Coverage Report

Created: 2026-08-14 07:18

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/libpng/pngtrans.c
Line
Count
Source
1
/* pngtrans.c - transforms the data in a row (used by both readers and writers)
2
 *
3
 * Copyright (c) 2018-2026 Cosmin Truta
4
 * Copyright (c) 1998-2002,2004,2006-2018 Glenn Randers-Pehrson
5
 * Copyright (c) 1996-1997 Andreas Dilger
6
 * Copyright (c) 1995-1996 Guy Eric Schalnat, Group 42, Inc.
7
 *
8
 * This code is released under the libpng license.
9
 * For conditions of distribution and use, see the disclaimer
10
 * and license in png.h
11
 */
12
13
#include "pngpriv.h"
14
15
#if defined(PNG_READ_SUPPORTED) || defined(PNG_WRITE_SUPPORTED)
16
17
#if defined(PNG_READ_BGR_SUPPORTED) || defined(PNG_WRITE_BGR_SUPPORTED)
18
/* Turn on BGR-to-RGB mapping */
19
void PNGAPI
20
png_set_bgr(png_structrp png_ptr)
21
3.03k
{
22
3.03k
   png_debug(1, "in png_set_bgr");
23
24
3.03k
   if (png_ptr == NULL)
25
0
      return;
26
27
3.03k
   png_ptr->transformations |= PNG_BGR;
28
3.03k
}
29
#endif
30
31
#if defined(PNG_READ_SWAP_SUPPORTED) || defined(PNG_WRITE_SWAP_SUPPORTED)
32
/* Turn on 16-bit byte swapping */
33
void PNGAPI
34
png_set_swap(png_structrp png_ptr)
35
3.71k
{
36
3.71k
   png_debug(1, "in png_set_swap");
37
38
3.71k
   if (png_ptr == NULL)
39
0
      return;
40
41
3.71k
   if (png_ptr->bit_depth == 16)
42
1.22k
      png_ptr->transformations |= PNG_SWAP_BYTES;
43
3.71k
}
44
#endif
45
46
#if defined(PNG_READ_PACK_SUPPORTED) || defined(PNG_WRITE_PACK_SUPPORTED)
47
/* Turn on pixel packing */
48
void PNGAPI
49
png_set_packing(png_structrp png_ptr)
50
14.1k
{
51
14.1k
   png_debug(1, "in png_set_packing");
52
53
14.1k
   if (png_ptr == NULL)
54
0
      return;
55
56
14.1k
   if (png_ptr->bit_depth < 8)
57
6.34k
   {
58
6.34k
      png_ptr->transformations |= PNG_PACK;
59
#     ifdef PNG_WRITE_SUPPORTED
60
         png_ptr->usr_bit_depth = 8;
61
#     endif
62
6.34k
   }
63
14.1k
}
64
#endif
65
66
#if defined(PNG_READ_PACKSWAP_SUPPORTED)||defined(PNG_WRITE_PACKSWAP_SUPPORTED)
67
/* Turn on packed pixel swapping */
68
void PNGAPI
69
png_set_packswap(png_structrp png_ptr)
70
3.04k
{
71
3.04k
   png_debug(1, "in png_set_packswap");
72
73
3.04k
   if (png_ptr == NULL)
74
0
      return;
75
76
3.04k
   if (png_ptr->bit_depth < 8)
77
735
      png_ptr->transformations |= PNG_PACKSWAP;
78
3.04k
}
79
#endif
80
81
#if defined(PNG_READ_SHIFT_SUPPORTED) || defined(PNG_WRITE_SHIFT_SUPPORTED)
82
void PNGAPI
83
png_set_shift(png_structrp png_ptr, png_const_color_8p true_bits)
84
135
{
85
135
   png_debug(1, "in png_set_shift");
86
87
135
   if (png_ptr == NULL || true_bits == NULL)
88
0
      return;
89
90
   /* Check the shift values before passing them on to png_do_shift. */
91
135
   {
92
135
      png_byte bit_depth = png_ptr->bit_depth;
93
135
      int invalid = 0;
94
95
135
      if ((png_ptr->color_type & PNG_COLOR_MASK_COLOR) != 0)
96
30
      {
97
30
         if (true_bits->red == 0 || true_bits->red > bit_depth ||
98
26
             true_bits->green == 0 || true_bits->green > bit_depth ||
99
25
             true_bits->blue == 0 || true_bits->blue > bit_depth)
100
7
            invalid = 1;
101
30
      }
102
105
      else
103
105
      {
104
105
         if (true_bits->gray == 0 || true_bits->gray > bit_depth)
105
0
            invalid = 1;
106
105
      }
107
108
135
      if ((png_ptr->color_type & PNG_COLOR_MASK_ALPHA) != 0 &&
109
23
          (true_bits->alpha == 0 || true_bits->alpha > bit_depth))
110
0
         invalid = 1;
111
112
135
      if (invalid)
113
7
      {
114
7
         png_app_error(png_ptr, "png_set_shift: invalid shift values");
115
7
         return;
116
7
      }
117
135
   }
118
119
128
   png_ptr->transformations |= PNG_SHIFT;
120
128
   png_ptr->shift = *true_bits;
121
128
}
122
#endif
123
124
#if defined(PNG_READ_INTERLACING_SUPPORTED) || \
125
    defined(PNG_WRITE_INTERLACING_SUPPORTED)
126
int PNGAPI
127
png_set_interlace_handling(png_structrp png_ptr)
128
32.0k
{
129
32.0k
   png_debug(1, "in png_set_interlace handling");
130
131
32.0k
   if (png_ptr != 0 && png_ptr->interlaced != 0)
132
17.2k
   {
133
17.2k
      png_ptr->transformations |= PNG_INTERLACE;
134
17.2k
      return 7;
135
17.2k
   }
136
137
14.7k
   return 1;
138
32.0k
}
139
#endif
140
141
#if defined(PNG_READ_FILLER_SUPPORTED) || defined(PNG_WRITE_FILLER_SUPPORTED)
142
/* Add a filler byte on read, or remove a filler or alpha byte on write.
