Copilot commented on code in PR #3266:
URL: https://github.com/apache/tika/pull/3266#discussion_r4176768720
##########
tika-core/src/main/resources/org/apache/tika/mime/tika-mimetypes.xml:
##########
@@ -6900,6 +6900,19 @@
<glob pattern="*.ico"/>
</mime-type>
+ <mime-type type="image/x-win-bitmap">
+ <acronym>CUR</acronym>
+ <_comment>Windows Cursor</_comment>
+ <tika:link>https://en.wikipedia.org/wiki/ICO_(file_format)</tika:link>
+ <magic priority="50">
+ <!-- reserved 0, type 2, count below 256 -->
+ <match value="\000\000\002\000" type="string" offset="0">
+ <match value="\000" type="string" offset="5"/>
+ </match>
+ </magic>
Review Comment:
The CUR directory's image count is a 16-bit field, but this nested match
requires its high byte to be zero, so valid cursors with 256 or more images
will not be detected by content and will fall back to a generic type.
`ICOParser` already reads the full unsigned count, and the documented magic is
just `00 00 02 00`; remove this extra count restriction.
##########
tika-parsers/tika-parsers-standard/tika-parsers-standard-modules/tika-parser-image-module/src/main/java/org/apache/tika/parser/image/ICOParser.java:
##########
@@ -0,0 +1,329 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements. See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.apache.tika.parser.image;
+
+import java.io.IOException;
+import java.util.Locale;
+import java.util.Set;
+
+import org.apache.commons.io.IOUtils;
+import org.xml.sax.ContentHandler;
+import org.xml.sax.SAXException;
+
+import org.apache.tika.annotation.TikaComponent;
+import org.apache.tika.exception.TikaException;
+import org.apache.tika.extractor.EmbeddedDocumentUtil;
+import org.apache.tika.io.BoundedInputStream;
+import org.apache.tika.io.EndianUtils;
+import org.apache.tika.io.TikaInputStream;
+import org.apache.tika.metadata.HttpHeaders;
+import org.apache.tika.metadata.Icon;
+import org.apache.tika.metadata.Metadata;
+import org.apache.tika.metadata.TIFF;
+import org.apache.tika.mime.MediaType;
+import org.apache.tika.parser.ParseContext;
+import org.apache.tika.parser.Parser;
+import org.apache.tika.sax.XHTMLContentHandler;
+
+/**
+ * Parser for Windows icon (ICO) and cursor (CUR) files. Reads the ICONDIR
+ * and the header of every image to report the dimensions and colour depth of
+ * the largest image, the list of all images and, for cursors, the hotspot.
+ * The images themselves are not decoded.
+ * <p>
+ * The directory's own width, height and colour fields are unreliable (256 px
+ * is stored as 0, many tools leave the bit count empty), so the values come
+ * from each image's PNG IHDR or BITMAPINFOHEADER and the directory is only
+ * the fallback. Colour depth is reported the TIFF way, bits per sample and
+ * samples per pixel; the per-image list carries the total bits per pixel.
+ * <p>
+ * OS/2 bitmap arrays are detected as the same type. They pass through
+ * without metadata.
