Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(344)

Side by Side Diff: third_party/libpng/pngpread.c

Issue 23494067: Revert "libpng 1.6.3" (Closed) Base URL: svn://svn.chromium.org/chrome/trunk/src
Patch Set: Created 7 years, 2 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch | Annotate | Revision Log
« no previous file with comments | « third_party/libpng/pngmem.c ('k') | third_party/libpng/pngpriv.h » ('j') | no next file with comments »
Toggle Intra-line Diffs ('i') | Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
OLDNEW
1 1
2 /* pngpread.c - read a png file in push mode 2 /* pngpread.c - read a png file in push mode
3 * 3 *
4 * Last changed in libpng 1.6.0 [February 14, 2013] 4 * Last changed in libpng 1.2.44 [June 26, 2010]
5 * Copyright (c) 1998-2013 Glenn Randers-Pehrson 5 * Copyright (c) 1998-2010 Glenn Randers-Pehrson
6 * (Version 0.96 Copyright (c) 1996, 1997 Andreas Dilger) 6 * (Version 0.96 Copyright (c) 1996, 1997 Andreas Dilger)
7 * (Version 0.88 Copyright (c) 1995, 1996 Guy Eric Schalnat, Group 42, Inc.) 7 * (Version 0.88 Copyright (c) 1995, 1996 Guy Eric Schalnat, Group 42, Inc.)
8 * 8 *
9 * This code is released under the libpng license. 9 * This code is released under the libpng license.
10 * For conditions of distribution and use, see the disclaimer 10 * For conditions of distribution and use, see the disclaimer
11 * and license in png.h 11 * and license in png.h
12 */ 12 */
13 13
14 #include "pngpriv.h" 14 #define PNG_INTERNAL
15 15 #define PNG_NO_PEDANTIC_WARNINGS
16 #include "png.h"
16 #ifdef PNG_PROGRESSIVE_READ_SUPPORTED 17 #ifdef PNG_PROGRESSIVE_READ_SUPPORTED
17 18
18 /* Push model modes */ 19 /* Push model modes */
19 #define PNG_READ_SIG_MODE 0 20 #define PNG_READ_SIG_MODE 0
20 #define PNG_READ_CHUNK_MODE 1 21 #define PNG_READ_CHUNK_MODE 1
21 #define PNG_READ_IDAT_MODE 2 22 #define PNG_READ_IDAT_MODE 2
22 #define PNG_SKIP_MODE 3 23 #define PNG_SKIP_MODE 3
23 #define PNG_READ_tEXt_MODE 4 24 #define PNG_READ_tEXt_MODE 4
24 #define PNG_READ_zTXt_MODE 5 25 #define PNG_READ_zTXt_MODE 5
25 #define PNG_READ_DONE_MODE 6 26 #define PNG_READ_DONE_MODE 6
26 #define PNG_READ_iTXt_MODE 7 27 #define PNG_READ_iTXt_MODE 7
27 #define PNG_ERROR_MODE 8 28 #define PNG_ERROR_MODE 8
28 29
29 void PNGAPI 30 void PNGAPI
30 png_process_data(png_structrp png_ptr, png_inforp info_ptr, 31 png_process_data(png_structp png_ptr, png_infop info_ptr,
31 png_bytep buffer, png_size_t buffer_size) 32 png_bytep buffer, png_size_t buffer_size)
32 { 33 {
33 if (png_ptr == NULL || info_ptr == NULL) 34 if (png_ptr == NULL || info_ptr == NULL)
34 return; 35 return;
35 36
36 png_push_restore_buffer(png_ptr, buffer, buffer_size); 37 png_push_restore_buffer(png_ptr, buffer, buffer_size);
37 38
38 while (png_ptr->buffer_size) 39 while (png_ptr->buffer_size)
39 { 40 {
40 png_process_some_data(png_ptr, info_ptr); 41 png_process_some_data(png_ptr, info_ptr);
41 } 42 }
42 } 43 }
43 44
44 png_size_t PNGAPI
45 png_process_data_pause(png_structrp png_ptr, int save)
46 {
47 if (png_ptr != NULL)
48 {
49 /* It's easiest for the caller if we do the save, then the caller doesn't
50 * have to supply the same data again:
51 */
52 if (save)
53 png_push_save_buffer(png_ptr);
54 else
55 {
56 /* This includes any pending saved bytes: */
57 png_size_t remaining = png_ptr->buffer_size;
58 png_ptr->buffer_size = 0;
59
60 /* So subtract the saved buffer size, unless all the data
61 * is actually 'saved', in which case we just return 0
62 */
63 if (png_ptr->save_buffer_size < remaining)
64 return remaining - png_ptr->save_buffer_size;
65 }
66 }
67
68 return 0;
69 }
70
71 png_uint_32 PNGAPI
72 png_process_data_skip(png_structrp png_ptr)
73 {
74 png_uint_32 remaining = 0;
75
76 if (png_ptr != NULL && png_ptr->process_mode == PNG_SKIP_MODE &&
77 png_ptr->skip_length > 0)
78 {
79 /* At the end of png_process_data the buffer size must be 0 (see the loop
80 * above) so we can detect a broken call here:
81 */
82 if (png_ptr->buffer_size != 0)
83 png_error(png_ptr,
84 "png_process_data_skip called inside png_process_data");
85
86 /* If is impossible for there to be a saved buffer at this point -
87 * otherwise we could not be in SKIP mode. This will also happen if
88 * png_process_skip is called inside png_process_data (but only very
89 * rarely.)
90 */
91 if (png_ptr->save_buffer_size != 0)
92 png_error(png_ptr, "png_process_data_skip called with saved data");
93
94 remaining = png_ptr->skip_length;
95 png_ptr->skip_length = 0;
96 png_ptr->process_mode = PNG_READ_CHUNK_MODE;
97 }
98
99 return remaining;
100 }
101
102 /* What we do with the incoming data depends on what we were previously 45 /* What we do with the incoming data depends on what we were previously
103 * doing before we ran out of data... 46 * doing before we ran out of data...
104 */ 47 */
105 void /* PRIVATE */ 48 void /* PRIVATE */
106 png_process_some_data(png_structrp png_ptr, png_inforp info_ptr) 49 png_process_some_data(png_structp png_ptr, png_infop info_ptr)
107 { 50 {
108 if (png_ptr == NULL) 51 if (png_ptr == NULL)
109 return; 52 return;
110 53
111 switch (png_ptr->process_mode) 54 switch (png_ptr->process_mode)
112 { 55 {
113 case PNG_READ_SIG_MODE: 56 case PNG_READ_SIG_MODE:
114 { 57 {
115 png_push_read_sig(png_ptr, info_ptr); 58 png_push_read_sig(png_ptr, info_ptr);
116 break; 59 break;
117 } 60 }
118 61
119 case PNG_READ_CHUNK_MODE: 62 case PNG_READ_CHUNK_MODE:
120 { 63 {
121 png_push_read_chunk(png_ptr, info_ptr); 64 png_push_read_chunk(png_ptr, info_ptr);
122 break; 65 break;
123 } 66 }
124 67
125 case PNG_READ_IDAT_MODE: 68 case PNG_READ_IDAT_MODE:
126 { 69 {
127 png_push_read_IDAT(png_ptr); 70 png_push_read_IDAT(png_ptr);
128 break; 71 break;
129 } 72 }
130 73
74 #ifdef PNG_READ_tEXt_SUPPORTED
75 case PNG_READ_tEXt_MODE:
76 {
77 png_push_read_tEXt(png_ptr, info_ptr);
78 break;
79 }
80
81 #endif
82 #ifdef PNG_READ_zTXt_SUPPORTED
83 case PNG_READ_zTXt_MODE:
84 {
85 png_push_read_zTXt(png_ptr, info_ptr);
86 break;
87 }
88
89 #endif
90 #ifdef PNG_READ_iTXt_SUPPORTED
91 case PNG_READ_iTXt_MODE:
92 {
93 png_push_read_iTXt(png_ptr, info_ptr);
94 break;
95 }
96
97 #endif
131 case PNG_SKIP_MODE: 98 case PNG_SKIP_MODE:
132 { 99 {
133 png_push_crc_finish(png_ptr); 100 png_push_crc_finish(png_ptr);
134 break; 101 break;
135 } 102 }
136 103
137 default: 104 default:
138 { 105 {
139 png_ptr->buffer_size = 0; 106 png_ptr->buffer_size = 0;
140 break; 107 break;
141 } 108 }
142 } 109 }
143 } 110 }
144 111
145 /* Read any remaining signature bytes from the stream and compare them with 112 /* Read any remaining signature bytes from the stream and compare them with
146 * the correct PNG signature. It is possible that this routine is called 113 * the correct PNG signature. It is possible that this routine is called
147 * with bytes already read from the signature, either because they have been 114 * with bytes already read from the signature, either because they have been
148 * checked by the calling application, or because of multiple calls to this 115 * checked by the calling application, or because of multiple calls to this
149 * routine. 116 * routine.
150 */ 117 */
151 void /* PRIVATE */ 118 void /* PRIVATE */
152 png_push_read_sig(png_structrp png_ptr, png_inforp info_ptr) 119 png_push_read_sig(png_structp png_ptr, png_infop info_ptr)
153 { 120 {
154 png_size_t num_checked = png_ptr->sig_bytes, /* SAFE, does not exceed 8 */ 121 png_size_t num_checked = png_ptr->sig_bytes,
155 num_to_check = 8 - num_checked; 122 num_to_check = 8 - num_checked;
156 123
157 if (png_ptr->buffer_size < num_to_check) 124 if (png_ptr->buffer_size < num_to_check)
158 { 125 {
159 num_to_check = png_ptr->buffer_size; 126 num_to_check = png_ptr->buffer_size;
160 } 127 }
161 128
162 png_push_fill_buffer(png_ptr, &(info_ptr->signature[num_checked]), 129 png_push_fill_buffer(png_ptr, &(info_ptr->signature[num_checked]),
163 num_to_check); 130 num_to_check);
164 png_ptr->sig_bytes = (png_byte)(png_ptr->sig_bytes + num_to_check); 131 png_ptr->sig_bytes = (png_byte)(png_ptr->sig_bytes + num_to_check);
165 132
166 if (png_sig_cmp(info_ptr->signature, num_checked, num_to_check)) 133 if (png_sig_cmp(info_ptr->signature, num_checked, num_to_check))
167 { 134 {
168 if (num_checked < 4 && 135 if (num_checked < 4 &&
169 png_sig_cmp(info_ptr->signature, num_checked, num_to_check - 4)) 136 png_sig_cmp(info_ptr->signature, num_checked, num_to_check - 4))
170 png_error(png_ptr, "Not a PNG file"); 137 png_error(png_ptr, "Not a PNG file");
171
172 else 138 else
173 png_error(png_ptr, "PNG file corrupted by ASCII conversion"); 139 png_error(png_ptr, "PNG file corrupted by ASCII conversion");
174 } 140 }
175 else 141 else
176 { 142 {
177 if (png_ptr->sig_bytes >= 8) 143 if (png_ptr->sig_bytes >= 8)
178 { 144 {
179 png_ptr->process_mode = PNG_READ_CHUNK_MODE; 145 png_ptr->process_mode = PNG_READ_CHUNK_MODE;
180 } 146 }
181 } 147 }
182 } 148 }
183 149
184 void /* PRIVATE */ 150 void /* PRIVATE */
185 png_push_read_chunk(png_structrp png_ptr, png_inforp info_ptr) 151 png_push_read_chunk(png_structp png_ptr, png_infop info_ptr)
186 { 152 {
187 png_uint_32 chunk_name; 153 #ifdef PNG_USE_LOCAL_ARRAYS
188 #ifdef PNG_HANDLE_AS_UNKNOWN_SUPPORTED 154 PNG_CONST PNG_IHDR;
189 int keep; /* unknown handling method */ 155 PNG_CONST PNG_IDAT;
156 PNG_CONST PNG_IEND;
157 PNG_CONST PNG_PLTE;
158 #ifdef PNG_READ_bKGD_SUPPORTED
159 PNG_CONST PNG_bKGD;
190 #endif 160 #endif
161 #ifdef PNG_READ_cHRM_SUPPORTED
162 PNG_CONST PNG_cHRM;
163 #endif
164 #ifdef PNG_READ_gAMA_SUPPORTED
165 PNG_CONST PNG_gAMA;
166 #endif
167 #ifdef PNG_READ_hIST_SUPPORTED
168 PNG_CONST PNG_hIST;
169 #endif
170 #ifdef PNG_READ_iCCP_SUPPORTED
171 PNG_CONST PNG_iCCP;
172 #endif
173 #ifdef PNG_READ_iTXt_SUPPORTED
174 PNG_CONST PNG_iTXt;
175 #endif
176 #ifdef PNG_READ_oFFs_SUPPORTED
177 PNG_CONST PNG_oFFs;
178 #endif
179 #ifdef PNG_READ_pCAL_SUPPORTED
180 PNG_CONST PNG_pCAL;
181 #endif
182 #ifdef PNG_READ_pHYs_SUPPORTED
183 PNG_CONST PNG_pHYs;
184 #endif
185 #ifdef PNG_READ_sBIT_SUPPORTED
186 PNG_CONST PNG_sBIT;
187 #endif
188 #ifdef PNG_READ_sCAL_SUPPORTED
189 PNG_CONST PNG_sCAL;
190 #endif
191 #ifdef PNG_READ_sRGB_SUPPORTED
192 PNG_CONST PNG_sRGB;
193 #endif
194 #ifdef PNG_READ_sPLT_SUPPORTED
195 PNG_CONST PNG_sPLT;
196 #endif
197 #ifdef PNG_READ_tEXt_SUPPORTED
198 PNG_CONST PNG_tEXt;
199 #endif
200 #ifdef PNG_READ_tIME_SUPPORTED
201 PNG_CONST PNG_tIME;
202 #endif
203 #ifdef PNG_READ_tRNS_SUPPORTED
204 PNG_CONST PNG_tRNS;
205 #endif
206 #ifdef PNG_READ_zTXt_SUPPORTED
207 PNG_CONST PNG_zTXt;
208 #endif
209 #endif /* PNG_USE_LOCAL_ARRAYS */
191 210
192 /* First we make sure we have enough data for the 4 byte chunk name 211 /* First we make sure we have enough data for the 4 byte chunk name
193 * and the 4 byte chunk length before proceeding with decoding the 212 * and the 4 byte chunk length before proceeding with decoding the
194 * chunk data. To fully decode each of these chunks, we also make 213 * chunk data. To fully decode each of these chunks, we also make
195 * sure we have enough data in the buffer for the 4 byte CRC at the 214 * sure we have enough data in the buffer for the 4 byte CRC at the
196 * end of every chunk (except IDAT, which is handled separately). 215 * end of every chunk (except IDAT, which is handled separately).
