Coverage Report

Created: 2026-01-09 06:32

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/lzma-fuzz/sdk/C/Lzma2Dec.c
Line
Count
Source
1
/* Lzma2Dec.c -- LZMA2 Decoder
2
2019-02-02 : Igor Pavlov : Public domain */
3
4
/* #define SHOW_DEBUG_INFO */
5
6
#include "Precomp.h"
7
8
#ifdef SHOW_DEBUG_INFO
9
#include <stdio.h>
10
#endif
11
12
#include <string.h>
13
14
#include "Lzma2Dec.h"
15
16
/*
17
00000000  -  End of data
18
00000001 U U  -  Uncompressed, reset dic, need reset state and set new prop
19
00000010 U U  -  Uncompressed, no reset
20
100uuuuu U U P P  -  LZMA, no reset
21
101uuuuu U U P P  -  LZMA, reset state
22
110uuuuu U U P P S  -  LZMA, reset state + set new prop
23
111uuuuu U U P P S  -  LZMA, reset state + set new prop, reset dic
24
25
  u, U - Unpack Size
26
  P - Pack Size
27
  S - Props
28
*/
29
30
103k
#define LZMA2_CONTROL_COPY_RESET_DIC 1
31
32
244k
#define LZMA2_IS_UNCOMPRESSED_STATE(p) (((p)->control & (1 << 7)) == 0)
33
34
19.5k
#define LZMA2_LCLP_MAX 4
35
10.5k
#define LZMA2_DIC_SIZE_FROM_PROP(p) (((UInt32)2 | ((p) & 1)) << ((p) / 2 + 11))
36
37
#ifdef SHOW_DEBUG_INFO
38
#define PRF(x) x
39
#else
40
#define PRF(x)
41
#endif
42
43
typedef enum
44
{
45
  LZMA2_STATE_CONTROL,
46
  LZMA2_STATE_UNPACK0,
47
  LZMA2_STATE_UNPACK1,
48
  LZMA2_STATE_PACK0,
49
  LZMA2_STATE_PACK1,
50
  LZMA2_STATE_PROP,
51
  LZMA2_STATE_DATA,
52
  LZMA2_STATE_DATA_CONT,
53
  LZMA2_STATE_FINISHED,
54
  LZMA2_STATE_ERROR
55
} ELzma2State;
56
57
static SRes Lzma2Dec_GetOldProps(Byte prop, Byte *props)
58
5.27k
{
59
5.27k
  UInt32 dicSize;
60
5.27k
  if (prop > 40)
61
0
    return SZ_ERROR_UNSUPPORTED;
62
5.27k
  dicSize = (prop == 40) ? 0xFFFFFFFF : LZMA2_DIC_SIZE_FROM_PROP(prop);
63
5.27k
  props[0] = (Byte)LZMA2_LCLP_MAX;
64
5.27k
  props[1] = (Byte)(dicSize);
65
5.27k
  props[2] = (Byte)(dicSize >> 8);
66
5.27k
  props[3] = (Byte)(dicSize >> 16);
67
5.27k
  props[4] = (Byte)(dicSize >> 24);
68
5.27k
  return SZ_OK;
69
5.27k
}
70
71
SRes Lzma2Dec_AllocateProbs(CLzma2Dec *p, Byte prop, ISzAllocPtr alloc)
72
0
{
73
0
  Byte props[LZMA_PROPS_SIZE];
74
0
  RINOK(Lzma2Dec_GetOldProps(prop, props));
75
0
  return LzmaDec_AllocateProbs(&p->decoder, props, LZMA_PROPS_SIZE, alloc);
76
0
}
77
78
SRes Lzma2Dec_Allocate(CLzma2Dec *p, Byte prop, ISzAllocPtr alloc)
79
5.27k
{
80
5.27k
  Byte props[LZMA_PROPS_SIZE];
81
5.27k
  RINOK(Lzma2Dec_GetOldProps(prop, props));
82
5.27k
  return LzmaDec_Allocate(&p->decoder, props, LZMA_PROPS_SIZE, alloc);
83
5.27k
}
84
85
void Lzma2Dec_Init(CLzma2Dec *p)
86
5.27k
{
87
5.27k
  p->state = LZMA2_STATE_CONTROL;
88
5.27k
  p->needInitLevel = 0xE0;
89
5.27k
  p->isExtraMode = False;
90
5.27k
  p->unpackSize = 0;
91
  
