Skip to content

Guard against encoding more items than the 16-bit item ID space allows - #3352

Open
krishna28238-arch wants to merge 4 commits into
AOMediaCodec:mainfrom
krishna28238-arch:fix-item-count-guard
Open

krishna28238-arch wants to merge 4 commits into
AOMediaCodec:mainfrom
krishna28238-arch:fix-item-count-guard

Conversation

@krishna28238-arch

Copy link
Copy Markdown
Contributor

avifEncoderAddImageItems() now refuses to create items that would overflow the unsigned int(16) item IDs written in the 'pitm', 'iloc', 'infe', 'iref' and 'ipma' boxes (item ID 0 is invalid, see ISO/IEC 14496-12 Section 8.11.1.1), instead of silently wrapping the lastItemID counter and generating an invalid file. A color grid and an alpha grid of 128x256 cells each for example need 65538 distinct item IDs.

Part of #3337.

avifEncoderAddImageItems() now refuses to create items that would overflow the
unsigned int(16) item IDs written in the 'pitm', 'iloc', 'infe', 'iref' and
'ipma' boxes (item ID 0 is invalid, see ISO/IEC 14496-12 Section 8.11.1.1),
instead of silently wrapping the lastItemID counter and generating an invalid
file. A color grid and an alpha grid of 128x256 cells each for example need
65538 distinct item IDs.

Part of AOMediaCodec#3337.
Keeps the end of avifgridapitest.cc identical to the merge base so that
merging main (which appends the CellsTooManyForDimgReferenceCount test
from AOMediaCodec#3354 there) does not conflict.
…limit

avifEncoderDataCreateItem() now returns AVIF_RESULT_NOT_IMPLEMENTED when
there is no unsigned int(16) item ID left, as a safety net for the item
creation paths that are not covered by the upfront check in
avifEncoderAddImageItems() (metadata items, gain maps...).

To let the error code be properly propagated, the function now returns an
avifResult through an out-pointer instead of NULL on failure. This also
fixes latent NULL-dereferences on allocation failure at the
avifEncoderAddImageItems(), avifEncoderCreateBitDepthExtensionItems() and
avifEncoderAddImageInternal() call sites, which did not check for NULL.

Follows the review of AOMediaCodec#3353.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant