1 2 /* pngpread.c - read a png file in push mode 3 * 4 * Last changed in libpng 1.6.24 [August 4, 2016] 5 * Copyright (c) 1998-2002,2004,2006-2016 Glenn Randers-Pehrson 6 * (Version 0.96 Copyright (c) 1996, 1997 Andreas Dilger) 7 * (Version 0.88 Copyright (c) 1995, 1996 Guy Eric Schalnat, Group 42, Inc.) 8 * 9 * This code is released under the libpng license. 10 * For conditions of distribution and use, see the disclaimer 11 * and license in png.h 12 */ 13 14 #include "pngpriv.h" 15 16 #ifdef PNG_PROGRESSIVE_READ_SUPPORTED 17 18 /* Push model modes */ 19 #define PNG_READ_SIG_MODE 0 20 #define PNG_READ_CHUNK_MODE 1 21 #define PNG_READ_IDAT_MODE 2 22 #define PNG_READ_tEXt_MODE 4 23 #define PNG_READ_zTXt_MODE 5 24 #define PNG_READ_DONE_MODE 6 25 #define PNG_READ_iTXt_MODE 7 26 #define PNG_ERROR_MODE 8 27 28 #define PNG_PUSH_SAVE_BUFFER_IF_FULL \ 29 if (png_ptr->push_length + 4 > png_ptr->buffer_size) \ 30 { png_push_save_buffer(png_ptr); return; } 31 #define PNG_PUSH_SAVE_BUFFER_IF_LT(N) \ 32 if (png_ptr->buffer_size < N) \ 33 { png_push_save_buffer(png_ptr); return; } 34 35 void PNGAPI 36 png_process_data(png_structrp png_ptr, png_inforp info_ptr, 37 png_bytep buffer, png_size_t buffer_size) 38 { 39 if (png_ptr == NULL || info_ptr == NULL) 40 return; 41 42 png_push_restore_buffer(png_ptr, buffer, buffer_size); 43 44 while (png_ptr->buffer_size) 45 { 46 png_process_some_data(png_ptr, info_ptr); 47 } 48 } 49 50 png_size_t PNGAPI 51 png_process_data_pause(png_structrp png_ptr, int save) 52 { 53 if (png_ptr != NULL) 54 { 55 /* It's easiest for the caller if we do the save; then the caller doesn't 56 * have to supply the same data again: 57 */ 58 if (save != 0) 59 png_push_save_buffer(png_ptr); 60 else 61 { 62 /* This includes any pending saved bytes: */ 63 png_size_t remaining = png_ptr->buffer_size; 64 png_ptr->buffer_size = 0; 65 66 /* So subtract the saved buffer size, unless all the data 67 * is actually 'saved', in which case we just return 0 68 */ 69 if (png_ptr->save_buffer_size < remaining) 70 return remaining - png_ptr->save_buffer_size; 71 } 72 } 73 74 return 0; 75 } 76 77 png_uint_32 PNGAPI 78 png_process_data_skip(png_structrp png_ptr) 79 { 80 /* TODO: Deprecate and remove this API. 81 * Somewhere the implementation of this seems to have been lost, 82 * or abandoned. It was only to support some internal back-door access 83 * to png_struct) in libpng-1.4.x. 84 */ 85 png_app_warning(png_ptr, 86 "png_process_data_skip is not implemented in any current version of libpng"); 87 return 0; 88 } 89 90 /* What we do with the incoming data depends on what we were previously 91 * doing before we ran out of data... 92 */ 93 void /* PRIVATE */ 94 png_process_some_data(png_structrp png_ptr, png_inforp info_ptr) 95 { 96 if (png_ptr == NULL) 97 return; 98 99 switch (png_ptr->process_mode) 100 { 101 case PNG_READ_SIG_MODE: 102 { 103 png_push_read_sig(png_ptr, info_ptr); 104 break; 105 } 106 107 case PNG_READ_CHUNK_MODE: 108 { 109 png_push_read_chunk(png_ptr, info_ptr); 110 break; 111 } 112 113 case PNG_READ_IDAT_MODE: 114 { 115 png_push_read_IDAT(png_ptr); 116 break; 117 } 118 119 default: 120 { 121 png_ptr->buffer_size = 0; 122 break; 123 } 124 } 125 } 126 127 /* Read any remaining signature bytes from the stream and compare them with 128 * the correct PNG signature. It is possible that this routine is called 129 * with bytes already read from the signature, either because they have been 130 * checked by the calling application, or because of multiple calls to this 131 * routine. 