Coverage Report

Created: 2024-07-27 06:27

/src/libtiff/libtiff/tif_read.c
Line
Count
Source (jump to first uncovered line)
1
/*
2
 * Copyright (c) 1988-1997 Sam Leffler
3
 * Copyright (c) 1991-1997 Silicon Graphics, Inc.
4
 *
5
 * Permission to use, copy, modify, distribute, and sell this software and
6
 * its documentation for any purpose is hereby granted without fee, provided
7
 * that (i) the above copyright notices and this permission notice appear in
8
 * all copies of the software and related documentation, and (ii) the names of
9
 * Sam Leffler and Silicon Graphics may not be used in any advertising or
10
 * publicity relating to the software without the specific, prior written
11
 * permission of Sam Leffler and Silicon Graphics.
12
 *
13
 * THE SOFTWARE IS PROVIDED "AS-IS" AND WITHOUT WARRANTY OF ANY KIND,
14
 * EXPRESS, IMPLIED OR OTHERWISE, INCLUDING WITHOUT LIMITATION, ANY
15
 * WARRANTY OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.
16
 *
17
 * IN NO EVENT SHALL SAM LEFFLER OR SILICON GRAPHICS BE LIABLE FOR
18
 * ANY SPECIAL, INCIDENTAL, INDIRECT OR CONSEQUENTIAL DAMAGES OF ANY KIND,
19
 * OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS,
20
 * WHETHER OR NOT ADVISED OF THE POSSIBILITY OF DAMAGE, AND ON ANY THEORY OF
21
 * LIABILITY, ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE
22
 * OF THIS SOFTWARE.
23
 */
24
25
/*
26
 * TIFF Library.
27
 * Scanline-oriented Read Support
28
 */
29
#include "tiffiop.h"
30
#include <stdio.h>
31
32
int TIFFFillStrip(TIFF *tif, uint32_t strip);
33
int TIFFFillTile(TIFF *tif, uint32_t tile);
34
static int TIFFStartStrip(TIFF *tif, uint32_t strip);
35
static int TIFFStartTile(TIFF *tif, uint32_t tile);
36
static int TIFFCheckRead(TIFF *, int);
37
static tmsize_t TIFFReadRawStrip1(TIFF *tif, uint32_t strip, void *buf,
38
                                  tmsize_t size, const char *module);
39
static tmsize_t TIFFReadRawTile1(TIFF *tif, uint32_t tile, void *buf,
40
                                 tmsize_t size, const char *module);
41
42
0
#define NOSTRIP ((uint32_t)(-1)) /* undefined state */
43
0
#define NOTILE ((uint32_t)(-1))  /* undefined state */
44
45
0
#define INITIAL_THRESHOLD (1024 * 1024)
46
0
#define THRESHOLD_MULTIPLIER 10
47
#define MAX_THRESHOLD                                                          \
48
0
    (THRESHOLD_MULTIPLIER * THRESHOLD_MULTIPLIER * THRESHOLD_MULTIPLIER *      \
49
0
     INITIAL_THRESHOLD)
50
51
0
#define TIFF_INT64_MAX ((((int64_t)0x7FFFFFFF) << 32) | 0xFFFFFFFF)
52
53
/* Read 'size' bytes in tif_rawdata buffer starting at offset 'rawdata_offset'
54
 * Returns 1 in case of success, 0 otherwise. */
55
static int TIFFReadAndRealloc(TIFF *tif, tmsize_t size, tmsize_t rawdata_offset,
56
                              int is_strip, uint32_t strip_or_tile,
57
                              const char *module)
58
0
{
59
0
#if SIZEOF_SIZE_T == 8
60
0
    tmsize_t threshold = INITIAL_THRESHOLD;
61
0
#endif
62
0
    tmsize_t already_read = 0;
63
64
#if SIZEOF_SIZE_T != 8
65
    /* On 32 bit processes, if the request is large enough, check against */
66
    /* file size */
67
    if (size > 1000 * 1000 * 1000)
68
    {
69
        uint64_t filesize = TIFFGetFileSize(tif);
70
        if ((uint64_t)size >= filesize)
71
        {
72
            TIFFErrorExtR(tif, module,
73
                          "Chunk size requested is larger than file size.");
74
            return 0;
75
        }
76
    }
77
#endif
78
79
    /* On 64 bit processes, read first a maximum of 1 MB, then 10 MB, etc */
80
    /* so as to avoid allocating too much memory in case the file is too */
81
    /* short. We could ask for the file size, but this might be */
82
    /* expensive with some I/O layers (think of reading a gzipped file) */
83
    /* Restrict to 64 bit processes, so as to avoid reallocs() */
84
    /* on 32 bit processes where virtual memory is scarce.  */
85
0
    while (already_read < size)
86
0
    {
87
0
        tmsize_t bytes_read;
88
0
        tmsize_t to_read = size - already_read;
89
0
#if SIZEOF_SIZE_T == 8
90
0
        if (to_read >= threshold && threshold < MAX_THRESHOLD &&
91
0
            already_read + to_read + rawdata_offset > tif->tif_rawdatasize)
92
0
        {
93
0
            to_read = threshold;
94
0
            threshold *= THRESHOLD_MULTIPLIER;
95
0
        }
96
0
#endif
97
0
        if (already_read + to_read + rawdata_offset > tif->tif_rawdatasize)
98
0
        {
99
0
            uint8_t *new_rawdata;
100
0
            assert((tif->tif_flags & TIFF_MYBUFFER) != 0);
101
0
            tif->tif_rawdatasize = (tmsize_t)TIFFroundup_64(
102
0
                (uint64_t)already_read + to_read + rawdata_offset, 1024);
103
0
            if (tif->tif_rawdatasize == 0)
104
0
            {
105
0
                TIFFErrorExtR(tif, module, "Invalid buffer size");
106
0
                return 0;
107
0
            }
108
0
            new_rawdata = (uint8_t *)_TIFFreallocExt(tif, tif->tif_rawdata,
109
0
                                                     tif->tif_rawdatasize);
110
0
            if (new_rawdata == 0)
111
0
            {
112
0
                TIFFErrorExtR(tif, module,
113
0
                              "No space for data buffer at scanline %" PRIu32,
114
0
                              tif->tif_row);
115
0
                _TIFFfreeExt(tif, tif->tif_rawdata);
116
0
                tif->tif_rawdata = 0;
117
0
                tif->tif_rawdatasize = 0;
118
0
                return 0;
119
0
            }
120
0
            tif->tif_rawdata = new_rawdata;
121
0
        }
122
0
        if (tif->tif_rawdata == NULL)
123
0
        {
124
            /* should not happen in practice but helps CoverityScan */
125
0
            return 0;
126
0
        }
127
128
0
        bytes_read = TIFFReadFile(
129
0
            tif, tif->tif_rawdata + rawdata_offset + already_read, to_read);
130
0
        already_read += bytes_read;
131
0
        if (bytes_read != to_read)
132
0
        {
133
0
            memset(tif->tif_rawdata + rawdata_offset + already_read, 0,
134
0
                   tif->tif_rawdatasize - rawdata_offset - already_read);
135
0
            if (is_strip)
136
0
            {
137
0
                TIFFErrorExtR(tif, module,
138
0
                              "Read error at scanline %" PRIu32
139
0
                              "; got %" TIFF_SSIZE_FORMAT " bytes, "
140
0
                              "expected %" TIFF_SSIZE_FORMAT,
141
0
                              tif->tif_row, already_read, size);
142
0
            }
143
0
            else
144
0
            {
145
0
                TIFFErrorExtR(tif, module,
146
0
                              "Read error at row %" PRIu32 ", col %" PRIu32
147
0
                              ", tile %" PRIu32 "; "
148
0
                              "got %" TIFF_SSIZE_FORMAT
149
0
                              " bytes, expected %" TIFF_SSIZE_FORMAT "",
150
0
                              tif->tif_row, tif->tif_col, strip_or_tile,
151
0
                              already_read, size);
152
0
            }
153
0
            return 0;
154
0
        }
155
0
    }
156
0
    return 1;
157
0
}
158
159
static int TIFFFillStripPartial(TIFF *tif, int strip, tmsize_t read_ahead,
160
                                int restart)
161
0
{
162
0
    static const char module[] = "TIFFFillStripPartial";
163
0
    register TIFFDirectory *td = &tif->tif_dir;
164
0
    tmsize_t unused_data;
165
0
    uint64_t read_offset;
166
0
    tmsize_t to_read;
167
0
    tmsize_t read_ahead_mod;
168
    /* tmsize_t bytecountm; */
169
170
    /*
171
     * Expand raw data buffer, if needed, to hold data
172
     * strip coming from file (perhaps should set upper
173
     * bound on the size of a buffer we'll use?).
