Coverage Report

Created: 2026-07-24 07:44

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/ghostpdl/psi/iscan.c
Line
Count
Source
1
/* Copyright (C) 2001-2023 Artifex Software, Inc.
2
   All Rights Reserved.
3
4
   This software is provided AS-IS with no warranty, either express or
5
   implied.
6
7
   This software is distributed under license and may not be copied,
8
   modified or distributed except as expressly authorized under the terms
9
   of the license contained in the file LICENSE in this distribution.
10
11
   Refer to licensing information at http://www.artifex.com or contact
12
   Artifex Software, Inc.,  39 Mesa Street, Suite 108A, San Francisco,
13
   CA 94129, USA, for further information.
14
*/
15
16
17
/* Token scanner for Ghostscript interpreter */
18
#include "ghost.h"
19
#include "memory_.h"
20
#include "string_.h"
21
#include "stream.h"
22
#include "ierrors.h"
23
#include "btoken.h"             /* for ref_binary_object_format */
24
#include "files.h"              /* for fptr */
25
#include "ialloc.h"
26
#include "idict.h"              /* for //name lookup */
27
#include "dstack.h"             /* ditto */
28
#include "ilevel.h"
29
#include "iname.h"
30
#include "ipacked.h"
31
#include "iparray.h"
32
#include "strimpl.h"            /* for string decoding */
33
#include "sa85d.h"              /* ditto */
34
#include "sfilter.h"            /* ditto */
35
#include "ostack.h"             /* for accumulating proc bodies; */
36
                                        /* must precede iscan.h */
37
#include "iscan.h"              /* defines interface */
38
#include "iscanbin.h"
39
#include "iscannum.h"
40
#include "istream.h"
41
#include "istruct.h"            /* for RELOC_REF_VAR */
42
#include "iutil.h"
43
#include "ivmspace.h"
44
#include "store.h"
45
#include "scanchar.h"
46
47
/*
48
 * Level 2 includes some changes in the scanner:
49
 *      - \ is always recognized in strings, regardless of the data source;
50
 *      - << and >> are legal tokens;
51
 *      - <~ introduces an ASCII85 encoded string (terminated by ~>);
52
 *      - Character codes above 127 introduce binary objects.
53
 * We explicitly enable or disable these changes based on level2_enabled.
54
 */
55
56
/* ------ Dynamic strings ------ */
57
58
/* Begin collecting a dynamically allocated string. */
59
static inline void
60
dynamic_init(da_ptr pda, gs_memory_t *mem)
61
187M
{
62
187M
    pda->is_dynamic = false;
63
187M
    pda->limit = pda->buf + sizeof(pda->buf);
64
187M
    pda->next = pda->base = pda->buf;
65
187M
    pda->memory = mem;
66
187M
}
67
68
/* Free a dynamic string. */
69
static void
70
dynamic_free(da_ptr pda)
71
1.47G
{
72
1.47G
    if (pda->is_dynamic)
73
10.2M
        gs_free_string(pda->memory, pda->base, da_size(pda), "scanner");
74
1.47G
}
75
76
/* Resize a dynamic string. */
77
/* If the allocation fails, return gs_error_VMerror; otherwise, return 0. */
78
static int
79
dynamic_resize(da_ptr pda, uint new_size)
80
198M
{
81
198M
    uint old_size = da_size(pda);
82
198M
    uint pos = pda->next - pda->base;
83
198M
    gs_memory_t *mem = pda->memory;
84
198M
    byte *base;
85
86
198M
    if (pda->is_dynamic) {
87
869k
        base = gs_resize_string(mem, pda->base, old_size,
88
869k
                                new_size, "scanner");
89
869k
        if (base == 0)
90
0
            return_error(gs_error_VMerror);
91
197M
    } else {                    /* switching from static to dynamic */
92
197M
        base = gs_alloc_string(mem, new_size, "scanner");
93
197M
        if (base == 0)
94
0
            return_error(gs_error_VMerror);
95
197M
        memcpy(base, pda->base, min(old_size, new_size));
96
197M
        pda->is_dynamic = true;
97
197M
    }
98
198M
    pda->base = base;
99
198M
    pda->next = base + pos;
100
198M
    pda->limit = base + new_size;
101
198M
    return 0;
102
198M
}
103
104
/* Grow a dynamic string. */
105
/* Return 0 if the allocation failed, the new 'next' ptr if OK. */
106
/* Return 0 or an error code, updating pda->next to point to the first */
107
/* available byte after growing. */
108
static int
109
dynamic_grow(da_ptr pda, byte * next, uint max_size)
110
11.1M
{
111
11.1M
    uint old_size = da_size(pda);
112
11.1M
    uint new_size = (old_size < 10 ? 20 :
113
11.1M
                     old_size >= (max_size >> 1) ? max_size :
114
2.39M
                     old_size << 1);
115
11.1M
    int code;
116
117
11.1M
    pda->next = next;
118
11.1M
    if (old_size >= max_size)
119
79
        return_error(gs_error_limitcheck);
120
11.1M
    while ((code = dynamic_resize(pda, new_size)) < 0) {
121
        /* Try trimming down the requested new size. */
122
0
        new_size -= (new_size - old_size + 1) >> 1;
123
0
        if (new_size <= old_size)
124
0
                break;
125
0
    }
126
11.1M
    return code;
127
11.1M
}
128
129
/* Ensure that a dynamic string is either on the heap or in the */
130
/* private buffer. */
131
static void
132
dynamic_save(da_ptr pda)
133
861k
{
134
861k
    if (!pda->is_dynamic && pda->base != pda->buf) {
135
34
        int len = da_size(pda);
136
137
34
        if (len > sizeof(pda->buf))
138
0
            len = sizeof(pda->buf);
139
        /* This can happen if we get a /<CR> at the end of a buffer, and the file is
140
         * not at EOF. In this case 'len' will be zero so we don't actually copy any
141
         * bytes. So this is safe on current C run-time libraries, but it's probably
142
         * best to avoid it. Coverity ID C382008
143
         */
144
34
        if (pda->base != NULL)
145
29
            memcpy(pda->buf, pda->base, len);
146
34
        pda->next = pda->buf + len;
147
34
        pda->base = pda->buf;
148
34
    }
149
861k
}
150
151
/* Finish collecting a dynamic string. */
152
static int
153
dynamic_make_string(i_ctx_t *i_ctx_p, ref * pref, da_ptr pda, byte * next)
154
186M
{
155
186M
    uint size = (pda->next = next) - pda->base;
156
186M
    int code = dynamic_resize(pda, size);
157
158
186M
    if (code < 0)
159
0
        return code;
160
186M
    make_tasv_new(pref, t_string,
161
186M
                  a_all | imemory_space((gs_ref_memory_t *) pda->memory),
162
186M
                  size, bytes, pda->base);
163
186M
    return 0;
164
186M
}
165
166
/* ------ Main scanner ------ */
167
168
/* GC procedures */
169
static
170
CLEAR_MARKS_PROC(scanner_clear_marks)
171
476
{
172
476
    scanner_state *const ssptr = vptr;