92
  // p->decoder.dicPos = 0; // we can use it instead of full init
93
5.27k
  LzmaDec_Init(&p->decoder);
94
5.27k
}
95
96
static ELzma2State Lzma2Dec_UpdateState(CLzma2Dec *p, Byte b)
97
262k
{
98
262k
  switch (p->state)
99
262k
  {
100
70.4k
    case LZMA2_STATE_CONTROL:
101
70.4k
      p->isExtraMode = False;
102
70.4k
      p->control = b;
103
70.4k
      PRF(printf("\n %8X", (unsigned)p->decoder.dicPos));
104
70.4k
      PRF(printf(" %02X", (unsigned)b));
105
70.4k
      if (b == 0)
106
15
        return LZMA2_STATE_FINISHED;
107
70.4k
      if (LZMA2_IS_UNCOMPRESSED_STATE(p))
108
51.8k
      {
109
51.8k
        if (b == LZMA2_CONTROL_COPY_RESET_DIC)
110
1.52k
          p->needInitLevel = 0xC0;
111
50.3k
        else if (b > 2 || p->needInitLevel == 0xE0)
112
23
          return LZMA2_STATE_ERROR;
113
51.8k
      }
114
18.5k
      else
115
18.5k
      {
116
18.5k
        if (b < p->needInitLevel)
117
6
          return LZMA2_STATE_ERROR;
118
18.5k
        p->needInitLevel = 0;
119
18.5k
        p->unpackSize = (UInt32)(b & 0x1F) << 16;
120
18.5k
      }
121
70.3k
      return LZMA2_STATE_UNPACK0;
122
    
123
70.3k
    case LZMA2_STATE_UNPACK0:
124
70.3k
      p->unpackSize |= (UInt32)b << 8;
125
70.3k
      return LZMA2_STATE_UNPACK1;
126
    
127
70.3k
    case LZMA2_STATE_UNPACK1:
128
70.3k
      p->unpackSize |= (UInt32)b;
129
70.3k
      p->unpackSize++;
130
70.3k
      PRF(printf(" %7u", (unsigned)p->unpackSize));
131
70.3k
      return LZMA2_IS_UNCOMPRESSED_STATE(p) ? LZMA2_STATE_DATA : LZMA2_STATE_PACK0;
132
    
