Coverage Report

Created: 2025-06-22 06:30

/src/libjpeg-turbo/src/jdinput.c
Line
Count
Source (jump to first uncovered line)
1
/*
2
 * jdinput.c
3
 *
4
 * This file was part of the Independent JPEG Group's software:
5
 * Copyright (C) 1991-1997, Thomas G. Lane.
6
 * Lossless JPEG Modifications:
7
 * Copyright (C) 1999, Ken Murchison.
8
 * libjpeg-turbo Modifications:
9
 * Copyright (C) 2010, 2016, 2018, 2022, 2024, D. R. Commander.
10
 * Copyright (C) 2015, Google, Inc.
11
 * For conditions of distribution and use, see the accompanying README.ijg
12
 * file.
13
 *
14
 * This file contains input control logic for the JPEG decompressor.
15
 * These routines are concerned with controlling the decompressor's input
16
 * processing (marker reading and coefficient/difference decoding).
17
 * The actual input reading is done in jdmarker.c, jdhuff.c, jdphuff.c,
18
 * and jdlhuff.c.
19
 */
20
21
#define JPEG_INTERNALS
22
#include "jinclude.h"
23
#include "jpeglib.h"
24
#include "jpegapicomp.h"
25
26
27
/* Private state */
28
29
typedef struct {
30
  struct jpeg_input_controller pub; /* public fields */
31
32
  boolean inheaders;            /* TRUE until first SOS is reached */
33
} my_input_controller;
34
35
typedef my_input_controller *my_inputctl_ptr;
36
37
38
/* Forward declarations */
39
METHODDEF(int) consume_markers(j_decompress_ptr cinfo);
40
41
42
/*
43
 * Routines to calculate various quantities related to the size of the image.
44
 */
45
46
LOCAL(void)
47
initial_setup(j_decompress_ptr cinfo)
48
/* Called once, when first SOS marker is reached */
49
4.90k
{
50
4.90k
  int ci;
51
4.90k
  jpeg_component_info *compptr;
52
4.90k
  int data_unit = cinfo->master->lossless ? 1 : DCTSIZE;
53
54
  /* Make sure image isn't bigger than I can handle */
55
4.90k
  if ((long)cinfo->image_height > (long)JPEG_MAX_DIMENSION ||
56
4.90k
      (long)cinfo->image_width > (long)JPEG_MAX_DIMENSION)
57
10
    ERREXIT1(cinfo, JERR_IMAGE_TOO_BIG, (unsigned int)JPEG_MAX_DIMENSION);
58
59
  /* Lossy JPEG images must have 8 or 12 bits per sample.  Lossless JPEG images
60
   * can have 2 to 16 bits per sample.
61
   */
62
4.90k
#ifdef D_LOSSLESS_SUPPORTED
63
4.90k
  if (cinfo->master->lossless) {
64
1.13k
    if (cinfo->data_precision < 2 || cinfo->data_precision > 16)
65
7
      ERREXIT1(cinfo, JERR_BAD_PRECISION, cinfo->data_precision);
66
1.13k
  } else
67
3.76k
#endif
68
3.76k
  {
69
3.76k
    if (cinfo->data_precision != 8 && cinfo->data_precision != 12)
70
7
      ERREXIT1(cinfo, JERR_BAD_PRECISION, cinfo->data_precision);
71
3.76k
  }
72
73
  /* Check that number of components won't exceed internal array sizes */
74
4.90k
  if (cinfo->num_components > MAX_COMPONENTS)
75
0
    ERREXIT2(cinfo, JERR_COMPONENT_COUNT, cinfo->num_components,
76
4.90k
             MAX_COMPONENTS);
77
78
  /* Compute maximum sampling factors; check factor validity */
79
4.90k
  cinfo->max_h_samp_factor = 1;
80
4.90k
  cinfo->max_v_samp_factor = 1;
81
18.0k
  for (ci = 0, compptr = cinfo->comp_info; ci < cinfo->num_components;
82
13.1k
       ci++, compptr++) {
83
13.1k
    if (compptr->h_samp_factor <= 0 ||
84
13.1k
        compptr->h_samp_factor > MAX_SAMP_FACTOR ||
85
13.1k
        compptr->v_samp_factor <= 0 ||
86
13.1k
        compptr->v_samp_factor > MAX_SAMP_FACTOR)
87
24
      ERREXIT(cinfo, JERR_BAD_SAMPLING);
88
13.1k
    cinfo->max_h_samp_factor = MAX(cinfo->max_h_samp_factor,
89
13.1k
                                   compptr->h_samp_factor);
90
13.1k
    cinfo->max_v_samp_factor = MAX(cinfo->max_v_samp_factor,
91
13.1k
                                   compptr->v_samp_factor);
92
13.1k
  }
93
94
#if JPEG_LIB_VERSION >= 80
95
  cinfo->block_size = data_unit;
96
  cinfo->natural_order = jpeg_natural_order;
97
  cinfo->lim_Se = DCTSIZE2 - 1;
98
#endif
99
100
  /* We initialize DCT_scaled_size and min_DCT_scaled_size to DCTSIZE in lossy
101
   * mode.  In the full decompressor, this will be overridden by jdmaster.c;
102
   * but in the transcoder, jdmaster.c is not used, so we must do it here.
