xref: /aosp_15_r20/external/libjpeg-turbo/jdmarker.c (revision dfc6aa5c1cfd4bc4e2018dc74aa96e29ee49c6da)
1 /*
2  * jdmarker.c
3  *
4  * This file was part of the Independent JPEG Group's software:
5  * Copyright (C) 1991-1998, Thomas G. Lane.
6  * Lossless JPEG Modifications:
7  * Copyright (C) 1999, Ken Murchison.
8  * libjpeg-turbo Modifications:
9  * Copyright (C) 2012, 2015, 2022, 2024, D. R. Commander.
10  * For conditions of distribution and use, see the accompanying README.ijg
11  * file.
12  *
13  * This file contains routines to decode JPEG datastream markers.
14  * Most of the complexity arises from our desire to support input
15  * suspension: if not all of the data for a marker is available,
16  * we must exit back to the application.  On resumption, we reprocess
17  * the marker.
18  */
19 
20 #define JPEG_INTERNALS
21 #include "jinclude.h"
22 #include "jpeglib.h"
23 
24 
25 typedef enum {                  /* JPEG marker codes */
26   M_SOF0  = 0xc0,
27   M_SOF1  = 0xc1,
28   M_SOF2  = 0xc2,
29   M_SOF3  = 0xc3,
30 
31   M_SOF5  = 0xc5,
32   M_SOF6  = 0xc6,
33   M_SOF7  = 0xc7,
34 
35   M_JPG   = 0xc8,
36   M_SOF9  = 0xc9,
37   M_SOF10 = 0xca,
38   M_SOF11 = 0xcb,
39 
40   M_SOF13 = 0xcd,
41   M_SOF14 = 0xce,
42   M_SOF15 = 0xcf,
43 
44   M_DHT   = 0xc4,
45 
46   M_DAC   = 0xcc,
47 
48   M_RST0  = 0xd0,
49   M_RST1  = 0xd1,
50   M_RST2  = 0xd2,
51   M_RST3  = 0xd3,
52   M_RST4  = 0xd4,
53   M_RST5  = 0xd5,
54   M_RST6  = 0xd6,
55   M_RST7  = 0xd7,
56 
57   M_SOI   = 0xd8,
58   M_EOI   = 0xd9,
59   M_SOS   = 0xda,
60   M_DQT   = 0xdb,
61   M_DNL   = 0xdc,
62   M_DRI   = 0xdd,
63   M_DHP   = 0xde,
64   M_EXP   = 0xdf,
65 
66   M_APP0  = 0xe0,
67   M_APP1  = 0xe1,
68   M_APP2  = 0xe2,
69   M_APP3  = 0xe3,
70   M_APP4  = 0xe4,
71   M_APP5  = 0xe5,
72   M_APP6  = 0xe6,
73   M_APP7  = 0xe7,
74   M_APP8  = 0xe8,
75   M_APP9  = 0xe9,
76   M_APP10 = 0xea,
77   M_APP11 = 0xeb,
78   M_APP12 = 0xec,
79   M_APP13 = 0xed,
80   M_APP14 = 0xee,
81   M_APP15 = 0xef,
82 
83   M_JPG0  = 0xf0,
84   M_JPG13 = 0xfd,
85   M_COM   = 0xfe,
86 
87   M_TEM   = 0x01,
88 
89   M_ERROR = 0x100
90 } JPEG_MARKER;
91 
92 
93 /* Private state */
94 
95 typedef struct {
96   struct jpeg_marker_reader pub; /* public fields */
97 
98   /* Application-overridable marker processing methods */
99   jpeg_marker_parser_method process_COM;
100   jpeg_marker_parser_method process_APPn[16];
101 
102   /* Limit on marker data length to save for each marker type */
103   unsigned int length_limit_COM;
104   unsigned int length_limit_APPn[16];
105 
106   /* Status of COM/APPn marker saving */
107   jpeg_saved_marker_ptr cur_marker;     /* NULL if not processing a marker */
108   unsigned int bytes_read;              /* data bytes read so far in marker */
109   /* Note: cur_marker is not linked into marker_list until it's all read. */
110 } my_marker_reader;
111 
112 typedef my_marker_reader *my_marker_ptr;
113 
114 
115 /*
116  * Macros for fetching data from the data source module.
117  *
118  * At all times, cinfo->src->next_input_byte and ->bytes_in_buffer reflect
119  * the current restart point; we update them only when we have reached a
120  * suitable place to restart if a suspension occurs.
121  */
122 
123 /* Declare and initialize local copies of input pointer/count */
124 #define INPUT_VARS(cinfo) \
125   struct jpeg_source_mgr *datasrc = (cinfo)->src; \
126   const JOCTET *next_input_byte = datasrc->next_input_byte; \
127   size_t bytes_in_buffer = datasrc->bytes_in_buffer
128 
129 /* Unload the local copies --- do this only at a restart boundary */
130 #define INPUT_SYNC(cinfo) \
131   ( datasrc->next_input_byte = next_input_byte, \
132     datasrc->bytes_in_buffer = bytes_in_buffer )
133 
134 /* Reload the local copies --- used only in MAKE_BYTE_AVAIL */
135 #define INPUT_RELOAD(cinfo) \
136   ( next_input_byte = datasrc->next_input_byte, \
137     bytes_in_buffer = datasrc->bytes_in_buffer )
138 
139 /* Internal macro for INPUT_BYTE and INPUT_2BYTES: make a byte available.
140  * Note we do *not* do INPUT_SYNC before calling fill_input_buffer,
141  * but we must reload the local copies after a successful fill.
142  */
143 #define MAKE_BYTE_AVAIL(cinfo, action) \
144   if (bytes_in_buffer == 0) { \
145     if (!(*datasrc->fill_input_buffer) (cinfo)) \
146       { action; } \
147     INPUT_RELOAD(cinfo); \
148   }
149 
150 /* Read a byte into variable V.
151  * If must suspend, take the specified action (typically "return FALSE").
152  */
153 #define INPUT_BYTE(cinfo, V, action) \
154   MAKESTMT( MAKE_BYTE_AVAIL(cinfo, action); \
155             bytes_in_buffer--; \
156             V = *next_input_byte++; )
157 
158 /* As above, but read two bytes interpreted as an unsigned 16-bit integer.
159  * V should be declared unsigned int or perhaps JLONG.
160  */
161 #define INPUT_2BYTES(cinfo, V, action) \
162   MAKESTMT( MAKE_BYTE_AVAIL(cinfo, action); \
163             bytes_in_buffer--; \
164             V = ((unsigned int)(*next_input_byte++)) << 8; \
165             MAKE_BYTE_AVAIL(cinfo, action); \
166             bytes_in_buffer--; \
167             V += *next_input_byte++; )
168 
169 
170 /*
171  * Routines to process JPEG markers.
172  *
173  * Entry condition: JPEG marker itself has been read and its code saved
174  *   in cinfo->unread_marker; input restart point is just after the marker.
175  *
176  * Exit: if return TRUE, have read and processed any parameters, and have
177  *   updated the restart point to point after the parameters.
178  *   If return FALSE, was forced to suspend before reaching end of
179  *   marker parameters; restart point has not been moved.  Same routine
180  *   will be called again after application supplies more input data.