133
18.5k
    case LZMA2_STATE_PACK0:
134
18.5k
      p->packSize = (UInt32)b << 8;
135
18.5k
      return LZMA2_STATE_PACK1;
136
137
18.5k
    case LZMA2_STATE_PACK1:
138
18.5k
      p->packSize |= (UInt32)b;
139
18.5k
      p->packSize++;
140
      // if (p->packSize < 5) return LZMA2_STATE_ERROR;
141
18.5k
      PRF(printf(" %5u", (unsigned)p->packSize));
142
18.5k
      return (p->control & 0x40) ? LZMA2_STATE_PROP : LZMA2_STATE_DATA;
143
144
14.2k
    case LZMA2_STATE_PROP:
145
14.2k
    {
146
14.2k
      unsigned lc, lp;
147
14.2k
      if (b >= (9 * 5 * 5))
148
2
        return LZMA2_STATE_ERROR;
149
14.2k
      lc = b % 9;
150
14.2k
      b /= 9;
151
14.2k
      p->decoder.prop.pb = (Byte)(b / 5);
152
14.2k
      lp = b % 5;
153
14.2k
      if (lc + lp > LZMA2_LCLP_MAX)
154
10
        return LZMA2_STATE_ERROR;
155
14.2k
      p->decoder.prop.lc = (Byte)lc;
156
14.2k
      p->decoder.prop.lp = (Byte)lp;
157
14.2k
      return LZMA2_STATE_DATA;
158
14.2k
    }
159
262k
  }
160
0
  return LZMA2_STATE_ERROR;
161
262k
}
162
163
static void LzmaDec_UpdateWithUncompressed(CLzmaDec *p, const Byte *src, SizeT size)
164
51.9k
{
165
51.9k
  memcpy(p->dic + p->dicPos, src, size);
166
51.9k
  p->dicPos += size;
167
51.9k
  if (p->checkDicSize == 0 && p->prop.dicSize - p->processedPos <= size)
168
135
    p->checkDicSize = p->prop.dicSize;
169
51.9k
  p->processedPos += (UInt32)size;
170
51.9k
}
171
172
void LzmaDec_InitDicAndState(CLzmaDec *p, BoolInt initDic, BoolInt initState);
173
174
175
SRes Lzma2Dec_DecodeToDic(CLzma2Dec *p, SizeT dicLimit,
176
    const Byte *src, SizeT *srcLen, ELzmaFinishMode finishMode, ELzmaStatus *status)
177
24.8k
{
178
24.8k
  SizeT inSize = *srcLen;
179
24.8k
  *srcLen = 0;
180
24.8k
  *status = LZMA_STATUS_NOT_SPECIFIED;
181
182
381k
  while (p->state != LZMA2_STATE_ERROR)
183
381k
  {
184
381k
    SizeT dicPos;
185
186
381k
    if (p->state == LZMA2_STATE_FINISHED)
187
28
    {
188
28
      *status = LZMA_STATUS_FINISHED_WITH_MARK;
189
28
      return SZ_OK;
190
28
    }
191
    
192
381k
    dicPos = p->decoder.dicPos;
193
    
194
381k
    if (dicPos == dicLimit && finishMode == LZMA_FINISH_ANY)
195
16.0k
    {
196
16.0k
      *status = LZMA_STATUS_NOT_FINISHED;
197
16.0k
      return SZ_OK;
198
16.0k
    }
199
200
365k
    if (p->state != LZMA2_STATE_DATA && p->state != LZMA2_STATE_DATA_CONT)
201
262k
    {
202
262k
      if (*srcLen == inSize)
203
201
      {
204
201
        *status = LZMA_STATUS_NEEDS_MORE_INPUT;
205
201
        return SZ_OK;
206
201
      }
207
262k
      (*srcLen)++;
208
262k
      p->state = Lzma2Dec_UpdateState(p, *src++);
209
262k
      if (dicPos == dicLimit && p->state != LZMA2_STATE_FINISHED)
210
0
        break;
211
262k
      continue;
212
262k
    }
213
    
214
103k
    {
215
103k
      SizeT inCur = inSize - *srcLen;
216
103k
      SizeT outCur = dicLimit - dicPos;
217
103k
      ELzmaFinishMode curFinishMode = LZMA_FINISH_ANY;
218
      
