]> git.sesse.net Git - ffmpeg/log
ffmpeg
3 years agoavfilter/af_aiir: remove unused variable
Paul B Mahol [Sun, 18 Oct 2020 20:51:55 +0000 (22:51 +0200)]
avfilter/af_aiir: remove unused variable

3 years agoavcodec/aacdec_fixed: Limit index in vector_pow43()
Michael Niedermayer [Mon, 12 Oct 2020 15:11:27 +0000 (17:11 +0200)]
avcodec/aacdec_fixed: Limit index in vector_pow43()

Fixes: out of array access
Fixes: 26087/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_AAC_FIXED_fuzzer-5724825462767616
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavformat/kvag: Fix integer overflow in bitrate computation
Michael Niedermayer [Sat, 10 Oct 2020 15:31:50 +0000 (17:31 +0200)]
avformat/kvag: Fix integer overflow in bitrate computation

Fixes: signed integer overflow: 1077952576 * 4 cannot be represented in type 'int'
Fixes: 26152/clusterfuzz-testcase-minimized-ffmpeg_DEMUXER_fuzzer-5674758518341632
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavcodec/h264_slice: fix undefined integer overflow with POC in error concealment
Michael Niedermayer [Wed, 7 Oct 2020 21:22:59 +0000 (23:22 +0200)]
avcodec/h264_slice: fix undefined integer overflow with POC in error concealment

Alternatively the POC could be changed to 64bit. the large values seem to be within what is allowed.

Fixes: signed integer overflow: 2147483646 + 2 cannot be represented in type 'int'
Fixes: 26076/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_H264_fuzzer-5711127201447936
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavcodec/decode: Consider discarded samples in max_samples
Michael Niedermayer [Fri, 25 Sep 2020 21:17:13 +0000 (23:17 +0200)]
avcodec/decode: Consider discarded samples in max_samples

Fixes: Timeout (several minutes -> 3 sec)
Fixes: 25246/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_ALS_fuzzer-5943400661254144
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agotools/target_dec_fuzzer: assume that discarded audio packets produced max samples
Michael Niedermayer [Fri, 25 Sep 2020 22:14:46 +0000 (00:14 +0200)]
tools/target_dec_fuzzer: assume that discarded audio packets produced max samples

We do not know how many samples these produce as its not exported.
Alternatively we could export that but as long as its not we better
assume its more than 0 as otherwise the thresholds would not work

Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agotools/target_dec_fuzzer: Correct maxsamples_per_frame if maxsamples has been changed
Michael Niedermayer [Fri, 25 Sep 2020 20:33:43 +0000 (22:33 +0200)]
tools/target_dec_fuzzer: Correct maxsamples_per_frame if maxsamples has been changed

Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavcodec/mpeg12dec: Limit maximum A53 CC size
Michael Niedermayer [Mon, 21 Sep 2020 20:40:48 +0000 (22:40 +0200)]
avcodec/mpeg12dec: Limit maximum A53 CC size

This is more than 10 times the size of the largest i found. And also alot more
than our encoder could handle (our encoder is limited to max 31)
Without any limit megabyte+ sized blocks can be reallocated millions of times.
Sadly the SCTE-20 spec does not seem to contain any hard limit directly, so this limit here
is arbitrary

Fixes: Timeout (25sec -> 152ms)
Fixes: 25714/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_MPEG2VIDEO_fuzzer-5713633336885248
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavcodec/photocd: Use ff_set_dimensions()
Michael Niedermayer [Sun, 20 Sep 2020 19:29:15 +0000 (21:29 +0200)]
avcodec/photocd: Use ff_set_dimensions()

Fixes: out of memory
Fixes: 25588/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_PHOTOCD_fuzzer-6612945080156160
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavformat/ape: Remove seektable and bittable
Michael Niedermayer [Sat, 25 Jul 2020 17:21:41 +0000 (19:21 +0200)]
avformat/ape: Remove seektable and bittable

Suggested-by: Andreas
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavformat/rmdec: sanity check coded_framesize
Michael Niedermayer [Sun, 16 Aug 2020 16:05:34 +0000 (18:05 +0200)]
avformat/rmdec: sanity check coded_framesize

Fixes: signed integer overflow: -14671840 * 8224 cannot be represented in type 'int'
Fixes: 24793/clusterfuzz-testcase-minimized-ffmpeg_DEMUXER_fuzzer-5101884323659776
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavfilter/af_aiir: add analog transfer function format
Paul B Mahol [Sun, 18 Oct 2020 16:25:51 +0000 (18:25 +0200)]
avfilter/af_aiir: add analog transfer function format

3 years agoavfilter/af_mcompand: Remove redundant calls to AVFilter.uninit
Andreas Rheinhardt [Tue, 13 Oct 2020 01:44:37 +0000 (03:44 +0200)]
avfilter/af_mcompand: Remove redundant calls to AVFilter.uninit

uninit is already called automatically (even when configuring the filter
failed).

Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>
3 years agoavcodec/asvenc: Avoid reversing output data twice
Andreas Rheinhardt [Tue, 13 Oct 2020 01:11:37 +0000 (03:11 +0200)]
avcodec/asvenc: Avoid reversing output data twice

The ASUS V2 format is designed for a little-endian bitstream reader, yet
our encoder used an ordinary big-endian bitstream writer to write it;
the bits of every byte were swapped at the end and some data (namely the
numbers not in static tables) had to be bitreversed before writing it at
all, so that it would be reversed twice.

This commit stops doing so; instead, a little-endian bitstream writer is
used. This also necessitated to switch certain static tables, which
required trivial modifications to the decoder (that uses the same
tables).

Reviewed-by: Michael Niedermayer <michael@niedermayer.cc>
Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>
3 years agoavcodec/asvenc: Simplify flushing and padding packet
Andreas Rheinhardt [Mon, 12 Oct 2020 22:01:29 +0000 (00:01 +0200)]
avcodec/asvenc: Simplify flushing and padding packet

Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>
3 years agoavcodec/asvdec: Avoid reversing input data twice
Andreas Rheinhardt [Mon, 12 Oct 2020 10:38:59 +0000 (12:38 +0200)]
avcodec/asvdec: Avoid reversing input data twice

Up until now the ASV2 decoder used an ordinary big-endian bitreader to
read data actually destined for a little-endian bitreader; this is done
by reversing the whole input packet bitwise, using the big-endian
bigreader and reversing (and shifting) the result again. This commit
stops this and instead uses a little-endian bitreader directly.

Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>
3 years agoavcodec/nvenc: update driver versions for SDK 11.0
Timo Rothenpieler [Sat, 17 Oct 2020 21:10:42 +0000 (23:10 +0200)]
avcodec/nvenc: update driver versions for SDK 11.0

3 years agoavfilter/af_aiir: use av_sscanf()
Paul B Mahol [Sat, 17 Oct 2020 16:30:27 +0000 (18:30 +0200)]
avfilter/af_aiir: use av_sscanf()

3 years agoavfilter/af_aiir: reverse order of biquads in serial processing
Paul B Mahol [Sat, 17 Oct 2020 16:23:35 +0000 (18:23 +0200)]
avfilter/af_aiir: reverse order of biquads in serial processing

This avoids most of clippings for fixed-point precision inputs.
Also add warning about filtering fixed-point precision with parallel processing.

3 years agoavformat/flvdec: Check for EOF in amf_parse_object()
Michael Niedermayer [Thu, 8 Oct 2020 18:44:23 +0000 (20:44 +0200)]
avformat/flvdec: Check for EOF in amf_parse_object()

Fixes: Timeout (too long -> 1ms)
Fixes: 26108/clusterfuzz-testcase-minimized-ffmpeg_DEMUXER_fuzzer-5653887668977664
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavcodec/mv30: Fix multiple integer overflows
Michael Niedermayer [Sun, 4 Oct 2020 17:28:47 +0000 (19:28 +0200)]
avcodec/mv30: Fix multiple integer overflows

Fixes: signed integer overflow: -895002 * 2400 cannot be represented in type 'int'
Fixes: 26052/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_MV30_fuzzer-5431812577558528
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavcodec/smacker: Check remaining bits in SMK_BLK_FULL
Michael Niedermayer [Fri, 2 Oct 2020 08:54:31 +0000 (10:54 +0200)]
avcodec/smacker: Check remaining bits in SMK_BLK_FULL

Fixes: out of array access
Fixes: 26047/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_SMACKER_fuzzer-5083031667474432
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavcodec/cook: Check subpacket index against max
Michael Niedermayer [Sun, 27 Sep 2020 18:23:10 +0000 (20:23 +0200)]
avcodec/cook: Check subpacket index against max

Fixes: off by 1 error
Fixes: index 5 out of bounds for type 'COOKSubpacket [5]'
Fixes: 25772/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_COOK_fuzzer-5762459498184704.fuzz
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavcodec/utils: Check for overflow with ATRAC* in get_audio_frame_duration()
Michael Niedermayer [Fri, 16 Oct 2020 11:30:29 +0000 (13:30 +0200)]
avcodec/utils: Check for overflow with ATRAC* in get_audio_frame_duration()

Fixes: signed integer overflow: 1024 * 13129048 cannot be represented in type 'int'
Fixes: 26378/clusterfuzz-testcase-minimized-ffmpeg_dem_CODEC2RAW_fuzzer-5634018353348608
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavcodec/hevcpred_template: Fix diagonal chroma availability in 4:2:2 edge case in...
Michael Niedermayer [Fri, 16 Oct 2020 11:30:28 +0000 (13:30 +0200)]
avcodec/hevcpred_template: Fix diagonal chroma availability in 4:2:2 edge case in intra_pred

