Add some bounds checking to CLLC; reduce HQX variable scoping, add an error message.tags/n2.7
| @@ -156,7 +156,7 @@ OBJS-$(CONFIG_CDXL_DECODER) += cdxl.o | |||||
| OBJS-$(CONFIG_CINEPAK_DECODER) += cinepak.o | OBJS-$(CONFIG_CINEPAK_DECODER) += cinepak.o | ||||
| OBJS-$(CONFIG_CLJR_DECODER) += cljrdec.o | OBJS-$(CONFIG_CLJR_DECODER) += cljrdec.o | ||||
| OBJS-$(CONFIG_CLJR_ENCODER) += cljrenc.o | OBJS-$(CONFIG_CLJR_ENCODER) += cljrenc.o | ||||
| OBJS-$(CONFIG_CLLC_DECODER) += cllc.o | |||||
| OBJS-$(CONFIG_CLLC_DECODER) += cllc.o canopus.o | |||||
| OBJS-$(CONFIG_COOK_DECODER) += cook.o | OBJS-$(CONFIG_COOK_DECODER) += cook.o | ||||
| OBJS-$(CONFIG_COMFORTNOISE_DECODER) += cngdec.o celp_filters.o | OBJS-$(CONFIG_COMFORTNOISE_DECODER) += cngdec.o celp_filters.o | ||||
| OBJS-$(CONFIG_COMFORTNOISE_ENCODER) += cngenc.o | OBJS-$(CONFIG_COMFORTNOISE_ENCODER) += cngenc.o | ||||
| @@ -232,7 +232,7 @@ OBJS-$(CONFIG_HEVC_DECODER) += hevc.o hevc_mvs.o hevc_ps.o hevc_sei.o | |||||
| hevc_cabac.o hevc_refs.o hevcpred.o \ | hevc_cabac.o hevc_refs.o hevcpred.o \ | ||||
| hevcdsp.o hevc_filter.o | hevcdsp.o hevc_filter.o | ||||
| OBJS-$(CONFIG_HNM4_VIDEO_DECODER) += hnm4video.o | OBJS-$(CONFIG_HNM4_VIDEO_DECODER) += hnm4video.o | ||||
| OBJS-$(CONFIG_HQX_DECODER) += hqx.o hqxvlc.o hqxdsp.o | |||||
| OBJS-$(CONFIG_HQX_DECODER) += hqx.o hqxvlc.o hqxdsp.o canopus.o | |||||
| OBJS-$(CONFIG_HUFFYUV_DECODER) += huffyuv.o huffyuvdec.o | OBJS-$(CONFIG_HUFFYUV_DECODER) += huffyuv.o huffyuvdec.o | ||||
| OBJS-$(CONFIG_HUFFYUV_ENCODER) += huffyuv.o huffyuvenc.o | OBJS-$(CONFIG_HUFFYUV_ENCODER) += huffyuv.o huffyuvenc.o | ||||
| OBJS-$(CONFIG_IDCIN_DECODER) += idcinvideo.o | OBJS-$(CONFIG_IDCIN_DECODER) += idcinvideo.o | ||||
| @@ -0,0 +1,63 @@ | |||||
| /* | |||||
| * Canopus common routines | |||||
| * Copyright (c) 2015 Vittorio Giovara <vittorio.giovara@gmail.com> | |||||
| * | |||||
| * This file is part of Libav. | |||||
| * | |||||
| * Libav is free software; you can redistribute it and/or | |||||
| * modify it under the terms of the GNU Lesser General Public | |||||
| * License as published by the Free Software Foundation; either | |||||
| * version 2.1 of the License, or (at your option) any later version. | |||||
| * | |||||
| * Libav is distributed in the hope that it will be useful, | |||||
| * but WITHOUT ANY WARRANTY; without even the implied warranty of | |||||
| * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU | |||||
| * Lesser General Public License for more details. | |||||
| * | |||||
| * You should have received a copy of the GNU Lesser General Public | |||||
| * License along with Libav; if not, write to the Free Software | |||||
| * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA | |||||
| */ | |||||
| #include <stdint.h> | |||||
| #include "libavutil/rational.h" | |||||
| #include "avcodec.h" | |||||
| #include "bytestream.h" | |||||
| #include "canopus.h" | |||||
| int ff_canopus_parse_info_tag(AVCodecContext *avctx, | |||||
