Coverage Report

Created: 2025-12-10 06:38

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/jbig2dec/jbig2.c
Line
Count
Source
1
/* Copyright (C) 2001-2023 Artifex Software, Inc.
2
   All Rights Reserved.
3
4
   This software is provided AS-IS with no warranty, either express or
5
   implied.
6
7
   This software is distributed under license and may not be copied,
8
   modified or distributed except as expressly authorized under the terms
9
   of the license contained in the file LICENSE in this distribution.
10
11
   Refer to licensing information at http://www.artifex.com or contact
12
   Artifex Software, Inc.,  39 Mesa Street, Suite 108A, San Francisco,
13
   CA 94129, USA, for further information.
14
*/
15
16
/*
17
    jbig2dec
18
*/
19
20
#ifdef HAVE_CONFIG_H
21
#include "config.h"
22
#endif
23
#include "os_types.h"
24
25
#include <stdio.h>
26
#include <stdlib.h>
27
#include <stdarg.h>
28
#include <string.h>
29
#include <limits.h>
30
31
#include "jbig2.h"
32
#include "jbig2_priv.h"
33
#include "jbig2_image.h"
34
#include "jbig2_page.h"
35
#include "jbig2_segment.h"
36
37
static void *
38
jbig2_default_alloc(Jbig2Allocator *allocator, size_t size)
39
0
{
40
0
    return malloc(size);
41
0
}
42
43
static void
44
jbig2_default_free(Jbig2Allocator *allocator, void *p)
45
0
{
46
0
    free(p);
47
0
}
48
49
static void *
50
jbig2_default_realloc(Jbig2Allocator *allocator, void *p, size_t size)
51
0
{
52
0
    return realloc(p, size);
53
0
}
54
55
static Jbig2Allocator jbig2_default_allocator = {
56
    jbig2_default_alloc,
57
    jbig2_default_free,
58
    jbig2_default_realloc
59
};
60
61
void *
62
jbig2_alloc(Jbig2Allocator *allocator, size_t size, size_t num)
63
45.9M
{
64
    /* Check for integer multiplication overflow when computing
65
    the full size of the allocation. */
66
45.9M
    if (num > 0 && size > SIZE_MAX / num)
67
0
        return NULL;
68
45.9M
    return allocator->alloc(allocator, size * num);
69
45.9M
}
70
71
/* jbig2_free and jbig2_realloc moved to the bottom of this file */
72
73
static void
74
jbig2_default_error(void *data, const char *msg, Jbig2Severity severity, uint32_t seg_idx)
75
62.3M
{
76
    /* report only fatal errors by default */
77
62.3M
    if (severity == JBIG2_SEVERITY_FATAL) {
78
5.64k
        fprintf(stderr, "jbig2 decoder FATAL ERROR: %s", msg);
79
5.64k
        if (seg_idx != JBIG2_UNKNOWN_SEGMENT_NUMBER)
80
1.84k
            fprintf(stderr, " (segment 0x%02x)", seg_idx);
81
5.64k
        fprintf(stderr, "\n");
82
5.64k
        fflush(stderr);
83
5.64k
    }
84
62.3M
}
85
86
int
87
jbig2_error(Jbig2Ctx *ctx, Jbig2Severity severity, uint32_t segment_number, const char *fmt, ...)