174
     */
175
176
    /* bytecountm=(tmsize_t) TIFFGetStrileByteCount(tif, strip); */
177
178
    /* Not completely sure where the * 2 comes from, but probably for */
179
    /* an exponentional growth strategy of tif_rawdatasize */
180
0
    if (read_ahead < TIFF_TMSIZE_T_MAX / 2)
181
0
        read_ahead_mod = read_ahead * 2;
182
0
    else
183
0
        read_ahead_mod = read_ahead;
184
0
    if (read_ahead_mod > tif->tif_rawdatasize)
185
0
    {
186
0
        assert(restart);
187
188
0
        tif->tif_curstrip = NOSTRIP;
189
0
        if ((tif->tif_flags & TIFF_MYBUFFER) == 0)
190
0
        {
191
0
            TIFFErrorExtR(tif, module,
192
0
                          "Data buffer too small to hold part of strip %d",
193
0
                          strip);
194
0
            return (0);
195
0
        }
196
0
    }
197
198
0
    if (restart)
199
0
    {
200
0
        tif->tif_rawdataloaded = 0;
201
0
        tif->tif_rawdataoff = 0;
202
0
    }
203
204
    /*
205
    ** If we are reading more data, move any unused data to the
206
    ** start of the buffer.
207
    */
208
0
    if (tif->tif_rawdataloaded > 0)
209
0
        unused_data =
210
0
            tif->tif_rawdataloaded - (tif->tif_rawcp - tif->tif_rawdata);
211
0
    else
212
0
        unused_data = 0;
213
214
0
    if (unused_data > 0)
215
0
    {
216
0
        assert((tif->tif_flags & TIFF_BUFFERMMAP) == 0);
217
0
        memmove(tif->tif_rawdata, tif->tif_rawcp, unused_data);
218
0
    }
219
220
    /*
221
    ** Seek to the point in the file where more data should be read.
222
    */
223
0
    read_offset = TIFFGetStrileOffset(tif, strip) + tif->tif_rawdataoff +
224
0
                  tif->tif_rawdataloaded;
225
226
0
    if (!SeekOK(tif, read_offset))
227
0
    {
228
0
        TIFFErrorExtR(tif, module,
229
0
                      "Seek error at scanline %" PRIu32 ", strip %d",
230
0
                      tif->tif_row, strip);
231
0
        return 0;
232
0
    }
233
234
    /*
235
    ** How much do we want to read?
236
    */
237
0
    if (read_ahead_mod > tif->tif_rawdatasize)
238
0
        to_read = read_ahead_mod - unused_data;
239
0
    else
240
0
        to_read = tif->tif_rawdatasize - unused_data;
241
0
    if ((uint64_t)to_read > TIFFGetStrileByteCount(tif, strip) -
242
0
                                tif->tif_rawdataoff - tif->tif_rawdataloaded)
243
0
    {
244
0
        to_read = (tmsize_t)TIFFGetStrileByteCount(tif, strip) -
245
0
                  tif->tif_rawdataoff - tif->tif_rawdataloaded;
246
0
    }
247
248
0
    assert((tif->tif_flags & TIFF_BUFFERMMAP) == 0);
249
0
    if (!TIFFReadAndRealloc(tif, to_read, unused_data, 1, /* is_strip */
250
0
                            0,                            /* strip_or_tile */
251
0
                            module))
252
0
    {
253
0
        return 0;
254
0
    }
255
256
0
    tif->tif_rawdataoff =
257
0
        tif->tif_rawdataoff + tif->tif_rawdataloaded - unused_data;
258
0
    tif->tif_rawdataloaded = unused_data + to_read;
259
260
0
    tif->tif_rawcc = tif->tif_rawdataloaded;
261
0
    tif->tif_rawcp = tif->tif_rawdata;
262
263
0
    if (!isFillOrder(tif, td->td_fillorder) &&
264
0
        (tif->tif_flags & TIFF_NOBITREV) == 0)
265
0
    {
266
0
        assert((tif->tif_flags & TIFF_BUFFERMMAP) == 0);
267
0
        TIFFReverseBits(tif->tif_rawdata + unused_data, to_read);
268
0
    }
269
270
    /*
271
    ** When starting a strip from the beginning we need to
272
    ** restart the decoder.
273
    */
274
0
    if (restart)
275
0
    {
276
277
#ifdef JPEG_SUPPORT
278
        /* A bit messy since breaks the codec abstraction. Ultimately */
279
        /* there should be a function pointer for that, but it seems */
280
        /* only JPEG is affected. */
281
        /* For JPEG, if there are multiple scans (can generally be known */
282
        /* with the  read_ahead used), we need to read the whole strip */
283
        if (tif->tif_dir.td_compression == COMPRESSION_JPEG &&
284
            (uint64_t)tif->tif_rawcc < TIFFGetStrileByteCount(tif, strip))
285
        {
286
            if (TIFFJPEGIsFullStripRequired(tif))
287
            {
288
                return TIFFFillStrip(tif, strip);
289
            }
290
        }
291
#endif
292
293
0
        return TIFFStartStrip(tif, strip);
294
0
    }
295
0
    else
296
0
    {
297
0
        return 1;
298
0
    }
299
0
}
300
301
/*
302
 * Seek to a random row+sample in a file.
303
 *
304
 * Only used by TIFFReadScanline, and is only used on
305
 * strip organized files.  We do some tricky stuff to try
306
 * and avoid reading the whole compressed raw data for big
307
 * strips.
308
 */
309
static int TIFFSeek(TIFF *tif, uint32_t row, uint16_t sample)
310
0
{
311
0
    register TIFFDirectory *td = &tif->tif_dir;
312
0
    uint32_t strip;
313
0
    int whole_strip;
314
0
    tmsize_t read_ahead = 0;
315
316
    /*
317
    ** Establish what strip we are working from.
318
    */
319
0
    if (row >= td->td_imagelength)
320
0
    { /* out of range */
321
0
        TIFFErrorExtR(tif, tif->tif_name,
322
0
                      "%" PRIu32 ": Row out of range, max %" PRIu32 "", row,
323
0
                      td->td_imagelength);
324
0
        return (0);
325
0
    }
326
0
    if (td->td_planarconfig == PLANARCONFIG_SEPARATE)
327
0
    {
328
0
        if (sample >= td->td_samplesperpixel)
329
0
        {
330
0
            TIFFErrorExtR(tif, tif->tif_name,
331
0
                          "%" PRIu16 ": Sample out of range, max %" PRIu16 "",
332
0
                          sample, td->td_samplesperpixel);
333
0
            return (0);
334
0
        }
335
0
        strip = (uint32_t)sample * td->td_stripsperimage +
336
0
                row / td->td_rowsperstrip;
337
0
    }
338
0
    else
339
0
        strip = row / td->td_rowsperstrip;
340
341
        /*
342
         * Do we want to treat this strip as one whole chunk or
343
         * read it a few lines at a time?
344
         */
345
#if defined(CHUNKY_STRIP_READ_SUPPORT)
346
    whole_strip = TIFFGetStrileByteCount(tif, strip) < 10 || isMapped(tif);
347
    if (td->td_compression == COMPRESSION_LERC ||
348
        td->td_compression == COMPRESSION_JBIG)
349
    {
350
        /* Ideally plugins should have a way to declare they don't support
351
         * chunk strip */
352
        whole_strip = 1;
353
    }
354
#else
355
0
    whole_strip = 1;
356
0
#endif
357
358
0
    if (!whole_strip)
359
0
    {
360
        /* 16 is for YCbCr mode where we may need to read 16 */
361
        /* lines at a time to get a decompressed line, and 5000 */
362
        /* is some constant value, for example for JPEG tables */
363
0
        if (tif->tif_scanlinesize < TIFF_TMSIZE_T_MAX / 16 &&
364
0
            tif->tif_scanlinesize * 16 < TIFF_TMSIZE_T_MAX - 5000)
365
0
        {
366
0
            read_ahead = tif->tif_scanlinesize * 16 + 5000;
367
0
        }
368
0
        else
369
0
        {
370
0
            read_ahead = tif->tif_scanlinesize;
371
0
        }
372
0
    }
373
374
    /*
375
     * If we haven't loaded this strip, do so now, possibly
376
     * only reading the first part.
377
     */
378
0
    if (strip != tif->tif_curstrip)
379
0
    { /* different strip, refill */
380
381
0
        if (whole_strip)
382
0
        {
383
0
            if (!TIFFFillStrip(tif, strip))
384
0
                return (0);
385
0
        }
386
0
        else
387
0
        {
388
0
            if (!TIFFFillStripPartial(tif, strip, read_ahead, 1))
389
0
                return 0;
390
0
        }
391
0
    }
392
393
    /*
394
    ** If we already have some data loaded, do we need to read some more?
395
    */
396
0
    else if (!whole_strip)
397
0
    {
398
0
        if (((tif->tif_rawdata + tif->tif_rawdataloaded) - tif->tif_rawcp) <
399
0
                read_ahead &&
400
0
            (uint64_t)tif->tif_rawdataoff + tif->tif_rawdataloaded <
401
0
                TIFFGetStrileByteCount(tif, strip))
402
0
        {
403
0
            if (!TIFFFillStripPartial(tif, strip, read_ahead, 0))
404
0
                return 0;
405
0
        }
406
0
    }
407
408
0
    if (row < tif->tif_row)
409
0
    {
410
        /*
411
         * Moving backwards within the same strip: backup
412
         * to the start and then decode forward (below).
413
         *
414
         * NB: If you're planning on lots of random access within a
415
         * strip, it's better to just read and decode the entire
416
         * strip, and then access the decoded data in a random fashion.
417
         */
418
419
0
        if (tif->tif_rawdataoff != 0)
420
0
        {
421
0
            if (!TIFFFillStripPartial(tif, strip, read_ahead, 1))
422
0
                return 0;
423
0
        }
424
0
        else
425
0
        {
426
0
            if (!TIFFStartStrip(tif, strip))
427
0
                return (0);
428
0
        }
429
0
    }
430
431
0
    if (row != tif->tif_row)
432
0
    {
433
        /*
434
         * Seek forward to the desired row.