181  *
182  * This approach to suspension assumes that all of a marker's parameters
183  * can fit into a single input bufferload.  This should hold for "normal"
184  * markers.  Some COM/APPn markers might have large parameter segments
185  * that might not fit.  If we are simply dropping such a marker, we use
186  * skip_input_data to get past it, and thereby put the problem on the
187  * source manager's shoulders.  If we are saving the marker's contents
188  * into memory, we use a slightly different convention: when forced to
189  * suspend, the marker processor updates the restart point to the end of
190  * what it's consumed (ie, the end of the buffer) before returning FALSE.
191  * On resumption, cinfo->unread_marker still contains the marker code,
192  * but the data source will point to the next chunk of marker data.
193  * The marker processor must retain internal state to deal with this.
194  *
195  * Note that we don't bother to avoid duplicate trace messages if a
196  * suspension occurs within marker parameters.  Other side effects
197  * require more care.
198  */
199 
200 
201 LOCAL(boolean)
get_soi(j_decompress_ptr cinfo)202 get_soi(j_decompress_ptr cinfo)
203 /* Process an SOI marker */
204 {
205   int i;
206 
207   TRACEMS(cinfo, 1, JTRC_SOI);
208 
209   if (cinfo->marker->saw_SOI)
210     ERREXIT(cinfo, JERR_SOI_DUPLICATE);
211 
212   /* Reset all parameters that are defined to be reset by SOI */
213 
214   for (i = 0; i < NUM_ARITH_TBLS; i++) {
215     cinfo->arith_dc_L[i] = 0;
216     cinfo->arith_dc_U[i] = 1;
217     cinfo->arith_ac_K[i] = 5;
218   }
219   cinfo->restart_interval = 0;
220 
221   /* Set initial assumptions for colorspace etc */
222 
223   cinfo->jpeg_color_space = JCS_UNKNOWN;
224   cinfo->CCIR601_sampling = FALSE; /* Assume non-CCIR sampling??? */
225 
226   cinfo->saw_JFIF_marker = FALSE;
227   cinfo->JFIF_major_version = 1; /* set default JFIF APP0 values */
228   cinfo->JFIF_minor_version = 1;
229   cinfo->density_unit = 0;
230   cinfo->X_density = 1;
231   cinfo->Y_density = 1;
232   cinfo->saw_Adobe_marker = FALSE;
233   cinfo->Adobe_transform = 0;
234 
235   cinfo->marker->saw_SOI = TRUE;
236 
237   return TRUE;
238 }
239 
240 
241 LOCAL(boolean)
get_sof(j_decompress_ptr cinfo,boolean is_prog,boolean is_arith)242 get_sof(j_decompress_ptr cinfo, boolean is_prog, boolean is_arith)
243 /* Process a SOFn marker */
244 {
245   JLONG length;
246   int c, ci;
247   jpeg_component_info *compptr;
248   INPUT_VARS(cinfo);
249 
250   cinfo->progressive_mode = is_prog;
251   cinfo->arith_code = is_arith;
252 
253   INPUT_2BYTES(cinfo, length, return FALSE);
254 
255   INPUT_BYTE(cinfo, cinfo->data_precision, return FALSE);
256   INPUT_2BYTES(cinfo, cinfo->image_height, return FALSE);
257   INPUT_2BYTES(cinfo, cinfo->image_width, return FALSE);
258   INPUT_BYTE(cinfo, cinfo->num_components, return FALSE);
259 
260   length -= 8;
261 
262   TRACEMS4(cinfo, 1, JTRC_SOF, cinfo->unread_marker,
263            (int)cinfo->image_width, (int)cinfo->image_height,
264            cinfo->num_components);
265 
266   if (cinfo->marker->saw_SOF)
267     ERREXIT(cinfo, JERR_SOF_DUPLICATE);
268 
269   /* We don't support files in which the image height is initially specified */
270   /* as 0 and is later redefined by DNL.  As long as we have to check that,  */
271   /* might as well have a general sanity check. */
272   if (cinfo->image_height <= 0 || cinfo->image_width <= 0 ||
273       cinfo->num_components <= 0)
274     ERREXIT(cinfo, JERR_EMPTY_IMAGE);
275 
276   if (length != (cinfo->num_components * 3))
277     ERREXIT(cinfo, JERR_BAD_LENGTH);
278 
279   if (cinfo->comp_info == NULL) /* do only once, even if suspend */
280     cinfo->comp_info = (jpeg_component_info *)(*cinfo->mem->alloc_small)
281                         ((j_common_ptr)cinfo, JPOOL_IMAGE,
282                          cinfo->num_components * sizeof(jpeg_component_info));
283 
284   for (ci = 0, compptr = cinfo->comp_info; ci < cinfo->num_components;
285        ci++, compptr++) {
286     compptr->component_index = ci;
287     INPUT_BYTE(cinfo, compptr->component_id, return FALSE);
288     INPUT_BYTE(cinfo, c, return FALSE);
289     compptr->h_samp_factor = (c >> 4) & 15;
290     compptr->v_samp_factor = (c     ) & 15;
291     INPUT_BYTE(cinfo, compptr->quant_tbl_no, return FALSE);
292 
293     TRACEMS4(cinfo, 1, JTRC_SOF_COMPONENT,
294              compptr->component_id, compptr->h_samp_factor,
295              compptr->v_samp_factor, compptr->quant_tbl_no);
296   }
297 
298   cinfo->marker->saw_SOF = TRUE;
299 
300   INPUT_SYNC(cinfo);
301   return TRUE;
302 }
303 
304 
305 LOCAL(boolean)
get_sos(j_decompress_ptr cinfo)306 get_sos(j_decompress_ptr cinfo)
307 /* Process a SOS marker */
308 {
309   JLONG length;
310   int i, ci, n, c, cc, pi;
311   jpeg_component_info *compptr;
312   INPUT_VARS(cinfo);
313 
314   if (!cinfo->marker->saw_SOF)
315     ERREXIT(cinfo, JERR_SOS_NO_SOF);
316 
317   INPUT_2BYTES(cinfo, length, return FALSE);
318 
319   INPUT_BYTE(cinfo, n, return FALSE); /* Number of components */
320 
321   TRACEMS1(cinfo, 1, JTRC_SOS, n);
322 
323   if (length != (n * 2 + 6) || n < 1 || n > MAX_COMPS_IN_SCAN)
324     ERREXIT(cinfo, JERR_BAD_LENGTH);
325 
326   cinfo->comps_in_scan = n;
327 
328   /* Collect the component-spec parameters */
329 
330   for (i = 0; i < MAX_COMPS_IN_SCAN; i++)
331     cinfo->cur_comp_info[i] = NULL;
332 
333   for (i = 0; i < n; i++) {
334     INPUT_BYTE(cinfo, cc, return FALSE);
335     INPUT_BYTE(cinfo, c, return FALSE);
336 
337     for (ci = 0, compptr = cinfo->comp_info;
338          ci < cinfo->num_components && ci < MAX_COMPS_IN_SCAN;
