]> git.sesse.net Git - vlc/blobdiff - modules/codec/speex.c
Fix for [oCERT-2008-004] multiple speex implementations insufficient boundary checks...
[vlc] / modules / codec / speex.c
index e26ede384d3791ea6ae28753e9d8a89fbe6b1732..83890bbfd615920c33a21a8173c24526511062ac 100644 (file)
 /*****************************************************************************
  * Preamble
  *****************************************************************************/
+#ifdef HAVE_CONFIG_H
+# include "config.h"
+#endif
+
 #include <vlc/vlc.h>
 #include <vlc_input.h>
 #include <vlc_codec.h>
@@ -43,7 +47,7 @@
 struct decoder_sys_t
 {
     /* Module mode */
-    vlc_bool_t b_packetizer;
+    bool b_packetizer;
 
     /*
      * Input properties
@@ -58,6 +62,7 @@ struct decoder_sys_t
     SpeexHeader *p_header;
     SpeexStereoState stereo;
     void *p_state;
+    unsigned int rtp_rate;
 
     /*
      * Common properties
@@ -85,12 +90,13 @@ static int  OpenPacketizer( vlc_object_t * );
 static void CloseDecoder  ( vlc_object_t * );
 
 static void *DecodeBlock  ( decoder_t *, block_t ** );
+static aout_buffer_t *DecodeRtpSpeexPacket( decoder_t *, block_t **);
 static int  ProcessHeaders( decoder_t * );
 static int  ProcessInitialHeader ( decoder_t *, ogg_packet * );
 static void *ProcessPacket( decoder_t *, ogg_packet *, block_t ** );
 
 static aout_buffer_t *DecodePacket( decoder_t *, ogg_packet * );
-static block_t *SendPacket( decoder_t *, ogg_packet *, block_t * );
+static block_t *SendPacket( decoder_t *, block_t * );
 
 static void ParseSpeexComments( decoder_t *, ogg_packet * );
 
@@ -128,7 +134,8 @@ static int OpenDecoder( vlc_object_t *p_this )
     decoder_t *p_dec = (decoder_t*)p_this;
     decoder_sys_t *p_sys = p_dec->p_sys;
 
-    if( p_dec->fmt_in.i_codec != VLC_FOURCC('s','p','x',' ') )
+    if( p_dec->fmt_in.i_codec != VLC_FOURCC('s','p','x',' ') 
+        && p_dec->fmt_in.i_codec != VLC_FOURCC('s', 'p', 'x', 'r') )
     {
         return VLC_EGENERIC;
     }
@@ -140,7 +147,9 @@ static int OpenDecoder( vlc_object_t *p_this )
         msg_Err( p_dec, "out of memory" );
         return VLC_EGENERIC;
     }
-    p_dec->p_sys->b_packetizer = VLC_FALSE;
+    p_dec->p_sys->bits.buf_size = 0;
+    p_dec->p_sys->b_packetizer = false;
+    p_dec->p_sys->rtp_rate = p_dec->fmt_in.audio.i_rate;
 
     aout_DateSet( &p_sys->end_date, 0 );
 
@@ -148,9 +157,24 @@ static int OpenDecoder( vlc_object_t *p_this )
     p_dec->fmt_out.i_cat = AUDIO_ES;
     p_dec->fmt_out.i_codec = AOUT_FMT_S16_NE;
 
-    /* Set callbacks */
-    p_dec->pf_decode_audio = (aout_buffer_t *(*)(decoder_t *, block_t **))
-        DecodeBlock;
+    /*
+      Set callbacks
+      If the codec is spxr then this decoder is 
+      being invoked on a Speex stream arriving via RTP. 
+      A special decoder callback is used.
+    */
+    if (p_dec->fmt_in.i_codec == VLC_FOURCC('s', 'p', 'x', 'r'))
+    {
+        msg_Dbg( p_dec, "Using RTP version of Speex decoder @ rate %d.", 
+           p_dec->fmt_in.audio.i_rate );
+        p_dec->pf_decode_audio = (aout_buffer_t *(*)(decoder_t *, block_t **))
+            DecodeRtpSpeexPacket;
+    }
+    else
+    {
+        p_dec->pf_decode_audio = (aout_buffer_t *(*)(decoder_t *, block_t **))
+            DecodeBlock;
+    }
     p_dec->pf_packetize    = (block_t *(*)(decoder_t *, block_t **))
         DecodeBlock;
 
@@ -170,7 +194,7 @@ static int OpenPacketizer( vlc_object_t *p_this )
 
     if( i_ret == VLC_SUCCESS )
     {
-        p_dec->p_sys->b_packetizer = VLC_TRUE;
+        p_dec->p_sys->b_packetizer = true;
         p_dec->fmt_out.i_codec = VLC_FOURCC('s','p','x',' ');
     }
 
