]> git.sesse.net Git - vlc/blobdiff - modules/codec/speex.c
Fix for [oCERT-2008-004] multiple speex implementations insufficient boundary checks...
[vlc] / modules / codec / speex.c
old mode 100755 (executable)
new mode 100644 (file)
index f201863..83890bb
@@ -1,7 +1,7 @@
 /*****************************************************************************
  * speex.c: speex decoder/packetizer/encoder module making use of libspeex.
  *****************************************************************************
- * Copyright (C) 2003 VideoLAN
+ * Copyright (C) 2003 the VideoLAN team
  * $Id$
  *
  * Authors: Gildas Bazin <gbazin@videolan.org>
  *
  * You should have received a copy of the GNU General Public License
  * along with this program; if not, write to the Free Software
- * Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA  02111, USA.
+ * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston MA 02110-1301, USA.
  *****************************************************************************/
 
 /*****************************************************************************
  * Preamble
  *****************************************************************************/
+#ifdef HAVE_CONFIG_H
+# include "config.h"
+#endif
+
 #include <vlc/vlc.h>
-#include <vlc/decoder.h>
+#include <vlc_input.h>
+#include <vlc_codec.h>
+#include <vlc_aout.h>
 
 #include <ogg/ogg.h>
-#include <speex.h>
-#include "speex_header.h"
-#include "speex_stereo.h"
-#include "speex_callbacks.h"
+#include <speex/speex.h>
+#include <speex/speex_header.h>
+#include <speex/speex_stereo.h>
+#include <speex/speex_callbacks.h>
+
+#include <assert.h>
 
 /*****************************************************************************
  * decoder_sys_t : speex decoder descriptor
@@ -39,7 +47,7 @@
 struct decoder_sys_t
 {
     /* Module mode */
-    vlc_bool_t b_packetizer;
+    bool b_packetizer;
 
     /*
      * Input properties
@@ -54,6 +62,7 @@ struct decoder_sys_t
     SpeexHeader *p_header;
     SpeexStereoState stereo;
     void *p_state;
+    unsigned int rtp_rate;
 
     /*
      * Common properties
@@ -81,23 +90,27 @@ static int  OpenPacketizer( vlc_object_t * );
 static void CloseDecoder  ( vlc_object_t * );
 
 static void *DecodeBlock  ( decoder_t *, block_t ** );
-static int  ProcessHeader ( decoder_t *, ogg_packet * );
+static aout_buffer_t *DecodeRtpSpeexPacket( decoder_t *, block_t **);
+static int  ProcessHeaders( decoder_t * );
+static int  ProcessInitialHeader ( decoder_t *, ogg_packet * );
 static void *ProcessPacket( decoder_t *, ogg_packet *, block_t ** );
 
 static aout_buffer_t *DecodePacket( decoder_t *, ogg_packet * );
-static block_t *SendPacket( decoder_t *, ogg_packet *, block_t * );
+static block_t *SendPacket( decoder_t *, block_t * );
 
 static void ParseSpeexComments( decoder_t *, ogg_packet * );
 
 static int OpenEncoder   ( vlc_object_t * );
 static void CloseEncoder ( vlc_object_t * );
-static block_t *Headers  ( encoder_t * );
 static block_t *Encode   ( encoder_t *, aout_buffer_t * );
 
 /*****************************************************************************
  * Module descriptor
  *****************************************************************************/
 vlc_module_begin();
+    set_category( CAT_INPUT );
+    set_subcategory( SUBCAT_INPUT_ACODEC );
+
     set_description( _("Speex audio decoder") );
     set_capability( "decoder", 100 );
     set_callbacks( OpenDecoder, CloseDecoder );
@@ -121,7 +134,8 @@ static int OpenDecoder( vlc_object_t *p_this )
     decoder_t *p_dec = (decoder_t*)p_this;
     decoder_sys_t *p_sys = p_dec->p_sys;
 
-    if( p_dec->fmt_in.i_codec != VLC_FOURCC('s','p','x',' ') )
+    if( p_dec->fmt_in.i_codec != VLC_FOURCC('s','p','x',' ') 
+        && p_dec->fmt_in.i_codec != VLC_FOURCC('s', 'p', 'x', 'r') )
     {
         return VLC_EGENERIC;
     }
@@ -133,7 +147,9 @@ static int OpenDecoder( vlc_object_t *p_this )
         msg_Err( p_dec, "out of memory" );
         return VLC_EGENERIC;
     }
-    p_dec->p_sys->b_packetizer = VLC_FALSE;
+    p_dec->p_sys->bits.buf_size = 0;
+    p_dec->p_sys->b_packetizer = false;
+    p_dec->p_sys->rtp_rate = p_dec->fmt_in.audio.i_rate;
 
     aout_DateSet( &p_sys->end_date, 0 );
 
