You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

1141 lines
41KB

  1. /*
  2. * Indeo Video v3 compatible decoder
  3. * Copyright (c) 2009 - 2011 Maxim Poliakovski
  4. *
  5. * This file is part of FFmpeg.
  6. *
  7. * FFmpeg is free software; you can redistribute it and/or
  8. * modify it under the terms of the GNU Lesser General Public
  9. * License as published by the Free Software Foundation; either
  10. * version 2.1 of the License, or (at your option) any later version.
  11. *
  12. * FFmpeg is distributed in the hope that it will be useful,
  13. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  14. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  15. * Lesser General Public License for more details.
  16. *
  17. * You should have received a copy of the GNU Lesser General Public
  18. * License along with FFmpeg; if not, write to the Free Software
  19. * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
  20. */
  21. /**
  22. * @file
  23. * This is a decoder for Intel Indeo Video v3.
  24. * It is based on vector quantization, run-length coding and motion compensation.
  25. * Known container formats: .avi and .mov
  26. * Known FOURCCs: 'IV31', 'IV32'
  27. *
  28. * @see http://wiki.multimedia.cx/index.php?title=Indeo_3
  29. */
  30. #include "libavutil/imgutils.h"
  31. #include "libavutil/intreadwrite.h"
  32. #include "avcodec.h"
  33. #include "copy_block.h"
  34. #include "bytestream.h"
  35. #include "get_bits.h"
  36. #include "hpeldsp.h"
  37. #include "internal.h"
  38. #include "indeo3data.h"
  39. /* RLE opcodes. */
  40. enum {
  41. RLE_ESC_F9 = 249, ///< same as RLE_ESC_FA + do the same with next block
  42. RLE_ESC_FA = 250, ///< INTRA: skip block, INTER: copy data from reference
  43. RLE_ESC_FB = 251, ///< apply null delta to N blocks / skip N blocks
  44. RLE_ESC_FC = 252, ///< same as RLE_ESC_FD + do the same with next block
  45. RLE_ESC_FD = 253, ///< apply null delta to all remaining lines of this block
  46. RLE_ESC_FE = 254, ///< apply null delta to all lines up to the 3rd line
  47. RLE_ESC_FF = 255 ///< apply null delta to all lines up to the 2nd line
  48. };
  49. /* Some constants for parsing frame bitstream flags. */
  50. #define BS_8BIT_PEL (1 << 1) ///< 8bit pixel bitdepth indicator
  51. #define BS_KEYFRAME (1 << 2) ///< intra frame indicator
  52. #define BS_MV_Y_HALF (1 << 4) ///< vertical mv halfpel resolution indicator
  53. #define BS_MV_X_HALF (1 << 5) ///< horizontal mv halfpel resolution indicator
  54. #define BS_NONREF (1 << 8) ///< nonref (discardable) frame indicator
  55. #define BS_BUFFER 9 ///< indicates which of two frame buffers should be used
  56. typedef struct Plane {
  57. uint8_t *buffers[2];
  58. uint8_t *pixels[2]; ///< pointer to the actual pixel data of the buffers above
  59. uint32_t width;
  60. uint32_t height;
  61. uint32_t pitch;
  62. } Plane;
  63. #define CELL_STACK_MAX 20
  64. typedef struct Cell {
  65. int16_t xpos; ///< cell coordinates in 4x4 blocks
  66. int16_t ypos;
  67. int16_t width; ///< cell width in 4x4 blocks
  68. int16_t height; ///< cell height in 4x4 blocks
  69. uint8_t tree; ///< tree id: 0- MC tree, 1 - VQ tree
  70. const int8_t *mv_ptr; ///< ptr to the motion vector if any
  71. } Cell;
  72. typedef struct Indeo3DecodeContext {
  73. AVCodecContext *avctx;
  74. HpelDSPContext hdsp;
  75. GetBitContext gb;
  76. int need_resync;
  77. int skip_bits;
  78. const uint8_t *next_cell_data;
  79. const uint8_t *last_byte;
  80. const int8_t *mc_vectors;
  81. unsigned num_vectors; ///< number of motion vectors in mc_vectors
  82. int16_t width, height;
  83. uint32_t frame_num; ///< current frame number (zero-based)
  84. uint32_t data_size; ///< size of the frame data in bytes
  85. uint16_t frame_flags; ///< frame properties
  86. uint8_t cb_offset; ///< needed for selecting VQ tables
  87. uint8_t buf_sel; ///< active frame buffer: 0 - primary, 1 -secondary
  88. const uint8_t *y_data_ptr;
  89. const uint8_t *v_data_ptr;
  90. const uint8_t *u_data_ptr;
  91. int32_t y_data_size;
  92. int32_t v_data_size;
  93. int32_t u_data_size;
  94. const uint8_t *alt_quant; ///< secondary VQ table set for the modes 1 and 4
  95. Plane planes[3];
  96. } Indeo3DecodeContext;
  97. static uint8_t requant_tab[8][128];
  98. /*
  99. * Build the static requantization table.
  100. * This table is used to remap pixel values according to a specific
  101. * quant index and thus avoid overflows while adding deltas.
