Coverage Report

Created: 2026-08-08 08:00

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/ghostpdl/psi/iscan.c
Line
Count
Source
1
/* Copyright (C) 2001-2023 Artifex Software, Inc.
2
   All Rights Reserved.
3
4
   This software is provided AS-IS with no warranty, either express or
5
   implied.
6
7
   This software is distributed under license and may not be copied,
8
   modified or distributed except as expressly authorized under the terms
9
   of the license contained in the file LICENSE in this distribution.
10
11
   Refer to licensing information at http://www.artifex.com or contact
12
   Artifex Software, Inc.,  39 Mesa Street, Suite 108A, San Francisco,
13
   CA 94129, USA, for further information.
14
*/
15
16
17
/* Token scanner for Ghostscript interpreter */
18
#include "ghost.h"
19
#include "memory_.h"
20
#include "string_.h"
21
#include "stream.h"
22
#include "ierrors.h"
23
#include "btoken.h"             /* for ref_binary_object_format */
24
#include "files.h"              /* for fptr */
25
#include "ialloc.h"
26
#include "idict.h"              /* for //name lookup */
27
#include "dstack.h"             /* ditto */
28
#include "ilevel.h"
29
#include "iname.h"
30
#include "ipacked.h"
31
#include "iparray.h"
32
#include "strimpl.h"            /* for string decoding */
33
#include "sa85d.h"              /* ditto */
34
#include "sfilter.h"            /* ditto */
35
#include "ostack.h"             /* for accumulating proc bodies; */
36
                                        /* must precede iscan.h */
37
#include "iscan.h"              /* defines interface */
38
#include "iscanbin.h"
39
#include "iscannum.h"
40
#include "istream.h"
41
#include "istruct.h"            /* for RELOC_REF_VAR */
42
#include "iutil.h"
43
#include "ivmspace.h"
44
#include "store.h"
45
#include "scanchar.h"
46
47
/*
48
 * Level 2 includes some changes in the scanner:
49
 *      - \ is always recognized in strings, regardless of the data source;
50
 *      - << and >> are legal tokens;
51
 *      - <~ introduces an ASCII85 encoded string (terminated by ~>);
52
 *      - Character codes above 127 introduce binary objects.
53
 * We explicitly enable or disable these changes based on level2_enabled.
54
 */
55
56
/* ------ Dynamic strings ------ */
57
58
/* Begin collecting a dynamically allocated string. */
59
static inline void
60
dynamic_init(da_ptr pda, gs_memory_t *mem)
61
165M
{
62
165M
    pda->is_dynamic = false;
63
165M
    pda->limit = pda->buf + sizeof(pda->buf);
64
165M
    pda->next = pda->base = pda->buf;
65
165M
    pda->memory = mem;
66
165M
}
67
68
/* Free a dynamic string. */
69
static void
70
dynamic_free(da_ptr pda)
71
1.30G
{
72
1.30G
    if (pda->is_dynamic)
73
8.32M
        gs_free_string(pda->memory, pda->base, da_size(pda), "scanner");
74
1.30G
}
75
76
/* Resize a dynamic string. */
77
/* If the allocation fails, return gs_error_VMerror; otherwise, return 0. */
78
static int
79
dynamic_resize(da_ptr pda, uint new_size)
80
175M
{
81
175M
    uint old_size = da_size(pda);
82
175M
    uint pos = pda->next - pda->base;
83
175M
    gs_memory_t *mem = pda->memory;
84
175M
    byte *base;
85
86
175M
    if (pda->is_dynamic) {
87
1.37M
        base = gs_resize_string(mem, pda->base, old_size,
88
1.37M
                                new_size, "scanner");
89
1.37M
        if (base == 0)
90
0
            return_error(gs_error_VMerror);
91
174M
    } else {                    /* switching from static to dynamic */
92
174M
        base = gs_alloc_string(mem, new_size, "scanner");
93
174M
        if (base == 0)
94
0
            return_error(gs_error_VMerror);
95
174M
        memcpy(base, pda->base, min(old_size, new_size));
96
174M
        pda->is_dynamic = true;
97
174M
    }
98
175M
    pda->base = base;
99
175M
    pda->next = base + pos;
100
175M
    pda->limit = base + new_size;
101
175M
    return 0;
102
175M
}
103
104
/* Grow a dynamic string. */
105
/* Return 0 if the allocation failed, the new 'next' ptr if OK. */
106
/* Return 0 or an error code, updating pda->next to point to the first */
107
/* available byte after growing. */
108
static int
109
dynamic_grow(da_ptr pda, byte * next, uint max_size)
110
9.70M
{
111
9.70M
    uint old_size = da_size(pda);
112
9.70M
    uint new_size = (old_size < 10 ? 20 :
113
9.70M
                     old_size >= (max_size >> 1) ? max_size :
114
2.25M
                     old_size << 1);
115
9.70M
    int code;
116
117
9.70M
    pda->next = next;
118
9.70M
    if (old_size >= max_size)
119
66
        return_error(gs_error_limitcheck);
120
9.70M
    while ((code = dynamic_resize(pda, new_size)) < 0) {
121
        /* Try trimming down the requested new size. */
122
0
        new_size -= (new_size - old_size + 1) >> 1;
123
0
        if (new_size <= old_size)
124
0
                break;
125
0
    }
126
9.70M
    return code;
127
9.70M
}
128
129
/* Ensure that a dynamic string is either on the heap or in the */
130
/* private buffer. */
131
static void
132
dynamic_save(da_ptr pda)
133
760k
{
134
760k
    if (!pda->is_dynamic && pda->base != pda->buf) {
135
24
        int len = da_size(pda);
136
137
24
        if (len > sizeof(pda->buf))
138
0
            len = sizeof(pda->buf);
139
        /* This can happen if we get a /<CR> at the end of a buffer, and the file is
140
         * not at EOF. In this case 'len' will be zero so we don't actually copy any
141
         * bytes. So this is safe on current C run-time libraries, but it's probably
142
         * best to avoid it. Coverity ID C382008
143
         */
144
24
        if (pda->base != NULL)
145
20
            memcpy(pda->buf, pda->base, len);
146
24
        pda->next = pda->buf + len;
147
24
        pda->base = pda->buf;
148
24
    }
149
760k
}
150
151
/* Finish collecting a dynamic string. */
152
static int
153
dynamic_make_string(i_ctx_t *i_ctx_p, ref * pref, da_ptr pda, byte * next)
154
164M
{
155
164M
    uint size = (pda->next = next) - pda->base;
156
164M
    int code = dynamic_resize(pda, size);
157
158
164M
    if (code < 0)
159
0
        return code;
160
164M
    make_tasv_new(pref, t_string,
161
164M
                  a_all | imemory_space((gs_ref_memory_t *) pda->memory),
162
164M
                  size, bytes, pda->base);
163
164M
    return 0;
164
164M
}
165
166
/* ------ Main scanner ------ */
167
168
/* GC procedures */
169
static
170
CLEAR_MARKS_PROC(scanner_clear_marks)
171
325
{
172
325
    scanner_state *const ssptr = vptr;
