• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 /*
2  * "Real" compatible demuxer.
3  * Copyright (c) 2000, 2001 Fabrice Bellard
4  *
5  * This file is part of FFmpeg.
6  *
7  * FFmpeg is free software; you can redistribute it and/or
8  * modify it under the terms of the GNU Lesser General Public
9  * License as published by the Free Software Foundation; either
10  * version 2.1 of the License, or (at your option) any later version.
11  *
12  * FFmpeg is distributed in the hope that it will be useful,
13  * but WITHOUT ANY WARRANTY; without even the implied warranty of
14  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
15  * Lesser General Public License for more details.
16  *
17  * You should have received a copy of the GNU Lesser General Public
18  * License along with FFmpeg; if not, write to the Free Software
19  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
20  */
21 
22 #include <inttypes.h>
23 
24 #include "libavutil/avassert.h"
25 #include "libavutil/avstring.h"
26 #include "libavutil/channel_layout.h"
27 #include "libavutil/internal.h"
28 #include "libavutil/intreadwrite.h"
29 #include "libavutil/dict.h"
30 #include "avformat.h"
31 #include "avio_internal.h"
32 #include "internal.h"
33 #include "rmsipr.h"
34 #include "rm.h"
35 
36 #define DEINT_ID_GENR MKTAG('g', 'e', 'n', 'r') ///< interleaving for Cooker/ATRAC
37 #define DEINT_ID_INT0 MKTAG('I', 'n', 't', '0') ///< no interleaving needed
38 #define DEINT_ID_INT4 MKTAG('I', 'n', 't', '4') ///< interleaving for 28.8
39 #define DEINT_ID_SIPR MKTAG('s', 'i', 'p', 'r') ///< interleaving for Sipro
40 #define DEINT_ID_VBRF MKTAG('v', 'b', 'r', 'f') ///< VBR case for AAC
41 #define DEINT_ID_VBRS MKTAG('v', 'b', 'r', 's') ///< VBR case for AAC
42 
43 struct RMStream {
44     AVPacket pkt;      ///< place to store merged video frame / reordered audio data
45     int videobufsize;  ///< current assembled frame size
46     int videobufpos;   ///< position for the next slice in the video buffer
47     int curpic_num;    ///< picture number of current frame
48     int cur_slice, slices;
49     int64_t pktpos;    ///< first slice position in file
50     /// Audio descrambling matrix parameters
51     int64_t audiotimestamp; ///< Audio packet timestamp
52     int sub_packet_cnt; // Subpacket counter, used while reading
53     int sub_packet_size, sub_packet_h, coded_framesize; ///< Descrambling parameters from container
54     int audio_framesize; /// Audio frame size from container
55     int sub_packet_lengths[16]; /// Length of each subpacket
56     int32_t deint_id;  ///< deinterleaver used in audio stream
57 };
58 
59 typedef struct RMDemuxContext {
60     int nb_packets;
61     int old_format;
62     int current_stream;
63     int remaining_len;
64     int audio_stream_num; ///< Stream number for audio packets
65     int audio_pkt_cnt; ///< Output packet counter
66     int data_end;
67 } RMDemuxContext;
68 
69 static int rm_read_close(AVFormatContext *s);
70 
get_strl(AVIOContext * pb,char * buf,int buf_size,int len)71 static inline void get_strl(AVIOContext *pb, char *buf, int buf_size, int len)
72 {
73     int read = avio_get_str(pb, len, buf, buf_size);
74 
75     if (read > 0)
76         avio_skip(pb, len - read);
77 }
78 
get_str8(AVIOContext * pb,char * buf,int buf_size)79 static void get_str8(AVIOContext *pb, char *buf, int buf_size)
80 {
81     get_strl(pb, buf, buf_size, avio_r8(pb));
82 }
83 
rm_read_extradata(AVFormatContext * s,AVIOContext * pb,AVCodecParameters * par,unsigned size)84 static int rm_read_extradata(AVFormatContext *s, AVIOContext *pb, AVCodecParameters *par, unsigned size)
85 {