173
174
476
    r_clear_attrs(&ssptr->s_file, l_mark);
175
476
    r_clear_attrs(&ssptr->s_ss.binary.bin_array, l_mark);
176
476
    r_clear_attrs(&ssptr->s_error.object, l_mark);
177
476
}
178
static
179
1.54k
ENUM_PTRS_WITH(scanner_enum_ptrs, scanner_state *ssptr) return 0;
180
386
case 0:
181
386
    ENUM_RETURN_REF(&ssptr->s_file);
182
386
case 1:
183
386
    ENUM_RETURN_REF(&ssptr->s_error.object);
184
386
case 2:
185
386
    if (ssptr->s_scan_type == scanning_none ||
186
20
        !ssptr->s_da.is_dynamic
187
386
        )
188
366
        ENUM_RETURN(0);
189
20
    return ENUM_STRING2(ssptr->s_da.base, da_size(&ssptr->s_da));
190
386
case 3:
191
386
    if (ssptr->s_scan_type != scanning_binary)
192
386
        return 0;
193
1.54k
    ENUM_RETURN_REF(&ssptr->s_ss.binary.bin_array);
194
1.54k
ENUM_PTRS_END
195
386
static RELOC_PTRS_WITH(scanner_reloc_ptrs, scanner_state *ssptr)
196
386
{
197
386
    RELOC_REF_VAR(ssptr->s_file);
198
386
    r_clear_attrs(&ssptr->s_file, l_mark);
199
386
    if (ssptr->s_scan_type != scanning_none && ssptr->s_da.is_dynamic) {
200
20
        gs_string sda;
201
202
20
        sda.data = ssptr->s_da.base;
203
20
        sda.size = da_size(&ssptr->s_da);
204
20
        RELOC_STRING_VAR(sda);
205
20
        ssptr->s_da.limit = sda.data + sda.size;
206
20
        ssptr->s_da.next = sda.data + (ssptr->s_da.next - ssptr->s_da.base);
207
20
        ssptr->s_da.base = sda.data;
208
20
    }
209
386
    if (ssptr->s_scan_type == scanning_binary) {
210
0
        RELOC_REF_VAR(ssptr->s_ss.binary.bin_array);
211
0
        r_clear_attrs(&ssptr->s_ss.binary.bin_array, l_mark);
212
0
    }
213
386
    RELOC_REF_VAR(ssptr->s_error.object);
214
386
    r_clear_attrs(&ssptr->s_error.object, l_mark);
215
386
}
216
386
RELOC_PTRS_END
217
/* Structure type */
218
public_st_scanner_state_dynamic();
219
220
/* Initialize a scanner. */
221
void
222
gs_scanner_init_options(scanner_state *sstate, const ref *fop, int options)
223
6.62G
{
224
6.62G
    ref_assign(&sstate->s_file, fop);
225
6.62G
    sstate->s_scan_type = scanning_none;
226
6.62G
    sstate->s_pstack = 0;
227
6.62G
    sstate->s_options = options;
228
6.62G
    SCAN_INIT_ERROR(sstate);
229
6.62G
}
230
void gs_scanner_init_stream_options(scanner_state *sstate, stream *s,
231
                                 int options)
232
3.07M
{
233
    /*
234
     * The file 'object' will never be accessed, but it must be in correct
235
     * form for the GC.
236
     */
237
3.07M
    ref fobj;
238
239
3.07M
    make_file(&fobj, a_read, 0, s);
240
3.07M
    gs_scanner_init_options(sstate, &fobj, options);
241
3.07M
}
242
243
/*
244
 * Return the "error object" to be stored in $error.command instead of
245
 * --token--, if any, or <0 if no special error object is available.
246
 */
247
int
248
gs_scanner_error_object(i_ctx_t *i_ctx_p, const scanner_state *pstate,
249
                     ref *pseo)
250
20.7k
{
251
20.7k
    if (!r_has_type(&pstate->s_error.object, t__invalid)) {
252
93
        ref_assign(pseo, &pstate->s_error.object);
253
93
        return 0;
254
93
    }
255
20.6k
    if (pstate->s_error.string[0]) {
256
6.95k
        int len = strlen(pstate->s_error.string);
257
258
6.95k
        if (pstate->s_error.is_name) {
259
187
            int code = name_ref(imemory, (const byte *)pstate->s_error.string, len, pseo, 1);
260
261
187
            if (code < 0)
262
0
                return code;
263
187
            r_set_attrs(pseo, a_executable); /* Adobe compatibility */
264
187
            return 0;
265
6.76k
        } else {
266
6.76k
            byte *estr = ialloc_string(len, "gs_scanner_error_object");
267
268
6.76k
            if (estr == 0)
269
0
                return -1;              /* VMerror */
270
6.76k
            memcpy(estr, (const byte *)pstate->s_error.string, len);
271
6.76k
            make_string(pseo, a_all | icurrent_space, len, estr);
272
6.76k
            return 0;
273
6.76k
        }
274
6.95k
    }
275
13.7k
    return -1;                  /* no error object */
276
20.6k
}
277
278
/* Handle a scan_Refill return from gs_scan_token. */
279
/* This may return o_push_estack, 0 (meaning just call gs_scan_token */
280
/* again), or an error code. */
281
int
282
gs_scan_handle_refill(i_ctx_t *i_ctx_p, scanner_state * sstate,
283
                   bool save, op_proc_t cont)
284
2.20M
{
285
2.20M
    const ref *const fop = &sstate->s_file;
286
2.20M
    stream *s = fptr(fop);
287
2.20M
    uint avail = sbufavailable(s);
288
2.20M
    int status;
289
290
2.20M
    if (s->end_status == EOFC) {
291
        /* More data needed, but none available, so this is a syntax error. */
292
867
        return_error(gs_error_syntaxerror);
293
867
    }
294
2.20M
    status = s_process_read_buf(s);
295
2.20M
    if (sbufavailable(s) > avail)
296
308k
        return 0;
297
1.89M
    if (status == 0)
298
1.89M
        status = s->end_status;
299
1.89M
    switch (status) {
300
985
        case EOFC:
301
            /* We just discovered that we're at EOF. */
302
            /* Let the caller find this out. */
303
985
            return 0;
304
32
        case ERRC:
305
32
            return_error(gs_error_ioerror);
306
0
        case INTC:
307
1.89M
        case CALLC:
308
1.89M
            {
309
1.89M
                ref rstate[1];
310
1.89M
                scanner_state *pstate;
311
312
1.89M
                if (save) {
313
1.73M
                    pstate = (scanner_state *)
314
1.73M
                        ialloc_struct(scanner_state_dynamic, &st_scanner_state_dynamic,
315
1.73M
                                      "gs_scan_handle_refill");
316
1.73M
                    if (pstate == 0)
317
0
                        return_error(gs_error_VMerror);
318
1.73M
                    ((scanner_state_dynamic *)pstate)->mem = imemory;
319
1.73M
                    *pstate = *sstate;
320
1.73M
                } else
321
159k
                    pstate = sstate;
322
1.89M
                make_istruct(&rstate[0], 0, pstate);
323
1.89M
                return s_handle_read_exception(i_ctx_p, status, fop,
324
1.89M
                                               rstate, 1, cont);
325
1.89M
            }
326
1.89M
    }
327
    /* No more data available, but no exception. */
328
    /* A filter is consuming headers but returns nothing. */
329
1.81k
    return 0;
330
1.89M
}
331
332
/*
333
 * Handle a comment.  The 'saved' argument is needed only for
334
 * tracing printout.