143
 * The filler type has changed in v0.95 to allow future 2-byte fillers
144
 * for 48-bit input data, as well as to avoid problems with some compilers
145
 * that don't like bytes as parameters.
146
 */
147
void PNGAPI
148
png_set_filler(png_structrp png_ptr, png_uint_32 filler, int filler_loc)
149
8.88k
{
150
8.88k
   png_debug(1, "in png_set_filler");
151
152
8.88k
   if (png_ptr == NULL)
153
0
      return;
154
155
   /* In libpng 1.6 it is possible to determine whether this is a read or write
156
    * operation and therefore to do more checking here for a valid call.
157
    */
158
8.88k
   if ((png_ptr->mode & PNG_IS_READ_STRUCT) != 0)
159
8.88k
   {
160
8.88k
#     ifdef PNG_READ_FILLER_SUPPORTED
161
         /* On read png_set_filler is always valid, regardless of the base PNG
162
          * format, because other transformations can give a format where the
163
          * filler code can execute (basically an 8 or 16-bit component RGB or G
164
          * format.)
165
          *
166
          * NOTE: usr_channels is not used by the read code!  (This has led to
167
          * confusion in the past.)  The filler is only used in the read code.
168
          */
169
8.88k
         png_ptr->filler = (png_uint_16)filler;
170
#     else
171
         png_app_error(png_ptr, "png_set_filler not supported on read");
172
         PNG_UNUSED(filler) /* not used in the write case */
173
         return;
174
#     endif
175
8.88k
   }
176
177
0
   else /* write */
178
0
   {
179
#     ifdef PNG_WRITE_FILLER_SUPPORTED
180
         /* On write the usr_channels parameter must be set correctly at the
181
          * start to record the number of channels in the app-supplied data.
182
          */
183
         switch (png_ptr->color_type)
184
         {
185
            case PNG_COLOR_TYPE_RGB:
186
               png_ptr->usr_channels = 4;
187
               break;
188
189
            case PNG_COLOR_TYPE_GRAY:
190
               if (png_ptr->bit_depth >= 8)
191
               {
192
                  png_ptr->usr_channels = 2;
193
                  break;
194
               }
195
196
               else
197
               {
198
                  /* There simply isn't any code in libpng to strip out bits
199
                   * from bytes when the components are less than a byte in
200
                   * size!
201
                   */
202
                  png_app_error(png_ptr,
203
                      "png_set_filler is invalid for"
204
                      " low bit depth gray output");
205
                  return;
206
               }
207
208
            default:
209
               png_app_error(png_ptr,
210
                   "png_set_filler: inappropriate color type");
211
               return;
212
         }
213
#     else
214
0
         png_app_error(png_ptr, "png_set_filler not supported on write");
215
0
         return;
216
0
#     endif
217
0
   }
218
219
   /* Here on success - libpng supports the operation, set the transformation
220
    * and the flag to say where the filler channel is.
221
    */
222
8.88k
   png_ptr->transformations |= PNG_FILLER;
223
224
8.88k
   if (filler_loc == PNG_FILLER_AFTER)
225
8.74k
      png_ptr->flags |= PNG_FLAG_FILLER_AFTER;
226
227
140
   else
228
140
      png_ptr->flags &= ~PNG_FLAG_FILLER_AFTER;
229
8.88k
}
230
231
/* Added to libpng-1.2.7 */
232
void PNGAPI
233
png_set_add_alpha(png_structrp png_ptr, png_uint_32 filler, int filler_loc)
234
8.88k
{
235
8.88k
   png_debug(1, "in png_set_add_alpha");
236
237
8.88k
   if (png_ptr == NULL)
238
0
      return;
239
240
8.88k
