Coverage Report

Created: 2026-03-12 07:14

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/ffmpeg/libavcodec/exif.c
Line
Count
Source
1
/*
2
 * EXIF metadata parser
3
 * Copyright (c) 2013 Thilo Borgmann <thilo.borgmann _at_ mail.de>
4
 * Copyright (c) 2024-2025 Leo Izen <leo.izen@gmail.com>
5
 *
6
 * This file is part of FFmpeg.
7
 *
8
 * FFmpeg is free software; you can redistribute it and/or
9
 * modify it under the terms of the GNU Lesser General Public
10
 * License as published by the Free Software Foundation; either
11
 * version 2.1 of the License, or (at your option) any later version.
12
 *
13
 * FFmpeg is distributed in the hope that it will be useful,
14
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
16
 * Lesser General Public License for more details.
17
 *
18
 * You should have received a copy of the GNU Lesser General Public
19
 * License along with FFmpeg; if not, write to the Free Software
20
 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
21
 */
22
23
/**
24
 * @file
25
 * EXIF metadata parser
26
 * @author Thilo Borgmann <thilo.borgmann _at_ mail.de>
27
 * @author Leo Izen <leo.izen@gmail.com>
28
 */
29
30
#include <inttypes.h>
31
32
#include "libavutil/avconfig.h"
33
#include "libavutil/bprint.h"
34
#include "libavutil/display.h"
35
#include "libavutil/intreadwrite.h"
36
#include "libavutil/mem.h"
37
38
#include "bytestream.h"
39
#include "exif_internal.h"
40
#include "tiff_common.h"
41
42
0
#define EXIF_II_LONG           0x49492a00
43
0
#define EXIF_MM_LONG           0x4d4d002a
44
45
0
#define BASE_TAG_SIZE          12
46
0
#define IFD_EXTRA_SIZE         6
47
48
#define EXIF_TAG_NAME_LENGTH   32
49
0
#define MAKERNOTE_TAG          0x927c
50
0
#define ORIENTATION_TAG        0x112
51
0
#define EXIFIFD_TAG            0x8769
52
0
#define IMAGE_WIDTH_TAG        0x100
53
0
#define IMAGE_LENGTH_TAG       0x101
54
0
#define PIXEL_X_TAG            0xa002
55
0
#define PIXEL_Y_TAG            0xa003
56
57
struct exif_tag {
58
    const char name[EXIF_TAG_NAME_LENGTH];
59
    uint16_t id;
60
};
61
62
static const struct exif_tag tag_list[] = { // JEITA CP-3451 EXIF specification:
63
    {"GPSVersionID",               0x00}, // <- Table 12 GPS Attribute Information
64
    {"GPSLatitudeRef",             0x01},
65
    {"GPSLatitude",                0x02},
66
    {"GPSLongitudeRef",            0x03},
67
    {"GPSLongitude",               0x04},
68
    {"GPSAltitudeRef",             0x05},
69
    {"GPSAltitude",                0x06},
70
    {"GPSTimeStamp",               0x07},
71
    {"GPSSatellites",              0x08},
72
    {"GPSStatus",                  0x09},
73
    {"GPSMeasureMode",             0x0A},
74
    {"GPSDOP",                     0x0B},
75
    {"GPSSpeedRef",                0x0C},
76
    {"GPSSpeed",                   0x0D},
77
    {"GPSTrackRef",                0x0E},
78
    {"GPSTrack",                   0x0F},
79
    {"GPSImgDirectionRef",         0x10},
80
    {"GPSImgDirection",            0x11},
81
    {"GPSMapDatum",                0x12},
82
    {"GPSDestLatitudeRef",         0x13},
83
    {"GPSDestLatitude",            0x14},
84
    {"GPSDestLongitudeRef",        0x15},
85
    {"GPSDestLongitude",           0x16},
86
    {"GPSDestBearingRef",          0x17},
87
    {"GPSDestBearing",             0x18},
88
    {"GPSDestDistanceRef",         0x19},
89
    {"GPSDestDistance",            0x1A},
90
    {"GPSProcessingMethod",        0x1B},
91
    {"GPSAreaInformation",         0x1C},
92
    {"GPSDateStamp",               0x1D},
93
    {"GPSDifferential",            0x1E},
94
    {"ImageWidth",                 0x100}, // <- Table 3 TIFF Rev. 6.0 Attribute Information Used in Exif
95
    {"ImageLength",                0x101},
96
    {"BitsPerSample",              0x102},
97
    {"Compression",                0x103},
98
    {"PhotometricInterpretation",  0x106},
99
    {"Orientation",                0x112},
100
    {"SamplesPerPixel",            0x115},
101
    {"PlanarConfiguration",        0x11C},
102
    {"YCbCrSubSampling",           0x212},
103
    {"YCbCrPositioning",           0x213},
104
    {"XResolution",                0x11A},
105
    {"YResolution",                0x11B},
106
    {"ResolutionUnit",             0x128},
107
    {"StripOffsets",               0x111},
108
    {"RowsPerStrip",               0x116},
109
    {"StripByteCounts",            0x117},
110
    {"JPEGInterchangeFormat",      0x201},
111
    {"JPEGInterchangeFormatLength",0x202},
112
    {"TransferFunction",           0x12D},
113
    {"WhitePoint",                 0x13E},
114
    {"PrimaryChromaticities",      0x13F},
115
    {"YCbCrCoefficients",          0x211},
116
    {"ReferenceBlackWhite",        0x214},
117
    {"DateTime",                   0x132},
118
    {"ImageDescription",           0x10E},
119
    {"Make",                       0x10F},
120
    {"Model",                      0x110},
121
    {"Software",                   0x131},
122
    {"Artist",                     0x13B},
123
    {"Copyright",                  0x8298},
124
    {"ExifVersion",                0x9000}, // <- Table 4 Exif IFD Attribute Information (1)
125
    {"FlashpixVersion",            0xA000},
126
    {"ColorSpace",                 0xA001},
127
    {"ComponentsConfiguration",    0x9101},
128
    {"CompressedBitsPerPixel",     0x9102},
129
    {"PixelXDimension",            0xA002},
130
    {"PixelYDimension",            0xA003},
131
    {"MakerNote",                  0x927C},
132
    {"UserComment",                0x9286},
133
    {"RelatedSoundFile",           0xA004},
134
    {"DateTimeOriginal",           0x9003},
135
    {"DateTimeDigitized",          0x9004},
136
    {"SubSecTime",                 0x9290},
137
    {"SubSecTimeOriginal",         0x9291},
138
    {"SubSecTimeDigitized",        0x9292},
139
    {"ImageUniqueID",              0xA420},
140
    {"ExposureTime",               0x829A}, // <- Table 5 Exif IFD Attribute Information (2)
141
    {"FNumber",                    0x829D},
142
    {"ExposureProgram",            0x8822},
143
    {"SpectralSensitivity",        0x8824},
144
    {"ISOSpeedRatings",            0x8827},
145
    {"OECF",                       0x8828},
146
    {"ShutterSpeedValue",          0x9201},
147
    {"ApertureValue",              0x9202},
148
    {"BrightnessValue",            0x9203},
149
    {"ExposureBiasValue",          0x9204},
150
    {"MaxApertureValue",           0x9205},
151
    {"SubjectDistance",            0x9206},
152
    {"MeteringMode",               0x9207},
153
    {"LightSource",                0x9208},
154
    {"Flash",                      0x9209},
155
    {"FocalLength",                0x920A},
156
    {"SubjectArea",                0x9214},
157
    {"FlashEnergy",                0xA20B},
158
    {"SpatialFrequencyResponse",   0xA20C},
159
    {"FocalPlaneXResolution",      0xA20E},
160
    {"FocalPlaneYResolution",      0xA20F},
161
    {"FocalPlaneResolutionUnit",   0xA210},
162
    {"SubjectLocation",            0xA214},
163
    {"ExposureIndex",              0xA215},
164
    {"SensingMethod",              0xA217},
165
    {"FileSource",                 0xA300},
166
    {"SceneType",                  0xA301},
167
    {"CFAPattern",                 0xA302},
168
    {"CustomRendered",             0xA401},
169
    {"ExposureMode",               0xA402},
170
    {"WhiteBalance",               0xA403},
171
    {"DigitalZoomRatio",           0xA404},