132 */ 133 void /* PRIVATE */ 134 png_push_read_sig(png_structrp png_ptr, png_inforp info_ptr) 135 { 136 png_size_t num_checked = png_ptr->sig_bytes, /* SAFE, does not exceed 8 */ 137 num_to_check = 8 - num_checked; 138 139 if (png_ptr->buffer_size < num_to_check) 140 { 141 num_to_check = png_ptr->buffer_size; 142 } 143 144 png_push_fill_buffer(png_ptr, &(info_ptr->signature[num_checked]), 145 num_to_check); 146 png_ptr->sig_bytes = (png_byte)(png_ptr->sig_bytes + num_to_check); 147 148 if (png_sig_cmp(info_ptr->signature, num_checked, num_to_check)) 149 { 150 if (num_checked < 4 && 151 png_sig_cmp(info_ptr->signature, num_checked, num_to_check - 4)) 152 png_error(png_ptr, "Not a PNG file"); 153 154 else 155 png_error(png_ptr, "PNG file corrupted by ASCII conversion"); 156 } 157 else 158 { 159 if (png_ptr->sig_bytes >= 8) 160 { 161 png_ptr->process_mode = PNG_READ_CHUNK_MODE; 162 } 163 } 164 } 165 166 void /* PRIVATE */ 167 png_push_read_chunk(png_structrp png_ptr, png_inforp info_ptr) 168 { 169 png_uint_32 chunk_name; 170 #ifdef PNG_HANDLE_AS_UNKNOWN_SUPPORTED 171 int keep; /* unknown handling method */ 172 #endif 173 174 /* First we make sure we have enough data for the 4-byte chunk name 175 * and the 4-byte chunk length before proceeding with decoding the 176 * chunk data. To fully decode each of these chunks, we also make 177 * sure we have enough data in the buffer for the 4-byte CRC at the 178 * end of every chunk (except IDAT, which is handled separately). 179 */ 180 if ((png_ptr->mode & PNG_HAVE_CHUNK_HEADER) == 0) 181 { 182 png_byte chunk_length[4]; 183 png_byte chunk_tag[4]; 184 185 PNG_PUSH_SAVE_BUFFER_IF_LT(8) 186 png_push_fill_buffer(png_ptr, chunk_length, 4); 187 png_ptr->push_length = png_get_uint_31(png_ptr, chunk_length); 188 png_reset_crc(png_ptr); 189 png_crc_read(png_ptr, chunk_tag, 4); 190 png_ptr->chunk_name = PNG_CHUNK_FROM_STRING(chunk_tag); 191 png_check_chunk_name(png_ptr, png_ptr->chunk_name); 192 png_ptr->mode |= PNG_HAVE_CHUNK_HEADER; 193 } 194 195 chunk_name = png_ptr->chunk_name; 196 197 if (chunk_name == png_IDAT) 198 { 199 if ((png_ptr->mode & PNG_AFTER_IDAT) != 0) 200 png_ptr->mode |= PNG_HAVE_CHUNK_AFTER_IDAT; 201 202 /* If we reach an IDAT chunk, this means we have read all of the 203 * header chunks, and we can start reading the image (or if this 204 * is called after the image has been read - we have an error). 205 */ 206 if ((png_ptr->mode & PNG_HAVE_IHDR) == 0) 207 png_error(png_ptr, "Missing IHDR before IDAT"); 208 209 else if (png_ptr->color_type == PNG_COLOR_TYPE_PALETTE && 210 (png_ptr->mode & PNG_HAVE_PLTE) == 0) 211 png_error(png_ptr, "Missing PLTE before IDAT"); 212 213 png_ptr->process_mode = PNG_READ_IDAT_MODE; 214 215 if ((png_ptr->mode & PNG_HAVE_IDAT) != 0) 216 if ((png_ptr->mode & PNG_HAVE_CHUNK_AFTER_IDAT) == 0) 217 if (png_ptr->push_length == 0) 218 return; 219 220 png_ptr->mode |= PNG_HAVE_IDAT; 221 222 if ((png_ptr->mode & PNG_AFTER_IDAT) != 0) 223 png_benign_error(png_ptr, "Too many IDATs found"); 224 } 225 226 if (chunk_name == png_IHDR) 227 { 228 if (png_ptr->push_length != 13) 229 png_error(png_ptr, "Invalid IHDR length"); 230 231 PNG_PUSH_SAVE_BUFFER_IF_FULL 232 png_handle_IHDR(png_ptr, info_ptr, png_ptr->push_length); 233 } 234 235 else if (chunk_name == png_IEND) 236 { 237 PNG_PUSH_SAVE_BUFFER_IF_FULL 238 png_handle_IEND(png_ptr, info_ptr, png_ptr->push_length); 239 240 png_ptr->process_mode = PNG_READ_DONE_MODE; 241 png_push_have_end(png_ptr, info_ptr); 242 } 243 244 #ifdef PNG_HANDLE_AS_UNKNOWN_SUPPORTED 245 else if ((keep = png_chunk_unknown_handling(png_ptr, chunk_name)) != 0) 246 { 247 PNG_PUSH_SAVE_BUFFER_IF_FULL 248 png_handle_unknown(png_ptr, info_ptr, png_ptr->push_length, keep); 249 250 if (chunk_name == png_PLTE) 251 png_ptr->mode |= PNG_HAVE_PLTE; 252 } 253 #endif 254 255 else if (chunk_name == png_PLTE) 256 { 257 PNG_PUSH_SAVE_BUFFER_IF_FULL 258 png_handle_PLTE(png_ptr, info_ptr, png_ptr->push_length); 259 } 260 261 else if (chunk_name == png_IDAT) 262 { 263 png_ptr->idat_size = png_ptr->push_length; 264 png_ptr->process_mode = PNG_READ_IDAT_MODE; 265 