@@ -141,9 +157,24 @@ static int OpenDecoder( vlc_object_t *p_this )
     p_dec->fmt_out.i_cat = AUDIO_ES;
     p_dec->fmt_out.i_codec = AOUT_FMT_S16_NE;
 
-    /* Set callbacks */
-    p_dec->pf_decode_audio = (aout_buffer_t *(*)(decoder_t *, block_t **))
-        DecodeBlock;
+    /*
+      Set callbacks
+      If the codec is spxr then this decoder is 
+      being invoked on a Speex stream arriving via RTP. 
+      A special decoder callback is used.
+    */
+    if (p_dec->fmt_in.i_codec == VLC_FOURCC('s', 'p', 'x', 'r'))
+    {
+        msg_Dbg( p_dec, "Using RTP version of Speex decoder @ rate %d.", 
+           p_dec->fmt_in.audio.i_rate );
+        p_dec->pf_decode_audio = (aout_buffer_t *(*)(decoder_t *, block_t **))
+            DecodeRtpSpeexPacket;
+    }
+    else
+    {
+        p_dec->pf_decode_audio = (aout_buffer_t *(*)(decoder_t *, block_t **))
+            DecodeBlock;
+    }
     p_dec->pf_packetize    = (block_t *(*)(decoder_t *, block_t **))
         DecodeBlock;
 
@@ -163,7 +194,7 @@ static int OpenPacketizer( vlc_object_t *p_this )
 
     if( i_ret == VLC_SUCCESS )
     {
-        p_dec->p_sys->b_packetizer = VLC_TRUE;
+        p_dec->p_sys->b_packetizer = true;
         p_dec->fmt_out.i_codec = VLC_FOURCC('s','p','x',' ');
     }
 
@@ -202,53 +233,131 @@ static void *DecodeBlock( decoder_t *p_dec, block_t **pp_block )
     oggpacket.e_o_s = 0;
     oggpacket.packetno = 0;
 
-    if( p_sys->i_headers == 0 )
+    /* Check for headers */
+    if( p_sys->i_headers == 0 && p_dec->fmt_in.i_extra )
+    {
+        p_sys->i_headers = 2;
+    }
+    else if( oggpacket.bytes && p_sys->i_headers < 2 )
+    {
+        uint8_t *p_extra;
+
+        p_dec->fmt_in.p_extra =
+            realloc( p_dec->fmt_in.p_extra, p_dec->fmt_in.i_extra +
+                     oggpacket.bytes + 2 );
+        p_extra = ((uint8_t *)p_dec->fmt_in.p_extra) + p_dec->fmt_in.i_extra;
+        *(p_extra++) = oggpacket.bytes >> 8;
+        *(p_extra++) = oggpacket.bytes & 0xFF;
+
+        memcpy( p_extra, oggpacket.packet, oggpacket.bytes );
+        p_dec->fmt_in.i_extra += oggpacket.bytes + 2;
+
+        block_Release( *pp_block );
+        p_sys->i_headers++;
+        return NULL;
+    }
+
+    if( p_sys->i_headers == 2 )
     {
-        /* Take care of the initial Speex header */
-        if( ProcessHeader( p_dec, &oggpacket ) != VLC_SUCCESS )
+        if( ProcessHeaders( p_dec ) != VLC_SUCCESS )
         {
-            msg_Err( p_dec, "initial Speex header is corrupted" );
+            p_sys->i_headers = 0;
+            p_dec->fmt_in.i_extra = 0;
             block_Release( *pp_block );
             return NULL;
         }
+        else p_sys->i_headers++;
+    }
 
-        p_sys->i_headers++;
+    return ProcessPacket( p_dec, &oggpacket, pp_block );
+}
 
