1
2 /* pngpread.c - read a png file in push mode
3 *
4 * Last changed in libpng 1.6.24 [August 4, 2016]
5 * Copyright (c) 1998-2002,2004,2006-2016 Glenn Randers-Pehrson
6 * (Version 0.96 Copyright (c) 1996, 1997 Andreas Dilger)
7 * (Version 0.88 Copyright (c) 1995, 1996 Guy Eric Schalnat, Group 42, Inc.)
8 *
9 * This code is released under the libpng license.
10 * For conditions of distribution and use, see the disclaimer
11 * and license in png.h
12 */
13
14 #include "pngpriv.h"
15
16 #ifdef PNG_PROGRESSIVE_READ_SUPPORTED
17
18 /* Push model modes */
19 #define PNG_READ_SIG_MODE 0
20 #define PNG_READ_CHUNK_MODE 1
21 #define PNG_READ_IDAT_MODE 2
22 #define PNG_READ_tEXt_MODE 4
23 #define PNG_READ_zTXt_MODE 5
24 #define PNG_READ_DONE_MODE 6
25 #define PNG_READ_iTXt_MODE 7
26 #define PNG_ERROR_MODE 8
27
28 #define PNG_PUSH_SAVE_BUFFER_IF_FULL \
29 if (png_ptr->push_length + 4 > png_ptr->buffer_size) \
30 { png_push_save_buffer(png_ptr); return; }
31 #define PNG_PUSH_SAVE_BUFFER_IF_LT(N) \
32 if (png_ptr->buffer_size < N) \
33 { png_push_save_buffer(png_ptr); return; }
34
35 void PNGAPI
png_process_data(png_structrp png_ptr,png_inforp info_ptr,png_bytep buffer,png_size_t buffer_size)36 png_process_data(png_structrp png_ptr, png_inforp info_ptr,
37 png_bytep buffer, png_size_t buffer_size)
38 {
39 if (png_ptr == NULL || info_ptr == NULL)
40 return;
41
42 png_push_restore_buffer(png_ptr, buffer, buffer_size);
43
44 while (png_ptr->buffer_size)
45 {
46 png_process_some_data(png_ptr, info_ptr);
47 }
48 }
49
50 png_size_t PNGAPI
png_process_data_pause(png_structrp png_ptr,int save)51 png_process_data_pause(png_structrp png_ptr, int save)
52 {
53 if (png_ptr != NULL)
54 {
55 /* It's easiest for the caller if we do the save; then the caller doesn't
56 * have to supply the same data again:
57 */
58 if (save != 0)
59 png_push_save_buffer(png_ptr);
60 else
61 {
62 /* This includes any pending saved bytes: */
63 png_size_t remaining = png_ptr->buffer_size;
64 png_ptr->buffer_size = 0;
65
66 /* So subtract the saved buffer size, unless all the data
67 * is actually 'saved', in which case we just return 0
68 */
69 if (png_ptr->save_buffer_size < remaining)
70 return remaining - png_ptr->save_buffer_size;
71 }
72 }
73
74 return 0;
75 }
76
77 png_uint_32 PNGAPI
png_process_data_skip(png_structrp png_ptr)78 png_process_data_skip(png_structrp png_ptr)
79 {
80 /* TODO: Deprecate and remove this API.
81 * Somewhere the implementation of this seems to have been lost,
82 * or abandoned. It was only to support some internal back-door access
83 * to png_struct) in libpng-1.4.x.
84 */
85 png_app_warning(png_ptr,
86 "png_process_data_skip is not implemented in any current version of libpng");
87 return 0;
88 }
89
90 /* What we do with the incoming data depends on what we were previously
91 * doing before we ran out of data...
92 */
93 void /* PRIVATE */
png_process_some_data(png_structrp png_ptr,png_inforp info_ptr)94 png_process_some_data(png_structrp png_ptr, png_inforp info_ptr)
95 {
96 if (png_ptr == NULL)
97 return;
98
99 switch (png_ptr->process_mode)
100 {
101 case PNG_READ_SIG_MODE:
102 {
103 png_push_read_sig(png_ptr, info_ptr);
104 break;
105 }
106
107 case PNG_READ_CHUNK_MODE:
108 {
109 png_push_read_chunk(png_ptr, info_ptr);
110 break;
111 }
112
113 case PNG_READ_IDAT_MODE:
114 {
115 png_push_read_IDAT(png_ptr);
116 break;
117 }
118
119 default:
120 {
121 png_ptr->buffer_size = 0;
122 break;
123 }
124 }
125 }
126
127 /* Read any remaining signature bytes from the stream and compare them with
128 * the correct PNG signature. It is possible that this routine is called
129 * with bytes already read from the signature, either because they have been
130 * checked by the calling application, or because of multiple calls to this
131 * routine.