339          ci++, compptr++) {
340       if (cc == compptr->component_id && !cinfo->cur_comp_info[ci])
341         goto id_found;
342     }
343 
344     ERREXIT1(cinfo, JERR_BAD_COMPONENT_ID, cc);
345 
346 id_found:
347 
348     cinfo->cur_comp_info[i] = compptr;
349     compptr->dc_tbl_no = (c >> 4) & 15;
350     compptr->ac_tbl_no = (c     ) & 15;
351 
352     TRACEMS3(cinfo, 1, JTRC_SOS_COMPONENT, cc,
353              compptr->dc_tbl_no, compptr->ac_tbl_no);
354 
355     /* This CSi (cc) should differ from the previous CSi */
356     for (pi = 0; pi < i; pi++) {
357       if (cinfo->cur_comp_info[pi] == compptr) {
358         ERREXIT1(cinfo, JERR_BAD_COMPONENT_ID, cc);
359       }
360     }
361   }
362 
363   /* Collect the additional scan parameters Ss, Se, Ah/Al. */
364   INPUT_BYTE(cinfo, c, return FALSE);
365   cinfo->Ss = c;
366   INPUT_BYTE(cinfo, c, return FALSE);
367   cinfo->Se = c;
368   INPUT_BYTE(cinfo, c, return FALSE);
369   cinfo->Ah = (c >> 4) & 15;
370   cinfo->Al = (c     ) & 15;
371 
372   TRACEMS4(cinfo, 1, JTRC_SOS_PARAMS, cinfo->Ss, cinfo->Se,
373            cinfo->Ah, cinfo->Al);
374 
375   /* Prepare to scan data & restart markers */
376   cinfo->marker->next_restart_num = 0;
377 
378   /* Count another SOS marker */
379   cinfo->input_scan_number++;
380 
381   INPUT_SYNC(cinfo);
382   return TRUE;
383 }
384 
385 
386 #ifdef D_ARITH_CODING_SUPPORTED
387 
388 LOCAL(boolean)
get_dac(j_decompress_ptr cinfo)389 get_dac(j_decompress_ptr cinfo)
390 /* Process a DAC marker */
391 {
392   JLONG length;
393   int index, val;
394   INPUT_VARS(cinfo);
395 
396   INPUT_2BYTES(cinfo, length, return FALSE);
397   length -= 2;
398 
399   while (length > 0) {
400     INPUT_BYTE(cinfo, index, return FALSE);
401     INPUT_BYTE(cinfo, val, return FALSE);
402 
403     length -= 2;
404 
405     TRACEMS2(cinfo, 1, JTRC_DAC, index, val);
406 
407     if (index < 0 || index >= (2 * NUM_ARITH_TBLS))
408       ERREXIT1(cinfo, JERR_DAC_INDEX, index);
409 
410     if (index >= NUM_ARITH_TBLS) { /* define AC table */
411       cinfo->arith_ac_K[index - NUM_ARITH_TBLS] = (UINT8)val;
412     } else {                    /* define DC table */
413       cinfo->arith_dc_L[index] = (UINT8)(val & 0x0F);
414       cinfo->arith_dc_U[index] = (UINT8)(val >> 4);
415       if (cinfo->arith_dc_L[index] > cinfo->arith_dc_U[index])
416         ERREXIT1(cinfo, JERR_DAC_VALUE, val);
417     }
418   }
419 
420   if (length != 0)
421     ERREXIT(cinfo, JERR_BAD_LENGTH);
422 
423   INPUT_SYNC(cinfo);
424   return TRUE;
425 }
426 
427 #else /* !D_ARITH_CODING_SUPPORTED */
428 
429 #define get_dac(cinfo)  skip_variable(cinfo)
430 
431 #endif /* D_ARITH_CODING_SUPPORTED */
432 
433 
434 LOCAL(boolean)
get_dht(j_decompress_ptr cinfo)435 get_dht(j_decompress_ptr cinfo)
436 /* Process a DHT marker */
437 {
438   JLONG length;
439   UINT8 bits[17];
440   UINT8 huffval[256];
441   int i, index, count;
442   JHUFF_TBL **htblptr;
443   INPUT_VARS(cinfo);
444 
445   INPUT_2BYTES(cinfo, length, return FALSE);
446   length -= 2;
447 
448   while (length > 16) {
449     INPUT_BYTE(cinfo, index, return FALSE);
450 
451     TRACEMS1(cinfo, 1, JTRC_DHT, index);
452 
453     bits[0] = 0;
454     count = 0;
455     for (i = 1; i <= 16; i++) {
456       INPUT_BYTE(cinfo, bits[i], return FALSE);
457       count += bits[i];
458     }
459 
460     length -= 1 + 16;
461 
462     TRACEMS8(cinfo, 2, JTRC_HUFFBITS,
463              bits[1], bits[2], bits[3], bits[4],
464              bits[5], bits[6], bits[7], bits[8]);
465     TRACEMS8(cinfo, 2, JTRC_HUFFBITS,
466              bits[9], bits[10], bits[11], bits[12],
467              bits[13], bits[14], bits[15], bits[16]);
468 
469     /* Here we just do minimal validation of the counts to avoid walking
470      * off the end of our table space.  jdhuff.c will check more carefully.
471      */
472     if (count > 256 || ((JLONG)count) > length)
473       ERREXIT(cinfo, JERR_BAD_HUFF_TABLE);
474 
475     for (i = 0; i < count; i++)
476       INPUT_BYTE(cinfo, huffval[i], return FALSE);
477 
478     memset(&huffval[count], 0, (256 - count) * sizeof(UINT8));
479 
480     length -= count;
481 
482     if (index & 0x10) {         /* AC table definition */
483       index -= 0x10;
484       if (index < 0 || index >= NUM_HUFF_TBLS)
485         ERREXIT1(cinfo, JERR_DHT_INDEX, index);
486       htblptr = &cinfo->ac_huff_tbl_ptrs[index];
487     } else {                    /* DC table definition */
488       if (index < 0 || index >= NUM_HUFF_TBLS)
489         ERREXIT1(cinfo, JERR_DHT_INDEX, index);
490       htblptr = &cinfo->dc_huff_tbl_ptrs[index];
491     }
492 
493     if (*htblptr == NULL)
494       *htblptr = jpeg_alloc_huff_table((j_common_ptr)cinfo);
495 
496     memcpy((*htblptr)->bits, bits, sizeof((*htblptr)->bits));
497     memcpy((*htblptr)->huffval, huffval, sizeof((*htblptr)->huffval));
498   }
499 
500   if (length != 0)
501     ERREXIT(cinfo, JERR_BAD_LENGTH);
502 
503   INPUT_SYNC(cinfo);
504   return TRUE;
505 }
506 
507 
508 LOCAL(boolean)
get_dqt(j_decompress_ptr cinfo)509 get_dqt(j_decompress_ptr cinfo)
510 /* Process a DQT marker */
511 {
512   JLONG length;
513   int n, i, prec;
514   unsigned int tmp;
515   JQUANT_TBL *quant_ptr;
516   INPUT_VARS(cinfo);
517 
518   INPUT_2BYTES(cinfo, length, return FALSE);
519   length -= 2;
520 
521   while (length > 0) {
522     INPUT_BYTE(cinfo, n, return FALSE);
523     prec = n >> 4;
524     n &= 0x0F;
525 
526     TRACEMS2(cinfo, 1, JTRC_DQT, n, prec);
527 
528     if (n >= NUM_QUANT_TBLS)
529       ERREXIT1(cinfo, JERR_DQT_INDEX, n);
530 
531     if (cinfo->quant_tbl_ptrs[n] == NULL)
