Coverage Report

Created: 2023-06-07 06:03

/src/libjpeg-turbo.2.0.x/jdmarker.c
Line
Count
Source (jump to first uncovered line)
1
/*
2
 * jdmarker.c
3
 *
4
 * This file was part of the Independent JPEG Group's software:
5
 * Copyright (C) 1991-1998, Thomas G. Lane.
6
 * libjpeg-turbo Modifications:
7
 * Copyright (C) 2012, 2015, D. R. Commander.
8
 * For conditions of distribution and use, see the accompanying README.ijg
9
 * file.
10
 *
11
 * This file contains routines to decode JPEG datastream markers.
12
 * Most of the complexity arises from our desire to support input
13
 * suspension: if not all of the data for a marker is available,
14
 * we must exit back to the application.  On resumption, we reprocess
15
 * the marker.
16
 */
17
18
#define JPEG_INTERNALS
19
#include "jinclude.h"
20
#include "jpeglib.h"
21
22
23
typedef enum {                  /* JPEG marker codes */
24
  M_SOF0  = 0xc0,
25
  M_SOF1  = 0xc1,
26
  M_SOF2  = 0xc2,
27
  M_SOF3  = 0xc3,
28
29
  M_SOF5  = 0xc5,
30
  M_SOF6  = 0xc6,
31
  M_SOF7  = 0xc7,
32
33
  M_JPG   = 0xc8,
34
  M_SOF9  = 0xc9,
35
  M_SOF10 = 0xca,
36
  M_SOF11 = 0xcb,
37
38
  M_SOF13 = 0xcd,
39
  M_SOF14 = 0xce,
40
  M_SOF15 = 0xcf,
41
42
  M_DHT   = 0xc4,
43
44
  M_DAC   = 0xcc,
45
46
  M_RST0  = 0xd0,
47
  M_RST1  = 0xd1,
48
  M_RST2  = 0xd2,
49
  M_RST3  = 0xd3,
50
  M_RST4  = 0xd4,
51
  M_RST5  = 0xd5,
52
  M_RST6  = 0xd6,
53
  M_RST7  = 0xd7,
54
55
  M_SOI   = 0xd8,
56
  M_EOI   = 0xd9,
57
  M_SOS   = 0xda,
58
  M_DQT   = 0xdb,
59
  M_DNL   = 0xdc,
60
  M_DRI   = 0xdd,
61
  M_DHP   = 0xde,
62
  M_EXP   = 0xdf,
63
64
  M_APP0  = 0xe0,
65
  M_APP1  = 0xe1,
66
  M_APP2  = 0xe2,
67
  M_APP3  = 0xe3,
68
  M_APP4  = 0xe4,
69
  M_APP5  = 0xe5,
70
  M_APP6  = 0xe6,
71
  M_APP7  = 0xe7,
72
  M_APP8  = 0xe8,
73
  M_APP9  = 0xe9,
74
  M_APP10 = 0xea,
75
  M_APP11 = 0xeb,
76
  M_APP12 = 0xec,
77
  M_APP13 = 0xed,
78
  M_APP14 = 0xee,
79
  M_APP15 = 0xef,
80
81
  M_JPG0  = 0xf0,
82
  M_JPG13 = 0xfd,
83
  M_COM   = 0xfe,
84
85
  M_TEM   = 0x01,
86
87
  M_ERROR = 0x100
88
} JPEG_MARKER;
89
90
91
/* Private state */
92
93
typedef struct {
94
  struct jpeg_marker_reader pub; /* public fields */
95
96
  /* Application-overridable marker processing methods */
97
  jpeg_marker_parser_method process_COM;
98
  jpeg_marker_parser_method process_APPn[16];
99
100
  /* Limit on marker data length to save for each marker type */
101
  unsigned int length_limit_COM;
102
  unsigned int length_limit_APPn[16];
103
104
  /* Status of COM/APPn marker saving */
105
  jpeg_saved_marker_ptr cur_marker;     /* NULL if not processing a marker */
106
  unsigned int bytes_read;              /* data bytes read so far in marker */
107
  /* Note: cur_marker is not linked into marker_list until it's all read. */
108
} my_marker_reader;
109
110
typedef my_marker_reader *my_marker_ptr;
111
112
113
/*
114
 * Macros for fetching data from the data source module.
115
 *
116
 * At all times, cinfo->src->next_input_byte and ->bytes_in_buffer reflect
117
 * the current restart point; we update them only when we have reached a
118
 * suitable place to restart if a suspension occurs.
119
 */
120
121
/* Declare and initialize local copies of input pointer/count */
122
#define INPUT_VARS(cinfo) \
123
5.09M
  struct jpeg_source_mgr *datasrc = (cinfo)->src; \
124
5.09M
  const JOCTET *next_input_byte = datasrc->next_input_byte; \
125
5.09M
  size_t bytes_in_buffer = datasrc->bytes_in_buffer
126
127
/* Unload the local copies --- do this only at a restart boundary */
128
#define INPUT_SYNC(cinfo) \
129
64.9M
  ( datasrc->next_input_byte = next_input_byte, \
130
64.9M
    datasrc->bytes_in_buffer = bytes_in_buffer )
131
132
/* Reload the local copies --- used only in MAKE_BYTE_AVAIL */
133
#define INPUT_RELOAD(cinfo) \
134
13.6M
  ( next_input_byte = datasrc->next_input_byte, \
135
13.6M
    bytes_in_buffer = datasrc->bytes_in_buffer )
136
137
/* Internal macro for INPUT_BYTE and INPUT_2BYTES: make a byte available.
138
 * Note we do *not* do INPUT_SYNC before calling fill_input_buffer,
139
 * but we must reload the local copies after a successful fill.
140
 */
141
#define MAKE_BYTE_AVAIL(cinfo, action) \
142
14.2M
  if (bytes_in_buffer == 0) { \
143
13.6M
    if (!(*datasrc->fill_input_buffer) (cinfo)) \
144
13.6M
      { action; } \
145
13.6M
    INPUT_RELOAD(cinfo); \
146
13.6M
  }
147
148
/* Read a byte into variable V.
149
 * If must suspend, take the specified action (typically "return FALSE").
150
 */
151
#define INPUT_BYTE(cinfo, V, action) \
152
75.6M
  MAKESTMT( MAKE_BYTE_AVAIL(cinfo, action); \
153
64.2M
            bytes_in_buffer--; \
154
64.2M
            V = GETJOCTET(*next_input_byte++); )
155
156
/* As above, but read two bytes interpreted as an unsigned 16-bit integer.
157
 * V should be declared unsigned int or perhaps JLONG.
158
 */
159
#define INPUT_2BYTES(cinfo, V, action) \
160
3.32M
  MAKESTMT( MAKE_BYTE_AVAIL(cinfo, action); \
161
9.82M
            bytes_in_buffer--; \
162
9.82M
            V = ((unsigned int)GETJOCTET(*next_input_byte++)) << 8; \
163
9.82M
            MAKE_BYTE_AVAIL(cinfo, action); \
164
9.82M
            bytes_in_buffer--; \
165
9.82M
            V += GETJOCTET(*next_input_byte++); )
166
167
168
/*
169
 * Routines to process JPEG markers.
170
 *
171
 * Entry condition: JPEG marker itself has been read and its code saved
172
 *   in cinfo->unread_marker; input restart point is just after the marker.
173
 *
174
 * Exit: if return TRUE, have read and processed any parameters, and have
175
 *   updated the restart point to point after the parameters.
176
 *   If return FALSE, was forced to suspend before reaching end of
177
 *   marker parameters; restart point has not been moved.  Same routine
178
 *   will be called again after application supplies more input data.
179
 *
180
 * This approach to suspension assumes that all of a marker's parameters
181
 * can fit into a single input bufferload.  This should hold for "normal"
182
 * markers.  Some COM/APPn markers might have large parameter segments
183
 * that might not fit.  If we are simply dropping such a marker, we use
184
 * skip_input_data to get past it, and thereby put the problem on the
185
 * source manager's shoulders.  If we are saving the marker's contents
186
 * into memory, we use a slightly different convention: when forced to
187
 * suspend, the marker processor updates the restart point to the end of
188
 * what it's consumed (ie, the end of the buffer) before returning FALSE.