  102. */
  103. static av_cold void build_requant_tab(void)
  104. {
  105. static int8_t offsets[8] = { 1, 1, 2, -3, -3, 3, 4, 4 };
  106. static int8_t deltas [8] = { 0, 1, 0, 4, 4, 1, 0, 1 };
  107. int i, j, step;
  108. for (i = 0; i < 8; i++) {
  109. step = i + 2;
  110. for (j = 0; j < 128; j++)
  111. requant_tab[i][j] = (j + offsets[i]) / step * step + deltas[i];
  112. }
  113. /* some last elements calculated above will have values >= 128 */
  114. /* pixel values shall never exceed 127 so set them to non-overflowing values */
  115. /* according with the quantization step of the respective section */
  116. requant_tab[0][127] = 126;
  117. requant_tab[1][119] = 118;
  118. requant_tab[1][120] = 118;
  119. requant_tab[2][126] = 124;
  120. requant_tab[2][127] = 124;
  121. requant_tab[6][124] = 120;
  122. requant_tab[6][125] = 120;
  123. requant_tab[6][126] = 120;
  124. requant_tab[6][127] = 120;
  125. /* Patch for compatibility with the Intel's binary decoders */
  126. requant_tab[1][7] = 10;
  127. requant_tab[4][8] = 10;
  128. }
  129. static av_cold int allocate_frame_buffers(Indeo3DecodeContext *ctx,
  130. AVCodecContext *avctx, int luma_width, int luma_height)
  131. {
  132. int p, chroma_width, chroma_height;
  133. int luma_pitch, chroma_pitch, luma_size, chroma_size;
  134. if (luma_width < 16 || luma_width > 640 ||
  135. luma_height < 16 || luma_height > 480 ||
  136. luma_width & 3 || luma_height & 3) {
  137. av_log(avctx, AV_LOG_ERROR, "Invalid picture dimensions: %d x %d!\n",
  138. luma_width, luma_height);
  139. return AVERROR_INVALIDDATA;
  140. }
  141. ctx->width = luma_width ;
  142. ctx->height = luma_height;
  143. chroma_width = FFALIGN(luma_width >> 2, 4);
  144. chroma_height = FFALIGN(luma_height >> 2, 4);
  145. luma_pitch = FFALIGN(luma_width, 16);
  146. chroma_pitch = FFALIGN(chroma_width, 16);
  147. /* Calculate size of the luminance plane. */
  148. /* Add one line more for INTRA prediction. */
  149. luma_size = luma_pitch * (luma_height + 1);
  150. /* Calculate size of a chrominance planes. */
  151. /* Add one line more for INTRA prediction. */
  152. chroma_size = chroma_pitch * (chroma_height + 1);
  153. /* allocate frame buffers */
  154. for (p = 0; p < 3; p++) {
  155. ctx->planes[p].pitch = !p ? luma_pitch : chroma_pitch;
  156. ctx->planes[p].width = !p ? luma_width : chroma_width;
  157. ctx->planes[p].height = !p ? luma_height : chroma_height;
  158. ctx->planes[p].buffers[0] = av_malloc(!p ? luma_size : chroma_size);
  159. ctx->planes[p].buffers[1] = av_malloc(!p ? luma_size : chroma_size);
  160. /* fill the INTRA prediction lines with the middle pixel value = 64 */
  161. memset(ctx->planes[p].buffers[0], 0x40, ctx->planes[p].pitch);
  162. memset(ctx->planes[p].buffers[1], 0x40, ctx->planes[p].pitch);
  163. /* set buffer pointers = buf_ptr + pitch and thus skip the INTRA prediction line */
  164. ctx->planes[p].pixels[0] = ctx->planes[p].buffers[0] + ctx->planes[p].pitch;
  165. ctx->planes[p].pixels[1] = ctx->planes[p].buffers[1] + ctx->planes[p].pitch;
  166. memset(ctx->planes[p].pixels[0], 0, ctx->planes[p].pitch * ctx->planes[p].height);
  167. memset(ctx->planes[p].pixels[1], 0, ctx->planes[p].pitch * ctx->planes[p].height);
  168. }
  169. return 0;
  170. }
  171. static av_cold void free_frame_buffers(Indeo3DecodeContext *ctx)
  172. {
  173. int p;
  174. ctx->width=
  175. ctx->height= 0;
  176. for (p = 0; p < 3; p++) {
  177. av_freep(&ctx->planes[p].buffers[0]);
  178. av_freep(&ctx->planes[p].buffers[1]);
  179. ctx->planes[p].pixels[0] = ctx->planes[p].pixels[1] = 0;
  180. }
  181. }
  182. /**
  183. * Copy pixels of the cell(x + mv_x, y + mv_y) from the previous frame into
  184. * the cell(x, y) in the current frame.
  185. *
  186. * @param ctx pointer to the decoder context
  187. * @param plane pointer to the plane descriptor
  188. * @param cell pointer to the cell descriptor
  189. */
  190. static int copy_cell(Indeo3DecodeContext *ctx, Plane *plane, Cell *cell)
  191. {
  192. int h, w, mv_x, mv_y, offset, offset_dst;
  193. uint8_t *src, *dst;
  194. /* setup output and reference pointers */
  195. offset_dst = (cell->ypos << 2) * plane->pitch + (cell->xpos << 2);
  196. dst = plane->pixels[ctx->buf_sel] + offset_dst;
  197. if(cell->mv_ptr){
  198. mv_y = cell->mv_ptr[0];
  199. mv_x = cell->mv_ptr[1];
  200. }else
  201. mv_x= mv_y= 0;
  202. /* -1 because there is an extra line on top for prediction */
  203. if ((cell->ypos << 2) + mv_y < -1 || (cell->xpos << 2) + mv_x < 0 ||
  204. ((cell->ypos + cell->height) << 2) + mv_y > plane->height ||
  205. ((cell->xpos + cell->width) << 2) + mv_x > plane->width) {
  206. av_log(ctx->avctx, AV_LOG_ERROR,
  207. "Motion vectors point out of the frame.\n");
  208. return AVERROR_INVALIDDATA;
  209. }
  210. offset = offset_dst + mv_y * plane->pitch + mv_x;
  211. src = plane->pixels[ctx->buf_sel ^ 1] + offset;
  212. h = cell->height << 2;
  213. for (w = cell->width; w > 0;) {
  214. /* copy using 16xH blocks */
  215. if (!((cell->xpos << 2) & 15) && w >= 4) {
  216. for (; w >= 4; src += 16, dst += 16, w -= 4)
  217. ctx->hdsp.put_pixels_tab[0][0](dst, src, plane->pitch, h);
  218. }
  219. /* copy using 8xH blocks */
  220. if (!((cell->xpos << 2) & 7) && w >= 2) {
  221. ctx->hdsp.put_pixels_tab[1][0](dst, src, plane->pitch, h);
  222. w -= 2;
  223. src += 8;
  224. dst += 8;
  225. } else if (w >= 1) {
  226. ctx->hdsp.put_pixels_tab[2][0](dst, src, plane->pitch, h);
  227. w--;
  228. src += 4;
  229. dst += 4;
  230. }
  231. }
  232. return 0;
  233. }
  234. /* Average 4/8 pixels at once without rounding using SWAR */
  235. #define AVG_32(dst, src, ref) \
  236. AV_WN32A(dst, ((AV_RN32(src) + AV_RN32(ref)) >> 1) & 0x7F7F7F7FUL)
  237. #define AVG_64(dst, src, ref) \
  238. AV_WN64A(dst, ((AV_RN64(src) + AV_RN64(ref)) >> 1) & 0x7F7F7F7F7F7F7F7FULL)
  239. /*
  240. * Replicate each even pixel as follows:
  241. * ABCDEFGH -> AACCEEGG
  242. */
  243. static inline uint64_t replicate64(uint64_t a) {
  244. #if HAVE_BIGENDIAN
  245. a &= 0xFF00FF00FF00FF00ULL;
  246. a |= a >> 8;
  247. #else
  248. a &= 0x00FF00FF00FF00FFULL;
  249. a |= a << 8;
  250. #endif
  251. return a;
  252. }
  253. static inline uint32_t replicate32(uint32_t a) {
  254. #if HAVE_BIGENDIAN
  255. a &= 0xFF00FF00UL;
  256. a |= a >> 8;
  257. #else
  258. a &= 0x00FF00FFUL;
  259. a |= a << 8;
  260. #endif
  261. return a;
  262. }
  263. /* Fill n lines with 64bit pixel value pix */
  264. static inline void fill_64(uint8_t *dst, const uint64_t pix, int32_t n,
  265. int32_t row_offset)
  266. {
  267. for (; n > 0; dst += row_offset, n--)
  268. AV_WN64A(dst, pix);
  269. }
  270. /* Error codes for cell decoding. */
  271. enum {
  272. IV3_NOERR = 0,
  273. IV3_BAD_RLE = 1,
  274. IV3_BAD_DATA = 2,
  275. IV3_BAD_COUNTER = 3,
  276. IV3_UNSUPPORTED = 4,
  277. IV3_OUT_OF_DATA = 5
  278. };
  279. #define BUFFER_PRECHECK \
  280. if (*data_ptr >= last_ptr) \
  281. return IV3_OUT_OF_DATA; \
  282. #define RLE_BLOCK_COPY \
  283. if (cell->mv_ptr || !skip_flag) \
  284. copy_block4(dst, ref, row_offset, row_offset, 4 << v_zoom)
  285. #define RLE_BLOCK_COPY_8 \
  286. pix64 = AV_RN64(ref);\
  287. if (is_first_row) {/* special prediction case: top line of a cell */\
  288. pix64 = replicate64(pix64);\
  289. fill_64(dst + row_offset, pix64, 7, row_offset);\
  290. AVG_64(dst, ref, dst + row_offset);\
  291. } else \
  292. fill_64(dst, pix64, 8, row_offset)
  293. #define RLE_LINES_COPY \
  294. copy_block4(dst, ref, row_offset, row_offset, num_lines << v_zoom)
  295. #define RLE_LINES_COPY_M10 \
  296. pix64 = AV_RN64(ref);\
  297. if (is_top_of_cell) {\
  298. pix64 = replicate64(pix64);\
  299. fill_64(dst + row_offset, pix64, (num_lines << 1) - 1, row_offset);\
  300. AVG_64(dst, ref, dst + row_offset);\
  301. } else \
  302. fill_64(dst, pix64, num_lines << 1, row_offset)
  303. #define APPLY_DELTA_4 \
  304. AV_WN16A(dst + line_offset ,\
  305. (AV_RN16(ref ) + delta_tab->deltas[dyad1]) & 0x7F7F);\
  306. AV_WN16A(dst + line_offset + 2,\
  307. (AV_RN16(ref + 2) + delta_tab->deltas[dyad2]) & 0x7F7F);\
  308. if (mode >= 3) {\
  309. if (is_top_of_cell && !cell->ypos) {\
  310. AV_COPY32U(dst, dst + row_offset);\
  311. } else {\
  312. AVG_32(dst, ref, dst + row_offset);\
  313. }\
  314. }
  315. #define APPLY_DELTA_8 \
  316. /* apply two 32-bit VQ deltas to next even line */\
  317. if (is_top_of_cell) { \
  318. AV_WN32A(dst + row_offset , \
  319. (replicate32(AV_RN32(ref )) + delta_tab->deltas_m10[dyad1]) & 0x7F7F7F7F);\
  320. AV_WN32A(dst + row_offset + 4, \
  321. (replicate32(AV_RN32(ref + 4)) + delta_tab->deltas_m10[dyad2]) & 0x7F7F7F7F);\
  322. } else { \
  323. AV_WN32A(dst + row_offset , \
  324. (AV_RN32(ref ) + delta_tab->deltas_m10[dyad1]) & 0x7F7F7F7F);\
  325. AV_WN32A(dst + row_offset + 4, \
  326. (AV_RN32(ref + 4) + delta_tab->deltas_m10[dyad2]) & 0x7F7F7F7F);\
  327. } \
  328. /* odd lines are not coded but rather interpolated/replicated */\
  329. /* first line of the cell on the top of image? - replicate */\
  330. /* otherwise - interpolate */\
  331. if (is_top_of_cell && !cell->ypos) {\
  332. AV_COPY64U(dst, dst + row_offset);\
  333. } else \
  334. AVG_64(dst, ref, dst + row_offset);
  335. #define APPLY_DELTA_1011_INTER \
  336. if (mode == 10) { \
  337. AV_WN32A(dst , \
  338. (AV_RN32(dst ) + delta_tab->deltas_m10[dyad1]) & 0x7F7F7F7F);\
  339. AV_WN32A(dst + 4 , \
  340. (AV_RN32(dst + 4 ) + delta_tab->deltas_m10[dyad2]) & 0x7F7F7F7F);\
  341. AV_WN32A(dst + row_offset , \
  342. (AV_RN32(dst + row_offset ) + delta_tab->deltas_m10[dyad1]) & 0x7F7F7F7F);\