| const uint8_t *src, size_t size) | |||||
| { | |||||
| GetByteContext gbc; | |||||
| int par_x, par_y, field_order; | |||||
| bytestream2_init(&gbc, src, size); | |||||
| /* Parse aspect ratio. */ | |||||
| bytestream2_skip(&gbc, 8); // unknown, 16 bits 1 | |||||
| par_x = bytestream2_get_le32(&gbc); | |||||
| par_y = bytestream2_get_le32(&gbc); | |||||
| if (par_x && par_y) | |||||
| av_reduce(&avctx->sample_aspect_ratio.num, | |||||
| &avctx->sample_aspect_ratio.den, | |||||
| par_x, par_y, 255); | |||||
| /* Short INFO tag (used in CLLC) has only AR data. */ | |||||
| if (size == 0x18) | |||||
| return 0; | |||||
| bytestream2_skip(&gbc, 16); // unknown RDRT tag | |||||
| /* Parse FIEL tag. */ | |||||
| bytestream2_skip(&gbc, 8); // 'FIEL' and 4 bytes 0 | |||||
| field_order = bytestream2_get_le32(&gbc); | |||||
| switch (field_order) { | |||||
| case 0: avctx->field_order = AV_FIELD_TT; break; | |||||
| case 1: avctx->field_order = AV_FIELD_BB; break; | |||||
| case 2: avctx->field_order = AV_FIELD_PROGRESSIVE; break; | |||||
| } | |||||
| return 0; | |||||
| } | |||||
| @@ -0,0 +1,32 @@ | |||||
| /* | |||||
| * Canopus common routines | |||||
| * Copyright (c) 2015 Vittorio Giovara <vittorio.giovara@gmail.com> | |||||
| * | |||||
| * This file is part of Libav. | |||||
| * | |||||
| * Libav is free software; you can redistribute it and/or | |||||
| * modify it under the terms of the GNU Lesser General Public | |||||
| * License as published by the Free Software Foundation; either | |||||
| * version 2.1 of the License, or (at your option) any later version. | |||||
| * | |||||
| * Libav is distributed in the hope that it will be useful, | |||||
| * but WITHOUT ANY WARRANTY; without even the implied warranty of | |||||
| * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU | |||||
| * Lesser General Public License for more details. | |||||
| * | |||||
| * You should have received a copy of the GNU Lesser General Public | |||||
| * License along with Libav; if not, write to the Free Software | |||||
| * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA | |||||
| */ | |||||
| #ifndef AVCODEC_CANOPUS_H | |||||
| #define AVCODEC_CANOPUS_H | |||||
| #include <stdint.h> | |||||
| #include "avcodec.h" | |||||
| int ff_canopus_parse_info_tag(AVCodecContext *avctx, | |||||
| const uint8_t *src, size_t size); | |||||
| #endif /* AVCODEC_CANOPUS_H */ | |||||
| @@ -24,6 +24,7 @@ | |||||
| #include "libavutil/intreadwrite.h" | #include "libavutil/intreadwrite.h" | ||||
| #include "bswapdsp.h" | #include "bswapdsp.h" | ||||
| #include "canopus.h" | |||||
| #include "get_bits.h" | #include "get_bits.h" | ||||
| #include "avcodec.h" | #include "avcodec.h" | ||||
| #include "internal.h" | #include "internal.h" | ||||
| @@ -362,7 +363,11 @@ static int cllc_decode_frame(AVCodecContext *avctx, void *data, | |||||
| GetBitContext gb; | GetBitContext gb; | ||||
| int coding_type, ret; | int coding_type, ret; | ||||
| /* Skip the INFO header if present */ | |||||