172
    {"FocalLengthIn35mmFilm",      0xA405},
173
    {"SceneCaptureType",           0xA406},
174
    {"GainControl",                0xA407},
175
    {"Contrast",                   0xA408},
176
    {"Saturation",                 0xA409},
177
    {"Sharpness",                  0xA40A},
178
    {"DeviceSettingDescription",   0xA40B},
179
    {"SubjectDistanceRange",       0xA40C},
180
181
    /* InteropIFD tags */
182
    {"RelatedImageFileFormat",     0x1000},
183
    {"RelatedImageWidth",          0x1001},
184
    {"RelatedImageLength",         0x1002},
185
186
    /* private EXIF tags */
187
    {"PrintImageMatching",         0xC4A5}, // <- undocumented meaning
188
189
    /* IFD tags */
190
    {"ExifIFD",                    0x8769}, // <- An IFD pointing to standard Exif metadata
191
    {"GPSInfo",                    0x8825}, // <- An IFD pointing to GPS Exif Metadata
192
    {"InteropIFD",                 0xA005}, // <- Table 13 Interoperability IFD Attribute Information
193
    {"GlobalParametersIFD",        0x0190},
194
    {"ProfileIFD",                 0xc6f5},
195
196
    /* Extra FFmpeg tags */
197
    { "IFD1",                      0xFFFC},
198
    { "IFD2",                      0xFFFB},
199
    { "IFD3",                      0xFFFA},
200
    { "IFD4",                      0xFFF9},
201
    { "IFD5",                      0xFFF8},
202
    { "IFD6",                      0xFFF7},
203
    { "IFD7",                      0xFFF6},
204
    { "IFD8",                      0xFFF5},
205
    { "IFD9",                      0xFFF4},
206
    { "IFD10",                     0xFFF3},
207
    { "IFD11",                     0xFFF2},
208
    { "IFD12",                     0xFFF1},
209
    { "IFD13",                     0xFFF0},
210
    { "IFD14",                     0xFFEF},
211
    { "IFD15",                     0xFFEE},
212
    { "IFD16",                     0xFFED},
213
};
214
215
/* same as type_sizes but with string == 1 */
216
static const size_t exif_sizes[] = {
217
    [0] = 0,
218
    [AV_TIFF_BYTE] = 1,
219
    [AV_TIFF_STRING] = 1,
220
    [AV_TIFF_SHORT] = 2,
221
    [AV_TIFF_LONG] = 4,
222
    [AV_TIFF_RATIONAL] = 8,
223
    [AV_TIFF_SBYTE] = 1,
224
    [AV_TIFF_UNDEFINED] = 1,
225
    [AV_TIFF_SSHORT] = 2,
226
    [AV_TIFF_SLONG] = 4,
227
    [AV_TIFF_SRATIONAL] = 8,
228
    [AV_TIFF_FLOAT] = 4,
229
    [AV_TIFF_DOUBLE] = 8,
230
    [AV_TIFF_IFD] = 4,
231
};
232
233
const char *av_exif_get_tag_name(uint16_t id)
234
0
{
235
0
    for (size_t i = 0; i < FF_ARRAY_ELEMS(tag_list); i++) {
236
0
        if (tag_list[i].id == id)
237
0
            return tag_list[i].name;
238
0
    }
239
240
0
    return NULL;
241
0
}
242
243
int32_t av_exif_get_tag_id(const char *name)
244
0
{
245
0
    if (!name)
246
0
        return -1;
247
248
0
    for (size_t i = 0; i < FF_ARRAY_ELEMS(tag_list); i++) {
249
0
        if (!strcmp(tag_list[i].name, name))
250
0
            return tag_list[i].id;
251
0
    }
252
253
0
    return -1;
254
0
}
255
256
static inline void tput16(PutByteContext *pb, const int le, const uint16_t value)
257
0
{
258
0
    le ? bytestream2_put_le16(pb, value) : bytestream2_put_be16(pb, value);
259
0
}
260
261
static inline void tput32(PutByteContext *pb, const int le, const uint32_t value)
262
0
{
263
0
    le ? bytestream2_put_le32(pb, value) : bytestream2_put_be32(pb, value);
264
0
}
265
266
static inline void tput64(PutByteContext *pb, const int le, const uint64_t value)
267
0
{
268
0
    le ? bytestream2_put_le64(pb, value) : bytestream2_put_be64(pb, value);
269
0
}
270
271
static int exif_read_values(void *logctx, GetByteContext *gb, int le, AVExifEntry *entry)
272
0
{
273
0
    if (exif_sizes[entry->type] * entry->count > bytestream2_get_bytes_left(gb))
274
0
        return AVERROR_INVALIDDATA;
275
276
0
    switch (entry->type) {
277
0
        case AV_TIFF_SHORT:
278
0
        case AV_TIFF_LONG:
279
0
            entry->value.uint = av_calloc(entry->count, sizeof(*entry->value.uint));
280
0
            break;
281
0
        case AV_TIFF_SSHORT:
282
0
        case AV_TIFF_SLONG:
283
0
            entry->value.sint = av_calloc(entry->count, sizeof(*entry->value.sint));
284
0
            break;
285
0
        case AV_TIFF_DOUBLE:
286
0
        case AV_TIFF_FLOAT:
287
0
            entry->value.dbl = av_calloc(entry->count, sizeof(*entry->value.dbl));
288
0
            break;
289
0
        case AV_TIFF_RATIONAL:
290
0
        case AV_TIFF_SRATIONAL:
291
0
            entry->value.rat = av_calloc(entry->count, sizeof(*entry->value.rat));
292
0
            break;
293
0
        case AV_TIFF_UNDEFINED:
294
0
        case AV_TIFF_BYTE:
295
0
            entry->value.ubytes = av_mallocz(entry->count);
296
0
            break;
297
0
        case AV_TIFF_SBYTE:
298
0
            entry->value.sbytes = av_mallocz(entry->count);
299
0
            break;
300
0
        case AV_TIFF_STRING:
301
0
            entry->value.str = av_mallocz(entry->count + 1);
302
0
            break;
303
0
        case AV_TIFF_IFD:
304
0
            av_log(logctx, AV_LOG_WARNING, "Bad IFD type for non-IFD tag\n");
305
0
            return AVERROR_INVALIDDATA;
306
0
    }
307
0
    if (!entry->value.ptr)
308
0
        return AVERROR(ENOMEM);
309
0
    switch (entry->type) {
310
0
        case AV_TIFF_SHORT:
311
0
            for (size_t i = 0; i < entry->count; i++)
312
0
                entry->value.uint[i] = ff_tget_short(gb, le);
313
0
            break;
314
0
        case AV_TIFF_LONG:
315
0
            for (size_t i = 0; i < entry->count; i++)
316
0
                entry->value.uint[i] = ff_tget_long(gb, le);
317
0
            break;
318
0
        case AV_TIFF_SSHORT:
319
0
            for (size_t i = 0; i < entry->count; i++)
320
0
                entry->value.sint[i] = (int16_t) ff_tget_short(gb, le);
321
0
            break;
322
0
        case AV_TIFF_SLONG:
323
0
            for (size_t i = 0; i < entry->count; i++)
324
0
                entry->value.sint[i] = (int32_t) ff_tget_long(gb, le);
325
0
            break;
326
0
        case AV_TIFF_DOUBLE:
327
0
            for (size_t i = 0; i < entry->count; i++)
328
0
                entry->value.dbl[i] = ff_tget_double(gb, le);
329
0
            break;
330
0
        case AV_TIFF_FLOAT:
331
0
            for (size_t i = 0; i < entry->count; i++) {
332
0
                av_alias32 alias = { .u32 = ff_tget_long(gb, le) };
333
0
                entry->value.dbl[i] = alias.f32;
334
0
            }
335
0
            break;
336
0
        case AV_TIFF_RATIONAL:
337
0
        case AV_TIFF_SRATIONAL:
338
0
            for (size_t i = 0; i < entry->count; i++) {
339
0
                int32_t num = ff_tget_long(gb, le);
340
0
                int32_t den = ff_tget_long(gb, le);
341
0
                entry->value.rat[i] = av_make_q(num, den);
342
0
            }
343
0
            break;
344
0
        case AV_TIFF_UNDEFINED:
345
0
        case AV_TIFF_BYTE:
346
            /* these three fields are aliased to entry->value.ptr via a union */
347
            /* and entry->value.ptr will always be nonzero here */
348
0
            av_assert0(entry->value.ubytes);
349
0
            bytestream2_get_buffer(gb, entry->value.ubytes, entry->count);
350
0
            break;
351
0
        case AV_TIFF_SBYTE:
352
0
            av_assert0(entry->value.sbytes);
353
0
            bytestream2_get_buffer(gb, entry->value.sbytes, entry->count);
354
0
            break;
355
0
        case AV_TIFF_STRING:
