2011/11/17 Måns Rullgård <[email protected]>:
> Alex Converse <[email protected]> writes:
>
>> From: Thierry Foucu <[email protected]>
>>
>> Found with Address Sanitizer
>> ---
>>  libavcodec/vp6.c |    8 +++++---
>>  1 files changed, 5 insertions(+), 3 deletions(-)
>>
>> diff --git a/libavcodec/vp6.c b/libavcodec/vp6.c
>> index 03024fa..b594003 100644
>> --- a/libavcodec/vp6.c
>> +++ b/libavcodec/vp6.c
>> @@ -442,7 +442,7 @@ static void vp6_parse_coeff(VP56Context *s)
>>          model1 = model->coeff_dccv[pt];
>>          model2 = model->coeff_dcct[pt][ctx];
>>
>> -        for (coeff_idx=0; coeff_idx<64; ) {
>> +        for (coeff_idx=0;;) {
>
> This looks a bit unusual.
>

If you mean stylistically I'm happy to split out the initial assignment.

If you mean functionally, the code decodes a rac coefficient (or run)
then looks-up the probability model for the next coefficient. After
decoding the last rac looking up the computation of the probability
model makes the illegal read, so I have simply moved the loop
termination condition. Alternatively, I could move the lookup to the
top of the loop and special case the first iteration (but the way the
patch is currently structured is more consistent with the rest of the
file).

>>              if ((coeff_idx>1 && ct==0) || vp56_rac_get_prob(c, model2[0])) {
>>                  /* parse a coeff */
>>                  if (vp56_rac_get_prob(c, model2[2])) {
>> @@ -483,8 +483,10 @@ static void vp6_parse_coeff(VP56Context *s)
>>                              run += vp56_rac_get_prob(c, model3[i+8]) << i;
>>                  }
>>              }
>> -
>> -            cg = vp6_coeff_groups[coeff_idx+=run];
>> +            coeff_idx += run;
>> +            if (coeff_idx >= 64)
>> +                break;
>> +            cg = vp6_coeff_groups[coeff_idx];
>>              model1 = model2 = model->coeff_ract[pt][ct][cg];
>>          }
>>

(left for context)

--Alex
_______________________________________________
libav-devel mailing list
[email protected]
https://lists.libav.org/mailman/listinfo/libav-devel

Reply via email to