| if (avpkt->size < 4 + 4) { | |||||
| av_log(avctx, AV_LOG_ERROR, "Frame is too small %d.\n", avpkt->size); | |||||
| return AVERROR_INVALIDDATA; | |||||
| } | |||||
| info_offset = 0; | info_offset = 0; | ||||
| info_tag = AV_RL32(src); | info_tag = AV_RL32(src); | ||||
| if (info_tag == MKTAG('I', 'N', 'F', 'O')) { | if (info_tag == MKTAG('I', 'N', 'F', 'O')) { | ||||
| @@ -373,11 +378,10 @@ static int cllc_decode_frame(AVCodecContext *avctx, void *data, | |||||
| info_offset); | info_offset); | ||||
| return AVERROR_INVALIDDATA; | return AVERROR_INVALIDDATA; | ||||
| } | } | ||||
| ff_canopus_parse_info_tag(avctx, src + 8, info_offset); | |||||
| info_offset += 8; | info_offset += 8; | ||||
| src += info_offset; | src += info_offset; | ||||
| av_log(avctx, AV_LOG_DEBUG, "Skipping INFO chunk.\n"); | |||||
| } | } | ||||
| data_size = (avpkt->size - info_offset) & ~1; | data_size = (avpkt->size - info_offset) & ~1; | ||||
| @@ -24,6 +24,7 @@ | |||||
| #include "libavutil/intreadwrite.h" | #include "libavutil/intreadwrite.h" | ||||
| #include "avcodec.h" | #include "avcodec.h" | ||||
| #include "canopus.h" | |||||
| #include "get_bits.h" | #include "get_bits.h" | ||||
| #include "internal.h" | #include "internal.h" | ||||
| @@ -405,29 +406,28 @@ static int hqx_decode_frame(AVCodecContext *avctx, void *data, | |||||
| { | { | ||||
| HQXContext *ctx = avctx->priv_data; | HQXContext *ctx = avctx->priv_data; | ||||
| uint8_t *src = avpkt->data; | uint8_t *src = avpkt->data; | ||||
| uint32_t info_tag, info_offset; | |||||
| uint32_t info_tag; | |||||
| int data_start; | int data_start; | ||||
| int i, ret; | int i, ret; | ||||
| if (avpkt->size < 8) | |||||
| if (avpkt->size < 4 + 4) { | |||||
| av_log(avctx, AV_LOG_ERROR, "Frame is too small %d.\n", avpkt->size); | |||||
| return AVERROR_INVALIDDATA; | return AVERROR_INVALIDDATA; | ||||
| } | |||||
| /* Skip the INFO header if present */ | |||||
| info_offset = 0; | |||||
| info_tag = AV_RL32(src); | info_tag = AV_RL32(src); | ||||
| if (info_tag == MKTAG('I', 'N', 'F', 'O')) { | if (info_tag == MKTAG('I', 'N', 'F', 'O')) { | ||||
| info_offset = AV_RL32(src + 4); | |||||
| int info_offset = AV_RL32(src + 4); | |||||
| if (info_offset > UINT32_MAX - 8 || info_offset + 8 > avpkt->size) { | if (info_offset > UINT32_MAX - 8 || info_offset + 8 > avpkt->size) { | ||||
| av_log(avctx, AV_LOG_ERROR, | av_log(avctx, AV_LOG_ERROR, | ||||
| "Invalid INFO header offset: 0x%08"PRIX32" is too large.\n", | "Invalid INFO header offset: 0x%08"PRIX32" is too large.\n", | ||||
| info_offset); | info_offset); | ||||
| return AVERROR_INVALIDDATA; | return AVERROR_INVALIDDATA; | ||||
| } | } | ||||
| ff_canopus_parse_info_tag(avctx, src + 8, info_offset); | |||||
| info_offset += 8; | info_offset += 8; | ||||
| src += info_offset; | src += info_offset; | ||||
| av_log(avctx, AV_LOG_DEBUG, "Skipping INFO chunk.\n"); | |||||
| } | } | ||||
| data_start = src - avpkt->data; | data_start = src - avpkt->data; | ||||