197 */ 216 */
198 if (!(png_ptr->mode & PNG_HAVE_CHUNK_HEADER)) 217 if (!(png_ptr->mode & PNG_HAVE_CHUNK_HEADER))
199 { 218 {
200 png_byte chunk_length[4]; 219 png_byte chunk_length[4];
201 png_byte chunk_tag[4];
202 220
203 if (png_ptr->buffer_size < 8) 221 if (png_ptr->buffer_size < 8)
204 { 222 {
205 png_push_save_buffer(png_ptr); 223 png_push_save_buffer(png_ptr);
206 return; 224 return;
207 } 225 }
208 226
209 png_push_fill_buffer(png_ptr, chunk_length, 4); 227 png_push_fill_buffer(png_ptr, chunk_length, 4);
210 png_ptr->push_length = png_get_uint_31(png_ptr, chunk_length); 228 png_ptr->push_length = png_get_uint_31(png_ptr, chunk_length);
211 png_reset_crc(png_ptr); 229 png_reset_crc(png_ptr);
212 png_crc_read(png_ptr, chunk_tag, 4); 230 png_crc_read(png_ptr, png_ptr->chunk_name, 4);
213 png_ptr->chunk_name = PNG_CHUNK_FROM_STRING(chunk_tag);
214 png_check_chunk_name(png_ptr, png_ptr->chunk_name); 231 png_check_chunk_name(png_ptr, png_ptr->chunk_name);
215 png_ptr->mode |= PNG_HAVE_CHUNK_HEADER; 232 png_ptr->mode |= PNG_HAVE_CHUNK_HEADER;
216 } 233 }
217 234
218 chunk_name = png_ptr->chunk_name; 235 if (!png_memcmp(png_ptr->chunk_name, png_IDAT, 4))
236 if (png_ptr->mode & PNG_AFTER_IDAT)
237 png_ptr->mode |= PNG_HAVE_CHUNK_AFTER_IDAT;
219 238
220 if (chunk_name == png_IDAT) 239 if (!png_memcmp(png_ptr->chunk_name, png_IHDR, 4))
221 {
222 if (png_ptr->mode & PNG_AFTER_IDAT)
223 png_ptr->mode |= PNG_HAVE_CHUNK_AFTER_IDAT;
224
225 /* If we reach an IDAT chunk, this means we have read all of the
226 * header chunks, and we can start reading the image (or if this
227 * is called after the image has been read - we have an error).
228 */
229 if (!(png_ptr->mode & PNG_HAVE_IHDR))
230 png_error(png_ptr, "Missing IHDR before IDAT");
231
232 else if (png_ptr->color_type == PNG_COLOR_TYPE_PALETTE &&
233 !(png_ptr->mode & PNG_HAVE_PLTE))
234 png_error(png_ptr, "Missing PLTE before IDAT");
235
236 png_ptr->mode |= PNG_HAVE_IDAT;
237
238 if (!(png_ptr->mode & PNG_HAVE_CHUNK_AFTER_IDAT))
239 if (png_ptr->push_length == 0)
240 return;
241
242 if (png_ptr->mode & PNG_AFTER_IDAT)
243 png_benign_error(png_ptr, "Too many IDATs found");
244 }
245
246 if (chunk_name == png_IHDR)
247 { 240 {
248 if (png_ptr->push_length != 13) 241 if (png_ptr->push_length != 13)
249 png_error(png_ptr, "Invalid IHDR length"); 242 png_error(png_ptr, "Invalid IHDR length");
250 243
251 if (png_ptr->push_length + 4 > png_ptr->buffer_size) 244 if (png_ptr->push_length + 4 > png_ptr->buffer_size)
252 { 245 {
253 png_push_save_buffer(png_ptr); 246 png_push_save_buffer(png_ptr);
254 return; 247 return;
255 } 248 }
256 249
257 png_handle_IHDR(png_ptr, info_ptr, png_ptr->push_length); 250 png_handle_IHDR(png_ptr, info_ptr, png_ptr->push_length);
258 } 251 }
259 252
260 else if (chunk_name == png_IEND) 253 else if (!png_memcmp(png_ptr->chunk_name, png_IEND, 4))
261 { 254 {
262 if (png_ptr->push_length + 4 > png_ptr->buffer_size) 255 if (png_ptr->push_length + 4 > png_ptr->buffer_size)
263 { 256 {
264 png_push_save_buffer(png_ptr); 257 png_push_save_buffer(png_ptr);
265 return; 258 return;
266 } 259 }
267 260
268 png_handle_IEND(png_ptr, info_ptr, png_ptr->push_length); 261 png_handle_IEND(png_ptr, info_ptr, png_ptr->push_length);
269 262
270 png_ptr->process_mode = PNG_READ_DONE_MODE; 263 png_ptr->process_mode = PNG_READ_DONE_MODE;
271 png_push_have_end(png_ptr, info_ptr); 264 png_push_have_end(png_ptr, info_ptr);
272 } 265 }
273 266
274 #ifdef PNG_HANDLE_AS_UNKNOWN_SUPPORTED 267 #ifdef PNG_HANDLE_AS_UNKNOWN_SUPPORTED
275 else if ((keep = png_chunk_unknown_handling(png_ptr, chunk_name)) != 0) 268 else if (png_handle_as_unknown(png_ptr, png_ptr->chunk_name))
276 { 269 {
277 if (png_ptr->push_length + 4 > png_ptr->buffer_size) 270 if (png_ptr->push_length + 4 > png_ptr->buffer_size)
278 { 271 {
279 png_push_save_buffer(png_ptr); 272 png_push_save_buffer(png_ptr);
280 return; 273 return;
281 } 274 }
282 275
283 png_handle_unknown(png_ptr, info_ptr, png_ptr->push_length, keep); 276 if (!png_memcmp(png_ptr->chunk_name, png_IDAT, 4))
277 png_ptr->mode |= PNG_HAVE_IDAT;
284 278
285 if (chunk_name == png_PLTE) 279 png_handle_unknown(png_ptr, info_ptr, png_ptr->push_length);
280
281 if (!png_memcmp(png_ptr->chunk_name, png_PLTE, 4))
286 png_ptr->mode |= PNG_HAVE_PLTE; 282 png_ptr->mode |= PNG_HAVE_PLTE;
283
284 else if (!png_memcmp(png_ptr->chunk_name, png_IDAT, 4))
285 {
286 if (!(png_ptr->mode & PNG_HAVE_IHDR))
287 png_error(png_ptr, "Missing IHDR before IDAT");
288
289 else if (png_ptr->color_type == PNG_COLOR_TYPE_PALETTE &&
290 !(png_ptr->mode & PNG_HAVE_PLTE))
291 png_error(png_ptr, "Missing PLTE before IDAT");
292 }
287 } 293 }
288 294
289 #endif 295 #endif
290 else if (chunk_name == png_PLTE) 296 else if (!png_memcmp(png_ptr->chunk_name, png_PLTE, 4))
291 { 297 {
292 if (png_ptr->push_length + 4 > png_ptr->buffer_size) 298 if (png_ptr->push_length + 4 > png_ptr->buffer_size)
293 { 299 {
294 png_push_save_buffer(png_ptr); 300 png_push_save_buffer(png_ptr);
295 return; 301 return;
296 } 302 }
297 png_handle_PLTE(png_ptr, info_ptr, png_ptr->push_length); 303 png_handle_PLTE(png_ptr, info_ptr, png_ptr->push_length);
298 } 304 }
299 305
300 else if (chunk_name == png_IDAT) 306 else if (!png_memcmp(png_ptr->chunk_name, png_IDAT, 4))
301 { 307 {
308 /* If we reach an IDAT chunk, this means we have read all of the
309 * header chunks, and we can start reading the image (or if this
310 * is called after the image has been read - we have an error).
311 */
312
313 if (!(png_ptr->mode & PNG_HAVE_IHDR))
314 png_error(png_ptr, "Missing IHDR before IDAT");
315
316 else if (png_ptr->color_type == PNG_COLOR_TYPE_PALETTE &&
317 !(png_ptr->mode & PNG_HAVE_PLTE))
318 png_error(png_ptr, "Missing PLTE before IDAT");
319
320 if (png_ptr->mode & PNG_HAVE_IDAT)
321 {
322 if (!(png_ptr->mode & PNG_HAVE_CHUNK_AFTER_IDAT))
323 if (png_ptr->push_length == 0)
324 return;
325
326 if (png_ptr->mode & PNG_AFTER_IDAT)
327 png_error(png_ptr, "Too many IDAT's found");
328 }
329
302 png_ptr->idat_size = png_ptr->push_length; 330 png_ptr->idat_size = png_ptr->push_length;
331 png_ptr->mode |= PNG_HAVE_IDAT;
303 png_ptr->process_mode = PNG_READ_IDAT_MODE; 332 png_ptr->process_mode = PNG_READ_IDAT_MODE;
304 png_push_have_info(png_ptr, info_ptr); 333 png_push_have_info(png_ptr, info_ptr);
305 png_ptr->zstream.avail_out = 334 png_ptr->zstream.avail_out =
306 (uInt) PNG_ROWBYTES(png_ptr->pixel_depth, 335 (uInt) PNG_ROWBYTES(png_ptr->pixel_depth,
307 png_ptr->iwidth) + 1; 336 png_ptr->iwidth) + 1;
308 png_ptr->zstream.next_out = png_ptr->row_buf; 337 png_ptr->zstream.next_out = png_ptr->row_buf;
309 return; 338 return;
310 } 339 }
311 340
312 #ifdef PNG_READ_gAMA_SUPPORTED 341 #ifdef PNG_READ_gAMA_SUPPORTED
313 else if (png_ptr->chunk_name == png_gAMA) 342 else if (!png_memcmp(png_ptr->chunk_name, png_gAMA, 4))
314 { 343 {
315 if (png_ptr->push_length + 4 > png_ptr->buffer_size) 344 if (png_ptr->push_length + 4 > png_ptr->buffer_size)
316 { 345 {
317 png_push_save_buffer(png_ptr); 346 png_push_save_buffer(png_ptr);
318 return; 347 return;
319 } 348 }
320 349
321 png_handle_gAMA(png_ptr, info_ptr, png_ptr->push_length); 350 png_handle_gAMA(png_ptr, info_ptr, png_ptr->push_length);
322 } 351 }
323 352
324 #endif 353 #endif
325 #ifdef PNG_READ_sBIT_SUPPORTED 354 #ifdef PNG_READ_sBIT_SUPPORTED
326 else if (png_ptr->chunk_name == png_sBIT) 355 else if (!png_memcmp(png_ptr->chunk_name, png_sBIT, 4))
327 { 356 {
328 if (png_ptr->push_length + 4 > png_ptr->buffer_size) 357 if (png_ptr->push_length + 4 > png_ptr->buffer_size)
329 { 358 {
330 png_push_save_buffer(png_ptr); 359 png_push_save_buffer(png_ptr);
331 return; 360 return;
332 } 361 }
333 362
334 png_handle_sBIT(png_ptr, info_ptr, png_ptr->push_length); 363 png_handle_sBIT(png_ptr, info_ptr, png_ptr->push_length);
335 } 364 }
336 365
337 #endif 366 #endif
338 #ifdef PNG_READ_cHRM_SUPPORTED 367 #ifdef PNG_READ_cHRM_SUPPORTED
339 else if (png_ptr->chunk_name == png_cHRM) 368 else if (!png_memcmp(png_ptr->chunk_name, png_cHRM, 4))
340 { 369 {
341 if (png_ptr->push_length + 4 > png_ptr->buffer_size) 370 if (png_ptr->push_length + 4 > png_ptr->buffer_size)
342 { 371 {
343 png_push_save_buffer(png_ptr); 372 png_push_save_buffer(png_ptr);
344 return; 373 return;
345 } 374 }
346 375
347 png_handle_cHRM(png_ptr, info_ptr, png_ptr->push_length); 376 png_handle_cHRM(png_ptr, info_ptr, png_ptr->push_length);
348 } 377 }
349 378
350 #endif 379 #endif
351 #ifdef PNG_READ_sRGB_SUPPORTED 380 #ifdef PNG_READ_sRGB_SUPPORTED
352 else if (chunk_name == png_sRGB) 381 else if (!png_memcmp(png_ptr->chunk_name, png_sRGB, 4))
353 { 382 {
354 if (png_ptr->push_length + 4 > png_ptr->buffer_size) 383 if (png_ptr->push_length + 4 > png_ptr->buffer_size)
355 { 384 {
356 png_push_save_buffer(png_ptr); 385 png_push_save_buffer(png_ptr);
357 return; 386 return;
358 } 387 }
359 388
360 png_handle_sRGB(png_ptr, info_ptr, png_ptr->push_length); 389 png_handle_sRGB(png_ptr, info_ptr, png_ptr->push_length);
361 } 390 }
362 391
363 #endif 392 #endif
364 #ifdef PNG_READ_iCCP_SUPPORTED 393 #ifdef PNG_READ_iCCP_SUPPORTED
365 else if (png_ptr->chunk_name == png_iCCP) 394 else if (!png_memcmp(png_ptr->chunk_name, png_iCCP, 4))
366 { 395 {
367 if (png_ptr->push_length + 4 > png_ptr->buffer_size) 396 if (png_ptr->push_length + 4 > png_ptr->buffer_size)
368 { 397 {
369 png_push_save_buffer(png_ptr); 398 png_push_save_buffer(png_ptr);
370 return; 399 return;
371 } 400 }
372 401
373 png_handle_iCCP(png_ptr, info_ptr, png_ptr->push_length); 402 png_handle_iCCP(png_ptr, info_ptr, png_ptr->push_length);
374 } 403 }
375 404
376 #endif 405 #endif
377 #ifdef PNG_READ_sPLT_SUPPORTED 406 #ifdef PNG_READ_sPLT_SUPPORTED
378 else if (chunk_name == png_sPLT) 407 else if (!png_memcmp(png_ptr->chunk_name, png_sPLT, 4))
379 { 408 {
380 if (png_ptr->push_length + 4 > png_ptr->buffer_size) 409 if (png_ptr->push_length + 4 > png_ptr->buffer_size)
381 { 410 {
382 png_push_save_buffer(png_ptr); 411 png_push_save_buffer(png_ptr);
383 return; 412 return;
384 } 413 }
385 414
386 png_handle_sPLT(png_ptr, info_ptr, png_ptr->push_length); 415 png_handle_sPLT(png_ptr, info_ptr, png_ptr->push_length);
387 } 416 }
388 417
389 #endif 418 #endif
390 #ifdef PNG_READ_tRNS_SUPPORTED 419 #ifdef PNG_READ_tRNS_SUPPORTED
391 else if (chunk_name == png_tRNS) 420 else if (!png_memcmp(png_ptr->chunk_name, png_tRNS, 4))
392 { 421 {
393 if (png_ptr->push_length + 4 > png_ptr->buffer_size) 422 if (png_ptr->push_length + 4 > png_ptr->buffer_size)
394 { 423 {
395 png_push_save_buffer(png_ptr); 424 png_push_save_buffer(png_ptr);
396 return; 425 return;
397 } 426 }
398 427
399 png_handle_tRNS(png_ptr, info_ptr, png_ptr->push_length); 428 png_handle_tRNS(png_ptr, info_ptr, png_ptr->push_length);
400 } 429 }
401 430
402 #endif 431 #endif
403 #ifdef PNG_READ_bKGD_SUPPORTED 432 #ifdef PNG_READ_bKGD_SUPPORTED
404 else if (chunk_name == png_bKGD) 433 else if (!png_memcmp(png_ptr->chunk_name, png_bKGD, 4))
405 { 434 {
406 if (png_ptr->push_length + 4 > png_ptr->buffer_size) 435 if (png_ptr->push_length + 4 > png_ptr->buffer_size)
407 { 436 {
408 png_push_save_buffer(png_ptr); 437 png_push_save_buffer(png_ptr);
409 return; 438 return;
410 } 439 }
411 440
412 png_handle_bKGD(png_ptr, info_ptr, png_ptr->push_length); 441 png_handle_bKGD(png_ptr, info_ptr, png_ptr->push_length);
413 } 442 }
414 443
415 #endif 444 #endif
416 #ifdef PNG_READ_hIST_SUPPORTED 445 #ifdef PNG_READ_hIST_SUPPORTED
417 else if (chunk_name == png_hIST) 446 else if (!png_memcmp(png_ptr->chunk_name, png_hIST, 4))
418 { 447 {
419 if (png_ptr->push_length + 4 > png_ptr->buffer_size) 448 if (png_ptr->push_length + 4 > png_ptr->buffer_size)
420 { 449 {
421 png_push_save_buffer(png_ptr); 450 png_push_save_buffer(png_ptr);
422 return; 451 return;
423 } 452 }
424 453
425 png_handle_hIST(png_ptr, info_ptr, png_ptr->push_length); 454 png_handle_hIST(png_ptr, info_ptr, png_ptr->push_length);
426 } 455 }
427 456
428 #endif 457 #endif
429 #ifdef PNG_READ_pHYs_SUPPORTED 458 #ifdef PNG_READ_pHYs_SUPPORTED
430 else if (chunk_name == png_pHYs) 459 else if (!png_memcmp(png_ptr->chunk_name, png_pHYs, 4))
431 { 460 {
432 if (png_ptr->push_length + 4 > png_ptr->buffer_size) 461 if (png_ptr->push_length + 4 > png_ptr->buffer_size)
433 { 462 {
434 png_push_save_buffer(png_ptr); 463 png_push_save_buffer(png_ptr);
435 return; 464 return;
436 } 465 }
437 466
438 png_handle_pHYs(png_ptr, info_ptr, png_ptr->push_length); 467 png_handle_pHYs(png_ptr, info_ptr, png_ptr->push_length);
439 } 468 }
440 469
441 #endif 470 #endif
442 #ifdef PNG_READ_oFFs_SUPPORTED 471 #ifdef PNG_READ_oFFs_SUPPORTED
443 else if (chunk_name == png_oFFs) 472 else if (!png_memcmp(png_ptr->chunk_name, png_oFFs, 4))
444 { 473 {
445 if (png_ptr->push_length + 4 > png_ptr->buffer_size) 474 if (png_ptr->push_length + 4 > png_ptr->buffer_size)
446 { 475 {
447 png_push_save_buffer(png_ptr); 476 png_push_save_buffer(png_ptr);
448 return; 477 return;
449 } 478 }
450 479
451 png_handle_oFFs(png_ptr, info_ptr, png_ptr->push_length); 480 png_handle_oFFs(png_ptr, info_ptr, png_ptr->push_length);
452 } 481 }
453 #endif 482 #endif
454 483
455 #ifdef PNG_READ_pCAL_SUPPORTED 484 #ifdef PNG_READ_pCAL_SUPPORTED
456 else if (chunk_name == png_pCAL) 485 else if (!png_memcmp(png_ptr->chunk_name, png_pCAL, 4))
457 { 486 {
458 if (png_ptr->push_length + 4 > png_ptr->buffer_size) 487 if (png_ptr->push_length + 4 > png_ptr->buffer_size)
459 { 488 {
460 png_push_save_buffer(png_ptr); 489 png_push_save_buffer(png_ptr);
461 return; 490 return;
462 } 491 }
463 492
464 png_handle_pCAL(png_ptr, info_ptr, png_ptr->push_length); 493 png_handle_pCAL(png_ptr, info_ptr, png_ptr->push_length);
465 } 494 }
466 495
467 #endif 496 #endif
468 #ifdef PNG_READ_sCAL_SUPPORTED 497 #ifdef PNG_READ_sCAL_SUPPORTED
469 else if (chunk_name == png_sCAL) 498 else if (!png_memcmp(png_ptr->chunk_name, png_sCAL, 4))
470 { 499 {
471 if (png_ptr->push_length + 4 > png_ptr->buffer_size) 500 if (png_ptr->push_length + 4 > png_ptr->buffer_size)
472 { 501 {
473 png_push_save_buffer(png_ptr); 502 png_push_save_buffer(png_ptr);
474 return; 503 return;
475 } 504 }
476 505
477 png_handle_sCAL(png_ptr, info_ptr, png_ptr->push_length); 506 png_handle_sCAL(png_ptr, info_ptr, png_ptr->push_length);
478 } 507 }
479 508
480 #endif 509 #endif
481 #ifdef PNG_READ_tIME_SUPPORTED 510 #ifdef PNG_READ_tIME_SUPPORTED
482 else if (chunk_name == png_tIME) 511 else if (!png_memcmp(png_ptr->chunk_name, png_tIME, 4))
483 { 512 {
484 if (png_ptr->push_length + 4 > png_ptr->buffer_size) 513 if (png_ptr->push_length + 4 > png_ptr->buffer_size)
485 { 514 {
486 png_push_save_buffer(png_ptr); 515 png_push_save_buffer(png_ptr);
487 return; 516 return;
488 } 517 }
489 518
490 png_handle_tIME(png_ptr, info_ptr, png_ptr->push_length); 519 png_handle_tIME(png_ptr, info_ptr, png_ptr->push_length);
491 } 520 }
492 521
493 #endif 522 #endif
494 #ifdef PNG_READ_tEXt_SUPPORTED 523 #ifdef PNG_READ_tEXt_SUPPORTED
495 else if (chunk_name == png_tEXt) 524 else if (!png_memcmp(png_ptr->chunk_name, png_tEXt, 4))
496 { 525 {
497 if (png_ptr->push_length + 4 > png_ptr->buffer_size) 526 if (png_ptr->push_length + 4 > png_ptr->buffer_size)
498 { 527 {
499 png_push_save_buffer(png_ptr); 528 png_push_save_buffer(png_ptr);
500 return; 529 return;
501 } 530 }
502 531
503 png_handle_tEXt(png_ptr, info_ptr, png_ptr->push_length); 532 png_push_handle_tEXt(png_ptr, info_ptr, png_ptr->push_length);
504 } 533 }
505 534
506 #endif 535 #endif
507 #ifdef PNG_READ_zTXt_SUPPORTED 536 #ifdef PNG_READ_zTXt_SUPPORTED
508 else if (chunk_name == png_zTXt) 537 else if (!png_memcmp(png_ptr->chunk_name, png_zTXt, 4))
509 { 538 {
510 if (png_ptr->push_length + 4 > png_ptr->buffer_size) 539 if (png_ptr->push_length + 4 > png_ptr->buffer_size)
511 { 540 {
512 png_push_save_buffer(png_ptr); 541 png_push_save_buffer(png_ptr);
513 return; 542 return;
514 } 543 }
515 544
516 png_handle_zTXt(png_ptr, info_ptr, png_ptr->push_length); 545 png_push_handle_zTXt(png_ptr, info_ptr, png_ptr->push_length);
517 } 546 }
518 547
519 #endif 548 #endif
520 #ifdef PNG_READ_iTXt_SUPPORTED 549 #ifdef PNG_READ_iTXt_SUPPORTED
521 else if (chunk_name == png_iTXt) 550 else if (!png_memcmp(png_ptr->chunk_name, png_iTXt, 4))
522 { 551 {
523 if (png_ptr->push_length + 4 > png_ptr->buffer_size) 552 if (png_ptr->push_length + 4 > png_ptr->buffer_size)
524 { 553 {
525 png_push_save_buffer(png_ptr); 554 png_push_save_buffer(png_ptr);
526 return; 555 return;
527 } 556 }
528 557
529 png_handle_iTXt(png_ptr, info_ptr, png_ptr->push_length); 558 png_push_handle_iTXt(png_ptr, info_ptr, png_ptr->push_length);
530 } 559 }
531 560
532 #endif 561 #endif
533 else 562 else
534 { 563 {
535 if (png_ptr->push_length + 4 > png_ptr->buffer_size) 564 if (png_ptr->push_length + 4 > png_ptr->buffer_size)
536 { 565 {
537 png_push_save_buffer(png_ptr); 566 png_push_save_buffer(png_ptr);
538 return; 567 return;
539 } 568 }
540 png_handle_unknown(png_ptr, info_ptr, png_ptr->push_length, 569 png_push_handle_unknown(png_ptr, info_ptr, png_ptr->push_length);
541 PNG_HANDLE_CHUNK_AS_DEFAULT);
542 } 570 }
543 571
544 png_ptr->mode &= ~PNG_HAVE_CHUNK_HEADER; 572 png_ptr->mode &= ~PNG_HAVE_CHUNK_HEADER;
545 } 573 }
546 574
547 void /* PRIVATE */ 575 void /* PRIVATE */
548 png_push_crc_skip(png_structrp png_ptr, png_uint_32 skip) 576 png_push_crc_skip(png_structp png_ptr, png_uint_32 skip)
549 { 577 {
550 png_ptr->process_mode = PNG_SKIP_MODE; 578 png_ptr->process_mode = PNG_SKIP_MODE;
551 png_ptr->skip_length = skip; 579 png_ptr->skip_length = skip;
552 } 580 }
553 581
554 void /* PRIVATE */ 582 void /* PRIVATE */
555 png_push_crc_finish(png_structrp png_ptr) 583 png_push_crc_finish(png_structp png_ptr)
556 { 584 {
557 if (png_ptr->skip_length && png_ptr->save_buffer_size) 585 if (png_ptr->skip_length && png_ptr->save_buffer_size)
558 { 586 {
559 png_size_t save_size = png_ptr->save_buffer_size; 587 png_size_t save_size;
560 png_uint_32 skip_length = png_ptr->skip_length;
561 588
562 /* We want the smaller of 'skip_length' and 'save_buffer_size', but 589 if (png_ptr->skip_length < (png_uint_32)png_ptr->save_buffer_size)
563 * they are of different types and we don't know which variable has the 590 save_size = (png_size_t)png_ptr->skip_length;
564 * fewest bits. Carefully select the smaller and cast it to the type of
565 * the larger - this cannot overflow. Do not cast in the following test
566 * - it will break on either 16 or 64 bit platforms.