86     if (size >= 1<<24) {
87         av_log(s, AV_LOG_ERROR, "extradata size %u too large\n", size);
88         return -1;
89     }
90     return ff_get_extradata(s, par, pb, size);
91 }
92 
rm_read_metadata(AVFormatContext * s,AVIOContext * pb,int wide)93 static void rm_read_metadata(AVFormatContext *s, AVIOContext *pb, int wide)
94 {
95     char buf[1024];
96     int i;
97 
98     for (i=0; i<FF_ARRAY_ELEMS(ff_rm_metadata); i++) {
99         int len = wide ? avio_rb16(pb) : avio_r8(pb);
100         if (len > 0) {
101             get_strl(pb, buf, sizeof(buf), len);
102             av_dict_set(&s->metadata, ff_rm_metadata[i], buf, 0);
103         }
104     }
105 }
106 
ff_rm_alloc_rmstream(void)107 RMStream *ff_rm_alloc_rmstream (void)
108 {
109     RMStream *rms = av_mallocz(sizeof(RMStream));
110     if (!rms)
111         return NULL;
112     rms->curpic_num = -1;
113     return rms;
114 }
115 
ff_rm_free_rmstream(RMStream * rms)116 void ff_rm_free_rmstream (RMStream *rms)
117 {
118     if (!rms)
119         return;
120 
121     av_packet_unref(&rms->pkt);
122 }
123 
rm_read_audio_stream_info(AVFormatContext * s,AVIOContext * pb,AVStream * st,RMStream * ast,int read_all)124 static int rm_read_audio_stream_info(AVFormatContext *s, AVIOContext *pb,
125                                      AVStream *st, RMStream *ast, int read_all)
126 {
127     char buf[256];
128     uint32_t version;
129     int ret;
130 
131     // Duplicate tags
132     if (st->codecpar->codec_type == AVMEDIA_TYPE_AUDIO)
133         return AVERROR_INVALIDDATA;
134 
135     /* ra type header */
136     version = avio_rb16(pb); /* version */
137     if (version == 3) {
138         unsigned bytes_per_minute;
139         int header_size = avio_rb16(pb);
140         int64_t startpos = avio_tell(pb);
141         avio_skip(pb, 8);
142         bytes_per_minute = avio_rb16(pb);
143         avio_skip(pb, 4);
144         rm_read_metadata(s, pb, 0);
145         if ((startpos + header_size) >= avio_tell(pb) + 2) {
146             // fourcc (should always be "lpcJ")
147             avio_r8(pb);
148             get_str8(pb, buf, sizeof(buf));
149         }
150         // Skip extra header crap (this should never happen)
151         if ((startpos + header_size) > avio_tell(pb))
152             avio_skip(pb, header_size + startpos - avio_tell(pb));
153         if (bytes_per_minute)
154             st->codecpar->bit_rate = 8LL * bytes_per_minute / 60;
155         st->codecpar->sample_rate = 8000;
156         st->codecpar->channels = 1;
157         st->codecpar->channel_layout = AV_CH_LAYOUT_MONO;
158         st->codecpar->codec_type = AVMEDIA_TYPE_AUDIO;
159         st->codecpar->codec_id = AV_CODEC_ID_RA_144;
160         ast->deint_id = DEINT_ID_INT0;
161     } else {
162         int flavor, sub_packet_h, coded_framesize, sub_packet_size;
163         int codecdata_length;
164         unsigned bytes_per_minute;
165         /* old version (4) */
166         avio_skip(pb, 2); /* unused */
167         avio_rb32(pb); /* .ra4 */
168         avio_rb32(pb); /* data size */
169         avio_rb16(pb); /* version2 */
170         avio_rb32(pb); /* header size */
171         flavor= avio_rb16(pb); /* add codec info / flavor */
172         coded_framesize = avio_rb32(pb); /* coded frame size */
173         if (coded_framesize < 0)
174             return AVERROR_INVALIDDATA;
175         ast->coded_framesize = coded_framesize;
176 
177         avio_rb32(pb); /* ??? */
178         bytes_per_minute = avio_rb32(pb);
179         if (version == 4) {
180             if (bytes_per_minute)
181                 st->codecpar->bit_rate = 8LL * bytes_per_minute / 60;
