row(png_ptr);
895                }
896             }
897 
898             break;
899          }
900 
901          case 4:
902          {
903             int i;
904 
905             for (i = 0; i < 2 && png_ptr->pass == 4; i++)
906             {
907                png_push_have_row(png_ptr, png_ptr->row_buf + 1);
908                png_read_push_finish_row(png_ptr);
909             }
910 
911             for (i = 0; i < 2 && png_ptr->pass == 4; i++)
912             {
913                png_push_have_row(png_ptr, NULL);
914                png_read_push_finish_row(png_ptr);
915             }
916 
917             if (png_ptr->pass == 6) /* Pass 5 might be empty */
918             {
919                png_push_have_row(png_ptr, NULL);
920                png_read_push_finish_row(png_ptr);
921             }
922 
923             break;
924          }
925 
926          case 5:
927          {
928             int i;
929 
930             for (i = 0; i < 2 && png_ptr->pass == 5; i++)
931             {
932                png_push_have_row(png_ptr, png_ptr->row_buf + 1);
933                png_read_push_finish_row(png_ptr);
934             }
935 
936             if (png_ptr->pass == 6) /* Skip top generated row */
937             {
938                png_push_have_row(png_ptr, NULL);
939                png_read_push_finish_row(png_ptr);
940             }
941 
942             break;
943          }
944 
945          default:
946          case 6:
947          {
948             png_push_have_row(png_ptr, png_ptr->row_buf + 1);
949             png_read_push_finish_row(png_ptr);
950 
951             if (png_ptr->pass != 6)
952                break;
953 
954             png_push_have_row(png_ptr, NULL);
955             png_read_push_finish_row(png_ptr);
956          }
957       }
958    }
959    else
960 #endif
961    {
962       png_push_have_row(png_ptr, png_ptr->row_buf + 1);
963       png_read_push_finish_row(png_ptr);
964    }
965 }
966 
967 void /* PRIVATE */
png_read_push_finish_row(png_structrp png_ptr)968 png_read_push_finish_row(png_structrp png_ptr)
969 {
970 #ifdef PNG_READ_INTERLACING_SUPPORTED
971    /* Arrays to facilitate easy interlacing - use pass (0 - 6) as index */
972 
973    /* Start of interlace block */
974    static PNG_CONST png_byte png_pass_start[] = {0, 4, 0, 2, 0, 1, 0};
975 
976    /* Offset to next interlace block */
977    static PNG_CONST png_byte png_pass_inc[] = {8, 8, 4, 4, 2, 2, 1};
978 
979    /* Start of interlace block in the y direction */
980    static PNG_CONST png_byte png_pass_ystart[] = {0, 0, 4, 0, 2, 0, 1};
981 
982    /* Offset to next interlace block in the y direction */
983    static PNG_CONST png_byte png_pass_yinc[] = {8, 8, 8, 4, 4, 2, 2};
984 
985    /* Height of interlace block.  This is not currently used - if you need
986     * it, uncomment it here and in png.h
987    static PNG_CONST png_byte png_pass_height[] = {8, 8, 4, 4, 2, 2, 1};
988    */
989 #endif
990 
991    png_ptr->row_number++;
992    if (png_ptr->row_number < png_ptr->num_rows)
993       return;
994 
995 #ifdef PNG_READ_INTERLACING_SUPPORTED
996    if (png_ptr->interlaced != 0)
997    {
998       png_ptr->row_number = 0;
999       memset(png_ptr->prev_row, 0, png_ptr->rowbytes + 1);
1000 
1001       do
1002       {
1003          png_ptr->pass++;
1004          if ((png_ptr->pass == 1 && png_ptr->width < 5) ||