335
 */
336
static int
337
scan_comment(i_ctx_t *i_ctx_p, ref *pref, scanner_state *pstate,
338
             const byte * base, const byte * end, bool saved)
339
3.71M
{
340
3.71M
    uint len = (uint) (end - base);
341
3.71M
    int code;
342
#ifdef DEBUG
343
    const char *sstr = (saved ? ">" : "");
344
#endif
345
346
3.71M
    if (len > 1 && (base[1] == '%' || base[1] == '!')) {
347
        /* Process as a DSC comment if requested. */
348
#ifdef DEBUG
349
        if (gs_debug_c('%')) {
350
            dmlprintf2(imemory, "[%%%%%s%c]", sstr, (len >= 3 ? '+' : '-'));
351
            debug_print_string(imemory, base, len);
352
            dmputs(imemory, "\n");
353
        }
354
#endif
355
1.34M
        if (pstate->s_options & SCAN_PROCESS_DSC_COMMENTS) {
356
1.31M
            code = scan_DSC_Comment;
357
1.31M
            goto comment;
358
1.31M
        }
359
        /* Treat as an ordinary comment. */
360
1.34M
    }
361
#ifdef DEBUG
362
    else {
363
        if (gs_debug_c('%')) {
364
            dmlprintf2(imemory, "[%% %s%c]", sstr, (len >= 2 ? '+' : '-'));
365
            debug_print_string(imemory, base, len);
366
            dmputs(imemory, "\n");
367
        }
368
    }
369
#endif
370
2.40M
    if (pstate->s_options & SCAN_PROCESS_COMMENTS) {
371
0
        code = scan_Comment;
372
0
        goto comment;
373
0
    }
374
2.40M
    return 0;
375
1.31M
 comment:
376
1.31M
    {
377
1.31M
        byte *cstr = ialloc_string(len, "scan_comment");
378
379
1.31M
        if (cstr == 0)
380
0
            return_error(gs_error_VMerror);
381
1.31M
        memcpy(cstr, base, len);
382
1.31M
        make_string(pref, a_all | icurrent_space, len, cstr);
383
1.31M
    }
384
0
    return code;
385
1.31M
}
386
387
/* Read a token from a string. */
388
/* Update the string if succesful. */
389
/* Store the error object in i_ctx_p->error_object if not. */
390
int
391
gs_scan_string_token_options(i_ctx_t *i_ctx_p, ref * pstr, ref * pref,
392
                             int options)
393
2.03M
{
394
2.03M
    stream st;
395
2.03M
    stream *s = &st;
396
2.03M
    scanner_state state;
397
2.03M
    int code;
398
399
2.03M
    if (!r_has_attr(pstr, a_read))
400
0
        return_error(gs_error_invalidaccess);
401
2.03M
    s_init(s, NULL);
402
2.03M
    sread_string(s, pstr->value.bytes, r_size(pstr));
403
2.03M
    gs_scanner_init_stream_options(&state, s, options | SCAN_FROM_STRING);
404
2.03M
    switch (code = gs_scan_token(i_ctx_p, pref, &state)) {
405
18
        default:                /* error or comment */
406
18
            if (code < 0)
407
18
                break;
408
            /* falls through */
409
2.03M
        case 0:         /* read a token */
410
2.03M
        case scan_BOS:
411
2.03M
            {
412
2.03M
                uint pos = stell(s);
413
414
2.03M
                pstr->value.bytes += pos;
415
2.03M
                r_dec_size(pstr, pos);
416
2.03M
            }
417
2.03M
            break;
418
0
        case scan_Refill:       /* error */
419
0
            code = gs_note_error(gs_error_syntaxerror);
420
143
        case scan_EOF:
421
143
            break;
422
2.03M
    }
423
2.03M
    if (code < 0)
424
18
        gs_scanner_error_object(i_ctx_p, &state, &i_ctx_p->error_object);
425
2.03M
    return code;
426
2.03M
}
427
428
/*
429
 * Read a token from a stream.  Return 0 if an ordinary token was read,
430
 * >0 for special situations (see iscan.h).
431
 * If the token required a terminating character (i.e., was a name or
432
 * number) and the next character was whitespace, read and discard
433
 * that character.  Note that the state is relevant for gs_error_VMerror
434
 * as well as for scan_Refill.
435
 */
436
int
437
gs_scan_token(i_ctx_t *i_ctx_p, ref * pref, scanner_state * pstate) /* lgtm [cpp/use-of-goto] */
438
6.62G
{
439
6.62G
    stream *const s = pstate->s_file.value.pfile;
440
6.62G
    ref *myref = pref;
441
6.62G
    int retcode = 0;
442
6.62G
    int c;
443
444
6.62G
    s_declare_inline(s, sptr, endptr);
445
6.62G
    const byte *newptr;
446
6.62G
    byte *daptr;
447
448
6.62G
#define sreturn(code)\
449
6.62G
  { retcode = gs_note_error(code); goto sret; }
450
6.62G
#define if_not_spush1()\
451
6.96G
  if ( osp < ostop ) osp++;\
452
6.96G
  else if ( (retcode = ref_stack_push(&o_stack, 1)) >= 0 )\
453
46.9k
    ;\
454
46.9k
  else
455
6.62G
#define spop1()\
456
6.62G
  if ( osp >= osbot ) osp--;\
457
228M
  else ref_stack_pop(&o_stack, 1)
458
6.62G
    int max_name_ctype =
459
6.62G
        ((ref_binary_object_format.value.intval != 0 && level2_enabled)? ctype_name : ctype_btoken);
460
461
6.62G
#define scan_sign(sign, ptr)\
462
6.62G
  switch ( *ptr ) {\
463
4.15M
    case '-': sign = -1; ptr++; break;\
464
7.82k
    case '+': sign = 1; ptr++; break;\
465
1.93G
    default: sign = 0;\
466
1.94G
  }
467
6.62G
#define refill2_back(styp,nback)\
468
6.62G
  BEGIN sptr -= nback; sstate.s_scan_type = styp; goto pause; END
469
6.62G
#define ensure2_back(styp,nback)\
470
6.62G
  if ( sptr >= endptr ) refill2_back(styp,nback)
471
6.62G
#define ensure2(styp) ensure2_back(styp, 1)
472
6.62G
#define refill2(styp) refill2_back(styp, 1)
473
6.62G
    byte s1[2];
474
6.62G
    const byte *const decoder = scan_char_decoder;
475
6.62G
    int status;
476
6.62G
    int sign;
477
6.62G
    const bool check_only = (pstate->s_options & SCAN_CHECK_ONLY) != 0;
478
6.62G
    const bool PDFScanRules = (i_ctx_p->scanner_options & SCAN_PDF_RULES) != 0;
479
    /*
480
     * The following is a hack so that ^D will be self-delimiting in PS files
481
     * (to compensate for bugs in some PostScript-generating applications)
482
     * but not in strings (to match CPSI on the CET) or PDF.