Fixes: pixel decode issue.ts
Fixes: raw frame.hevc
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavcodec/hevc_mvs: Cleanup ff_hevc_set_neighbour_available()
Michael Niedermayer [Fri, 16 Oct 2020 11:30:27 +0000 (13:30 +0200)]
avcodec/hevc_mvs: Cleanup ff_hevc_set_neighbour_available()

Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavformat/icodec: Change order of operations to avoid NULL dereference
Michael Niedermayer [Fri, 16 Oct 2020 17:05:23 +0000 (19:05 +0200)]
avformat/icodec: Change order of operations to avoid NULL dereference

Fixes: SEGV on unknown address 0x000000000000
Fixes: 26379/clusterfuzz-testcase-minimized-ffmpeg_dem_ICO_fuzzer-5709011753893888
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Reviewed-by: Peter Ross
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoffmpeg: deduplicate init_output_stream usage logic
Jan Ekström [Thu, 10 Sep 2020 21:13:27 +0000 (00:13 +0300)]
ffmpeg: deduplicate init_output_stream usage logic

Adds a wrapper function, which handles any errors depending on how
fatal a failure would be.

3 years agoavcodec/adpcmenc: remove BLKSIZE #define
Zane van Iperen [Wed, 14 Oct 2020 12:56:49 +0000 (22:56 +1000)]
avcodec/adpcmenc: remove BLKSIZE #define

Signed-off-by: Zane van Iperen <zane@zanevaniperen.com>
3 years agoavcodec/adpcm_ima_wav: support custom block size for encoding
Zane van Iperen [Wed, 14 Oct 2020 12:43:34 +0000 (22:43 +1000)]
avcodec/adpcm_ima_wav: support custom block size for encoding

Signed-off-by: Zane van Iperen <zane@zanevaniperen.com>
3 years agoavcodec/adpcm_yamaha: support custom block size for encoding
Zane van Iperen [Wed, 14 Oct 2020 12:43:03 +0000 (22:43 +1000)]
avcodec/adpcm_yamaha: support custom block size for encoding

Signed-off-by: Zane van Iperen <zane@zanevaniperen.com>
3 years agoavcodec/adpcm_ima_apm: support custom block size for encoding
Zane van Iperen [Wed, 14 Oct 2020 12:42:11 +0000 (22:42 +1000)]
avcodec/adpcm_ima_apm: support custom block size for encoding

Signed-off-by: Zane van Iperen <zane@zanevaniperen.com>
3 years agoavcodec/adpcm_ima_ssi: support custom block size for encoding
Zane van Iperen [Wed, 14 Oct 2020 12:41:43 +0000 (22:41 +1000)]
avcodec/adpcm_ima_ssi: support custom block size for encoding

Signed-off-by: Zane van Iperen <zane@zanevaniperen.com>
3 years agoavcodec/adpcm_ms: support custom block size for encoding
Zane van Iperen [Wed, 14 Oct 2020 12:21:30 +0000 (22:21 +1000)]
avcodec/adpcm_ms: support custom block size for encoding

Fixes tickets #6585 and #7109

Signed-off-by: Zane van Iperen <zane@zanevaniperen.com>
3 years agoavcodec/adpcmenc: add "block_size" option
Zane van Iperen [Wed, 14 Oct 2020 12:16:53 +0000 (22:16 +1000)]
avcodec/adpcmenc: add "block_size" option

Signed-off-by: Zane van Iperen <zane@zanevaniperen.com>
3 years agoavformat/mpegts: replace magic descriptor_tag values with defines
Brad Hards [Sat, 10 Oct 2020 06:04:30 +0000 (17:04 +1100)]
avformat/mpegts: replace magic descriptor_tag values with defines

This takes the used values from ISO/IEC 13818-1 Table 2-45 and adds
them to the mpegts.h header. No functional changes.

Signed-off-by: Brad Hards <bradh@frogmouth.net>
Signed-off-by: Marton Balint <cus@passwd.hu>
3 years agoavformat/udp: remove redundant setting of h->max_packet_size
Zhao Zhili [Wed, 23 Sep 2020 16:15:16 +0000 (00:15 +0800)]
avformat/udp: remove redundant setting of h->max_packet_size

h->max_packet_size is being reset in the following code.

Signed-off-by: Marton Balint <cus@passwd.hu>
3 years agoRevert "aviobuf: Discard old buffered, previously read data in ffio_read_partial"
Marton Balint [Thu, 8 Oct 2020 22:18:07 +0000 (00:18 +0200)]
Revert "aviobuf: Discard old buffered, previously read data in ffio_read_partial"

This is unneeded after 2ca48e466675a8a3630061cd2c15325eab8eda97 and it breaks
ffio_ensure_seekback().

This reverts commit 53c25ee0736497b46bb76064cc2c84c976b2d295.

