Branch: refs/heads/main
  Home:   https://github.com/WebKit/WebKit
  Commit: 9e24a3d38c948f5880764864ed9017cd043543d4
      
https://github.com/WebKit/WebKit/commit/9e24a3d38c948f5880764864ed9017cd043543d4
  Author: Przemyslaw Gorszkowski <[email protected]>
  Date:   2026-09-29 (Tue, 29 Sep 2026)

  Changed paths:
    M 
Source/WebCore/platform/graphics/gstreamer/GStreamerVideoFrameConverter.cpp
    M Source/WebCore/platform/graphics/gstreamer/MediaSampleGStreamer.cpp
    M Source/WebCore/platform/graphics/gstreamer/VideoFrameGStreamer.cpp
    M Source/WebCore/platform/graphics/gstreamer/VideoFrameMetadataGStreamer.cpp
    M Source/WebCore/platform/mediastream/gstreamer/GStreamerCapturer.cpp
    M 
Source/WebCore/platform/mediastream/libwebrtc/gstreamer/RealtimeOutgoingAudioSourceLibWebRTC.cpp

  Log Message:
  -----------
  [GStreamer] crash if we try to add metadata to not writable buffer
https://bugs.webkit.org/show_bug.cgi?id=324960

Reviewed by Philippe Normand.

gst_buffer_make_writable() returns the buffer itself when it is already
writable. Otherwise it returns a shallow copy and drops the reference to the
original. The copy fails and NULL is returned when the buffer holds memory
that can be neither shared nor copied, for example memory that cannot be
mapped. Several call sites used the result without checking it, which led
to null pointer dereferences.

When gst_buffer_make_writable() fails, it only drops the reference that was
passed to it. The original buffer stays alive, still held by its sample or
by the pad probe info. Each call site now checks for NULL and handles the
failure as follows:

- Pad probes leave the original buffer in place and let it pass through
  unmodified.
- Functions that create a new sample or frame return nullptr. Their callers
  already handle that case.
- The MediaSampleGStreamer copy functions return a fake sample with the
  requested timing and flags.
- MediaSampleGStreamer::updateSampleTimestamps() logs an error and leaves
  the buffer timestamps unchanged.

No new tests. The failure depends on the memory type of the underlying buffer
and cannot be triggered from a layout test. Existing media, MSE, mediastream,
WebCodecs and WebRTC tests cover the non-failing paths.

* Source/WebCore/platform/graphics/gstreamer/GStreamerVideoFrameConverter.cpp:
(WebCore::GStreamerVideoFrameConverter::convert):
* Source/WebCore/platform/graphics/gstreamer/MediaSampleGStreamer.cpp:
(WebCore::MediaSampleGStreamer::updateSampleTimestamps):
(WebCore::MediaSampleGStreamer::createNonDisplayingCopy const):
(WebCore::MediaSampleGStreamer::createCopyWithAdjustedStartTime const):
* Source/WebCore/platform/graphics/gstreamer/VideoFrameGStreamer.cpp:
(WebCore::VideoFrameGStreamer::createFromPixelBuffer):
(WebCore::VideoFrameGStreamer::setMetadata):
* Source/WebCore/platform/graphics/gstreamer/VideoFrameMetadataGStreamer.cpp:
(webkitGstBufferSetVideoFrameMetadata):
(webkitGstTraceProcessingTimeForElement):
* Source/WebCore/platform/mediastream/gstreamer/GStreamerCapturer.cpp:
* 
Source/WebCore/platform/mediastream/libwebrtc/gstreamer/RealtimeOutgoingAudioSourceLibWebRTC.cpp:
(WebCore::RealtimeOutgoingAudioSourceLibWebRTC::pullAudioData):

Canonical link: https://commits.webkit.org/322152@main



To unsubscribe from these emails, change your notification settings at 
https://github.com/WebKit/WebKit/settings/notifications

Reply via email to