88
62.3M
{
89
62.3M
    char buf[1024];
90
62.3M
    va_list ap;
91
62.3M
    int n;
92
93
62.3M
    va_start(ap, fmt);
94
62.3M
    n = vsnprintf(buf, sizeof(buf), fmt, ap);
95
62.3M
    va_end(ap);
96
62.3M
    if (n < 0 || n == sizeof(buf))
97
0
        strncpy(buf, "failed to generate error string", sizeof(buf));
98
62.3M
    ctx->error_callback(ctx->error_callback_data, buf, severity, segment_number);
99
62.3M
    return -1;
100
62.3M
}
101
102
Jbig2Ctx *
103
jbig2_ctx_new_imp(Jbig2Allocator *allocator, Jbig2Options options, Jbig2GlobalCtx *global_ctx, Jbig2ErrorCallback error_callback, void *error_callback_data, int jbig2_version_major, int jbig2_version_minor)
104
6.54k
{
105
6.54k
    Jbig2Ctx *result;
106
107
6.54k
    if (jbig2_version_major != JBIG2_VERSION_MAJOR || jbig2_version_minor != JBIG2_VERSION_MINOR) {
108
0
        Jbig2Ctx fakectx;
109
0
        fakectx.error_callback = error_callback;
110
0
        fakectx.error_callback_data = error_callback_data;
111
0
        jbig2_error(&fakectx, JBIG2_SEVERITY_FATAL, JBIG2_UNKNOWN_SEGMENT_NUMBER, "incompatible jbig2dec header (%d.%d) and library (%d.%d) versions",
112
0
            jbig2_version_major, jbig2_version_minor, JBIG2_VERSION_MAJOR, JBIG2_VERSION_MINOR);
113
0
        return NULL;
114
0
    }
115
116
6.54k
    if (allocator == NULL)
117
0
        allocator = &jbig2_default_allocator;
118
6.54k
    if (error_callback == NULL)
119
6.54k
        error_callback = &jbig2_default_error;
120
121
6.54k
    result = (Jbig2Ctx *) jbig2_alloc(allocator, sizeof(Jbig2Ctx), 1);
122
6.54k
    if (result == NULL) {
123
0
        error_callback(error_callback_data, "failed to allocate initial context", JBIG2_SEVERITY_FATAL, JBIG2_UNKNOWN_SEGMENT_NUMBER);
124
0
        return NULL;
125
0
    }
126
127
6.54k
    result->allocator = allocator;
128
6.54k
    result->options = options;
129
6.54k
    result->global_ctx = (const Jbig2Ctx *)global_ctx;
130
6.54k
    result->error_callback = error_callback;
131
6.54k
    result->error_callback_data = error_callback_data;
132
133
6.54k
    result->state = (options & JBIG2_OPTIONS_EMBEDDED) ? JBIG2_FILE_SEQUENTIAL_HEADER : JBIG2_FILE_HEADER;
134
135
6.54k
    result->buf = NULL;
136
137
6.54k
    result->n_segments = 0;
138
6.54k
    result->n_segments_max = 16;
139
6.54k
    result->segments = jbig2_new(result, Jbig2Segment *, result->n_segments_max);
140
6.54k
    if (result->segments == NULL) {
141
0
        error_callback(error_callback_data, "failed to allocate initial segments", JBIG2_SEVERITY_FATAL, JBIG2_UNKNOWN_SEGMENT_NUMBER);
142
0
        jbig2_free(allocator, result);
143
0
        return NULL;
144
0
    }
145
6.54k
    result->segment_index = 0;
146
147
6.54k
    result->current_page = 0;
148
6.54k
    result->max_page_index = 4;
149
6.54k
    result->pages = jbig2_new(result, Jbig2Page, result->max_page_index);
150
6.54k
    if (result->pages == NULL) {
151
0
        error_callback(error_callback_data, "failed to allocated initial pages", JBIG2_SEVERITY_FATAL, JBIG2_UNKNOWN_SEGMENT_NUMBER);
152
0
        jbig2_free(allocator, result->segments);
153
0
        jbig2_free(allocator, result);
154
0
        return NULL;
155
0
    }
156
6.54k
    {
157
6.54k
        uint32_t index;
158
159
32.7k
        for (index = 0; index < result->max_page_index; index++) {
160
26.1k
            result->pages[index].state = JBIG2_PAGE_FREE;
161
26.1k
            result->pages[index].number = 0;
162
26.1k
            result->pages[index].width = 0;
163
26.1k
            result->pages[index].height = 0xffffffff;
164
26.1k
            result->pages[index].x_resolution = 0;
165
26.1k
            result->pages[index].y_resolution = 0;
166
26.1k
            result->pages[index].stripe_size = 0;
167
26.1k
            result->pages[index].striped = 0;
168
26.1k
            result->pages[index].end_row = 0;
169
26.1k
            result->pages[index].flags = 0;
170
26.1k
            result->pages[index].image = NULL;
171
26.1k
        }
172
6.54k
    }
173
174
6.54k
    return result;
175
6.54k
}
176
177
#define get_uint16(bptr)\
178
1.89M
    (((bptr)[0] << 8) | (bptr)[1])
179
#define get_int16(bptr)\
180
12.1k
    (((int)get_uint16(bptr) ^ 0x8000) - 0x8000)
181
182
/* coverity[ -tainted_data_return ] */
183
/* coverity[ -tainted_data_argument : arg-0 ] */
184
int16_t
185
jbig2_get_int16(const byte *bptr)
186
3.89k
{
187
3.89k
    return get_int16(bptr);
188
3.89k
}
189
190
/* coverity[ -tainted_data_return ] */
191
/* coverity[ -tainted_data_argument : arg-0 ] */
192
uint16_t
193
jbig2_get_uint16(const byte *bptr)
194
19.3k
{
195
19.3k
    return get_uint16(bptr);
196
19.3k
}
197
198
/* coverity[ -tainted_data_return ] */
199
/* coverity[ -tainted_data_argument : arg-0 ] */
200
int32_t
201
jbig2_get_int32(const byte *bptr)
202
8.24k
{
203
8.24k
    return ((int32_t) get_int16(bptr) << 16) | get_uint16(bptr + 2);
204
8.24k
}
205
206
/* coverity[ -tainted_data_return ] */
207
/* coverity[ -tainted_data_argument : arg-0 ] */
208
uint32_t
209
jbig2_get_uint32(const byte *bptr)
210
927k
{
211
927k
    return ((uint32_t) get_uint16(bptr) << 16) | get_uint16(bptr + 2);
212
927k
}
213
214
static size_t
215
jbig2_find_buffer_size(size_t desired)
216
6.54k
{
217
6.54k
    const size_t initial_buf_size = 1024;
218
6.54k
    size_t size = initial_buf_size;
219
220
6.54k
    if (desired == SIZE_MAX)
221
0
        return SIZE_MAX;
222
223
9.48k
    while (size < desired)
224
2.94k
        size <<= 1;
225
226
6.54k
    return size;
227
6.54k
}
228
229
230
/**
231
 * jbig2_data_in: submit data for decoding
232
 * @ctx: The jbig2dec decoder context
233
 * @data: a pointer to the data buffer
234
 * @size: the size of the data buffer in bytes
235
 *
236
 * Copies the specified data into internal storage and attempts
237
 * to (continue to) parse it as part of a jbig2 data stream.
238
 *
239
 * Return code: 0 on success
240
 *             -1 if there is a parsing error
241
 **/
242
int
243
jbig2_data_in(Jbig2Ctx *ctx, const unsigned char *data, size_t size)
244
6.54k
{
245
6.54k
    if (ctx->buf == NULL) {
246
6.54k
        size_t buf_size = jbig2_find_buffer_size(size);
247
6.54k
        ctx->buf = jbig2_new(ctx, byte, buf_size);
248
6.54k
        if (ctx->buf == NULL) {
249
0
            return jbig2_error(ctx, JBIG2_SEVERITY_FATAL, JBIG2_UNKNOWN_SEGMENT_NUMBER, "failed to allocate buffer when reading data");
250
0
        }
251
6.54k
        ctx->buf_size = buf_size;
252
6.54k
        ctx->buf_rd_ix = 0;
253
6.54k
        ctx->buf_wr_ix = 0;
254
6.54k
    } else if (size > ctx->buf_size - ctx->buf_wr_ix) {
255
0
        size_t already = ctx->buf_wr_ix - ctx->buf_rd_ix;
256
257
0
        if (ctx->buf_rd_ix <= (ctx->buf_size >> 1) && size <= ctx->buf_size - already) {
258
0
            memmove(ctx->buf, ctx->buf + ctx->buf_rd_ix, already);
259
0
        } else {
260
0
            byte *buf;
261
0
            size_t buf_size;
262
263
0
            if (already > SIZE_MAX - size) {
264
0
                return jbig2_error(ctx, JBIG2_SEVERITY_FATAL, JBIG2_UNKNOWN_SEGMENT_NUMBER, "read data causes buffer to grow too large");
265
0
            }
266
267
0
            buf_size = jbig2_find_buffer_size(size + already);
268
269
0
            buf = jbig2_new(ctx, byte, buf_size);
270
0
            if (buf == NULL) {
271
0
                return jbig2_error(ctx, JBIG2_SEVERITY_FATAL, JBIG2_UNKNOWN_SEGMENT_NUMBER, "failed to allocate bigger buffer when reading data");
272
0
            }
273
0
            memcpy(buf, ctx->buf + ctx->buf_rd_ix, already);
274
0
            jbig2_free(ctx->allocator, ctx->buf);
275
0
            ctx->buf = buf;
276
0
            ctx->buf_size = buf_size;
277
0
        }
278
0
        ctx->buf_wr_ix -= ctx->buf_rd_ix;
279
0
        ctx->buf_rd_ix = 0;
280
0
    }
281
282
6.54k
    memcpy(ctx->buf + ctx->buf_wr_ix, data, size);
283
6.54k
    ctx->buf_wr_ix += size;
284
285
    /* data has now been added to buffer */
286
287
219k
    for (;;) {
288
219k
        const byte jbig2_id_string[8] = { 0x97, 0x4a, 0x42, 0x32, 0x0d, 0x0a, 0x1a, 0x0a };
289
219k
        Jbig2Segment *segment;
290
219k
        size_t header_size;
291
219k
        int code;
292
293
219k
        switch (ctx->state) {
294
6.54k
        case JBIG2_FILE_HEADER:
295
            /* D.4.1 */
296
6.54k
            if (ctx->buf_wr_ix - ctx->buf_rd_ix < 9)
297
6
                return 0;
298
6.54k
            if (memcmp(ctx->buf + ctx->buf_rd_ix, jbig2_id_string, 8))
299
71
                return jbig2_error(ctx, JBIG2_SEVERITY_FATAL, JBIG2_UNKNOWN_SEGMENT_NUMBER, "not a JBIG2 file header");
300
            /* D.4.2 */
301
6.47k
            ctx->file_header_flags = ctx->buf[ctx->buf_rd_ix + 8];
302
            /* Check for T.88 amendment 2 */
303
6.47k
            if (ctx->file_header_flags & 0x04)
304
1
                return jbig2_error(ctx, JBIG2_SEVERITY_FATAL, JBIG2_UNKNOWN_SEGMENT_NUMBER, "file header indicates use of 12 adaptive template pixels (NYI)");
305
            /* Check for T.88 amendment 3 */
306
6.46k
            if (ctx->file_header_flags & 0x08)
307
1
                return jbig2_error(ctx, JBIG2_SEVERITY_FATAL, JBIG2_UNKNOWN_SEGMENT_NUMBER, "file header indicates use of colored region segments (NYI)");
308
6.46k
            if (ctx->file_header_flags & 0xFC) {
309
1.43k
                jbig2_error(ctx, JBIG2_SEVERITY_WARNING, JBIG2_UNKNOWN_SEGMENT_NUMBER, "reserved bits (2-7) of file header flags are not zero (0x%02x)", ctx->file_header_flags);
310
1.43k
            }
311
            /* D.4.3 */
312
6.46k
            if (!(ctx->file_header_flags & 2)) {        /* number of pages is known */
313
2.17k
                if (ctx->buf_wr_ix - ctx->buf_rd_ix < 13)
314
7
                    return 0;
315
2.16k
                ctx->n_pages = jbig2_get_uint32(ctx->buf + ctx->buf_rd_ix + 9);
316
2.16k
                ctx->buf_rd_ix += 13;
317
2.16k
                if (ctx->n_pages == 1)
318
36
                    jbig2_error(ctx, JBIG2_SEVERITY_INFO, JBIG2_UNKNOWN_SEGMENT_NUMBER, "file header indicates a single page document");
319
2.13k
                else
320
2.13k
                    jbig2_error(ctx, JBIG2_SEVERITY_INFO, JBIG2_UNKNOWN_SEGMENT_NUMBER, "file header indicates a %d page document", ctx->n_pages);
321
4.29k
            } else {            /* number of pages not known */
322
4.29k
                ctx->n_pages = 0;
323
4.29k
                ctx->buf_rd_ix += 9;
324
4.29k
            }
325
            /* determine the file organization based on the flags - D.4.2 again */
326
6.46k
            if (ctx->file_header_flags & 1) {
327
5.56k
                ctx->state = JBIG2_FILE_SEQUENTIAL_HEADER;
328
5.56k
                jbig2_error(ctx, JBIG2_SEVERITY_DEBUG, JBIG2_UNKNOWN_SEGMENT_NUMBER, "file header indicates sequential organization");
329
5.56k
            } else {
330
900
                ctx->state = JBIG2_FILE_RANDOM_HEADERS;
331
900
                jbig2_error(ctx, JBIG2_SEVERITY_DEBUG, JBIG2_UNKNOWN_SEGMENT_NUMBER, "file header indicates random-access organization");
332
900
            }
333
6.46k
            break;
334
42.7k
        case JBIG2_FILE_SEQUENTIAL_HEADER:
335
170k
        case JBIG2_FILE_RANDOM_HEADERS:
336
170k
            segment = jbig2_parse_segment_header(ctx, ctx->buf + ctx->buf_rd_ix, ctx->buf_wr_ix - ctx->buf_rd_ix, &header_size);
337
170k
            if (segment == NULL)
338
1.25k
                return 0; /* need more data */
339
169k
            ctx->buf_rd_ix += header_size;
340
341
169k
            if (ctx->n_segments >= ctx->n_segments_max) {
342
604
                Jbig2Segment **segments;
343
344
604
                if (ctx->n_segments_max == UINT32_MAX) {
345
0
                    ctx->state = JBIG2_FILE_EOF;
346
0
                    jbig2_free_segment(ctx, segment);
347
0
                    return jbig2_error(ctx, JBIG2_SEVERITY_FATAL, segment->number, "too many segments in jbig2 image");
348
0
                }
349
604
                else if (ctx->n_segments_max > (UINT32_MAX >> 2)) {
350
0
                    ctx->n_segments_max = UINT32_MAX;
351
604
                } else {
352
604
                    ctx->n_segments_max <<= 2;
353
604
                }
354
355
604
                segments = jbig2_renew(ctx, ctx->segments, Jbig2Segment *, ctx->n_segments_max);
356
604
                if (segments == NULL) {
357
2
                    ctx->state = JBIG2_FILE_EOF;
358
2
                    jbig2_free_segment(ctx, segment);
359
2
                    return jbig2_error(ctx, JBIG2_SEVERITY_FATAL, segment->number, "failed to allocate space for more segments");
360
2
                }
361
602
                ctx->segments = segments;
362
602
            }
363
364
169k
            ctx->segments[ctx->n_segments++] = segment;
365
169k
            if (ctx->state == JBIG2_FILE_RANDOM_HEADERS) {
366
126k
                if ((segment->flags & 63) == 51)        /* end of file */
367
38
                    ctx->state = JBIG2_FILE_RANDOM_BODIES;
368
126k
            } else              /* JBIG2_FILE_SEQUENTIAL_HEADER */
369
42.3k
                ctx->state = JBIG2_FILE_SEQUENTIAL_BODY;
370
169k
            break;
371
42.3k
        case JBIG2_FILE_SEQUENTIAL_BODY:
372
42.6k
        case JBIG2_FILE_RANDOM_BODIES:
373
42.6k
            segment = ctx->segments[ctx->segment_index];
374
375
            /* immediate generic regions may have unknown size */
376
42.6k
            if (segment->data_length == 0xffffffff && (segment->flags & 63) == 38) {
377
12.3k
                byte *s, *e, *p;
378
12.3k
                int mmr;
379
12.3k
                byte mmr_marker[2] = { 0x00, 0x00 };
380
12.3k
                byte arith_marker[2] = { 0xff, 0xac };
381
12.3k
                byte *desired_marker;
382
383
12.3k
                s = p = ctx->buf + ctx->buf_rd_ix;
384
12.3k
                e = ctx->buf + ctx->buf_wr_ix;
385
386
12.3k
                if (e - p < 18)
387
33
                        return 0; /* need more data */
388
389
12.2k
                mmr = p[17] & 1;
390
12.2k
                p += 18;
391
12.2k
                desired_marker = mmr ? mmr_marker : arith_marker;
392
393
                /* look for two byte marker */
394
12.2k
                if (e - p < 2)
395
38
                    return 0; /* need more data */
396
397
2.62M
                while (p[0] != desired_marker[0] || p[1] != desired_marker[1]) {
398
2.60M
                    p++;
399
2.60M
                    if (e - p < 2)
400
407
                        return 0; /* need more data */
401
2.60M
                }
402
11.8k
                p += 2;
403
404
                /* the marker is followed by a four byte row count */
405
11.8k
                if (e - p < 4)
406
29
                        return 0; /* need more data */
407
11.8k
                segment->rows = jbig2_get_uint32(p);
408
11.8k
                p += 4;
409
410
11.8k
                segment->data_length = (size_t) (p - s);
411
11.8k
                jbig2_error(ctx, JBIG2_SEVERITY_INFO, segment->number, "unknown length determined to be %lu", (long) segment->data_length);
412
11.8k
            }
413
30.2k
            else if (segment->data_length > ctx->buf_wr_ix - ctx->buf_rd_ix)
414
3.62k
                    return 0; /* need more data */
415
416
38.4k
            code = jbig2_parse_segment(ctx, segment, ctx->buf + ctx->buf_rd_ix);
417
38.4k
            ctx->buf_rd_ix += segment->data_length;
418
38.4k
            ctx->segment_index++;
419
38.4k
            if (ctx->state == JBIG2_FILE_RANDOM_BODIES) {
420
253
                if (ctx->segment_index == ctx->n_segments)
421
0
                    ctx->state = JBIG2_FILE_EOF;
422
38.2k
            } else {            /* JBIG2_FILE_SEQUENTIAL_BODY */
423
38.2k
                ctx->state = JBIG2_FILE_SEQUENTIAL_HEADER;
424
38.2k
            }
425
38.4k
            if (code < 0) {
426
1.07k
                ctx->state = JBIG2_FILE_EOF;
427
1.07k
                return jbig2_error(ctx, JBIG2_SEVERITY_WARNING, segment->number, "failed to decode; treating as end of file");
428
1.07k
            }
429
37.4k
            break;
430
37.4k
        case JBIG2_FILE_EOF:
431
0
            if (ctx->buf_rd_ix == ctx->buf_wr_ix)
432
0
                return 0;
433
0
            return jbig2_error(ctx, JBIG2_SEVERITY_WARNING, JBIG2_UNKNOWN_SEGMENT_NUMBER, "garbage beyond end of file");
434
219k
        }
435
219k
    }
436
6.54k
}
437
438
Jbig2Allocator *
439
jbig2_ctx_free(Jbig2Ctx *ctx)
440
6.54k
{
441
6.54k
    Jbig2Allocator *ca;
442
6.54k
    uint32_t i;
443
444
6.54k
    if (ctx == NULL)
445
0
        return NULL;
446
447
6.54k
    ca = ctx->allocator;
448
6.54k
    jbig2_free(ca, ctx->buf);
449
6.54k
    if (ctx->segments != NULL) {
450
175k
        for (i = 0; i < ctx->n_segments; i++)
451
169k
            jbig2_free_segment(ctx, ctx->segments[i]);
452
6.54k
        jbig2_free(ca, ctx->segments);
453
6.54k
    }
454
455
6.54k
    if (ctx->pages != NULL) {
456
15.9k
        for (i = 0; i <= ctx->current_page; i++)
457
9.35k
            if (ctx->pages[i].image != NULL)
458
3.80k
                jbig2_image_release(ctx, ctx->pages[i].image);
459
6.54k
        jbig2_free(ca, ctx->pages);
460
6.54k
    }
461
462
6.54k
    jbig2_free(ca, ctx);
463
464
6.54k
    return ca;
465
6.54k
}
466
467
Jbig2GlobalCtx *
468
jbig2_make_global_ctx(Jbig2Ctx *ctx)
469
0
{
470
0
    return (Jbig2GlobalCtx *) ctx;
471
0
}
472
473
Jbig2Allocator *
474
jbig2_global_ctx_free(Jbig2GlobalCtx *global_ctx)
475
0
{
476
0
    return jbig2_ctx_free((Jbig2Ctx *) global_ctx);
477
0
}
478
479
/* I'm not committed to keeping the word stream interface. It's handy
480
   when you think you may be streaming your input, but if you're not
481
   (as is currently the case), it just adds complexity.
482
*/
483
484
typedef struct {
485
    Jbig2WordStream super;
486
    const byte *data;
487
    size_t size;
488
} Jbig2WordStreamBuf;
489
490
static int
491
jbig2_word_stream_buf_get_next_word(Jbig2Ctx *ctx, Jbig2WordStream *self, size_t offset, uint32_t *word)
492
15.1M
{
493
15.1M
    Jbig2WordStreamBuf *z = (Jbig2WordStreamBuf *) self;
494
15.1M
    uint32_t val = 0;
495
15.1M
    int ret = 0;
496
497
15.1M
    if (self == NULL || word == NULL) {
498
0
        return jbig2_error(ctx, JBIG2_SEVERITY_FATAL, JBIG2_UNKNOWN_SEGMENT_NUMBER, "failed to read next word of stream because stream or output missing");
499
0
    }
500
15.1M
    if (offset >= z->size) {
501
14.8M
        *word = 0;
502
14.8M
        return 0;
503
14.8M
    }
504
505
301k
    if (offset < z->size) {
506
301k
        val = (uint32_t) z->data[offset] << 24;
507
301k
        ret++;
508
301k
    }
509
301k
    if (offset + 1 < z->size) {
510
297k
        val |= (uint32_t) z->data[offset + 1] << 16;
511
297k
        ret++;
512
297k
    }
513
301k
    if (offset + 2 < z->size) {
514
293k
        val |= (uint32_t) z->data[offset + 2] << 8;
515
293k
        ret++;
516
293k
    }
517
301k
    if (offset + 3 < z->size) {
518
291k
        val |= z->data[offset + 3];
519
291k
        ret++;
520
291k
    }
521
301k
    *word = val;
522
301k
    return ret;
523
15.1M
}
524
525
Jbig2WordStream *
526
jbig2_word_stream_buf_new(Jbig2Ctx *ctx, const byte *data, size_t size)
527
21.9k
{
528
21.9k
    Jbig2WordStreamBuf *result = jbig2_new(ctx, Jbig2WordStreamBuf, 1);
529
530
21.9k
    if (result == NULL) {
531
6
        jbig2_error(ctx, JBIG2_SEVERITY_FATAL, JBIG2_UNKNOWN_SEGMENT_NUMBER, "failed to allocate word stream");
532
6
        return NULL;
533
6
    }
534
535
21.9k
    result->super.get_next_word = jbig2_word_stream_buf_get_next_word;
536
21.9k
    result->data = data;
537
21.9k
    result->size = size;
538
539
21.9k
    return &result->super;
540
21.9k
}
541
542
void
543
jbig2_word_stream_buf_free(Jbig2Ctx *ctx, Jbig2WordStream *ws)
544
22.5k
{
545
22.5k
    jbig2_free(ctx->allocator, ws);
546
22.5k
}
547
548
/* When Memento is in use, the ->free and ->realloc calls get
549
 * turned into ->Memento_free and ->Memento_realloc, which is
550
 * obviously problematic. Undefine free and realloc here to
551
 * avoid this. */
552
#ifdef MEMENTO
553
#undef free
554
#undef realloc
555
#endif
556
557
void
558
jbig2_free(Jbig2Allocator *allocator, void *p)
559
46.0M
{
560
46.0M
    allocator->free(allocator, p);
561
46.0M
}
562
563
void *
564
jbig2_realloc(Jbig2Allocator *allocator, void *p, size_t size, size_t num)
565
3.30k
{
566
    /* check for integer multiplication overflow */
567
3.30k
    if (num > 0 && size >= SIZE_MAX / num)
568
0
        return NULL;
569
3.30k
    return allocator->realloc(allocator, p, size * num);
570
3.30k
}