Coverage Report

Created: 2026-09-28 06:47

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/libjxl/lib/jxl/modular/encoding/dec_ma.cc
Line
Count
Source
1
// Copyright (c) the JPEG XL Project Authors. All rights reserved.
2
//
3
// Use of this source code is governed by a BSD-style
4
// license that can be found in the LICENSE file.
5
6
#include "lib/jxl/modular/encoding/dec_ma.h"
7
8
#include <jxl/memory_manager.h>
9
10
#include <algorithm>
11
#include <cstddef>
12
#include <cstdint>
13
#include <limits>
14
#include <utility>
15
#include <vector>
16
17
#include "lib/jxl/base/printf_macros.h"
18
#include "lib/jxl/base/status.h"
19
#include "lib/jxl/dec_ans.h"
20
#include "lib/jxl/dec_bit_reader.h"
21
#include "lib/jxl/modular/encoding/ma_common.h"
22
#include "lib/jxl/modular/modular_image.h"
23
#include "lib/jxl/modular/options.h"
24
#include "lib/jxl/pack_signed.h"
25
26
namespace jxl {
27
28
namespace {
29
30
enum class NextAction { CHECK_AND_GO_LEFT, GO_RIGHT, POP };
31
32
struct WorkItem {
33
  size_t node_index;
34
  pixel_type orig_l;
35
  pixel_type orig_u;
36
  NextAction action;
37
};
38
39
40.4k
Status ValidateTree(const Tree& tree) {
40
40.4k
  if (tree.empty()) return true;
41
  // TODO(eustas): or invalid?
42
43
40.4k
  int num_properties = 0;
44
152k
  for (auto node : tree) {
45
152k
    if (node.property >= num_properties) {
46
4.81k
      num_properties = node.property + 1;
47
4.81k
    }
48
152k
  }
49
50
40.4k
  std::vector<std::pair<pixel_type, pixel_type>> property_ranges(
51
40.4k
      num_properties);
52
77.0k
  for (int i = 0; i < num_properties; i++) {
53
36.6k
    property_ranges[i].first = std::numeric_limits<pixel_type>::min();
54
36.6k
    property_ranges[i].second = std::numeric_limits<pixel_type>::max();
55
36.6k
  }
56
57
40.4k
  constexpr size_t kHeightLimit = 2048;
58
59
40.4k
  std::vector<WorkItem> stack;
60
40.4k
  stack.push_back({/*node_index=*/0, /*orig_l=*/0, /*orig_u=*/0,
61
40.4k
                   NextAction::CHECK_AND_GO_LEFT});
62
63
304k
  while (!stack.empty()) {
64
263k
    if (stack.size() >= kHeightLimit) return JXL_FAILURE("Tree too tall");
65
263k
    WorkItem& item = stack.back();
66
263k
    const auto& node = tree[item.node_index];
67
263k
    switch (item.action) {
68
152k
      case NextAction::CHECK_AND_GO_LEFT: {
69
152k
        int16_t p = node.property;
70
152k
        if (p == -1) {
71
96.2k
          stack.pop_back();
72
96.2k
          continue;
73
96.2k
        }
74
55.9k
        PropertyVal v = node.splitval;
75
55.9k
        pixel_type l = property_ranges[p].first;
76
55.9k
        pixel_type u = property_ranges[p].second;
77
55.9k
        if (l > v || u <= v) {
78
18
          return JXL_FAILURE("Invalid tree");
79
18
        }
80
55.8k
        item.orig_l = l;
81
55.8k
        item.orig_u = u;
82
55.8k
        item.action = NextAction::GO_RIGHT;
83
55.8k
        property_ranges[node.property].first = node.splitval + 1;
84
55.8k
        stack.push_back({/*node_index=*/node.lchild,
85
55.8k
                         /*orig_l=*/0, /*orig_u=*/0,
86
55.8k
                         NextAction::CHECK_AND_GO_LEFT});
87
55.8k
        continue;
88
55.9k
      }
89
90
55.8k
      case NextAction::GO_RIGHT:
91
55.8k
        item.action = NextAction::POP;
92
55.8k
        property_ranges[node.property].first = item.orig_l;
93
55.8k
        property_ranges[node.property].second = node.splitval;
94
55.8k
        stack.push_back({/*node_index=*/node.rchild,
95
55.8k
                         /*orig_l=*/0, /*orig_u=*/0,
96
55.8k
                         NextAction::CHECK_AND_GO_LEFT});
97
55.8k
        continue;
98
99
55.8k
      case NextAction::POP:
100
55.8k
        property_ranges[node.property].second = item.orig_u;
101
55.8k