173
174
325
    r_clear_attrs(&ssptr->s_file, l_mark);
175
325
    r_clear_attrs(&ssptr->s_ss.binary.bin_array, l_mark);
176
325
    r_clear_attrs(&ssptr->s_error.object, l_mark);
177
325
}
178
static
179
1.04k
ENUM_PTRS_WITH(scanner_enum_ptrs, scanner_state *ssptr) return 0;
180
262
case 0:
181
262
    ENUM_RETURN_REF(&ssptr->s_file);
182
262
case 1:
183
262
    ENUM_RETURN_REF(&ssptr->s_error.object);
184
262
case 2:
185
262
    if (ssptr->s_scan_type == scanning_none ||
186
14
        !ssptr->s_da.is_dynamic
187
262
        )
188
248
        ENUM_RETURN(0);
189
14
    return ENUM_STRING2(ssptr->s_da.base, da_size(&ssptr->s_da));
190
262
case 3:
191
262
    if (ssptr->s_scan_type != scanning_binary)
192
262
        return 0;
193
1.04k
    ENUM_RETURN_REF(&ssptr->s_ss.binary.bin_array);
194
1.04k
ENUM_PTRS_END
195
262
static RELOC_PTRS_WITH(scanner_reloc_ptrs, scanner_state *ssptr)
196
262
{
197
262
    RELOC_REF_VAR(ssptr->s_file);
198
262
    r_clear_attrs(&ssptr->s_file, l_mark);
199
262
    if (ssptr->s_scan_type != scanning_none && ssptr->s_da.is_dynamic) {
200
14
        gs_string sda;
201
202
14
        sda.data = ssptr->s_da.base;
203
14
        sda.size = da_size(&ssptr->s_da);
204
14
        RELOC_STRING_VAR(sda);
205
14
        ssptr->s_da.limit = sda.data + sda.size;
206
14
        ssptr->s_da.next = sda.data + (ssptr->s_da.next - ssptr->s_da.base);
207
14
        ssptr->s_da.base = sda.data;
208
14
    }
209
262
    if (ssptr->s_scan_type == scanning_binary) {
210
0
        RELOC_REF_VAR(ssptr->s_ss.binary.bin_array);
211
0
        r_clear_attrs(&ssptr->s_ss.binary.bin_array, l_mark);
212
0
    }
213
262
    RELOC_REF_VAR(ssptr->s_error.object);
214
262
    r_clear_attrs(&ssptr->s_error.object, l_mark);
215
262
}
216
262
RELOC_PTRS_END
217
/* Structure type */
218
public_st_scanner_state_dynamic();
219
220
/* Initialize a scanner. */
221
void
222
gs_scanner_init_options(scanner_state *sstate, const ref *fop, int options)
223
5.76G
{
224
5.76G
    ref_assign(&sstate->s_file, fop);
225
5.76G
    sstate->s_scan_type = scanning_none;
226
5.76G
    sstate->s_pstack = 0;
227
5.76G
    sstate->s_options = options;
228
5.76G
    SCAN_INIT_ERROR(sstate);
229
5.76G
}
230
void gs_scanner_init_stream_options(scanner_state *sstate, stream *s,
231
                                 int options)
232
2.57M
{
233
    /*
234
     * The file 'object' will never be accessed, but it must be in correct
235
     * form for the GC.
236
     */
237
2.57M
    ref fobj;
238
239
2.57M
    make_file(&fobj, a_read, 0, s);
240
2.57M
    gs_scanner_init_options(sstate, &fobj, options);
241
2.57M
}
242
243
/*
244
 * Return the "error object" to be stored in $error.command instead of
245
 * --token--, if any, or <0 if no special error object is available.
246
 */
247
int
248
gs_scanner_error_object(i_ctx_t *i_ctx_p, const scanner_state *pstate,
249
                     ref *pseo)
250
17.1k
{
251
17.1k
    if (!r_has_type(&pstate->s_error.object, t__invalid)) {
252
77
        ref_assign(pseo, &pstate->s_error.object);
253
77
        return 0;
254
77
    }
255
17.0k
    if (pstate->s_error.string[0]) {
256
5.55k
        int len = strlen(pstate->s_error.string);
257
258
5.55k
        if (pstate->s_error.is_name) {
259
143
            int code = name_ref(imemory, (const byte *)pstate->s_error.string, len, pseo, 1);
260
261
143
            if (code < 0)
262
0
                return code;
263
143
            r_set_attrs(pseo, a_executable); /* Adobe compatibility */
264
143
            return 0;
265
5.40k
        } else {
266
5.40k
            byte *estr = ialloc_string(len, "gs_scanner_error_object");
267
268
5.40k
            if (estr == 0)
269
0
                return -1;              /* VMerror */
270
5.40k
            memcpy(estr, (const byte *)pstate->s_error.string, len);
271
5.40k
            make_string(pseo, a_all | icurrent_space, len, estr);
272
5.40k
            return 0;
273
5.40k
        }
274
5.55k
    }
275
11.4k
    return -1;                  /* no error object */
276
17.0k
}
277
278
/* Handle a scan_Refill return from gs_scan_token. */
279
/* This may return o_push_estack, 0 (meaning just call gs_scan_token */
280
/* again), or an error code. */
281
int
282
gs_scan_handle_refill(i_ctx_t *i_ctx_p, scanner_state * sstate,
283
                   bool save, op_proc_t cont)
284
1.94M
{
285
1.94M
    const ref *const fop = &sstate->s_file;
286
1.94M
    stream *s = fptr(fop);
287
1.94M
    uint avail = sbufavailable(s);
288
1.94M
    int status;
289
290
1.94M
    if (s->end_status == EOFC) {
291
        /* More data needed, but none available, so this is a syntax error. */
292
773
        return_error(gs_error_syntaxerror);
293
773
    }
294
1.94M
    status = s_process_read_buf(s);
295
1.94M
    if (sbufavailable(s) > avail)
296
267k
        return 0;
297
1.67M
    if (status == 0)
298
1.67M
        status = s->end_status;
299
1.67M
    switch (status) {
300
877
        case EOFC:
301
            /* We just discovered that we're at EOF. */
302
            /* Let the caller find this out. */
303
877
            return 0;
304
32
        case ERRC:
305
32
            return_error(gs_error_ioerror);
306
0
        case INTC:
307
1.67M
        case CALLC:
308
1.67M
            {
309
1.67M
                ref rstate[1];
310
1.67M
                scanner_state *pstate;
311
312
1.67M
                if (save) {
313
1.53M
                    pstate = (scanner_state *)
314
1.53M
                        ialloc_struct(scanner_state_dynamic, &st_scanner_state_dynamic,
315
1.53M
                                      "gs_scan_handle_refill");
316
1.53M
                    if (pstate == 0)
317
0
                        return_error(gs_error_VMerror);
318
1.53M
                    ((scanner_state_dynamic *)pstate)->mem = imemory;
319
1.53M
                    *pstate = *sstate;
320
1.53M
                } else
321
139k
                    pstate = sstate;
322
1.67M
                make_istruct(&rstate[0], 0, pstate);
323
1.67M
                return s_handle_read_exception(i_ctx_p, status, fop,
324
1.67M
                                               rstate, 1, cont);
325
1.67M
            }
326
1.67M
    }
327
    /* No more data available, but no exception. */
328
    /* A filter is consuming headers but returns nothing. */
329
1.83k
    return 0;
330
1.67M
}
331
332
/*
333
 * Handle a comment.  The 'saved' argument is needed only for
334
 * tracing printout.