132 */
133 void /* PRIVATE */
png_push_read_sig(png_structrp png_ptr,png_inforp info_ptr)134 png_push_read_sig(png_structrp png_ptr, png_inforp info_ptr)
135 {
136 png_size_t num_checked = png_ptr->sig_bytes, /* SAFE, does not exceed 8 */
137 num_to_check = 8 - num_checked;
138
139 if (png_ptr->buffer_size < num_to_check)
140 {
141 num_to_check = png_ptr->buffer_size;
142 }
143
144 png_push_fill_buffer(png_ptr, &(info_ptr->signature[num_checked]),
145 num_to_check);
146 png_ptr->sig_bytes = (png_byte)(png_ptr->sig_bytes + num_to_check);
147
148 if (png_sig_cmp(info_ptr->signature, num_checked, num_to_check))
149 {
150 if (num_checked < 4 &&
151 png_sig_cmp(info_ptr->signature, num_checked, num_to_check - 4))
152 png_error(png_ptr, "Not a PNG file");
153
154 else
155 png_error(png_ptr, "PNG file corrupted by ASCII conversion");
156 }
157 else
158 {
159 if (png_ptr->sig_bytes >= 8)
160 {
161 png_ptr->process_mode = PNG_READ_CHUNK_MODE;
162 }
163 }
164 }
165
166 void /* PRIVATE */
png_push_read_chunk(png_structrp png_ptr,png_inforp info_ptr)167 png_push_read_chunk(png_structrp png_ptr, png_inforp info_ptr)
168 {
169 png_uint_32 chunk_name;
170 #ifdef PNG_HANDLE_AS_UNKNOWN_SUPPORTED
171 int keep; /* unknown handling method */
172 #endif
173
174 /* First we make sure we have enough data for the 4-byte chunk name
175 * and the 4-byte chunk length before proceeding with decoding the
176 * chunk data. To fully decode each of these chunks, we also make
177 * sure we have enough data in the buffer for the 4-byte CRC at the
178 * end of every chunk (except IDAT, which is handled separately).
179 */
180 if ((png_ptr->mode & PNG_HAVE_CHUNK_HEADER) == 0)
181 {
182 png_byte chunk_length[4];
183 png_byte chunk_tag[4];
184
185 PNG_PUSH_SAVE_BUFFER_IF_LT(8)
186 png_push_fill_buffer(png_ptr, chunk_length, 4);
187 png_ptr->push_length = png_get_uint_31(png_ptr, chunk_length);
188 png_reset_crc(png_ptr);
189 png_crc_read(png_ptr, chunk_tag, 4);
190 png_ptr->chunk_name = PNG_CHUNK_FROM_STRING(chunk_tag);
191 png_check_chunk_name(png_ptr, png_ptr->chunk_name);
192 png_ptr->mode |= PNG_HAVE_CHUNK_HEADER;
193 }
194
195 chunk_name = png_ptr->chunk_name;
196
197 if (chunk_name == png_IDAT)
198 {
199 if ((png_ptr->mode & PNG_AFTER_IDAT) != 0)
200 png_ptr->mode |= PNG_HAVE_CHUNK_AFTER_IDAT;
201
202 /* If we reach an IDAT chunk, this means we have read all of the
203 * header chunks, and we can start reading the image (or if this
204 * is called after the image has been read - we have an error).
205 */
206 if ((png_ptr->mode & PNG_HAVE_IHDR) == 0)
207 png_error(png_ptr, "Missing IHDR before IDAT");
208
209 else if (png_ptr->color_type == PNG_COLOR_TYPE_PALETTE &&
210 (png_ptr->mode & PNG_HAVE_PLTE) == 0)
211 png_error(png_ptr, "Missing PLTE before IDAT");
212
213 png_ptr->process_mode = PNG_READ_IDAT_MODE;
214
215 if ((png_ptr->mode & PNG_HAVE_IDAT) != 0)
216 if ((png_ptr->mode & PNG_HAVE_CHUNK_AFTER_IDAT) == 0)
217 if (png_ptr->push_length == 0)
218 return;
219
220 png_ptr->mode |= PNG_HAVE_IDAT;
221
222 if ((png_ptr->mode & PNG_AFTER_IDAT) != 0)
223 png_benign_error(png_ptr, "Too many IDATs found");
224 }
225
226 if (chunk_name == png_IHDR)
227 {
228 if (png_ptr->push_length != 13)
229 png_error(png_ptr, "Invalid IHDR length");
230
231 PNG_PUSH_SAVE_BUFFER_IF_FULL
232 png_handle_IHDR(png_ptr, info_ptr, png_ptr->push_length);
233 }
234
235 else if (chunk_name == png_IEND)
236 {
237 PNG_PUSH_SAVE_BUFFER_IF_FULL
238 png_handle_IEND(png_ptr, info_ptr, png_ptr->push_length);
239
240 png_ptr->process_mode = PNG_READ_DONE_MODE;
241 png_push_have_end(png_ptr, info_ptr);
242 }
243
244 #ifdef PNG_HANDLE_AS_UNKNOWN_SUPPORTED
245 else if ((keep = png_chunk_unknown_handling(png_ptr, chunk_name)) != 0)
246 {
247 PNG_PUSH_SAVE_BUFFER_IF_FULL
248 png_handle_unknown(png_ptr, info_ptr, png_ptr->push_length, keep);
249
250 if (chunk_name == png_PLTE)
251 png_ptr->mode |= PNG_HAVE_PLTE;
252 }
253 #endif
254
255 else if (chunk_name == png_PLTE)
256 {
257 PNG_PUSH_SAVE_BUFFER_IF_FULL
258 png_handle_PLTE(png_ptr, info_ptr, png_ptr->push_length);
259 }
260
261 else if (chunk_name == png_IDAT)
262 {
263 png_ptr->idat_size = png_ptr->push_length;
264 png_ptr->process_mode = PNG_READ_IDAT_MODE;
265 png_push_have_info(png_ptr, info_ptr);
