1 /* Copyright © 2013 Canonical Limited
3 * This library is free software; you can redistribute it and/or
4 * modify it under the terms of the GNU Lesser General Public
5 * License as published by the Free Software Foundation; either
6 * version 2 of the License, or (at your option) any later version.
8 * This library is distributed in the hope that it will be useful,
9 * but WITHOUT ANY WARRANTY; without even the implied warranty of
10 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
11 * Lesser General Public License for more details.
13 * You should have received a copy of the GNU Lesser General
14 * Public License along with this library; if not, write to the
15 * Free Software Foundation, Inc., 59 Temple Place, Suite 330,
16 * Boston, MA 02111-1307, USA.
18 * Author: Ryan Lortie <desrt@desrt.ca>
23 #include "thumbnail-verify.h"
27 /* Begin code to check the validity of thumbnail files. In order to do
28 * that we need to parse enough PNG in order to get the Thumb::URI,
29 * Thumb::MTime and Thumb::Size tags out of the file. Fortunately this
39 /* We *require* matches on URI and MTime, but the Size field is optional
42 * http://specifications.freedesktop.org/thumbnail-spec/thumbnail-spec-latest.html
44 #define MATCHED_URI (1u << 0)
45 #define MATCHED_MTIME (1u << 1)
46 #define MATCHED_ALL (MATCHED_URI | MATCHED_MTIME)
49 check_integer_match (guint64 expected
,
53 /* Would be nice to g_ascii_strtoll here, but we don't have a variant
54 * that works on strings that are not nul-terminated.
56 * It's easy enough to do it ourselves...
58 if (expected
== 0) /* special case: "0" */
59 return value_size
== 1 && value
[0] == '0';
61 /* Check each digit, as long as we have data from both */
62 while (expected
&& value_size
)
64 /* Check the low-order digit */
65 if (value
[value_size
- 1] != (gchar
) ((expected
% 10) + '0'))
73 /* Make sure nothing is left over, on either side */
74 return !expected
&& !value_size
;
78 check_png_info_chunk (ExpectedInfo
*expected_info
,
83 guint
*required_matches
)
85 if (key_size
== 10 && memcmp (key
, "Thumb::URI", 10) == 0)
89 expected_size
= strlen (expected_info
->uri
);
91 if (expected_size
!= value_size
)
94 if (memcmp (expected_info
->uri
, value
, value_size
) != 0)
97 *required_matches
|= MATCHED_URI
;
100 else if (key_size
== 12 && memcmp (key
, "Thumb::MTime", 12) == 0)
102 if (!check_integer_match (expected_info
->mtime
, value
, value_size
))
105 *required_matches
|= MATCHED_MTIME
;
108 else if (key_size
== 11 && memcmp (key
, "Thumb::Size", 11) == 0)
110 /* A match on Thumb::Size is not required for success, but if we
111 * find this optional field and it's wrong, we should reject the
114 if (!check_integer_match (expected_info
->size
, value
, value_size
))
122 check_thumbnail_validity (ExpectedInfo
*expected_info
,
123 const gchar
*contents
,
126 guint required_matches
= 0;
128 /* Reference: http://www.w3.org/TR/PNG/ */
132 if (memcmp (contents
, "\x89PNG\r\n\x1a\n", 8) != 0)
135 contents
+= 8, size
-= 8;
137 /* We need at least 12 bytes to have a chunk... */
140 guint32 chunk_size_be
;
143 /* PNG is not an aligned file format so we have to be careful
144 * about reading integers...
146 memcpy (&chunk_size_be
, contents
, 4);
147 chunk_size
= GUINT32_FROM_BE (chunk_size_be
);
149 contents
+= 4, size
-= 4;
151 /* After consuming the size field, we need to have enough bytes
152 * for 4 bytes type field, chunk_size bytes for data, then 4 byte
153 * for CRC (which we ignore)
155 * We just read chunk_size from the file, so it may be very large.
156 * Make sure it won't wrap when we add 8 to it.
158 if (G_MAXUINT32
- chunk_size
< 8 || size
< chunk_size
+ 8)
161 /* We are only interested in tEXt fields */
162 if (memcmp (contents
, "tEXt", 4) == 0)
164 const gchar
*key
= contents
+ 4;
167 /* We need to find the nul separator character that splits the
168 * key/value. The value is not terminated.
170 * If we find no nul then we just ignore the field.
172 * value may contain extra nuls, but check_png_info_chunk()
175 for (key_size
= 0; key_size
< chunk_size
; key_size
++)
177 if (key
[key_size
] == '\0')
182 /* Since key_size < chunk_size, value_size is
183 * definitely non-negative.
185 value_size
= chunk_size
- key_size
- 1;
186 value
= key
+ key_size
+ 1;
188 /* We found the separator character. */
189 if (!check_png_info_chunk (expected_info
,
199 /* A bit of a hack: assume that all tEXt chunks will appear
200 * together. Therefore, if we have already seen both required
201 * fields and then see a non-tEXt chunk then we can assume we
204 * The common case is that the tEXt chunks come at the start
205 * of the file before any of the image data. This trick means
206 * that we will only fault in a single page (4k) whereas many
207 * thumbnails (particularly the large ones) can approach 100k
210 if (required_matches
== MATCHED_ALL
)
214 /* skip to the next chunk, ignoring CRC. */
215 contents
+= 4, size
-= 4; /* type field */
216 contents
+= chunk_size
, size
-= chunk_size
; /* data */
217 contents
+= 4, size
-= 4; /* CRC */
221 return required_matches
== MATCHED_ALL
;
225 thumbnail_verify (const char *thumbnail_path
,
226 const gchar
*file_uri
,
227 const GStatBuf
*file_stat_buf
)
229 gboolean thumbnail_is_valid
= FALSE
;
230 ExpectedInfo expected_info
;
233 if (file_stat_buf
== NULL
)
236 expected_info
.uri
= file_uri
;
237 expected_info
.mtime
= file_stat_buf
->st_mtime
;
238 expected_info
.size
= file_stat_buf
->st_size
;
240 file
= g_mapped_file_new (thumbnail_path
, FALSE
, NULL
);
243 thumbnail_is_valid
= check_thumbnail_validity (&expected_info
,
244 g_mapped_file_get_contents (file
),
245 g_mapped_file_get_length (file
));
246 g_mapped_file_unref (file
);
249 return thumbnail_is_valid
;