483
     */
484
6.62G
    const int ctrld = (pstate->s_options & SCAN_FROM_STRING ||
485
6.62G
                      PDFScanRules ? 0x04 : 0xffff);
486
6.62G
    scanner_state sstate;
487
488
6.62G
    sptr = endptr = NULL; /* Quiet compiler */
489
6.62G
    if (pstate->s_pstack != 0) {
490
238k
        if_not_spush1()
491
0
            return retcode;
492
238k
        myref = osp;
493
238k
    }
494
    /* Check whether we are resuming after an interruption. */
495
6.62G
    if (pstate->s_scan_type != scanning_none) {
496
885k
        sstate = *pstate;
497
885k
        if (!sstate.s_da.is_dynamic && sstate.s_da.base != sstate.s_da.buf) {
498
            /* The sstate.s_da contains some self-referencing pointers. */
499
            /* Fix them up now. */
500
288
            uint next = sstate.s_da.next - sstate.s_da.base;
501
288
            uint limit = sstate.s_da.limit - sstate.s_da.base;
502
503
288
            sstate.s_da.base = sstate.s_da.buf;
504
288
            sstate.s_da.next = sstate.s_da.buf + next;
505
288
            sstate.s_da.limit = sstate.s_da.buf + limit;
506
288
        }
507
885k
        daptr = sstate.s_da.next;
508
885k
        switch (sstate.s_scan_type) {
509
24.6k
            case scanning_binary:
510
24.6k
                retcode = (*sstate.s_ss.binary.cont)
511
24.6k
                    (i_ctx_p, myref, &sstate);
512
24.6k
                s_begin_inline(s, sptr, endptr);
513
24.6k
                if (retcode == scan_Refill)
514
24.4k
                    goto pause;
515
236
                goto sret;
516
236
            case scanning_comment:
517
0
                s_begin_inline(s, sptr, endptr);
518
0
                goto cont_comment;
519
861k
            case scanning_name:
520
861k
                goto cont_name;
521
0
            case scanning_string:
522
0
                goto cont_string;
523
0
            default:
524
0
                return_error(gs_error_Fatal);
525
885k
        }
526
885k
    }
527
6.62G
    else {
528
        /* We *may* use these in the event of returning to this function after
529
         * a interruption, but not every code path below sets them. Set them
530
         * to sane values here for safety. We can write the contents of sstate
531
         * (back) to pstate before returning.
532
         */
533
6.62G
        sstate.s_da.base = sstate.s_da.next = &(sstate.s_da.buf[0]);
534
6.62G
        sstate.s_da.limit = sstate.s_da.next;
535
6.62G
        sstate.s_da.is_dynamic = false;
536
6.62G
    }
537
    /* Fetch any state variables that are relevant even if */
538
    /* sstate.s_scan_type == scanning_none. */
539
6.62G
    sstate.s_pstack = pstate->s_pstack;
540
6.62G
    sstate.s_pdepth = pstate->s_pdepth;
541
6.62G
    ref_assign(&sstate.s_file, &pstate->s_file);
542
6.62G
    sstate.s_options = pstate->s_options;
543
6.62G
    SCAN_INIT_ERROR(&sstate);
544
6.62G
    s_begin_inline(s, sptr, endptr);
545
    /*
546
     * Loop invariants:
547
     *      If sstate.s_pstack != 0, myref = osp, and *osp is a valid slot.
548
     */
549
13.4G
  top:c = sgetc_inline(s, sptr, endptr);
550
13.4G
    if_debug1m('S', imemory, (c >= 32 && c <= 126 ? "`%c'" : c >= 0 ? "`\\%03o'" : "`%d'"), c);
551
13.4G
    switch (c) {
552
41.2M
        case ' ':
553
41.4M
        case '\f':
554
41.9M
        case '\t':
555
42.1M
        case char_CR:
556
45.0M
        case char_EOL:
557
51.7M
        case char_NULL:
558
51.7M
            goto top;
559
870k
        case 0x04:              /* see ctrld above */
560
870k
            if (c == ctrld)     /* treat as ordinary name char */
561
5
                goto begin_name;
562
            /* fall through */
563
724M
        case '[':
564
1.42G
        case ']':
565
1.42G
            s1[0] = (byte) c;
566
1.42G
            retcode = name_ref(imemory, s1, 1, myref, 1);       /* can't fail */
567
1.42G
            r_set_attrs(myref, a_executable);
568
1.42G
            break;
569
14.0M
        case '<':
570
14.0M
            if (level2_enabled) {
571
12.8M
                ensure2(scanning_none);
572
12.8M
                c = sgetc_inline(s, sptr, endptr);
573
12.8M
                switch (c) {
574
8.34M
                    case '<':
575
8.34M
                        sputback_inline(s, sptr, endptr);
576
8.34M
                        sstate.s_ss.s_name.s_name_type = 0;
577
8.34M
                        sstate.s_ss.s_name.s_try_number = false;
578
8.34M
                        goto try_funny_name;
579
857
                    case '~':
580
857
                        s_A85D_init_inline(&sstate.s_ss.a85d);
581
857
                        sstate.s_ss.st.templat = &s_A85D_template;
582
857
                        sstate.s_ss.a85d.require_eod = true;
583
                        /* If this is an inline ASCII string, interpret it normally, throw an error
584
                         * if it fails rather than ignoring it as PDF (Acrobat) does.
585
                         */
586
857
                        sstate.s_ss.a85d.pdf_rules = false;
587
857
                        goto str;
588
12.8M
                }
589
4.46M
                sputback_inline(s, sptr, endptr);
590
4.46M
            }
591
5.68M
            (void)s_AXD_init_inline(&sstate.s_ss.axd);
592
5.68M
            sstate.s_ss.st.templat = &s_AXD_template;
593
186M
          str:s_end_inline(s, sptr, endptr);
594
186M
            dynamic_init(&sstate.s_da, imemory);
595
187M
          cont_string:for (;;) {
596
187M
                stream_cursor_write w;
597
598
187M
                w.ptr = sstate.s_da.next - 1;
599
187M
                w.limit = sstate.s_da.limit - 1;
600
187M
                status = (*sstate.s_ss.st.templat->process)
601
187M
                    (&sstate.s_ss.st, &s->cursor.r, &w,
602
187M
                     s->end_status == EOFC);
603
187M
                if (!check_only)
604
187M
                    sstate.s_da.next = w.ptr + 1;
605
187M
                switch (status) {
606
985k
                    case 0:
607
985k
                        status = s->end_status;
608
985k
                        if (status < 0) {
609
3.29k
                            if (status == EOFC) {
610
3.29k
                                if (check_only) {
611
0
                                    retcode = scan_Refill;
612
0
                                    sstate.s_scan_type = scanning_string;
613
0
                                    goto suspend;
614
0
                                } else
615
3.29k
                                    sreturn(gs_error_syntaxerror);
616
0
                            }
617
0
                            break;
618
3.29k
                        }
619
981k
                        s_process_read_buf(s);
620
981k
                        continue;
621
9.44k
                    case 1:
622
9.44k
                        if (!check_only) {
623
9.44k
                            retcode = dynamic_grow(&sstate.s_da, sstate.s_da.next, max_string_size);
624
9.44k
                            if (retcode == gs_error_VMerror) {
625
0
                                sstate.s_scan_type = scanning_string;
626
0
                                goto suspend;
627
9.44k
                            } else if (retcode < 0)
628
9.44k
                                sreturn(retcode);
629
9.44k
                        }
630
9.44k
                        continue;
631
187M
                }
632
186M
                break;
633
187M
            }
634
186M
            s_begin_inline(s, sptr, endptr);
635
186M
            switch (status) {
636
1.94k
                default:
637
                    /*case ERRC: */
638
1.94k
                    sreturn(gs_error_syntaxerror);
639
0
                case INTC:
640
0
                case CALLC:
641
0
                    sstate.s_scan_type = scanning_string;
642
0
                    goto pause;
643
186M
                case EOFC:
644
186M
                    ;
645
186M
            }
646
186M
            retcode = dynamic_make_string(i_ctx_p, myref, &sstate.s_da, sstate.s_da.next);
647
186M
            if (retcode < 0) {  /* VMerror */
648
0
                sputback(s);    /* rescan ) */
649
0
