Coverage Report

Created: 2026-09-14 07:34

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/ghostpdl/jbig2dec/jbig2_arith_int.c
Line
Count
Source
1
/* Copyright (C) 2001-2023 Artifex Software, Inc.
2
   All Rights Reserved.
3
4
   This software is provided AS-IS with no warranty, either express or
5
   implied.
6
7
   This software is distributed under license and may not be copied,
8
   modified or distributed except as expressly authorized under the terms
9
   of the license contained in the file LICENSE in this distribution.
10
11
   Refer to licensing information at http://www.artifex.com or contact
12
   Artifex Software, Inc.,  39 Mesa Street, Suite 108A, San Francisco,
13
   CA 94129, USA, for further information.
14
*/
15
16
/*
17
    jbig2dec
18
*/
19
20
/* Annex A */
21
22
#ifdef HAVE_CONFIG_H
23
#include "config.h"
24
#endif
25
#include "os_types.h"
26
27
#include <stddef.h>
28
#include <string.h>             /* memset() */
29
30
#include "jbig2.h"
31
#include "jbig2_priv.h"
32
#include "jbig2_arith.h"
33
#include "jbig2_arith_int.h"
34
35
struct _Jbig2ArithIntCtx {
36
    Jbig2ArithCx IAx[512];
37
};
38
39
Jbig2ArithIntCtx *
40
jbig2_arith_int_ctx_new(Jbig2Ctx *ctx)
41
1.78k
{
42
1.78k
    Jbig2ArithIntCtx *result = jbig2_new(ctx, Jbig2ArithIntCtx, 1);
43
44
1.78k
    if (result == NULL) {
45
0
        jbig2_error(ctx, JBIG2_SEVERITY_FATAL, JBIG2_UNKNOWN_SEGMENT_NUMBER, "failed to allocate arithmetic integer coding state");
46
0
        return NULL;
47
1.78k
    } else {
48
1.78k
        memset(result->IAx, 0, sizeof(result->IAx));
49
1.78k
    }
50
51
1.78k
    return result;
52
1.78k
}
53
54
/* A.2 */
55
/* Return value: -1 on error, 0 on normal value, 1 on OOB return. */
56
int
57
jbig2_arith_int_decode(Jbig2Ctx *ctx, Jbig2ArithIntCtx *actx, Jbig2ArithState *as, int32_t *p_result)
58
3.48k
{
59
3.48k
    Jbig2ArithCx *IAx = actx->IAx;
60
3.48k
    int PREV = 1;
61
3.48k
    int S;
62
3.48k
    int32_t V;
63
3.48k
    int bit;
64
3.48k
    int n_tail, offset;
65
3.48k
    int i;
66
67
3.48k
    S = jbig2_arith_decode(ctx, as, &IAx[PREV]);
68
3.48k
    if (S < 0)
69
0
        return jbig2_error(ctx, JBIG2_SEVERITY_WARNING, JBIG2_UNKNOWN_SEGMENT_NUMBER, "failed to decode IAx S");
70
3.48k
    PREV = (PREV << 1) | S;
71
72
3.48k
    bit = jbig2_arith_decode(ctx, as, &IAx[PREV]);
73
3.48k
    if (bit < 0)
74
0
        return jbig2_error(ctx, JBIG2_SEVERITY_WARNING, JBIG2_UNKNOWN_SEGMENT_NUMBER, "failed to decode IAx decision bit 0");
75
3.48k
    PREV = (PREV << 1) | bit;
76
3.48k
    if (bit) {
77
1.56k
        bit = jbig2_arith_decode(ctx, as, &IAx[PREV]);
78
1.56k
        if (bit < 0)
79
0
            return jbig2_error(ctx, JBIG2_SEVERITY_WARNING, JBIG2_UNKNOWN_SEGMENT_NUMBER, "failed to decode IAx decision bit 1");
80
1.56k
        PREV = (PREV << 1) | bit;
81
82
1.56k
        if (bit) {
83
834
            bit = jbig2_arith_decode(ctx, as, &IAx[PREV]);
84
834
            if (bit < 0)
85
0
                return jbig2_error(ctx, JBIG2_SEVERITY_WARNING, JBIG2_UNKNOWN_SEGMENT_NUMBER, "failed to decode IAx decision bit 2");
86
834
            PREV = (PREV << 1) | bit;
87
88
834
            if (bit) {
89
417
                bit = jbig2_arith_decode(ctx, as, &IAx[PREV]);
90
417
                if (bit < 0)
91
0
                    return jbig2_error(ctx, JBIG2_SEVERITY_WARNING, JBIG2_UNKNOWN_SEGMENT_NUMBER, "failed to decode IAx decision bit 3");
92
417
                PREV = (PREV << 1) | bit;
93
94
417
                if (bit) {
95
105
                    bit = jbig2_arith_decode(ctx, as, &IAx[PREV]);
96
105
                    if (bit < 0)
97
0
                        return jbig2_error(ctx, JBIG2_SEVERITY_WARNING, JBIG2_UNKNOWN_SEGMENT_NUMBER, "failed to decode IAx decision bit 4");
98
105
                    PREV = (PREV << 1) | bit;
99
100
105
                    if (bit) {
101
66
                        n_tail = 32;
102
66
                        offset = 4436;
103
66
                    } else {
104
39
                        n_tail = 12;
105
39
                        offset = 340;
106
39
                    }
107
312
                } else {
108
312
                    n_tail = 8;
109
312
                    offset = 84;
110
312
                }
111
417
            } else {
112
417
                n_tail = 6;
113
417
                offset = 20;
114
417
            }
115
834
        } else {
116
730
            n_tail = 4;
117
730
            offset = 4;
118
730
        }
119
1.91k
    } else {
120
1.91k
        n_tail = 2;
121
1.91k
        offset = 0;
122
1.91k
    }
123
124
3.48k
    V = 0;
125
17.8k
    for (i = 0; i < n_tail; i++) {
126
14.3k
        bit = jbig2_arith_decode(ctx, as, &IAx[PREV]);
127
14.3k
        if (bit < 0)
128
0
            return jbig2_error(ctx, JBIG2_SEVERITY_WARNING, JBIG2_UNKNOWN_SEGMENT_NUMBER, "failed to decode IAx V bit %d", i);
129
14.3k
        PREV = ((PREV << 1) & 511) | (PREV & 256) | bit;
130
14.3k
        V = (V << 1) | bit;
131
14.3k
    }
132
133
    /* offset is always >=0, so underflow can't happen. */
134
    /* avoid overflow by clamping 32 bit value. */
135
3.48k
    if (V > INT32_MAX - offset)
136
0
        V = INT32_MAX;
137
3.48k
    else
138
3.48k
        V += offset;
139
3.48k
    V = S ? -V : V;
140
3.48k
    *p_result = V;
141
3.48k
    return S && V == 0 ? 1 : 0;
142
3.48k
}
143
144
void
145
jbig2_arith_int_ctx_free(Jbig2Ctx *ctx, Jbig2ArithIntCtx *iax)
146
2.54k
{
147
2.54k
    jbig2_free(ctx->allocator, iax);
148
2.54k
}