219
103k
      if (outCur >= p->unpackSize)
220
80.0k
      {
221
80.0k
        outCur = (SizeT)p->unpackSize;
222
80.0k
        curFinishMode = LZMA_FINISH_END;
223
80.0k
      }
224
225
103k
      if (LZMA2_IS_UNCOMPRESSED_STATE(p))
226
52.1k
      {
227
52.1k
        if (inCur == 0)
228
225
        {
229
225
          *status = LZMA_STATUS_NEEDS_MORE_INPUT;
230
225
          return SZ_OK;
231
225
        }
232
233
51.9k
        if (p->state == LZMA2_STATE_DATA)
234
51.7k
        {
235
51.7k
          BoolInt initDic = (p->control == LZMA2_CONTROL_COPY_RESET_DIC);
236
51.7k
          LzmaDec_InitDicAndState(&p->decoder, initDic, False);
237
51.7k
        }
238
239
51.9k
        if (inCur > outCur)
240
51.8k
          inCur = outCur;
241
51.9k
        if (inCur == 0)
242
0
          break;
243
244
51.9k
        LzmaDec_UpdateWithUncompressed(&p->decoder, src, inCur);
245
246
51.9k
        src += inCur;
247
51.9k
        *srcLen += inCur;
248
51.9k
        p->unpackSize -= (UInt32)inCur;
249
51.9k
        p->state = (p->unpackSize == 0) ? LZMA2_STATE_CONTROL : LZMA2_STATE_DATA_CONT;
250
51.9k
      }
251
51.1k
      else
252
51.1k
      {
253
51.1k
        SRes res;
254
255
51.1k
        if (p->state == LZMA2_STATE_DATA)
256
18.4k
        {
257
18.4k
          BoolInt initDic = (p->control >= 0xE0);
258
18.4k
          BoolInt initState = (p->control >= 0xA0);
259
18.4k
          LzmaDec_InitDicAndState(&p->decoder, initDic, initState);
260
18.4k
          p->state = LZMA2_STATE_DATA_CONT;
261
18.4k
        }
262
  
263
51.1k
        if (inCur > p->packSize)
264
29.0k
          inCur = (SizeT)p->packSize;
265
        
266
51.1k
        res = LzmaDec_DecodeToDic(&p->decoder, dicPos + outCur, src, &inCur, curFinishMode, status);
267
268
51.1k
        src += inCur;
269
51.1k
        *srcLen += inCur;
270
51.1k
        p->packSize -= (UInt32)inCur;
271
51.1k
        outCur = p->decoder.dicPos - dicPos;
272
51.1k
        p->unpackSize -= (UInt32)outCur;
273
274
51.1k
        if (res != 0)
275
1.03k
          break;
276
        
277
50.0k
        if (*status == LZMA_STATUS_NEEDS_MORE_INPUT)
278
7.22k
        {
279
7.22k
          if (p->packSize == 0)
280
86
            break;
281
7.14k
          return SZ_OK;
282
7.22k
        }
283
284
42.8k
        if (inCur == 0 && outCur == 0)
285
13.5k
        {
286
13.5k
          if (*status != LZMA_STATUS_MAYBE_FINISHED_WITHOUT_MARK
287
13.5k
              || p->unpackSize != 0
288
13.5k
              || p->packSize != 0)
289
36
            break;
290
13.5k
          p->state = LZMA2_STATE_CONTROL;
291
13.5k
        }
292
        
293
42.8k
        *status = LZMA_STATUS_NOT_SPECIFIED;
294
42.8k
      }
295
103k
    }
296
103k
  }
297
  
298
1.20k
  *status = LZMA_STATUS_NOT_SPECIFIED;
299
1.20k
  p->state = LZMA2_STATE_ERROR;
300
1.20k
  return SZ_ERROR_DATA;
301
24.8k
}
302
303
304
305
306
ELzma2ParseStatus Lzma2Dec_Parse(CLzma2Dec *p,
307
    SizeT outSize,
308
    const Byte *src, SizeT *srcLen,
309
    int checkFinishBlock)
310
0
{
311
0
  SizeT inSize = *srcLen;
312
0
  *srcLen = 0;
313
314
0
  while (p->state != LZMA2_STATE_ERROR)
315
0
  {
316
0
    if (p->state == LZMA2_STATE_FINISHED)
317
0
      return (ELzma2ParseStatus)LZMA_STATUS_FINISHED_WITH_MARK;
318
319
0
    if (outSize == 0 && !checkFinishBlock)
320
0
      return (ELzma2ParseStatus)LZMA_STATUS_NOT_FINISHED;
321
    
