Coverage Report

Created: 2025-12-31 06:48

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/gdal/frmts/gtiff/libtiff/tif_dirread.c
Line
Count
Source
1
/*
2
 * Copyright (c) 1988-1997 Sam Leffler
3
 * Copyright (c) 1991-1997 Silicon Graphics, Inc.
4
 *
5
 * Permission to use, copy, modify, distribute, and sell this software and
6
 * its documentation for any purpose is hereby granted without fee, provided
7
 * that (i) the above copyright notices and this permission notice appear in
8
 * all copies of the software and related documentation, and (ii) the names of
9
 * Sam Leffler and Silicon Graphics may not be used in any advertising or
10
 * publicity relating to the software without the specific, prior written
11
 * permission of Sam Leffler and Silicon Graphics.
12
 *
13
 * THE SOFTWARE IS PROVIDED "AS-IS" AND WITHOUT WARRANTY OF ANY KIND,
14
 * EXPRESS, IMPLIED OR OTHERWISE, INCLUDING WITHOUT LIMITATION, ANY
15
 * WARRANTY OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.
16
 *
17
 * IN NO EVENT SHALL SAM LEFFLER OR SILICON GRAPHICS BE LIABLE FOR
18
 * ANY SPECIAL, INCIDENTAL, INDIRECT OR CONSEQUENTIAL DAMAGES OF ANY KIND,
19
 * OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS,
20
 * WHETHER OR NOT ADVISED OF THE POSSIBILITY OF DAMAGE, AND ON ANY THEORY OF
21
 * LIABILITY, ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE
22
 * OF THIS SOFTWARE.
23
 */
24
25
/*
26
 * TIFF Library.
27
 *
28
 * Directory Read Support Routines.
29
 */
30
31
/* Suggested pending improvements:
32
 * - add a field 'field_info' to the TIFFDirEntry structure, and set that with
33
 *   the pointer to the appropriate TIFFField structure early on in
34
 *   TIFFReadDirectory, so as to eliminate current possibly repetitive lookup.
35
 */
36
37
#include "tiffconf.h"
38
#include "tiffiop.h"
39
#include <float.h>
40
#include <limits.h>
41
#include <stdlib.h>
42
#include <string.h>
43
44
0
#define FAILED_FII ((uint32_t)-1)
45
46
#ifdef HAVE_IEEEFP
47
#define TIFFCvtIEEEFloatToNative(tif, n, fp)
48
#define TIFFCvtIEEEDoubleToNative(tif, n, dp)
49
#else
50
/* If your machine does not support IEEE floating point then you will need to
51
 * add support to tif_machdep.c to convert between the native format and
52
 * IEEE format. */
53
extern void TIFFCvtIEEEFloatToNative(TIFF *, uint32_t, float *);
54
extern void TIFFCvtIEEEDoubleToNative(TIFF *, uint32_t, double *);
55
#endif
56
57
enum TIFFReadDirEntryErr
58
{
59
    TIFFReadDirEntryErrOk = 0,
60
    TIFFReadDirEntryErrCount = 1,
61
    TIFFReadDirEntryErrType = 2,
62
    TIFFReadDirEntryErrIo = 3,
63
    TIFFReadDirEntryErrRange = 4,
64
    TIFFReadDirEntryErrPsdif = 5,
65
    TIFFReadDirEntryErrSizesan = 6,
66
    TIFFReadDirEntryErrAlloc = 7,
67
};
68
69
static enum TIFFReadDirEntryErr
70
TIFFReadDirEntryByte(TIFF *tif, TIFFDirEntry *direntry, uint8_t *value);
71
static enum TIFFReadDirEntryErr
72
TIFFReadDirEntrySbyte(TIFF *tif, TIFFDirEntry *direntry, int8_t *value);
73
static enum TIFFReadDirEntryErr
74
TIFFReadDirEntryShort(TIFF *tif, TIFFDirEntry *direntry, uint16_t *value);
75
static enum TIFFReadDirEntryErr
76
TIFFReadDirEntrySshort(TIFF *tif, TIFFDirEntry *direntry, int16_t *value);
77
static enum TIFFReadDirEntryErr
78
TIFFReadDirEntryLong(TIFF *tif, TIFFDirEntry *direntry, uint32_t *value);
79
static enum TIFFReadDirEntryErr
80
TIFFReadDirEntrySlong(TIFF *tif, TIFFDirEntry *direntry, int32_t *value);
81
static enum TIFFReadDirEntryErr
82
TIFFReadDirEntryLong8(TIFF *tif, TIFFDirEntry *direntry, uint64_t *value);
83
static enum TIFFReadDirEntryErr
84
TIFFReadDirEntrySlong8(TIFF *tif, TIFFDirEntry *direntry, int64_t *value);
85
static enum TIFFReadDirEntryErr
86
TIFFReadDirEntryFloat(TIFF *tif, TIFFDirEntry *direntry, float *value);
87
static enum TIFFReadDirEntryErr
88
TIFFReadDirEntryDouble(TIFF *tif, TIFFDirEntry *direntry, double *value);
89
static enum TIFFReadDirEntryErr
90
TIFFReadDirEntryIfd8(TIFF *tif, TIFFDirEntry *direntry, uint64_t *value);
91
92
static enum TIFFReadDirEntryErr
93
TIFFReadDirEntryArray(TIFF *tif, TIFFDirEntry *direntry, uint32_t *count,
94
                      uint32_t desttypesize, void **value);
95
static enum TIFFReadDirEntryErr
96
TIFFReadDirEntryByteArray(TIFF *tif, TIFFDirEntry *direntry, uint8_t **value);
97
static enum TIFFReadDirEntryErr
98
TIFFReadDirEntrySbyteArray(TIFF *tif, TIFFDirEntry *direntry, int8_t **value);
99
static enum TIFFReadDirEntryErr
100
TIFFReadDirEntryShortArray(TIFF *tif, TIFFDirEntry *direntry, uint16_t **value);
101
static enum TIFFReadDirEntryErr
102
TIFFReadDirEntrySshortArray(TIFF *tif, TIFFDirEntry *direntry, int16_t **value);
103
static enum TIFFReadDirEntryErr
104
TIFFReadDirEntryLongArray(TIFF *tif, TIFFDirEntry *direntry, uint32_t **value);
105
static enum TIFFReadDirEntryErr
106
TIFFReadDirEntrySlongArray(TIFF *tif, TIFFDirEntry *direntry, int32_t **value);
107
static enum TIFFReadDirEntryErr
108
TIFFReadDirEntryLong8Array(TIFF *tif, TIFFDirEntry *direntry, uint64_t **value);
109
static enum TIFFReadDirEntryErr
110
TIFFReadDirEntrySlong8Array(TIFF *tif, TIFFDirEntry *direntry, int64_t **value);
111
static enum TIFFReadDirEntryErr
112
TIFFReadDirEntryFloatArray(TIFF *tif, TIFFDirEntry *direntry, float **value);
113
static enum TIFFReadDirEntryErr
114
TIFFReadDirEntryDoubleArray(TIFF *tif, TIFFDirEntry *direntry, double **value);
115
static enum TIFFReadDirEntryErr
116
TIFFReadDirEntryIfd8Array(TIFF *tif, TIFFDirEntry *direntry, uint64_t **value);
117
118
static enum TIFFReadDirEntryErr
119
TIFFReadDirEntryPersampleShort(TIFF *tif, TIFFDirEntry *direntry,
120
                               uint16_t *value);
121
122
static void TIFFReadDirEntryCheckedByte(TIFF *tif, TIFFDirEntry *direntry,
123
                                        uint8_t *value);
124
static void TIFFReadDirEntryCheckedSbyte(TIFF *tif, TIFFDirEntry *direntry,
125
                                         int8_t *value);
126
static void TIFFReadDirEntryCheckedShort(TIFF *tif, TIFFDirEntry *direntry,
127
                                         uint16_t *value);
128
static void TIFFReadDirEntryCheckedSshort(TIFF *tif, TIFFDirEntry *direntry,
129
                                          int16_t *value);
130
static void TIFFReadDirEntryCheckedLong(TIFF *tif, TIFFDirEntry *direntry,
131
                                        uint32_t *value);
132
static void TIFFReadDirEntryCheckedSlong(TIFF *tif, TIFFDirEntry *direntry,
133
                                         int32_t *value);
134
static enum TIFFReadDirEntryErr
135
TIFFReadDirEntryCheckedLong8(TIFF *tif, TIFFDirEntry *direntry,
136
                             uint64_t *value);
137
static enum TIFFReadDirEntryErr
138
TIFFReadDirEntryCheckedSlong8(TIFF *tif, TIFFDirEntry *direntry,
139
                              int64_t *value);
140
static enum TIFFReadDirEntryErr
141
TIFFReadDirEntryCheckedRational(TIFF *tif, TIFFDirEntry *direntry,
142
                                double *value);
143
static enum TIFFReadDirEntryErr
144
TIFFReadDirEntryCheckedSrational(TIFF *tif, TIFFDirEntry *direntry,
145
                                 double *value);
146
static void TIFFReadDirEntryCheckedFloat(TIFF *tif, TIFFDirEntry *direntry,
147
                                         float *value);
148
static enum TIFFReadDirEntryErr
149
TIFFReadDirEntryCheckedDouble(TIFF *tif, TIFFDirEntry *direntry, double *value);
150
#if 0
151
static enum TIFFReadDirEntryErr
152
TIFFReadDirEntryCheckedRationalDirect(TIFF *tif, TIFFDirEntry *direntry,
153
                                      TIFFRational_t *value);
154
#endif
155
static enum TIFFReadDirEntryErr
156
TIFFReadDirEntryCheckRangeByteSbyte(int8_t value);
157
static enum TIFFReadDirEntryErr
158
TIFFReadDirEntryCheckRangeByteShort(uint16_t value);
159
static enum TIFFReadDirEntryErr
160
TIFFReadDirEntryCheckRangeByteSshort(int16_t value);
161
static enum TIFFReadDirEntryErr
162
TIFFReadDirEntryCheckRangeByteLong(uint32_t value);
163
static enum TIFFReadDirEntryErr
164
TIFFReadDirEntryCheckRangeByteSlong(int32_t value);
165
static enum TIFFReadDirEntryErr
166
TIFFReadDirEntryCheckRangeByteLong8(uint64_t value);
167
static enum TIFFReadDirEntryErr
168
TIFFReadDirEntryCheckRangeByteSlong8(int64_t value);
169
170
static enum TIFFReadDirEntryErr
171
TIFFReadDirEntryCheckRangeSbyteByte(uint8_t value);
172
static enum TIFFReadDirEntryErr
173
TIFFReadDirEntryCheckRangeSbyteShort(uint16_t value);
174
static enum TIFFReadDirEntryErr
175
TIFFReadDirEntryCheckRangeSbyteSshort(int16_t value);
176
static enum TIFFReadDirEntryErr
177
TIFFReadDirEntryCheckRangeSbyteLong(uint32_t value);
178
static enum TIFFReadDirEntryErr
179
TIFFReadDirEntryCheckRangeSbyteSlong(int32_t value);
180
static enum TIFFReadDirEntryErr
181
TIFFReadDirEntryCheckRangeSbyteLong8(uint64_t value);
182
static enum TIFFReadDirEntryErr
183
TIFFReadDirEntryCheckRangeSbyteSlong8(int64_t value);
184
185
static enum TIFFReadDirEntryErr
186
TIFFReadDirEntryCheckRangeShortSbyte(int8_t value);
187
static enum TIFFReadDirEntryErr
188
TIFFReadDirEntryCheckRangeShortSshort(int16_t value);
189
static enum TIFFReadDirEntryErr
190
TIFFReadDirEntryCheckRangeShortLong(uint32_t value);
191
static enum TIFFReadDirEntryErr
192
TIFFReadDirEntryCheckRangeShortSlong(int32_t value);
193
static enum TIFFReadDirEntryErr
194
TIFFReadDirEntryCheckRangeShortLong8(uint64_t value);
195
static enum TIFFReadDirEntryErr
196
TIFFReadDirEntryCheckRangeShortSlong8(int64_t value);
197
198
static enum TIFFReadDirEntryErr
199
TIFFReadDirEntryCheckRangeSshortShort(uint16_t value);
200
static enum TIFFReadDirEntryErr
201
TIFFReadDirEntryCheckRangeSshortLong(uint32_t value);
202
static enum TIFFReadDirEntryErr
203
TIFFReadDirEntryCheckRangeSshortSlong(int32_t value);
204
static enum TIFFReadDirEntryErr
205
TIFFReadDirEntryCheckRangeSshortLong8(uint64_t value);
206
static enum TIFFReadDirEntryErr
207
TIFFReadDirEntryCheckRangeSshortSlong8(int64_t value);
208
209
static enum TIFFReadDirEntryErr
210
TIFFReadDirEntryCheckRangeLongSbyte(int8_t value);
211
static enum TIFFReadDirEntryErr
212
TIFFReadDirEntryCheckRangeLongSshort(int16_t value);
213
static enum TIFFReadDirEntryErr
214
TIFFReadDirEntryCheckRangeLongSlong(int32_t value);
215
static enum TIFFReadDirEntryErr
216
TIFFReadDirEntryCheckRangeLongLong8(uint64_t value);
217
static enum TIFFReadDirEntryErr
218
TIFFReadDirEntryCheckRangeLongSlong8(int64_t value);
219
220
static enum TIFFReadDirEntryErr
221
TIFFReadDirEntryCheckRangeSlongLong(uint32_t value);
222
static enum TIFFReadDirEntryErr
223
TIFFReadDirEntryCheckRangeSlongLong8(uint64_t value);
224
static enum TIFFReadDirEntryErr
225
TIFFReadDirEntryCheckRangeSlongSlong8(int64_t value);
226
227
static enum TIFFReadDirEntryErr
228
TIFFReadDirEntryCheckRangeLong8Sbyte(int8_t value);
229
static enum TIFFReadDirEntryErr
230
TIFFReadDirEntryCheckRangeLong8Sshort(int16_t value);
231
static enum TIFFReadDirEntryErr
232
TIFFReadDirEntryCheckRangeLong8Slong(int32_t value);
233
static enum TIFFReadDirEntryErr
234
TIFFReadDirEntryCheckRangeLong8Slong8(int64_t value);
235
236
static enum TIFFReadDirEntryErr
237
TIFFReadDirEntryCheckRangeSlong8Long8(uint64_t value);
238
239
static enum TIFFReadDirEntryErr TIFFReadDirEntryData(TIFF *tif, uint64_t offset,
240
                                                     tmsize_t size, void *dest);
241
static void TIFFReadDirEntryOutputErr(TIFF *tif, enum TIFFReadDirEntryErr err,
242
                                      const char *module, const char *tagname,
243
                                      int recover);
244
245
static void TIFFReadDirectoryCheckOrder(TIFF *tif, TIFFDirEntry *dir,
246
                                        uint16_t dircount);
247
static TIFFDirEntry *TIFFReadDirectoryFindEntry(TIFF *tif, TIFFDirEntry *dir,
248
                                                uint16_t dircount,
249
                                                uint16_t tagid);
250
static void TIFFReadDirectoryFindFieldInfo(TIFF *tif, uint16_t tagid,
251
                                           uint32_t *fii);
252
253
static int EstimateStripByteCounts(TIFF *tif, TIFFDirEntry *dir,
254
                                   uint16_t dircount);
255
static void MissingRequired(TIFF *, const char *);
256
static int CheckDirCount(TIFF *, TIFFDirEntry *, uint32_t);
257
static uint16_t TIFFFetchDirectory(TIFF *tif, uint64_t diroff,
258
                                   TIFFDirEntry **pdir, uint64_t *nextdiroff);
259
static int TIFFFetchNormalTag(TIFF *, TIFFDirEntry *, int recover);
260
static int TIFFFetchStripThing(TIFF *tif, TIFFDirEntry *dir, uint32_t nstrips,
261
                               uint64_t **lpp);
262
static int TIFFFetchSubjectDistance(TIFF *, TIFFDirEntry *);
263
static void ChopUpSingleUncompressedStrip(TIFF *);
264
static void TryChopUpUncompressedBigTiff(TIFF *);
265
static uint64_t TIFFReadUInt64(const uint8_t *value);
266
static int _TIFFGetMaxColorChannels(uint16_t photometric);
267
268
static int _TIFFFillStrilesInternal(TIFF *tif, int loadStripByteCount);
269
270
typedef union _UInt64Aligned_t
271
{
272
    double d;
273
    uint64_t l;
274
    uint32_t i[2];
275
    uint16_t s[4];
276
    uint8_t c[8];
277
} UInt64Aligned_t;
278
279
/*
280
  Unaligned safe copy of a uint64_t value from an octet array.
281
*/
282
static uint64_t TIFFReadUInt64(const uint8_t *value)
283
0
{
284
0
    UInt64Aligned_t result;
285
286
0
    result.c[0] = value[0];
287
0
    result.c[1] = value[1];
288
0
    result.c[2] = value[2];
289
0
    result.c[3] = value[3];
290
0
    result.c[4] = value[4];
291
0
    result.c[5] = value[5];
292
0
    result.c[6] = value[6];
293
0
    result.c[7] = value[7];
294
295
0
    return result.l;
296
0
}
297
298
static enum TIFFReadDirEntryErr
299
TIFFReadDirEntryByte(TIFF *tif, TIFFDirEntry *direntry, uint8_t *value)
300
0
{
301
0
    enum TIFFReadDirEntryErr err;
302
0
    if (direntry->tdir_count != 1)
303
0
        return (TIFFReadDirEntryErrCount);
304
0
    switch (direntry->tdir_type)
305
0
    {
306
0
        case TIFF_BYTE:
307
0
        case TIFF_UNDEFINED: /* Support to read TIFF_UNDEFINED with
308
                                field_readcount==1 */
309
0
            TIFFReadDirEntryCheckedByte(tif, direntry, value);
310
0
            return (TIFFReadDirEntryErrOk);
311
0
        case TIFF_SBYTE:
312
0
        {
313
0
            int8_t m;
314
0
            TIFFReadDirEntryCheckedSbyte(tif, direntry, &m);
315
0
            err = TIFFReadDirEntryCheckRangeByteSbyte(m);
316
0
            if (err != TIFFReadDirEntryErrOk)
317
0
                return (err);
318
0
            *value = (uint8_t)m;
319
0
            return (TIFFReadDirEntryErrOk);
320
0
        }
321
0
        case TIFF_SHORT:
322
0
        {
323
0
            uint16_t m;
324
0
            TIFFReadDirEntryCheckedShort(tif, direntry, &m);
325
0
            err = TIFFReadDirEntryCheckRangeByteShort(m);
326
0
            if (err != TIFFReadDirEntryErrOk)
327
0
                return (err);
328
0
            *value = (uint8_t)m;
329
0
            return (TIFFReadDirEntryErrOk);
330
0
        }
331
0
        case TIFF_SSHORT:
332
0
        {
333
0
            int16_t m;
334
0
            TIFFReadDirEntryCheckedSshort(tif, direntry, &m);
335
0
            err = TIFFReadDirEntryCheckRangeByteSshort(m);
336
0
            if (err != TIFFReadDirEntryErrOk)
337
0
                return (err);
338
0
            *value = (uint8_t)m;
339
0
            return (TIFFReadDirEntryErrOk);
340
0
        }
341
0
        case TIFF_LONG:
342
0
        {
343
0
            uint32_t m;
344
0
            TIFFReadDirEntryCheckedLong(tif, direntry, &m);
345
0
            err = TIFFReadDirEntryCheckRangeByteLong(m);
346
0
            if (err != TIFFReadDirEntryErrOk)
347
0
                return (err);
348
0
            *value = (uint8_t)m;
349
0
            return (TIFFReadDirEntryErrOk);
350
0
        }
351
0
        case TIFF_SLONG:
352
0
        {
353
0
            int32_t m;
354
0
            TIFFReadDirEntryCheckedSlong(tif, direntry, &m);
355
0
            err = TIFFReadDirEntryCheckRangeByteSlong(m);
356
0
            if (err != TIFFReadDirEntryErrOk)
357
0
                return (err);
358
0
            *value = (uint8_t)m;
359
0
            return (TIFFReadDirEntryErrOk);
360
0
        }
361
0
        case TIFF_LONG8:
362
0
        {
363
0
            uint64_t m;
364
0
            err = TIFFReadDirEntryCheckedLong8(tif, direntry, &m);
365
0
            if (err != TIFFReadDirEntryErrOk)
366
0
                return (err);
367
0
            err = TIFFReadDirEntryCheckRangeByteLong8(m);
368
0
            if (err != TIFFReadDirEntryErrOk)
369
0
                return (err);
370
0
            *value = (uint8_t)m;
371
0
            return (TIFFReadDirEntryErrOk);
372
0
        }
373
0
        case TIFF_SLONG8:
374
0
        {
375
0
            int64_t m;
376
0
            err = TIFFReadDirEntryCheckedSlong8(tif, direntry, &m);
377
0
            if (err != TIFFReadDirEntryErrOk)
378
0
                return (err);
379
0
            err = TIFFReadDirEntryCheckRangeByteSlong8(m);
380
0
            if (err != TIFFReadDirEntryErrOk)
381
0
                return (err);
382
0
            *value = (uint8_t)m;
383
0
            return (TIFFReadDirEntryErrOk);
384
0
        }
385
0
        default:
386
0
            return (TIFFReadDirEntryErrType);
387
0
    }
388
0
}
389
390
static enum TIFFReadDirEntryErr
391
TIFFReadDirEntrySbyte(TIFF *tif, TIFFDirEntry *direntry, int8_t *value)
392
0
{
393
0
    enum TIFFReadDirEntryErr err;
394
0
    if (direntry->tdir_count != 1)
395
0
        return (TIFFReadDirEntryErrCount);
396
0
    switch (direntry->tdir_type)
397
0
    {
398
0
        case TIFF_BYTE:
399
0
        case TIFF_UNDEFINED: /* Support to read TIFF_UNDEFINED with
400
                                field_readcount==1 */
401
0
        {
402
0
            uint8_t m;
403
0
            TIFFReadDirEntryCheckedByte(tif, direntry, &m);
404
0
            err = TIFFReadDirEntryCheckRangeSbyteByte(m);
405
0
            if (err != TIFFReadDirEntryErrOk)
406
0
                return (err);
407
0
            *value = (int8_t)m;
408
0
            return (TIFFReadDirEntryErrOk);
409
0
        }
410
0
        case TIFF_SBYTE:
411
0
        {
412
0
            TIFFReadDirEntryCheckedSbyte(tif, direntry, value);
413
0
            return (TIFFReadDirEntryErrOk);
414
0
        }
415
0
        case TIFF_SHORT:
416
0
        {
417
0
            uint16_t m;
418
0
            TIFFReadDirEntryCheckedShort(tif, direntry, &m);
419
0
            err = TIFFReadDirEntryCheckRangeSbyteShort(m);
420
0
            if (err != TIFFReadDirEntryErrOk)
421
0
                return (err);
422
0
            *value = (int8_t)m;
423
0
            return (TIFFReadDirEntryErrOk);
424
0
        }
425
0
        case TIFF_SSHORT:
426
0
        {
427
0
            int16_t m;
428
0
            TIFFReadDirEntryCheckedSshort(tif, direntry, &m);
429
0
            err = TIFFReadDirEntryCheckRangeSbyteSshort(m);
430
0
            if (err != TIFFReadDirEntryErrOk)
431
0
                return (err);
432
0
            *value = (int8_t)m;
433
0
            return (TIFFReadDirEntryErrOk);
434
0
        }
435
0
        case TIFF_LONG:
436
0
        {
437
0
            uint32_t m;
438
0
            TIFFReadDirEntryCheckedLong(tif, direntry, &m);
439
0
            err = TIFFReadDirEntryCheckRangeSbyteLong(m);
440
0
            if (err != TIFFReadDirEntryErrOk)
441
0
                return (err);
442
0
            *value = (int8_t)m;
443
0
            return (TIFFReadDirEntryErrOk);
444
0
        }
445
0
        case TIFF_SLONG:
446
0
        {
447
0
            int32_t m;
448
0
            TIFFReadDirEntryCheckedSlong(tif, direntry, &m);
449
0
            err = TIFFReadDirEntryCheckRangeSbyteSlong(m);
450
0
            if (err != TIFFReadDirEntryErrOk)
451
0
                return (err);
452
0
            *value = (int8_t)m;
453
0
            return (TIFFReadDirEntryErrOk);
454
0
        }
455
0
        case TIFF_LONG8:
456
0
        {
457
0
            uint64_t m;
458
0
            err = TIFFReadDirEntryCheckedLong8(tif, direntry, &m);
459
0
            if (err != TIFFReadDirEntryErrOk)
460
0
                return (err);
461
0
            err = TIFFReadDirEntryCheckRangeSbyteLong8(m);
462
0
            if (err != TIFFReadDirEntryErrOk)
463
0
                return (err);
464
0
            *value = (int8_t)m;
465
0
            return (TIFFReadDirEntryErrOk);
466
0
        }
467
0
        case TIFF_SLONG8:
468
0
        {
469
0
            int64_t m;
470
0
            err = TIFFReadDirEntryCheckedSlong8(tif, direntry, &m);
471
0
            if (err != TIFFReadDirEntryErrOk)
472
0
                return (err);
473
0
            err = TIFFReadDirEntryCheckRangeSbyteSlong8(m);
474
0
            if (err != TIFFReadDirEntryErrOk)
475
0
                return (err);
476
0
            *value = (int8_t)m;
477
0
            return (TIFFReadDirEntryErrOk);
478
0
        }
479
0
        default:
480
0
            return (TIFFReadDirEntryErrType);
481
0
    }
482
0
} /*-- TIFFReadDirEntrySbyte() --*/
483
484
static enum TIFFReadDirEntryErr
485
TIFFReadDirEntryShort(TIFF *tif, TIFFDirEntry *direntry, uint16_t *value)
486
0
{
487
0
    enum TIFFReadDirEntryErr err;
488
0
    if (direntry->tdir_count != 1)
489
0
        return (TIFFReadDirEntryErrCount);
490
0
    switch (direntry->tdir_type)
491
0
    {
492
0
        case TIFF_BYTE:
493
0
        {
494
0
            uint8_t m;
495
0
            TIFFReadDirEntryCheckedByte(tif, direntry, &m);
496
0
            *value = (uint16_t)m;
497
0
            return (TIFFReadDirEntryErrOk);
498
0
        }
499
0
        case TIFF_SBYTE:
500
0
        {
501
0
            int8_t m;
502
0
            TIFFReadDirEntryCheckedSbyte(tif, direntry, &m);
503
0
            err = TIFFReadDirEntryCheckRangeShortSbyte(m);
504
0
            if (err != TIFFReadDirEntryErrOk)
505
0
                return (err);
506
0
            *value = (uint16_t)m;
507
0
            return (TIFFReadDirEntryErrOk);
508
0
        }
509
0
        case TIFF_SHORT:
510
0
            TIFFReadDirEntryCheckedShort(tif, direntry, value);
511
0
            return (TIFFReadDirEntryErrOk);
512
0
        case TIFF_SSHORT:
513
0
        {
514
0
            int16_t m;
515
0
            TIFFReadDirEntryCheckedSshort(tif, direntry, &m);
516
0
            err = TIFFReadDirEntryCheckRangeShortSshort(m);
517
0
            if (err != TIFFReadDirEntryErrOk)
518
0
                return (err);
519
0
            *value = (uint16_t)m;
520
0
            return (TIFFReadDirEntryErrOk);
521
0
        }
522
0
        case TIFF_LONG:
523
0
        {
524
0
            uint32_t m;
525
0
            TIFFReadDirEntryCheckedLong(tif, direntry, &m);
526
0
            err = TIFFReadDirEntryCheckRangeShortLong(m);
527
0
            if (err != TIFFReadDirEntryErrOk)
528
0
                return (err);
529
0
            *value = (uint16_t)m;
530
0
            return (TIFFReadDirEntryErrOk);
531
0
        }
532
0
        case TIFF_SLONG:
533
0
        {
534
0
            int32_t m;
535
0
            TIFFReadDirEntryCheckedSlong(tif, direntry, &m);
536
0
            err = TIFFReadDirEntryCheckRangeShortSlong(m);
537
0
            if (err != TIFFReadDirEntryErrOk)
538
0
                return (err);
539
0
            *value = (uint16_t)m;
540
0
            return (TIFFReadDirEntryErrOk);
541
0
        }
542
0
        case TIFF_LONG8:
543
0
        {
544
0
            uint64_t m;
545
0
            err = TIFFReadDirEntryCheckedLong8(tif, direntry, &m);
546
0
            if (err != TIFFReadDirEntryErrOk)
547
0
                return (err);
548
0
            err = TIFFReadDirEntryCheckRangeShortLong8(m);
549
0
            if (err != TIFFReadDirEntryErrOk)
550
0
                return (err);
551
0
            *value = (uint16_t)m;
552
0
            return (TIFFReadDirEntryErrOk);
553
0
        }
554
0
        case TIFF_SLONG8:
555
0
        {
556
0
            int64_t m;
557
0
            err = TIFFReadDirEntryCheckedSlong8(tif, direntry, &m);
558
0
            if (err != TIFFReadDirEntryErrOk)
559
0
                return (err);
560
0
            err = TIFFReadDirEntryCheckRangeShortSlong8(m);
561
0
            if (err != TIFFReadDirEntryErrOk)
562
0
                return (err);
563
0
            *value = (uint16_t)m;
564
0
            return (TIFFReadDirEntryErrOk);
565
0
        }
566
0
        default:
567
0
            return (TIFFReadDirEntryErrType);
568
0
    }
569
0
} /*-- TIFFReadDirEntryShort() --*/
570
571
static enum TIFFReadDirEntryErr
572
TIFFReadDirEntrySshort(TIFF *tif, TIFFDirEntry *direntry, int16_t *value)
573
0
{
574
0
    enum TIFFReadDirEntryErr err;
575
0
    if (direntry->tdir_count != 1)
576
0
        return (TIFFReadDirEntryErrCount);
577
0
    switch (direntry->tdir_type)
578
0
    {
579
0
        case TIFF_BYTE:
580
0
        {
581
0
            uint8_t m;
582
0
            TIFFReadDirEntryCheckedByte(tif, direntry, &m);
583
0
            *value = (int16_t)m;
584
0
            return (TIFFReadDirEntryErrOk);
585
0
        }
586
0
        case TIFF_SBYTE:
587
0
        {
588
0
            int8_t m;
589
0
            TIFFReadDirEntryCheckedSbyte(tif, direntry, &m);
590
0
            *value = (int16_t)m;
591
0
            return (TIFFReadDirEntryErrOk);
592
0
        }
593
0
        case TIFF_SHORT:
594
0
        {
595
0
            uint16_t m;
596
0
            TIFFReadDirEntryCheckedShort(tif, direntry, &m);
597
0
            err = TIFFReadDirEntryCheckRangeSshortShort(m);
598
0
            if (err != TIFFReadDirEntryErrOk)
599
0
                return (err);
600
0
            *value = (uint16_t)m;
601
0
            return (TIFFReadDirEntryErrOk);
602
0
        }
603
0
        case TIFF_SSHORT:
604
0
            TIFFReadDirEntryCheckedSshort(tif, direntry, value);
605
0
            return (TIFFReadDirEntryErrOk);
606
0
        case TIFF_LONG:
607
0
        {
608
0
            uint32_t m;
609
0
            TIFFReadDirEntryCheckedLong(tif, direntry, &m);
610
0
            err = TIFFReadDirEntryCheckRangeSshortLong(m);
611
0
            if (err != TIFFReadDirEntryErrOk)
612
0
                return (err);
613
0
            *value = (int16_t)m;
614
0
            return (TIFFReadDirEntryErrOk);
615
0
        }
616
0
        case TIFF_SLONG:
617
0
        {
618
0
            int32_t m;
619
0
            TIFFReadDirEntryCheckedSlong(tif, direntry, &m);
620
0
            err = TIFFReadDirEntryCheckRangeSshortSlong(m);
621
0
            if (err != TIFFReadDirEntryErrOk)
622
0
                return (err);
623
0
            *value = (int16_t)m;
624
0
            return (TIFFReadDirEntryErrOk);
625
0
        }
626
0
        case TIFF_LONG8:
627
0
        {
628
0
            uint64_t m;
629
0
            err = TIFFReadDirEntryCheckedLong8(tif, direntry, &m);
630
0
            if (err != TIFFReadDirEntryErrOk)
631
0
                return (err);
632
0
            err = TIFFReadDirEntryCheckRangeSshortLong8(m);
633
0
            if (err != TIFFReadDirEntryErrOk)
634
0
                return (err);
635
0
            *value = (int16_t)m;
636
0
            return (TIFFReadDirEntryErrOk);
637
0
        }
638
0
        case TIFF_SLONG8:
639
0
        {
640
0
            int64_t m;
641
0
            err = TIFFReadDirEntryCheckedSlong8(tif, direntry, &m);
642
0
            if (err != TIFFReadDirEntryErrOk)
643
0
                return (err);
644
0
            err = TIFFReadDirEntryCheckRangeSshortSlong8(m);
645
0
            if (err != TIFFReadDirEntryErrOk)
646
0
                return (err);
647
0
            *value = (int16_t)m;
648
0
            return (TIFFReadDirEntryErrOk);
649
0
        }
650
0
        default:
651
0
            return (TIFFReadDirEntryErrType);
652
0
    }
653
0
} /*-- TIFFReadDirEntrySshort() --*/
654
655
static enum TIFFReadDirEntryErr
656
TIFFReadDirEntryLong(TIFF *tif, TIFFDirEntry *direntry, uint32_t *value)
657
0
{
658
0
    enum TIFFReadDirEntryErr err;
659
0
    if (direntry->tdir_count != 1)
660
0
        return (TIFFReadDirEntryErrCount);
661
0
    switch (direntry->tdir_type)
662
0
    {
663
0
        case TIFF_BYTE:
664
0
        {
665
0
            uint8_t m;
666
0
            TIFFReadDirEntryCheckedByte(tif, direntry, &m);
667
0
            *value = (uint32_t)m;
668
0
            return (TIFFReadDirEntryErrOk);
669
0
        }
670
0
        case TIFF_SBYTE:
671
0
        {
672
0
            int8_t m;
673
0
            TIFFReadDirEntryCheckedSbyte(tif, direntry, &m);
674
0
            err = TIFFReadDirEntryCheckRangeLongSbyte(m);
675
0
            if (err != TIFFReadDirEntryErrOk)
676
0
                return (err);
677
0
            *value = (uint32_t)m;
678
0
            return (TIFFReadDirEntryErrOk);
679
0
        }
680
0
        case TIFF_SHORT:
681
0
        {
682
0
            uint16_t m;
683
0
            TIFFReadDirEntryCheckedShort(tif, direntry, &m);
684
0
            *value = (uint32_t)m;
685
0
            return (TIFFReadDirEntryErrOk);
686
0
        }
687
0
        case TIFF_SSHORT:
688
0
        {
689
0
            int16_t m;
690
0
            TIFFReadDirEntryCheckedSshort(tif, direntry, &m);
691
0
            err = TIFFReadDirEntryCheckRangeLongSshort(m);
692
0
            if (err != TIFFReadDirEntryErrOk)
693
0
                return (err);
694
0
            *value = (uint32_t)m;
695
0
            return (TIFFReadDirEntryErrOk);
696
0
        }
697
0
        case TIFF_LONG:
698
0
            TIFFReadDirEntryCheckedLong(tif, direntry, value);
699
0
            return (TIFFReadDirEntryErrOk);
700
0
        case TIFF_SLONG:
701
0
        {
702
0
            int32_t m;
703
0
            TIFFReadDirEntryCheckedSlong(tif, direntry, &m);
704
0
            err = TIFFReadDirEntryCheckRangeLongSlong(m);
705
0
            if (err != TIFFReadDirEntryErrOk)
706
0
                return (err);
707
0
            *value = (uint32_t)m;
708
0
            return (TIFFReadDirEntryErrOk);
709
0
        }
710
0
        case TIFF_LONG8:
711
0
        {
712
0
            uint64_t m;
713
0
            err = TIFFReadDirEntryCheckedLong8(tif, direntry, &m);
714
0
            if (err != TIFFReadDirEntryErrOk)
715
0
                return (err);
716
0
            err = TIFFReadDirEntryCheckRangeLongLong8(m);
717
0
            if (err != TIFFReadDirEntryErrOk)
718
0
                return (err);
719
0
            *value = (uint32_t)m;
720
0
            return (TIFFReadDirEntryErrOk);
721
0
        }
722
0
        case TIFF_SLONG8:
723
0
        {
724
0
            int64_t m;
725
0
            err = TIFFReadDirEntryCheckedSlong8(tif, direntry, &m);
726
0
            if (err != TIFFReadDirEntryErrOk)
727
0
                return (err);
728
0
            err = TIFFReadDirEntryCheckRangeLongSlong8(m);
729
0
            if (err != TIFFReadDirEntryErrOk)
730
0
                return (err);
731
0
            *value = (uint32_t)m;
732
0
            return (TIFFReadDirEntryErrOk);
733
0
        }
734
0
        default:
735
0
            return (TIFFReadDirEntryErrType);
736
0
    }
737
0
} /*-- TIFFReadDirEntryLong() --*/
738
739
static enum TIFFReadDirEntryErr
740
TIFFReadDirEntrySlong(TIFF *tif, TIFFDirEntry *direntry, int32_t *value)
741
0
{
742
0
    enum TIFFReadDirEntryErr err;
743
0
    if (direntry->tdir_count != 1)
744
0
        return (TIFFReadDirEntryErrCount);
745
0
    switch (direntry->tdir_type)
746
0
    {
747
0
        case TIFF_BYTE:
748
0
        {
749
0
            uint8_t m;
750
0
            TIFFReadDirEntryCheckedByte(tif, direntry, &m);
751
0
            *value = (int32_t)m;
752
0
            return (TIFFReadDirEntryErrOk);
753
0
        }
754
0
        case TIFF_SBYTE:
755
0
        {
756
0
            int8_t m;
757
0
            TIFFReadDirEntryCheckedSbyte(tif, direntry, &m);
758
0
            *value = (int32_t)m;
759
0
            return (TIFFReadDirEntryErrOk);
760
0
        }
761
0
        case TIFF_SHORT:
762
0
        {
763
0
            uint16_t m;
764
0
            TIFFReadDirEntryCheckedShort(tif, direntry, &m);
765
0
            *value = (int32_t)m;
766
0
            return (TIFFReadDirEntryErrOk);
767
0
        }
768
0
        case TIFF_SSHORT:
769
0
        {
770
0
            int16_t m;
771
0
            TIFFReadDirEntryCheckedSshort(tif, direntry, &m);
772
0
            *value = (int32_t)m;
773
0
            return (TIFFReadDirEntryErrOk);
774
0
        }
775
0
        case TIFF_LONG:
776
0
        {
777
0
            uint32_t m;
778
0
            TIFFReadDirEntryCheckedLong(tif, direntry, &m);
779
0
            err = TIFFReadDirEntryCheckRangeSlongLong(m);
780
0
            if (err != TIFFReadDirEntryErrOk)
781
0
                return (err);
782
0
            *value = (int32_t)m;
783
0
            return (TIFFReadDirEntryErrOk);
784
0
        }
785
0
        case TIFF_SLONG:
786
0
            TIFFReadDirEntryCheckedSlong(tif, direntry, value);
787
0
            return (TIFFReadDirEntryErrOk);
788
0
        case TIFF_LONG8:
789
0
        {
790
0
            uint64_t m;
791
0
            err = TIFFReadDirEntryCheckedLong8(tif, direntry, &m);
792
0
            if (err != TIFFReadDirEntryErrOk)
793
0
                return (err);
794
0
            err = TIFFReadDirEntryCheckRangeSlongLong8(m);
795
0
            if (err != TIFFReadDirEntryErrOk)
796
0
                return (err);
797
0
            *value = (int32_t)m;
798
0
            return (TIFFReadDirEntryErrOk);
799
0
        }
800
0
        case TIFF_SLONG8:
801
0
        {
802
0
            int64_t m;
803
0
            err = TIFFReadDirEntryCheckedSlong8(tif, direntry, &m);
804
0
            if (err != TIFFReadDirEntryErrOk)
805
0
                return (err);
806
0
            err = TIFFReadDirEntryCheckRangeSlongSlong8(m);
807
0
            if (err != TIFFReadDirEntryErrOk)
808
0
                return (err);
809
0
            *value = (int32_t)m;
810
0
            return (TIFFReadDirEntryErrOk);
811
0
        }
812
0
        default:
813
0
            return (TIFFReadDirEntryErrType);
814
0
    }
815
0
} /*-- TIFFReadDirEntrySlong() --*/
816
817
static enum TIFFReadDirEntryErr
818
TIFFReadDirEntryLong8(TIFF *tif, TIFFDirEntry *direntry, uint64_t *value)
819
0
{
820
0
    enum TIFFReadDirEntryErr err;
821
0
    if (direntry->tdir_count != 1)
822
0
        return (TIFFReadDirEntryErrCount);
823
0
    switch (direntry->tdir_type)
824
0
    {
825
0
        case TIFF_BYTE:
826
0
        {
827
0
            uint8_t m;
828
0
            TIFFReadDirEntryCheckedByte(tif, direntry, &m);
829
0
            *value = (uint64_t)m;
830
0
            return (TIFFReadDirEntryErrOk);
831
0
        }
832
0
        case TIFF_SBYTE:
833
0
        {
834
0
            int8_t m;
835
0
            TIFFReadDirEntryCheckedSbyte(tif, direntry, &m);
836
0
            err = TIFFReadDirEntryCheckRangeLong8Sbyte(m);
837
0
            if (err != TIFFReadDirEntryErrOk)
838
0
                return (err);
839
0
            *value = (uint64_t)m;
840
0
            return (TIFFReadDirEntryErrOk);
841
0
        }
842
0
        case TIFF_SHORT:
843
0
        {
844
0
            uint16_t m;
845
0
            TIFFReadDirEntryCheckedShort(tif, direntry, &m);
846
0
            *value = (uint64_t)m;
847
0
            return (TIFFReadDirEntryErrOk);
848
0
        }
849
0
        case TIFF_SSHORT:
850
0
        {
851
0
            int16_t m;
852
0
            TIFFReadDirEntryCheckedSshort(tif, direntry, &m);
853
0
            err = TIFFReadDirEntryCheckRangeLong8Sshort(m);
854
0
            if (err != TIFFReadDirEntryErrOk)
855
0
                return (err);
856
0
            *value = (uint64_t)m;
857
0
            return (TIFFReadDirEntryErrOk);
858
0
        }
859
0
        case TIFF_LONG:
860
0
        {
861
0
            uint32_t m;
862
0
            TIFFReadDirEntryCheckedLong(tif, direntry, &m);
863
0
            *value = (uint64_t)m;
864
0
            return (TIFFReadDirEntryErrOk);
865
0
        }
866
0
        case TIFF_SLONG:
867
0
        {
868
0
            int32_t m;
869
0
            TIFFReadDirEntryCheckedSlong(tif, direntry, &m);
870
0
            err = TIFFReadDirEntryCheckRangeLong8Slong(m);
871
0
            if (err != TIFFReadDirEntryErrOk)
872
0
                return (err);
873
0
            *value = (uint64_t)m;
874
0
            return (TIFFReadDirEntryErrOk);
875
0
        }
876
0
        case TIFF_LONG8:
877
0
            err = TIFFReadDirEntryCheckedLong8(tif, direntry, value);
878
0
            return (err);
879
0
        case TIFF_SLONG8:
880
0
        {
881
0
            int64_t m;
882
0
            err = TIFFReadDirEntryCheckedSlong8(tif, direntry, &m);
883
0
            if (err != TIFFReadDirEntryErrOk)
884
0
                return (err);
885
0
            err = TIFFReadDirEntryCheckRangeLong8Slong8(m);
886
0
            if (err != TIFFReadDirEntryErrOk)
887
0
                return (err);
888
0
            *value = (uint64_t)m;
889
0
            return (TIFFReadDirEntryErrOk);
890
0
        }
891
0
        default:
892
0
            return (TIFFReadDirEntryErrType);
893
0
    }
894
0
} /*-- TIFFReadDirEntryLong8() --*/
895
896
static enum TIFFReadDirEntryErr
897
TIFFReadDirEntrySlong8(TIFF *tif, TIFFDirEntry *direntry, int64_t *value)
898
0
{
899
0
    enum TIFFReadDirEntryErr err;
900
0
    if (direntry->tdir_count != 1)
901
0
        return (TIFFReadDirEntryErrCount);
902
0
    switch (direntry->tdir_type)
903
0
    {
904
0
        case TIFF_BYTE:
905
0
        {
906
0
            uint8_t m;
907
0
            TIFFReadDirEntryCheckedByte(tif, direntry, &m);
908
0
            *value = (int64_t)m;
909
0
            return (TIFFReadDirEntryErrOk);
910
0
        }
911
0
        case TIFF_SBYTE:
912
0
        {
913
0
            int8_t m;
914
0
            TIFFReadDirEntryCheckedSbyte(tif, direntry, &m);
915
0
            *value = (int64_t)m;
916
0
            return (TIFFReadDirEntryErrOk);
917
0
        }
918
0
        case TIFF_SHORT:
919
0
        {
920
0
            uint16_t m;
921
0
            TIFFReadDirEntryCheckedShort(tif, direntry, &m);
922
0
            *value = (int64_t)m;
923
0
            return (TIFFReadDirEntryErrOk);
924
0
        }
925
0
        case TIFF_SSHORT:
926
0
        {
927
0
            int16_t m;
928
0
            TIFFReadDirEntryCheckedSshort(tif, direntry, &m);
929
0
            *value = (int64_t)m;
930
0
            return (TIFFReadDirEntryErrOk);
931
0
        }
932
0
        case TIFF_LONG:
933
0
        {
934
0
            uint32_t m;
935
0
            TIFFReadDirEntryCheckedLong(tif, direntry, &m);
936
0
            *value = (int64_t)m;
937
0
            return (TIFFReadDirEntryErrOk);
938
0
        }
939
0
        case TIFF_SLONG:
940
0
        {
941
0
            int32_t m;
942
0
            TIFFReadDirEntryCheckedSlong(tif, direntry, &m);
943
0
            *value = (int64_t)m;
944
0
            return (TIFFReadDirEntryErrOk);
945
0
        }
946
0
        case TIFF_LONG8:
947
0
        {
948
0
            uint64_t m;
949
0
            err = TIFFReadDirEntryCheckedLong8(tif, direntry, &m);
950
0
            if (err != TIFFReadDirEntryErrOk)
951
0
                return (err);
952
0
            err = TIFFReadDirEntryCheckRangeSlong8Long8(m);
953
0
            if (err != TIFFReadDirEntryErrOk)
954
0
                return (err);
955
0
            *value = (int64_t)m;
956
0
            return (TIFFReadDirEntryErrOk);
957
0
        }
958
0
        case TIFF_SLONG8:
959
0
            err = TIFFReadDirEntryCheckedSlong8(tif, direntry, value);
960
0
            return (err);
961
0
        default:
962
0
            return (TIFFReadDirEntryErrType);
963
0
    }
964
0
} /*-- TIFFReadDirEntrySlong8() --*/
965
966
static enum TIFFReadDirEntryErr
967
TIFFReadDirEntryFloat(TIFF *tif, TIFFDirEntry *direntry, float *value)
968
0
{
969
0
    enum TIFFReadDirEntryErr err;
970
0
    if (direntry->tdir_count != 1)
971
0
        return (TIFFReadDirEntryErrCount);
972
0
    switch (direntry->tdir_type)
973
0
    {
974
0
        case TIFF_BYTE:
975
0
        {
976
0
            uint8_t m;
977
0
            TIFFReadDirEntryCheckedByte(tif, direntry, &m);
978
0
            *value = (float)m;
979
0
            return (TIFFReadDirEntryErrOk);
980
0
        }
981
0
        case TIFF_SBYTE:
982
0
        {
983
0
            int8_t m;
984
0
            TIFFReadDirEntryCheckedSbyte(tif, direntry, &m);
985
0
            *value = (float)m;
986
0
            return (TIFFReadDirEntryErrOk);
987
0
        }
988
0
        case TIFF_SHORT:
989
0
        {
990
0
            uint16_t m;
991
0
            TIFFReadDirEntryCheckedShort(tif, direntry, &m);
992
0
            *value = (float)m;
993
0
            return (TIFFReadDirEntryErrOk);
994
0
        }
995
0
        case TIFF_SSHORT:
996
0
        {
997
0
            int16_t m;
998
0
            TIFFReadDirEntryCheckedSshort(tif, direntry, &m);
999
0
            *value = (float)m;
1000
0
            return (TIFFReadDirEntryErrOk);
1001
0
        }
1002
0
        case TIFF_LONG:
1003
0
        {
1004
0
            uint32_t m;
1005
0
            TIFFReadDirEntryCheckedLong(tif, direntry, &m);
1006
0
            *value = (float)m;
1007
0
            return (TIFFReadDirEntryErrOk);
1008
0
        }
1009
0
        case TIFF_SLONG:
1010
0
        {
1011
0
            int32_t m;
1012
0
            TIFFReadDirEntryCheckedSlong(tif, direntry, &m);
1013
0
            *value = (float)m;
1014
0
            return (TIFFReadDirEntryErrOk);
1015
0
        }
1016
0
        case TIFF_LONG8:
1017
0
        {
1018
0
            uint64_t m;
1019
0
            err = TIFFReadDirEntryCheckedLong8(tif, direntry, &m);
1020
0
            if (err != TIFFReadDirEntryErrOk)
1021
0
                return (err);
1022
0
            *value = (float)m;
1023
0
            return (TIFFReadDirEntryErrOk);
1024
0
        }
1025
0
        case TIFF_SLONG8:
1026
0
        {
1027
0
            int64_t m;
1028
0
            err = TIFFReadDirEntryCheckedSlong8(tif, direntry, &m);
1029
0
            if (err != TIFFReadDirEntryErrOk)
1030
0
                return (err);
1031
0
            *value = (float)m;
1032
0
            return (TIFFReadDirEntryErrOk);
1033
0
        }
1034
0
        case TIFF_RATIONAL:
1035
0
        {
1036
0
            double m;
1037
0
            err = TIFFReadDirEntryCheckedRational(tif, direntry, &m);
1038
0
            if (err != TIFFReadDirEntryErrOk)
1039
0
                return (err);
1040
0
            *value = (float)m;
1041
0
            return (TIFFReadDirEntryErrOk);
1042
0
        }
1043
0
        case TIFF_SRATIONAL:
1044
0
        {
1045
0
            double m;
1046
0
            err = TIFFReadDirEntryCheckedSrational(tif, direntry, &m);
1047
0
            if (err != TIFFReadDirEntryErrOk)
1048
0
                return (err);
1049
0
            *value = (float)m;
1050
0
            return (TIFFReadDirEntryErrOk);
1051
0
        }
1052
0
        case TIFF_FLOAT:
1053
0
            TIFFReadDirEntryCheckedFloat(tif, direntry, value);
1054
0
            return (TIFFReadDirEntryErrOk);
1055
0
        case TIFF_DOUBLE:
1056
0
        {
1057
0
            double m;
1058
0
            err = TIFFReadDirEntryCheckedDouble(tif, direntry, &m);
1059
0
            if (err != TIFFReadDirEntryErrOk)
1060
0
                return (err);
1061
0
            if ((m > FLT_MAX) || (m < -FLT_MAX))
1062
0
                return (TIFFReadDirEntryErrRange);
1063
0
            *value = (float)m;
1064
0
            return (TIFFReadDirEntryErrOk);
1065
0
        }
1066
0
        default:
1067
0
            return (TIFFReadDirEntryErrType);
1068
0
    }
1069
0
}
1070
1071
static enum TIFFReadDirEntryErr
1072
TIFFReadDirEntryDouble(TIFF *tif, TIFFDirEntry *direntry, double *value)
1073
0
{
1074
0
    enum TIFFReadDirEntryErr err;
1075
0
    if (direntry->tdir_count != 1)
1076
0
        return (TIFFReadDirEntryErrCount);
1077
0
    switch (direntry->tdir_type)
1078
0
    {
1079
0
        case TIFF_BYTE:
1080
0
        {
1081
0
            uint8_t m;
1082
0
            TIFFReadDirEntryCheckedByte(tif, direntry, &m);
1083
0
            *value = (double)m;
1084
0
            return (TIFFReadDirEntryErrOk);
1085
0
        }
1086
0
        case TIFF_SBYTE:
1087
0
        {
1088
0
            int8_t m;
1089
0
            TIFFReadDirEntryCheckedSbyte(tif, direntry, &m);
1090
0
            *value = (double)m;
1091
0
            return (TIFFReadDirEntryErrOk);
1092
0
        }
1093
0
        case TIFF_SHORT:
1094
0
        {
1095
0
            uint16_t m;
1096
0
            TIFFReadDirEntryCheckedShort(tif, direntry, &m);
1097
0
            *value = (double)m;
1098
0
            return (TIFFReadDirEntryErrOk);
1099
0
        }
1100
0
        case TIFF_SSHORT:
1101
0
        {
1102
0
            int16_t m;
1103
0
            TIFFReadDirEntryCheckedSshort(tif, direntry, &m);
1104
0
            *value = (double)m;
1105
0
            return (TIFFReadDirEntryErrOk);
1106
0
        }
1107
0
        case TIFF_LONG:
1108
0
        {
1109
0
            uint32_t m;
1110
0
            TIFFReadDirEntryCheckedLong(tif, direntry, &m);
1111
0
            *value = (double)m;
1112
0
            return (TIFFReadDirEntryErrOk);
1113
0
        }
1114
0
        case TIFF_SLONG:
1115
0
        {
1116
0
            int32_t m;
1117
0
            TIFFReadDirEntryCheckedSlong(tif, direntry, &m);
1118
0
            *value = (double)m;
1119
0
            return (TIFFReadDirEntryErrOk);
1120
0
        }
1121
0
        case TIFF_LONG8:
1122
0
        {
1123
0
            uint64_t m;
1124
0
            err = TIFFReadDirEntryCheckedLong8(tif, direntry, &m);
1125
0
            if (err != TIFFReadDirEntryErrOk)
1126
0
                return (err);
1127
0
            *value = (double)m;
1128
0
            return (TIFFReadDirEntryErrOk);
1129
0
        }
1130
0
        case TIFF_SLONG8:
1131
0
        {
1132
0
            int64_t m;
1133
0
            err = TIFFReadDirEntryCheckedSlong8(tif, direntry, &m);
1134
0
            if (err != TIFFReadDirEntryErrOk)
1135
0
                return (err);
1136
0
            *value = (double)m;
1137
0
            return (TIFFReadDirEntryErrOk);
1138
0
        }
1139
0
        case TIFF_RATIONAL:
1140
0
            err = TIFFReadDirEntryCheckedRational(tif, direntry, value);
1141
0
            return (err);
1142
0
        case TIFF_SRATIONAL:
1143
0
            err = TIFFReadDirEntryCheckedSrational(tif, direntry, value);
1144
0
            return (err);
1145
0
        case TIFF_FLOAT:
1146
0
        {
1147
0
            float m;
1148
0
            TIFFReadDirEntryCheckedFloat(tif, direntry, &m);
1149
0
            *value = (double)m;
1150
0
            return (TIFFReadDirEntryErrOk);
1151
0
        }
1152
0
        case TIFF_DOUBLE:
1153
0
            err = TIFFReadDirEntryCheckedDouble(tif, direntry, value);
1154
0
            return (err);
1155
0
        default:
1156
0
            return (TIFFReadDirEntryErrType);
1157
0
    }
1158
0
}
1159
1160
static enum TIFFReadDirEntryErr
1161
TIFFReadDirEntryIfd8(TIFF *tif, TIFFDirEntry *direntry, uint64_t *value)
1162
0
{
1163
0
    enum TIFFReadDirEntryErr err;
1164
0
    if (direntry->tdir_count != 1)
1165
0
        return (TIFFReadDirEntryErrCount);
1166
0
    switch (direntry->tdir_type)
1167
0
    {
1168
0
        case TIFF_LONG:
1169
0
        case TIFF_IFD:
1170
0
        {
1171
0
            uint32_t m;
1172
0
            TIFFReadDirEntryCheckedLong(tif, direntry, &m);
1173
0
            *value = (uint64_t)m;
1174
0
            return (TIFFReadDirEntryErrOk);
1175
0
        }
1176
0
        case TIFF_LONG8:
1177
0
        case TIFF_IFD8:
1178
0
            err = TIFFReadDirEntryCheckedLong8(tif, direntry, value);
1179
0
            return (err);
1180
0
        default:
1181
0
            return (TIFFReadDirEntryErrType);
1182
0
    }
1183
0
}
1184
1185
0
#define INITIAL_THRESHOLD (1024 * 1024)
1186
0
#define THRESHOLD_MULTIPLIER 10
1187
#define MAX_THRESHOLD                                                          \
1188
0
    (THRESHOLD_MULTIPLIER * THRESHOLD_MULTIPLIER * THRESHOLD_MULTIPLIER *      \
1189
0
     INITIAL_THRESHOLD)
1190
1191
static enum TIFFReadDirEntryErr TIFFReadDirEntryDataAndRealloc(TIFF *tif,
1192
                                                               uint64_t offset,
1193
                                                               tmsize_t size,
1194
                                                               void **pdest)
1195
0
{
1196
0
#if SIZEOF_SIZE_T == 8
1197
0
    tmsize_t threshold = INITIAL_THRESHOLD;
1198
0
#endif
1199
0
    tmsize_t already_read = 0;
1200
1201
0
    assert(!isMapped(tif));
1202
1203
0
    if (!SeekOK(tif, offset))
1204
0
        return (TIFFReadDirEntryErrIo);
1205
1206
    /* On 64 bit processes, read first a maximum of 1 MB, then 10 MB, etc */
1207
    /* so as to avoid allocating too much memory in case the file is too */
1208
    /* short. We could ask for the file size, but this might be */
1209
    /* expensive with some I/O layers (think of reading a gzipped file) */
1210
    /* Restrict to 64 bit processes, so as to avoid reallocs() */
1211
    /* on 32 bit processes where virtual memory is scarce.  */
1212
0
    while (already_read < size)
1213
0
    {
1214
0
        void *new_dest;
1215
0
        tmsize_t bytes_read;
1216
0
        tmsize_t to_read = size - already_read;
1217
0
#if SIZEOF_SIZE_T == 8
1218
0
        if (to_read >= threshold && threshold < MAX_THRESHOLD)
1219
0
        {
1220
0
            to_read = threshold;
1221
0
            threshold *= THRESHOLD_MULTIPLIER;
1222
0
        }
1223
0
#endif
1224
1225
0
        new_dest =
1226
0
            (uint8_t *)_TIFFreallocExt(tif, *pdest, already_read + to_read);
1227
0
        if (new_dest == NULL)
1228
0
        {
1229
0
            TIFFErrorExtR(tif, tif->tif_name,
1230
0
                          "Failed to allocate memory for %s "
1231
0
                          "(%" TIFF_SSIZE_FORMAT
1232
0
                          " elements of %" TIFF_SSIZE_FORMAT " bytes each)",
1233
0
                          "TIFFReadDirEntryArray", (tmsize_t)1,
1234
0
                          already_read + to_read);
1235
0
            return TIFFReadDirEntryErrAlloc;
1236
0
        }
1237
0
        *pdest = new_dest;
1238
1239
0
        bytes_read = TIFFReadFile(tif, (char *)*pdest + already_read, to_read);
1240
0
        already_read += bytes_read;
1241
0
        if (bytes_read != to_read)
1242
0
        {
1243
0
            return TIFFReadDirEntryErrIo;
1244
0
        }
1245
0
    }
1246
0
    return TIFFReadDirEntryErrOk;
1247
0
}
1248
1249
/* Caution: if raising that value, make sure int32 / uint32 overflows can't
1250
 * occur elsewhere */
1251
0
#define MAX_SIZE_TAG_DATA 2147483647U
1252
1253
static enum TIFFReadDirEntryErr
1254
TIFFReadDirEntryArrayWithLimit(TIFF *tif, TIFFDirEntry *direntry,
1255
                               uint32_t *count, uint32_t desttypesize,
1256
                               void **value, uint64_t maxcount)
1257
0
{
1258
0
    int typesize;
1259
0
    uint32_t datasize;
1260
0
    void *data;
1261
0
    uint64_t target_count64;
1262
0
    int original_datasize_clamped;
1263
0
    typesize = TIFFDataWidth((TIFFDataType)direntry->tdir_type);
1264
1265
0
    target_count64 =
1266
0
        (direntry->tdir_count > maxcount) ? maxcount : direntry->tdir_count;
1267
1268
0
    if ((target_count64 == 0) || (typesize == 0))
1269
0
    {
1270
0
        *value = 0;
1271
0
        return (TIFFReadDirEntryErrOk);
1272
0
    }
1273
0
    (void)desttypesize;
1274
1275
    /* We just want to know if the original tag size is more than 4 bytes
1276
     * (classic TIFF) or 8 bytes (BigTIFF)
1277
     */
1278
0
    original_datasize_clamped =
1279
0
        ((direntry->tdir_count > 10) ? 10 : (int)direntry->tdir_count) *
1280
0
        typesize;
1281
1282
    /*
1283
     * As a sanity check, make sure we have no more than a 2GB tag array
1284
     * in either the current data type or the dest data type.  This also
1285
     * avoids problems with overflow of tmsize_t on 32bit systems.