266 png_ptr->zstream.avail_out =
267 (uInt) PNG_ROWBYTES(png_ptr->pixel_depth,
268 png_ptr->iwidth) + 1;
269 png_ptr->zstream.next_out = png_ptr->row_buf;
270 return;
271 }
272
273 #ifdef PNG_READ_gAMA_SUPPORTED
274 else if (png_ptr->chunk_name == png_gAMA)
275 {
276 PNG_PUSH_SAVE_BUFFER_IF_FULL
277 png_handle_gAMA(png_ptr, info_ptr, png_ptr->push_length);
278 }
279
280 #endif
281 #ifdef PNG_READ_sBIT_SUPPORTED
282 else if (png_ptr->chunk_name == png_sBIT)
283 {
284 PNG_PUSH_SAVE_BUFFER_IF_FULL
285 png_handle_sBIT(png_ptr, info_ptr, png_ptr->push_length);
286 }
287
288 #endif
289 #ifdef PNG_READ_cHRM_SUPPORTED
290 else if (png_ptr->chunk_name == png_cHRM)
291 {
292 PNG_PUSH_SAVE_BUFFER_IF_FULL
293 png_handle_cHRM(png_ptr, info_ptr, png_ptr->push_length);
294 }
295
296 #endif
297 #ifdef PNG_READ_sRGB_SUPPORTED
298 else if (chunk_name == png_sRGB)
299 {
300 PNG_PUSH_SAVE_BUFFER_IF_FULL
301 png_handle_sRGB(png_ptr, info_ptr, png_ptr->push_length);
302 }
303
304 #endif
305 #ifdef PNG_READ_iCCP_SUPPORTED
306 else if (png_ptr->chunk_name == png_iCCP)
307 {
308 PNG_PUSH_SAVE_BUFFER_IF_FULL
309 png_handle_iCCP(png_ptr, info_ptr, png_ptr->push_length);
310 }
311
312 #endif
313 #ifdef PNG_READ_sPLT_SUPPORTED
314 else if (chunk_name == png_sPLT)
315 {
316 PNG_PUSH_SAVE_BUFFER_IF_FULL
317 png_handle_sPLT(png_ptr, info_ptr, png_ptr->push_length);
318 }
319
320 #endif
321 #ifdef PNG_READ_tRNS_SUPPORTED
322 else if (chunk_name == png_tRNS)
323 {
324 PNG_PUSH_SAVE_BUFFER_IF_FULL
325 png_handle_tRNS(png_ptr, info_ptr, png_ptr->push_length);
326 }
327
328 #endif
329 #ifdef PNG_READ_bKGD_SUPPORTED
330 else if (chunk_name == png_bKGD)
331 {
332 PNG_PUSH_SAVE_BUFFER_IF_FULL
333 png_handle_bKGD(png_ptr, info_ptr, png_ptr->push_length);
334 }
335
336 #endif
337 #ifdef PNG_READ_hIST_SUPPORTED
338 else if (chunk_name == png_hIST)
339 {
340 PNG_PUSH_SAVE_BUFFER_IF_FULL
341 png_handle_hIST(png_ptr, info_ptr, png_ptr->push_length);
342 }
343
344 #endif
345 #ifdef PNG_READ_pHYs_SUPPORTED
346 else if (chunk_name == png_pHYs)
347 {
348 PNG_PUSH_SAVE_BUFFER_IF_FULL
349 png_handle_pHYs(png_ptr, info_ptr, png_ptr->push_length);
350 }
351
352 #endif
353 #ifdef PNG_READ_oFFs_SUPPORTED
354 else if (chunk_name == png_oFFs)
355 {
356 PNG_PUSH_SAVE_BUFFER_IF_FULL
357 png_handle_oFFs(png_ptr, info_ptr, png_ptr->push_length);
358 }
359 #endif
360
361 #ifdef PNG_READ_pCAL_SUPPORTED
362 else if (chunk_name == png_pCAL)
363 {
364 PNG_PUSH_SAVE_BUFFER_IF_FULL
365 png_handle_pCAL(png_ptr, info_ptr, png_ptr->push_length);
366 }
367
368 #endif
369 #ifdef PNG_READ_sCAL_SUPPORTED
370 else if (chunk_name == png_sCAL)
371 {
372 PNG_PUSH_SAVE_BUFFER_IF_FULL
373 png_handle_sCAL(png_ptr, info_ptr, png_ptr->push_length);
374 }
375
376 #endif
377 #ifdef PNG_READ_tIME_SUPPORTED
378 else if (chunk_name == png_tIME)
379 {
380 PNG_PUSH_SAVE_BUFFER_IF_FULL
381 png_handle_tIME(png_ptr, info_ptr, png_ptr->push_length);
382 }
383
384 #endif
385 #ifdef PNG_READ_tEXt_SUPPORTED
386 else if (chunk_name == png_tEXt)
387 {
388 PNG_PUSH_SAVE_BUFFER_IF_FULL
389 png_handle_tEXt(png_ptr, info_ptr, png_ptr->push_length);
390 }
391
392 #endif
393 #ifdef PNG_READ_zTXt_SUPPORTED
394 else if (chunk_name == png_zTXt)
395 {
396 PNG_PUSH_SAVE_BUFFER_IF_FULL
397 png_handle_zTXt(png_ptr, info_ptr, png_ptr->push_length);
398 }
399
400 #endif
401 #ifdef PNG_READ_iTXt_SUPPORTED
402 else if (chunk_name == png_iTXt)
403 {
404 PNG_PUSH_SAVE_BUFFER_IF_FULL
405 png_handle_iTXt(png_ptr, info_ptr, png_ptr->push_length);
406 }
407 #endif
408
409 else
410 {
411 PNG_PUSH_SAVE_BUFFER_IF_FULL
412 png_handle_unknown(png_ptr, info_ptr, png_ptr->push_length,
413 PNG_HANDLE_CHUNK_AS_DEFAULT);
414 }
415
416 png_ptr->mode &= ~PNG_HAVE_CHUNK_HEADER;
417 }
418
419 void PNGCBAPI
png_push_fill_buffer(png_structp png_ptr,png_bytep buffer,png_size_t length)420 png_push_fill_buffer(png_structp png_ptr, png_bytep buffer, png_size_t length)
421 {
422 png_bytep ptr;
423
424 if (png_ptr == NULL)
425 return;
426
427 ptr = buffer;
428 if (png_ptr->save_buffer_size != 0)
429 {
430 png_size_t save_size;
431
432 if (length < png_ptr->save_buffer_size)
433 save_size = length;
434
435 else
436 save_size = png_ptr->save_buffer_size;
437
438 memcpy(ptr, png_ptr->save_buffer_ptr, save_size);
439 length -= save_size;
440 ptr += save_size;
