Home | History | Annotate | Download | only in libpng
      1 
      2 /* pngpread.c - read a png file in push mode
      3  *
      4  * Last changed in libpng 1.6.24 [August 4, 2016]
      5  * Copyright (c) 1998-2002,2004,2006-2016 Glenn Randers-Pehrson
      6  * (Version 0.96 Copyright (c) 1996, 1997 Andreas Dilger)
      7  * (Version 0.88 Copyright (c) 1995, 1996 Guy Eric Schalnat, Group 42, Inc.)
      8  *
      9  * This code is released under the libpng license.
     10  * For conditions of distribution and use, see the disclaimer
     11  * and license in png.h
     12  */
     13 
     14 #include "pngpriv.h"
     15 
     16 #ifdef PNG_PROGRESSIVE_READ_SUPPORTED
     17 
     18 /* Push model modes */
     19 #define PNG_READ_SIG_MODE   0
     20 #define PNG_READ_CHUNK_MODE 1
     21 #define PNG_READ_IDAT_MODE  2
     22 #define PNG_READ_tEXt_MODE  4
     23 #define PNG_READ_zTXt_MODE  5
     24 #define PNG_READ_DONE_MODE  6
     25 #define PNG_READ_iTXt_MODE  7
     26 #define PNG_ERROR_MODE      8
     27 
     28 #define PNG_PUSH_SAVE_BUFFER_IF_FULL \
     29 if (png_ptr->push_length + 4 > png_ptr->buffer_size) \
     30    { png_push_save_buffer(png_ptr); return; }
     31 #define PNG_PUSH_SAVE_BUFFER_IF_LT(N) \
     32 if (png_ptr->buffer_size < N) \
     33    { png_push_save_buffer(png_ptr); return; }
     34 
     35 void PNGAPI
     36 png_process_data(png_structrp png_ptr, png_inforp info_ptr,
     37     png_bytep buffer, png_size_t buffer_size)
     38 {
     39    if (png_ptr == NULL || info_ptr == NULL)
     40       return;
     41 
     42    png_push_restore_buffer(png_ptr, buffer, buffer_size);
     43 
     44    while (png_ptr->buffer_size)
     45    {
     46       png_process_some_data(png_ptr, info_ptr);
     47    }
     48 }
     49 
     50 png_size_t PNGAPI
     51 png_process_data_pause(png_structrp png_ptr, int save)
     52 {
     53    if (png_ptr != NULL)
     54    {
     55       /* It's easiest for the caller if we do the save; then the caller doesn't
     56        * have to supply the same data again:
     57        */
     58       if (save != 0)
     59          png_push_save_buffer(png_ptr);
     60       else
     61       {
     62          /* This includes any pending saved bytes: */
     63          png_size_t remaining = png_ptr->buffer_size;
     64          png_ptr->buffer_size = 0;
     65 
     66          /* So subtract the saved buffer size, unless all the data
     67           * is actually 'saved', in which case we just return 0
     68           */
     69          if (png_ptr->save_buffer_size < remaining)
     70             return remaining - png_ptr->save_buffer_size;
     71       }
     72    }
     73 
     74    return 0;
     75 }
     76 
     77 png_uint_32 PNGAPI
     78 png_process_data_skip(png_structrp png_ptr)
     79 {
     80 /* TODO: Deprecate and remove this API.
     81  * Somewhere the implementation of this seems to have been lost,
     82  * or abandoned.  It was only to support some internal back-door access
     83  * to png_struct) in libpng-1.4.x.
     84  */
     85    png_app_warning(png_ptr,
     86 "png_process_data_skip is not implemented in any current version of libpng");
     87    return 0;
     88 }
     89 
     90 /* What we do with the incoming data depends on what we were previously
     91  * doing before we ran out of data...
     92  */
     93 void /* PRIVATE */
     94 png_process_some_data(png_structrp png_ptr, png_inforp info_ptr)
     95 {
     96    if (png_ptr == NULL)
     97       return;
     98 
     99    switch (png_ptr->process_mode)
    100    {
    101       case PNG_READ_SIG_MODE:
    102       {
    103          png_push_read_sig(png_ptr, info_ptr);
    104          break;
    105       }
    106 
    107       case PNG_READ_CHUNK_MODE:
    108       {
    109          png_push_read_chunk(png_ptr, info_ptr);
    110          break;
    111       }
    112 
    113       case PNG_READ_IDAT_MODE:
    114       {
    115          png_push_read_IDAT(png_ptr);
    116          break;
    117       }
    118 
    119       default:
    120       {
    121          png_ptr->buffer_size = 0;
    122          break;
    123       }
    124    }
    125 }
    126 
    127 /* Read any remaining signature bytes from the stream and compare them with
    128  * the correct PNG signature.  It is possible that this routine is called
    129  * with bytes already read from the signature, either because they have been
    130  * checked by the calling application, or because of multiple calls to this
    131  * routine.