  343. AV_WN32A(dst + row_offset + 4, \
  344. (AV_RN32(dst + row_offset + 4) + delta_tab->deltas_m10[dyad2]) & 0x7F7F7F7F);\
  345. } else { \
  346. AV_WN16A(dst , \
  347. (AV_RN16(dst ) + delta_tab->deltas[dyad1]) & 0x7F7F);\
  348. AV_WN16A(dst + 2 , \
  349. (AV_RN16(dst + 2 ) + delta_tab->deltas[dyad2]) & 0x7F7F);\
  350. AV_WN16A(dst + row_offset , \
  351. (AV_RN16(dst + row_offset ) + delta_tab->deltas[dyad1]) & 0x7F7F);\
  352. AV_WN16A(dst + row_offset + 2, \
  353. (AV_RN16(dst + row_offset + 2) + delta_tab->deltas[dyad2]) & 0x7F7F);\
  354. }
  355. static int decode_cell_data(Indeo3DecodeContext *ctx, Cell *cell,
  356. uint8_t *block, uint8_t *ref_block,
  357. int pitch, int h_zoom, int v_zoom, int mode,
  358. const vqEntry *delta[2], int swap_quads[2],
  359. const uint8_t **data_ptr, const uint8_t *last_ptr)
  360. {
  361. int x, y, line, num_lines;
  362. int rle_blocks = 0;
  363. uint8_t code, *dst, *ref;
  364. const vqEntry *delta_tab;
  365. unsigned int dyad1, dyad2;
  366. uint64_t pix64;
  367. int skip_flag = 0, is_top_of_cell, is_first_row = 1;
  368. int row_offset, blk_row_offset, line_offset;
  369. row_offset = pitch;
  370. blk_row_offset = (row_offset << (2 + v_zoom)) - (cell->width << 2);
  371. line_offset = v_zoom ? row_offset : 0;
  372. if (cell->height & v_zoom || cell->width & h_zoom)
  373. return IV3_BAD_DATA;
  374. for (y = 0; y < cell->height; is_first_row = 0, y += 1 + v_zoom) {
  375. for (x = 0; x < cell->width; x += 1 + h_zoom) {
  376. ref = ref_block;
  377. dst = block;
  378. if (rle_blocks > 0) {
  379. if (mode <= 4) {
  380. RLE_BLOCK_COPY;
  381. } else if (mode == 10 && !cell->mv_ptr) {
  382. RLE_BLOCK_COPY_8;
  383. }
  384. rle_blocks--;
  385. } else {
  386. for (line = 0; line < 4;) {
  387. num_lines = 1;
  388. is_top_of_cell = is_first_row && !line;
  389. /* select primary VQ table for odd, secondary for even lines */
  390. if (mode <= 4)
  391. delta_tab = delta[line & 1];
  392. else
  393. delta_tab = delta[1];
  394. BUFFER_PRECHECK;
  395. code = bytestream_get_byte(data_ptr);
  396. if (code < 248) {
  397. if (code < delta_tab->num_dyads) {
  398. BUFFER_PRECHECK;
  399. dyad1 = bytestream_get_byte(data_ptr);
  400. dyad2 = code;
  401. if (dyad1 >= delta_tab->num_dyads || dyad1 >= 248)
  402. return IV3_BAD_DATA;
  403. } else {
  404. /* process QUADS */
  405. code -= delta_tab->num_dyads;
  406. dyad1 = code / delta_tab->quad_exp;
  407. dyad2 = code % delta_tab->quad_exp;
  408. if (swap_quads[line & 1])
  409. FFSWAP(unsigned int, dyad1, dyad2);
  410. }
  411. if (mode <= 4) {
  412. APPLY_DELTA_4;
  413. } else if (mode == 10 && !cell->mv_ptr) {
  414. APPLY_DELTA_8;
  415. } else {
  416. APPLY_DELTA_1011_INTER;
  417. }
  418. } else {
  419. /* process RLE codes */
  420. switch (code) {
  421. case RLE_ESC_FC:
  422. skip_flag = 0;
  423. rle_blocks = 1;
  424. code = 253;
  425. /* FALLTHROUGH */
  426. case RLE_ESC_FF:
  427. case RLE_ESC_FE:
  428. case RLE_ESC_FD:
  429. num_lines = 257 - code - line;
  430. if (num_lines <= 0)
  431. return IV3_BAD_RLE;
  432. if (mode <= 4) {
  433. RLE_LINES_COPY;
  434. } else if (mode == 10 && !cell->mv_ptr) {
  435. RLE_LINES_COPY_M10;
  436. }
  437. break;
  438. case RLE_ESC_FB:
  439. BUFFER_PRECHECK;
  440. code = bytestream_get_byte(data_ptr);
  441. rle_blocks = (code & 0x1F) - 1; /* set block counter */
  442. if (code >= 64 || rle_blocks < 0)
  443. return IV3_BAD_COUNTER;
  444. skip_flag = code & 0x20;
  445. num_lines = 4 - line; /* enforce next block processing */
  446. if (mode >= 10 || (cell->mv_ptr || !skip_flag)) {
  447. if (mode <= 4) {
  448. RLE_LINES_COPY;
  449. } else if (mode == 10 && !cell->mv_ptr) {
  450. RLE_LINES_COPY_M10;
  451. }
  452. }
  453. break;
  454. case RLE_ESC_F9:
  455. skip_flag = 1;
  456. rle_blocks = 1;
  457. /* FALLTHROUGH */
  458. case RLE_ESC_FA:
  459. if (line)
  460. return IV3_BAD_RLE;
  461. num_lines = 4; /* enforce next block processing */
  462. if (cell->mv_ptr) {
  463. if (mode <= 4) {
  464. RLE_LINES_COPY;
  465. } else if (mode == 10 && !cell->mv_ptr) {
  466. RLE_LINES_COPY_M10;
  467. }
  468. }
  469. break;
  470. default:
  471. return IV3_UNSUPPORTED;
  472. }
  473. }
  474. line += num_lines;
  475. ref += row_offset * (num_lines << v_zoom);
  476. dst += row_offset * (num_lines << v_zoom);
  477. }
  478. }
  479. /* move to next horizontal block */
  480. block += 4 << h_zoom;
  481. ref_block += 4 << h_zoom;
  482. }
  483. /* move to next line of blocks */
  484. ref_block += blk_row_offset;
  485. block += blk_row_offset;
  486. }
  487. return IV3_NOERR;
  488. }
  489. /**
  490. * Decode a vector-quantized cell.
  491. * It consists of several routines, each of which handles one or more "modes"
  492. * with which a cell can be encoded.