   png_set_filler(png_ptr, filler, filler_loc);
241
   /* The above may fail to do anything. */
242
8.88k
   if ((png_ptr->transformations & PNG_FILLER) != 0)
243
8.88k
      png_ptr->transformations |= PNG_ADD_ALPHA;
244
8.88k
}
245
246
#endif
247
248
#if defined(PNG_READ_SWAP_ALPHA_SUPPORTED) || \
249
    defined(PNG_WRITE_SWAP_ALPHA_SUPPORTED)
250
void PNGAPI
251
png_set_swap_alpha(png_structrp png_ptr)
252
3.07k
{
253
3.07k
   png_debug(1, "in png_set_swap_alpha");
254
255
3.07k
   if (png_ptr == NULL)
256
0
      return;
257
258
3.07k
   png_ptr->transformations |= PNG_SWAP_ALPHA;
259
3.07k
}
260
#endif
261
262
#if defined(PNG_READ_INVERT_ALPHA_SUPPORTED) || \
263
    defined(PNG_WRITE_INVERT_ALPHA_SUPPORTED)
264
void PNGAPI
265
png_set_invert_alpha(png_structrp png_ptr)
266
2.99k
{
267
2.99k
   png_debug(1, "in png_set_invert_alpha");
268
269
2.99k
   if (png_ptr == NULL)
270
0
      return;
271
272
2.99k
   png_ptr->transformations |= PNG_INVERT_ALPHA;
273
2.99k
}
274
#endif
275
276
#if defined(PNG_READ_INVERT_SUPPORTED) || defined(PNG_WRITE_INVERT_SUPPORTED)
277
void PNGAPI
278
png_set_invert_mono(png_structrp png_ptr)
279
2.86k
{
280
2.86k
   png_debug(1, "in png_set_invert_mono");
281
282
2.86k
   if (png_ptr == NULL)
283
0
      return;
284
285
2.86k
   png_ptr->transformations |= PNG_INVERT_MONO;
286
2.86k
}
287
288
/* Invert monochrome grayscale data */
289
void /* PRIVATE */
290
png_do_invert(png_row_infop row_info, png_bytep row)
291
24.5k
{
292
24.5k
   png_debug(1, "in png_do_invert");
293
294
  /* This test removed from libpng version 1.0.13 and 1.2.0:
295
   *   if (row_info->bit_depth == 1 &&
296
   */
297
24.5k
   if (row_info->color_type == PNG_COLOR_TYPE_GRAY)
298
4.37k
   {
299
4.37k
      png_bytep rp = row;
300
4.37k
      size_t i;
301
4.37k
      size_t istop = row_info->rowbytes;
302
303
6.74M
      for (i = 0; i < istop; i++)
304
6.74M
      {
305
6.74M
         *rp = (png_byte)(~(*rp));
306
6.74M
         rp++;
307
6.74M
      }
308
4.37k
   }
309
310
20.1k
   else if (row_info->color_type == PNG_COLOR_TYPE_GRAY_ALPHA &&
311
1.63k
      row_info->bit_depth == 8)
312
715
   {
313
715
      png_bytep rp = row;
314
715
      size_t i;
315
715
      size_t istop = row_info->rowbytes;
316
317
1.81M
      for (i = 0; i < istop; i += 2)
318
1.81M
      {
319
1.81M
         *rp = (png_byte)(~(*rp));
320
1.81M
         rp += 2;
321
1.81M
      }
322
715
   }
323
324
19.4k
#ifdef PNG_16BIT_SUPPORTED
325
19.4k
   else if (row_info->color_type == PNG_COLOR_TYPE_GRAY_ALPHA &&
326
918
      row_info->bit_depth == 16)
327
918
   {
328
918
      png_bytep rp = row;
329
918
      size_t i;
330
918
      size_t istop = row_info->rowbytes;
331
332
135k
      for (i = 0; i < istop; i += 4)
333
134k
      {
334
134k
         *rp = (png_byte)(~(*rp));
335
134k
         *(rp + 1) = (png_byte)(~(*(rp + 1)));
336
134k
         rp += 4;
337
134k
      }
338
918
   }
339
24.5k
#endif
340
24.5k
}
341
#endif
342
343
#ifdef PNG_16BIT_SUPPORTED
344
#if defined(PNG_READ_SWAP_SUPPORTED) || defined(PNG_WRITE_SWAP_SUPPORTED)
345
/* Swaps byte order on 16-bit depth images */
346
void /* PRIVATE */
347
png_do_swap(png_row_infop row_info, png_bytep row)
348
9.68k
{
349
9.68k
   png_debug(1, "in png_do_swap");
350
351
9.68k
   if (row_info->bit_depth == 16)
352
8.58k
   {
353
8.58k
      png_bytep rp = row;
354
8.58k
      png_uint_32 i;
355
8.58k
      png_uint_32 istop= row_info->width * row_info->channels;
356
357
19.6M
      for (i = 0; i < istop; i++, rp += 2)
358
19.6M
      {
359
#ifdef PNG_BUILTIN_BSWAP16_SUPPORTED
360