1286
     */
1287
0
    if ((uint64_t)(MAX_SIZE_TAG_DATA / typesize) < target_count64)
1288
0
        return (TIFFReadDirEntryErrSizesan);
1289
0
    if ((uint64_t)(MAX_SIZE_TAG_DATA / desttypesize) < target_count64)
1290
0
        return (TIFFReadDirEntryErrSizesan);
1291
1292
0
    *count = (uint32_t)target_count64;
1293
0
    datasize = (*count) * typesize;
1294
0
    assert((tmsize_t)datasize > 0);
1295
1296
0
    if (datasize > 100 * 1024 * 1024)
1297
0
    {
1298
        /* Before allocating a huge amount of memory for corrupted files, check
1299
         * if size of requested memory is not greater than file size.
1300
         */
1301
0
        const uint64_t filesize = TIFFGetFileSize(tif);
1302
0
        if (datasize > filesize)
1303
0
        {
1304
0
            TIFFWarningExtR(tif, "ReadDirEntryArray",
1305
0
                            "Requested memory size for tag %d (0x%x) %" PRIu32
1306
0
                            " is greater than filesize %" PRIu64
1307
0
                            ". Memory not allocated, tag not read",
1308
0
                            direntry->tdir_tag, direntry->tdir_tag, datasize,
1309
0
                            filesize);
1310
0
            return (TIFFReadDirEntryErrAlloc);
1311
0
        }
1312
0
    }
1313
1314
0
    if (isMapped(tif) && datasize > (uint64_t)tif->tif_size)
1315
0
        return TIFFReadDirEntryErrIo;
1316
1317
0
    if (!isMapped(tif) && (((tif->tif_flags & TIFF_BIGTIFF) && datasize > 8) ||
1318
0
                           (!(tif->tif_flags & TIFF_BIGTIFF) && datasize > 4)))
1319
0
    {
1320
0
        data = NULL;
1321
0
    }
1322
0
    else
1323
0
    {
1324
0
        data = _TIFFCheckMalloc(tif, *count, typesize, "ReadDirEntryArray");
1325
0
        if (data == 0)
1326
0
            return (TIFFReadDirEntryErrAlloc);
1327
0
    }
1328
0
    if (!(tif->tif_flags & TIFF_BIGTIFF))
1329
0
    {
1330
        /* Only the condition on original_datasize_clamped. The second
1331
         * one is implied, but Coverity Scan cannot see it. */
1332
0
        if (original_datasize_clamped <= 4 && datasize <= 4)
1333
0
            _TIFFmemcpy(data, &direntry->tdir_offset, datasize);
1334
0
        else
1335
0
        {
1336
0
            enum TIFFReadDirEntryErr err;
1337
0
            uint32_t offset = direntry->tdir_offset.toff_long;
1338
0
            if (tif->tif_flags & TIFF_SWAB)
1339
0
                TIFFSwabLong(&offset);
1340
0
            if (isMapped(tif))
1341
0
                err = TIFFReadDirEntryData(tif, (uint64_t)offset,
1342
0
                                           (tmsize_t)datasize, data);
1343
0
            else
1344
0
                err = TIFFReadDirEntryDataAndRealloc(tif, (uint64_t)offset,
1345
0
                                                     (tmsize_t)datasize, &data);
1346
0
            if (err != TIFFReadDirEntryErrOk)
1347
0
            {
1348
0
                _TIFFfreeExt(tif, data);
1349
0
                return (err);
1350
0
            }
1351
0
        }
1352
0
    }
1353
0
    else
1354
0
    {
1355
        /* See above comment for the Classic TIFF case */
1356
0
        if (original_datasize_clamped <= 8 && datasize <= 8)
1357
0
            _TIFFmemcpy(data, &direntry->tdir_offset, datasize);
1358
0
        else
1359
0
        {
1360
0
            enum TIFFReadDirEntryErr err;
1361
0
            uint64_t offset = direntry->tdir_offset.toff_long8;
1362
0
            if (tif->tif_flags & TIFF_SWAB)
1363
0
                TIFFSwabLong8(&offset);
1364
0
            if (isMapped(tif))
1365
0
                err = TIFFReadDirEntryData(tif, (uint64_t)offset,
1366
0
                                           (tmsize_t)datasize, data);
1367
0
            else
1368
0
                err = TIFFReadDirEntryDataAndRealloc(tif, (uint64_t)offset,
1369
0
                                                     (tmsize_t)datasize, &data);
1370
0
            if (err != TIFFReadDirEntryErrOk)
1371
0
            {
1372
0
                _TIFFfreeExt(tif, data);
1373
0
                return (err);
1374
0
            }
1375
0
        }
1376
0
    }
1377
0
    *value = data;
1378
0
    return (TIFFReadDirEntryErrOk);
1379
0
}
1380
1381
static enum TIFFReadDirEntryErr
1382
TIFFReadDirEntryArray(TIFF *tif, TIFFDirEntry *direntry, uint32_t *count,
1383
                      uint32_t desttypesize, void **value)
1384
0
{
1385
0
    return TIFFReadDirEntryArrayWithLimit(tif, direntry, count, desttypesize,
1386
0
                                          value, ~((uint64_t)0));
1387
0
}
1388
1389
static enum TIFFReadDirEntryErr
1390
TIFFReadDirEntryByteArray(TIFF *tif, TIFFDirEntry *direntry, uint8_t **value)
1391
0
{
1392
0
    enum TIFFReadDirEntryErr err;
1393
0
    uint32_t count;
1394
0
    void *origdata;
1395
0
    uint8_t *data;
1396
0
    switch (direntry->tdir_type)
1397
0
    {
1398
0
        case TIFF_ASCII:
1399
0
        case TIFF_UNDEFINED:
1400
0
        case TIFF_BYTE:
1401
0
        case TIFF_SBYTE:
1402
0
        case TIFF_SHORT:
1403
0
        case TIFF_SSHORT:
1404
0
        case TIFF_LONG:
1405
0
        case TIFF_SLONG:
1406
0
        case TIFF_LONG8:
1407
0
        case TIFF_SLONG8:
1408
0
            break;
1409
0
        default:
1410
0
            return (TIFFReadDirEntryErrType);
1411
0
    }
1412
0
    err = TIFFReadDirEntryArray(tif, direntry, &count, 1, &origdata);
1413
0
    if ((err != TIFFReadDirEntryErrOk) || (origdata == 0))
1414
0
    {
1415
0
        *value = 0;
1416
0
        return (err);
1417
0
    }
1418
0
    switch (direntry->tdir_type)
1419
0
    {
1420
0
        case TIFF_ASCII:
1421
0
        case TIFF_UNDEFINED:
1422
0
        case TIFF_BYTE:
1423
0
            *value = (uint8_t *)origdata;
1424
0
            return (TIFFReadDirEntryErrOk);
1425
0
        case TIFF_SBYTE:
1426
0
        {
1427
0
            int8_t *m;
1428
0
            uint32_t n;
1429
0
            m = (int8_t *)origdata;
1430
0
            for (n = 0; n < count; n++)
1431
0
            {
1432
0
                err = TIFFReadDirEntryCheckRangeByteSbyte(*m);
1433
0
                if (err != TIFFReadDirEntryErrOk)
1434
0
                {
1435
0
                    _TIFFfreeExt(tif, origdata);
1436
0
                    return (err);
1437
0
                }
1438
0
                m++;
1439
0
            }
1440
0
            *value = (uint8_t *)origdata;
1441
0
            return (TIFFReadDirEntryErrOk);
1442
0
        }
1443
0
    }
1444
0
    data = (uint8_t *)_TIFFmallocExt(tif, count);
1445
0
    if (data == 0)
1446
0
    {
1447
0
        _TIFFfreeExt(tif, origdata);
1448
0
        return (TIFFReadDirEntryErrAlloc);
1449
0
    }
1450
0
    switch (direntry->tdir_type)
1451
0
    {
1452
0
        case TIFF_SHORT:
1453
0
        {
1454
0
            uint16_t *ma;
1455
0
            uint8_t *mb;
1456
0
            uint32_t n;
1457
0
            ma = (uint16_t *)origdata;
1458
0
            mb = data;
1459
0
            for (n = 0; n < count; n++)
1460
0
            {
1461
0
                if (tif->tif_flags & TIFF_SWAB)
1462
0
                    TIFFSwabShort(ma);
1463
0
                err = TIFFReadDirEntryCheckRangeByteShort(*ma);
1464
0
                if (err != TIFFReadDirEntryErrOk)
1465
0
                    break;
1466
0
                *mb++ = (uint8_t)(*ma++);
1467
0
            }
1468
0
        }
1469
0
        break;
1470
0
        case TIFF_SSHORT:
1471
0
        {
1472
0
            int16_t *ma;
1473
0
            uint8_t *mb;
1474
0
            uint32_t n;
1475
0
            ma = (int16_t *)origdata;
1476
0
            mb = data;
1477
0
            for (n = 0; n < count; n++)
1478
0
            {
1479
0
                if (tif->tif_flags & TIFF_SWAB)
1480
0
                    TIFFSwabShort((uint16_t *)ma);
1481
0
                err = TIFFReadDirEntryCheckRangeByteSshort(*ma);
1482
0
                if (err != TIFFReadDirEntryErrOk)
1483
0
                    break;
1484
0
                *mb++ = (uint8_t)(*ma++);
1485
0
            }
1486
0
        }
1487
0
        break;
1488
0
        case TIFF_LONG:
1489
0
        {
1490
0
            uint32_t *ma;
1491
0
            uint8_t *mb;
1492
0
            uint32_t n;
1493
0
            ma = (uint32_t *)origdata;
1494
0
            mb = data;
1495
0
            for (n = 0; n < count; n++)
1496
0
            {
1497
0
                if (tif->tif_flags & TIFF_SWAB)
1498
0
                    TIFFSwabLong(ma);
1499
0
                err = TIFFReadDirEntryCheckRangeByteLong(*ma);
1500
0
                if (err != TIFFReadDirEntryErrOk)
1501
0
                    break;
1502
0
                *mb++ = (uint8_t)(*ma++);
1503
0
            }
1504
0
        }
1505
0
        break;
1506
0
        case TIFF_SLONG:
1507
0
        {
1508
0
            int32_t *ma;
1509
0
            uint8_t *mb;
1510
0
            uint32_t n;
1511
0
            ma = (int32_t *)origdata;
1512
0
            mb = data;
1513
0
            for (n = 0; n < count; n++)
1514
0
            {
1515
0
                if (tif->tif_flags & TIFF_SWAB)
1516
0
                    TIFFSwabLong((uint32_t *)ma);
1517
0
                err = TIFFReadDirEntryCheckRangeByteSlong(*ma);
1518
0
                if (err != TIFFReadDirEntryErrOk)
1519
0
                    break;
1520
0
                *mb++ = (uint8_t)(*ma++);
1521
0
            }
1522
0
        }
1523
0
        break;
1524
0
        case TIFF_LONG8:
1525
0
        {
1526
0
            uint64_t *ma;
1527
0
            uint8_t *mb;
1528
0
            uint32_t n;
1529
0
            ma = (uint64_t *)origdata;
1530
0
            mb = data;
1531
0
            for (n = 0; n < count; n++)
1532
0
            {
1533
0
                if (tif->tif_flags & TIFF_SWAB)
1534
0
                    TIFFSwabLong8(ma);
1535
0
                err = TIFFReadDirEntryCheckRangeByteLong8(*ma);
1536
0
                if (err != TIFFReadDirEntryErrOk)
1537
0
                    break;
1538
0
                *mb++ = (uint8_t)(*ma++);
1539
0
            }
1540
0
        }
1541
0
        break;
1542
0
        case TIFF_SLONG8:
1543
0
        {
1544
0
            int64_t *ma;
1545
0
            uint8_t *mb;
1546
0
            uint32_t n;
1547
0
            ma = (int64_t *)origdata;
1548
0
            mb = data;
1549
0
            for (n = 0; n < count; n++)
1550
0
            {
1551
0
                if (tif->tif_flags & TIFF_SWAB)
1552
0
                    TIFFSwabLong8((uint64_t *)ma);
1553
0
                err = TIFFReadDirEntryCheckRangeByteSlong8(*ma);
1554
0
                if (err != TIFFReadDirEntryErrOk)
1555
0
                    break;
1556
0
                *mb++ = (uint8_t)(*ma++);
1557
0
            }
1558
0
        }
1559
0
        break;
1560
0
    }
1561
0
    _TIFFfreeExt(tif, origdata);
1562
0
    if (err != TIFFReadDirEntryErrOk)
1563
0
    {
1564
0
        _TIFFfreeExt(tif, data);
1565
0
        return (err);
1566
0
    }
1567
0
    *value = data;
1568
0
    return (TIFFReadDirEntryErrOk);
1569
0
}
1570
1571
static enum TIFFReadDirEntryErr
1572
TIFFReadDirEntrySbyteArray(TIFF *tif, TIFFDirEntry *direntry, int8_t **value)
1573
0
{
1574
0
    enum TIFFReadDirEntryErr err;
1575
0
    uint32_t count;
1576
0
    void *origdata;
1577
0
    int8_t *data;
1578
0
    switch (direntry->tdir_type)
1579
0
    {
1580
0
        case TIFF_UNDEFINED:
1581
0
        case TIFF_BYTE:
1582
0
        case TIFF_SBYTE:
1583
0
        case TIFF_SHORT:
1584
0
        case TIFF_SSHORT:
1585
0
        case TIFF_LONG:
1586
0
        case TIFF_SLONG:
1587
0
        case TIFF_LONG8:
1588
0
        case TIFF_SLONG8:
1589
0
            break;
1590
0
        default:
1591
0
            return (TIFFReadDirEntryErrType);
1592
0
    }
1593
0
    err = TIFFReadDirEntryArray(tif, direntry, &count, 1, &origdata);
1594
0
    if ((err != TIFFReadDirEntryErrOk) || (origdata == 0))
1595
0
    {
1596
0
        *value = 0;
1597
0
        return (err);
1598
0
    }
1599
0
    switch (direntry->tdir_type)
1600
0
    {
1601
0
        case TIFF_UNDEFINED:
1602
0
        case TIFF_BYTE:
1603
0
        {
1604
0
            uint8_t *m;
1605
0
            uint32_t n;
1606
0
            m = (uint8_t *)origdata;
1607
0
            for (n = 0; n < count; n++)
1608
0
            {
1609
0
                err = TIFFReadDirEntryCheckRangeSbyteByte(*m);
1610
0
                if (err != TIFFReadDirEntryErrOk)
1611
0
                {
1612
0
                    _TIFFfreeExt(tif, origdata);
1613
0
                    return (err);
1614
0
                }
1615
0
                m++;
1616
0
            }
1617
0
            *value = (int8_t *)origdata;
1618
0
            return (TIFFReadDirEntryErrOk);
1619
0
        }
1620
0
        case TIFF_SBYTE:
1621
0
            *value = (int8_t *)origdata;
1622
0
            return (TIFFReadDirEntryErrOk);
1623
0
    }
1624
0
    data = (int8_t *)_TIFFmallocExt(tif, count);
1625
0
    if (data == 0)
1626
0
    {
1627
0
        _TIFFfreeExt(tif, origdata);
1628
0
        return (TIFFReadDirEntryErrAlloc);
1629
0
    }
1630
0
    switch (direntry->tdir_type)
1631
0
    {
1632
0
        case TIFF_SHORT:
1633
0
        {
1634
0
            uint16_t *ma;
1635
0
            int8_t *mb;
1636
0
            uint32_t n;
1637
0
            ma = (uint16_t *)origdata;
1638
0
            mb = data;
1639
0
            for (n = 0; n < count; n++)
1640
0
            {
1641
0
                if (tif->tif_flags & TIFF_SWAB)
1642
0
                    TIFFSwabShort(ma);
1643
0
                err = TIFFReadDirEntryCheckRangeSbyteShort(*ma);
1644
0
                if (err != TIFFReadDirEntryErrOk)
1645
0
                    break;
1646
0
                *mb++ = (int8_t)(*ma++);
1647
0
            }
1648
0
        }
1649
0
        break;
1650
0
        case TIFF_SSHORT:
1651
0
        {
1652
0
            int16_t *ma;
1653
0
            int8_t *mb;
1654
0
            uint32_t n;
1655
0
            ma = (int16_t *)origdata;
1656
0
            mb = data;
1657
0
            for (n = 0; n < count; n++)
1658
0
            {
1659
0
                if (tif->tif_flags & TIFF_SWAB)
1660
0
                    TIFFSwabShort((uint16_t *)ma);
1661
0
                err = TIFFReadDirEntryCheckRangeSbyteSshort(*ma);
1662
0
                if (err != TIFFReadDirEntryErrOk)
1663
0
                    break;
1664
0
                *mb++ = (int8_t)(*ma++);
1665
0
            }
1666
0
        }
1667
0
        break;
1668
0
        case TIFF_LONG:
1669
0
        {
1670
0
            uint32_t *ma;
1671
0
            int8_t *mb;
1672
0
            uint32_t n;
1673
0
            ma = (uint32_t *)origdata;
1674
0
            mb = data;
1675
0
            for (n = 0; n < count; n++)
1676
0
            {
1677
0
                if (tif->tif_flags & TIFF_SWAB)
1678
0
                    TIFFSwabLong(ma);
1679
0
                err = TIFFReadDirEntryCheckRangeSbyteLong(*ma);
1680
0
                if (err != TIFFReadDirEntryErrOk)
1681
0
                    break;
1682
0
                *mb++ = (int8_t)(*ma++);
1683
0
            }
1684
0
        }
1685
0
        break;
1686
0
        case TIFF_SLONG:
1687
0
        {
1688
0
            int32_t *ma;
1689
0
            int8_t *mb;
1690
0
            uint32_t n;
1691
0
            ma = (int32_t *)origdata;
1692
0
            mb = data;
1693
0
            for (n = 0; n < count; n++)
1694
0
            {
1695
0
                if (tif->tif_flags & TIFF_SWAB)
1696
0
                    TIFFSwabLong((uint32_t *)ma);
1697
0
                err = TIFFReadDirEntryCheckRangeSbyteSlong(*ma);
1698
0
                if (err != TIFFReadDirEntryErrOk)
1699
0
                    break;
1700
0
                *mb++ = (int8_t)(*ma++);
1701
0
            }
1702
0
        }
1703
0
        break;
1704
0
        case TIFF_LONG8:
1705
0
        {
1706
0
            uint64_t *ma;
1707
0
            int8_t *mb;
1708
0
            uint32_t n;
1709
0
            ma = (uint64_t *)origdata;
1710
0
            mb = data;
1711
0
            for (n = 0; n < count; n++)
1712
0
            {
1713
0
                if (tif->tif_flags & TIFF_SWAB)
1714
0
                    TIFFSwabLong8(ma);
1715
0
                err = TIFFReadDirEntryCheckRangeSbyteLong8(*ma);
1716
0
                if (err != TIFFReadDirEntryErrOk)
1717
0
                    break;
1718
0
                *mb++ = (int8_t)(*ma++);
1719
0
            }
1720
0
        }
1721
0
        break;
1722
0
        case TIFF_SLONG8:
1723
0
        {
1724
0
            int64_t *ma;
1725
0
            int8_t *mb;
1726
0
            uint32_t n;
1727
0
            ma = (int64_t *)origdata;
1728
0
            mb = data;
1729
0
            for (n = 0; n < count; n++)
1730
0
            {
1731
0
                if (tif->tif_flags & TIFF_SWAB)
1732
0
                    TIFFSwabLong8((uint64_t *)ma);
1733
0
                err = TIFFReadDirEntryCheckRangeSbyteSlong8(*ma);
1734
0
                if (err != TIFFReadDirEntryErrOk)
1735
0
                    break;
1736
0
                *mb++ = (int8_t)(*ma++);
1737
0
            }
1738
0
        }
1739
0
        break;
1740
0
    }
1741
0
    _TIFFfreeExt(tif, origdata);
1742
0
    if (err != TIFFReadDirEntryErrOk)
1743
0
    {
1744
0
        _TIFFfreeExt(tif, data);
1745
0
        return (err);
1746
0
    }
1747
0
    *value = data;
1748
0
    return (TIFFReadDirEntryErrOk);
1749
0
}
1750
1751
static enum TIFFReadDirEntryErr
1752
TIFFReadDirEntryShortArray(TIFF *tif, TIFFDirEntry *direntry, uint16_t **value)
1753
0
{
1754
0
    enum TIFFReadDirEntryErr err;
1755
0
    uint32_t count;
1756
0
    void *origdata;
1757
0
    uint16_t *data;
1758
0
    switch (direntry->tdir_type)
1759
0
    {
1760
0
        case TIFF_BYTE:
1761
0
        case TIFF_SBYTE:
1762
0
        case TIFF_SHORT:
1763
0
        case TIFF_SSHORT:
1764
0
        case TIFF_LONG:
1765
0
        case TIFF_SLONG:
1766
0
        case TIFF_LONG8:
1767
0
        case TIFF_SLONG8:
1768
0
            break;
1769
0
        default:
1770
0
            return (TIFFReadDirEntryErrType);
1771
0
    }
1772
0
    err = TIFFReadDirEntryArray(tif, direntry, &count, 2, &origdata);
1773
0
    if ((err != TIFFReadDirEntryErrOk) || (origdata == 0))
1774
0
    {
1775
0
        *value = 0;
1776
0
        return (err);
1777
0
    }
1778
0
    switch (direntry->tdir_type)
1779
0
    {
1780
0
        case TIFF_SHORT:
1781
0
            *value = (uint16_t *)origdata;
1782
0
            if (tif->tif_flags & TIFF_SWAB)
1783
0
                TIFFSwabArrayOfShort(*value, count);
1784
0
            return (TIFFReadDirEntryErrOk);
1785
0
        case TIFF_SSHORT:
1786
0
        {
1787
0
            int16_t *m;
1788
0
            uint32_t n;
1789
0
            m = (int16_t *)origdata;
1790
0
            for (n = 0; n < count; n++)
1791
0
            {
1792
0
                if (tif->tif_flags & TIFF_SWAB)
1793
0
                    TIFFSwabShort((uint16_t *)m);
1794
0
                err = TIFFReadDirEntryCheckRangeShortSshort(*m);
1795
0
                if (err != TIFFReadDirEntryErrOk)
1796
0
                {
1797
0
                    _TIFFfreeExt(tif, origdata);
1798
0
                    return (err);
1799
0
                }
1800
0
                m++;
1801
0
            }
1802
0
            *value = (uint16_t *)origdata;
1803
0
            return (TIFFReadDirEntryErrOk);
1804
0
        }
1805
0
    }
1806
0
    data = (uint16_t *)_TIFFmallocExt(tif, count * 2);
1807
0
    if (data == 0)
1808
0
    {
1809
0
        _TIFFfreeExt(tif, origdata);
1810
0
        return (TIFFReadDirEntryErrAlloc);
1811
0
    }
1812
0
    switch (direntry->tdir_type)
1813
0
    {
1814
0
        case TIFF_BYTE:
1815
0
        {
1816
0
            uint8_t *ma;
1817
0
            uint16_t *mb;
1818
0
            uint32_t n;
1819
0
            ma = (uint8_t *)origdata;
1820
0
            mb = data;
1821
0
            for (n = 0; n < count; n++)
1822
0
                *mb++ = (uint16_t)(*ma++);
1823
0
        }
1824
0
        break;
1825
0
        case TIFF_SBYTE:
1826
0
        {
1827
0
            int8_t *ma;
1828
0
            uint16_t *mb;
1829
0
            uint32_t n;
1830
0
            ma = (int8_t *)origdata;
1831
0
            mb = data;
1832
0
            for (n = 0; n < count; n++)
1833
0
            {
1834
0
                err = TIFFReadDirEntryCheckRangeShortSbyte(*ma);
1835
0
                if (err != TIFFReadDirEntryErrOk)
1836
0
                    break;
1837
0
                *mb++ = (uint16_t)(*ma++);
1838
0
            }
1839
0
        }
1840
0
        break;
1841
0
        case TIFF_LONG:
1842
0
        {
1843
0
            uint32_t *ma;
1844
0
            uint16_t *mb;
1845
0
            uint32_t n;
1846
0
            ma = (uint32_t *)origdata;
1847
0
            mb = data;
1848
0
            for (n = 0; n < count; n++)
1849
0
            {
1850
0
                if (tif->tif_flags & TIFF_SWAB)
1851
0
                    TIFFSwabLong(ma);
1852
0
                err = TIFFReadDirEntryCheckRangeShortLong(*ma);
1853
0
                if (err != TIFFReadDirEntryErrOk)
1854
0
                    break;
1855
0
                *mb++ = (uint16_t)(*ma++);
1856
0
            }
1857
0
        }
1858
0
        break;
1859
0
        case TIFF_SLONG:
1860
0
        {
1861
0
            int32_t *ma;
1862
0
            uint16_t *mb;
1863
0
            uint32_t n;
1864
0
            ma = (int32_t *)origdata;
1865
0
            mb = data;
1866
0
            for (n = 0; n < count; n++)
1867
0
            {
1868
0
                if (tif->tif_flags & TIFF_SWAB)
1869
0
                    TIFFSwabLong((uint32_t *)ma);
1870
0
                err = TIFFReadDirEntryCheckRangeShortSlong(*ma);
1871
0
                if (err != TIFFReadDirEntryErrOk)
1872
0
                    break;
1873
0
                *mb++ = (uint16_t)(*ma++);
1874
0
            }
1875
0
        }
1876
0
        break;
1877
0
        case TIFF_LONG8:
1878
0
        {
1879
0
            uint64_t *ma;
1880
0
            uint16_t *mb;
1881
0
            uint32_t n;
1882
0
            ma = (uint64_t *)origdata;
1883
0
            mb = data;
1884
0
            for (n = 0; n < count; n++)
1885
0
            {
1886
0
                if (tif->tif_flags & TIFF_SWAB)
1887
0
                    TIFFSwabLong8(ma);
1888
0
                err = TIFFReadDirEntryCheckRangeShortLong8(*ma);
1889
0
                if (err != TIFFReadDirEntryErrOk)
1890
0
                    break;
1891
0
                *mb++ = (uint16_t)(*ma++);
1892
0
            }
1893
0
        }
1894
0
        break;
1895
0
        case TIFF_SLONG8:
1896
0
        {
1897
0
            int64_t *ma;
1898
0
            uint16_t *mb;
1899
0
            uint32_t n;
1900
0
            ma = (int64_t *)origdata;
1901
0
            mb = data;
1902
0
            for (n = 0; n < count; n++)
1903
0
            {
1904
0
                if (tif->tif_flags & TIFF_SWAB)
1905
0
                    TIFFSwabLong8((uint64_t *)ma);
1906
0
                err = TIFFReadDirEntryCheckRangeShortSlong8(*ma);
1907
0
                if (err != TIFFReadDirEntryErrOk)
1908
0
                    break;
1909
0
                *mb++ = (uint16_t)(*ma++);
1910
0
            }
1911
0
        }
1912
0
        break;
1913
0
    }
1914
0
    _TIFFfreeExt(tif, origdata);
1915
0
    if (err != TIFFReadDirEntryErrOk)
1916
0
    {
1917
0
        _TIFFfreeExt(tif, data);
1918
0
        return (err);
1919
0
    }
1920
0
    *value = data;
1921
0
    return (TIFFReadDirEntryErrOk);
1922
0
}
1923
1924
static enum TIFFReadDirEntryErr
1925
TIFFReadDirEntrySshortArray(TIFF *tif, TIFFDirEntry *direntry, int16_t **value)
1926
0
{
1927
0
    enum TIFFReadDirEntryErr err;
1928
0
    uint32_t count;
1929
0
    void *origdata;
1930
0
    int16_t *data;
1931
0
    switch (direntry->tdir_type)
1932
0
    {
1933
0
        case TIFF_BYTE:
1934
0
        case TIFF_SBYTE:
1935
0
        case TIFF_SHORT:
1936
0
        case TIFF_SSHORT:
1937
0
        case TIFF_LONG:
1938
0
        case TIFF_SLONG:
1939
0
        case TIFF_LONG8:
1940
0
        case TIFF_SLONG8:
1941
0
            break;
1942
0
        default:
1943
0
            return (TIFFReadDirEntryErrType);
1944
0
    }
1945
0
    err = TIFFReadDirEntryArray(tif, direntry, &count, 2, &origdata);
1946
0
    if ((err != TIFFReadDirEntryErrOk) || (origdata == 0))
1947
0
    {
1948
0
        *value = 0;
1949
0
        return (err);
1950
0
    }
1951
0
    switch (direntry->tdir_type)
1952
0
    {
1953
0
        case TIFF_SHORT:
1954
0
        {
1955
0
            uint16_t *m;
1956
0
            uint32_t n;
1957
0
            m = (uint16_t *)origdata;
1958
0
            for (n = 0; n < count; n++)
1959
0
            {
1960
0
                if (tif->tif_flags & TIFF_SWAB)
1961
0
                    TIFFSwabShort(m);
1962
0
                err = TIFFReadDirEntryCheckRangeSshortShort(*m);
1963
0
                if (err != TIFFReadDirEntryErrOk)
1964
0
                {
1965
0
                    _TIFFfreeExt(tif, origdata);
1966
0
                    return (err);
1967
0
                }
1968
0
                m++;
1969
0
            }
1970
0
            *value = (int16_t *)origdata;
1971
0
            return (TIFFReadDirEntryErrOk);
1972
0
        }
1973
0
        case TIFF_SSHORT:
1974
0
            *value = (int16_t *)origdata;
1975
0
            if (tif->tif_flags & TIFF_SWAB)
1976
0
                TIFFSwabArrayOfShort((uint16_t *)(*value), count);
1977
0
            return (TIFFReadDirEntryErrOk);
1978
0
    }
1979
0
    data = (int16_t *)_TIFFmallocExt(tif, count * 2);
1980
0
    if (data == 0)
1981
0
    {
1982
0
        _TIFFfreeExt(tif, origdata);
1983
0
        return (TIFFReadDirEntryErrAlloc);
1984
0
    }
1985
0
    switch (direntry->tdir_type)
1986
0
    {
1987
0
        case TIFF_BYTE:
1988
0
        {
1989
0
            uint8_t *ma;
1990
0
            int16_t *mb;
1991
0
            uint32_t n;
1992
0
            ma = (uint8_t *)origdata;
1993
0
            mb = data;
1994
0
            for (n = 0; n < count; n++)
1995
0
                *mb++ = (int16_t)(*ma++);
1996
0
        }
1997
0
        break;
1998
0
        case TIFF_SBYTE:
1999
0
        {
2000
0
            int8_t *ma;
2001
0
            int16_t *mb;
2002
0
            uint32_t n;
2003
0
            ma = (int8_t *)origdata;
2004
0
            mb = data;
2005
0
            for (n = 0; n < count; n++)
2006
0
                *mb++ = (int16_t)(*ma++);
2007
0
        }
2008
0
        break;
2009
0
        case TIFF_LONG:
2010
0
        {
2011
0
            uint32_t *ma;
2012
0
            int16_t *mb;
2013
0
            uint32_t n;
2014
0
            ma = (uint32_t *)origdata;
2015
0
            mb = data;
2016
0
            for (n = 0; n < count; n++)
2017
0
            {
2018
0
                if (tif->tif_flags & TIFF_SWAB)
2019
0
                    TIFFSwabLong(ma);
2020
0
                err = TIFFReadDirEntryCheckRangeSshortLong(*ma);
2021
0
                if (err != TIFFReadDirEntryErrOk)
2022
0
                    break;
2023
0
                *mb++ = (int16_t)(*ma++);
2024
0
            }
2025
0
        }
2026
0
        break;
2027
0
        case TIFF_SLONG:
2028
0
        {
2029
0
            int32_t *ma;
2030
0
            int16_t *mb;
2031
0
            uint32_t n;
2032
0
            ma = (int32_t *)origdata;
2033
0
            mb = data;
2034
0
            for (n = 0; n < count; n++)
2035
0
            {
2036
0
                if (tif->tif_flags & TIFF_SWAB)
2037
0
                    TIFFSwabLong((uint32_t *)ma);
2038
0
                err = TIFFReadDirEntryCheckRangeSshortSlong(*ma);
2039
0
                if (err != TIFFReadDirEntryErrOk)
2040
0
                    break;
2041
0
                *mb++ = (int16_t)(*ma++);
2042
0
            }
2043
0
        }
2044
0
        break;
2045
0
        case TIFF_LONG8:
2046
0
        {
2047
0
            uint64_t *ma;
2048
0
            int16_t *mb;
2049
0
            uint32_t n;
2050
0
            ma = (uint64_t *)origdata;
2051
0
            mb = data;
2052
0
            for (n = 0; n < count; n++)
2053
0
            {
2054
0
                if (tif->tif_flags & TIFF_SWAB)
2055
0
                    TIFFSwabLong8(ma);
2056
0
                err = TIFFReadDirEntryCheckRangeSshortLong8(*ma);
2057
0
                if (err != TIFFReadDirEntryErrOk)
2058
0
                    break;
2059
0
                *mb++ = (int16_t)(*ma++);
2060
0
            }
2061
0
        }
2062
0
        break;
2063
0
        case TIFF_SLONG8:
2064
0
        {
2065
0
            int64_t *ma;
2066
0
            int16_t *mb;
2067
0
            uint32_t n;
2068
0
            ma = (int64_t *)origdata;
2069
0
            mb = data;
2070
0
            for (n = 0; n < count; n++)
2071
0
            {
2072
0
                if (tif->tif_flags & TIFF_SWAB)
2073
0
                    TIFFSwabLong8((uint64_t *)ma);
2074
0
                err = TIFFReadDirEntryCheckRangeSshortSlong8(*ma);
2075
0
                if (err != TIFFReadDirEntryErrOk)
2076
0
                    break;
2077
0
                *mb++ = (int16_t)(*ma++);
2078
0
            }
2079
0
        }
2080
0
        break;
2081
0
    }
2082
0
    _TIFFfreeExt(tif, origdata);
2083
0
    if (err != TIFFReadDirEntryErrOk)
2084
0
    {
2085
0
        _TIFFfreeExt(tif, data);
2086
0
        return (err);
2087
0
    }
2088
0
    *value = data;
2089
0
    return (TIFFReadDirEntryErrOk);
2090
0
}
2091
2092
static enum TIFFReadDirEntryErr
2093
TIFFReadDirEntryLongArray(TIFF *tif, TIFFDirEntry *direntry, uint32_t **value)
2094
0
{
2095
0
    enum TIFFReadDirEntryErr err;
2096
0
    uint32_t count;
2097
0
    void *origdata;
2098
0
    uint32_t *data;
2099
0
    switch (direntry->tdir_type)
2100
0
    {
2101
0
        case TIFF_BYTE:
2102
0
        case TIFF_SBYTE:
2103
0
        case TIFF_SHORT:
2104
0
        case TIFF_SSHORT:
2105
0
        case TIFF_LONG:
2106
0
        case TIFF_SLONG:
2107
0
        case TIFF_LONG8:
2108
0
        case TIFF_SLONG8:
2109
0
            break;
2110
0
        default:
2111
0
            return (TIFFReadDirEntryErrType);
2112
0
    }
2113
0
    err = TIFFReadDirEntryArray(tif, direntry, &count, 4, &origdata);
2114
0
    if ((err != TIFFReadDirEntryErrOk) || (origdata == 0))
2115
0
    {
2116
0
        *value = 0;
2117
0
        return (err);
2118
0
    }
2119
0
    switch (direntry->tdir_type)
2120
0
    {
2121
0
        case TIFF_LONG:
2122
0
            *value = (uint32_t *)origdata;
2123
0
            if (tif->tif_flags & TIFF_SWAB)
2124
0
                TIFFSwabArrayOfLong(*value, count);
2125
0
            return (TIFFReadDirEntryErrOk);
2126
0
        case TIFF_SLONG:
2127
0
        {
2128
0
            int32_t *m;
2129
0
            uint32_t n;
2130
0
            m = (int32_t *)origdata;
2131
0
            for (n = 0; n < count; n++)
2132
0
            {
2133
0
                if (tif->tif_flags & TIFF_SWAB)
2134
0
                    TIFFSwabLong((uint32_t *)m);
2135
0
                err = TIFFReadDirEntryCheckRangeLongSlong(*m);
2136
0
                if (err != TIFFReadDirEntryErrOk)
2137
0
                {
2138
0
                    _TIFFfreeExt(tif, origdata);
2139
0
                    return (err);
2140
0
                }
2141
0
                m++;
2142
0
            }
2143
0
            *value = (uint32_t *)origdata;
2144
0
            return (TIFFReadDirEntryErrOk);
2145
0
        }
2146
0
    }
2147
0
    data = (uint32_t *)_TIFFmallocExt(tif, count * 4);
2148
0
    if (data == 0)
2149
0
    {
2150
0
        _TIFFfreeExt(tif, origdata);
2151
0
        return (TIFFReadDirEntryErrAlloc);
2152
0
    }
2153
0
    switch (direntry->tdir_type)
2154
0
    {
2155
0
        case TIFF_BYTE:
2156
0
        {
2157
0
            uint8_t *ma;
2158
0
            uint32_t *mb;
2159
0
            uint32_t n;
2160
0
            ma = (uint8_t *)origdata;
2161
0
            mb = data;
2162
0
            for (n = 0; n < count; n++)
2163
0
                *mb++ = (uint32_t)(*ma++);
2164
0
        }
2165
0
        break;
2166
0
        case TIFF_SBYTE:
2167
0
        {
2168
0
            int8_t *ma;
2169
0
            uint32_t *mb;
2170
0
            uint32_t n;
2171
0
            ma = (int8_t *)origdata;
2172
0
            mb = data;
2173
0
            for (n = 0; n < count; n++)
2174
0
            {
2175
0
                err = TIFFReadDirEntryCheckRangeLongSbyte(*ma);
2176
0
                if (err != TIFFReadDirEntryErrOk)
2177
0
                    break;
2178
0
                *mb++ = (uint32_t)(*ma++);
2179
0
            }
2180
0
        }
2181
0
        break;
2182
0
        case TIFF_SHORT:
2183
0
        {
2184
0
            uint16_t *ma;
2185
0
            uint32_t *mb;
2186
0
            uint32_t n;
2187
0
            ma = (uint16_t *)origdata;
2188
0
            mb = data;
2189
0
            for (n = 0; n < count; n++)
2190
0
            {
2191
0
                if (tif->tif_flags & TIFF_SWAB)
2192
0
                    TIFFSwabShort(ma);
2193
0
                *mb++ = (uint32_t)(*ma++);
2194
0
            }
2195
0
        }
2196
0
        break;
2197
0
        case TIFF_SSHORT:
2198
0
        {
2199
0
            int16_t *ma;
2200
0
            uint32_t *mb;
2201
0
            uint32_t n;
2202
0
            ma = (int16_t *)origdata;
2203
0
            mb = data;
2204
0
            for (n = 0; n < count; n++)
2205
0
            {
2206
0
                if (tif->tif_flags & TIFF_SWAB)
2207
0
                    TIFFSwabShort((uint16_t *)ma);
2208
0
                err = TIFFReadDirEntryCheckRangeLongSshort(*ma);
2209
0
                if (err != TIFFReadDirEntryErrOk)
2210
0
                    break;
2211
0
                *mb++ = (uint32_t)(*ma++);
2212
0
            }
2213
0
        }
2214
0
        break;
2215
0
        case TIFF_LONG8:
2216
0
        {
2217
0
            uint64_t *ma;
2218
0
            uint32_t *mb;
2219
0
            uint32_t n;
2220
0
            ma = (uint64_t *)origdata;
2221
0
            mb = data;
2222
0
            for (n = 0; n < count; n++)
2223
0
            {
2224
0
                if (tif->tif_flags & TIFF_SWAB)
2225
0
                    TIFFSwabLong8(ma);
2226
0
                err = TIFFReadDirEntryCheckRangeLongLong8(*ma);
2227
0
                if (err != TIFFReadDirEntryErrOk)
2228
0
                    break;
2229
0
                *mb++ = (uint32_t)(*ma++);
2230
0
            }
2231
0
        }
2232
0
        break;
2233
0
        case TIFF_SLONG8:
2234
0
        {
2235
0
            int64_t *ma;
2236
0
            uint32_t *mb;
2237
0
            uint32_t n;
2238
0
            ma = (int64_t *)origdata;
2239
0
            mb = data;
2240
0
            for (n = 0; n < count; n++)
2241
0
            {
2242
0
                if (tif->tif_flags & TIFF_SWAB)
2243
0
                    TIFFSwabLong8((uint64_t *)ma);
2244
0
                err = TIFFReadDirEntryCheckRangeLongSlong8(*ma);
2245
0
                if (err != TIFFReadDirEntryErrOk)
2246
0
                    break;
2247
0
                *mb++ = (uint32_t)(*ma++);
2248
0
            }
2249
0
        }
2250
0
        break;
2251
0
    }
2252
0
    _TIFFfreeExt(tif, origdata);
2253
0
    if (err != TIFFReadDirEntryErrOk)
2254
0
    {
2255
0
        _TIFFfreeExt(tif, data);
2256
0
        return (err);
2257
0
    }
2258
0
    *value = data;
2259
0
    return (TIFFReadDirEntryErrOk);
2260
0
}
2261
2262
static enum TIFFReadDirEntryErr
2263
TIFFReadDirEntrySlongArray(TIFF *tif, TIFFDirEntry *direntry, int32_t **value)
2264
0
{
2265
0
    enum TIFFReadDirEntryErr err;
2266
0
    uint32_t count;
2267
0
    void *origdata;
2268
0
    int32_t *data;
2269
0
    switch (direntry->tdir_type)
2270
0
    {
2271
0
        case TIFF_BYTE:
2272
0
        case TIFF_SBYTE:
2273
0
        case TIFF_SHORT:
2274
0
        case TIFF_SSHORT:
2275
0
        case TIFF_LONG:
2276
0
        case TIFF_SLONG:
2277
0
        case TIFF_LONG8:
2278
0
        case TIFF_SLONG8:
2279
0
            break;
2280
0
        default:
2281
0
            return (TIFFReadDirEntryErrType);
2282
0
    }
2283
0
    err = TIFFReadDirEntryArray(tif, direntry, &count, 4, &origdata);
2284
0
    if ((err != TIFFReadDirEntryErrOk) || (origdata == 0))
2285
0
    {
2286
0
        *value = 0;
2287
0
        return (err);
2288
0
    }
2289
0
    switch (direntry->tdir_type)
2290
0
    {
2291
0
        case TIFF_LONG:
2292
0
        {
2293
0
