Coverage Report

Created: 2026-08-14 06:29

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/ProtoToGif.cpp
Line
Count
Source
1
#include "ProtoToGif.h"
2
3
using namespace gifProtoFuzzer;
4
using namespace std;
5
6
constexpr unsigned char ProtoConverter::m_sig[];
7
constexpr unsigned char ProtoConverter::m_ver89a[];
8
constexpr unsigned char ProtoConverter::m_ver87a[];
9
10
string ProtoConverter::gifProtoToString(GifProto const &proto)
11
1.04k
{
12
1.04k
  visit(proto);
13
1.04k
  return m_output.str();
14
1.04k
}
15
16
void ProtoConverter::visit(GifProto const &gif)
17
1.04k
{
18
1.04k
  visit(gif.header());
19
1.04k
  visit(gif.lsd());
20
1.04k
  if (m_hasGCT)
21
387
    visit(gif.gct());
22
1.04k
  for (auto const &chunk : gif.chunks())
23
5.49k
    visit(chunk);
24
1.04k
  visit(gif.trailer());
25
1.04k
}
26
27
void ProtoConverter::visit(Header const &header)
28
1.04k
{
29
  // Signature GIF
30
1.04k
  m_output.write((const char *)m_sig, sizeof(m_sig));
31
32
1.04k
  switch (header.ver())
33
1.04k
  {
34
473
  case Header::ENA:
35
473
    m_output.write((const char *)m_ver89a, sizeof(m_ver89a));
36
473
    break;
37
102
  case Header::ESA:
38
102
    m_output.write((const char *)m_ver87a, sizeof(m_ver87a));
39
102
    break;
40
  // We simply don't write anything if it's an invalid version
41
  // Bytes that follow (LSD) will be interpreted as version
42
469
  case Header::INV:
43
469
    break;
44
1.04k
  }
45
1.04k
}
46
47
void ProtoConverter::visit(LogicalScreenDescriptor const &lsd)
48
1.04k
{
49
1.04k
  writeWord(extractWordFromUInt32(lsd.screenwidth()));
50
1.04k
  writeWord(extractWordFromUInt32(lsd.screenheight()));
51
52
1.04k
  uint8_t packedByte = extractByteFromUInt32(lsd.packed());
53
  // If MSB of packed byte is 1, GCT follows
54
1.04k
  if (packedByte & 0x80)
55
387
  {
56
387
    m_hasGCT = true;
57
    // N: 2^(N+1) colors in GCT
58
387
    m_globalColorExp = packedByte & 0x07;
59
387
  }
60
1.04k
  writeByte(packedByte);
61
1.04k
  writeByte(extractByteFromUInt32(lsd.backgroundcolor()));
62
1.04k
  writeByte(extractByteFromUInt32(lsd.aspectratio()));
63
1.04k
}
64
65
void ProtoConverter::visit(GlobalColorTable const &gct)
66
387
{
67
  //[TODO 27/04/2019 VU]: Should it really be exactly the same size? Or do we want some deterministic randomness here?