-        return ProcessPacket( p_dec, &oggpacket, pp_block );
+/*****************************************************************************
+ * ProcessHeaders: process Speex headers.
+ *****************************************************************************/
+static int ProcessHeaders( decoder_t *p_dec )
+{
+    decoder_sys_t *p_sys = p_dec->p_sys;
+    ogg_packet oggpacket;
+    uint8_t *p_extra;
+    int i_extra;
+
+    if( !p_dec->fmt_in.i_extra ) return VLC_EGENERIC;
+
+    oggpacket.granulepos = -1;
+    oggpacket.b_o_s = 1; /* yes this actually is a b_o_s packet :) */
+    oggpacket.e_o_s = 0;
+    oggpacket.packetno = 0;
+    p_extra = p_dec->fmt_in.p_extra;
+    i_extra = p_dec->fmt_in.i_extra;
+
+    /* Take care of the initial Vorbis header */
+    oggpacket.bytes = *(p_extra++) << 8;
+    oggpacket.bytes |= (*(p_extra++) & 0xFF);
+    oggpacket.packet = p_extra;
+    p_extra += oggpacket.bytes;
+    i_extra -= (oggpacket.bytes + 2);
+    if( i_extra < 0 )
+    {
+        msg_Err( p_dec, "header data corrupted");
+        return VLC_EGENERIC;
     }
 
-    if( p_sys->i_headers == 1 )
+    /* Take care of the initial Speex header */
+    if( ProcessInitialHeader( p_dec, &oggpacket ) != VLC_SUCCESS )
     {
-        /* The next packet in order is the comments header */
-        ParseSpeexComments( p_dec, &oggpacket );
-        p_sys->i_headers++;
+        msg_Err( p_dec, "initial Speex header is corrupted" );
+        return VLC_EGENERIC;
+    }
 
-        return ProcessPacket( p_dec, &oggpacket, pp_block );
+    /* The next packet in order is the comments header */
+    oggpacket.b_o_s = 0;
+    oggpacket.bytes = *(p_extra++) << 8;
+    oggpacket.bytes |= (*(p_extra++) & 0xFF);
+    oggpacket.packet = p_extra;
+    p_extra += oggpacket.bytes;
+    i_extra -= (oggpacket.bytes + 2);
+    if( i_extra < 0 )
+    {
+        msg_Err( p_dec, "header data corrupted");
+        return VLC_EGENERIC;
     }
 
-    return ProcessPacket( p_dec, &oggpacket, pp_block );
+    ParseSpeexComments( p_dec, &oggpacket );
+
+    if( p_sys->b_packetizer )
+    {
+        p_dec->fmt_out.i_extra = p_dec->fmt_in.i_extra;
+        p_dec->fmt_out.p_extra =
+            realloc( p_dec->fmt_out.p_extra, p_dec->fmt_out.i_extra );
+        memcpy( p_dec->fmt_out.p_extra,
+                p_dec->fmt_in.p_extra, p_dec->fmt_out.i_extra );
+    }
+
+    return VLC_SUCCESS;
 }
 
 /*****************************************************************************
- * ProcessHeader: processes the inital Speex header packet.
+ * ProcessInitialHeader: processes the inital Speex header packet.
  *****************************************************************************/
-static int ProcessHeader( decoder_t *p_dec, ogg_packet *p_oggpacket )
+static int ProcessInitialHeader( decoder_t *p_dec, ogg_packet *p_oggpacket )
 {
     decoder_sys_t *p_sys = p_dec->p_sys;
 
     void *p_state;
     SpeexHeader *p_header;
-    SpeexMode *p_mode;
+    const SpeexMode *p_mode;
     SpeexCallback callback;
 
     p_sys->p_header = p_header =
-        speex_packet_to_header( p_oggpacket->packet, p_oggpacket->bytes );
+        speex_packet_to_header( (char *)p_oggpacket->packet,
+                                p_oggpacket->bytes );
     if( !p_header )
     {
         msg_Err( p_dec, "cannot read Speex header" );
         return VLC_EGENERIC;
     }
-    if( p_header->mode >= SPEEX_NB_MODES )
+    if( p_header->mode >= SPEEX_NB_MODES || p_header->mode < 0 )
     {
         msg_Err( p_dec, "mode number %d does not (yet/any longer) exist in "
                  "this version of libspeex.", p_header->mode );
@@ -256,11 +365,13 @@ static int ProcessHeader( decoder_t *p_dec, ogg_packet *p_oggpacket )
     }
 
     p_mode = speex_mode_list[p_header->mode];
+    if( p_mode == NULL )
+        return VLC_EGENERIC;
 