532       cinfo->quant_tbl_ptrs[n] = jpeg_alloc_quant_table((j_common_ptr)cinfo);
533     quant_ptr = cinfo->quant_tbl_ptrs[n];
534 
535     for (i = 0; i < DCTSIZE2; i++) {
536       if (prec)
537         INPUT_2BYTES(cinfo, tmp, return FALSE);
538       else
539         INPUT_BYTE(cinfo, tmp, return FALSE);
540       /* We convert the zigzag-order table to natural array order. */
541       quant_ptr->quantval[jpeg_natural_order[i]] = (UINT16)tmp;
542     }
543 
544     if (cinfo->err->trace_level >= 2) {
545       for (i = 0; i < DCTSIZE2; i += 8) {
546         TRACEMS8(cinfo, 2, JTRC_QUANTVALS,
547                  quant_ptr->quantval[i],     quant_ptr->quantval[i + 1],
548                  quant_ptr->quantval[i + 2], quant_ptr->quantval[i + 3],
549                  quant_ptr->quantval[i + 4], quant_ptr->quantval[i + 5],
550                  quant_ptr->quantval[i + 6], quant_ptr->quantval[i + 7]);
551       }
552     }
553 
554     length -= DCTSIZE2 + 1;
555     if (prec) length -= DCTSIZE2;
556   }
557 
558   if (length != 0)
559     ERREXIT(cinfo, JERR_BAD_LENGTH);
560 
561   INPUT_SYNC(cinfo);
562   return TRUE;
563 }
564 
565 
566 LOCAL(boolean)
get_dri(j_decompress_ptr cinfo)567 get_dri(j_decompress_ptr cinfo)
568 /* Process a DRI marker */
569 {
570   JLONG length;
571   unsigned int tmp;
572   INPUT_VARS(cinfo);
573 
574   INPUT_2BYTES(cinfo, length, return FALSE);
575 
576   if (length != 4)
577     ERREXIT(cinfo, JERR_BAD_LENGTH);
578 
579   INPUT_2BYTES(cinfo, tmp, return FALSE);
580 
581   TRACEMS1(cinfo, 1, JTRC_DRI, tmp);
582 
583   cinfo->restart_interval = tmp;
584 
585   INPUT_SYNC(cinfo);
586   return TRUE;
587 }
588 
589 
590 /*
591  * Routines for processing APPn and COM markers.
592  * These are either saved in memory or discarded, per application request.
593  * APP0 and APP14 are specially checked to see if they are
594  * JFIF and Adobe markers, respectively.
595  */
596 
597 #define APP0_DATA_LEN   14      /* Length of interesting data in APP0 */
598 #define APP14_DATA_LEN  12      /* Length of interesting data in APP14 */
599 #define APPN_DATA_LEN   14      /* Must be the largest of the above!! */
600 
601 
602 LOCAL(void)
examine_app0(j_decompress_ptr cinfo,JOCTET * data,unsigned int datalen,JLONG remaining)603 examine_app0(j_decompress_ptr cinfo, JOCTET *data, unsigned int datalen,
604              JLONG remaining)
605 /* Examine first few bytes from an APP0.
606  * Take appropriate action if it is a JFIF marker.
607  * datalen is # of bytes at data[], remaining is length of rest of marker data.
608  */
609 {
610   JLONG totallen = (JLONG)datalen + remaining;
611 
612   if (datalen >= APP0_DATA_LEN &&
613       data[0] == 0x4A &&
614       data[1] == 0x46 &&
615       data[2] == 0x49 &&
616       data[3] == 0x46 &&
617       data[4] == 0) {
618     /* Found JFIF APP0 marker: save info */
619     cinfo->saw_JFIF_marker = TRUE;
620     cinfo->JFIF_major_version = data[5];
621     cinfo->JFIF_minor_version = data[6];
622     cinfo->density_unit = data[7];
623     cinfo->X_density = (data[8] << 8) + data[9];
624     cinfo->Y_density = (data[10] << 8) + data[11];
625     /* Check version.
626      * Major version must be 1, anything else signals an incompatible change.
627      * (We used to treat this as an error, but now it's a nonfatal warning,
628      * because some bozo at Hijaak couldn't read the spec.)
629      * Minor version should be 0..2, but process anyway if newer.
630      */
631     if (cinfo->JFIF_major_version != 1)
632       WARNMS2(cinfo, JWRN_JFIF_MAJOR,
633               cinfo->JFIF_major_version, cinfo->JFIF_minor_version);
634     /* Generate trace messages */
635     TRACEMS5(cinfo, 1, JTRC_JFIF,
636              cinfo->JFIF_major_version, cinfo->JFIF_minor_version,
637              cinfo->X_density, cinfo->Y_density, cinfo->density_unit);
638     /* Validate thumbnail dimensions and issue appropriate messages */
639     if (data[12] | data[13])
640       TRACEMS2(cinfo, 1, JTRC_JFIF_THUMBNAIL, data[12], data[13]);
641     totallen -= APP0_DATA_LEN;
642     if (totallen != ((JLONG)data[12] * (JLONG)data[13] * (JLONG)3))
643       TRACEMS1(cinfo, 1, JTRC_JFIF_BADTHUMBNAILSIZE, (int)totallen);
644   } else if (datalen >= 6 &&
645              data[0] == 0x4A &&
646              data[1] == 0x46 &&
647              data[2] == 0x58 &&
648              data[3] == 0x58 &&
649              data[4] == 0) {
650     /* Found JFIF "JFXX" extension APP0 marker */
651     /* The library doesn't actually do anything with these,
652      * but we try to produce a helpful trace message.
653      */
654     switch (data[5]) {
655     case 0x10:
656       TRACEMS1(cinfo, 1, JTRC_THUMB_JPEG, (int)totallen);
657       break;
658     case 0x11:
659       TRACEMS1(cinfo, 1, JTRC_THUMB_PALETTE, (int)totallen);
660       break;
661     case 0x13:
662       TRACEMS1(cinfo, 1, JTRC_THUMB_RGB, (int)totallen);
663       break;
664     default:
665       TRACEMS2(cinfo, 1, JTRC_JFIF_EXTENSION, data[5], (int)totallen);
666       break;
667     }
668   } else {
669     /* Start of APP0 does not match "JFIF" or "JFXX", or too short */
670     TRACEMS1(cinfo, 1, JTRC_APP0, (int)totallen);
671   }
672 }
673 
674 
675 LOCAL(void)
examine_app14(j_decompress_ptr cinfo,JOCTET * data,unsigned int datalen,JLONG remaining)676 examine_app14(j_decompress_ptr cinfo, JOCTET *data, unsigned int datalen,
677               JLONG remaining)
678 /* Examine first few bytes from an APP14.
679  * Take appropriate action if it is an Adobe marker.
680  * datalen is # of bytes at data[], remaining is length of rest of marker data.