567 */
568 if (skip_length < save_size)
569 save_size = (png_size_t)skip_length;
570
571 else 591 else
572 skip_length = (png_uint_32)save_size; 592 save_size = png_ptr->save_buffer_size;
573 593
574 png_calculate_crc(png_ptr, png_ptr->save_buffer_ptr, save_size); 594 png_calculate_crc(png_ptr, png_ptr->save_buffer_ptr, save_size);
575 595
576 png_ptr->skip_length -= skip_length; 596 png_ptr->skip_length -= save_size;
577 png_ptr->buffer_size -= save_size; 597 png_ptr->buffer_size -= save_size;
578 png_ptr->save_buffer_size -= save_size; 598 png_ptr->save_buffer_size -= save_size;
579 png_ptr->save_buffer_ptr += save_size; 599 png_ptr->save_buffer_ptr += save_size;
580 } 600 }
581 if (png_ptr->skip_length && png_ptr->current_buffer_size) 601 if (png_ptr->skip_length && png_ptr->current_buffer_size)
582 { 602 {
583 png_size_t save_size = png_ptr->current_buffer_size; 603 png_size_t save_size;
584 png_uint_32 skip_length = png_ptr->skip_length;
585 604
586 /* We want the smaller of 'skip_length' and 'current_buffer_size', here, 605 if (png_ptr->skip_length < (png_uint_32)png_ptr->current_buffer_size)
587 * the same problem exists as above and the same solution. 606 save_size = (png_size_t)png_ptr->skip_length;
588 */
589 if (skip_length < save_size)
590 save_size = (png_size_t)skip_length;
591
592 else 607 else
593 skip_length = (png_uint_32)save_size; 608 save_size = png_ptr->current_buffer_size;
594 609
595 png_calculate_crc(png_ptr, png_ptr->current_buffer_ptr, save_size); 610 png_calculate_crc(png_ptr, png_ptr->current_buffer_ptr, save_size);
596 611
597 png_ptr->skip_length -= skip_length; 612 png_ptr->skip_length -= save_size;
598 png_ptr->buffer_size -= save_size; 613 png_ptr->buffer_size -= save_size;
599 png_ptr->current_buffer_size -= save_size; 614 png_ptr->current_buffer_size -= save_size;
600 png_ptr->current_buffer_ptr += save_size; 615 png_ptr->current_buffer_ptr += save_size;
601 } 616 }
602 if (!png_ptr->skip_length) 617 if (!png_ptr->skip_length)
603 { 618 {
604 if (png_ptr->buffer_size < 4) 619 if (png_ptr->buffer_size < 4)
605 { 620 {
606 png_push_save_buffer(png_ptr); 621 png_push_save_buffer(png_ptr);
607 return; 622 return;
608 } 623 }
609 624
610 png_crc_finish(png_ptr, 0); 625 png_crc_finish(png_ptr, 0);
611 png_ptr->process_mode = PNG_READ_CHUNK_MODE; 626 png_ptr->process_mode = PNG_READ_CHUNK_MODE;
612 } 627 }
613 } 628 }
614 629
615 void PNGCBAPI 630 void PNGAPI
616 png_push_fill_buffer(png_structp png_ptr, png_bytep buffer, png_size_t length) 631 png_push_fill_buffer(png_structp png_ptr, png_bytep buffer, png_size_t length)
617 { 632 {
618 png_bytep ptr; 633 png_bytep ptr;
619 634
620 if (png_ptr == NULL) 635 if (png_ptr == NULL)
621 return; 636 return;
622 637
623 ptr = buffer; 638 ptr = buffer;
624 if (png_ptr->save_buffer_size) 639 if (png_ptr->save_buffer_size)
625 { 640 {
626 png_size_t save_size; 641 png_size_t save_size;
627 642
628 if (length < png_ptr->save_buffer_size) 643 if (length < png_ptr->save_buffer_size)
629 save_size = length; 644 save_size = length;
630
631 else 645 else
632 save_size = png_ptr->save_buffer_size; 646 save_size = png_ptr->save_buffer_size;
633 647
634 memcpy(ptr, png_ptr->save_buffer_ptr, save_size); 648 png_memcpy(ptr, png_ptr->save_buffer_ptr, save_size);
635 length -= save_size; 649 length -= save_size;
636 ptr += save_size; 650 ptr += save_size;
637 png_ptr->buffer_size -= save_size; 651 png_ptr->buffer_size -= save_size;
638 png_ptr->save_buffer_size -= save_size; 652 png_ptr->save_buffer_size -= save_size;
639 png_ptr->save_buffer_ptr += save_size; 653 png_ptr->save_buffer_ptr += save_size;
640 } 654 }
641 if (length && png_ptr->current_buffer_size) 655 if (length && png_ptr->current_buffer_size)
642 { 656 {
643 png_size_t save_size; 657 png_size_t save_size;
644 658
645 if (length < png_ptr->current_buffer_size) 659 if (length < png_ptr->current_buffer_size)
646 save_size = length; 660 save_size = length;
647 661
648 else 662 else
649 save_size = png_ptr->current_buffer_size; 663 save_size = png_ptr->current_buffer_size;
650 664
651 memcpy(ptr, png_ptr->current_buffer_ptr, save_size); 665 png_memcpy(ptr, png_ptr->current_buffer_ptr, save_size);
652 png_ptr->buffer_size -= save_size; 666 png_ptr->buffer_size -= save_size;
653 png_ptr->current_buffer_size -= save_size; 667 png_ptr->current_buffer_size -= save_size;
654 png_ptr->current_buffer_ptr += save_size; 668 png_ptr->current_buffer_ptr += save_size;
655 } 669 }
656 } 670 }
657 671
658 void /* PRIVATE */ 672 void /* PRIVATE */
659 png_push_save_buffer(png_structrp png_ptr) 673 png_push_save_buffer(png_structp png_ptr)
660 { 674 {
661 if (png_ptr->save_buffer_size) 675 if (png_ptr->save_buffer_size)
662 { 676 {
663 if (png_ptr->save_buffer_ptr != png_ptr->save_buffer) 677 if (png_ptr->save_buffer_ptr != png_ptr->save_buffer)
664 { 678 {
665 png_size_t i, istop; 679 png_size_t i, istop;
666 png_bytep sp; 680 png_bytep sp;
667 png_bytep dp; 681 png_bytep dp;
668 682
669 istop = png_ptr->save_buffer_size; 683 istop = png_ptr->save_buffer_size;
670 for (i = 0, sp = png_ptr->save_buffer_ptr, dp = png_ptr->save_buffer; 684 for (i = 0, sp = png_ptr->save_buffer_ptr, dp = png_ptr->save_buffer;
671 i < istop; i++, sp++, dp++) 685 i < istop; i++, sp++, dp++)
672 { 686 {
673 *dp = *sp; 687 *dp = *sp;
674 } 688 }
675 } 689 }
676 } 690 }
677 if (png_ptr->save_buffer_size + png_ptr->current_buffer_size > 691 if (png_ptr->save_buffer_size + png_ptr->current_buffer_size >
678 png_ptr->save_buffer_max) 692 png_ptr->save_buffer_max)
679 { 693 {
680 png_size_t new_max; 694 png_size_t new_max;
681 png_bytep old_buffer; 695 png_bytep old_buffer;
682 696
683 if (png_ptr->save_buffer_size > PNG_SIZE_MAX - 697 if (png_ptr->save_buffer_size > PNG_SIZE_MAX -
684 (png_ptr->current_buffer_size + 256)) 698 (png_ptr->current_buffer_size + 256))
685 { 699 {
686 png_error(png_ptr, "Potential overflow of save_buffer"); 700 png_error(png_ptr, "Potential overflow of save_buffer");
687 } 701 }
688 702
689 new_max = png_ptr->save_buffer_size + png_ptr->current_buffer_size + 256; 703 new_max = png_ptr->save_buffer_size + png_ptr->current_buffer_size + 256;
690 old_buffer = png_ptr->save_buffer; 704 old_buffer = png_ptr->save_buffer;
691 png_ptr->save_buffer = (png_bytep)png_malloc_warn(png_ptr, 705 png_ptr->save_buffer = (png_bytep)png_malloc_warn(png_ptr,
692 (png_size_t)new_max); 706 (png_uint_32)new_max);
693
694 if (png_ptr->save_buffer == NULL) 707 if (png_ptr->save_buffer == NULL)
695 { 708 {
696 png_free(png_ptr, old_buffer); 709 png_free(png_ptr, old_buffer);
697 png_error(png_ptr, "Insufficient memory for save_buffer"); 710 png_error(png_ptr, "Insufficient memory for save_buffer");
698 } 711 }
699 712 png_memcpy(png_ptr->save_buffer, old_buffer, png_ptr->save_buffer_size);
700 memcpy(png_ptr->save_buffer, old_buffer, png_ptr->save_buffer_size);
701 png_free(png_ptr, old_buffer); 713 png_free(png_ptr, old_buffer);
702 png_ptr->save_buffer_max = new_max; 714 png_ptr->save_buffer_max = new_max;
703 } 715 }
704 if (png_ptr->current_buffer_size) 716 if (png_ptr->current_buffer_size)
705 { 717 {
706 memcpy(png_ptr->save_buffer + png_ptr->save_buffer_size, 718 png_memcpy(png_ptr->save_buffer + png_ptr->save_buffer_size,
707 png_ptr->current_buffer_ptr, png_ptr->current_buffer_size); 719 png_ptr->current_buffer_ptr, png_ptr->current_buffer_size);
708 png_ptr->save_buffer_size += png_ptr->current_buffer_size; 720 png_ptr->save_buffer_size += png_ptr->current_buffer_size;
709 png_ptr->current_buffer_size = 0; 721 png_ptr->current_buffer_size = 0;
710 } 722 }
711 png_ptr->save_buffer_ptr = png_ptr->save_buffer; 723 png_ptr->save_buffer_ptr = png_ptr->save_buffer;
712 png_ptr->buffer_size = 0; 724 png_ptr->buffer_size = 0;
713 } 725 }
714 726
715 void /* PRIVATE */ 727 void /* PRIVATE */
716 png_push_restore_buffer(png_structrp png_ptr, png_bytep buffer, 728 png_push_restore_buffer(png_structp png_ptr, png_bytep buffer,
717 png_size_t buffer_length) 729 png_size_t buffer_length)
718 { 730 {
719 png_ptr->current_buffer = buffer; 731 png_ptr->current_buffer = buffer;
720 png_ptr->current_buffer_size = buffer_length; 732 png_ptr->current_buffer_size = buffer_length;
721 png_ptr->buffer_size = buffer_length + png_ptr->save_buffer_size; 733 png_ptr->buffer_size = buffer_length + png_ptr->save_buffer_size;
722 png_ptr->current_buffer_ptr = png_ptr->current_buffer; 734 png_ptr->current_buffer_ptr = png_ptr->current_buffer;
723 } 735 }
724 736
725 void /* PRIVATE */ 737 void /* PRIVATE */
726 png_push_read_IDAT(png_structrp png_ptr) 738 png_push_read_IDAT(png_structp png_ptr)
727 { 739 {
740 #ifdef PNG_USE_LOCAL_ARRAYS
741 PNG_CONST PNG_IDAT;
742 #endif
728 if (!(png_ptr->mode & PNG_HAVE_CHUNK_HEADER)) 743 if (!(png_ptr->mode & PNG_HAVE_CHUNK_HEADER))
729 { 744 {
730 png_byte chunk_length[4]; 745 png_byte chunk_length[4];
731 png_byte chunk_tag[4];
732 746
733 /* TODO: this code can be commoned up with the same code in push_read */
734 if (png_ptr->buffer_size < 8) 747 if (png_ptr->buffer_size < 8)
735 { 748 {
736 png_push_save_buffer(png_ptr); 749 png_push_save_buffer(png_ptr);
737 return; 750 return;
738 } 751 }
739 752
740 png_push_fill_buffer(png_ptr, chunk_length, 4); 753 png_push_fill_buffer(png_ptr, chunk_length, 4);
741 png_ptr->push_length = png_get_uint_31(png_ptr, chunk_length); 754 png_ptr->push_length = png_get_uint_31(png_ptr, chunk_length);
742 png_reset_crc(png_ptr); 755 png_reset_crc(png_ptr);
743 png_crc_read(png_ptr, chunk_tag, 4); 756 png_crc_read(png_ptr, png_ptr->chunk_name, 4);
744 png_ptr->chunk_name = PNG_CHUNK_FROM_STRING(chunk_tag);
745 png_ptr->mode |= PNG_HAVE_CHUNK_HEADER; 757 png_ptr->mode |= PNG_HAVE_CHUNK_HEADER;
746 758
747 if (png_ptr->chunk_name != png_IDAT) 759 if (png_memcmp(png_ptr->chunk_name, png_IDAT, 4))
748 { 760 {
749 png_ptr->process_mode = PNG_READ_CHUNK_MODE; 761 png_ptr->process_mode = PNG_READ_CHUNK_MODE;
750 762 if (!(png_ptr->flags & PNG_FLAG_ZLIB_FINISHED))
751 if (!(png_ptr->flags & PNG_FLAG_ZSTREAM_ENDED))
752 png_error(png_ptr, "Not enough compressed data"); 763 png_error(png_ptr, "Not enough compressed data");
753
754 return; 764 return;
755 } 765 }
756 766
757 png_ptr->idat_size = png_ptr->push_length; 767 png_ptr->idat_size = png_ptr->push_length;
758 } 768 }
759
760 if (png_ptr->idat_size && png_ptr->save_buffer_size) 769 if (png_ptr->idat_size && png_ptr->save_buffer_size)
761 { 770 {
762 png_size_t save_size = png_ptr->save_buffer_size; 771 png_size_t save_size;
763 png_uint_32 idat_size = png_ptr->idat_size;
764 772
765 /* We want the smaller of 'idat_size' and 'current_buffer_size', but they 773 if (png_ptr->idat_size < (png_uint_32)png_ptr->save_buffer_size)
766 * are of different types and we don't know which variable has the fewest 774 {
767 * bits. Carefully select the smaller and cast it to the type of the 775 save_size = (png_size_t)png_ptr->idat_size;
768 * larger - this cannot overflow. Do not cast in the following test - it
769 * will break on either 16 or 64 bit platforms.