356
0
            av_assert0(entry->value.str);
357
0
            bytestream2_get_buffer(gb, entry->value.str, entry->count);
358
0
            break;
359
0
    }
360
361
0
    return 0;
362
0
}
363
364
static void exif_write_values(PutByteContext *pb, int le, const AVExifEntry *entry)
365
0
{
366
0
    switch (entry->type) {
367
0
        case AV_TIFF_SHORT:
368
0
            for (size_t i = 0; i < entry->count; i++)
369
0
                tput16(pb, le, entry->value.uint[i]);
370
0
            break;
371
0
        case AV_TIFF_LONG:
372
0
            for (size_t i = 0; i < entry->count; i++)
373
0
                tput32(pb, le, entry->value.uint[i]);
374
0
            break;
375
0
        case AV_TIFF_SSHORT:
376
0
            for (size_t i = 0; i < entry->count; i++)
377
0
                tput16(pb, le, entry->value.sint[i]);
378
0
            break;
379
0
        case AV_TIFF_SLONG:
380
0
            for (size_t i = 0; i < entry->count; i++)
381
0
                tput32(pb, le, entry->value.sint[i]);
382
0
            break;
383
0
        case AV_TIFF_DOUBLE:
384
0
            for (size_t i = 0; i < entry->count; i++) {
385
0
                const av_alias64 a = { .f64 = entry->value.dbl[i] };
386
0
                tput64(pb, le, a.u64);
387
0
            }
388
0
            break;
389
0
        case AV_TIFF_FLOAT:
390
0
            for (size_t i = 0; i < entry->count; i++) {
391
0
                const av_alias32 a = { .f32 = entry->value.dbl[i] };
392
0
                tput32(pb, le, a.u32);
393
0
            }
394
0
            break;
395
0
        case AV_TIFF_RATIONAL:
396
0
        case AV_TIFF_SRATIONAL:
397
0
            for (size_t i = 0; i < entry->count; i++) {
398
0
                tput32(pb, le, entry->value.rat[i].num);
399
0
                tput32(pb, le, entry->value.rat[i].den);
400
0
            }
401
0
            break;
402
0
        case AV_TIFF_UNDEFINED:
403
0
        case AV_TIFF_BYTE:
404
0
            bytestream2_put_buffer(pb, entry->value.ubytes, entry->count);
405
0
            break;
406
0
        case AV_TIFF_SBYTE:
407
0
            bytestream2_put_buffer(pb, entry->value.sbytes, entry->count);
408
0
            break;
409
0
        case AV_TIFF_STRING:
410
0
            bytestream2_put_buffer(pb, entry->value.str, entry->count);
411
0
            break;
412
0
    }
413
0
}
414
415
static const uint8_t aoc_header[] = { 'A', 'O', 'C', 0, };
416
static const uint8_t casio_header[] = { 'Q', 'V', 'C', 0, 0, 0, };
417
static const uint8_t foveon_header[] = { 'F', 'O', 'V', 'E', 'O', 'N', 0, 0, };
418
static const uint8_t fuji_header[] = { 'F', 'U', 'J', 'I', };
419
static const uint8_t nikon_header[] = { 'N', 'i', 'k', 'o', 'n', 0, };
420
static const uint8_t olympus1_header[] = { 'O', 'L', 'Y', 'M', 'P', 0, };
421
static const uint8_t olympus2_header[] = { 'O', 'L', 'Y', 'M', 'P', 'U', 'S', 0, 'I', 'I', };
422
static const uint8_t panasonic_header[] = { 'P', 'a', 'n', 'a', 's', 'o', 'n', 'i', 'c', 0, 0, 0, };
423
static const uint8_t sigma_header[] = { 'S', 'I', 'G', 'M', 'A', 0, 0, 0, };
424
static const uint8_t sony_header[] = { 'S', 'O', 'N', 'Y', ' ', 'D', 'S', 'C', ' ', 0, 0, 0, };
425
426
struct exif_makernote_data {
427
    const uint8_t *header;
428
    size_t header_size;
429
    int result;
430
};
431
432
#define MAKERNOTE_STRUCT(h, r) { \
433
    .header = (h),               \
434
    .header_size = sizeof((h)),  \
435
    .result = (r),               \
436
}
437
438
static const struct exif_makernote_data makernote_data[] = {
439
    MAKERNOTE_STRUCT(aoc_header, 6),
440
    MAKERNOTE_STRUCT(casio_header, -1),
441
    MAKERNOTE_STRUCT(foveon_header, 10),
442
    MAKERNOTE_STRUCT(fuji_header, -1),
443
    MAKERNOTE_STRUCT(olympus1_header, 8),
444
    MAKERNOTE_STRUCT(olympus2_header, -1),
445
    MAKERNOTE_STRUCT(panasonic_header, 12),
446
    MAKERNOTE_STRUCT(sigma_header, 10),
447
    MAKERNOTE_STRUCT(sony_header, 12),
448
};
449
450
/*
451
 * derived from Exiv2 MakerNote's article
452
 * https://exiv2.org/makernote.html or archived at
453
 * https://web.archive.org/web/20250311155857/https://exiv2.org/makernote.html
454
 */
455
static int exif_get_makernote_offset(GetByteContext *gb)
456
0
{
457
0
    if (bytestream2_get_bytes_left(gb) < BASE_TAG_SIZE)
458
0
        return -1;
459
460
0
    for (int i = 0; i < FF_ARRAY_ELEMS(makernote_data); i++) {
461
0
        if (!memcmp(gb->buffer, makernote_data[i].header, makernote_data[i].header_size))
462
0
            return makernote_data[i].result;
463
0
    }
464
465
0
    if (!memcmp(gb->buffer, nikon_header, sizeof(nikon_header))) {
466
0
        if (bytestream2_get_bytes_left(gb) < 14)
467
0
            return -1;
468
0
        else if (AV_RB32(gb->buffer + 10) == EXIF_MM_LONG || AV_RB32(gb->buffer + 10) == EXIF_II_LONG)
469
0
            return -1;
470
0
        return 8;
471
0
    }
472
473
0
    return 0;
474
0
}
475
476
static int exif_parse_ifd_list(void *logctx, GetByteContext *gb, int le,
477
                               int depth, AVExifMetadata *ifd, int guess);
478
479
static int exif_decode_tag(void *logctx, GetByteContext *gb, int le,
480
                           int depth, AVExifEntry *entry)
481
0
{
482
0
    int ret = 0, makernote_offset = -1, tell, is_ifd, count;
483
0
    enum AVTiffDataType type;
484
0
    uint32_t payload;
485
486
    /* safety check to prevent infinite recursion on malicious IFDs */
487
0
    if (depth > 3)
488
0
        return AVERROR_INVALIDDATA;
489
490
0
    tell = bytestream2_tell(gb);
491
492
0
    entry->id = ff_tget_short(gb, le);
493
0
    type = ff_tget_short(gb, le);
494
0
    count = ff_tget_long(gb, le);
495
0
    payload = ff_tget_long(gb, le);
496
497
0
    av_log(logctx, AV_LOG_DEBUG, "TIFF Tag: id: 0x%04x, type: %d, count: %u, offset: %d, "
498
0
                                 "payload: %" PRIu32 "\n", entry->id, type, count, tell, payload);
499
500
0
    if (!type) {
501
0
        av_log(logctx, AV_LOG_DEBUG, "Skipping invalid TIFF tag 0\n");
502
0
        goto end;
503
0
    }
504
505
    /* AV_TIFF_IFD is the largest, numerically */
506
0
    if (type > AV_TIFF_IFD || count >= INT_MAX/8U)
507
0
        return AVERROR_INVALIDDATA;
508
509
0
    is_ifd = type == AV_TIFF_IFD || ff_tis_ifd(entry->id) || entry->id == MAKERNOTE_TAG;
510
511
0
    if (is_ifd) {
512
0
        if (!payload)
513
0
            goto end;
514
0
        bytestream2_seek(gb, payload, SEEK_SET);
515
0
    }
516
517
0
    if (entry->id == MAKERNOTE_TAG) {
518
0
        makernote_offset = exif_get_makernote_offset(gb);
519
0
        if (makernote_offset < 0)
520
0
            is_ifd = 0;
521
0
    }
522
523
0
    if (is_ifd) {
524
0
        entry->type = AV_TIFF_IFD;
525
0
        entry->count = 1;
526
0
        entry->ifd_offset = makernote_offset > 0 ? makernote_offset : 0;
527
0
        if (entry->ifd_offset) {
528
0
            entry->ifd_lead = av_malloc(entry->ifd_offset);
529
0
            if (!entry->ifd_lead)
530
0
                return AVERROR(ENOMEM);
531
0
            bytestream2_get_buffer(gb, entry->ifd_lead, entry->ifd_offset);
532
0
        }
533
0
        ret = exif_parse_ifd_list(logctx, gb, le, depth + 1, &entry->value.ifd, entry->id == MAKERNOTE_TAG);
534
0
        if (ret < 0 && entry->id == MAKERNOTE_TAG) {
535
            /*
536
             * we guessed that MakerNote was an IFD
537
             * but we were probably incorrect at this
538