441 png_ptr->buffer_size -= save_size;
442 png_ptr->save_buffer_size -= save_size;
443 png_ptr->save_buffer_ptr += save_size;
444 }
445 if (length != 0 && png_ptr->current_buffer_size != 0)
446 {
447 png_size_t save_size;
448
449 if (length < png_ptr->current_buffer_size)
450 save_size = length;
451
452 else
453 save_size = png_ptr->current_buffer_size;
454
455 memcpy(ptr, png_ptr->current_buffer_ptr, save_size);
456 png_ptr->buffer_size -= save_size;
457 png_ptr->current_buffer_size -= save_size;
458 png_ptr->current_buffer_ptr += save_size;
459 }
460 }
461
462 void /* PRIVATE */
png_push_save_buffer(png_structrp png_ptr)463 png_push_save_buffer(png_structrp png_ptr)
464 {
465 if (png_ptr->save_buffer_size != 0)
466 {
467 if (png_ptr->save_buffer_ptr != png_ptr->save_buffer)
468 {
469 png_size_t i, istop;
470 png_bytep sp;
471 png_bytep dp;
472
473 istop = png_ptr->save_buffer_size;
474 for (i = 0, sp = png_ptr->save_buffer_ptr, dp = png_ptr->save_buffer;
475 i < istop; i++, sp++, dp++)
476 {
477 *dp = *sp;
478 }
479 }
480 }
481 if (png_ptr->save_buffer_size + png_ptr->current_buffer_size >
482 png_ptr->save_buffer_max)
483 {
484 png_size_t new_max;
485 png_bytep old_buffer;
486
487 if (png_ptr->save_buffer_size > PNG_SIZE_MAX -
488 (png_ptr->current_buffer_size + 256))
489 {
490 png_error(png_ptr, "Potential overflow of save_buffer");
491 }
492
493 new_max = png_ptr->save_buffer_size + png_ptr->current_buffer_size + 256;
494 old_buffer = png_ptr->save_buffer;
495 png_ptr->save_buffer = (png_bytep)png_malloc_warn(png_ptr,
496 (png_size_t)new_max);
497
498 if (png_ptr->save_buffer == NULL)
499 {
500 png_free(png_ptr, old_buffer);
501 png_error(png_ptr, "Insufficient memory for save_buffer");
502 }
503
504 if (old_buffer)
505 memcpy(png_ptr->save_buffer, old_buffer, png_ptr->save_buffer_size);
506 else if (png_ptr->save_buffer_size)
507 png_error(png_ptr, "save_buffer error");
508 png_free(png_ptr, old_buffer);
509 png_ptr->save_buffer_max = new_max;
510 }
511 if (png_ptr->current_buffer_size)
512 {
513 memcpy(png_ptr->save_buffer + png_ptr->save_buffer_size,
514 png_ptr->current_buffer_ptr, png_ptr->current_buffer_size);
515 png_ptr->save_buffer_size += png_ptr->current_buffer_size;
516 png_ptr->current_buffer_size = 0;
517 }
518 png_ptr->save_buffer_ptr = png_ptr->save_buffer;
519 png_ptr->buffer_size = 0;
520 }
521
522 void /* PRIVATE */
png_push_restore_buffer(png_structrp png_ptr,png_bytep buffer,png_size_t buffer_length)523 png_push_restore_buffer(png_structrp png_ptr, png_bytep buffer,
524 png_size_t buffer_length)
525 {
526 png_ptr->current_buffer = buffer;
527 png_ptr->current_buffer_size = buffer_length;
528 png_ptr->buffer_size = buffer_length + png_ptr->save_buffer_size;
529 png_ptr->current_buffer_ptr = png_ptr->current_buffer;
530 }
531
532 void /* PRIVATE */
png_push_read_IDAT(png_structrp png_ptr)533 png_push_read_IDAT(png_structrp png_ptr)
534 {
535 if ((png_ptr->mode & PNG_HAVE_CHUNK_HEADER) == 0)
536 {
537 png_byte chunk_length[4];
538 png_byte chunk_tag[4];
539
540 /* TODO: this code can be commoned up with the same code in push_read */
541 PNG_PUSH_SAVE_BUFFER_IF_LT(8)
542 png_push_fill_buffer(png_ptr, chunk_length, 4);
543 png_ptr->push_length = png_get_uint_31(png_ptr, chunk_length);
544 png_reset_crc(png_ptr);
545 png_crc_read(png_ptr, chunk_tag, 4);
546 png_ptr->chunk_name = PNG_CHUNK_FROM_STRING(chunk_tag);
547 png_ptr->mode |= PNG_HAVE_CHUNK_HEADER;
548
549 if (png_ptr->chunk_name != png_IDAT)
550 {
551 png_ptr->process_mode = PNG_READ_CHUNK_MODE;
552
553 if ((png_ptr->flags & PNG_FLAG_ZSTREAM_ENDED) == 0)
554 png_error(png_ptr, "Not enough compressed data");
555
556 return;
557 }
558
559 png_ptr->idat_size = png_ptr->push_length;
560 }
561
562 if (png_ptr->idat_size != 0 && png_ptr->save_buffer_size != 0)
563 {
564 png_size_t save_size = png_ptr->save_buffer_size;
565 png_uint_32 idat_size = png_ptr->idat_size;
566
567 /* We want the smaller of 'idat_size' and 'current_buffer_size', but they
568 * are of different types and we don't know which variable has the fewest
569 * bits. Carefully select the smaller and cast it to the type of the
570 * larger - this cannot overflow. Do not cast in the following test - it
571 * will break on either 16-bit or 64-bit platforms.