770 */
771 if (idat_size < save_size)
772 save_size = (png_size_t)idat_size;
773 776
777 /* Check for overflow */
778 if ((png_uint_32)save_size != png_ptr->idat_size)
779 png_error(png_ptr, "save_size overflowed in pngpread");
780 }
774 else 781 else
775 idat_size = (png_uint_32)save_size; 782 save_size = png_ptr->save_buffer_size;
776 783
777 png_calculate_crc(png_ptr, png_ptr->save_buffer_ptr, save_size); 784 png_calculate_crc(png_ptr, png_ptr->save_buffer_ptr, save_size);
778 785
779 png_process_IDAT_data(png_ptr, png_ptr->save_buffer_ptr, save_size); 786 png_process_IDAT_data(png_ptr, png_ptr->save_buffer_ptr, save_size);
780 787
781 png_ptr->idat_size -= idat_size; 788 png_ptr->idat_size -= save_size;
782 png_ptr->buffer_size -= save_size; 789 png_ptr->buffer_size -= save_size;
783 png_ptr->save_buffer_size -= save_size; 790 png_ptr->save_buffer_size -= save_size;
784 png_ptr->save_buffer_ptr += save_size; 791 png_ptr->save_buffer_ptr += save_size;
785 } 792 }
786
787 if (png_ptr->idat_size && png_ptr->current_buffer_size) 793 if (png_ptr->idat_size && png_ptr->current_buffer_size)
788 { 794 {
789 png_size_t save_size = png_ptr->current_buffer_size; 795 png_size_t save_size;
790 png_uint_32 idat_size = png_ptr->idat_size;
791 796
792 /* We want the smaller of 'idat_size' and 'current_buffer_size', but they 797 if (png_ptr->idat_size < (png_uint_32)png_ptr->current_buffer_size)
793 * are of different types and we don't know which variable has the fewest 798 {
794 * bits. Carefully select the smaller and cast it to the type of the 799 save_size = (png_size_t)png_ptr->idat_size;
795 * larger - this cannot overflow.
796 */
797 if (idat_size < save_size)
798 save_size = (png_size_t)idat_size;
799 800
801 /* Check for overflow */
802 if ((png_uint_32)save_size != png_ptr->idat_size)
803 png_error(png_ptr, "save_size overflowed in pngpread");
804 }
800 else 805 else
801 idat_size = (png_uint_32)save_size; 806 save_size = png_ptr->current_buffer_size;
802 807
803 png_calculate_crc(png_ptr, png_ptr->current_buffer_ptr, save_size); 808 png_calculate_crc(png_ptr, png_ptr->current_buffer_ptr, save_size);
804 809
805 png_process_IDAT_data(png_ptr, png_ptr->current_buffer_ptr, save_size); 810 png_process_IDAT_data(png_ptr, png_ptr->current_buffer_ptr, save_size);
806 811
807 png_ptr->idat_size -= idat_size; 812 png_ptr->idat_size -= save_size;
808 png_ptr->buffer_size -= save_size; 813 png_ptr->buffer_size -= save_size;
809 png_ptr->current_buffer_size -= save_size; 814 png_ptr->current_buffer_size -= save_size;
810 png_ptr->current_buffer_ptr += save_size; 815 png_ptr->current_buffer_ptr += save_size;
811 } 816 }
812 if (!png_ptr->idat_size) 817 if (!png_ptr->idat_size)
813 { 818 {
814 if (png_ptr->buffer_size < 4) 819 if (png_ptr->buffer_size < 4)
815 { 820 {
816 png_push_save_buffer(png_ptr); 821 png_push_save_buffer(png_ptr);
817 return; 822 return;
818 } 823 }
819 824
820 png_crc_finish(png_ptr, 0); 825 png_crc_finish(png_ptr, 0);
821 png_ptr->mode &= ~PNG_HAVE_CHUNK_HEADER; 826 png_ptr->mode &= ~PNG_HAVE_CHUNK_HEADER;
822 png_ptr->mode |= PNG_AFTER_IDAT; 827 png_ptr->mode |= PNG_AFTER_IDAT;
823 png_ptr->zowner = 0;
824 } 828 }
825 } 829 }
826 830
827 void /* PRIVATE */ 831 void /* PRIVATE */
828 png_process_IDAT_data(png_structrp png_ptr, png_bytep buffer, 832 png_process_IDAT_data(png_structp png_ptr, png_bytep buffer,
829 png_size_t buffer_length) 833 png_size_t buffer_length)
830 { 834 {
831 /* The caller checks for a non-zero buffer length. */ 835 /* The caller checks for a non-zero buffer length. */
832 if (!(buffer_length > 0) || buffer == NULL) 836 if (!(buffer_length > 0) || buffer == NULL)
833 png_error(png_ptr, "No IDAT data (internal error)"); 837 png_error(png_ptr, "No IDAT data (internal error)");
834 838
835 /* This routine must process all the data it has been given 839 /* This routine must process all the data it has been given
836 * before returning, calling the row callback as required to 840 * before returning, calling the row callback as required to
837 * handle the uncompressed results. 841 * handle the uncompressed results.
838 */ 842 */
839 png_ptr->zstream.next_in = buffer; 843 png_ptr->zstream.next_in = buffer;
840 /* TODO: WARNING: TRUNCATION ERROR: DANGER WILL ROBINSON: */
841 png_ptr->zstream.avail_in = (uInt)buffer_length; 844 png_ptr->zstream.avail_in = (uInt)buffer_length;
842 845
843 /* Keep going until the decompressed data is all processed 846 /* Keep going until the decompressed data is all processed
844 * or the stream marked as finished. 847 * or the stream marked as finished.
845 */ 848 */
846 while (png_ptr->zstream.avail_in > 0 && 849 while (png_ptr->zstream.avail_in > 0 &&
847 !(png_ptr->flags & PNG_FLAG_ZSTREAM_ENDED)) 850 » !(png_ptr->flags & PNG_FLAG_ZLIB_FINISHED))
848 { 851 {
849 int ret; 852 int ret;
850 853
851 /* We have data for zlib, but we must check that zlib 854 /* We have data for zlib, but we must check that zlib
852 * has someplace to put the results. It doesn't matter 855 * has somewhere to put the results. It doesn't matter
853 * if we don't expect any results -- it may be the input 856 * if we don't expect any results -- it may be the input
854 * data is just the LZ end code. 857 * data is just the LZ end code.
855 */ 858 */
856 if (!(png_ptr->zstream.avail_out > 0)) 859 if (!(png_ptr->zstream.avail_out > 0))
857 { 860 {
858 /* TODO: WARNING: TRUNCATION ERROR: DANGER WILL ROBINSON: */ 861 png_ptr->zstream.avail_out =
859 png_ptr->zstream.avail_out = (uInt)(PNG_ROWBYTES(png_ptr->pixel_depth, 862 (uInt) PNG_ROWBYTES(png_ptr->pixel_depth,
860 png_ptr->iwidth) + 1); 863 png_ptr->iwidth) + 1;
861
862 png_ptr->zstream.next_out = png_ptr->row_buf; 864 png_ptr->zstream.next_out = png_ptr->row_buf;
863 } 865 }
864 866
865 /* Using Z_SYNC_FLUSH here means that an unterminated 867 /* Using Z_SYNC_FLUSH here means that an unterminated
866 * LZ stream (a stream with a missing end code) can still 868 * LZ stream can still be handled (a stream with a missing
867 * be handled, otherwise (Z_NO_FLUSH) a future zlib 869 * end code), otherwise (Z_NO_FLUSH) a future zlib
868 * implementation might defer output and therefore 870 * implementation might defer output and, therefore,
869 * change the current behavior (see comments in inflate.c 871 * change the current behavior. (See comments in inflate.c
870 * for why this doesn't happen at present with zlib 1.2.5). 872 * for why this doesn't happen at present with zlib 1.2.5.)
871 */ 873 */
872 ret = inflate(&png_ptr->zstream, Z_SYNC_FLUSH); 874 ret = inflate(&png_ptr->zstream, Z_SYNC_FLUSH);
873 875
874 /* Check for any failure before proceeding. */ 876 /* Check for any failure before proceeding. */
875 if (ret != Z_OK && ret != Z_STREAM_END) 877 if (ret != Z_OK && ret != Z_STREAM_END)
876 { 878 {
877 /* Terminate the decompression. */ 879 » /* Terminate the decompression. */
878 png_ptr->flags |= PNG_FLAG_ZSTREAM_ENDED; 880 » png_ptr->flags |= PNG_FLAG_ZLIB_FINISHED;
879 png_ptr->zowner = 0;
880 881
881 /* This may be a truncated stream (missing or 882 /* This may be a truncated stream (missing or
882 * damaged end code). Treat that as a warning. 883 » * damaged end code). Treat that as a warning.
883 */ 884 » */
884 if (png_ptr->row_number >= png_ptr->num_rows || 885 if (png_ptr->row_number >= png_ptr->num_rows ||
885 png_ptr->pass > 6) 886 » png_ptr->pass > 6)
886 png_warning(png_ptr, "Truncated compressed data in IDAT"); 887 » png_warning(png_ptr, "Truncated compressed data in IDAT");
888 » else
889 » png_error(png_ptr, "Decompression error in IDAT");
887 890
888 else 891 » /* Skip the check on unprocessed input */
889 png_error(png_ptr, "Decompression error in IDAT");
890
891 /* Skip the check on unprocessed input */
892 return; 892 return;
893 } 893 }
894 894
895 /* Did inflate output any data? */ 895 /* Did inflate output any data? */
896 if (png_ptr->zstream.next_out != png_ptr->row_buf) 896 if (png_ptr->zstream.next_out != png_ptr->row_buf)
897 { 897 {
898 /* Is this unexpected data after the last row? 898 » /* Is this unexpected data after the last row?
899 * If it is, artificially terminate the LZ output 899 » * If it is, artificially terminate the LZ output
900 * here. 900 » * here.
901 */ 901 » */
902 if (png_ptr->row_number >= png_ptr->num_rows || 902 if (png_ptr->row_number >= png_ptr->num_rows ||
903 png_ptr->pass > 6) 903 » png_ptr->pass > 6)
904 { 904 {
905 /* Extra data. */ 905 » /* Extra data. */
906 png_warning(png_ptr, "Extra compressed data in IDAT"); 906 » png_warning(png_ptr, "Extra compressed data in IDAT");
907 png_ptr->flags |= PNG_FLAG_ZSTREAM_ENDED; 907 png_ptr->flags |= PNG_FLAG_ZLIB_FINISHED;
908 png_ptr->zowner = 0; 908 » /* Do no more processing; skip the unprocessed
909 » * input check below.
910 » */
911 return;
912 » }
909 913
910 /* Do no more processing; skip the unprocessed 914 » /* Do we have a complete row? */
911 * input check below. 915 » if (png_ptr->zstream.avail_out == 0)
912 */ 916 » png_push_process_row(png_ptr);
913 return;
914 }
915
916 /* Do we have a complete row? */
917 if (png_ptr->zstream.avail_out == 0)
918 png_push_process_row(png_ptr);
919 } 917 }
920 918
921 /* And check for the end of the stream. */ 919 /* And check for the end of the stream. */
922 if (ret == Z_STREAM_END) 920 if (ret == Z_STREAM_END)
923 png_ptr->flags |= PNG_FLAG_ZSTREAM_ENDED; 921 » png_ptr->flags |= PNG_FLAG_ZLIB_FINISHED;
924 } 922 }
925 923
926 /* All the data should have been processed, if anything 924 /* All the data should have been processed, if anything
927 * is left at this point we have bytes of IDAT data 925 * is left at this point we have bytes of IDAT data
928 * after the zlib end code. 926 * after the zlib end code.