103
   */
104
#if JPEG_LIB_VERSION >= 70
105
  cinfo->min_DCT_h_scaled_size = cinfo->min_DCT_v_scaled_size = data_unit;
106
#else
107
4.90k
  cinfo->min_DCT_scaled_size = data_unit;
108
4.90k
#endif
109
110
  /* Compute dimensions of components */
111
17.9k
  for (ci = 0, compptr = cinfo->comp_info; ci < cinfo->num_components;
112
13.0k
       ci++, compptr++) {
113
#if JPEG_LIB_VERSION >= 70
114
    compptr->DCT_h_scaled_size = compptr->DCT_v_scaled_size = data_unit;
115
#else
116
13.0k
    compptr->DCT_scaled_size = data_unit;
117
13.0k
#endif
118
    /* Size in data units */
119
13.0k
    compptr->width_in_blocks = (JDIMENSION)
120
13.0k
      jdiv_round_up((long)cinfo->image_width * (long)compptr->h_samp_factor,
121
13.0k
                    (long)(cinfo->max_h_samp_factor * data_unit));
122
13.0k
    compptr->height_in_blocks = (JDIMENSION)
123
13.0k
      jdiv_round_up((long)cinfo->image_height * (long)compptr->v_samp_factor,
124
13.0k
                    (long)(cinfo->max_v_samp_factor * data_unit));
125
    /* Set the first and last MCU columns to decompress from multi-scan images.
126
     * By default, decompress all of the MCU columns.
127
     */
128
13.0k
    cinfo->master->first_MCU_col[ci] = 0;
129
13.0k
    cinfo->master->last_MCU_col[ci] = compptr->width_in_blocks - 1;
130
    /* downsampled_width and downsampled_height will also be overridden by
131
     * jdmaster.c if we are doing full decompression.  The transcoder library
132
     * doesn't use these values, but the calling application might.
133
     */
134
    /* Size in samples */
135
13.0k
    compptr->downsampled_width = (JDIMENSION)
136
13.0k
      jdiv_round_up((long)cinfo->image_width * (long)compptr->h_samp_factor,
137
13.0k
                    (long)cinfo->max_h_samp_factor);
138
13.0k
    compptr->downsampled_height = (JDIMENSION)
139
13.0k
      jdiv_round_up((long)cinfo->image_height * (long)compptr->v_samp_factor,
140
13.0k
                    (long)cinfo->max_v_samp_factor);
141
    /* Mark component needed, until color conversion says otherwise */
142
13.0k
    compptr->component_needed = TRUE;
143
    /* Mark no quantization table yet saved for component */
144
13.0k
    compptr->quant_table = NULL;
145
13.0k
  }
146
147
  /* Compute number of fully interleaved MCU rows. */
148
4.90k
  cinfo->total_iMCU_rows = (JDIMENSION)
149
4.90k
    jdiv_round_up((long)cinfo->image_height,
150
4.90k
                  (long)(cinfo->max_v_samp_factor * data_unit));
151
152
  /* Decide whether file contains multiple scans */
153
4.90k
  if (cinfo->comps_in_scan < cinfo->num_components || cinfo->progressive_mode)
154
2.97k
    cinfo->inputctl->has_multiple_scans = TRUE;
155
1.93k
  else
156
1.93k
    cinfo->inputctl->has_multiple_scans = FALSE;
157
4.90k
}
158
159
160
LOCAL(void)
161
per_scan_setup(j_decompress_ptr cinfo)
162
/* Do computations that are needed before processing a JPEG scan */
163
/* cinfo->comps_in_scan and cinfo->cur_comp_info[] were set from SOS marker */
164
6.81k
{
165
6.81k
  int ci, mcublks, tmp;
166
6.81k
  jpeg_component_info *compptr;
167
6.81k
  int data_unit = cinfo->master->lossless ? 1 : DCTSIZE;
168
169
6.81k
  if (cinfo->comps_in_scan == 1) {
170
171
    /* Noninterleaved (single-component) scan */
172
3.85k
    compptr = cinfo->cur_comp_info[0];
173
174
    /* Overall image size in MCUs */
175
3.85k
    cinfo->MCUs_per_row = compptr->width_in_blocks;
176
3.85k
    cinfo->MCU_rows_in_scan = compptr->height_in_blocks;
177
178
    /* For noninterleaved scan, always one data unit per MCU */
179
3.85k
    compptr->MCU_width = 1;
180
3.85k
    compptr->MCU_height = 1;
181
3.85k
    compptr->MCU_blocks = 1;
182
3.85k
    compptr->MCU_sample_width = compptr->_DCT_scaled_size;
183
3.85k
    compptr->last_col_width = 1;
184
    /* For noninterleaved scans, it is convenient to define last_row_height
185
     * as the number of data unit rows present in the last iMCU row.