189
 * On resumption, cinfo->unread_marker still contains the marker code,
190
 * but the data source will point to the next chunk of marker data.
191
 * The marker processor must retain internal state to deal with this.
192
 *
193
 * Note that we don't bother to avoid duplicate trace messages if a
194
 * suspension occurs within marker parameters.  Other side effects
195
 * require more care.
196
 */
197
198
199
LOCAL(boolean)
200
get_soi(j_decompress_ptr cinfo)
201
/* Process an SOI marker */
202
104k
{
203
104k
  int i;
204
205
104k
  TRACEMS(cinfo, 1, JTRC_SOI);
206
207
104k
  if (cinfo->marker->saw_SOI)
208
1.18k
    ERREXIT(cinfo, JERR_SOI_DUPLICATE);
209
210
  /* Reset all parameters that are defined to be reset by SOI */
211
212
1.75M
  for (i = 0; i < NUM_ARITH_TBLS; i++) {
213
1.65M
    cinfo->arith_dc_L[i] = 0;
214
1.65M
    cinfo->arith_dc_U[i] = 1;
215
1.65M
    cinfo->arith_ac_K[i] = 5;
216
1.65M
  }
217
104k
  cinfo->restart_interval = 0;
218
219
  /* Set initial assumptions for colorspace etc */
220
221
104k
  cinfo->jpeg_color_space = JCS_UNKNOWN;
222
104k
  cinfo->CCIR601_sampling = FALSE; /* Assume non-CCIR sampling??? */
223
224
104k
  cinfo->saw_JFIF_marker = FALSE;
225
104k
  cinfo->JFIF_major_version = 1; /* set default JFIF APP0 values */
226
104k
  cinfo->JFIF_minor_version = 1;
227
104k
  cinfo->density_unit = 0;
228
104k
  cinfo->X_density = 1;
229
104k
  cinfo->Y_density = 1;
230
104k
  cinfo->saw_Adobe_marker = FALSE;
231
104k
  cinfo->Adobe_transform = 0;
232
233
104k
  cinfo->marker->saw_SOI = TRUE;
234
235
104k
  return TRUE;
236
104k
}
237
238
239
LOCAL(boolean)
240
get_sof(j_decompress_ptr cinfo, boolean is_prog, boolean is_arith)
241
/* Process a SOFn marker */
242
94.1k
{
243
94.1k
  JLONG length;
244
94.1k
  int c, ci;
245
94.1k
  jpeg_component_info *compptr;
246
94.1k
  INPUT_VARS(cinfo);
247
248
94.1k
  cinfo->progressive_mode = is_prog;
249
94.1k
  cinfo->arith_code = is_arith;
250
251
94.1k
  INPUT_2BYTES(cinfo, length, return FALSE);
252
253
94.1k
  INPUT_BYTE(cinfo, cinfo->data_precision, return FALSE);
254
94.1k
  INPUT_2BYTES(cinfo, cinfo->image_height, return FALSE);
255
94.1k
  INPUT_2BYTES(cinfo, cinfo->image_width, return FALSE);
256
94.1k
  INPUT_BYTE(cinfo, cinfo->num_components, return FALSE);
257
258
94.1k
  length -= 8;
259
260
94.1k
  TRACEMS4(cinfo, 1, JTRC_SOF, cinfo->unread_marker,
261
94.1k
           (int)cinfo->image_width, (int)cinfo->image_height,
262
94.1k
           cinfo->num_components);
263
264
94.1k
  if (cinfo->marker->saw_SOF)
265
714
    ERREXIT(cinfo, JERR_SOF_DUPLICATE);
266
267
  /* We don't support files in which the image height is initially specified */
268
  /* as 0 and is later redefined by DNL.  As long as we have to check that,  */
269
  /* might as well have a general sanity check. */
270
94.1k
  if (cinfo->image_height <= 0 || cinfo->image_width <= 0 ||
271
94.1k
      cinfo->num_components <= 0)
272
62
    ERREXIT(cinfo, JERR_EMPTY_IMAGE);
273
274
94.1k
  if (length != (cinfo->num_components * 3))
275
670
    ERREXIT(cinfo, JERR_BAD_LENGTH);
276
277
94.1k
  if (cinfo->comp_info == NULL) /* do only once, even if suspend */
278
92.7k
    cinfo->comp_info = (jpeg_component_info *)(*cinfo->mem->alloc_small)
279
92.7k
                        ((j_common_ptr)cinfo, JPOOL_IMAGE,
280
92.7k
                         cinfo->num_components * sizeof(jpeg_component_info));
281
282
294k
  for (ci = 0, compptr = cinfo->comp_info; ci < cinfo->num_components;
283
200k
       ci++, compptr++) {
284
200k
    compptr->component_index = ci;
285
200k
    INPUT_BYTE(cinfo, compptr->component_id, return FALSE);
286
200k
    INPUT_BYTE(cinfo, c, return FALSE);
287
200k
    compptr->h_samp_factor = (c >> 4) & 15;
288
200k
    compptr->v_samp_factor = (c     ) & 15;
289
200k
    INPUT_BYTE(cinfo, compptr->quant_tbl_no, return FALSE);
290
291
200k
    TRACEMS4(cinfo, 1, JTRC_SOF_COMPONENT,
292
200k
             compptr->component_id, compptr->h_samp_factor,
293
200k
             compptr->v_samp_factor, compptr->quant_tbl_no);
294
200k
  }
295
296
94.1k
  cinfo->marker->saw_SOF = TRUE;
297
298
94.1k
  INPUT_SYNC(cinfo);
299
94.1k
  return TRUE;
300
94.1k
}
301
302
303
LOCAL(boolean)
304
get_sos(j_decompress_ptr cinfo)
305
/* Process a SOS marker */
306
297k
{
307
297k
  JLONG length;
308
297k
  int i, ci, n, c, cc, pi;
309
297k
  jpeg_component_info *compptr;
310
297k
  INPUT_VARS(cinfo);
311
312
297k
  if (!cinfo->marker->saw_SOF)
313
134
    ERREXIT(cinfo, JERR_SOS_NO_SOF);
314
315
297k
  INPUT_2BYTES(cinfo, length, return FALSE);
316
317
297k
  INPUT_BYTE(cinfo, n, return FALSE); /* Number of components */
318
319
297k
  TRACEMS1(cinfo, 1, JTRC_SOS, n);
320
321
297k
  if (length != (n * 2 + 6) || n < 1 || n > MAX_COMPS_IN_SCAN)
322
1.03k
    ERREXIT(cinfo, JERR_BAD_LENGTH);
323
324
297k
  cinfo->comps_in_scan = n;
325
326
  /* Collect the component-spec parameters */
327
328
1.48M
  for (i = 0; i < MAX_COMPS_IN_SCAN; i++)
329
1.18M
    cinfo->cur_comp_info[i] = NULL;
330
331
711k
  for (i = 0; i < n; i++) {
332
414k
    INPUT_BYTE(cinfo, cc, return FALSE);
333
414k
    INPUT_BYTE(cinfo, c, return FALSE);
334
335
414k
    for (ci = 0, compptr = cinfo->comp_info;
336
710k
         ci < cinfo->num_components && ci < MAX_COMPS_IN_SCAN;
337
710k
         ci++, compptr++) {
338
710k
      if (cc == compptr->component_id && !cinfo->cur_comp_info[ci])
339
413k
        goto id_found;
340
710k
    }
341
342
788
    ERREXIT1(cinfo, JERR_BAD_COMPONENT_ID, cc);
343
344
413k
id_found:
345
346
413k
    cinfo->cur_comp_info[i] = compptr;
347
413k
    compptr->dc_tbl_no = (c >> 4) & 15;
348
413k
    compptr->ac_tbl_no = (c     ) & 15;
349
350
413k
    TRACEMS3(cinfo, 1, JTRC_SOS_COMPONENT, cc,
351
413k
             compptr->dc_tbl_no, compptr->ac_tbl_no);
352
353
    /* This CSi (cc) should differ from the previous CSi */
354
584k
    for (pi = 0; pi < i; pi++) {
355
170k
      if (cinfo->cur_comp_info[pi] == compptr) {
356
33
        ERREXIT1(cinfo, JERR_BAD_COMPONENT_ID, cc);
357
33
      }
358
170k
    }
359
413k
  }
360
361
  /* Collect the additional scan parameters Ss, Se, Ah/Al. */
362
297k
  INPUT_BYTE(cinfo, c, return FALSE);
363
297k
  cinfo->Ss = c;
364
297k
  INPUT_BYTE(cinfo, c, return FALSE);
365
297k
  cinfo->Se = c;
366
297k
  INPUT_BYTE(cinfo, c, return FALSE);
367
297k
  cinfo->Ah = (c >> 4) & 15;
368
297k
  cinfo->Al = (c     ) & 15;
369
370
297k
  TRACEMS4(cinfo, 1, JTRC_SOS_PARAMS, cinfo->Ss, cinfo->Se,
371
297k
           cinfo->Ah, cinfo->Al);
372
373
  /* Prepare to scan data & restart markers */
374
297k
  cinfo->marker->next_restart_num = 0;
375
376
  /* Count another SOS marker */