335
 */
336
static int
337
scan_comment(i_ctx_t *i_ctx_p, ref *pref, scanner_state *pstate,
338
             const byte * base, const byte * end, bool saved)
339
3.27M
{
340
3.27M
    uint len = (uint) (end - base);
341
3.27M
    int code;
342
#ifdef DEBUG
343
    const char *sstr = (saved ? ">" : "");
344
#endif
345
346
3.27M
    if (len > 1 && (base[1] == '%' || base[1] == '!')) {
347
        /* Process as a DSC comment if requested. */
348
#ifdef DEBUG
349
        if (gs_debug_c('%')) {
350
            dmlprintf2(imemory, "[%%%%%s%c]", sstr, (len >= 3 ? '+' : '-'));
351
            debug_print_string(imemory, base, len);
352
            dmputs(imemory, "\n");
353
        }
354
#endif
355
1.16M
        if (pstate->s_options & SCAN_PROCESS_DSC_COMMENTS) {
356
1.14M
            code = scan_DSC_Comment;
357
1.14M
            goto comment;
358
1.14M
        }
359
        /* Treat as an ordinary comment. */
360
1.16M
    }
361
#ifdef DEBUG
362
    else {
363
        if (gs_debug_c('%')) {
364
            dmlprintf2(imemory, "[%% %s%c]", sstr, (len >= 2 ? '+' : '-'));
365
            debug_print_string(imemory, base, len);
366
            dmputs(imemory, "\n");
367
        }
368
    }
369
#endif
370
2.12M
    if (pstate->s_options & SCAN_PROCESS_COMMENTS) {
371
0
        code = scan_Comment;
372
0
        goto comment;
373
0
    }
374
2.12M
    return 0;
375
1.14M
 comment:
376
1.14M
    {
377
1.14M
        byte *cstr = ialloc_string(len, "scan_comment");
378
379
1.14M
        if (cstr == 0)
380
0
            return_error(gs_error_VMerror);
381
1.14M
        memcpy(cstr, base, len);
382
1.14M
        make_string(pref, a_all | icurrent_space, len, cstr);
383
1.14M
    }
384
0
    return code;
385
1.14M
}
386
387
/* Read a token from a string. */
388
/* Update the string if succesful. */
389
/* Store the error object in i_ctx_p->error_object if not. */
390
int
391
gs_scan_string_token_options(i_ctx_t *i_ctx_p, ref * pstr, ref * pref,
392
                             int options)
393
1.65M
{
394
1.65M
    stream st;
395
1.65M
    stream *s = &st;
396
1.65M
    scanner_state state;
397
1.65M
    int code;
398
399
1.65M
    if (!r_has_attr(pstr, a_read))
400
0
        return_error(gs_error_invalidaccess);
401
1.65M
    s_init(s, NULL);
402
1.65M
    sread_string(s, pstr->value.bytes, r_size(pstr));
403
1.65M
    gs_scanner_init_stream_options(&state, s, options | SCAN_FROM_STRING);
404
1.65M
    switch (code = gs_scan_token(i_ctx_p, pref, &state)) {
405
11
        default:                /* error or comment */
406
11
            if (code < 0)
407
11
                break;
408
            /* falls through */
409
1.65M
        case 0:         /* read a token */
410
1.65M
        case scan_BOS:
411
1.65M
            {
412
1.65M
                uint pos = stell(s);
413
414
1.65M
                pstr->value.bytes += pos;
415
1.65M
                r_dec_size(pstr, pos);
416
1.65M
            }
417
1.65M
            break;
418
0
        case scan_Refill:       /* error */
419
0
            code = gs_note_error(gs_error_syntaxerror);
420
112
        case scan_EOF:
421
112
            break;
422
1.65M
    }
423
1.65M
    if (code < 0)
424
11
        gs_scanner_error_object(i_ctx_p, &state, &i_ctx_p->error_object);
425
1.65M
    return code;
426
1.65M
}
427
428
/*
429
 * Read a token from a stream.  Return 0 if an ordinary token was read,
430
 * >0 for special situations (see iscan.h).
431
 * If the token required a terminating character (i.e., was a name or
432
 * number) and the next character was whitespace, read and discard
433
 * that character.  Note that the state is relevant for gs_error_VMerror
434
 * as well as for scan_Refill.
435
 */
436
int
437
gs_scan_token(i_ctx_t *i_ctx_p, ref * pref, scanner_state * pstate) /* lgtm [cpp/use-of-goto] */
438
5.76G
{
439
5.76G
    stream *const s = pstate->s_file.value.pfile;
440
5.76G
    ref *myref = pref;
441
5.76G
    int retcode = 0;
442
5.76G
    int c;
443
444
5.76G
    s_declare_inline(s, sptr, endptr);
445
5.76G
    const byte *newptr;
446
5.76G
    byte *daptr;
447
448
5.76G
#define sreturn(code)\
449
5.76G
  { retcode = gs_note_error(code); goto sret; }
450
5.76G
#define if_not_spush1()\
451
6.13G
  if ( osp < ostop ) osp++;\
452
6.13G
  else if ( (retcode = ref_stack_push(&o_stack, 1)) >= 0 )\
453
43.1k
    ;\
454
43.1k
  else
455
5.76G
#define spop1()\
456
5.76G
  if ( osp >= osbot ) osp--;\
457
202M
  else ref_stack_pop(&o_stack, 1)
458
5.76G
    int max_name_ctype =
459
5.76G
        ((ref_binary_object_format.value.intval != 0 && level2_enabled)? ctype_name : ctype_btoken);
460
461
5.76G
#define scan_sign(sign, ptr)\
462
5.76G
  switch ( *ptr ) {\
463
3.58M
    case '-': sign = -1; ptr++; break;\
464
6.37k
    case '+': sign = 1; ptr++; break;\
465
1.71G
    default: sign = 0;\
466
1.71G
  }
467
5.76G
#define refill2_back(styp,nback)\
468
5.76G
  BEGIN sptr -= nback; sstate.s_scan_type = styp; goto pause; END
469
5.76G
#define ensure2_back(styp,nback)\
470
5.76G
  if ( sptr >= endptr ) refill2_back(styp,nback)
471
5.76G
#define ensure2(styp) ensure2_back(styp, 1)
472
5.76G
#define refill2(styp) refill2_back(styp, 1)
473
5.76G
    byte s1[2];
474
5.76G
    const byte *const decoder = scan_char_decoder;
475
5.76G
    int status;
476
5.76G
    int sign;
477
5.76G
    const bool check_only = (pstate->s_options & SCAN_CHECK_ONLY) != 0;
478
5.76G
    const bool PDFScanRules = (i_ctx_p->scanner_options & SCAN_PDF_RULES) != 0;
479
    /*
480
     * The following is a hack so that ^D will be self-delimiting in PS files
481
     * (to compensate for bugs in some PostScript-generating applications)
482
     * but not in strings (to match CPSI on the CET) or PDF.