            uint32_t *m;
2294
0
            uint32_t n;
2295
0
            m = (uint32_t *)origdata;
2296
0
            for (n = 0; n < count; n++)
2297
0
            {
2298
0
                if (tif->tif_flags & TIFF_SWAB)
2299
0
                    TIFFSwabLong((uint32_t *)m);
2300
0
                err = TIFFReadDirEntryCheckRangeSlongLong(*m);
2301
0
                if (err != TIFFReadDirEntryErrOk)
2302
0
                {
2303
0
                    _TIFFfreeExt(tif, origdata);
2304
0
                    return (err);
2305
0
                }
2306
0
                m++;
2307
0
            }
2308
0
            *value = (int32_t *)origdata;
2309
0
            return (TIFFReadDirEntryErrOk);
2310
0
        }
2311
0
        case TIFF_SLONG:
2312
0
            *value = (int32_t *)origdata;
2313
0
            if (tif->tif_flags & TIFF_SWAB)
2314
0
                TIFFSwabArrayOfLong((uint32_t *)(*value), count);
2315
0
            return (TIFFReadDirEntryErrOk);
2316
0
    }
2317
0
    data = (int32_t *)_TIFFmallocExt(tif, count * 4);
2318
0
    if (data == 0)
2319
0
    {
2320
0
        _TIFFfreeExt(tif, origdata);
2321
0
        return (TIFFReadDirEntryErrAlloc);
2322
0
    }
2323
0
    switch (direntry->tdir_type)
2324
0
    {
2325
0
        case TIFF_BYTE:
2326
0
        {
2327
0
            uint8_t *ma;
2328
0
            int32_t *mb;
2329
0
            uint32_t n;
2330
0
            ma = (uint8_t *)origdata;
2331
0
            mb = data;
2332
0
            for (n = 0; n < count; n++)
2333
0
                *mb++ = (int32_t)(*ma++);
2334
0
        }
2335
0
        break;
2336
0
        case TIFF_SBYTE:
2337
0
        {
2338
0
            int8_t *ma;
2339
0
            int32_t *mb;
2340
0
            uint32_t n;
2341
0
            ma = (int8_t *)origdata;
2342
0
            mb = data;
2343
0
            for (n = 0; n < count; n++)
2344
0
                *mb++ = (int32_t)(*ma++);
2345
0
        }
2346
0
        break;
2347
0
        case TIFF_SHORT:
2348
0
        {
2349
0
            uint16_t *ma;
2350
0
            int32_t *mb;
2351
0
            uint32_t n;
2352
0
            ma = (uint16_t *)origdata;
2353
0
            mb = data;
2354
0
            for (n = 0; n < count; n++)
2355
0
            {
2356
0
                if (tif->tif_flags & TIFF_SWAB)
2357
0
                    TIFFSwabShort(ma);
2358
0
                *mb++ = (int32_t)(*ma++);
2359
0
            }
2360
0
        }
2361
0
        break;
2362
0
        case TIFF_SSHORT:
2363
0
        {
2364
0
            int16_t *ma;
2365
0
            int32_t *mb;
2366
0
            uint32_t n;
2367
0
            ma = (int16_t *)origdata;
2368
0
            mb = data;
2369
0
            for (n = 0; n < count; n++)
2370
0
            {
2371
0
                if (tif->tif_flags & TIFF_SWAB)
2372
0
                    TIFFSwabShort((uint16_t *)ma);
2373
0
                *mb++ = (int32_t)(*ma++);
2374
0
            }
2375
0
        }
2376
0
        break;
2377
0
        case TIFF_LONG8:
2378
0
        {
2379
0
            uint64_t *ma;
2380
0
            int32_t *mb;
2381
0
            uint32_t n;
2382
0
            ma = (uint64_t *)origdata;
2383
0
            mb = data;
2384
0
            for (n = 0; n < count; n++)
2385
0
            {
2386
0
                if (tif->tif_flags & TIFF_SWAB)
2387
0
                    TIFFSwabLong8(ma);
2388
0
                err = TIFFReadDirEntryCheckRangeSlongLong8(*ma);
2389
0
                if (err != TIFFReadDirEntryErrOk)
2390
0
                    break;
2391
0
                *mb++ = (int32_t)(*ma++);
2392
0
            }
2393
0
        }
2394
0
        break;
2395
0
        case TIFF_SLONG8:
2396
0
        {
2397
0
            int64_t *ma;
2398
0
            int32_t *mb;
2399
0
            uint32_t n;
2400
0
            ma = (int64_t *)origdata;
2401
0
            mb = data;
2402
0
            for (n = 0; n < count; n++)
2403
0
            {
2404
0
                if (tif->tif_flags & TIFF_SWAB)
2405
0
                    TIFFSwabLong8((uint64_t *)ma);
2406
0
                err = TIFFReadDirEntryCheckRangeSlongSlong8(*ma);
2407
0
                if (err != TIFFReadDirEntryErrOk)
2408
0
                    break;
2409
0
                *mb++ = (int32_t)(*ma++);
2410
0
            }
2411
0
        }
2412
0
        break;
2413
0
    }
2414
0
    _TIFFfreeExt(tif, origdata);
2415
0
    if (err != TIFFReadDirEntryErrOk)
2416
0
    {
2417
0
        _TIFFfreeExt(tif, data);
2418
0
        return (err);
2419
0
    }
2420
0
    *value = data;
2421
0
    return (TIFFReadDirEntryErrOk);
2422
0
}
2423
2424
static enum TIFFReadDirEntryErr
2425
TIFFReadDirEntryLong8ArrayWithLimit(TIFF *tif, TIFFDirEntry *direntry,
2426
                                    uint64_t **value, uint64_t maxcount)
2427
0
{
2428
0
    enum TIFFReadDirEntryErr err;
2429
0
    uint32_t count;
2430
0
    void *origdata;
2431
0
    uint64_t *data;
2432
0
    switch (direntry->tdir_type)
2433
0
    {
2434
0
        case TIFF_BYTE:
2435
0
        case TIFF_SBYTE:
2436
0
        case TIFF_SHORT:
2437
0
        case TIFF_SSHORT:
2438
0
        case TIFF_LONG:
2439
0
        case TIFF_SLONG:
2440
0
        case TIFF_LONG8:
2441
0
        case TIFF_SLONG8:
2442
0
            break;
2443
0
        default:
2444
0
            return (TIFFReadDirEntryErrType);
2445
0
    }
2446
0
    err = TIFFReadDirEntryArrayWithLimit(tif, direntry, &count, 8, &origdata,
2447
0
                                         maxcount);
2448
0
    if ((err != TIFFReadDirEntryErrOk) || (origdata == 0))
2449
0
    {
2450
0
        *value = 0;
2451
0
        return (err);
2452
0
    }
2453
0
    switch (direntry->tdir_type)
2454
0
    {
2455
0
        case TIFF_LONG8:
2456
0
            *value = (uint64_t *)origdata;
2457
0
            if (tif->tif_flags & TIFF_SWAB)
2458
0
                TIFFSwabArrayOfLong8(*value, count);
2459
0
            return (TIFFReadDirEntryErrOk);
2460
0
        case TIFF_SLONG8:
2461
0
        {
2462
0
            int64_t *m;
2463
0
            uint32_t n;
2464
0
            m = (int64_t *)origdata;
2465
0
            for (n = 0; n < count; n++)
2466
0
            {
2467
0
                if (tif->tif_flags & TIFF_SWAB)
2468
0
                    TIFFSwabLong8((uint64_t *)m);
2469
0
                err = TIFFReadDirEntryCheckRangeLong8Slong8(*m);
2470
0
                if (err != TIFFReadDirEntryErrOk)
2471
0
                {
2472
0
                    _TIFFfreeExt(tif, origdata);
2473
0
                    return (err);
2474
0
                }
2475
0
                m++;
2476
0
            }
2477
0
            *value = (uint64_t *)origdata;
2478
0
            return (TIFFReadDirEntryErrOk);
2479
0
        }
2480
0
    }
2481
0
    data = (uint64_t *)_TIFFmallocExt(tif, count * 8);
2482
0
    if (data == 0)
2483
0
    {
2484
0
        _TIFFfreeExt(tif, origdata);
2485
0
        return (TIFFReadDirEntryErrAlloc);
2486
0
    }
2487
0
    switch (direntry->tdir_type)
2488
0
    {
2489
0
        case TIFF_BYTE:
2490
0
        {
2491
0
            uint8_t *ma;
2492
0
            uint64_t *mb;
2493
0
            uint32_t n;
2494
0
            ma = (uint8_t *)origdata;
2495
0
            mb = data;
2496
0
            for (n = 0; n < count; n++)
2497
0
                *mb++ = (uint64_t)(*ma++);
2498
0
        }
2499
0
        break;
2500
0
        case TIFF_SBYTE:
2501
0
        {
2502
0
            int8_t *ma;
2503
0
            uint64_t *mb;
2504
0
            uint32_t n;
2505
0
            ma = (int8_t *)origdata;
2506
0
            mb = data;
2507
0
            for (n = 0; n < count; n++)
2508
0
            {
2509
0
                err = TIFFReadDirEntryCheckRangeLong8Sbyte(*ma);
2510
0
                if (err != TIFFReadDirEntryErrOk)
2511
0
                    break;
2512
0
                *mb++ = (uint64_t)(*ma++);
2513
0
            }
2514
0
        }
2515
0
        break;
2516
0
        case TIFF_SHORT:
2517
0
        {
2518
0
            uint16_t *ma;
2519
0
            uint64_t *mb;
2520
0
            uint32_t n;
2521
0
            ma = (uint16_t *)origdata;
2522
0
            mb = data;
2523
0
            for (n = 0; n < count; n++)
2524
0
            {
2525
0
                if (tif->tif_flags & TIFF_SWAB)
2526
0
                    TIFFSwabShort(ma);
2527
0
                *mb++ = (uint64_t)(*ma++);
2528
0
            }
2529
0
        }
2530
0
        break;
2531
0
        case TIFF_SSHORT:
2532
0
        {
2533
0
            int16_t *ma;
2534
0
            uint64_t *mb;
2535
0
            uint32_t n;
2536
0
            ma = (int16_t *)origdata;
2537
0
            mb = data;
2538
0
            for (n = 0; n < count; n++)
2539
0
            {
2540
0
                if (tif->tif_flags & TIFF_SWAB)
2541
0
                    TIFFSwabShort((uint16_t *)ma);
2542
0
                err = TIFFReadDirEntryCheckRangeLong8Sshort(*ma);
2543
0
                if (err != TIFFReadDirEntryErrOk)
2544
0
                    break;
2545
0
                *mb++ = (uint64_t)(*ma++);
2546
0
            }
2547
0
        }
2548
0
        break;
2549
0
        case TIFF_LONG:
2550
0
        {
2551
0
            uint32_t *ma;
2552
0
            uint64_t *mb;
2553
0
            uint32_t n;
2554
0
            ma = (uint32_t *)origdata;
2555
0
            mb = data;
2556
0
            for (n = 0; n < count; n++)
2557
0
            {
2558
0
                if (tif->tif_flags & TIFF_SWAB)
2559
0
                    TIFFSwabLong(ma);
2560
0
                *mb++ = (uint64_t)(*ma++);
2561
0
            }
2562
0
        }
2563
0
        break;
2564
0
        case TIFF_SLONG:
2565
0
        {
2566
0
            int32_t *ma;
2567
0
            uint64_t *mb;
2568
0
            uint32_t n;
2569
0
            ma = (int32_t *)origdata;
2570
0
            mb = data;
2571
0
            for (n = 0; n < count; n++)
2572
0
            {
2573
0
                if (tif->tif_flags & TIFF_SWAB)
2574
0
                    TIFFSwabLong((uint32_t *)ma);
2575
0
                err = TIFFReadDirEntryCheckRangeLong8Slong(*ma);
2576
0
                if (err != TIFFReadDirEntryErrOk)
2577
0
                    break;
2578
0
                *mb++ = (uint64_t)(*ma++);
2579
0
            }
2580
0
        }
2581
0
        break;
2582
0
    }
2583
0
    _TIFFfreeExt(tif, origdata);
2584
0
    if (err != TIFFReadDirEntryErrOk)
2585
0
    {
2586
0
        _TIFFfreeExt(tif, data);
2587
0
        return (err);
2588
0
    }
2589
0
    *value = data;
2590
0
    return (TIFFReadDirEntryErrOk);
2591
0
}
2592
2593
static enum TIFFReadDirEntryErr
2594
TIFFReadDirEntryLong8Array(TIFF *tif, TIFFDirEntry *direntry, uint64_t **value)
2595
0
{
2596
0
    return TIFFReadDirEntryLong8ArrayWithLimit(tif, direntry, value,
2597
0
                                               ~((uint64_t)0));
2598
0
}
2599
2600
static enum TIFFReadDirEntryErr
2601
TIFFReadDirEntrySlong8Array(TIFF *tif, TIFFDirEntry *direntry, int64_t **value)
2602
0
{
2603
0
    enum TIFFReadDirEntryErr err;
2604
0
    uint32_t count;
2605
0
    void *origdata;
2606
0
    int64_t *data;
2607
0
    switch (direntry->tdir_type)
2608
0
    {
2609
0
        case TIFF_BYTE:
2610
0
        case TIFF_SBYTE:
2611
0
        case TIFF_SHORT:
2612
0
        case TIFF_SSHORT:
2613
0
        case TIFF_LONG:
2614
0
        case TIFF_SLONG:
2615
0
        case TIFF_LONG8:
2616
0
        case TIFF_SLONG8:
2617
0
            break;
2618
0
        default:
2619
0
            return (TIFFReadDirEntryErrType);
2620
0
    }
2621
0
    err = TIFFReadDirEntryArray(tif, direntry, &count, 8, &origdata);
2622
0
    if ((err != TIFFReadDirEntryErrOk) || (origdata == 0))
2623
0
    {
2624
0
        *value = 0;
2625
0
        return (err);
2626
0
    }
2627
0
    switch (direntry->tdir_type)
2628
0
    {
2629
0
        case TIFF_LONG8:
2630
0
        {
2631
0
            uint64_t *m;
2632
0
            uint32_t n;
2633
0
            m = (uint64_t *)origdata;
2634
0
            for (n = 0; n < count; n++)
2635
0
            {
2636
0
                if (tif->tif_flags & TIFF_SWAB)
2637
0
                    TIFFSwabLong8(m);
2638
0
                err = TIFFReadDirEntryCheckRangeSlong8Long8(*m);
2639
0
                if (err != TIFFReadDirEntryErrOk)
2640
0
                {
2641
0
                    _TIFFfreeExt(tif, origdata);
2642
0
                    return (err);
2643
0
                }
2644
0
                m++;
2645
0
            }
2646
0
            *value = (int64_t *)origdata;
2647
0
            return (TIFFReadDirEntryErrOk);
2648
0
        }
2649
0
        case TIFF_SLONG8:
2650
0
            *value = (int64_t *)origdata;
2651
0
            if (tif->tif_flags & TIFF_SWAB)
2652
0
                TIFFSwabArrayOfLong8((uint64_t *)(*value), count);
2653
0
            return (TIFFReadDirEntryErrOk);
2654
0
    }
2655
0
    data = (int64_t *)_TIFFmallocExt(tif, count * 8);
2656
0
    if (data == 0)
2657
0
    {
2658
0
        _TIFFfreeExt(tif, origdata);
2659
0
        return (TIFFReadDirEntryErrAlloc);
2660
0
    }
2661
0
    switch (direntry->tdir_type)
2662
0
    {
2663
0
        case TIFF_BYTE:
2664
0
        {
2665
0
            uint8_t *ma;
2666
0
            int64_t *mb;
2667
0
            uint32_t n;
2668
0
            ma = (uint8_t *)origdata;
2669
0
            mb = data;
2670
0
            for (n = 0; n < count; n++)
2671
0
                *mb++ = (int64_t)(*ma++);
2672
0
        }
2673
0
        break;
2674
0
        case TIFF_SBYTE:
2675
0
        {
2676
0
            int8_t *ma;
2677
0
            int64_t *mb;
2678
0
            uint32_t n;
2679
0
            ma = (int8_t *)origdata;
2680
0
            mb = data;
2681
0
            for (n = 0; n < count; n++)
2682
0
                *mb++ = (int64_t)(*ma++);
2683
0
        }
2684
0
        break;
2685
0
        case TIFF_SHORT:
2686
0
        {
2687
0
            uint16_t *ma;
2688
0
            int64_t *mb;
2689
0
            uint32_t n;
2690
0
            ma = (uint16_t *)origdata;
2691
0
            mb = data;
2692
0
            for (n = 0; n < count; n++)
2693
0
            {
2694
0
                if (tif->tif_flags & TIFF_SWAB)
2695
0
                    TIFFSwabShort(ma);
2696
0
                *mb++ = (int64_t)(*ma++);
2697
0
            }
2698
0
        }
2699
0
        break;
2700
0
        case TIFF_SSHORT:
2701
0
        {
2702
0
            int16_t *ma;
2703
0
            int64_t *mb;
2704
0
            uint32_t n;
2705
0
            ma = (int16_t *)origdata;
2706
0
            mb = data;
2707
0
            for (n = 0; n < count; n++)
2708
0
            {
2709
0
                if (tif->tif_flags & TIFF_SWAB)
2710
0
                    TIFFSwabShort((uint16_t *)ma);
2711
0
                *mb++ = (int64_t)(*ma++);
2712
0
            }
2713
0
        }
2714
0
        break;
2715
0
        case TIFF_LONG:
2716
0
        {
2717
0
            uint32_t *ma;
2718
0
            int64_t *mb;
2719
0
            uint32_t n;
2720
0
            ma = (uint32_t *)origdata;
2721
0
            mb = data;
2722
0
            for (n = 0; n < count; n++)
2723
0
            {
2724
0
                if (tif->tif_flags & TIFF_SWAB)
2725
0
                    TIFFSwabLong(ma);
2726
0
                *mb++ = (int64_t)(*ma++);
2727
0
            }
2728
0
        }
2729
0
        break;
2730
0
        case TIFF_SLONG:
2731
0
        {
2732
0
            int32_t *ma;
2733
0
            int64_t *mb;
2734
0
            uint32_t n;
2735
0
            ma = (int32_t *)origdata;
2736
0
            mb = data;
2737
0
            for (n = 0; n < count; n++)
2738
0
            {
2739
0
                if (tif->tif_flags & TIFF_SWAB)
2740
0
                    TIFFSwabLong((uint32_t *)ma);
2741
0
                *mb++ = (int64_t)(*ma++);
2742
0
            }
2743
0
        }
2744
0
        break;
2745
0
    }
2746
0
    _TIFFfreeExt(tif, origdata);
2747
0
    *value = data;
2748
0
    return (TIFFReadDirEntryErrOk);
2749
0
}
2750
2751
static enum TIFFReadDirEntryErr
2752
TIFFReadDirEntryFloatArray(TIFF *tif, TIFFDirEntry *direntry, float **value)
2753
0
{
2754
0
    enum TIFFReadDirEntryErr err;
2755
0
    uint32_t count;
2756
0
    void *origdata;
2757
0
    float *data;
2758
0
    switch (direntry->tdir_type)
2759
0
    {
2760
0
        case TIFF_BYTE:
2761
0
        case TIFF_SBYTE:
2762
0
        case TIFF_SHORT:
2763
0
        case TIFF_SSHORT:
2764
0
        case TIFF_LONG:
2765
0
        case TIFF_SLONG:
2766
0
        case TIFF_LONG8:
2767
0
        case TIFF_SLONG8:
2768
0
        case TIFF_RATIONAL:
2769
0
        case TIFF_SRATIONAL:
2770
0
        case TIFF_FLOAT:
2771
0
        case TIFF_DOUBLE:
2772
0
            break;
2773
0
        default:
2774
0
            return (TIFFReadDirEntryErrType);
2775
0
    }
2776
0
    err = TIFFReadDirEntryArray(tif, direntry, &count, 4, &origdata);
2777
0
    if ((err != TIFFReadDirEntryErrOk) || (origdata == 0))
2778
0
    {
2779
0
        *value = 0;
2780
0
        return (err);
2781
0
    }
2782
0
    switch (direntry->tdir_type)
2783
0
    {
2784
0
        case TIFF_FLOAT:
2785
0
            if (tif->tif_flags & TIFF_SWAB)
2786
0
                TIFFSwabArrayOfLong((uint32_t *)origdata, count);
2787
0
            TIFFCvtIEEEFloatToNative(tif, count, (float *)origdata);
2788
0
            *value = (float *)origdata;
2789
0
            return (TIFFReadDirEntryErrOk);
2790
0
    }
2791
0
    data = (float *)_TIFFmallocExt(tif, count * sizeof(float));
2792
0
    if (data == 0)
2793
0
    {
2794
0
        _TIFFfreeExt(tif, origdata);
2795
0
        return (TIFFReadDirEntryErrAlloc);
2796
0
    }
2797
0
    switch (direntry->tdir_type)
2798
0
    {
2799
0
        case TIFF_BYTE:
2800
0
        {
2801
0
            uint8_t *ma;
2802
0
            float *mb;
2803
0
            uint32_t n;
2804
0
            ma = (uint8_t *)origdata;
2805
0
            mb = data;
2806
0
            for (n = 0; n < count; n++)
2807
0
                *mb++ = (float)(*ma++);
2808
0
        }
2809
0
        break;
2810
0
        case TIFF_SBYTE:
2811
0
        {
2812
0
            int8_t *ma;
2813
0
            float *mb;
2814
0
            uint32_t n;
2815
0
            ma = (int8_t *)origdata;
2816
0
            mb = data;
2817
0
            for (n = 0; n < count; n++)
2818
0
                *mb++ = (float)(*ma++);
2819
0
        }
2820
0
        break;
2821
0
        case TIFF_SHORT:
2822
0
        {
2823
0
            uint16_t *ma;
2824
0
            float *mb;
2825
0
            uint32_t n;
2826
0
            ma = (uint16_t *)origdata;
2827
0
            mb = data;
2828
0
            for (n = 0; n < count; n++)
2829
0
            {
2830
0
                if (tif->tif_flags & TIFF_SWAB)
2831
0
                    TIFFSwabShort(ma);
2832
0
                *mb++ = (float)(*ma++);
2833
0
            }
2834
0
        }
2835
0
        break;
2836
0
        case TIFF_SSHORT:
2837
0
        {
2838
0
            int16_t *ma;
2839
0
            float *mb;
2840
0
            uint32_t n;
2841
0
            ma = (int16_t *)origdata;
2842
0
            mb = data;
2843
0
            for (n = 0; n < count; n++)
2844
0
            {
2845
0
                if (tif->tif_flags & TIFF_SWAB)
2846
0
                    TIFFSwabShort((uint16_t *)ma);
2847
0
                *mb++ = (float)(*ma++);
2848
0
            }
2849
0
        }
2850
0
        break;
2851
0
        case TIFF_LONG:
2852
0
        {
2853
0
            uint32_t *ma;
2854
0
            float *mb;
2855
0
            uint32_t n;
2856
0
            ma = (uint32_t *)origdata;
2857
0
            mb = data;
2858
0
            for (n = 0; n < count; n++)
2859
0
            {
2860
0
                if (tif->tif_flags & TIFF_SWAB)
2861
0
                    TIFFSwabLong(ma);
2862
0
                *mb++ = (float)(*ma++);
2863
0
            }
2864
0
        }
2865
0
        break;
2866
0
        case TIFF_SLONG:
2867
0
        {
2868
0
            int32_t *ma;
2869
0
            float *mb;
2870
0
            uint32_t n;
2871
0
            ma = (int32_t *)origdata;
2872
0
            mb = data;
2873
0
            for (n = 0; n < count; n++)
2874
0
            {
2875
0
                if (tif->tif_flags & TIFF_SWAB)
2876
0
                    TIFFSwabLong((uint32_t *)ma);
2877
0
                *mb++ = (float)(*ma++);
2878
0
            }
2879
0
        }
2880
0
        break;
2881
0
        case TIFF_LONG8:
2882
0
        {
2883
0
            uint64_t *ma;
2884
0
            float *mb;
2885
0
            uint32_t n;
2886
0
            ma = (uint64_t *)origdata;
2887
0
            mb = data;
2888
0
            for (n = 0; n < count; n++)
2889
0
            {
2890
0
                if (tif->tif_flags & TIFF_SWAB)
2891
0
                    TIFFSwabLong8(ma);
2892
0
                *mb++ = (float)(*ma++);
2893
0
            }
2894
0
        }
2895
0
        break;
2896
0
        case TIFF_SLONG8:
2897
0
        {
2898
0
            int64_t *ma;
2899
0
            float *mb;
2900
0
            uint32_t n;
2901
0
            ma = (int64_t *)origdata;
2902
0
            mb = data;
2903
0
            for (n = 0; n < count; n++)
2904
0
            {
2905
0
                if (tif->tif_flags & TIFF_SWAB)
2906
0
                    TIFFSwabLong8((uint64_t *)ma);
2907
0
                *mb++ = (float)(*ma++);
2908
0
            }
2909
0
        }
2910
0
        break;
2911
0
        case TIFF_RATIONAL:
2912
0
        {
2913
0
            uint32_t *ma;
2914
0
            uint32_t maa;
2915
0
            uint32_t mab;
2916
0
            float *mb;
2917
0
            uint32_t n;
2918
0
            ma = (uint32_t *)origdata;
2919
0
            mb = data;
2920
0
            for (n = 0; n < count; n++)
2921
0
            {
2922
0
                if (tif->tif_flags & TIFF_SWAB)
2923
0
                    TIFFSwabLong(ma);
2924
0
                maa = *ma++;
2925
0
                if (tif->tif_flags & TIFF_SWAB)
2926
0
                    TIFFSwabLong(ma);
2927
0
                mab = *ma++;
2928
0
                if (mab == 0)
2929
0
                    *mb++ = 0.0;
2930
0
                else
2931
0
                    *mb++ = (float)maa / (float)mab;
2932
0
            }
2933
0
        }
2934
0
        break;
2935
0
        case TIFF_SRATIONAL:
2936
0
        {
2937
0
            uint32_t *ma;
2938
0
            int32_t maa;
2939
0
            uint32_t mab;
2940
0
            float *mb;
2941
0
            uint32_t n;
2942
0
            ma = (uint32_t *)origdata;
2943
0
            mb = data;
2944
0
            for (n = 0; n < count; n++)
2945
0
            {
2946
0
                if (tif->tif_flags & TIFF_SWAB)
2947
0
                    TIFFSwabLong(ma);
2948
0
                maa = *(int32_t *)ma;
2949
0
                ma++;
2950
0
                if (tif->tif_flags & TIFF_SWAB)
2951
0
                    TIFFSwabLong(ma);
2952
0
                mab = *ma++;
2953
0
                if (mab == 0)
2954
0
                    *mb++ = 0.0;
2955
0
                else
2956
0
                    *mb++ = (float)maa / (float)mab;
2957
0
            }
2958
0
        }
2959
0
        break;
2960
0
        case TIFF_DOUBLE:
2961
0
        {
2962
0
            double *ma;
2963
0
            float *mb;
2964
0
            uint32_t n;
2965
0
            if (tif->tif_flags & TIFF_SWAB)
2966
0
                TIFFSwabArrayOfLong8((uint64_t *)origdata, count);
2967
0
            TIFFCvtIEEEDoubleToNative(tif, count, (double *)origdata);
2968
0
            ma = (double *)origdata;
2969
0
            mb = data;
2970
0
            for (n = 0; n < count; n++)
2971
0
            {
2972
0
                double val = *ma++;
2973
0
                if (val > FLT_MAX)
2974
0
                    val = FLT_MAX;
2975
0
                else if (val < -FLT_MAX)
2976
0
                    val = -FLT_MAX;
2977
0
                *mb++ = (float)val;
2978
0
            }
2979
0
        }
2980
0
        break;
2981
0
    }
2982
0
    _TIFFfreeExt(tif, origdata);
2983
0
    *value = data;
2984
0
    return (TIFFReadDirEntryErrOk);
2985
0
}
2986
2987
static enum TIFFReadDirEntryErr
2988
TIFFReadDirEntryDoubleArray(TIFF *tif, TIFFDirEntry *direntry, double **value)
2989
0
{
2990
0
    enum TIFFReadDirEntryErr err;
2991
0
    uint32_t count;
2992
0
    void *origdata;
2993
0
    double *data;
2994
0
    switch (direntry->tdir_type)
2995
0
    {
2996
0
        case TIFF_BYTE:
2997
0
        case TIFF_SBYTE:
2998
0
        case TIFF_SHORT:
2999
0
        case TIFF_SSHORT:
3000
0
        case TIFF_LONG:
3001
0
        case TIFF_SLONG:
3002
0
        case TIFF_LONG8:
3003
0
        case TIFF_SLONG8:
3004
0
        case TIFF_RATIONAL:
3005
0
        case TIFF_SRATIONAL:
3006
0
        case TIFF_FLOAT:
3007
0
        case TIFF_DOUBLE:
3008
0
            break;
3009
0
        default:
3010
0
            return (TIFFReadDirEntryErrType);
3011
0
    }
3012
0
    err = TIFFReadDirEntryArray(tif, direntry, &count, 8, &origdata);
3013
0
    if ((err != TIFFReadDirEntryErrOk) || (origdata == 0))
3014
0
    {
3015
0
        *value = 0;
3016
0
        return (err);
3017
0
    }
3018
0
    switch (direntry->tdir_type)
3019
0
    {
3020
0
        case TIFF_DOUBLE:
3021
0
            if (tif->tif_flags & TIFF_SWAB)
3022
0
                TIFFSwabArrayOfLong8((uint64_t *)origdata, count);
3023
0
            TIFFCvtIEEEDoubleToNative(tif, count, (double *)origdata);
3024
0
            *value = (double *)origdata;
3025
0
            return (TIFFReadDirEntryErrOk);
3026
0
    }
3027
0
    data = (double *)_TIFFmallocExt(tif, count * sizeof(double));
3028
0
    if (data == 0)
3029
0
    {
3030
0
        _TIFFfreeExt(tif, origdata);
3031
0
        return (TIFFReadDirEntryErrAlloc);
3032
0
    }
3033
0
    switch (direntry->tdir_type)
3034
0
    {
3035
0
        case TIFF_BYTE:
3036
0
        {
3037
0
            uint8_t *ma;
3038
0
            double *mb;
3039
0
            uint32_t n;
3040
0
            ma = (uint8_t *)origdata;
3041
0
            mb = data;
3042
0
            for (n = 0; n < count; n++)
3043
0
                *mb++ = (double)(*ma++);
3044
0
        }
3045
0
        break;
3046
0
        case TIFF_SBYTE:
3047
0
        {
3048
0
            int8_t *ma;
3049
0
            double *mb;
3050
0
            uint32_t n;
3051
0
            ma = (int8_t *)origdata;
3052
0
            mb = data;
3053
0
            for (n = 0; n < count; n++)
3054
0
                *mb++ = (double)(*ma++);
3055
0
        }
3056
0
        break;
3057
0
        case TIFF_SHORT:
3058
0
        {
3059
0
            uint16_t *ma;
3060
0
            double *mb;
3061
0
            uint32_t n;
3062
0
            ma = (uint16_t *)origdata;
3063
0
            mb = data;
3064
0
            for (n = 0; n < count; n++)
3065
0
            {
3066
0
                if (tif->tif_flags & TIFF_SWAB)
3067
0
                    TIFFSwabShort(ma);
3068
0
                *mb++ = (double)(*ma++);
3069
0
            }
3070
0
        }
3071
0
        break;
3072
0
        case TIFF_SSHORT:
3073
0
        {
3074
0
            int16_t *ma;
3075
0
            double *mb;
3076
0
            uint32_t n;
3077
0
            ma = (int16_t *)origdata;
3078
0
            mb = data;
3079
0
            for (n = 0; n < count; n++)
3080
0
            {
3081
0
                if (tif->tif_flags & TIFF_SWAB)
3082
0
                    TIFFSwabShort((uint16_t *)ma);
3083
0
                *mb++ = (double)(*ma++);
3084
0
            }
3085
0
        }
3086
0
        break;
3087
0
        case TIFF_LONG:
3088
0
        {
3089
0
            uint32_t *ma;
3090
0
            double *mb;
3091
0
            uint32_t n;
3092
0
            ma = (uint32_t *)origdata;
3093
0
            mb = data;
3094
0
            for (n = 0; n < count; n++)
3095
0
            {
3096
0
                if (tif->tif_flags & TIFF_SWAB)
3097
0
                    TIFFSwabLong(ma);
3098
0
                *mb++ = (double)(*ma++);
3099
0
            }
3100
0
        }
3101
0
        break;
3102
0
        case TIFF_SLONG:
3103
0
        {
3104
0
            int32_t *ma;
3105
0
            double *mb;
3106
0
            uint32_t n;
3107
0
            ma = (int32_t *)origdata;
3108
0
            mb = data;
3109
0
            for (n = 0; n < count; n++)
3110
0
            {
3111
0
                if (tif->tif_flags & TIFF_SWAB)
3112
0
                    TIFFSwabLong((uint32_t *)ma);
3113
0
                *mb++ = (double)(*ma++);
3114
0
            }
3115
0
        }
3116
0
        break;
3117
0
        case TIFF_LONG8:
3118
0
        {
3119
0
            uint64_t *ma;
3120
0
            double *mb;
3121
0
            uint32_t n;
3122
0
            ma = (uint64_t *)origdata;
3123
0
            mb = data;
3124
0
            for (n = 0; n < count; n++)
3125
0
            {
3126
0
                if (tif->tif_flags & TIFF_SWAB)
3127
0
                    TIFFSwabLong8(ma);
3128
0
                *mb++ = (double)(*ma++);
3129
0
            }
3130
0
        }
3131
0
        break;
3132
0
        case TIFF_SLONG8:
3133
0
        {
3134
0
            int64_t *ma;
3135
0
            double *mb;
3136
0
            uint32_t n;
3137
0
            ma = (int64_t *)origdata;
3138
0
            mb = data;
3139
0
            for (n = 0; n < count; n++)
3140
0
            {
3141
0
                if (tif->tif_flags & TIFF_SWAB)
3142
0
                    TIFFSwabLong8((uint64_t *)ma);
3143
0
                *mb++ = (double)(*ma++);
3144
0
            }
3145
0
        }
3146
0
        break;
3147
0
        case TIFF_RATIONAL:
3148
0
        {
3149
0
            uint32_t *ma;
3150
0
            uint32_t maa;
3151
0
            uint32_t mab;
3152
0
            double *mb;
3153
0
            uint32_t n;
3154
0
            ma = (uint32_t *)origdata;
3155
0
            mb = data;
3156
0
            for (n = 0; n < count; n++)
3157
0
            {
3158
0
                if (tif->tif_flags & TIFF_SWAB)
3159
0
                    TIFFSwabLong(ma);
3160
0
                maa = *ma++;
3161
0
                if (tif->tif_flags & TIFF_SWAB)
3162
0
                    TIFFSwabLong(ma);
3163
0
                mab = *ma++;
3164
0
                if (mab == 0)
3165
0
                    *mb++ = 0.0;
3166
0
                else
3167
0
                    *mb++ = (double)maa / (double)mab;
3168
0
            }
3169
0
        }
3170
0
        break;
3171
0
        case TIFF_SRATIONAL:
3172
0
        {
3173
0
            uint32_t *ma;
3174
0
            int32_t maa;
3175
0
            uint32_t mab;
3176
0
            double *mb;
3177
0
            uint32_t n;
3178
0
            ma = (uint32_t *)origdata;
3179
0
            mb = data;
3180
0
            for (n = 0; n < count; n++)
3181
0
            {
3182
0
                if (tif->tif_flags & TIFF_SWAB)
3183
0
                    TIFFSwabLong(ma);
3184
0
                maa = *(int32_t *)ma;
3185
0
                ma++;
3186
0
                if (tif->tif_flags & TIFF_SWAB)
3187
0
                    TIFFSwabLong(ma);
3188
0
                mab = *ma++;
3189
0
                if (mab == 0)
3190
0
                    *mb++ = 0.0;
3191
0
                else
3192
0
                    *mb++ = (double)maa / (double)mab;
3193
0
            }
3194
0
        }
3195
0
        break;
3196
0
        case TIFF_FLOAT:
3197
0
        {
3198
0
            float *ma;
3199
0
            double *mb;
3200
0
            uint32_t n;
3201
0
            if (tif->tif_flags & TIFF_SWAB)
3202
0
                TIFFSwabArrayOfLong((uint32_t *)origdata, count);
3203
0
            TIFFCvtIEEEFloatToNative(tif, count, (float *)origdata);
3204
0
            ma = (float *)origdata;
3205
0
            mb = data;
3206
0
            for (n = 0; n < count; n++)
3207
0
                *mb++ = (double)(*ma++);
3208
0
        }
3209
0
        break;
3210
0
    }
3211
0
    _TIFFfreeExt(tif, origdata);
3212
0
    *value = data;
3213
0
    return (TIFFReadDirEntryErrOk);
3214
0
}
3215
3216
static enum TIFFReadDirEntryErr
3217
TIFFReadDirEntryIfd8Array(TIFF *tif, TIFFDirEntry *direntry, uint64_t **value)
3218
0
{
3219
0
    enum TIFFReadDirEntryErr err;
3220
0
    uint32_t count;
3221
0
    void *origdata;
3222
0
    uint64_t *data;
3223
0
    switch (direntry->tdir_type)
3224
0
    {
3225
0
        case TIFF_LONG:
3226
0
        case TIFF_LONG8:
3227
0
        case TIFF_IFD:
3228
0
        case TIFF_IFD8:
3229
0
            break;
3230
0
        default:
3231
0
            return (TIFFReadDirEntryErrType);
3232
0
    }
3233
0
    err = TIFFReadDirEntryArray(tif, direntry, &count, 8, &origdata);
3234
0
    if ((err != TIFFReadDirEntryErrOk) || (origdata == 0))
3235
0
    {
3236
0
        *value = 0;
3237
0
        return (err);
3238
0
    }
3239
0
    switch (direntry->tdir_type)
3240
0
    {
3241
0
        case TIFF_LONG8:
3242
0
        case TIFF_IFD8:
3243
0
            *value = (uint64_t *)origdata;
3244
0
            if (tif->tif_flags & TIFF_SWAB)
3245
0
                TIFFSwabArrayOfLong8(*value, count);
3246
0
            return (TIFFReadDirEntryErrOk);
3247
0
    }
3248
0
    data = (uint64_t *)_TIFFmallocExt(tif, count * 8);
3249
0
    if (data == 0)
3250
0
    {
3251
0
        _TIFFfreeExt(tif, origdata);
3252
0
        return (TIFFReadDirEntryErrAlloc);
3253
0
    }
3254
0
    switch (direntry->tdir_type)
3255
0
    {
3256
0
        case TIFF_LONG:
3257
0
        case TIFF_IFD:
3258
0
        {
3259
0
            uint32_t *ma;
3260
0
            uint64_t *mb;
3261
0
            uint32_t n;
3262
0
            ma = (uint32_t *)origdata;
3263
0
            mb = data;
3264
0
            for (n = 0; n < count; n++)
3265
0
            {
3266
0
                if (tif->tif_flags & TIFF_SWAB)
3267
0
                    TIFFSwabLong(ma);
3268
0
                *mb++ = (uint64_t)(*ma++);
3269
0
            }
3270
0
        }
3271
0
        break;
3272
0
    }
3273
0
    _TIFFfreeExt(tif, origdata);
3274
0
    *value = data;
3275
0
    return (TIFFReadDirEntryErrOk);
3276
0
}
3277
3278
static enum TIFFReadDirEntryErr
3279
TIFFReadDirEntryPersampleShort(TIFF *tif, TIFFDirEntry *direntry,
3280
                               uint16_t *value)
3281
0
{
3282
0
    enum TIFFReadDirEntryErr err;
3283
0
    uint16_t *m;
3284
0
    uint16_t *na;
3285
0
    uint16_t nb;
3286
0
    if (direntry->tdir_count != (uint64_t)tif->tif_dir.td_samplesperpixel)
3287
0
    {
3288
0
        const TIFFField *fip = TIFFFieldWithTag(tif, direntry->tdir_tag);
3289
0
        if (direntry->tdir_count == 0)
3290
0
        {
3291
0
            return TIFFReadDirEntryErrCount;
3292
0
        }
3293
0
        else if (direntry->tdir_count <
3294
0
                 (uint64_t)tif->tif_dir.td_samplesperpixel)
3295
0
        {
3296
0
            TIFFWarningExtR(
3297
0
                tif, "TIFFReadDirEntryPersampleShort",
3298
0
                "Tag %s entry count is %" PRIu64
3299
0
                " , whereas it should be SamplesPerPixel=%d. Assuming that "
3300
0
                "missing entries are all at the value of the first one",
3301
0
                fip ? fip->field_name : "unknown tagname", direntry->tdir_count,
3302
0
                tif->tif_dir.td_samplesperpixel);
3303
0
        }
3304
0
        else
3305
0
        {
3306
0
            TIFFWarningExtR(tif, "TIFFReadDirEntryPersampleShort",
3307
0
                            "Tag %s entry count is %" PRIu64
3308
0
                            " , whereas it should be SamplesPerPixel=%d. "
3309
0
                            "Ignoring extra entries",
3310
0
                            fip ? fip->field_name : "unknown tagname",
3311
0
                            direntry->tdir_count,
3312
0
                            tif->tif_dir.td_samplesperpixel);
3313
0
        }
3314
0
    }
3315
0
    err = TIFFReadDirEntryShortArray(tif, direntry, &m);
3316
0
    if (err != TIFFReadDirEntryErrOk || m == NULL)
3317
0
        return (err);
3318
0
    na = m;
3319
0
    nb = tif->tif_dir.td_samplesperpixel;
3320
0
    if (direntry->tdir_count < nb)
3321
0
        nb = (uint16_t)direntry->tdir_count;
3322
0
    *value = *na++;
3323
0
    nb--;
3324
0
    while (nb > 0)
3325
0
    {
3326
0
        if (*na++ != *value)
3327
0
        {
3328
0
            err = TIFFReadDirEntryErrPsdif;
3329
0
            break;
3330
0
        }
3331
0
        nb--;
3332
0
    }
3333
0
    _TIFFfreeExt(tif, m);
3334
0
    return (err);
3335
0
}
3336
3337