             * point so we try again as a binary blob
539
             */
540
0
            av_log(logctx, AV_LOG_DEBUG, "unrecognized MakerNote IFD, retrying as blob\n");
541
0
            is_ifd = 0;
542
0
        }
543
0
    }
544
545
    /* inverted condition instead of else so we can fall through from above */
546
0
    if (!is_ifd) {
547
0
        entry->type = type == AV_TIFF_IFD ? AV_TIFF_UNDEFINED : type;
548
0
        entry->count = count;
549
0
        bytestream2_seek(gb, count * exif_sizes[type] > 4 ? payload : tell + 8, SEEK_SET);
550
0
        ret = exif_read_values(logctx, gb, le, entry);
551
0
    }
552
553
0
end:
554
0
    bytestream2_seek(gb, tell + BASE_TAG_SIZE, SEEK_SET);
555
556
0
    return ret;
557
0
}
558
559
static int exif_parse_ifd_list(void *logctx, GetByteContext *gb, int le,
560
                               int depth, AVExifMetadata *ifd, int guess)
561
0
{
562
0
    uint32_t entries;
563
0
    size_t required_size;
564
0
    void *temp;
565
0
    int ret = 0;
566
567
0
    av_log(logctx, AV_LOG_DEBUG, "parsing IFD list at offset: %d\n", bytestream2_tell(gb));
568
569
0
    if (bytestream2_get_bytes_left(gb) < 2) {
570
0
        av_log(logctx, guess ? AV_LOG_DEBUG : AV_LOG_ERROR,
571
0
               "not enough bytes remaining in EXIF buffer: 2 required\n");
572
0
        ret = AVERROR_INVALIDDATA;
573
0
        goto end;
574
0
    }
575
576
0
    entries = ff_tget_short(gb, le);
577
0
    if (bytestream2_get_bytes_left(gb) < entries * BASE_TAG_SIZE) {
578
0
        av_log(logctx, guess ? AV_LOG_DEBUG : AV_LOG_ERROR,
579
0
               "not enough bytes remaining in EXIF buffer. entries: %" PRIu32 "\n", entries);
580
0
        ret = AVERROR_INVALIDDATA;
581
0
        goto end;
582
0
    }
583
0
    if (entries > 4096) {
584
        /* that is a lot of entries, probably an error */
585
0
        av_log(logctx, guess ? AV_LOG_DEBUG : AV_LOG_ERROR,
586
0
               "too many entries: %" PRIu32 "\n", entries);
587
0
        ret = AVERROR_INVALIDDATA;
588
0
        goto end;
589
0
    }
590
591
0
    ifd->count = entries;
592
0
    av_log(logctx, AV_LOG_DEBUG, "entry count for IFD: %u\n", ifd->count);
593
594
    /* empty IFD is technically legal but equivalent to no metadata present */
595
0
    if (!ifd->count) {
596
0
        ret = 0;
597
0
        goto end;
598
0
    }
599
600
0
    if (av_size_mult(ifd->count, sizeof(*ifd->entries), &required_size) < 0) {
601
0
        ret = AVERROR(ENOMEM);
602
0
        goto end;
603
0
    }
604
0
    temp = av_fast_realloc(ifd->entries, &ifd->size, required_size);
605
0
    if (!temp) {
606
0
        av_freep(&ifd->entries);
607
0
        ret = AVERROR(ENOMEM);
608
0
        goto end;
609
0
    }
610
0
    ifd->entries = temp;
611
612
    /* entries have pointers in them which can cause issues if */
613
    /* they are freed or realloc'd when garbage */
614
0
    memset(ifd->entries, 0, required_size);
615
616
0
    for (uint32_t i = 0; i < entries; i++) {
617
0
        ret = exif_decode_tag(logctx, gb, le, depth, &ifd->entries[i]);
618
0
        if (ret < 0)
619
0
            goto end;
620
0
    }
621
622
0
end:
623
0
    if (ret < 0) {
624
0
        av_exif_free(ifd);
625
0
        return ret;
626
0
    }
627
    /*
628
     * at the end of an IFD is an pointer to the next IFD
629
     * or zero if there are no more IFDs, which is usually the case
630
     */
631
0
    ret = ff_tget_long(gb, le);
632
633
    /* overflow */
634
0
    if (ret < 0) {
635
0
        ret = AVERROR_INVALIDDATA;
636
0
        av_exif_free(ifd);
637
0
    }
638
639
0
    return ret;
640
0
}
641
642
/*
643
 * note that this function does not free the entry pointer itself
644
 * because it's probably part of a larger array that should be freed
645
 * all at once
646
 */
647
static void exif_free_entry(AVExifEntry *entry)
648
0
{
649
0
    if (!entry)
650
0
        return;
651
0
    if (entry->type == AV_TIFF_IFD)
652
0
        av_exif_free(&entry->value.ifd);
653
0
    else
654
0
        av_freep(&entry->value.ptr);
655
0
    av_freep(&entry->ifd_lead);
656
0
}
657
658
void av_exif_free(AVExifMetadata *ifd)
659
0
{
660
0
    if (!ifd)
661
0
        return;
662
0
    if (!ifd->entries) {
663
0
        ifd->count = 0;
664
0
        ifd->size = 0;
665
0
        return;
666
0
    }
667
0
    for (size_t i = 0; i < ifd->count; i++) {
668
0
        AVExifEntry *entry = &ifd->entries[i];
669
0
        exif_free_entry(entry);
670
0
    }
671
0
    av_freep(&ifd->entries);
672
0
    ifd->count = 0;
673
0
    ifd->size = 0;
674
0
}
675
676
static size_t exif_get_ifd_size(const AVExifMetadata *ifd)
677
0
{
678
    /* 6 == 4 + 2; 2-byte entry-count at the beginning */
679
    /* plus 4-byte next-IFD pointer at the end */
680
0
    size_t total_size = IFD_EXTRA_SIZE;
681
0
    for (size_t i = 0; i < ifd->count; i++) {
682
0
        const AVExifEntry *entry = &ifd->entries[i];
683
0
        if (entry->type == AV_TIFF_IFD) {
684
0
            total_size += BASE_TAG_SIZE + exif_get_ifd_size(&entry->value.ifd) + entry->ifd_offset;
685
0
        } else {
686
0
            size_t payload_size = entry->count * exif_sizes[entry->type];
687
0
            total_size += BASE_TAG_SIZE + (payload_size > 4 ? payload_size : 0);
688
0
        }
689
0
    }
690
0
    return total_size;
691
0
}
692
693
static int exif_write_ifd(void *logctx, PutByteContext *pb, int le, int depth, const AVExifMetadata *ifd)
694
0
{
695
0
    int offset, ret, tell, tell2;
696
0
    tell = bytestream2_tell_p(pb);
697
0
    tput16(pb, le, ifd->count);
698
0
    offset = tell + IFD_EXTRA_SIZE + BASE_TAG_SIZE * (uint32_t) ifd->count;
699
0
    av_log(logctx, AV_LOG_DEBUG, "writing IFD with %u entries and initial offset %d\n", ifd->count, offset);
700
0
    for (size_t i = 0; i < ifd->count; i++) {
701
0
        const AVExifEntry *entry = &ifd->entries[i];
702
0
        av_log(logctx, AV_LOG_DEBUG, "writing TIFF entry: id: 0x%04" PRIx16 ", type: %d, count: %"
703
0
                                      PRIu32 ", offset: %d, offset value: %d\n",
704
0
                                      entry->id, entry->type, entry->count,
705
0
                                      bytestream2_tell_p(pb), offset);
706
0
        tput16(pb, le, entry->id);
707
0
        if (entry->id == MAKERNOTE_TAG && entry->type == AV_TIFF_IFD) {
708
0
            size_t ifd_size = exif_get_ifd_size(&entry->value.ifd);
709
0
            tput16(pb, le, AV_TIFF_UNDEFINED);
710
0
            tput32(pb, le, ifd_size);
711
0
        } else {
712
0
            tput16(pb, le, entry->type);
713
0
            tput32(pb, le, entry->count);
714
0
        }
715
0
        if (entry->type == AV_TIFF_IFD) {
716
0
            tput32(pb, le, offset);
717
0
            tell2 = bytestream2_tell_p(pb);
718
0
            bytestream2_seek_p(pb, offset, SEEK_SET);
719
0
            if (entry->ifd_offset)
720
0
                bytestream2_put_buffer(pb, entry->ifd_lead, entry->ifd_offset);
721
0
            ret = exif_write_ifd(logctx, pb, le, depth + 1, &entry->value.ifd);
722
0
            if (ret < 0)
723
0
                return ret;
724
0
            offset += ret + entry->ifd_offset;
725
0
            bytestream2_seek_p(pb, tell2, SEEK_SET);
726
0
        } else {
727
0
            size_t payload_size = entry->count * exif_sizes[entry->type];
728
0
            if (payload_size > 4) {
729
0
                tput32(pb, le, offset);
730
0
                tell2 = bytestream2_tell_p(pb);