377
297k
  cinfo->input_scan_number++;
378
379
297k
  INPUT_SYNC(cinfo);
380
297k
  return TRUE;
381
297k
}
382
383
384
#ifdef D_ARITH_CODING_SUPPORTED
385
386
LOCAL(boolean)
387
get_dac(j_decompress_ptr cinfo)
388
/* Process a DAC marker */
389
6.79k
{
390
6.79k
  JLONG length;
391
6.79k
  int index, val;
392
6.79k
  INPUT_VARS(cinfo);
393
394
6.79k
  INPUT_2BYTES(cinfo, length, return FALSE);
395
6.79k
  length -= 2;
396
397
34.8k
  while (length > 0) {
398
28.0k
    INPUT_BYTE(cinfo, index, return FALSE);
399
28.0k
    INPUT_BYTE(cinfo, val, return FALSE);
400
401
28.0k
    length -= 2;
402
403
28.0k
    TRACEMS2(cinfo, 1, JTRC_DAC, index, val);
404
405
28.0k
    if (index < 0 || index >= (2 * NUM_ARITH_TBLS))
406
843
      ERREXIT1(cinfo, JERR_DAC_INDEX, index);
407
408
28.0k
    if (index >= NUM_ARITH_TBLS) { /* define AC table */
409
4.37k
      cinfo->arith_ac_K[index - NUM_ARITH_TBLS] = (UINT8)val;
410
23.7k
    } else {                    /* define DC table */
411
23.7k
      cinfo->arith_dc_L[index] = (UINT8)(val & 0x0F);
412
23.7k
      cinfo->arith_dc_U[index] = (UINT8)(val >> 4);
413
23.7k
      if (cinfo->arith_dc_L[index] > cinfo->arith_dc_U[index])
414
142
        ERREXIT1(cinfo, JERR_DAC_VALUE, val);
415
23.7k
    }
416
28.0k
  }
417
418
6.79k
  if (length != 0)
419
43
    ERREXIT(cinfo, JERR_BAD_LENGTH);
420
421
6.79k
  INPUT_SYNC(cinfo);
422
6.79k
  return TRUE;
423
6.79k
}
424
425
#else /* !D_ARITH_CODING_SUPPORTED */
426
427
#define get_dac(cinfo)  skip_variable(cinfo)
428
429
#endif /* D_ARITH_CODING_SUPPORTED */
430
431
432
LOCAL(boolean)
433
get_dht(j_decompress_ptr cinfo)
434
/* Process a DHT marker */
435
96.6k
{
436
96.6k
  JLONG length;
437
96.6k
  UINT8 bits[17];
438
96.6k
  UINT8 huffval[256];
439
96.6k
  int i, index, count;
440
96.6k
  JHUFF_TBL **htblptr;
441
96.6k
  INPUT_VARS(cinfo);
442
443
96.6k
  INPUT_2BYTES(cinfo, length, return FALSE);
444
96.6k
  length -= 2;
445
446
208k
  while (length > 16) {
447
111k
    INPUT_BYTE(cinfo, index, return FALSE);
448
449
111k
    TRACEMS1(cinfo, 1, JTRC_DHT, index);
450
451
111k
    bits[0] = 0;
452
111k
    count = 0;
453
1.89M
    for (i = 1; i <= 16; i++) {
454
1.78M
      INPUT_BYTE(cinfo, bits[i], return FALSE);
455
1.78M
      count += bits[i];
456
1.78M
    }
457
458
111k
    length -= 1 + 16;
459
460
111k
    TRACEMS8(cinfo, 2, JTRC_HUFFBITS,
461
111k
             bits[1], bits[2], bits[3], bits[4],
462
111k
             bits[5], bits[6], bits[7], bits[8]);
463
111k
    TRACEMS8(cinfo, 2, JTRC_HUFFBITS,
464
111k
             bits[9], bits[10], bits[11], bits[12],
465
111k
             bits[13], bits[14], bits[15], bits[16]);
466
467
    /* Here we just do minimal validation of the counts to avoid walking
468
     * off the end of our table space.  jdhuff.c will check more carefully.
469
     */
470
111k
    if (count > 256 || ((JLONG)count) > length)
471
2.00k
      ERREXIT(cinfo, JERR_BAD_HUFF_TABLE);
472
473
1.25M
    for (i = 0; i < count; i++)
474
1.13M
      INPUT_BYTE(cinfo, huffval[i], return FALSE);
475
476
111k
    MEMZERO(&huffval[count], (256 - count) * sizeof(UINT8));
477
478
111k
    length -= count;
479
480
111k
    if (index & 0x10) {         /* AC table definition */
481
61.3k
      index -= 0x10;
482
61.3k
      if (index < 0 || index >= NUM_HUFF_TBLS)
483
133
        ERREXIT1(cinfo, JERR_DHT_INDEX, index);
484
61.3k
      htblptr = &cinfo->ac_huff_tbl_ptrs[index];
485
61.3k
    } else {                    /* DC table definition */
486
50.1k
      if (index < 0 || index >= NUM_HUFF_TBLS)
487
161
        ERREXIT1(cinfo, JERR_DHT_INDEX, index);
488
50.1k
      htblptr = &cinfo->dc_huff_tbl_ptrs[index];
489
50.1k
    }
490
491
111k
    if (*htblptr == NULL)
492
15.7k
      *htblptr = jpeg_alloc_huff_table((j_common_ptr)cinfo);
493
494
111k
    MEMCOPY((*htblptr)->bits, bits, sizeof((*htblptr)->bits));
495
111k
    MEMCOPY((*htblptr)->huffval, huffval, sizeof((*htblptr)->huffval));
496
111k
  }
497
498
96.6k
  if (length != 0)
499
263
    ERREXIT(cinfo, JERR_BAD_LENGTH);
500
501
96.6k
  INPUT_SYNC(cinfo);
502
96.6k
  return TRUE;
503
96.6k
}
504
505
506
LOCAL(boolean)
507
get_dqt(j_decompress_ptr cinfo)
508
/* Process a DQT marker */
509
100k
{
510
100k
  JLONG length;
511
100k
  int n, i, prec;
512
100k
  unsigned int tmp;
513
100k
  JQUANT_TBL *quant_ptr;
514
100k
  INPUT_VARS(cinfo);
515
516
100k
  INPUT_2BYTES(cinfo, length, return FALSE);
517
100k
  length -= 2;
518
519
208k
  while (length > 0) {
520
107k
    INPUT_BYTE(cinfo, n, return FALSE);
521
107k
    prec = n >> 4;
522
107k
    n &= 0x0F;
523
524
107k
    TRACEMS2(cinfo, 1, JTRC_DQT, n, prec);
525
526
107k
    if (n >= NUM_QUANT_TBLS)
527
858
      ERREXIT1(cinfo, JERR_DQT_INDEX, n);
528
529
107k
    if (cinfo->quant_tbl_ptrs[n] == NULL)
530
34.5k
      cinfo->quant_tbl_ptrs[n] = jpeg_alloc_quant_table((j_common_ptr)cinfo);
531
107k
    quant_ptr = cinfo->quant_tbl_ptrs[n];
532
533
6.95M
    for (i = 0; i < DCTSIZE2; i++) {
534
6.84M
      if (prec)
535
6.84M
        INPUT_2BYTES(cinfo, tmp, return FALSE);
536
6.49M
      else
537
6.84M
        INPUT_BYTE(cinfo, tmp, return FALSE);
538
      /* We convert the zigzag-order table to natural array order. */
539
6.84M
      quant_ptr->quantval[jpeg_natural_order[i]] = (UINT16)tmp;
540
6.84M
    }
541
542
107k
    if (cinfo->err->trace_level >= 2) {
543
0
      for (i = 0; i < DCTSIZE2; i += 8) {
544
0
        TRACEMS8(cinfo, 2, JTRC_QUANTVALS,
545
0
                 quant_ptr->quantval[i],     quant_ptr->quantval[i + 1],
546
0
                 quant_ptr->quantval[i + 2], quant_ptr->quantval[i + 3],
547
0
                 quant_ptr->quantval[i + 4], quant_ptr->quantval[i + 5],
548
0
                 quant_ptr->quantval[i + 6], quant_ptr->quantval[i + 7]);
549
0
      }
550
0
    }
551
552
107k
    length -= DCTSIZE2 + 1;
553
107k
    if (prec) length -= DCTSIZE2;
554
107k
  }
555
556
100k
  if (length != 0)
557
348
    ERREXIT(cinfo, JERR_BAD_LENGTH);
558
559
100k
  INPUT_SYNC(cinfo);
560
100k
  return TRUE;
561
100k
}
562
563
564
LOCAL(boolean)
565
get_dri(j_decompress_ptr cinfo)
566
/* Process a DRI marker */
567
251k
{
568
251k
  JLONG length;
569
251k
  unsigned int tmp;
570
251k
  INPUT_VARS(cinfo);
571
572
251k
  INPUT_2BYTES(cinfo, length, return FALSE);
573
574
251k
  if (length != 4)
575
290
    ERREXIT(cinfo, JERR_BAD_LENGTH);
576
577
251k
  INPUT_2BYTES(cinfo, tmp, return FALSE);
578
579
251k
  TRACEMS1(cinfo, 1, JTRC_DRI, tmp);
580
581
251k
  cinfo->restart_interval = tmp;
582
583
251k
  INPUT_SYNC(cinfo);
584
251k
  return TRUE;
585
251k
}
586
587
588
/*
589
 * Routines for processing APPn and COM markers.