186
     */
187
3.85k
    tmp = (int)(compptr->height_in_blocks % compptr->v_samp_factor);
188
3.85k
    if (tmp == 0) tmp = compptr->v_samp_factor;
189
3.85k
    compptr->last_row_height = tmp;
190
191
    /* Prepare array describing MCU composition */
192
3.85k
    cinfo->blocks_in_MCU = 1;
193
3.85k
    cinfo->MCU_membership[0] = 0;
194
195
3.85k
  } else {
196
197
    /* Interleaved (multi-component) scan */
198
2.96k
    if (cinfo->comps_in_scan <= 0 || cinfo->comps_in_scan > MAX_COMPS_IN_SCAN)
199
0
      ERREXIT2(cinfo, JERR_COMPONENT_COUNT, cinfo->comps_in_scan,
200
2.96k
               MAX_COMPS_IN_SCAN);
201
202
    /* Overall image size in MCUs */
203
2.96k
    cinfo->MCUs_per_row = (JDIMENSION)
204
2.96k
      jdiv_round_up((long)cinfo->image_width,
205
2.96k
                    (long)(cinfo->max_h_samp_factor * data_unit));
206
2.96k
    cinfo->MCU_rows_in_scan = (JDIMENSION)
207
2.96k
      jdiv_round_up((long)cinfo->image_height,
208
2.96k
                    (long)(cinfo->max_v_samp_factor * data_unit));
209
210
2.96k
    cinfo->blocks_in_MCU = 0;
211
212
14.3k
    for (ci = 0; ci < cinfo->comps_in_scan; ci++) {
213
11.4k
      compptr = cinfo->cur_comp_info[ci];
214
      /* Sampling factors give # of data units of component in each MCU */
215
11.4k
      compptr->MCU_width = compptr->h_samp_factor;
216
11.4k
      compptr->MCU_height = compptr->v_samp_factor;
217
11.4k
      compptr->MCU_blocks = compptr->MCU_width * compptr->MCU_height;
218
11.4k
      compptr->MCU_sample_width = compptr->MCU_width *
219
11.4k
                                  compptr->_DCT_scaled_size;
220
      /* Figure number of non-dummy data units in last MCU column & row */
221
11.4k
      tmp = (int)(compptr->width_in_blocks % compptr->MCU_width);
222
11.4k
      if (tmp == 0) tmp = compptr->MCU_width;
223
11.4k
      compptr->last_col_width = tmp;
224
11.4k
      tmp = (int)(compptr->height_in_blocks % compptr->MCU_height);
225
11.4k
      if (tmp == 0) tmp = compptr->MCU_height;
226
11.4k
      compptr->last_row_height = tmp;
227
      /* Prepare array describing MCU composition */
228
11.4k
      mcublks = compptr->MCU_blocks;
229
11.4k
      if (cinfo->blocks_in_MCU + mcublks > D_MAX_BLOCKS_IN_MCU)
230
16
        ERREXIT(cinfo, JERR_BAD_MCU_SIZE);
231
28.1k
      while (mcublks-- > 0) {
232
16.7k
        cinfo->MCU_membership[cinfo->blocks_in_MCU++] = ci;
233
16.7k
      }
234
11.4k
    }
235
236
2.96k
  }
237
6.81k
}
238
239
240
/*
241
 * Save away a copy of the Q-table referenced by each component present
242
 * in the current scan, unless already saved during a prior scan.