483
     */
484
5.76G
    const int ctrld = (pstate->s_options & SCAN_FROM_STRING ||
485
5.76G
                      PDFScanRules ? 0x04 : 0xffff);
486
5.76G
    scanner_state sstate;
487
488
5.76G
    sptr = endptr = NULL; /* Quiet compiler */
489
5.76G
    if (pstate->s_pstack != 0) {
490
167k
        if_not_spush1()
491
0
            return retcode;
492
167k
        myref = osp;
493
167k
    }
494
    /* Check whether we are resuming after an interruption. */
495
5.76G
    if (pstate->s_scan_type != scanning_none) {
496
784k
        sstate = *pstate;
497
784k
        if (!sstate.s_da.is_dynamic && sstate.s_da.base != sstate.s_da.buf) {
498
            /* The sstate.s_da contains some self-referencing pointers. */
499
            /* Fix them up now. */
500
245
            uint next = sstate.s_da.next - sstate.s_da.base;
501
245
            uint limit = sstate.s_da.limit - sstate.s_da.base;
502
503
245
            sstate.s_da.base = sstate.s_da.buf;
504
245
            sstate.s_da.next = sstate.s_da.buf + next;
505
245
            sstate.s_da.limit = sstate.s_da.buf + limit;
506
245
        }
507
784k
        daptr = sstate.s_da.next;
508
784k
        switch (sstate.s_scan_type) {
509
24.1k
            case scanning_binary:
510
24.1k
                retcode = (*sstate.s_ss.binary.cont)
511
24.1k
                    (i_ctx_p, myref, &sstate);
512
24.1k
                s_begin_inline(s, sptr, endptr);
513
24.1k
                if (retcode == scan_Refill)
514
23.9k
                    goto pause;
515
218
                goto sret;
516
218
            case scanning_comment:
517
0
                s_begin_inline(s, sptr, endptr);
518
0
                goto cont_comment;
519
760k
            case scanning_name:
520
760k
                goto cont_name;
521
5
            case scanning_string:
522
5
                goto cont_string;
523
0
            default:
524
0
                return_error(gs_error_Fatal);
525
784k
        }
526
784k
    }
527
5.76G
    else {
528
        /* We *may* use these in the event of returning to this function after
529
         * a interruption, but not every code path below sets them. Set them
530
         * to sane values here for safety. We can write the contents of sstate
531
         * (back) to pstate before returning.
532
         */
533
5.76G
        sstate.s_da.base = sstate.s_da.next = &(sstate.s_da.buf[0]);
534
5.76G
        sstate.s_da.limit = sstate.s_da.next;
535
5.76G
        sstate.s_da.is_dynamic = false;
536
5.76G
    }
537
    /* Fetch any state variables that are relevant even if */
538
    /* sstate.s_scan_type == scanning_none. */
539
5.76G
    sstate.s_pstack = pstate->s_pstack;
540
5.76G
    sstate.s_pdepth = pstate->s_pdepth;
541
5.76G
    ref_assign(&sstate.s_file, &pstate->s_file);
542
5.76G
    sstate.s_options = pstate->s_options;
543
5.76G
    SCAN_INIT_ERROR(&sstate);
544
5.76G
    s_begin_inline(s, sptr, endptr);
545
    /*
546
     * Loop invariants:
547
     *      If sstate.s_pstack != 0, myref = osp, and *osp is a valid slot.
548
     */
549
11.7G
  top:c = sgetc_inline(s, sptr, endptr);
550
11.7G
    if_debug1m('S', imemory, (c >= 32 && c <= 126 ? "`%c'" : c >= 0 ? "`\\%03o'" : "`%d'"), c);
551
11.7G
    switch (c) {
552
36.9M
        case ' ':
553
37.1M
        case '\f':
554
37.5M
        case '\t':
555
37.9M
        case char_CR:
556
40.6M
        case char_EOL:
557
46.6M
        case char_NULL:
558
46.6M
            goto top;
559
750k
        case 0x04:              /* see ctrld above */
560
750k
            if (c == ctrld)     /* treat as ordinary name char */
561
3
                goto begin_name;
562
            /* fall through */
563
641M
        case '[':
564
1.26G
        case ']':
565
1.26G
            s1[0] = (byte) c;
566
1.26G
            retcode = name_ref(imemory, s1, 1, myref, 1);       /* can't fail */
567
1.26G
            r_set_attrs(myref, a_executable);
568
1.26G
            break;
569
12.0M
        case '<':
570
12.0M
            if (level2_enabled) {
571
10.9M
                ensure2(scanning_none);
572
10.9M
                c = sgetc_inline(s, sptr, endptr);
573
10.9M
                switch (c) {
574
7.04M
                    case '<':
575
7.04M
                        sputback_inline(s, sptr, endptr);
576
7.04M
                        sstate.s_ss.s_name.s_name_type = 0;
577
7.04M
                        sstate.s_ss.s_name.s_try_number = false;
578
7.04M
                        goto try_funny_name;
579
688
                    case '~':
580
688
                        s_A85D_init_inline(&sstate.s_ss.a85d);
581
688
                        sstate.s_ss.st.templat = &s_A85D_template;
582
688
                        sstate.s_ss.a85d.require_eod = true;
583
                        /* If this is an inline ASCII string, interpret it normally, throw an error
584
                         * if it fails rather than ignoring it as PDF (Acrobat) does.
585
                         */
586
688
                        sstate.s_ss.a85d.pdf_rules = false;
587
688
                        goto str;
588
10.9M
                }
589
3.94M
                sputback_inline(s, sptr, endptr);
590
3.94M
            }
591
5.02M
            (void)s_AXD_init_inline(&sstate.s_ss.axd);
592
5.02M
            sstate.s_ss.st.templat = &s_AXD_template;
593
164M
          str:s_end_inline(s, sptr, endptr);
594
164M
            dynamic_init(&sstate.s_da, imemory);
595
165M
          cont_string:for (;;) {
596
165M
                stream_cursor_write w;
597
598
165M
                w.ptr = sstate.s_da.next - 1;
599
165M
                w.limit = sstate.s_da.limit - 1;
600
165M
                status = (*sstate.s_ss.st.templat->process)
601
165M
                    (&sstate.s_ss.st, &s->cursor.r, &w,
602
165M
                     s->end_status == EOFC);
603
165M
                if (!check_only)
604
165M
                    sstate.s_da.next = w.ptr + 1;
605
165M
                switch (status) {
606
586k
                    case 0:
607
586k
                        status = s->end_status;
608
586k
                        if (status < 0) {
609
2.87k
                            if (status == EOFC) {
610
2.87k
                                if (check_only) {
611
0
                                    retcode = scan_Refill;
612
0
                                    sstate.s_scan_type = scanning_string;
613
0
                                    goto suspend;
614
0
                                } else
615
2.87k
                                    sreturn(gs_error_syntaxerror);
616
0
                            }
617
5
                            break;
618
2.87k
                        }
619
583k
                        s_process_read_buf(s);
620
583k
                        continue;
621
8.90k
                    case 1:
622
8.90k
                        if (!check_only) {
623
8.90k
                            retcode = dynamic_grow(&sstate.s_da, sstate.s_da.next, max_string_size);
624
8.90k
                            if (retcode == gs_error_VMerror) {
625
0
                                sstate.s_scan_type = scanning_string;
626
0
                                goto suspend;
627
8.90k
                            } else if (retcode < 0)
628
8.90k
                                sreturn(retcode);
629
8.90k
                        }
630
8.90k
                        continue;
631
165M
                }
632
164M
                break;
633
165M
            }
634
164M
            s_begin_inline(s, sptr, endptr);
635
164M
            switch (status) {
636
1.59k
                default:
637
                    /*case ERRC: */
638
1.59k
                    sreturn(gs_error_syntaxerror);
639
0
                case INTC:
640
5
                case CALLC:
641
5
                    sstate.s_scan_type = scanning_string;
642
5
                    goto pause;
643
164M
                case EOFC:
644
164M
                    ;
645
164M
            }
646
164M
            retcode = dynamic_make_string(i_ctx_p, myref, &sstate.s_da, sstate.s_da.next);
647
164M
            if (retcode < 0) {  /* VMerror */
648
0
                sputback(s);    /* rescan ) */
649
0