590
 * These are either saved in memory or discarded, per application request.
591
 * APP0 and APP14 are specially checked to see if they are
592
 * JFIF and Adobe markers, respectively.
593
 */
594
595
1.93M
#define APP0_DATA_LEN   14      /* Length of interesting data in APP0 */
596
1.05M
#define APP14_DATA_LEN  12      /* Length of interesting data in APP14 */
597
1.66M
#define APPN_DATA_LEN   14      /* Must be the largest of the above!! */
598
599
600
LOCAL(void)
601
examine_app0(j_decompress_ptr cinfo, JOCTET *data, unsigned int datalen,
602
             JLONG remaining)
603
/* Examine first few bytes from an APP0.
604
 * Take appropriate action if it is a JFIF marker.
605
 * datalen is # of bytes at data[], remaining is length of rest of marker data.
606
 */
607
956k
{
608
956k
  JLONG totallen = (JLONG)datalen + remaining;
609
610
956k
  if (datalen >= APP0_DATA_LEN &&
611
956k
      GETJOCTET(data[0]) == 0x4A &&
612
956k
      GETJOCTET(data[1]) == 0x46 &&
613
956k
      GETJOCTET(data[2]) == 0x49 &&
614
956k
      GETJOCTET(data[3]) == 0x46 &&
615
956k
      GETJOCTET(data[4]) == 0) {
616
    /* Found JFIF APP0 marker: save info */
617
13.7k
    cinfo->saw_JFIF_marker = TRUE;
618
13.7k
    cinfo->JFIF_major_version = GETJOCTET(data[5]);
619
13.7k
    cinfo->JFIF_minor_version = GETJOCTET(data[6]);
620
13.7k
    cinfo->density_unit = GETJOCTET(data[7]);
621
13.7k
    cinfo->X_density = (GETJOCTET(data[8]) << 8) + GETJOCTET(data[9]);
622
13.7k
    cinfo->Y_density = (GETJOCTET(data[10]) << 8) + GETJOCTET(data[11]);
623
    /* Check version.
624
     * Major version must be 1, anything else signals an incompatible change.
625
     * (We used to treat this as an error, but now it's a nonfatal warning,
626
     * because some bozo at Hijaak couldn't read the spec.)
627
     * Minor version should be 0..2, but process anyway if newer.
628
     */
629
13.7k
    if (cinfo->JFIF_major_version != 1)
630
7.30k
      WARNMS2(cinfo, JWRN_JFIF_MAJOR,
631
13.7k
              cinfo->JFIF_major_version, cinfo->JFIF_minor_version);
632
    /* Generate trace messages */
633
13.7k
    TRACEMS5(cinfo, 1, JTRC_JFIF,
634
13.7k
             cinfo->JFIF_major_version, cinfo->JFIF_minor_version,
635
13.7k
             cinfo->X_density, cinfo->Y_density, cinfo->density_unit);
636
    /* Validate thumbnail dimensions and issue appropriate messages */
637
13.7k
    if (GETJOCTET(data[12]) | GETJOCTET(data[13]))
638
8.25k
      TRACEMS2(cinfo, 1, JTRC_JFIF_THUMBNAIL,
639
13.7k
               GETJOCTET(data[12]), GETJOCTET(data[13]));
640
13.7k
    totallen -= APP0_DATA_LEN;
641
13.7k
    if (totallen !=
642
13.7k
        ((JLONG)GETJOCTET(data[12]) * (JLONG)GETJOCTET(data[13]) * (JLONG)3))
643
5.29k
      TRACEMS1(cinfo, 1, JTRC_JFIF_BADTHUMBNAILSIZE, (int)totallen);
644
942k
  } else if (datalen >= 6 &&
645
942k
             GETJOCTET(data[0]) == 0x4A &&
646
942k
             GETJOCTET(data[1]) == 0x46 &&
647
942k
             GETJOCTET(data[2]) == 0x58 &&
648
942k
             GETJOCTET(data[3]) == 0x58 &&
649
942k
             GETJOCTET(data[4]) == 0) {
650
    /* Found JFIF "JFXX" extension APP0 marker */
651
    /* The library doesn't actually do anything with these,
652
     * but we try to produce a helpful trace message.
653
     */
654
209k
    switch (GETJOCTET(data[5])) {
655
2.46k
    case 0x10:
656
2.46k
      TRACEMS1(cinfo, 1, JTRC_THUMB_JPEG, (int)totallen);
657
2.46k
      break;
658
2.26k
    case 0x11:
659
2.26k
      TRACEMS1(cinfo, 1, JTRC_THUMB_PALETTE, (int)totallen);
660
2.26k
      break;
661
2.14k
    case 0x13:
662
2.14k
      TRACEMS1(cinfo, 1, JTRC_THUMB_RGB, (int)totallen);
663
2.14k
      break;
664
202k
    default:
665
202k
      TRACEMS2(cinfo, 1, JTRC_JFIF_EXTENSION,
666
202k
               GETJOCTET(data[5]), (int)totallen);
667
202k
      break;
668
209k
    }
669
732k
  } else {
670
    /* Start of APP0 does not match "JFIF" or "JFXX", or too short */
671
732k
    TRACEMS1(cinfo, 1, JTRC_APP0, (int)totallen);
672
732k
  }
673
956k
}
674
675
676
LOCAL(void)
677
examine_app14(j_decompress_ptr cinfo, JOCTET *data, unsigned int datalen,
678
              JLONG remaining)
679
/* Examine first few bytes from an APP14.
680
 * Take appropriate action if it is an Adobe marker.
681
 * datalen is # of bytes at data[], remaining is length of rest of marker data.