68
  // TODO BS: We never overflow expected table size due to the use of min
69
387
  uint32_t tableSize = min((uint32_t)gct.colors().size(), tableExpToTableSize(m_globalColorExp));
70
387
  m_output.write(gct.colors().data(), tableSize);
71
387
}
72
73
void ProtoConverter::visit(GraphicControlExtension const &gce)
74
418
{
75
418
  writeByte(0x21); // Extension Introducer
76
418
  writeByte(0xF9); // Graphic Control Label
77
418
  writeByte(4); // Block size
78
418
  uint8_t packedByte = extractByteFromUInt32(gce.packed());
79
  // packed byte
80
418
  writeByte(packedByte);
81
  // Delay time is 2 bytes
82
418
  writeWord(extractWordFromUInt32(gce.delaytime()));
83
  // Transparent color index is 1 byte
84
418
  writeByte(extractByteFromUInt32(gce.transparentcolorindex()));
85
418
  writeByte(0x0); // Block Terminator
86
418
}
87
88
void ProtoConverter::visit(ImageChunk const &chunk)
89
5.49k
{
90
5.49k
  switch (chunk.chunk_oneof_case())
91
5.49k
  {
92
1.49k
  case ImageChunk::kBasic:
93
1.49k
    visit(chunk.basic());
94
1.49k
    break;
95
1.13k
  case ImageChunk::kPlaintext:
96
1.13k
    visit(chunk.plaintext());
97
1.13k
    break;
98
1.47k
  case ImageChunk::kAppExt:
99
1.47k
    visit(chunk.appext());
100
1.47k
    break;
101
709
  case ImageChunk::kComExt:
102
709
    visit(chunk.comext());
103
709
    break;
104
674
  case ImageChunk::CHUNK_ONEOF_NOT_SET:
105
674
    break;
106
5.49k
  }
107
5.49k
}
108
109
void ProtoConverter::visit(const BasicChunk &chunk)
110
1.49k
{
111
  // Visit GCExt if necessary
112
1.49k
  if (chunk.has_gcext())
113
206
    visit(chunk.gcext());
114
1.49k
  visit(chunk.imdescriptor());
115
1.49k
  if (m_hasLCT)
116
498
    visit(chunk.lct());
117
1.49k
  visit(chunk.img());
118
1.49k
}
119
120
void ProtoConverter::visit(LocalColorTable const &lct)
121
498
{
122
  //[TODO 27/04/2019 VU]: Should it really be exactly the same size? Or do we want some deterministic randomness here?
123
  // TODO BS: We never overflow expected table size due to the use of min
124
498
  uint32_t tableSize = min((uint32_t)lct.colors().size(), tableExpToTableSize(m_localColorExp));
125
498
  m_output.write(lct.colors().data(), tableSize);
126
498
}
127
128
void ProtoConverter::visit(ImageDescriptor const &descriptor)
129
1.49k
{
130
  // TODO: Remove seperator from proto since it is always 2C
131
1.49k
  writeByte(0x2C);
132
1.49k
  writeWord(extractWordFromUInt32(descriptor.left()));
133
1.49k
  writeWord(extractWordFromUInt32(descriptor.top()));
134
1.49k
  writeWord(extractWordFromUInt32(descriptor.height()));
135
1.49k
  writeWord(extractWordFromUInt32(descriptor.width()));
136
1.49k
  uint8_t packedByte = extractByteFromUInt32(descriptor.packed());
137
1.49k
  if (packedByte & 0x80)
138
498
  {
139
498
    m_hasLCT = true;
140
498
    m_localColorExp = packedByte & 0x07;
141
498
  }
142
999
  else
143
999
    m_hasLCT = false;
144
1.49k
}
145
146
void ProtoConverter::visit(SubBlock const &block)
147
15.2k
{
148
15.2k
  uint8_t len = extractByteFromUInt32(block.len());
149
15.2k
  if (len == 0)
150
2.49k
  {
151
2.49k
    writeByte(0x00);
152
2.49k
  }
153
12.7k
  else
154
12.7k
  {
155
    // TODO BS: We never overflow expected block size due to the use of min
156
12.7k
    uint32_t write_len = min((uint32_t)len, (uint32_t)block.data().size());
157
12.7k
    m_output.write(block.data().data(), write_len);
158
12.7k
  }
159
15.2k
}
160
161