    132  */
    133 void /* PRIVATE */
    134 png_push_read_sig(png_structrp png_ptr, png_inforp info_ptr)
    135 {
    136    png_size_t num_checked = png_ptr->sig_bytes, /* SAFE, does not exceed 8 */
    137        num_to_check = 8 - num_checked;
    138 
    139    if (png_ptr->buffer_size < num_to_check)
    140    {
    141       num_to_check = png_ptr->buffer_size;
    142    }
    143 
    144    png_push_fill_buffer(png_ptr, &(info_ptr->signature[num_checked]),
    145        num_to_check);
    146    png_ptr->sig_bytes = (png_byte)(png_ptr->sig_bytes + num_to_check);
    147 
    148    if (png_sig_cmp(info_ptr->signature, num_checked, num_to_check))
    149    {
    150       if (num_checked < 4 &&
    151           png_sig_cmp(info_ptr->signature, num_checked, num_to_check - 4))
    152          png_error(png_ptr, "Not a PNG file");
    153 
    154       else
    155          png_error(png_ptr, "PNG file corrupted by ASCII conversion");
    156    }
    157    else
    158    {
    159       if (png_ptr->sig_bytes >= 8)
    160       {
    161          png_ptr->process_mode = PNG_READ_CHUNK_MODE;
    162       }
    163    }
    164 }
    165 
    166 void /* PRIVATE */
    167 png_push_read_chunk(png_structrp png_ptr, png_inforp info_ptr)
    168 {
    169    png_uint_32 chunk_name;
    170 #ifdef PNG_HANDLE_AS_UNKNOWN_SUPPORTED
    171    int keep; /* unknown handling method */
    172 #endif
    173 
    174    /* First we make sure we have enough data for the 4-byte chunk name
    175     * and the 4-byte chunk length before proceeding with decoding the
    176     * chunk data.  To fully decode each of these chunks, we also make
    177     * sure we have enough data in the buffer for the 4-byte CRC at the
    178     * end of every chunk (except IDAT, which is handled separately).
    179     */
    180    if ((png_ptr->mode & PNG_HAVE_CHUNK_HEADER) == 0)
    181    {
    182       png_byte chunk_length[4];
    183       png_byte chunk_tag[4];
    184 
    185       PNG_PUSH_SAVE_BUFFER_IF_LT(8)
    186       png_push_fill_buffer(png_ptr, chunk_length, 4);
    187       png_ptr->push_length = png_get_uint_31(png_ptr, chunk_length);
    188       png_reset_crc(png_ptr);
    189       png_crc_read(png_ptr, chunk_tag, 4);
    190       png_ptr->chunk_name = PNG_CHUNK_FROM_STRING(chunk_tag);
    191       png_check_chunk_name(png_ptr, png_ptr->chunk_name);
    192       png_ptr->mode |= PNG_HAVE_CHUNK_HEADER;
    193    }
    194 
    195    chunk_name = png_ptr->chunk_name;
    196 
    197    if (chunk_name == png_IDAT)
    198    {
    199       if ((png_ptr->mode & PNG_AFTER_IDAT) != 0)
    200          png_ptr->mode |= PNG_HAVE_CHUNK_AFTER_IDAT;
    201 
    202       /* If we reach an IDAT chunk, this means we have read all of the
    203        * header chunks, and we can start reading the image (or if this
    204        * is called after the image has been read - we have an error).
    205        */
    206       if ((png_ptr->mode & PNG_HAVE_IHDR) == 0)
    207          png_error(png_ptr, "Missing IHDR before IDAT");
    208 
    209       else if (png_ptr->color_type == PNG_COLOR_TYPE_PALETTE &&
    210           (png_ptr->mode & PNG_HAVE_PLTE) == 0)
    211          png_error(png_ptr, "Missing PLTE before IDAT");
    212 
    213       png_ptr->process_mode = PNG_READ_IDAT_MODE;
    214 
    215       if ((png_ptr->mode & PNG_HAVE_IDAT) != 0)
    216          if ((png_ptr->mode & PNG_HAVE_CHUNK_AFTER_IDAT) == 0)
    217             if (png_ptr->push_length == 0)
    218                return;
    219 
    220       png_ptr->mode |= PNG_HAVE_IDAT;
    221 
    222       if ((png_ptr->mode & PNG_AFTER_IDAT) != 0)
    223          png_benign_error(png_ptr, "Too many IDATs found");
    224    }
    225 
    226    if (chunk_name == png_IHDR)
    227    {
    228       if (png_ptr->push_length != 13)
    229          png_error(png_ptr, "Invalid IHDR length");
    230 
    231       PNG_PUSH_SAVE_BUFFER_IF_FULL
    232       png_handle_IHDR(png_ptr, info_ptr, png_ptr->push_length);
    233    }
    234 
    235    else if (chunk_name == png_IEND)
    236    {
    237       PNG_PUSH_SAVE_BUFFER_IF_FULL
    238       png_handle_IEND(png_ptr, info_ptr, png_ptr->push_length);
    239 
    240       png_ptr->process_mode = PNG_READ_DONE_MODE;
    241       png_push_have_end(png_ptr, info_ptr);
    242    }
    243 
    244 #ifdef PNG_HANDLE_AS_UNKNOWN_SUPPORTED
    245    else if ((keep = png_chunk_unknown_handling(png_ptr, chunk_name)) != 0)
    246    {
    247       PNG_PUSH_SAVE_BUFFER_IF_FULL
    248       png_handle_unknown(png_ptr, info_ptr, png_ptr->push_length, keep);
    249 
    250       if (chunk_name == png_PLTE)
    251          png_ptr->mode |= PNG_HAVE_PLTE;
    252    }
    253 #endif
    254 
    255    else if (chunk_name == png_PLTE)
    256    {
    257       PNG_PUSH_SAVE_BUFFER_IF_FULL
    258       png_handle_PLTE(png_ptr, info_ptr, png_ptr->push_length);
    259    }
    260 
    261    else if (chunk_name == png_IDAT)
    262    {
    263       png_ptr->idat_size = png_ptr->push_length;
    264       png_ptr->process_mode = PNG_READ_IDAT_MODE;
    265       png_push_have_info(png_ptr, info_ptr);
    266       png_ptr->zstream.avail_out =
    267           (uInt) PNG_ROWBYTES(png_ptr->pixel_depth,