243
 *
244
 * In a multiple-scan JPEG file, the encoder could assign different components
245
 * the same Q-table slot number, but change table definitions between scans
246
 * so that each component uses a different Q-table.  (The IJG encoder is not
247
 * currently capable of doing this, but other encoders might.)  Since we want
248
 * to be able to dequantize all the components at the end of the file, this
249
 * means that we have to save away the table actually used for each component.
250
 * We do this by copying the table at the start of the first scan containing
251
 * the component.
252
 * Rec. ITU-T T.81 | ISO/IEC 10918-1 prohibits the encoder from changing the
253
 * contents of a Q-table slot between scans of a component using that slot.  If
254
 * the encoder does so anyway, this decoder will simply use the Q-table values
255
 * that were current at the start of the first scan for the component.
256
 *
257
 * The decompressor output side looks only at the saved quant tables,
258
 * not at the current Q-table slots.
259
 */
260
261
LOCAL(void)
262
latch_quant_tables(j_decompress_ptr cinfo)
263
5.74k
{
264
5.74k
  int ci, qtblno;
265
5.74k
  jpeg_component_info *compptr;
266
5.74k
  JQUANT_TBL *qtbl;
267
268
19.4k
  for (ci = 0; ci < cinfo->comps_in_scan; ci++) {
269
13.6k
    compptr = cinfo->cur_comp_info[ci];
270
    /* No work if we already saved Q-table for this component */
271
13.6k
    if (compptr->quant_table != NULL)
272
4.62k
      continue;
273
    /* Make sure specified quantization table is present */
274
9.03k
    qtblno = compptr->quant_tbl_no;
275
9.03k
    if (qtblno < 0 || qtblno >= NUM_QUANT_TBLS ||
276
9.03k
        cinfo->quant_tbl_ptrs[qtblno] == NULL)
277
24
      ERREXIT1(cinfo, JERR_NO_QUANT_TABLE, qtblno);
278
    /* OK, save away the quantization table */
279
9.03k
    qtbl = (JQUANT_TBL *)
280
9.03k
      (*cinfo->mem->alloc_small) ((j_common_ptr)cinfo, JPOOL_IMAGE,
281
9.03k
                                  sizeof(JQUANT_TBL));
282
9.03k
    memcpy(qtbl, cinfo->quant_tbl_ptrs[qtblno], sizeof(JQUANT_TBL));
283
9.03k
    compptr->quant_table = qtbl;
284
9.03k
  }
285
5.74k
}
286
287
288
/*
289
 * Initialize the input modules to read a scan of compressed data.
290
 * The first call to this is done by jdmaster.c after initializing
291
 * the entire decompressor (during jpeg_start_decompress).
292
 * Subsequent calls come from consume_markers, below.
293
 */
294
295
METHODDEF(void)
296
start_input_pass(j_decompress_ptr cinfo)
297
6.81k
{
298
6.81k
  per_scan_setup(cinfo);
299
6.81k
  if (!cinfo->master->lossless)
300
5.74k
    latch_quant_tables(cinfo);
301
6.81k
  (*cinfo->entropy->start_pass) (cinfo);
302
6.81k
  (*cinfo->coef->start_input_pass) (cinfo);
303
6.81k
  cinfo->inputctl->consume_input = cinfo->coef->consume_data;
304
6.81k
}
305
306
307
/*
308
 * Finish up after inputting a compressed-data scan.
309
 * This is called by the coefficient or difference controller after it's read
310
 * all the expected data of the scan.
311
 */
312
313
METHODDEF(void)
314
finish_input_pass(j_decompress_ptr cinfo)
315
4.61k
{
316
4.61k
  cinfo->inputctl->consume_input = consume_markers;
317
4.61k
}
318
319
320
/*
321
 * Read JPEG markers before, between, or after compressed-data scans.
322
 * Change state as necessary when a new scan is reached.
323
 * Return value is JPEG_SUSPENDED, JPEG_REACHED_SOS, or JPEG_REACHED_EOI.
324
 *
325
 * The consume_input method pointer points either here or to the
326
 * coefficient or difference controller's consume_data routine, depending on
327
 * whether we are reading a compressed data segment or inter-segment markers.
