-
Notifications
You must be signed in to change notification settings - Fork 48
Bound exp-Golomb prefix k < 30 in dec_vlc_read_kparam0() and dec_vlc_read_1bit_read() #290
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
kpchoi
merged 1 commit into
AcademySoftwareFoundation:main
from
fkyslov:fix-vlc-and-metadata-overflows
Sep 29, 2026
Merged
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -662,7 +662,7 @@ int oapve_vlc_get_coef_rate(oapve_core_t* core, s16* coef, int c) | |
|
|
||
| static int dec_vlc_read_kparam0(oapv_bs_t *bs) | ||
| { | ||
| int symbol; | ||
| u32 symbol; | ||
| int flag, k; | ||
|
|
||
| symbol = 2; | ||
|
|
@@ -679,7 +679,7 @@ static int dec_vlc_read_kparam0(oapv_bs_t *bs) | |
| k++; | ||
| } | ||
| } | ||
| oapv_assert_rv(k < 32, -1); /* prevent too large (impossible) k value */ | ||
| oapv_assert_rv(k < 30, -1); /* prevent too large (impossible) k value */ | ||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. This is a correct comparison. thanks. |
||
|
|
||
| if(k > 0) { | ||
| symbol += ((u32)0xFFFFFFFF) >> (32 - k); | ||
|
|
@@ -693,18 +693,18 @@ static int dec_vlc_read_kparam0(oapv_bs_t *bs) | |
| bs->code <<= k; | ||
| bs->leftbits -= k; | ||
| } | ||
| return symbol; | ||
| return (int)symbol; | ||
| } | ||
|
|
||
| static int dec_vlc_read_1bit_read(oapv_bs_t *bs) | ||
| { | ||
| int symbol; | ||
| u32 symbol; | ||
| int flag, k; | ||
|
|
||
| if(bs->leftbits == 0) BSR_FLUSH_1BYTE(bs); | ||
| BSR_READ_1BIT(bs, flag); | ||
|
|
||
| symbol = (1 + flag); | ||
| symbol = (u32)(1 + flag); | ||
| k = 0; | ||
| if(flag) { // parse_exp_golomb | ||
| while(1) { | ||
|
|
@@ -720,7 +720,7 @@ static int dec_vlc_read_1bit_read(oapv_bs_t *bs) | |
| } | ||
| } | ||
|
|
||
| oapv_assert_rv(k < 32, -1); /* prevent too large (impossible) k value */ | ||
| oapv_assert_rv(k < 30, -1); /* prevent too large (impossible) k value */ | ||
|
|
||
| if(k > 0) { | ||
| symbol += ((u32)0xFFFFFFFF) >> (32 - k); | ||
|
|
@@ -734,7 +734,7 @@ static int dec_vlc_read_1bit_read(oapv_bs_t *bs) | |
| bs->code <<= k; | ||
| bs->leftbits -= k; | ||
| } | ||
| return symbol; | ||
| return (int)symbol; | ||
| } | ||
|
|
||
| static int dec_vlc_read(oapv_bs_t *bs, int k) | ||
|
|
||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Changing
symbolfrominttou32is not needed for correctness. The additions are already done in unsigned arithmetic (int + u32,int + u64), so there is no signed overflow. With thekcheck after the loop, the result always fits inint.Still, the change is fine to keep as a cosmetic change. It matches
dec_vlc_read(), which already usesu32 symbol, and it keeps code reviewers and coding agents from mistaking this pattern for a signed overflow.