435
         */
436
437
        /* TODO: Will this really work with partial buffers? */
438
439
0
        if (!(*tif->tif_seek)(tif, row - tif->tif_row))
440
0
            return (0);
441
0
        tif->tif_row = row;
442
0
    }
443
444
0
    return (1);
445
0
}
446
447
int TIFFReadScanline(TIFF *tif, void *buf, uint32_t row, uint16_t sample)
448
0
{
449
0
    int e;
450
451
0
    if (!TIFFCheckRead(tif, 0))
452
0
        return (-1);
453
0
    if ((e = TIFFSeek(tif, row, sample)) != 0)
454
0
    {
455
        /*
456
         * Decompress desired row into user buffer.
457
         */
458
0
        e = (*tif->tif_decoderow)(tif, (uint8_t *)buf, tif->tif_scanlinesize,
459
0
                                  sample);
460
461
        /* we are now poised at the beginning of the next row */
462
0
        tif->tif_row = row + 1;
463
464
0
        if (e)
465
0
            (*tif->tif_postdecode)(tif, (uint8_t *)buf, tif->tif_scanlinesize);
466
0
    }
467
0
    else
468
0
    {
469
0
        memset(buf, 0, (size_t)tif->tif_scanlinesize);
470
0
    }
471
0
    return (e > 0 ? 1 : -1);
472
0
}
473
474
/*
475
 * Calculate the strip size according to the number of
476
 * rows in the strip (check for truncated last strip on any
477
 * of the separations).
478
 */
479
static tmsize_t TIFFReadEncodedStripGetStripSize(TIFF *tif, uint32_t strip,
480
                                                 uint16_t *pplane)
481
0
{
482
0
    static const char module[] = "TIFFReadEncodedStrip";
483
0
    TIFFDirectory *td = &tif->tif_dir;
484
0
    uint32_t rowsperstrip;
485
0
    uint32_t stripsperplane;
486
0
    uint32_t stripinplane;
487
0
    uint32_t rows;
488
0
    tmsize_t stripsize;
489
0
    if (!TIFFCheckRead(tif, 0))
490
0
        return ((tmsize_t)(-1));
491
0
    if (strip >= td->td_nstrips)
492
0
    {
493
0
        TIFFErrorExtR(tif, module,
494
0
                      "%" PRIu32 ": Strip out of range, max %" PRIu32, strip,
495
0
                      td->td_nstrips);
496
0
        return ((tmsize_t)(-1));
497
0
    }
498
499
0
    rowsperstrip = td->td_rowsperstrip;
500
0
    if (rowsperstrip > td->td_imagelength)
501
0
        rowsperstrip = td->td_imagelength;
502
0
    if (rowsperstrip == 0)
503
0
    {
504
0
        TIFFErrorExtR(tif, module, "rowsperstrip is zero");
505
0
        return ((tmsize_t)(-1));
506
0
    }
507
0
    stripsperplane =
508
0
        TIFFhowmany_32_maxuint_compat(td->td_imagelength, rowsperstrip);
509
0
    stripinplane = (strip % stripsperplane);
510
0
    if (pplane)
511
0
        *pplane = (uint16_t)(strip / stripsperplane);
512
0
    rows = td->td_imagelength - stripinplane * rowsperstrip;
513
0
    if (rows > rowsperstrip)
514
0
        rows = rowsperstrip;
515
0
    stripsize = TIFFVStripSize(tif, rows);
516
0
    if (stripsize == 0)
517
0
        return ((tmsize_t)(-1));
518
0
    return stripsize;
519
0
}
520
521
/*
522
 * Read a strip of data and decompress the specified
523
 * amount into the user-supplied buffer.
524
 */
525
tmsize_t TIFFReadEncodedStrip(TIFF *tif, uint32_t strip, void *buf,
526
                              tmsize_t size)
527
0
{
528
0
    static const char module[] = "TIFFReadEncodedStrip";
529
0
    TIFFDirectory *td = &tif->tif_dir;
530
0
    tmsize_t stripsize;
531
0
    uint16_t plane;
532
533
0
    stripsize = TIFFReadEncodedStripGetStripSize(tif, strip, &plane);
534
0
    if (stripsize == ((tmsize_t)(-1)))
535
0
        return ((tmsize_t)(-1));
536
537
    /* shortcut to avoid an extra memcpy() */
538
0
    if (td->td_compression == COMPRESSION_NONE && size != (tmsize_t)(-1) &&
539
0
        size >= stripsize && !isMapped(tif) &&
540
0
        ((tif->tif_flags & TIFF_NOREADRAW) == 0))
541
0
    {
542
0
        if (TIFFReadRawStrip1(tif, strip, buf, stripsize, module) != stripsize)
543
0
            return ((tmsize_t)(-1));
544
545
0
        if (!isFillOrder(tif, td->td_fillorder) &&
546
0
            (tif->tif_flags & TIFF_NOBITREV) == 0)
547
0
            TIFFReverseBits(buf, stripsize);
548
549
0
        (*tif->tif_postdecode)(tif, buf, stripsize);
550
0
        return (stripsize);
551
0
    }
552
553
0
    if ((size != (tmsize_t)(-1)) && (size < stripsize))
554
0
        stripsize = size;
555
0
    if (!TIFFFillStrip(tif, strip))
556
0
    {
557
0
        memset(buf, 0, (size_t)stripsize);
558
0
        return ((tmsize_t)(-1));
559
0
    }
560
0
    if ((*tif->tif_decodestrip)(tif, buf, stripsize, plane) <= 0)
561
0
        return ((tmsize_t)(-1));
562
0
    (*tif->tif_postdecode)(tif, buf, stripsize);
563
0
    return (stripsize);
564
0
}
565
566
/* Variant of TIFFReadEncodedStrip() that does
567
 * * if *buf == NULL, *buf = _TIFFmallocExt(tif, bufsizetoalloc) only after
568
 * TIFFFillStrip() has succeeded. This avoid excessive memory allocation in case
569
 * of truncated file.
570
 * * calls regular TIFFReadEncodedStrip() if *buf != NULL
571
 */
572
tmsize_t _TIFFReadEncodedStripAndAllocBuffer(TIFF *tif, uint32_t strip,
573
                                             void **buf,
574
                                             tmsize_t bufsizetoalloc,
575
                                             tmsize_t size_to_read)
576
0
{
577
0
    tmsize_t this_stripsize;
578
0
    uint16_t plane;
579
580
0
    if (*buf != NULL)
581
0
    {
582
0
        return TIFFReadEncodedStrip(tif, strip, *buf, size_to_read);
583
0
    }
584
585
0
    this_stripsize = TIFFReadEncodedStripGetStripSize(tif, strip, &plane);
586
0
    if (this_stripsize == ((tmsize_t)(-1)))
587
0
        return ((tmsize_t)(-1));
588
589
0
    if ((size_to_read != (tmsize_t)(-1)) && (size_to_read < this_stripsize))
590
0
        this_stripsize = size_to_read;
591
0
    if (!TIFFFillStrip(tif, strip))
592
0
        return ((tmsize_t)(-1));
593
594
0
    *buf = _TIFFmallocExt(tif, bufsizetoalloc);
595
0
    if (*buf == NULL)
596
0
    {
597
0
        TIFFErrorExtR(tif, TIFFFileName(tif), "No space for strip buffer");
598
0
        return ((tmsize_t)(-1));
599
0
    }
600
0
    _TIFFmemset(*buf, 0, bufsizetoalloc);
601
602
0
    if ((*tif->tif_decodestrip)(tif, *buf, this_stripsize, plane) <= 0)
603
0
        return ((tmsize_t)(-1));
604
0
    (*tif->tif_postdecode)(tif, *buf, this_stripsize);
605
0
    return (this_stripsize);
606
0
}
607
608
static tmsize_t TIFFReadRawStrip1(TIFF *tif, uint32_t strip, void *buf,
609
                                  tmsize_t size, const char *module)
610
0
{
611
0
    assert((tif->tif_flags & TIFF_NOREADRAW) == 0);
612
0
    if (!isMapped(tif))
613
0
    {
614
0
        tmsize_t cc;
615
616
0
        if (!SeekOK(tif, TIFFGetStrileOffset(tif, strip)))
617
0
        {
618
0
            TIFFErrorExtR(tif, module,
619
0
                          "Seek error at scanline %" PRIu32 ", strip %" PRIu32,
620
0
                          tif->tif_row, strip);
621
0
            return ((tmsize_t)(-1));
622
0
        }
623
0
        cc = TIFFReadFile(tif, buf, size);
624
0
        if (cc != size)
625
0
        {
626
0
            TIFFErrorExtR(tif, module,
627
0
                          "Read error at scanline %" PRIu32
628
0
                          "; got %" TIFF_SSIZE_FORMAT
629
0
                          " bytes, expected %" TIFF_SSIZE_FORMAT,
630
0
                          tif->tif_row, cc, size);
631
0
            return ((tmsize_t)(-1));
632
0
        }
633
0
    }
634
0
    else
635
0
    {
636
0
        tmsize_t ma = 0;
637
0
        tmsize_t n;
638
0
        if ((TIFFGetStrileOffset(tif, strip) > (uint64_t)TIFF_TMSIZE_T_MAX) ||
639
0
            ((ma = (tmsize_t)TIFFGetStrileOffset(tif, strip)) > tif->tif_size))
640
0
        {
641
0
            n = 0;
642
0
        }
643
0
        else if (ma > TIFF_TMSIZE_T_MAX - size)
644
0
        {
645
0
            n = 0;
646
0
        }
647
0
        else
648
0
        {
649
0
            tmsize_t mb = ma + size;
650
0
            if (mb > tif->tif_size)
651
0
                n = tif->tif_size - ma;
652
0
            else
653
0
                n = size;
654
0
        }
655
0
        if (n != size)
656
0
        {
657
0
            TIFFErrorExtR(tif, module,
658
0
                          "Read error at scanline %" PRIu32 ", strip %" PRIu32
659
0
                          "; got %" TIFF_SSIZE_FORMAT
660
0
                          " bytes, expected %" TIFF_SSIZE_FORMAT,
661
0
                          tif->tif_row, strip, n, size);
662
0
            return ((tmsize_t)(-1));
663
0
        }
664
0
        _TIFFmemcpy(buf, tif->tif_base + ma, size);
665
0
    }
666
0
    return (size);
667
0
}
668
669
static tmsize_t TIFFReadRawStripOrTile2(TIFF *tif, uint32_t strip_or_tile,
670
                                        int is_strip, tmsize_t size,
671
                                        const char *module)
672
0
{
673
0
    assert(!isMapped(tif));
674
0
    assert((tif->tif_flags & TIFF_NOREADRAW) == 0);
675
676
0
    if (!SeekOK(tif, TIFFGetStrileOffset(tif, strip_or_tile)))
677
0
    {
678
0
        if (is_strip)
679
0
        {
680
0
            TIFFErrorExtR(tif, module,
681
0
                          "Seek error at scanline %" PRIu32 ", strip %" PRIu32,
682
0
                          tif->tif_row, strip_or_tile);
683
0
        }
684
0
        else
685
0
        {
686
0
            TIFFErrorExtR(tif, module,
687
0
                          "Seek error at row %" PRIu32 ", col %" PRIu32
688
0
                          ", tile %" PRIu32,
689
0
                          tif->tif_row, tif->tif_col, strip_or_tile);
690
0
        }
691
0
        return ((tmsize_t)(-1));
692
0
    }
693
694
0
    if (!TIFFReadAndRealloc(tif, size, 0, is_strip, strip_or_tile, module))
695
0
    {
696
0
        return ((tmsize_t)(-1));
697
0
    }
698
699
0
    return (size);
700
0
}
701
702
/*
703
 * Read a strip of data from the file.