731
0
                bytestream2_seek_p(pb, offset, SEEK_SET);
732
0
                exif_write_values(pb, le, entry);
733
0
                offset += payload_size;
734
0
                bytestream2_seek_p(pb, tell2, SEEK_SET);
735
0
            } else {
736
                /* zero uninitialized excess payload values */
737
0
                AV_WN32(pb->buffer, 0);
738
0
                exif_write_values(pb, le, entry);
739
0
                bytestream2_seek_p(pb, 4 - payload_size, SEEK_CUR);
740
0
            }
741
0
        }
742
0
    }
743
744
    /*
745
     * we write 0 if this is the top-level exif IFD
746
     * indicating that there are no more IFD pointers
747
     */
748
0
    tput32(pb, le, depth ? offset : 0);
749
0
    return offset - tell;
750
0
}
751
752
int av_exif_write(void *logctx, const AVExifMetadata *ifd, AVBufferRef **buffer, enum AVExifHeaderMode header_mode)
753
0
{
754
0
    AVBufferRef *buf = NULL;
755
0
    size_t size, headsize = 8;
756
0
    PutByteContext pb;
757
0
    int ret = 0, off = 0, next;
758
0
    AVExifMetadata *ifd_new = NULL;
759
0
    AVExifMetadata extra_ifds[16] = { 0 };
760
761
0
    int le = 1;
762
763
0
    if (*buffer) {
764
0
        ret = AVERROR(EINVAL);
765
0
        goto end;
766
0
    }
767
768
0
    size = exif_get_ifd_size(ifd);
769
0
    switch (header_mode) {
770
0
        case AV_EXIF_EXIF00:
771
0
            off = 6;
772
0
            break;
773
0
        case AV_EXIF_T_OFF:
774
0
            off = 4;
775
0
            break;
776
0
        case AV_EXIF_ASSUME_BE:
777
0
            le = 0;
778
0
            headsize = 0;
779
0
            break;
780
0
        case AV_EXIF_ASSUME_LE:
781
0
            le = 1;
782
0
            headsize = 0;
783
0
            break;
784
0
    }
785
786
0
    ret = av_buffer_realloc(&buf, size + off + headsize);
787
0
    if (ret < 0)
788
0
        goto end;
789
790
0
    if (header_mode == AV_EXIF_EXIF00) {
791
0
        AV_WL32(buf->data, MKTAG('E','x','i','f'));
792
0
        AV_WN16(buf->data + 4, 0);
793
0
    } else if (header_mode == AV_EXIF_T_OFF) {
794
0
        AV_WN32(buf->data, 0);
795
0
    }
796
797
0
    bytestream2_init_writer(&pb, buf->data + off, buf->size - off);
798
799
0
    if (header_mode != AV_EXIF_ASSUME_BE && header_mode != AV_EXIF_ASSUME_LE) {
800
        /* these constants are be32 in both cases */
801
        /* le == 1 always in this case */
802
0
        bytestream2_put_be32(&pb, EXIF_II_LONG);
803
0
        tput32(&pb, le, 8);
804
0
    }
805
806
0
    int extras = 0;
807
0
    for (int i = 0; i < FF_ARRAY_ELEMS(extra_ifds); i++) {
808
0
        AVExifEntry *extra_entry = NULL;
809
0
        uint16_t extra_tag = 0xFFFCu - i;
810
0
        ret = av_exif_get_entry(logctx, (AVExifMetadata *) ifd, extra_tag, 0, &extra_entry);
811
0
        if (ret < 0)
812
0
            break;
813
0
        if (!ret)
814
0
            continue;
815
0
        av_log(logctx, AV_LOG_DEBUG, "found extra IFD tag: %04x\n", extra_tag);
816
0
        if (!ifd_new) {
817
0
            ifd_new = av_exif_clone_ifd(ifd);
818
0
            if (!ifd_new)
819
0
                break;
820
0
            ifd = ifd_new;
821
0
        }
822
        /* calling remove_entry will call av_exif_free on the original */
823
0
        AVExifMetadata *cloned = av_exif_clone_ifd(&extra_entry->value.ifd);
824
0
        if (!cloned)
825
0
            break;
826
0
        extra_ifds[extras++] = *cloned;
827
        /* don't use av_exif_free here, we want to preserve internals */
828
0
        av_free(cloned);
829
0
        ret = av_exif_remove_entry(logctx, ifd_new, extra_tag, 0);
830
0
        if (ret < 0)
831
0
            break;
832
0
    }
833
834
0
    if (ret < 0) {
835
0
        av_log(logctx, AV_LOG_ERROR, "error popping additional IFD: %s\n", av_err2str(ret));
836
0
        goto end;
837
0
    }
838
839
0
    next = bytestream2_tell_p(&pb);
840
0
    ret = exif_write_ifd(logctx, &pb, le, 0, ifd);
841
0
    if (ret < 0) {
842
0
        av_log(logctx, AV_LOG_ERROR, "error writing EXIF data: %s\n", av_err2str(ret));
843
0
        goto end;
844
0
    }
845
0
    next += ret;
846
847
0
    for (int i = 0; i < extras; i++) {
848
0
        av_log(logctx, AV_LOG_DEBUG, "writing additional ifd at: %d\n", next);
849
        /* exif_write_ifd always writes 0 i.e. last ifd so we overwrite that here */
850
0
        bytestream2_seek_p(&pb, -4, SEEK_CUR);
851
0
        tput32(&pb, le, next);
852
0
        bytestream2_seek_p(&pb, next, SEEK_SET);
853
0
        ret = exif_write_ifd(logctx, &pb, le, 0, &extra_ifds[i]);
854
0
        if (ret < 0) {
855
0
            av_log(logctx, AV_LOG_ERROR, "error writing additional IFD: %s\n", av_err2str(ret));
856
0
            goto end;
857
0
        }
858
0
        next += ret;
859
0
    }
860
861
    /* shrink the buffer to the amount of data we actually used */
862
    /* extras don't contribute the initial BASE_TAG_SIZE each */
863
0
    ret = av_buffer_realloc(&buf, buf->size - BASE_TAG_SIZE * extras);
864
0
    if (ret < 0)
865
0
        goto end;
866
867
0
    *buffer = buf;
868
0
    ret = 0;
869
870
0
end:
871
0
    av_exif_free(ifd_new);
872
0
    av_freep(&ifd_new);
873
0
    for (int i = 0; i < FF_ARRAY_ELEMS(extra_ifds); i++)
874
0
        av_exif_free(&extra_ifds[i]);
875
0
    if (ret < 0)
876
0
        av_buffer_unref(&buf);
877
878
0
    return ret;
879
0
}
880
881
int av_exif_parse_buffer(void *logctx, const uint8_t *buf, size_t size,
882
                         AVExifMetadata *ifd, enum AVExifHeaderMode header_mode)
883
0
{
884
0
    int ret, le;
885
0
    GetByteContext gbytes;
886
0
    if (size > INT_MAX)
887
0
        return AVERROR(EINVAL);
888
0
    size_t off = 0;
889
0
    switch (header_mode) {
890
0
        case AV_EXIF_EXIF00:
891
0
            if (size < 6)
892
0
                return AVERROR_INVALIDDATA;
893
0
            off = 6;
894
            /* fallthrough */
895
0
        case AV_EXIF_T_OFF:
896
0
            if (size < 4)
897
0
                return AVERROR_INVALIDDATA;
898
0
            if (!off)
899
0
                off = AV_RB32(buf) + 4;
900
            /* fallthrough */
901
0
        case AV_EXIF_TIFF_HEADER: {
902
0
            int ifd_offset;
903
0
            if (size <= off)
904
0
                return AVERROR_INVALIDDATA;
905
0
            bytestream2_init(&gbytes, buf + off, size - off);
906
            // read TIFF header
907
0
            ret = ff_tdecode_header(&gbytes, &le, &ifd_offset);
908
0
            if (ret < 0) {
909
0
                av_log(logctx, AV_LOG_ERROR, "invalid TIFF header in EXIF data: %s\n", av_err2str(ret));
910
0
                return ret;
911
0
            }
912
0
            bytestream2_seek(&gbytes, ifd_offset, SEEK_SET);
913
0
            break;
914
0
        }
915
0
        case AV_EXIF_ASSUME_LE:
916
0
            le = 1;
917
0
            bytestream2_init(&gbytes, buf, size);
918
0
            break;
919
0
        case AV_EXIF_ASSUME_BE:
920
0
            le = 0;
921
0
            bytestream2_init(&gbytes, buf, size);
922
0
            break;
923
0
        default:
924
0
            return AVERROR(EINVAL);
925
0
    }
926
927
    /*
928
     * parse IFD0 here. If the return value is positive that tells us
929
     * there is subimage metadata, but we don't parse that IFD here
930
     */
931
0
    ret = exif_parse_ifd_list(logctx, &gbytes, le, 0, ifd, 0);
932
0
    if (ret < 0) {
933
0
