Coverage Report

Created: 2025-08-26 06:41

/src/libjpeg-turbo.main/src/jdicc.c
Line
Count
Source (jump to first uncovered line)
1
/*
2
 * jdicc.c
3
 *
4
 * Copyright (C) 1997-1998, Thomas G. Lane, Todd Newman.
5
 * Copyright (C) 2017, D. R. Commander.
6
 * For conditions of distribution and use, see the accompanying README.ijg
7
 * file.
8
 *
9
 * This file provides code to read International Color Consortium (ICC) device
10
 * profiles embedded in JFIF JPEG image files.  The ICC has defined a standard
11
 * for including such data in JPEG "APP2" markers.  The code given here does
12
 * not know anything about the internal structure of the ICC profile data; it
13
 * just knows how to get the profile data from a JPEG file while reading it.
14
 */
15
16
#define JPEG_INTERNALS
17
#include "jinclude.h"
18
#include "jpeglib.h"
19
#include "jerror.h"
20
21
22
16.8k
#define ICC_MARKER  (JPEG_APP0 + 2)     /* JPEG marker code for ICC */
23
17.4k
#define ICC_OVERHEAD_LEN  14            /* size of non-profile data in APP2 */
24
25
26
/*
27
 * Handy subroutine to test whether a saved marker is an ICC profile marker.
28
 */
29
30
LOCAL(boolean)
31
marker_is_icc(jpeg_saved_marker_ptr marker)
32
8.44k
{
33
8.44k
  return
34
8.44k
    marker->marker == ICC_MARKER &&
35
8.44k
    marker->data_length >= ICC_OVERHEAD_LEN &&
36
    /* verify the identifying string */
37
8.44k
    marker->data[0] == 0x49 &&
38
8.44k
    marker->data[1] == 0x43 &&
39
8.44k
    marker->data[2] == 0x43 &&
40
8.44k
    marker->data[3] == 0x5F &&
41
8.44k
    marker->data[4] == 0x50 &&
42
8.44k
    marker->data[5] == 0x52 &&
43
8.44k
    marker->data[6] == 0x4F &&
44
8.44k
    marker->data[7] == 0x46 &&
45
8.44k
    marker->data[8] == 0x49 &&
46
8.44k
    marker->data[9] == 0x4C &&
47
8.44k
    marker->data[10] == 0x45 &&
48
8.44k
    marker->data[11] == 0x0;
49
8.44k
}
50
51
52
/*
53
 * See if there was an ICC profile in the JPEG file being read; if so,
54
 * reassemble and return the profile data.
55
 *
56
 * TRUE is returned if an ICC profile was found, FALSE if not.  If TRUE is
57
 * returned, *icc_data_ptr is set to point to the returned data, and
58
 * *icc_data_len is set to its length.
59
 *
60
 * IMPORTANT: the data at *icc_data_ptr is allocated with malloc() and must be
61
 * freed by the caller with free() when the caller no longer needs it.
62
 * (Alternatively, we could write this routine to use the IJG library's memory
63
 * allocator, so that the data would be freed implicitly when
64
 * jpeg_finish_decompress() is called.  But it seems likely that many
65
 * applications will prefer to have the data stick around after decompression
66
 * finishes.)
67
 */
68
69
GLOBAL(boolean)
70
jpeg_read_icc_profile(j_decompress_ptr cinfo, JOCTET **icc_data_ptr,
71
                      unsigned int *icc_data_len)
72
4.54k
{
73
4.54k
  jpeg_saved_marker_ptr marker;
74
4.54k
  int num_markers = 0;
75
4.54k
  int seq_no;
76
4.54k
  JOCTET *icc_data;
77
4.54k
  unsigned int total_length;
78
1.16M
#define MAX_SEQ_NO  255         /* sufficient since marker numbers are bytes */
79
4.54k
  char marker_present[MAX_SEQ_NO + 1];      /* 1 if marker found */
80
4.54k
  unsigned int data_length[MAX_SEQ_NO + 1]; /* size of profile data in marker */
81
4.54k
  unsigned int data_offset[MAX_SEQ_NO + 1]; /* offset for data in marker */
82
83
4.54k
  if (icc_data_ptr == NULL || icc_data_len == NULL)
84
0
    ERREXIT(cinfo, JERR_BUFFER_SIZE);
85
4.54k
  if (cinfo->global_state < DSTATE_READY)
86
0
    ERREXIT1(cinfo, JERR_BAD_STATE, cinfo->global_state);
87
88
4.54k
  *icc_data_ptr = NULL;         /* avoid confusion if FALSE return */
89
4.54k
  *icc_data_len = 0;
90
91
  /* This first pass over the saved markers discovers whether there are
92
   * any ICC markers and verifies the consistency of the marker numbering.