     if( p_header->speex_version_id > 1 )
     {
         msg_Err( p_dec, "this file was encoded with Speex bit-stream "
-                 "version %d, which I don't know how to decode.",
+                 "version %d which is not supported by this decoder.",
                  p_header->speex_version_id );
         return VLC_EGENERIC;
     }
@@ -299,6 +410,13 @@ static int ProcessHeader( decoder_t *p_dec, ogg_packet *p_oggpacket )
         callback.data = &p_sys->stereo;
         speex_decoder_ctl( p_state, SPEEX_SET_HANDLER, &callback );
     }
+    if( p_header->nb_channels <= 0 ||
+        p_header->nb_channels > 5 )
+    {
+        msg_Err( p_dec, "invalid number of channels (not between 1 and 5): %i",
+                 p_header->nb_channels );
+        return VLC_EGENERIC;
+    }
 
     /* Setup the format */
     p_dec->fmt_out.audio.i_physical_channels =
@@ -322,7 +440,7 @@ static void *ProcessPacket( decoder_t *p_dec, ogg_packet *p_oggpacket,
     block_t *p_block = *pp_block;
 
     /* Date management */
-    if( p_block && p_block->i_pts > 0 &&
+    if( p_block && p_block->i_pts > 0 && 
         p_block->i_pts != aout_DateGet( &p_sys->end_date ) )
     {
         aout_DateSet( &p_sys->end_date, p_block->i_pts );
@@ -339,7 +457,74 @@ static void *ProcessPacket( decoder_t *p_dec, ogg_packet *p_oggpacket,
 
     if( p_sys->b_packetizer )
     {
-         return SendPacket( p_dec, p_oggpacket, p_block );
+       if ( p_sys->p_header->frames_per_packet > 1 )
+       {
+           short *p_frame_holder = NULL;
+           int i_bits_before = 0, i_bits_after = 0, i_bytes_in_speex_frame = 0,
+               i_pcm_output_size = 0, i_bits_in_speex_frame = 0;
+           block_t *p_new_block = NULL;
+
+           i_pcm_output_size = p_sys->p_header->frame_size;
+           p_frame_holder = (short*)malloc( sizeof(short)*i_pcm_output_size );
+
+            speex_bits_read_from( &p_sys->bits, (char*)p_oggpacket->packet,
+               p_oggpacket->bytes);
+            i_bits_before = speex_bits_remaining( &p_sys->bits );
+           speex_decode_int(p_sys->p_state, &p_sys->bits, p_frame_holder);
+           i_bits_after = speex_bits_remaining( &p_sys->bits );
+
+            i_bits_in_speex_frame = i_bits_before - i_bits_after;
+           i_bytes_in_speex_frame = ( i_bits_in_speex_frame + 
+               (8 - (i_bits_in_speex_frame % 8)) )
+                / 8;
+
+            p_new_block = block_New( p_dec, i_bytes_in_speex_frame );
+           memset( p_new_block->p_buffer, 0xff, i_bytes_in_speex_frame );
+
+           /*
+            * Copy the first frame in this packet to a new packet.
+            */
+           speex_bits_rewind( &p_sys->bits );
+           speex_bits_write( &p_sys->bits, 
+               (char*)p_new_block->p_buffer, 
+                   (int)i_bytes_in_speex_frame );
+
+           /*
+            * Move the remaining part of the original packet (subsequent
+            * frames, if there are any) into the beginning 
+            * of the original packet so
+            * they are preserved following the realloc. 
+            * Note: Any bits that
+            * remain in the initial packet
+            * are "filler" if they do not constitute
+            * an entire byte. 
+            */
+           if ( i_bits_after > 7 )
+           {
+               /* round-down since we rounded-up earlier (to include
+                * the speex terminator code. 
+                */
+               i_bytes_in_speex_frame--;
+               speex_bits_write( &p_sys->bits, 
+                       (char*)p_block->p_buffer, 
+                       p_block->i_buffer - i_bytes_in_speex_frame );
+            p_block = block_Realloc( p_block, 
+                   0, 
+                       p_block->i_buffer-i_bytes_in_speex_frame );
+               *pp_block = p_block;
+           }
+           else
+           {
+               speex_bits_reset( &p_sys->bits );
+           }
+
+           free( p_frame_holder );
+           return SendPacket( p_dec, p_new_block);
+       }
+       else
+       {
+            return SendPacket( p_dec, p_block );
+       }
     }
     else
     {
@@ -350,14 +535,129 @@ static void *ProcessPacket( decoder_t *p_dec, ogg_packet *p_oggpacket,
         else
             p_aout_buffer = NULL; /* Skip headers */
 