png_push_have_info(png_ptr, info_ptr); 266 png_ptr->zstream.avail_out = 267 (uInt) PNG_ROWBYTES(png_ptr->pixel_depth, 268 png_ptr->iwidth) + 1; 269 png_ptr->zstream.next_out = png_ptr->row_buf; 270 return; 271 } 272 273 #ifdef PNG_READ_gAMA_SUPPORTED 274 else if (png_ptr->chunk_name == png_gAMA) 275 { 276 PNG_PUSH_SAVE_BUFFER_IF_FULL 277 png_handle_gAMA(png_ptr, info_ptr, png_ptr->push_length); 278 } 279 280 #endif 281 #ifdef PNG_READ_sBIT_SUPPORTED 282 else if (png_ptr->chunk_name == png_sBIT) 283 { 284 PNG_PUSH_SAVE_BUFFER_IF_FULL 285 png_handle_sBIT(png_ptr, info_ptr, png_ptr->push_length); 286 } 287 288 #endif 289 #ifdef PNG_READ_cHRM_SUPPORTED 290 else if (png_ptr->chunk_name == png_cHRM) 291 { 292 PNG_PUSH_SAVE_BUFFER_IF_FULL 293 png_handle_cHRM(png_ptr, info_ptr, png_ptr->push_length); 294 } 295 296 #endif 297 #ifdef PNG_READ_sRGB_SUPPORTED 298 else if (chunk_name == png_sRGB) 299 { 300 PNG_PUSH_SAVE_BUFFER_IF_FULL 301 png_handle_sRGB(png_ptr, info_ptr, png_ptr->push_length); 302 } 303 304 #endif 305 #ifdef PNG_READ_iCCP_SUPPORTED 306 else if (png_ptr->chunk_name == png_iCCP) 307 { 308 PNG_PUSH_SAVE_BUFFER_IF_FULL 309 png_handle_iCCP(png_ptr, info_ptr, png_ptr->push_length); 310 } 311 312 #endif 313 #ifdef PNG_READ_sPLT_SUPPORTED 314 else if (chunk_name == png_sPLT) 315 { 316 PNG_PUSH_SAVE_BUFFER_IF_FULL 317 png_handle_sPLT(png_ptr, info_ptr, png_ptr->push_length); 318 } 319 320 #endif 321 #ifdef PNG_READ_tRNS_SUPPORTED 322 else if (chunk_name == png_tRNS) 323 { 324 PNG_PUSH_SAVE_BUFFER_IF_FULL 325 png_handle_tRNS(png_ptr, info_ptr, png_ptr->push_length); 326 } 327 328 #endif 329 #ifdef PNG_READ_bKGD_SUPPORTED 330 else if (chunk_name == png_bKGD) 331 { 332 PNG_PUSH_SAVE_BUFFER_IF_FULL 333 png_handle_bKGD(png_ptr, info_ptr, png_ptr->push_length); 334 } 335 336 #endif 337 #ifdef PNG_READ_hIST_SUPPORTED 338 else if (chunk_name == png_hIST) 339 { 340 PNG_PUSH_SAVE_BUFFER_IF_FULL 341 png_handle_hIST(png_ptr, info_ptr, png_ptr->push_length); 342 } 343 344 #endif 345 #ifdef PNG_READ_pHYs_SUPPORTED 346 else if (chunk_name == png_pHYs) 347 { 348 PNG_PUSH_SAVE_BUFFER_IF_FULL 349 png_handle_pHYs(png_ptr, info_ptr, png_ptr->push_length); 350 } 351 352 #endif 353 #ifdef PNG_READ_oFFs_SUPPORTED 354 else if (chunk_name == png_oFFs) 355 { 356 PNG_PUSH_SAVE_BUFFER_IF_FULL 357 png_handle_oFFs(png_ptr, info_ptr, png_ptr->push_length); 358 } 359 #endif 360 361 #ifdef PNG_READ_pCAL_SUPPORTED 362 else if (chunk_name == png_pCAL) 363 { 364 PNG_PUSH_SAVE_BUFFER_IF_FULL 365 png_handle_pCAL(png_ptr, info_ptr, png_ptr->push_length); 366 } 367 368 #endif 369 #ifdef PNG_READ_sCAL_SUPPORTED 370 else if (chunk_name == png_sCAL) 371 { 372 PNG_PUSH_SAVE_BUFFER_IF_FULL 373 png_handle_sCAL(png_ptr, info_ptr, png_ptr->push_length); 374 } 375 376 #endif 377 #ifdef PNG_READ_tIME_SUPPORTED 378 else if (chunk_name == png_tIME) 379 { 380 PNG_PUSH_SAVE_BUFFER_IF_FULL 381 png_handle_tIME(png_ptr, info_ptr, png_ptr->push_length); 382 } 383 384 #endif 385 #ifdef PNG_READ_tEXt_SUPPORTED 386 else if (chunk_name == png_tEXt) 387 { 388 PNG_PUSH_SAVE_BUFFER_IF_FULL 389 png_handle_tEXt(png_ptr, info_ptr, png_ptr->push_length); 390 } 391 392 #endif 393 #ifdef PNG_READ_zTXt_SUPPORTED 394 else if (chunk_name == png_zTXt) 395 { 396 PNG_PUSH_SAVE_BUFFER_IF_FULL 397 png_handle_zTXt(png_ptr, info_ptr, png_ptr->push_length); 398 } 399 400 #endif 401 #ifdef PNG_READ_iTXt_SUPPORTED 402 else if (chunk_name == png_iTXt) 403 { 404 PNG_PUSH_SAVE_BUFFER_IF_FULL 405 png_handle_iTXt(png_ptr, info_ptr, png_ptr->push_length); 406 } 407 #endif 408 409 else 410 { 411 PNG_PUSH_SAVE_BUFFER_IF_FULL 412 png_handle_unknown(png_ptr, info_ptr, png_ptr->push_length, 413 PNG_HANDLE_CHUNK_AS_DEFAULT); 414 } 415 416 png_ptr->mode &= ~PNG_HAVE_CHUNK_HEADER; 417 } 418 419 void PNGCBAPI 420 png_push_fill_buffer(png_structp png_ptr, png_bytep