681  */
682 {
683   unsigned int version, flags0, flags1, transform;
684 
685   if (datalen >= APP14_DATA_LEN &&
686       data[0] == 0x41 &&
687       data[1] == 0x64 &&
688       data[2] == 0x6F &&
689       data[3] == 0x62 &&
690       data[4] == 0x65) {
691     /* Found Adobe APP14 marker */
692     version = (data[5] << 8) + data[6];
693     flags0 = (data[7] << 8) + data[8];
694     flags1 = (data[9] << 8) + data[10];
695     transform = data[11];
696     TRACEMS4(cinfo, 1, JTRC_ADOBE, version, flags0, flags1, transform);
697     cinfo->saw_Adobe_marker = TRUE;
698     cinfo->Adobe_transform = (UINT8)transform;
699   } else {
700     /* Start of APP14 does not match "Adobe", or too short */
701     TRACEMS1(cinfo, 1, JTRC_APP14, (int)(datalen + remaining));
702   }
703 }
704 
705 
706 METHODDEF(boolean)
get_interesting_appn(j_decompress_ptr cinfo)707 get_interesting_appn(j_decompress_ptr cinfo)
708 /* Process an APP0 or APP14 marker without saving it */
709 {
710   JLONG length;
711   JOCTET b[APPN_DATA_LEN];
712   unsigned int i, numtoread;
713   INPUT_VARS(cinfo);
714 
715   INPUT_2BYTES(cinfo, length, return FALSE);
716   length -= 2;
717 
718   /* get the interesting part of the marker data */
719   if (length >= APPN_DATA_LEN)
720     numtoread = APPN_DATA_LEN;
721   else if (length > 0)
722     numtoread = (unsigned int)length;
723   else
724     numtoread = 0;
725   for (i = 0; i < numtoread; i++)
726     INPUT_BYTE(cinfo, b[i], return FALSE);
727   length -= numtoread;
728 
729   /* process it */
730   switch (cinfo->unread_marker) {
731   case M_APP0:
732     examine_app0(cinfo, (JOCTET *)b, numtoread, length);
733     break;
734   case M_APP14:
735     examine_app14(cinfo, (JOCTET *)b, numtoread, length);
736     break;
737   default:
738     /* can't get here unless jpeg_save_markers chooses wrong processor */
739     ERREXIT1(cinfo, JERR_UNKNOWN_MARKER, cinfo->unread_marker);
740     break;
741   }
742 
743   /* skip any remaining data -- could be lots */
744   INPUT_SYNC(cinfo);
745   if (length > 0)
746     (*cinfo->src->skip_input_data) (cinfo, (long)length);
747 
748   return TRUE;
749 }
750 
751 
752 #ifdef SAVE_MARKERS_SUPPORTED
753 
754 METHODDEF(boolean)
save_marker(j_decompress_ptr cinfo)755 save_marker(j_decompress_ptr cinfo)
756 /* Save an APPn or COM marker into the marker list */
757 {
758   my_marker_ptr marker = (my_marker_ptr)cinfo->marker;
759   jpeg_saved_marker_ptr cur_marker = marker->cur_marker;
760   unsigned int bytes_read, data_length;
761   JOCTET *data;
762   JLONG length = 0;
763   INPUT_VARS(cinfo);
764 
765   if (cur_marker == NULL) {
766     /* begin reading a marker */
767     INPUT_2BYTES(cinfo, length, return FALSE);
768     length -= 2;
769     if (length >= 0) {          /* watch out for bogus length word */
770       /* figure out how much we want to save */
771       unsigned int limit;
772       if (cinfo->unread_marker == (int)M_COM)
773         limit = marker->length_limit_COM;
774       else
775         limit = marker->length_limit_APPn[cinfo->unread_marker - (int)M_APP0];
776       if ((unsigned int)length < limit)
777         limit = (unsigned int)length;
778       /* allocate and initialize the marker item */
779       cur_marker = (jpeg_saved_marker_ptr)
780         (*cinfo->mem->alloc_large) ((j_common_ptr)cinfo, JPOOL_IMAGE,
781                                     sizeof(struct jpeg_marker_struct) + limit);
782       cur_marker->next = NULL;
783       cur_marker->marker = (UINT8)cinfo->unread_marker;
784       cur_marker->original_length = (unsigned int)length;
785       cur_marker->data_length = limit;
786       /* data area is just beyond the jpeg_marker_struct */
787       data = cur_marker->data = (JOCTET *)(cur_marker + 1);
788       marker->cur_marker = cur_marker;
789       marker->bytes_read = 0;
790       bytes_read = 0;
791       data_length = limit;
792     } else {
793       /* deal with bogus length word */
794       bytes_read = data_length = 0;
795       data = NULL;
796     }
797   } else {
798     /* resume reading a marker */
799     bytes_read = marker->bytes_read;
800     data_length = cur_marker->data_length;
801     data = cur_marker->data + bytes_read;
802   }
803 
804   while (bytes_read < data_length) {
805     INPUT_SYNC(cinfo);          /* move the restart point to here */
806     marker->bytes_read = bytes_read;
807     /* If there's not at least one byte in buffer, suspend */
808     MAKE_BYTE_AVAIL(cinfo, return FALSE);
809     /* Copy bytes with reasonable rapidity */
810     while (bytes_read < data_length && bytes_in_buffer > 0) {
811       *data++ = *next_input_byte++;
812       bytes_in_buffer--;
813       bytes_read++;
814     }
815   }
816 
817   /* Done reading what we want to read */
818   if (cur_marker != NULL) {     /* will be NULL if bogus length word */
819     /* Add new marker to end of list */
820     if (cinfo->marker_list == NULL || cinfo->master->marker_list_end == NULL) {
821       cinfo->marker_list = cinfo->master->marker_list_end = cur_marker;
822     } else {
823       cinfo->master->marker_list_end->next = cur_marker;
824       cinfo->master->marker_list_end = cur_marker;
825     }
826     /* Reset pointer & calc remaining data length */
827     data = cur_marker->data;
828     length = cur_marker->original_length - data_length;
829   }
830   /* Reset to initial state for next marker */
831   marker->cur_marker = NULL;
832 
833   /* Process the marker if interesting; else just make a generic trace msg */
834   switch (cinfo->unread_marker) {
835   case M_APP0:
836     examine_app0(cinfo, data, data_length, length);
837     break;
838   case M_APP14:
839     examine_app14(cinfo, data, data_length, length);
840     break;
841   default:
842     TRACEMS2(cinfo, 1, JTRC_MISC_MARKER, cinfo->unread_marker,
843              (int)(data_length + length));
844     break;
845   }
846 
847   /* skip any remaining data -- could be lots */
848   INPUT_SYNC(cinfo);            /* do before skip_input_data */
849   if (length > 0)
850     (*cinfo->src->skip_input_data) (cinfo, (long)length);
851 
852   return TRUE;
853 }
854 
855 #endif /* SAVE_MARKERS_SUPPORTED */
856 
857 
858 METHODDEF(boolean)
skip_variable(j_decompress_ptr cinfo)859 skip_variable(j_decompress_ptr cinfo)
860 /* Skip over an unknown or uninteresting variable-length marker */
861 {
862   JLONG length;
863   INPUT_VARS(cinfo);
864 
865   INPUT_2BYTES(cinfo, length, return FALSE);
866   length -= 2;
867 
868   TRACEMS2(cinfo, 1, JTRC_MISC_MARKER, cinfo->unread_marker, (int)length);
869 
870   INPUT_SYNC(cinfo);            /* do before skip_input_data */
871   if (length > 0)
872     (*cinfo->src->skip_input_data) (cinfo, (long)length);
873 
874   return TRUE;
875 }
876 
877 
878 /*
879  * Find the next JPEG marker, save it in cinfo->unread_marker.
