2 * VMware Screen Codec (VMnc) decoder
3 * Copyright (c) 2006 Konstantin Shishkov
5 * This file is part of FFmpeg.
7 * FFmpeg is free software; you can redistribute it and/or
8 * modify it under the terms of the GNU Lesser General Public
9 * License as published by the Free Software Foundation; either
10 * version 2.1 of the License, or (at your option) any later version.
12 * FFmpeg is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
15 * Lesser General Public License for more details.
17 * You should have received a copy of the GNU Lesser General Public
18 * License along with FFmpeg; if not, write to the Free Software
19 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
24 * VMware Screen Codec (VMnc) decoder
25 * As Alex Beregszaszi discovered, this is effectively RFB data dump
31 #include "libavutil/common.h"
32 #include "libavutil/intreadwrite.h"
37 MAGIC_WMVd = 0x574D5664,
47 HT_RAW = 1, // tile is raw
48 HT_BKG = 2, // background color is present
49 HT_FG = 4, // foreground color is present
50 HT_SUB = 8, // subrects are present
51 HT_CLR = 16 // each subrect has own color
57 typedef struct VmncContext {
58 AVCodecContext *avctx;
71 uint8_t* curbits, *curmask;
75 /* read pixel value from stream */
76 static av_always_inline int vmnc_get_pixel(const uint8_t* buf, int bpp, int be) {
77 switch(bpp * 2 + be) {
80 case 4: return AV_RL16(buf);
81 case 5: return AV_RB16(buf);
82 case 8: return AV_RL32(buf);
83 case 9: return AV_RB32(buf);
88 static void load_cursor(VmncContext *c, const uint8_t *src)
91 const int bpp = c->bpp2;
92 uint8_t *dst8 = c->curbits;
93 uint16_t *dst16 = (uint16_t*)c->curbits;
94 uint32_t *dst32 = (uint32_t*)c->curbits;
96 for(j = 0; j < c->cur_h; j++) {
97 for(i = 0; i < c->cur_w; i++) {
98 p = vmnc_get_pixel(src, bpp, c->bigendian);
100 if(bpp == 1) *dst8++ = p;
101 if(bpp == 2) *dst16++ = p;
102 if(bpp == 4) *dst32++ = p;
106 dst16 = (uint16_t*)c->curmask;
107 dst32 = (uint32_t*)c->curmask;
108 for(j = 0; j < c->cur_h; j++) {
109 for(i = 0; i < c->cur_w; i++) {
110 p = vmnc_get_pixel(src, bpp, c->bigendian);
112 if(bpp == 1) *dst8++ = p;
113 if(bpp == 2) *dst16++ = p;
114 if(bpp == 4) *dst32++ = p;
119 static void put_cursor(uint8_t *dst, int stride, VmncContext *c, int dx, int dy)
124 if(c->width < c->cur_x + c->cur_w) w = c->width - c->cur_x;
126 if(c->height < c->cur_y + c->cur_h) h = c->height - c->cur_y;
138 if((w < 1) || (h < 1)) return;
139 dst += x * c->bpp2 + y * stride;
142 uint8_t* cd = c->curbits, *msk = c->curmask;
143 for(j = 0; j < h; j++) {
144 for(i = 0; i < w; i++)
145 dst[i] = (dst[i] & cd[i]) ^ msk[i];
150 } else if(c->bpp2 == 2) {
151 uint16_t* cd = (uint16_t*)c->curbits, *msk = (uint16_t*)c->curmask;
153 for(j = 0; j < h; j++) {
154 dst2 = (uint16_t*)dst;
155 for(i = 0; i < w; i++)
156 dst2[i] = (dst2[i] & cd[i]) ^ msk[i];
161 } else if(c->bpp2 == 4) {
162 uint32_t* cd = (uint32_t*)c->curbits, *msk = (uint32_t*)c->curmask;
164 for(j = 0; j < h; j++) {
165 dst2 = (uint32_t*)dst;
166 for(i = 0; i < w; i++)
167 dst2[i] = (dst2[i] & cd[i]) ^ msk[i];
175 /* fill rectangle with given color */
176 static av_always_inline void paint_rect(uint8_t *dst, int dx, int dy, int w, int h, int color, int bpp, int stride)
179 dst += dx * bpp + dy * stride;
181 for(j = 0; j < h; j++) {
182 memset(dst, color, w);
187 for(j = 0; j < h; j++) {
188 dst2 = (uint16_t*)dst;
189 for(i = 0; i < w; i++) {