Signed-off-by: Marton Balint <cus@passwd.hu>
3 years agoavformat/libsrt: fix cleanups on failed libsrt_open() and libsrt_setup()
Marton Balint [Fri, 9 Oct 2020 19:37:07 +0000 (21:37 +0200)]
avformat/libsrt: fix cleanups on failed libsrt_open() and libsrt_setup()

- Call srt_epoll_release() to avoid fd leak on libsrt_setup() error.
- Call srt_cleanup() on libsrt_open() failure.
- Fix return value and method on mode parsing failure.

Based on a patch by Nicolas Sugino <nsugino@3way.com.ar>.

Signed-off-by: Marton Balint <cus@passwd.hu>
3 years agoavfilter/af_aiir: use transposed II form for biquad sections
Paul B Mahol [Fri, 16 Oct 2020 20:51:16 +0000 (22:51 +0200)]
avfilter/af_aiir: use transposed II form for biquad sections

3 years agoavfilter/af_aiir: implement parallel processing
Paul B Mahol [Thu, 15 Oct 2020 15:29:04 +0000 (17:29 +0200)]
avfilter/af_aiir: implement parallel processing

3 years agoavcodec/av1dec: add cur_frame.spatial_id and temporal_id to AV1Frame
James Almer [Fri, 16 Oct 2020 16:34:31 +0000 (13:34 -0300)]
avcodec/av1dec: add cur_frame.spatial_id and temporal_id to AV1Frame

Will be used by hwaccels, which have access to a frame's AV1RawFrameHeader but not
its AV1RawOBUHeader.

Signed-off-by: James Almer <jamrial@gmail.com>
3 years agotools/target_dem_fuzzer: Set format independent of c
Michael Niedermayer [Fri, 16 Oct 2020 09:36:26 +0000 (11:36 +0200)]
tools/target_dem_fuzzer: Set format independent of c

Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavcodec/movtextenc: cosmetics
Andriy Gelman [Wed, 14 Oct 2020 21:27:16 +0000 (17:27 -0400)]
avcodec/movtextenc: cosmetics

Change pointer position.

Signed-off-by: Andriy Gelman <andriy.gelman@gmail.com>
3 years agoavcodec/movtextenc: fix writing to bytestream on BE arches
Andriy Gelman [Wed, 14 Oct 2020 04:38:22 +0000 (00:38 -0400)]
avcodec/movtextenc: fix writing to bytestream on BE arches

Fixes fate-binsub-movtextenc on PPC64

Currently tags are written in reverse order on BE arches. This is fixed
by using MKBETAG() and AV_RB32() to be arch agnostics.

Also s->font_count is of type int. On BE arches with 32bit int,
count = AV_RB16(&s->font_count) will read two most significant bytes
instead of the least significant bytes. This is fixed by assigning
s->font_count to count first.

The final change is modifying the type of len. On BE arches
the most significant byte of the int was written instead of the least
significant byte.

Signed-off-by: Andriy Gelman <andriy.gelman@gmail.com>
3 years agoavcodec/asvenc: Inline constants
Andreas Rheinhardt [Mon, 12 Oct 2020 21:22:27 +0000 (23:22 +0200)]
avcodec/asvenc: Inline constants

Reviewed-by: Michael Niedermayer <michael@niedermayer.cc>
Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>
3 years agoavcodec/asvdec: Use init_get_bits8()
Andreas Rheinhardt [Mon, 12 Oct 2020 09:09:27 +0000 (11:09 +0200)]
avcodec/asvdec: Use init_get_bits8()

Reviewed-by: Michael Niedermayer <michael@niedermayer.cc>
Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>
3 years agoavcodec/asvdec: Reduce the size of some VLCs
Andreas Rheinhardt [Mon, 12 Oct 2020 08:48:29 +0000 (10:48 +0200)]
avcodec/asvdec: Reduce the size of some VLCs

Reviewed-by: Michael Niedermayer <michael@niedermayer.cc>
Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>
3 years agoavcodec/ylc: Inline constants
Andreas Rheinhardt [Tue, 13 Oct 2020 08:50:42 +0000 (10:50 +0200)]
avcodec/ylc: Inline constants

Reviewed-by: Michael Niedermayer <michael@niedermayer.cc>
Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>
3 years agoavcodec/v3/408enc: Remove empty close functions
Andreas Rheinhardt [Tue, 13 Oct 2020 07:08:32 +0000 (09:08 +0200)]
avcodec/v3/408enc: Remove empty close functions

Reviewed-by: Michael Niedermayer <michael@niedermayer.cc>
Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>
3 years agoavcodec/exr: Fix overflow with many blocks
Michael Niedermayer [Sat, 26 Sep 2020 19:58:37 +0000 (21:58 +0200)]
avcodec/exr: Fix overflow with many blocks

Fixes: signed integer overflow: 1073741827 * 8 cannot be represented in type 'int'
Fixes: 25621/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_EXR_fuzzer-6304841641754624
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavcodec/Makefile: add missing av1_cuvid entry
James Almer [Thu, 15 Oct 2020 21:30:04 +0000 (18:30 -0300)]
avcodec/Makefile: add missing av1_cuvid entry