572 */
573 if (idat_size < save_size)
574 save_size = (png_size_t)idat_size;
575
576 else
577 idat_size = (png_uint_32)save_size;
578
579 png_calculate_crc(png_ptr, png_ptr->save_buffer_ptr, save_size);
580
581 png_process_IDAT_data(png_ptr, png_ptr->save_buffer_ptr, save_size);
582
583 png_ptr->idat_size -= idat_size;
584 png_ptr->buffer_size -= save_size;
585 png_ptr->save_buffer_size -= save_size;
586 png_ptr->save_buffer_ptr += save_size;
587 }
588
589 if (png_ptr->idat_size != 0 && png_ptr->current_buffer_size != 0)
590 {
591 png_size_t save_size = png_ptr->current_buffer_size;
592 png_uint_32 idat_size = png_ptr->idat_size;
593
594 /* We want the smaller of 'idat_size' and 'current_buffer_size', but they
595 * are of different types and we don't know which variable has the fewest
596 * bits. Carefully select the smaller and cast it to the type of the
597 * larger - this cannot overflow.
598 */
599 if (idat_size < save_size)
600 save_size = (png_size_t)idat_size;
601
602 else
603 idat_size = (png_uint_32)save_size;
604
605 png_calculate_crc(png_ptr, png_ptr->current_buffer_ptr, save_size);
606
607 png_process_IDAT_data(png_ptr, png_ptr->current_buffer_ptr, save_size);
608
609 png_ptr->idat_size -= idat_size;
610 png_ptr->buffer_size -= save_size;
611 png_ptr->current_buffer_size -= save_size;
612 png_ptr->current_buffer_ptr += save_size;
613 }
614
615 if (png_ptr->idat_size == 0)
616 {
617 PNG_PUSH_SAVE_BUFFER_IF_LT(4)
618 png_crc_finish(png_ptr, 0);
619 png_ptr->mode &= ~PNG_HAVE_CHUNK_HEADER;
620 png_ptr->mode |= PNG_AFTER_IDAT;
621 png_ptr->zowner = 0;
622 }
623 }
624
625 void /* PRIVATE */
png_process_IDAT_data(png_structrp png_ptr,png_bytep buffer,png_size_t buffer_length)626 png_process_IDAT_data(png_structrp png_ptr, png_bytep buffer,
627 png_size_t buffer_length)
628 {
629 /* The caller checks for a non-zero buffer length. */
630 if (!(buffer_length > 0) || buffer == NULL)
631 png_error(png_ptr, "No IDAT data (internal error)");
632
633 /* This routine must process all the data it has been given
634 * before returning, calling the row callback as required to
635 * handle the uncompressed results.
636 */
637 png_ptr->zstream.next_in = buffer;
638 /* TODO: WARNING: TRUNCATION ERROR: DANGER WILL ROBINSON: */
639 png_ptr->zstream.avail_in = (uInt)buffer_length;
640
641 /* Keep going until the decompressed data is all processed
642 * or the stream marked as finished.
643 */
644 while (png_ptr->zstream.avail_in > 0 &&
645 (png_ptr->flags & PNG_FLAG_ZSTREAM_ENDED) == 0)
646 {
647 int ret;
648
649 /* We have data for zlib, but we must check that zlib
650 * has someplace to put the results. It doesn't matter
651 * if we don't expect any results -- it may be the input
652 * data is just the LZ end code.
653 */
654 if (!(png_ptr->zstream.avail_out > 0))
655 {
656 /* TODO: WARNING: TRUNCATION ERROR: DANGER WILL ROBINSON: */
657 png_ptr->zstream.avail_out = (uInt)(PNG_ROWBYTES(png_ptr->pixel_depth,
658 png_ptr->iwidth) + 1);
659
660 png_ptr->zstream.next_out = png_ptr->row_buf;
661 }
662
663 /* Using Z_SYNC_FLUSH here means that an unterminated
664 * LZ stream (a stream with a missing end code) can still
665 * be handled, otherwise (Z_NO_FLUSH) a future zlib
666 * implementation might defer output and therefore
667 * change the current behavior (see comments in inflate.c
668 * for why this doesn't happen at present with zlib 1.2.5).