         /* Feature added to libpng-1.6.11 for testing purposes, not
361
          * enabled by default.
362
          */
363
         *(png_uint_16*)rp = __builtin_bswap16(*(png_uint_16*)rp);
364
#else
365
19.6M
         png_byte t = *rp;
366
19.6M
         *rp = *(rp + 1);
367
19.6M
         *(rp + 1) = t;
368
19.6M
#endif
369
19.6M
      }
370
8.58k
   }
371
9.68k
}
372
#endif
373
#endif
374
375
#if defined(PNG_READ_PACKSWAP_SUPPORTED)||defined(PNG_WRITE_PACKSWAP_SUPPORTED)
376
static const png_byte onebppswaptable[256] = {
377
   0x00, 0x80, 0x40, 0xC0, 0x20, 0xA0, 0x60, 0xE0,
378
   0x10, 0x90, 0x50, 0xD0, 0x30, 0xB0, 0x70, 0xF0,
379
   0x08, 0x88, 0x48, 0xC8, 0x28, 0xA8, 0x68, 0xE8,
380
   0x18, 0x98, 0x58, 0xD8, 0x38, 0xB8, 0x78, 0xF8,
381
   0x04, 0x84, 0x44, 0xC4, 0x24, 0xA4, 0x64, 0xE4,
382
   0x14, 0x94, 0x54, 0xD4, 0x34, 0xB4, 0x74, 0xF4,
383
   0x0C, 0x8C, 0x4C, 0xCC, 0x2C, 0xAC, 0x6C, 0xEC,
384
   0x1C, 0x9C, 0x5C, 0xDC, 0x3C, 0xBC, 0x7C, 0xFC,
385
   0x02, 0x82, 0x42, 0xC2, 0x22, 0xA2, 0x62, 0xE2,
386
   0x12, 0x92, 0x52, 0xD2, 0x32, 0xB2, 0x72, 0xF2,
387
   0x0A, 0x8A, 0x4A, 0xCA, 0x2A, 0xAA, 0x6A, 0xEA,
388
   0x1A, 0x9A, 0x5A, 0xDA, 0x3A, 0xBA, 0x7A, 0xFA,
389
   0x06, 0x86, 0x46, 0xC6, 0x26, 0xA6, 0x66, 0xE6,
390
   0x16, 0x96, 0x56, 0xD6, 0x36, 0xB6, 0x76, 0xF6,
391
   0x0E, 0x8E, 0x4E, 0xCE, 0x2E, 0xAE, 0x6E, 0xEE,
392
   0x1E, 0x9E, 0x5E, 0xDE, 0x3E, 0xBE, 0x7E, 0xFE,
393
   0x01, 0x81, 0x41, 0xC1, 0x21, 0xA1, 0x61, 0xE1,
394
   0x11, 0x91, 0x51, 0xD1, 0x31, 0xB1, 0x71, 0xF1,
395
   0x09, 0x89, 0x49, 0xC9, 0x29, 0xA9, 0x69, 0xE9,
396
   0x19, 0x99, 0x59, 0xD9, 0x39, 0xB9, 0x79, 0xF9,
397
   0x05, 0x85, 0x45, 0xC5, 0x25, 0xA5, 0x65, 0xE5,
398
   0x15, 0x95, 0x55, 0xD5, 0x35, 0xB5, 0x75, 0xF5,
399
   0x0D, 0x8D, 0x4D, 0xCD, 0x2D, 0xAD, 0x6D, 0xED,
400
   0x1D, 0x9D, 0x5D, 0xDD, 0x3D, 0xBD, 0x7D, 0xFD,
401
   0x03, 0x83, 0x43, 0xC3, 0x23, 0xA3, 0x63, 0xE3,
402
   0x13, 0x93, 0x53, 0xD3, 0x33, 0xB3, 0x73, 0xF3,
403
   0x0B, 0x8B, 0x4B, 0xCB, 0x2B, 0xAB, 0x6B, 0xEB,
404
   0x1B, 0x9B, 0x5B, 0xDB, 0x3B, 0xBB, 0x7B, 0xFB,
405
   0x07, 0x87, 0x47, 0xC7, 0x27, 0xA7, 0x67, 0xE7,
406
   0x17, 0x97, 0x57, 0xD7, 0x37, 0xB7, 0x77, 0xF7,
407
   0x0F, 0x8F, 0x4F, 0xCF, 0x2F, 0xAF, 0x6F, 0xEF,
408
   0x1F, 0x9F, 0x5F, 0xDF, 0x3F, 0xBF, 0x7F, 0xFF
409
};
410
411
static const png_byte twobppswaptable[256] = {
412
   0x00, 0x40, 0x80, 0xC0, 0x10, 0x50, 0x90, 0xD0,
413
   0x20, 0x60, 0xA0, 0xE0, 0x30, 0x70, 0xB0, 0xF0,
414
   0x04, 0x44, 0x84, 0xC4, 0x14, 0x54, 0x94, 0xD4,
415
   0x24, 0x64, 0xA4, 0xE4, 0x34, 0x74, 0xB4, 0xF4,
416
   0x08, 0x48, 0x88, 0xC8, 0x18, 0x58, 0x98, 0xD8,
417
   0x28, 0x68, 0xA8, 0xE8, 0x38, 0x78, 0xB8, 0xF8,
418
   0x0C, 0x4C, 0x8C, 0xCC, 0x1C, 0x5C, 0x9C, 0xDC,
419
   0x2C, 0x6C, 0xAC, 0xEC, 0x3C, 0x7C, 0xBC, 0xFC,
420
   0x01, 0x41, 0x81, 0xC1, 0x11, 0x51, 0x91, 0xD1,
421
   0x21, 0x61, 0xA1, 0xE1, 0x31, 0x71, 0xB1, 0xF1,
422
   0x05, 0x45, 0x85, 0xC5, 0x15, 0x55, 0x95, 0xD5,
423
   0x25, 0x65, 0xA5, 0xE5, 0x35, 0x75, 0xB5, 0xF5,
424
   0x09, 0x49, 0x89, 0xC9, 0x19, 0x59, 0x99, 0xD9,
425
   0x29, 0x69, 0xA9, 0xE9, 0x39, 0x79, 0xB9, 0xF9,
426
   0x0D, 0x4D, 0x8D, 0xCD, 0x1D, 0x5D, 0x9D, 0xDD,
427
   0x2D, 0x6D, 0xAD, 0xED, 0x3D, 0x7D, 0xBD, 0xFD,
428
   0x02, 0x42, 0x82, 0xC2, 0x12, 0x52, 0x92, 0xD2,
429
   0x22, 0x62, 0xA2, 0xE2, 0x32, 0x72, 0xB2, 0xF2,
430
   0x06, 0x46, 0x86, 0xC6, 0x16, 0x56, 0x96, 0xD6,
431
   0x26, 0x66, 0xA6, 0xE6, 0x36, 0x76, 0xB6, 0xF6,
432
   0x0A, 0x4A, 0x8A, 0xCA, 0x1A, 0x5A, 0x9A, 0xDA,
433
   0x2A, 0x6A, 0xAA, 0xEA, 0x3A, 0x7A, 0xBA, 0xFA,
434
   0x0E, 0x4E, 0x8E, 0xCE, 0x1E, 0x5E, 0x9E, 0xDE,