Signed-off-by: James Almer <jamrial@gmail.com>
3 years agoconfigure: check for nvdec/cuvid AV1 support
Timo Rothenpieler [Thu, 15 Oct 2020 21:25:05 +0000 (23:25 +0200)]
configure: check for nvdec/cuvid AV1 support

3 years agoavcodec/vp9dsp_template: Fix integer overflows in idct16_1d()
Michael Niedermayer [Sat, 19 Sep 2020 14:40:22 +0000 (16:40 +0200)]
avcodec/vp9dsp_template: Fix integer overflows in idct16_1d()

Fixes: signed integer overflow: -190760 * 11585 cannot be represented in type 'int'
Fixes: 25471/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_VP9_fuzzer-5743354917421056
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavcodec/ansi: Check initial dimensions
Michael Niedermayer [Sat, 19 Sep 2020 19:17:32 +0000 (21:17 +0200)]
avcodec/ansi: Check initial dimensions

Fixes: Timeout (minutes to less than 1sec)
Fixes: 25682/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_ANSI_fuzzer-6320712032452608
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavcodec/hevcdec: Check slice_cb_qp_offset / slice_cr_qp_offset
Michael Niedermayer [Sat, 19 Sep 2020 14:29:15 +0000 (16:29 +0200)]
avcodec/hevcdec: Check slice_cb_qp_offset / slice_cr_qp_offset

Fixes: signed integer overflow: 29 + 2147483640 cannot be represented in type 'int'
Fixes: 25413/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_HEVC_fuzzer-5697909331591168
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavcodec/sonic: Check for overread
Michael Niedermayer [Sat, 19 Sep 2020 09:29:01 +0000 (11:29 +0200)]
avcodec/sonic: Check for overread

Fixes: Timeout (too long -> 1.3 sec)
Fixes: 24358/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_SONIC_fuzzer-5107284099989504
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavcodec/mobiclip: Check that Motion vectors are within the input frame
Michael Niedermayer [Fri, 2 Oct 2020 20:48:12 +0000 (22:48 +0200)]
avcodec/mobiclip: Check that Motion vectors are within the input frame

The MV checks did not consider the width and height of the block, also they
had some off by 1 errors. This resulted in undefined behavior and crashes.
This commit instead errors out on these

Fixes: out of array read
Fixes: 26080/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_MOBICLIP_fuzzer-5758146355920896
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavcodec/mobiclip: set the bitstream size to the input
Michael Niedermayer [Sat, 12 Sep 2020 14:35:55 +0000 (16:35 +0200)]
avcodec/mobiclip: set the bitstream size to the input

Fixes: out of array read
Fixes: 25453/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_MOBICLIP_fuzzer-5163575973511168
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Reviewed-by: Paul B Mahol <onemda@gmail.com>
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavcodec/allcodecs: move av1_cuvid below libaom_av1
James Almer [Thu, 15 Oct 2020 20:29:27 +0000 (17:29 -0300)]
avcodec/allcodecs: move av1_cuvid below libaom_av1

Software decoders should always be first.

Signed-off-by: James Almer <jamrial@gmail.com>
3 years agoavcodec/cuviddec: add av1 support
Roman Arzumanyan [Thu, 3 Sep 2020 11:52:08 +0000 (14:52 +0300)]
avcodec/cuviddec: add av1 support

Signed-off-by: Timo Rothenpieler <timo@rothenpieler.org>
3 years agoavformat/subviewerdec: fail on AV_NOPTS_VALUE
Michael Niedermayer [Sun, 19 Jul 2020 15:13:10 +0000 (17:13 +0200)]
avformat/subviewerdec: fail on AV_NOPTS_VALUE

Such values are not supported by ff_subtitles_queue*

Fixes: signed integer overflow: 10 - -9223372036854775808 cannot be represented in type 'long'
Fixes: 24193/clusterfuzz-testcase-minimized-ffmpeg_DEMUXER_fuzzer-5714901855895552
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agolibavformat/avidec: check memory allocation
Chris Miceli [Tue, 13 Oct 2020 03:22:25 +0000 (14:22 +1100)]
libavformat/avidec: check memory allocation

Memory allocation for AVIOContext should be checked. In this code,
all error conditions are sent to the "goto error".

Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agolibavfilter/dnn/dnn_backend{openvino, tf}: check memory alloc non-NULL
Chris Miceli [Wed, 14 Oct 2020 00:59:44 +0000 (11:59 +1100)]
libavfilter/dnn/dnn_backend{openvino, tf}: check memory alloc non-NULL

These previously would not check that the return value was non-null
meaning it was susceptible to a sigsegv. This checks those values.

3 years agolibavfilter/dnn_backend_native: check mem allocation
Chris Miceli [Wed, 14 Oct 2020 00:19:50 +0000 (11:19 +1100)]
libavfilter/dnn_backend_native: check mem allocation

check that frame allocations return non-null.