        av_log(logctx, AV_LOG_ERROR, "error decoding EXIF data: %s\n", av_err2str(ret));
934
0
        return ret;
935
0
    }
936
0
    if (!ret)
937
0
        goto finish;
938
0
    int next = ret;
939
0
    bytestream2_seek(&gbytes, next, SEEK_SET);
940
941
    /* cap at 16 extra IFDs for sanity/parse security */
942
0
    for (int extra_tag = 0xFFFCu; extra_tag > 0xFFECu; extra_tag--) {
943
0
        AVExifMetadata extra_ifd = { 0 };
944
0
        ret = exif_parse_ifd_list(logctx, &gbytes, le, 0, &extra_ifd, 1);
945
0
        if (ret < 0) {
946
0
            av_exif_free(&extra_ifd);
947
0
            break;
948
0
        }
949
0
        next = ret;
950
0
        av_log(logctx, AV_LOG_DEBUG, "found extra IFD: %04x with next=%d\n", extra_tag, ret);
951
0
        bytestream2_seek(&gbytes, next, SEEK_SET);
952
0
        ret = av_exif_set_entry(logctx, ifd, extra_tag, AV_TIFF_IFD, 1, NULL, 0, &extra_ifd);
953
0
        av_exif_free(&extra_ifd);
954
0
        if (ret < 0 || !next || bytestream2_get_bytes_left(&gbytes) <= 0)
955
0
            break;
956
0
    }
957
958
0
finish:
959
0
    return bytestream2_tell(&gbytes) + off;
960
0
}
961
962
0
#define COLUMN_SEP(i, c) ((i) ? ((i) % (c) ? ", " : "\n") : "")
963
964
static int exif_ifd_to_dict(void *logctx, const char *prefix, const AVExifMetadata *ifd, AVDictionary **metadata)
965
0
{
966
0
    AVBPrint bp;
967
0
    int ret = 0;
968
0
    char *key = NULL;
969
0
    char *value = NULL;
970
971
0
    if (!prefix)
972
0
        prefix = "";
973
974
0
    for (uint16_t i = 0; i < ifd->count; i++) {
975
0
        const AVExifEntry *entry = &ifd->entries[i];
976
0
        const char *name = av_exif_get_tag_name(entry->id);
977
0
        av_bprint_init(&bp, entry->count * 10, AV_BPRINT_SIZE_UNLIMITED);
978
0
        if (*prefix)
979
0
            av_bprintf(&bp, "%s/", prefix);
980
0
        if (name)
981
0
            av_bprintf(&bp, "%s", name);
982
0
        else
983
0
            av_bprintf(&bp, "0x%04X", entry->id);
984
0
        ret = av_bprint_finalize(&bp, &key);
985
0
        if (ret < 0)
986
0
            goto end;
987
0
        av_bprint_init(&bp, entry->count * 10, AV_BPRINT_SIZE_UNLIMITED);
988
0
        switch (entry->type) {
989
0
            case AV_TIFF_IFD:
990
0
                ret = exif_ifd_to_dict(logctx, key, &entry->value.ifd, metadata);
991
0
                if (ret < 0)
992
0
                    goto end;
993
0
                break;
994
0
            case AV_TIFF_SHORT:
995
0
            case AV_TIFF_LONG:
996
0
                for (uint32_t j = 0; j < entry->count; j++)
997
0
                    av_bprintf(&bp, "%s%7" PRIu32, COLUMN_SEP(j, 8), (uint32_t)entry->value.uint[j]);
998
0
                break;
999
0
            case AV_TIFF_SSHORT:
1000
0
            case AV_TIFF_SLONG:
1001
0
                for (uint32_t j = 0; j < entry->count; j++)
1002
0
                    av_bprintf(&bp, "%s%7" PRId32, COLUMN_SEP(j, 8), (int32_t)entry->value.sint[j]);
1003
0
                break;
1004
0
            case AV_TIFF_RATIONAL:
1005
0
            case AV_TIFF_SRATIONAL:
1006
0
                for (uint32_t j = 0; j < entry->count; j++)
1007
0
                    av_bprintf(&bp, "%s%7i:%-7i", COLUMN_SEP(j, 4), entry->value.rat[j].num, entry->value.rat[j].den);
1008
0
                break;
1009
0
            case AV_TIFF_DOUBLE:
1010
0
            case AV_TIFF_FLOAT:
1011
0
                for (uint32_t j = 0; j < entry->count; j++)
1012
0
                    av_bprintf(&bp, "%s%.15g", COLUMN_SEP(j, 4), entry->value.dbl[j]);
1013
0
                break;
1014
0
            case AV_TIFF_STRING:
1015
0
                av_bprintf(&bp, "%s", entry->value.str);
1016
0
                break;
1017
0
            case AV_TIFF_UNDEFINED:
1018
0
            case AV_TIFF_BYTE:
1019
0
                for (uint32_t j = 0; j < entry->count; j++)
1020
0
                    av_bprintf(&bp, "%s%3i", COLUMN_SEP(j, 16), entry->value.ubytes[j]);
1021
0
                break;
1022
0
            case AV_TIFF_SBYTE:
1023
0
                for (uint32_t j = 0; j < entry->count; j++)
1024
0
                    av_bprintf(&bp, "%s%3i", COLUMN_SEP(j, 16), entry->value.sbytes[j]);
1025
0
                break;
1026
0
        }
1027
0
        if (entry->type != AV_TIFF_IFD) {
1028
0
            if (!av_bprint_is_complete(&bp)) {
1029
0
                av_bprint_finalize(&bp, NULL);
1030
0
                ret = AVERROR(ENOMEM);
1031
0
                goto end;
1032
0
            }
1033
0
            ret = av_bprint_finalize(&bp, &value);
1034
0
            if (ret < 0)
1035
0
                goto end;
1036
0
            ret = av_dict_set(metadata, key, value, AV_DICT_DONT_STRDUP_KEY | AV_DICT_DONT_STRDUP_VAL);
1037
0
            key = NULL;
1038
0
            value = NULL;
1039
0
            if (ret < 0)
1040
0
                goto end;
1041
0
        } else {
1042
0
            av_freep(&key);
1043
0
        }
1044
0
    }
1045
1046
0
end:
1047
0
    av_freep(&key);
1048
0
    av_freep(&value);
1049
0
    return ret;
1050
0
}
1051
1052
int av_exif_ifd_to_dict(void *logctx, const AVExifMetadata *ifd, AVDictionary **metadata)
1053
0
{
1054
0
    return exif_ifd_to_dict(logctx, "", ifd, metadata);
1055
0
}
1056
1057
#if LIBAVCODEC_VERSION_MAJOR < 63
1058
int avpriv_exif_decode_ifd(void *logctx, const uint8_t *buf, int size,
1059
                           int le, int depth, AVDictionary **metadata)
1060
0
{
1061
0
    AVExifMetadata ifd = { 0 };
1062
0
    GetByteContext gb;
1063
0
    int ret;
1064
0
    bytestream2_init(&gb, buf, size);
1065
0
    ret = exif_parse_ifd_list(logctx, &gb, le, depth, &ifd, 0);
1066
0
    if (ret < 0)
1067
0
        return ret;
1068
0
    ret = av_exif_ifd_to_dict(logctx, &ifd, metadata);
1069
0
    av_exif_free(&ifd);
1070
0
    return ret;
1071
0
}
1072
#endif
1073
1074
0
#define EXIF_COPY(fname, srcname) do { \
1075
0
    size_t sz; \
1076
0
    if (av_size_mult(src->count, sizeof(*(fname)), &sz) < 0) { \
1077
0
        ret = AVERROR(ENOMEM); \
1078
0
        goto end; \
1079
0
    } \
1080
0
    (fname) = av_memdup((srcname), sz); \
1081
0
    if (!(fname)) { \
1082
0
        ret = AVERROR(ENOMEM); \
1083
0
        goto end; \
1084
0
    } \
1085
0
} while (0)
1086
1087
static int exif_clone_entry(AVExifEntry *dst, const AVExifEntry *src)
1088
0
{
1089
0
    int ret = 0;
1090
1091
0
    memset(dst, 0, sizeof(*dst));
1092
1093
0
    dst->count = src->count;
1094
0
    dst->id = src->id;
1095
0
    dst->type = src->type;
1096
1097
0
    dst->ifd_offset = src->ifd_offset;
1098
0
    if (src->ifd_lead) {
1099
0
        dst->ifd_lead = av_memdup(src->ifd_lead, src->ifd_offset);
1100
0
        if (!dst->ifd_lead) {
1101
0
            ret = AVERROR(ENOMEM);
1102
0
            goto end;
1103
0
        }
1104
0
    } else {
1105
0
        dst->ifd_lead = NULL;
1106
0
    }
1107
1108
0
    switch(src->type) {
1109
0
        case AV_TIFF_IFD: {
1110
0
            AVExifMetadata *cloned = av_exif_clone_ifd(&src->value.ifd);
1111
0
            if (!cloned) {
1112
0
                ret = AVERROR(ENOMEM);
1113
0
                goto end;
1114
0
            }
1115
0
            dst->value.ifd = *cloned;
1116
0
            av_freep(&cloned);
1117
0
            break;
1118
0
        }
1119
0
        case AV_TIFF_SHORT:
1120
0
        case AV_TIFF_LONG:
1121
0
            EXIF_COPY(dst->value.uint, src->value.uint);
1122
0
            break;
1123
0