435
   0x2E, 0x6E, 0xAE, 0xEE, 0x3E, 0x7E, 0xBE, 0xFE,
436
   0x03, 0x43, 0x83, 0xC3, 0x13, 0x53, 0x93, 0xD3,
437
   0x23, 0x63, 0xA3, 0xE3, 0x33, 0x73, 0xB3, 0xF3,
438
   0x07, 0x47, 0x87, 0xC7, 0x17, 0x57, 0x97, 0xD7,
439
   0x27, 0x67, 0xA7, 0xE7, 0x37, 0x77, 0xB7, 0xF7,
440
   0x0B, 0x4B, 0x8B, 0xCB, 0x1B, 0x5B, 0x9B, 0xDB,
441
   0x2B, 0x6B, 0xAB, 0xEB, 0x3B, 0x7B, 0xBB, 0xFB,
442
   0x0F, 0x4F, 0x8F, 0xCF, 0x1F, 0x5F, 0x9F, 0xDF,
443
   0x2F, 0x6F, 0xAF, 0xEF, 0x3F, 0x7F, 0xBF, 0xFF
444
};
445
446
static const png_byte fourbppswaptable[256] = {
447
   0x00, 0x10, 0x20, 0x30, 0x40, 0x50, 0x60, 0x70,
448
   0x80, 0x90, 0xA0, 0xB0, 0xC0, 0xD0, 0xE0, 0xF0,
449
   0x01, 0x11, 0x21, 0x31, 0x41, 0x51, 0x61, 0x71,
450
   0x81, 0x91, 0xA1, 0xB1, 0xC1, 0xD1, 0xE1, 0xF1,
451
   0x02, 0x12, 0x22, 0x32, 0x42, 0x52, 0x62, 0x72,
452
   0x82, 0x92, 0xA2, 0xB2, 0xC2, 0xD2, 0xE2, 0xF2,
453
   0x03, 0x13, 0x23, 0x33, 0x43, 0x53, 0x63, 0x73,
454
   0x83, 0x93, 0xA3, 0xB3, 0xC3, 0xD3, 0xE3, 0xF3,
455
   0x04, 0x14, 0x24, 0x34, 0x44, 0x54, 0x64, 0x74,
456
   0x84, 0x94, 0xA4, 0xB4, 0xC4, 0xD4, 0xE4, 0xF4,
457
   0x05, 0x15, 0x25, 0x35, 0x45, 0x55, 0x65, 0x75,
458
   0x85, 0x95, 0xA5, 0xB5, 0xC5, 0xD5, 0xE5, 0xF5,
459
   0x06, 0x16, 0x26, 0x36, 0x46, 0x56, 0x66, 0x76,
460
   0x86, 0x96, 0xA6, 0xB6, 0xC6, 0xD6, 0xE6, 0xF6,
461
   0x07, 0x17, 0x27, 0x37, 0x47, 0x57, 0x67, 0x77,
462
   0x87, 0x97, 0xA7, 0xB7, 0xC7, 0xD7, 0xE7, 0xF7,
463
   0x08, 0x18, 0x28, 0x38, 0x48, 0x58, 0x68, 0x78,
464
   0x88, 0x98, 0xA8, 0xB8, 0xC8, 0xD8, 0xE8, 0xF8,
465
   0x09, 0x19, 0x29, 0x39, 0x49, 0x59, 0x69, 0x79,
466
   0x89, 0x99, 0xA9, 0xB9, 0xC9, 0xD9, 0xE9, 0xF9,
467
   0x0A, 0x1A, 0x2A, 0x3A, 0x4A, 0x5A, 0x6A, 0x7A,
468
   0x8A, 0x9A, 0xAA, 0xBA, 0xCA, 0xDA, 0xEA, 0xFA,
469
   0x0B, 0x1B, 0x2B, 0x3B, 0x4B, 0x5B, 0x6B, 0x7B,
470
   0x8B, 0x9B, 0xAB, 0xBB, 0xCB, 0xDB, 0xEB, 0xFB,
471
   0x0C, 0x1C, 0x2C, 0x3C, 0x4C, 0x5C, 0x6C, 0x7C,
472
   0x8C, 0x9C, 0xAC, 0xBC, 0xCC, 0xDC, 0xEC, 0xFC,
473
   0x0D, 0x1D, 0x2D, 0x3D, 0x4D, 0x5D, 0x6D, 0x7D,
474
   0x8D, 0x9D, 0xAD, 0xBD, 0xCD, 0xDD, 0xED, 0xFD,
475
   0x0E, 0x1E, 0x2E, 0x3E, 0x4E, 0x5E, 0x6E, 0x7E,
476
   0x8E, 0x9E, 0xAE, 0xBE, 0xCE, 0xDE, 0xEE, 0xFE,
477
   0x0F, 0x1F, 0x2F, 0x3F, 0x4F, 0x5F, 0x6F, 0x7F,
478
   0x8F, 0x9F, 0xAF, 0xBF, 0xCF, 0xDF, 0xEF, 0xFF
479
};
480
481
/* Swaps pixel packing order within bytes */
482
void /* PRIVATE */
483
png_do_packswap(png_row_infop row_info, png_bytep row)
484
6.35k
{
485
6.35k
   png_debug(1, "in png_do_packswap");
486
487
6.35k
   if (row_info->bit_depth < 8)
488
2.21k
   {
489
2.21k
      png_const_bytep table;
490
2.21k
      png_bytep rp;
491
2.21k
      png_bytep row_end = row + row_info->rowbytes;
492
493
2.21k
      if (row_info->bit_depth == 1)
494
627
         table = onebppswaptable;
495
496
1.59k
      else if (row_info->bit_depth == 2)
497
899
         table = twobppswaptable;
498
499
693
      else if (row_info->bit_depth == 4)
500
693
         table = fourbppswaptable;
501
502
0
      else
503
0
         return;
504
505
1.67M
      for (rp = row; rp < row_end; rp++)
506
1.67M
         *rp = table[*rp];
507
2.21k
   }
508
6.35k
}
509
#endif /* PACKSWAP || WRITE_PACKSWAP */
510
511
#if defined(PNG_WRITE_FILLER_SUPPORTED) || \
512
    defined(PNG_READ_STRIP_ALPHA_SUPPORTED)
513
/* Remove a channel - this used to be 'png_do_strip_filler' but it used a
514
 * somewhat weird combination of flags to determine what to do.  All the calls
515
 * to png_do_strip_filler are changed in 1.5.2 to call this instead with the
516
 * correct arguments.