    268           png_ptr->iwidth) + 1;
    269       png_ptr->zstream.next_out = png_ptr->row_buf;
    270       return;
    271    }
    272 
    273 #ifdef PNG_READ_gAMA_SUPPORTED
    274    else if (png_ptr->chunk_name == png_gAMA)
    275    {
    276       PNG_PUSH_SAVE_BUFFER_IF_FULL
    277       png_handle_gAMA(png_ptr, info_ptr, png_ptr->push_length);
    278    }
    279 
    280 #endif
    281 #ifdef PNG_READ_sBIT_SUPPORTED
    282    else if (png_ptr->chunk_name == png_sBIT)
    283    {
    284       PNG_PUSH_SAVE_BUFFER_IF_FULL
    285       png_handle_sBIT(png_ptr, info_ptr, png_ptr->push_length);
    286    }
    287 
    288 #endif
    289 #ifdef PNG_READ_cHRM_SUPPORTED
    290    else if (png_ptr->chunk_name == png_cHRM)
    291    {
    292       PNG_PUSH_SAVE_BUFFER_IF_FULL
    293       png_handle_cHRM(png_ptr, info_ptr, png_ptr->push_length);
    294    }
    295 
    296 #endif
    297 #ifdef PNG_READ_sRGB_SUPPORTED
    298    else if (chunk_name == png_sRGB)
    299    {
    300       PNG_PUSH_SAVE_BUFFER_IF_FULL
    301       png_handle_sRGB(png_ptr, info_ptr, png_ptr->push_length);
    302    }
    303 
    304 #endif
    305 #ifdef PNG_READ_iCCP_SUPPORTED
    306    else if (png_ptr->chunk_name == png_iCCP)
    307    {
    308       PNG_PUSH_SAVE_BUFFER_IF_FULL
    309       png_handle_iCCP(png_ptr, info_ptr, png_ptr->push_length);
    310    }
    311 
    312 #endif
    313 #ifdef PNG_READ_sPLT_SUPPORTED
    314    else if (chunk_name == png_sPLT)
    315    {
    316       PNG_PUSH_SAVE_BUFFER_IF_FULL
    317       png_handle_sPLT(png_ptr, info_ptr, png_ptr->push_length);
    318    }
    319 
    320 #endif
    321 #ifdef PNG_READ_tRNS_SUPPORTED
    322    else if (chunk_name == png_tRNS)
    323    {
    324       PNG_PUSH_SAVE_BUFFER_IF_FULL
    325       png_handle_tRNS(png_ptr, info_ptr, png_ptr->push_length);
    326    }
    327 
    328 #endif
    329 #ifdef PNG_READ_bKGD_SUPPORTED
    330    else if (chunk_name == png_bKGD)
    331    {
    332       PNG_PUSH_SAVE_BUFFER_IF_FULL
    333       png_handle_bKGD(png_ptr, info_ptr, png_ptr->push_length);
    334    }
    335 
    336 #endif
    337 #ifdef PNG_READ_hIST_SUPPORTED
    338    else if (chunk_name == png_hIST)
    339    {
    340       PNG_PUSH_SAVE_BUFFER_IF_FULL
    341       png_handle_hIST(png_ptr, info_ptr, png_ptr->push_length);
    342    }
    343 
    344 #endif
    345 #ifdef PNG_READ_pHYs_SUPPORTED
    346    else if (chunk_name == png_pHYs)
    347    {
    348       PNG_PUSH_SAVE_BUFFER_IF_FULL
    349       png_handle_pHYs(png_ptr, info_ptr, png_ptr->push_length);
    350    }
    351 
    352 #endif
    353 #ifdef PNG_READ_oFFs_SUPPORTED
    354    else if (chunk_name == png_oFFs)
    355    {
    356       PNG_PUSH_SAVE_BUFFER_IF_FULL
    357       png_handle_oFFs(png_ptr, info_ptr, png_ptr->push_length);
    358    }
    359 #endif
    360 
    361 #ifdef PNG_READ_pCAL_SUPPORTED
    362    else if (chunk_name == png_pCAL)
    363    {
    364       PNG_PUSH_SAVE_BUFFER_IF_FULL
    365       png_handle_pCAL(png_ptr, info_ptr, png_ptr->push_length);
    366    }
    367 
    368 #endif
    369 #ifdef PNG_READ_sCAL_SUPPORTED
    370    else if (chunk_name == png_sCAL)
    371    {
    372       PNG_PUSH_SAVE_BUFFER_IF_FULL
    373       png_handle_sCAL(png_ptr, info_ptr, png_ptr->push_length);
    374    }
    375 
    376 #endif
    377 #ifdef PNG_READ_tIME_SUPPORTED
    378    else if (chunk_name == png_tIME)
    379    {
    380       PNG_PUSH_SAVE_BUFFER_IF_FULL
    381       png_handle_tIME(png_ptr, info_ptr, png_ptr->push_length);
    382    }
    383 
    384 #endif
    385 #ifdef PNG_READ_tEXt_SUPPORTED
    386    else if (chunk_name == png_tEXt)
    387    {
    388       PNG_PUSH_SAVE_BUFFER_IF_FULL
    389       png_handle_tEXt(png_ptr, info_ptr, png_ptr->push_length);
    390    }
    391 
    392 #endif
    393 #ifdef PNG_READ_zTXt_SUPPORTED
    394    else if (chunk_name == png_zTXt)
    395    {
    396       PNG_PUSH_SAVE_BUFFER_IF_FULL
    397       png_handle_zTXt(png_ptr, info_ptr, png_ptr->push_length);
    398    }
    399 
    400 #endif
    401 #ifdef PNG_READ_iTXt_SUPPORTED
    402    else if (chunk_name == png_iTXt)
    403    {
    404       PNG_PUSH_SAVE_BUFFER_IF_FULL
    405       png_handle_iTXt(png_ptr, info_ptr, png_ptr->push_length);
    406    }
    407 #endif
    408 
    409    else
    410    {
    411       PNG_PUSH_SAVE_BUFFER_IF_FULL
    412       png_handle_unknown(png_ptr, info_ptr, png_ptr->push_length,
    413           PNG_HANDLE_CHUNK_AS_DEFAULT);
    414    }
    415 
    416    png_ptr->mode &= ~PNG_HAVE_CHUNK_HEADER;
    417 }
    418 
    419 void PNGCBAPI
    420 png_push_fill_buffer(png_structp png_ptr, png_bytep buffer, png_size_t length)
    421 {
    422    png_bytep ptr;
    423 
    424    if (png_ptr == NULL)
    425       return;
    426 
    427    ptr = buffer;
    428    if (png_ptr->save_buffer_size != 0)
    429    {
    430       png_size_t save_size;
    431 
    432       if (length < png_ptr->save_buffer_size)
    433          save_size = length;
    434 
    435       else
    436          save_size = png_ptr->save_buffer_size;
    437 
    438       memcpy(ptr, png_ptr->save_buffer_ptr, save_size);