        stack.pop_back();
102
55.8k
        continue;
103
263k
    }
104
263k
  }
105
106
40.4k
  return true;
107
40.4k
}
108
109
Status DecodeTree(BitReader* br, ANSSymbolReader* reader,
110
                  const std::vector<uint8_t>& context_map, Tree* tree,
111
40.6k
                  size_t tree_size_limit) {
112
40.6k
  size_t leaf_id = 0;
113
40.6k
  size_t to_decode = 1;
114
40.6k
  tree->clear();
115
581k
  while (to_decode > 0) {
116
540k
    JXL_RETURN_IF_ERROR(br->AllReadsWithinBounds());
117
540k
    if (tree->size() > tree_size_limit) {
118
10
      return JXL_FAILURE("Tree is too large: %" PRIuS " nodes vs %" PRIuS
119
10
                         " max nodes",
120
10
                         tree->size(), tree_size_limit);
121
10
    }
122
540k
    to_decode--;
123
540k
    uint32_t prop1 = reader->ReadHybridUint(kPropertyContext, br, context_map);
124
540k
    if (prop1 > 256) return JXL_FAILURE("Invalid tree property value");
125
540k
    int property = prop1 - 1;
126
540k
    if (property == -1) {
127
159k
      size_t predictor =
128
159k
          reader->ReadHybridUint(kPredictorContext, br, context_map);
129
159k
      if (predictor >= kNumModularPredictors) {
130
8
        return JXL_FAILURE("Invalid predictor");
131
8
      }
132
159k
      int64_t predictor_offset =
133
159k
          UnpackSigned(reader->ReadHybridUint(kOffsetContext, br, context_map));
134
159k
      uint32_t mul_log =
135
159k
          reader->ReadHybridUint(kMultiplierLogContext, br, context_map);
136
159k
      if (mul_log >= 31) {
137
2
        return JXL_FAILURE("Invalid multiplier logarithm");
138
2
      }
139
159k
      uint32_t mul_bits =
140
159k
          reader->ReadHybridUint(kMultiplierBitsContext, br, context_map);
141
159k
      if (mul_bits >= (1u << (31u - mul_log)) - 1u) {
142
2
        return JXL_FAILURE("Invalid multiplier");
143
2
      }
144
159k
      uint32_t multiplier = (mul_bits + 1U) << mul_log;
145
159k
      Predictor p = static_cast<Predictor>(static_cast<uint32_t>(predictor));
146
159k
      tree->emplace_back(-1, 0, static_cast<int>(leaf_id), 0, p,
147
159k
                         predictor_offset, multiplier);
148
159k
      leaf_id++;
149
159k
      continue;
150
159k
    }
151
381k
    int splitval =
152
381k
        UnpackSigned(reader->ReadHybridUint(kSplitValContext, br, context_map));
153
381k
    tree->emplace_back(
154
381k
        property, splitval, static_cast<int>(tree->size() + to_decode + 1),
155
381k
        static_cast<int>(tree->size() + to_decode + 2), Predictor::Zero, 0, 1);
156
381k
    to_decode += 2;
157
381k
  }
158
40.4k
  return ValidateTree(*tree);
159
40.6k
}
160
}  // namespace
161
162
Status DecodeTree(JxlMemoryManager* memory_manager, BitReader* br, Tree* tree,
163
40.8k
                  size_t tree_size_limit) {
164
40.8k
  std::vector<uint8_t> tree_context_map;
165
40.8k
  ANSCode tree_code;
166
40.8k
  JXL_RETURN_IF_ERROR(DecodeHistograms(memory_manager, br, kNumTreeContexts,
167
40.8k
                                       &tree_code, &tree_context_map));
168
  // TODO(eustas): investigate more infinite tree cases.
169
40.6k
  if (tree_code.degenerate_symbols[tree_context_map[kPropertyContext]] > 0) {
170
5
    return JXL_FAILURE("Infinite tree");
171
5
  }
172
81.2k
  JXL_ASSIGN_OR_RETURN(ANSSymbolReader reader,
173
81.2k
                       ANSSymbolReader::Create(&tree_code, br));
174
81.2k
  JXL_RETURN_IF_ERROR(DecodeTree(br, &reader, tree_context_map, tree,
175
81.2k
                                 std::min(tree_size_limit, kMaxTreeSize)));
176
40.4k
  if (!reader.CheckANSFinalState()) {
177
0
    return JXL_FAILURE("ANS decode final state failed");
178
0
  }
179
40.4k
  return true;
180
40.4k
}
181
182
}  // namespace jxl