1005              (png_ptr->pass == 3 && png_ptr->width < 3) ||
1006              (png_ptr->pass == 5 && png_ptr->width < 2))
1007             png_ptr->pass++;
1008 
1009          if (png_ptr->pass > 7)
1010             png_ptr->pass--;
1011 
1012          if (png_ptr->pass >= 7)
1013             break;
1014 
1015          png_ptr->iwidth = (png_ptr->width +
1016              png_pass_inc[png_ptr->pass] - 1 -
1017              png_pass_start[png_ptr->pass]) /
1018              png_pass_inc[png_ptr->pass];
1019 
1020          if ((png_ptr->transformations & PNG_INTERLACE) != 0)
1021             break;
1022 
1023          png_ptr->num_rows = (png_ptr->height +
1024              png_pass_yinc[png_ptr->pass] - 1 -
1025              png_pass_ystart[png_ptr->pass]) /
1026              png_pass_yinc[png_ptr->pass];
1027 
1028       } while (png_ptr->iwidth == 0 || png_ptr->num_rows == 0);
1029    }
1030 #endif /* READ_INTERLACING */
1031 }
1032 
1033 void /* PRIVATE */
png_push_have_info(png_structrp png_ptr,png_inforp info_ptr)1034 png_push_have_info(png_structrp png_ptr, png_inforp info_ptr)
1035 {
1036    if (png_ptr->info_fn != NULL)
1037       (*(png_ptr->info_fn))(png_ptr, info_ptr);
1038 }
1039 
1040 void /* PRIVATE */
png_push_have_end(png_structrp png_ptr,png_inforp info_ptr)1041 png_push_have_end(png_structrp png_ptr, png_inforp info_ptr)
1042 {
1043    if (png_ptr->end_fn != NULL)
1044       (*(png_ptr->end_fn))(png_ptr, info_ptr);
1045 }
1046 
1047 void /* PRIVATE */
png_push_have_row(png_structrp png_ptr,png_bytep row)1048 png_push_have_row(png_structrp png_ptr, png_bytep row)
1049 {
1050    if (png_ptr->row_fn != NULL)
1051       (*(png_ptr->row_fn))(png_ptr, row, png_ptr->row_number,
1052           (int)png_ptr->pass);
1053 }
1054 
1055 #ifdef PNG_READ_INTERLACING_SUPPORTED
1056 void PNGAPI
png_progressive_combine_row(png_const_structrp png_ptr,png_bytep old_row,png_const_bytep new_row)1057 png_progressive_combine_row(png_const_structrp png_ptr, png_bytep old_row,
1058     png_const_bytep new_row)
1059 {
1060    if (png_ptr == NULL)
1061       return;
1062 
1063    /* new_row is a flag here - if it is NULL then the app callback was called
1064     * from an empty row (see the calls to png_struct::row_fn below), otherwise
1065     * it must be png_ptr->row_buf+1
1066     */
1067    if (new_row != NULL)
1068       png_combine_row(png_ptr, old_row, 1/*blocky display*/);
1069 }
1070 #endif /* READ_INTERLACING */
1071 
1072 void PNGAPI
png_set_progressive_read_fn(png_structrp png_ptr,png_voidp progressive_ptr,png_progressive_info_ptr info_fn,png_progressive_row_ptr row_fn,png_progressive_end_ptr end_fn)1073 png_set_progressive_read_fn(png_structrp png_ptr, png_voidp progressive_ptr,
1074     png_progressive_info_ptr info_fn, png_progressive_row_ptr row_fn,
1075     png_progressive_end_ptr end_fn)
1076 {
1077    if (png_ptr == NULL)
1078       return;
1079 
1080    png_ptr->info_fn = info_fn;
1081    png_ptr->row_fn = row_fn;
1082    png_ptr->end_fn = end_fn;
1083 
1084    png_set_read_fn(png_ptr, progressive_ptr, png_push_fill_buffer);
1085 }
1086 
1087 png_voidp PNGAPI
png_get_progressive_ptr(png_const_structrp png_ptr)1088 png_get_progressive_ptr(png_const_structrp png_ptr)
1089 {
1090    if (png_ptr == NULL)
1091       return (NULL);
1092 
1093    return png_ptr->io_ptr;
1094 }
1095 #endif /* PROGRESSIVE_READ */
1096