                sstate.s_scan_type = scanning_string;
650
0
                goto suspend;
651
0
            }
652
164M
            break;
653
164M
        case '(':
654
159M
            sstate.s_ss.pssd.from_string =
655
159M
                ((pstate->s_options & SCAN_FROM_STRING) != 0) &&
656
3
                !level2_enabled;
657
159M
            s_PSSD_partially_init_inline(&sstate.s_ss.pssd);
658
159M
            sstate.s_ss.st.templat = &s_PSSD_template;
659
159M
            goto str;
660
723M
        case '{':
661
723M
            if (sstate.s_pstack == 0) {  /* outermost procedure */
662
202M
                if_not_spush1() {
663
0
                    sputback_inline(s, sptr, endptr);
664
0
                    sstate.s_scan_type = scanning_none;
665
0
                    goto pause_ret;
666
0
                }
667
202M
                sstate.s_pdepth = ref_stack_count_inline(&o_stack);
668
202M
            }
669
723M
            make_int(osp, sstate.s_pstack);
670
723M
            sstate.s_pstack = ref_stack_count_inline(&o_stack);
671
723M
            if_debug3m('S', imemory, "[S{]d=%d, s=%d->%d\n",
672
723M
                       sstate.s_pdepth, (int)osp->value.intval, sstate.s_pstack);
673
723M
            goto snext;
674
6.96M
        case '>':
675
6.96M
            if (level2_enabled) {
676
6.96M
                ensure2(scanning_none);
677
6.96M
                sstate.s_ss.s_name.s_name_type = 0;
678
6.96M
                sstate.s_ss.s_name.s_try_number = false;
679
6.96M
                goto try_funny_name;
680
6.96M
            }
681
            /* falls through */
682
174
        case ')':
683
174
            sreturn(gs_error_syntaxerror);
684
720M
        case '}':
685
720M
            if (sstate.s_pstack == 0)
686
720M
                sreturn(gs_error_syntaxerror);
687
720M
            osp--;
688
720M
            {
689
720M
                uint size = ref_stack_count_inline(&o_stack) - sstate.s_pstack;
690
720M
                ref arr;
691
692
720M
                if_debug4m('S', imemory, "[S}]d=%"PRIu32", s=%"PRIu32"->%"PRIpsint", c=%"PRIu32"\n",
693
720M
                           sstate.s_pdepth, sstate.s_pstack,
694
720M
                           (sstate.s_pstack == sstate.s_pdepth ? 0 :
695
720M
                           ref_stack_index(&o_stack, size)->value.intval),
696
720M
                           size + sstate.s_pstack);
697
720M
                if (size > max_array_size)
698
720M
                    sreturn(gs_error_limitcheck);
699
720M
                myref = (sstate.s_pstack == sstate.s_pdepth ? pref : &arr);
700
720M
                if (check_only) {
701
0
                    make_empty_array(myref, 0);
702
0
                    ref_stack_pop(&o_stack, size);
703
720M
                } else if (ref_array_packing.value.boolval) {
704
700M
                    retcode = make_packed_array(myref, &o_stack, size,
705
700M
                                                idmemory, "scanner(packed)");
706
700M
                    if (retcode < 0) {  /* must be VMerror */
707
0
                        osp++;
708
0
                        sputback_inline(s, sptr, endptr);
709
0
                        sstate.s_scan_type = scanning_none;
710
0
                        goto pause_ret;
711
0
                    }
712
700M
                    r_set_attrs(myref, a_executable);
713
700M
                } else {
714
19.8M
                    retcode = ialloc_ref_array(myref,
715
19.8M
                                               a_executable + a_all, size,
716
19.8M
                                               "scanner(proc)");
717
19.8M
                    if (retcode < 0) {  /* must be VMerror */
718
0
                        osp++;
719
0
                        sputback_inline(s, sptr, endptr);
720
0
                        sstate.s_scan_type = scanning_none;
721
0
                        goto pause_ret;
722
0
                    }
723
19.8M
                    retcode = ref_stack_store(&o_stack, myref, size, 0, 1,
724
19.8M
                                              false, idmemory, "scanner");
725
19.8M
                    if (retcode < 0) {
726
0
                        ifree_ref_array(myref, "scanner(proc)");
727
0
                        sreturn(retcode);
728
0
                    }
729
19.8M
                    ref_stack_pop(&o_stack, size);
730
19.8M
                }
731
720M
                if (sstate.s_pstack == sstate.s_pdepth) {         /* This was the top-level procedure. */
732
202M
                    spop1();
733
202M
                    sstate.s_pstack = 0;
734
518M
                } else {
735
518M
                    if (osp < osbot)
736
0
                        ref_stack_pop_block(&o_stack);
737
518M
                    sstate.s_pstack = osp->value.intval;
738
518M
                    *osp = arr;
739
518M
                    goto snext;
740
518M
                }
741
720M
            }
742
202M
            break;
743
2.77G
        case '/':
744
            /*
745
             * If the last thing in the input is a '/', don't try to read
746
             * any more data.
747
             */
748
2.77G
            if (sptr >= endptr && s->end_status != EOFC) {
749
238k
                refill2(scanning_none);
750
238k
            }
751
2.77G
            c = sgetc_inline(s, sptr, endptr);
752
2.77G
            if (!PDFScanRules && (c == '/')) {
753
262M
                sstate.s_ss.s_name.s_name_type = 2;
754
262M
                c = sgetc_inline(s, sptr, endptr);
755
262M
            } else
756
2.51G
                sstate.s_ss.s_name.s_name_type = 1;
757
2.77G
            sstate.s_ss.s_name.s_try_number = false;
758
2.77G
            switch (decoder[c]) {
759
306M
                case ctype_name:
760
2.77G
                default:
761
2.77G
                    goto do_name;
762
2.77G
                case ctype_btoken:
763
2.00k
                    if (!(ref_binary_object_format.value.intval != 0 && level2_enabled))
764
0
                        goto do_name;
765
                    /* otherwise, an empty name */
766
2.32k
                case ctype_exception:
767
170k
                case ctype_space:
768
                    /*
769
                     * Amazingly enough, the Adobe implementations don't accept
770
                     * / or // followed by [, ], <<, or >>, so we do the same.
771
                     * (Older versions of our code had a ctype_other case here
772
                     * that handled these specially.)
773
                     */
774
880k
                case ctype_other:
775
880k
                    if (c == ctrld) /* see above */
776
0
                        goto do_name;
777
880k
                    sstate.s_da.base = sstate.s_da.limit = daptr = 0;
778
880k
                    sstate.s_da.is_dynamic = false;
779
880k
                    goto nx;
780
2.77G
            }
781
3.27M
        case '%':
782
3.27M
            {                   /* Scan as much as possible within the buffer. */
783
3.27M
                const byte *base = sptr;
784
3.27M
                const byte *end;
785
786
43.9M
                while (++sptr < endptr)         /* stop 1 char early */
787
43.9M
                    switch (*sptr) {
788
94.8k
                        case char_CR:
789
94.8k
                            end = sptr;
790
94.8k
                            if (sptr[1] == char_EOL)
791
19.2k
                                sptr++;
792
3.24M
                          cend: /* Check for externally processed comments. */
793
3.24M
                            retcode = scan_comment(i_ctx_p, myref, &sstate,
794
3.24M
                                                   base, end, false);
795
3.24M
                            if (retcode != 0)
796
1.13M
                                goto comment;
797
2.11M
                            goto top;
798
3.09M
                        case char_EOL:
799
3.15M
                        case '\f':
800
3.15M
                            end = sptr;
801
3.15M
                            goto cend;
802
43.9M
                    }
803
                /*
804
                 * We got to the end of the buffer while inside a comment.