322
0
    if (p->state != LZMA2_STATE_DATA && p->state != LZMA2_STATE_DATA_CONT)
323
0
    {
324
0
      if (*srcLen == inSize)
325
0
        return (ELzma2ParseStatus)LZMA_STATUS_NEEDS_MORE_INPUT;
326
0
      (*srcLen)++;
327
328
0
      p->state = Lzma2Dec_UpdateState(p, *src++);
329
330
0
      if (p->state == LZMA2_STATE_UNPACK0)
331
0
      {
332
        // if (p->decoder.dicPos != 0)
333
0
        if (p->control == LZMA2_CONTROL_COPY_RESET_DIC || p->control >= 0xE0)
334
0
          return LZMA2_PARSE_STATUS_NEW_BLOCK;
335
        // if (outSize == 0) return LZMA_STATUS_NOT_FINISHED;
336
0
      }
337
338
      // The following code can be commented.
339
      // It's not big problem, if we read additional input bytes.
340
      // It will be stopped later in LZMA2_STATE_DATA / LZMA2_STATE_DATA_CONT state.
341
342
0
      if (outSize == 0 && p->state != LZMA2_STATE_FINISHED)
343
0
      {
344
        // checkFinishBlock is true. So we expect that block must be finished,
345
        // We can return LZMA_STATUS_NOT_SPECIFIED or LZMA_STATUS_NOT_FINISHED here
346
        // break;
347
0
        return (ELzma2ParseStatus)LZMA_STATUS_NOT_FINISHED;
348
0
      }
349
350
0
      if (p->state == LZMA2_STATE_DATA)
351
0
        return LZMA2_PARSE_STATUS_NEW_CHUNK;
352
353
0
      continue;
354
0
    }
355
356
0
    if (outSize == 0)
357
0
      return (ELzma2ParseStatus)LZMA_STATUS_NOT_FINISHED;
358
359
0
    {
360
0
      SizeT inCur = inSize - *srcLen;
361
362
0
      if (LZMA2_IS_UNCOMPRESSED_STATE(p))
363
0
      {
364
0
        if (inCur == 0)
365
0
          return (ELzma2ParseStatus)LZMA_STATUS_NEEDS_MORE_INPUT;
366
0
        if (inCur > p->unpackSize)
367
0
          inCur = p->unpackSize;
368
0
        if (inCur > outSize)
369
0
          inCur = outSize;
370
0
        p->decoder.dicPos += inCur;
371
0
        src += inCur;
372
0
        *srcLen += inCur;
373
0
        outSize -= inCur;
374
0
        p->unpackSize -= (UInt32)inCur;
375
0
        p->state = (p->unpackSize == 0) ? LZMA2_STATE_CONTROL : LZMA2_STATE_DATA_CONT;
376
0
      }
377
0
      else
378
0
      {
379
0
        p->isExtraMode = True;
380
381
0
        if (inCur == 0)
382
0
        {
383
0
          if (p->packSize != 0)
384
0
            return (ELzma2ParseStatus)LZMA_STATUS_NEEDS_MORE_INPUT;
385
0
        }
386
0
        else if (p->state == LZMA2_STATE_DATA)
387
0
        {
388
0
          p->state = LZMA2_STATE_DATA_CONT;
389
0
          if (*src != 0)
390
0
          {
391
            // first byte of lzma chunk must be Zero
392
0
            *srcLen += 1;
393
0
            p->packSize--;
394
0
            break;
395
0
          }
396
0
        }
397
  
398
0
        if (inCur > p->packSize)
399
0
          inCur = (SizeT)p->packSize;
400
401
0
        src += inCur;
402
0
        *srcLen += inCur;
403
0
        p->packSize -= (UInt32)inCur;
404
405
0
        if (p->packSize == 0)
406
0
        {
407
0
          SizeT rem = outSize;
408
0
          if (rem > p->unpackSize)
409
0
            rem = p->unpackSize;
410
0
          p->decoder.dicPos += rem;
411
0
          p->unpackSize -= (UInt32)rem;
412
0
          outSize -= rem;
413
0
          if (p->unpackSize == 0)
414
0
            p->state = LZMA2_STATE_CONTROL;
415
0
        }
416
0
      }
417
0
    }
418
0
  }
419
  