182         }
183         avio_rb32(pb); /* ??? */
184         ast->sub_packet_h = sub_packet_h = avio_rb16(pb); /* 1 */
185         st->codecpar->block_align= avio_rb16(pb); /* frame size */
186         ast->sub_packet_size = sub_packet_size = avio_rb16(pb); /* sub packet size */
187         avio_rb16(pb); /* ??? */
188         if (version == 5) {
189             avio_rb16(pb); avio_rb16(pb); avio_rb16(pb);
190         }
191         st->codecpar->sample_rate = avio_rb16(pb);
192         avio_rb32(pb);
193         st->codecpar->channels = avio_rb16(pb);
194         if (version == 5) {
195             ast->deint_id = avio_rl32(pb);
196             avio_read(pb, buf, 4);
197             buf[4] = 0;
198         } else {
199             AV_WL32(buf, 0);
200             get_str8(pb, buf, sizeof(buf)); /* desc */
201             ast->deint_id = AV_RL32(buf);
202             get_str8(pb, buf, sizeof(buf)); /* desc */
203         }
204         st->codecpar->codec_type = AVMEDIA_TYPE_AUDIO;
205         st->codecpar->codec_tag  = AV_RL32(buf);
206         st->codecpar->codec_id   = ff_codec_get_id(ff_rm_codec_tags,
207                                                    st->codecpar->codec_tag);
208 
209         switch (st->codecpar->codec_id) {
210         case AV_CODEC_ID_AC3:
211             st->need_parsing = AVSTREAM_PARSE_FULL;
212             break;
213         case AV_CODEC_ID_RA_288:
214             st->codecpar->extradata_size= 0;
215             av_freep(&st->codecpar->extradata);
216             ast->audio_framesize = st->codecpar->block_align;
217             st->codecpar->block_align = coded_framesize;
218             break;
219         case AV_CODEC_ID_COOK:
220             st->need_parsing = AVSTREAM_PARSE_HEADERS;
221         case AV_CODEC_ID_ATRAC3:
222         case AV_CODEC_ID_SIPR:
223             if (read_all) {
224                 codecdata_length = 0;
225             } else {
226                 avio_rb16(pb); avio_r8(pb);
227                 if (version == 5)
228                     avio_r8(pb);
229                 codecdata_length = avio_rb32(pb);
230                 if((unsigned)codecdata_length > INT_MAX - AV_INPUT_BUFFER_PADDING_SIZE){
231                     av_log(s, AV_LOG_ERROR, "codecdata_length too large\n");
232                     return -1;
233                 }
234             }
235 
236             ast->audio_framesize = st->codecpar->block_align;
237             if (st->codecpar->codec_id == AV_CODEC_ID_SIPR) {
238                 if (flavor > 3) {
239                     av_log(s, AV_LOG_ERROR, "bad SIPR file flavor %d\n",
240                            flavor);
241                     return -1;
242                 }
243                 st->codecpar->block_align = ff_sipr_subpk_size[flavor];
244                 st->need_parsing = AVSTREAM_PARSE_FULL_RAW;
245             } else {
246                 if(sub_packet_size <= 0){
247                     av_log(s, AV_LOG_ERROR, "sub_packet_size is invalid\n");
248                     return -1;
249                 }
250                 st->codecpar->block_align = ast->sub_packet_size;
251             }
252             if ((ret = rm_read_extradata(s, pb, st->codecpar, codecdata_length)) < 0)
253                 return ret;
254 
255             break;
256         case AV_CODEC_ID_AAC:
257             avio_rb16(pb); avio_r8(pb);
258             if (version == 5)
259                 avio_r8(pb);
260             codecdata_length = avio_rb32(pb);
261             if((unsigned)codecdata_length > INT_MAX - AV_INPUT_BUFFER_PADDING_SIZE){
262                 av_log(s, AV_LOG_ERROR, "codecdata_length too large\n");