                sstate.s_scan_type = scanning_string;
650
0
                goto suspend;
651
0
            }
652
186M
            break;
653
186M
        case '(':
654
180M
            sstate.s_ss.pssd.from_string =
655
180M
                ((pstate->s_options & SCAN_FROM_STRING) != 0) &&
656
5
                !level2_enabled;
657
180M
            s_PSSD_partially_init_inline(&sstate.s_ss.pssd);
658
180M
            sstate.s_ss.st.templat = &s_PSSD_template;
659
180M
            goto str;
660
819M
        case '{':
661
819M
            if (sstate.s_pstack == 0) {  /* outermost procedure */
662
228M
                if_not_spush1() {
663
0
                    sputback_inline(s, sptr, endptr);
664
0
                    sstate.s_scan_type = scanning_none;
665
0
                    goto pause_ret;
666
0
                }
667
228M
                sstate.s_pdepth = ref_stack_count_inline(&o_stack);
668
228M
            }
669
819M
            make_int(osp, sstate.s_pstack);
670
819M
            sstate.s_pstack = ref_stack_count_inline(&o_stack);
671
819M
            if_debug3m('S', imemory, "[S{]d=%d, s=%d->%d\n",
672
819M
                       sstate.s_pdepth, (int)osp->value.intval, sstate.s_pstack);
673
819M
            goto snext;
674
8.21M
        case '>':
675
8.21M
            if (level2_enabled) {
676
8.21M
                ensure2(scanning_none);
677
8.21M
                sstate.s_ss.s_name.s_name_type = 0;
678
8.21M
                sstate.s_ss.s_name.s_try_number = false;
679
8.21M
                goto try_funny_name;
680
8.21M
            }
681
            /* falls through */
682
212
        case ')':
683
212
            sreturn(gs_error_syntaxerror);
684
816M
        case '}':
685
816M
            if (sstate.s_pstack == 0)
686
816M
                sreturn(gs_error_syntaxerror);
687
816M
            osp--;
688
816M
            {
689
816M
                uint size = ref_stack_count_inline(&o_stack) - sstate.s_pstack;
690
816M
                ref arr;
691
692
816M
                if_debug4m('S', imemory, "[S}]d=%"PRIu32", s=%"PRIu32"->%"PRIpsint", c=%"PRIu32"\n",
693
816M
                           sstate.s_pdepth, sstate.s_pstack,
694
816M
                           (sstate.s_pstack == sstate.s_pdepth ? 0 :
695
816M
                           ref_stack_index(&o_stack, size)->value.intval),
696
816M
                           size + sstate.s_pstack);
697
816M
                if (size > max_array_size)
698
816M
                    sreturn(gs_error_limitcheck);
699
816M
                myref = (sstate.s_pstack == sstate.s_pdepth ? pref : &arr);
700
816M
                if (check_only) {
701
0
                    make_empty_array(myref, 0);
702
0
                    ref_stack_pop(&o_stack, size);
703
816M
                } else if (ref_array_packing.value.boolval) {
704
793M
                    retcode = make_packed_array(myref, &o_stack, size,
705
793M
                                                idmemory, "scanner(packed)");
706
793M
                    if (retcode < 0) {  /* must be VMerror */
707
0
                        osp++;
708
0
                        sputback_inline(s, sptr, endptr);
709
0
                        sstate.s_scan_type = scanning_none;
710
0
                        goto pause_ret;
711
0
                    }
712
793M
                    r_set_attrs(myref, a_executable);
713
793M
                } else {
714
22.6M
                    retcode = ialloc_ref_array(myref,
715
22.6M
                                               a_executable + a_all, size,
716
22.6M
                                               "scanner(proc)");
717
22.6M
                    if (retcode < 0) {  /* must be VMerror */
718
0
                        osp++;
719
0
                        sputback_inline(s, sptr, endptr);
720
0
                        sstate.s_scan_type = scanning_none;
721
0
                        goto pause_ret;
722
0
                    }
723
22.6M
                    retcode = ref_stack_store(&o_stack, myref, size, 0, 1,
724
22.6M
                                              false, idmemory, "scanner");
725
22.6M
                    if (retcode < 0) {
726
0
                        ifree_ref_array(myref, "scanner(proc)");
727
0
                        sreturn(retcode);
728
0
                    }
729
22.6M
                    ref_stack_pop(&o_stack, size);
730
22.6M
                }
731
816M
                if (sstate.s_pstack == sstate.s_pdepth) {         /* This was the top-level procedure. */
732
228M
                    spop1();
733
228M
                    sstate.s_pstack = 0;
734
588M
                } else {
735
588M
                    if (osp < osbot)
736
0
                        ref_stack_pop_block(&o_stack);
737
588M
                    sstate.s_pstack = osp->value.intval;
738
588M
                    *osp = arr;
739
588M
                    goto snext;
740
588M
                }
741
816M
            }
742
228M
            break;
743
3.14G
        case '/':
744
            /*
745
             * If the last thing in the input is a '/', don't try to read
746
             * any more data.
747
             */
748
3.14G
            if (sptr >= endptr && s->end_status != EOFC) {
749
278k
                refill2(scanning_none);
750
278k
            }
751
3.14G
            c = sgetc_inline(s, sptr, endptr);
752
3.14G
            if (!PDFScanRules && (c == '/')) {
753
299M
                sstate.s_ss.s_name.s_name_type = 2;
754
299M
                c = sgetc_inline(s, sptr, endptr);
755
299M
            } else
756
2.84G
                sstate.s_ss.s_name.s_name_type = 1;
757
3.14G
            sstate.s_ss.s_name.s_try_number = false;
758
3.14G
            switch (decoder[c]) {
759
348M
                case ctype_name:
760
3.14G
                default:
761
3.14G
                    goto do_name;
762
3.14G
                case ctype_btoken:
763
3.14k
                    if (!(ref_binary_object_format.value.intval != 0 && level2_enabled))
764
0
                        goto do_name;
765
                    /* otherwise, an empty name */
766
3.55k
                case ctype_exception:
767
193k
                case ctype_space:
768
                    /*
769
                     * Amazingly enough, the Adobe implementations don't accept
770
                     * / or // followed by [, ], <<, or >>, so we do the same.
771
                     * (Older versions of our code had a ctype_other case here
772
                     * that handled these specially.)
773
                     */
774
965k
                case ctype_other:
775
965k
                    if (c == ctrld) /* see above */
776
0
                        goto do_name;
777
965k
                    sstate.s_da.base = sstate.s_da.limit = daptr = 0;
778
965k
                    sstate.s_da.is_dynamic = false;
779
965k
                    goto nx;
780
3.14G
            }
781
3.71M
        case '%':
782
3.71M
            {                   /* Scan as much as possible within the buffer. */
783
3.71M
                const byte *base = sptr;
784
3.71M
                const byte *end;
785
786
49.9M
                while (++sptr < endptr)         /* stop 1 char early */
787
49.8M
                    switch (*sptr) {
788
102k
                        case char_CR:
789
102k
                            end = sptr;
790
102k
                            if (sptr[1] == char_EOL)
791
19.6k
                                sptr++;
792
3.68M
                          cend: /* Check for externally processed comments. */
793
3.68M
                            retcode = scan_comment(i_ctx_p, myref, &sstate,
794
3.68M
                                                   base, end, false);
795
3.68M
                            if (retcode != 0)
796
1.30M
                                goto comment;
797
2.38M
                            goto top;
798
3.50M
                        case char_EOL:
799
3.58M
                        case '\f':
800
3.58M
                            end = sptr;
801
3.58M
                            goto cend;
802
49.8M
                    }
803
                /*
804
                 * We got to the end of the buffer while inside a comment.