669 */
670 ret = PNG_INFLATE(png_ptr, Z_SYNC_FLUSH);
671
672 /* Check for any failure before proceeding. */
673 if (ret != Z_OK && ret != Z_STREAM_END)
674 {
675 /* Terminate the decompression. */
676 png_ptr->flags |= PNG_FLAG_ZSTREAM_ENDED;
677 png_ptr->zowner = 0;
678
679 /* This may be a truncated stream (missing or
680 * damaged end code). Treat that as a warning.
681 */
682 if (png_ptr->row_number >= png_ptr->num_rows ||
683 png_ptr->pass > 6)
684 png_warning(png_ptr, "Truncated compressed data in IDAT");
685
686 else
687 {
688 if (ret == Z_DATA_ERROR)
689 png_benign_error(png_ptr, "IDAT: ADLER32 checksum mismatch");
690 else
691 png_error(png_ptr, "Decompression error in IDAT");
692 }
693
694 /* Skip the check on unprocessed input */
695 return;
696 }
697
698 /* Did inflate output any data? */
699 if (png_ptr->zstream.next_out != png_ptr->row_buf)
700 {
701 /* Is this unexpected data after the last row?
702 * If it is, artificially terminate the LZ output
703 * here.
704 */
705 if (png_ptr->row_number >= png_ptr->num_rows ||
706 png_ptr->pass > 6)
707 {
708 /* Extra data. */
709 png_warning(png_ptr, "Extra compressed data in IDAT");
710 png_ptr->flags |= PNG_FLAG_ZSTREAM_ENDED;
711 png_ptr->zowner = 0;
712
713 /* Do no more processing; skip the unprocessed
714 * input check below.
715 */
716 return;
717 }
718
719 /* Do we have a complete row? */
720 if (png_ptr->zstream.avail_out == 0)
721 png_push_process_row(png_ptr);
722 }
723
724 /* And check for the end of the stream. */
725 if (ret == Z_STREAM_END)
726 png_ptr->flags |= PNG_FLAG_ZSTREAM_ENDED;
727 }
728
729 /* All the data should have been processed, if anything
730 * is left at this point we have bytes of IDAT data
731 * after the zlib end code.
732 */
733 if (png_ptr->zstream.avail_in > 0)
734 png_warning(png_ptr, "Extra compression data in IDAT");
735 }
736
737 void /* PRIVATE */
png_push_process_row(png_structrp png_ptr)738 png_push_process_row(png_structrp png_ptr)
739 {
740 /* 1.5.6: row_info moved out of png_struct to a local here. */
741 png_row_info row_info;
742
743 row_info.width = png_ptr->iwidth; /* NOTE: width of current interlaced row */
744 row_info.color_type = png_ptr->color_type;
745 row_info.bit_depth = png_ptr->bit_depth;
746 row_info.channels = png_ptr->channels;
747 row_info.pixel_depth = png_ptr->pixel_depth;
748 row_info.rowbytes = PNG_ROWBYTES(row_info.pixel_depth, row_info.width);
749
750 if (png_ptr->row_buf[0] > PNG_FILTER_VALUE_NONE)
751 {
752 if (png_ptr->row_buf[0] < PNG_FILTER_VALUE_LAST)
753 png_read_filter_row(png_ptr, &row_info, png_ptr->row_buf + 1,
754 png_ptr->prev_row + 1, png_ptr->row_buf[0]);
755 else
756 png_error(png_ptr, "bad adaptive filter value");
757 }
758
759 /* libpng 1.5.6: the following line was copying png_ptr->rowbytes before
760 * 1.5.6, while the buffer really is this big in current versions of libpng
761 * it may not be in the future, so this was changed just to copy the
762 * interlaced row count:
763 */
764 memcpy(png_ptr->prev_row, png_ptr->row_buf, row_info.rowbytes + 1);
765
766 #ifdef PNG_READ_TRANSFORMS_SUPPORTED
767 if (png_ptr->transformations != 0)
768 png_do_read_transformations(png_ptr, &row_info);
769 #endif
770
771 /* The transformed pixel depth should match the depth now in row_info. */
772 if (png_ptr->transformed_pixel_depth == 0)
773 {
774 png_ptr->transformed_pixel_depth = row_info.pixel_depth;
775 if (row_info.pixel_depth > png_ptr->maximum_pixel_depth)
776 png_error(png_ptr, "progressive row overflow");
777 }
778
779 else if (png_ptr->transformed_pixel_depth != row_info.pixel_depth)
780 png_error(png_ptr, "internal progressive row size calculation error");
781
782
783 #ifdef PNG_READ_INTERLACING_SUPPORTED
784 /* Expand interlaced rows to full size */
785 if (png_ptr->interlaced != 0 &&
786 (png_ptr->transformations & PNG_INTERLACE) != 0)
787 {
788 if (png_ptr->pass < 6)
789 png_do_read_interlace(&row_info, png_ptr->row_buf + 1, png_ptr->pass,