    439       length -= save_size;
    440       ptr += save_size;
    441       png_ptr->buffer_size -= save_size;
    442       png_ptr->save_buffer_size -= save_size;
    443       png_ptr->save_buffer_ptr += save_size;
    444    }
    445    if (length != 0 && png_ptr->current_buffer_size != 0)
    446    {
    447       png_size_t save_size;
    448 
    449       if (length < png_ptr->current_buffer_size)
    450          save_size = length;
    451 
    452       else
    453          save_size = png_ptr->current_buffer_size;
    454 
    455       memcpy(ptr, png_ptr->current_buffer_ptr, save_size);
    456       png_ptr->buffer_size -= save_size;
    457       png_ptr->current_buffer_size -= save_size;
    458       png_ptr->current_buffer_ptr += save_size;
    459    }
    460 }
    461 
    462 void /* PRIVATE */
    463 png_push_save_buffer(png_structrp png_ptr)
    464 {
    465    if (png_ptr->save_buffer_size != 0)
    466    {
    467       if (png_ptr->save_buffer_ptr != png_ptr->save_buffer)
    468       {
    469          png_size_t i, istop;
    470          png_bytep sp;
    471          png_bytep dp;
    472 
    473          istop = png_ptr->save_buffer_size;
    474          for (i = 0, sp = png_ptr->save_buffer_ptr, dp = png_ptr->save_buffer;
    475              i < istop; i++, sp++, dp++)
    476          {
    477             *dp = *sp;
    478          }
    479       }
    480    }
    481    if (png_ptr->save_buffer_size + png_ptr->current_buffer_size >
    482        png_ptr->save_buffer_max)
    483    {
    484       png_size_t new_max;
    485       png_bytep old_buffer;
    486 
    487       if (png_ptr->save_buffer_size > PNG_SIZE_MAX -
    488           (png_ptr->current_buffer_size + 256))
    489       {
    490          png_error(png_ptr, "Potential overflow of save_buffer");
    491       }
    492 
    493       new_max = png_ptr->save_buffer_size + png_ptr->current_buffer_size + 256;
    494       old_buffer = png_ptr->save_buffer;
    495       png_ptr->save_buffer = (png_bytep)png_malloc_warn(png_ptr,
    496           (png_size_t)new_max);
    497 
    498       if (png_ptr->save_buffer == NULL)
    499       {
    500          png_free(png_ptr, old_buffer);
    501          png_error(png_ptr, "Insufficient memory for save_buffer");
    502       }
    503 
    504       if (old_buffer)
    505          memcpy(png_ptr->save_buffer, old_buffer, png_ptr->save_buffer_size);
    506       else if (png_ptr->save_buffer_size)
    507          png_error(png_ptr, "save_buffer error");
    508       png_free(png_ptr, old_buffer);
    509       png_ptr->save_buffer_max = new_max;
    510    }
    511    if (png_ptr->current_buffer_size)
    512    {
    513       memcpy(png_ptr->save_buffer + png_ptr->save_buffer_size,
    514          png_ptr->current_buffer_ptr, png_ptr->current_buffer_size);
    515       png_ptr->save_buffer_size += png_ptr->current_buffer_size;
    516       png_ptr->current_buffer_size = 0;
    517    }
    518    png_ptr->save_buffer_ptr = png_ptr->save_buffer;
    519    png_ptr->buffer_size = 0;
    520 }
    521 
    522 void /* PRIVATE */
    523 png_push_restore_buffer(png_structrp png_ptr, png_bytep buffer,
    524     png_size_t buffer_length)
    525 {
    526    png_ptr->current_buffer = buffer;
    527    png_ptr->current_buffer_size = buffer_length;
    528    png_ptr->buffer_size = buffer_length + png_ptr->save_buffer_size;
    529    png_ptr->current_buffer_ptr = png_ptr->current_buffer;
    530 }
    531 
    532 void /* PRIVATE */
    533 png_push_read_IDAT(png_structrp png_ptr)
    534 {
    535    if ((png_ptr->mode & PNG_HAVE_CHUNK_HEADER) == 0)
    536    {
    537       png_byte chunk_length[4];
    538       png_byte chunk_tag[4];
    539 
    540       /* TODO: this code can be commoned up with the same code in push_read */
    541       PNG_PUSH_SAVE_BUFFER_IF_LT(8)
    542       png_push_fill_buffer(png_ptr, chunk_length, 4);
    543       png_ptr->push_length = png_get_uint_31(png_ptr, chunk_length);
    544       png_reset_crc(png_ptr);
    545       png_crc_read(png_ptr, chunk_tag, 4);
    546       png_ptr->chunk_name = PNG_CHUNK_FROM_STRING(chunk_tag);
    547       png_ptr->mode |= PNG_HAVE_CHUNK_HEADER;
    548 
    549       if (png_ptr->chunk_name != png_IDAT)
    550       {
    551          png_ptr->process_mode = PNG_READ_CHUNK_MODE;
    552 
    553          if ((png_ptr->flags & PNG_FLAG_ZSTREAM_ENDED) == 0)
    554             png_error(png_ptr, "Not enough compressed data");
    555 
    556          return;
    557       }
    558 
    559       png_ptr->idat_size = png_ptr->push_length;
    560    }
    561 
    562    if (png_ptr->idat_size != 0 && png_ptr->save_buffer_size != 0)
    563    {
    564       png_size_t save_size = png_ptr->save_buffer_size;
    565       png_uint_32 idat_size = png_ptr->idat_size;
    566 
    567       /* We want the smaller of 'idat_size' and 'current_buffer_size', but they
    568        * are of different types and we don't know which variable has the fewest
    569        * bits.  Carefully select the smaller and cast it to the type of the
    570        * larger - this cannot overflow.  Do not cast in the following test - it
    571        * will break on either 16-bit or 64-bit platforms.