263                 return -1;
264             }
265             if (codecdata_length >= 1) {
266                 avio_r8(pb);
267                 if ((ret = rm_read_extradata(s, pb, st->codecpar, codecdata_length - 1)) < 0)
268                     return ret;
269             }
270             break;
271         }
272         switch (ast->deint_id) {
273         case DEINT_ID_INT4:
274             if (ast->coded_framesize > ast->audio_framesize ||
275                 sub_packet_h <= 1 ||
276                 ast->coded_framesize * (uint64_t)sub_packet_h > (2 + (sub_packet_h & 1)) * ast->audio_framesize)
277                 return AVERROR_INVALIDDATA;
278             if (ast->coded_framesize * (uint64_t)sub_packet_h != 2*ast->audio_framesize) {
279                 avpriv_request_sample(s, "mismatching interleaver parameters");
280                 return AVERROR_INVALIDDATA;
281             }
282             break;
283         case DEINT_ID_GENR:
284             if (ast->sub_packet_size <= 0 ||
285                 ast->sub_packet_size > ast->audio_framesize)
286                 return AVERROR_INVALIDDATA;
287             if (ast->audio_framesize % ast->sub_packet_size)
288                 return AVERROR_INVALIDDATA;
289             break;
290         case DEINT_ID_SIPR:
291         case DEINT_ID_INT0:
292         case DEINT_ID_VBRS:
293         case DEINT_ID_VBRF:
294             break;
295         default:
296             av_log(s, AV_LOG_ERROR ,"Unknown interleaver %"PRIX32"\n", ast->deint_id);
297             return AVERROR_INVALIDDATA;
298         }
299         if (ast->deint_id == DEINT_ID_INT4 ||
300             ast->deint_id == DEINT_ID_GENR ||
301             ast->deint_id == DEINT_ID_SIPR) {
302             if (st->codecpar->block_align <= 0 ||
303                 ast->audio_framesize * (uint64_t)sub_packet_h > (unsigned)INT_MAX ||
304                 ast->audio_framesize * sub_packet_h < st->codecpar->block_align)
305                 return AVERROR_INVALIDDATA;
306             if (av_new_packet(&ast->pkt, ast->audio_framesize * sub_packet_h) < 0)
307                 return AVERROR(ENOMEM);
308         }
309 
310         if (read_all) {
311             avio_r8(pb);
312             avio_r8(pb);
313             avio_r8(pb);
314             rm_read_metadata(s, pb, 0);
315         }
316     }
317     return 0;
318 }
319 
ff_rm_read_mdpr_codecdata(AVFormatContext * s,AVIOContext * pb,AVStream * st,RMStream * rst,unsigned int codec_data_size,const uint8_t * mime)320 int ff_rm_read_mdpr_codecdata(AVFormatContext *s, AVIOContext *pb,
321                               AVStream *st, RMStream *rst,
322                               unsigned int codec_data_size, const uint8_t *mime)
323 {
324     unsigned int v;
325     int size;
326     int64_t codec_pos;
327     int ret;
328 
329     if (codec_data_size > INT_MAX)
330         return AVERROR_INVALIDDATA;
331     if (codec_data_size == 0)
332         return 0;
333 
334     avpriv_set_pts_info(st, 64, 1, 1000);
335     codec_pos = avio_tell(pb);
336     v = avio_rb32(pb);
337 
338     if (v == MKTAG(0xfd, 'a', 'r', '.')) {
339         /* ra type header */
340         if (rm_read_audio_stream_info(s, pb, st, rst, 0))
341             return -1;
342     } else if (v == MKBETAG('L', 'S', 'D', ':')) {
343         avio_seek(pb, -4, SEEK_CUR);
344         if ((ret = rm_read_extradata(s, pb, st->codecpar, codec_data_size)) < 0)
345             return ret;
346 
347         st->codecpar->codec_type = AVMEDIA_TYPE_AUDIO;
348         st->codecpar->codec_tag  = AV_RL32(st->codecpar->extradata);
349         st->codecpar->codec_id   = ff_codec_get_id(ff_rm_codec_tags,
