[vlc-commits] [Git][videolan/vlc][3.0.x] 4 commits: packetizer: speex: only use frame_size from decoder
Thomas Guillem (@tguillem)
gitlab at videolan.org
Mon Sep 14 16:05:28 UTC 2026
Thomas Guillem pushed to branch 3.0.x at VideoLAN / VLC
Commits:
7f396226 by François Cartegnie at 2026-09-14T15:59:45+00:00
packetizer: speex: only use frame_size from decoder
(cherry picked from commit 919963e6ea0851b7c5486f009f4dbb410e4ca43c)
- - - - -
54c6d8d3 by François Cartegnie at 2026-09-14T15:59:45+00:00
codec: speex: only use frame_size from decoder
fix #30103
(cherry picked from commit aaa782b87d23410973cb7f27f2f3d8f8ea561480)
- - - - -
d8c1cedc by François Cartegnie at 2026-09-14T15:59:45+00:00
resampler: speex: check new rate assignment
(adapted from commit fbe70dd6ca71477effb810d22371ed0309dadab0)
- - - - -
b6677773 by François Cartegnie at 2026-09-14T15:59:45+00:00
resampler: speex: check for overflow
(cherry picked from commit d6a50c1a61acea4d943e7272ccdf27bfa4c4306b)
- - - - -
2 changed files:
- modules/audio_filter/resampler/speex.c
- modules/codec/speex.c
Changes:
=====================================
modules/audio_filter/resampler/speex.c
=====================================
@@ -23,6 +23,8 @@
#endif
#include <inttypes.h>
+#include <stdckdint.h>
+#include <limits.h>
#include <vlc_common.h>
#include <vlc_aout.h>
@@ -118,20 +120,36 @@ static void Close (vlc_object_t *obj)
static block_t *Resample (filter_t *filter, block_t *in)
{
SpeexResamplerState *st = (SpeexResamplerState *)filter->p_sys;
+ block_t *out = NULL;
const size_t framesize = filter->fmt_out.audio.i_bytes_per_frame;
const unsigned irate = filter->fmt_in.audio.i_rate;
const unsigned orate = filter->fmt_out.audio.i_rate;
- spx_uint32_t ilen = in->i_nb_samples;
- spx_uint32_t olen = ((ilen + 2) * orate * UINT64_C(11))
- / (irate * UINT64_C(10));
+ if( speex_resampler_set_rate (st, irate, orate) != RESAMPLER_ERR_SUCCESS )
+ goto error;
- block_t *out = block_Alloc (olen * framesize);
- if (unlikely(out == NULL))
+ unsigned ilen = in->i_nb_samples;
+ unsigned olen;
+
+ // spx_uint32_t olen = ((ilen + 2) * orate * UINT64_C(11))
+ // / (irate * UINT64_C(10));
+ uint64_t num, den;
+ if( ckd_add(&olen, ilen, 2U) ||
+ ckd_mul(&num, (uint64_t)orate, UINT64_C(11)) ||
+ ckd_mul(&den, (uint64_t)irate, UINT64_C(10)) ||
+ ckd_mul(&num, (uint64_t)olen, num) ||
+ num / UINT_MAX >= den )
goto error;
- speex_resampler_set_rate (st, irate, orate);
+ olen = num / den;
+
+ if(SIZE_MAX / framesize < olen)
+ goto error;
+
+ out = block_Alloc (olen * framesize);
+ if (unlikely(out == NULL))
+ goto error;
int err;
if (filter->fmt_in.audio.i_format == VLC_CODEC_FL32)
=====================================
modules/codec/speex.c
=====================================
@@ -660,7 +660,17 @@ static block_t *ProcessPacket( decoder_t *p_dec, ogg_packet *p_oggpacket,
i_pcm_output_size = 0, i_bits_in_speex_frame = 0;
block_t *p_new_block = NULL;
- i_pcm_output_size = p_sys->p_header->frame_size * sizeof(short);
+ spx_int32_t frame_size = 0;
+ if( speex_decoder_ctl( p_sys->p_state, SPEEX_GET_FRAME_SIZE, &frame_size ) != 0 ||
+ frame_size <= 0 || (size_t)frame_size > INT_MAX / sizeof(short) )
+ {
+ msg_Warn( p_dec, "Invalid or unknown frame size %d", frame_size );
+ if( p_block )
+ block_Release( p_block );
+ return NULL;
+ }
+
+ i_pcm_output_size = frame_size * sizeof(short);
/* Alloc/Update our temp buffer if needed */
void *p_realloc = realloc( p_sys->p_tempbuffer, i_pcm_output_size );
@@ -916,13 +926,17 @@ static block_t *DecodePacket( decoder_t *p_dec, ogg_packet *p_oggpacket )
if( p_sys->i_frame_in_packet < p_sys->p_header->frames_per_packet )
{
block_t *p_aout_buffer;
- if( p_sys->p_header->frame_size == 0 )
+ spx_int32_t frame_size = 0;
+ if( speex_decoder_ctl( p_sys->p_state, SPEEX_GET_FRAME_SIZE, &frame_size ) != 0 ||
+ frame_size <= 0 || (size_t)frame_size > INT_MAX )
+ {
+ msg_Warn( p_dec, "Invalid or unknown frame size %d", frame_size );
return NULL;
+ }
if( decoder_UpdateAudioFormat( p_dec ) )
return NULL;
- p_aout_buffer =
- decoder_NewAudioBuffer( p_dec, p_sys->p_header->frame_size );
+ p_aout_buffer = decoder_NewAudioBuffer( p_dec, frame_size );
if( !p_aout_buffer )
{
return NULL;
@@ -945,13 +959,13 @@ static block_t *DecodePacket( decoder_t *p_dec, ogg_packet *p_oggpacket )
if( p_sys->p_header->nb_channels == 2 )
speex_decode_stereo_int( (int16_t *)p_aout_buffer->p_buffer,
- p_sys->p_header->frame_size,
+ frame_size,
&p_sys->stereo );
/* Date management */
p_aout_buffer->i_pts = date_Get( &p_sys->end_date );
p_aout_buffer->i_length =
- date_Increment( &p_sys->end_date, p_sys->p_header->frame_size )
+ date_Increment( &p_sys->end_date, frame_size )
- p_aout_buffer->i_pts;
p_sys->i_frame_in_packet++;
View it on GitLab: https://code.videolan.org/videolan/vlc/-/compare/e0e7e4bc85dd206707cd255e9ef816bb8d320133...b667777390252023556ffbb5ebeaa0475f7ca28e
--
View it on GitLab: https://code.videolan.org/videolan/vlc/-/compare/e0e7e4bc85dd206707cd255e9ef816bb8d320133...b667777390252023556ffbb5ebeaa0475f7ca28e
You're receiving this email because of your account on code.videolan.org. Manage all notifications: https://code.videolan.org/-/profile/notifications | Help: https://code.videolan.org/help
More information about the vlc-commits
mailing list