        case AV_TIFF_SLONG:
1124
0
        case AV_TIFF_SSHORT:
1125
0
            EXIF_COPY(dst->value.sint, src->value.sint);
1126
0
            break;
1127
0
        case AV_TIFF_RATIONAL:
1128
0
        case AV_TIFF_SRATIONAL:
1129
0
            EXIF_COPY(dst->value.rat, src->value.rat);
1130
0
            break;
1131
0
        case AV_TIFF_DOUBLE:
1132
0
        case AV_TIFF_FLOAT:
1133
0
            EXIF_COPY(dst->value.dbl, src->value.dbl);
1134
0
            break;
1135
0
        case AV_TIFF_BYTE:
1136
0
        case AV_TIFF_UNDEFINED:
1137
0
            EXIF_COPY(dst->value.ubytes, src->value.ubytes);
1138
0
            break;
1139
0
        case AV_TIFF_SBYTE:
1140
0
            EXIF_COPY(dst->value.sbytes, src->value.sbytes);
1141
0
            break;
1142
0
        case AV_TIFF_STRING:
1143
0
            dst->value.str = av_memdup(src->value.str, src->count+1);
1144
0
            if (!dst->value.str) {
1145
0
                ret = AVERROR(ENOMEM);
1146
0
                goto end;
1147
0
            }
1148
0
            break;
1149
0
    }
1150
1151
0
    return 0;
1152
1153
0
end:
1154
0
    av_freep(&dst->ifd_lead);
1155
0
    if (src->type == AV_TIFF_IFD)
1156
0
        av_exif_free(&dst->value.ifd);
1157
0
    else
1158
0
        av_freep(&dst->value.ptr);
1159
0
    memset(dst, 0, sizeof(*dst));
1160
1161
0
    return ret;
1162
0
}
1163
1164
static int exif_get_entry(void *logctx, AVExifMetadata *ifd, uint16_t id, int depth, AVExifEntry **value)
1165
0
{
1166
0
    int offset = 1;
1167
1168
0
    if (!ifd || ifd->count && !ifd->entries || !value)
1169
0
        return AVERROR(EINVAL);
1170
1171
0
    for (size_t i = 0; i < ifd->count; i++) {
1172
0
        if (ifd->entries[i].id == id) {
1173
0
            *value = &ifd->entries[i];
1174
0
            return i + offset;
1175
0
        }
1176
0
        if (ifd->entries[i].type == AV_TIFF_IFD) {
1177
0
            if (depth < 3) {
1178
0
                int ret = exif_get_entry(logctx, &ifd->entries[i].value.ifd, id, depth + 1, value);
1179
0
                if (ret)
1180
0
                    return ret < 0 ? ret : ret + offset;
1181
0
            }
1182
0
            offset += ifd->entries[i].value.ifd.count;
1183
0
        }
1184
0
    }
1185
1186
0
    return 0;
1187
0
}
1188
1189
int av_exif_get_entry(void *logctx, AVExifMetadata *ifd, uint16_t id, int flags, AVExifEntry **value)
1190
0
{
1191
0
    return exif_get_entry(logctx, ifd, id, (flags & AV_EXIF_FLAG_RECURSIVE) ? 0 : INT_MAX, value);
1192
0
}
1193
1194
int av_exif_set_entry(void *logctx, AVExifMetadata *ifd, uint16_t id, enum AVTiffDataType type,
1195
    uint32_t count, const uint8_t *ifd_lead, uint32_t ifd_offset, const void *value)
1196
0
{
1197
0
    void *temp;
1198
0
    int ret = 0;
1199
0
    AVExifEntry *entry = NULL;
1200
0
    AVExifEntry src = { 0 };
1201
1202
0
    if (!ifd || ifd->count && !ifd->entries
1203
0
             || ifd_lead && !ifd_offset || !ifd_lead && ifd_offset
1204
0
             || !value || ifd->count == 0xFFFFu)
1205
0
        return AVERROR(EINVAL);
1206
1207
0
    ret = av_exif_get_entry(logctx, ifd, id, 0, &entry);
1208
0
    if (ret < 0)
1209
0
        return ret;
1210
1211
0
    if (entry) {
1212
0
        exif_free_entry(entry);
1213
0
    } else {
1214
0
        size_t required_size;
1215
0
        ret = av_size_mult(ifd->count + 1, sizeof(*ifd->entries), &required_size);
1216
0
        if (ret < 0)
1217
0
            return AVERROR(ENOMEM);
1218
0
        temp = av_fast_realloc(ifd->entries, &ifd->size, required_size);
1219
0
        if (!temp)
1220
0
            return AVERROR(ENOMEM);
1221
0
        ifd->entries = temp;
1222
0
        entry = &ifd->entries[ifd->count++];
1223
0
    }
1224
1225
0
    src.count = count;
1226
0
    src.id = id;
1227
0
    src.type = type;
1228
0
    src.ifd_lead = (uint8_t *) ifd_lead;
1229
0
    src.ifd_offset = ifd_offset;
1230
0
    if (type == AV_TIFF_IFD)
1231
0
        src.value.ifd = * (const AVExifMetadata *) value;
1232
0
    else
1233
0
        src.value.ptr = (void *) value;
1234
1235
0
    ret = exif_clone_entry(entry, &src);
1236
1237
0
    if (ret < 0)
1238
0
        ifd->count--;
1239
1240
0
    return ret;
1241
0
}
1242
1243
static int exif_remove_entry(void *logctx, AVExifMetadata *ifd, uint16_t id, int depth)
1244
0
{
1245
0
    int32_t index = -1;
1246
0
    int ret = 0;
1247
1248
0
    if (!ifd || ifd->count && !ifd->entries)
1249
0
        return AVERROR(EINVAL);
1250
1251
0
    for (size_t i = 0; i < ifd->count; i++) {
1252
0
        if (ifd->entries[i].id == id) {
1253
0
            index = i;
1254
0
            break;
1255
0
        }
1256
0
        if (ifd->entries[i].type == AV_TIFF_IFD && depth < 3) {
1257
0
            ret = exif_remove_entry(logctx, &ifd->entries[i].value.ifd, id, depth + 1);
1258
0
            if (ret)
1259
0
                return ret;
1260
0
        }
1261
0
    }
1262
1263
0
    if (index < 0)
1264
0
        return 0;
1265
0
    exif_free_entry(&ifd->entries[index]);
1266
1267
0
    if (index == --ifd->count) {
1268
0
        if (!index)
1269
0
            av_freep(&ifd->entries);
1270
0
        return 1;
1271
0
    }
1272
1273
0
    memmove(&ifd->entries[index], &ifd->entries[index + 1], (ifd->count - index) * sizeof(*ifd->entries));
1274
1275
0
    return 1 + (ifd->count - index);
1276
0
}
1277
1278
int av_exif_remove_entry(void *logctx, AVExifMetadata *ifd, uint16_t id, int flags)
1279
0
{
1280
0
    return exif_remove_entry(logctx, ifd, id, (flags & AV_EXIF_FLAG_RECURSIVE) ? 0 : INT_MAX);
1281
0
}
1282
1283
AVExifMetadata *av_exif_clone_ifd(const AVExifMetadata *ifd)
1284
0
{
1285
0
    AVExifMetadata *ret = av_mallocz(sizeof(*ret));
1286
0
    if (!ret)
1287
0
        return NULL;
1288
1289
0
    ret->count = ifd->count;
1290
0
    if (ret->count) {
1291
0
        size_t required_size;
1292
0
        if (av_size_mult(ret->count, sizeof(*ret->entries), &required_size) < 0)
1293
0
            goto fail;
1294
0
        av_fast_mallocz(&ret->entries, &ret->size, required_size);
1295
0
        if (!ret->entries)
1296
0
            goto fail;
1297
0
    }
1298
1299
0
    for (size_t i = 0; i < ret->count; i++) {
1300
0
        const AVExifEntry *entry = &ifd->entries[i];
1301
0
        AVExifEntry *ret_entry = &ret->entries[i];
1302
0
        int status = exif_clone_entry(ret_entry, entry);
1303
0
        if (status < 0)
1304
0
            goto fail;
1305
0
    }
1306
1307
0
    return ret;
1308
1309
0
fail:
1310
0
    av_exif_free(ret);
1311
0
    av_free(ret);
1312
0
    return NULL;
1313
0
}
1314
1315
static const int rotation_lut[2][4] = {
1316
    {1, 8, 3, 6}, {4, 7, 2, 5},
1317
};
1318
1319
int av_exif_matrix_to_orientation(const int32_t *matrix)
1320
0
{
1321
0
    double rotation = av_display_rotation_get(matrix);
1322
    // determinant
1323
0
    int vflip = ((int64_t)matrix[0] * (int64_t)matrix[4]
1324
0
               - (int64_t)matrix[1] * (int64_t)matrix[3]) < 0;
1325
0
    if (!isfinite(rotation))
1326
0
        return 0;
1327
0
    int rot = (int)(rotation + 0.5);
1328
0
    rot = (((rot % 360) + 360) % 360) / 90;
1329
0
    return rotation_lut[vflip][rot];
1330
0
}
1331
1332
int av_exif_orientation_to_matrix(int32_t *matrix, int orientation)
1333
0
{
1334
0
    switch (orientation) {
1335
0
        case 1:
1336
0
            av_display_rotation_set(matrix, 0.0);
1337
0
            break;
1338
0
        case 2:
1339
0
            av_display_rotation_set(matrix, 0.0);