350                                                 st->codecpar->codec_tag);
351     } else if(mime && !strcmp(mime, "logical-fileinfo")){
352         int stream_count, rule_count, property_count, i;
353         ff_free_stream(s, st);
354         if (avio_rb16(pb) != 0) {
355             av_log(s, AV_LOG_WARNING, "Unsupported version\n");
356             goto skip;
357         }
358         stream_count = avio_rb16(pb);
359         avio_skip(pb, 6*stream_count);
360         rule_count = avio_rb16(pb);
361         avio_skip(pb, 2*rule_count);
362         property_count = avio_rb16(pb);
363         for(i=0; i<property_count; i++){
364             uint8_t name[128], val[128];
365             avio_rb32(pb);
366             if (avio_rb16(pb) != 0) {
367                 av_log(s, AV_LOG_WARNING, "Unsupported Name value property version\n");
368                 goto skip; //FIXME skip just this one
369             }
370             get_str8(pb, name, sizeof(name));
371             switch(avio_rb32(pb)) {
372             case 2: get_strl(pb, val, sizeof(val), avio_rb16(pb));
373                 av_dict_set(&s->metadata, name, val, 0);
374                 break;
375             default: avio_skip(pb, avio_rb16(pb));
376             }
377         }
378     } else {
379         int fps;
380         if (avio_rl32(pb) != MKTAG('V', 'I', 'D', 'O')) {
381         fail1:
382             av_log(s, AV_LOG_WARNING, "Unsupported stream type %08x\n", v);
383             goto skip;
384         }
385         st->codecpar->codec_tag = avio_rl32(pb);
386         st->codecpar->codec_id  = ff_codec_get_id(ff_rm_codec_tags,
387                                                   st->codecpar->codec_tag);
388         av_log(s, AV_LOG_TRACE, "%"PRIX32" %X\n",
389                st->codecpar->codec_tag, MKTAG('R', 'V', '2', '0'));
390         if (st->codecpar->codec_id == AV_CODEC_ID_NONE)
391             goto fail1;
392         st->codecpar->width  = avio_rb16(pb);
393         st->codecpar->height = avio_rb16(pb);
394         avio_skip(pb, 2); // looks like bits per sample
395         avio_skip(pb, 4); // always zero?
396         st->codecpar->codec_type = AVMEDIA_TYPE_VIDEO;
397         st->need_parsing = AVSTREAM_PARSE_TIMESTAMPS;
398         fps = avio_rb32(pb);
399 
400         if ((ret = rm_read_extradata(s, pb, st->codecpar, codec_data_size - (avio_tell(pb) - codec_pos))) < 0)
401             return ret;
402 
403         if (fps > 0) {
404             av_reduce(&st->avg_frame_rate.den, &st->avg_frame_rate.num,
405                       0x10000, fps, (1 << 30) - 1);
406 #if FF_API_R_FRAME_RATE
407             st->r_frame_rate = st->avg_frame_rate;
408 #endif
409         } else if (s->error_recognition & AV_EF_EXPLODE) {
410             av_log(s, AV_LOG_ERROR, "Invalid framerate\n");
411             return AVERROR_INVALIDDATA;
412         }
413     }
414 
415 skip:
416     /* skip codec info */
417     size = avio_tell(pb) - codec_pos;
418     if (codec_data_size >= size) {
419         avio_skip(pb, codec_data_size - size);
420     } else {
421         av_log(s, AV_LOG_WARNING, "codec_data_size %u < size %d\n", codec_data_size, size);
422     }
423 
424     return 0;
425 }
426 
427 /** this function assumes that the demuxer has already seeked to the start
428  * of the INDX chunk, and will bail out if not. */
rm_read_index(AVFormatContext * s)429 static int rm_read_index(AVFormatContext *s)
430 {
431     AVIOContext *pb = s->pb;
432     unsigned int size, n_pkts, str_id, next_off, n, pos, pts;
433     AVStream *st;
434 
435     do {
436         if (avio_rl32(pb) != MKTAG('I','N','D','X'))