704
 */
705
tmsize_t TIFFReadRawStrip(TIFF *tif, uint32_t strip, void *buf, tmsize_t size)
706
0
{
707
0
    static const char module[] = "TIFFReadRawStrip";
708
0
    TIFFDirectory *td = &tif->tif_dir;
709
0
    uint64_t bytecount64;
710
0
    tmsize_t bytecountm;
711
712
0
    if (!TIFFCheckRead(tif, 0))
713
0
        return ((tmsize_t)(-1));
714
0
    if (strip >= td->td_nstrips)
715
0
    {
716
0
        TIFFErrorExtR(tif, module,
717
0
                      "%" PRIu32 ": Strip out of range, max %" PRIu32, strip,
718
0
                      td->td_nstrips);
719
0
        return ((tmsize_t)(-1));
720
0
    }
721
0
    if (tif->tif_flags & TIFF_NOREADRAW)
722
0
    {
723
0
        TIFFErrorExtR(tif, module,
724
0
                      "Compression scheme does not support access to raw "
725
0
                      "uncompressed data");
726
0
        return ((tmsize_t)(-1));
727
0
    }
728
0
    bytecount64 = TIFFGetStrileByteCount(tif, strip);
729
0
    if (size != (tmsize_t)(-1) && (uint64_t)size <= bytecount64)
730
0
        bytecountm = size;
731
0
    else
732
0
        bytecountm = _TIFFCastUInt64ToSSize(tif, bytecount64, module);
733
0
    if (bytecountm == 0)
734
0
    {
735
0
        return ((tmsize_t)(-1));
736
0
    }
737
0
    return (TIFFReadRawStrip1(tif, strip, buf, bytecountm, module));
738
0
}
739
740
TIFF_NOSANITIZE_UNSIGNED_INT_OVERFLOW
741
0
static uint64_t NoSanitizeSubUInt64(uint64_t a, uint64_t b) { return a - b; }
742
743
/*
744
 * Read the specified strip and setup for decoding. The data buffer is
745
 * expanded, as necessary, to hold the strip's data.
746
 */
747
int TIFFFillStrip(TIFF *tif, uint32_t strip)
748
0
{
749
0
    static const char module[] = "TIFFFillStrip";
750
0
    TIFFDirectory *td = &tif->tif_dir;
751
752
0
    if ((tif->tif_flags & TIFF_NOREADRAW) == 0)
753
0
    {
754
0
        uint64_t bytecount = TIFFGetStrileByteCount(tif, strip);
755
0
        if (bytecount == 0 || bytecount > (uint64_t)TIFF_INT64_MAX)
756
0
        {
757
0
            TIFFErrorExtR(tif, module,
758
0
                          "Invalid strip byte count %" PRIu64
759
0
                          ", strip %" PRIu32,
760
0
                          bytecount, strip);
761
0
            return (0);
762
0
        }
763
764
        /* To avoid excessive memory allocations: */
765
        /* Byte count should normally not be larger than a number of */
766
        /* times the uncompressed size plus some margin */
767
0
        if (bytecount > 1024 * 1024)
768
0
        {
769
            /* 10 and 4096 are just values that could be adjusted. */
770
            /* Hopefully they are safe enough for all codecs */
771
0
            tmsize_t stripsize = TIFFStripSize(tif);
772
0
            if (stripsize != 0 && (bytecount - 4096) / 10 > (uint64_t)stripsize)
773
0
            {
774
0
                uint64_t newbytecount = (uint64_t)stripsize * 10 + 4096;
775
0
                TIFFErrorExtR(tif, module,
776
0
                              "Too large strip byte count %" PRIu64
777
0
                              ", strip %" PRIu32 ". Limiting to %" PRIu64,
778
0
                              bytecount, strip, newbytecount);
779
0
                bytecount = newbytecount;
780
0
            }
781
0
        }
782
783
0
        if (isMapped(tif))
784
0
        {
785
            /*
786
             * We must check for overflow, potentially causing
787
             * an OOB read. Instead of simple
788
             *
789
             *  TIFFGetStrileOffset(tif, strip)+bytecount > tif->tif_size
790
             *
791
             * comparison (which can overflow) we do the following
792
             * two comparisons:
793
             */
794
0
            if (bytecount > (uint64_t)tif->tif_size ||
795
0
                TIFFGetStrileOffset(tif, strip) >
796
0
                    (uint64_t)tif->tif_size - bytecount)
797
0
            {
798
                /*
799
                 * This error message might seem strange, but
800
                 * it's what would happen if a read were done
801
                 * instead.
802
                 */
803
0
                TIFFErrorExtR(
804
0
                    tif, module,
805
806
0
                    "Read error on strip %" PRIu32 "; "
807
0
                    "got %" PRIu64 " bytes, expected %" PRIu64,
808
0
                    strip,
809
0
                    NoSanitizeSubUInt64(tif->tif_size,
810
0
                                        TIFFGetStrileOffset(tif, strip)),
811
0
                    bytecount);
812
0
                tif->tif_curstrip = NOSTRIP;
813
0
                return (0);
814
0
            }
815
0
        }
816
817
0
        if (isMapped(tif) && (isFillOrder(tif, td->td_fillorder) ||
818
0
                              (tif->tif_flags & TIFF_NOBITREV)))
819
0
        {
820
            /*
821
             * The image is mapped into memory and we either don't
822
             * need to flip bits or the compression routine is
823
             * going to handle this operation itself.  In this
824
             * case, avoid copying the raw data and instead just
825
             * reference the data from the memory mapped file
826
             * image.  This assumes that the decompression
827
             * routines do not modify the contents of the raw data
828
             * buffer (if they try to, the application will get a
829
             * fault since the file is mapped read-only).
830
             */
831
0
            if ((tif->tif_flags & TIFF_MYBUFFER) && tif->tif_rawdata)
832
0
            {
833
0
                _TIFFfreeExt(tif, tif->tif_rawdata);
834
0
                tif->tif_rawdata = NULL;
835
0
                tif->tif_rawdatasize = 0;
836
0
            }
837
0
            tif->tif_flags &= ~TIFF_MYBUFFER;
838
0
            tif->tif_rawdatasize = (tmsize_t)bytecount;
839
0
            tif->tif_rawdata =
840
0
                tif->tif_base + (tmsize_t)TIFFGetStrileOffset(tif, strip);
841
0
            tif->tif_rawdataoff = 0;
842
0
            tif->tif_rawdataloaded = (tmsize_t)bytecount;
843
844
            /*
845
             * When we have tif_rawdata reference directly into the memory
846
             * mapped file we need to be pretty careful about how we use the
847
             * rawdata.  It is not a general purpose working buffer as it
848
             * normally otherwise is.  So we keep track of this fact to avoid
849
             * using it improperly.
850
             */
851
0
            tif->tif_flags |= TIFF_BUFFERMMAP;
852
0
        }
853
0
        else
854
0
        {
855
            /*
856
             * Expand raw data buffer, if needed, to hold data
857
             * strip coming from file (perhaps should set upper
858
             * bound on the size of a buffer we'll use?).