196 for(j = 0; j < h; j++) {
197 dst2 = (uint32_t*)dst;
198 for(i = 0; i < w; i++) {
206 static av_always_inline void paint_raw(uint8_t *dst, int w, int h, const uint8_t* src, int bpp, int be, int stride)
209 for(j = 0; j < h; j++) {
210 for(i = 0; i < w; i++) {
211 p = vmnc_get_pixel(src, bpp, be);
218 ((uint16_t*)dst)[i] = p;
221 ((uint32_t*)dst)[i] = p;
229 static int decode_hextile(VmncContext *c, uint8_t* dst, const uint8_t* src, int ssize, int w, int h, int stride)
232 int bg = 0, fg = 0, rects, color, flags, xy, wh;
233 const int bpp = c->bpp2;
235 int bw = 16, bh = 16;
236 const uint8_t *ssrc=src;
238 for(j = 0; j < h; j += 16) {
241 if(j + 16 > h) bh = h - j;
242 for(i = 0; i < w; i += 16, dst2 += 16 * bpp) {
243 if(src - ssrc >= ssize) {
244 av_log(c->avctx, AV_LOG_ERROR, "Premature end of data!\n");
247 if(i + 16 > w) bw = w - i;
250 if(src - ssrc > ssize - bw * bh * bpp) {
251 av_log(c->avctx, AV_LOG_ERROR, "Premature end of data!\n");
254 paint_raw(dst2, bw, bh, src, bpp, c->bigendian, stride);
255 src += bw * bh * bpp;
258 bg = vmnc_get_pixel(src, bpp, c->bigendian); src += bpp;
261 fg = vmnc_get_pixel(src, bpp, c->bigendian); src += bpp;
266 color = !!(flags & HT_CLR);
268 paint_rect(dst2, 0, 0, bw, bh, bg, bpp, stride);
270 if(src - ssrc > ssize - rects * (color * bpp + 2)) {
271 av_log(c->avctx, AV_LOG_ERROR, "Premature end of data!\n");
274 for(k = 0; k < rects; k++) {
276 fg = vmnc_get_pixel(src, bpp, c->bigendian); src += bpp;
280 paint_rect(dst2, xy >> 4, xy & 0xF, (wh>>4)+1, (wh & 0xF)+1, fg, bpp, stride);
289 static int decode_frame(AVCodecContext *avctx, void *data, int *got_frame,
292 const uint8_t *buf = avpkt->data;
293 int buf_size = avpkt->size;
294 VmncContext * const c = avctx->priv_data;
296 const uint8_t *src = buf;
297 int dx, dy, w, h, depth, enc, chunks, res, size_left, ret;
298 AVFrame *frame = c->frame;
300 if ((ret = ff_reget_buffer(avctx, frame)) < 0)
303 frame->key_frame = 0;
304 frame->pict_type = AV_PICTURE_TYPE_P;
306 //restore screen after cursor
310 if(c->width < c->cur_x + w) w = c->width - c->cur_x;
312 if(c->height < c->cur_y + h) h = c->height - c->cur_y;
323 if((w > 0) && (h > 0)) {
324 outptr = frame->data[0] + dx * c->bpp2 + dy * frame->linesize[0];
325 for(i = 0; i < h; i++) {
326 memcpy(outptr, c->screendta + i * c->cur_w * c->bpp2, w * c->bpp2);
327 outptr += frame->linesize[0];
332 chunks = AV_RB16(src); src += 2;
334 if(buf_size - (src - buf) < 12) {
335 av_log(avctx, AV_LOG_ERROR, "Premature end of data!\n");
338 dx = AV_RB16(src); src += 2;
339 dy = AV_RB16(src); src += 2;
340 w = AV_RB16(src); src += 2;
341 h = AV_RB16(src); src += 2;
342 enc = AV_RB32(src); src += 4;
343 outptr = frame->data[0] + dx * c->bpp2 + dy * frame->linesize[0];
344 size_left = buf_size - (src - buf);
346 case MAGIC_WMVd: // cursor
347 if (w*(int64_t)h*c->bpp2 > INT_MAX/2 - 2) {
348 av_log(avctx, AV_LOG_ERROR, "dimensions too large\n");
349 return AVERROR_INVALIDDATA;
351 if(size_left < 2 + w * h * c->bpp2 * 2) {
352 av_log(avctx, AV_LOG_ERROR, "Premature end of data! (need %i got %i)\n", 2 + w * h * c->bpp2 * 2, size_left);
360 if((c->cur_hx > c->cur_w) || (c->cur_hy > c->cur_h)) {
361 av_log(avctx, AV_LOG_ERROR, "Cursor hot spot is not in image: %ix%i of %ix%i cursor size\n", c->cur_hx, c->cur_hy, c->cur_w, c->cur_h);
362 c->cur_hx = c->cur_hy = 0;
364 c->curbits = av_realloc_f(c->curbits, c->cur_w * c->cur_h, c->bpp2);