437             return -1;
438         size     = avio_rb32(pb);
439         if (size < 20)
440             return -1;
441         avio_skip(pb, 2);
442         n_pkts   = avio_rb32(pb);
443         str_id   = avio_rb16(pb);
444         next_off = avio_rb32(pb);
445         for (n = 0; n < s->nb_streams; n++)
446             if (s->streams[n]->id == str_id) {
447                 st = s->streams[n];
448                 break;
449             }
450         if (n == s->nb_streams) {
451             av_log(s, AV_LOG_ERROR,
452                    "Invalid stream index %d for index at pos %"PRId64"\n",
453                    str_id, avio_tell(pb));
454             goto skip;
455         } else if ((avio_size(pb) - avio_tell(pb)) / 14 < n_pkts) {
456             av_log(s, AV_LOG_ERROR,
457                    "Nr. of packets in packet index for stream index %d "
458                    "exceeds filesize (%"PRId64" at %"PRId64" = %"PRId64")\n",
459                    str_id, avio_size(pb), avio_tell(pb),
460                    (avio_size(pb) - avio_tell(pb)) / 14);
461             goto skip;
462         }
463 
464         for (n = 0; n < n_pkts; n++) {
465             if (avio_feof(pb))
466                 return AVERROR_INVALIDDATA;
467             avio_skip(pb, 2);
468             pts = avio_rb32(pb);
469             pos = avio_rb32(pb);
470             avio_skip(pb, 4); /* packet no. */
471 
472             av_add_index_entry(st, pos, pts, 0, 0, AVINDEX_KEYFRAME);
473         }
474 
475 skip:
476         if (next_off && avio_tell(pb) < next_off &&
477             avio_seek(pb, next_off, SEEK_SET) < 0) {
478             av_log(s, AV_LOG_ERROR,
479                    "Non-linear index detected, not supported\n");
480             return -1;
481         }
482     } while (next_off);
483 
484     return 0;
485 }
486 
rm_read_header_old(AVFormatContext * s)487 static int rm_read_header_old(AVFormatContext *s)
488 {
489     RMDemuxContext *rm = s->priv_data;
490     AVStream *st;
491 
492     rm->old_format = 1;
493     st = avformat_new_stream(s, NULL);
494     if (!st)
495         return -1;
496     st->priv_data = ff_rm_alloc_rmstream();
497     if (!st->priv_data)
498         return AVERROR(ENOMEM);
499     return rm_read_audio_stream_info(s, s->pb, st, st->priv_data, 1);
500 }
501 
rm_read_multi(AVFormatContext * s,AVIOContext * pb,AVStream * st,char * mime)502 static int rm_read_multi(AVFormatContext *s, AVIOContext *pb,
503                          AVStream *st, char *mime)
504 {
505     int number_of_streams = avio_rb16(pb);
506     int number_of_mdpr;
507     int i, ret;
508     unsigned size2;
509     for (i = 0; i<number_of_streams; i++)
510         avio_rb16(pb);
511     number_of_mdpr = avio_rb16(pb);
512     if (number_of_mdpr != 1) {
513         avpriv_request_sample(s, "MLTI with multiple (%d) MDPR", number_of_mdpr);
514     }
515     for (i = 0; i < number_of_mdpr; i++) {
516         AVStream *st2;
517         if (i > 0) {
518             st2 = avformat_new_stream(s, NULL);
519             if (!st2) {
520                 ret = AVERROR(ENOMEM);
521                 return ret;
522             }
523             st2->id = st->id + (i<<16);
524             st2->codecpar->bit_rate = st->codecpar->bit_rate;
525             st2->start_time = st->start_time;
526             st2->duration   = st->duration;
527             st2->codecpar->codec_type = AVMEDIA_TYPE_DATA;
528             st2->priv_data = ff_rm_alloc_rmstream();
529             if (!st2->priv_data)
530                 return AVERROR(ENOMEM);
531         } else
532             st2 = st;
533 
534         size2 = avio_rb32(pb);