void ProtoConverter::visit(ImageData const &img)
162
1.49k
{
163
  // TODO: Verify we are writing the image data correctly
164
  // LZW
165
1.49k
  writeByte(extractByteFromUInt32(img.lzw()));
166
  // Sub-blocks
167
1.49k
  for (auto const &block : img.subs())
168
1.16k
    visit(block);
169
  // NULL sub block signals end of image data
170
1.49k
  writeByte(0x00);
171
1.49k
}
172
173
void ProtoConverter::visit(PlainTextExtension const &ptExt)
174
1.13k
{
175
  // Visit GCExt if necessary
176
1.13k
  if (ptExt.has_gcext())
177
212
    visit(ptExt.gcext());
178
179
  // First two bytes are 0x21 0x01
180
1.13k
  writeByte(0x21);
181
1.13k
  writeByte(0x01);
182
  // Skip zero bytes
183
1.13k
  writeByte(0x00);
184
1.13k
  for (auto const &block : ptExt.subs())
185
6.09k
    visit(block);
186
  // NULL sub block signals end
187
1.13k
  writeByte(0x00);
188
1.13k
}
189
190
void ProtoConverter::visit(CommentExtension const &comExt)
191
709
{
192
  // First two bytes are 0x21 0xFE
193
709
  writeByte(0x21);
194
709
  writeByte(0xFE);
195
  // Sub-blocks
196
709
  for (auto const &block : comExt.subs())
197
5.90k
    visit(block);
198
  // NULL sub block signals end of image data
199
709
  writeByte(0x00);
200
709
}
201
202
void ProtoConverter::visit(ApplicationExtension const &appExt)
203
1.47k
{
204
  // First two bytes are 0x21 0xFF
205
1.47k
  writeByte(0x21);
206
1.47k
  writeByte(0xFF);
207
  // Next, we write "11" decimal or 0x0B
208
1.47k
  writeByte(0x0B);
209
1.47k
  writeLong(appExt.appid());
210
  // We hardcode the auth code to 1.0 or 0x31 0x2E 0x30
211
1.47k
  writeByte(0x31);
212
1.47k
  writeByte(0x2E);
213
1.47k
  writeByte(0x30);
214
  // Sub-blocks
215
1.47k
  for (auto const &block : appExt.subs())
216
2.11k
    visit(block);
217
  // NULL sub block signals end of image data
218
1.47k
  writeByte(0x00);
219
1.47k
}
220
221
void ProtoConverter::visit(Trailer const &)
222
1.04k
{
223
1.04k
  writeByte(0x3B);
224
1.04k
}
225
226
// =============================================================
227
// Utility functions
228
// =============================================================
229
void ProtoConverter::writeByte(uint8_t x)
230
30.6k
{
231
30.6k
  m_output.write((char *)&x, sizeof(x));
232
30.6k
}
233
234
void ProtoConverter::writeWord(uint16_t x)
235
8.49k
{
236
8.49k
  m_output.write((char *)&x, sizeof(x));
237
8.49k
}
238
239
void ProtoConverter::writeInt(uint32_t x)
240
0
{
241
0
  m_output.write((char *)&x, sizeof(x));
242
0
}
243
244
void ProtoConverter::writeLong(uint64_t x)
245
1.47k
{
246
1.47k
  m_output.write((char *)&x, sizeof(x));
247
1.47k
}
248
249
uint16_t ProtoConverter::extractWordFromUInt32(uint32_t a)
250
8.49k
{
251
8.49k
  uint16_t first_byte = (a & 0xFF);
252
8.49k
  uint16_t second_byte = ((a >> 8) & 0xFF) << 8;
253
8.49k
  return first_byte | second_byte;
254
8.49k
}
255
256
uint8_t ProtoConverter::extractByteFromUInt32(uint32_t a)
257
22.2k
{
258
22.2k
  uint8_t byte = a & 0x80;
259
22.2k
  return byte;
260
22.2k
}
261
262
/**
263
 * Given an exponent, returns the global/local color table size, given by 3*2^(exp+1)
264
 * @param tableExp The exponent
265
 * @return The actual color table size
266
 */
267
uint32_t ProtoConverter::tableExpToTableSize(uint32_t tableExp)
268
885
{
269
  // 0 <= tableExp <= 7
270
  // 6 <= tableSize <= 768
271
885
  uint32_t tableSize = 3 * (pow(2, tableExp + 1));
272
885
  return tableSize;
273
885
}