  493. *
  494. * @param ctx pointer to the decoder context
  495. * @param avctx ptr to the AVCodecContext
  496. * @param plane pointer to the plane descriptor
  497. * @param cell pointer to the cell descriptor
  498. * @param data_ptr pointer to the compressed data
  499. * @param last_ptr pointer to the last byte to catch reads past end of buffer
  500. * @return number of consumed bytes or negative number in case of error
  501. */
  502. static int decode_cell(Indeo3DecodeContext *ctx, AVCodecContext *avctx,
  503. Plane *plane, Cell *cell, const uint8_t *data_ptr,
  504. const uint8_t *last_ptr)
  505. {
  506. int x, mv_x, mv_y, mode, vq_index, prim_indx, second_indx;
  507. int zoom_fac;
  508. int offset, error = 0, swap_quads[2];
  509. uint8_t code, *block, *ref_block = 0;
  510. const vqEntry *delta[2];
  511. const uint8_t *data_start = data_ptr;
  512. /* get coding mode and VQ table index from the VQ descriptor byte */
  513. code = *data_ptr++;
  514. mode = code >> 4;
  515. vq_index = code & 0xF;
  516. /* setup output and reference pointers */
  517. offset = (cell->ypos << 2) * plane->pitch + (cell->xpos << 2);
  518. block = plane->pixels[ctx->buf_sel] + offset;
  519. if (!cell->mv_ptr) {
  520. /* use previous line as reference for INTRA cells */
  521. ref_block = block - plane->pitch;
  522. } else if (mode >= 10) {
  523. /* for mode 10 and 11 INTER first copy the predicted cell into the current one */
  524. /* so we don't need to do data copying for each RLE code later */
  525. int ret = copy_cell(ctx, plane, cell);
  526. if (ret < 0)
  527. return ret;
  528. } else {
  529. /* set the pointer to the reference pixels for modes 0-4 INTER */
  530. mv_y = cell->mv_ptr[0];
  531. mv_x = cell->mv_ptr[1];
  532. /* -1 because there is an extra line on top for prediction */
  533. if ((cell->ypos << 2) + mv_y < -1 || (cell->xpos << 2) + mv_x < 0 ||
  534. ((cell->ypos + cell->height) << 2) + mv_y > plane->height ||
  535. ((cell->xpos + cell->width) << 2) + mv_x > plane->width) {
  536. av_log(ctx->avctx, AV_LOG_ERROR,
  537. "Motion vectors point out of the frame.\n");
  538. return AVERROR_INVALIDDATA;
  539. }
  540. offset += mv_y * plane->pitch + mv_x;
  541. ref_block = plane->pixels[ctx->buf_sel ^ 1] + offset;
  542. }
  543. /* select VQ tables as follows: */
  544. /* modes 0 and 3 use only the primary table for all lines in a block */
  545. /* while modes 1 and 4 switch between primary and secondary tables on alternate lines */
  546. if (mode == 1 || mode == 4) {
  547. code = ctx->alt_quant[vq_index];
  548. prim_indx = (code >> 4) + ctx->cb_offset;
  549. second_indx = (code & 0xF) + ctx->cb_offset;
  550. } else {
  551. vq_index += ctx->cb_offset;
  552. prim_indx = second_indx = vq_index;
  553. }
  554. if (prim_indx >= 24 || second_indx >= 24) {
  555. av_log(avctx, AV_LOG_ERROR, "Invalid VQ table indexes! Primary: %d, secondary: %d!\n",
  556. prim_indx, second_indx);
  557. return AVERROR_INVALIDDATA;
  558. }
  559. delta[0] = &vq_tab[second_indx];
  560. delta[1] = &vq_tab[prim_indx];
  561. swap_quads[0] = second_indx >= 16;
  562. swap_quads[1] = prim_indx >= 16;
  563. /* requantize the prediction if VQ index of this cell differs from VQ index */
  564. /* of the predicted cell in order to avoid overflows. */
  565. if (vq_index >= 8 && ref_block) {
  566. for (x = 0; x < cell->width << 2; x++)
  567. ref_block[x] = requant_tab[vq_index & 7][ref_block[x] & 127];
  568. }
  569. error = IV3_NOERR;
  570. switch (mode) {
  571. case 0: /*------------------ MODES 0 & 1 (4x4 block processing) --------------------*/
  572. case 1:
  573. case 3: /*------------------ MODES 3 & 4 (4x8 block processing) --------------------*/
  574. case 4:
  575. if (mode >= 3 && cell->mv_ptr) {
  576. av_log(avctx, AV_LOG_ERROR, "Attempt to apply Mode 3/4 to an INTER cell!\n");
  577. return AVERROR_INVALIDDATA;
  578. }
  579. zoom_fac = mode >= 3;
  580. error = decode_cell_data(ctx, cell, block, ref_block, plane->pitch,
  581. 0, zoom_fac, mode, delta, swap_quads,
  582. &data_ptr, last_ptr);
  583. break;
  584. case 10: /*-------------------- MODE 10 (8x8 block processing) ---------------------*/
  585. case 11: /*----------------- MODE 11 (4x8 INTER block processing) ------------------*/
  586. if (mode == 10 && !cell->mv_ptr) { /* MODE 10 INTRA processing */
  587. error = decode_cell_data(ctx, cell, block, ref_block, plane->pitch,
  588. 1, 1, mode, delta, swap_quads,
  589. &data_ptr, last_ptr);
  590. } else { /* mode 10 and 11 INTER processing */
  591. if (mode == 11 && !cell->mv_ptr) {
  592. av_log(avctx, AV_LOG_ERROR, "Attempt to use Mode 11 for an INTRA cell!\n");
  593. return AVERROR_INVALIDDATA;
  594. }
  595. zoom_fac = mode == 10;
  596. error = decode_cell_data(ctx, cell, block, ref_block, plane->pitch,
  597. zoom_fac, 1, mode, delta, swap_quads,
  598. &data_ptr, last_ptr);
  599. }
  600. break;
  601. default:
  602. av_log(avctx, AV_LOG_ERROR, "Unsupported coding mode: %d\n", mode);
  603. return AVERROR_INVALIDDATA;
  604. }//switch mode
  605. switch (error) {
  606. case IV3_BAD_RLE:
  607. av_log(avctx, AV_LOG_ERROR, "Mode %d: RLE code %X is not allowed at the current line\n",
  608. mode, data_ptr[-1]);
  609. return AVERROR_INVALIDDATA;
  610. case IV3_BAD_DATA:
  611. av_log(avctx, AV_LOG_ERROR, "Mode %d: invalid VQ data\n", mode);
  612. return AVERROR_INVALIDDATA;
  613. case IV3_BAD_COUNTER:
  614. av_log(avctx, AV_LOG_ERROR, "Mode %d: RLE-FB invalid counter: %d\n", mode, code);
  615. return AVERROR_INVALIDDATA;
  616. case IV3_UNSUPPORTED:
  617. av_log(avctx, AV_LOG_ERROR, "Mode %d: unsupported RLE code: %X\n", mode, data_ptr[-1]);
  618. return AVERROR_INVALIDDATA;
  619. case IV3_OUT_OF_DATA:
  620. av_log(avctx, AV_LOG_ERROR, "Mode %d: attempt to read past end of buffer\n", mode);
  621. return AVERROR_INVALIDDATA;
  622. }
  623. return data_ptr - data_start; /* report number of bytes consumed from the input buffer */
  624. }
  625. /* Binary tree codes. */
  626. enum {
  627. H_SPLIT = 0,
  628. V_SPLIT = 1,
  629. INTRA_NULL = 2,
  630. INTER_DATA = 3
  631. };
  632. #define SPLIT_CELL(size, new_size) (new_size) = ((size) > 2) ? ((((size) + 2) >> 2) << 1) : 1
  633. #define UPDATE_BITPOS(n) \
  634. ctx->skip_bits += (n); \
  635. ctx->need_resync = 1
  636. #define RESYNC_BITSTREAM \
  637. if (ctx->need_resync && !(get_bits_count(&ctx->gb) & 7)) { \
  638. skip_bits_long(&ctx->gb, ctx->skip_bits); \
  639. ctx->skip_bits = 0; \
  640. ctx->need_resync = 0; \
  641. }
  642. #define CHECK_CELL \
  643. if (curr_cell.xpos + curr_cell.width > (plane->width >> 2) || \
  644. curr_cell.ypos + curr_cell.height > (plane->height >> 2)) { \
  645. av_log(avctx, AV_LOG_ERROR, "Invalid cell: x=%d, y=%d, w=%d, h=%d\n", \
  646. curr_cell.xpos, curr_cell.ypos, curr_cell.width, curr_cell.height); \
  647. return AVERROR_INVALIDDATA; \
  648. }
  649. static int parse_bintree(Indeo3DecodeContext *ctx, AVCodecContext *avctx,
  650. Plane *plane, int code, Cell *ref_cell,
  651. const int depth, const int strip_width)
  652. {
  653. Cell curr_cell;
  654. int bytes_used, ret;
  655. if (depth <= 0) {
  656. av_log(avctx, AV_LOG_ERROR, "Stack overflow (corrupted binary tree)!\n");
  657. return AVERROR_INVALIDDATA; // unwind recursion
  658. }
  659. curr_cell = *ref_cell; // clone parent cell
  660. if (code == H_SPLIT) {
  661. SPLIT_CELL(ref_cell->height, curr_cell.height);
  662. ref_cell->ypos += curr_cell.height;
  663. ref_cell->height -= curr_cell.height;
  664. if (ref_cell->height <= 0 || curr_cell.height <= 0)
  665. return AVERROR_INVALIDDATA;
  666. } else if (code == V_SPLIT) {
  667. if (curr_cell.width > strip_width) {
  668. /* split strip */
  669. curr_cell.width = (curr_cell.width <= (strip_width << 1) ? 1 : 2) * strip_width;
  670. } else
  671. SPLIT_CELL(ref_cell->width, curr_cell.width);
  672. ref_cell->xpos += curr_cell.width;
  673. ref_cell->width -= curr_cell.width;
  674. if (ref_cell->width <= 0 || curr_cell.width <= 0)
  675. return AVERROR_INVALIDDATA;
  676. }
  677. while (get_bits_left(&ctx->gb) >= 2) { /* loop until return */
  678. RESYNC_BITSTREAM;
  679. switch (code = get_bits(&ctx->gb, 2)) {
  680. case H_SPLIT:
  681. case V_SPLIT:
  682. if (parse_bintree(ctx, avctx, plane, code, &curr_cell, depth - 1, strip_width))
  683. return AVERROR_INVALIDDATA;
  684. break;
  685. case INTRA_NULL:
  686. if (!curr_cell.tree) { /* MC tree INTRA code */
  687. curr_cell.mv_ptr = 0; /* mark the current strip as INTRA */
  688. curr_cell.tree = 1; /* enter the VQ tree */
  689. } else { /* VQ tree NULL code */
  690. RESYNC_BITSTREAM;
  691. code = get_bits(&ctx->gb, 2);
  692. if (code >= 2) {
  693. av_log(avctx, AV_LOG_ERROR, "Invalid VQ_NULL code: %d\n", code);
  694. return AVERROR_INVALIDDATA;
  695. }
  696. if (code == 1)
  697. av_log(avctx, AV_LOG_ERROR, "SkipCell procedure not implemented yet!\n");
  698. CHECK_CELL
  699. if (!curr_cell.mv_ptr)
  700. return AVERROR_INVALIDDATA;
  701. ret = copy_cell(ctx, plane, &curr_cell);
  702. return ret;
  703. }
  704. break;
  705. case INTER_DATA:
  706. if (!curr_cell.tree) { /* MC tree INTER code */
  707. unsigned mv_idx;
  708. /* get motion vector index and setup the pointer to the mv set */
  709. if (!ctx->need_resync)
  710. ctx->next_cell_data = &ctx->gb.buffer[(get_bits_count(&ctx->gb) + 7) >> 3];
  711. if (ctx->next_cell_data >= ctx->last_byte) {
  712. av_log(avctx, AV_LOG_ERROR, "motion vector out of array\n");
  713. return AVERROR_INVALIDDATA;
  714. }
  715. mv_idx = *(ctx->next_cell_data++);
  716. if (mv_idx >= ctx->num_vectors) {
  717. av_log(avctx, AV_LOG_ERROR, "motion vector index out of range\n");
  718. return AVERROR_INVALIDDATA;
  719. }
  720. curr_cell.mv_ptr = &ctx->mc_vectors[mv_idx << 1];
  721. curr_cell.tree = 1; /* enter the VQ tree */
  722. UPDATE_BITPOS(8);
  723. } else { /* VQ tree DATA code */
  724. if (!ctx->need_resync)
  725. ctx->next_cell_data = &ctx->gb.buffer[(get_bits_count(&ctx->gb) + 7) >> 3];
  726. CHECK_CELL
  727. bytes_used = decode_cell(ctx, avctx, plane, &curr_cell,
  728. ctx->next_cell_data, ctx->last_byte);
  729. if (bytes_used < 0)
  730. return AVERROR_INVALIDDATA;
  731. UPDATE_BITPOS(bytes_used << 3);
  732. ctx->next_cell_data += bytes_used;
  733. return 0;
  734. }
  735. break;
  736. }
  737. }//while
  738. return AVERROR_INVALIDDATA;
  739. }
  740. static int decode_plane(Indeo3DecodeContext *ctx, AVCodecContext *avctx,
  741. Plane *plane, const uint8_t *data, int32_t data_size,
  742. int32_t strip_width)
  743. {