790 png_ptr->transformations);
791
792 switch (png_ptr->pass)
793 {
794 case 0:
795 {
796 int i;
797 for (i = 0; i < 8 && png_ptr->pass == 0; i++)
798 {
799 png_push_have_row(png_ptr, png_ptr->row_buf + 1);
800 png_read_push_finish_row(png_ptr); /* Updates png_ptr->pass */
801 }
802
803 if (png_ptr->pass == 2) /* Pass 1 might be empty */
804 {
805 for (i = 0; i < 4 && png_ptr->pass == 2; i++)
806 {
807 png_push_have_row(png_ptr, NULL);
808 png_read_push_finish_row(png_ptr);
809 }
810 }
811
812 if (png_ptr->pass == 4 && png_ptr->height <= 4)
813 {
814 for (i = 0; i < 2 && png_ptr->pass == 4; i++)
815 {
816 png_push_have_row(png_ptr, NULL);
817 png_read_push_finish_row(png_ptr);
818 }
819 }
820
821 if (png_ptr->pass == 6 && png_ptr->height <= 4)
822 {
823 png_push_have_row(png_ptr, NULL);
824 png_read_push_finish_row(png_ptr);
825 }
826
827 break;
828 }
829
830 case 1:
831 {
832 int i;
833 for (i = 0; i < 8 && png_ptr->pass == 1; i++)
834 {
835 png_push_have_row(png_ptr, png_ptr->row_buf + 1);
836 png_read_push_finish_row(png_ptr);
837 }
838
839 if (png_ptr->pass == 2) /* Skip top 4 generated rows */
840 {
841 for (i = 0; i < 4 && png_ptr->pass == 2; i++)
842 {
843 png_push_have_row(png_ptr, NULL);
844 png_read_push_finish_row(png_ptr);
845 }
846 }
847
848 break;
849 }
850
851 case 2:
852 {
853 int i;
854
855 for (i = 0; i < 4 && png_ptr->pass == 2; i++)
856 {
857 png_push_have_row(png_ptr, png_ptr->row_buf + 1);
858 png_read_push_finish_row(png_ptr);
859 }
860
861 for (i = 0; i < 4 && png_ptr->pass == 2; i++)
862 {
863 png_push_have_row(png_ptr, NULL);
864 png_read_push_finish_row(png_ptr);
865 }
866
867 if (png_ptr->pass == 4) /* Pass 3 might be empty */
868 {
869 for (i = 0; i < 2 && png_ptr->pass == 4; i++)
870 {
871 png_push_have_row(png_ptr, NULL);
872 png_read_push_finish_row(png_ptr);
873 }
874 }
875
876 break;
877 }
878
879 case 3:
880 {
881 int i;
882
883 for (i = 0; i < 4 && png_ptr->pass == 3; i++)
884 {
885 png_push_have_row(png_ptr, png_ptr->row_buf + 1);
886 png_read_push_finish_row(png_ptr);
887 }
888
889 if (png_ptr->pass == 4) /* Skip top two generated rows */
890 {
891 for (i = 0; i < 2 && png_ptr->pass == 4; i++)
892 {
893 png_push_have_row(png_ptr, NULL);
894 png_read_push_finish_row(png_ptr);
895 }
896 }
897
898 break;
899 }
900
901 case 4:
902 {
903 int i;
904
905 for (i = 0; i < 2 && png_ptr->pass == 4; i++)
906 {
907 png_push_have_row(png_ptr, png_ptr->row_buf + 1);
908 png_read_push_finish_row(png_ptr);
909 }
910
911 for (i = 0; i < 2 && png_ptr->pass == 4; i++)
912 {
913 png_push_have_row(png_ptr, NULL);
914 png_read_push_finish_row(png_ptr);
915 }
916
917 if (png_ptr->pass == 6) /* Pass 5 might be empty */
918 {
919 png_push_have_row(png_ptr, NULL);
920 png_read_push_finish_row(png_ptr);
921 }
922
923 break;
924 }
925
926 case 5:
927 {
928 int i;
929
930 for (i = 0; i < 2 && png_ptr->pass == 5; i++)
931 {
932 png_push_have_row(png_ptr, png_ptr->row_buf + 1);
933 png_read_push_finish_row(png_ptr);
934 }
935
936 if (png_ptr->pass == 6) /* Skip top generated row */
937 {
938 png_push_have_row(png_ptr, NULL);
939 png_read_push_finish_row(png_ptr);
940 }
941
942 break;
943 }
944
945 default:
946 case 6:
947 {
948 png_push_have_row(png_ptr, png_ptr->row_buf + 1);
949 png_read_push_finish_row(png_ptr);
950
951 if (png_ptr->pass != 6)
952 break;
953
954 png_push_have_row(png_ptr, NULL);
955 png_read_push_finish_row(png_ptr);
956 }
957 }
958 }
959 else
960 #endif
961 {
962 png_push_have_row(png_ptr, png_ptr->row_buf + 1);
963 png_read_push_finish_row(png_ptr);
964 }
965 }
966
967 void /* PRIVATE */
png_read_push_finish_row(png_structrp png_ptr)968 png_read_push_finish_row(png_structrp png_ptr)
969 {
970 #ifdef PNG_READ_INTERLACING_SUPPORTED
971 /* Arrays to facilitate easy interlacing - use pass (0 - 6) as index */
972
973 /* Start of interlace block */
974 static PNG_CONST png_byte png_pass_start[] = {0, 4, 0, 2, 0, 1, 0};
975
976 /* Offset to next interlace block */