682
 */
683
522k
{
684
522k
  unsigned int version, flags0, flags1, transform;
685
686
522k
  if (datalen >= APP14_DATA_LEN &&
687
522k
      GETJOCTET(data[0]) == 0x41 &&
688
522k
      GETJOCTET(data[1]) == 0x64 &&
689
522k
      GETJOCTET(data[2]) == 0x6F &&
690
522k
      GETJOCTET(data[3]) == 0x62 &&
691
522k
      GETJOCTET(data[4]) == 0x65) {
692
    /* Found Adobe APP14 marker */
693
334k
    version = (GETJOCTET(data[5]) << 8) + GETJOCTET(data[6]);
694
334k
    flags0 = (GETJOCTET(data[7]) << 8) + GETJOCTET(data[8]);
695
334k
    flags1 = (GETJOCTET(data[9]) << 8) + GETJOCTET(data[10]);
696
334k
    transform = GETJOCTET(data[11]);
697
334k
    TRACEMS4(cinfo, 1, JTRC_ADOBE, version, flags0, flags1, transform);
698
334k
    cinfo->saw_Adobe_marker = TRUE;
699
334k
    cinfo->Adobe_transform = (UINT8)transform;
700
334k
  } else {
701
    /* Start of APP14 does not match "Adobe", or too short */
702
188k
    TRACEMS1(cinfo, 1, JTRC_APP14, (int)(datalen + remaining));
703
188k
  }
704
522k
}
705
706
707
METHODDEF(boolean)
708
get_interesting_appn(j_decompress_ptr cinfo)
709
/* Process an APP0 or APP14 marker without saving it */
710
848k
{
711
848k
  JLONG length;
712
848k
  JOCTET b[APPN_DATA_LEN];
713
848k
  unsigned int i, numtoread;
714
848k
  INPUT_VARS(cinfo);
715
716
848k
  INPUT_2BYTES(cinfo, length, return FALSE);
717
848k
  length -= 2;
718
719
  /* get the interesting part of the marker data */
720
848k
  if (length >= APPN_DATA_LEN)
721
818k
    numtoread = APPN_DATA_LEN;
722
30.4k
  else if (length > 0)
723
18.5k
    numtoread = (unsigned int)length;
724
11.8k
  else
725
11.8k
    numtoread = 0;
726
12.4M
  for (i = 0; i < numtoread; i++)
727
11.5M
    INPUT_BYTE(cinfo, b[i], return FALSE);
728
848k
  length -= numtoread;
729
730
  /* process it */
731
848k
  switch (cinfo->unread_marker) {
732
523k
  case M_APP0:
733
523k
    examine_app0(cinfo, (JOCTET *)b, numtoread, length);
734
523k
    break;
735
325k
  case M_APP14:
736
325k
    examine_app14(cinfo, (JOCTET *)b, numtoread, length);
737
325k
    break;
738
0
  default:
739
    /* can't get here unless jpeg_save_markers chooses wrong processor */
740
0
    ERREXIT1(cinfo, JERR_UNKNOWN_MARKER, cinfo->unread_marker);
741
0
    break;
742
848k
  }
743
744
  /* skip any remaining data -- could be lots */
745
848k
  INPUT_SYNC(cinfo);
746
848k
  if (length > 0)
747
41.7k
    (*cinfo->src->skip_input_data) (cinfo, (long)length);
748
749
848k
  return TRUE;
750
848k
}
751
752
753
#ifdef SAVE_MARKERS_SUPPORTED
754
755
METHODDEF(boolean)
756
save_marker(j_decompress_ptr cinfo)
757
/* Save an APPn or COM marker into the marker list */
758
653k
{
759
653k
  my_marker_ptr marker = (my_marker_ptr)cinfo->marker;
760
653k
  jpeg_saved_marker_ptr cur_marker = marker->cur_marker;
761
653k
  unsigned int bytes_read, data_length;
762
653k
  JOCTET *data;
763
653k
  JLONG length = 0;
764
653k
  INPUT_VARS(cinfo);
765
766
653k
  if (cur_marker == NULL) {
767
    /* begin reading a marker */
768
653k
    INPUT_2BYTES(cinfo, length, return FALSE);
769
653k
    length -= 2;
770
653k
    if (length >= 0) {          /* watch out for bogus length word */
771
      /* figure out how much we want to save */
772
646k
      unsigned int limit;
773
646k
      if (cinfo->unread_marker == (int)M_COM)
774
1.17k
        limit = marker->length_limit_COM;
775
645k
      else
776
645k
        limit = marker->length_limit_APPn[cinfo->unread_marker - (int)M_APP0];
777
646k
      if ((unsigned int)length < limit)
778
646k
        limit = (unsigned int)length;
779
      /* allocate and initialize the marker item */
780
646k
      cur_marker = (jpeg_saved_marker_ptr)
781
646k
        (*cinfo->mem->alloc_large) ((j_common_ptr)cinfo, JPOOL_IMAGE,
782
646k
                                    sizeof(struct jpeg_marker_struct) + limit);
783
646k
      cur_marker->next = NULL;
784
646k
      cur_marker->marker = (UINT8)cinfo->unread_marker;
785
646k
      cur_marker->original_length = (unsigned int)length;
786
646k
      cur_marker->data_length = limit;
787
      /* data area is just beyond the jpeg_marker_struct */
788
646k
      data = cur_marker->data = (JOCTET *)(cur_marker + 1);
789
646k
      marker->cur_marker = cur_marker;
790
646k
      marker->bytes_read = 0;
791
646k
      bytes_read = 0;
792
646k
      data_length = limit;
793
646k
    } else {
794
      /* deal with bogus length word */
795
7.48k
      bytes_read = data_length = 0;
796
7.48k
      data = NULL;
797
7.48k
    }
798
653k
  } else {
799
    /* resume reading a marker */
800
0
    bytes_read = marker->bytes_read;
801
0
    data_length = cur_marker->data_length;
802
0
    data = cur_marker->data + bytes_read;
803
0
  }
804
805
14.9M
  while (bytes_read < data_length) {
806
14.2M
    INPUT_SYNC(cinfo);          /* move the restart point to here */
807
14.2M
    marker->bytes_read = bytes_read;
808
    /* If there's not at least one byte in buffer, suspend */
809
14.2M
    MAKE_BYTE_AVAIL(cinfo, return FALSE);
810
    /* Copy bytes with reasonable rapidity */
811
82.7M
    while (bytes_read < data_length && bytes_in_buffer > 0) {
812
68.4M
      *data++ = *next_input_byte++;
813
68.4M
      bytes_in_buffer--;
814
68.4M
      bytes_read++;
815
68.4M
    }
816
14.2M
  }
817
818
  /* Done reading what we want to read */
819
653k
  if (cur_marker != NULL) {     /* will be NULL if bogus length word */
820
    /* Add new marker to end of list */
821
646k
    if (cinfo->marker_list == NULL) {
822
2.97k
      cinfo->marker_list = cur_marker;
823
643k
    } else {
824
643k
      jpeg_saved_marker_ptr prev = cinfo->marker_list;
825
3.75G
      while (prev->next != NULL)
826
3.75G
        prev = prev->next;
827
643k
      prev->next = cur_marker;
828
643k
    }
829
    /* Reset pointer & calc remaining data length */
830
646k
    data = cur_marker->data;
831
646k
    length = cur_marker->original_length - data_length;
832
646k
  }
833
  /* Reset to initial state for next marker */
834
653k
  marker->cur_marker = NULL;
835
836
  /* Process the marker if interesting; else just make a generic trace msg */
837
653k
  switch (cinfo->unread_marker) {
838
433k
  case M_APP0:
839
433k
    examine_app0(cinfo, data, data_length, length);
840
433k
    break;
841
197k
  case M_APP14:
842
197k
    examine_app14(cinfo, data, data_length, length);
843
197k
    break;
844
23.3k
  default:
845
23.3k
    TRACEMS2(cinfo, 1, JTRC_MISC_MARKER, cinfo->unread_marker,
846
23.3k
             (int)(data_length + length));
847
23.3k
    break;
848
653k
  }
849
850
  /* skip any remaining data -- could be lots */
851
653k
  INPUT_SYNC(cinfo);            /* do before skip_input_data */
852
653k
  if (length > 0)
853
0
    (*cinfo->src->skip_input_data) (cinfo, (long)length);
854
855
653k
  return TRUE;
856
653k
}
857
858
#endif /* SAVE_MARKERS_SUPPORTED */
859
860
861
METHODDEF(boolean)
862
skip_variable(j_decompress_ptr cinfo)
863
/* Skip over an unknown or uninteresting variable-length marker */
864
185k
{
865
185k
  JLONG length;
866
185k
  INPUT_VARS(cinfo);
867
868
185k
  INPUT_2BYTES(cinfo, length, return FALSE);
869
185k
  length -= 2;
870
871
185k
  TRACEMS2(cinfo, 1, JTRC_MISC_MARKER, cinfo->unread_marker, (int)length);
872
873
185k
  INPUT_SYNC(cinfo);            /* do before skip_input_data */
874
185k
  if (length > 0)
875
131k
    (*cinfo->src->skip_input_data) (cinfo, (long)length);
876
877
185k
  return TRUE;
878
185k
}
879
880
881
/*
882
 * Find the next JPEG marker, save it in cinfo->unread_marker.