93
   */
94
95
1.16M
  for (seq_no = 1; seq_no <= MAX_SEQ_NO; seq_no++)
96
1.15M
    marker_present[seq_no] = 0;
97
98
9.74k
  for (marker = cinfo->marker_list; marker != NULL; marker = marker->next) {
99
5.21k
    if (marker_is_icc(marker)) {
100
300
      if (num_markers == 0)
101
278
        num_markers = marker->data[13];
102
22
      else if (num_markers != marker->data[13]) {
103
8
        WARNMS(cinfo, JWRN_BOGUS_ICC);  /* inconsistent num_markers fields */
104
8
        return FALSE;
105
8
      }
106
292
      seq_no = marker->data[12];
107
292
      if (seq_no <= 0 || seq_no > num_markers) {
108
4
        WARNMS(cinfo, JWRN_BOGUS_ICC);  /* bogus sequence number */
109
4
        return FALSE;
110
4
      }
111
288
      if (marker_present[seq_no]) {
112
2
        WARNMS(cinfo, JWRN_BOGUS_ICC);  /* duplicate sequence numbers */
113
2
        return FALSE;
114
2
      }
115
286
      marker_present[seq_no] = 1;
116
286
      data_length[seq_no] = marker->data_length - ICC_OVERHEAD_LEN;
117
286
    }
118
5.21k
  }
119
120
4.53k
  if (num_markers == 0)
121
4.27k
    return FALSE;
122
123
  /* Check for missing markers, count total space needed,
124
   * compute offset of each marker's part of the data.
125
   */
126
127
264
  total_length = 0;
128
514
  for (seq_no = 1; seq_no <= num_markers; seq_no++) {
129
270
    if (marker_present[seq_no] == 0) {
130
20
      WARNMS(cinfo, JWRN_BOGUS_ICC);  /* missing sequence number */
131
20
      return FALSE;
132
20
    }
133
250
    data_offset[seq_no] = total_length;
134
250
    total_length += data_length[seq_no];
135
250
  }
136
137
244
  if (total_length == 0) {
138
1
    WARNMS(cinfo, JWRN_BOGUS_ICC);  /* found only empty markers? */
139
1
    return FALSE;
140
1
  }
141
142
  /* Allocate space for assembled data */
143
243
  icc_data = (JOCTET *)malloc(total_length * sizeof(JOCTET));
144
243
  if (icc_data == NULL)
145
0
    ERREXIT1(cinfo, JERR_OUT_OF_MEMORY, 11);  /* oops, out of memory */
146
147
  /* and fill it in */
148
3.47k
  for (marker = cinfo->marker_list; marker != NULL; marker = marker->next) {
149
3.23k
    if (marker_is_icc(marker)) {
150
243
      JOCTET FAR *src_ptr;
151
243
      JOCTET *dst_ptr;
152
243
      unsigned int length;
153
243
      seq_no = marker->data[12];
154
243
      dst_ptr = icc_data + data_offset[seq_no];
155
243
      src_ptr = marker->data + ICC_OVERHEAD_LEN;
156
243
      length = data_length[seq_no];
157
19.1k
      while (length--) {
158
18.9k
        *dst_ptr++ = *src_ptr++;
159
18.9k
      }
160
243
    }
161
3.23k
  }
162
163
243
  *icc_data_ptr = icc_data;
164
243
  *icc_data_len = total_length;
165
166
243
  return TRUE;
167
244
}