@@ -212,12 +236,10 @@ static void *DecodeBlock( decoder_t *p_dec, block_t **pp_block )
     /* Check for headers */
     if( p_sys->i_headers == 0 && p_dec->fmt_in.i_extra )
     {
-        /* Headers already available as extra data */
         p_sys->i_headers = 2;
     }
     else if( oggpacket.bytes && p_sys->i_headers < 2 )
     {
-        /* Backup headers as extra data */
         uint8_t *p_extra;
 
         p_dec->fmt_in.p_extra =
@@ -335,7 +357,7 @@ static int ProcessInitialHeader( decoder_t *p_dec, ogg_packet *p_oggpacket )
         msg_Err( p_dec, "cannot read Speex header" );
         return VLC_EGENERIC;
     }
-    if( p_header->mode >= SPEEX_NB_MODES )
+    if( p_header->mode >= SPEEX_NB_MODES || p_header->mode < 0 )
     {
         msg_Err( p_dec, "mode number %d does not (yet/any longer) exist in "
                  "this version of libspeex.", p_header->mode );
@@ -418,7 +440,7 @@ static void *ProcessPacket( decoder_t *p_dec, ogg_packet *p_oggpacket,
     block_t *p_block = *pp_block;
 
     /* Date management */
-    if( p_block && p_block->i_pts > 0 &&
+    if( p_block && p_block->i_pts > 0 && 
         p_block->i_pts != aout_DateGet( &p_sys->end_date ) )
     {
         aout_DateSet( &p_sys->end_date, p_block->i_pts );
@@ -435,7 +457,74 @@ static void *ProcessPacket( decoder_t *p_dec, ogg_packet *p_oggpacket,
 
     if( p_sys->b_packetizer )
     {
-         return SendPacket( p_dec, p_oggpacket, p_block );
+       if ( p_sys->p_header->frames_per_packet > 1 )
+       {
+           short *p_frame_holder = NULL;
+           int i_bits_before = 0, i_bits_after = 0, i_bytes_in_speex_frame = 0,
+               i_pcm_output_size = 0, i_bits_in_speex_frame = 0;
+           block_t *p_new_block = NULL;
+
+           i_pcm_output_size = p_sys->p_header->frame_size;
+           p_frame_holder = (short*)malloc( sizeof(short)*i_pcm_output_size );
+
+            speex_bits_read_from( &p_sys->bits, (char*)p_oggpacket->packet,
+               p_oggpacket->bytes);
+            i_bits_before = speex_bits_remaining( &p_sys->bits );
+           speex_decode_int(p_sys->p_state, &p_sys->bits, p_frame_holder);
+           i_bits_after = speex_bits_remaining( &p_sys->bits );
+
+            i_bits_in_speex_frame = i_bits_before - i_bits_after;
+           i_bytes_in_speex_frame = ( i_bits_in_speex_frame + 
+               (8 - (i_bits_in_speex_frame % 8)) )
+                / 8;
+
+            p_new_block = block_New( p_dec, i_bytes_in_speex_frame );
+           memset( p_new_block->p_buffer, 0xff, i_bytes_in_speex_frame );
+
+           /*
+            * Copy the first frame in this packet to a new packet.
+            */
+           speex_bits_rewind( &p_sys->bits );
+           speex_bits_write( &p_sys->bits, 
+               (char*)p_new_block->p_buffer, 
+                   (int)i_bytes_in_speex_frame );
+
+           /*
+            * Move the remaining part of the original packet (subsequent
+            * frames, if there are any) into the beginning 
+            * of the original packet so
+            * they are preserved following the realloc. 
+            * Note: Any bits that
+            * remain in the initial packet
+            * are "filler" if they do not constitute
+            * an entire byte. 
+            */
+           if ( i_bits_after > 7 )
+           {
+               /* round-down since we rounded-up earlier (to include
+                * the speex terminator code. 
+                */
+               i_bytes_in_speex_frame--;
+               speex_bits_write( &p_sys->bits, 
+                       (char*)p_block->p_buffer, 
+                       p_block->i_buffer - i_bytes_in_speex_frame );
+            p_block = block_Realloc( p_block, 
+                   0, 
+                       p_block->i_buffer-i_bytes_in_speex_frame );
+               *pp_block = p_block;
+           }
+           else
+           {
+               speex_bits_reset( &p_sys->bits );
+           }
+
+           free( p_frame_holder );
+           return SendPacket( p_dec, p_new_block);
+       }
+       else
+       {
+            return SendPacket( p_dec, p_block );
+       }
     }
     else
     {
@@ -451,6 +540,124 @@ static void *ProcessPacket( decoder_t *p_dec, ogg_packet *p_oggpacket,
     }
 }
 