3 years agoavcodec/webp: Use LE VLC table for LE bitstream reader
Andreas Rheinhardt [Mon, 12 Oct 2020 07:05:42 +0000 (09:05 +0200)]
avcodec/webp: Use LE VLC table for LE bitstream reader

The WebP format uses Huffman tables and the decoder therefore uses
VLC tables. Given that WebP is a LE format, a LE bitreader is used;
yet the VLC table is not created for a LE reader (the process used to
create the tables puts the last bit to be read in the lowest bit) and
therefore custom code for reading the VLCs that reverses the bits
read is used instead of get_vlc2(). This commit changes this to use
a table designed for LE bitreader which allows to use get_vlc2() directly.
The necessary reversing of the codes is delegated to
ff_init_vlc_sparse() (and is therefore only done during init and not
when actually reading the VLCs).

Reviewed-by: Paul B Mahol <onemda@gmail.com>
Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>
3 years agoavcodec/ivi: Avoid reversing BE VLC codes for LE bitstream reader
Andreas Rheinhardt [Mon, 12 Oct 2020 05:45:23 +0000 (07:45 +0200)]
avcodec/ivi: Avoid reversing BE VLC codes for LE bitstream reader

Reviewed-by: Paul B Mahol <onemda@gmail.com>
Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>
3 years agoavcodec/speedhq: Avoid reversing BE codes for LE bitstream reader
Andreas Rheinhardt [Mon, 12 Oct 2020 03:59:34 +0000 (05:59 +0200)]
avcodec/speedhq: Avoid reversing BE codes for LE bitstream reader

Reviewed-by: Paul B Mahol <onemda@gmail.com>
Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>
3 years agoavcodec/vlc, bitstream: Allow to use BE codes to initialize LE VLC
Andreas Rheinhardt [Mon, 12 Oct 2020 03:24:42 +0000 (05:24 +0200)]
avcodec/vlc, bitstream: Allow to use BE codes to initialize LE VLC

This is easily possible because ff_init_vlc_sparse() already transforms
both LE as well as BE codes to a normal form internally before
processing them further. This will be used in subsequent commits.

Reviewed-by: Michael Niedermayer <michael@niedermayer.cc>
Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>
3 years agoavcodec/speedhq: Don't use ff_ prefix for static symbols
Andreas Rheinhardt [Mon, 12 Oct 2020 02:21:17 +0000 (04:21 +0200)]
avcodec/speedhq: Don't use ff_ prefix for static symbols

Reviewed-by: Paul B Mahol <onemda@gmail.com>
Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>
3 years agoavcodec/speedhq: Don't pretend reading DC can fail
Andreas Rheinhardt [Mon, 12 Oct 2020 02:08:07 +0000 (04:08 +0200)]
avcodec/speedhq: Don't pretend reading DC can fail

It can't, because the tables used don't have any loose ends. This also
fixes a bug in the only caller of decode_dc_le(): It didn't check the
return value.

Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>
3 years agoavcodec/indeo2: Remove #ifdef BITSTREAM_READER_LE cruft
Andreas Rheinhardt [Mon, 12 Oct 2020 01:49:05 +0000 (03:49 +0200)]
avcodec/indeo2: Remove #ifdef BITSTREAM_READER_LE cruft

Before the LE bitstream reader was used in the Indeo 2 decoder,
a standard BE bitstream reader with swapped bits was used; when the LE
bitstream reader was added, the old code was only #ifdef'ed away and not
removed. Said code has several problems: It modifies the input packet
without ensuring that the packet is indeed writable; and it doesn't work
since 09c4e5c5988c0037d108c5fc2a137d9ad488f7f4 because said commit
removed the BE table used to initialize the VLC table. So just remove
this cruft from the actual decoder, too.

Also use INIT_LE_VLC_STATIC while at it.

Reviewed-by: Paul B Mahol <onemda@gmail.com>
Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>
3 years agoavfilter/vf_scale_cuda: unload cuModule on uninit
leozhang [Mon, 12 Oct 2020 11:59:39 +0000 (19:59 +0800)]
avfilter/vf_scale_cuda: unload cuModule on uninit

Signed-off-by: leozhang <nowerzt@gmail.com>
Signed-off-by: Timo Rothenpieler <timo@rothenpieler.org>
3 years agoAdd support for building fuzzer tools for an individual demuxer
Michael Niedermayer [Sat, 10 Oct 2020 15:25:46 +0000 (17:25 +0200)]
Add support for building fuzzer tools for an individual demuxer

Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agofate-mxf-probe-applehdr10: Ignore endianness
Tomas Härdin [Mon, 5 Oct 2020 08:17:13 +0000 (10:17 +0200)]
fate-mxf-probe-applehdr10: Ignore endianness

3 years agoavcodec/cbs_av1: Free content in cbs_av1_free_metadata()
Michael Niedermayer [Sun, 11 Oct 2020 13:22:51 +0000 (15:22 +0200)]
avcodec/cbs_av1: Free content in cbs_av1_free_metadata()

