[vlc-commits] [Git][videolan/vlc][3.0.x] 4 commits: packetizer: speex: only use frame_size from decoder

Thomas Guillem (@tguillem) gitlab at videolan.org
Mon Sep 14 16:05:28 UTC 2026



Thomas Guillem pushed to branch 3.0.x at VideoLAN / VLC


Commits:
7f396226 by François Cartegnie at 2026-09-14T15:59:45+00:00
packetizer: speex: only use frame_size from decoder

(cherry picked from commit 919963e6ea0851b7c5486f009f4dbb410e4ca43c)

- - - - -
54c6d8d3 by François Cartegnie at 2026-09-14T15:59:45+00:00
codec: speex: only use frame_size from decoder

fix #30103

(cherry picked from commit aaa782b87d23410973cb7f27f2f3d8f8ea561480)

- - - - -
d8c1cedc by François Cartegnie at 2026-09-14T15:59:45+00:00
resampler: speex: check new rate assignment

(adapted from commit fbe70dd6ca71477effb810d22371ed0309dadab0)

- - - - -
b6677773 by François Cartegnie at 2026-09-14T15:59:45+00:00
resampler: speex: check for overflow

(cherry picked from commit d6a50c1a61acea4d943e7272ccdf27bfa4c4306b)

- - - - -


2 changed files:

- modules/audio_filter/resampler/speex.c
- modules/codec/speex.c


Changes:

=====================================
modules/audio_filter/resampler/speex.c
=====================================
@@ -23,6 +23,8 @@
 #endif
 
 #include <inttypes.h>
+#include <stdckdint.h>
+#include <limits.h>
 
 #include <vlc_common.h>
 #include <vlc_aout.h>
@@ -118,20 +120,36 @@ static void Close (vlc_object_t *obj)
 static block_t *Resample (filter_t *filter, block_t *in)
 {
     SpeexResamplerState *st = (SpeexResamplerState *)filter->p_sys;
+    block_t *out = NULL;
 
     const size_t framesize = filter->fmt_out.audio.i_bytes_per_frame;
     const unsigned irate = filter->fmt_in.audio.i_rate;
     const unsigned orate = filter->fmt_out.audio.i_rate;
 
-    spx_uint32_t ilen = in->i_nb_samples;
-    spx_uint32_t olen = ((ilen + 2) * orate * UINT64_C(11))
-                      / (irate * UINT64_C(10));
+    if( speex_resampler_set_rate (st, irate, orate) != RESAMPLER_ERR_SUCCESS )
+        goto error;
 
-    block_t *out = block_Alloc (olen * framesize);
-    if (unlikely(out == NULL))
+    unsigned ilen = in->i_nb_samples;
+    unsigned olen;
+
+    // spx_uint32_t olen = ((ilen + 2) * orate * UINT64_C(11))
+    //                   / (irate * UINT64_C(10));
+    uint64_t num, den;
+    if( ckd_add(&olen, ilen, 2U) ||
+        ckd_mul(&num, (uint64_t)orate, UINT64_C(11)) ||
+        ckd_mul(&den, (uint64_t)irate, UINT64_C(10)) ||
+        ckd_mul(&num, (uint64_t)olen, num) ||
+        num / UINT_MAX >= den )
         goto error;
 
-    speex_resampler_set_rate (st, irate, orate);
+    olen = num / den;
+
+    if(SIZE_MAX / framesize < olen)
+        goto error;
+
+    out = block_Alloc (olen * framesize);
+    if (unlikely(out == NULL))
+        goto error;
 
     int err;
     if (filter->fmt_in.audio.i_format == VLC_CODEC_FL32)


=====================================
modules/codec/speex.c
=====================================
@@ -660,7 +660,17 @@ static block_t *ProcessPacket( decoder_t *p_dec, ogg_packet *p_oggpacket,
                 i_pcm_output_size = 0, i_bits_in_speex_frame = 0;
             block_t *p_new_block = NULL;
 
-            i_pcm_output_size = p_sys->p_header->frame_size * sizeof(short);
+            spx_int32_t frame_size = 0;
+            if( speex_decoder_ctl( p_sys->p_state, SPEEX_GET_FRAME_SIZE, &frame_size ) != 0 ||
+                frame_size <= 0 || (size_t)frame_size > INT_MAX / sizeof(short) )
+            {
+                msg_Warn( p_dec, "Invalid or unknown frame size %d", frame_size );
+                if( p_block )
+                    block_Release( p_block );
+                return NULL;
+            }
+
+            i_pcm_output_size = frame_size * sizeof(short);
 
             /* Alloc/Update our temp buffer if needed */
             void *p_realloc = realloc( p_sys->p_tempbuffer, i_pcm_output_size );
@@ -916,13 +926,17 @@ static block_t *DecodePacket( decoder_t *p_dec, ogg_packet *p_oggpacket )
     if( p_sys->i_frame_in_packet < p_sys->p_header->frames_per_packet )
     {
         block_t *p_aout_buffer;
-        if( p_sys->p_header->frame_size == 0 )
+        spx_int32_t frame_size = 0;
+        if( speex_decoder_ctl( p_sys->p_state, SPEEX_GET_FRAME_SIZE, &frame_size ) != 0 ||
+            frame_size <= 0 || (size_t)frame_size > INT_MAX )
+        {
+            msg_Warn( p_dec, "Invalid or unknown frame size %d", frame_size );
             return NULL;
+        }
 
         if( decoder_UpdateAudioFormat( p_dec ) )
             return NULL;
-        p_aout_buffer =
-            decoder_NewAudioBuffer( p_dec, p_sys->p_header->frame_size );
+        p_aout_buffer = decoder_NewAudioBuffer( p_dec, frame_size );
         if( !p_aout_buffer )
         {
             return NULL;
@@ -945,13 +959,13 @@ static block_t *DecodePacket( decoder_t *p_dec, ogg_packet *p_oggpacket )
 
         if( p_sys->p_header->nb_channels == 2 )
             speex_decode_stereo_int( (int16_t *)p_aout_buffer->p_buffer,
-                                     p_sys->p_header->frame_size,
+                                     frame_size,
                                      &p_sys->stereo );
 
         /* Date management */
         p_aout_buffer->i_pts = date_Get( &p_sys->end_date );
         p_aout_buffer->i_length =
-            date_Increment( &p_sys->end_date, p_sys->p_header->frame_size )
+            date_Increment( &p_sys->end_date, frame_size )
             - p_aout_buffer->i_pts;
 
         p_sys->i_frame_in_packet++;



View it on GitLab: https://code.videolan.org/videolan/vlc/-/compare/e0e7e4bc85dd206707cd255e9ef816bb8d320133...b667777390252023556ffbb5ebeaa0475f7ca28e

-- 
View it on GitLab: https://code.videolan.org/videolan/vlc/-/compare/e0e7e4bc85dd206707cd255e9ef816bb8d320133...b667777390252023556ffbb5ebeaa0475f7ca28e
You're receiving this email because of your account on code.videolan.org. Manage all notifications: https://code.videolan.org/-/profile/notifications | Help: https://code.videolan.org/help




More information about the vlc-commits mailing list