    572        */
    573       if (idat_size < save_size)
    574          save_size = (png_size_t)idat_size;
    575 
    576       else
    577          idat_size = (png_uint_32)save_size;
    578 
    579       png_calculate_crc(png_ptr, png_ptr->save_buffer_ptr, save_size);
    580 
    581       png_process_IDAT_data(png_ptr, png_ptr->save_buffer_ptr, save_size);
    582 
    583       png_ptr->idat_size -= idat_size;
    584       png_ptr->buffer_size -= save_size;
    585       png_ptr->save_buffer_size -= save_size;
    586       png_ptr->save_buffer_ptr += save_size;
    587    }
    588 
    589    if (png_ptr->idat_size != 0 && png_ptr->current_buffer_size != 0)
    590    {
    591       png_size_t save_size = png_ptr->current_buffer_size;
    592       png_uint_32 idat_size = png_ptr->idat_size;
    593 
    594       /* We want the smaller of 'idat_size' and 'current_buffer_size', but they
    595        * are of different types and we don't know which variable has the fewest
    596        * bits.  Carefully select the smaller and cast it to the type of the
    597        * larger - this cannot overflow.
    598        */
    599       if (idat_size < save_size)
    600          save_size = (png_size_t)idat_size;
    601 
    602       else
    603          idat_size = (png_uint_32)save_size;
    604 
    605       png_calculate_crc(png_ptr, png_ptr->current_buffer_ptr, save_size);
    606 
    607       png_process_IDAT_data(png_ptr, png_ptr->current_buffer_ptr, save_size);
    608 
    609       png_ptr->idat_size -= idat_size;
    610       png_ptr->buffer_size -= save_size;
    611       png_ptr->current_buffer_size -= save_size;
    612       png_ptr->current_buffer_ptr += save_size;
    613    }
    614 
    615    if (png_ptr->idat_size == 0)
    616    {
    617       PNG_PUSH_SAVE_BUFFER_IF_LT(4)
    618       png_crc_finish(png_ptr, 0);
    619       png_ptr->mode &= ~PNG_HAVE_CHUNK_HEADER;
    620       png_ptr->mode |= PNG_AFTER_IDAT;
    621       png_ptr->zowner = 0;
    622    }
    623 }
    624 
    625 void /* PRIVATE */
    626 png_process_IDAT_data(png_structrp png_ptr, png_bytep buffer,
    627     png_size_t buffer_length)
    628 {
    629    /* The caller checks for a non-zero buffer length. */
    630    if (!(buffer_length > 0) || buffer == NULL)
    631       png_error(png_ptr, "No IDAT data (internal error)");
    632 
    633    /* This routine must process all the data it has been given
    634     * before returning, calling the row callback as required to
    635     * handle the uncompressed results.
    636     */
    637    png_ptr->zstream.next_in = buffer;
    638    /* TODO: WARNING: TRUNCATION ERROR: DANGER WILL ROBINSON: */
    639    png_ptr->zstream.avail_in = (uInt)buffer_length;
    640 
    641    /* Keep going until the decompressed data is all processed
    642     * or the stream marked as finished.
    643     */
    644    while (png_ptr->zstream.avail_in > 0 &&
    645       (png_ptr->flags & PNG_FLAG_ZSTREAM_ENDED) == 0)
    646    {
    647       int ret;
    648 
    649       /* We have data for zlib, but we must check that zlib
    650        * has someplace to put the results.  It doesn't matter
    651        * if we don't expect any results -- it may be the input
    652        * data is just the LZ end code.
    653        */
    654       if (!(png_ptr->zstream.avail_out > 0))
    655       {
    656          /* TODO: WARNING: TRUNCATION ERROR: DANGER WILL ROBINSON: */
    657          png_ptr->zstream.avail_out = (uInt)(PNG_ROWBYTES(png_ptr->pixel_depth,
    658              png_ptr->iwidth) + 1);
    659 
    660          png_ptr->zstream.next_out = png_ptr->row_buf;
    661       }
    662 
    663       /* Using Z_SYNC_FLUSH here means that an unterminated
    664        * LZ stream (a stream with a missing end code) can still
    665        * be handled, otherwise (Z_NO_FLUSH) a future zlib
    666        * implementation might defer output and therefore
    667        * change the current behavior (see comments in inflate.c
    668        * for why this doesn't happen at present with zlib 1.2.5).