859
             */
860
0
            tmsize_t bytecountm;
861
0
            bytecountm = (tmsize_t)bytecount;
862
0
            if ((uint64_t)bytecountm != bytecount)
863
0
            {
864
0
                TIFFErrorExtR(tif, module, "Integer overflow");
865
0
                return (0);
866
0
            }
867
0
            if (bytecountm > tif->tif_rawdatasize)
868
0
            {
869
0
                tif->tif_curstrip = NOSTRIP;
870
0
                if ((tif->tif_flags & TIFF_MYBUFFER) == 0)
871
0
                {
872
0
                    TIFFErrorExtR(
873
0
                        tif, module,
874
0
                        "Data buffer too small to hold strip %" PRIu32, strip);
875
0
                    return (0);
876
0
                }
877
0
            }
878
0
            if (tif->tif_flags & TIFF_BUFFERMMAP)
879
0
            {
880
0
                tif->tif_curstrip = NOSTRIP;
881
0
                tif->tif_rawdata = NULL;
882
0
                tif->tif_rawdatasize = 0;
883
0
                tif->tif_flags &= ~TIFF_BUFFERMMAP;
884
0
            }
885
886
0
            if (isMapped(tif))
887
0
            {
888
0
                if (bytecountm > tif->tif_rawdatasize &&
889
0
                    !TIFFReadBufferSetup(tif, 0, bytecountm))
890
0
                {
891
0
                    return (0);
892
0
                }
893
0
                if (TIFFReadRawStrip1(tif, strip, tif->tif_rawdata, bytecountm,
894
0
                                      module) != bytecountm)
895
0
                {
896
0
                    return (0);
897
0
                }
898
0
            }
899
0
            else
900
0
            {
901
0
                if (TIFFReadRawStripOrTile2(tif, strip, 1, bytecountm,
902
0
                                            module) != bytecountm)
903
0
                {
904
0
                    return (0);
905
0
                }
906
0
            }
907
908
0
            tif->tif_rawdataoff = 0;
909
0
            tif->tif_rawdataloaded = bytecountm;
910
911
0
            if (!isFillOrder(tif, td->td_fillorder) &&
912
0
                (tif->tif_flags & TIFF_NOBITREV) == 0)
913
0
                TIFFReverseBits(tif->tif_rawdata, bytecountm);
914
0
        }
915
0
    }
916
0
    return (TIFFStartStrip(tif, strip));
917
0
}
918
919
/*
920
 * Tile-oriented Read Support
921
 * Contributed by Nancy Cam (Silicon Graphics).
922
 */
923
924
/*
925
 * Read and decompress a tile of data.  The
926
 * tile is selected by the (x,y,z,s) coordinates.
927
 */
928
tmsize_t TIFFReadTile(TIFF *tif, void *buf, uint32_t x, uint32_t y, uint32_t z,
929
                      uint16_t s)
930
0
{
931
0
    if (!TIFFCheckRead(tif, 1) || !TIFFCheckTile(tif, x, y, z, s))
932
0
        return ((tmsize_t)(-1));
933
0
    return (TIFFReadEncodedTile(tif, TIFFComputeTile(tif, x, y, z, s), buf,
934
0
                                (tmsize_t)(-1)));
935
0
}
936
937
/*
938
 * Read a tile of data and decompress the specified
939
 * amount into the user-supplied buffer.
940
 */
941
tmsize_t TIFFReadEncodedTile(TIFF *tif, uint32_t tile, void *buf, tmsize_t size)
942
0
{
943
0
    static const char module[] = "TIFFReadEncodedTile";
944
0
    TIFFDirectory *td = &tif->tif_dir;
945
0
    tmsize_t tilesize = tif->tif_tilesize;
946
947
0
    if (!TIFFCheckRead(tif, 1))
948
0
        return ((tmsize_t)(-1));
949
0
    if (tile >= td->td_nstrips)
950
0
    {
951
0
        TIFFErrorExtR(tif, module,
952
0
                      "%" PRIu32 ": Tile out of range, max %" PRIu32, tile,
953
0
                      td->td_nstrips);
954
0
        return ((tmsize_t)(-1));
955
0
    }
956
957
    /* shortcut to avoid an extra memcpy() */
958
0
    if (td->td_compression == COMPRESSION_NONE && size != (tmsize_t)(-1) &&
959
0
        size >= tilesize && !isMapped(tif) &&
960
0
        ((tif->tif_flags & TIFF_NOREADRAW) == 0))
961
0
    {
962
0
        if (TIFFReadRawTile1(tif, tile, buf, tilesize, module) != tilesize)
963
0
            return ((tmsize_t)(-1));
964
965
0
        if (!isFillOrder(tif, td->td_fillorder) &&
966
0
            (tif->tif_flags & TIFF_NOBITREV) == 0)
967
0
            TIFFReverseBits(buf, tilesize);
968
969
0
        (*tif->tif_postdecode)(tif, buf, tilesize);
970
0
        return (tilesize);
971
0
    }
972
973
0
    if (size == (tmsize_t)(-1))
974
0
        size = tilesize;
975
0
    else if (size > tilesize)
976
0
        size = tilesize;
977
0
    if (!TIFFFillTile(tif, tile))
978
0
    {
979
0
        memset(buf, 0, (size_t)size);
980
0
        return ((tmsize_t)(-1));
981
0
    }
982
0
    else if ((*tif->tif_decodetile)(tif, (uint8_t *)buf, size,
983
0
                                    (uint16_t)(tile / td->td_stripsperimage)))
984
0
    {
985
0
        (*tif->tif_postdecode)(tif, (uint8_t *)buf, size);
986
0
        return (size);
987
0
    }
988
0
    else
989
0
        return ((tmsize_t)(-1));
990
0
}
991
992
/* Variant of TIFFReadTile() that does
993
 * * if *buf == NULL, *buf = _TIFFmallocExt(tif, bufsizetoalloc) only after
994
 * TIFFFillTile() has succeeded. This avoid excessive memory allocation in case
995
 * of truncated file.
996
 * * calls regular TIFFReadEncodedTile() if *buf != NULL
997
 */
998
tmsize_t _TIFFReadTileAndAllocBuffer(TIFF *tif, void **buf,
999
                                     tmsize_t bufsizetoalloc, uint32_t x,
1000
                                     uint32_t y, uint32_t z, uint16_t s)
1001
0
{
1002
0
    if (!TIFFCheckRead(tif, 1) || !TIFFCheckTile(tif, x, y, z, s))
1003
0
        return ((tmsize_t)(-1));
1004
0
    return (_TIFFReadEncodedTileAndAllocBuffer(
1005
0
        tif, TIFFComputeTile(tif, x, y, z, s), buf, bufsizetoalloc,
1006
0
        (tmsize_t)(-1)));
1007
0
}
1008
1009
/* Variant of TIFFReadEncodedTile() that does
1010
 * * if *buf == NULL, *buf = _TIFFmallocExt(tif, bufsizetoalloc) only after
1011
 * TIFFFillTile() has succeeded. This avoid excessive memory allocation in case
1012
 * of truncated file.
1013
 * * calls regular TIFFReadEncodedTile() if *buf != NULL
1014
 */
1015
tmsize_t _TIFFReadEncodedTileAndAllocBuffer(TIFF *tif, uint32_t tile,
1016
                                            void **buf, tmsize_t bufsizetoalloc,
1017
                                            tmsize_t size_to_read)
1018
0
{
1019
0
    static const char module[] = "_TIFFReadEncodedTileAndAllocBuffer";
1020
0
    TIFFDirectory *td = &tif->tif_dir;
1021
0
    tmsize_t tilesize = tif->tif_tilesize;
1022
1023
0
    if (*buf != NULL)
1024
0
    {
1025
0
        return TIFFReadEncodedTile(tif, tile, *buf, size_to_read);
1026
0
    }
1027
1028
0
    if (!TIFFCheckRead(tif, 1))
1029
0
        return ((tmsize_t)(-1));
1030
0
    if (tile >= td->td_nstrips)
1031
0
    {
1032
0
        TIFFErrorExtR(tif, module,
1033
0
                      "%" PRIu32 ": Tile out of range, max %" PRIu32, tile,
1034
0
                      td->td_nstrips);
1035
0
        return ((tmsize_t)(-1));
1036
0
    }
1037
1038
0
    if (!TIFFFillTile(tif, tile))
1039
0
        return ((tmsize_t)(-1));
1040
1041
    /* Sanity checks to avoid excessive memory allocation */
1042
    /* Cf https://gitlab.com/libtiff/libtiff/-/issues/479 */
1043
0
    if (td->td_compression == COMPRESSION_NONE)
1044
0
    {
1045
0
        if (tif->tif_rawdatasize != tilesize)
1046
0
        {
1047
0
            TIFFErrorExtR(tif, TIFFFileName(tif),
1048
0
                          "Invalid tile byte count for tile %u. "
1049
0
                          "Expected %" PRIu64 ", got %" PRIu64,
1050
0
                          tile, (uint64_t)tilesize,
1051
0
                          (uint64_t)tif->tif_rawdatasize);
1052
0
            return ((tmsize_t)(-1));
1053
0
        }
1054
0
    }
1055
0
    else
1056
0
    {
1057
        /* Max compression ratio experimentally determined. Might be fragile...
1058
         * Only apply this heuristics to situations where the memory allocation
1059
         * would be big, to avoid breaking nominal use cases.
1060
         */
1061
0
        const int maxCompressionRatio =
1062
0
            td->td_compression == COMPRESSION_ZSTD ? 33000
1063
0
            : td->td_compression == COMPRESSION_JXL
1064
0
                ?