buffer, png_size_t length) 421 { 422 png_bytep ptr; 423 424 if (png_ptr == NULL) 425 return; 426 427 ptr = buffer; 428 if (png_ptr->save_buffer_size != 0) 429 { 430 png_size_t save_size; 431 432 if (length < png_ptr->save_buffer_size) 433 save_size = length; 434 435 else 436 save_size = png_ptr->save_buffer_size; 437 438 memcpy(ptr, png_ptr->save_buffer_ptr, save_size); 439 length -= save_size; 440 ptr += save_size; 441 png_ptr->buffer_size -= save_size; 442 png_ptr->save_buffer_size -= save_size; 443 png_ptr->save_buffer_ptr += save_size; 444 } 445 if (length != 0 && png_ptr->current_buffer_size != 0) 446 { 447 png_size_t save_size; 448 449 if (length < png_ptr->current_buffer_size) 450 save_size = length; 451 452 else 453 save_size = png_ptr->current_buffer_size; 454 455 memcpy(ptr, png_ptr->current_buffer_ptr, save_size); 456 png_ptr->buffer_size -= save_size; 457 png_ptr->current_buffer_size -= save_size; 458 png_ptr->current_buffer_ptr += save_size; 459 } 460 } 461 462 void /* PRIVATE */ 463 png_push_save_buffer(png_structrp png_ptr) 464 { 465 if (png_ptr->save_buffer_size != 0) 466 { 467 if (png_ptr->save_buffer_ptr != png_ptr->save_buffer) 468 { 469 png_size_t i, istop; 470 png_bytep sp; 471 png_bytep dp; 472 473 istop = png_ptr->save_buffer_size; 474 for (i = 0, sp = png_ptr->save_buffer_ptr, dp = png_ptr->save_buffer; 475 i < istop; i++, sp++, dp++) 476 { 477 *dp = *sp; 478 } 479 } 480 } 481 if (png_ptr->save_buffer_size + png_ptr->current_buffer_size > 482 png_ptr->save_buffer_max) 483 { 484 png_size_t new_max; 485 png_bytep old_buffer; 486 487 if (png_ptr->save_buffer_size > PNG_SIZE_MAX - 488 (png_ptr->current_buffer_size + 256)) 489 { 490 png_error(png_ptr, "Potential overflow of save_buffer"); 491 } 492 493 new_max = png_ptr->save_buffer_size + png_ptr->current_buffer_size + 256; 494 old_buffer = png_ptr->save_buffer; 495 png_ptr->save_buffer = (png_bytep)png_malloc_warn(png_ptr, 496 (png_size_t)new_max); 497 498 if (png_ptr->save_buffer == NULL) 499 { 500 png_free(png_ptr, old_buffer); 501 png_error(png_ptr, "Insufficient memory for save_buffer"); 502 } 503 504 if (old_buffer) 505 memcpy(png_ptr->save_buffer, old_buffer, png_ptr->save_buffer_size); 506 else if (png_ptr->save_buffer_size) 507 png_error(png_ptr, "save_buffer error"); 508 png_free(png_ptr, old_buffer); 509 png_ptr->save_buffer_max = new_max; 510 } 511 if (png_ptr->current_buffer_size) 512 { 513 memcpy(png_ptr->save_buffer + png_ptr->save_buffer_size, 514 png_ptr->current_buffer_ptr, png_ptr->current_buffer_size); 515 png_ptr->save_buffer_size += png_ptr->current_buffer_size; 516 png_ptr->current_buffer_size = 0; 517 } 518 png_ptr->save_buffer_ptr = png_ptr->save_buffer; 519 png_ptr->buffer_size = 0; 520 } 521 522 void /* PRIVATE */ 523 png_push_restore_buffer(png_structrp png_ptr, png_bytep buffer, 524 png_size_t buffer_length) 525 { 526 png_ptr->current_buffer = buffer; 527 png_ptr->current_buffer_size = buffer_length; 528 png_ptr->buffer_size = buffer_length + png_ptr->save_buffer_size; 529 png_ptr->current_buffer_ptr = png_ptr->current_buffer; 530 } 531 532 void /* PRIVATE */ 533 png_push_read_IDAT(png_structrp png_ptr) 534 { 535 if ((png_ptr->mode & PNG_HAVE_CHUNK_HEADER) == 0) 536 { 537 png_byte chunk_length[4]; 538 png_byte chunk_tag[4]; 539 540 /* TODO: this code can be commoned up with the same code in push_read */ 541 PNG_PUSH_SAVE_BUFFER_IF_LT(8) 542 png_push_fill_buffer(png_ptr, chunk_length, 4); 543 png_ptr->push_length = png_get_uint_31(png_ptr, chunk_length); 544 png_reset_crc(png_ptr); 545 png_crc_read(png_ptr, chunk_tag, 4); 546 png_ptr->chunk_name = PNG_CHUNK_FROM_STRING(chunk_tag); 547 png_ptr->mode |= PNG_HAVE_CHUNK_HEADER; 548 549 if (png_ptr->chunk_name != png_IDAT) 550 { 551 png_ptr->process_mode = PNG_READ_CHUNK_MODE; 552 553 if ((png_ptr->flags & PNG_FLAG_ZSTREAM_ENDED) == 0) 554 png_error(png_ptr, "Not enough compressed data"); 555 556 return; 557 } 558 559 png_ptr->idat_size = png_ptr->push_length; 560 } 561 562 if (png_ptr->idat_size != 0 && png_ptr->save_buffer_size != 0) 563 { 564 png_size_t save_size = png_ptr->save_buffer_size; 565 png_uint_32 idat_size = png_ptr->idat_size; 566 567 /* We want the smaller of 'idat_size' and 'current_buffer_size', but they 568 * are of different types and we don't know which variable has the fewest 569 * bits. Carefully select the smaller and cast it to the type of the 570 * larger - this cannot overflow. Do not cast in the following test - it 571 * will break on either 16-bit or 64-bit platforms. 572 */ 573 if (idat_size < save_size) 574 save_size = (png_size_t)idat_size; 575 576 else 577 idat_size = (png_uint_32)save_size; 578 579 png_calculate_crc(png_ptr, png_ptr->save_buffer_ptr, save_size); 580 581 png_process_IDAT_data(png_ptr, png_ptr->save_buffer_ptr, save_size); 582 583 png_ptr->idat_size -= idat_size; 584 png_ptr->buffer_size -= save_size; 585 png_ptr->save_buffer_size -= save_size; 586 png_ptr->save_buffer_ptr += save_size; 587 } 588 589 if (png_ptr->idat_size != 0 && png_ptr->current_buffer_size != 0) 590 { 591 png_size_t save_size = png_ptr->current_buffer_size; 592 png_uint_32 idat_size = png_ptr->idat_size; 593 594 /* We want the smaller of 'idat_size' and 'current_buffer_size', but they 595 * are of different types and we don't know which variable has the fewest 596 * bits. Carefully select the smaller and cast it to the type of the 597 * larger - this cannot overflow. 598 */ 599 if (idat_size < save_size) 600 save_size = (png_size_t)idat_size; 601 602 else 603 idat_size = (png_uint_32)save_size; 604 605 png_calculate_crc(png_ptr, png_ptr->current_buffer_ptr, save_size); 606 607 png_process_IDAT_data(png_ptr, png_ptr->current_buffer_ptr, save_size); 608 609 png_ptr->idat_size -= idat_size; 610 png_ptr->buffer_size -= save_size; 611 png_ptr->current_buffer_size -= save_size; 612 png_ptr->current_buffer_ptr += save_size; 613 } 614 615 if (png_ptr->idat_size == 0) 616 { 617 PNG_PUSH_SAVE_BUFFER_IF_LT(4) 618 png_crc_finish(png_ptr, 0); 619 png_ptr->mode &= ~PNG_HAVE_CHUNK_HEADER; 620 png_ptr->mode |= PNG_AFTER_IDAT; 621 png_ptr->zowner = 0; 622 } 623 } 624 625 void /* PRIVATE */ 626 png_process_IDAT_data(png_structrp png_ptr, png_bytep buffer, 627 png_size_t buffer_length) 628 { 629 /* The caller checks for a non-zero buffer length. */ 630 if (!(buffer_length > 0) || buffer == NULL) 631 png_error(png_ptr, "No IDAT data (internal error)"); 632 633 /* This routine must process all the data it has been given 634 * before returning, calling the row callback as required to 635 * handle the uncompressed results. 636 */ 637 png_ptr->zstream.next_in = buffer; 638 /* TODO: WARNING: TRUNCATION ERROR: DANGER WILL ROBINSON: */ 639 png_ptr->zstream.avail_in = (uInt)buffer_length; 640 641 /* Keep going until the decompressed data is all processed 642 * or the stream marked as finished. 643 */ 644 while (png_ptr->zstream.avail_in > 0 && 645 (png_ptr->flags & PNG_FLAG_ZSTREAM_ENDED) == 0) 646 { 647 int ret; 648 649 /* We have data for zlib, but we must check that zlib 650 * has someplace to put the results. It doesn't matter 651 * if we don't expect any results -- it may be the input 652 * data is just the LZ end code. 653 */ 654 if (!(png_ptr->zstream.avail_out > 0)) 655 { 656 /* TODO: WARNING: TRUNCATION ERROR: DANGER WILL ROBINSON: */ 657 png_ptr->zstream.avail_out = (uInt)(PNG_ROWBYTES(png_ptr->pixel_depth, 658 png_ptr->iwidth) + 1); 659 660 png_ptr->zstream.next_out = png_ptr->row_buf; 661 } 662 663 /* Using Z_SYNC_FLUSH here means that an unterminated 664 * LZ stream (a stream with a missing end code) can still 665 * be handled, otherwise (Z_NO_FLUSH) a future zlib 666 * implementation might defer output and therefore 667 * change the current behavior (see comments in inflate.c 668 * for why this doesn't happen at present with zlib 1.2.5). 