883
 * Returns FALSE if had to suspend before reaching a marker;
884
 * in that case cinfo->unread_marker is unchanged.
885
 *
886
 * Note that the result might not be a valid marker code,
887
 * but it will never be 0 or FF.
888
 */
889
890
LOCAL(boolean)
891
next_marker(j_decompress_ptr cinfo)
892
2.45M
{
893
2.45M
  int c;
894
2.45M
  INPUT_VARS(cinfo);
895
896
3.00M
  for (;;) {
897
3.00M
    INPUT_BYTE(cinfo, c, return FALSE);
898
    /* Skip any non-FF bytes.
899
     * This may look a bit inefficient, but it will not occur in a valid file.
900
     * We sync after each discarded byte so that a suspending data source
901
     * can discard the byte from its buffer.
902
     */
903
47.9M
    while (c != 0xFF) {
904
44.9M
      cinfo->marker->discarded_bytes++;
905
44.9M
      INPUT_SYNC(cinfo);
906
44.9M
      INPUT_BYTE(cinfo, c, return FALSE);
907
44.9M
    }
908
    /* This loop swallows any duplicate FF bytes.  Extra FFs are legal as
909
     * pad bytes, so don't count them in discarded_bytes.  We assume there
910
     * will not be so many consecutive FF bytes as to overflow a suspending
911
     * data source's input buffer.
912
     */
913
3.41M
    do {
914
3.41M
      INPUT_BYTE(cinfo, c, return FALSE);
915
3.41M
    } while (c == 0xFF);
916
3.00M
    if (c != 0)
917
2.45M
      break;                    /* found a valid marker, exit loop */
918
    /* Reach here if we found a stuffed-zero data sequence (FF/00).
919
     * Discard it and loop back to try again.
920
     */
921
549k
    cinfo->marker->discarded_bytes += 2;
922
549k
    INPUT_SYNC(cinfo);
923
549k
  }
924
925
2.45M
  if (cinfo->marker->discarded_bytes != 0) {
926
1.59M
    WARNMS2(cinfo, JWRN_EXTRANEOUS_DATA, cinfo->marker->discarded_bytes, c);
927
1.59M
    cinfo->marker->discarded_bytes = 0;
928
1.59M
  }
929
930
2.45M
  cinfo->unread_marker = c;
931
932
2.45M
  INPUT_SYNC(cinfo);
933
2.45M
  return TRUE;
934
2.45M
}
935
936
937
LOCAL(boolean)
938
first_marker(j_decompress_ptr cinfo)
939
/* Like next_marker, but used to obtain the initial SOI marker. */
940
/* For this marker, we do not allow preceding garbage or fill; otherwise,
941
 * we might well scan an entire input file before realizing it ain't JPEG.
942
 * If an application wants to process non-JFIF files, it must seek to the
943
 * SOI before calling the JPEG library.
944
 */
945
103k
{
946
103k
  int c, c2;
947
103k
  INPUT_VARS(cinfo);
948
949
103k
  INPUT_BYTE(cinfo, c, return FALSE);
950
103k
  INPUT_BYTE(cinfo, c2, return FALSE);
951
103k
  if (c != 0xFF || c2 != (int)M_SOI)
952
232
    ERREXIT2(cinfo, JERR_NO_SOI, c, c2);
953
954
103k
  cinfo->unread_marker = c2;
955
956
103k
  INPUT_SYNC(cinfo);
957
103k
  return TRUE;
958
103k
}
959
960
961
/*
962
 * Read markers until SOS or EOI.
963
 *
964
 * Returns same codes as are defined for jpeg_consume_input:
965
 * JPEG_SUSPENDED, JPEG_REACHED_SOS, or JPEG_REACHED_EOI.
966
 */
967
968
METHODDEF(int)
969
read_markers(j_decompress_ptr cinfo)
970
228k
{
971
  /* Outer loop repeats once for each marker. */
972
1.70M
  for (;;) {
973
    /* Collect the marker proper, unless we already did. */
974
    /* NB: first_marker() enforces the requirement that SOI appear first. */
975
1.70M
    if (cinfo->unread_marker == 0) {
976
1.54M
      if (!cinfo->marker->saw_SOI) {
977
65.0k
        if (!first_marker(cinfo))
978
0
          return JPEG_SUSPENDED;
979
1.48M
      } else {
980
1.48M
        if (!next_marker(cinfo))
981
0
          return JPEG_SUSPENDED;
982
1.48M
      }
983
1.54M
    }
984
    /* At this point cinfo->unread_marker contains the marker code and the
985
     * input point is just past the marker proper, but before any parameters.
986
     * A suspension will cause us to return with this state still true.
987
     */
988
1.70M
    switch (cinfo->unread_marker) {
989
65.8k
    case M_SOI:
990
65.8k
      if (!get_soi(cinfo))
991
0
        return JPEG_SUSPENDED;
992
65.8k
      break;
993
994
65.8k
    case M_SOF0:                /* Baseline */
995
18.6k
    case M_SOF1:                /* Extended sequential, Huffman */
996
18.6k
      if (!get_sof(cinfo, FALSE, FALSE))
997
0
        return JPEG_SUSPENDED;
998
18.6k
      break;
999
1000
18.6k
    case M_SOF2:                /* Progressive, Huffman */
1001
13.1k
      if (!get_sof(cinfo, TRUE, FALSE))
1002
0
        return JPEG_SUSPENDED;
1003
13.1k
      break;
1004
1005
13.1k
    case M_SOF9:                /* Extended sequential, arithmetic */
1006
8.44k
      if (!get_sof(cinfo, FALSE, TRUE))
1007
0
        return JPEG_SUSPENDED;
1008
8.44k
      break;
1009
1010
18.8k
    case M_SOF10:               /* Progressive, arithmetic */
1011
18.8k
      if (!get_sof(cinfo, TRUE, TRUE))
1012
0
        return JPEG_SUSPENDED;
1013
18.8k
      break;
1014
1015
    /* Currently unsupported SOFn types */
1016
18.8k
    case M_SOF3:                /* Lossless, Huffman */
1017
48
    case M_SOF5:                /* Differential sequential, Huffman */
1018
63
    case M_SOF6:                /* Differential progressive, Huffman */
1019
83
    case M_SOF7:                /* Differential lossless, Huffman */
1020
104
    case M_JPG:                 /* Reserved for JPEG extensions */
1021
172
    case M_SOF11:               /* Lossless, arithmetic */
1022
194
    case M_SOF13:               /* Differential sequential, arithmetic */
1023
208
    case M_SOF14:               /* Differential progressive, arithmetic */
1024
224
    case M_SOF15:               /* Differential lossless, arithmetic */
1025
224
      ERREXIT1(cinfo, JERR_SOF_UNSUPPORTED, cinfo->unread_marker);
1026
224
      break;
1027
1028
197k
    case M_SOS:
1029
197k
      if (!get_sos(cinfo))
1030
0
        return JPEG_SUSPENDED;
1031
197k
      cinfo->unread_marker = 0; /* processed the marker */
1032
197k
      return JPEG_REACHED_SOS;
1033
1034
23.8k
    case M_EOI:
1035
23.8k
      TRACEMS(cinfo, 1, JTRC_EOI);
1036
23.8k
      cinfo->unread_marker = 0; /* processed the marker */
1037
23.8k
      return JPEG_REACHED_EOI;
1038
1039
4.82k
    case M_DAC:
1040
4.82k
      if (!get_dac(cinfo))
1041
0
        return JPEG_SUSPENDED;
1042
4.82k
      break;
1043
1044
75.2k
    case M_DHT:
1045
75.2k
      if (!get_dht(cinfo))
1046
0
        return JPEG_SUSPENDED;
1047
75.2k
      break;
1048
1049
75.2k
    case M_DQT:
1050
69.3k
      if (!get_dqt(cinfo))
1051
0
        return JPEG_SUSPENDED;
1052
69.3k
      break;
1053
1054
204k
    case M_DRI:
1055
204k
      if (!get_dri(cinfo))
1056
0
        return JPEG_SUSPENDED;
1057
204k
      break;
1058
1059
310k
    case M_APP0:
1060
406k
    case M_APP1:
1061
408k
    case M_APP2:
1062
409k
    case M_APP3:
1063
412k
    case M_APP4:
1064
415k
    case M_APP5:
1065
417k
    case M_APP6:
1066
421k
    case M_APP7:
1067
423k
    case M_APP8:
1068
427k
    case M_APP9:
1069
429k
    case M_APP10:
1070
430k
    case M_APP11:
1071
434k
    case M_APP12:
1072
436k
    case M_APP13:
1073
943k
    case M_APP14:
1074
945k
    case M_APP15:
1075
945k
      if (!(*((my_marker_ptr)cinfo->marker)->process_APPn[
1076
945k
               cinfo->unread_marker - (int)M_APP0]) (cinfo))
1077
0
        return JPEG_SUSPENDED;
1078
945k
      break;
1079
1080
945k
    case M_COM:
1081
3.72k
      if (!(*((my_marker_ptr)cinfo->marker)->process_COM) (cinfo))
1082
0
        return JPEG_SUSPENDED;
1083
3.72k
      break;
1084
1085
3.72k
    case M_RST0:                /* these are all parameterless */
1086
28.1k
    case M_RST1:
1087
30.6k
    case M_RST2:
1088
32.4k
    case M_RST3:
1089
36.5k
    case M_RST4:
1090
38.8k
    case M_RST5:
1091
40.9k
    case M_RST6:
1092
47.1k
    case M_RST7:
1093
51.6k
    case M_TEM:
1094
51.6k
      TRACEMS1(cinfo, 1, JTRC_PARMLESS_MARKER, cinfo->unread_marker);
1095
51.6k
      break;
1096
1097
4.11k
    case M_DNL:                 /* Ignore DNL ... perhaps the wrong thing */
1098
4.11k
      if (!skip_variable(cinfo))
1099
0
        return JPEG_SUSPENDED;
1100
4.11k
      break;
1101
1102
4.11k
    default:                    /* must be DHP, EXP, JPGn, or RESn */
1103
      /* For now, we treat the reserved markers as fatal errors since they are
1104
       * likely to be used to signal incompatible JPEG Part 3 extensions.
1105
       * Once the JPEG 3 version-number marker is well defined, this code
1106
       * ought to change!
1107
       */
1108
1.98k
      ERREXIT1(cinfo, JERR_UNKNOWN_MARKER, cinfo->unread_marker);
1109
1.98k
      break;
1110
1.70M
    }
1111
    /* Successfully processed marker, so reset state variable */
1112
1.47M
    cinfo->unread_marker = 0;
1113
1.47M
  } /* end loop */
1114
228k
}
1115
1116
1117
/*
1118
 * Read a restart marker, which is expected to appear next in the datastream;
1119
 * if the marker is not there, take appropriate recovery action.
1120
 * Returns FALSE if suspension is required.
1121
 *
1122
 * This is called by the entropy decoder after it has read an appropriate
1123
 * number of MCUs.  cinfo->unread_marker may be nonzero if the entropy decoder
1124
 * has already read a marker from the data source.  Under normal conditions
1125
 * cinfo->unread_marker will be reset to 0 before returning; if not reset,
1126
 * it holds a marker which the decoder will be unable to read past.
1127
 */
1128
1129
METHODDEF(boolean)
1130
read_restart_marker(j_decompress_ptr cinfo)
1131
170M
{
1132
  /* Obtain a marker unless we already did. */
1133
  /* Note that next_marker will complain if it skips any data. */
1134
170M
  if (cinfo->unread_marker == 0) {
1135
26.3k
    if (!next_marker(cinfo))
1136
0
      return FALSE;
1137
26.3k
  }
1138
1139
170M
  if (cinfo->unread_marker ==
1140
170M
      ((int)M_RST0 + cinfo->marker->next_restart_num)) {
1141
    /* Normal case --- swallow the marker and let entropy decoder continue */
1142
26.7k
    TRACEMS1(cinfo, 3, JTRC_RST, cinfo->marker->next_restart_num);
1143
26.7k
    cinfo->unread_marker = 0;
1144
170M
  } else {
1145
    /* Uh-oh, the restart markers have been messed up. */
1146
    /* Let the data source manager determine how to resync. */
1147
170M
    if (!(*cinfo->src->resync_to_restart) (cinfo,
1148
170M
                                           cinfo->marker->next_restart_num))
1149
0
      return FALSE;
1150
170M
  }
1151
1152
  /* Update next-restart state */
1153
170M
  cinfo->marker->next_restart_num = (cinfo->marker->next_restart_num + 1) & 7;
1154
1155
170M
  return TRUE;
1156
170M
}
1157
1158
1159
/*
1160
 * This is the default resync_to_restart method for data source managers
1161
 * to use if they don't have any better approach.  Some data source managers
1162
 * may be able to back up, or may have additional knowledge about the data
1163
 * which permits a more intelligent recovery strategy; such managers would
1164
 * presumably supply their own resync method.
1165
 *
1166
 * read_restart_marker calls resync_to_restart if it finds a marker other than
1167
 * the restart marker it was expecting.  (This code is *not* used unless
1168
 * a nonzero restart interval has been declared.)  cinfo->unread_marker is
1169
 * the marker code actually found (might be anything, except 0 or FF).
1170
 * The desired restart marker number (0..7) is passed as a parameter.
1171
 * This routine is supposed to apply whatever error recovery strategy seems
1172
 * appropriate in order to position the input stream to the next data segment.
1173
 * Note that cinfo->unread_marker is treated as a marker appearing before
1174
 * the current data-source input point; usually it should be reset to zero
1175
 * before returning.
1176
 * Returns FALSE if suspension is required.
1177
 *
1178
 * This implementation is substantially constrained by wanting to treat the
1179
 * input as a data stream; this means we can't back up.  Therefore, we have
1180
 * only the following actions to work with:
1181
 *   1. Simply discard the marker and let the entropy decoder resume at next
1182
 *      byte of file.
1183
 *   2. Read forward until we find another marker, discarding intervening
1184
 *      data.  (In theory we could look ahead within the current bufferload,
1185
 *      without having to discard data if we don't find the desired marker.
1186
 *      This idea is not implemented here, in part because it makes behavior
1187
 *      dependent on buffer size and chance buffer-boundary positions.)
1188
 *   3. Leave the marker unread (by failing to zero cinfo->unread_marker).
1189
 *      This will cause the entropy decoder to process an empty data segment,
1190
 *      inserting dummy zeroes, and then we will reprocess the marker.
1191
 *
1192
 * #2 is appropriate if we think the desired marker lies ahead, while #3 is
1193
 * appropriate if the found marker is a future restart marker (indicating
1194
 * that we have missed the desired restart marker, probably because it got
1195
 * corrupted).
1196
 * We apply #2 or #3 if the found marker is a restart marker no more than
1197
 * two counts behind or ahead of the expected one.  We also apply #2 if the
1198
 * found marker is not a legal JPEG marker code (it's certainly bogus data).
1199
 * If the found marker is a restart marker more than 2 counts away, we do #1
1200
 * (too much risk that the marker is erroneous; with luck we will be able to
1201
 * resync at some future point).
1202
 * For any valid non-restart JPEG marker, we apply #3.  This keeps us from
1203
 * overrunning the end of a scan.  An implementation limited to single-scan
1204
 * files might find it better to apply #2 for markers other than EOI, since
1205
 * any other marker would have to be bogus data in that case.