880  * Returns FALSE if had to suspend before reaching a marker;
881  * in that case cinfo->unread_marker is unchanged.
882  *
883  * Note that the result might not be a valid marker code,
884  * but it will never be 0 or FF.
885  */
886 
887 LOCAL(boolean)
next_marker(j_decompress_ptr cinfo)888 next_marker(j_decompress_ptr cinfo)
889 {
890   int c;
891   INPUT_VARS(cinfo);
892 
893   for (;;) {
894     INPUT_BYTE(cinfo, c, return FALSE);
895     /* Skip any non-FF bytes.
896      * This may look a bit inefficient, but it will not occur in a valid file.
897      * We sync after each discarded byte so that a suspending data source
898      * can discard the byte from its buffer.
899      */
900     while (c != 0xFF) {
901       cinfo->marker->discarded_bytes++;
902       INPUT_SYNC(cinfo);
903       INPUT_BYTE(cinfo, c, return FALSE);
904     }
905     /* This loop swallows any duplicate FF bytes.  Extra FFs are legal as
906      * pad bytes, so don't count them in discarded_bytes.  We assume there
907      * will not be so many consecutive FF bytes as to overflow a suspending
908      * data source's input buffer.
909      */
910     do {
911       INPUT_BYTE(cinfo, c, return FALSE);
912     } while (c == 0xFF);
913     if (c != 0)
914       break;                    /* found a valid marker, exit loop */
915     /* Reach here if we found a stuffed-zero data sequence (FF/00).
916      * Discard it and loop back to try again.
917      */
918     cinfo->marker->discarded_bytes += 2;
919     INPUT_SYNC(cinfo);
920   }
921 
922   if (cinfo->marker->discarded_bytes != 0) {
923     WARNMS2(cinfo, JWRN_EXTRANEOUS_DATA, cinfo->marker->discarded_bytes, c);
924     cinfo->marker->discarded_bytes = 0;
925   }
926 
927   cinfo->unread_marker = c;
928 
929   INPUT_SYNC(cinfo);
930   return TRUE;
931 }
932 
933 
934 LOCAL(boolean)
first_marker(j_decompress_ptr cinfo)935 first_marker(j_decompress_ptr cinfo)
936 /* Like next_marker, but used to obtain the initial SOI marker. */
937 /* For this marker, we do not allow preceding garbage or fill; otherwise,
938  * we might well scan an entire input file before realizing it ain't JPEG.
939  * If an application wants to process non-JFIF files, it must seek to the
940  * SOI before calling the JPEG library.
941  */
942 {
943   int c, c2;
944   INPUT_VARS(cinfo);
945 
946   INPUT_BYTE(cinfo, c, return FALSE);
947   INPUT_BYTE(cinfo, c2, return FALSE);
948   if (c != 0xFF || c2 != (int)M_SOI)
949     ERREXIT2(cinfo, JERR_NO_SOI, c, c2);
950 
951   cinfo->unread_marker = c2;
952 
953   INPUT_SYNC(cinfo);
954   return TRUE;
955 }
956 
957 
958 /*
959  * Read markers until SOS or EOI.
960  *
961  * Returns same codes as are defined for jpeg_consume_input:
962  * JPEG_SUSPENDED, JPEG_REACHED_SOS, or JPEG_REACHED_EOI.
963  */
964 
965 METHODDEF(int)
read_markers(j_decompress_ptr cinfo)966 read_markers(j_decompress_ptr cinfo)
967 {
968   /* Outer loop repeats once for each marker. */
969   for (;;) {
970     /* Collect the marker proper, unless we already did. */
971     /* NB: first_marker() enforces the requirement that SOI appear first. */
972     if (cinfo->unread_marker == 0) {
973       if (!cinfo->marker->saw_SOI) {
974         if (!first_marker(cinfo))
975           return JPEG_SUSPENDED;
976       } else {
977         if (!next_marker(cinfo))
978           return JPEG_SUSPENDED;
979       }
980     }
981     /* At this point cinfo->unread_marker contains the marker code and the
982      * input point is just past the marker proper, but before any parameters.
983      * A suspension will cause us to return with this state still true.
984      */
985     switch (cinfo->unread_marker) {
986     case M_SOI:
987       if (!get_soi(cinfo))
988         return JPEG_SUSPENDED;
989       break;
990 
991     case M_SOF0:                /* Baseline */
992     case M_SOF1:                /* Extended sequential, Huffman */
993       if (!get_sof(cinfo, FALSE, FALSE))
994         return JPEG_SUSPENDED;
995       break;
996 
997     case M_SOF2:                /* Progressive, Huffman */
998       if (!get_sof(cinfo, TRUE, FALSE))
999         return JPEG_SUSPENDED;
1000       break;
1001 
1002     case M_SOF9:                /* Extended sequential, arithmetic */
1003       if (!get_sof(cinfo, FALSE, TRUE))
1004         return JPEG_SUSPENDED;
1005       break;
1006 
1007     case M_SOF10:               /* Progressive, arithmetic */
1008       if (!get_sof(cinfo, TRUE, TRUE))
1009         return JPEG_SUSPENDED;
1010       break;
1011 
1012     /* Currently unsupported SOFn types */
1013     case M_SOF3:                /* Lossless, Huffman */
1014     case M_SOF5:                /* Differential sequential, Huffman */
1015     case M_SOF6:                /* Differential progressive, Huffman */
1016     case M_SOF7:                /* Differential lossless, Huffman */
1017     case M_JPG:                 /* Reserved for JPEG extensions */
1018     case M_SOF11:               /* Lossless, arithmetic */
1019     case M_SOF13:               /* Differential sequential, arithmetic */
1020     case M_SOF14:               /* Differential progressive, arithmetic */
1021     case M_SOF15:               /* Differential lossless, arithmetic */
1022       ERREXIT1(cinfo, JERR_SOF_UNSUPPORTED, cinfo->unread_marker);
1023       break;
1024 
1025     case M_SOS:
1026       if (!get_sos(cinfo))
1027         return JPEG_SUSPENDED;
1028       cinfo->unread_marker = 0; /* processed the marker */
1029       return JPEG_REACHED_SOS;
1030 
1031     case M_EOI:
1032       TRACEMS(cinfo, 1, JTRC_EOI);
1033       cinfo->unread_marker = 0; /* processed the marker */
1034       return JPEG_REACHED_EOI;
1035 
1036     case M_DAC:
1037       if (!get_dac(cinfo))
1038         return JPEG_SUSPENDED;
1039       break;
1040 
1041     case M_DHT:
1042       if (!get_dht(cinfo))
1043         return JPEG_SUSPENDED;
1044       break;
1045 
1046     case M_DQT:
1047       if (!get_dqt(cinfo))
1048         return JPEG_SUSPENDED;
1049       break;
1050 
1051     case M_DRI:
1052       if (!get_dri(cinfo))
1053         return JPEG_SUSPENDED;
1054       break;
1055 
1056     case M_APP0:
1057     case M_APP1:
1058     case M_APP2:
1059     case M_APP3:
1060     case M_APP4:
1061     case M_APP5:
1062     case M_APP6:
1063     case M_APP7:
1064     case M_APP8:
1065     case M_APP9:
1066     case M_APP10:
1067     case M_APP11:
1068     case M_APP12:
1069     case M_APP13:
1070     case M_APP14:
1071     case M_APP15:
1072       if (!(*((my_marker_ptr)cinfo->marker)->process_APPn[
1073                cinfo->unread_marker - (int)M_APP0]) (cinfo))
1074         return JPEG_SUSPENDED;
1075       break;
1076 
1077     case M_COM:
1078       if (!(*((my_marker_ptr)cinfo->marker)->process_COM) (cinfo))
1079         return JPEG_SUSPENDED;
1080       break;
1081 
1082     case M_RST0:                /* these are all parameterless */
1083     case M_RST1:
1084     case M_RST2:
1085     case M_RST3:
1086     case M_RST4:
1087     case M_RST5:
1088     case M_RST6:
1089     case M_RST7:
1090     case M_TEM:
1091       TRACEMS1(cinfo, 1, JTRC_PARMLESS_MARKER, cinfo->unread_marker);
1092       break;
1093 
1094     case M_DNL:                 /* Ignore DNL ... perhaps the wrong thing */
1095       if (!skip_variable(cinfo))
1096         return JPEG_SUSPENDED;
1097       break;
1098 
1099     default:                    /* must be DHP, EXP, JPGn, or RESn */
1100       /* For now, we treat the reserved markers as fatal errors since they are
1101        * likely to be used to signal incompatible JPEG Part 3 extensions.