669 */ 670 ret = PNG_INFLATE(png_ptr, Z_SYNC_FLUSH); 671 672 /* Check for any failure before proceeding. */ 673 if (ret != Z_OK && ret != Z_STREAM_END) 674 { 675 /* Terminate the decompression. */ 676 png_ptr->flags |= PNG_FLAG_ZSTREAM_ENDED; 677 png_ptr->zowner = 0; 678 679 /* This may be a truncated stream (missing or 680 * damaged end code). Treat that as a warning. 681 */ 682 if (png_ptr->row_number >= png_ptr->num_rows || 683 png_ptr->pass > 6) 684 png_warning(png_ptr, "Truncated compressed data in IDAT"); 685 686 else 687 { 688 if (ret == Z_DATA_ERROR) 689 png_benign_error(png_ptr, "IDAT: ADLER32 checksum mismatch"); 690 else 691 png_error(png_ptr, "Decompression error in IDAT"); 692 } 693 694 /* Skip the check on unprocessed input */ 695 return; 696 } 697 698 /* Did inflate output any data? */ 699 if (png_ptr->zstream.next_out != png_ptr->row_buf) 700 { 701 /* Is this unexpected data after the last row? 702 * If it is, artificially terminate the LZ output 703 * here. 704 */ 705 if (png_ptr->row_number >= png_ptr->num_rows || 706 png_ptr->pass > 6) 707 { 708 /* Extra data. */ 709 png_warning(png_ptr, "Extra compressed data in IDAT"); 710 png_ptr->flags |= PNG_FLAG_ZSTREAM_ENDED; 711 png_ptr->zowner = 0; 712 713 /* Do no more processing; skip the unprocessed 714 * input check below. 715 */ 716 return; 717 } 718 719 /* Do we have a complete row? */ 720 if (png_ptr->zstream.avail_out == 0) 721 png_push_process_row(png_ptr); 722 } 723 724 /* And check for the end of the stream. */ 725 if (ret == Z_STREAM_END) 726 png_ptr->flags |= PNG_FLAG_ZSTREAM_ENDED; 727 } 728 729 /* All the data should have been processed, if anything 730 * is left at this point we have bytes of IDAT data 731 * after the zlib end code. 732 */ 733 if (png_ptr->zstream.avail_in > 0) 734 png_warning(png_ptr, "Extra compression data in IDAT"); 735 } 736 737 void /* PRIVATE */ 738 png_push_process_row(png_structrp png_ptr) 739 { 740 /* 1.5.6: row_info moved out of png_struct to a local here. */ 741 png_row_info row_info; 742 743 row_info.width = png_ptr->iwidth; /* NOTE: width of current interlaced row */ 744 row_info.color_type = png_ptr->color_type; 745 row_info.bit_depth = png_ptr->bit_depth; 746 row_info.channels = png_ptr->channels; 747 row_info.pixel_depth = png_ptr->pixel_depth; 748 row_info.rowbytes = PNG_ROWBYTES(row_info.pixel_depth, row_info.width); 749 750 if (png_ptr->row_buf[0] > PNG_FILTER_VALUE_NONE) 751 { 752 if (png_ptr->row_buf[0] < PNG_FILTER_VALUE_LAST) 753 png_read_filter_row(png_ptr, &row_info, png_ptr->row_buf + 1, 754 png_ptr->prev_row + 1, png_ptr->row_buf[0]); 755 else 756 png_error(png_ptr, "bad adaptive filter value"); 757 } 758 759 /* libpng 1.5.6: the following line was copying png_ptr->rowbytes before 760 * 1.5.6, while the buffer really is this big in current versions of libpng 761 * it may not be in the future, so this was changed just to copy the 762 * interlaced row count: 763 */ 764 memcpy(png_ptr->prev_row, png_ptr->row_buf, row_info.rowbytes + 1); 765 766 #ifdef PNG_READ_TRANSFORMS_SUPPORTED 767 if (png_ptr->transformations != 0) 768 png_do_read_transformations(png_ptr, &row_info); 769 #endif 770 771 /* The transformed pixel depth should match the depth now in row_info. */ 772 if (png_ptr->transformed_pixel_depth == 0) 773 { 774 png_ptr->transformed_pixel_depth = row_info.pixel_depth; 775 if (row_info.pixel_depth > png_ptr->maximum_pixel_depth) 776 png_error(png_ptr, "progressive row overflow"); 777 } 778 779 else if (png_ptr->transformed_pixel_depth != row_info.pixel_depth) 780 png_error(png_ptr, "internal progressive row size calculation error"); 781 782 783 #ifdef