805
                 * If there is a possibility that we must pass the comment
806
                 * to an external procedure, move what we have collected
807
                 * so far into a private buffer now.
808
                 */
809
28.9k
                --sptr;
810
28.9k
                sstate.s_da.buf[1] = 0;
811
28.9k
                {
812
                    /* Could be an externally processable comment. */
813
28.9k
                    uint len = sptr + 1 - base;
814
28.9k
                    if (len > sizeof(sstate.s_da.buf))
815
10
                        len = sizeof(sstate.s_da.buf);
816
817
28.9k
                    memcpy(sstate.s_da.buf, base, len);
818
28.9k
                    daptr = sstate.s_da.buf + len;
819
28.9k
                }
820
28.9k
                sstate.s_da.base = sstate.s_da.buf;
821
28.9k
                sstate.s_da.is_dynamic = false;
822
28.9k
            }
823
            /* Enter here to continue scanning a comment. */
824
            /* daptr must be set. */
825
4.73M
          cont_comment:for (;;) {
826
4.73M
                switch ((c = sgetc_inline(s, sptr, endptr))) {
827
4.70M
                    default:
828
4.70M
                        if (c < 0)
829
5.65k
                            switch (c) {
830
0
                                case INTC:
831
0
                                case CALLC:
832
0
                                    sstate.s_da.next = daptr;
833
0
                                    sstate.s_scan_type = scanning_comment;
834
0
                                    goto pause;
835
5.65k
                                case EOFC:
836
                                    /*
837
                                     * One would think that an EOF in a comment
838
                                     * should be a syntax error, but there are
839
                                     * quite a number of files that end that way.
840
                                     */
841
5.65k
                                    goto end_comment;
842
1
                                default:
843
1
                                    sreturn(gs_error_syntaxerror);
844
5.65k
                            }
845
4.70M
                        if (daptr < sstate.s_da.buf + max_comment_line)
846
530k
                            *daptr++ = c;
847
4.70M
                        continue;
848
1.99k
                    case char_CR:
849
21.1k
                    case char_EOL:
850
23.2k
                    case '\f':
851
28.9k
                      end_comment:
852
28.9k
                        retcode = scan_comment(i_ctx_p, myref, &sstate,
853
28.9k
                                               sstate.s_da.buf, daptr, true);
854
28.9k
                        if (retcode != 0)
855
15.4k
                            goto comment;
856
13.4k
                        goto top;
857
4.73M
                }
858
4.73M
            }
859
            /*NOTREACHED */
860
1.80M
        case EOFC:
861
1.80M
            if (sstate.s_pstack != 0) {
862
7.55k
                if (check_only)
863
0
                    goto pause;
864
7.55k
                sreturn(gs_error_syntaxerror);
865
0
            }
866
1.79M
            retcode = scan_EOF;
867
1.79M
            break;
868
4
        case ERRC:
869
4
            sreturn(gs_error_ioerror);
870
871
            /* Check for a Level 2 funny name (<< or >>). */
872
            /* c is '<' or '>'.  We already did an ensure2. */
873
16.5M
          try_funny_name:
874
16.5M
            {
875
16.5M
                int c1 = sgetc_inline(s, sptr, endptr);
876
877
16.5M
                if (c1 == c) {
878
16.5M
                    s1[0] = s1[1] = c;
879
16.5M
                    name_ref(imemory, s1, 2, myref, 1); /* can't fail */
880
16.5M
                    goto have_name;
881
16.5M
                }
882
66
                sputback_inline(s, sptr, endptr);
883
66
            }
884
66
            sreturn(gs_error_syntaxerror);
885
886
            /* Handle separately the names that might be a number. */
887
152M
        case '0':
888
1.88G
        case '1':
889
2.04G
        case '2':
890
2.16G
        case '3':
891
2.23G
        case '4':
892
2.26G
        case '5':
893
2.28G
        case '6':
894
2.29G
        case '7':
895
2.31G
        case '8':
896
2.33G
        case '9':
897
2.79G
        case '.':
898
2.79G
            sign = 0;
899
2.85G
    nr:     /*
900
             * Skip a leading sign, if any, by conditionally passing
901
             * sptr + 1 rather than sptr.  Also, if the last character
902
             * in the buffer is a CR, we must stop the scan 1 character
903
             * early, to be sure that we can test for CR+LF within the
904
             * buffer, by passing endptr rather than endptr + 1.
905
             */
906
2.85G
            retcode = scan_number(sptr + (sign & 1),
907
2.85G
                    endptr /*(*endptr == char_CR ? endptr : endptr + 1) */ ,
908
2.85G
                                  sign, myref, &newptr, i_ctx_p->scanner_options);
909
2.85G
            if (retcode == 1 && decoder[newptr[-1]] == ctype_space) {
910
910M
                sptr = newptr - 1;
911
910M
                if (*sptr == char_CR && sptr[1] == char_EOL)
912
1.74k
                    sptr++;
913
910M
                retcode = 0;
914
910M
                ref_mark_new(myref);
915
910M
                break;
916
910M
            }
917
1.94G
            sstate.s_ss.s_name.s_name_type = 0;
918
1.94G
            sstate.s_ss.s_name.s_try_number = true;
919
1.94G
            goto do_name;
920
7.92k
        case '+':
921
7.92k
            sign = 1;
922
7.92k
            goto nr;
923
55.6M
        case '-':
924
55.6M
            sign = -1;
925
55.6M
            if(i_ctx_p->scanner_options & SCAN_PDF_INV_NUM) {
926
0
                const byte *osptr = sptr;
927
0
                do {
928
                    /* This is slightly unpleasant: we have to bounds check the buffer,
929
                       rather than just incrementing the point until we find a non '-' character.
930
                       But we cannot differentiate between multiple '-' characters that
931
                       straddle a buffer boundary, or a token that is only one or more '-' characters.
932
                       Handling this relies on the fact that the Postscript-based PDF interpreter
933
                       always uses the "token" operator to tokenize a stream, thus we can assume
934
                       here that the current buffer contains the entire token. So if we reach
935
                       the end of the buffer without hitting a character taht is not a '-', we'll reset
936
                       the buffer pointer, and retry, treating it as a name object.