517
 *
518
 * The routine isn't general - the channel must be the channel at the start or
519
 * end (not in the middle) of each pixel.
520
 */
521
void /* PRIVATE */
522
png_do_strip_channel(png_row_infop row_info, png_bytep row, int at_start)
523
9.86k
{
524
9.86k
   png_bytep sp = row; /* source pointer */
525
9.86k
   png_bytep dp = row; /* destination pointer */
526
9.86k
   png_bytep ep = row + row_info->rowbytes; /* One beyond end of row */
527
528
9.86k
   png_debug(1, "in png_do_strip_channel");
529
530
   /* At the start sp will point to the first byte to copy and dp to where
531
    * it is copied to.  ep always points just beyond the end of the row, so
532
    * the loop simply copies (channels-1) channels until sp reaches ep.
533
    *
534
    * at_start:        0 -- convert AG, XG, ARGB, XRGB, AAGG, XXGG, etc.
535
    *            nonzero -- convert GA, GX, RGBA, RGBX, GGAA, RRGGBBXX, etc.
536
    */
537
538
   /* GA, GX, XG cases */
539
9.86k
   if (row_info->channels == 2)
540
4.59k
   {
541
4.59k
      if (row_info->bit_depth == 8)
542
1.89k
      {
543
1.89k
         if (at_start != 0) /* Skip initial filler */
544
0
            ++sp;
545
1.89k
         else          /* Skip initial channel and, for sp, the filler */
546
1.89k
         {
547
1.89k
            sp += 2; ++dp;
548
1.89k
         }
549
550
         /* For a 1 pixel wide image there is nothing to do */
551
135k
         while (sp < ep)
552
133k
         {
553
133k
            *dp++ = *sp; sp += 2;
554
133k
         }
555
556
1.89k
         row_info->pixel_depth = 8;
557
1.89k
      }
558
559
2.69k
      else if (row_info->bit_depth == 16)
560
2.69k
      {
561
2.69k
         if (at_start != 0) /* Skip initial filler */
562
0
            sp += 2;
563
2.69k
         else          /* Skip initial channel and, for sp, the filler */
564
2.69k
         {
565
2.69k
            sp += 4; dp += 2;
566
2.69k
         }
567
568
1.17M
         while (sp < ep)
569
1.17M
         {
570
1.17M
            *dp++ = *sp++; *dp++ = *sp; sp += 3;
571
1.17M
         }
572
573
2.69k
         row_info->pixel_depth = 16;
574
2.69k
      }
575
576
0
      else
577
0
         return; /* bad bit depth */
578
579
4.59k
      row_info->channels = 1;
580
581
      /* Finally fix the color type if it records an alpha channel */
582
4.59k
      if (row_info->color_type == PNG_COLOR_TYPE_GRAY_ALPHA)
583
4.59k
         row_info->color_type = PNG_COLOR_TYPE_GRAY;
584
4.59k
   }
585
586
   /* RGBA, RGBX, XRGB cases */
587
5.27k
   else if (row_info->channels == 4)
588
5.27k
   {
589
5.27k
      if (row_info->bit_depth == 8)
590
2.18k
      {
591
2.18k
         if (at_start != 0) /* Skip initial filler */
592
0
            ++sp;
593
2.18k
         else          /* Skip initial channels and, for sp, the filler */
594
2.18k
         {
595
2.18k
            sp += 4; dp += 3;
596
2.18k
         }
597
598
         /* Note that the loop adds 3 to dp and 4 to sp each time. */
599
2.92M
         while (sp < ep)
600
2.92M
         {
601
2.92M
            *dp++ = *sp++; *dp++ = *sp++; *dp++ = *sp; sp += 2;
602
2.92M
         }
603
604
2.18k
         row_info->pixel_depth = 24;
605
2.18k
      }
606
607
3.09k
      else if (row_info->bit_depth == 16)
608
3.09k
      {
609
3.09k
         if (at_start != 0) /* Skip initial filler */
610
0
            sp += 2;
611
3.09k
         else          /* Skip initial channels and, for sp, the filler */
612
3.09k
         {
613
3.09k
            sp += 8; dp += 6;
614
3.09k
         }
615
616
123k
         while (sp < ep)
617
120k
         {
618
            /* Copy 6 bytes, skip 2 */
619
120k
            *dp++ = *sp++; *dp++ = *sp++;
620
120k
            *dp++ = *sp++; *dp++ = *sp++;
621
120k
            *dp++ = *sp++; *dp++ = *sp; sp += 3;
622
120k
         }
623
624
3.09k
         row_info->pixel_depth = 48;
625
3.09k
      }
626
627
0
      else
628
0
         return; /* bad bit depth */
629
630
5.27k
      row_info->channels = 3;
631
632
      /* Finally fix the color type if it records an alpha channel */
633
5.27k
      if (row_info->color_type == PNG_COLOR_TYPE_RGB_ALPHA)
634
5.27k
         row_info->color_type = PNG_COLOR_TYPE_RGB;
635
5.27k
   }
636
637
0
   else
638
0