-        if( p_block )
-        {
-            block_Release( p_block );
-        }
+        if( p_block ) block_Release( p_block );
         return p_aout_buffer;
     }
 }
 
+static aout_buffer_t *DecodeRtpSpeexPacket( decoder_t *p_dec, block_t **pp_block )
+{
+    block_t *p_speex_bit_block = *pp_block;
+    decoder_sys_t *p_sys = p_dec->p_sys;
+    aout_buffer_t *p_aout_buffer;
+    int i_decode_ret;
+    unsigned int i_speex_frame_size;
+
+    if ( !p_speex_bit_block || p_speex_bit_block->i_pts == 0 ) return NULL;
+
+    /* 
+      If the SpeexBits buffer size is 0 (a default value),
+      we know that a proper initialization has not yet been done.
+    */
+    if ( p_sys->bits.buf_size==0 )
+    {
+       p_sys->p_header = (SpeexHeader *)malloc(sizeof(SpeexHeader));
+       if ( !p_sys->p_header )
+       {
+           msg_Err( p_dec, "Could not allocate a Speex header.");
+           return NULL;
+       }
+       speex_init_header( p_sys->p_header,p_sys->rtp_rate,1,&speex_nb_mode );
+        speex_bits_init( &p_sys->bits );
+       p_sys->p_state = speex_decoder_init( &speex_nb_mode );
+       if ( !p_sys->p_state )
+       {
+           msg_Err( p_dec, "Could not allocate a Speex decoder." );
+           free( p_sys->p_header );
+           return NULL;
+       }
+
+        /*
+         Assume that variable bit rate is enabled. Also assume
+         that there is only one frame per packet. 
+       */
+       p_sys->p_header->vbr = 1;
+       p_sys->p_header->frames_per_packet = 1;
+
+        p_dec->fmt_out.audio.i_channels = p_sys->p_header->nb_channels;
+       p_dec->fmt_out.audio.i_physical_channels = 
+       p_dec->fmt_out.audio.i_original_channels = 
+           pi_channels_maps[p_sys->p_header->nb_channels];
+        p_dec->fmt_out.audio.i_rate = p_sys->p_header->rate;
+
+        if ( speex_mode_query( &speex_nb_mode, 
+           SPEEX_MODE_FRAME_SIZE, 
+           &i_speex_frame_size ) )
+       {
+           msg_Err( p_dec, "Could not determine the frame size." );
+           speex_decoder_destroy( p_sys->p_state );
+           free( p_sys->p_header );
+           return NULL;
+       }
+       p_dec->fmt_out.audio.i_bytes_per_frame = i_speex_frame_size;
+
+       aout_DateInit(&p_sys->end_date, p_sys->p_header->rate);
+    }
+
+    /* 
+      If the SpeexBits are initialized but there is 
+      still no header, an error must be thrown.
+    */
+    if ( !p_sys->p_header )
+    {
+        msg_Err( p_dec, "There is no valid Speex header found." );
+       return NULL;
+    }
+    *pp_block = NULL;
+
+    if ( !aout_DateGet( &p_sys->end_date ) )
+        aout_DateSet( &p_sys->end_date, p_speex_bit_block->i_dts );
+
+    /*
+      Ask for a new audio output buffer and make sure
+      we get one. 
+    */
+    p_aout_buffer = p_dec->pf_aout_buffer_new( p_dec, 
+        p_sys->p_header->frame_size );
+    if ( !p_aout_buffer || p_aout_buffer->i_nb_bytes == 0 )
+    {
+        msg_Err(p_dec, "Oops: No new buffer was returned!");
+       return NULL;
+    }
+
+    /*
+      Read the Speex payload into the SpeexBits buffer.
+    */
+    speex_bits_read_from( &p_sys->bits, 
+        (char*)p_speex_bit_block->p_buffer, 
+        p_speex_bit_block->i_buffer );
+    
+    /* 
+      Decode the input and ensure that no errors 
+      were encountered.
+    */
+    i_decode_ret = speex_decode_int( p_sys->p_state, &p_sys->bits, 
+            (int16_t*)p_aout_buffer->p_buffer );
+    if ( i_decode_ret < 0 )
+    {
+        msg_Err( p_dec, "Decoding failed. Perhaps we have a bad stream?" );
+       return NULL;
+    }
+
+    /* 
+      Handle date management on the audio output buffer. 
+    */
+    p_aout_buffer->start_date = aout_DateGet( &p_sys->end_date );
+    p_aout_buffer->end_date = aout_DateIncrement( &p_sys->end_date, 
+        p_sys->p_header->frame_size );
+    
+    
+    p_sys->i_frame_in_packet++;
+    block_Release( p_speex_bit_block );
+
+    return p_aout_buffer;
+}
+
 /*****************************************************************************
  * DecodePacket: decodes a Speex packet.
  *****************************************************************************/
@@ -368,7 +668,7 @@ static aout_buffer_t *DecodePacket( decoder_t *p_dec, ogg_packet *p_oggpacket )
     if( p_oggpacket->bytes )
     {
         /* Copy Ogg packet to Speex bitstream */
-        speex_bits_read_from( &p_sys->bits, p_oggpacket->packet,
+        speex_bits_read_from( &p_sys->bits, (char *)p_oggpacket->packet,
                               p_oggpacket->bytes );
         p_sys->i_frame_in_packet = 0;
     }
@@ -377,7 +677,8 @@ static aout_buffer_t *DecodePacket( decoder_t *p_dec, ogg_packet *p_oggpacket )
     if( p_sys->i_frame_in_packet < p_sys->p_header->frames_per_packet )
     {
         aout_buffer_t *p_aout_buffer;
-        int i_ret;
+        if( p_sys->p_header->frame_size == 0 )
+            return NULL;
 