929 */ 927 */
930 if (png_ptr->zstream.avail_in > 0) 928 if (png_ptr->zstream.avail_in > 0)
931 png_warning(png_ptr, "Extra compression data in IDAT"); 929 png_warning(png_ptr, "Extra compression data");
932 } 930 }
933 931
934 void /* PRIVATE */ 932 void /* PRIVATE */
935 png_push_process_row(png_structrp png_ptr) 933 png_push_process_row(png_structp png_ptr)
936 { 934 {
937 /* 1.5.6: row_info moved out of png_struct to a local here. */ 935 png_ptr->row_info.color_type = png_ptr->color_type;
938 png_row_info row_info; 936 png_ptr->row_info.width = png_ptr->iwidth;
937 png_ptr->row_info.channels = png_ptr->channels;
938 png_ptr->row_info.bit_depth = png_ptr->bit_depth;
939 png_ptr->row_info.pixel_depth = png_ptr->pixel_depth;
939 940
940 row_info.width = png_ptr->iwidth; /* NOTE: width of current interlaced row */ 941 png_ptr->row_info.rowbytes = PNG_ROWBYTES(png_ptr->row_info.pixel_depth,
941 row_info.color_type = png_ptr->color_type; 942 png_ptr->row_info.width);
942 row_info.bit_depth = png_ptr->bit_depth;
943 row_info.channels = png_ptr->channels;
944 row_info.pixel_depth = png_ptr->pixel_depth;
945 row_info.rowbytes = PNG_ROWBYTES(row_info.pixel_depth, row_info.width);
946 943
947 if (png_ptr->row_buf[0] > PNG_FILTER_VALUE_NONE) 944 png_read_filter_row(png_ptr, &(png_ptr->row_info),
948 { 945 png_ptr->row_buf + 1, png_ptr->prev_row + 1,
949 if (png_ptr->row_buf[0] < PNG_FILTER_VALUE_LAST) 946 (int)(png_ptr->row_buf[0]));
950 png_read_filter_row(png_ptr, &row_info, png_ptr->row_buf + 1,
951 png_ptr->prev_row + 1, png_ptr->row_buf[0]);
952 else
953 png_error(png_ptr, "bad adaptive filter value");
954 }
955 947
956 /* libpng 1.5.6: the following line was copying png_ptr->rowbytes before 948 png_memcpy_check(png_ptr, png_ptr->prev_row, png_ptr->row_buf,
957 * 1.5.6, while the buffer really is this big in current versions of libpng 949 png_ptr->rowbytes + 1);
958 * it may not be in the future, so this was changed just to copy the
959 * interlaced row count:
960 */
961 memcpy(png_ptr->prev_row, png_ptr->row_buf, row_info.rowbytes + 1);
962 950
963 #ifdef PNG_READ_TRANSFORMS_SUPPORTED 951 if (png_ptr->transformations || (png_ptr->flags&PNG_FLAG_STRIP_ALPHA))
964 if (png_ptr->transformations) 952 png_do_read_transformations(png_ptr);
965 png_do_read_transformations(png_ptr, &row_info);
966 #endif
967
968 /* The transformed pixel depth should match the depth now in row_info. */
969 if (png_ptr->transformed_pixel_depth == 0)
970 {
971 png_ptr->transformed_pixel_depth = row_info.pixel_depth;
972 if (row_info.pixel_depth > png_ptr->maximum_pixel_depth)
973 png_error(png_ptr, "progressive row overflow");
974 }
975
976 else if (png_ptr->transformed_pixel_depth != row_info.pixel_depth)
977 png_error(png_ptr, "internal progressive row size calculation error");
978
979 953
980 #ifdef PNG_READ_INTERLACING_SUPPORTED 954 #ifdef PNG_READ_INTERLACING_SUPPORTED
981 /* Blow up interlaced rows to full size */ 955 /* Blow up interlaced rows to full size */
982 if (png_ptr->interlaced && (png_ptr->transformations & PNG_INTERLACE)) 956 if (png_ptr->interlaced && (png_ptr->transformations & PNG_INTERLACE))
983 { 957 {
984 if (png_ptr->pass < 6) 958 if (png_ptr->pass < 6)
985 png_do_read_interlace(&row_info, png_ptr->row_buf + 1, png_ptr->pass, 959 /* old interface (pre-1.0.9):
986 png_ptr->transformations); 960 png_do_read_interlace(&(png_ptr->row_info),
961 png_ptr->row_buf + 1, png_ptr->pass, png_ptr->transformations);
962 */
963 png_do_read_interlace(png_ptr);
987 964
988 switch (png_ptr->pass) 965 switch (png_ptr->pass)
989 { 966 {
990 case 0: 967 case 0:
991 { 968 {
992 int i; 969 int i;
993 for (i = 0; i < 8 && png_ptr->pass == 0; i++) 970 for (i = 0; i < 8 && png_ptr->pass == 0; i++)
994 { 971 {
995 png_push_have_row(png_ptr, png_ptr->row_buf + 1); 972 png_push_have_row(png_ptr, png_ptr->row_buf + 1);
996 png_read_push_finish_row(png_ptr); /* Updates png_ptr->pass */ 973 png_read_push_finish_row(png_ptr); /* Updates png_ptr->pass */
997 } 974 }
998 975
999 if (png_ptr->pass == 2) /* Pass 1 might be empty */ 976 if (png_ptr->pass == 2) /* Pass 1 might be empty */
1000 { 977 {
1001 for (i = 0; i < 4 && png_ptr->pass == 2; i++) 978 for (i = 0; i < 4 && png_ptr->pass == 2; i++)
1002 { 979 {
1003 png_push_have_row(png_ptr, NULL); 980 png_push_have_row(png_ptr, png_bytep_NULL);
1004 png_read_push_finish_row(png_ptr); 981 png_read_push_finish_row(png_ptr);
1005 } 982 }
1006 } 983 }
1007 984
1008 if (png_ptr->pass == 4 && png_ptr->height <= 4) 985 if (png_ptr->pass == 4 && png_ptr->height <= 4)
1009 { 986 {
1010 for (i = 0; i < 2 && png_ptr->pass == 4; i++) 987 for (i = 0; i < 2 && png_ptr->pass == 4; i++)
1011 { 988 {
1012 png_push_have_row(png_ptr, NULL); 989 png_push_have_row(png_ptr, png_bytep_NULL);
1013 png_read_push_finish_row(png_ptr); 990 png_read_push_finish_row(png_ptr);
1014 } 991 }
1015 } 992 }
1016 993
1017 if (png_ptr->pass == 6 && png_ptr->height <= 4) 994 if (png_ptr->pass == 6 && png_ptr->height <= 4)
1018 { 995 {
1019 png_push_have_row(png_ptr, NULL); 996 png_push_have_row(png_ptr, png_bytep_NULL);
1020 png_read_push_finish_row(png_ptr); 997 png_read_push_finish_row(png_ptr);
1021 } 998 }
1022 999
1023 break; 1000 break;
1024 } 1001 }
1025 1002
1026 case 1: 1003 case 1:
1027 { 1004 {
1028 int i; 1005 int i;
1029 for (i = 0; i < 8 && png_ptr->pass == 1; i++) 1006 for (i = 0; i < 8 && png_ptr->pass == 1; i++)
1030 { 1007 {
1031 png_push_have_row(png_ptr, png_ptr->row_buf + 1); 1008 png_push_have_row(png_ptr, png_ptr->row_buf + 1);
1032 png_read_push_finish_row(png_ptr); 1009 png_read_push_finish_row(png_ptr);
1033 } 1010 }
1034 1011
1035 if (png_ptr->pass == 2) /* Skip top 4 generated rows */ 1012 if (png_ptr->pass == 2) /* Skip top 4 generated rows */
1036 { 1013 {
1037 for (i = 0; i < 4 && png_ptr->pass == 2; i++) 1014 for (i = 0; i < 4 && png_ptr->pass == 2; i++)
1038 { 1015 {
1039 png_push_have_row(png_ptr, NULL); 1016 png_push_have_row(png_ptr, png_bytep_NULL);
1040 png_read_push_finish_row(png_ptr); 1017 png_read_push_finish_row(png_ptr);
1041 } 1018 }
1042 } 1019 }
1043 1020
1044 break; 1021 break;
1045 } 1022 }
1046 1023
1047 case 2: 1024 case 2:
1048 { 1025 {
1049 int i; 1026 int i;
1050 1027
1051 for (i = 0; i < 4 && png_ptr->pass == 2; i++) 1028 for (i = 0; i < 4 && png_ptr->pass == 2; i++)
1052 { 1029 {
1053 png_push_have_row(png_ptr, png_ptr->row_buf + 1); 1030 png_push_have_row(png_ptr, png_ptr->row_buf + 1);
1054 png_read_push_finish_row(png_ptr); 1031 png_read_push_finish_row(png_ptr);
1055 } 1032 }
1056 1033
1057 for (i = 0; i < 4 && png_ptr->pass == 2; i++) 1034 for (i = 0; i < 4 && png_ptr->pass == 2; i++)
1058 { 1035 {
1059 png_push_have_row(png_ptr, NULL); 1036 png_push_have_row(png_ptr, png_bytep_NULL);
1060 png_read_push_finish_row(png_ptr); 1037 png_read_push_finish_row(png_ptr);
1061 } 1038 }
1062 1039
1063 if (png_ptr->pass == 4) /* Pass 3 might be empty */ 1040 if (png_ptr->pass == 4) /* Pass 3 might be empty */
1064 { 1041 {
1065 for (i = 0; i < 2 && png_ptr->pass == 4; i++) 1042 for (i = 0; i < 2 && png_ptr->pass == 4; i++)
1066 { 1043 {
1067 png_push_have_row(png_ptr, NULL); 1044 png_push_have_row(png_ptr, png_bytep_NULL);
1068 png_read_push_finish_row(png_ptr); 1045 png_read_push_finish_row(png_ptr);
1069 } 1046 }
1070 } 1047 }
1071 1048
1072 break; 1049 break;
1073 } 1050 }
1074 1051
1075 case 3: 1052 case 3:
1076 { 1053 {
1077 int i; 1054 int i;
1078 1055
1079 for (i = 0; i < 4 && png_ptr->pass == 3; i++) 1056 for (i = 0; i < 4 && png_ptr->pass == 3; i++)
1080 { 1057 {
1081 png_push_have_row(png_ptr, png_ptr->row_buf + 1); 1058 png_push_have_row(png_ptr, png_ptr->row_buf + 1);
1082 png_read_push_finish_row(png_ptr); 1059 png_read_push_finish_row(png_ptr);
1083 } 1060 }
1084 1061
1085 if (png_ptr->pass == 4) /* Skip top two generated rows */ 1062 if (png_ptr->pass == 4) /* Skip top two generated rows */
1086 { 1063 {
1087 for (i = 0; i < 2 && png_ptr->pass == 4; i++) 1064 for (i = 0; i < 2 && png_ptr->pass == 4; i++)
1088 { 1065 {
1089 png_push_have_row(png_ptr, NULL); 1066 png_push_have_row(png_ptr, png_bytep_NULL);
1090 png_read_push_finish_row(png_ptr); 1067 png_read_push_finish_row(png_ptr);
1091 } 1068 }
1092 } 1069 }
1093 1070
1094 break; 1071 break;
1095 } 1072 }
1096 1073
1097 case 4: 1074 case 4:
1098 { 1075 {
1099 int i; 1076 int i;
1100 1077
1101 for (i = 0; i < 2 && png_ptr->pass == 4; i++) 1078 for (i = 0; i < 2 && png_ptr->pass == 4; i++)
1102 { 1079 {
1103 png_push_have_row(png_ptr, png_ptr->row_buf + 1); 1080 png_push_have_row(png_ptr, png_ptr->row_buf + 1);
1104 png_read_push_finish_row(png_ptr); 1081 png_read_push_finish_row(png_ptr);
1105 } 1082 }
1106 1083
1107 for (i = 0; i < 2 && png_ptr->pass == 4; i++) 1084 for (i = 0; i < 2 && png_ptr->pass == 4; i++)
1108 { 1085 {
1109 png_push_have_row(png_ptr, NULL); 1086 png_push_have_row(png_ptr, png_bytep_NULL);
1110 png_read_push_finish_row(png_ptr); 1087 png_read_push_finish_row(png_ptr);
1111 } 1088 }
1112 1089
1113 if (png_ptr->pass == 6) /* Pass 5 might be empty */ 1090 if (png_ptr->pass == 6) /* Pass 5 might be empty */
1114 { 1091 {
1115 png_push_have_row(png_ptr, NULL); 1092 png_push_have_row(png_ptr, png_bytep_NULL);
1116 png_read_push_finish_row(png_ptr); 1093 png_read_push_finish_row(png_ptr);
1117 } 1094 }
1118 1095
1119 break; 1096 break;
1120 } 1097 }
1121 1098
1122 case 5: 1099 case 5:
1123 { 1100 {
1124 int i; 1101 int i;
1125 1102
1126 for (i = 0; i < 2 && png_ptr->pass == 5; i++) 1103 for (i = 0; i < 2 && png_ptr->pass == 5; i++)
1127 { 1104 {
1128 png_push_have_row(png_ptr, png_ptr->row_buf + 1); 1105 png_push_have_row(png_ptr, png_ptr->row_buf + 1);
1129 png_read_push_finish_row(png_ptr); 1106 png_read_push_finish_row(png_ptr);
1130 } 1107 }
1131 1108
1132 if (png_ptr->pass == 6) /* Skip top generated row */ 1109 if (png_ptr->pass == 6) /* Skip top generated row */
1133 { 1110 {
1134 png_push_have_row(png_ptr, NULL); 1111 png_push_have_row(png_ptr, png_bytep_NULL);
1135 png_read_push_finish_row(png_ptr); 1112 png_read_push_finish_row(png_ptr);
1136 } 1113 }
1137 1114
1138 break; 1115 break;
1139 } 1116 }
1140
1141 default:
1142 case 6: 1117 case 6:
1143 { 1118 {
1144 png_push_have_row(png_ptr, png_ptr->row_buf + 1); 1119 png_push_have_row(png_ptr, png_ptr->row_buf + 1);
1145 png_read_push_finish_row(png_ptr); 1120 png_read_push_finish_row(png_ptr);
1146 1121
1147 if (png_ptr->pass != 6) 1122 if (png_ptr->pass != 6)
1148 break; 1123 break;
1149 1124
1150 png_push_have_row(png_ptr, NULL); 1125 png_push_have_row(png_ptr, png_bytep_NULL);
1151 png_read_push_finish_row(png_ptr); 1126 png_read_push_finish_row(png_ptr);
1152 } 1127 }
1153 } 1128 }
1154 } 1129 }
1155 else 1130 else
1156 #endif 1131 #endif
1157 { 1132 {
1158 png_push_have_row(png_ptr, png_ptr->row_buf + 1); 1133 png_push_have_row(png_ptr, png_ptr->row_buf + 1);
1159 png_read_push_finish_row(png_ptr); 1134 png_read_push_finish_row(png_ptr);
1160 } 1135 }
1161 } 1136 }