1206
 */
1207
1208
GLOBAL(boolean)
1209
jpeg_resync_to_restart(j_decompress_ptr cinfo, int desired)
1210
170M
{
1211
170M
  int marker = cinfo->unread_marker;
1212
170M
  int action = 1;
1213
1214
  /* Always put up a warning. */
1215
170M
  WARNMS2(cinfo, JWRN_MUST_RESYNC, marker, desired);
1216
1217
  /* Outer loop handles repeated decision after scanning forward. */
1218
170M
  for (;;) {
1219
170M
    if (marker < (int)M_SOF0)
1220
9.19k
      action = 2;               /* invalid marker */
1221
170M
    else if (marker < (int)M_RST0 || marker > (int)M_RST7)
1222
170M
      action = 3;               /* valid non-restart marker */
1223
71.9k
    else {
1224
71.9k
      if (marker == ((int)M_RST0 + ((desired + 1) & 7)) ||
1225
71.9k
          marker == ((int)M_RST0 + ((desired + 2) & 7)))
1226
28.3k
        action = 3;             /* one of the next two expected restarts */
1227
43.5k
      else if (marker == ((int)M_RST0 + ((desired - 1) & 7)) ||
1228
43.5k
               marker == ((int)M_RST0 + ((desired - 2) & 7)))
1229
10.4k
        action = 2;             /* a prior restart, so advance */
1230
33.0k
      else
1231
33.0k
        action = 1;             /* desired restart or too far away */
1232
71.9k
    }
1233
170M
    TRACEMS2(cinfo, 4, JTRC_RECOVERY_ACTION, marker, action);
1234
170M
    switch (action) {
1235
33.0k
    case 1:
1236
      /* Discard marker and let entropy decoder resume processing. */
1237
33.0k
      cinfo->unread_marker = 0;
1238
33.0k
      return TRUE;
1239
19.6k
    case 2:
1240
      /* Scan to the next marker, and repeat the decision loop. */
1241
19.6k
      if (!next_marker(cinfo))
1242
0
        return FALSE;
1243
19.6k
      marker = cinfo->unread_marker;
1244
19.6k
      break;
1245
170M
    case 3:
1246
      /* Return without advancing past this marker. */
1247
      /* Entropy decoder will be forced to process an empty segment. */
1248
170M
      return TRUE;
1249
170M
    }
1250
170M
  } /* end loop */
1251
170M
}
1252
1253
1254
/*
1255
 * Reset marker processing state to begin a fresh datastream.
1256
 */
1257
1258
METHODDEF(void)
1259
reset_marker_reader(j_decompress_ptr cinfo)
1260
152k
{
1261
152k
  my_marker_ptr marker = (my_marker_ptr)cinfo->marker;
1262
1263
152k
  cinfo->comp_info = NULL;              /* until allocated by get_sof */
1264
152k
  cinfo->input_scan_number = 0;         /* no SOS seen yet */
1265
152k
  cinfo->unread_marker = 0;             /* no pending marker */
1266
152k
  marker->pub.saw_SOI = FALSE;          /* set internal state too */
1267
152k
  marker->pub.saw_SOF = FALSE;
1268
152k
  marker->pub.discarded_bytes = 0;
1269
152k
  marker->cur_marker = NULL;
1270
152k
}
1271
1272
1273
/*
1274
 * Initialize the marker reader module.
1275
 * This is called only once, when the decompression object is created.
1276
 */
1277
1278
GLOBAL(void)
1279
jinit_marker_reader(j_decompress_ptr cinfo)
1280
48.8k
{
1281
48.8k
  my_marker_ptr marker;
1282
48.8k
  int i;
1283
1284
  /* Create subobject in permanent pool */
1285
48.8k
  marker = (my_marker_ptr)
1286
48.8k
    (*cinfo->mem->alloc_small) ((j_common_ptr)cinfo, JPOOL_PERMANENT,
1287
48.8k
                                sizeof(my_marker_reader));
1288
48.8k
  cinfo->marker = (struct jpeg_marker_reader *)marker;
1289
  /* Initialize public method pointers */
1290
48.8k
  marker->pub.reset_marker_reader = reset_marker_reader;
1291
48.8k
  marker->pub.read_markers = read_markers;
1292
48.8k
  marker->pub.read_restart_marker = read_restart_marker;
1293
  /* Initialize COM/APPn processing.
1294
   * By default, we examine and then discard APP0 and APP14,
1295
   * but simply discard COM and all other APPn.
1296
   */
1297
48.8k
  marker->process_COM = skip_variable;
1298
48.8k
  marker->length_limit_COM = 0;
1299
831k
  for (i = 0; i < 16; i++) {
1300
782k
    marker->process_APPn[i] = skip_variable;
1301
782k
    marker->length_limit_APPn[i] = 0;
1302
782k
  }
1303
48.8k
  marker->process_APPn[0] = get_interesting_appn;
1304
48.8k
  marker->process_APPn[14] = get_interesting_appn;
1305
  /* Reset marker processing state */
1306
48.8k
  reset_marker_reader(cinfo);
1307
48.8k
}
1308
1309
1310
/*
1311
 * Control saving of COM and APPn markers into marker_list.
1312
 */
1313
1314
#ifdef SAVE_MARKERS_SUPPORTED
1315
1316
GLOBAL(void)
1317
jpeg_save_markers(j_decompress_ptr cinfo, int marker_code,
1318
                  unsigned int length_limit)
1319
208k
{
1320
208k
  my_marker_ptr marker = (my_marker_ptr)cinfo->marker;
1321
208k
  long maxlength;
1322
208k
  jpeg_marker_parser_method processor;
1323
1324
  /* Length limit mustn't be larger than what we can allocate
1325
   * (should only be a concern in a 16-bit environment).
1326
   */
1327
208k
  maxlength = cinfo->mem->max_alloc_chunk - sizeof(struct jpeg_marker_struct);
1328
208k
  if (((long)length_limit) > maxlength)
1329
0
    length_limit = (unsigned int)maxlength;
1330
1331
  /* Choose processor routine to use.
1332
   * APP0/APP14 have special requirements.
1333
   */
1334
208k
  if (length_limit) {
1335
208k
    processor = save_marker;
1336
    /* If saving APP0/APP14, save at least enough for our internal use. */
1337
208k
    if (marker_code == (int)M_APP0 && length_limit < APP0_DATA_LEN)
1338
0
      length_limit = APP0_DATA_LEN;
1339
208k
    else if (marker_code == (int)M_APP14 && length_limit < APP14_DATA_LEN)
1340
0
      length_limit = APP14_DATA_LEN;
1341
208k
  } else {
1342
0
    processor = skip_variable;
1343
    /* If discarding APP0/APP14, use our regular on-the-fly processor. */
1344
0
    if (marker_code == (int)M_APP0 || marker_code == (int)M_APP14)
1345
0
      processor = get_interesting_appn;
1346
0
  }
1347
1348
208k
  if (marker_code == (int)M_COM) {
1349
12.2k
    marker->process_COM = processor;
1350
12.2k
    marker->length_limit_COM = length_limit;
1351
195k
  } else if (marker_code >= (int)M_APP0 && marker_code <= (int)M_APP15) {
1352
195k
    marker->process_APPn[marker_code - (int)M_APP0] = processor;
1353
195k
    marker->length_limit_APPn[marker_code - (int)M_APP0] = length_limit;
1354
195k
  } else
1355
0
    ERREXIT1(cinfo, JERR_UNKNOWN_MARKER, marker_code);
1356
208k
}
1357
1358
#endif /* SAVE_MARKERS_SUPPORTED */
1359
1360
1361
/*
1362
 * Install a special processing method for COM or APPn markers.
1363
 */
1364
1365
GLOBAL(void)
1366
jpeg_set_marker_processor(j_decompress_ptr cinfo, int marker_code,
1367
                          jpeg_marker_parser_method routine)
1368
0
{
1369
0
  my_marker_ptr marker = (my_marker_ptr)cinfo->marker;
1370
1371
0
  if (marker_code == (int)M_COM)
1372
0
    marker->process_COM = routine;
1373
0
  else if (marker_code >= (int)M_APP0 && marker_code <= (int)M_APP15)
1374
0
    marker->process_APPn[marker_code - (int)M_APP0] = routine;
1375
0
  else
1376
0
    ERREXIT1(cinfo, JERR_UNKNOWN_MARKER, marker_code);
1377
0
}