1065
                /* Evaluated on a 8000x8000 tile */
1066
0
                25000 * (td->td_planarconfig == PLANARCONFIG_CONTIG
1067
0
                             ? td->td_samplesperpixel
1068
0
                             : 1)
1069
0
                : td->td_compression == COMPRESSION_LZMA ? 7000 : 1000;
1070
0
        if (bufsizetoalloc > 100 * 1000 * 1000 &&
1071
0
            tif->tif_rawdatasize < tilesize / maxCompressionRatio)
1072
0
        {
1073
0
            TIFFErrorExtR(tif, TIFFFileName(tif),
1074
0
                          "Likely invalid tile byte count for tile %u. "
1075
0
                          "Uncompressed tile size is %" PRIu64 ", "
1076
0
                          "compressed one is %" PRIu64,
1077
0
                          tile, (uint64_t)tilesize,
1078
0
                          (uint64_t)tif->tif_rawdatasize);
1079
0
            return ((tmsize_t)(-1));
1080
0
        }
1081
0
    }
1082
1083
0
    *buf = _TIFFmallocExt(tif, bufsizetoalloc);
1084
0
    if (*buf == NULL)
1085
0
    {
1086
0
        TIFFErrorExtR(tif, TIFFFileName(tif), "No space for tile buffer");
1087
0
        return ((tmsize_t)(-1));
1088
0
    }
1089
0
    _TIFFmemset(*buf, 0, bufsizetoalloc);
1090
1091
0
    if (size_to_read == (tmsize_t)(-1))
1092
0
        size_to_read = tilesize;
1093
0
    else if (size_to_read > tilesize)
1094
0
        size_to_read = tilesize;
1095
0
    if ((*tif->tif_decodetile)(tif, (uint8_t *)*buf, size_to_read,
1096
0
                               (uint16_t)(tile / td->td_stripsperimage)))
1097
0
    {
1098
0
        (*tif->tif_postdecode)(tif, (uint8_t *)*buf, size_to_read);
1099
0
        return (size_to_read);
1100
0
    }
1101
0
    else
1102
0
        return ((tmsize_t)(-1));
1103
0
}
1104
1105
static tmsize_t TIFFReadRawTile1(TIFF *tif, uint32_t tile, void *buf,
1106
                                 tmsize_t size, const char *module)
1107
0
{
1108
0
    assert((tif->tif_flags & TIFF_NOREADRAW) == 0);
1109
0
    if (!isMapped(tif))
1110
0
    {
1111
0
        tmsize_t cc;
1112
1113
0
        if (!SeekOK(tif, TIFFGetStrileOffset(tif, tile)))
1114
0
        {
1115
0
            TIFFErrorExtR(tif, module,
1116
0
                          "Seek error at row %" PRIu32 ", col %" PRIu32
1117
0
                          ", tile %" PRIu32,
1118
0
                          tif->tif_row, tif->tif_col, tile);
1119
0
            return ((tmsize_t)(-1));
1120
0
        }
1121
0
        cc = TIFFReadFile(tif, buf, size);
1122
0
        if (cc != size)
1123
0
        {
1124
0
            TIFFErrorExtR(tif, module,
1125
0
                          "Read error at row %" PRIu32 ", col %" PRIu32
1126
0
                          "; got %" TIFF_SSIZE_FORMAT
1127
0
                          " bytes, expected %" TIFF_SSIZE_FORMAT,
1128
0
                          tif->tif_row, tif->tif_col, cc, size);
1129
0
            return ((tmsize_t)(-1));
1130
0
        }
1131
0
    }
1132
0
    else
1133
0
    {
1134
0
        tmsize_t ma, mb;
1135
0
        tmsize_t n;
1136
0
        ma = (tmsize_t)TIFFGetStrileOffset(tif, tile);
1137
0
        mb = ma + size;
1138
0
        if ((TIFFGetStrileOffset(tif, tile) > (uint64_t)TIFF_TMSIZE_T_MAX) ||
1139
0
            (ma > tif->tif_size))
1140
0
            n = 0;
1141
0
        else if ((mb < ma) || (mb < size) || (mb > tif->tif_size))
1142
0
            n = tif->tif_size - ma;
1143
0
        else
1144
0
            n = size;
1145
0
        if (n != size)
1146
0
        {
1147
0
            TIFFErrorExtR(tif, module,
1148
0
                          "Read error at row %" PRIu32 ", col %" PRIu32
1149
0
                          ", tile %" PRIu32 "; got %" TIFF_SSIZE_FORMAT
1150
0
                          " bytes, expected %" TIFF_SSIZE_FORMAT,
1151
0
                          tif->tif_row, tif->tif_col, tile, n, size);
1152
0
            return ((tmsize_t)(-1));
1153
0
        }
1154
0
        _TIFFmemcpy(buf, tif->tif_base + ma, size);
1155
0
    }
1156
0
    return (size);
1157
0
}
1158
1159
/*
1160
 * Read a tile of data from the file.
1161
 */
1162
tmsize_t TIFFReadRawTile(TIFF *tif, uint32_t tile, void *buf, tmsize_t size)
1163
0
{
1164
0
    static const char module[] = "TIFFReadRawTile";
1165
0
    TIFFDirectory *td = &tif->tif_dir;
1166
0
    uint64_t bytecount64;
1167
0
    tmsize_t bytecountm;
1168
1169
0
    if (!TIFFCheckRead(tif, 1))
1170
0
        return ((tmsize_t)(-1));
1171
0
    if (tile >= td->td_nstrips)
1172
0
    {
1173
0
        TIFFErrorExtR(tif, module,
1174
0
                      "%" PRIu32 ": Tile out of range, max %" PRIu32, tile,
1175
0
                      td->td_nstrips);
1176
0
        return ((tmsize_t)(-1));
1177
0
    }
1178
0
    if (tif->tif_flags & TIFF_NOREADRAW)
1179
0
    {
1180
0
        TIFFErrorExtR(tif, module,
1181
0
                      "Compression scheme does not support access to raw "
1182
0
                      "uncompressed data");
1183
0
        return ((tmsize_t)(-1));
1184
0
    }
1185
0
    bytecount64 = TIFFGetStrileByteCount(tif, tile);
1186
0
    if (size != (tmsize_t)(-1) && (uint64_t)size <= bytecount64)
1187
0
        bytecountm = size;
1188
0
    else
1189
0
        bytecountm = _TIFFCastUInt64ToSSize(tif, bytecount64, module);
1190
0
    if (bytecountm == 0)
1191
0
    {
1192
0
        return ((tmsize_t)(-1));
1193
0
    }
1194
0
    return (TIFFReadRawTile1(tif, tile, buf, bytecountm, module));
1195
0
}
1196
1197
/*
1198
 * Read the specified tile and setup for decoding. The data buffer is
1199
 * expanded, as necessary, to hold the tile's data.
1200
 */
1201
int TIFFFillTile(TIFF *tif, uint32_t tile)
1202
0
{
1203
0
    static const char module[] = "TIFFFillTile";
1204
0
    TIFFDirectory *td = &tif->tif_dir;
1205
1206
0
    if ((tif->tif_flags & TIFF_NOREADRAW) == 0)
1207
0
    {
1208
0
        uint64_t bytecount = TIFFGetStrileByteCount(tif, tile);
1209
0
        if (bytecount == 0 || bytecount > (uint64_t)TIFF_INT64_MAX)
1210
0
        {
1211
0
            TIFFErrorExtR(tif, module,
1212
0
                          "%" PRIu64 ": Invalid tile byte count, tile %" PRIu32,
1213
0
                          bytecount, tile);
1214
0
            return (0);
1215
0
        }
1216
1217
        /* To avoid excessive memory allocations: */
1218
        /* Byte count should normally not be larger than a number of */
1219
        /* times the uncompressed size plus some margin */
1220
0
        if (bytecount > 1024 * 1024)
1221
0
        {
1222
            /* 10 and 4096 are just values that could be adjusted. */
1223
            /* Hopefully they are safe enough for all codecs */
1224
0
            tmsize_t stripsize = TIFFTileSize(tif);
1225
0
            if (stripsize != 0 && (bytecount - 4096) / 10 > (uint64_t)stripsize)
1226
0
            {
1227
0
                uint64_t newbytecount = (uint64_t)stripsize * 10 + 4096;
1228
0
                TIFFErrorExtR(tif, module,
1229
0
                              "Too large tile byte count %" PRIu64
1230
0
                              ", tile %" PRIu32 ". Limiting to %" PRIu64,
1231
0
                              bytecount, tile, newbytecount);
1232
0
                bytecount = newbytecount;
1233
0
            }
1234
0
        }
1235
1236
0
        if (isMapped(tif))
1237
0
        {
1238
            /*
1239
             * We must check for overflow, potentially causing
1240
             * an OOB read. Instead of simple
1241
             *
1242
             *  TIFFGetStrileOffset(tif, tile)+bytecount > tif->tif_size
1243
             *
1244
             * comparison (which can overflow) we do the following
1245
             * two comparisons:
1246
             */
1247
0
            if (bytecount > (uint64_t)tif->tif_size ||
1248
0
                TIFFGetStrileOffset(tif, tile) >
1249
0
                    (uint64_t)tif->tif_size - bytecount)
1250
0
            {
1251
0
                tif->tif_curtile = NOTILE;
1252
0
                return (0);
1253
0
            }
1254
0
        }
1255
1256
0
        if (isMapped(tif) && (isFillOrder(tif, td->td_fillorder) ||
1257
0
                              (tif->tif_flags & TIFF_NOBITREV)))
1258
0
        {
1259
            /*
1260
             * The image is mapped into memory and we either don't
1261
             * need to flip bits or the compression routine is
1262
             * going to handle this operation itself.  In this
1263
             * case, avoid copying the raw data and instead just
1264
             * reference the data from the memory mapped file
1265
             * image.  This assumes that the decompression
1266
             * routines do not modify the contents of the raw data
1267
             * buffer (if they try to, the application will get a
1268
             * fault since the file is mapped read-only).