static void TIFFReadDirEntryCheckedByte(TIFF *tif, TIFFDirEntry *direntry,
3338
                                        uint8_t *value)
3339
0
{
3340
0
    (void)tif;
3341
0
    *value = *(uint8_t *)(&direntry->tdir_offset);
3342
0
}
3343
3344
static void TIFFReadDirEntryCheckedSbyte(TIFF *tif, TIFFDirEntry *direntry,
3345
                                         int8_t *value)
3346
0
{
3347
0
    (void)tif;
3348
0
    *value = *(int8_t *)(&direntry->tdir_offset);
3349
0
}
3350
3351
static void TIFFReadDirEntryCheckedShort(TIFF *tif, TIFFDirEntry *direntry,
3352
                                         uint16_t *value)
3353
0
{
3354
0
    *value = direntry->tdir_offset.toff_short;
3355
    /* *value=*(uint16_t*)(&direntry->tdir_offset); */
3356
0
    if (tif->tif_flags & TIFF_SWAB)
3357
0
        TIFFSwabShort(value);
3358
0
}
3359
3360
static void TIFFReadDirEntryCheckedSshort(TIFF *tif, TIFFDirEntry *direntry,
3361
                                          int16_t *value)
3362
0
{
3363
0
    *value = *(int16_t *)(&direntry->tdir_offset);
3364
0
    if (tif->tif_flags & TIFF_SWAB)
3365
0
        TIFFSwabShort((uint16_t *)value);
3366
0
}
3367
3368
static void TIFFReadDirEntryCheckedLong(TIFF *tif, TIFFDirEntry *direntry,
3369
                                        uint32_t *value)
3370
0
{
3371
0
    *value = *(uint32_t *)(&direntry->tdir_offset);
3372
0
    if (tif->tif_flags & TIFF_SWAB)
3373
0
        TIFFSwabLong(value);
3374
0
}
3375
3376
static void TIFFReadDirEntryCheckedSlong(TIFF *tif, TIFFDirEntry *direntry,
3377
                                         int32_t *value)
3378
0
{
3379
0
    *value = *(int32_t *)(&direntry->tdir_offset);
3380
0
    if (tif->tif_flags & TIFF_SWAB)
3381
0
        TIFFSwabLong((uint32_t *)value);
3382
0
}
3383
3384
static enum TIFFReadDirEntryErr
3385
TIFFReadDirEntryCheckedLong8(TIFF *tif, TIFFDirEntry *direntry, uint64_t *value)
3386
0
{
3387
0
    if (!(tif->tif_flags & TIFF_BIGTIFF))
3388
0
    {
3389
0
        enum TIFFReadDirEntryErr err;
3390
0
        uint32_t offset = direntry->tdir_offset.toff_long;
3391
0
        if (tif->tif_flags & TIFF_SWAB)
3392
0
            TIFFSwabLong(&offset);
3393
0
        err = TIFFReadDirEntryData(tif, offset, 8, value);
3394
0
        if (err != TIFFReadDirEntryErrOk)
3395
0
            return (err);
3396
0
    }
3397
0
    else
3398
0
        *value = direntry->tdir_offset.toff_long8;
3399
0
    if (tif->tif_flags & TIFF_SWAB)
3400
0
        TIFFSwabLong8(value);
3401
0
    return (TIFFReadDirEntryErrOk);
3402
0
}
3403
3404
static enum TIFFReadDirEntryErr
3405
TIFFReadDirEntryCheckedSlong8(TIFF *tif, TIFFDirEntry *direntry, int64_t *value)
3406
0
{
3407
0
    if (!(tif->tif_flags & TIFF_BIGTIFF))
3408
0
    {
3409
0
        enum TIFFReadDirEntryErr err;
3410
0
        uint32_t offset = direntry->tdir_offset.toff_long;
3411
0
        if (tif->tif_flags & TIFF_SWAB)
3412
0
            TIFFSwabLong(&offset);
3413
0
        err = TIFFReadDirEntryData(tif, offset, 8, value);
3414
0
        if (err != TIFFReadDirEntryErrOk)
3415
0
            return (err);
3416
0
    }
3417
0
    else
3418
0
        *value = *(int64_t *)(&direntry->tdir_offset);
3419
0
    if (tif->tif_flags & TIFF_SWAB)
3420
0
        TIFFSwabLong8((uint64_t *)value);
3421
0
    return (TIFFReadDirEntryErrOk);
3422
0
}
3423
3424
static enum TIFFReadDirEntryErr
3425
TIFFReadDirEntryCheckedRational(TIFF *tif, TIFFDirEntry *direntry,
3426
                                double *value)
3427
0
{
3428
0
    UInt64Aligned_t m;
3429
3430
0
    assert(sizeof(double) == 8);
3431
0
    assert(sizeof(uint64_t) == 8);
3432
0
    assert(sizeof(uint32_t) == 4);
3433
0
    if (!(tif->tif_flags & TIFF_BIGTIFF))
3434
0
    {
3435
0
        enum TIFFReadDirEntryErr err;
3436
0
        uint32_t offset = direntry->tdir_offset.toff_long;
3437
0
        if (tif->tif_flags & TIFF_SWAB)
3438
0
            TIFFSwabLong(&offset);
3439
0
        err = TIFFReadDirEntryData(tif, offset, 8, m.i);
3440
0
        if (err != TIFFReadDirEntryErrOk)
3441
0
            return (err);
3442
0
    }
3443
0
    else
3444
0
        m.l = direntry->tdir_offset.toff_long8;
3445
0
    if (tif->tif_flags & TIFF_SWAB)
3446
0
        TIFFSwabArrayOfLong(m.i, 2);
3447
    /* Not completely sure what we should do when m.i[1]==0, but some */
3448
    /* sanitizers do not like division by 0.0: */
3449
    /* http://bugzilla.maptools.org/show_bug.cgi?id=2644 */
3450
0
    if (m.i[0] == 0 || m.i[1] == 0)
3451
0
        *value = 0.0;
3452
0
    else
3453
0
        *value = (double)m.i[0] / (double)m.i[1];
3454
0
    return (TIFFReadDirEntryErrOk);
3455
0
}
3456
3457
static enum TIFFReadDirEntryErr
3458
TIFFReadDirEntryCheckedSrational(TIFF *tif, TIFFDirEntry *direntry,
3459
                                 double *value)
3460
0
{
3461
0
    UInt64Aligned_t m;
3462
0
    assert(sizeof(double) == 8);
3463
0
    assert(sizeof(uint64_t) == 8);
3464
0
    assert(sizeof(int32_t) == 4);
3465
0
    assert(sizeof(uint32_t) == 4);
3466
0
    if (!(tif->tif_flags & TIFF_BIGTIFF))
3467
0
    {
3468
0
        enum TIFFReadDirEntryErr err;
3469
0
        uint32_t offset = direntry->tdir_offset.toff_long;
3470
0
        if (tif->tif_flags & TIFF_SWAB)
3471
0
            TIFFSwabLong(&offset);
3472
0
        err = TIFFReadDirEntryData(tif, offset, 8, m.i);
3473
0
        if (err != TIFFReadDirEntryErrOk)
3474
0
            return (err);
3475
0
    }
3476
0
    else
3477
0
        m.l = direntry->tdir_offset.toff_long8;
3478
0
    if (tif->tif_flags & TIFF_SWAB)
3479
0
        TIFFSwabArrayOfLong(m.i, 2);
3480
    /* Not completely sure what we should do when m.i[1]==0, but some */
3481
    /* sanitizers do not like division by 0.0: */
3482
    /* http://bugzilla.maptools.org/show_bug.cgi?id=2644 */
3483
0
    if ((int32_t)m.i[0] == 0 || m.i[1] == 0)
3484
0
        *value = 0.0;
3485
0
    else
3486
0
        *value = (double)((int32_t)m.i[0]) / (double)m.i[1];
3487
0
    return (TIFFReadDirEntryErrOk);
3488
0
}
3489
3490
#if 0
3491
static enum TIFFReadDirEntryErr
3492
TIFFReadDirEntryCheckedRationalDirect(TIFF *tif, TIFFDirEntry *direntry,
3493
                                      TIFFRational_t *value)
3494
{ /*--: SetGetRATIONAL_directly:_CustomTag: Read rational (and signed rationals)
3495
     directly --*/
3496
    UInt64Aligned_t m;
3497
3498
    assert(sizeof(double) == 8);
3499
    assert(sizeof(uint64_t) == 8);
3500
    assert(sizeof(uint32_t) == 4);
3501
3502
    if (direntry->tdir_count != 1)
3503
        return (TIFFReadDirEntryErrCount);
3504
3505
    if (direntry->tdir_type != TIFF_RATIONAL &&
3506
        direntry->tdir_type != TIFF_SRATIONAL)
3507
        return (TIFFReadDirEntryErrType);
3508
3509
    if (!(tif->tif_flags & TIFF_BIGTIFF))
3510
    {
3511
        enum TIFFReadDirEntryErr err;
3512
        uint32_t offset = direntry->tdir_offset.toff_long;
3513
        if (tif->tif_flags & TIFF_SWAB)
3514
            TIFFSwabLong(&offset);
3515
        err = TIFFReadDirEntryData(tif, offset, 8, m.i);
3516
        if (err != TIFFReadDirEntryErrOk)
3517
            return (err);
3518
    }
3519
    else
3520
    {
3521
        m.l = direntry->tdir_offset.toff_long8;
3522
    }
3523
3524
    if (tif->tif_flags & TIFF_SWAB)
3525
        TIFFSwabArrayOfLong(m.i, 2);
3526
3527
    value->uNum = m.i[0];
3528
    value->uDenom = m.i[1];
3529
    return (TIFFReadDirEntryErrOk);
3530
} /*-- TIFFReadDirEntryCheckedRationalDirect() --*/
3531
#endif
3532
3533
static void TIFFReadDirEntryCheckedFloat(TIFF *tif, TIFFDirEntry *direntry,
3534
                                         float *value)
3535
0
{
3536
0
    union
3537
0
    {
3538
0
        float f;
3539
0
        uint32_t i;
3540
0
    } float_union;
3541
0
    assert(sizeof(float) == 4);
3542
0
    assert(sizeof(uint32_t) == 4);
3543
0
    assert(sizeof(float_union) == 4);
3544
0
    float_union.i = *(uint32_t *)(&direntry->tdir_offset);
3545
0
    *value = float_union.f;
3546
0
    if (tif->tif_flags & TIFF_SWAB)
3547
0
        TIFFSwabLong((uint32_t *)value);
3548
0
}
3549
3550
static enum TIFFReadDirEntryErr
3551
TIFFReadDirEntryCheckedDouble(TIFF *tif, TIFFDirEntry *direntry, double *value)
3552
0
{
3553
0
    assert(sizeof(double) == 8);
3554
0
    assert(sizeof(uint64_t) == 8);
3555
0
    assert(sizeof(UInt64Aligned_t) == 8);
3556
0
    if (!(tif->tif_flags & TIFF_BIGTIFF))
3557
0
    {
3558
0
        enum TIFFReadDirEntryErr err;
3559
0
        uint32_t offset = direntry->tdir_offset.toff_long;
3560
0
        if (tif->tif_flags & TIFF_SWAB)
3561
0
            TIFFSwabLong(&offset);
3562
0
        err = TIFFReadDirEntryData(tif, offset, 8, value);
3563
0
        if (err != TIFFReadDirEntryErrOk)
3564
0
            return (err);
3565
0
    }
3566
0
    else
3567
0
    {
3568
0
        UInt64Aligned_t uint64_union;
3569
0
        uint64_union.l = direntry->tdir_offset.toff_long8;
3570
0
        *value = uint64_union.d;
3571
0
    }
3572
0
    if (tif->tif_flags & TIFF_SWAB)
3573
0
        TIFFSwabLong8((uint64_t *)value);
3574
0
    return (TIFFReadDirEntryErrOk);
3575
0
}
3576
3577
static enum TIFFReadDirEntryErr
3578
TIFFReadDirEntryCheckRangeByteSbyte(int8_t value)
3579
0
{
3580
0
    if (value < 0)
3581
0
        return (TIFFReadDirEntryErrRange);
3582
0
    else
3583
0
        return (TIFFReadDirEntryErrOk);
3584
0
}
3585
3586
static enum TIFFReadDirEntryErr
3587
TIFFReadDirEntryCheckRangeByteShort(uint16_t value)
3588
0
{
3589
0
    if (value > 0xFF)
3590
0
        return (TIFFReadDirEntryErrRange);
3591
0
    else
3592
0
        return (TIFFReadDirEntryErrOk);
3593
0
}
3594
3595
static enum TIFFReadDirEntryErr
3596
TIFFReadDirEntryCheckRangeByteSshort(int16_t value)
3597
0
{
3598
0
    if ((value < 0) || (value > 0xFF))
3599
0
        return (TIFFReadDirEntryErrRange);
3600
0
    else
3601
0
        return (TIFFReadDirEntryErrOk);
3602
0
}
3603
3604
static enum TIFFReadDirEntryErr
3605
TIFFReadDirEntryCheckRangeByteLong(uint32_t value)
3606
0
{
3607
0
    if (value > 0xFF)
3608
0
        return (TIFFReadDirEntryErrRange);
3609
0
    else
3610
0
        return (TIFFReadDirEntryErrOk);
3611
0
}
3612
3613
static enum TIFFReadDirEntryErr
3614
TIFFReadDirEntryCheckRangeByteSlong(int32_t value)
3615
0
{
3616
0
    if ((value < 0) || (value > 0xFF))
3617
0
        return (TIFFReadDirEntryErrRange);
3618
0
    else
3619
0
        return (TIFFReadDirEntryErrOk);
3620
0
}
3621
3622
static enum TIFFReadDirEntryErr
3623
TIFFReadDirEntryCheckRangeByteLong8(uint64_t value)
3624
0
{
3625
0
    if (value > 0xFF)
3626
0
        return (TIFFReadDirEntryErrRange);
3627
0
    else
3628
0
        return (TIFFReadDirEntryErrOk);
3629
0
}
3630
3631
static enum TIFFReadDirEntryErr
3632
TIFFReadDirEntryCheckRangeByteSlong8(int64_t value)
3633
0
{
3634
0
    if ((value < 0) || (value > 0xFF))
3635
0
        return (TIFFReadDirEntryErrRange);
3636
0
    else
3637
0
        return (TIFFReadDirEntryErrOk);
3638
0
}
3639
3640
static enum TIFFReadDirEntryErr
3641
TIFFReadDirEntryCheckRangeSbyteByte(uint8_t value)
3642
0
{
3643
0
    if (value > 0x7F)
3644
0
        return (TIFFReadDirEntryErrRange);
3645
0
    else
3646
0
        return (TIFFReadDirEntryErrOk);
3647
0
}
3648
3649
static enum TIFFReadDirEntryErr
3650
TIFFReadDirEntryCheckRangeSbyteShort(uint16_t value)
3651
0
{
3652
0
    if (value > 0x7F)
3653
0
        return (TIFFReadDirEntryErrRange);
3654
0
    else
3655
0
        return (TIFFReadDirEntryErrOk);
3656
0
}
3657
3658
static enum TIFFReadDirEntryErr
3659
TIFFReadDirEntryCheckRangeSbyteSshort(int16_t value)
3660
0
{
3661
0
    if ((value < -0x80) || (value > 0x7F))
3662
0
        return (TIFFReadDirEntryErrRange);
3663
0
    else
3664
0
        return (TIFFReadDirEntryErrOk);
3665
0
}
3666
3667
static enum TIFFReadDirEntryErr
3668
TIFFReadDirEntryCheckRangeSbyteLong(uint32_t value)
3669
0
{
3670
0
    if (value > 0x7F)
3671
0
        return (TIFFReadDirEntryErrRange);
3672
0
    else
3673
0
        return (TIFFReadDirEntryErrOk);
3674
0
}
3675
3676
static enum TIFFReadDirEntryErr
3677
TIFFReadDirEntryCheckRangeSbyteSlong(int32_t value)
3678
0
{
3679
0
    if ((value < -0x80) || (value > 0x7F))
3680
0
        return (TIFFReadDirEntryErrRange);
3681
0
    else
3682
0
        return (TIFFReadDirEntryErrOk);
3683
0
}
3684
3685
static enum TIFFReadDirEntryErr
3686
TIFFReadDirEntryCheckRangeSbyteLong8(uint64_t value)
3687
0
{
3688
0
    if (value > 0x7F)
3689
0
        return (TIFFReadDirEntryErrRange);
3690
0
    else
3691
0
        return (TIFFReadDirEntryErrOk);
3692
0
}
3693
3694
static enum TIFFReadDirEntryErr
3695
TIFFReadDirEntryCheckRangeSbyteSlong8(int64_t value)
3696
0
{
3697
0
    if ((value < -0x80) || (value > 0x7F))
3698
0
        return (TIFFReadDirEntryErrRange);
3699
0
    else
3700
0
        return (TIFFReadDirEntryErrOk);
3701
0
}
3702
3703
static enum TIFFReadDirEntryErr
3704
TIFFReadDirEntryCheckRangeShortSbyte(int8_t value)
3705
0
{
3706
0
    if (value < 0)
3707
0
        return (TIFFReadDirEntryErrRange);
3708
0
    else
3709
0
        return (TIFFReadDirEntryErrOk);
3710
0
}
3711
3712
static enum TIFFReadDirEntryErr
3713
TIFFReadDirEntryCheckRangeShortSshort(int16_t value)
3714
0
{
3715
0
    if (value < 0)
3716
0
        return (TIFFReadDirEntryErrRange);
3717
0
    else
3718
0
        return (TIFFReadDirEntryErrOk);
3719
0
}
3720
3721
static enum TIFFReadDirEntryErr
3722
TIFFReadDirEntryCheckRangeShortLong(uint32_t value)
3723
0
{
3724
0
    if (value > 0xFFFF)
3725
0
        return (TIFFReadDirEntryErrRange);
3726
0
    else
3727
0
        return (TIFFReadDirEntryErrOk);
3728
0
}
3729
3730
static enum TIFFReadDirEntryErr
3731
TIFFReadDirEntryCheckRangeShortSlong(int32_t value)
3732
0
{
3733
0
    if ((value < 0) || (value > 0xFFFF))
3734
0
        return (TIFFReadDirEntryErrRange);
3735
0
    else
3736
0
        return (TIFFReadDirEntryErrOk);
3737
0
}
3738
3739
static enum TIFFReadDirEntryErr
3740
TIFFReadDirEntryCheckRangeShortLong8(uint64_t value)
3741
0
{
3742
0
    if (value > 0xFFFF)
3743
0
        return (TIFFReadDirEntryErrRange);
3744
0
    else
3745
0
        return (TIFFReadDirEntryErrOk);
3746
0
}
3747
3748
static enum TIFFReadDirEntryErr
3749
TIFFReadDirEntryCheckRangeShortSlong8(int64_t value)
3750
0
{
3751
0
    if ((value < 0) || (value > 0xFFFF))
3752
0
        return (TIFFReadDirEntryErrRange);
3753
0
    else
3754
0
        return (TIFFReadDirEntryErrOk);
3755
0
}
3756
3757
static enum TIFFReadDirEntryErr
3758
TIFFReadDirEntryCheckRangeSshortShort(uint16_t value)
3759
0
{
3760
0
    if (value > 0x7FFF)
3761
0
        return (TIFFReadDirEntryErrRange);
3762
0
    else
3763
0
        return (TIFFReadDirEntryErrOk);
3764
0
}
3765
3766
static enum TIFFReadDirEntryErr
3767
TIFFReadDirEntryCheckRangeSshortLong(uint32_t value)
3768
0
{
3769
0
    if (value > 0x7FFF)
3770
0
        return (TIFFReadDirEntryErrRange);
3771
0
    else
3772
0
        return (TIFFReadDirEntryErrOk);
3773
0
}
3774
3775
static enum TIFFReadDirEntryErr
3776
TIFFReadDirEntryCheckRangeSshortSlong(int32_t value)
3777
0
{
3778
0
    if ((value < -0x8000) || (value > 0x7FFF))
3779
0
        return (TIFFReadDirEntryErrRange);
3780
0
    else
3781
0
        return (TIFFReadDirEntryErrOk);
3782
0
}
3783
3784
static enum TIFFReadDirEntryErr
3785
TIFFReadDirEntryCheckRangeSshortLong8(uint64_t value)
3786
0
{
3787
0
    if (value > 0x7FFF)
3788
0
        return (TIFFReadDirEntryErrRange);
3789
0
    else
3790
0
        return (TIFFReadDirEntryErrOk);
3791
0
}
3792
3793
static enum TIFFReadDirEntryErr
3794
TIFFReadDirEntryCheckRangeSshortSlong8(int64_t value)
3795
0
{
3796
0
    if ((value < -0x8000) || (value > 0x7FFF))
3797
0
        return (TIFFReadDirEntryErrRange);
3798
0
    else
3799
0
        return (TIFFReadDirEntryErrOk);
3800
0
}
3801
3802
static enum TIFFReadDirEntryErr
3803
TIFFReadDirEntryCheckRangeLongSbyte(int8_t value)
3804
0
{
3805
0
    if (value < 0)
3806
0
        return (TIFFReadDirEntryErrRange);
3807
0
    else
3808
0
        return (TIFFReadDirEntryErrOk);
3809
0
}
3810
3811
static enum TIFFReadDirEntryErr
3812
TIFFReadDirEntryCheckRangeLongSshort(int16_t value)
3813
0
{
3814
0
    if (value < 0)
3815
0
        return (TIFFReadDirEntryErrRange);
3816
0
    else
3817
0
        return (TIFFReadDirEntryErrOk);
3818
0
}
3819
3820
static enum TIFFReadDirEntryErr
3821
TIFFReadDirEntryCheckRangeLongSlong(int32_t value)
3822
0
{
3823
0
    if (value < 0)
3824
0
        return (TIFFReadDirEntryErrRange);
3825
0
    else
3826
0
        return (TIFFReadDirEntryErrOk);
3827
0
}
3828
3829
static enum TIFFReadDirEntryErr
3830
TIFFReadDirEntryCheckRangeLongLong8(uint64_t value)
3831
0
{
3832
0
    if (value > UINT32_MAX)
3833
0
        return (TIFFReadDirEntryErrRange);
3834
0
    else
3835
0
        return (TIFFReadDirEntryErrOk);
3836
0
}
3837
3838
static enum TIFFReadDirEntryErr
3839
TIFFReadDirEntryCheckRangeLongSlong8(int64_t value)
3840
0
{
3841
0
    if ((value < 0) || (value > (int64_t)UINT32_MAX))
3842
0
        return (TIFFReadDirEntryErrRange);
3843
0
    else
3844
0
        return (TIFFReadDirEntryErrOk);
3845
0
}
3846
3847
static enum TIFFReadDirEntryErr
3848
TIFFReadDirEntryCheckRangeSlongLong(uint32_t value)
3849
0
{
3850
0
    if (value > 0x7FFFFFFFUL)
3851
0
        return (TIFFReadDirEntryErrRange);
3852
0
    else
3853
0
        return (TIFFReadDirEntryErrOk);
3854
0
}
3855
3856
/* Check that the 8-byte unsigned value can fit in a 4-byte unsigned range */
3857
static enum TIFFReadDirEntryErr
3858
TIFFReadDirEntryCheckRangeSlongLong8(uint64_t value)
3859
0
{
3860
0
    if (value > 0x7FFFFFFF)
3861
0
        return (TIFFReadDirEntryErrRange);
3862
0
    else
3863
0
        return (TIFFReadDirEntryErrOk);
3864
0
}
3865
3866
/* Check that the 8-byte signed value can fit in a 4-byte signed range */
3867
static enum TIFFReadDirEntryErr
3868
TIFFReadDirEntryCheckRangeSlongSlong8(int64_t value)
3869
0
{
3870
0
    if ((value < 0 - ((int64_t)0x7FFFFFFF + 1)) || (value > 0x7FFFFFFF))
3871
0
        return (TIFFReadDirEntryErrRange);
3872
0
    else
3873
0
        return (TIFFReadDirEntryErrOk);
3874
0
}
3875
3876
static enum TIFFReadDirEntryErr
3877
TIFFReadDirEntryCheckRangeLong8Sbyte(int8_t value)
3878
0
{
3879
0
    if (value < 0)
3880
0
        return (TIFFReadDirEntryErrRange);
3881
0
    else
3882
0
        return (TIFFReadDirEntryErrOk);
3883
0
}
3884
3885
static enum TIFFReadDirEntryErr
3886
TIFFReadDirEntryCheckRangeLong8Sshort(int16_t value)
3887
0
{
3888
0
    if (value < 0)
3889
0
        return (TIFFReadDirEntryErrRange);
3890
0
    else
3891
0
        return (TIFFReadDirEntryErrOk);
3892
0
}
3893
3894
static enum TIFFReadDirEntryErr
3895
TIFFReadDirEntryCheckRangeLong8Slong(int32_t value)
3896
0
{
3897
0
    if (value < 0)
3898
0
        return (TIFFReadDirEntryErrRange);
3899
0
    else
3900
0
        return (TIFFReadDirEntryErrOk);
3901
0
}
3902
3903
static enum TIFFReadDirEntryErr
3904
TIFFReadDirEntryCheckRangeLong8Slong8(int64_t value)
3905
0
{
3906
0
    if (value < 0)
3907
0
        return (TIFFReadDirEntryErrRange);
3908
0
    else
3909
0
        return (TIFFReadDirEntryErrOk);
3910
0
}
3911
3912
static enum TIFFReadDirEntryErr
3913
TIFFReadDirEntryCheckRangeSlong8Long8(uint64_t value)
3914
0
{
3915
0
    if (value > INT64_MAX)
3916
0
        return (TIFFReadDirEntryErrRange);
3917
0
    else
3918
0
        return (TIFFReadDirEntryErrOk);
3919
0
}
3920
3921
static enum TIFFReadDirEntryErr TIFFReadDirEntryData(TIFF *tif, uint64_t offset,
3922
                                                     tmsize_t size, void *dest)
3923
0
{
3924
0
    assert(size > 0);
3925
0
    if (!isMapped(tif))
3926
0
    {
3927
0
        if (!SeekOK(tif, offset))
3928
0
            return (TIFFReadDirEntryErrIo);
3929
0
        if (!ReadOK(tif, dest, size))
3930
0
            return (TIFFReadDirEntryErrIo);
3931
0
    }
3932
0
    else
3933
0
    {
3934
0
        size_t ma, mb;
3935
0
        ma = (size_t)offset;
3936
0
        if ((uint64_t)ma != offset || ma > (~(size_t)0) - (size_t)size)
3937
0
        {
3938
0
            return TIFFReadDirEntryErrIo;
3939
0
        }
3940
0
        mb = ma + size;
3941
0
        if (mb > (uint64_t)tif->tif_size)
3942
0
            return (TIFFReadDirEntryErrIo);
3943
0
        _TIFFmemcpy(dest, tif->tif_base + ma, size);
3944
0
    }
3945
0
    return (TIFFReadDirEntryErrOk);
3946
0
}
3947
3948
static void TIFFReadDirEntryOutputErr(TIFF *tif, enum TIFFReadDirEntryErr err,
3949
                                      const char *module, const char *tagname,
3950
                                      int recover)
3951
0
{
3952
0
    if (!recover)
3953
0
    {
3954
0
        switch (err)
3955
0
        {
3956
0
            case TIFFReadDirEntryErrCount:
3957
0
                TIFFErrorExtR(tif, module, "Incorrect count for \"%s\"",
3958
0
                              tagname);
3959
0
                break;
3960
0
            case TIFFReadDirEntryErrType:
3961
0
                TIFFErrorExtR(tif, module, "Incompatible type for \"%s\"",
3962
0
                              tagname);
3963
0
                break;
3964
0
            case TIFFReadDirEntryErrIo:
3965
0
                TIFFErrorExtR(tif, module, "IO error during reading of \"%s\"",
3966
0
                              tagname);
3967
0
                break;
3968
0
            case TIFFReadDirEntryErrRange:
3969
0
                TIFFErrorExtR(tif, module, "Incorrect value for \"%s\"",
3970
0
                              tagname);
3971
0
                break;
3972
0
            case TIFFReadDirEntryErrPsdif:
3973
0
                TIFFErrorExtR(
3974
0
                    tif, module,
3975
0
                    "Cannot handle different values per sample for \"%s\"",
3976
0
                    tagname);
3977
0
                break;
3978
0
            case TIFFReadDirEntryErrSizesan:
3979
0
                TIFFErrorExtR(tif, module,
3980
0
                              "Sanity check on size of \"%s\" value failed",
3981
0
                              tagname);
3982
0
                break;
3983
0
            case TIFFReadDirEntryErrAlloc:
3984
0
                TIFFErrorExtR(tif, module, "Out of memory reading of \"%s\"",
3985
0
                              tagname);
3986
0
                break;
3987
0
            default:
3988
0
                assert(0); /* we should never get here */
3989
0
                break;
3990
0
        }
3991
0
    }
3992
0
    else
3993
0
    {
3994
0
        switch (err)
3995
0
        {
3996
0
            case TIFFReadDirEntryErrCount:
3997
0
                TIFFWarningExtR(tif, module,
3998
0
                                "Incorrect count for \"%s\"; tag ignored",
3999
0
                                tagname);
4000
0
                break;
4001
0
            case TIFFReadDirEntryErrType:
4002
0
                TIFFWarningExtR(tif, module,
4003
0
                                "Incompatible type for \"%s\"; tag ignored",
4004
0
                                tagname);
4005
0
                break;
4006
0
            case TIFFReadDirEntryErrIo:
4007
0
                TIFFWarningExtR(
4008
0
                    tif, module,
4009
0
                    "IO error during reading of \"%s\"; tag ignored", tagname);
4010
0
                break;
4011
0
            case TIFFReadDirEntryErrRange:
4012
0
                TIFFWarningExtR(tif, module,
4013
0
                                "Incorrect value for \"%s\"; tag ignored",
4014
0
                                tagname);
4015
0
                break;
4016
0
            case TIFFReadDirEntryErrPsdif:
4017
0
                TIFFWarningExtR(tif, module,
4018
0
                                "Cannot handle different values per sample for "
4019
0
                                "\"%s\"; tag ignored",
4020
0
                                tagname);
4021
0
                break;
4022
0
            case TIFFReadDirEntryErrSizesan:
4023
0
                TIFFWarningExtR(
4024
0
                    tif, module,
4025
0
                    "Sanity check on size of \"%s\" value failed; tag ignored",
4026
0
                    tagname);
4027
0
                break;
4028
0
            case TIFFReadDirEntryErrAlloc:
4029
0
                TIFFWarningExtR(tif, module,
4030
0
                                "Out of memory reading of \"%s\"; tag ignored",
4031
0
                                tagname);
4032
0
                break;
4033
0
            default:
4034
0
                assert(0); /* we should never get here */
4035
0
                break;
4036
0
        }
4037
0
    }
4038
0
}
4039
4040
/*
4041
 * Return the maximum number of color channels specified for a given photometric
4042
 * type. 0 is returned if photometric type isn't supported or no default value
4043
 * is defined by the specification.
4044
 */
4045
static int _TIFFGetMaxColorChannels(uint16_t photometric)
4046
0
{
4047
0
    switch (photometric)
4048
0
    {
4049
0
        case PHOTOMETRIC_PALETTE:
4050
0
        case PHOTOMETRIC_MINISWHITE:
4051
0
        case PHOTOMETRIC_MINISBLACK:
4052
0
            return 1;
4053
0
        case PHOTOMETRIC_YCBCR:
4054
0
        case PHOTOMETRIC_RGB:
4055
0
        case PHOTOMETRIC_CIELAB:
4056
0
        case PHOTOMETRIC_LOGLUV:
4057
0
        case PHOTOMETRIC_ITULAB:
4058
0
        case PHOTOMETRIC_ICCLAB:
4059
0
            return 3;
4060
0
        case PHOTOMETRIC_SEPARATED:
4061
0
        case PHOTOMETRIC_MASK:
4062
0
            return 4;
4063
0
        case PHOTOMETRIC_LOGL:
4064
0
        case PHOTOMETRIC_CFA:
4065
0
        default:
4066
0
            return 0;
4067
0
    }
4068
0
}
4069
4070
static int ByteCountLooksBad(TIFF *tif)
4071
0
{
4072
    /*
4073
     * Assume we have wrong StripByteCount value (in case
4074
     * of single strip) in following cases:
4075
     *   - it is equal to zero along with StripOffset;
4076
     *   - it is larger than file itself (in case of uncompressed
4077
     *     image);
4078
     *   - it is smaller than the size of the bytes per row
4079
     *     multiplied on the number of rows.  The last case should
4080
     *     not be checked in the case of writing new image,
4081
     *     because we may do not know the exact strip size
4082
     *     until the whole image will be written and directory
4083
     *     dumped out.
4084
     */
4085
0
    uint64_t bytecount = TIFFGetStrileByteCount(tif, 0);
4086
0
    uint64_t offset = TIFFGetStrileOffset(tif, 0);
4087
0
    uint64_t filesize;
4088
4089
0
    if (offset == 0)
4090
0
        return 0;
4091
0
    if (bytecount == 0)
4092
0
        return 1;
4093
0
    if (tif->tif_dir.td_compression != COMPRESSION_NONE)
4094
0
        return 0;
4095
0
    filesize = TIFFGetFileSize(tif);
4096
0
    if (offset <= filesize && bytecount > filesize - offset)
4097
0
        return 1;
4098
0
    if (tif->tif_mode == O_RDONLY)
4099
0
    {
4100
0
        uint64_t scanlinesize = TIFFScanlineSize64(tif);
4101
0
        if (tif->tif_dir.td_imagelength > 0 &&
4102
0
            scanlinesize > UINT64_MAX / tif->tif_dir.td_imagelength)
4103
0
        {
4104
0
            return 1;
4105
0
        }
4106
0
        if (bytecount < scanlinesize * tif->tif_dir.td_imagelength)
4107
0
            return 1;
4108
0
    }
4109
0
    return 0;
4110
0
}
4111
4112
/*
4113
 * To evaluate the IFD data size when reading, save the offset and data size of
4114
 * all data that does not fit into the IFD entries themselves.
4115
 */
4116
static bool EvaluateIFDdatasizeReading(TIFF *tif, TIFFDirEntry *dp)
4117
0
{
4118
0
    const uint64_t data_width = TIFFDataWidth((TIFFDataType)dp->tdir_type);
4119
0
    if (data_width != 0 && dp->tdir_count > UINT64_MAX / data_width)
4120
0
    {
4121
0
        TIFFErrorExtR(tif, "EvaluateIFDdatasizeReading",
4122
0
                      "Too large IFD data size");
4123
0
        return false;
4124
0
    }
4125
0
    const uint64_t datalength = dp->tdir_count * data_width;
4126
0
    if (datalength > ((tif->tif_flags & TIFF_BIGTIFF) ? 0x8U : 0x4U))
4127
0
    {
4128
0
        if (tif->tif_dir.td_dirdatasize_read > UINT64_MAX - datalength)
4129
0
        {
4130
0
            TIFFErrorExtR(tif, "EvaluateIFDdatasizeReading",
4131
0
                          "Too large IFD data size");
4132
0
            return false;
4133
0
        }
4134
0
        tif->tif_dir.td_dirdatasize_read += datalength;
4135
0
        if (!(tif->tif_flags & TIFF_BIGTIFF))
4136
0
        {
4137
            /* The offset of TIFFDirEntry are not swapped when read in. That has
4138
             * to be done when used. */
4139
0
            uint32_t offset = dp->tdir_offset.toff_long;
4140
0
            if (tif->tif_flags & TIFF_SWAB)
4141
0
                TIFFSwabLong(&offset);
4142
0
            tif->tif_dir
4143
0
                .td_dirdatasize_offsets[tif->tif_dir.td_dirdatasize_Noffsets]
4144
0
                .offset = (uint64_t)offset;
4145
0
        }
4146
0
        else
4147
0
        {
4148
0
            tif->tif_dir
4149
0
                .td_dirdatasize_offsets[tif->tif_dir.td_dirdatasize_Noffsets]
4150
0
                .offset = dp->tdir_offset.toff_long8;
4151
0
            if (tif->tif_flags & TIFF_SWAB)
4152
0
                TIFFSwabLong8(
4153
0
                    &tif->tif_dir
4154
0
                         .td_dirdatasize_offsets[tif->tif_dir
4155
0
                                                     .td_dirdatasize_Noffsets]
4156
0
                         .offset);
4157
0
        }
4158
0
        tif->tif_dir
4159
0
            .td_dirdatasize_offsets[tif->tif_dir.td_dirdatasize_Noffsets]
4160
0
            .length = datalength;
4161
0
        tif->tif_dir.td_dirdatasize_Noffsets++;
4162
0
    }
4163
0
    return true;
4164
0
}
4165
4166
/*
4167
 * Compare function for qsort() sorting TIFFEntryOffsetAndLength array entries.
4168
 */
4169
static int cmpTIFFEntryOffsetAndLength(const void *a, const void *b)
4170
0
{
4171
0
    const TIFFEntryOffsetAndLength *ta = (const TIFFEntryOffsetAndLength *)a;
4172
0
    const TIFFEntryOffsetAndLength *tb = (const TIFFEntryOffsetAndLength *)b;
4173
    /* Compare offsets */
4174
0
    if (ta->offset > tb->offset)
4175
0
        return 1;
4176
0
    else if (ta->offset < tb->offset)
4177
0
        return -1;
4178
0
    else
4179
0
        return 0;
4180
0
}
4181
4182
/*
4183
 * Determine the IFD data size after reading an IFD from the file that can be
4184
 * overwritten and saving it in tif_dir.td_dirdatasize_read. This data size
4185
 * includes the IFD entries themselves as well as the data that does not fit
4186
 * directly into the IFD entries but is located directly after the IFD entries
4187
 * in the file.
4188
 */
4189
static void CalcFinalIFDdatasizeReading(TIFF *tif, uint16_t dircount)
4190
0
{
4191
    /* IFD data size is only needed if file-writing is enabled.
4192
     * This also avoids the seek() to EOF to determine the file size, which
4193
     * causes the stdin-streaming-friendly mode of libtiff for GDAL to fail. */
4194
0
    if (tif->tif_mode == O_RDONLY)
4195
0
        return;
4196
4197
    /* Sort TIFFEntryOffsetAndLength array in ascending order. */
4198
0
    qsort(tif->tif_dir.td_dirdatasize_offsets,
4199
0
          tif->tif_dir.td_dirdatasize_Noffsets,
4200
0
          sizeof(TIFFEntryOffsetAndLength), cmpTIFFEntryOffsetAndLength);
4201
4202
    /* Get offset of end of IFD entry space. */
4203
0
    uint64_t IFDendoffset;
4204
0
    if (!(tif->tif_flags & TIFF_BIGTIFF))
4205
0
        IFDendoffset = tif->tif_diroff + 2 + dircount * 12 + 4;
4206
0
    else
4207
0
        IFDendoffset = tif->tif_diroff + 8 + dircount * 20 + 8;
4208
4209
    /* Check which offsets are right behind IFD entries. However, LibTIFF
4210
     * increments the writing address for every external data to an even offset.
4211
     * Thus gaps of 1 byte can occur. */
4212
0
    uint64_t size = 0;
4213
0
    uint64_t offset;
4214
0
    uint32_t i;
4215
0
    for (i = 0; i < tif->tif_dir.td_dirdatasize_Noffsets; i++)
4216
0
    {
4217
0
        offset = tif->tif_dir.td_dirdatasize_offsets[i].offset;
4218
0
        if (offset == IFDendoffset)
4219
0
        {
4220
0
            size += tif->tif_dir.td_dirdatasize_offsets[i].length;
4221
0
            IFDendoffset += tif->tif_dir.td_dirdatasize_offsets[i].length;
4222
0
        }
4223
0
        else if (offset == IFDendoffset + 1)
4224
0
        {
4225
            /* Add gap byte after previous IFD data set. */
4226
0
            size += tif->tif_dir.td_dirdatasize_offsets[i].length + 1;
4227
0
            IFDendoffset += tif->tif_dir.td_dirdatasize_offsets[i].length;
4228
0
        }
4229
0
        else
4230
0
        {
4231
            /* Further data is no more continuously after IFD */
4232
0
            break;
4233
0
        }
4234
0
    }
4235
    /* Check for gap byte of some easy cases. This should cover 90% of cases.
4236
     * Otherwise, IFD will be re-written even it might be safely overwritten. */
4237
0
    if (tif->tif_nextdiroff != 0)
4238
0
    {
4239
0
        if (tif->tif_nextdiroff == IFDendoffset + 1)
4240
0
            size++;
4241
0
    }
4242
0
    else
4243
0
    {
4244
        /* Check for IFD data ends at EOF. Then IFD can always be safely
4245
         * overwritten. */
4246
0
        offset = TIFFSeekFile(tif, 0, SEEK_END);
4247
0
        if (offset == IFDendoffset)
4248
0
        {
4249
0
            tif->tif_dir.td_dirdatasize_read = UINT64_MAX;
4250
0
            return;
4251
0
        }
4252
0
    }
4253
4254
    /* Finally, add the size of the IFD tag entries themselves. */
4255
0
    if (!(tif->tif_flags & TIFF_BIGTIFF))
4256
0
        tif->tif_dir.td_dirdatasize_read = 2 + dircount * 12 + 4 + size;
4257
0
    else
4258
0
        tif->tif_dir.td_dirdatasize_read = 8 + dircount * 20 + 8 + size;
4259
0
} /*-- CalcFinalIFDdatasizeReading() --*/
4260
4261
/*
4262
 * Read the next TIFF directory from a file and convert it to the internal
4263
 * format. We read directories sequentially.
4264
 */
4265
int TIFFReadDirectory(TIFF *tif)
4266
0
{
4267
0
    static const char module[] = "TIFFReadDirectory";
4268
0
    TIFFDirEntry *dir;
4269
0
    uint16_t dircount;
4270
0
    TIFFDirEntry *dp;
4271
0
    uint16_t di;
4272
0
    const TIFFField *fip;
4273
0
    uint32_t fii = FAILED_FII;
4274
0
    toff_t nextdiroff;
4275
0
    int bitspersample_read = FALSE;
4276
0
    int color_channels;
4277
4278
0
    if (tif->tif_nextdiroff == 0)
4279
0
    {
4280
        /* In this special case, tif_diroff needs also to be set to 0.
4281
         * This is behind the last IFD, thus no checking or reading necessary.
4282
         */
4283
0
        tif->tif_diroff = tif->tif_nextdiroff;
4284
0
        return 0;
4285
0
    }
4286
4287
0
    nextdiroff = tif->tif_nextdiroff;
4288
    /* tif_curdir++ and tif_nextdiroff should only be updated after SUCCESSFUL
4289
     * reading of the directory. Otherwise, invalid IFD offsets could corrupt
4290
     * the IFD list. */
4291
0
    if (!_TIFFCheckDirNumberAndOffset(tif,
4292
0
                                      tif->tif_curdir ==
4293
0
                                              TIFF_NON_EXISTENT_DIR_NUMBER
4294
0
                                          ? 0
4295
0
                                          : tif->tif_curdir + 1,
4296
0
                                      nextdiroff))
4297
0
    {
4298
0
        return 0; /* bad offset (IFD looping or more than TIFF_MAX_DIR_COUNT
4299
                     IFDs) */
4300
0
    }
4301
0
    dircount = TIFFFetchDirectory(tif, nextdiroff, &dir, &tif->tif_nextdiroff);
4302
0
    if (!dircount)
4303
0
    {
4304
0
        TIFFErrorExtR(tif, module,
4305
0
                      "Failed to read directory at offset %" PRIu64,
4306
0
                      nextdiroff);
4307
0
        return 0;
4308
0
    }
4309
    /* Set global values after a valid directory has been fetched.
4310
     * tif_diroff is already set to nextdiroff in TIFFFetchDirectory() in the
4311
     * beginning. */
4312
0
    if (tif->tif_curdir == TIFF_NON_EXISTENT_DIR_NUMBER)
4313
0
        tif->tif_curdir = 0;
4314
0
    else
4315
0
        tif->tif_curdir++;
4316
4317
0
    TIFFReadDirectoryCheckOrder(tif, dir, dircount);
4318
4319
    /*
4320
     * Mark duplicates of any tag to be ignored (bugzilla 1994)
4321
     * to avoid certain pathological problems.