    669        */
    670       ret = PNG_INFLATE(png_ptr, Z_SYNC_FLUSH);
    671 
    672       /* Check for any failure before proceeding. */
    673       if (ret != Z_OK && ret != Z_STREAM_END)
    674       {
    675          /* Terminate the decompression. */
    676          png_ptr->flags |= PNG_FLAG_ZSTREAM_ENDED;
    677          png_ptr->zowner = 0;
    678 
    679          /* This may be a truncated stream (missing or
    680           * damaged end code).  Treat that as a warning.
    681           */
    682          if (png_ptr->row_number >= png_ptr->num_rows ||
    683              png_ptr->pass > 6)
    684             png_warning(png_ptr, "Truncated compressed data in IDAT");
    685 
    686          else
    687          {
    688             if (ret == Z_DATA_ERROR)
    689                png_benign_error(png_ptr, "IDAT: ADLER32 checksum mismatch");
    690             else
    691                png_error(png_ptr, "Decompression error in IDAT");
    692          }
    693 
    694          /* Skip the check on unprocessed input */
    695          return;
    696       }
    697 
    698       /* Did inflate output any data? */
    699       if (png_ptr->zstream.next_out != png_ptr->row_buf)
    700       {
    701          /* Is this unexpected data after the last row?
    702           * If it is, artificially terminate the LZ output
    703           * here.
    704           */
    705          if (png_ptr->row_number >= png_ptr->num_rows ||
    706              png_ptr->pass > 6)
    707          {
    708             /* Extra data. */
    709             png_warning(png_ptr, "Extra compressed data in IDAT");
    710             png_ptr->flags |= PNG_FLAG_ZSTREAM_ENDED;
    711             png_ptr->zowner = 0;
    712 
    713             /* Do no more processing; skip the unprocessed
    714              * input check below.
    715              */
    716             return;
    717          }
    718 
    719          /* Do we have a complete row? */
    720          if (png_ptr->zstream.avail_out == 0)
    721             png_push_process_row(png_ptr);
    722       }
    723 
    724       /* And check for the end of the stream. */
    725       if (ret == Z_STREAM_END)
    726          png_ptr->flags |= PNG_FLAG_ZSTREAM_ENDED;
    727    }
    728 
    729    /* All the data should have been processed, if anything
    730     * is left at this point we have bytes of IDAT data
    731     * after the zlib end code.
    732     */
    733    if (png_ptr->zstream.avail_in > 0)
    734       png_warning(png_ptr, "Extra compression data in IDAT");
    735 }
    736 
    737 void /* PRIVATE */
    738 png_push_process_row(png_structrp png_ptr)
    739 {
    740    /* 1.5.6: row_info moved out of png_struct to a local here. */
    741    png_row_info row_info;
    742 
    743    row_info.width = png_ptr->iwidth; /* NOTE: width of current interlaced row */
    744    row_info.color_type = png_ptr->color_type;
    745    row_info.bit_depth = png_ptr->bit_depth;
    746    row_info.channels = png_ptr->channels;
    747    row_info.pixel_depth = png_ptr->pixel_depth;
    748    row_info.rowbytes = PNG_ROWBYTES(row_info.pixel_depth, row_info.width);
    749 
    750    if (png_ptr->row_buf[0] > PNG_FILTER_VALUE_NONE)
    751    {
    752       if (png_ptr->row_buf[0] < PNG_FILTER_VALUE_LAST)
    753          png_read_filter_row(png_ptr, &row_info, png_ptr->row_buf + 1,
    754             png_ptr->prev_row + 1, png_ptr->row_buf[0]);
    755       else
    756          png_error(png_ptr, "bad adaptive filter value");
    757    }
    758 
    759    /* libpng 1.5.6: the following line was copying png_ptr->rowbytes before
    760     * 1.5.6, while the buffer really is this big in current versions of libpng
    761     * it may not be in the future, so this was changed just to copy the
    762     * interlaced row count:
    763     */
    764    memcpy(png_ptr->prev_row, png_ptr->row_buf, row_info.rowbytes + 1);
    765 
    766 #ifdef PNG_READ_TRANSFORMS_SUPPORTED
    767    if (png_ptr->transformations != 0)
    768       png_do_read_transformations(png_ptr, &row_info);
    769 #endif
    770 
    771    /* The transformed pixel depth should match the depth now in row_info. */
    772    if (png_ptr->transformed_pixel_depth == 0)
    773    {
    774       png_ptr->transformed_pixel_depth = row_info.pixel_depth;
    775       if (row_info.pixel_depth > png_ptr->maximum_pixel_depth)
    776          png_error(png_ptr, "progressive row overflow");
    777    }
    778 
    779    else if (png_ptr->transformed_pixel_depth != row_info.pixel_depth)
    780       png_error(png_ptr, "internal progressive row size calculation error");
    781 
    782 
    783 #ifdef PNG_READ_INTERLACING_SUPPORTED
    784    /* Expand interlaced rows to full size */
    785    if (png_ptr->interlaced != 0 &&
    786        (png_ptr->transformations & PNG_INTERLACE) != 0)
    787    {
    788       if (png_ptr->pass < 6)
    789          png_do_read_interlace(&row_info, png_ptr->row_buf + 1, png_ptr->pass,
    790              png_ptr->transformations);
    791 
    792       switch (png_ptr->pass)
    793       {
    794          case 0:
    795          {
    796             int i;