1102        * Once the JPEG 3 version-number marker is well defined, this code
1103        * ought to change!
1104        */
1105       ERREXIT1(cinfo, JERR_UNKNOWN_MARKER, cinfo->unread_marker);
1106       break;
1107     }
1108     /* Successfully processed marker, so reset state variable */
1109     cinfo->unread_marker = 0;
1110   } /* end loop */
1111 }
1112 
1113 
1114 /*
1115  * Read a restart marker, which is expected to appear next in the datastream;
1116  * if the marker is not there, take appropriate recovery action.
1117  * Returns FALSE if suspension is required.
1118  *
1119  * This is called by the entropy decoder after it has read an appropriate
1120  * number of MCUs.  cinfo->unread_marker may be nonzero if the entropy decoder
1121  * has already read a marker from the data source.  Under normal conditions
1122  * cinfo->unread_marker will be reset to 0 before returning; if not reset,
1123  * it holds a marker which the decoder will be unable to read past.
1124  */
1125 
1126 METHODDEF(boolean)
read_restart_marker(j_decompress_ptr cinfo)1127 read_restart_marker(j_decompress_ptr cinfo)
1128 {
1129   /* Obtain a marker unless we already did. */
1130   /* Note that next_marker will complain if it skips any data. */
1131   if (cinfo->unread_marker == 0) {
1132     if (!next_marker(cinfo))
1133       return FALSE;
1134   }
1135 
1136   if (cinfo->unread_marker ==
1137       ((int)M_RST0 + cinfo->marker->next_restart_num)) {
1138     /* Normal case --- swallow the marker and let entropy decoder continue */
1139     TRACEMS1(cinfo, 3, JTRC_RST, cinfo->marker->next_restart_num);
1140     cinfo->unread_marker = 0;
1141   } else {
1142     /* Uh-oh, the restart markers have been messed up. */
1143     /* Let the data source manager determine how to resync. */
1144     if (!(*cinfo->src->resync_to_restart) (cinfo,
1145                                            cinfo->marker->next_restart_num))
1146       return FALSE;
1147   }
1148 
1149   /* Update next-restart state */
1150   cinfo->marker->next_restart_num = (cinfo->marker->next_restart_num + 1) & 7;
1151 
1152   return TRUE;
1153 }
1154 
1155 
1156 /*
1157  * This is the default resync_to_restart method for data source managers
1158  * to use if they don't have any better approach.  Some data source managers
1159  * may be able to back up, or may have additional knowledge about the data
1160  * which permits a more intelligent recovery strategy; such managers would
1161  * presumably supply their own resync method.
1162  *
1163  * read_restart_marker calls resync_to_restart if it finds a marker other than
1164  * the restart marker it was expecting.  (This code is *not* used unless
1165  * a nonzero restart interval has been declared.)  cinfo->unread_marker is
1166  * the marker code actually found (might be anything, except 0 or FF).
1167  * The desired restart marker number (0..7) is passed as a parameter.
1168  * This routine is supposed to apply whatever error recovery strategy seems
1169  * appropriate in order to position the input stream to the next data segment.
1170  * Note that cinfo->unread_marker is treated as a marker appearing before
1171  * the current data-source input point; usually it should be reset to zero
1172  * before returning.
1173  * Returns FALSE if suspension is required.
1174  *
1175  * This implementation is substantially constrained by wanting to treat the
1176  * input as a data stream; this means we can't back up.  Therefore, we have
1177  * only the following actions to work with:
1178  *   1. Simply discard the marker and let the entropy decoder resume at next
1179  *      byte of file.
1180  *   2. Read forward until we find another marker, discarding intervening
1181  *      data.  (In theory we could look ahead within the current bufferload,
1182  *      without having to discard data if we don't find the desired marker.
1183  *      This idea is not implemented here, in part because it makes behavior
1184  *      dependent on buffer size and chance buffer-boundary positions.)
1185  *   3. Leave the marker unread (by failing to zero cinfo->unread_marker).
1186  *      This will cause the entropy decoder to process an empty data segment,
1187  *      inserting dummy zeroes, and then we will reprocess the marker.
1188  *
1189  * #2 is appropriate if we think the desired marker lies ahead, while #3 is
1190  * appropriate if the found marker is a future restart marker (indicating
1191  * that we have missed the desired restart marker, probably because it got
1192  * corrupted).
1193  * We apply #2 or #3 if the found marker is a restart marker no more than
1194  * two counts behind or ahead of the expected one.  We also apply #2 if the
1195  * found marker is not a legal JPEG marker code (it's certainly bogus data).
1196  * If the found marker is a restart marker more than 2 counts away, we do #1
1197  * (too much risk that the marker is erroneous; with luck we will be able to
1198  * resync at some future point).
1199  * For any valid non-restart JPEG marker, we apply #3.  This keeps us from
1200  * overrunning the end of a scan.  An implementation limited to single-scan
1201  * files might find it better to apply #2 for markers other than EOI, since
1202  * any other marker would have to be bogus data in that case.