805
                 * If there is a possibility that we must pass the comment
806
                 * to an external procedure, move what we have collected
807
                 * so far into a private buffer now.
808
                 */
809
25.3k
                --sptr;
810
25.3k
                sstate.s_da.buf[1] = 0;
811
25.3k
                {
812
                    /* Could be an externally processable comment. */
813
25.3k
                    uint len = sptr + 1 - base;
814
25.3k
                    if (len > sizeof(sstate.s_da.buf))
815
9
                        len = sizeof(sstate.s_da.buf);
816
817
25.3k
                    memcpy(sstate.s_da.buf, base, len);
818
25.3k
                    daptr = sstate.s_da.buf + len;
819
25.3k
                }
820
25.3k
                sstate.s_da.base = sstate.s_da.buf;
821
25.3k
                sstate.s_da.is_dynamic = false;
822
25.3k
            }
823
            /* Enter here to continue scanning a comment. */
824
            /* daptr must be set. */
825
4.50M
          cont_comment:for (;;) {
826
4.50M
                switch ((c = sgetc_inline(s, sptr, endptr))) {
827
4.48M
                    default:
828
4.48M
                        if (c < 0)
829
4.66k
                            switch (c) {
830
0
                                case INTC:
831
0
                                case CALLC:
832
0
                                    sstate.s_da.next = daptr;
833
0
                                    sstate.s_scan_type = scanning_comment;
834
0
                                    goto pause;
835
4.66k
                                case EOFC:
836
                                    /*
837
                                     * One would think that an EOF in a comment
838
                                     * should be a syntax error, but there are
839
                                     * quite a number of files that end that way.
840
                                     */
841
4.66k
                                    goto end_comment;
842
0
                                default:
843
0
                                    sreturn(gs_error_syntaxerror);
844
4.66k
                            }
845
4.48M
                        if (daptr < sstate.s_da.buf + max_comment_line)
846
469k
                            *daptr++ = c;
847
4.48M
                        continue;
848
1.87k
                    case char_CR:
849
18.9k
                    case char_EOL:
850
20.6k
                    case '\f':
851
25.3k
                      end_comment:
852
25.3k
                        retcode = scan_comment(i_ctx_p, myref, &sstate,
853
25.3k
                                               sstate.s_da.buf, daptr, true);
854
25.3k
                        if (retcode != 0)
855
13.4k
                            goto comment;
856
11.8k
                        goto top;
857
4.50M
                }
858
4.50M
            }
859
            /*NOTREACHED */
860
1.57M
        case EOFC:
861
1.57M
            if (sstate.s_pstack != 0) {
862
6.27k
                if (check_only)
863
0
                    goto pause;
864
6.27k
                sreturn(gs_error_syntaxerror);
865
0
            }
866
1.57M
            retcode = scan_EOF;
867
1.57M
            break;
868
4
        case ERRC:
869
4
            sreturn(gs_error_ioerror);
870
871
            /* Check for a Level 2 funny name (<< or >>). */
872
            /* c is '<' or '>'.  We already did an ensure2. */
873
14.0M
          try_funny_name:
874
14.0M
            {
875
14.0M
                int c1 = sgetc_inline(s, sptr, endptr);
876
877
14.0M
                if (c1 == c) {
878
14.0M
                    s1[0] = s1[1] = c;
879
14.0M
                    name_ref(imemory, s1, 2, myref, 1); /* can't fail */
880
14.0M
                    goto have_name;
881
14.0M
                }
882
53
                sputback_inline(s, sptr, endptr);
883
53
            }
884
53
            sreturn(gs_error_syntaxerror);
885
886
            /* Handle separately the names that might be a number. */
887
134M
        case '0':
888
1.62G
        case '1':
889
1.77G
        case '2':
890
1.87G
        case '3':
891
1.93G
        case '4':
892
1.96G
        case '5':
893
1.98G
        case '6':
894
1.99G
        case '7':
895
2.01G
        case '8':
896
2.02G
        case '9':
897
2.43G
        case '.':
898
2.43G
            sign = 0;
899
2.48G
    nr:     /*
900
             * Skip a leading sign, if any, by conditionally passing
901
             * sptr + 1 rather than sptr.  Also, if the last character
902
             * in the buffer is a CR, we must stop the scan 1 character
903
             * early, to be sure that we can test for CR+LF within the
904
             * buffer, by passing endptr rather than endptr + 1.
905
             */
906
2.48G
            retcode = scan_number(sptr + (sign & 1),
907
2.48G
                    endptr /*(*endptr == char_CR ? endptr : endptr + 1) */ ,
908
2.48G
                                  sign, myref, &newptr, i_ctx_p->scanner_options);
909
2.48G
            if (retcode == 1 && decoder[newptr[-1]] == ctype_space) {
910
766M
                sptr = newptr - 1;
911
766M
                if (*sptr == char_CR && sptr[1] == char_EOL)
912
1.56k
                    sptr++;
913
766M
                retcode = 0;
914
766M
                ref_mark_new(myref);
915
766M
                break;
916
766M
            }
917
1.71G
            sstate.s_ss.s_name.s_name_type = 0;
918
1.71G
            sstate.s_ss.s_name.s_try_number = true;
919
1.71G
            goto do_name;
920
6.47k
        case '+':
921
6.47k
            sign = 1;
922
6.47k
            goto nr;
923
49.1M
        case '-':
924
49.1M
            sign = -1;
925
49.1M
            if(i_ctx_p->scanner_options & SCAN_PDF_INV_NUM) {
926
0
                const byte *osptr = sptr;
927
0
                do {
928
                    /* This is slightly unpleasant: we have to bounds check the buffer,
929
                       rather than just incrementing the point until we find a non '-' character.
930
                       But we cannot differentiate between multiple '-' characters that
931
                       straddle a buffer boundary, or a token that is only one or more '-' characters.
932
                       Handling this relies on the fact that the Postscript-based PDF interpreter
933
                       always uses the "token" operator to tokenize a stream, thus we can assume
934
                       here that the current buffer contains the entire token. So if we reach
935
                       the end of the buffer without hitting a character taht is not a '-', we'll reset
936
                       the buffer pointer, and retry, treating it as a name object.