PNG_READ_INTERLACING_SUPPORTED 784 /* Expand interlaced rows to full size */ 785 if (png_ptr->interlaced != 0 && 786 (png_ptr->transformations & PNG_INTERLACE) != 0) 787 { 788 if (png_ptr->pass < 6) 789 png_do_read_interlace(&row_info, png_ptr->row_buf + 1, png_ptr->pass, 790 png_ptr->transformations); 791 792 switch (png_ptr->pass) 793 { 794 case 0: 795 { 796 int i; 797 for (i = 0; i < 8 && png_ptr->pass == 0; i++) 798 { 799 png_push_have_row(png_ptr, png_ptr->row_buf + 1); 800 png_read_push_finish_row(png_ptr); /* Updates png_ptr->pass */ 801 } 802 803 if (png_ptr->pass == 2) /* Pass 1 might be empty */ 804 { 805 for (i = 0; i < 4 && png_ptr->pass == 2; i++) 806 { 807 png_push_have_row(png_ptr, NULL); 808 png_read_push_finish_row(png_ptr); 809 } 810 } 811 812 if (png_ptr->pass == 4 && png_ptr->height <= 4) 813 { 814 for (i = 0; i < 2 && png_ptr->pass == 4; i++) 815 { 816 png_push_have_row(png_ptr, NULL); 817 png_read_push_finish_row(png_ptr); 818 } 819 } 820 821 if (png_ptr->pass == 6 && png_ptr->height <= 4) 822 { 823 png_push_have_row(png_ptr, NULL); 824 png_read_push_finish_row(png_ptr); 825 } 826 827 break; 828 } 829 830 case 1: 831 { 832 int i; 833 for (i = 0; i < 8 && png_ptr->pass == 1; i++) 834 { 835 png_push_have_row(png_ptr, png_ptr->row_buf + 1); 836 png_read_push_finish_row(png_ptr); 837 } 838 839 if (png_ptr->pass == 2) /* Skip top 4 generated rows */ 840 { 841 for (i = 0; i < 4 && png_ptr->pass == 2; i++) 842 { 843 png_push_have_row(png_ptr, NULL); 844 png_read_push_finish_row(png_ptr); 845 } 846 } 847 848 break; 849 } 850 851 case 2: 852 { 853 int i; 854 855 for (i = 0; i < 4 && png_ptr->pass == 2; i++) 856 { 857 png_push_have_row(png_ptr, png_ptr->row_buf + 1); 858 png_read_push_finish_row(png_ptr); 859 } 860 861 for (i = 0; i < 4 && png_ptr->pass == 2; i++) 862 { 863 png_push_have_row(png_ptr, NULL); 864 png_read_push_finish_row(png_ptr); 865 } 866 867 if (png_ptr->pass == 4) /* Pass 3 might be empty */ 868 { 869 for (i = 0; i < 2 && png_ptr->pass == 4; i++) 870 { 871 png_push_have_row(png_ptr, NULL); 872 png_read_push_finish_row(png_ptr); 873 } 874 } 875 876 break; 877 } 878 879 case 3: 880 { 881 int i; 882 883 for (i = 0; i < 4 && png_ptr->pass == 3; i++) 884 { 885 png_push_have_row(png_ptr, png_ptr->row_buf + 1); 886 png_read_push_finish_row(png_ptr); 887 } 888 889 if (png_ptr->pass == 4) /* Skip top two generated rows */ 890 { 891 for (i = 0; i < 2 && png_ptr->pass == 4; i++) 892 { 893 png_push_have_row(png_ptr, NULL); 894 png_read_push_finish_row(png_ptr); 895 } 896 } 897 898 break; 899 } 900 901 case 4: 902 { 903 int i; 904 905 for (i = 0; i < 2 && png_ptr->pass == 4; i++) 906 { 907 png_push_have_row(png_ptr, png_ptr->row_buf + 1); 908 png_read_push_finish_row(png_ptr); 909 } 910 911 for (i = 0; i < 2 && png_ptr->pass == 4; i++) 912 { 913 png_push_have_row(png_ptr, NULL); 914 png_read_push_finish_row(png_ptr); 915 } 916 917 if (png_ptr->pass == 6) /* Pass 5 might be empty */ 918 { 919 png_push_have_row(png_ptr, NULL); 920 png_read_push_finish_row(png_ptr); 921 } 922 923 break; 924 } 925 926 case 5: 927 { 928 int i; 929 930 for (i = 0; i < 2 && png_ptr->pass == 5; i++) 931 { 932 png_push_have_row(png_ptr, png_ptr->row_buf + 1); 933 png_read_push_finish_row(png_ptr); 934 } 935 936 if (png_ptr->pass == 6) /* Skip top generated row */ 937 { 938 png_push_have_row(png_ptr, NULL); 939 png_read_push_finish_row(png_ptr); 940 } 941 942 break; 943 } 944 945 default: 946 case 6: 947 { 948 png_push_have_row(png_ptr, png_ptr->row_buf + 1); 949 png_read_push_finish_row(png_ptr); 950 951 if (png_ptr->pass != 6) 952 break; 953 954 png_push_have_row(png_ptr, NULL); 955 png_read_push_finish_row(png_ptr); 956 } 957 } 958 } 959 else 960 #endif 961 { 962 png_push_have_row(png_ptr, png_ptr->row_buf + 1); 963 png_read_push_finish_row(png_ptr); 964 } 965 } 966 967 void /* PRIVATE */ 968 png_read_push_finish_row(png_structrp png_ptr) 969 { 970 #ifdef PNG_READ_INTERLACING_SUPPORTED 971 /* Arrays to facilitate easy interlacing - use pass (0 - 6) as index */ 972 973 /* Start of interlace block */ 974 static PNG_CONST png_byte png_pass_start[] = {0, 4, 0, 2, 0, 1, 0}; 975 976 /* Offset to next interlace block */ 977 static PNG_CONST png_byte png_pass_inc[] = {8, 8, 4, 4, 2, 2, 1}; 978 979 /* Start of interlace block in the y direction */ 980 static PNG_CONST png_byte png_pass_ystart[] = {0, 0, 4, 0, 2, 0, 1}; 981 982 /* Offset to next interlace block in the y direction */ 983 static PNG_CONST png_byte png_pass_yinc[] = {8, 8, 8, 4, 4, 2, 2}; 984 985 /* Height of interlace block. This is not currently used - if you need 986 * it, uncomment it here and in png.h 987 static PNG_CONST png_byte png_pass_height[] = {8, 8, 4, 4, 2, 2, 1}; 988 */ 989 #endif 990 991 png_ptr->row_number++; 992 if (png_ptr->row_number < png_ptr->num_rows) 993 return; 994 995 #ifdef PNG_READ_INTERLACING_SUPPORTED 996 if (png_ptr->interlaced != 0) 997 { 998 png_ptr->row_number = 0; 999 memset(png_ptr->prev_row, 0, png_ptr->rowbytes + 1); 1000 1001 do 1002 { 1003 png_ptr->pass++; 1004 if ((png_ptr->pass == 1 && png_ptr->width < 5) || 1005 (png_ptr->pass == 3 && png_ptr->width < 3) || 1006 (png_ptr->pass == 5 && png_ptr->width < 2)) 1007 png_ptr->pass++; 1008 1009 if (png_ptr->pass > 7) 1010 png_ptr->pass--; 1011 1012 if (png_ptr->pass >= 7) 1013 break; 1014 1015 png_ptr->iwidth = (png_ptr->width + 1016 png_pass_inc[png_ptr->pass] - 1 - 1017 png_pass_start[png_ptr->pass]) / 1018 png_pass_inc[png_ptr->pass]; 1019 1020 if ((png_ptr->transformations & PNG_INTERLACE) != 0) 1021 break; 1022 1023 png_ptr->num_rows = (png_ptr->height + 1024 png_pass_yinc[png_ptr->pass] - 1 - 1025 png_pass_ystart[png_ptr->pass]) / 1026 png_pass_yinc[png_ptr->pass]; 1027 1028 } while (png_ptr->iwidth == 0 || png_ptr->num_rows == 0); 1029 } 1030 #endif /* READ_INTERLACING */ 1031 } 1032 1033 void /* PRIVATE */ 1034 png_push_have_info(png_structrp png_ptr, png_inforp info_ptr) 1035 { 1036 if (png_ptr->info_fn != NULL) 1037 (*(png_ptr->info_fn))(png_ptr, info_ptr); 1038 } 1039 1040 void /* PRIVATE */ 1041 png_push_have_end(png_structrp png_ptr, png_inforp info_ptr) 1042 { 1043 if (png_ptr->end_fn != NULL) 1044 (*(png_ptr->end_fn))(png_ptr, info_ptr); 1045 } 1046 1047 void /* PRIVATE */ 1048 png_push_have_row(png_structrp png_ptr, png_bytep row) 1049 { 1050 if (png_ptr->row_fn != NULL) 1051 (*(png_ptr->row_fn))(png_ptr, row, png_ptr->row_number, 1052 (int)png_ptr->pass); 1053 } 1054 1055 #ifdef PNG_READ_INTERLACING_SUPPORTED 1056 void PNGAPI 1057 png_progressive_combine_row(png_const_structrp png_ptr, png_bytep old_row, 1058 png_const_bytep new_row) 1059 { 1060 if (png_ptr == NULL) 1061 return; 1062 1063 /* new_row is a flag here - if it is NULL then the app callback was called 1064 * from an empty row (see the calls to png_struct::row_fn below), otherwise 1065 * it must be png_ptr->row_buf+1 1066 */ 1067 if (new_row != NULL) 1068 png_combine_row(png_ptr, old_row, 1/*blocky display*/); 1069 } 1070 #endif /* READ_INTERLACING */ 1071 1072 void PNGAPI 1073 png_set_progressive_read_fn(png_structrp png_ptr, png_voidp progressive_ptr, 1074 png_progressive_info_ptr info_fn, png_progressive_row_ptr row_fn, 1075 png_progressive_end_ptr end_fn) 1076 { 1077 if (png_ptr == NULL) 1078 return; 1079 1080 png_ptr->info_fn = info_fn; 1081 png_ptr->row_fn = row_fn; 1082 png_ptr->end_fn = end_fn; 1083 1084 png_set_read_fn(png_ptr, progressive_ptr, png_push_fill_buffer); 1085 } 1086 1087 png_voidp PNGAPI 1088 png_get_progressive_ptr(png_const_structrp png_ptr) 1089 { 1090 if (png_ptr == NULL) 1091 return (NULL); 1092 1093 return png_ptr->io_ptr; 1094 } 1095 #endif /* PROGRESSIVE_READ */ 1096