         p_aout_buffer =
             p_dec->pf_aout_buffer_new( p_dec, p_sys->p_header->frame_size );
@@ -386,33 +687,29 @@ static aout_buffer_t *DecodePacket( decoder_t *p_dec, ogg_packet *p_oggpacket )
             return NULL;
         }
 
-        i_ret = speex_decode( p_sys->p_state, &p_sys->bits,
-                              (int16_t *)p_aout_buffer->p_buffer );
-        if( i_ret == -1 )
-        {
-            /* End of stream */
-            return NULL;
-        }
-
-        if( i_ret== -2 )
+        switch( speex_decode_int( p_sys->p_state, &p_sys->bits,
+                                  (int16_t *)p_aout_buffer->p_buffer ) )
         {
-            msg_Warn( p_dec, "decoding error: corrupted stream?" );
-            return NULL;
+            case -2:
+                msg_Err( p_dec, "decoding error: corrupted stream?" );
+            case -1: /* End of stream */
+                return NULL;
         }
 
         if( speex_bits_remaining( &p_sys->bits ) < 0 )
         {
-            msg_Warn( p_dec, "decoding overflow: corrupted stream?" );
+            msg_Err( p_dec, "decoding overflow: corrupted stream?" );
         }
 
         if( p_sys->p_header->nb_channels == 2 )
-            speex_decode_stereo( (int16_t *)p_aout_buffer->p_buffer,
-                                 p_sys->p_header->frame_size, &p_sys->stereo );
+            speex_decode_stereo_int( (int16_t *)p_aout_buffer->p_buffer,
+                                     p_sys->p_header->frame_size,
+                                     &p_sys->stereo );
 
         /* Date management */
         p_aout_buffer->start_date = aout_DateGet( &p_sys->end_date );
         p_aout_buffer->end_date =
-            aout_DateIncrement( &p_sys->end_date, p_sys->p_header->frame_size);
+            aout_DateIncrement( &p_sys->end_date, p_sys->p_header->frame_size );
 
         p_sys->i_frame_in_packet++;
 
@@ -427,8 +724,7 @@ static aout_buffer_t *DecodePacket( decoder_t *p_dec, ogg_packet *p_oggpacket )
 /*****************************************************************************
  * SendPacket: send an ogg packet to the stream output.
  *****************************************************************************/
-static block_t *SendPacket( decoder_t *p_dec, ogg_packet *p_oggpacket,
-                            block_t *p_block )
+static block_t *SendPacket( decoder_t *p_dec, block_t *p_block )
 {
     decoder_sys_t *p_sys = p_dec->p_sys;
 