1340
0
            av_display_matrix_flip(matrix, 1, 0);
1341
0
            break;
1342
0
        case 3:
1343
0
            av_display_rotation_set(matrix, 180.0);
1344
0
            break;
1345
0
        case 4:
1346
0
            av_display_rotation_set(matrix, 180.0);
1347
0
            av_display_matrix_flip(matrix, 1, 0);
1348
0
            break;
1349
0
        case 5:
1350
0
            av_display_rotation_set(matrix, 90.0);
1351
0
            av_display_matrix_flip(matrix, 1, 0);
1352
0
            break;
1353
0
        case 6:
1354
0
            av_display_rotation_set(matrix, 90.0);
1355
0
            break;
1356
0
        case 7:
1357
0
            av_display_rotation_set(matrix, -90.0);
1358
0
            av_display_matrix_flip(matrix, 1, 0);
1359
0
            break;
1360
0
        case 8:
1361
0
            av_display_rotation_set(matrix, -90.0);
1362
0
            break;
1363
0
        default:
1364
0
            return AVERROR(EINVAL);
1365
0
    }
1366
1367
0
    return 0;
1368
0
}
1369
1370
int ff_exif_sanitize_ifd(void *logctx, const AVFrame *frame, AVExifMetadata *ifd)
1371
0
{
1372
0
    int ret = 0;
1373
0
    AVFrameSideData *sd_orient = NULL;
1374
0
    AVExifEntry *or = NULL;
1375
0
    AVExifEntry *iw = NULL;
1376
0
    AVExifEntry *ih = NULL;
1377
0
    AVExifEntry *pw = NULL;
1378
0
    AVExifEntry *ph = NULL;
1379
0
    uint64_t orientation = 1;
1380
0
    uint64_t w = frame->width;
1381
0
    uint64_t h = frame->height;
1382
0
    int rewrite = 0;
1383
1384
0
    sd_orient = av_frame_get_side_data(frame, AV_FRAME_DATA_DISPLAYMATRIX);
1385
1386
0
    if (sd_orient)
1387
0
        orientation = av_exif_matrix_to_orientation((int32_t *) sd_orient->data);
1388
0
    if (orientation != 1)
1389
0
        av_log(logctx, AV_LOG_DEBUG, "matrix contains nontrivial EXIF orientation: %" PRIu64 "\n", orientation);
1390
1391
0
    for (size_t i = 0; i < ifd->count; i++) {
1392
0
        AVExifEntry *entry = &ifd->entries[i];
1393
0
        if (entry->id == ORIENTATION_TAG && entry->count > 0 && entry->type == AV_TIFF_SHORT) {
1394
0
            or = entry;
1395
0
            continue;
1396
0
        }
1397
0
        if (entry->id == IMAGE_WIDTH_TAG && entry->count > 0 && entry->type == AV_TIFF_LONG) {
1398
0
            iw = entry;
1399
0
            continue;
1400
0
        }
1401
0
        if (entry->id == IMAGE_LENGTH_TAG && entry->count > 0 && entry->type == AV_TIFF_LONG) {
1402
0
            ih = entry;
1403
0
            continue;
1404
0
        }
1405
0
        if (entry->id == EXIFIFD_TAG && entry->type == AV_TIFF_IFD) {
1406
0
            AVExifMetadata *exif = &entry->value.ifd;
1407
0
            for (size_t j = 0; j < exif->count; j++) {
1408
0
                AVExifEntry *exifentry = &exif->entries[j];
1409
0
                if (exifentry->id == PIXEL_X_TAG && exifentry->count > 0 && exifentry->type == AV_TIFF_SHORT) {
1410
0
                    pw = exifentry;
1411
0
                    continue;
1412
0
                }
1413
0
                if (exifentry->id == PIXEL_Y_TAG && exifentry->count > 0 && exifentry->type == AV_TIFF_SHORT) {
1414
0
                    ph = exifentry;
1415
0
                    continue;
1416
0
                }
1417
0
            }
1418
0
        }
1419
0
    }
1420
1421
0
    if (or && or->value.uint[0] != orientation) {
1422
0
        rewrite = 1;
1423
0
        or->value.uint[0] = orientation;
1424
0
    }
1425
0
    if (iw && iw->value.uint[0] != w) {
1426
0
        rewrite = 1;
1427
0
        iw->value.uint[0] = w;
1428
0
    }
1429
0
    if (ih && ih->value.uint[0] != h) {
1430
0
        rewrite = 1;
1431
0
        ih->value.uint[0] = h;
1432
0
    }
1433
0
    if (pw && pw->value.uint[0] != w) {
1434
0
        rewrite = 1;
1435
0
        pw->value.uint[0] = w;
1436
0
    }
1437
0
    if (ph && ph->value.uint[0] != h) {
1438
0
        rewrite = 1;
1439
0
        ph->value.uint[0] = h;
1440
0
    }
1441
0
    if (!or && orientation != 1) {
1442
0
        rewrite = 1;
1443
0
        ret = av_exif_set_entry(logctx, ifd, ORIENTATION_TAG, AV_TIFF_SHORT, 1, NULL, 0, &orientation);
1444
0
        if (ret < 0)
1445
0
            goto end;
1446
0
    }
1447
0
    if (!iw && w) {
1448
0
        rewrite = 1;
1449
0
        ret = av_exif_set_entry(logctx, ifd, IMAGE_WIDTH_TAG, AV_TIFF_LONG, 1, NULL, 0, &w);
1450
0
        if (ret < 0)
1451
0
            goto end;
1452
0
    }
1453
0
    if (!ih && h) {
1454
0
        rewrite = 1;
1455
0
        ret = av_exif_set_entry(logctx, ifd, IMAGE_LENGTH_TAG, AV_TIFF_LONG, 1, NULL, 0, &h);
1456
0
        if (ret < 0)
1457
0
            goto end;
1458
0
    }
1459
0
    if (!pw && w && w < 0xFFFFu || !ph && h && h < 0xFFFFu) {
1460
0
        AVExifMetadata *exif;
1461
0
        AVExifEntry *exif_entry;
1462
0
        int exif_found = av_exif_get_entry(logctx, ifd, EXIFIFD_TAG, 0, &exif_entry);
1463
0
        rewrite = 1;
1464
0
        if (exif_found < 0)
1465
0
            goto end;
1466
0
        if (exif_found > 0) {
1467
0
            exif = &exif_entry->value.ifd;
1468
0
        } else {
1469
0
            AVExifMetadata exif_new = { 0 };
1470
0
            ret = av_exif_set_entry(logctx, ifd, EXIFIFD_TAG, AV_TIFF_IFD, 1, NULL, 0, &exif_new);
1471
0
            if (ret < 0) {
1472
0
                av_exif_free(&exif_new);
1473
0
                goto end;
1474
0
            }
1475
0
            exif = &ifd->entries[ifd->count - 1].value.ifd;
1476
0
        }
1477
0
        if (!pw && w && w < 0xFFFFu) {
1478
0
            ret = av_exif_set_entry(logctx, exif, PIXEL_X_TAG, AV_TIFF_SHORT, 1, NULL, 0, &w);
1479
0
            if (ret < 0)
1480
0
                goto end;
1481
0
        }
1482
0
        if (!ph && h && h < 0xFFFFu) {
1483
0
            ret = av_exif_set_entry(logctx, exif, PIXEL_Y_TAG, AV_TIFF_SHORT, 1, NULL, 0, &h);
1484
0
            if (ret < 0)
1485
0
                goto end;
1486
0
        }
1487
0
    }
1488
1489
0
    return rewrite;
1490
1491
0
end:
1492
0
    return ret;
1493
0
}
1494
1495
int ff_exif_get_buffer(void *logctx, const AVFrame *frame, AVBufferRef **buffer_ptr, enum AVExifHeaderMode header_mode)
1496
0
{
1497
0
    AVFrameSideData *sd_exif = NULL;
1498
0
    AVBufferRef *buffer = NULL;
1499
0
    AVExifMetadata ifd = { 0 };
1500
0
    int ret = 0;
1501
0
    int rewrite = 0;
1502
1503
0
    if (!buffer_ptr || *buffer_ptr)
1504
0
        return AVERROR(EINVAL);
1505
1506
0
    sd_exif = av_frame_get_side_data(frame, AV_FRAME_DATA_EXIF);
1507
0
    if (!sd_exif)
1508
0
        return 0;
1509
1510
0
    ret = av_exif_parse_buffer(logctx, sd_exif->data, sd_exif->size, &ifd, AV_EXIF_TIFF_HEADER);
1511
0
    if (ret < 0)
1512
0
        goto end;
1513
1514
0
    rewrite = ff_exif_sanitize_ifd(logctx, frame, &ifd);
1515
0
    if (rewrite < 0) {
1516
0
        ret = rewrite;
1517
0
        goto end;
1518
0
    }
1519
1520
0
    if (rewrite) {
1521
0
        ret = av_exif_write(logctx, &ifd, &buffer, header_mode);
1522
0
        if (ret < 0)
1523
0
            goto end;
1524
1525
0
        *buffer_ptr = buffer;
1526
0
    } else {
1527
0
        *buffer_ptr = av_buffer_ref(sd_exif->buf);
1528
0
        if (!*buffer_ptr) {
1529
0
            ret = AVERROR(ENOMEM);
1530
0
            goto end;
1531
0
        }
1532
0
    }
1533
1534
0
    av_exif_free(&ifd);
1535
0
    return rewrite;
1536
1537
0
end:
1538
0
    av_exif_free(&ifd);
1539
0
    return ret;
1540
0
}