4322
     */
4323
0
    {
4324
0
        TIFFDirEntry *ma;
4325
0
        uint16_t mb;
4326
0
        for (ma = dir, mb = 0; mb < dircount; ma++, mb++)
4327
0
        {
4328
0
            TIFFDirEntry *na;
4329
0
            uint16_t nb;
4330
0
            for (na = ma + 1, nb = mb + 1; nb < dircount; na++, nb++)
4331
0
            {
4332
0
                if (ma->tdir_tag == na->tdir_tag)
4333
0
                {
4334
0
                    na->tdir_ignore = TRUE;
4335
0
                }
4336
0
            }
4337
0
        }
4338
0
    }
4339
4340
0
    tif->tif_flags &= ~TIFF_BEENWRITING; /* reset before new dir */
4341
0
    tif->tif_flags &= ~TIFF_BUF4WRITE;   /* reset before new dir */
4342
0
    tif->tif_flags &= ~TIFF_CHOPPEDUPARRAYS;
4343
4344
    /* When changing directory, in deferred strile loading mode, we must also
4345
     * unset the TIFF_LAZYSTRILELOAD_DONE bit if it was initially set,
4346
     * to make sure the strile offset/bytecount are read again (when they fit
4347
     * in the tag data area).
4348
     */
4349
0
    tif->tif_flags &= ~TIFF_LAZYSTRILELOAD_DONE;
4350
4351
    /* free any old stuff and reinit */
4352
0
    TIFFFreeDirectory(tif);
4353
0
    TIFFDefaultDirectory(tif);
4354
4355
    /* After setup a fresh directory indicate that now active IFD is also
4356
     * present on file, even if its entries could not be read successfully
4357
     * below.  */
4358
0
    tif->tif_dir.td_iswrittentofile = TRUE;
4359
4360
    /* Allocate arrays for offset values outside IFD entry for IFD data size
4361
     * checking. Note: Counter are reset within TIFFFreeDirectory(). */
4362
0
    tif->tif_dir.td_dirdatasize_offsets =
4363
0
        (TIFFEntryOffsetAndLength *)_TIFFmallocExt(
4364
0
            tif, dircount * sizeof(TIFFEntryOffsetAndLength));
4365
0
    if (tif->tif_dir.td_dirdatasize_offsets == NULL)
4366
0
    {
4367
0
        TIFFErrorExtR(
4368
0
            tif, module,
4369
0
            "Failed to allocate memory for counting IFD data size at reading");
4370
0
        goto bad;
4371
0
    }
4372
    /*
4373
     * Electronic Arts writes gray-scale TIFF files
4374
     * without a PlanarConfiguration directory entry.
4375
     * Thus we setup a default value here, even though
4376
     * the TIFF spec says there is no default value.
4377
     * After PlanarConfiguration is preset in TIFFDefaultDirectory()
4378
     * the following setting is not needed, but does not harm either.
4379
     */
4380
0
    TIFFSetField(tif, TIFFTAG_PLANARCONFIG, PLANARCONFIG_CONTIG);
4381
    /*
4382
     * Setup default value and then make a pass over
4383
     * the fields to check type and tag information,
4384
     * and to extract info required to size data
4385
     * structures.  A second pass is made afterwards
4386
     * to read in everything not taken in the first pass.
4387
     * But we must process the Compression tag first
4388
     * in order to merge in codec-private tag definitions (otherwise
4389
     * we may get complaints about unknown tags).  However, the
4390
     * Compression tag may be dependent on the SamplesPerPixel
4391
     * tag value because older TIFF specs permitted Compression
4392
     * to be written as a SamplesPerPixel-count tag entry.
4393
     * Thus if we don't first figure out the correct SamplesPerPixel
4394
     * tag value then we may end up ignoring the Compression tag
4395
     * value because it has an incorrect count value (if the
4396
     * true value of SamplesPerPixel is not 1).
4397
     */
4398
0
    dp =
4399
0
        TIFFReadDirectoryFindEntry(tif, dir, dircount, TIFFTAG_SAMPLESPERPIXEL);
4400
0
    if (dp)
4401
0
    {
4402
0
        if (!TIFFFetchNormalTag(tif, dp, 0))
4403
0
            goto bad;
4404
0
        dp->tdir_ignore = TRUE;
4405
0
    }
4406
0
    dp = TIFFReadDirectoryFindEntry(tif, dir, dircount, TIFFTAG_COMPRESSION);
4407
0
    if (dp)
4408
0
    {
4409
        /*
4410
         * The 5.0 spec says the Compression tag has one value, while
4411
         * earlier specs say it has one value per sample.  Because of
4412
         * this, we accept the tag if one value is supplied with either
4413
         * count.
4414
         */
4415
0
        uint16_t value;
4416
0
        enum TIFFReadDirEntryErr err;
4417
0
        err = TIFFReadDirEntryShort(tif, dp, &value);
4418
0
        if (err == TIFFReadDirEntryErrCount)
4419
0
            err = TIFFReadDirEntryPersampleShort(tif, dp, &value);
4420
0
        if (err != TIFFReadDirEntryErrOk)
4421
0
        {
4422
0
            TIFFReadDirEntryOutputErr(tif, err, module, "Compression", 0);
4423
0
            goto bad;
4424
0
        }
4425
0
        if (!TIFFSetField(tif, TIFFTAG_COMPRESSION, value))
4426
0
            goto bad;
4427
0
        dp->tdir_ignore = TRUE;
4428
0
    }
4429
0
    else
4430
0
    {
4431
0
        if (!TIFFSetField(tif, TIFFTAG_COMPRESSION, COMPRESSION_NONE))
4432
0
            goto bad;
4433
0
    }
4434
    /*
4435
     * First real pass over the directory.
4436
     */
4437
0
    for (di = 0, dp = dir; di < dircount; di++, dp++)
4438
0
    {
4439
0
        if (!dp->tdir_ignore)
4440
0
        {
4441
0
            TIFFReadDirectoryFindFieldInfo(tif, dp->tdir_tag, &fii);
4442
0
            if (fii == FAILED_FII)
4443
0
            {
4444
0
                if (tif->tif_warn_about_unknown_tags)
4445
0
                {
4446
0
                    TIFFWarningExtR(tif, module,
4447
0
                                    "Unknown field with tag %" PRIu16
4448
0
                                    " (0x%" PRIx16 ") encountered",
4449
0
                                    dp->tdir_tag, dp->tdir_tag);
4450
0
                }
4451
                /* the following knowingly leaks the
4452
                   anonymous field structure */
4453
0
                const TIFFField *fld = _TIFFCreateAnonField(
4454
0
                    tif, dp->tdir_tag, (TIFFDataType)dp->tdir_type);
4455
0
                if (fld == NULL || !_TIFFMergeFields(tif, fld, 1))
4456
0
                {
4457
0
                    TIFFWarningExtR(
4458
0
                        tif, module,
4459
0
                        "Registering anonymous field with tag %" PRIu16
4460
0
                        " (0x%" PRIx16 ") failed",
4461
0
                        dp->tdir_tag, dp->tdir_tag);
4462
0
                    dp->tdir_ignore = TRUE;
4463
0
                }
4464
0
                else
4465
0
                {
4466
0
                    TIFFReadDirectoryFindFieldInfo(tif, dp->tdir_tag, &fii);
4467
0
                    assert(fii != FAILED_FII);
4468
0
                }
4469
0
            }
4470
0
        }
4471
0
        if (!dp->tdir_ignore)
4472
0
        {
4473
0
            fip = tif->tif_fields[fii];
4474
0
            if (fip->field_bit == FIELD_IGNORE)
4475
0
                dp->tdir_ignore = TRUE;
4476
0
            else
4477
0
            {
4478
0
                switch (dp->tdir_tag)
4479
0
                {
4480
0
                    case TIFFTAG_STRIPOFFSETS:
4481
0
                    case TIFFTAG_STRIPBYTECOUNTS:
4482
0
                    case TIFFTAG_TILEOFFSETS:
4483
0
                    case TIFFTAG_TILEBYTECOUNTS:
4484
0
                        TIFFSetFieldBit(tif, fip->field_bit);
4485
0
                        break;
4486
0
                    case TIFFTAG_IMAGEWIDTH:
4487
0
                    case TIFFTAG_IMAGELENGTH:
4488
0
                    case TIFFTAG_IMAGEDEPTH:
4489
0
                    case TIFFTAG_TILELENGTH:
4490
0
                    case TIFFTAG_TILEWIDTH:
4491
0
                    case TIFFTAG_TILEDEPTH:
4492
0
                    case TIFFTAG_PLANARCONFIG:
4493
0
                    case TIFFTAG_ROWSPERSTRIP:
4494
0
                    case TIFFTAG_EXTRASAMPLES:
4495
0
                        if (!TIFFFetchNormalTag(tif, dp, 0))
4496
0
                            goto bad;
4497
0
                        dp->tdir_ignore = TRUE;
4498
0
                        break;
4499
0
                    default:
4500
0
                        if (!_TIFFCheckFieldIsValidForCodec(tif, dp->tdir_tag))
4501
0
                            dp->tdir_ignore = TRUE;
4502
0
                        break;
4503
0
                }
4504
0
            }
4505
0
        }
4506
0
    }
4507
    /*
4508
     * XXX: OJPEG hack.
4509
     * If a) compression is OJPEG, b) planarconfig tag says it's separate,
4510
     * c) strip offsets/bytecounts tag are both present and
4511
     * d) both contain exactly one value, then we consistently find
4512
     * that the buggy implementation of the buggy compression scheme
4513
     * matches contig planarconfig best. So we 'fix-up' the tag here
4514
     */
4515
0
    if ((tif->tif_dir.td_compression == COMPRESSION_OJPEG) &&
4516
0
        (tif->tif_dir.td_planarconfig == PLANARCONFIG_SEPARATE))
4517
0
    {
4518
0
        if (!_TIFFFillStriles(tif))
4519
0
            goto bad;
4520
0
        dp = TIFFReadDirectoryFindEntry(tif, dir, dircount,
4521
0
                                        TIFFTAG_STRIPOFFSETS);
4522
0
        if ((dp != 0) && (dp->tdir_count == 1))
4523
0
        {
4524
0
            dp = TIFFReadDirectoryFindEntry(tif, dir, dircount,
4525
0
                                            TIFFTAG_STRIPBYTECOUNTS);
4526
0
            if ((dp != 0) && (dp->tdir_count == 1))
4527
0
            {
4528
0
                tif->tif_dir.td_planarconfig = PLANARCONFIG_CONTIG;
4529
0
                TIFFWarningExtR(tif, module,
4530
0
                                "Planarconfig tag value assumed incorrect, "
4531
0
                                "assuming data is contig instead of chunky");
4532
0
            }
4533
0
        }
4534
0
    }
4535
    /*
4536
     * Allocate directory structure and setup defaults.
4537
     */
4538
0
    if (!TIFFFieldSet(tif, FIELD_IMAGEDIMENSIONS))
4539
0
    {
4540
0
        MissingRequired(tif, "ImageLength");
4541
0
        goto bad;
4542
0
    }
4543
4544
    /*
4545
     * Second pass: extract other information.
4546
     */
4547
0
    for (di = 0, dp = dir; di < dircount; di++, dp++)
4548
0
    {
4549
0
        if (!dp->tdir_ignore)
4550
0
        {
4551
0
            switch (dp->tdir_tag)
4552
0
            {
4553
0
                case TIFFTAG_MINSAMPLEVALUE:
4554
0
                case TIFFTAG_MAXSAMPLEVALUE:
4555
0
                case TIFFTAG_BITSPERSAMPLE:
4556
0
                case TIFFTAG_DATATYPE:
4557
0
                case TIFFTAG_SAMPLEFORMAT:
4558
                    /*
4559
                     * The MinSampleValue, MaxSampleValue, BitsPerSample
4560
                     * DataType and SampleFormat tags are supposed to be
4561
                     * written as one value/sample, but some vendors
4562
                     * incorrectly write one value only -- so we accept
4563
                     * that as well (yuck). Other vendors write correct
4564
                     * value for NumberOfSamples, but incorrect one for
4565
                     * BitsPerSample and friends, and we will read this
4566
                     * too.
4567
                     */
4568
0
                    {
4569
0
                        uint16_t value;
4570
0
                        enum TIFFReadDirEntryErr err;
4571
0
                        err = TIFFReadDirEntryShort(tif, dp, &value);
4572
0
                        if (!EvaluateIFDdatasizeReading(tif, dp))
4573
0
                            goto bad;
4574
0
                        if (err == TIFFReadDirEntryErrCount)
4575
0
                            err =
4576
0
                                TIFFReadDirEntryPersampleShort(tif, dp, &value);
4577
0
                        if (err != TIFFReadDirEntryErrOk)
4578
0
                        {
4579
0
                            fip = TIFFFieldWithTag(tif, dp->tdir_tag);
4580
0
                            TIFFReadDirEntryOutputErr(
4581
0
                                tif, err, module,
4582
0
                                fip ? fip->field_name : "unknown tagname", 0);
4583
0
                            goto bad;
4584
0
                        }
4585
0
                        if (!TIFFSetField(tif, dp->tdir_tag, value))
4586
0
                            goto bad;
4587
0
                        if (dp->tdir_tag == TIFFTAG_BITSPERSAMPLE)
4588
0
                            bitspersample_read = TRUE;
4589
0
                    }
4590
0
                    break;
4591
0
                case TIFFTAG_SMINSAMPLEVALUE:
4592
0
                case TIFFTAG_SMAXSAMPLEVALUE:
4593
0
                {
4594
4595
0
                    double *data = NULL;
4596
0
                    enum TIFFReadDirEntryErr err;
4597
0
                    uint32_t saved_flags;
4598
0
                    int m;
4599
0
                    if (dp->tdir_count !=
4600
0
                        (uint64_t)tif->tif_dir.td_samplesperpixel)
4601
0
                        err = TIFFReadDirEntryErrCount;
4602
0
                    else
4603
0
                        err = TIFFReadDirEntryDoubleArray(tif, dp, &data);
4604
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
4605
0
                        goto bad;
4606
0
                    if (err != TIFFReadDirEntryErrOk)
4607
0
                    {
4608
0
                        fip = TIFFFieldWithTag(tif, dp->tdir_tag);
4609
0
                        TIFFReadDirEntryOutputErr(
4610
0
                            tif, err, module,
4611
0
                            fip ? fip->field_name : "unknown tagname", 0);
4612
0
                        goto bad;
4613
0
                    }
4614
0
                    saved_flags = tif->tif_flags;
4615
0
                    tif->tif_flags |= TIFF_PERSAMPLE;
4616
0
                    m = TIFFSetField(tif, dp->tdir_tag, data);
4617
0
                    tif->tif_flags = saved_flags;
4618
0
                    _TIFFfreeExt(tif, data);
4619
0
                    if (!m)
4620
0
                        goto bad;
4621
0
                }
4622
0
                break;
4623
0
                case TIFFTAG_STRIPOFFSETS:
4624
0
                case TIFFTAG_TILEOFFSETS:
4625
0
                {
4626
0
                    switch (dp->tdir_type)
4627
0
                    {
4628
0
                        case TIFF_SHORT:
4629
0
                        case TIFF_LONG:
4630
0
                        case TIFF_LONG8:
4631
0
                            break;
4632
0
                        default:
4633
                            /* Warn except if directory typically created with
4634
                             * TIFFDeferStrileArrayWriting() */
4635
0
                            if (!(tif->tif_mode == O_RDWR &&
4636
0
                                  dp->tdir_count == 0 && dp->tdir_type == 0 &&
4637
0
                                  dp->tdir_offset.toff_long8 == 0))
4638
0
                            {
4639
0
                                fip = TIFFFieldWithTag(tif, dp->tdir_tag);
4640
0
                                TIFFWarningExtR(
4641
0
                                    tif, module, "Invalid data type for tag %s",
4642
0
                                    fip ? fip->field_name : "unknown tagname");
4643
0
                            }
4644
0
                            break;
4645
0
                    }
4646
0
                    _TIFFmemcpy(&(tif->tif_dir.td_stripoffset_entry), dp,
4647
0
                                sizeof(TIFFDirEntry));
4648
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
4649
0
                        goto bad;
4650
0
                }
4651
0
                break;
4652
0
                case TIFFTAG_STRIPBYTECOUNTS:
4653
0
                case TIFFTAG_TILEBYTECOUNTS:
4654
0
                {
4655
0
                    switch (dp->tdir_type)
4656
0
                    {
4657
0
                        case TIFF_SHORT:
4658
0
                        case TIFF_LONG:
4659
0
                        case TIFF_LONG8:
4660
0
                            break;
4661
0
                        default:
4662
                            /* Warn except if directory typically created with
4663
                             * TIFFDeferStrileArrayWriting() */
4664
0
                            if (!(tif->tif_mode == O_RDWR &&
4665
0
                                  dp->tdir_count == 0 && dp->tdir_type == 0 &&
4666
0
                                  dp->tdir_offset.toff_long8 == 0))
4667
0
                            {
4668
0
                                fip = TIFFFieldWithTag(tif, dp->tdir_tag);
4669
0
                                TIFFWarningExtR(
4670
0
                                    tif, module, "Invalid data type for tag %s",
4671
0
                                    fip ? fip->field_name : "unknown tagname");
4672
0
                            }
4673
0
                            break;
4674
0
                    }
4675
0
                    _TIFFmemcpy(&(tif->tif_dir.td_stripbytecount_entry), dp,
4676
0
                                sizeof(TIFFDirEntry));
4677
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
4678
0
                        goto bad;
4679
0
                }
4680
0
                break;
4681
0
                case TIFFTAG_COLORMAP:
4682
0
                case TIFFTAG_TRANSFERFUNCTION:
4683
0
                {
4684
0
                    enum TIFFReadDirEntryErr err;
4685
0
                    uint32_t countpersample;
4686
0
                    uint32_t countrequired;
4687
0
                    uint32_t incrementpersample;
4688
0
                    uint16_t *value = NULL;
4689
                    /* It would be dangerous to instantiate those tag values */
4690
                    /* since if td_bitspersample has not yet been read (due to
4691
                     */
4692
                    /* unordered tags), it could be read afterwards with a */
4693
                    /* values greater than the default one (1), which may cause
4694
                     */
4695
                    /* crashes in user code */
4696
0
                    if (!bitspersample_read)
4697
0
                    {
4698
0
                        fip = TIFFFieldWithTag(tif, dp->tdir_tag);
4699
0
                        TIFFWarningExtR(
4700
0
                            tif, module,
4701
0
                            "Ignoring %s since BitsPerSample tag not found",
4702
0
                            fip ? fip->field_name : "unknown tagname");
4703
0
                        continue;
4704
0
                    }
4705
                    /* ColorMap or TransferFunction for high bit */
4706
                    /* depths do not make much sense and could be */
4707
                    /* used as a denial of service vector */
4708
0
                    if (tif->tif_dir.td_bitspersample > 24)
4709
0
                    {
4710
0
                        fip = TIFFFieldWithTag(tif, dp->tdir_tag);
4711
0
                        TIFFWarningExtR(
4712
0
                            tif, module,
4713
0
                            "Ignoring %s because BitsPerSample=%" PRIu16 ">24",
4714
0
                            fip ? fip->field_name : "unknown tagname",
4715
0
                            tif->tif_dir.td_bitspersample);
4716
0
                        continue;
4717
0
                    }
4718
0
                    countpersample = (1U << tif->tif_dir.td_bitspersample);
4719
0
                    if ((dp->tdir_tag == TIFFTAG_TRANSFERFUNCTION) &&
4720
0
                        (dp->tdir_count == (uint64_t)countpersample))
4721
0
                    {
4722
0
                        countrequired = countpersample;
4723
0
                        incrementpersample = 0;
4724
0
                    }
4725
0
                    else
4726
0
                    {
4727
0
                        countrequired = 3 * countpersample;
4728
0
                        incrementpersample = countpersample;
4729
0
                    }
4730
0
                    if (dp->tdir_count != (uint64_t)countrequired)
4731
0
                        err = TIFFReadDirEntryErrCount;
4732
0
                    else
4733
0
                        err = TIFFReadDirEntryShortArray(tif, dp, &value);
4734
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
4735
0
                        goto bad;
4736
0
                    if (err != TIFFReadDirEntryErrOk)
4737
0
                    {
4738
0
                        fip = TIFFFieldWithTag(tif, dp->tdir_tag);
4739
0
                        TIFFReadDirEntryOutputErr(
4740
0
                            tif, err, module,
4741
0
                            fip ? fip->field_name : "unknown tagname", 1);
4742
0
                    }
4743
0
                    else
4744
0
                    {
4745
0
                        TIFFSetField(tif, dp->tdir_tag, value,
4746
0
                                     value + incrementpersample,
4747
0
                                     value + 2 * incrementpersample);
4748
0
                        _TIFFfreeExt(tif, value);
4749
0
                    }
4750
0
                }
4751
0
                break;
4752
                    /* BEGIN REV 4.0 COMPATIBILITY */
4753
0
                case TIFFTAG_OSUBFILETYPE:
4754
0
                {
4755
0
                    uint16_t valueo;
4756
0
                    uint32_t value;
4757
0
                    if (TIFFReadDirEntryShort(tif, dp, &valueo) ==
4758
0
                        TIFFReadDirEntryErrOk)
4759
0
                    {
4760
0
                        switch (valueo)
4761
0
                        {
4762
0
                            case OFILETYPE_REDUCEDIMAGE:
4763
0
                                value = FILETYPE_REDUCEDIMAGE;
4764
0
                                break;
4765
0
                            case OFILETYPE_PAGE:
4766
0
                                value = FILETYPE_PAGE;
4767
0
                                break;
4768
0
                            default:
4769
0
                                value = 0;
4770
0
                                break;
4771
0
                        }
4772
0
                        if (value != 0)
4773
0
                            TIFFSetField(tif, TIFFTAG_SUBFILETYPE, value);
4774
0
                    }
4775
0
                }
4776
0
                break;
4777
                /* END REV 4.0 COMPATIBILITY */
4778
#if 0
4779
                case TIFFTAG_EP_BATTERYLEVEL:
4780
                    /* TIFFTAG_EP_BATTERYLEVEL can be RATIONAL or ASCII.
4781
                     * LibTiff defines it as ASCII and converts RATIONAL to an
4782
                     * ASCII string. */
4783
                    switch (dp->tdir_type)
4784
                    {
4785
                        case TIFF_RATIONAL:
4786
                        {
4787
                            /* Read rational and convert to ASCII*/
4788
                            enum TIFFReadDirEntryErr err;
4789
                            TIFFRational_t rValue;
4790
                            err = TIFFReadDirEntryCheckedRationalDirect(
4791
                                tif, dp, &rValue);
4792
                            if (err != TIFFReadDirEntryErrOk)
4793
                            {
4794
                                fip = TIFFFieldWithTag(tif, dp->tdir_tag);
4795
                                TIFFReadDirEntryOutputErr(
4796
                                    tif, err, module,
4797
                                    fip ? fip->field_name : "unknown tagname",
4798
                                    1);
4799
                            }
4800
                            else
4801
                            {
4802
                                char szAux[32];
4803
                                snprintf(szAux, sizeof(szAux) - 1, "%d/%d",
4804
                                         rValue.uNum, rValue.uDenom);
4805
                                TIFFSetField(tif, dp->tdir_tag, szAux);
4806
                            }
4807
                        }
4808
                        break;
4809
                        case TIFF_ASCII:
4810
                            (void)TIFFFetchNormalTag(tif, dp, TRUE);
4811
                            break;
4812
                        default:
4813
                            fip = TIFFFieldWithTag(tif, dp->tdir_tag);
4814
                            TIFFWarningExtR(tif, module,
4815
                                            "Invalid data type for tag %s. "
4816
                                            "ASCII or RATIONAL expected",
4817
                                            fip ? fip->field_name
4818
                                                : "unknown tagname");
4819
                            break;
4820
                    }
4821
                    break;
4822
#endif
4823
0
                default:
4824
0
                    (void)TIFFFetchNormalTag(tif, dp, TRUE);
4825
0
                    break;
4826
0
            } /* -- switch (dp->tdir_tag) -- */
4827
0
        }     /* -- if (!dp->tdir_ignore) */
4828
0
    }         /* -- for-loop -- */
4829
4830
    /* Evaluate final IFD data size. */
4831
0
    CalcFinalIFDdatasizeReading(tif, dircount);
4832
4833
    /*
4834
     * OJPEG hack:
4835
     * - If a) compression is OJPEG, and b) photometric tag is missing,
4836
     * then we consistently find that photometric should be YCbCr
4837
     * - If a) compression is OJPEG, and b) photometric tag says it's RGB,
4838
     * then we consistently find that the buggy implementation of the
4839
     * buggy compression scheme matches photometric YCbCr instead.
4840
     * - If a) compression is OJPEG, and b) bitspersample tag is missing,
4841
     * then we consistently find bitspersample should be 8.
4842
     * - If a) compression is OJPEG, b) samplesperpixel tag is missing,
4843
     * and c) photometric is RGB or YCbCr, then we consistently find
4844
     * samplesperpixel should be 3
4845
     * - If a) compression is OJPEG, b) samplesperpixel tag is missing,
4846
     * and c) photometric is MINISWHITE or MINISBLACK, then we consistently
4847
     * find samplesperpixel should be 3
4848
     */
4849
0
    if (tif->tif_dir.td_compression == COMPRESSION_OJPEG)
4850
0
    {
4851
0
        if (!TIFFFieldSet(tif, FIELD_PHOTOMETRIC))
4852
0
        {
4853
0
            TIFFWarningExtR(
4854
0
                tif, module,
4855
0
                "Photometric tag is missing, assuming data is YCbCr");
4856
0
            if (!TIFFSetField(tif, TIFFTAG_PHOTOMETRIC, PHOTOMETRIC_YCBCR))
4857
0
                goto bad;
4858
0
        }
4859
0
        else if (tif->tif_dir.td_photometric == PHOTOMETRIC_RGB)
4860
0
        {
4861
0
            tif->tif_dir.td_photometric = PHOTOMETRIC_YCBCR;
4862
0
            TIFFWarningExtR(tif, module,
4863
0
                            "Photometric tag value assumed incorrect, "
4864
0
                            "assuming data is YCbCr instead of RGB");
4865
0
        }
4866
0
        if (!TIFFFieldSet(tif, FIELD_BITSPERSAMPLE))
4867
0
        {
4868
0
            TIFFWarningExtR(
4869
0
                tif, module,
4870
0
                "BitsPerSample tag is missing, assuming 8 bits per sample");
4871
0
            if (!TIFFSetField(tif, TIFFTAG_BITSPERSAMPLE, 8))
4872
0
                goto bad;
4873
0
        }
4874
0
        if (!TIFFFieldSet(tif, FIELD_SAMPLESPERPIXEL))
4875
0
        {
4876
0
            if (tif->tif_dir.td_photometric == PHOTOMETRIC_RGB)
4877
0
            {
4878
0
                TIFFWarningExtR(tif, module,
4879
0
                                "SamplesPerPixel tag is missing, "
4880
0
                                "assuming correct SamplesPerPixel value is 3");
4881
0
                if (!TIFFSetField(tif, TIFFTAG_SAMPLESPERPIXEL, 3))
4882
0
                    goto bad;
4883
0
            }
4884
0
            if (tif->tif_dir.td_photometric == PHOTOMETRIC_YCBCR)
4885
0
            {
4886
0
                TIFFWarningExtR(tif, module,
4887
0
                                "SamplesPerPixel tag is missing, "
4888
0
                                "applying correct SamplesPerPixel value of 3");
4889
0
                if (!TIFFSetField(tif, TIFFTAG_SAMPLESPERPIXEL, 3))
4890
0
                    goto bad;
4891
0
            }
4892
0
            else if ((tif->tif_dir.td_photometric == PHOTOMETRIC_MINISWHITE) ||
4893
0
                     (tif->tif_dir.td_photometric == PHOTOMETRIC_MINISBLACK))
4894
0
            {
4895
                /*
4896
                 * SamplesPerPixel tag is missing, but is not required
4897
                 * by spec.  Assume correct SamplesPerPixel value of 1.
4898
                 */
4899
0
                if (!TIFFSetField(tif, TIFFTAG_SAMPLESPERPIXEL, 1))
4900
0
                    goto bad;
4901
0
            }
4902
0
        }
4903
0
    }
4904
4905
    /*
4906
     * Setup appropriate structures (by strip or by tile)
4907
     * We do that only after the above OJPEG hack which alters SamplesPerPixel
4908
     * and thus influences the number of strips in the separate planarconfig.
4909
     */
4910
0
    if (!TIFFFieldSet(tif, FIELD_TILEDIMENSIONS))
4911
0
    {
4912
0
        tif->tif_dir.td_nstrips = TIFFNumberOfStrips(tif);
4913
0
        tif->tif_dir.td_tilewidth = tif->tif_dir.td_imagewidth;
4914
0
        tif->tif_dir.td_tilelength = tif->tif_dir.td_rowsperstrip;
4915
0
        tif->tif_dir.td_tiledepth = tif->tif_dir.td_imagedepth;
4916
0
        tif->tif_flags &= ~TIFF_ISTILED;
4917
0
    }
4918
0
    else
4919
0
    {
4920
0
        tif->tif_dir.td_nstrips = TIFFNumberOfTiles(tif);
4921
0
        tif->tif_flags |= TIFF_ISTILED;
4922
0
    }
4923
0
    if (!tif->tif_dir.td_nstrips)
4924
0
    {
4925
0
        TIFFErrorExtR(tif, module, "Cannot handle zero number of %s",
4926
0
                      isTiled(tif) ? "tiles" : "strips");
4927
0
        goto bad;
4928
0
    }
4929
0
    tif->tif_dir.td_stripsperimage = tif->tif_dir.td_nstrips;
4930
0
    if (tif->tif_dir.td_planarconfig == PLANARCONFIG_SEPARATE)
4931
0
        tif->tif_dir.td_stripsperimage /= tif->tif_dir.td_samplesperpixel;
4932
0
    if (!TIFFFieldSet(tif, FIELD_STRIPOFFSETS))
4933
0
    {
4934
0
#ifdef OJPEG_SUPPORT
4935
0
        if ((tif->tif_dir.td_compression == COMPRESSION_OJPEG) &&
4936
0
            (isTiled(tif) == 0) && (tif->tif_dir.td_nstrips == 1))
4937
0
        {
4938
            /*
4939
             * XXX: OJPEG hack.
4940
             * If a) compression is OJPEG, b) it's not a tiled TIFF,
4941
             * and c) the number of strips is 1,
4942
             * then we tolerate the absence of stripoffsets tag,
4943
             * because, presumably, all required data is in the
4944
             * JpegInterchangeFormat stream.
4945
             */
4946
0
            TIFFSetFieldBit(tif, FIELD_STRIPOFFSETS);
4947
0
        }
4948
0
        else
4949
0
#endif
4950
0
        {
4951
0
            MissingRequired(tif, isTiled(tif) ? "TileOffsets" : "StripOffsets");
4952
0
            goto bad;
4953
0
        }
4954
0
    }
4955
4956
0
    if (tif->tif_mode == O_RDWR &&
4957
0
        tif->tif_dir.td_stripoffset_entry.tdir_tag != 0 &&
4958
0
        tif->tif_dir.td_stripoffset_entry.tdir_count == 0 &&
4959
0
        tif->tif_dir.td_stripoffset_entry.tdir_type == 0 &&
4960
0
        tif->tif_dir.td_stripoffset_entry.tdir_offset.toff_long8 == 0 &&
4961
0
        tif->tif_dir.td_stripbytecount_entry.tdir_tag != 0 &&
4962
0
        tif->tif_dir.td_stripbytecount_entry.tdir_count == 0 &&
4963
0
        tif->tif_dir.td_stripbytecount_entry.tdir_type == 0 &&
4964
0
        tif->tif_dir.td_stripbytecount_entry.tdir_offset.toff_long8 == 0)
4965
0
    {
4966
        /* Directory typically created with TIFFDeferStrileArrayWriting() */
4967
0
        TIFFSetupStrips(tif);
4968
0
    }
4969
0
    else if (!(tif->tif_flags & TIFF_DEFERSTRILELOAD))
4970
0
    {
4971
0
        if (tif->tif_dir.td_stripoffset_entry.tdir_tag != 0)
4972
0
        {
4973
0
            if (!TIFFFetchStripThing(tif, &(tif->tif_dir.td_stripoffset_entry),
4974
0
                                     tif->tif_dir.td_nstrips,
4975
0
                                     &tif->tif_dir.td_stripoffset_p))
4976
0
            {
4977
0
                goto bad;
4978
0
            }
4979
0
        }
4980
0
        if (tif->tif_dir.td_stripbytecount_entry.tdir_tag != 0)
4981
0
        {
4982
0
            if (!TIFFFetchStripThing(
4983
0
                    tif, &(tif->tif_dir.td_stripbytecount_entry),
4984
0
                    tif->tif_dir.td_nstrips, &tif->tif_dir.td_stripbytecount_p))
4985
0
            {
4986
0
                goto bad;
4987
0
            }
4988
0
        }
4989
0
    }
4990
4991
    /*
4992
     * Make sure all non-color channels are extrasamples.
4993
     * If it's not the case, define them as such.
4994
     */
4995
0
    color_channels = _TIFFGetMaxColorChannels(tif->tif_dir.td_photometric);
4996
0
    if (color_channels &&
4997
0
        tif->tif_dir.td_samplesperpixel - tif->tif_dir.td_extrasamples >
4998
0
            color_channels)
4999
0
    {
5000
0
        uint16_t old_extrasamples;
5001
0
        uint16_t *new_sampleinfo;
5002
5003
0
        TIFFWarningExtR(
5004
0
            tif, module,
5005
0
            "Sum of Photometric type-related "
5006
0
            "color channels and ExtraSamples doesn't match SamplesPerPixel. "
5007
0
            "Defining non-color channels as ExtraSamples.");
5008
5009
0
        old_extrasamples = tif->tif_dir.td_extrasamples;
5010
0
        tif->tif_dir.td_extrasamples =
5011
0
            (uint16_t)(tif->tif_dir.td_samplesperpixel - color_channels);
5012
5013
        // sampleinfo should contain information relative to these new extra
5014
        // samples
5015
0
        new_sampleinfo = (uint16_t *)_TIFFcallocExt(
5016
0
            tif, tif->tif_dir.td_extrasamples, sizeof(uint16_t));
5017
0
        if (!new_sampleinfo)
5018
0
        {
5019
0
            TIFFErrorExtR(tif, module,
5020
0
                          "Failed to allocate memory for "
5021
0
                          "temporary new sampleinfo array "
5022
0
                          "(%" PRIu16 " 16 bit elements)",
5023
0
                          tif->tif_dir.td_extrasamples);
5024
0
            goto bad;
5025
0
        }
5026
5027
0
        if (old_extrasamples > 0)
5028
0
            memcpy(new_sampleinfo, tif->tif_dir.td_sampleinfo,
5029
0
                   old_extrasamples * sizeof(uint16_t));
5030
0
        _TIFFsetShortArrayExt(tif, &tif->tif_dir.td_sampleinfo, new_sampleinfo,
5031
0
                              tif->tif_dir.td_extrasamples);
5032
0
        _TIFFfreeExt(tif, new_sampleinfo);
5033
0
    }
5034
5035
    /*
5036
     * Verify Palette image has a Colormap.
5037
     */
5038
0
    if (tif->tif_dir.td_photometric == PHOTOMETRIC_PALETTE &&
5039
0
        !TIFFFieldSet(tif, FIELD_COLORMAP))
5040
0
    {
5041
0
        if (tif->tif_dir.td_bitspersample >= 8 &&
5042
0
            tif->tif_dir.td_samplesperpixel == 3)
5043
0
            tif->tif_dir.td_photometric = PHOTOMETRIC_RGB;
5044
0
        else if (tif->tif_dir.td_bitspersample >= 8)
5045
0
            tif->tif_dir.td_photometric = PHOTOMETRIC_MINISBLACK;
5046
0
        else
5047
0
        {
5048
0
            MissingRequired(tif, "Colormap");
5049
0
            goto bad;
5050
0
        }
5051
0
    }
5052
    /*
5053
     * OJPEG hack:
5054
     * We do no further messing with strip/tile offsets/bytecounts in OJPEG
5055
     * TIFFs
5056
     */
5057
0
    if (tif->tif_dir.td_compression != COMPRESSION_OJPEG)
5058
0
    {
5059
        /*
5060
         * Attempt to deal with a missing StripByteCounts tag.
5061
         */
5062
0
        if (!TIFFFieldSet(tif, FIELD_STRIPBYTECOUNTS))
5063
0
        {
5064
            /*
5065
             * Some manufacturers violate the spec by not giving
5066
             * the size of the strips.  In this case, assume there
5067
             * is one uncompressed strip of data.
5068
             */
5069
0
            if ((tif->tif_dir.td_planarconfig == PLANARCONFIG_CONTIG &&
5070
0
                 tif->tif_dir.td_nstrips > 1) ||
5071
0
                (tif->tif_dir.td_planarconfig == PLANARCONFIG_SEPARATE &&
5072
0
                 tif->tif_dir.td_nstrips !=
5073
0
                     (uint32_t)tif->tif_dir.td_samplesperpixel))
5074
0
            {
5075
0
                MissingRequired(tif, "StripByteCounts");
5076
0
                goto bad;
5077
0
            }
5078
0
            TIFFWarningExtR(
5079
0
                tif, module,
5080
0
                "TIFF directory is missing required "
5081
0
                "\"StripByteCounts\" field, calculating from imagelength");
5082
0
            if (EstimateStripByteCounts(tif, dir, dircount) < 0)
5083
0
                goto bad;
5084
0
        }
5085
0
        else if (tif->tif_dir.td_nstrips == 1 &&
5086
0
                 !(tif->tif_flags & TIFF_ISTILED) && ByteCountLooksBad(tif))
5087
0
        {
5088
            /*
5089
             * XXX: Plexus (and others) sometimes give a value of
5090
             * zero for a tag when they don't know what the
5091
             * correct value is!  Try and handle the simple case
5092
             * of estimating the size of a one strip image.
5093
             */
5094
0
            TIFFWarningExtR(tif, module,
5095
0
                            "Bogus \"StripByteCounts\" field, ignoring and "
5096
0
                            "calculating from imagelength");
5097
0
            if (EstimateStripByteCounts(tif, dir, dircount) < 0)
5098
0
                goto bad;
5099
0
        }
5100
0
        else if (!(tif->tif_flags & TIFF_DEFERSTRILELOAD) &&
5101
0
                 tif->tif_dir.td_planarconfig == PLANARCONFIG_CONTIG &&
5102
0
                 tif->tif_dir.td_nstrips > 2 &&
5103
0
                 tif->tif_dir.td_compression == COMPRESSION_NONE &&
5104
0
                 TIFFGetStrileByteCount(tif, 0) !=
5105
0
                     TIFFGetStrileByteCount(tif, 1) &&
5106
0
                 TIFFGetStrileByteCount(tif, 0) != 0 &&
5107
0
                 TIFFGetStrileByteCount(tif, 1) != 0)
5108
0
        {
5109
            /*
5110
             * XXX: Some vendors fill StripByteCount array with
5111
             * absolutely wrong values (it can be equal to
5112
             * StripOffset array, for example). Catch this case
5113
             * here.
5114
             *
5115
             * We avoid this check if deferring strile loading
5116
             * as it would always force us to load the strip/tile
5117
             * information.
5118
             */
5119
0
            TIFFWarningExtR(tif, module,
5120
0
                            "Wrong \"StripByteCounts\" field, ignoring and "
5121
0
                            "calculating from imagelength");
5122
0
            if (EstimateStripByteCounts(tif, dir, dircount) < 0)
5123
0
                goto bad;
5124
0
        }
5125
0
    }
5126
0
    if (dir)
5127
0
    {
5128
0
        _TIFFfreeExt(tif, dir);
5129
0
        dir = NULL;
5130
0
    }
5131
0
    if (!TIFFFieldSet(tif, FIELD_MAXSAMPLEVALUE))
5132
0
    {
5133
0
        if (tif->tif_dir.td_bitspersample >= 16)
5134
0
            tif->tif_dir.td_maxsamplevalue = 0xFFFF;
5135
0
        else
5136
0
            tif->tif_dir.td_maxsamplevalue =
5137
0
                (uint16_t)((1L << tif->tif_dir.td_bitspersample) - 1);
5138
0
    }
5139
5140
#ifdef STRIPBYTECOUNTSORTED_UNUSED
5141
    /*
5142
     * XXX: We can optimize checking for the strip bounds using the sorted
5143
     * bytecounts array. See also comments for TIFFAppendToStrip()
5144
     * function in tif_write.c.
5145
     */
5146
    if (!(tif->tif_flags & TIFF_DEFERSTRILELOAD) && tif->tif_dir.td_nstrips > 1)
5147
    {
5148
        uint32_t strip;
5149
5150
        tif->tif_dir.td_stripbytecountsorted = 1;
5151
        for (strip = 1; strip < tif->tif_dir.td_nstrips; strip++)
5152
        {
5153
            if (TIFFGetStrileOffset(tif, strip - 1) >
5154
                TIFFGetStrileOffset(tif, strip))
5155
            {
5156
                tif->tif_dir.td_stripbytecountsorted = 0;
5157
                break;
5158
            }
5159
        }
5160
    }
5161
#endif
5162
5163
    /*
5164
     * An opportunity for compression mode dependent tag fixup
5165
     */
5166
0
    (*tif->tif_fixuptags)(tif);
5167
5168
    /*
5169
     * Some manufacturers make life difficult by writing
5170
     * large amounts of uncompressed data as a single strip.
5171
     * This is contrary to the recommendations of the spec.
5172
     * The following makes an attempt at breaking such images
5173
     * into strips closer to the recommended 8k bytes.  A
5174
     * side effect, however, is that the RowsPerStrip tag
5175
     * value may be changed.
5176
     */
5177
0
    if ((tif->tif_dir.td_planarconfig == PLANARCONFIG_CONTIG) &&
5178
0
        (tif->tif_dir.td_nstrips == 1) &&
5179
0
        (tif->tif_dir.td_compression == COMPRESSION_NONE) &&
5180
0
        ((tif->tif_flags & (TIFF_STRIPCHOP | TIFF_ISTILED)) == TIFF_STRIPCHOP))
5181
0
    {
5182
0
        ChopUpSingleUncompressedStrip(tif);
5183
0
    }
5184
5185
    /* There are also uncompressed striped files with strips larger than */
5186
    /* 2 GB, which make them unfriendly with a lot of code. If possible, */
5187
    /* try to expose smaller "virtual" strips. */
5188
0
    if (tif->tif_dir.td_planarconfig == PLANARCONFIG_CONTIG &&
5189
0
        tif->tif_dir.td_compression == COMPRESSION_NONE &&
5190
0
        (tif->tif_flags & (TIFF_STRIPCHOP | TIFF_ISTILED)) == TIFF_STRIPCHOP &&
5191
0
        TIFFStripSize64(tif) > 0x7FFFFFFFUL)
5192
0
    {
5193
0
        TryChopUpUncompressedBigTiff(tif);
5194
0
    }
5195
5196
    /*
5197
     * Clear the dirty directory flag.
5198
     */
5199
0
    tif->tif_flags &= ~TIFF_DIRTYDIRECT;
5200
0
    tif->tif_flags &= ~TIFF_DIRTYSTRIP;
5201
5202
    /*
5203
     * Reinitialize i/o since we are starting on a new directory.
5204
     */
5205
0
    tif->tif_row = (uint32_t)-1;
5206
0
    tif->tif_curstrip = (uint32_t)-1;
5207
0
    tif->tif_col = (uint32_t)-1;
5208
0
    tif->tif_curtile = (uint32_t)-1;
5209
0
    tif->tif_tilesize = (tmsize_t)-1;
5210
5211
0
    tif->tif_scanlinesize = TIFFScanlineSize(tif);
5212
0
    if (!tif->tif_scanlinesize)
5213
0
    {
5214
0
        TIFFErrorExtR(tif, module, "Cannot handle zero scanline size");
5215
0
        return (0);
5216
0
    }
5217
5218
0
    if (isTiled(tif))
5219
0
    {
5220
0
        tif->tif_tilesize = TIFFTileSize(tif);
5221
0
        if (!tif->tif_tilesize)
5222
0
        {
5223
0
            TIFFErrorExtR(tif, module, "Cannot handle zero tile size");
5224
0
            return (0);
5225
0
        }
5226
0
    }
5227
0
    else
5228
0
    {
5229
0
        if (!TIFFStripSize(tif))
5230
0
        {
5231
0
            TIFFErrorExtR(tif, module, "Cannot handle zero strip size");
5232
0
            return (0);
5233
0
        }
5234
0
    }
5235
0
    return (1);
5236
0
bad:
5237
0
    if (dir)
5238
0
        _TIFFfreeExt(tif, dir);
5239
0
    return (0);
5240
0
} /*-- TIFFReadDirectory() --*/
5241
5242
static void TIFFReadDirectoryCheckOrder(TIFF *tif, TIFFDirEntry *dir,
5243
                                        uint16_t dircount)
5244
0
{
5245
0
    static const char module[] = "TIFFReadDirectoryCheckOrder";
5246
0
    uint32_t m;
5247
0
    uint16_t n;
5248
0
    TIFFDirEntry *o;
5249
0
    m = 0;
5250
0
    for (n = 0, o = dir; n < dircount; n++, o++)
5251
0
    {
5252
0
        if (o->tdir_tag < m)
5253
0
        {
5254
0
            TIFFWarningExtR(tif, module,
5255
0
                            "Invalid TIFF directory; tags are not sorted in "
5256
0
                            "ascending order");
5257
0
            break;
5258
0
        }
5259
0
        m = o->tdir_tag + 1;
5260
0
    }
5261
0
}
5262
5263
static TIFFDirEntry *TIFFReadDirectoryFindEntry(TIFF *tif, TIFFDirEntry *dir,
5264
                                                uint16_t dircount,
5265
                                                uint16_t tagid)
5266
0
{
5267
0
    TIFFDirEntry *m;
5268
0
    uint16_t n;
5269
0
    (void)tif;
5270
0
    for (m = dir, n = 0; n < dircount; m++, n++)
5271
0
    {
5272
0
        if (m->tdir_tag == tagid)
5273
0
            return (m);
5274
0
    }
5275
0
    return (0);
5276
0
}
5277
5278
static void TIFFReadDirectoryFindFieldInfo(TIFF *tif, uint16_t tagid,
5279
                                           uint32_t *fii)
5280
0
{
5281
0
    int32_t ma, mb, mc;
5282
0
    ma = -1;
5283
0
    mc = (int32_t)tif->tif_nfields;
5284
0
    while (1)
5285
0
    {
5286
0
        if (ma + 1 == mc)
5287
0
        {
5288
0
            *fii = FAILED_FII;
5289
0
            return;
5290
0
        }
5291
0
        mb = (ma + mc) / 2;
5292
0
        if (tif->tif_fields[mb]->field_tag == (uint32_t)tagid)
5293
0
            break;
5294
0
        if (tif->tif_fields[mb]->field_tag < (uint32_t)tagid)
5295
0
            ma = mb;
5296
0
        else
5297
0
            mc = mb;
5298
0
    }
5299
0
    while (1)
5300
0
    {
5301
0
        if (mb == 0)
5302
0
            break;
5303
0
        if (tif->tif_fields[mb - 1]->field_tag != (uint32_t)tagid)
5304
0
            break;
5305
0
        mb--;
5306
0
    }
5307
0
    *fii = mb;
5308
0
}
5309
5310
/*
5311
 * Read custom directory from the arbitrary offset.