937
                     */
938
0
                    if (sptr + 1 > endptr) {
939
0
                        sptr = osptr;
940
0
                        sstate.s_ss.s_name.s_name_type = 0;
941
0
                        sstate.s_ss.s_name.s_try_number = true;
942
0
                        goto do_name;
943
0
                    }
944
0
                    if (*(sptr + 1) == '-') {
945
0
                        sptr++;
946
0
                    } else
947
0
                        break;
948
0
                } while (1);
949
0
            }
950
49.1M
            goto nr;
951
952
            /* Check for a binary object */
953
49.1M
          case 128: case 129: case 130: case 131: case 132: case 133: case 134: case 135:
954
840k
          case 136: case 137: case 138: case 139: case 140: case 141: case 142: case 143:
955
1.48M
          case 144: case 145: case 146: case 147: case 148: case 149: case 150: case 151:
956
1.48M
          case 152: case 153: case 154: case 155: case 156: case 157: case 158: case 159:
957
1.48M
            if ((ref_binary_object_format.value.intval != 0 && level2_enabled)) {
958
1.48M
                s_end_inline(s, sptr, endptr);
959
1.48M
                retcode = scan_binary_token(i_ctx_p, myref, &sstate);
960
1.48M
                s_begin_inline(s, sptr, endptr);
961
1.48M
                if (retcode == scan_Refill)
962
5.89k
                    goto pause;
963
1.47M
                break;
964
1.48M
            }
965
            /* Not a binary object, fall through. */
966
967
            /* The default is a name. */
968
2.47M
        default:
969
2.47M
            if (c < 0) {
970
916k
                dynamic_init(&sstate.s_da, name_memory(imemory));        /* sstate.s_da state must be clean */
971
916k
                sstate.s_scan_type = scanning_none;
972
916k
                goto pause;
973
916k
            }
974
            /* Populate the switch with enough cases to force */
975
            /* simple compilers to use a dispatch rather than tests. */
976
1.57M
        case '!':
977
2.28M
        case '"':
978
5.70M
        case '#':
979
21.7M
        case '$':
980
22.0M
        case '&':
981
23.2M
        case '\'':
982
23.4M
        case '*':
983
25.1M
        case ',':
984
64.9M
        case '=':
985
64.9M
        case ':':
986
95.5M
        case ';':
987
95.6M
        case '?':
988
95.6M
        case '@':
989
96.8M
        case 'A':
990
97.3M
        case 'B':
991
105M
        case 'C':
992
110M
        case 'D':
993
116M
        case 'E':
994
122M
        case 'F':
995
124M
        case 'G':
996
126M
        case 'H':
997
131M
        case 'I':
998
131M
        case 'J':
999
131M
        case 'K':
1000
134M
        case 'L':
1001
135M
        case 'M':
1002
147M
        case 'N':
1003
150M
        case 'O':
1004
158M
        case 'P':
1005
163M
        case 'Q':
1006
180M
        case 'R':
1007
191M
        case 'S':
1008
201M
        case 'T':
1009
203M
        case 'U':
1010
207M
        case 'V':
1011
209M
        case 'W':
1012
209M
        case 'X':
1013
209M
        case 'Y':
1014
209M
        case 'Z':
1015
209M
        case '\\':
1016
209M
        case '^':
1017
209M
        case '_':
1018
209M
        case '`':
1019
309M
        case 'a':
1020
360M
        case 'b':
1021
571M
        case 'c':
1022
1.07G
        case 'd':
1023
1.54G
        case 'e':
1024
1.64G
        case 'f':
1025
1.84G
        case 'g':
1026
1.84G
        case 'h':
1027
2.33G
        case 'i':
1028
2.33G
        case 'j':
1029
2.37G
        case 'k':
1030
2.47G
        case 'l':
1031
2.52G
        case 'm':
1032
2.61G
        case 'n':
1033
2.66G
        case 'o':
1034
3.09G
        case 'p':
1035
3.09G
        case 'q':
1036
3.23G
        case 'r':
1037
3.43G
        case 's':
1038
3.48G
        case 't':
1039
3.50G
        case 'u':
1040
3.50G
        case 'v':
1041
3.54G
        case 'w':
1042
3.54G
        case 'x':
1043
3.55G
        case 'y':
1044
3.55G
        case 'z':
1045
3.55G
        case '|':
1046
3.55G
        case '~':
1047
3.55G
          begin_name:
1048
            /* Common code for scanning a name. */
1049
            /* sstate.s_ss.s_name.s_try_number and sstate.s_ss.s_name.s_name_type are already set. */
1050
            /* We know c has ctype_name (or maybe ctype_btoken, */
1051
            /* or is ^D) or is a digit. */
1052
3.55G
            sstate.s_ss.s_name.s_name_type = 0;
1053
3.55G
            sstate.s_ss.s_name.s_try_number = false;
1054
8.04G
          do_name:
1055
            /* Try to scan entirely within the stream buffer. */
1056
            /* We stop 1 character early, so we don't switch buffers */
1057
            /* looking ahead if the name is terminated by \r\n. */
1058
8.04G
            sstate.s_da.base = (byte *) sptr;
1059
8.04G
            sstate.s_da.is_dynamic = false;
1060
8.04G
            {
1061
8.04G
                const byte *endp1 = endptr - 1;
1062
1063
60.6G
                do {
1064
60.6G
                    if (sptr >= endp1)  /* stop 1 early! */
1065
9.51M
                        goto dyn_name;
1066
60.6G
                }
1067
60.6G
                while (decoder[*++sptr] <= max_name_ctype || *sptr == ctrld);   /* digit or name */
1068
8.04G
            }
1069
            /* Name ended within the buffer. */
1070
8.03G
            daptr = (byte *) sptr;
1071
8.03G
            c = *sptr;
1072
8.03G
            goto nx;
1073
9.51M
          dyn_name:             /* Name extended past end of buffer. */
1074
9.51M
            s_end_inline(s, sptr, endptr);
1075
            /* Initialize the dynamic area. */
1076
            /* We have to do this before the next */
1077
            /* sgetc, which will overwrite the buffer. */
1078
9.51M
            sstate.s_da.limit = (byte *)++ sptr;
1079
9.51M
            sstate.s_da.memory = name_memory(imemory);
1080
9.51M
            retcode = dynamic_grow(&sstate.s_da, sstate.s_da.limit, name_max_string);
1081
9.51M
            if (retcode < 0) {
1082
20
                dynamic_save(&sstate.s_da);
1083
20
                if (retcode != gs_error_VMerror)
1084
20
                    sreturn(retcode);
1085
0
                sstate.s_scan_type = scanning_name;
1086
0
                goto pause_ret;
1087
20
            }
1088
9.51M
            daptr = sstate.s_da.next;
1089
            /* Enter here to continue scanning a name. */
1090
            /* daptr must be set. */
1091
10.2M
          cont_name:s_begin_inline(s, sptr, endptr);
1092
40.9M
            while (decoder[c = sgetc_inline(s, sptr, endptr)] <= max_name_ctype || c == ctrld) {
1093
30.6M
                if (daptr == sstate.s_da.limit) {
1094
173k
                    retcode = dynamic_grow(&sstate.s_da, daptr,
1095
173k
                                           name_max_string);
1096
173k
                    if (retcode < 0) {
1097
46
                        dynamic_save(&sstate.s_da);
1098
46
                        if (retcode != gs_error_VMerror)
1099
46
                            sreturn(retcode);
1100
0
                        sputback_inline(s, sptr, endptr);
1101
0
                        sstate.s_scan_type = scanning_name;
1102
0
                        goto pause_ret;
1103
46
                    }
1104
173k
                    daptr = sstate.s_da.next;
1105
173k
                }
1106
30.6M
                *daptr++ = c;
1107
30.6M
            }
1108
8.04G
          nx:switch (decoder[c]) {
1109
4.53G
                case ctype_other:
1110
4.53G
                    if (c == ctrld) /* see above */