  744. Cell curr_cell;
  745. unsigned num_vectors;
  746. /* each plane data starts with mc_vector_count field, */
  747. /* an optional array of motion vectors followed by the vq data */
  748. num_vectors = bytestream_get_le32(&data); data_size -= 4;
  749. if (num_vectors > 256) {
  750. av_log(ctx->avctx, AV_LOG_ERROR,
  751. "Read invalid number of motion vectors %d\n", num_vectors);
  752. return AVERROR_INVALIDDATA;
  753. }
  754. if (num_vectors * 2 > data_size)
  755. return AVERROR_INVALIDDATA;
  756. ctx->num_vectors = num_vectors;
  757. ctx->mc_vectors = num_vectors ? data : 0;
  758. /* init the bitreader */
  759. init_get_bits(&ctx->gb, &data[num_vectors * 2], (data_size - num_vectors * 2) << 3);
  760. ctx->skip_bits = 0;
  761. ctx->need_resync = 0;
  762. ctx->last_byte = data + data_size;
  763. /* initialize the 1st cell and set its dimensions to whole plane */
  764. curr_cell.xpos = curr_cell.ypos = 0;
  765. curr_cell.width = plane->width >> 2;
  766. curr_cell.height = plane->height >> 2;
  767. curr_cell.tree = 0; // we are in the MC tree now
  768. curr_cell.mv_ptr = 0; // no motion vector = INTRA cell
  769. return parse_bintree(ctx, avctx, plane, INTRA_NULL, &curr_cell, CELL_STACK_MAX, strip_width);
  770. }
  771. #define OS_HDR_ID MKBETAG('F', 'R', 'M', 'H')
  772. static int decode_frame_headers(Indeo3DecodeContext *ctx, AVCodecContext *avctx,
  773. const uint8_t *buf, int buf_size)
  774. {
  775. GetByteContext gb;
  776. const uint8_t *bs_hdr;
  777. uint32_t frame_num, word2, check_sum, data_size;
  778. uint32_t y_offset, u_offset, v_offset, starts[3], ends[3];
  779. uint16_t height, width;
  780. int i, j;
  781. bytestream2_init(&gb, buf, buf_size);
  782. /* parse and check the OS header */
  783. frame_num = bytestream2_get_le32(&gb);
  784. word2 = bytestream2_get_le32(&gb);
  785. check_sum = bytestream2_get_le32(&gb);
  786. data_size = bytestream2_get_le32(&gb);
  787. if ((frame_num ^ word2 ^ data_size ^ OS_HDR_ID) != check_sum) {
  788. av_log(avctx, AV_LOG_ERROR, "OS header checksum mismatch!\n");
  789. return AVERROR_INVALIDDATA;
  790. }
  791. /* parse the bitstream header */
  792. bs_hdr = gb.buffer;
  793. if (bytestream2_get_le16(&gb) != 32) {
  794. av_log(avctx, AV_LOG_ERROR, "Unsupported codec version!\n");
  795. return AVERROR_INVALIDDATA;
  796. }
  797. ctx->frame_num = frame_num;
  798. ctx->frame_flags = bytestream2_get_le16(&gb);
  799. ctx->data_size = (bytestream2_get_le32(&gb) + 7) >> 3;
  800. ctx->cb_offset = bytestream2_get_byte(&gb);
  801. if (ctx->data_size == 16)
  802. return 4;
  803. ctx->data_size = FFMIN(ctx->data_size, buf_size - 16);
  804. bytestream2_skip(&gb, 3); // skip reserved byte and checksum
  805. /* check frame dimensions */
  806. height = bytestream2_get_le16(&gb);
  807. width = bytestream2_get_le16(&gb);
  808. if (av_image_check_size(width, height, 0, avctx))
  809. return AVERROR_INVALIDDATA;
  810. if (width != ctx->width || height != ctx->height) {
  811. int res;
  812. av_dlog(avctx, "Frame dimensions changed!\n");
  813. if (width < 16 || width > 640 ||
  814. height < 16 || height > 480 ||
  815. width & 3 || height & 3) {
  816. av_log(avctx, AV_LOG_ERROR,
  817. "Invalid picture dimensions: %d x %d!\n", width, height);
  818. return AVERROR_INVALIDDATA;
  819. }
  820. free_frame_buffers(ctx);
  821. if ((res = allocate_frame_buffers(ctx, avctx, width, height)) < 0)
  822. return res;
  823. avcodec_set_dimensions(avctx, width, height);
  824. }
  825. y_offset = bytestream2_get_le32(&gb);
  826. v_offset = bytestream2_get_le32(&gb);
  827. u_offset = bytestream2_get_le32(&gb);
  828. bytestream2_skip(&gb, 4);
  829. /* unfortunately there is no common order of planes in the buffer */
  830. /* so we use that sorting algo for determining planes data sizes */
  831. starts[0] = y_offset;
  832. starts[1] = v_offset;
  833. starts[2] = u_offset;
  834. for (j = 0; j < 3; j++) {
  835. ends[j] = ctx->data_size;
  836. for (i = 2; i >= 0; i--)
  837. if (starts[i] < ends[j] && starts[i] > starts[j])
  838. ends[j] = starts[i];
  839. }
  840. ctx->y_data_size = ends[0] - starts[0];
  841. ctx->v_data_size = ends[1] - starts[1];
  842. ctx->u_data_size = ends[2] - starts[2];
  843. if (FFMAX3(y_offset, v_offset, u_offset) >= ctx->data_size - 16 ||
  844. FFMIN3(y_offset, v_offset, u_offset) < gb.buffer - bs_hdr + 16 ||
  845. FFMIN3(ctx->y_data_size, ctx->v_data_size, ctx->u_data_size) <= 0) {
  846. av_log(avctx, AV_LOG_ERROR, "One of the y/u/v offsets is invalid\n");
  847. return AVERROR_INVALIDDATA;
  848. }
  849. ctx->y_data_ptr = bs_hdr + y_offset;
  850. ctx->v_data_ptr = bs_hdr + v_offset;
  851. ctx->u_data_ptr = bs_hdr + u_offset;
  852. ctx->alt_quant = gb.buffer;
  853. if (ctx->data_size == 16) {
  854. av_log(avctx, AV_LOG_DEBUG, "Sync frame encountered!\n");
  855. return 16;
  856. }
  857. if (ctx->frame_flags & BS_8BIT_PEL) {
  858. avpriv_request_sample(avctx, "8-bit pixel format");
  859. return AVERROR_PATCHWELCOME;
  860. }
  861. if (ctx->frame_flags & BS_MV_X_HALF || ctx->frame_flags & BS_MV_Y_HALF) {
  862. avpriv_request_sample(avctx, "Halfpel motion vectors");
  863. return AVERROR_PATCHWELCOME;
  864. }
  865. return 0;
  866. }
  867. /**
  868. * Convert and output the current plane.