1269
             */
1270
0
            if ((tif->tif_flags & TIFF_MYBUFFER) && tif->tif_rawdata)
1271
0
            {
1272
0
                _TIFFfreeExt(tif, tif->tif_rawdata);
1273
0
                tif->tif_rawdata = NULL;
1274
0
                tif->tif_rawdatasize = 0;
1275
0
            }
1276
0
            tif->tif_flags &= ~TIFF_MYBUFFER;
1277
1278
0
            tif->tif_rawdatasize = (tmsize_t)bytecount;
1279
0
            tif->tif_rawdata =
1280
0
                tif->tif_base + (tmsize_t)TIFFGetStrileOffset(tif, tile);
1281
0
            tif->tif_rawdataoff = 0;
1282
0
            tif->tif_rawdataloaded = (tmsize_t)bytecount;
1283
0
            tif->tif_flags |= TIFF_BUFFERMMAP;
1284
0
        }
1285
0
        else
1286
0
        {
1287
            /*
1288
             * Expand raw data buffer, if needed, to hold data
1289
             * tile coming from file (perhaps should set upper
1290
             * bound on the size of a buffer we'll use?).
1291
             */
1292
0
            tmsize_t bytecountm;
1293
0
            bytecountm = (tmsize_t)bytecount;
1294
0
            if ((uint64_t)bytecountm != bytecount)
1295
0
            {
1296
0
                TIFFErrorExtR(tif, module, "Integer overflow");
1297
0
                return (0);
1298
0
            }
1299
0
            if (bytecountm > tif->tif_rawdatasize)
1300
0
            {
1301
0
                tif->tif_curtile = NOTILE;
1302
0
                if ((tif->tif_flags & TIFF_MYBUFFER) == 0)
1303
0
                {
1304
0
                    TIFFErrorExtR(tif, module,
1305
0
                                  "Data buffer too small to hold tile %" PRIu32,
1306
0
                                  tile);
1307
0
                    return (0);
1308
0
                }
1309
0
            }
1310
0
            if (tif->tif_flags & TIFF_BUFFERMMAP)
1311
0
            {
1312
0
                tif->tif_curtile = NOTILE;
1313
0
                tif->tif_rawdata = NULL;
1314
0
                tif->tif_rawdatasize = 0;
1315
0
                tif->tif_flags &= ~TIFF_BUFFERMMAP;
1316
0
            }
1317
1318
0
            if (isMapped(tif))
1319
0
            {
1320
0
                if (bytecountm > tif->tif_rawdatasize &&
1321
0
                    !TIFFReadBufferSetup(tif, 0, bytecountm))
1322
0
                {
1323
0
                    return (0);
1324
0
                }
1325
0
                if (TIFFReadRawTile1(tif, tile, tif->tif_rawdata, bytecountm,
1326
0
                                     module) != bytecountm)
1327
0
                {
1328
0
                    return (0);
1329
0
                }
1330
0
            }
1331
0
            else
1332
0
            {
1333
0
                if (TIFFReadRawStripOrTile2(tif, tile, 0, bytecountm, module) !=
1334
0
                    bytecountm)
1335
0
                {
1336
0
                    return (0);
1337
0
                }
1338
0
            }
1339
1340
0
            tif->tif_rawdataoff = 0;
1341
0
            tif->tif_rawdataloaded = bytecountm;
1342
1343
0
            if (tif->tif_rawdata != NULL &&
1344
0
                !isFillOrder(tif, td->td_fillorder) &&
1345
0
                (tif->tif_flags & TIFF_NOBITREV) == 0)
1346
0
                TIFFReverseBits(tif->tif_rawdata, tif->tif_rawdataloaded);
1347
0
        }
1348
0
    }
1349
0
    return (TIFFStartTile(tif, tile));
1350
0
}
1351
1352
/*
1353
 * Setup the raw data buffer in preparation for
1354
 * reading a strip of raw data.  If the buffer
1355
 * is specified as zero, then a buffer of appropriate
1356
 * size is allocated by the library.  Otherwise,
1357
 * the client must guarantee that the buffer is
1358
 * large enough to hold any individual strip of
1359
 * raw data.
1360
 */
1361
int TIFFReadBufferSetup(TIFF *tif, void *bp, tmsize_t size)
1362
0
{
1363
0
    static const char module[] = "TIFFReadBufferSetup";
1364
1365
0
    assert((tif->tif_flags & TIFF_NOREADRAW) == 0);
1366
0
    tif->tif_flags &= ~TIFF_BUFFERMMAP;
1367
1368
0
    if (tif->tif_rawdata)
1369
0
    {
1370
0
        if (tif->tif_flags & TIFF_MYBUFFER)
1371
0
            _TIFFfreeExt(tif, tif->tif_rawdata);
1372
0
        tif->tif_rawdata = NULL;
1373
0
        tif->tif_rawdatasize = 0;
1374
0
    }
1375
0
    if (bp)
1376
0
    {
1377
0
        tif->tif_rawdatasize = size;
1378
0
        tif->tif_rawdata = (uint8_t *)bp;
1379
0
        tif->tif_flags &= ~TIFF_MYBUFFER;
1380
0
    }
1381
0
    else
1382
0
    {
1383
0
        tif->tif_rawdatasize = (tmsize_t)TIFFroundup_64((uint64_t)size, 1024);
1384
0
        if (tif->tif_rawdatasize == 0)
1385
0
        {
1386
0
            TIFFErrorExtR(tif, module, "Invalid buffer size");
1387
0
            return (0);
1388
0
        }
1389
        /* Initialize to zero to avoid uninitialized buffers in case of */
1390
        /* short reads (http://bugzilla.maptools.org/show_bug.cgi?id=2651) */
1391
0
        tif->tif_rawdata =
1392
0
            (uint8_t *)_TIFFcallocExt(tif, 1, tif->tif_rawdatasize);
1393
0
        tif->tif_flags |= TIFF_MYBUFFER;
1394
0
    }
1395
0
    if (tif->tif_rawdata == NULL)
1396
0
    {
1397
0
        TIFFErrorExtR(tif, module,
1398
0
                      "No space for data buffer at scanline %" PRIu32,
1399
0
                      tif->tif_row);
1400
0
        tif->tif_rawdatasize = 0;
1401
0
        return (0);
1402
0
    }
1403
0
    return (1);
1404
0
}
1405
1406
/*
1407
 * Set state to appear as if a
1408
 * strip has just been read in.
1409
 */
1410
static int TIFFStartStrip(TIFF *tif, uint32_t strip)
1411
0
{
1412
0
    TIFFDirectory *td = &tif->tif_dir;
1413
1414
0
    if ((tif->tif_flags & TIFF_CODERSETUP) == 0)
1415
0
    {
1416
0
        if (!(*tif->tif_setupdecode)(tif))
1417
0
            return (0);
1418
0
        tif->tif_flags |= TIFF_CODERSETUP;
1419
0
    }
1420
0
    tif->tif_curstrip = strip;
1421
0
    tif->tif_row = (strip % td->td_stripsperimage) * td->td_rowsperstrip;
1422
0
    tif->tif_flags &= ~TIFF_BUF4WRITE;
1423
1424
0
    if (tif->tif_flags & TIFF_NOREADRAW)
1425
0
    {
1426
0
        tif->tif_rawcp = NULL;
1427
0
        tif->tif_rawcc = 0;
1428
0
    }
1429
0
    else
1430
0
    {
1431
0
        tif->tif_rawcp = tif->tif_rawdata;
1432
0
        if (tif->tif_rawdataloaded > 0)
1433
0
            tif->tif_rawcc = tif->tif_rawdataloaded;
1434
0
        else
1435
0
            tif->tif_rawcc = (tmsize_t)TIFFGetStrileByteCount(tif, strip);
1436
0
    }
1437
0
    if ((*tif->tif_predecode)(tif, (uint16_t)(strip / td->td_stripsperimage)) ==
1438
0
        0)
1439
0
    {
1440
        /* Needed for example for scanline access, if tif_predecode */
1441
        /* fails, and we try to read the same strip again. Without invalidating
1442
         */
1443
        /* tif_curstrip, we'd call tif_decoderow() on a possibly invalid */
1444
        /* codec state. */
1445
0
        tif->tif_curstrip = NOSTRIP;
1446
0
        return 0;
1447
0
    }
1448
0
    return 1;
1449
0
}
1450
1451
/*
1452
 * Set state to appear as if a
1453
 * tile has just been read in.