937
                     */
938
0
                    if (sptr + 1 > endptr) {
939
0
                        sptr = osptr;
940
0
                        sstate.s_ss.s_name.s_name_type = 0;
941
0
                        sstate.s_ss.s_name.s_try_number = true;
942
0
                        goto do_name;
943
0
                    }
944
0
                    if (*(sptr + 1) == '-') {
945
0
                        sptr++;
946
0
                    } else
947
0
                        break;
948
0
                } while (1);
949
0
            }
950
55.6M
            goto nr;
951
952
            /* Check for a binary object */
953
55.6M
          case 128: case 129: case 130: case 131: case 132: case 133: case 134: case 135:
954
905k
          case 136: case 137: case 138: case 139: case 140: case 141: case 142: case 143:
955
1.62M
          case 144: case 145: case 146: case 147: case 148: case 149: case 150: case 151:
956
1.62M
          case 152: case 153: case 154: case 155: case 156: case 157: case 158: case 159:
957
1.62M
            if ((ref_binary_object_format.value.intval != 0 && level2_enabled)) {
958
1.62M
                s_end_inline(s, sptr, endptr);
959
1.62M
                retcode = scan_binary_token(i_ctx_p, myref, &sstate);
960
1.62M
                s_begin_inline(s, sptr, endptr);
961
1.62M
                if (retcode == scan_Refill)
962
6.22k
                    goto pause;
963
1.62M
                break;
964
1.62M
            }
965
            /* Not a binary object, fall through. */
966
967
            /* The default is a name. */
968
2.73M
        default:
969
2.73M
            if (c < 0) {
970
1.03M
                dynamic_init(&sstate.s_da, name_memory(imemory));        /* sstate.s_da state must be clean */
971
1.03M
                sstate.s_scan_type = scanning_none;
972
1.03M
                goto pause;
973
1.03M
            }
974
            /* Populate the switch with enough cases to force */
975
            /* simple compilers to use a dispatch rather than tests. */
976
1.71M
        case '!':
977
2.48M
        case '"':
978
6.20M
        case '#':
979
24.3M
        case '$':
980
24.7M
        case '&':
981
25.9M
        case '\'':
982
26.2M
        case '*':
983
27.8M
        case ',':
984
72.8M
        case '=':
985
72.9M
        case ':':
986
107M
        case ';':
987
107M
        case '?':
988
107M
        case '@':
989
109M
        case 'A':
990
110M
        case 'B':
991
119M
        case 'C':
992
126M
        case 'D':
993
133M
        case 'E':
994
141M
        case 'F':
995
143M
        case 'G':
996
146M
        case 'H':
997
151M
        case 'I':
998
152M
        case 'J':
999
153M
        case 'K':
1000
159M
        case 'L':
1001
160M
        case 'M':
1002
174M
        case 'N':
1003
179M
        case 'O':
1004
188M
        case 'P':
1005
194M
        case 'Q':
1006
214M
        case 'R':
1007
229M
        case 'S':
1008
240M
        case 'T':
1009
243M
        case 'U':
1010
248M
        case 'V':
1011
250M
        case 'W':
1012
250M
        case 'X':
1013
251M
        case 'Y':
1014
252M
        case 'Z':
1015
252M
        case '\\':
1016
252M
        case '^':
1017
252M
        case '_':
1018
252M
        case '`':
1019
373M
        case 'a':
1020
432M
        case 'b':
1021
674M
        case 'c':
1022
1.24G
        case 'd':
1023
1.77G
        case 'e':
1024
1.89G
        case 'f':
1025
2.12G
        case 'g':
1026
2.12G
        case 'h':
1027
2.68G
        case 'i':
1028
2.68G
        case 'j':
1029
2.73G
        case 'k':
1030
2.83G
        case 'l':
1031
2.90G
        case 'm':
1032
3.01G
        case 'n':
1033
3.05G
        case 'o':
1034
3.54G
        case 'p':
1035
3.54G
        case 'q':
1036
3.71G
        case 'r':
1037
3.94G
        case 's':
1038
4.00G
        case 't':
1039
4.02G
        case 'u':
1040
4.02G
        case 'v':
1041
4.07G
        case 'w':
1042
4.07G
        case 'x':
1043
4.08G
        case 'y':
1044
4.08G
        case 'z':
1045
4.08G
        case '|':
1046
4.08G
        case '~':
1047
4.08G
          begin_name:
1048
            /* Common code for scanning a name. */
1049
            /* sstate.s_ss.s_name.s_try_number and sstate.s_ss.s_name.s_name_type are already set. */
1050
            /* We know c has ctype_name (or maybe ctype_btoken, */
1051
            /* or is ^D) or is a digit. */
1052
4.08G
            sstate.s_ss.s_name.s_name_type = 0;
1053
4.08G
            sstate.s_ss.s_name.s_try_number = false;
1054
9.17G
          do_name:
1055
            /* Try to scan entirely within the stream buffer. */
1056
            /* We stop 1 character early, so we don't switch buffers */
1057
            /* looking ahead if the name is terminated by \r\n. */
1058
9.17G
            sstate.s_da.base = (byte *) sptr;
1059
9.17G
            sstate.s_da.is_dynamic = false;
1060
9.17G
            {
1061
9.17G
                const byte *endp1 = endptr - 1;
1062
1063
69.3G
                do {
1064
69.3G
                    if (sptr >= endp1)  /* stop 1 early! */
1065
11.0M
                        goto dyn_name;
1066
69.3G
                }
1067
69.3G
                while (decoder[*++sptr] <= max_name_ctype || *sptr == ctrld);   /* digit or name */
1068
9.17G
            }
1069
            /* Name ended within the buffer. */
1070
9.16G
            daptr = (byte *) sptr;
1071
9.16G
            c = *sptr;
1072
9.16G
            goto nx;
1073
11.0M
          dyn_name:             /* Name extended past end of buffer. */
1074
11.0M
            s_end_inline(s, sptr, endptr);
1075
            /* Initialize the dynamic area. */
1076
            /* We have to do this before the next */
1077
            /* sgetc, which will overwrite the buffer. */
1078
11.0M
            sstate.s_da.limit = (byte *)++ sptr;
1079
11.0M
            sstate.s_da.memory = name_memory(imemory);
1080
11.0M
            retcode = dynamic_grow(&sstate.s_da, sstate.s_da.limit, name_max_string);
1081
11.0M
            if (retcode < 0) {
1082
29
                dynamic_save(&sstate.s_da);
1083
29
                if (retcode != gs_error_VMerror)
1084
29
                    sreturn(retcode);
1085
0
                sstate.s_scan_type = scanning_name;
1086
0
                goto pause_ret;
1087
29
            }
1088
11.0M
            daptr = sstate.s_da.next;
1089
            /* Enter here to continue scanning a name. */
1090
            /* daptr must be set. */
1091
11.9M
          cont_name:s_begin_inline(s, sptr, endptr);
1092
47.3M
            while (decoder[c = sgetc_inline(s, sptr, endptr)] <= max_name_ctype || c == ctrld) {
1093
35.3M
                if (daptr == sstate.s_da.limit) {
1094
19.9k
                    retcode = dynamic_grow(&sstate.s_da, daptr,
1095
19.9k
                                           name_max_string);
1096
19.9k
                    if (retcode < 0) {
1097
50
                        dynamic_save(&sstate.s_da);
1098
50
                        if (retcode != gs_error_VMerror)
1099
50
                            sreturn(retcode);
1100
0
                        sputback_inline(s, sptr, endptr);
1101
0
                        sstate.s_scan_type = scanning_name;
1102
0
                        goto pause_ret;
1103
50
                    }
1104
19.9k
                    daptr = sstate.s_da.next;
1105
19.9k
                }
1106
35.3M
                *daptr++ = c;
1107
35.3M
            }
1108
9.17G
          nx:switch (decoder[c]) {
1109
5.14G
                case ctype_other:
1110
5.14G
                    if (c == ctrld) /* see above */