1162 1137
1163 void /* PRIVATE */ 1138 void /* PRIVATE */
1164 png_read_push_finish_row(png_structrp png_ptr) 1139 png_read_push_finish_row(png_structp png_ptr)
1165 { 1140 {
1166 #ifdef PNG_READ_INTERLACING_SUPPORTED 1141 #ifdef PNG_USE_LOCAL_ARRAYS
1167 /* Arrays to facilitate easy interlacing - use pass (0 - 6) as index */ 1142 /* Arrays to facilitate easy interlacing - use pass (0 - 6) as index */
1168 1143
1169 /* Start of interlace block */ 1144 /* Start of interlace block */
1170 static PNG_CONST png_byte png_pass_start[] = {0, 4, 0, 2, 0, 1, 0}; 1145 PNG_CONST int FARDATA png_pass_start[] = {0, 4, 0, 2, 0, 1, 0};
1171 1146
1172 /* Offset to next interlace block */ 1147 /* Offset to next interlace block */
1173 static PNG_CONST png_byte png_pass_inc[] = {8, 8, 4, 4, 2, 2, 1}; 1148 PNG_CONST int FARDATA png_pass_inc[] = {8, 8, 4, 4, 2, 2, 1};
1174 1149
1175 /* Start of interlace block in the y direction */ 1150 /* Start of interlace block in the y direction */
1176 static PNG_CONST png_byte png_pass_ystart[] = {0, 0, 4, 0, 2, 0, 1}; 1151 PNG_CONST int FARDATA png_pass_ystart[] = {0, 0, 4, 0, 2, 0, 1};
1177 1152
1178 /* Offset to next interlace block in the y direction */ 1153 /* Offset to next interlace block in the y direction */
1179 static PNG_CONST png_byte png_pass_yinc[] = {8, 8, 8, 4, 4, 2, 2}; 1154 PNG_CONST int FARDATA png_pass_yinc[] = {8, 8, 8, 4, 4, 2, 2};
1180 1155
1181 /* Height of interlace block. This is not currently used - if you need 1156 /* Height of interlace block. This is not currently used - if you need
1182 * it, uncomment it here and in png.h 1157 * it, uncomment it here and in png.h
1183 static PNG_CONST png_byte png_pass_height[] = {8, 8, 4, 4, 2, 2, 1}; 1158 PNG_CONST int FARDATA png_pass_height[] = {8, 8, 4, 4, 2, 2, 1};
1184 */ 1159 */
1185 #endif 1160 #endif
1186 1161
1187 png_ptr->row_number++; 1162 png_ptr->row_number++;
1188 if (png_ptr->row_number < png_ptr->num_rows) 1163 if (png_ptr->row_number < png_ptr->num_rows)
1189 return; 1164 return;
1190 1165
1191 #ifdef PNG_READ_INTERLACING_SUPPORTED 1166 #ifdef PNG_READ_INTERLACING_SUPPORTED
1192 if (png_ptr->interlaced) 1167 if (png_ptr->interlaced)
1193 { 1168 {
1194 png_ptr->row_number = 0; 1169 png_ptr->row_number = 0;
1195 memset(png_ptr->prev_row, 0, png_ptr->rowbytes + 1); 1170 png_memset_check(png_ptr, png_ptr->prev_row, 0,
1196 1171 png_ptr->rowbytes + 1);
1197 do 1172 do
1198 { 1173 {
1199 png_ptr->pass++; 1174 png_ptr->pass++;
1200 if ((png_ptr->pass == 1 && png_ptr->width < 5) || 1175 if ((png_ptr->pass == 1 && png_ptr->width < 5) ||
1201 (png_ptr->pass == 3 && png_ptr->width < 3) || 1176 (png_ptr->pass == 3 && png_ptr->width < 3) ||
1202 (png_ptr->pass == 5 && png_ptr->width < 2)) 1177 (png_ptr->pass == 5 && png_ptr->width < 2))
1203 png_ptr->pass++; 1178 png_ptr->pass++;
1204 1179
1205 if (png_ptr->pass > 7) 1180 if (png_ptr->pass > 7)
1206 png_ptr->pass--; 1181 png_ptr->pass--;
1207 1182
1208 if (png_ptr->pass >= 7) 1183 if (png_ptr->pass >= 7)
1209 break; 1184 break;
1210 1185
1211 png_ptr->iwidth = (png_ptr->width + 1186 png_ptr->iwidth = (png_ptr->width +
1212 png_pass_inc[png_ptr->pass] - 1 - 1187 png_pass_inc[png_ptr->pass] - 1 -
1213 png_pass_start[png_ptr->pass]) / 1188 png_pass_start[png_ptr->pass]) /
1214 png_pass_inc[png_ptr->pass]; 1189 png_pass_inc[png_ptr->pass];
1215 1190
1216 if (png_ptr->transformations & PNG_INTERLACE) 1191 if (png_ptr->transformations & PNG_INTERLACE)
1217 break; 1192 break;
1218 1193
1219 png_ptr->num_rows = (png_ptr->height + 1194 png_ptr->num_rows = (png_ptr->height +
1220 png_pass_yinc[png_ptr->pass] - 1 - 1195 png_pass_yinc[png_ptr->pass] - 1 -
1221 png_pass_ystart[png_ptr->pass]) / 1196 png_pass_ystart[png_ptr->pass]) /
1222 png_pass_yinc[png_ptr->pass]; 1197 png_pass_yinc[png_ptr->pass];
1223 1198
1224 } while (png_ptr->iwidth == 0 || png_ptr->num_rows == 0); 1199 } while (png_ptr->iwidth == 0 || png_ptr->num_rows == 0);
1225 } 1200 }
1226 #endif /* PNG_READ_INTERLACING_SUPPORTED */ 1201 #endif /* PNG_READ_INTERLACING_SUPPORTED */
1227 } 1202 }
1228 1203
1229 void /* PRIVATE */ 1204 #ifdef PNG_READ_tEXt_SUPPORTED
1230 png_push_have_info(png_structrp png_ptr, png_inforp info_ptr) 1205 void /* PRIVATE */
1206 png_push_handle_tEXt(png_structp png_ptr, png_infop info_ptr, png_uint_32
1207 length)
1208 {
1209 if (!(png_ptr->mode & PNG_HAVE_IHDR) || (png_ptr->mode & PNG_HAVE_IEND))
1210 {
1211 png_error(png_ptr, "Out of place tEXt");
1212 info_ptr = info_ptr; /* To quiet some compiler warnings */
1213 }
1214
1215 #ifdef PNG_MAX_MALLOC_64K
1216 png_ptr->skip_length = 0; /* This may not be necessary */
1217
1218 if (length > (png_uint_32)65535L) /* Can't hold entire string in memory */
1219 {
1220 png_warning(png_ptr, "tEXt chunk too large to fit in memory");
1221 png_ptr->skip_length = length - (png_uint_32)65535L;
1222 length = (png_uint_32)65535L;
1223 }
1224 #endif
1225
1226 png_ptr->current_text = (png_charp)png_malloc(png_ptr,
1227 (png_uint_32)(length + 1));
1228 png_ptr->current_text[length] = '\0';
1229 png_ptr->current_text_ptr = png_ptr->current_text;
1230 png_ptr->current_text_size = (png_size_t)length;
1231 png_ptr->current_text_left = (png_size_t)length;
1232 png_ptr->process_mode = PNG_READ_tEXt_MODE;
1233 }
1234
1235 void /* PRIVATE */
1236 png_push_read_tEXt(png_structp png_ptr, png_infop info_ptr)
1237 {
1238 if (png_ptr->buffer_size && png_ptr->current_text_left)
1239 {
1240 png_size_t text_size;
1241
1242 if (png_ptr->buffer_size < png_ptr->current_text_left)
1243 text_size = png_ptr->buffer_size;
1244
1245 else
1246 text_size = png_ptr->current_text_left;
1247
1248 png_crc_read(png_ptr, (png_bytep)png_ptr->current_text_ptr, text_size);
1249 png_ptr->current_text_left -= text_size;
1250 png_ptr->current_text_ptr += text_size;
1251 }
1252 if (!(png_ptr->current_text_left))
1253 {
1254 png_textp text_ptr;
1255 png_charp text;
1256 png_charp key;
1257 int ret;
1258
1259 if (png_ptr->buffer_size < 4)
1260 {
1261 png_push_save_buffer(png_ptr);
1262 return;
1263 }
1264
1265 png_push_crc_finish(png_ptr);
1266
1267 #ifdef PNG_MAX_MALLOC_64K
1268 if (png_ptr->skip_length)
1269 return;
1270 #endif
1271
1272 key = png_ptr->current_text;
1273
1274 for (text = key; *text; text++)
1275 /* Empty loop */ ;
1276
1277 if (text < key + png_ptr->current_text_size)
1278 text++;
1279
1280 text_ptr = (png_textp)png_malloc(png_ptr,
1281 (png_uint_32)png_sizeof(png_text));
1282 text_ptr->compression = PNG_TEXT_COMPRESSION_NONE;
1283 text_ptr->key = key;
1284 #ifdef PNG_iTXt_SUPPORTED
1285 text_ptr->lang = NULL;
1286 text_ptr->lang_key = NULL;
1287 #endif
1288 text_ptr->text = text;
1289
1290 ret = png_set_text_2(png_ptr, info_ptr, text_ptr, 1);
1291
1292 png_free(png_ptr, key);
1293 png_free(png_ptr, text_ptr);
1294 png_ptr->current_text = NULL;
1295
1296 if (ret)
1297 png_warning(png_ptr, "Insufficient memory to store text chunk.");
1298 }
1299 }
1300 #endif
1301
1302 #ifdef PNG_READ_zTXt_SUPPORTED
1303 void /* PRIVATE */
1304 png_push_handle_zTXt(png_structp png_ptr, png_infop info_ptr, png_uint_32
1305 length)
1306 {
1307 if (!(png_ptr->mode & PNG_HAVE_IHDR) || (png_ptr->mode & PNG_HAVE_IEND))
1308 {
1309 png_error(png_ptr, "Out of place zTXt");
1310 info_ptr = info_ptr; /* To quiet some compiler warnings */
1311 }
1312
1313 #ifdef PNG_MAX_MALLOC_64K
1314 /* We can't handle zTXt chunks > 64K, since we don't have enough space
1315 * to be able to store the uncompressed data. Actually, the threshold
1316 * is probably around 32K, but it isn't as definite as 64K is.
1317 */
1318 if (length > (png_uint_32)65535L)
1319 {
1320 png_warning(png_ptr, "zTXt chunk too large to fit in memory");
1321 png_push_crc_skip(png_ptr, length);
1322 return;
1323 }
1324 #endif
1325
1326 png_ptr->current_text = (png_charp)png_malloc(png_ptr,
1327 (png_uint_32)(length + 1));
1328 png_ptr->current_text[length] = '\0';
1329 png_ptr->current_text_ptr = png_ptr->current_text;
1330 png_ptr->current_text_size = (png_size_t)length;
1331 png_ptr->current_text_left = (png_size_t)length;
1332 png_ptr->process_mode = PNG_READ_zTXt_MODE;
1333 }
1334
1335 void /* PRIVATE */
1336 png_push_read_zTXt(png_structp png_ptr, png_infop info_ptr)
1337 {
1338 if (png_ptr->buffer_size && png_ptr->current_text_left)
1339 {
1340 png_size_t text_size;
1341
1342 if (png_ptr->buffer_size < (png_uint_32)png_ptr->current_text_left)
1343 text_size = png_ptr->buffer_size;
1344
1345 else
1346 text_size = png_ptr->current_text_left;
1347
1348 png_crc_read(png_ptr, (png_bytep)png_ptr->current_text_ptr, text_size);
1349 png_ptr->current_text_left -= text_size;
1350 png_ptr->current_text_ptr += text_size;
1351 }
1352 if (!(png_ptr->current_text_left))
1353 {
1354 png_textp text_ptr;
1355 png_charp text;
1356 png_charp key;
1357 int ret;
1358 png_size_t text_size, key_size;
1359
1360 if (png_ptr->buffer_size < 4)
1361 {
1362 png_push_save_buffer(png_ptr);
1363 return;
1364 }
1365
1366 png_push_crc_finish(png_ptr);
1367
1368 key = png_ptr->current_text;
1369
1370 for (text = key; *text; text++)
1371 /* Empty loop */ ;
1372
1373 /* zTXt can't have zero text */
1374 if (text >= key + png_ptr->current_text_size)
1375 {
1376 png_ptr->current_text = NULL;
1377 png_free(png_ptr, key);
1378 return;
1379 }
1380
1381 text++;
1382
1383 if (*text != PNG_TEXT_COMPRESSION_zTXt) /* Check compression byte */
1384 {
1385 png_ptr->current_text = NULL;
1386 png_free(png_ptr, key);
1387 return;
1388 }
1389
1390 text++;
1391
1392 png_ptr->zstream.next_in = (png_bytep )text;
1393 png_ptr->zstream.avail_in = (uInt)(png_ptr->current_text_size -
1394 (text - key));
1395 png_ptr->zstream.next_out = png_ptr->zbuf;
1396 png_ptr->zstream.avail_out = (uInt)png_ptr->zbuf_size;
1397
1398 key_size = text - key;
1399 text_size = 0;
1400 text = NULL;
1401 ret = Z_STREAM_END;
1402
1403 while (png_ptr->zstream.avail_in)
1404 {
1405 ret = inflate(&png_ptr->zstream, Z_PARTIAL_FLUSH);
1406 if (ret != Z_OK && ret != Z_STREAM_END)
1407 {
1408 inflateReset(&png_ptr->zstream);
1409 png_ptr->zstream.avail_in = 0;
1410 png_ptr->current_text = NULL;
1411 png_free(png_ptr, key);
1412 png_free(png_ptr, text);
1413 return;
1414 }
1415 if (!(png_ptr->zstream.avail_out) || ret == Z_STREAM_END)
1416 {
1417 if (text == NULL)
1418 {
1419 text = (png_charp)png_malloc(png_ptr,
1420 (png_uint_32)(png_ptr->zbuf_size
1421 - png_ptr->zstream.avail_out + key_size + 1));
1422
1423 png_memcpy(text + key_size, png_ptr->zbuf,
1424 png_ptr->zbuf_size - png_ptr->zstream.avail_out);
1425
1426 png_memcpy(text, key, key_size);
1427
1428 text_size = key_size + png_ptr->zbuf_size -
1429 png_ptr->zstream.avail_out;
1430
1431 *(text + text_size) = '\0';
1432 }
1433 else
1434 {
1435 png_charp tmp;
1436
1437 tmp = text;
1438 text = (png_charp)png_malloc(png_ptr, text_size +
1439 (png_uint_32)(png_ptr->zbuf_size
1440 - png_ptr->zstream.avail_out + 1));
1441
1442 png_memcpy(text, tmp, text_size);
1443 png_free(png_ptr, tmp);
1444