@@ -436,10 +732,12 @@ static block_t *SendPacket( decoder_t *p_dec, ogg_packet *p_oggpacket,
     p_block->i_dts = p_block->i_pts = aout_DateGet( &p_sys->end_date );
 
     if( p_sys->i_headers >= p_sys->p_header->extra_headers + 2 )
+    {
         p_block->i_length =
             aout_DateIncrement( &p_sys->end_date,
                                 p_sys->p_header->frame_size ) -
             p_block->i_pts;
+    }
     else
         p_block->i_length = 0;
 
@@ -460,10 +758,15 @@ static void ParseSpeexComments( decoder_t *p_dec, ogg_packet *p_oggpacket )
     decoder_sys_t *p_sys = p_dec->p_sys;
 
     char *p_buf = (char *)p_oggpacket->packet;
-    SpeexMode *p_mode;
+    const SpeexMode *p_mode;
     int i_len;
 
+    if( p_input->i_object_type != VLC_OBJECT_INPUT ) return;
+
+    assert( p_sys->p_header->mode < SPEEX_NB_MODES );
+
     p_mode = speex_mode_list[p_sys->p_header->mode];
+    assert( p_mode != NULL );
 
     input_Control( p_input, INPUT_ADD_INFO, _("Speex comment"), _("Mode"),
                    "%s%s", p_mode->modeName,
@@ -471,14 +774,14 @@ static void ParseSpeexComments( decoder_t *p_dec, ogg_packet *p_oggpacket )
 
     if( p_oggpacket->bytes < 8 )
     {
-        msg_Warn( p_dec, "invalid/corrupted comments" );
+        msg_Err( p_dec, "invalid/corrupted comments" );
         return;
     }
 
     i_len = readint( p_buf, 0 ); p_buf += 4;
     if( i_len > p_oggpacket->bytes - 4 )
     {
-        msg_Warn( p_dec, "invalid/corrupted comments" );
+        msg_Err( p_dec, "invalid/corrupted comments" );
         return;
     }
 
@@ -501,7 +804,7 @@ static void CloseDecoder( vlc_object_t *p_this )
         speex_bits_destroy( &p_sys->bits );
     }
 
-    if( p_sys->p_header ) free( p_sys->p_header );
+    free( p_sys->p_header );
     free( p_sys );
 }
 
@@ -516,10 +819,8 @@ struct encoder_sys_t
     /*
      * Input properties
      */
-    int i_headers;
-
     char *p_buffer;
-    char *p_buffer_out[MAX_FRAME_BYTES];
+    char p_buffer_out[MAX_FRAME_BYTES];
 
     /*
      * Speex properties
@@ -549,10 +850,14 @@ static int OpenEncoder( vlc_object_t *p_this )
 {
     encoder_t *p_enc = (encoder_t *)p_this;
     encoder_sys_t *p_sys;
-    SpeexMode *p_speex_mode = &speex_nb_mode;
-    int i_quality;
-
-    if( p_enc->fmt_out.i_codec != VLC_FOURCC('s','p','x',' ') )
+    const SpeexMode *p_speex_mode = &speex_nb_mode;
+    int i_quality, i;
+    const char *pp_header[2];
+    int pi_header[2];
+    uint8_t *p_extra;
+
+    if( p_enc->fmt_out.i_codec != VLC_FOURCC('s','p','x',' ') &&
+        !p_enc->b_force )
     {
         return VLC_EGENERIC;
     }
@@ -564,9 +869,9 @@ static int OpenEncoder( vlc_object_t *p_this )
         return VLC_EGENERIC;
     }
     p_enc->p_sys = p_sys;
-    p_enc->pf_header = Headers;
     p_enc->pf_encode_audio = Encode;
     p_enc->fmt_in.i_codec = AOUT_FMT_S16_NE;
+    p_enc->fmt_out.i_codec = VLC_FOURCC('s','p','x',' ');
 
     speex_init_header( &p_sys->header, p_enc->fmt_in.audio.i_rate,
                        1, p_speex_mode );
@@ -587,7 +892,6 @@ static int OpenEncoder( vlc_object_t *p_this )
 
     p_sys->i_frames_in_packet = 0;
     p_sys->i_samples_delay = 0;
-    p_sys->i_headers = 0;
     p_sys->i_pts = 0;
 
     speex_encoder_ctl( p_sys->p_state, SPEEX_GET_FRAME_SIZE,
@@ -597,6 +901,21 @@ static int OpenEncoder( vlc_object_t *p_this )
         sizeof(int16_t) * p_enc->fmt_in.audio.i_channels;
     p_sys->p_buffer = malloc( p_sys->i_frame_size );
 