  869. * All pixel values will be upsampled by shifting right by one bit.
  870. *
  871. * @param[in] plane pointer to the descriptor of the plane being processed
  872. * @param[in] buf_sel indicates which frame buffer the input data stored in
  873. * @param[out] dst pointer to the buffer receiving converted pixels
  874. * @param[in] dst_pitch pitch for moving to the next y line
  875. * @param[in] dst_height output plane height
  876. */
  877. static void output_plane(const Plane *plane, int buf_sel, uint8_t *dst,
  878. int dst_pitch, int dst_height)
  879. {
  880. int x,y;
  881. const uint8_t *src = plane->pixels[buf_sel];
  882. uint32_t pitch = plane->pitch;
  883. dst_height = FFMIN(dst_height, plane->height);
  884. for (y = 0; y < dst_height; y++) {
  885. /* convert four pixels at once using SWAR */
  886. for (x = 0; x < plane->width >> 2; x++) {
  887. AV_WN32A(dst, (AV_RN32A(src) & 0x7F7F7F7F) << 1);
  888. src += 4;
  889. dst += 4;
  890. }
  891. for (x <<= 2; x < plane->width; x++)
  892. *dst++ = *src++ << 1;
  893. src += pitch - plane->width;
  894. dst += dst_pitch - plane->width;
  895. }
  896. }
  897. static av_cold int decode_init(AVCodecContext *avctx)
  898. {
  899. Indeo3DecodeContext *ctx = avctx->priv_data;
  900. ctx->avctx = avctx;
  901. avctx->pix_fmt = AV_PIX_FMT_YUV410P;
  902. build_requant_tab();
  903. ff_hpeldsp_init(&ctx->hdsp, avctx->flags);
  904. return allocate_frame_buffers(ctx, avctx, avctx->width, avctx->height);
  905. }
  906. static int decode_frame(AVCodecContext *avctx, void *data, int *got_frame,
  907. AVPacket *avpkt)
  908. {
  909. Indeo3DecodeContext *ctx = avctx->priv_data;
  910. const uint8_t *buf = avpkt->data;
  911. int buf_size = avpkt->size;
  912. AVFrame *frame = data;
  913. int res;
  914. res = decode_frame_headers(ctx, avctx, buf, buf_size);
  915. if (res < 0)
  916. return res;
  917. /* skip sync(null) frames */
  918. if (res) {
  919. // we have processed 16 bytes but no data was decoded
  920. *got_frame = 0;
  921. return buf_size;
  922. }
  923. /* skip droppable INTER frames if requested */
  924. if (ctx->frame_flags & BS_NONREF &&
  925. (avctx->skip_frame >= AVDISCARD_NONREF))
  926. return 0;
  927. /* skip INTER frames if requested */
  928. if (!(ctx->frame_flags & BS_KEYFRAME) && avctx->skip_frame >= AVDISCARD_NONKEY)
  929. return 0;
  930. /* use BS_BUFFER flag for buffer switching */
  931. ctx->buf_sel = (ctx->frame_flags >> BS_BUFFER) & 1;
  932. if ((res = ff_get_buffer(avctx, frame, 0)) < 0)
  933. return res;
  934. /* decode luma plane */
  935. if ((res = decode_plane(ctx, avctx, ctx->planes, ctx->y_data_ptr, ctx->y_data_size, 40)))
  936. return res;
  937. /* decode chroma planes */
  938. if ((res = decode_plane(ctx, avctx, &ctx->planes[1], ctx->u_data_ptr, ctx->u_data_size, 10)))
  939. return res;
  940. if ((res = decode_plane(ctx, avctx, &ctx->planes[2], ctx->v_data_ptr, ctx->v_data_size, 10)))
  941. return res;
  942. output_plane(&ctx->planes[0], ctx->buf_sel,
  943. frame->data[0], frame->linesize[0],
  944. avctx->height);
  945. output_plane(&ctx->planes[1], ctx->buf_sel,
  946. frame->data[1], frame->linesize[1],
  947. (avctx->height + 3) >> 2);
  948. output_plane(&ctx->planes[2], ctx->buf_sel,
  949. frame->data[2], frame->linesize[2],
  950. (avctx->height + 3) >> 2);
  951. *got_frame = 1;
  952. return buf_size;
  953. }
  954. static av_cold int decode_close(AVCodecContext *avctx)
  955. {
  956. free_frame_buffers(avctx->priv_data);
  957. return 0;
  958. }
  959. AVCodec ff_indeo3_decoder = {
  960. .name = "indeo3",
  961. .type = AVMEDIA_TYPE_VIDEO,
  962. .id = AV_CODEC_ID_INDEO3,
  963. .priv_data_size = sizeof(Indeo3DecodeContext),
  964. .init = decode_init,
  965. .close = decode_close,
  966. .decode = decode_frame,
  967. .capabilities = CODEC_CAP_DR1,
  968. .long_name = NULL_IF_CONFIG_SMALL("Intel Indeo 3"),
  969. };