      return; /* The filler channel has gone already */
639
640
   /* Fix the rowbytes value. */
641
9.86k
   row_info->rowbytes = (size_t)(dp-row);
642
9.86k
}
643
#endif
644
645
#if defined(PNG_READ_BGR_SUPPORTED) || defined(PNG_WRITE_BGR_SUPPORTED)
646
/* Swaps red and blue bytes within a pixel */
647
void /* PRIVATE */
648
png_do_bgr(png_row_infop row_info, png_bytep row)
649
23.5k
{
650
23.5k
   png_debug(1, "in png_do_bgr");
651
652
23.5k
   if ((row_info->color_type & PNG_COLOR_MASK_COLOR) != 0)
653
20.1k
   {
654
20.1k
      png_uint_32 row_width = row_info->width;
655
20.1k
      if (row_info->bit_depth == 8)
656
3.35k
      {
657
3.35k
         if (row_info->color_type == PNG_COLOR_TYPE_RGB)
658
1.89k
         {
659
1.89k
            png_bytep rp;
660
1.89k
            png_uint_32 i;
661
662
3.75M
            for (i = 0, rp = row; i < row_width; i++, rp += 3)
663
3.75M
            {
664
3.75M
               png_byte save = *rp;
665
3.75M
               *rp = *(rp + 2);
666
3.75M
               *(rp + 2) = save;
667
3.75M
            }
668
1.89k
         }
669
670
1.46k
         else if (row_info->color_type == PNG_COLOR_TYPE_RGB_ALPHA)
671
1.16k
         {
672
1.16k
            png_bytep rp;
673
1.16k
            png_uint_32 i;
674
675
2.74M
            for (i = 0, rp = row; i < row_width; i++, rp += 4)
676
2.74M
            {
677
2.74M
               png_byte save = *rp;
678
2.74M
               *rp = *(rp + 2);
679
2.74M
               *(rp + 2) = save;
680
2.74M
            }
681
1.16k
         }
682
3.35k
      }
683
684
16.8k
#ifdef PNG_16BIT_SUPPORTED
685
16.8k
      else if (row_info->bit_depth == 16)
686
15.8k
      {
687
15.8k
         if (row_info->color_type == PNG_COLOR_TYPE_RGB)
688
14.7k
         {
689
14.7k
            png_bytep rp;
690
14.7k
            png_uint_32 i;
691
692
15.4M
            for (i = 0, rp = row; i < row_width; i++, rp += 6)
693
15.4M
            {
694
15.4M
               png_byte save = *rp;
695
15.4M
               *rp = *(rp + 4);
696
15.4M
               *(rp + 4) = save;
697
15.4M
               save = *(rp + 1);
698
15.4M
               *(rp + 1) = *(rp + 5);
699
15.4M
               *(rp + 5) = save;
700
15.4M
            }
701
14.7k
         }
702
703
1.08k
         else if (row_info->color_type == PNG_COLOR_TYPE_RGB_ALPHA)
704
1.08k
         {
705
1.08k
            png_bytep rp;
706
1.08k
            png_uint_32 i;
707
708
4.19M
            for (i = 0, rp = row; i < row_width; i++, rp += 8)
709
4.19M
            {
710
4.19M
               png_byte save = *rp;
711
4.19M
               *rp = *(rp + 4);
712
4.19M
               *(rp + 4) = save;
713
4.19M
               save = *(rp + 1);
714
4.19M
               *(rp + 1) = *(rp + 5);
715
4.19M
               *(rp + 5) = save;
716
4.19M
            }
717
1.08k
         }
718
15.8k
      }
719
20.1k
#endif
720
20.1k
   }
721
23.5k
}
722
#endif /* READ_BGR || WRITE_BGR */
723
724
#if defined(PNG_READ_CHECK_FOR_INVALID_INDEX_SUPPORTED) || \
725
    defined(PNG_WRITE_CHECK_FOR_INVALID_INDEX_SUPPORTED)
726
/* Added at libpng-1.5.10 */
727
void /* PRIVATE */
728
png_do_check_palette_indexes(png_structrp png_ptr, png_row_infop row_info)
729
3.55k
{
730
3.55k
   png_debug(1, "in png_do_check_palette_indexes");
731
732
3.55k
   if (png_ptr->num_palette < (1 << row_info->bit_depth) &&
733
2.91k
      png_ptr->num_palette > 0) /* num_palette can be 0 in MNG files */
734
2.91k
   {
735
      /* Calculations moved outside switch in an attempt to stop different
736
       * compiler warnings.  'padding' is in *bits* within the last byte, it is
737
       * an 'int' because pixel_depth becomes an 'int' in the expression below,
738
       * and this calculation is used because it avoids warnings that other
739
       * forms produced on either GCC or MSVC.
740
       */
741
2.91k
      int padding = PNG_PADBITS(row_info->pixel_depth, row_info->width);
742
2.91k
      png_bytep rp = png_ptr->row_buf + row_info->rowbytes;
743
744
2.91k
      switch (row_info->bit_depth)
745
2.91k
      {
746
304
         case 1:
747
304
         {
748
            /* in this case, all bytes must be 0 so we don't need
749
             * to unpack the pixels except for the rightmost one.