+ */
+@TikaComponent
+public class ICOParser implements Parser {
+
+ private static final long serialVersionUID = 4212837190215395123L;
+
+ static final MediaType ICO_TYPE = MediaType.image("vnd.microsoft.icon");
+ static final MediaType ICO_ALIAS = MediaType.image("x-icon");
+ static final MediaType CUR_TYPE = MediaType.image("x-win-bitmap");
+
+ private static final Set<MediaType> SUPPORTED_TYPES = Set.of(ICO_TYPE,
ICO_ALIAS, CUR_TYPE);
+
+ private static final int TYPE_ICON = 1;
+ private static final int TYPE_CURSOR = 2;
+ private static final int COUNT_OFFSET = 4;
+ private static final int HEADER_SIZE = 6;
+ private static final int ENTRY_SIZE = 16;
+ private static final int BITMAP_INFO_HEADER_SIZE = 40;
+ private static final byte[] PNG_SIGNATURE =
+ {(byte) 0x89, 'P', 'N', 'G', '\r', '\n', 0x1a, '\n'};
+ private static final int PNG_IHDR_SIZE = 8 + 8 + 13;
+ // Icons are small; anything bigger is read only this far
+ static final int MAX_FILE_SIZE = 16 * 1024 * 1024;
+ // Far beyond any real icon; a header that claims more is not believed
+ private static final int MAX_DIMENSION = 65535;
+
+ private enum Encoding {
+ PNG, BMP, UNKNOWN
+ }
+
+ @Override
+ public Set<MediaType> getSupportedTypes(ParseContext context) {
+ return SUPPORTED_TYPES;
+ }
+
+ @Override
+ public void parse(TikaInputStream tis, ContentHandler handler, Metadata
metadata,
+ ParseContext context) throws IOException, SAXException,
TikaException {
+ byte[] file = IOUtils.toByteArray(new
BoundedInputStream(MAX_FILE_SIZE, tis));
+ if (isOs2BitmapArray(file)) {
+ metadata.set(HttpHeaders.CONTENT_TYPE, ICO_TYPE.toString());
+ } else {
+ extractMetadata(file, metadata, context);
+ }
+
+ XHTMLContentHandler xhtml = new XHTMLContentHandler(handler, metadata,
context);
+ xhtml.startDocument();
+ xhtml.endDocument();
+ }
+
+ private static boolean isOs2BitmapArray(byte[] file) {
+ return file.length >= 2 && file[0] == 'B' && file[1] == 'A';
+ }
+
+ private static void extractMetadata(byte[] file, Metadata metadata,
ParseContext context)
+ throws TikaException {
+ if (file.length < COUNT_OFFSET || EndianUtils.getUShortLE(file, 0) !=
0) {
+ throw new TikaException("Not an ICO or CUR file");
+ }
+ int type = EndianUtils.getUShortLE(file, 2);
+ if (type != TYPE_ICON && type != TYPE_CURSOR) {
+ throw new TikaException("Not an ICO or CUR file: type " + type);
+ }
+ boolean cursor = type == TYPE_CURSOR;
+ metadata.set(HttpHeaders.CONTENT_TYPE, (cursor ? CUR_TYPE :
ICO_TYPE).toString());
+ if (file.length < HEADER_SIZE) {
+ warn("The header ends before the image count", metadata, context);
+ return;
+ }
+
+ int count = EndianUtils.getUShortLE(file, COUNT_OFFSET);
+ metadata.set(Icon.IMAGE_COUNT, count);
+ if (count == 0) {
+ warn("The directory lists no images", metadata, context);
+ return;
+ }
+ Image largest = null;
+ int unreadable = 0;
+ for (int i = 0; i < count; i++) {
+ int entryOffset = HEADER_SIZE + i * ENTRY_SIZE;
+ if (entryOffset + ENTRY_SIZE > file.length) {
+ unreadable += count - i;
+ break;
+ }
+ Image image = Image.read(file, entryOffset, cursor);
+ if (image == null) {
+ unreadable++;
+ continue;
+ }
+ if (image.encoding == Encoding.UNKNOWN) {
+ // still listed with what the directory says, but worth a
warning
+ unreadable++;
+ }
+ metadata.add(Icon.IMAGES, image.describe());
+ if (largest == null || image.outranks(largest)) {
+ largest = image;
+ }
+ }
+ if (largest != null) {