328
 */
329
330
METHODDEF(int)
331
consume_markers(j_decompress_ptr cinfo)
332
10.6k
{
333
10.6k
  my_inputctl_ptr inputctl = (my_inputctl_ptr)cinfo->inputctl;
334
10.6k
  int val;
335
336
10.6k
  if (inputctl->pub.eoi_reached) /* After hitting EOI, read no further */
337
0
    return JPEG_REACHED_EOI;
338
339
10.6k
  val = (*cinfo->marker->read_markers) (cinfo);
340
341
10.6k
  switch (val) {
342
6.99k
  case JPEG_REACHED_SOS:        /* Found SOS */
343
6.99k
    if (inputctl->inheaders) {  /* 1st SOS */
344
4.90k
      initial_setup(cinfo);
345
4.90k
      inputctl->inheaders = FALSE;
346
      /* Note: start_input_pass must be called by jdmaster.c
347
       * before any more input can be consumed.  jdapimin.c is
348
       * responsible for enforcing this sequencing.
349
       */
350
4.90k
    } else {                    /* 2nd or later SOS marker */
351
2.08k
      if (!inputctl->pub.has_multiple_scans)
352
5
        ERREXIT(cinfo, JERR_EOI_EXPECTED); /* Oops, I wasn't expecting this! */
353
2.08k
      start_input_pass(cinfo);
354
2.08k
    }
355
6.99k
    break;
356
2.18k
  case JPEG_REACHED_EOI:        /* Found EOI */
357
2.18k
    inputctl->pub.eoi_reached = TRUE;
358
2.18k
    if (inputctl->inheaders) {  /* Tables-only datastream, apparently */
359
39
      if (cinfo->marker->saw_SOF)
360
24
        ERREXIT(cinfo, JERR_SOF_NO_SOS);
361
2.15k
    } else {
362
      /* Prevent infinite loop in coef ctlr's decompress_data routine
363
       * if user set output_scan_number larger than number of scans.
364
       */
365
2.15k
      if (cinfo->output_scan_number > cinfo->input_scan_number)
366
0
        cinfo->output_scan_number = cinfo->input_scan_number;
367
2.15k
    }
368
2.18k
    break;
369
0
  case JPEG_SUSPENDED:
370
0
    break;
371
10.6k
  }
372
373
9.07k
  return val;
374
10.6k
}
375
376
377
/*
378
 * Reset state to begin a fresh datastream.
379
 */
380
381
METHODDEF(void)
382
reset_input_controller(j_decompress_ptr cinfo)
383
6.08k
{
384
6.08k
  my_inputctl_ptr inputctl = (my_inputctl_ptr)cinfo->inputctl;
385
386
6.08k
  inputctl->pub.consume_input = consume_markers;
387
6.08k
  inputctl->pub.has_multiple_scans = FALSE; /* "unknown" would be better */
388
6.08k
  inputctl->pub.eoi_reached = FALSE;
389
6.08k
  inputctl->inheaders = TRUE;
390
  /* Reset other modules */
391
6.08k
  (*cinfo->err->reset_error_mgr) ((j_common_ptr)cinfo);
392
6.08k
  (*cinfo->marker->reset_marker_reader) (cinfo);
393
  /* Reset progression state -- would be cleaner if entropy decoder did this */
394
6.08k
  cinfo->coef_bits = NULL;
395
6.08k
}
396
397
398
/*
399
 * Initialize the input controller module.
400
 * This is called only once, when the decompression object is created.
401
 */
402
403
GLOBAL(void)
404
jinit_input_controller(j_decompress_ptr cinfo)
405
6.08k
{
406
6.08k
  my_inputctl_ptr inputctl;
407
408
  /* Create subobject in permanent pool */
409
6.08k
  inputctl = (my_inputctl_ptr)
410
6.08k
    (*cinfo->mem->alloc_small) ((j_common_ptr)cinfo, JPOOL_PERMANENT,
411
6.08k
                                sizeof(my_input_controller));
412
6.08k
  cinfo->inputctl = (struct jpeg_input_controller *)inputctl;
413
  /* Initialize method pointers */
414
6.08k
  inputctl->pub.consume_input = consume_markers;
415
6.08k
  inputctl->pub.reset_input_controller = reset_input_controller;
416
6.08k
  inputctl->pub.start_input_pass = start_input_pass;
417
6.08k
  inputctl->pub.finish_input_pass = finish_input_pass;
418
  /* Initialize state: can't use reset_input_controller since we don't
419
   * want to try to reset other modules yet.
420
   */
421
6.08k
  inputctl->pub.has_multiple_scans = FALSE; /* "unknown" would be better */
422
6.08k
  inputctl->pub.eoi_reached = FALSE;
423
6.08k
  inputctl->inheaders = TRUE;
424
6.08k
}