+    /* Create and store headers */
+    pp_header[0] = speex_header_to_packet( &p_sys->header, &pi_header[0] );
+    pp_header[1] = "ENCODER=VLC media player";
+    pi_header[1] = sizeof("ENCODER=VLC media player");
+
+    p_enc->fmt_out.i_extra = 3 * 2 + pi_header[0] + pi_header[1];
+    p_extra = p_enc->fmt_out.p_extra = malloc( p_enc->fmt_out.i_extra );
+    for( i = 0; i < 2; i++ )
+    {
+        *(p_extra++) = pi_header[i] >> 8;
+        *(p_extra++) = pi_header[i] & 0xFF;
+        memcpy( p_extra, pp_header[i], pi_header[i] );
+        p_extra += pi_header[i];
+    }
+
     msg_Dbg( p_enc, "encoding: frame size:%d, channels:%d, samplerate:%d",
              p_sys->i_frame_size, p_enc->fmt_in.audio.i_channels,
              p_enc->fmt_in.audio.i_rate );
@@ -604,42 +923,6 @@ static int OpenEncoder( vlc_object_t *p_this )
     return VLC_SUCCESS;
 }
 
-/****************************************************************************
- * Headers: spits out the headers
- ****************************************************************************
- * This function spits out ogg packets.
- ****************************************************************************/
-static block_t *Headers( encoder_t *p_enc )
-{
-    encoder_sys_t *p_sys = p_enc->p_sys;
-    block_t *p_block, *p_chain = NULL;
-
-    /* Create speex headers */
-    if( !p_sys->i_headers )
-    {
-        char *p_buffer;
-        int i_buffer;
-
-        /* Main header */
-        p_buffer = speex_header_to_packet( &p_sys->header, &i_buffer );
-        p_block = block_New( p_enc, i_buffer );
-        memcpy( p_block->p_buffer, p_buffer, i_buffer );
-        p_block->i_dts = p_block->i_pts = p_block->i_length = 0;
-        block_ChainAppend( &p_chain, p_block );
-
-        /* Comment */
-        p_block = block_New( p_enc, sizeof("ENCODER=VLC media player") );
-        memcpy( p_block->p_buffer, "ENCODER=VLC media player",
-                p_block->i_buffer );
-        p_block->i_dts = p_block->i_pts = p_block->i_length = 0;
-        block_ChainAppend( &p_chain, p_block );
-
-        p_sys->i_headers = 2;
-    }
-
-    return p_chain;
-}
-
 /****************************************************************************
  * Encode: the whole thing
  ****************************************************************************
@@ -650,7 +933,7 @@ static block_t *Encode( encoder_t *p_enc, aout_buffer_t *p_aout_buf )
     encoder_sys_t *p_sys = p_enc->p_sys;
     block_t *p_block, *p_chain = NULL;
 
-    char *p_buffer = p_aout_buf->p_buffer;
+    unsigned char *p_buffer = p_aout_buf->p_buffer;
     int i_samples = p_aout_buf->i_nb_samples;
     int i_samples_delay = p_sys->i_samples_delay;
 
@@ -685,15 +968,15 @@ static block_t *Encode( encoder_t *p_enc, aout_buffer_t *p_aout_buf )
 
         /* Encode current frame */
         if( p_enc->fmt_in.audio.i_channels == 2 )
-            speex_encode_stereo( p_samples, p_sys->i_frame_length,
-                                 &p_sys->bits );
+            speex_encode_stereo_int( p_samples, p_sys->i_frame_length,
+                                     &p_sys->bits );
 
 #if 0
         if( p_sys->preprocess )
             speex_preprocess( p_sys->preprocess, p_samples, NULL );
 #endif
 
-        speex_encode( p_sys->p_state, p_samples, &p_sys->bits );
+        speex_encode_int( p_sys->p_state, p_samples, &p_sys->bits );
 
         p_buffer += p_sys->i_frame_size;
         p_sys->i_samples_delay -= p_sys->i_frame_length;
@@ -748,6 +1031,6 @@ static void CloseEncoder( vlc_object_t *p_this )
     speex_encoder_destroy( p_sys->p_state );
     speex_bits_destroy( &p_sys->bits );
 
-    if( p_sys->p_buffer ) free( p_sys->p_buffer );
+    free( p_sys->p_buffer );
     free( p_sys );
 }