5312
 * The code is very similar to TIFFReadDirectory().
5313
 */
5314
int TIFFReadCustomDirectory(TIFF *tif, toff_t diroff,
5315
                            const TIFFFieldArray *infoarray)
5316
0
{
5317
0
    static const char module[] = "TIFFReadCustomDirectory";
5318
0
    TIFFDirEntry *dir;
5319
0
    uint16_t dircount;
5320
0
    TIFFDirEntry *dp;
5321
0
    uint16_t di;
5322
0
    const TIFFField *fip;
5323
0
    uint32_t fii;
5324
5325
0
    assert(infoarray != NULL);
5326
0
    dircount = TIFFFetchDirectory(tif, diroff, &dir, NULL);
5327
0
    if (!dircount)
5328
0
    {
5329
0
        TIFFErrorExtR(tif, module,
5330
0
                      "Failed to read custom directory at offset %" PRIu64,
5331
0
                      diroff);
5332
0
        return 0;
5333
0
    }
5334
0
    TIFFReadDirectoryCheckOrder(tif, dir, dircount);
5335
5336
    /*
5337
     * Mark duplicates of any tag to be ignored (bugzilla 1994)
5338
     * to avoid certain pathological problems.
5339
     */
5340
0
    {
5341
0
        TIFFDirEntry *ma;
5342
0
        uint16_t mb;
5343
0
        for (ma = dir, mb = 0; mb < dircount; ma++, mb++)
5344
0
        {
5345
0
            TIFFDirEntry *na;
5346
0
            uint16_t nb;
5347
0
            for (na = ma + 1, nb = mb + 1; nb < dircount; na++, nb++)
5348
0
            {
5349
0
                if (ma->tdir_tag == na->tdir_tag)
5350
0
                {
5351
0
                    na->tdir_ignore = TRUE;
5352
0
                }
5353
0
            }
5354
0
        }
5355
0
    }
5356
5357
    /* Free any old stuff and reinit. */
5358
0
    TIFFFreeDirectory(tif);
5359
    /* Even if custom directories do not need the default settings of a standard
5360
     * IFD, the pointer to the TIFFSetField() and TIFFGetField() (i.e.
5361
     * tif->tif_tagmethods.vsetfield and tif->tif_tagmethods.vgetfield) need to
5362
     * be initialized, which is done in TIFFDefaultDirectory().
5363
     * After that, the field array for the custom tags needs to be setup again.
5364
     */
5365
0
    TIFFDefaultDirectory(tif);
5366
0
    _TIFFSetupFields(tif, infoarray);
5367
5368
    /* Allocate arrays for offset values outside IFD entry for IFD data size
5369
     * checking. Note: Counter are reset within TIFFFreeDirectory(). */
5370
0
    tif->tif_dir.td_dirdatasize_offsets =
5371
0
        (TIFFEntryOffsetAndLength *)_TIFFmallocExt(
5372
0
            tif, dircount * sizeof(TIFFEntryOffsetAndLength));
5373
0
    if (tif->tif_dir.td_dirdatasize_offsets == NULL)
5374
0
    {
5375
0
        TIFFErrorExtR(
5376
0
            tif, module,
5377
0
            "Failed to allocate memory for counting IFD data size at reading");
5378
0
        if (dir)
5379
0
            _TIFFfreeExt(tif, dir);
5380
0
        return 0;
5381
0
    }
5382
5383
0
    for (di = 0, dp = dir; di < dircount; di++, dp++)
5384
0
    {
5385
0
        TIFFReadDirectoryFindFieldInfo(tif, dp->tdir_tag, &fii);
5386
0
        if (fii == FAILED_FII)
5387
0
        {
5388
0
            if (tif->tif_warn_about_unknown_tags)
5389
0
            {
5390
0
                TIFFWarningExtR(tif, module,
5391
0
                                "Unknown field with tag %" PRIu16 " (0x%" PRIx16
5392
0
                                ") encountered",
5393
0
                                dp->tdir_tag, dp->tdir_tag);
5394
0
            }
5395
0
            const TIFFField *fld = _TIFFCreateAnonField(
5396
0
                tif, dp->tdir_tag, (TIFFDataType)dp->tdir_type);
5397
0
            if (fld == NULL || !_TIFFMergeFields(tif, fld, 1))
5398
0
            {
5399
0
                if (tif->tif_warn_about_unknown_tags)
5400
0
                {
5401
0
                    TIFFWarningExtR(
5402
0
                        tif, module,
5403
0
                        "Registering anonymous field with tag %" PRIu16
5404
0
                        " (0x%" PRIx16 ") failed",
5405
0
                        dp->tdir_tag, dp->tdir_tag);
5406
0
                }
5407
0
                dp->tdir_ignore = TRUE;
5408
0
            }
5409
0
            else
5410
0
            {
5411
0
                TIFFReadDirectoryFindFieldInfo(tif, dp->tdir_tag, &fii);
5412
0
                assert(fii != FAILED_FII);
5413
0
            }
5414
0
        }
5415
0
        if (!dp->tdir_ignore)
5416
0
        {
5417
0
            fip = tif->tif_fields[fii];
5418
0
            if (fip->field_bit == FIELD_IGNORE)
5419
0
                dp->tdir_ignore = TRUE;
5420
0
            else
5421
0
            {
5422
                /* check data type */
5423
0
                while ((fip->field_type != TIFF_ANY) &&
5424
0
                       (fip->field_type != dp->tdir_type))
5425
0
                {
5426
0
                    fii++;
5427
0
                    if ((fii == tif->tif_nfields) ||
5428
0
                        (tif->tif_fields[fii]->field_tag !=
5429
0
                         (uint32_t)dp->tdir_tag))
5430
0
                    {
5431
0
                        fii = 0xFFFF;
5432
0
                        break;
5433
0
                    }
5434
0
                    fip = tif->tif_fields[fii];
5435
0
                }
5436
0
                if (fii == 0xFFFF)
5437
0
                {
5438
0
                    TIFFWarningExtR(tif, module,
5439
0
                                    "Wrong data type %" PRIu16
5440
0
                                    " for \"%s\"; tag ignored",
5441
0
                                    dp->tdir_type, fip->field_name);
5442
0
                    dp->tdir_ignore = TRUE;
5443
0
                }
5444
0
                else
5445
0
                {
5446
                    /* check count if known in advance */
5447
0
                    if ((fip->field_readcount != TIFF_VARIABLE) &&
5448
0
                        (fip->field_readcount != TIFF_VARIABLE2))
5449
0
                    {
5450
0
                        uint32_t expected;
5451
0
                        if (fip->field_readcount == TIFF_SPP)
5452
0
                            expected =
5453
0
                                (uint32_t)tif->tif_dir.td_samplesperpixel;
5454
0
                        else
5455
0
                            expected = (uint32_t)fip->field_readcount;
5456
0
                        if (!CheckDirCount(tif, dp, expected))
5457
0
                            dp->tdir_ignore = TRUE;
5458
0
                    }
5459
0
                }
5460
0
            }
5461
0
            if (!dp->tdir_ignore)
5462
0
            {
5463
0
                switch (dp->tdir_tag)
5464
0
                {
5465
0
                    case EXIFTAG_SUBJECTDISTANCE:
5466
0
                        if (!TIFFFieldIsAnonymous(fip))
5467
0
                        {
5468
                            /* should only be called on a Exif directory */
5469
                            /* when exifFields[] is active */
5470
0
                            (void)TIFFFetchSubjectDistance(tif, dp);
5471
0
                        }
5472
0
                        else
5473
0
                        {
5474
0
                            (void)TIFFFetchNormalTag(tif, dp, TRUE);
5475
0
                        }
5476
0
                        break;
5477
0
                    default:
5478
0
                        (void)TIFFFetchNormalTag(tif, dp, TRUE);
5479
0
                        break;
5480
0
                }
5481
0
            } /*-- if (!dp->tdir_ignore) */
5482
0
        }
5483
0
    }
5484
    /* Evaluate final IFD data size. */
5485
0
    CalcFinalIFDdatasizeReading(tif, dircount);
5486
5487
    /* To be able to return from SubIFD or custom-IFD to main-IFD */
5488
0
    tif->tif_setdirectory_force_absolute = TRUE;
5489
0
    if (dir)
5490
0
        _TIFFfreeExt(tif, dir);
5491
0
    return 1;
5492
0
}
5493
5494
/*
5495
 * EXIF is important special case of custom IFD, so we have a special
5496
 * function to read it.
5497
 */
5498
int TIFFReadEXIFDirectory(TIFF *tif, toff_t diroff)
5499
0
{
5500
0
    return TIFFReadCustomDirectory(tif, diroff, _TIFFGetExifFields());
5501
0
}
5502
5503
/*
5504
 *--: EXIF-GPS custom directory reading as another special case of custom IFD.
5505
 */
5506
int TIFFReadGPSDirectory(TIFF *tif, toff_t diroff)
5507
0
{
5508
0
    return TIFFReadCustomDirectory(tif, diroff, _TIFFGetGpsFields());
5509
0
}
5510
5511
static int EstimateStripByteCounts(TIFF *tif, TIFFDirEntry *dir,
5512
                                   uint16_t dircount)
5513
0
{
5514
0
    static const char module[] = "EstimateStripByteCounts";
5515
5516
0
    TIFFDirEntry *dp;
5517
0
    TIFFDirectory *td = &tif->tif_dir;
5518
0
    uint32_t strip;
5519
5520
    /* Do not try to load stripbytecount as we will compute it */
5521
0
    if (!_TIFFFillStrilesInternal(tif, 0))
5522
0
        return -1;
5523
5524
0
    const uint64_t allocsize = (uint64_t)td->td_nstrips * sizeof(uint64_t);
5525
0
    uint64_t filesize = 0;
5526
0
    if (allocsize > 100 * 1024 * 1024)
5527
0
    {
5528
        /* Before allocating a huge amount of memory for corrupted files, check
5529
         * if size of requested memory is not greater than file size. */
5530
0
        filesize = TIFFGetFileSize(tif);
5531
0
        if (allocsize > filesize)
5532
0
        {
5533
0
            TIFFWarningExtR(
5534
0
                tif, module,
5535
0
                "Requested memory size for StripByteCounts of %" PRIu64
5536
0
                " is greater than filesize %" PRIu64 ". Memory not allocated",
5537
0
                allocsize, filesize);
5538
0
            return -1;
5539
0
        }
5540
0
    }
5541
5542
0
    if (td->td_stripbytecount_p)
5543
0
        _TIFFfreeExt(tif, td->td_stripbytecount_p);
5544
0
    td->td_stripbytecount_p = (uint64_t *)_TIFFCheckMalloc(
5545
0
        tif, td->td_nstrips, sizeof(uint64_t), "for \"StripByteCounts\" array");
5546
0
    if (td->td_stripbytecount_p == NULL)
5547
0
        return -1;
5548
5549
0
    if (td->td_compression != COMPRESSION_NONE)
5550
0
    {
5551
0
        uint64_t space;
5552
0
        uint16_t n;
5553
0
        if (!(tif->tif_flags & TIFF_BIGTIFF))
5554
0
            space = sizeof(TIFFHeaderClassic) + 2 + dircount * 12 + 4;
5555
0
        else
5556
0
            space = sizeof(TIFFHeaderBig) + 8 + dircount * 20 + 8;
5557
        /* calculate amount of space used by indirect values */
5558
0
        for (dp = dir, n = dircount; n > 0; n--, dp++)
5559
0
        {
5560
0
            uint32_t typewidth;
5561
0
            uint64_t datasize;
5562
0
            typewidth = TIFFDataWidth((TIFFDataType)dp->tdir_type);
5563
0
            if (typewidth == 0)
5564
0
            {
5565
0
                TIFFErrorExtR(
5566
0
                    tif, module,
5567
0
                    "Cannot determine size of unknown tag type %" PRIu16,
5568
0
                    dp->tdir_type);
5569
0
                return -1;
5570
0
            }
5571
0
            if (dp->tdir_count > UINT64_MAX / typewidth)
5572
0
                return -1;
5573
0
            datasize = (uint64_t)typewidth * dp->tdir_count;
5574
0
            if (!(tif->tif_flags & TIFF_BIGTIFF))
5575
0
            {
5576
0
                if (datasize <= 4)
5577
0
                    datasize = 0;
5578
0
            }
5579
0
            else
5580
0
            {
5581
0
                if (datasize <= 8)
5582
0
                    datasize = 0;
5583
0
            }
5584
0
            if (space > UINT64_MAX - datasize)
5585
0
                return -1;
5586
0
            space += datasize;
5587
0
        }
5588
0
        if (filesize == 0)
5589
0
            filesize = TIFFGetFileSize(tif);
5590
0
        if (filesize < space)
5591
            /* we should perhaps return in error ? */
5592
0
            space = filesize;
5593
0
        else
5594
0
            space = filesize - space;
5595
0
        if (td->td_planarconfig == PLANARCONFIG_SEPARATE)
5596
0
            space /= td->td_samplesperpixel;
5597
0
        for (strip = 0; strip < td->td_nstrips; strip++)
5598
0
            td->td_stripbytecount_p[strip] = space;
5599
        /*
5600
         * This gross hack handles the case were the offset to
5601
         * the last strip is past the place where we think the strip
5602
         * should begin.  Since a strip of data must be contiguous,
5603
         * it's safe to assume that we've overestimated the amount
5604
         * of data in the strip and trim this number back accordingly.
5605
         */
5606
0
        strip--;
5607
0
        if (td->td_stripoffset_p[strip] >
5608
0
            UINT64_MAX - td->td_stripbytecount_p[strip])
5609
0
            return -1;
5610
0
        if (td->td_stripoffset_p[strip] + td->td_stripbytecount_p[strip] >
5611
0
            filesize)
5612
0
        {
5613
0
            if (td->td_stripoffset_p[strip] >= filesize)
5614
0
            {
5615
                /* Not sure what we should in that case... */
5616
0
                td->td_stripbytecount_p[strip] = 0;
5617
0
            }
5618
0
            else
5619
0
            {
5620
0
                td->td_stripbytecount_p[strip] =
5621
0
                    filesize - td->td_stripoffset_p[strip];
5622
0
            }
5623
0
        }
5624
0
    }
5625
0
    else if (isTiled(tif))
5626
0
    {
5627
0
        uint64_t bytespertile = TIFFTileSize64(tif);
5628
5629
0
        for (strip = 0; strip < td->td_nstrips; strip++)
5630
0
            td->td_stripbytecount_p[strip] = bytespertile;
5631
0
    }
5632
0
    else
5633
0
    {
5634
0
        uint64_t rowbytes = TIFFScanlineSize64(tif);
5635
0
        uint32_t rowsperstrip = td->td_imagelength / td->td_stripsperimage;
5636
0
        for (strip = 0; strip < td->td_nstrips; strip++)
5637
0
        {
5638
0
            if (rowbytes > 0 && rowsperstrip > UINT64_MAX / rowbytes)
5639
0
                return -1;
5640
0
            td->td_stripbytecount_p[strip] = rowbytes * rowsperstrip;
5641
0
        }
5642
0
    }
5643
0
    TIFFSetFieldBit(tif, FIELD_STRIPBYTECOUNTS);
5644
0
    if (!TIFFFieldSet(tif, FIELD_ROWSPERSTRIP))
5645
0
        td->td_rowsperstrip = td->td_imagelength;
5646
0
    return 1;
5647
0
}
5648
5649
static void MissingRequired(TIFF *tif, const char *tagname)
5650
0
{
5651
0
    static const char module[] = "MissingRequired";
5652
5653
0
    TIFFErrorExtR(tif, module,
5654
0
                  "TIFF directory is missing required \"%s\" field", tagname);
5655
0
}
5656
5657
static unsigned long hashFuncOffsetToNumber(const void *elt)
5658
0
{
5659
0
    const TIFFOffsetAndDirNumber *offsetAndDirNumber =
5660
0
        (const TIFFOffsetAndDirNumber *)elt;
5661
0
    const uint32_t hash = (uint32_t)(offsetAndDirNumber->offset >> 32) ^
5662
0
                          ((uint32_t)offsetAndDirNumber->offset & 0xFFFFFFFFU);
5663
0
    return hash;
5664
0
}
5665
5666
static bool equalFuncOffsetToNumber(const void *elt1, const void *elt2)
5667
0
{
5668
0
    const TIFFOffsetAndDirNumber *offsetAndDirNumber1 =
5669
0
        (const TIFFOffsetAndDirNumber *)elt1;
5670
0
    const TIFFOffsetAndDirNumber *offsetAndDirNumber2 =
5671
0
        (const TIFFOffsetAndDirNumber *)elt2;
5672
0
    return offsetAndDirNumber1->offset == offsetAndDirNumber2->offset;
5673
0
}
5674
5675
static unsigned long hashFuncNumberToOffset(const void *elt)
5676
0
{
5677
0
    const TIFFOffsetAndDirNumber *offsetAndDirNumber =
5678
0
        (const TIFFOffsetAndDirNumber *)elt;
5679
0
    return offsetAndDirNumber->dirNumber;
5680
0
}
5681
5682
static bool equalFuncNumberToOffset(const void *elt1, const void *elt2)
5683
0
{
5684
0
    const TIFFOffsetAndDirNumber *offsetAndDirNumber1 =
5685
0
        (const TIFFOffsetAndDirNumber *)elt1;
5686
0
    const TIFFOffsetAndDirNumber *offsetAndDirNumber2 =
5687
0
        (const TIFFOffsetAndDirNumber *)elt2;
5688
0
    return offsetAndDirNumber1->dirNumber == offsetAndDirNumber2->dirNumber;
5689
0
}
5690
5691
/*
5692
 * Check the directory number and offset against the list of already seen
5693
 * directory numbers and offsets. This is a trick to prevent IFD looping.
5694
 * The one can create TIFF file with looped directory pointers. We will
5695
 * maintain a list of already seen directories and check every IFD offset
5696
 * and its IFD number against that list. However, the offset of an IFD number
5697
 * can change - e.g. when writing updates to file.
5698
 * Returns 1 if all is ok; 0 if last directory or IFD loop is encountered,
5699
 * or an error has occurred.
5700
 */
5701
int _TIFFCheckDirNumberAndOffset(TIFF *tif, tdir_t dirn, uint64_t diroff)
5702
0
{
5703
0
    if (diroff == 0) /* no more directories */
5704
0
        return 0;
5705
5706
0
    if (tif->tif_map_dir_offset_to_number == NULL)
5707
0
    {
5708
0
        tif->tif_map_dir_offset_to_number = TIFFHashSetNew(
5709
0
            hashFuncOffsetToNumber, equalFuncOffsetToNumber, free);
5710
0
        if (tif->tif_map_dir_offset_to_number == NULL)
5711
0
        {
5712
0
            TIFFErrorExtR(tif, "_TIFFCheckDirNumberAndOffset",
5713
0
                          "Not enough memory");
5714
0
            return 1;
5715
0
        }
5716
0
    }
5717
5718
0
    if (tif->tif_map_dir_number_to_offset == NULL)
5719
0
    {
5720
        /* No free callback for this map, as it shares the same items as
5721
         * tif->tif_map_dir_offset_to_number. */
5722
0
        tif->tif_map_dir_number_to_offset = TIFFHashSetNew(
5723
0
            hashFuncNumberToOffset, equalFuncNumberToOffset, NULL);
5724
0
        if (tif->tif_map_dir_number_to_offset == NULL)
5725
0
        {
5726
0
            TIFFErrorExtR(tif, "_TIFFCheckDirNumberAndOffset",
5727
0
                          "Not enough memory");
5728
0
            return 1;
5729
0
        }
5730
0
    }
5731
5732
    /* Check if offset is already in the list:
5733
     * - yes: check, if offset is at the same IFD number - if not, it is an IFD
5734
     * loop
5735
     * -  no: add to list or update offset at that IFD number
5736
     */
5737
0
    TIFFOffsetAndDirNumber entry;
5738
0
    entry.offset = diroff;
5739
0
    entry.dirNumber = dirn;
5740
5741
0
    TIFFOffsetAndDirNumber *foundEntry =
5742
0
        (TIFFOffsetAndDirNumber *)TIFFHashSetLookup(
5743
0
            tif->tif_map_dir_offset_to_number, &entry);
5744
0
    if (foundEntry)
5745
0
    {
5746
0
        if (foundEntry->dirNumber == dirn)
5747
0
        {
5748
0
            return 1;
5749
0
        }
5750
0
        else
5751
0
        {
5752
0
            TIFFWarningExtR(tif, "_TIFFCheckDirNumberAndOffset",
5753
0
                            "TIFF directory %d has IFD looping to directory %u "
5754
0
                            "at offset 0x%" PRIx64 " (%" PRIu64 ")",
5755
0
                            (int)dirn - 1, foundEntry->dirNumber, diroff,
5756
0
                            diroff);
5757
0
            return 0;
5758
0
        }
5759
0
    }
5760
5761
    /* Check if offset of an IFD has been changed and update offset of that IFD
5762
     * number. */
5763
0
    foundEntry = (TIFFOffsetAndDirNumber *)TIFFHashSetLookup(
5764
0
        tif->tif_map_dir_number_to_offset, &entry);
5765
0
    if (foundEntry)
5766
0
    {
5767
0
        if (foundEntry->offset != diroff)
5768
0
        {
5769
0
            TIFFOffsetAndDirNumber entryOld;
5770
0
            entryOld.offset = foundEntry->offset;
5771
0
            entryOld.dirNumber = dirn;
5772
            /* We must remove first from tif_map_dir_number_to_offset as the */
5773
            /* entry is owned (and thus freed) by */
5774
            /* tif_map_dir_offset_to_number */
5775
0
            TIFFOffsetAndDirNumber *foundEntryOld =
5776
0
                (TIFFOffsetAndDirNumber *)TIFFHashSetLookup(
5777
0
                    tif->tif_map_dir_number_to_offset, &entryOld);
5778
0
            if (foundEntryOld)
5779
0
            {
5780
0
                TIFFHashSetRemove(tif->tif_map_dir_number_to_offset,
5781
0
                                  foundEntryOld);
5782
0
            }
5783
0
            foundEntryOld = (TIFFOffsetAndDirNumber *)TIFFHashSetLookup(
5784
0
                tif->tif_map_dir_offset_to_number, &entryOld);
5785
0
            if (foundEntryOld)
5786
0
            {
5787
0
                TIFFHashSetRemove(tif->tif_map_dir_offset_to_number,
5788
0
                                  foundEntryOld);
5789
0
            }
5790
5791
0
            TIFFOffsetAndDirNumber *entryPtr = (TIFFOffsetAndDirNumber *)malloc(
5792
0
                sizeof(TIFFOffsetAndDirNumber));
5793
0
            if (entryPtr == NULL)
5794
0
            {
5795
0
                return 0;
5796
0
            }
5797
5798
            /* Add IFD offset and dirn to IFD directory list */
5799
0
            *entryPtr = entry;
5800
5801
0
            if (!TIFFHashSetInsert(tif->tif_map_dir_offset_to_number, entryPtr))
5802
0
            {
5803
0
                TIFFErrorExtR(
5804
0
                    tif, "_TIFFCheckDirNumberAndOffset",
5805
0
                    "Insertion in tif_map_dir_offset_to_number failed");
5806
0
                return 0;
5807
0
            }
5808
0
            if (!TIFFHashSetInsert(tif->tif_map_dir_number_to_offset, entryPtr))
5809
0
            {
5810
0
                TIFFErrorExtR(
5811
0
                    tif, "_TIFFCheckDirNumberAndOffset",
5812
0
                    "Insertion in tif_map_dir_number_to_offset failed");
5813
0
                return 0;
5814
0
            }
5815
0
        }
5816
0
        return 1;
5817
0
    }
5818
5819
    /* Arbitrary (hopefully big enough) limit */
5820
0
    if (TIFFHashSetSize(tif->tif_map_dir_offset_to_number) >=
5821
0
        TIFF_MAX_DIR_COUNT)
5822
0
    {
5823
0
        TIFFErrorExtR(tif, "_TIFFCheckDirNumberAndOffset",
5824
0
                      "Cannot handle more than %u TIFF directories",
5825
0
                      (unsigned)TIFF_MAX_DIR_COUNT);
5826
0
        return 0;
5827
0
    }
5828
5829
0
    TIFFOffsetAndDirNumber *entryPtr =
5830
0
        (TIFFOffsetAndDirNumber *)malloc(sizeof(TIFFOffsetAndDirNumber));
5831
0
    if (entryPtr == NULL)
5832
0
    {
5833
0
        TIFFErrorExtR(tif, "_TIFFCheckDirNumberAndOffset",
5834
0
                      "malloc(sizeof(TIFFOffsetAndDirNumber)) failed");
5835
0
        return 0;
5836
0
    }
5837
5838
    /* Add IFD offset and dirn to IFD directory list */
5839
0
    *entryPtr = entry;
5840
5841
0
    if (!TIFFHashSetInsert(tif->tif_map_dir_offset_to_number, entryPtr))
5842
0
    {
5843
0
        TIFFErrorExtR(tif, "_TIFFCheckDirNumberAndOffset",
5844
0
                      "Insertion in tif_map_dir_offset_to_number failed");
5845
0
        return 0;
5846
0
    }
5847
0
    if (!TIFFHashSetInsert(tif->tif_map_dir_number_to_offset, entryPtr))
5848
0
    {
5849
0
        TIFFErrorExtR(tif, "_TIFFCheckDirNumberAndOffset",
5850
0
                      "Insertion in tif_map_dir_number_to_offset failed");
5851
0
        return 0;
5852
0
    }
5853
5854
0
    return 1;
5855
0
} /* --- _TIFFCheckDirNumberAndOffset() ---*/
5856
5857
/*
5858
 * Retrieve the matching IFD directory number of a given IFD offset
5859
 * from the list of directories already seen.
5860
 * Returns 1 if the offset was in the list and the directory number
5861
 * can be returned.
5862
 * Otherwise returns 0 or if an error occurred.
5863
 */
5864
int _TIFFGetDirNumberFromOffset(TIFF *tif, uint64_t diroff, tdir_t *dirn)
5865
0
{
5866
0
    if (diroff == 0) /* no more directories */
5867
0
        return 0;
5868
5869
    /* Check if offset is already in the list and return matching directory
5870
     * number. Otherwise update IFD list using TIFFNumberOfDirectories() and
5871
     * search again in IFD list.
5872
     */
5873
0
    if (tif->tif_map_dir_offset_to_number == NULL)
5874
0
        return 0;
5875
0
    TIFFOffsetAndDirNumber entry;
5876
0
    entry.offset = diroff;
5877
0
    entry.dirNumber = 0; /* not used */
5878
5879
0
    TIFFOffsetAndDirNumber *foundEntry =
5880
0
        (TIFFOffsetAndDirNumber *)TIFFHashSetLookup(
5881
0
            tif->tif_map_dir_offset_to_number, &entry);
5882
0
    if (foundEntry)
5883
0
    {
5884
0
        *dirn = foundEntry->dirNumber;
5885
0
        return 1;
5886
0
    }
5887
5888
    /* This updates the directory list for all main-IFDs in the file. */
5889
0
    TIFFNumberOfDirectories(tif);
5890
5891
0
    foundEntry = (TIFFOffsetAndDirNumber *)TIFFHashSetLookup(
5892
0
        tif->tif_map_dir_offset_to_number, &entry);
5893
0
    if (foundEntry)
5894
0
    {
5895
0
        *dirn = foundEntry->dirNumber;
5896
0
        return 1;
5897
0
    }
5898
5899
0
    return 0;
5900
0
} /*--- _TIFFGetDirNumberFromOffset() ---*/
5901
5902
/*
5903
 * Retrieve the matching IFD directory offset of a given IFD number
5904
 * from the list of directories already seen.
5905
 * Returns 1 if the offset was in the list of already seen IFDs and the
5906
 * directory offset can be returned. The directory list is not updated.
5907
 * Otherwise returns 0 or if an error occurred.
5908
 */
5909
int _TIFFGetOffsetFromDirNumber(TIFF *tif, tdir_t dirn, uint64_t *diroff)
5910
0
{
5911
5912
0
    if (tif->tif_map_dir_number_to_offset == NULL)
5913
0
        return 0;
5914
0
    TIFFOffsetAndDirNumber entry;
5915
0
    entry.offset = 0; /* not used */
5916
0
    entry.dirNumber = dirn;
5917
5918
0
    TIFFOffsetAndDirNumber *foundEntry =
5919
0
        (TIFFOffsetAndDirNumber *)TIFFHashSetLookup(
5920
0
            tif->tif_map_dir_number_to_offset, &entry);
5921
0
    if (foundEntry)
5922
0
    {
5923
0
        *diroff = foundEntry->offset;
5924
0
        return 1;
5925
0
    }
5926
5927
0
    return 0;
5928
0
} /*--- _TIFFGetOffsetFromDirNumber() ---*/
5929
5930
/*
5931
 * Remove an entry from the directory list of already seen directories
5932
 * by directory offset.
5933
 * If an entry is to be removed from the list, it is also okay if the entry
5934
 * is not in the list or the list does not exist.
5935
 */
5936
int _TIFFRemoveEntryFromDirectoryListByOffset(TIFF *tif, uint64_t diroff)
5937
0
{
5938
0
    if (tif->tif_map_dir_offset_to_number == NULL)
5939
0
        return 1;
5940
5941
0
    TIFFOffsetAndDirNumber entryOld;
5942
0
    entryOld.offset = diroff;
5943
0
    entryOld.dirNumber = 0;
5944
    /* We must remove first from tif_map_dir_number_to_offset as the
5945
     * entry is owned (and thus freed) by tif_map_dir_offset_to_number.
5946
     * However, we need firstly to find the directory number from offset. */
5947
5948
0
    TIFFOffsetAndDirNumber *foundEntryOldOff =
5949
0
        (TIFFOffsetAndDirNumber *)TIFFHashSetLookup(
5950
0
            tif->tif_map_dir_offset_to_number, &entryOld);
5951
0
    if (foundEntryOldOff)
5952
0
    {
5953
0
        entryOld.dirNumber = foundEntryOldOff->dirNumber;
5954
0
        if (tif->tif_map_dir_number_to_offset != NULL)
5955
0
        {
5956
0
            TIFFOffsetAndDirNumber *foundEntryOldDir =
5957
0
                (TIFFOffsetAndDirNumber *)TIFFHashSetLookup(
5958
0
                    tif->tif_map_dir_number_to_offset, &entryOld);
5959
0
            if (foundEntryOldDir)
5960
0
            {
5961
0
                TIFFHashSetRemove(tif->tif_map_dir_number_to_offset,
5962
0
                                  foundEntryOldDir);
5963
0
                TIFFHashSetRemove(tif->tif_map_dir_offset_to_number,
5964
0
                                  foundEntryOldOff);
5965
0
                return 1;
5966
0
            }
5967
0
        }
5968
0
        else
5969
0
        {
5970
0
            TIFFErrorExtR(tif, "_TIFFRemoveEntryFromDirectoryListByOffset",
5971
0
                          "Unexpectedly tif_map_dir_number_to_offset is "
5972
0
                          "missing but tif_map_dir_offset_to_number exists.");
5973
0
            return 0;
5974
0
        }
5975
0
    }
5976
0
    return 1;
5977
0
} /*--- _TIFFRemoveEntryFromDirectoryListByOffset() ---*/
5978
5979
/*
5980
 * Check the count field of a directory entry against a known value.  The
5981
 * caller is expected to skip/ignore the tag if there is a mismatch.
5982
 */
5983
static int CheckDirCount(TIFF *tif, TIFFDirEntry *dir, uint32_t count)
5984
0
{
5985
0
    if ((uint64_t)count > dir->tdir_count)
5986
0
    {
5987
0
        const TIFFField *fip = TIFFFieldWithTag(tif, dir->tdir_tag);
5988
0
        TIFFWarningExtR(tif, tif->tif_name,
5989
0
                        "incorrect count for field \"%s\" (%" PRIu64
5990
0
                        ", expecting %" PRIu32 "); tag ignored",
5991
0
                        fip ? fip->field_name : "unknown tagname",
5992
0
                        dir->tdir_count, count);
5993
0
        return (0);
5994
0
    }
5995
0
    else if ((uint64_t)count < dir->tdir_count)
5996
0
    {
5997
0
        const TIFFField *fip = TIFFFieldWithTag(tif, dir->tdir_tag);
5998
0
        TIFFWarningExtR(tif, tif->tif_name,
5999
0
                        "incorrect count for field \"%s\" (%" PRIu64
6000
0
                        ", expecting %" PRIu32 "); tag trimmed",
6001
0
                        fip ? fip->field_name : "unknown tagname",
6002
0
                        dir->tdir_count, count);
6003
0
        dir->tdir_count = count;
6004
0
        return (1);
6005
0
    }
6006
0
    return (1);
6007
0
}
6008
6009
/*
6010
 * Read IFD structure from the specified offset. If the pointer to
6011
 * nextdiroff variable has been specified, read it too. Function returns a
6012
 * number of fields in the directory or 0 if failed.
6013
 */
6014
static uint16_t TIFFFetchDirectory(TIFF *tif, uint64_t diroff,
6015
                                   TIFFDirEntry **pdir, uint64_t *nextdiroff)
6016
0
{
6017
0
    static const char module[] = "TIFFFetchDirectory";
6018
6019
0
    void *origdir;
6020
0
    uint16_t dircount16;
6021
0
    uint32_t dirsize;
6022
0
    TIFFDirEntry *dir;
6023
0
    uint8_t *ma;
6024
0
    TIFFDirEntry *mb;
6025
0
    uint16_t n;
6026
6027
0
    assert(pdir);
6028
6029
0
    tif->tif_diroff = diroff;
6030
0
    if (nextdiroff)
6031
0
        *nextdiroff = 0;
6032
0
    if (!isMapped(tif))
6033
0
    {
6034
0
        if (!SeekOK(tif, tif->tif_diroff))
6035
0
        {
6036
0
            TIFFErrorExtR(tif, module,
6037
0
                          "%s: Seek error accessing TIFF directory",
6038
0
                          tif->tif_name);
6039
0
            return 0;
6040
0
        }
6041
0
        if (!(tif->tif_flags & TIFF_BIGTIFF))
6042
0
        {
6043
0
            if (!ReadOK(tif, &dircount16, sizeof(uint16_t)))
6044
0
            {
6045
0
                TIFFErrorExtR(tif, module,
6046
0
                              "%s: Can not read TIFF directory count",
6047
0
                              tif->tif_name);
6048
0
                return 0;
6049
0
            }
6050
0
            if (tif->tif_flags & TIFF_SWAB)
6051
0
                TIFFSwabShort(&dircount16);
6052
0
            if (dircount16 > 4096)
6053
0
            {
6054
0
                TIFFErrorExtR(tif, module,
6055
0
                              "Sanity check on directory count failed, this is "
6056
0
                              "probably not a valid IFD offset");
6057
0
                return 0;
6058
0
            }
6059
0
            dirsize = 12;
6060
0
        }
6061
0
        else
6062
0
        {
6063
0
            uint64_t dircount64;
6064
0
            if (!ReadOK(tif, &dircount64, sizeof(uint64_t)))
6065
0
            {
6066
0
                TIFFErrorExtR(tif, module,
6067
0
                              "%s: Can not read TIFF directory count",
6068
0
                              tif->tif_name);
6069
0
                return 0;
6070
0
            }
6071
0
            if (tif->tif_flags & TIFF_SWAB)
6072
0
                TIFFSwabLong8(&dircount64);
6073
0
            if (dircount64 > 4096)
6074
0
            {
6075
0
                TIFFErrorExtR(tif, module,
6076
0
                              "Sanity check on directory count failed, this is "
6077
0
                              "probably not a valid IFD offset");
6078
0
                return 0;
6079
0
            }
6080
0
            dircount16 = (uint16_t)dircount64;
6081
0
            dirsize = 20;
6082
0
        }
6083
0
        origdir = _TIFFCheckMalloc(tif, dircount16, dirsize,
6084
0
                                   "to read TIFF directory");
6085
0
        if (origdir == NULL)
6086
0
            return 0;
6087
0
        if (!ReadOK(tif, origdir, (tmsize_t)(dircount16 * dirsize)))
6088
0
        {
6089
0
            TIFFErrorExtR(tif, module, "%.100s: Can not read TIFF directory",
6090
0
                          tif->tif_name);
6091
0
            _TIFFfreeExt(tif, origdir);
6092
0
            return 0;
6093
0
        }
6094
        /*
6095
         * Read offset to next directory for sequential scans if
6096
         * needed.
6097
         */
6098
0
        if (nextdiroff)
6099
0
        {
6100
0
            if (!(tif->tif_flags & TIFF_BIGTIFF))
6101
0
            {
6102
0
                uint32_t nextdiroff32;
6103
0
                if (!ReadOK(tif, &nextdiroff32, sizeof(uint32_t)))
6104
0
                    nextdiroff32 = 0;
6105
0
                if (tif->tif_flags & TIFF_SWAB)
6106
0
                    TIFFSwabLong(&nextdiroff32);
6107
0
                *nextdiroff = nextdiroff32;
6108
0
            }
6109
0
            else
6110
0
            {
6111
0
                if (!ReadOK(tif, nextdiroff, sizeof(uint64_t)))
6112
0
                    *nextdiroff = 0;
6113
0
                if (tif->tif_flags & TIFF_SWAB)
6114
0
                    TIFFSwabLong8(nextdiroff);
6115
0
            }
6116
0
        }
6117
0
    }
6118
0
    else
6119
0
    {
6120
0
        tmsize_t m;
6121
0
        tmsize_t off;
6122
0
        if (tif->tif_diroff > (uint64_t)INT64_MAX)
6123
0
        {
6124
0
            TIFFErrorExtR(tif, module, "Can not read TIFF directory count");
6125
0
            return (0);
6126
0
        }
6127
0
        off = (tmsize_t)tif->tif_diroff;
6128
6129
        /*
6130
         * Check for integer overflow when validating the dir_off,
6131
         * otherwise a very high offset may cause an OOB read and
6132
         * crash the client. Make two comparisons instead of
6133
         *
6134
         *  off + sizeof(uint16_t) > tif->tif_size
6135
         *
6136
         * to avoid overflow.
6137
         */
6138
0
        if (!(tif->tif_flags & TIFF_BIGTIFF))
6139
0
        {
6140
0
            m = off + sizeof(uint16_t);
6141
0
            if ((m < off) || (m < (tmsize_t)sizeof(uint16_t)) ||
6142
0
                (m > tif->tif_size))
6143
0
            {
6144
0
                TIFFErrorExtR(tif, module, "Can not read TIFF directory count");
6145
0
                return 0;
6146
0
            }
6147
0
            else
6148
0
            {
6149
0
                _TIFFmemcpy(&dircount16, tif->tif_base + off, sizeof(uint16_t));
6150
0
            }
6151
0
            off += sizeof(uint16_t);
6152
0
            if (tif->tif_flags & TIFF_SWAB)
6153
0
                TIFFSwabShort(&dircount16);
6154
0
            if (dircount16 > 4096)
6155
0
            {
6156
0
                TIFFErrorExtR(tif, module,
6157
0
                              "Sanity check on directory count failed, this is "
6158
0
                              "probably not a valid IFD offset");
6159
0
                return 0;
6160
0
            }
6161
0
            dirsize = 12;
6162
0
        }
6163
0
        else
6164
0
        {
6165
0
            uint64_t dircount64;
6166
0
            m = off + sizeof(uint64_t);
6167
0
            if ((m < off) || (m < (tmsize_t)sizeof(uint64_t)) ||
6168
0
                (m > tif->tif_size))
6169
0
            {
6170
0
                TIFFErrorExtR(tif, module, "Can not read TIFF directory count");
6171
0
                return 0;
6172
0
            }
6173
0
            else
6174
0
            {
6175
0
                _TIFFmemcpy(&dircount64, tif->tif_base + off, sizeof(uint64_t));
6176
0
            }
6177
0
            off += sizeof(uint64_t);
6178
0
            if (tif->tif_flags & TIFF_SWAB)
6179
0
                TIFFSwabLong8(&dircount64);
6180
0
            if (dircount64 > 4096)
6181
0
            {
6182
0
                TIFFErrorExtR(tif, module,
6183
0
                              "Sanity check on directory count failed, this is "
6184
0
                              "probably not a valid IFD offset");
6185
0
                return 0;
6186
0
            }
6187
0
            dircount16 = (uint16_t)dircount64;
6188
0
            dirsize = 20;
6189
0
        }
6190
0
        if (dircount16 == 0)
6191
0
        {
6192
0
            TIFFErrorExtR(tif, module,
6193
0
                          "Sanity check on directory count failed, zero tag "
6194
0
                          "directories not supported");
6195
0
            return 0;
6196
0
        }
6197
        /* Before allocating a huge amount of memory for corrupted files, check
6198
         * if size of requested memory is not greater than file size. */
6199
0
        uint64_t filesize = TIFFGetFileSize(tif);
6200
0
        uint64_t allocsize = (uint64_t)dircount16 * dirsize;
6201
0
        if (allocsize > filesize)
6202
0
        {
6203
0
            TIFFWarningExtR(
6204
0
                tif, module,
6205
0
                "Requested memory size for TIFF directory of %" PRIu64
6206
0
                " is greater than filesize %" PRIu64
6207
0
                ". Memory not allocated, TIFF directory not read",
6208
0
                allocsize, filesize);
6209
0
            return 0;
6210
0
        }
6211
0
        origdir = _TIFFCheckMalloc(tif, dircount16, dirsize,
6212
0
                                   "to read TIFF directory");
6213
0
        if (origdir == NULL)
6214
0
            return 0;
6215
0
        m = off + dircount16 * dirsize;
6216
0
        if ((m < off) || (m < (tmsize_t)(dircount16 * dirsize)) ||
6217
0
            (m > tif->tif_size))
6218
0
        {
6219
0
            TIFFErrorExtR(tif, module, "Can not read TIFF directory");
6220
0
            _TIFFfreeExt(tif, origdir);
6221
0
            return 0;
6222
0
        }
6223
0
        else
6224
0
        {
6225
0
            _TIFFmemcpy(origdir, tif->tif_base + off, dircount16 * dirsize);
6226
0
        }
6227
0
        if (nextdiroff)
6228
0
        {
6229
0
            off += dircount16 * dirsize;
6230
0
            if (!(tif->tif_flags & TIFF_BIGTIFF))
6231
0
            {
6232
0
                uint32_t nextdiroff32;
6233
0
                m = off + sizeof(uint32_t);
6234
0
                if ((m < off) || (m < (tmsize_t)sizeof(uint32_t)) ||
6235
0
                    (m > tif->tif_size))
6236
0
                    nextdiroff32 = 0;
6237
0
                else
6238
0
                    _TIFFmemcpy(&nextdiroff32, tif->tif_base + off,
6239
0
                                sizeof(uint32_t));
6240
0
                if (tif->tif_flags & TIFF_SWAB)
6241
0
                    TIFFSwabLong(&nextdiroff32);
6242
0
                *nextdiroff = nextdiroff32;
6243
0
            }
6244
0
            else
6245
0
            {
6246
0
                m = off + sizeof(uint64_t);
6247
0
                if ((m < off) || (m < (tmsize_t)sizeof(uint64_t)) ||
6248
0
                    (m > tif->tif_size))
6249
0
                    *nextdiroff = 0;
6250
0
                else
6251
0
                    _TIFFmemcpy(nextdiroff, tif->tif_base + off,
6252
0
                                sizeof(uint64_t));
6253
0
                if (tif->tif_flags & TIFF_SWAB)
6254
0
                    TIFFSwabLong8(nextdiroff);
6255
0
            }
6256
0
        }
6257
0
    }
6258
    /* No check against filesize needed here because "dir" should have same size
6259
     * than "origdir" checked above. */
6260
0
    dir = (TIFFDirEntry *)_TIFFCheckMalloc(
6261
0
        tif, dircount16, sizeof(TIFFDirEntry), "to read TIFF directory");
6262
0
    if (dir == 0)
6263
0
    {
6264
0
        _TIFFfreeExt(tif, origdir);
6265
0
        return 0;
6266
0
    }
6267
0
    ma = (uint8_t *)origdir;
6268
0
    mb = dir;
6269
0
    for (n = 0; n < dircount16; n++)
6270
0
    {
6271
0
        mb->tdir_ignore = FALSE;
6272
0
        if (tif->tif_flags & TIFF_SWAB)
6273
0
            TIFFSwabShort((uint16_t *)ma);
6274
0
        mb->tdir_tag = *(uint16_t *)ma;
6275
0
        ma += sizeof(uint16_t);
6276
0
        if (tif->tif_flags & TIFF_SWAB)
6277
0
            TIFFSwabShort((uint16_t *)ma);
6278
0
        mb->tdir_type = *(uint16_t *)ma;
6279
0
        ma += sizeof(uint16_t);
6280
0
        if (!(tif->tif_flags & TIFF_BIGTIFF))
6281
0
        {
6282
0
            if (tif->tif_flags & TIFF_SWAB)
6283
0
                TIFFSwabLong((uint32_t *)ma);
6284
0
            mb->tdir_count = (uint64_t)(*(uint32_t *)ma);
6285
0
            ma += sizeof(uint32_t);
6286
0
            mb->tdir_offset.toff_long8 = 0;
6287
0
            *(uint32_t *)(&mb->tdir_offset) = *(uint32_t *)ma;
6288
0
            ma += sizeof(uint32_t);
6289
0
        }
6290
0
        else
6291
0
        {
6292
0
            if (tif->tif_flags & TIFF_SWAB)
6293
0
                TIFFSwabLong8((uint64_t *)ma);
6294
0
            mb->tdir_count = TIFFReadUInt64(ma);
6295
0
            ma += sizeof(uint64_t);
6296
0
            mb->tdir_offset.toff_long8 = TIFFReadUInt64(ma);
6297
0
            ma += sizeof(uint64_t);
6298
0
        }
6299
0
        mb++;
6300
0
    }
6301
0
    _TIFFfreeExt(tif, origdir);
6302
0
    *pdir = dir;
6303
0
    return dircount16;
6304
0
}
6305
6306
/*
6307
 * Fetch a tag that is not handled by special case code.