    797             for (i = 0; i < 8 && png_ptr->pass == 0; i++)
    798             {
    799                png_push_have_row(png_ptr, png_ptr->row_buf + 1);
    800                png_read_push_finish_row(png_ptr); /* Updates png_ptr->pass */
    801             }
    802 
    803             if (png_ptr->pass == 2) /* Pass 1 might be empty */
    804             {
    805                for (i = 0; i < 4 && png_ptr->pass == 2; i++)
    806                {
    807                   png_push_have_row(png_ptr, NULL);
    808                   png_read_push_finish_row(png_ptr);
    809                }
    810             }
    811 
    812             if (png_ptr->pass == 4 && png_ptr->height <= 4)
    813             {
    814                for (i = 0; i < 2 && png_ptr->pass == 4; i++)
    815                {
    816                   png_push_have_row(png_ptr, NULL);
    817                   png_read_push_finish_row(png_ptr);
    818                }
    819             }
    820 
    821             if (png_ptr->pass == 6 && png_ptr->height <= 4)
    822             {
    823                 png_push_have_row(png_ptr, NULL);
    824                 png_read_push_finish_row(png_ptr);
    825             }
    826 
    827             break;
    828          }
    829 
    830          case 1:
    831          {
    832             int i;
    833             for (i = 0; i < 8 && png_ptr->pass == 1; i++)
    834             {
    835                png_push_have_row(png_ptr, png_ptr->row_buf + 1);
    836                png_read_push_finish_row(png_ptr);
    837             }
    838 
    839             if (png_ptr->pass == 2) /* Skip top 4 generated rows */
    840             {
    841                for (i = 0; i < 4 && png_ptr->pass == 2; i++)
    842                {
    843                   png_push_have_row(png_ptr, NULL);
    844                   png_read_push_finish_row(png_ptr);
    845                }
    846             }
    847 
    848             break;
    849          }
    850 
    851          case 2:
    852          {
    853             int i;
    854 
    855             for (i = 0; i < 4 && png_ptr->pass == 2; i++)
    856             {
    857                png_push_have_row(png_ptr, png_ptr->row_buf + 1);
    858                png_read_push_finish_row(png_ptr);
    859             }
    860 
    861             for (i = 0; i < 4 && png_ptr->pass == 2; i++)
    862             {
    863                png_push_have_row(png_ptr, NULL);
    864                png_read_push_finish_row(png_ptr);
    865             }
    866 
    867             if (png_ptr->pass == 4) /* Pass 3 might be empty */
    868             {
    869                for (i = 0; i < 2 && png_ptr->pass == 4; i++)
    870                {
    871                   png_push_have_row(png_ptr, NULL);
    872                   png_read_push_finish_row(png_ptr);
    873                }
    874             }
    875 
    876             break;
    877          }
    878 
    879          case 3:
    880          {
    881             int i;
    882 
    883             for (i = 0; i < 4 && png_ptr->pass == 3; i++)
    884             {
    885                png_push_have_row(png_ptr, png_ptr->row_buf + 1);
    886                png_read_push_finish_row(png_ptr);
    887             }
    888 
    889             if (png_ptr->pass == 4) /* Skip top two generated rows */
    890             {
    891                for (i = 0; i < 2 && png_ptr->pass == 4; i++)
    892                {
    893                   png_push_have_row(png_ptr, NULL);
    894                   png_read_push_finish_row(png_ptr);
    895                }
    896             }
    897 
    898             break;
    899          }
    900 
    901          case 4:
    902          {
    903             int i;
    904 
    905             for (i = 0; i < 2 && png_ptr->pass == 4; i++)
    906             {
    907                png_push_have_row(png_ptr, png_ptr->row_buf + 1);
    908                png_read_push_finish_row(png_ptr);
    909             }
    910 
    911             for (i = 0; i < 2 && png_ptr->pass == 4; i++)
    912             {
    913                png_push_have_row(png_ptr, NULL);
    914                png_read_push_finish_row(png_ptr);
    915             }
    916 
    917             if (png_ptr->pass == 6) /* Pass 5 might be empty */
    918             {
    919                png_push_have_row(png_ptr, NULL);
    920                png_read_push_finish_row(png_ptr);
    921             }
    922 
    923             break;
    924          }
    925 
    926          case 5:
    927          {
    928             int i;
    929 
    930             for (i = 0; i < 2 && png_ptr->pass == 5; i++)
    931             {
    932                png_push_have_row(png_ptr, png_ptr->row_buf + 1);
    933                png_read_push_finish_row(png_ptr);
    934             }
    935 
    936             if (png_ptr->pass == 6) /* Skip top generated row */
    937             {
    938                png_push_have_row(png_ptr, NULL);
    939                png_read_push_finish_row(png_ptr);
    940             }
    941 
    942             break;
    943          }
    944 
    945          default:
    946          case 6:
    947          {
    948             png_push_have_row(png_ptr, png_ptr->row_buf + 1);
    949             png_read_push_finish_row(png_ptr);
    950 
    951             if (png_ptr->pass != 6)
    952                break;
    953 
    954             png_push_have_row(png_ptr, NULL);
    955             png_read_push_finish_row(png_ptr);
    956          }
    957       }
    958    }
    959    else
    960 #endif
    961    {
    962       png_push_have_row(png_ptr, png_ptr->row_buf + 1);
    963       png_read_push_finish_row(png_ptr);
    964    }
    965 }
    966 
    967 void /* PRIVATE */
    968 png_read_push_finish_row(png_structrp png_ptr)
    969 {
    970 #ifdef PNG_READ_INTERLACING_SUPPORTED
    971    /* Arrays to facilitate easy interlacing - use pass (0 - 6) as index */
    972 
    973    /* Start of interlace block */
    974    static PNG_CONST png_byte png_pass_start[] = {0, 4, 0, 2, 0, 1, 0};
    975 
    976    /* Offset to next interlace block */
    977    static PNG_CONST png_byte png_pass_inc[] = {8, 8, 4, 4, 2, 2, 1};
    978 
    979    /* Start of interlace block in the y direction */
    980    static PNG_CONST png_byte png_pass_ystart[] = {0, 0, 4, 0, 2, 0, 1};
    981 
    982    /* Offset to next interlace block in the y direction */
    983    static PNG_CONST png_byte png_pass_yinc[] = {8, 8, 8, 4, 4, 2, 2};
    984 
    985    /* Height of interlace block.  This is not currently used - if you need
    986     * it, uncomment it here and in png.h
    987    static PNG_CONST png_byte png_pass_height[] = {8, 8, 4, 4, 2, 2, 1};
    988    */
    989 #endif
    990 
    991    png_ptr->row_number++;
    992    if (png_ptr->row_number < png_ptr->num_rows)
    993       return;
    994 
    995 #ifdef PNG_READ_INTERLACING_SUPPORTED
    996    if (png_ptr->interlaced != 0)
    997    {
    998       png_ptr->row_number = 0;
    999       memset(png_ptr->prev_row, 0, png_ptr->rowbytes + 1);
   1000 
   1001       do
   1002       {
   1003          png_ptr->pass++;
   1004          if ((png_ptr->pass == 1 && png_ptr->width < 5) ||
   1005              (png_ptr->pass == 3 && png_ptr->width < 3) ||
   1006              (png_ptr->pass == 5 && png_ptr->width < 2))
   1007             png_ptr->pass++;
   1008 
   1009          if (png_ptr->pass > 7)
   1010             png_ptr->pass--;
   1011 
   1012          if (png_ptr->pass >= 7)
   1013             break;
   1014 
   1015          png_ptr->iwidth = (png_ptr->width +
   1016              png_pass_inc[png_ptr->pass] - 1 -
   1017              png_pass_start[png_ptr->pass]) /
   1018              png_pass_inc[png_ptr->pass];
   1019 
   1020          if ((png_ptr->transformations & PNG_INTERLACE) != 0)
   1021             break;
   1022 
   1023          png_ptr->num_rows = (png_ptr->height +
   1024              png_pass_yinc[png_ptr->pass] - 1 -
   1025              png_pass_ystart[png_ptr->pass]) /
   1026              png_pass_yinc[png_ptr->pass];
   1027 
   1028       } while (png_ptr->iwidth == 0 || png_ptr->num_rows == 0);
   1029    }
   1030 #endif /* READ_INTERLACING */
   1031 }
   1032 
   1033 void /* PRIVATE */
   1034 png_push_have_info(png_structrp png_ptr, png_inforp info_ptr)
   1035 {
   1036    if (png_ptr->info_fn != NULL)
   1037       (*(png_ptr->info_fn))(png_ptr, info_ptr);
   1038 }
   1039 
   1040 void /* PRIVATE */
   1041 png_push_have_end(png_structrp png_ptr, png_inforp info_ptr)
   1042 {
   1043    if (png_ptr->end_fn != NULL)
   1044       (*(png_ptr->end_fn))(png_ptr, info_ptr);
   1045 }
   1046 
   1047 void /* PRIVATE */
   1048 png_push_have_row(png_structrp png_ptr, png_bytep row)
   1049 {
   1050    if (png_ptr->row_fn != NULL)
   1051       (*(png_ptr->row_fn))(png_ptr, row, png_ptr->row_number,
   1052           (int)png_ptr->pass);
   1053 }
   1054 
   1055 #ifdef PNG_READ_INTERLACING_SUPPORTED
   1056 void PNGAPI
   1057 png_progressive_combine_row(png_const_structrp png_ptr, png_bytep old_row,
   1058     png_const_bytep new_row)
   1059 {
   1060    if (png_ptr == NULL)
   1061       return;
   1062 
   1063    /* new_row is a flag here - if it is NULL then the app callback was called
   1064     * from an empty row (see the calls to png_struct::row_fn below), otherwise
   1065     * it must be png_ptr->row_buf+1
   1066     */
   1067    if (new_row != NULL)
   1068       png_combine_row(png_ptr, old_row, 1/*blocky display*/);
   1069 }
   1070 #endif /* READ_INTERLACING */
   1071 
   1072 void PNGAPI
   1073 png_set_progressive_read_fn(png_structrp png_ptr, png_voidp progressive_ptr,
   1074     png_progressive_info_ptr info_fn, png_progressive_row_ptr row_fn,
   1075     png_progressive_end_ptr end_fn)
   1076 {
   1077    if (png_ptr == NULL)
   1078       return;
   1079 
   1080    png_ptr->info_fn = info_fn;
   1081    png_ptr->row_fn = row_fn;
   1082    png_ptr->end_fn = end_fn;
   1083 
   1084    png_set_read_fn(png_ptr, progressive_ptr, png_push_fill_buffer);
   1085 }
   1086 
   1087 png_voidp PNGAPI
   1088 png_get_progressive_ptr(png_const_structrp png_ptr)
   1089 {
   1090    if (png_ptr == NULL)
   1091       return (NULL);
   1092 
   1093    return png_ptr->io_ptr;
   1094 }
   1095 #endif /* PROGRESSIVE_READ */
   1096