1203  */
1204 
1205 GLOBAL(boolean)
jpeg_resync_to_restart(j_decompress_ptr cinfo,int desired)1206 jpeg_resync_to_restart(j_decompress_ptr cinfo, int desired)
1207 {
1208   int marker = cinfo->unread_marker;
1209   int action = 1;
1210 
1211   /* Always put up a warning. */
1212   WARNMS2(cinfo, JWRN_MUST_RESYNC, marker, desired);
1213 
1214   /* Outer loop handles repeated decision after scanning forward. */
1215   for (;;) {
1216     if (marker < (int)M_SOF0)
1217       action = 2;               /* invalid marker */
1218     else if (marker < (int)M_RST0 || marker > (int)M_RST7)
1219       action = 3;               /* valid non-restart marker */
1220     else {
1221       if (marker == ((int)M_RST0 + ((desired + 1) & 7)) ||
1222           marker == ((int)M_RST0 + ((desired + 2) & 7)))
1223         action = 3;             /* one of the next two expected restarts */
1224       else if (marker == ((int)M_RST0 + ((desired - 1) & 7)) ||
1225                marker == ((int)M_RST0 + ((desired - 2) & 7)))
1226         action = 2;             /* a prior restart, so advance */
1227       else
1228         action = 1;             /* desired restart or too far away */
1229     }
1230     TRACEMS2(cinfo, 4, JTRC_RECOVERY_ACTION, marker, action);
1231     switch (action) {
1232     case 1:
1233       /* Discard marker and let entropy decoder resume processing. */
1234       cinfo->unread_marker = 0;
1235       return TRUE;
1236     case 2:
1237       /* Scan to the next marker, and repeat the decision loop. */
1238       if (!next_marker(cinfo))
1239         return FALSE;
1240       marker = cinfo->unread_marker;
1241       break;
1242     case 3:
1243       /* Return without advancing past this marker. */
1244       /* Entropy decoder will be forced to process an empty segment. */
1245       return TRUE;
1246     }
1247   } /* end loop */
1248 }
1249 
1250 
1251 /*
1252  * Reset marker processing state to begin a fresh datastream.
1253  */
1254 
1255 METHODDEF(void)
reset_marker_reader(j_decompress_ptr cinfo)1256 reset_marker_reader(j_decompress_ptr cinfo)
1257 {
1258   my_marker_ptr marker = (my_marker_ptr)cinfo->marker;
1259 
1260   cinfo->comp_info = NULL;              /* until allocated by get_sof */
1261   cinfo->input_scan_number = 0;         /* no SOS seen yet */
1262   cinfo->unread_marker = 0;             /* no pending marker */
1263   marker->pub.saw_SOI = FALSE;          /* set internal state too */
1264   marker->pub.saw_SOF = FALSE;
1265   marker->pub.discarded_bytes = 0;
1266   marker->cur_marker = NULL;
1267 }
1268 
1269 
1270 /*
1271  * Initialize the marker reader module.
1272  * This is called only once, when the decompression object is created.
1273  */
1274 
1275 GLOBAL(void)
jinit_marker_reader(j_decompress_ptr cinfo)1276 jinit_marker_reader(j_decompress_ptr cinfo)
1277 {
1278   my_marker_ptr marker;
1279   int i;
1280 
1281   /* Create subobject in permanent pool */
1282   marker = (my_marker_ptr)
1283     (*cinfo->mem->alloc_small) ((j_common_ptr)cinfo, JPOOL_PERMANENT,
1284                                 sizeof(my_marker_reader));
1285   cinfo->marker = (struct jpeg_marker_reader *)marker;
1286   /* Initialize public method pointers */
1287   marker->pub.reset_marker_reader = reset_marker_reader;
1288   marker->pub.read_markers = read_markers;
1289   marker->pub.read_restart_marker = read_restart_marker;
1290   /* Initialize COM/APPn processing.
1291    * By default, we examine and then discard APP0 and APP14,
1292    * but simply discard COM and all other APPn.
1293    */
1294   marker->process_COM = skip_variable;
1295   marker->length_limit_COM = 0;
1296   for (i = 0; i < 16; i++) {
1297     marker->process_APPn[i] = skip_variable;
1298     marker->length_limit_APPn[i] = 0;
1299   }
1300   marker->process_APPn[0] = get_interesting_appn;
1301   marker->process_APPn[14] = get_interesting_appn;
1302   /* Reset marker processing state */
1303   reset_marker_reader(cinfo);
1304 }
1305 
1306 
1307 /*
1308  * Control saving of COM and APPn markers into marker_list.
1309  */
1310 
1311 #ifdef SAVE_MARKERS_SUPPORTED
1312 
1313 GLOBAL(void)
jpeg_save_markers(j_decompress_ptr cinfo,int marker_code,unsigned int length_limit)1314 jpeg_save_markers(j_decompress_ptr cinfo, int marker_code,
1315                   unsigned int length_limit)
1316 {
1317   my_marker_ptr marker = (my_marker_ptr)cinfo->marker;
1318   long maxlength;
1319   jpeg_marker_parser_method processor;
1320 
1321   /* Length limit mustn't be larger than what we can allocate
1322    * (should only be a concern in a 16-bit environment).
1323    */
1324   maxlength = cinfo->mem->max_alloc_chunk - sizeof(struct jpeg_marker_struct);
1325   if (((long)length_limit) > maxlength)
1326     length_limit = (unsigned int)maxlength;
1327 
1328   /* Choose processor routine to use.
1329    * APP0/APP14 have special requirements.
1330    */
1331   if (length_limit) {
1332     processor = save_marker;
1333     /* If saving APP0/APP14, save at least enough for our internal use. */
1334     if (marker_code == (int)M_APP0 && length_limit < APP0_DATA_LEN)
1335       length_limit = APP0_DATA_LEN;
1336     else if (marker_code == (int)M_APP14 && length_limit < APP14_DATA_LEN)
1337       length_limit = APP14_DATA_LEN;
1338   } else {
1339     processor = skip_variable;
1340     /* If discarding APP0/APP14, use our regular on-the-fly processor. */
1341     if (marker_code == (int)M_APP0 || marker_code == (int)M_APP14)
1342       processor = get_interesting_appn;
1343   }
1344 
1345   if (marker_code == (int)M_COM) {
1346     marker->process_COM = processor;
1347     marker->length_limit_COM = length_limit;
1348   } else if (marker_code >= (int)M_APP0 && marker_code <= (int)M_APP15) {
1349     marker->process_APPn[marker_code - (int)M_APP0] = processor;
1350     marker->length_limit_APPn[marker_code - (int)M_APP0] = length_limit;
1351   } else
1352     ERREXIT1(cinfo, JERR_UNKNOWN_MARKER, marker_code);
1353 }
1354 
1355 #endif /* SAVE_MARKERS_SUPPORTED */
1356 
1357 
1358 /*
1359  * Install a special processing method for COM or APPn markers.
1360  */
1361 
1362 GLOBAL(void)
jpeg_set_marker_processor(j_decompress_ptr cinfo,int marker_code,jpeg_marker_parser_method routine)1363 jpeg_set_marker_processor(j_decompress_ptr cinfo, int marker_code,
1364                           jpeg_marker_parser_method routine)
1365 {
1366   my_marker_ptr marker = (my_marker_ptr)cinfo->marker;
1367 
1368   if (marker_code == (int)M_COM)
1369     marker->process_COM = routine;
1370   else if (marker_code >= (int)M_APP0 && marker_code <= (int)M_APP15)
1371     marker->process_APPn[marker_code - (int)M_APP0] = routine;
1372   else
1373     ERREXIT1(cinfo, JERR_UNKNOWN_MARKER, marker_code);
1374 }
1375