977 static PNG_CONST png_byte png_pass_inc[] = {8, 8, 4, 4, 2, 2, 1};
978
979 /* Start of interlace block in the y direction */
980 static PNG_CONST png_byte png_pass_ystart[] = {0, 0, 4, 0, 2, 0, 1};
981
982 /* Offset to next interlace block in the y direction */
983 static PNG_CONST png_byte png_pass_yinc[] = {8, 8, 8, 4, 4, 2, 2};
984
985 /* Height of interlace block. This is not currently used - if you need
986 * it, uncomment it here and in png.h
987 static PNG_CONST png_byte png_pass_height[] = {8, 8, 4, 4, 2, 2, 1};
988 */
989 #endif
990
991 png_ptr->row_number++;
992 if (png_ptr->row_number < png_ptr->num_rows)
993 return;
994
995 #ifdef PNG_READ_INTERLACING_SUPPORTED
996 if (png_ptr->interlaced != 0)
997 {
998 png_ptr->row_number = 0;
999 memset(png_ptr->prev_row, 0, png_ptr->rowbytes + 1);
1000
1001 do
1002 {
1003 png_ptr->pass++;
1004 if ((png_ptr->pass == 1 && png_ptr->width < 5) ||
1005 (png_ptr->pass == 3 && png_ptr->width < 3) ||
1006 (png_ptr->pass == 5 && png_ptr->width < 2))
1007 png_ptr->pass++;
1008
1009 if (png_ptr->pass > 7)
1010 png_ptr->pass--;
1011
1012 if (png_ptr->pass >= 7)
1013 break;
1014
1015 png_ptr->iwidth = (png_ptr->width +
1016 png_pass_inc[png_ptr->pass] - 1 -
1017 png_pass_start[png_ptr->pass]) /
1018 png_pass_inc[png_ptr->pass];
1019
1020 if ((png_ptr->transformations & PNG_INTERLACE) != 0)
1021 break;
1022
1023 png_ptr->num_rows = (png_ptr->height +
1024 png_pass_yinc[png_ptr->pass] - 1 -
1025 png_pass_ystart[png_ptr->pass]) /
1026 png_pass_yinc[png_ptr->pass];
1027
1028 } while (png_ptr->iwidth == 0 || png_ptr->num_rows == 0);
1029 }
1030 #endif /* READ_INTERLACING */
1031 }
1032
1033 void /* PRIVATE */
png_push_have_info(png_structrp png_ptr,png_inforp info_ptr)1034 png_push_have_info(png_structrp png_ptr, png_inforp info_ptr)
1035 {
1036 if (png_ptr->info_fn != NULL)
1037 (*(png_ptr->info_fn))(png_ptr, info_ptr);
1038 }
1039
1040 void /* PRIVATE */
png_push_have_end(png_structrp png_ptr,png_inforp info_ptr)1041 png_push_have_end(png_structrp png_ptr, png_inforp info_ptr)
1042 {
1043 if (png_ptr->end_fn != NULL)
1044 (*(png_ptr->end_fn))(png_ptr, info_ptr);
1045 }
1046
1047 void /* PRIVATE */
png_push_have_row(png_structrp png_ptr,png_bytep row)1048 png_push_have_row(png_structrp png_ptr, png_bytep row)
1049 {
1050 if (png_ptr->row_fn != NULL)
1051 (*(png_ptr->row_fn))(png_ptr, row, png_ptr->row_number,
1052 (int)png_ptr->pass);
1053 }
1054
1055 #ifdef PNG_READ_INTERLACING_SUPPORTED
1056 void PNGAPI
png_progressive_combine_row(png_const_structrp png_ptr,png_bytep old_row,png_const_bytep new_row)1057 png_progressive_combine_row(png_const_structrp png_ptr, png_bytep old_row,
1058 png_const_bytep new_row)
1059 {
1060 if (png_ptr == NULL)
1061 return;
1062
1063 /* new_row is a flag here - if it is NULL then the app callback was called
1064 * from an empty row (see the calls to png_struct::row_fn below), otherwise
1065 * it must be png_ptr->row_buf+1
1066 */
1067 if (new_row != NULL)
1068 png_combine_row(png_ptr, old_row, 1/*blocky display*/);
1069 }
1070 #endif /* READ_INTERLACING */
1071
1072 void PNGAPI
png_set_progressive_read_fn(png_structrp png_ptr,png_voidp progressive_ptr,png_progressive_info_ptr info_fn,png_progressive_row_ptr row_fn,png_progressive_end_ptr end_fn)1073 png_set_progressive_read_fn(png_structrp png_ptr, png_voidp progressive_ptr,
1074 png_progressive_info_ptr info_fn, png_progressive_row_ptr row_fn,
1075 png_progressive_end_ptr end_fn)
1076 {
1077 if (png_ptr == NULL)
1078 return;
1079
1080 png_ptr->info_fn = info_fn;
1081 png_ptr->row_fn = row_fn;
1082 png_ptr->end_fn = end_fn;
1083
1084 png_set_read_fn(png_ptr, progressive_ptr, png_push_fill_buffer);
1085 }
1086
1087 png_voidp PNGAPI
png_get_progressive_ptr(png_const_structrp png_ptr)1088 png_get_progressive_ptr(png_const_structrp png_ptr)
1089 {
1090 if (png_ptr == NULL)
1091 return (NULL);
1092
1093 return png_ptr->io_ptr;
1094 }
1095 #endif /* PROGRESSIVE_READ */
1096