420
0
  p->state = LZMA2_STATE_ERROR;
421
0
  return (ELzma2ParseStatus)LZMA_STATUS_NOT_SPECIFIED;
422
0
}
423
424
425
426
427
SRes Lzma2Dec_DecodeToBuf(CLzma2Dec *p, Byte *dest, SizeT *destLen, const Byte *src, SizeT *srcLen, ELzmaFinishMode finishMode, ELzmaStatus *status)
428
17.9k
{
429
17.9k
  SizeT outSize = *destLen, inSize = *srcLen;
430
17.9k
  *srcLen = *destLen = 0;
431
  
432
17.9k
  for (;;)
433
24.8k
  {
434
24.8k
    SizeT inCur = inSize, outCur, dicPos;
435
24.8k
    ELzmaFinishMode curFinishMode;
436
24.8k
    SRes res;
437
    
438
24.8k
    if (p->decoder.dicPos == p->decoder.dicBufSize)
439
6.51k
      p->decoder.dicPos = 0;
440
24.8k
    dicPos = p->decoder.dicPos;
441
24.8k
    curFinishMode = LZMA_FINISH_ANY;
442
24.8k
    outCur = p->decoder.dicBufSize - dicPos;
443
    
444
24.8k
    if (outCur >= outSize)
445
19.4k
    {
446
19.4k
      outCur = outSize;
447
19.4k
      curFinishMode = finishMode;
448
19.4k
    }
449
450
24.8k
    res = Lzma2Dec_DecodeToDic(p, dicPos + outCur, src, &inCur, curFinishMode, status);
451
    
452
24.8k
    src += inCur;
453
24.8k
    inSize -= inCur;
454
24.8k
    *srcLen += inCur;
455
24.8k
    outCur = p->decoder.dicPos - dicPos;
456
24.8k
    memcpy(dest, p->decoder.dic + dicPos, outCur);
457
24.8k
    dest += outCur;
458
24.8k
    outSize -= outCur;
459
24.8k
    *destLen += outCur;
460
24.8k
    if (res != 0)
461
1.20k
      return res;
462
23.6k
    if (outCur == 0 || outSize == 0)
463
16.7k
      return SZ_OK;
464
23.6k
  }
465
17.9k
}
466
467
468
SRes Lzma2Decode(Byte *dest, SizeT *destLen, const Byte *src, SizeT *srcLen,
469
    Byte prop, ELzmaFinishMode finishMode, ELzmaStatus *status, ISzAllocPtr alloc)
470
0
{
471
0
  CLzma2Dec p;
472
0
  SRes res;
473
0
  SizeT outSize = *destLen, inSize = *srcLen;
474
0
  *destLen = *srcLen = 0;
475
0
  *status = LZMA_STATUS_NOT_SPECIFIED;
476
0
  Lzma2Dec_Construct(&p);
477
0
  RINOK(Lzma2Dec_AllocateProbs(&p, prop, alloc));
478
0
  p.decoder.dic = dest;
479
0
  p.decoder.dicBufSize = outSize;
480
0
  Lzma2Dec_Init(&p);
481
0
  *srcLen = inSize;
482
0
  res = Lzma2Dec_DecodeToDic(&p, outSize, src, srcLen, finishMode, status);
483
0
  *destLen = p.decoder.dicPos;
484
0
  if (res == SZ_OK && *status == LZMA_STATUS_NEEDS_MORE_INPUT)
485
0
    res = SZ_ERROR_INPUT_EOF;
486
0
  Lzma2Dec_FreeProbs(&p, alloc);
487
0
  return res;
488
0
}