Fixes: memleak
Fixes: 25838/clusterfuzz-testcase-minimized-ffmpeg_BSF_TRACE_HEADERS_fuzzer-5736255957237760
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Reviewed-by: James Almer <jamrial@gmail.com>
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavfilter/af_sofalizer: allow up to 64 channels
Paul B Mahol [Mon, 12 Oct 2020 10:15:27 +0000 (12:15 +0200)]
avfilter/af_sofalizer: allow up to 64 channels

3 years agoavfilter/af_sofalizer: allow to specify virtual speakers indetifier as number
Paul B Mahol [Sun, 11 Oct 2020 13:23:31 +0000 (15:23 +0200)]
avfilter/af_sofalizer: allow to specify virtual speakers indetifier as number

3 years agoavcodec/apedec: use proper macro and type for pivot variable
Paul B Mahol [Mon, 5 Oct 2020 23:56:43 +0000 (01:56 +0200)]
avcodec/apedec: use proper macro and type for pivot variable

3 years agoavcodec/apedec: properly calculate and store absolute value
Paul B Mahol [Mon, 5 Oct 2020 23:24:42 +0000 (01:24 +0200)]
avcodec/apedec: properly calculate and store absolute value

3 years agoavcodec/apedec: fix decoding 24bit insane files with recent versions
Paul B Mahol [Mon, 5 Oct 2020 20:24:13 +0000 (22:24 +0200)]
avcodec/apedec: fix decoding 24bit insane files with recent versions

3 years agoavformat/isom: add support for RAW ASC Bayer BGGR in mov
Paul B Mahol [Thu, 8 Oct 2020 17:24:11 +0000 (19:24 +0200)]
avformat/isom: add support for RAW ASC Bayer BGGR in mov

3 years agoavcodec/mpeg12: Don't pretend reading dct_dc_size_* VLCs can fail
Andreas Rheinhardt [Thu, 8 Oct 2020 15:54:19 +0000 (17:54 +0200)]
avcodec/mpeg12: Don't pretend reading dct_dc_size_* VLCs can fail

It can't because the corresponding trees don't have any loose ends.

Removing the checks also removed an instance of av_log(NULL (with a
nonsense message) from the codebase.

Reviewed-by: Michael Niedermayer <michael@niedermayer.cc>
Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>
3 years agoavcodec/mpeg12: Reduce size of motion-vector VLC
Andreas Rheinhardt [Thu, 8 Oct 2020 14:59:40 +0000 (16:59 +0200)]
avcodec/mpeg12: Reduce size of motion-vector VLC

It currently uses 9 bits per table, but there are no codes with
nine bits at all, while there are codes with eight, ten and eleven bits.
So reducing the table size to eight bits will not reduce the amount of
codes that can be parsed in the first step, but it allows to reduce the
size of the motion-vector VLC.

Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>
3 years agolavc, lavf: Remove newlines from calls to avpriv_request_sample().
Carl Eugen Hoyos [Sun, 11 Oct 2020 17:59:24 +0000 (19:59 +0200)]
lavc, lavf: Remove newlines from calls to avpriv_request_sample().

3 years agoavcodec/exr: Check line size for overflow
Michael Niedermayer [Sat, 26 Sep 2020 20:04:16 +0000 (22:04 +0200)]
avcodec/exr: Check line size for overflow

Fixes: signed integer overflow: 570425356 * 6 cannot be represented in type 'int
Fixes: 25929/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_EXR_fuzzer-5099197739827200
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavcodec/exr: Check xdelta, ydelta
Michael Niedermayer [Sat, 26 Sep 2020 19:54:36 +0000 (21:54 +0200)]
avcodec/exr: Check xdelta, ydelta

Fixes: assertion failure
Fixes: 25617/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_EXR_fuzzer-5648746061496320
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavcodec/adpcm: Check block align for AV_CODEC_ID_ADPCM_PSX
Michael Niedermayer [Tue, 29 Sep 2020 19:23:39 +0000 (21:23 +0200)]
avcodec/adpcm: Check block align for AV_CODEC_ID_ADPCM_PSX

Regression since: ca49476ace90ddebc5f92d9d82297f77e528c21e
Fixes: out of array write
Fixes: 25786/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_ADPCM_PSX_fuzzer-5704869380620288
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoavcodec/mobiclip: Fix multiple integer overflows
Michael Niedermayer [Tue, 29 Sep 2020 20:43:13 +0000 (22:43 +0200)]
avcodec/mobiclip: Fix multiple integer overflows

Fixes: signed integer overflow: 872415232 * 7 cannot be represented in type 'int'
Fixes: signed integer overflow: -2013265888 + -1744830464 cannot be represented in type 'int'
Fixes: 25834/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_MOBICLIP_fuzzer-5471406434025472
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
3 years agoAllow using only the mfra info for seeking using the fragment index
Justin Ruggles [Fri, 2 Oct 2020 12:51:19 +0000 (08:51 -0400)]
Allow using only the mfra info for seeking using the fragment index

The mfra has enough information to enable seeking, and reading it is
behind an AVOption flag, so we shouldn't require that sidx information
also be present in order to seek using the fragment index.

