4 limits.c - manages data/functions for limiting the sizes of images read from files.
9 if (!i_set_image_file_limits(max_width, max_height, max_bytes)) {
12 i_get_image_file_limits(&max_width, &max_height, &max_bytes);
14 // file reader implementations
15 if (!i_int_check_image_file_limits(width, height, channels, sizeof(i_sample_t))) {
21 Manage limits for image files read by Imager.
23 Setting a value of zero means that limit will be ignored.
29 static i_img_dim max_width, max_height;
30 static size_t max_bytes = 0x40000000;
33 =item i_set_image_file_limits(width, height, bytes)
36 =synopsis i_set_image_file_limits(500, 500, 1000000);
38 Set limits on the sizes of images read by Imager.
40 Setting a limit to 0 means that limit is ignored.
42 Negative limits result in failure.
50 i_img_dim width, height - maximum width and height.
54 size_t bytes - maximum size in memory in bytes
58 Returns non-zero on success.
64 i_set_image_file_limits(i_img_dim width, i_img_dim height, size_t bytes) {
68 i_push_error(0, "width must be non-negative");
72 i_push_error(0, "height must be non-negative");
76 i_push_error(0, "bytes must be non-negative");
88 =item i_get_image_file_limits(&width, &height, &bytes)
91 =synopsis i_get_image_file_limits(&width, &height, &bytes)
93 Retrieves the file limits set by i_set_image_file_limits().
99 i_img_dim *width, *height - the maximum width and height of the image.
103 size_t *bytes - size in memory of the image in bytes.
111 i_get_image_file_limits(i_img_dim *width, i_img_dim *height, size_t *bytes) {
115 *height = max_height;
122 =item i_int_check_image_file_limits(width, height, channels, sample_size)
125 =synopsis i_i_int_check_image_file_limits(width, height, channels, sizeof(i_sample_t))
127 Checks the size of a file in memory against the configured image file
130 This also range checks the values to those permitted by Imager and
131 checks for overflows in calculating the size.
133 Returns non-zero if the file is within limits.
135 This function is intended to be called by image file read functions.
141 i_int_check_image_file_limits(i_img_dim width, i_img_dim height, int channels, size_t sample_size) {
146 i_push_errorf(0, "file size limit - image width of %" i_DF " is not positive",
150 if (max_width && width > max_width) {
151 i_push_errorf(0, "file size limit - image width of %" i_DF " exceeds limit of %" i_DF,
152 i_DFc(width), i_DFc(max_width));
157 i_push_errorf(0, "file size limit - image height %" i_DF " is not positive",
162 if (max_height && height > max_height) {
163 i_push_errorf(0, "file size limit - image height of %" i_DF
164 " exceeds limit of %" i_DF, i_DFc(height), i_DFc(max_height));
168 if (channels < 1 || channels > MAXCHANNELS) {
169 i_push_errorf(0, "file size limit - channels %d out of range",
174 if (sample_size < 1 || sample_size > sizeof(long double)) {
175 i_push_errorf(0, "file size limit - sample_size %ld out of range",
180 /* This overflow check is a bit more paranoid than usual.
181 We don't protect it under max_bytes since we always want to check
184 bytes = width * height * channels * sample_size;
185 if (bytes / width != height * channels * sample_size
186 || bytes / height != width * channels * sample_size) {
187 i_push_error(0, "file size limit - integer overflow calculating storage");
191 if (bytes > max_bytes) {
192 i_push_errorf(0, "file size limit - storage size of %lu "
193 "exceeds limit of %lu", (unsigned long)bytes,
194 (unsigned long)max_bytes);