6308
 */
6309
static int TIFFFetchNormalTag(TIFF *tif, TIFFDirEntry *dp, int recover)
6310
0
{
6311
0
    static const char module[] = "TIFFFetchNormalTag";
6312
0
    enum TIFFReadDirEntryErr err;
6313
0
    uint32_t fii;
6314
0
    const TIFFField *fip = NULL;
6315
0
    TIFFReadDirectoryFindFieldInfo(tif, dp->tdir_tag, &fii);
6316
0
    if (fii == FAILED_FII)
6317
0
    {
6318
0
        TIFFErrorExtR(tif, "TIFFFetchNormalTag",
6319
0
                      "No definition found for tag %" PRIu16, dp->tdir_tag);
6320
0
        return 0;
6321
0
    }
6322
0
    fip = tif->tif_fields[fii];
6323
0
    assert(fip != NULL); /* should not happen */
6324
0
    assert(fip->set_get_field_type !=
6325
0
           TIFF_SETGET_OTHER); /* if so, we shouldn't arrive here but deal with
6326
                                  this in specialized code */
6327
0
    assert(fip->set_get_field_type !=
6328
0
           TIFF_SETGET_INT); /* if so, we shouldn't arrive here as this is only
6329
                                the case for pseudo-tags */
6330
0
    err = TIFFReadDirEntryErrOk;
6331
0
    switch (fip->set_get_field_type)
6332
0
    {
6333
0
        case TIFF_SETGET_UNDEFINED:
6334
0
            TIFFErrorExtR(
6335
0
                tif, "TIFFFetchNormalTag",
6336
0
                "Defined set_get_field_type of custom tag %u (%s) is "
6337
0
                "TIFF_SETGET_UNDEFINED and thus tag is not read from file",
6338
0
                fip->field_tag, fip->field_name);
6339
0
            break;
6340
0
        case TIFF_SETGET_ASCII:
6341
0
        {
6342
0
            uint8_t *data;
6343
0
            assert(fip->field_passcount == 0);
6344
0
            err = TIFFReadDirEntryByteArray(tif, dp, &data);
6345
0
            if (err == TIFFReadDirEntryErrOk)
6346
0
            {
6347
0
                size_t mb = 0;
6348
0
                int n;
6349
0
                if (data != NULL)
6350
0
                {
6351
0
                    if (dp->tdir_count > 0 && data[dp->tdir_count - 1] == 0)
6352
0
                    {
6353
                        /* optimization: if data is known to be 0 terminated, we
6354
                         * can use strlen() */
6355
0
                        mb = strlen((const char *)data);
6356
0
                    }
6357
0
                    else
6358
0
                    {
6359
                        /* general case. equivalent to non-portable */
6360
                        /* mb = strnlen((const char*)data,
6361
                         * (uint32_t)dp->tdir_count); */
6362
0
                        uint8_t *ma = data;
6363
0
                        while (mb < (uint32_t)dp->tdir_count)
6364
0
                        {
6365
0
                            if (*ma == 0)
6366
0
                                break;
6367
0
                            ma++;
6368
0
                            mb++;
6369
0
                        }
6370
0
                    }
6371
0
                }
6372
0
                if (!EvaluateIFDdatasizeReading(tif, dp))
6373
0
                {
6374
0
                    if (data != NULL)
6375
0
                        _TIFFfreeExt(tif, data);
6376
0
                    return (0);
6377
0
                }
6378
0
                if (mb + 1 < (uint32_t)dp->tdir_count)
6379
0
                    TIFFWarningExtR(
6380
0
                        tif, module,
6381
0
                        "ASCII value for tag \"%s\" contains null byte in "
6382
0
                        "value; value incorrectly truncated during reading due "
6383
0
                        "to implementation limitations",
6384
0
                        fip->field_name);
6385
0
                else if (mb + 1 > (uint32_t)dp->tdir_count)
6386
0
                {
6387
0
                    TIFFWarningExtR(tif, module,
6388
0
                                    "ASCII value for tag \"%s\" does not end "
6389
0
                                    "in null byte. Forcing it to be null",
6390
0
                                    fip->field_name);
6391
                    /* TIFFReadDirEntryArrayWithLimit() ensures this can't be
6392
                     * larger than MAX_SIZE_TAG_DATA */
6393
0
                    assert((uint32_t)dp->tdir_count + 1 == dp->tdir_count + 1);
6394
0
                    uint8_t *o = (uint8_t *)_TIFFmallocExt(
6395
0
                        tif, (uint32_t)dp->tdir_count + 1);
6396
0
                    if (o == NULL)
6397
0
                    {
6398
0
                        if (data != NULL)
6399
0
                            _TIFFfreeExt(tif, data);
6400
0
                        return (0);
6401
0
                    }
6402
0
                    if (dp->tdir_count > 0)
6403
0
                    {
6404
0
                        _TIFFmemcpy(o, data, (uint32_t)dp->tdir_count);
6405
0
                    }
6406
0
                    o[(uint32_t)dp->tdir_count] = 0;
6407
0
                    if (data != 0)
6408
0
                        _TIFFfreeExt(tif, data);
6409
0
                    data = o;
6410
0
                }
6411
0
                n = TIFFSetField(tif, dp->tdir_tag, data);
6412
0
                if (data != 0)
6413
0
                    _TIFFfreeExt(tif, data);
6414
0
                if (!n)
6415
0
                    return (0);
6416
0
            }
6417
0
        }
6418
0
        break;
6419
0
        case TIFF_SETGET_UINT8:
6420
0
        {
6421
0
            uint8_t data = 0;
6422
0
            assert(fip->field_readcount == 1);
6423
0
            assert(fip->field_passcount == 0);
6424
0
            err = TIFFReadDirEntryByte(tif, dp, &data);
6425
0
            if (err == TIFFReadDirEntryErrOk)
6426
0
            {
6427
0
                if (!TIFFSetField(tif, dp->tdir_tag, data))
6428
0
                    return (0);
6429
0
            }
6430
0
        }
6431
0
        break;
6432
0
        case TIFF_SETGET_SINT8:
6433
0
        {
6434
0
            int8_t data = 0;
6435
0
            assert(fip->field_readcount == 1);
6436
0
            assert(fip->field_passcount == 0);
6437
0
            err = TIFFReadDirEntrySbyte(tif, dp, &data);
6438
0
            if (err == TIFFReadDirEntryErrOk)
6439
0
            {
6440
0
                if (!TIFFSetField(tif, dp->tdir_tag, data))
6441
0
                    return (0);
6442
0
            }
6443
0
        }
6444
0
        break;
6445
0
        case TIFF_SETGET_UINT16:
6446
0
        {
6447
0
            uint16_t data;
6448
0
            assert(fip->field_readcount == 1);
6449
0
            assert(fip->field_passcount == 0);
6450
0
            err = TIFFReadDirEntryShort(tif, dp, &data);
6451
0
            if (err == TIFFReadDirEntryErrOk)
6452
0
            {
6453
0
                if (!TIFFSetField(tif, dp->tdir_tag, data))
6454
0
                    return (0);
6455
0
            }
6456
0
        }
6457
0
        break;
6458
0
        case TIFF_SETGET_SINT16:
6459
0
        {
6460
0
            int16_t data;
6461
0
            assert(fip->field_readcount == 1);
6462
0
            assert(fip->field_passcount == 0);
6463
0
            err = TIFFReadDirEntrySshort(tif, dp, &data);
6464
0
            if (err == TIFFReadDirEntryErrOk)
6465
0
            {
6466
0
                if (!TIFFSetField(tif, dp->tdir_tag, data))
6467
0
                    return (0);
6468
0
            }
6469
0
        }
6470
0
        break;
6471
0
        case TIFF_SETGET_UINT32:
6472
0
        {
6473
0
            uint32_t data;
6474
0
            assert(fip->field_readcount == 1);
6475
0
            assert(fip->field_passcount == 0);
6476
0
            err = TIFFReadDirEntryLong(tif, dp, &data);
6477
0
            if (err == TIFFReadDirEntryErrOk)
6478
0
            {
6479
0
                if (!TIFFSetField(tif, dp->tdir_tag, data))
6480
0
                    return (0);
6481
0
            }
6482
0
        }
6483
0
        break;
6484
0
        case TIFF_SETGET_SINT32:
6485
0
        {
6486
0
            int32_t data;
6487
0
            assert(fip->field_readcount == 1);
6488
0
            assert(fip->field_passcount == 0);
6489
0
            err = TIFFReadDirEntrySlong(tif, dp, &data);
6490
0
            if (err == TIFFReadDirEntryErrOk)
6491
0
            {
6492
0
                if (!TIFFSetField(tif, dp->tdir_tag, data))
6493
0
                    return (0);
6494
0
            }
6495
0
        }
6496
0
        break;
6497
0
        case TIFF_SETGET_UINT64:
6498
0
        {
6499
0
            uint64_t data;
6500
0
            assert(fip->field_readcount == 1);
6501
0
            assert(fip->field_passcount == 0);
6502
0
            err = TIFFReadDirEntryLong8(tif, dp, &data);
6503
0
            if (err == TIFFReadDirEntryErrOk)
6504
0
            {
6505
0
                if (!EvaluateIFDdatasizeReading(tif, dp))
6506
0
                    return 0;
6507
0
                if (!TIFFSetField(tif, dp->tdir_tag, data))
6508
0
                    return (0);
6509
0
            }
6510
0
        }
6511
0
        break;
6512
0
        case TIFF_SETGET_SINT64:
6513
0
        {
6514
0
            int64_t data;
6515
0
            assert(fip->field_readcount == 1);
6516
0
            assert(fip->field_passcount == 0);
6517
0
            err = TIFFReadDirEntrySlong8(tif, dp, &data);
6518
0
            if (err == TIFFReadDirEntryErrOk)
6519
0
            {
6520
0
                if (!EvaluateIFDdatasizeReading(tif, dp))
6521
0
                    return 0;
6522
0
                if (!TIFFSetField(tif, dp->tdir_tag, data))
6523
0
                    return (0);
6524
0
            }
6525
0
        }
6526
0
        break;
6527
0
        case TIFF_SETGET_FLOAT:
6528
0
        {
6529
0
            float data;
6530
0
            assert(fip->field_readcount == 1);
6531
0
            assert(fip->field_passcount == 0);
6532
0
            err = TIFFReadDirEntryFloat(tif, dp, &data);
6533
0
            if (err == TIFFReadDirEntryErrOk)
6534
0
            {
6535
0
                if (!EvaluateIFDdatasizeReading(tif, dp))
6536
0
                    return 0;
6537
0
                if (!TIFFSetField(tif, dp->tdir_tag, data))
6538
0
                    return (0);
6539
0
            }
6540
0
        }
6541
0
        break;
6542
0
        case TIFF_SETGET_DOUBLE:
6543
0
        {
6544
0
            double data;
6545
0
            assert(fip->field_readcount == 1);
6546
0
            assert(fip->field_passcount == 0);
6547
0
            err = TIFFReadDirEntryDouble(tif, dp, &data);
6548
0
            if (err == TIFFReadDirEntryErrOk)
6549
0
            {
6550
0
                if (!EvaluateIFDdatasizeReading(tif, dp))
6551
0
                    return 0;
6552
0
                if (!TIFFSetField(tif, dp->tdir_tag, data))
6553
0
                    return (0);
6554
0
            }
6555
0
        }
6556
0
        break;
6557
0
        case TIFF_SETGET_IFD8:
6558
0
        {
6559
0
            uint64_t data;
6560
0
            assert(fip->field_readcount == 1);
6561
0
            assert(fip->field_passcount == 0);
6562
0
            err = TIFFReadDirEntryIfd8(tif, dp, &data);
6563
0
            if (err == TIFFReadDirEntryErrOk)
6564
0
            {
6565
0
                if (!EvaluateIFDdatasizeReading(tif, dp))
6566
0
                    return 0;
6567
0
                if (!TIFFSetField(tif, dp->tdir_tag, data))
6568
0
                    return (0);
6569
0
            }
6570
0
        }
6571
0
        break;
6572
0
        case TIFF_SETGET_UINT16_PAIR:
6573
0
        {
6574
0
            uint16_t *data;
6575
0
            assert(fip->field_readcount == 2);
6576
0
            assert(fip->field_passcount == 0);
6577
0
            if (dp->tdir_count != 2)
6578
0
            {
6579
0
                TIFFWarningExtR(tif, module,
6580
0
                                "incorrect count for field \"%s\", expected 2, "
6581
0
                                "got %" PRIu64,
6582
0
                                fip->field_name, dp->tdir_count);
6583
0
                return (0);
6584
0
            }
6585
0
            err = TIFFReadDirEntryShortArray(tif, dp, &data);
6586
0
            if (err == TIFFReadDirEntryErrOk)
6587
0
            {
6588
0
                int m;
6589
0
                assert(data); /* avoid CLang static Analyzer false positive */
6590
0
                m = TIFFSetField(tif, dp->tdir_tag, data[0], data[1]);
6591
0
                _TIFFfreeExt(tif, data);
6592
0
                if (!m)
6593
0
                    return (0);
6594
0
            }
6595
0
        }
6596
0
        break;
6597
0
        case TIFF_SETGET_C0_UINT8:
6598
0
        {
6599
0
            uint8_t *data;
6600
0
            assert(fip->field_readcount >= 1);
6601
0
            assert(fip->field_passcount == 0);
6602
0
            if (dp->tdir_count != (uint64_t)fip->field_readcount)
6603
0
            {
6604
0
                TIFFWarningExtR(tif, module,
6605
0
                                "incorrect count for field \"%s\", expected "
6606
0
                                "%d, got %" PRIu64,
6607
0
                                fip->field_name, (int)fip->field_readcount,
6608
0
                                dp->tdir_count);
6609
0
                return (0);
6610
0
            }
6611
0
            else
6612
0
            {
6613
0
                err = TIFFReadDirEntryByteArray(tif, dp, &data);
6614
0
                if (err == TIFFReadDirEntryErrOk)
6615
0
                {
6616
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
6617
0
                    {
6618
0
                        if (data != 0)
6619
0
                            _TIFFfreeExt(tif, data);
6620
0
                        return 0;
6621
0
                    }
6622
0
                    int m;
6623
0
                    m = TIFFSetField(tif, dp->tdir_tag, data);
6624
0
                    if (data != 0)
6625
0
                        _TIFFfreeExt(tif, data);
6626
0
                    if (!m)
6627
0
                        return (0);
6628
0
                }
6629
0
            }
6630
0
        }
6631
0
        break;
6632
0
        case TIFF_SETGET_C0_SINT8:
6633
0
        {
6634
0
            int8_t *data;
6635
0
            assert(fip->field_readcount >= 1);
6636
0
            assert(fip->field_passcount == 0);
6637
0
            if (dp->tdir_count != (uint64_t)fip->field_readcount)
6638
0
            {
6639
0
                TIFFWarningExtR(tif, module,
6640
0
                                "incorrect count for field \"%s\", expected "
6641
0
                                "%d, got %" PRIu64,
6642
0
                                fip->field_name, (int)fip->field_readcount,
6643
0
                                dp->tdir_count);
6644
0
                return (0);
6645
0
            }
6646
0
            else
6647
0
            {
6648
0
                err = TIFFReadDirEntrySbyteArray(tif, dp, &data);
6649
0
                if (err == TIFFReadDirEntryErrOk)
6650
0
                {
6651
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
6652
0
                    {
6653
0
                        if (data != 0)
6654
0
                            _TIFFfreeExt(tif, data);
6655
0
                        return 0;
6656
0
                    }
6657
0
                    int m;
6658
0
                    m = TIFFSetField(tif, dp->tdir_tag, data);
6659
0
                    if (data != 0)
6660
0
                        _TIFFfreeExt(tif, data);
6661
0
                    if (!m)
6662
0
                        return (0);
6663
0
                }
6664
0
            }
6665
0
        }
6666
0
        break;
6667
0
        case TIFF_SETGET_C0_UINT16:
6668
0
        {
6669
0
            uint16_t *data;
6670
0
            assert(fip->field_readcount >= 1);
6671
0
            assert(fip->field_passcount == 0);
6672
0
            if (dp->tdir_count != (uint64_t)fip->field_readcount)
6673
0
            {
6674
0
                TIFFWarningExtR(tif, module,
6675
0
                                "incorrect count for field \"%s\", expected "
6676
0
                                "%d, got %" PRIu64,
6677
0
                                fip->field_name, (int)fip->field_readcount,
6678
0
                                dp->tdir_count);
6679
0
                return (0);
6680
0
            }
6681
0
            else
6682
0
            {
6683
0
                err = TIFFReadDirEntryShortArray(tif, dp, &data);
6684
0
                if (err == TIFFReadDirEntryErrOk)
6685
0
                {
6686
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
6687
0
                    {
6688
0
                        if (data != 0)
6689
0
                            _TIFFfreeExt(tif, data);
6690
0
                        return 0;
6691
0
                    }
6692
0
                    int m;
6693
0
                    m = TIFFSetField(tif, dp->tdir_tag, data);
6694
0
                    if (data != 0)
6695
0
                        _TIFFfreeExt(tif, data);
6696
0
                    if (!m)
6697
0
                        return (0);
6698
0
                }
6699
0
            }
6700
0
        }
6701
0
        break;
6702
0
        case TIFF_SETGET_C0_SINT16:
6703
0
        {
6704
0
            int16_t *data;
6705
0
            assert(fip->field_readcount >= 1);
6706
0
            assert(fip->field_passcount == 0);
6707
0
            if (dp->tdir_count != (uint64_t)fip->field_readcount)
6708
0
            {
6709
0
                TIFFWarningExtR(tif, module,
6710
0
                                "incorrect count for field \"%s\", expected "
6711
0
                                "%d, got %" PRIu64,
6712
0
                                fip->field_name, (int)fip->field_readcount,
6713
0
                                dp->tdir_count);
6714
0
                return (0);
6715
0
            }
6716
0
            else
6717
0
            {
6718
0
                err = TIFFReadDirEntrySshortArray(tif, dp, &data);
6719
0
                if (err == TIFFReadDirEntryErrOk)
6720
0
                {
6721
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
6722
0
                    {
6723
0
                        if (data != 0)
6724
0
                            _TIFFfreeExt(tif, data);
6725
0
                        return 0;
6726
0
                    }
6727
0
                    int m;
6728
0
                    m = TIFFSetField(tif, dp->tdir_tag, data);
6729
0
                    if (data != 0)
6730
0
                        _TIFFfreeExt(tif, data);
6731
0
                    if (!m)
6732
0
                        return (0);
6733
0
                }
6734
0
            }
6735
0
        }
6736
0
        break;
6737
0
        case TIFF_SETGET_C0_UINT32:
6738
0
        {
6739
0
            uint32_t *data;
6740
0
            assert(fip->field_readcount >= 1);
6741
0
            assert(fip->field_passcount == 0);
6742
0
            if (dp->tdir_count != (uint64_t)fip->field_readcount)
6743
0
            {
6744
0
                TIFFWarningExtR(tif, module,
6745
0
                                "incorrect count for field \"%s\", expected "
6746
0
                                "%d, got %" PRIu64,
6747
0
                                fip->field_name, (int)fip->field_readcount,
6748
0
                                dp->tdir_count);
6749
0
                return (0);
6750
0
            }
6751
0
            else
6752
0
            {
6753
0
                err = TIFFReadDirEntryLongArray(tif, dp, &data);
6754
0
                if (err == TIFFReadDirEntryErrOk)
6755
0
                {
6756
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
6757
0
                    {
6758
0
                        if (data != 0)
6759
0
                            _TIFFfreeExt(tif, data);
6760
0
                        return 0;
6761
0
                    }
6762
0
                    int m;
6763
0
                    m = TIFFSetField(tif, dp->tdir_tag, data);
6764
0
                    if (data != 0)
6765
0
                        _TIFFfreeExt(tif, data);
6766
0
                    if (!m)
6767
0
                        return (0);
6768
0
                }
6769
0
            }
6770
0
        }
6771
0
        break;
6772
0
        case TIFF_SETGET_C0_SINT32:
6773
0
        {
6774
0
            int32_t *data;
6775
0
            assert(fip->field_readcount >= 1);
6776
0
            assert(fip->field_passcount == 0);
6777
0
            if (dp->tdir_count != (uint64_t)fip->field_readcount)
6778
0
            {
6779
0
                TIFFWarningExtR(tif, module,
6780
0
                                "incorrect count for field \"%s\", expected "
6781
0
                                "%d, got %" PRIu64,
6782
0
                                fip->field_name, (int)fip->field_readcount,
6783
0
                                dp->tdir_count);
6784
0
                return (0);
6785
0
            }
6786
0
            else
6787
0
            {
6788
0
                err = TIFFReadDirEntrySlongArray(tif, dp, &data);
6789
0
                if (err == TIFFReadDirEntryErrOk)
6790
0
                {
6791
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
6792
0
                    {
6793
0
                        if (data != 0)
6794
0
                            _TIFFfreeExt(tif, data);
6795
0
                        return 0;
6796
0
                    }
6797
0
                    int m;
6798
0
                    m = TIFFSetField(tif, dp->tdir_tag, data);
6799
0
                    if (data != 0)
6800
0
                        _TIFFfreeExt(tif, data);
6801
0
                    if (!m)
6802
0
                        return (0);
6803
0
                }
6804
0
            }
6805
0
        }
6806
0
        break;
6807
0
        case TIFF_SETGET_C0_UINT64:
6808
0
        {
6809
0
            uint64_t *data;
6810
0
            assert(fip->field_readcount >= 1);
6811
0
            assert(fip->field_passcount == 0);
6812
0
            if (dp->tdir_count != (uint64_t)fip->field_readcount)
6813
0
            {
6814
0
                TIFFWarningExtR(tif, module,
6815
0
                                "incorrect count for field \"%s\", expected "
6816
0
                                "%d, got %" PRIu64,
6817
0
                                fip->field_name, (int)fip->field_readcount,
6818
0
                                dp->tdir_count);
6819
0
                return (0);
6820
0
            }
6821
0
            else
6822
0
            {
6823
0
                err = TIFFReadDirEntryLong8Array(tif, dp, &data);
6824
0
                if (err == TIFFReadDirEntryErrOk)
6825
0
                {
6826
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
6827
0
                    {
6828
0
                        if (data != 0)
6829
0
                            _TIFFfreeExt(tif, data);
6830
0
                        return 0;
6831
0
                    }
6832
0
                    int m;
6833
0
                    m = TIFFSetField(tif, dp->tdir_tag, data);
6834
0
                    if (data != 0)
6835
0
                        _TIFFfreeExt(tif, data);
6836
0
                    if (!m)
6837
0
                        return (0);
6838
0
                }
6839
0
            }
6840
0
        }
6841
0
        break;
6842
0
        case TIFF_SETGET_C0_SINT64:
6843
0
        {
6844
0
            int64_t *data;
6845
0
            assert(fip->field_readcount >= 1);
6846
0
            assert(fip->field_passcount == 0);
6847
0
            if (dp->tdir_count != (uint64_t)fip->field_readcount)
6848
0
            {
6849
0
                TIFFWarningExtR(tif, module,
6850
0
                                "incorrect count for field \"%s\", expected "
6851
0
                                "%d, got %" PRIu64,
6852
0
                                fip->field_name, (int)fip->field_readcount,
6853
0
                                dp->tdir_count);
6854
0
                return (0);
6855
0
            }
6856
0
            else
6857
0
            {
6858
0
                err = TIFFReadDirEntrySlong8Array(tif, dp, &data);
6859
0
                if (err == TIFFReadDirEntryErrOk)
6860
0
                {
6861
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
6862
0
                    {
6863
0
                        if (data != 0)
6864
0
                            _TIFFfreeExt(tif, data);
6865
0
                        return 0;
6866
0
                    }
6867
0
                    int m;
6868
0
                    m = TIFFSetField(tif, dp->tdir_tag, data);
6869
0
                    if (data != 0)
6870
0
                        _TIFFfreeExt(tif, data);
6871
0
                    if (!m)
6872
0
                        return (0);
6873
0
                }
6874
0
            }
6875
0
        }
6876
0
        break;
6877
0
        case TIFF_SETGET_C0_FLOAT:
6878
0
        {
6879
0
            float *data;
6880
0
            assert(fip->field_readcount >= 1);
6881
0
            assert(fip->field_passcount == 0);
6882
0
            if (dp->tdir_count != (uint64_t)fip->field_readcount)
6883
0
            {
6884
0
                TIFFWarningExtR(tif, module,
6885
0
                                "incorrect count for field \"%s\", expected "
6886
0
                                "%d, got %" PRIu64,
6887
0
                                fip->field_name, (int)fip->field_readcount,
6888
0
                                dp->tdir_count);
6889
0
                return (0);
6890
0
            }
6891
0
            else
6892
0
            {
6893
0
                err = TIFFReadDirEntryFloatArray(tif, dp, &data);
6894
0
                if (err == TIFFReadDirEntryErrOk)
6895
0
                {
6896
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
6897
0
                    {
6898
0
                        if (data != 0)
6899
0
                            _TIFFfreeExt(tif, data);
6900
0
                        return 0;
6901
0
                    }
6902
0
                    int m;
6903
0
                    m = TIFFSetField(tif, dp->tdir_tag, data);
6904
0
                    if (data != 0)
6905
0
                        _TIFFfreeExt(tif, data);
6906
0
                    if (!m)
6907
0
                        return (0);
6908
0
                }
6909
0
            }
6910
0
        }
6911
0
        break;
6912
        /*--: Rational2Double: Extend for Double Arrays and Rational-Arrays read
6913
         * into Double-Arrays. */
6914
0
        case TIFF_SETGET_C0_DOUBLE:
6915
0
        {
6916
0
            double *data;
6917
0
            assert(fip->field_readcount >= 1);
6918
0
            assert(fip->field_passcount == 0);
6919
0
            if (dp->tdir_count != (uint64_t)fip->field_readcount)
6920
0
            {
6921
0
                TIFFWarningExtR(tif, module,
6922
0
                                "incorrect count for field \"%s\", expected "
6923
0
                                "%d, got %" PRIu64,
6924
0
                                fip->field_name, (int)fip->field_readcount,
6925
0
                                dp->tdir_count);
6926
0
                return (0);
6927
0
            }
6928
0
            else
6929
0
            {
6930
0
                err = TIFFReadDirEntryDoubleArray(tif, dp, &data);
6931
0
                if (err == TIFFReadDirEntryErrOk)
6932
0
                {
6933
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
6934
0
                    {
6935
0
                        if (data != 0)
6936
0
                            _TIFFfreeExt(tif, data);
6937
0
                        return 0;
6938
0
                    }
6939
0
                    int m;
6940
0
                    m = TIFFSetField(tif, dp->tdir_tag, data);
6941
0
                    if (data != 0)
6942
0
                        _TIFFfreeExt(tif, data);
6943
0
                    if (!m)
6944
0
                        return (0);
6945
0
                }
6946
0
            }
6947
0
        }
6948
0
        break;
6949
0
        case TIFF_SETGET_C16_ASCII:
6950
0
        {
6951
0
            uint8_t *data;
6952
0
            assert(fip->field_readcount == TIFF_VARIABLE);
6953
0
            assert(fip->field_passcount == 1);
6954
0
            if (dp->tdir_count > 0xFFFF)
6955
0
                err = TIFFReadDirEntryErrCount;
6956
0
            else
6957
0
            {
6958
0
                err = TIFFReadDirEntryByteArray(tif, dp, &data);
6959
0
                if (err == TIFFReadDirEntryErrOk)
6960
0
                {
6961
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
6962
0
                    {
6963
0
                        if (data != 0)
6964
0
                            _TIFFfreeExt(tif, data);
6965
0
                        return 0;
6966
0
                    }
6967
0
                    int m;
6968
0
                    if (data != 0 && dp->tdir_count > 0 &&
6969
0
                        data[dp->tdir_count - 1] != '\0')
6970
0
                    {
6971
0
                        TIFFWarningExtR(tif, module,
6972
0
                                        "ASCII value for ASCII array tag "
6973
0
                                        "\"%s\" does not end in null "
6974
0
                                        "byte. Forcing it to be null",
6975
0
                                        fip->field_name);
6976
                        /* Enlarge buffer and add terminating null. */
6977
0
                        uint8_t *o = (uint8_t *)_TIFFmallocExt(
6978
0
                            tif, (uint32_t)dp->tdir_count + 1);
6979
0
                        if (o == NULL)
6980
0
                        {
6981
0
                            if (data != NULL)
6982
0
                                _TIFFfreeExt(tif, data);
6983
0
                            return (0);
6984
0
                        }
6985
0
                        if (dp->tdir_count > 0)
6986
0
                        {
6987
0
                            _TIFFmemcpy(o, data, (uint32_t)dp->tdir_count);
6988
0
                        }
6989
0
                        o[(uint32_t)dp->tdir_count] = 0;
6990
0
                        dp->tdir_count++; /* Increment for added null. */
6991
0
                        if (data != 0)
6992
0
                            _TIFFfreeExt(tif, data);
6993
0
                        data = o;
6994
0
                    }
6995
0
                    m = TIFFSetField(tif, dp->tdir_tag,
6996
0
                                     (uint16_t)(dp->tdir_count), data);
6997
0
                    if (data != 0)
6998
0
                        _TIFFfreeExt(tif, data);
6999
0
                    if (!m)
7000
0
                        return (0);
7001
0
                }
7002
0
            }
7003
0
        }
7004
0
        break;
7005
0
        case TIFF_SETGET_C16_UINT8:
7006
0
        {
7007
0
            uint8_t *data;
7008
0
            assert(fip->field_readcount == TIFF_VARIABLE);
7009
0
            assert(fip->field_passcount == 1);
7010
0
            if (dp->tdir_count > 0xFFFF)
7011
0
                err = TIFFReadDirEntryErrCount;
7012
0
            else
7013
0
            {
7014
0
                err = TIFFReadDirEntryByteArray(tif, dp, &data);
7015
0
                if (err == TIFFReadDirEntryErrOk)
7016
0
                {
7017
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
7018
0
                    {
7019
0
                        if (data != 0)
7020
0
                            _TIFFfreeExt(tif, data);
7021
0
                        return 0;
7022
0
                    }
7023
0
                    int m;
7024
0
                    m = TIFFSetField(tif, dp->tdir_tag,
7025
0
                                     (uint16_t)(dp->tdir_count), data);
7026
0
                    if (data != 0)
7027
0
                        _TIFFfreeExt(tif, data);
7028
0
                    if (!m)
7029
0
                        return (0);
7030
0
                }
7031
0
            }
7032
0
        }
7033
0
        break;
7034
0
        case TIFF_SETGET_C16_SINT8:
7035
0
        {
7036
0
            int8_t *data;
7037
0
            assert(fip->field_readcount == TIFF_VARIABLE);
7038
0
            assert(fip->field_passcount == 1);
7039
0
            if (dp->tdir_count > 0xFFFF)
7040
0
                err = TIFFReadDirEntryErrCount;
7041
0
            else
7042
0
            {
7043
0
                err = TIFFReadDirEntrySbyteArray(tif, dp, &data);
7044
0
                if (err == TIFFReadDirEntryErrOk)
7045
0
                {
7046
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
7047
0
                    {
7048
0
                        if (data != 0)
7049
0
                            _TIFFfreeExt(tif, data);
7050
0
                        return 0;
7051
0
                    }
7052
0
                    int m;
7053
0
                    m = TIFFSetField(tif, dp->tdir_tag,
7054
0
                                     (uint16_t)(dp->tdir_count), data);
7055
0
                    if (data != 0)
7056
0
                        _TIFFfreeExt(tif, data);
7057
0
                    if (!m)
7058
0
                        return (0);
7059
0
                }
7060
0
            }
7061
0
        }
7062
0
        break;
7063
0
        case TIFF_SETGET_C16_UINT16:
7064
0
        {
7065
0
            uint16_t *data;
7066
0
            assert(fip->field_readcount == TIFF_VARIABLE);
7067
0
            assert(fip->field_passcount == 1);
7068
0
            if (dp->tdir_count > 0xFFFF)
7069
0
                err = TIFFReadDirEntryErrCount;
7070
0
            else
7071
0
            {
7072
0
                err = TIFFReadDirEntryShortArray(tif, dp, &data);
7073
0
                if (err == TIFFReadDirEntryErrOk)
7074
0
                {
7075
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
7076
0
                    {
7077
0
                        if (data != 0)
7078
0
                            _TIFFfreeExt(tif, data);
7079
0
                        return 0;
7080
0
                    }
7081
0
                    int m;
7082
0
                    m = TIFFSetField(tif, dp->tdir_tag,
7083
0
                                     (uint16_t)(dp->tdir_count), data);
7084
0
                    if (data != 0)
7085
0
                        _TIFFfreeExt(tif, data);
7086
0
                    if (!m)
7087
0
                        return (0);
7088
0
                }
7089
0
            }
7090
0
        }
7091
0
        break;
7092
0
        case TIFF_SETGET_C16_SINT16:
7093
0
        {
7094
0
            int16_t *data;
7095
0
            assert(fip->field_readcount == TIFF_VARIABLE);
7096
0
            assert(fip->field_passcount == 1);
7097
0
            if (dp->tdir_count > 0xFFFF)
7098
0
                err = TIFFReadDirEntryErrCount;
7099
0
            else
7100
0
            {
7101
0
                err = TIFFReadDirEntrySshortArray(tif, dp, &data);
7102
0
                if (err == TIFFReadDirEntryErrOk)
7103
0
                {
7104
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
7105
0
                    {
7106
0
                        if (data != 0)
7107
0
                            _TIFFfreeExt(tif, data);
7108
0
                        return 0;
7109
0
                    }
7110
0
                    int m;
7111
0
                    m = TIFFSetField(tif, dp->tdir_tag,
7112
0
                                     (uint16_t)(dp->tdir_count), data);
7113
0
                    if (data != 0)
7114
0
                        _TIFFfreeExt(tif, data);
7115
0
                    if (!m)
7116
0
                        return (0);
7117
0
                }
7118
0
            }
7119
0
        }
7120
0
        break;
7121
0
        case TIFF_SETGET_C16_UINT32:
7122
0
        {
7123
0
            uint32_t *data;
7124
0
            assert(fip->field_readcount == TIFF_VARIABLE);
7125
0
            assert(fip->field_passcount == 1);
7126
0
            if (dp->tdir_count > 0xFFFF)
7127
0
                err = TIFFReadDirEntryErrCount;
7128
0
            else
7129
0
            {
7130
0
                err = TIFFReadDirEntryLongArray(tif, dp, &data);
7131
0
                if (err == TIFFReadDirEntryErrOk)
7132
0
                {
7133
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
7134
0
                    {
7135
0
                        if (data != 0)
7136
0
                            _TIFFfreeExt(tif, data);
7137
0
                        return 0;
7138
0
                    }
7139
0
                    int m;
7140
0
                    m = TIFFSetField(tif, dp->tdir_tag,
7141
0
                                     (uint16_t)(dp->tdir_count), data);
7142
0
                    if (data != 0)
7143
0
                        _TIFFfreeExt(tif, data);
7144
0
                    if (!m)
7145
0
                        return (0);
7146
0
                }
7147
0
            }
7148
0
        }
7149
0
        break;
7150
0
        case TIFF_SETGET_C16_SINT32:
7151
0
        {
7152
0
            int32_t *data;
7153
0
            assert(fip->field_readcount == TIFF_VARIABLE);
7154
0
            assert(fip->field_passcount == 1);
7155
0
            if (dp->tdir_count > 0xFFFF)
7156
0
                err = TIFFReadDirEntryErrCount;
7157
0
            else
7158
0
            {
7159
0
                err = TIFFReadDirEntrySlongArray(tif, dp, &data);
7160
0
                if (err == TIFFReadDirEntryErrOk)
7161
0
                {
7162
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
7163
0
                    {
7164
0
                        if (data != 0)
7165
0
                            _TIFFfreeExt(tif, data);
7166
0
                        return 0;
7167
0
                    }
7168
0
                    int m;
7169
0
                    m = TIFFSetField(tif, dp->tdir_tag,
7170
0
                                     (uint16_t)(dp->tdir_count), data);
7171
0
                    if (data != 0)
7172
0
                        _TIFFfreeExt(tif, data);
7173
0
                    if (!m)
7174
0
                        return (0);
7175
0
                }
7176
0
            }
7177
0
        }
7178
0
        break;
7179
0
        case TIFF_SETGET_C16_UINT64:
7180
0
        {
7181
0
            uint64_t *data;
7182
0
            assert(fip->field_readcount == TIFF_VARIABLE);
7183
0
            assert(fip->field_passcount == 1);
7184
0
            if (dp->tdir_count > 0xFFFF)
7185
0
                err = TIFFReadDirEntryErrCount;
7186
0
            else
7187
0
            {
7188
0
                err = TIFFReadDirEntryLong8Array(tif, dp, &data);
7189
0
                if (err == TIFFReadDirEntryErrOk)
7190
0
                {
7191
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
7192
0
                    {
7193
0
                        if (data != 0)
7194
0
                            _TIFFfreeExt(tif, data);
7195
0
                        return 0;
7196
0
                    }
7197
0
                    int m;
7198
0
                    m = TIFFSetField(tif, dp->tdir_tag,
7199
0
                                     (uint16_t)(dp->tdir_count), data);
7200
0
                    if (data != 0)
7201
0
                        _TIFFfreeExt(tif, data);
7202
0
                    if (!m)
7203
0
                        return (0);
7204
0
                }
7205
0
            }
7206
0
        }
7207
0
        break;
7208
0
        case TIFF_SETGET_C16_SINT64:
7209
0
        {
7210
0
            int64_t *data;
7211
0
            assert(fip->field_readcount == TIFF_VARIABLE);
7212
0
            assert(fip->field_passcount == 1);
7213
0
            if (dp->tdir_count > 0xFFFF)
7214
0
                err = TIFFReadDirEntryErrCount;
7215
0
            else
7216
0
            {
7217
0
                err = TIFFReadDirEntrySlong8Array(tif, dp, &data);
7218
0
                if (err == TIFFReadDirEntryErrOk)
7219
0
                {
7220
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
7221
0
                    {
7222
0
                        if (data != 0)
7223
0
                            _TIFFfreeExt(tif, data);
7224
0
                        return 0;
7225
0
                    }
7226
0
                    int m;
7227
0
                    m = TIFFSetField(tif, dp->tdir_tag,
7228
0
                                     (uint16_t)(dp->tdir_count), data);
7229
0
                    if (data != 0)
7230
0
                        _TIFFfreeExt(tif, data);
7231
0
                    if (!m)
7232
0
                        return (0);
7233
0
                }
7234
0
            }
7235
0
        }
7236
0
        break;
7237
0
        case TIFF_SETGET_C16_FLOAT:
7238
0
        {
7239
0
            float *data;
7240
0
            assert(fip->field_readcount == TIFF_VARIABLE);
7241
0
            assert(fip->field_passcount == 1);
7242
0
            if (dp->tdir_count > 0xFFFF)
7243
0
                err = TIFFReadDirEntryErrCount;
7244
0
            else
7245
0
            {
7246
0
                err = TIFFReadDirEntryFloatArray(tif, dp, &data);
7247
0
                if (err == TIFFReadDirEntryErrOk)
7248
0
                {
7249
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
7250
0
                    {
7251
0
                        if (data != 0)
7252
0
                            _TIFFfreeExt(tif, data);
7253
0
                        return 0;
7254
0
                    }
7255
0
                    int m;
7256
0
                    m = TIFFSetField(tif, dp->tdir_tag,
7257
0
                                     (uint16_t)(dp->tdir_count), data);
7258
0
                    if (data != 0)
7259
0
                        _TIFFfreeExt(tif, data);
7260
0
                    if (!m)
7261
0
                        return (0);
7262
0
                }
7263
0
            }
7264
0
        }
7265
0
        break;
7266
0
        case TIFF_SETGET_C16_DOUBLE:
7267
0
        {
7268
0
            double *data;
7269
0
            assert(fip->field_readcount == TIFF_VARIABLE);
7270
0
            assert(fip->field_passcount == 1);
7271
0
            if (dp->tdir_count > 0xFFFF)
7272
0
                err = TIFFReadDirEntryErrCount;
7273
0
            else
7274
0
            {
7275
0
                err = TIFFReadDirEntryDoubleArray(tif, dp, &data);
7276
0
                if (err == TIFFReadDirEntryErrOk)
7277
0
                {
7278
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
7279
0
                    {
7280
0
                        if (data != 0)
7281
0
                            _TIFFfreeExt(tif, data);
7282
0
                        return 0;
7283
0
                    }
7284
0
                    int m;
7285
0
                    m = TIFFSetField(tif, dp->tdir_tag,
7286
0
                                     (uint16_t)(dp->tdir_count), data);
7287
0
                    if (data != 0)
7288
0
                        _TIFFfreeExt(tif, data);
7289
0
                    if (!m)
7290
0
                        return (0);
7291
0
                }
7292
0
            }
7293
0
        }
7294
0
        break;
7295
0
        case TIFF_SETGET_C16_IFD8:
7296
0
        {
7297
0
            uint64_t *data;
7298
0
            assert(fip->field_readcount == TIFF_VARIABLE);
7299
0
            assert(fip->field_passcount == 1);
7300
0
            if (dp->tdir_count > 0xFFFF)
7301
0
                err = TIFFReadDirEntryErrCount;
7302
0
            else
7303
0
            {
7304
0
                err = TIFFReadDirEntryIfd8Array(tif, dp, &data);
7305
0
                if (err == TIFFReadDirEntryErrOk)
7306
0
                {
7307
0
                    if (!EvaluateIFDdatasizeReading(tif, dp))
7308
0
                    {
7309
0
                        if (data != 0)
7310
0
                            _TIFFfreeExt(tif, data);
7311
0
                        return 0;
7312
0
                    }
7313
0
                    int m;
7314
0
                    m = TIFFSetField(tif, dp->tdir_tag,
7315
0
                                     (uint16_t)(dp->tdir_count), data);
7316
0
                    if (data != 0)
7317
0
                        _TIFFfreeExt(tif, data);
7318
0
                    if (!m)
7319
0
                        return (0);
7320
0
                }
7321
0
            }
7322
0
        }
7323
0
        break;
7324
0
        case TIFF_SETGET_C32_ASCII:
7325
0
        {
7326
0
            uint8_t *data;
7327
0
            assert(fip->field_readcount == TIFF_VARIABLE2);
7328
0
            assert(fip->field_passcount == 1);
7329
0
            err = TIFFReadDirEntryByteArray(tif, dp, &data);
7330
0
            if (err == TIFFReadDirEntryErrOk)
7331
0
            {
7332
0
                if (!EvaluateIFDdatasizeReading(tif, dp))
7333
0
                {
7334
0
                    if (data != 0)
7335
0
                        _TIFFfreeExt(tif, data);
7336
0
                    return 0;
7337
0
                }
7338
0
                int m;
7339
0
                if (data != 0 && dp->tdir_count > 0 &&
7340
0
                    data[dp->tdir_count - 1] != '\0')
7341
0
                {
7342
0
                    TIFFWarningExtR(
7343
0
                        tif, module,
7344
0
                        "ASCII value for ASCII array tag \"%s\" does not end "
7345
0
                        "in null byte. Forcing it to be null",
7346
0
                        fip->field_name);
7347
                    /* Enlarge buffer and add terminating null. */
7348
0
                    uint8_t *o = (uint8_t *)_TIFFmallocExt(
7349
0
                        tif, (uint32_t)dp->tdir_count + 1);
7350
0
                    if (o == NULL)
7351
0
                    {
7352
0
                        if (data != NULL)
7353
0
                            _TIFFfreeExt(tif, data);
7354
0
                        return (0);
7355
0
                    }
7356
0
                    if (dp->tdir_count > 0)
7357
0
                    {
7358
0
                        _TIFFmemcpy(o, data, (uint32_t)dp->tdir_count);
7359
0
                    }
7360
0
                    o[(uint32_t)dp->tdir_count] = 0;
7361
0
                    dp->tdir_count++; /* Increment for added null. */
7362
0
                    if (data != 0)
7363
0
                        _TIFFfreeExt(tif, data);
7364
0
                    data = o;
7365
0
                }
7366
0
                m = TIFFSetField(tif, dp->tdir_tag, (uint32_t)(dp->tdir_count),
7367
0
                                 data);
7368
0
                if (data != 0)
7369
0
                    _TIFFfreeExt(tif, data);
7370
0
                if (!m)
7371
0
                    return (0);
7372
0
            }
7373
0
        }
7374
0
        break;
7375
0
        case TIFF_SETGET_C32_UINT8:
7376
0
        {
7377
0
            uint8_t *data;
7378
0
            uint32_t count = 0;
7379
0
            assert(fip->field_readcount == TIFF_VARIABLE2);
7380
0
            assert(fip->field_passcount == 1);
7381
0
            if (fip->field_tag == TIFFTAG_RICHTIFFIPTC &&
7382
0
                dp->tdir_type == TIFF_LONG)
7383
0
            {
7384
                /* Adobe's software (wrongly) writes RichTIFFIPTC tag with
7385
                 * data type LONG instead of UNDEFINED. Work around this
7386
                 * frequently found issue */
7387
0
                void *origdata;
7388
0
                err = TIFFReadDirEntryArray(tif, dp, &count, 4, &origdata);
7389
0
                if ((err != TIFFReadDirEntryErrOk) || (origdata == 0))
7390
0
                {
7391
0
                    data = NULL;
7392
0
                }
7393
0
                else
7394
0
                {
7395
0
                    if (tif->tif_flags & TIFF_SWAB)
7396
0
                        TIFFSwabArrayOfLong((uint32_t *)origdata, count);
7397
0
                    data = (uint8_t *)origdata;
7398
0
                    count = (uint32_t)(count * 4);
7399
0
                }
7400
0
            }
7401
0
            else
7402
0
            {
7403
0
                err = TIFFReadDirEntryByteArray(tif, dp, &data);
7404
0
                count = (uint32_t)(dp->tdir_count);
7405
0
            }
7406
0
            if (err == TIFFReadDirEntryErrOk)
7407
0
            {
7408
0
                if (!EvaluateIFDdatasizeReading(tif, dp))
7409
0
                {
7410
0
                    if (data != 0)
7411
0
                        _TIFFfreeExt(tif, data);
7412
0
                    return 0;
7413
0
                }
7414
0
                int m;
7415
0
                m = TIFFSetField(tif, dp->tdir_tag, count, data);
7416
0
                if (data != 0)
7417
0
                    _TIFFfreeExt(tif, data);
7418
0
                if (!m)
7419
0
                    return (0);
7420
0
            }
7421
0
        }
7422
0
        break;
7423
0
        case TIFF_SETGET_C32_SINT8:
7424
0
        {
7425
0
            int8_t *data = NULL;
7426
0
            assert(fip->field_readcount == TIFF_VARIABLE2);
7427
0
            assert(fip->field_passcount == 1);
7428
0
            err = TIFFReadDirEntrySbyteArray(tif, dp, &data);
7429
0
            if (err == TIFFReadDirEntryErrOk)
7430
0
            {
7431
0
                if (!EvaluateIFDdatasizeReading(tif, dp))
7432
0
                {
7433
0
                    if (data != 0)
7434
0
                        _TIFFfreeExt(tif, data);
7435
0
                    return 0;
7436
0
                }
7437
0
                int m;
7438
0
                m = TIFFSetField(tif, dp->tdir_tag, (uint32_t)(dp->tdir_count),
7439
0
                                 data);
7440
0
                if (data != 0)
7441
0
                    _TIFFfreeExt(tif, data);
7442
0
                if (!m)
7443
0
                    return (0);
7444
0
            }
7445
0
        }
7446
0
        break;
7447
0
        case TIFF_SETGET_C32_UINT16:
7448
0
        {
7449
0
            uint16_t *data;
7450
0
            assert(fip->field_readcount == TIFF_VARIABLE2);
7451
0
            assert(fip->field_passcount == 1);
7452
0
            err = TIFFReadDirEntryShortArray(tif, dp, &data);
7453
0
            if (err == TIFFReadDirEntryErrOk)
7454
0
            {
7455
0
                if (!EvaluateIFDdatasizeReading(tif, dp))
7456
0
                {
7457
0
                    if (data != 0)
7458
0
                        _TIFFfreeExt(tif, data);
7459
0
                    return 0;
7460
0
                }
7461
0
                int m;
7462
0
                m = TIFFSetField(tif, dp->tdir_tag, (uint32_t)(dp->tdir_count),
7463
0
                                 data);
7464
0
                if (data != 0)
7465
0
                    _TIFFfreeExt(tif, data);
7466
0
                if (!m)
7467
0
                    return (0);
7468
0
            }
7469
0
        }
7470
0
        break;
7471
0
        case TIFF_SETGET_C32_SINT16:
7472
0
        {
7473
0
            int16_t *data = NULL;
7474
0
            assert(fip->field_readcount == TIFF_VARIABLE2);
7475
0
            assert(fip->field_passcount == 1);
7476
0
            err = TIFFReadDirEntrySshortArray(tif, dp, &data);
7477
0
            if (err == TIFFReadDirEntryErrOk)
7478
0
            {
7479
0
                if (!EvaluateIFDdatasizeReading(tif, dp))
7480
0
                {
7481
0
                    if (data != 0)
7482
0
                        _TIFFfreeExt(tif, data);
7483
0
                    return 0;
7484
0
                }
7485
0
                int m;
7486
0
                m = TIFFSetField(tif, dp->tdir_tag, (uint32_t)(dp->tdir_count),
7487
0
                                 data);
7488
0
                if (data != 0)
7489
0
                    _TIFFfreeExt(tif, data);
7490
0
                if (!m)
7491
0
                    return (0);
7492
0
            }
7493
0
        }
7494
0
        break;
7495
0
        case TIFF_SETGET_C32_UINT32:
7496
0
        {
7497
0
            uint32_t *data;
7498
0
            assert(fip->field_readcount == TIFF_VARIABLE2);
7499
0
            assert(fip->field_passcount == 1);
7500
0
            err = TIFFReadDirEntryLongArray(tif, dp, &data);
7501
0
            if (err == TIFFReadDirEntryErrOk)
7502
0
            {
7503
0
                if (!EvaluateIFDdatasizeReading(tif, dp))
7504
0
                {
7505
0
                    if (data != 0)
7506
0
                        _TIFFfreeExt(tif, data);
7507
0
                    return 0;
7508
0
                }
7509
0
                int m;
7510
0
                m = TIFFSetField(tif, dp->tdir_tag, (uint32_t)(dp->tdir_count),
7511
0
                                 data);
7512
0
                if (data != 0)
7513
0
                    _TIFFfreeExt(tif, data);
7514
0
                if (!m)
7515
0
                    return (0);
7516
0
            }
7517
0
        }
7518
0
        break;
7519
0
        case TIFF_SETGET_C32_SINT32:
7520
0
        {
7521
0
            int32_t *data = NULL;
7522
0
            assert(fip->field_readcount == TIFF_VARIABLE2);
7523
0
            assert(fip->field_passcount == 1);
7524
0
            err = TIFFReadDirEntrySlongArray(tif, dp, &data);
7525
0
            if (err == TIFFReadDirEntryErrOk)
7526
0
            {
7527
0
                if (!EvaluateIFDdatasizeReading(tif, dp))
7528
0
                {
7529
0
                    if (data != 0)
7530
0
                        _TIFFfreeExt(tif, data);
7531
0
                    return 0;
7532
0
                }
7533
0
                int m;
7534
0
                m = TIFFSetField(tif, dp->tdir_tag, (uint32_t)(dp->tdir_count),
7535
0
                                 data);
7536
0
                if (data != 0)
7537
0
                    _TIFFfreeExt(tif, data);
7538
0
                if (!m)
7539
0
                    return (0);
7540
0
            }
7541
0
        }
7542
0
        break;
7543
0
        case TIFF_SETGET_C32_UINT64:
7544
0
        {
7545
0
            uint64_t *data;
7546
0
            assert(fip->field_readcount == TIFF_VARIABLE2);
7547
0
            assert(fip->field_passcount == 1);
7548
0
            err = TIFFReadDirEntryLong8Array(tif, dp, &data);
7549
0
            if (err == TIFFReadDirEntryErrOk)
7550
0
            {
7551
0
                if (!EvaluateIFDdatasizeReading(tif, dp))
7552
0
                {
7553
0
                    if (data != 0)
7554
0
                        _TIFFfreeExt(tif, data);
7555
0
                    return 0;
7556
0
                }
7557
0
                int m;
7558
0
                m = TIFFSetField(tif, dp->tdir_tag, (uint32_t)(dp->tdir_count),
7559
0
                                 data);
7560
0
                if (data != 0)
7561
0
                    _TIFFfreeExt(tif, data);
7562
0
                if (!m)
7563
0
                    return (0);
7564
0
            }
7565
0
        }
7566
0
        break;
7567
0
        case TIFF_SETGET_C32_SINT64:
7568
0
        {
7569
0
            int64_t *data = NULL;
7570
0
            assert(fip->field_readcount == TIFF_VARIABLE2);
7571
0
            assert(fip->field_passcount == 1);
7572
0
            err = TIFFReadDirEntrySlong8Array(tif, dp, &data);
7573
0
            if (err == TIFFReadDirEntryErrOk)
7574
0
            {
7575
0
                if (!EvaluateIFDdatasizeReading(tif, dp))
7576
0
                {
7577
0
                    if (data != 0)
7578
0
                        _TIFFfreeExt(tif, data);
7579
0
                    return 0;
7580
0
                }
7581
0
                int m;
7582
0
                m = TIFFSetField(tif, dp->tdir_tag, (uint32_t)(dp->tdir_count),
7583
0
                                 data);
7584
0
                if (data != 0)
7585
0
                    _TIFFfreeExt(tif, data);
7586
0
                if (!m)
7587
0
                    return (0);
7588
0
            }
7589
0
        }
7590
0
        break;
7591
0
        case TIFF_SETGET_C32_FLOAT:
7592
0
        {
7593
0
            float *data;
7594
0
            assert(fip->field_readcount == TIFF_VARIABLE2);
7595
0
            assert(fip->field_passcount == 1);
7596
0
            err = TIFFReadDirEntryFloatArray(tif, dp, &data);
7597
0
            if (err == TIFFReadDirEntryErrOk)
7598
0
            {
7599
0
                if (!EvaluateIFDdatasizeReading(tif, dp))
7600
0
                {
7601
0
                    if (data != 0)
7602
0
                        _TIFFfreeExt(tif, data);
7603
0
                    return 0;
7604
0
                }
7605
0
                int m;
7606
0
                m = TIFFSetField(tif, dp->tdir_tag, (uint32_t)(dp->tdir_count),
7607
0
                                 data);
7608
0
                if (data != 0)
7609
0
                    _TIFFfreeExt(tif, data);
7610
0
                if (!m)
7611
0
                    return (0);
7612
0
            }
7613
0
        }
7614
0
        break;
7615
0
        case TIFF_SETGET_C32_DOUBLE:
7616
0
        {
7617
0
            double *data;
7618
0
            assert(fip->field_readcount == TIFF_VARIABLE2);
7619
0
            assert(fip->field_passcount == 1);
7620
0
            err = TIFFReadDirEntryDoubleArray(tif, dp, &data);
7621
0
            if (err == TIFFReadDirEntryErrOk)
7622
0
            {
7623
0
                if (!EvaluateIFDdatasizeReading(tif, dp))
7624
0
                {
7625
0
                    if (data != 0)
7626
0
                        _TIFFfreeExt(tif, data);
7627
0
                    return 0;
7628
0
                }
7629
0
                int m;
7630
0
                m = TIFFSetField(tif, dp->tdir_tag, (uint32_t)(dp->tdir_count),
7631
0
                                 data);
7632
0
                if (data != 0)
7633
0
                    _TIFFfreeExt(tif, data);
7634
0
                if (!m)
7635
0
                    return (0);
7636
0
            }
7637
0
        }
7638
0
        break;
7639
0
        case TIFF_SETGET_C32_IFD8:
7640
0
        {
7641
0
            uint64_t *data;
7642
0
            assert(fip->field_readcount == TIFF_VARIABLE2);
7643
0
            assert(fip->field_passcount == 1);
7644
0
            err = TIFFReadDirEntryIfd8Array(tif, dp, &data);
7645
0
            if (err == TIFFReadDirEntryErrOk)
7646
0
            {
7647
0
                if (!EvaluateIFDdatasizeReading(tif, dp))
7648
0
                {
7649
0
                    if (data != 0)
7650
0
                        _TIFFfreeExt(tif, data);
7651
0
                    return 0;
7652
0
                }
7653
0
                int m;
7654
0
                m = TIFFSetField(tif, dp->tdir_tag, (uint32_t)(dp->tdir_count),
7655
0
                                 data);
7656
0
                if (data != 0)
7657
0
                    _TIFFfreeExt(tif, data);
7658
0
                if (!m)
7659
0
                    return (0);
7660
0
            }
7661
0
        }
7662
0
        break;
7663
0
        default:
7664
0
            assert(0); /* we should never get here */
7665
0
            break;
7666
0
    }
7667
0
    if (err != TIFFReadDirEntryErrOk)
7668
0
    {
7669
0
        TIFFReadDirEntryOutputErr(tif, err, module, fip->field_name, recover);
7670
0
        return (0);
7671
0
    }
7672
0
    return (1);
7673
0
}
7674
7675
/*
7676
 * Fetch a set of offsets or lengths.