1454
 */
1455
static int TIFFStartTile(TIFF *tif, uint32_t tile)
1456
0
{
1457
0
    static const char module[] = "TIFFStartTile";
1458
0
    TIFFDirectory *td = &tif->tif_dir;
1459
0
    uint32_t howmany32;
1460
1461
0
    if ((tif->tif_flags & TIFF_CODERSETUP) == 0)
1462
0
    {
1463
0
        if (!(*tif->tif_setupdecode)(tif))
1464
0
            return (0);
1465
0
        tif->tif_flags |= TIFF_CODERSETUP;
1466
0
    }
1467
0
    tif->tif_curtile = tile;
1468
0
    if (td->td_tilewidth == 0)
1469
0
    {
1470
0
        TIFFErrorExtR(tif, module, "Zero tilewidth");
1471
0
        return 0;
1472
0
    }
1473
0
    howmany32 = TIFFhowmany_32(td->td_imagewidth, td->td_tilewidth);
1474
0
    if (howmany32 == 0)
1475
0
    {
1476
0
        TIFFErrorExtR(tif, module, "Zero tiles");
1477
0
        return 0;
1478
0
    }
1479
0
    tif->tif_row = (tile % howmany32) * td->td_tilelength;
1480
0
    howmany32 = TIFFhowmany_32(td->td_imagelength, td->td_tilelength);
1481
0
    if (howmany32 == 0)
1482
0
    {
1483
0
        TIFFErrorExtR(tif, module, "Zero tiles");
1484
0
        return 0;
1485
0
    }
1486
0
    tif->tif_col = (tile % howmany32) * td->td_tilewidth;
1487
0
    tif->tif_flags &= ~TIFF_BUF4WRITE;
1488
0
    if (tif->tif_flags & TIFF_NOREADRAW)
1489
0
    {
1490
0
        tif->tif_rawcp = NULL;
1491
0
        tif->tif_rawcc = 0;
1492
0
    }
1493
0
    else
1494
0
    {
1495
0
        tif->tif_rawcp = tif->tif_rawdata;
1496
0
        if (tif->tif_rawdataloaded > 0)
1497
0
            tif->tif_rawcc = tif->tif_rawdataloaded;
1498
0
        else
1499
0
            tif->tif_rawcc = (tmsize_t)TIFFGetStrileByteCount(tif, tile);
1500
0
    }
1501
0
    return (
1502
0
        (*tif->tif_predecode)(tif, (uint16_t)(tile / td->td_stripsperimage)));
1503
0
}
1504
1505
static int TIFFCheckRead(TIFF *tif, int tiles)
1506
0
{
1507
0
    if (tif->tif_mode == O_WRONLY)
1508
0
    {
1509
0
        TIFFErrorExtR(tif, tif->tif_name, "File not open for reading");
1510
0
        return (0);
1511
0
    }
1512
0
    if (tiles ^ isTiled(tif))
1513
0
    {
1514
0
        TIFFErrorExtR(tif, tif->tif_name,
1515
0
                      tiles ? "Can not read tiles from a striped image"
1516
0
                            : "Can not read scanlines from a tiled image");
1517
0
        return (0);
1518
0
    }
1519
0
    return (1);
1520
0
}
1521
1522
/* Use the provided input buffer (inbuf, insize) and decompress it into
1523
 * (outbuf, outsize).
1524
 * This function replaces the use of
1525
 * TIFFReadEncodedStrip()/TIFFReadEncodedTile() when the user can provide the
1526
 * buffer for the input data, for example when he wants to avoid libtiff to read
1527
 * the strile offset/count values from the [Strip|Tile][Offsets/ByteCounts]
1528
 * array. inbuf content must be writable (if bit reversal is needed) Returns 1
1529
 * in case of success, 0 otherwise.
1530
 */
1531
int TIFFReadFromUserBuffer(TIFF *tif, uint32_t strile, void *inbuf,
1532
                           tmsize_t insize, void *outbuf, tmsize_t outsize)
1533
0
{
1534
0
    static const char module[] = "TIFFReadFromUserBuffer";
1535
0
    TIFFDirectory *td = &tif->tif_dir;
1536
0
    int ret = 1;
1537
0
    uint32_t old_tif_flags = tif->tif_flags;
1538
0
    tmsize_t old_rawdatasize = tif->tif_rawdatasize;
1539
0
    void *old_rawdata = tif->tif_rawdata;
1540
1541
0
    if (tif->tif_mode == O_WRONLY)
1542
0
    {
1543
0
        TIFFErrorExtR(tif, tif->tif_name, "File not open for reading");
1544
0
        return 0;
1545
0
    }
1546
0
    if (tif->tif_flags & TIFF_NOREADRAW)
1547
0
    {
1548
0
        TIFFErrorExtR(tif, module,
1549
0
                      "Compression scheme does not support access to raw "
1550
0
                      "uncompressed data");
1551
0
        return 0;
1552
0
    }
1553
1554
0
    tif->tif_flags &= ~TIFF_MYBUFFER;
1555
0
    tif->tif_flags |= TIFF_BUFFERMMAP;
1556
0
    tif->tif_rawdatasize = insize;
1557
0
    tif->tif_rawdata = inbuf;
1558
0
    tif->tif_rawdataoff = 0;
1559
0
    tif->tif_rawdataloaded = insize;
1560
1561
0
    if (!isFillOrder(tif, td->td_fillorder) &&
1562
0
        (tif->tif_flags & TIFF_NOBITREV) == 0)
1563
0
    {
1564
0
        TIFFReverseBits(inbuf, insize);
1565
0
    }
1566
1567
0
    if (TIFFIsTiled(tif))
1568
0
    {
1569
0
        if (!TIFFStartTile(tif, strile))
1570
0
        {
1571
0
            ret = 0;
1572
0
            memset(outbuf, 0, (size_t)outsize);
1573
0
        }
1574
0
        else if (!(*tif->tif_decodetile)(
1575
0
                     tif, (uint8_t *)outbuf, outsize,
1576
0
                     (uint16_t)(strile / td->td_stripsperimage)))
1577
0
        {
1578
0
            ret = 0;
1579
0
        }
1580
0
    }
1581
0
    else
1582
0
    {
1583
0
        uint32_t rowsperstrip = td->td_rowsperstrip;
1584
0
        uint32_t stripsperplane;
1585
0
        if (rowsperstrip > td->td_imagelength)
1586
0
            rowsperstrip = td->td_imagelength;
1587
0
        if (rowsperstrip == 0)
1588
0
        {
1589
0
            TIFFErrorExtR(tif, module, "rowsperstrip is zero");
1590
0
            ret = 0;
1591
0
        }
1592
0
        else
1593
0
        {
1594
0
            stripsperplane =
1595
0
                TIFFhowmany_32_maxuint_compat(td->td_imagelength, rowsperstrip);
1596
0
            if (!TIFFStartStrip(tif, strile))
1597
0
            {
1598
0
                ret = 0;
1599
0
                memset(outbuf, 0, (size_t)outsize);
1600
0
            }
1601
0
            else if (!(*tif->tif_decodestrip)(
1602
0
                         tif, (uint8_t *)outbuf, outsize,
1603
0
                         (uint16_t)(strile / stripsperplane)))
1604
0
            {
1605
0
                ret = 0;
1606
0
            }
1607
0
        }
1608
0
    }
1609
0
    if (ret)
1610
0
    {
1611
0
        (*tif->tif_postdecode)(tif, (uint8_t *)outbuf, outsize);
1612
0
    }
1613
1614
0
    if (!isFillOrder(tif, td->td_fillorder) &&
1615
0
        (tif->tif_flags & TIFF_NOBITREV) == 0)
1616
0
    {
1617
0
        TIFFReverseBits(inbuf, insize);
1618
0
    }
1619
1620
0
    tif->tif_flags = (old_tif_flags & (TIFF_MYBUFFER | TIFF_BUFFERMMAP)) |
1621
0
                     (tif->tif_flags & ~(TIFF_MYBUFFER | TIFF_BUFFERMMAP));
1622
0
    tif->tif_rawdatasize = old_rawdatasize;
1623
0
    tif->tif_rawdata = old_rawdata;
1624
0
    tif->tif_rawdataoff = 0;
1625
0
    tif->tif_rawdataloaded = 0;
1626
1627
0
    return ret;
1628
0
}
1629
1630
void _TIFFNoPostDecode(TIFF *tif, uint8_t *buf, tmsize_t cc)
1631
0
{
1632
0
    (void)tif;
1633
0
    (void)buf;
1634
0
    (void)cc;
1635
0
}
1636
1637
void _TIFFSwab16BitData(TIFF *tif, uint8_t *buf, tmsize_t cc)
1638
0
{
1639
0
    (void)tif;
1640
0
    assert((cc & 1) == 0);
1641
0
    TIFFSwabArrayOfShort((uint16_t *)buf, cc / 2);
1642
0
}
1643
1644
void _TIFFSwab24BitData(TIFF *tif, uint8_t *buf, tmsize_t cc)
1645
0
{
1646
0
    (void)tif;
1647
0
    assert((cc % 3) == 0);
1648
0
    TIFFSwabArrayOfTriples((uint8_t *)buf, cc / 3);
1649
0
}
1650
1651
void _TIFFSwab32BitData(TIFF *tif, uint8_t *buf, tmsize_t cc)
1652
0
{
1653
0
    (void)tif;
1654
0
    assert((cc & 3) == 0);
1655
0
    TIFFSwabArrayOfLong((uint32_t *)buf, cc / 4);
1656
0
}
1657
1658
void _TIFFSwab64BitData(TIFF *tif, uint8_t *buf, tmsize_t cc)
1659
0
{
1660
0
    (void)tif;
1661
0
    assert((cc & 7) == 0);
1662
0
    TIFFSwabArrayOfDouble((double *)buf, cc / 8);
1663
0
}