1111
0
                        break;
1112
4.54G
                case ctype_btoken:
1113
4.54G
                    sputback_inline(s, sptr, endptr);
1114
4.54G
                    break;
1115
3.49G
                case ctype_space:
1116
                    /* Check for \r\n */
1117
3.49G
                    if (c == char_CR) {
1118
1.77M
                        if (sptr >= endptr) {   /* ensure2 *//* We have to check specially for */
1119
                            /* the case where the very last */
1120
                            /* character of a file is a CR. */
1121
2.70k
                            if (s->end_status != EOFC) {
1122
2.51k
                                sptr--;
1123
2.51k
                                goto pause_name;
1124
2.51k
                            }
1125
1.76M
                        } else if (sptr[1] == char_EOL)
1126
18.2k
                            sptr++;
1127
1.77M
                    }
1128
3.49G
                    break;
1129
3.49G
                case ctype_exception:
1130
4.88M
                    switch (c) {
1131
0
                        case INTC:
1132
757k
                        case CALLC:
1133
757k
                            goto pause_name;
1134
4
                        case ERRC:
1135
4
                            sreturn(gs_error_ioerror);
1136
4.13M
                        case EOFC:
1137
4.13M
                            break;
1138
4.88M
                    }
1139
8.04G
            }
1140
            /* Check for a number */
1141
8.04G
            if (sstate.s_ss.s_name.s_try_number) {
1142
1.71G
                const byte *base = sstate.s_da.base;
1143
1144
1.71G
                scan_sign(sign, base);
1145
1.71G
                retcode = scan_number(base, daptr, sign, myref, &newptr, i_ctx_p->scanner_options);
1146
1.71G
                if (retcode == 1) {
1147
2.41M
                    ref_mark_new(myref);
1148
2.41M
                    retcode = 0;
1149
1.71G
                } else if (retcode != gs_error_syntaxerror) {
1150
1.30G
                    dynamic_free(&sstate.s_da);
1151
1.30G
                    if (sstate.s_ss.s_name.s_name_type == 2)
1152
1.30G
                        sreturn(gs_error_syntaxerror);
1153
1.30G
                    break;      /* might be gs_error_limitcheck */
1154
1.30G
                }
1155
1.71G
            }
1156
6.74G
            if (sstate.s_da.is_dynamic) {        /* We've already allocated the string on the heap. */
1157
6.99M
                uint size = daptr - sstate.s_da.base;
1158
1159
6.99M
                retcode = name_ref(imemory, sstate.s_da.base, size, myref, -1);
1160
6.99M
                if (retcode >= 0) {
1161
5.80M
                    dynamic_free(&sstate.s_da);
1162
5.80M
                } else {
1163
1.19M
                    retcode = dynamic_resize(&sstate.s_da, size);
1164
1.19M
                    if (retcode < 0) {  /* VMerror */
1165
0
                        if (c != EOFC)
1166
0
                            sputback_inline(s, sptr, endptr);
1167
0
                        sstate.s_scan_type = scanning_name;
1168
0
                        goto pause_ret;
1169
0
                    }
1170
1.19M
                    retcode = name_ref(imemory, sstate.s_da.base, size, myref, 2);
1171
1.19M
                }
1172
6.73G
            } else {
1173
6.73G
                retcode = name_ref(imemory, sstate.s_da.base, (uint) (daptr - sstate.s_da.base),
1174
6.73G
                                   myref, !s->foreign);
1175
6.73G
            }
1176
            /* Done scanning.  Check for preceding /'s. */
1177
6.74G
            if (retcode < 0) {
1178
1
                if (retcode != gs_error_VMerror)
1179
1
                    sreturn(retcode);
1180
0
                if (!sstate.s_da.is_dynamic) {
1181
0
                    sstate.s_da.next = daptr;
1182
0
                    dynamic_save(&sstate.s_da);
1183
0
                }
1184
0
                if (c != EOFC)
1185
0
                    sputback_inline(s, sptr, endptr);
1186
0
                sstate.s_scan_type = scanning_name;
1187
0
                goto pause_ret;
1188
1
            }
1189
6.75G
          have_name:switch (sstate.s_ss.s_name.s_name_type) {
1190
3.97G
                case 0: /* ordinary executable name */
1191
3.97G
                    if (r_has_type(myref, t_name))      /* i.e., not a number */
1192
3.97G
                        r_set_attrs(myref, a_executable);
1193
6.49G
                case 1: /* quoted name */
1194
6.49G
                    break;
1195
262M
                case 2: /* immediate lookup */
1196
262M
                    {
1197
262M
                        ref *pvalue;
1198
1199
262M
                        if (!r_has_type(myref, t_name) ||
1200
262M
                            (pvalue = dict_find_name(myref)) == 0) {
1201
77
                            ref_assign(&sstate.s_error.object, myref);
1202
77
                            r_set_attrs(&sstate.s_error.object,
1203
77
                                a_executable); /* Adobe compatibility */
1204
77
                            sreturn(gs_error_undefined);
1205
0
                        }
1206
262M
                        if (sstate.s_pstack != 0 &&
1207
229M
                            r_space(pvalue) > ialloc_space(idmemory)
1208
262M
                            )
1209
262M
                            sreturn(gs_error_invalidaccess);
1210
262M
                        ref_assign_new(myref, pvalue);
1211
262M
                    }
1212
6.75G
            }
1213
11.7G
    }
1214
10.4G
  sret:if (retcode < 0) {
1215
17.1k
        s_end_inline(s, sptr, endptr);
1216
17.1k
        pstate->s_error = sstate.s_error;
1217
17.1k
        if (sstate.s_pstack != 0) {
1218
7.57k
            if (retcode == gs_error_undefined)
1219
48
                *pref = *osp;   /* return undefined name as error token */
1220
7.57k
            ref_stack_pop(&o_stack,
1221
7.57k
                          ref_stack_count(&o_stack) - (sstate.s_pdepth - 1));
1222
7.57k
        }
1223
17.1k
        return retcode;
1224
17.1k
    }
1225
    /* If we are at the top level, return the object, */
1226
    /* otherwise keep going. */
1227
10.4G
    if (sstate.s_pstack == 0) {
1228
5.76G
        s_end_inline(s, sptr, endptr);
1229
5.76G
        return retcode;
1230
5.76G
    }
1231
5.93G
  snext:if_not_spush1() {
1232
11
        s_end_inline(s, sptr, endptr);
1233
11
        sstate.s_scan_type = scanning_none;
1234
11
        goto save;
1235
11
    }
1236
5.93G
    myref = osp;
1237
5.93G
    goto top;
1238
1239
    /* Pause for an interrupt or callout. */
1240
760k
  pause_name:
1241
    /* If we're still scanning within the stream buffer, */
1242
    /* move the characters to the private buffer (sstate.s_da.buf) now. */
1243
760k
    sstate.s_da.next = daptr;
1244
760k
    dynamic_save(&sstate.s_da);
1245
760k
    sstate.s_scan_type = scanning_name;
1246
1.94M
  pause:
1247
1.94M
    retcode = scan_Refill;
1248
1.94M
  pause_ret:
1249
1.94M
    s_end_inline(s, sptr, endptr);
1250
1.94M
  suspend:
1251
1.94M
    if (sstate.s_pstack != 0)
1252
11.4k
        osp--;                  /* myref */
1253
3.09M
  save:
1254
3.09M
    *pstate = sstate;
1255
3.09M
    return retcode;
1256
1257
    /* Handle a scanned comment. */
1258
1.14M
 comment:
1259
1.14M
    if (retcode < 0)
1260
0
        goto sret;
1261
1.14M
    s_end_inline(s, sptr, endptr);
1262
1.14M
    sstate.s_scan_type = scanning_none;
1263
1.14M
    goto save;
1264
1.14M
}