7677
 * While this routine says "strips", in fact it's also used for tiles.
7678
 */
7679
static int TIFFFetchStripThing(TIFF *tif, TIFFDirEntry *dir, uint32_t nstrips,
7680
                               uint64_t **lpp)
7681
0
{
7682
0
    static const char module[] = "TIFFFetchStripThing";
7683
0
    enum TIFFReadDirEntryErr err;
7684
0
    uint64_t *data;
7685
0
    err = TIFFReadDirEntryLong8ArrayWithLimit(tif, dir, &data, nstrips);
7686
0
    if (err != TIFFReadDirEntryErrOk)
7687
0
    {
7688
0
        const TIFFField *fip = TIFFFieldWithTag(tif, dir->tdir_tag);
7689
0
        TIFFReadDirEntryOutputErr(tif, err, module,
7690
0
                                  fip ? fip->field_name : "unknown tagname", 0);
7691
0
        return (0);
7692
0
    }
7693
0
    if (dir->tdir_count < (uint64_t)nstrips)
7694
0
    {
7695
0
        uint64_t *resizeddata;
7696
0
        const TIFFField *fip = TIFFFieldWithTag(tif, dir->tdir_tag);
7697
0
        const char *pszMax = getenv("LIBTIFF_STRILE_ARRAY_MAX_RESIZE_COUNT");
7698
0
        uint32_t max_nstrips = 1000000;
7699
0
        if (pszMax)
7700
0
            max_nstrips = (uint32_t)atoi(pszMax);
7701
0
        TIFFReadDirEntryOutputErr(tif, TIFFReadDirEntryErrCount, module,
7702
0
                                  fip ? fip->field_name : "unknown tagname",
7703
0
                                  (nstrips <= max_nstrips));
7704
7705
0
        if (nstrips > max_nstrips)
7706
0
        {
7707
0
            _TIFFfreeExt(tif, data);
7708
0
            return (0);
7709
0
        }
7710
7711
0
        const uint64_t allocsize = (uint64_t)nstrips * sizeof(uint64_t);
7712
0
        if (allocsize > 100 * 1024 * 1024)
7713
0
        {
7714
            /* Before allocating a huge amount of memory for corrupted files,
7715
             * check if size of requested memory is not greater than file size.
7716
             */
7717
0
            const uint64_t filesize = TIFFGetFileSize(tif);
7718
0
            if (allocsize > filesize)
7719
0
            {
7720
0
                TIFFWarningExtR(
7721
0
                    tif, module,
7722
0
                    "Requested memory size for StripArray of %" PRIu64
7723
0
                    " is greater than filesize %" PRIu64
7724
0
                    ". Memory not allocated",
7725
0
                    allocsize, filesize);
7726
0
                _TIFFfreeExt(tif, data);
7727
0
                return (0);
7728
0
            }
7729
0
        }
7730
0
        resizeddata = (uint64_t *)_TIFFCheckMalloc(
7731
0
            tif, nstrips, sizeof(uint64_t), "for strip array");
7732
0
        if (resizeddata == 0)
7733
0
        {
7734
0
            _TIFFfreeExt(tif, data);
7735
0
            return (0);
7736
0
        }
7737
0
        if (dir->tdir_count)
7738
0
            _TIFFmemcpy(resizeddata, data,
7739
0
                        (uint32_t)dir->tdir_count * sizeof(uint64_t));
7740
0
        _TIFFmemset(resizeddata + (uint32_t)dir->tdir_count, 0,
7741
0
                    (nstrips - (uint32_t)dir->tdir_count) * sizeof(uint64_t));
7742
0
        _TIFFfreeExt(tif, data);
7743
0
        data = resizeddata;
7744
0
    }
7745
0
    *lpp = data;
7746
0
    return (1);
7747
0
}
7748
7749
/*
7750
 * Fetch and set the SubjectDistance EXIF tag.
7751
 */
7752
static int TIFFFetchSubjectDistance(TIFF *tif, TIFFDirEntry *dir)
7753
0
{
7754
0
    static const char module[] = "TIFFFetchSubjectDistance";
7755
0
    enum TIFFReadDirEntryErr err;
7756
0
    UInt64Aligned_t m;
7757
0
    m.l = 0;
7758
0
    assert(sizeof(double) == 8);
7759
0
    assert(sizeof(uint64_t) == 8);
7760
0
    assert(sizeof(uint32_t) == 4);
7761
0
    if (dir->tdir_count != 1)
7762
0
        err = TIFFReadDirEntryErrCount;
7763
0
    else if (dir->tdir_type != TIFF_RATIONAL)
7764
0
        err = TIFFReadDirEntryErrType;
7765
0
    else
7766
0
    {
7767
0
        if (!(tif->tif_flags & TIFF_BIGTIFF))
7768
0
        {
7769
0
            uint32_t offset;
7770
0
            offset = *(uint32_t *)(&dir->tdir_offset);
7771
0
            if (tif->tif_flags & TIFF_SWAB)
7772
0
                TIFFSwabLong(&offset);
7773
0
            err = TIFFReadDirEntryData(tif, offset, 8, m.i);
7774
0
        }
7775
0
        else
7776
0
        {
7777
0
            m.l = dir->tdir_offset.toff_long8;
7778
0
            err = TIFFReadDirEntryErrOk;
7779
0
        }
7780
0
    }
7781
0
    if (err == TIFFReadDirEntryErrOk)
7782
0
    {
7783
0
        double n;
7784
0
        if (tif->tif_flags & TIFF_SWAB)
7785
0
            TIFFSwabArrayOfLong(m.i, 2);
7786
0
        if (m.i[0] == 0)
7787
0
            n = 0.0;
7788
0
        else if (m.i[0] == 0xFFFFFFFF || m.i[1] == 0)
7789
            /*
7790
             * XXX: Numerator 0xFFFFFFFF means that we have infinite
7791
             * distance. Indicate that with a negative floating point
7792
             * SubjectDistance value.
7793
             */
7794
0
            n = -1.0;
7795
0
        else
7796
0
            n = (double)m.i[0] / (double)m.i[1];
7797
0
        return (TIFFSetField(tif, dir->tdir_tag, n));
7798
0
    }
7799
0
    else
7800
0
    {
7801
0
        TIFFReadDirEntryOutputErr(tif, err, module, "SubjectDistance", TRUE);
7802
0
        return (0);
7803
0
    }
7804
0
}
7805
7806
static void allocChoppedUpStripArrays(TIFF *tif, uint32_t nstrips,
7807
                                      uint64_t stripbytes,
7808
                                      uint32_t rowsperstrip)
7809
0
{
7810
0
    TIFFDirectory *td = &tif->tif_dir;
7811
0
    uint64_t bytecount;
7812
0
    uint64_t offset;
7813
0
    uint64_t last_offset;
7814
0
    uint64_t last_bytecount;
7815
0
    uint32_t i;
7816
0
    uint64_t *newcounts;
7817
0
    uint64_t *newoffsets;
7818
7819
0
    offset = TIFFGetStrileOffset(tif, 0);
7820
0
    last_offset = TIFFGetStrileOffset(tif, td->td_nstrips - 1);
7821
0
    last_bytecount = TIFFGetStrileByteCount(tif, td->td_nstrips - 1);
7822
0
    if (last_offset > UINT64_MAX - last_bytecount ||
7823
0
        last_offset + last_bytecount < offset)
7824
0
    {
7825
0
        return;
7826
0
    }
7827
0
    bytecount = last_offset + last_bytecount - offset;
7828
7829
    /* Before allocating a huge amount of memory for corrupted files, check if
7830
     * size of StripByteCount and StripOffset tags is not greater than
7831
     * file size.
7832
     */
7833
0
    const uint64_t allocsize = (uint64_t)nstrips * sizeof(uint64_t) * 2;
7834
0
    if (allocsize > 100 * 1024 * 1024)
7835
0
    {
7836
0
        const uint64_t filesize = TIFFGetFileSize(tif);
7837
0
        if (allocsize > filesize)
7838
0
        {
7839
0
            TIFFWarningExtR(tif, "allocChoppedUpStripArrays",
7840
0
                            "Requested memory size for StripByteCount and "
7841
0
                            "StripOffsets %" PRIu64
7842
0
                            " is greater than filesize %" PRIu64
7843
0
                            ". Memory not allocated",
7844
0
                            allocsize, filesize);
7845
0
            return;
7846
0
        }
7847
0
    }
7848
7849
0
    newcounts =
7850
0
        (uint64_t *)_TIFFCheckMalloc(tif, nstrips, sizeof(uint64_t),
7851
0
                                     "for chopped \"StripByteCounts\" array");
7852
0
    newoffsets = (uint64_t *)_TIFFCheckMalloc(
7853
0
        tif, nstrips, sizeof(uint64_t), "for chopped \"StripOffsets\" array");
7854
0
    if (newcounts == NULL || newoffsets == NULL)
7855
0
    {
7856
        /*
7857
         * Unable to allocate new strip information, give up and use
7858
         * the original one strip information.
7859
         */
7860
0
        if (newcounts != NULL)
7861
0
            _TIFFfreeExt(tif, newcounts);
7862
0
        if (newoffsets != NULL)
7863
0
            _TIFFfreeExt(tif, newoffsets);
7864
0
        return;
7865
0
    }
7866
7867
    /*
7868
     * Fill the strip information arrays with new bytecounts and offsets
7869
     * that reflect the broken-up format.
7870
     */
7871
0
    for (i = 0; i < nstrips; i++)
7872
0
    {
7873
0
        if (stripbytes > bytecount)
7874
0
            stripbytes = bytecount;
7875
0
        newcounts[i] = stripbytes;
7876
0
        newoffsets[i] = stripbytes ? offset : 0;
7877
0
        offset += stripbytes;
7878
0
        bytecount -= stripbytes;
7879
0
    }
7880
7881
    /*
7882
     * Replace old single strip info with multi-strip info.
7883
     */
7884
0
    td->td_stripsperimage = td->td_nstrips = nstrips;
7885
0
    TIFFSetField(tif, TIFFTAG_ROWSPERSTRIP, rowsperstrip);
7886
7887
0
    _TIFFfreeExt(tif, td->td_stripbytecount_p);
7888
0
    _TIFFfreeExt(tif, td->td_stripoffset_p);
7889
0
    td->td_stripbytecount_p = newcounts;
7890
0
    td->td_stripoffset_p = newoffsets;
7891
#ifdef STRIPBYTECOUNTSORTED_UNUSED
7892
    td->td_stripbytecountsorted = 1;
7893
#endif
7894
0
    tif->tif_flags |= TIFF_CHOPPEDUPARRAYS;
7895
0
}
7896
7897
/*
7898
 * Replace a single strip (tile) of uncompressed data by multiple strips
7899
 * (tiles), each approximately STRIP_SIZE_DEFAULT bytes. This is useful for
7900
 * dealing with large images or for dealing with machines with a limited
7901
 * amount memory.
7902
 */
7903
static void ChopUpSingleUncompressedStrip(TIFF *tif)
7904
0
{
7905
0
    TIFFDirectory *td = &tif->tif_dir;
7906
0
    uint64_t bytecount;
7907
0
    uint64_t offset;
7908
0
    uint32_t rowblock;
7909
0
    uint64_t rowblockbytes;
7910
0
    uint64_t stripbytes;
7911
0
    uint32_t nstrips;
7912
0
    uint32_t rowsperstrip;
7913
7914
0
    bytecount = TIFFGetStrileByteCount(tif, 0);
7915
    /* On a newly created file, just re-opened to be filled, we */
7916
    /* don't want strip chop to trigger as it is going to cause issues */
7917
    /* later ( StripOffsets and StripByteCounts improperly filled) . */
7918
0
    if (bytecount == 0 && tif->tif_mode != O_RDONLY)
7919
0
        return;
7920
0
    offset = TIFFGetStrileByteCount(tif, 0);
7921
0
    assert(td->td_planarconfig == PLANARCONFIG_CONTIG);
7922
0
    if ((td->td_photometric == PHOTOMETRIC_YCBCR) && (!isUpSampled(tif)))
7923
0
        rowblock = td->td_ycbcrsubsampling[1];
7924
0
    else
7925
0
        rowblock = 1;
7926
0
    rowblockbytes = TIFFVTileSize64(tif, rowblock);
7927
    /*
7928
     * Make the rows hold at least one scanline, but fill specified amount
7929
     * of data if possible.
7930
     */
7931
0
    if (rowblockbytes > STRIP_SIZE_DEFAULT)
7932
0
    {
7933
0
        stripbytes = rowblockbytes;
7934
0
        rowsperstrip = rowblock;
7935
0
    }
7936
0
    else if (rowblockbytes > 0)
7937
0
    {
7938
0
        uint32_t rowblocksperstrip;
7939
0
        rowblocksperstrip = (uint32_t)(STRIP_SIZE_DEFAULT / rowblockbytes);
7940
0
        rowsperstrip = rowblocksperstrip * rowblock;
7941
0
        stripbytes = rowblocksperstrip * rowblockbytes;
7942
0
    }
7943
0
    else
7944
0
        return;
7945
7946
    /*
7947
     * never increase the number of rows per strip
7948
     */
7949
0
    if (rowsperstrip >= td->td_rowsperstrip || rowsperstrip == 0)
7950
0
        return;
7951
0
    nstrips = TIFFhowmany_32(td->td_imagelength, rowsperstrip);
7952
0
    if (nstrips == 0)
7953
0
        return;
7954
7955
    /* If we are going to allocate a lot of memory, make sure that the */
7956
    /* file is as big as needed */
7957
0
    if (tif->tif_mode == O_RDONLY && nstrips > 1000000 &&
7958
0
        (offset >= TIFFGetFileSize(tif) ||
7959
0
         stripbytes > (TIFFGetFileSize(tif) - offset) / (nstrips - 1)))
7960
0
    {
7961
0
        return;
7962
0
    }
7963
7964
0
    allocChoppedUpStripArrays(tif, nstrips, stripbytes, rowsperstrip);
7965
0
}
7966
7967
/*
7968
 * Replace a file with contiguous strips > 2 GB of uncompressed data by
7969
 * multiple smaller strips. This is useful for
7970
 * dealing with large images or for dealing with machines with a limited
7971
 * amount memory.
7972
 */
7973
static void TryChopUpUncompressedBigTiff(TIFF *tif)
7974
0
{
7975
0
    TIFFDirectory *td = &tif->tif_dir;
7976
0
    uint32_t rowblock;
7977
0
    uint64_t rowblockbytes;
7978
0
    uint32_t i;
7979
0
    uint64_t stripsize;
7980
0
    uint32_t rowblocksperstrip;
7981
0
    uint32_t rowsperstrip;
7982
0
    uint64_t stripbytes;
7983
0
    uint32_t nstrips;
7984
7985
0
    stripsize = TIFFStripSize64(tif);
7986
7987
0
    assert(tif->tif_dir.td_planarconfig == PLANARCONFIG_CONTIG);
7988
0
    assert(tif->tif_dir.td_compression == COMPRESSION_NONE);
7989
0
    assert((tif->tif_flags & (TIFF_STRIPCHOP | TIFF_ISTILED)) ==
7990
0
           TIFF_STRIPCHOP);
7991
0
    assert(stripsize > 0x7FFFFFFFUL);
7992
7993
    /* On a newly created file, just re-opened to be filled, we */
7994
    /* don't want strip chop to trigger as it is going to cause issues */
7995
    /* later ( StripOffsets and StripByteCounts improperly filled) . */
7996
0
    if (TIFFGetStrileByteCount(tif, 0) == 0 && tif->tif_mode != O_RDONLY)
7997
0
        return;
7998
7999
0
    if ((td->td_photometric == PHOTOMETRIC_YCBCR) && (!isUpSampled(tif)))
8000
0
        rowblock = td->td_ycbcrsubsampling[1];
8001
0
    else
8002
0
        rowblock = 1;
8003
0
    rowblockbytes = TIFFVStripSize64(tif, rowblock);
8004
0
    if (rowblockbytes == 0 || rowblockbytes > 0x7FFFFFFFUL)
8005
0
    {
8006
        /* In case of file with gigantic width */
8007
0
        return;
8008
0
    }
8009
8010
    /* Check that the strips are contiguous and of the expected size */
8011
0
    for (i = 0; i < td->td_nstrips; i++)
8012
0
    {
8013
0
        if (i == td->td_nstrips - 1)
8014
0
        {
8015
0
            if (TIFFGetStrileByteCount(tif, i) <
8016
0
                TIFFVStripSize64(tif,
8017
0
                                 td->td_imagelength - i * td->td_rowsperstrip))
8018
0
            {
8019
0
                return;
8020
0
            }
8021
0
        }
8022
0
        else
8023
0
        {
8024
0
            if (TIFFGetStrileByteCount(tif, i) != stripsize)
8025
0
            {
8026
0
                return;
8027
0
            }
8028
0
            if (i > 0 && TIFFGetStrileOffset(tif, i) !=
8029
0
                             TIFFGetStrileOffset(tif, i - 1) +
8030
0
                                 TIFFGetStrileByteCount(tif, i - 1))
8031
0
            {
8032
0
                return;
8033
0
            }
8034
0
        }
8035
0
    }
8036
8037
    /* Aim for 512 MB strips (that will still be manageable by 32 bit builds */
8038
0
    rowblocksperstrip = (uint32_t)(512 * 1024 * 1024 / rowblockbytes);
8039
0
    if (rowblocksperstrip == 0)
8040
0
        rowblocksperstrip = 1;
8041
0
    rowsperstrip = rowblocksperstrip * rowblock;
8042
0
    stripbytes = rowblocksperstrip * rowblockbytes;
8043
0
    assert(stripbytes <= 0x7FFFFFFFUL);
8044
8045
0
    if (rowsperstrip == 0)
8046
0
        return;
8047
0
    nstrips = TIFFhowmany_32(td->td_imagelength, rowsperstrip);
8048
0
    if (nstrips == 0)
8049
0
        return;
8050
8051
    /* If we are going to allocate a lot of memory, make sure that the */
8052
    /* file is as big as needed */
8053
0
    if (tif->tif_mode == O_RDONLY && nstrips > 1000000)
8054
0
    {
8055
0
        uint64_t last_offset = TIFFGetStrileOffset(tif, td->td_nstrips - 1);
8056
0
        uint64_t filesize = TIFFGetFileSize(tif);
8057
0
        uint64_t last_bytecount =
8058
0
            TIFFGetStrileByteCount(tif, td->td_nstrips - 1);
8059
0
        if (last_offset > filesize || last_bytecount > filesize - last_offset)
8060
0
        {
8061
0
            return;
8062
0
        }
8063
0
    }
8064
8065
0
    allocChoppedUpStripArrays(tif, nstrips, stripbytes, rowsperstrip);
8066
0
}
8067
8068
TIFF_NOSANITIZE_UNSIGNED_INT_OVERFLOW
8069
static uint64_t _TIFFUnsanitizedAddUInt64AndInt(uint64_t a, int b)
8070
0
{
8071
0
    return a + b;
8072
0
}
8073
8074
/* Read the value of [Strip|Tile]Offset or [Strip|Tile]ByteCount around
8075
 * strip/tile of number strile. Also fetch the neighbouring values using a
8076
 * 4096 byte page size.
8077
 */
8078
static int _TIFFPartialReadStripArray(TIFF *tif, TIFFDirEntry *dirent,
8079
                                      int strile, uint64_t *panVals)
8080
0
{
8081
0
    static const char module[] = "_TIFFPartialReadStripArray";
8082
0
#define IO_CACHE_PAGE_SIZE 4096
8083
8084
0
    size_t sizeofval;
8085
0
    const int bSwab = (tif->tif_flags & TIFF_SWAB) != 0;
8086
0
    int sizeofvalint;
8087
0
    uint64_t nBaseOffset;
8088
0
    uint64_t nOffset;
8089
0
    uint64_t nOffsetStartPage;
8090
0
    uint64_t nOffsetEndPage;
8091
0
    tmsize_t nToRead;
8092
0
    tmsize_t nRead;
8093
0
    uint64_t nLastStripOffset;
8094
0
    int iStartBefore;
8095
0
    int i;
8096
0
    const uint32_t arraySize = tif->tif_dir.td_stripoffsetbyteallocsize;
8097
0
    unsigned char buffer[2 * IO_CACHE_PAGE_SIZE];
8098
8099
0
    assert(dirent->tdir_count > 4);
8100
8101
0
    if (dirent->tdir_type == TIFF_SHORT)
8102
0
    {
8103
0
        sizeofval = sizeof(uint16_t);
8104
0
    }
8105
0
    else if (dirent->tdir_type == TIFF_LONG)
8106
0
    {
8107
0
        sizeofval = sizeof(uint32_t);
8108
0
    }
8109
0
    else if (dirent->tdir_type == TIFF_LONG8)
8110
0
    {
8111
0
        sizeofval = sizeof(uint64_t);
8112
0
    }
8113
0
    else if (dirent->tdir_type == TIFF_SLONG8)
8114
0
    {
8115
        /* Non conformant but used by some images as in */
8116
        /* https://github.com/OSGeo/gdal/issues/2165 */
8117
0
        sizeofval = sizeof(int64_t);
8118
0
    }
8119
0
    else
8120
0
    {
8121
0
        TIFFErrorExtR(tif, module,
8122
0
                      "Invalid type for [Strip|Tile][Offset/ByteCount] tag");
8123
0
        panVals[strile] = 0;
8124
0
        return 0;
8125
0
    }
8126
0
    sizeofvalint = (int)(sizeofval);
8127
8128
0
    if (tif->tif_flags & TIFF_BIGTIFF)
8129
0
    {
8130
0
        uint64_t offset = dirent->tdir_offset.toff_long8;
8131
0
        if (bSwab)
8132
0
            TIFFSwabLong8(&offset);
8133
0
        nBaseOffset = offset;
8134
0
    }
8135
0
    else
8136
0
    {
8137
0
        uint32_t offset = dirent->tdir_offset.toff_long;
8138
0
        if (bSwab)
8139
0
            TIFFSwabLong(&offset);
8140
0
        nBaseOffset = offset;
8141
0
    }
8142
    /* To avoid later unsigned integer overflows */
8143
0
    if (nBaseOffset > (uint64_t)INT64_MAX)
8144
0
    {
8145
0
        TIFFErrorExtR(tif, module, "Cannot read offset/size for strile %d",
8146
0
                      strile);
8147
0
        panVals[strile] = 0;
8148
0
        return 0;
8149
0
    }
8150
0
    nOffset = nBaseOffset + sizeofval * strile;
8151
0
    nOffsetStartPage = (nOffset / IO_CACHE_PAGE_SIZE) * IO_CACHE_PAGE_SIZE;
8152
0
    nOffsetEndPage = nOffsetStartPage + IO_CACHE_PAGE_SIZE;
8153
8154
0
    if (nOffset + sizeofval > nOffsetEndPage)
8155
0
        nOffsetEndPage += IO_CACHE_PAGE_SIZE;
8156
0
#undef IO_CACHE_PAGE_SIZE
8157
8158
0
    nLastStripOffset = nBaseOffset + arraySize * sizeofval;
8159
0
    if (nLastStripOffset < nOffsetEndPage)
8160
0
        nOffsetEndPage = nLastStripOffset;
8161
0
    if (nOffsetStartPage >= nOffsetEndPage)
8162
0
    {
8163
0
        TIFFErrorExtR(tif, module, "Cannot read offset/size for strile %d",
8164
0
                      strile);
8165
0
        panVals[strile] = 0;
8166
0
        return 0;
8167
0
    }
8168
0
    if (!SeekOK(tif, nOffsetStartPage))
8169
0
    {
8170
0
        panVals[strile] = 0;
8171
0
        return 0;
8172
0
    }
8173
8174
0
    nToRead = (tmsize_t)(nOffsetEndPage - nOffsetStartPage);
8175
0
    nRead = TIFFReadFile(tif, buffer, nToRead);
8176
0
    if (nRead < nToRead)
8177
0
    {
8178
0
        TIFFErrorExtR(tif, module,
8179
0
                      "Cannot read offset/size for strile around ~%d", strile);
8180
0
        return 0;
8181
0
    }
8182
0
    iStartBefore = -(int)((nOffset - nOffsetStartPage) / sizeofval);
8183
0
    if (strile + iStartBefore < 0)
8184
0
        iStartBefore = -strile;
8185
0
    for (i = iStartBefore;
8186
0
         (uint32_t)(strile + i) < arraySize &&
8187
0
         _TIFFUnsanitizedAddUInt64AndInt(nOffset, (i + 1) * sizeofvalint) <=
8188
0
             nOffsetEndPage;
8189
0
         ++i)
8190
0
    {
8191
0
        if (dirent->tdir_type == TIFF_SHORT)
8192
0
        {
8193
0
            uint16_t val;
8194
0
            memcpy(&val,
8195
0
                   buffer + (nOffset - nOffsetStartPage) + i * sizeofvalint,
8196
0
                   sizeof(val));
8197
0
            if (bSwab)
8198
0
                TIFFSwabShort(&val);
8199
0
            panVals[strile + i] = val;
8200
0
        }
8201
0
        else if (dirent->tdir_type == TIFF_LONG)
8202
0
        {
8203
0
            uint32_t val;
8204
0
            memcpy(&val,
8205
0
                   buffer + (nOffset - nOffsetStartPage) + i * sizeofvalint,
8206
0
                   sizeof(val));
8207
0
            if (bSwab)
8208
0
                TIFFSwabLong(&val);
8209
0
            panVals[strile + i] = val;
8210
0
        }
8211
0
        else if (dirent->tdir_type == TIFF_LONG8)
8212
0
        {
8213
0
            uint64_t val;
8214
0
            memcpy(&val,
8215
0
                   buffer + (nOffset - nOffsetStartPage) + i * sizeofvalint,
8216
0
                   sizeof(val));
8217
0
            if (bSwab)
8218
0
                TIFFSwabLong8(&val);
8219
0
            panVals[strile + i] = val;
8220
0
        }
8221
0
        else /* if( dirent->tdir_type == TIFF_SLONG8 ) */
8222
0
        {
8223
            /* Non conformant data type */
8224
0
            int64_t val;
8225
0
            memcpy(&val,
8226
0
                   buffer + (nOffset - nOffsetStartPage) + i * sizeofvalint,
8227
0
                   sizeof(val));
8228
0
            if (bSwab)
8229
0
                TIFFSwabLong8((uint64_t *)&val);
8230
0
            panVals[strile + i] = (uint64_t)val;
8231
0
        }
8232
0
    }
8233
0
    return 1;
8234
0
}
8235
8236
static int _TIFFFetchStrileValue(TIFF *tif, uint32_t strile,
8237
                                 TIFFDirEntry *dirent, uint64_t **parray)
8238
0
{
8239
0
    static const char module[] = "_TIFFFetchStrileValue";
8240
0
    TIFFDirectory *td = &tif->tif_dir;
8241
0
    if (strile >= dirent->tdir_count)
8242
0
    {
8243
0
        return 0;
8244
0
    }
8245
0
    if (strile >= td->td_stripoffsetbyteallocsize)
8246
0
    {
8247
0
        uint32_t nStripArrayAllocBefore = td->td_stripoffsetbyteallocsize;
8248
0
        uint32_t nStripArrayAllocNew;
8249
0
        uint64_t nArraySize64;
8250
0
        size_t nArraySize;
8251
0
        uint64_t *offsetArray;
8252
0
        uint64_t *bytecountArray;
8253
8254
0
        if (strile > 1000000)
8255
0
        {
8256
0
            uint64_t filesize = TIFFGetFileSize(tif);
8257
            /* Avoid excessive memory allocation attempt */
8258
            /* For such a big blockid we need at least a TIFF_LONG per strile */
8259
            /* for the offset array. */
8260
0
            if (strile > filesize / sizeof(uint32_t))
8261
0
            {
8262
0
                TIFFErrorExtR(tif, module, "File too short");
8263
0
                return 0;
8264
0
            }
8265
0
        }
8266
8267
0
        if (td->td_stripoffsetbyteallocsize == 0 &&
8268
0
            td->td_nstrips < 1024 * 1024)
8269
0
        {
8270
0
            nStripArrayAllocNew = td->td_nstrips;
8271
0
        }
8272
0
        else
8273
0
        {
8274
0
#define TIFF_MAX(a, b) (((a) > (b)) ? (a) : (b))
8275
0
#define TIFF_MIN(a, b) (((a) < (b)) ? (a) : (b))
8276
0
            nStripArrayAllocNew = TIFF_MAX(strile + 1, 1024U * 512U);
8277
0
            if (nStripArrayAllocNew < 0xFFFFFFFFU / 2)
8278
0
                nStripArrayAllocNew *= 2;
8279
0
            nStripArrayAllocNew = TIFF_MIN(nStripArrayAllocNew, td->td_nstrips);
8280
0
        }
8281
0
        assert(strile < nStripArrayAllocNew);
8282
0
        nArraySize64 = (uint64_t)sizeof(uint64_t) * nStripArrayAllocNew;
8283
0
        nArraySize = (size_t)(nArraySize64);
8284
#if SIZEOF_SIZE_T == 4
8285
        if (nArraySize != nArraySize64)
8286
        {
8287
            TIFFErrorExtR(tif, module,
8288
                          "Cannot allocate strip offset and bytecount arrays");
8289
            return 0;
8290
        }
8291
#endif
8292
0
        offsetArray = (uint64_t *)(_TIFFreallocExt(tif, td->td_stripoffset_p,
8293
0
                                                   nArraySize));
8294
0
        bytecountArray = (uint64_t *)(_TIFFreallocExt(
8295
0
            tif, td->td_stripbytecount_p, nArraySize));
8296
0
        if (offsetArray)
8297
0
            td->td_stripoffset_p = offsetArray;
8298
0
        if (bytecountArray)
8299
0
            td->td_stripbytecount_p = bytecountArray;
8300
0
        if (offsetArray && bytecountArray)
8301
0
        {
8302
0
            td->td_stripoffsetbyteallocsize = nStripArrayAllocNew;
8303
            /* Initialize new entries to ~0 / -1 */
8304
            /* coverity[overrun-buffer-arg] */
8305
0
            memset(td->td_stripoffset_p + nStripArrayAllocBefore, 0xFF,
8306
0
                   (td->td_stripoffsetbyteallocsize - nStripArrayAllocBefore) *
8307
0
                       sizeof(uint64_t));
8308
            /* coverity[overrun-buffer-arg] */
8309
0
            memset(td->td_stripbytecount_p + nStripArrayAllocBefore, 0xFF,
8310
0
                   (td->td_stripoffsetbyteallocsize - nStripArrayAllocBefore) *
8311
0
                       sizeof(uint64_t));
8312
0
        }
8313
0
        else
8314
0
        {
8315
0
            TIFFErrorExtR(tif, module,
8316
0
                          "Cannot allocate strip offset and bytecount arrays");
8317
0
            _TIFFfreeExt(tif, td->td_stripoffset_p);
8318
0
            td->td_stripoffset_p = NULL;
8319
0
            _TIFFfreeExt(tif, td->td_stripbytecount_p);
8320
0
            td->td_stripbytecount_p = NULL;
8321
0
            td->td_stripoffsetbyteallocsize = 0;
8322
0
        }
8323
0
    }
8324
0
    if (*parray == NULL || strile >= td->td_stripoffsetbyteallocsize)
8325
0
        return 0;
8326
8327
0
    if (~((*parray)[strile]) == 0)
8328
0
    {
8329
0
        if (!_TIFFPartialReadStripArray(tif, dirent, strile, *parray))
8330
0
        {
8331
0
            (*parray)[strile] = 0;
8332
0
            return 0;
8333
0
        }
8334
0
    }
8335
8336
0
    return 1;
8337
0
}
8338
8339
static uint64_t _TIFFGetStrileOffsetOrByteCountValue(TIFF *tif, uint32_t strile,
8340
                                                     TIFFDirEntry *dirent,
8341
                                                     uint64_t **parray,
8342
                                                     int *pbErr)
8343
0
{
8344
0
    TIFFDirectory *td = &tif->tif_dir;
8345
0
    if (pbErr)
8346
0
        *pbErr = 0;
8347
8348
    /* Check that StripOffsets and StripByteCounts tags have the same number
8349
     * of declared entries. Otherwise we might take the "dirent->tdir_count <=
8350
     * 4" code path for one of them, and the other code path for the other one,
8351
     * which will lead to inconsistencies and potential out-of-bounds reads.
8352
     */
8353
0
    if (td->td_stripoffset_entry.tdir_count !=
8354
0
        td->td_stripbytecount_entry.tdir_count)
8355
0
    {
8356
0
        if (pbErr)
8357
0
            *pbErr = 1;
8358
0
        return 0;
8359
0
    }
8360
8361
0
    if ((tif->tif_flags & TIFF_DEFERSTRILELOAD) &&
8362
0
        !(tif->tif_flags & TIFF_CHOPPEDUPARRAYS))
8363
0
    {
8364
0
        if (!(tif->tif_flags & TIFF_LAZYSTRILELOAD_ASKED) ||
8365
            /* If the values may fit in the toff_long/toff_long8 member */
8366
            /* then use _TIFFFillStriles to simplify _TIFFFetchStrileValue */
8367
0
            dirent->tdir_count <= 4)
8368
0
        {
8369
0
            if (!_TIFFFillStriles(tif))
8370
0
            {
8371
0
                if (pbErr)
8372
0
                    *pbErr = 1;
8373
                /* Do not return, as we want this function to always */
8374
                /* return the same value if called several times with */
8375
                /* the same arguments */
8376
0
            }
8377
0
        }
8378
0
        else
8379
0
        {
8380
0
            if (!_TIFFFetchStrileValue(tif, strile, dirent, parray))
8381
0
            {
8382
0
                if (pbErr)
8383
0
                    *pbErr = 1;
8384
0
                return 0;
8385
0
            }
8386
0
        }
8387
0
    }
8388
0
    if (*parray == NULL || strile >= td->td_nstrips)
8389
0
    {
8390
0
        if (pbErr)
8391
0
            *pbErr = 1;
8392
0
        return 0;
8393
0
    }
8394
0
    return (*parray)[strile];
8395
0
}
8396
8397
/* Return the value of the TileOffsets/StripOffsets array for the specified
8398
 * tile/strile */
8399
uint64_t TIFFGetStrileOffset(TIFF *tif, uint32_t strile)
8400
0
{
8401
0
    return TIFFGetStrileOffsetWithErr(tif, strile, NULL);
8402
0
}
8403
8404
/* Return the value of the TileOffsets/StripOffsets array for the specified
8405
 * tile/strile */
8406
uint64_t TIFFGetStrileOffsetWithErr(TIFF *tif, uint32_t strile, int *pbErr)
8407
0
{
8408
0
    TIFFDirectory *td = &tif->tif_dir;
8409
0
    return _TIFFGetStrileOffsetOrByteCountValue(tif, strile,
8410
0
                                                &(td->td_stripoffset_entry),
8411
0
                                                &(td->td_stripoffset_p), pbErr);
8412
0
}
8413
8414
/* Return the value of the TileByteCounts/StripByteCounts array for the
8415
 * specified tile/strile */
8416
uint64_t TIFFGetStrileByteCount(TIFF *tif, uint32_t strile)
8417
0
{
8418
0
    return TIFFGetStrileByteCountWithErr(tif, strile, NULL);
8419
0
}
8420
8421
/* Return the value of the TileByteCounts/StripByteCounts array for the
8422
 * specified tile/strile */
8423
uint64_t TIFFGetStrileByteCountWithErr(TIFF *tif, uint32_t strile, int *pbErr)
8424
0
{
8425
0
    TIFFDirectory *td = &tif->tif_dir;
8426
0
    return _TIFFGetStrileOffsetOrByteCountValue(
8427
0
        tif, strile, &(td->td_stripbytecount_entry), &(td->td_stripbytecount_p),
8428
0
        pbErr);
8429
0
}
8430
8431
0
int _TIFFFillStriles(TIFF *tif) { return _TIFFFillStrilesInternal(tif, 1); }
8432
8433
static int _TIFFFillStrilesInternal(TIFF *tif, int loadStripByteCount)
8434
0
{
8435
0
    TIFFDirectory *td = &tif->tif_dir;
8436
0
    int return_value = 1;
8437
8438
    /* Do not do anything if TIFF_DEFERSTRILELOAD is not set */
8439
0
    if (!(tif->tif_flags & TIFF_DEFERSTRILELOAD) ||
8440
0
        (tif->tif_flags & TIFF_CHOPPEDUPARRAYS) != 0)
8441
0
        return 1;
8442
8443
0
    if ((tif->tif_flags & TIFF_LAZYSTRILELOAD_ASKED) &&
8444
0
        !(tif->tif_flags & TIFF_LAZYSTRILELOAD_DONE))
8445
0
    {
8446
        /* In case of lazy loading, reload completely the arrays */
8447
0
        _TIFFfreeExt(tif, td->td_stripoffset_p);
8448
0
        _TIFFfreeExt(tif, td->td_stripbytecount_p);
8449
0
        td->td_stripoffset_p = NULL;
8450
0
        td->td_stripbytecount_p = NULL;
8451
0
        td->td_stripoffsetbyteallocsize = 0;
8452
0
        tif->tif_flags |= TIFF_LAZYSTRILELOAD_DONE;
8453
0
    }
8454
8455
    /* If stripoffset array is already loaded, exit with success */
8456
0
    if (td->td_stripoffset_p != NULL)
8457
0
        return 1;
8458
8459
    /* If tdir_count was canceled, then we already got there, but in error */
8460
0
    if (td->td_stripoffset_entry.tdir_count == 0)
8461
0
        return 0;
8462
8463
0
    if (!TIFFFetchStripThing(tif, &(td->td_stripoffset_entry), td->td_nstrips,
8464
0
                             &td->td_stripoffset_p))
8465
0
    {
8466
0
        return_value = 0;
8467
0
    }
8468
8469
0
    if (loadStripByteCount &&
8470
0
        !TIFFFetchStripThing(tif, &(td->td_stripbytecount_entry),
8471
0
                             td->td_nstrips, &td->td_stripbytecount_p))
8472
0
    {
8473
0
        return_value = 0;
8474
0
    }
8475
8476
0
    _TIFFmemset(&(td->td_stripoffset_entry), 0, sizeof(TIFFDirEntry));
8477
0
    _TIFFmemset(&(td->td_stripbytecount_entry), 0, sizeof(TIFFDirEntry));
8478
8479
#ifdef STRIPBYTECOUNTSORTED_UNUSED
8480
    if (tif->tif_dir.td_nstrips > 1 && return_value == 1)
8481
    {
8482
        uint32_t strip;
8483
8484
        tif->tif_dir.td_stripbytecountsorted = 1;
8485
        for (strip = 1; strip < tif->tif_dir.td_nstrips; strip++)
8486
        {
8487
            if (tif->tif_dir.td_stripoffset_p[strip - 1] >
8488
                tif->tif_dir.td_stripoffset_p[strip])
8489
            {
8490
                tif->tif_dir.td_stripbytecountsorted = 0;
8491
                break;
8492
            }
8493
        }
8494
    }
8495
#endif
8496
8497
0
    return return_value;
8498
0
}