1111
0
                        break;
1112
5.14G
                case ctype_btoken:
1113
5.14G
                    sputback_inline(s, sptr, endptr);
1114
5.14G
                    break;
1115
4.02G
                case ctype_space:
1116
                    /* Check for \r\n */
1117
4.02G
                    if (c == char_CR) {
1118
1.98M
                        if (sptr >= endptr) {   /* ensure2 *//* We have to check specially for */
1119
                            /* the case where the very last */
1120
                            /* character of a file is a CR. */
1121
3.03k
                            if (s->end_status != EOFC) {
1122
2.81k
                                sptr--;
1123
2.81k
                                goto pause_name;
1124
2.81k
                            }
1125
1.98M
                        } else if (sptr[1] == char_EOL)
1126
21.3k
                            sptr++;
1127
1.98M
                    }
1128
4.02G
                    break;
1129
4.02G
                case ctype_exception:
1130
5.70M
                    switch (c) {
1131
0
                        case INTC:
1132
858k
                        case CALLC:
1133
858k
                            goto pause_name;
1134
5
                        case ERRC:
1135
5
                            sreturn(gs_error_ioerror);
1136
4.84M
                        case EOFC:
1137
4.84M
                            break;
1138
5.70M
                    }
1139
9.17G
            }
1140
            /* Check for a number */
1141
9.17G
            if (sstate.s_ss.s_name.s_try_number) {
1142
1.94G
                const byte *base = sstate.s_da.base;
1143
1144
1.94G
                scan_sign(sign, base);
1145
1.94G
                retcode = scan_number(base, daptr, sign, myref, &newptr, i_ctx_p->scanner_options);
1146
1.94G
                if (retcode == 1) {
1147
2.98M
                    ref_mark_new(myref);
1148
2.98M
                    retcode = 0;
1149
1.93G
                } else if (retcode != gs_error_syntaxerror) {
1150
1.47G
                    dynamic_free(&sstate.s_da);
1151
1.47G
                    if (sstate.s_ss.s_name.s_name_type == 2)
1152
1.47G
                        sreturn(gs_error_syntaxerror);
1153
1.47G
                    break;      /* might be gs_error_limitcheck */
1154
1.47G
                }
1155
1.94G
            }
1156
7.70G
            if (sstate.s_da.is_dynamic) {        /* We've already allocated the string on the heap. */
1157
7.86M
                uint size = daptr - sstate.s_da.base;
1158
1159
7.86M
                retcode = name_ref(imemory, sstate.s_da.base, size, myref, -1);
1160
7.86M
                if (retcode >= 0) {
1161
7.02M
                    dynamic_free(&sstate.s_da);
1162
7.02M
                } else {
1163
841k
                    retcode = dynamic_resize(&sstate.s_da, size);
1164
841k
                    if (retcode < 0) {  /* VMerror */
1165
0
                        if (c != EOFC)
1166
0
                            sputback_inline(s, sptr, endptr);
1167
0
                        sstate.s_scan_type = scanning_name;
1168
0
                        goto pause_ret;
1169
0
                    }
1170
841k
                    retcode = name_ref(imemory, sstate.s_da.base, size, myref, 2);
1171
841k
                }
1172
7.69G
            } else {
1173
7.69G
                retcode = name_ref(imemory, sstate.s_da.base, (uint) (daptr - sstate.s_da.base),
1174
7.69G
                                   myref, !s->foreign);
1175
7.69G
            }
1176
            /* Done scanning.  Check for preceding /'s. */
1177
7.70G
            if (retcode < 0) {
1178
1
                if (retcode != gs_error_VMerror)
1179
1
                    sreturn(retcode);
1180
0
                if (!sstate.s_da.is_dynamic) {
1181
0
                    sstate.s_da.next = daptr;
1182
0
                    dynamic_save(&sstate.s_da);
1183
0
                }
1184
0
                if (c != EOFC)
1185
0
                    sputback_inline(s, sptr, endptr);
1186
0
                sstate.s_scan_type = scanning_name;
1187
0
                goto pause_ret;
1188
1
            }
1189
7.71G
          have_name:switch (sstate.s_ss.s_name.s_name_type) {
1190
4.57G
                case 0: /* ordinary executable name */
1191
4.57G
                    if (r_has_type(myref, t_name))      /* i.e., not a number */
1192
4.57G
                        r_set_attrs(myref, a_executable);
1193
7.41G
                case 1: /* quoted name */
1194
7.41G
                    break;
1195
299M
                case 2: /* immediate lookup */
1196
299M
                    {
1197
299M
                        ref *pvalue;
1198
1199
299M
                        if (!r_has_type(myref, t_name) ||
1200
299M
                            (pvalue = dict_find_name(myref)) == 0) {
1201
93
                            ref_assign(&sstate.s_error.object, myref);
1202
93
                            r_set_attrs(&sstate.s_error.object,
1203
93
                                a_executable); /* Adobe compatibility */
1204
93
                            sreturn(gs_error_undefined);
1205
0
                        }
1206
299M
                        if (sstate.s_pstack != 0 &&
1207
260M
                            r_space(pvalue) > ialloc_space(idmemory)
1208
299M
                            )
1209
299M
                            sreturn(gs_error_invalidaccess);
1210
299M
                        ref_assign_new(myref, pvalue);
1211
299M
                    }
1212
7.71G
            }
1213
13.4G
    }
1214
11.9G
  sret:if (retcode < 0) {
1215
20.7k
        s_end_inline(s, sptr, endptr);
1216
20.7k
        pstate->s_error = sstate.s_error;
1217
20.7k
        if (sstate.s_pstack != 0) {
1218
9.07k
            if (retcode == gs_error_undefined)
1219
58
                *pref = *osp;   /* return undefined name as error token */
1220
9.07k
            ref_stack_pop(&o_stack,
1221
9.07k
                          ref_stack_count(&o_stack) - (sstate.s_pdepth - 1));
1222
9.07k
        }
1223
20.7k
        return retcode;
1224
20.7k
    }
1225
    /* If we are at the top level, return the object, */
1226
    /* otherwise keep going. */
1227
11.9G
    if (sstate.s_pstack == 0) {
1228
6.62G
        s_end_inline(s, sptr, endptr);
1229
6.62G
        return retcode;
1230
6.62G
    }
1231
6.73G
  snext:if_not_spush1() {
1232
11
        s_end_inline(s, sptr, endptr);
1233
11
        sstate.s_scan_type = scanning_none;
1234
11
        goto save;
1235
11
    }
1236
6.73G
    myref = osp;
1237
6.73G
    goto top;
1238
1239
    /* Pause for an interrupt or callout. */
1240
861k
  pause_name:
1241
    /* If we're still scanning within the stream buffer, */
1242
    /* move the characters to the private buffer (sstate.s_da.buf) now. */
1243
861k
    sstate.s_da.next = daptr;
1244
861k
    dynamic_save(&sstate.s_da);
1245
861k
    sstate.s_scan_type = scanning_name;
1246
2.20M
  pause:
1247
2.20M
    retcode = scan_Refill;
1248
2.20M
  pause_ret:
1249
2.20M
    s_end_inline(s, sptr, endptr);
1250
2.20M
  suspend:
1251
2.20M
    if (sstate.s_pstack != 0)
1252
12.7k
        osp--;                  /* myref */
1253
3.52M
  save:
1254
3.52M
    *pstate = sstate;
1255
3.52M
    return retcode;
1256
1257
    /* Handle a scanned comment. */
1258
1.31M
 comment:
1259
1.31M
    if (retcode < 0)
1260
0
        goto sret;
1261
1.31M
    s_end_inline(s, sptr, endptr);
1262
1.31M
    sstate.s_scan_type = scanning_none;
1263
1.31M
    goto save;
1264
1.31M
}