+static aout_buffer_t *DecodeRtpSpeexPacket( decoder_t *p_dec, block_t **pp_block )
+{
+    block_t *p_speex_bit_block = *pp_block;
+    decoder_sys_t *p_sys = p_dec->p_sys;
+    aout_buffer_t *p_aout_buffer;
+    int i_decode_ret;
+    unsigned int i_speex_frame_size;
+
+    if ( !p_speex_bit_block || p_speex_bit_block->i_pts == 0 ) return NULL;
+
+    /* 
+      If the SpeexBits buffer size is 0 (a default value),
+      we know that a proper initialization has not yet been done.
+    */
+    if ( p_sys->bits.buf_size==0 )
+    {
+       p_sys->p_header = (SpeexHeader *)malloc(sizeof(SpeexHeader));
+       if ( !p_sys->p_header )
+       {
+           msg_Err( p_dec, "Could not allocate a Speex header.");
+           return NULL;
+       }
+       speex_init_header( p_sys->p_header,p_sys->rtp_rate,1,&speex_nb_mode );
+        speex_bits_init( &p_sys->bits );
+       p_sys->p_state = speex_decoder_init( &speex_nb_mode );
+       if ( !p_sys->p_state )
+       {
+           msg_Err( p_dec, "Could not allocate a Speex decoder." );
+           free( p_sys->p_header );
+           return NULL;
+       }
+
+        /*
+         Assume that variable bit rate is enabled. Also assume
+         that there is only one frame per packet. 
+       */
+       p_sys->p_header->vbr = 1;
+       p_sys->p_header->frames_per_packet = 1;
+
+        p_dec->fmt_out.audio.i_channels = p_sys->p_header->nb_channels;
+       p_dec->fmt_out.audio.i_physical_channels = 
+       p_dec->fmt_out.audio.i_original_channels = 
+           pi_channels_maps[p_sys->p_header->nb_channels];
+        p_dec->fmt_out.audio.i_rate = p_sys->p_header->rate;
+
+        if ( speex_mode_query( &speex_nb_mode, 
+           SPEEX_MODE_FRAME_SIZE, 
+           &i_speex_frame_size ) )
+       {
+           msg_Err( p_dec, "Could not determine the frame size." );
+           speex_decoder_destroy( p_sys->p_state );
+           free( p_sys->p_header );
+           return NULL;
+       }
+       p_dec->fmt_out.audio.i_bytes_per_frame = i_speex_frame_size;
+
+       aout_DateInit(&p_sys->end_date, p_sys->p_header->rate);
+    }
+
+    /* 
+      If the SpeexBits are initialized but there is 
+      still no header, an error must be thrown.
+    */
+    if ( !p_sys->p_header )
+    {
+        msg_Err( p_dec, "There is no valid Speex header found." );
+       return NULL;
+    }
+    *pp_block = NULL;
+
+    if ( !aout_DateGet( &p_sys->end_date ) )
+        aout_DateSet( &p_sys->end_date, p_speex_bit_block->i_dts );
+
+    /*
+      Ask for a new audio output buffer and make sure
+      we get one. 
+    */
+    p_aout_buffer = p_dec->pf_aout_buffer_new( p_dec, 
+        p_sys->p_header->frame_size );
+    if ( !p_aout_buffer || p_aout_buffer->i_nb_bytes == 0 )
+    {
+        msg_Err(p_dec, "Oops: No new buffer was returned!");
+       return NULL;
+    }
+
+    /*
+      Read the Speex payload into the SpeexBits buffer.
+    */
+    speex_bits_read_from( &p_sys->bits, 
+        (char*)p_speex_bit_block->p_buffer, 
+        p_speex_bit_block->i_buffer );
+    
+    /* 
+      Decode the input and ensure that no errors 
+      were encountered.
+    */
+    i_decode_ret = speex_decode_int( p_sys->p_state, &p_sys->bits, 
+            (int16_t*)p_aout_buffer->p_buffer );
+    if ( i_decode_ret < 0 )
+    {
+        msg_Err( p_dec, "Decoding failed. Perhaps we have a bad stream?" );
+       return NULL;
+    }
+
+    /* 
+      Handle date management on the audio output buffer. 
+    */
+    p_aout_buffer->start_date = aout_DateGet( &p_sys->end_date );
+    p_aout_buffer->end_date = aout_DateIncrement( &p_sys->end_date, 
+        p_sys->p_header->frame_size );
+    
+    
+    p_sys->i_frame_in_packet++;
+    block_Release( p_speex_bit_block );
+
+    return p_aout_buffer;
+}
+
 /*****************************************************************************
  * DecodePacket: decodes a Speex packet.
  *****************************************************************************/
@@ -470,7 +677,8 @@ static aout_buffer_t *DecodePacket( decoder_t *p_dec, ogg_packet *p_oggpacket )
     if( p_sys->i_frame_in_packet < p_sys->p_header->frames_per_packet )
     {
         aout_buffer_t *p_aout_buffer;
-        int i_ret;
+        if( p_sys->p_header->frame_size == 0 )
+            return NULL;
 