Signed-off-by: Derek Buitenhuis <derek.buitenhuis@gmail.com>
3 years agoswscale/utils: override forced-zero formats back to full range
Jan Ekström [Fri, 9 Oct 2020 22:33:27 +0000 (01:33 +0300)]
swscale/utils: override forced-zero formats back to full range

Fixes vf_scale outputting RGB AVFrames with limited range flagged
in case either input or output specifically sets the range.

This is the reverse of the logic utilized for RGB and PAL8 content
in sws_setColorspaceDetails.

3 years agoswscale/utils: split range override check into its own function
Jan Ekström [Fri, 9 Oct 2020 22:29:18 +0000 (01:29 +0300)]
swscale/utils: split range override check into its own function

3 years agoavfilter/avfilter.h: add missing FF_API_NEXT wrapper
James Almer [Sun, 11 Oct 2020 02:54:35 +0000 (23:54 -0300)]
avfilter/avfilter.h: add missing FF_API_NEXT wrapper

Signed-off-by: James Almer <jamrial@gmail.com>
3 years agoavformat/avformat.h: add missing FF_API_NEXT wrappers
James Almer [Sun, 11 Oct 2020 02:54:17 +0000 (23:54 -0300)]
avformat/avformat.h: add missing FF_API_NEXT wrappers

Signed-off-by: James Almer <jamrial@gmail.com>
3 years agoavcodec/codec.h: add missing FF_API_NEXT wrapper
James Almer [Sun, 11 Oct 2020 02:54:03 +0000 (23:54 -0300)]
avcodec/codec.h: add missing FF_API_NEXT wrapper

Signed-off-by: James Almer <jamrial@gmail.com>
3 years agoavcodec/vp9: Fix stack-buffer overflow with VP9 VDPAU available
Andreas Rheinhardt [Sat, 10 Oct 2020 23:29:57 +0000 (01:29 +0200)]
avcodec/vp9: Fix stack-buffer overflow with VP9 VDPAU available

ccca62ef991f0a47dfa30c3e822d91294b8afe4c added new VP9 VDPAU profiles
and as a consequence AV_PIX_FMT_VDPAU can now be twice in the list of
pixel formats used for format negotiation by ff_thread_get_format(); yet
there is only one entry in said list reserved for VDPAU, leading to a
stack-buffer overflow. This commit fixes this by making sure that
AV_PIX_FMT_VDPAU will not occur twice in said list.

Fixes Coverity ticket 1468046.

Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>
3 years agoavcodec/sheervideo: Avoid code duplication when creating VLC tables
Andreas Rheinhardt [Sat, 10 Oct 2020 18:28:16 +0000 (20:28 +0200)]
avcodec/sheervideo: Avoid code duplication when creating VLC tables

The SheerVideo decoder uses two VLC tables and these are in turn created
from structures (called SheerTable) that are naturally paired. This
commit unifies these pairs of SheerTables to arrays and unifies creating
the VLC tables.

Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>
3 years agoavcodec/sheervideo: Reduce the size of static arrays
Andreas Rheinhardt [Sat, 10 Oct 2020 15:47:54 +0000 (17:47 +0200)]
avcodec/sheervideo: Reduce the size of static arrays

The SheerVideo decoder uses VLC tables which are currently stored in
large arrays that contain the length of each leaf of the corresponding
tree from left to right, taking 15.5KB of space. But all these arrays
follow a common pattern: First the entries are ascending and then they
are descending with lots of successive entries have the same value.
Therefore it makes sense to use a run-length encoding to store them, as
this commit does. Notice that the length 16 has to be treated specially
because there are arrays with more than 256 consecutive entries with
value 16 and because the length of the entries start to descend from
this length onward.

Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>
3 years agoavcodec/sheervideo: Don't leave context in inconsistent state upon error
Andreas Rheinhardt [Sat, 10 Oct 2020 18:11:49 +0000 (20:11 +0200)]
avcodec/sheervideo: Don't leave context in inconsistent state upon error

This has happened if the format changed midstream and if the new packet
is so small that it is instantaneously rejected: In this case the VLC
tables were for the new format, although the context says that they are
still the ones for the old format. It can also happen if the format
changed midstream and the allocation of the new tables fails. If the
next packet is a packet for the old format, the decoder thinks it
already has the correct VLC tables, leading to a segfault.

Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>
3 years agoavcodec/sheervideo: Inline compile-time constants
Andreas Rheinhardt [Sat, 10 Oct 2020 04:45:01 +0000 (06:45 +0200)]
avcodec/sheervideo: Inline compile-time constants

Reviewed-by: Paul B Mahol <onemda@gmail.com>
Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt@gmail.com>