+ metadata.set(TIFF.IMAGE_WIDTH, largest.width);
+ metadata.set(TIFF.IMAGE_LENGTH, largest.height);
+ if (largest.bitsPerSample > 0) {
+ metadata.set(TIFF.BITS_PER_SAMPLE,
Integer.toString(largest.bitsPerSample));
+ metadata.set(TIFF.SAMPLES_PER_PIXEL, largest.samplesPerPixel);
+ }
+ if (cursor) {
+ metadata.set(Icon.HOTSPOT_X, largest.hotspotX);
+ metadata.set(Icon.HOTSPOT_Y, largest.hotspotY);
+ }
+ }
+ if (unreadable > 0) {
+ warn(unreadable + " of " + count + " images lie outside the file
or have no" +
+ " readable header", metadata, context);
+ }
+ }
+
+ private static void warn(String message, Metadata metadata, ParseContext
context) {
+ EmbeddedDocumentUtil.recordException(new TikaException(message),
metadata, context);
+ }
+
+ private static boolean startsWithPngSignature(byte[] file, int offset) {
+ for (int i = 0; i < PNG_SIGNATURE.length; i++) {
+ if (file[offset + i] != PNG_SIGNATURE[i]) {
+ return false;
+ }
+ }
+ return true;
+ }
+
+ /**
+ * @return the samples per pixel, or 0 for a colour type PNG does not
define
+ */
+ private static int pngSamplesPerPixel(int colorType) {
+ switch (colorType) {
+ case 0: // greyscale
+ case 3: // palette
+ return 1;
+ case 2: // truecolour
+ return 3;
+ case 4: // greyscale with alpha
+ return 2;
+ case 6: // truecolour with alpha
+ return 4;
+ default:
+ return 0;
+ }
+ }
+
+ private static final class Image {
+ int width;
+ int height;
+ int bitsPerPixel;
+ int bitsPerSample;
+ int samplesPerPixel;
+ int hotspotX;
+ int hotspotY;
+ Encoding encoding = Encoding.UNKNOWN;
+
+ /**
+ * Reads one ICONDIRENTRY and the header of the image it points to.
+ * Without a header that has a usable size, the image keeps the
+ * directory's values and an unknown encoding.
+ *
+ * @return the image, or null if its data lies outside the file
+ */
+ static Image read(byte[] file, int entryOffset, boolean cursor) {
+ Image image = new Image();
+ image.width = directorySize(file[entryOffset]);
+ image.height = directorySize(file[entryOffset + 1]);
+ if (cursor) {
+ // a cursor's directory holds the hotspot where an icon's
holds planes and bit count
+ image.hotspotX = EndianUtils.getUShortLE(file, entryOffset +
4);
+ image.hotspotY = EndianUtils.getUShortLE(file, entryOffset +
6);
+ } else {
+ image.setDepth(EndianUtils.getUShortLE(file, entryOffset + 6));
+ }
+ long size = EndianUtils.getUIntLE(file, entryOffset + 8);
+ long offset = EndianUtils.getUIntLE(file, entryOffset + 12);
+ if (offset < HEADER_SIZE || offset >= file.length) {
+ return null;
+ }
+ int dataOffset = (int) offset;
+ long available = Math.min(size, file.length - offset);
+ if (available >= PNG_IHDR_SIZE && startsWithPngSignature(file,
dataOffset)) {
+ if (image.trySetSize(EndianUtils.getUIntBE(file, dataOffset +
16),
+ EndianUtils.getUIntBE(file, dataOffset + 20))) {
+ image.encoding = Encoding.PNG;
+ image.setPngDepth(file[dataOffset + 24] & 0xff,
file[dataOffset + 25] & 0xff);
+ }
Review Comment:
This treats any payload with a PNG signature and at least 29 bytes as having
a usable IHDR, without checking the first chunk's length or that its type is
`IHDR`. A truncated/malformed entry whose bytes at these offsets happen to form
plausible dimensions will therefore be reported as a valid PNG and will not
contribute to the unreadable warning, contrary to the parser's stated fallback
behavior. Validate the 13-byte IHDR chunk before reading its dimensions.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]