750
             */
751
166k
            for (; rp > png_ptr->row_buf; rp--)
752
165k
            {
753
165k
              if ((*rp >> padding) != 0)
754
134k
                 png_ptr->num_palette_max = 1;
755
165k
              padding = 0;
756
165k
            }
757
758
304
            break;
759
0
         }
760
761
716
         case 2:
762
716
         {
763
176k
            for (; rp > png_ptr->row_buf; rp--)
764
175k
            {
765
175k
              int i = ((*rp >> padding) & 0x03);
766
767
175k
              if (i > png_ptr->num_palette_max)
768
24
                 png_ptr->num_palette_max = i;
769
770
175k
              i = (((*rp >> padding) >> 2) & 0x03);
771
772
175k
              if (i > png_ptr->num_palette_max)
773
18
                 png_ptr->num_palette_max = i;
774
775
175k
              i = (((*rp >> padding) >> 4) & 0x03);
776
777
175k
              if (i > png_ptr->num_palette_max)
778
7
                 png_ptr->num_palette_max = i;
779
780
175k
              i = (((*rp >> padding) >> 6) & 0x03);
781
782
175k
              if (i > png_ptr->num_palette_max)
783
7
                 png_ptr->num_palette_max = i;
784
785
175k
              padding = 0;
786
175k
            }
787
788
716
            break;
789
0
         }
790
791
468
         case 4:
792
468
         {
793
1.08M
            for (; rp > png_ptr->row_buf; rp--)
794
1.08M
            {
795
1.08M
              int i = ((*rp >> padding) & 0x0f);
796
797
1.08M
              if (i > png_ptr->num_palette_max)
798
66
                 png_ptr->num_palette_max = i;
799
800
1.08M
              i = (((*rp >> padding) >> 4) & 0x0f);
801
802
1.08M
              if (i > png_ptr->num_palette_max)
803
34
                 png_ptr->num_palette_max = i;
804
805
1.08M
              padding = 0;
806
1.08M
            }
807
808
468
            break;
809
0
         }
810
811
1.42k
         case 8:
812
1.42k
         {
813
5.67M
            for (; rp > png_ptr->row_buf; rp--)
814
5.67M
            {
815
5.67M
               if (*rp > png_ptr->num_palette_max)
816
460
                  png_ptr->num_palette_max = (int) *rp;
817
5.67M
            }
818
819
1.42k
            break;
820
0
         }
821
822
0
         default:
823
0
            break;
824
2.91k
      }
825
2.91k
   }
826
3.55k
}
827
#endif /* CHECK_FOR_INVALID_INDEX */
828
829
#if defined(PNG_READ_USER_TRANSFORM_SUPPORTED) || \
830
    defined(PNG_WRITE_USER_TRANSFORM_SUPPORTED)
831
#ifdef PNG_USER_TRANSFORM_PTR_SUPPORTED
832
void PNGAPI
833
png_set_user_transform_info(png_structrp png_ptr, png_voidp user_transform_ptr,
834
    int user_transform_depth, int user_transform_channels)
835
0
{
836
0
   png_debug(1, "in png_set_user_transform_info");
837
838
0
   if (png_ptr == NULL)
839
0
      return;
840
841
0
#ifdef PNG_READ_USER_TRANSFORM_SUPPORTED
842
0
   if ((png_ptr->mode & PNG_IS_READ_STRUCT) != 0 &&
843
0
      (png_ptr->flags & PNG_FLAG_ROW_INIT) != 0)
844
0
   {
845
0
      png_app_error(png_ptr,
846
0
          "info change after png_start_read_image or png_read_update_info");
847
0
      return;
848
0
   }
849
0
#endif
850
851
0
   png_ptr->user_transform_ptr = user_transform_ptr;
852
0
   png_ptr->user_transform_depth = (png_byte)user_transform_depth;
853
0
   png_ptr->user_transform_channels = (png_byte)user_transform_channels;
854
0
}
855
#endif
856
857
/* This function returns a pointer to the user_transform_ptr associated with
858
 * the user transform functions.  The application should free any memory
859
 * associated with this pointer before png_write_destroy and png_read_destroy
860
 * are called.
861
 */
862
#ifdef PNG_USER_TRANSFORM_PTR_SUPPORTED
863
png_voidp PNGAPI
864
png_get_user_transform_ptr(png_const_structrp png_ptr)
865
0
{
866
0
   if (png_ptr == NULL)
867
0
      return NULL;
868
869
0
   return png_ptr->user_transform_ptr;
870
0
}
871
#endif
872
873
#ifdef PNG_USER_TRANSFORM_INFO_SUPPORTED
874
png_uint_32 PNGAPI
875
png_get_current_row_number(png_const_structrp png_ptr)
876
0
{
877
   /* See the comments in png.h - this is the sub-image row when reading an
878
    * interlaced image.
879
    */
880
0
   if (png_ptr != NULL)
881
0
      return png_ptr->row_number;
882
883
0
   return PNG_UINT_32_MAX; /* help the app not to fail silently */
884
0
}
885
886
png_byte PNGAPI
887
png_get_current_pass_number(png_const_structrp png_ptr)
888
0
{
889
0
   if (png_ptr != NULL)
890
0
      return png_ptr->pass;
891
0
   return 8; /* invalid */
892
0
}
893
#endif /* USER_TRANSFORM_INFO */
894
#endif /* READ_USER_TRANSFORM || WRITE_USER_TRANSFORM */
895
#endif /* READ || WRITE */