1445 png_memcpy(text + text_size, png_ptr->zbuf,
1446 png_ptr->zbuf_size - png_ptr->zstream.avail_out);
1447
1448 text_size += png_ptr->zbuf_size - png_ptr->zstream.avail_out;
1449 *(text + text_size) = '\0';
1450 }
1451 if (ret != Z_STREAM_END)
1452 {
1453 png_ptr->zstream.next_out = png_ptr->zbuf;
1454 png_ptr->zstream.avail_out = (uInt)png_ptr->zbuf_size;
1455 }
1456 }
1457 else
1458 {
1459 break;
1460 }
1461
1462 if (ret == Z_STREAM_END)
1463 break;
1464 }
1465
1466 inflateReset(&png_ptr->zstream);
1467 png_ptr->zstream.avail_in = 0;
1468
1469 if (ret != Z_STREAM_END)
1470 {
1471 png_ptr->current_text = NULL;
1472 png_free(png_ptr, key);
1473 png_free(png_ptr, text);
1474 return;
1475 }
1476
1477 png_ptr->current_text = NULL;
1478 png_free(png_ptr, key);
1479 key = text;
1480 text += key_size;
1481
1482 text_ptr = (png_textp)png_malloc(png_ptr,
1483 (png_uint_32)png_sizeof(png_text));
1484 text_ptr->compression = PNG_TEXT_COMPRESSION_zTXt;
1485 text_ptr->key = key;
1486 #ifdef PNG_iTXt_SUPPORTED
1487 text_ptr->lang = NULL;
1488 text_ptr->lang_key = NULL;
1489 #endif
1490 text_ptr->text = text;
1491
1492 ret = png_set_text_2(png_ptr, info_ptr, text_ptr, 1);
1493
1494 png_free(png_ptr, key);
1495 png_free(png_ptr, text_ptr);
1496
1497 if (ret)
1498 png_warning(png_ptr, "Insufficient memory to store text chunk.");
1499 }
1500 }
1501 #endif
1502
1503 #ifdef PNG_READ_iTXt_SUPPORTED
1504 void /* PRIVATE */
1505 png_push_handle_iTXt(png_structp png_ptr, png_infop info_ptr, png_uint_32
1506 length)
1507 {
1508 if (!(png_ptr->mode & PNG_HAVE_IHDR) || (png_ptr->mode & PNG_HAVE_IEND))
1509 {
1510 png_error(png_ptr, "Out of place iTXt");
1511 info_ptr = info_ptr; /* To quiet some compiler warnings */
1512 }
1513
1514 #ifdef PNG_MAX_MALLOC_64K
1515 png_ptr->skip_length = 0; /* This may not be necessary */
1516
1517 if (length > (png_uint_32)65535L) /* Can't hold entire string in memory */
1518 {
1519 png_warning(png_ptr, "iTXt chunk too large to fit in memory");
1520 png_ptr->skip_length = length - (png_uint_32)65535L;
1521 length = (png_uint_32)65535L;
1522 }
1523 #endif
1524
1525 png_ptr->current_text = (png_charp)png_malloc(png_ptr,
1526 (png_uint_32)(length + 1));
1527 png_ptr->current_text[length] = '\0';
1528 png_ptr->current_text_ptr = png_ptr->current_text;
1529 png_ptr->current_text_size = (png_size_t)length;
1530 png_ptr->current_text_left = (png_size_t)length;
1531 png_ptr->process_mode = PNG_READ_iTXt_MODE;
1532 }
1533
1534 void /* PRIVATE */
1535 png_push_read_iTXt(png_structp png_ptr, png_infop info_ptr)
1536 {
1537
1538 if (png_ptr->buffer_size && png_ptr->current_text_left)
1539 {
1540 png_size_t text_size;
1541
1542 if (png_ptr->buffer_size < png_ptr->current_text_left)
1543 text_size = png_ptr->buffer_size;
1544
1545 else
1546 text_size = png_ptr->current_text_left;
1547
1548 png_crc_read(png_ptr, (png_bytep)png_ptr->current_text_ptr, text_size);
1549 png_ptr->current_text_left -= text_size;
1550 png_ptr->current_text_ptr += text_size;
1551 }
1552 if (!(png_ptr->current_text_left))
1553 {
1554 png_textp text_ptr;
1555 png_charp key;
1556 int comp_flag;
1557 png_charp lang;
1558 png_charp lang_key;
1559 png_charp text;
1560 int ret;
1561
1562 if (png_ptr->buffer_size < 4)
1563 {
1564 png_push_save_buffer(png_ptr);
1565 return;
1566 }
1567
1568 png_push_crc_finish(png_ptr);
1569
1570 #ifdef PNG_MAX_MALLOC_64K
1571 if (png_ptr->skip_length)
1572 return;
1573 #endif
1574
1575 key = png_ptr->current_text;
1576
1577 for (lang = key; *lang; lang++)
1578 /* Empty loop */ ;
1579
1580 if (lang < key + png_ptr->current_text_size - 3)
1581 lang++;
1582
1583 comp_flag = *lang++;
1584 lang++; /* Skip comp_type, always zero */
1585
1586 for (lang_key = lang; *lang_key; lang_key++)
1587 /* Empty loop */ ;
1588
1589 lang_key++; /* Skip NUL separator */
1590
1591 text=lang_key;
1592
1593 if (lang_key < key + png_ptr->current_text_size - 1)
1594 {
1595 for (; *text; text++)
1596 /* Empty loop */ ;
1597 }
1598
1599 if (text < key + png_ptr->current_text_size)
1600 text++;
1601
1602 text_ptr = (png_textp)png_malloc(png_ptr,
1603 (png_uint_32)png_sizeof(png_text));
1604
1605 text_ptr->compression = comp_flag + 2;
1606 text_ptr->key = key;
1607 text_ptr->lang = lang;
1608 text_ptr->lang_key = lang_key;
1609 text_ptr->text = text;
1610 text_ptr->text_length = 0;
1611 text_ptr->itxt_length = png_strlen(text);
1612
1613 ret = png_set_text_2(png_ptr, info_ptr, text_ptr, 1);
1614
1615 png_ptr->current_text = NULL;
1616
1617 png_free(png_ptr, text_ptr);
1618 if (ret)
1619 png_warning(png_ptr, "Insufficient memory to store iTXt chunk.");
1620 }
1621 }
1622 #endif
1623
1624 /* This function is called when we haven't found a handler for this
1625 * chunk. If there isn't a problem with the chunk itself (ie a bad chunk
1626 * name or a critical chunk), the chunk is (currently) silently ignored.
1627 */
1628 void /* PRIVATE */
1629 png_push_handle_unknown(png_structp png_ptr, png_infop info_ptr, png_uint_32
1630 length)
1631 {
1632 png_uint_32 skip = 0;
1633
1634 if (!(png_ptr->chunk_name[0] & 0x20))
1635 {
1636 #ifdef PNG_READ_UNKNOWN_CHUNKS_SUPPORTED
1637 if (png_handle_as_unknown(png_ptr, png_ptr->chunk_name) !=
1638 PNG_HANDLE_CHUNK_ALWAYS
1639 #ifdef PNG_READ_USER_CHUNKS_SUPPORTED
1640 && png_ptr->read_user_chunk_fn == NULL
1641 #endif
1642 )
1643 #endif
1644 png_chunk_error(png_ptr, "unknown critical chunk");
1645
1646 info_ptr = info_ptr; /* To quiet some compiler warnings */
1647 }
1648
1649 #ifdef PNG_READ_UNKNOWN_CHUNKS_SUPPORTED
1650 if (png_ptr->flags & PNG_FLAG_KEEP_UNKNOWN_CHUNKS)
1651 {
1652 #ifdef PNG_MAX_MALLOC_64K
1653 if (length > (png_uint_32)65535L)
1654 {
1655 png_warning(png_ptr, "unknown chunk too large to fit in memory");
1656 skip = length - (png_uint_32)65535L;
1657 length = (png_uint_32)65535L;
1658 }
1659 #endif
1660 png_memcpy((png_charp)png_ptr->unknown_chunk.name,
1661 (png_charp)png_ptr->chunk_name,
1662 png_sizeof(png_ptr->unknown_chunk.name));
1663 png_ptr->unknown_chunk.name[png_sizeof(png_ptr->unknown_chunk.name) - 1]
1664 = '\0';
1665
1666 png_ptr->unknown_chunk.size = (png_size_t)length;
1667
1668 if (length == 0)
1669 png_ptr->unknown_chunk.data = NULL;
1670
1671 else
1672 {
1673 png_ptr->unknown_chunk.data = (png_bytep)png_malloc(png_ptr,
1674 (png_uint_32)length);
1675 png_crc_read(png_ptr, (png_bytep)png_ptr->unknown_chunk.data, length);
1676 }
1677
1678 #ifdef PNG_READ_USER_CHUNKS_SUPPORTED
1679 if (png_ptr->read_user_chunk_fn != NULL)
1680 {
1681 /* Callback to user unknown chunk handler */
1682 int ret;
1683 ret = (*(png_ptr->read_user_chunk_fn))
1684 (png_ptr, &png_ptr->unknown_chunk);
1685
1686 if (ret < 0)
1687 png_chunk_error(png_ptr, "error in user chunk");
1688
1689 if (ret == 0)
1690 {
1691 if (!(png_ptr->chunk_name[0] & 0x20))
1692 if (png_handle_as_unknown(png_ptr, png_ptr->chunk_name) !=
1693 PNG_HANDLE_CHUNK_ALWAYS)
1694 png_chunk_error(png_ptr, "unknown critical chunk");
1695 png_set_unknown_chunks(png_ptr, info_ptr,
1696 &png_ptr->unknown_chunk, 1);
1697 }
1698 }
1699
1700 else
1701 #endif
1702 png_set_unknown_chunks(png_ptr, info_ptr, &png_ptr->unknown_chunk, 1);
1703 png_free(png_ptr, png_ptr->unknown_chunk.data);
1704 png_ptr->unknown_chunk.data = NULL;
1705 }
1706
1707 else
1708 #endif
1709 skip=length;
1710 png_push_crc_skip(png_ptr, skip);
1711 }
1712
1713 void /* PRIVATE */
1714 png_push_have_info(png_structp png_ptr, png_infop info_ptr)
1231 { 1715 {
1232 if (png_ptr->info_fn != NULL) 1716 if (png_ptr->info_fn != NULL)
1233 (*(png_ptr->info_fn))(png_ptr, info_ptr); 1717 (*(png_ptr->info_fn))(png_ptr, info_ptr);
1234 } 1718 }
1235 1719
1236 void /* PRIVATE */ 1720 void /* PRIVATE */
1237 png_push_have_end(png_structrp png_ptr, png_inforp info_ptr) 1721 png_push_have_end(png_structp png_ptr, png_infop info_ptr)
1238 { 1722 {
1239 if (png_ptr->end_fn != NULL) 1723 if (png_ptr->end_fn != NULL)
1240 (*(png_ptr->end_fn))(png_ptr, info_ptr); 1724 (*(png_ptr->end_fn))(png_ptr, info_ptr);
1241 } 1725 }
1242 1726
1243 void /* PRIVATE */ 1727 void /* PRIVATE */
1244 png_push_have_row(png_structrp png_ptr, png_bytep row) 1728 png_push_have_row(png_structp png_ptr, png_bytep row)
1245 { 1729 {
1246 if (png_ptr->row_fn != NULL) 1730 if (png_ptr->row_fn != NULL)
1247 (*(png_ptr->row_fn))(png_ptr, row, png_ptr->row_number, 1731 (*(png_ptr->row_fn))(png_ptr, row, png_ptr->row_number,
1248 (int)png_ptr->pass); 1732 (int)png_ptr->pass);
1249 } 1733 }
1250 1734
1251 #ifdef PNG_READ_INTERLACING_SUPPORTED
1252 void PNGAPI 1735 void PNGAPI
1253 png_progressive_combine_row(png_const_structrp png_ptr, png_bytep old_row, 1736 png_progressive_combine_row (png_structp png_ptr,
1254 png_const_bytep new_row) 1737 png_bytep old_row, png_bytep new_row)
1255 { 1738 {
1739 #ifdef PNG_USE_LOCAL_ARRAYS
1740 PNG_CONST int FARDATA png_pass_dsp_mask[7] =
1741 {0xff, 0x0f, 0xff, 0x33, 0xff, 0x55, 0xff};
1742 #endif
1743
1256 if (png_ptr == NULL) 1744 if (png_ptr == NULL)
1257 return; 1745 return;
1258 1746
1259 /* new_row is a flag here - if it is NULL then the app callback was called 1747 if (new_row != NULL) /* new_row must == png_ptr->row_buf here. */
1260 * from an empty row (see the calls to png_struct::row_fn below), otherwise 1748 png_combine_row(png_ptr, old_row, png_pass_dsp_mask[png_ptr->pass]);
1261 * it must be png_ptr->row_buf+1 1749 }
1262 */
1263 if (new_row != NULL)
1264 png_combine_row(png_ptr, old_row, 1/*display*/);
1265 }
1266 #endif /* PNG_READ_INTERLACING_SUPPORTED */
1267 1750
1268 void PNGAPI 1751 void PNGAPI
1269 png_set_progressive_read_fn(png_structrp png_ptr, png_voidp progressive_ptr, 1752 png_set_progressive_read_fn(png_structp png_ptr, png_voidp progressive_ptr,
1270 png_progressive_info_ptr info_fn, png_progressive_row_ptr row_fn, 1753 png_progressive_info_ptr info_fn, png_progressive_row_ptr row_fn,
1271 png_progressive_end_ptr end_fn) 1754 png_progressive_end_ptr end_fn)
1272 { 1755 {
1273 if (png_ptr == NULL) 1756 if (png_ptr == NULL)
1274 return; 1757 return;
1275 1758
1276 png_ptr->info_fn = info_fn; 1759 png_ptr->info_fn = info_fn;
1277 png_ptr->row_fn = row_fn; 1760 png_ptr->row_fn = row_fn;
1278 png_ptr->end_fn = end_fn; 1761 png_ptr->end_fn = end_fn;
1279 1762
1280 png_set_read_fn(png_ptr, progressive_ptr, png_push_fill_buffer); 1763 png_set_read_fn(png_ptr, progressive_ptr, png_push_fill_buffer);
1281 } 1764 }
1282 1765
1283 png_voidp PNGAPI 1766 png_voidp PNGAPI
1284 png_get_progressive_ptr(png_const_structrp png_ptr) 1767 png_get_progressive_ptr(png_structp png_ptr)
1285 { 1768 {
1286 if (png_ptr == NULL) 1769 if (png_ptr == NULL)
1287 return (NULL); 1770 return (NULL);
1288 1771
1289 return png_ptr->io_ptr; 1772 return png_ptr->io_ptr;
1290 } 1773 }
1291 #endif /* PNG_PROGRESSIVE_READ_SUPPORTED */ 1774 #endif /* PNG_PROGRESSIVE_READ_SUPPORTED */
OLDNEW
« no previous file with comments | « third_party/libpng/pngmem.c ('k') | third_party/libpng/pngpriv.h » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698