         p_aout_buffer =
             p_dec->pf_aout_buffer_new( p_dec, p_sys->p_header->frame_size );
@@ -479,23 +687,18 @@ static aout_buffer_t *DecodePacket( decoder_t *p_dec, ogg_packet *p_oggpacket )
             return NULL;
         }
 
-        i_ret = speex_decode_int( p_sys->p_state, &p_sys->bits,
-                                  (int16_t *)p_aout_buffer->p_buffer );
-        if( i_ret == -1 )
+        switch( speex_decode_int( p_sys->p_state, &p_sys->bits,
+                                  (int16_t *)p_aout_buffer->p_buffer ) )
         {
-            /* End of stream */
-            return NULL;
-        }
-
-        if( i_ret== -2 )
-        {
-            msg_Warn( p_dec, "decoding error: corrupted stream?" );
-            return NULL;
+            case -2:
+                msg_Err( p_dec, "decoding error: corrupted stream?" );
+            case -1: /* End of stream */
+                return NULL;
         }
 
         if( speex_bits_remaining( &p_sys->bits ) < 0 )
         {
-            msg_Warn( p_dec, "decoding overflow: corrupted stream?" );
+            msg_Err( p_dec, "decoding overflow: corrupted stream?" );
         }
 
         if( p_sys->p_header->nb_channels == 2 )
@@ -506,7 +709,7 @@ static aout_buffer_t *DecodePacket( decoder_t *p_dec, ogg_packet *p_oggpacket )
         /* Date management */
         p_aout_buffer->start_date = aout_DateGet( &p_sys->end_date );
         p_aout_buffer->end_date =
-            aout_DateIncrement( &p_sys->end_date, p_sys->p_header->frame_size);
+            aout_DateIncrement( &p_sys->end_date, p_sys->p_header->frame_size );
 
         p_sys->i_frame_in_packet++;
 
@@ -521,8 +724,7 @@ static aout_buffer_t *DecodePacket( decoder_t *p_dec, ogg_packet *p_oggpacket )
 /*****************************************************************************
  * SendPacket: send an ogg packet to the stream output.
  *****************************************************************************/
-static block_t *SendPacket( decoder_t *p_dec, ogg_packet *p_oggpacket,
-                            block_t *p_block )
+static block_t *SendPacket( decoder_t *p_dec, block_t *p_block )
 {
     decoder_sys_t *p_sys = p_dec->p_sys;
 
@@ -530,10 +732,12 @@ static block_t *SendPacket( decoder_t *p_dec, ogg_packet *p_oggpacket,
     p_block->i_dts = p_block->i_pts = aout_DateGet( &p_sys->end_date );
 
     if( p_sys->i_headers >= p_sys->p_header->extra_headers + 2 )
+    {
         p_block->i_length =
             aout_DateIncrement( &p_sys->end_date,
                                 p_sys->p_header->frame_size ) -
             p_block->i_pts;
+    }
     else
         p_block->i_length = 0;
 
@@ -570,14 +774,14 @@ static void ParseSpeexComments( decoder_t *p_dec, ogg_packet *p_oggpacket )
 
     if( p_oggpacket->bytes < 8 )
     {
-        msg_Warn( p_dec, "invalid/corrupted comments" );
+        msg_Err( p_dec, "invalid/corrupted comments" );
         return;
     }
 
     i_len = readint( p_buf, 0 ); p_buf += 4;
     if( i_len > p_oggpacket->bytes - 4 )
     {
-        msg_Warn( p_dec, "invalid/corrupted comments" );
+        msg_Err( p_dec, "invalid/corrupted comments" );
         return;
     }
 
@@ -600,7 +804,7 @@ static void CloseDecoder( vlc_object_t *p_this )
         speex_bits_destroy( &p_sys->bits );
     }
 
-    if( p_sys->p_header ) free( p_sys->p_header );
+    free( p_sys->p_header );
     free( p_sys );
 }
 
@@ -827,6 +1031,6 @@ static void CloseEncoder( vlc_object_t *p_this )
     speex_encoder_destroy( p_sys->p_state );
     speex_bits_destroy( &p_sys->bits );
 
-    if( p_sys->p_buffer ) free( p_sys->p_buffer );
+    free( p_sys->p_buffer );
     free( p_sys );
 }