365 c->curmask = av_realloc_f(c->curmask, c->cur_w * c->cur_h, c->bpp2);
366 c->screendta = av_realloc_f(c->screendta, c->cur_w * c->cur_h, c->bpp2);
367 if (!c->curbits || !c->curmask || !c->screendta)
368 return AVERROR(ENOMEM);
370 src += w * h * c->bpp2 * 2;
372 case MAGIC_WMVe: // unknown
375 case MAGIC_WMVf: // update cursor position
376 c->cur_x = dx - c->cur_hx;
377 c->cur_y = dy - c->cur_hy;
379 case MAGIC_WMVg: // unknown
382 case MAGIC_WMVh: // unknown
385 case MAGIC_WMVi: // ServerInitialization struct
386 frame->key_frame = 1;
387 frame->pict_type = AV_PICTURE_TYPE_I;
389 if(depth != c->bpp) {
390 av_log(avctx, AV_LOG_INFO, "Depth mismatch. Container %i bpp, Frame data: %i bpp\n", c->bpp, depth);
393 c->bigendian = *src++;
394 if(c->bigendian & (~1)) {
395 av_log(avctx, AV_LOG_INFO, "Invalid header: bigendian flag = %i\n", c->bigendian);
398 //skip the rest of pixel format data
401 case MAGIC_WMVj: // unknown
404 case 0x00000000: // raw rectangle data
405 if((dx + w > c->width) || (dy + h > c->height)) {
406 av_log(avctx, AV_LOG_ERROR, "Incorrect frame size: %ix%i+%ix%i of %ix%i\n", w, h, dx, dy, c->width, c->height);
409 if(size_left < w * h * c->bpp2) {
410 av_log(avctx, AV_LOG_ERROR, "Premature end of data! (need %i got %i)\n", w * h * c->bpp2, size_left);
413 paint_raw(outptr, w, h, src, c->bpp2, c->bigendian, frame->linesize[0]);
414 src += w * h * c->bpp2;
416 case 0x00000005: // HexTile encoded rectangle
417 if((dx + w > c->width) || (dy + h > c->height)) {
418 av_log(avctx, AV_LOG_ERROR, "Incorrect frame size: %ix%i+%ix%i of %ix%i\n", w, h, dx, dy, c->width, c->height);
421 res = decode_hextile(c, outptr, src, size_left, w, h, frame->linesize[0]);
427 av_log(avctx, AV_LOG_ERROR, "Unsupported block type 0x%08X\n", enc);
428 chunks = 0; // leave chunks decoding loop
433 //save screen data before painting cursor
435 if(c->width < c->cur_x + w) w = c->width - c->cur_x;
437 if(c->height < c->cur_y + h) h = c->height - c->cur_y;
448 if((w > 0) && (h > 0)) {
449 outptr = frame->data[0] + dx * c->bpp2 + dy * frame->linesize[0];
450 for(i = 0; i < h; i++) {
451 memcpy(c->screendta + i * c->cur_w * c->bpp2, outptr, w * c->bpp2);
452 outptr += frame->linesize[0];
454 outptr = frame->data[0];
455 put_cursor(outptr, frame->linesize[0], c, c->cur_x, c->cur_y);
459 if ((ret = av_frame_ref(data, frame)) < 0)
462 /* always report that the buffer was completely consumed */
473 static av_cold int decode_init(AVCodecContext *avctx)
475 VmncContext * const c = avctx->priv_data;
479 c->width = avctx->width;
480 c->height = avctx->height;
482 c->bpp = avctx->bits_per_coded_sample;
487 avctx->pix_fmt = AV_PIX_FMT_PAL8;
490 avctx->pix_fmt = AV_PIX_FMT_RGB555;
493 avctx->pix_fmt = AV_PIX_FMT_RGB32;
496 av_log(avctx, AV_LOG_ERROR, "Unsupported bitdepth %i\n", c->bpp);
497 return AVERROR_INVALIDDATA;
500 c->frame = av_frame_alloc();
502 return AVERROR(ENOMEM);
511 * Uninit VMnc decoder
514 static av_cold int decode_end(AVCodecContext *avctx)
516 VmncContext * const c = avctx->priv_data;
518 av_frame_free(&c->frame);
522 av_free(c->screendta);
526 AVCodec ff_vmnc_decoder = {
528 .type = AVMEDIA_TYPE_VIDEO,
529 .id = AV_CODEC_ID_VMNC,
530 .priv_data_size = sizeof(VmncContext),
533 .decode = decode_frame,
534 .capabilities = CODEC_CAP_DR1,
535 .long_name = NULL_IF_CONFIG_SMALL("VMware Screen Codec / VMware Video"),