535         ret = ff_rm_read_mdpr_codecdata(s, s->pb, st2, st2->priv_data,
536                                         size2, NULL);
537         if (ret < 0)
538             return ret;
539     }
540     return 0;
541 }
542 
rm_read_header(AVFormatContext * s)543 static int rm_read_header(AVFormatContext *s)
544 {
545     RMDemuxContext *rm = s->priv_data;
546     AVStream *st;
547     AVIOContext *pb = s->pb;
548     unsigned int tag;
549     int tag_size;
550     unsigned int start_time, duration;
551     unsigned int data_off = 0, indx_off = 0;
552     char buf[128], mime[128];
553     int flags = 0;
554     int ret;
555     unsigned size, v;
556     int64_t codec_pos;
557 
558     tag = avio_rl32(pb);
559     if (tag == MKTAG('.', 'r', 'a', 0xfd)) {
560         /* very old .ra format */
561         return rm_read_header_old(s);
562     } else if (tag != MKTAG('.', 'R', 'M', 'F')) {
563         return AVERROR(EIO);
564     }
565 
566     tag_size = avio_rb32(pb);
567     avio_skip(pb, tag_size - 8);
568 
569     for(;;) {
570         ret = AVERROR_INVALIDDATA;
571         if (avio_feof(pb))
572             goto fail;
573         tag = avio_rl32(pb);
574         tag_size = avio_rb32(pb);
575         avio_rb16(pb);
576         av_log(s, AV_LOG_TRACE, "tag=%s size=%d\n",
577                av_fourcc2str(tag), tag_size);
578         if (tag_size < 10 && tag != MKTAG('D', 'A', 'T', 'A'))
579             goto fail;
580         switch(tag) {
581         case MKTAG('P', 'R', 'O', 'P'):
582             /* file header */
583             avio_rb32(pb); /* max bit rate */
584             avio_rb32(pb); /* avg bit rate */
585             avio_rb32(pb); /* max packet size */
586             avio_rb32(pb); /* avg packet size */
587             avio_rb32(pb); /* nb packets */
588             duration = avio_rb32(pb); /* duration */
589             s->duration = av_rescale(duration, AV_TIME_BASE, 1000);
590             avio_rb32(pb); /* preroll */
591             indx_off = avio_rb32(pb); /* index offset */
592             data_off = avio_rb32(pb); /* data offset */
593             avio_rb16(pb); /* nb streams */
594             flags = avio_rb16(pb); /* flags */
595             break;
596         case MKTAG('C', 'O', 'N', 'T'):
597             rm_read_metadata(s, pb, 1);
598             break;
599         case MKTAG('M', 'D', 'P', 'R'):
600             st = avformat_new_stream(s, NULL);
601             if (!st) {
602                 ret = AVERROR(ENOMEM);
603                 goto fail;
604             }
605             st->id = avio_rb16(pb);
606             avio_rb32(pb); /* max bit rate */
607             st->codecpar->bit_rate = avio_rb32(pb); /* bit rate */
608             avio_rb32(pb); /* max packet size */
609             avio_rb32(pb); /* avg packet size */
610             start_time = avio_rb32(pb); /* start time */
611             avio_rb32(pb); /* preroll */
612             duration = avio_rb32(pb); /* duration */
613             st->start_time = start_time;
614             st->duration = duration;
615             if(duration>0)
616                 s->duration = AV_NOPTS_VALUE;
617             get_str8(pb, buf, sizeof(buf)); /* desc */
618             get_str8(pb, mime, sizeof(mime)); /* mimetype */
619             st->codecpar->codec_type = AVMEDIA_TYPE_DATA;
620             st->priv_data = ff_rm_alloc_rmstream();
621             if (!st->priv_data) {
622                 ret = AVERROR(ENOMEM);
623                 goto fail;
624             }
625 
626             size = avio_rb32(pb);
627             codec_pos = avio_tell(pb);
628 
629             ffio_ensure_seekback(pb, 4);
630             v = avio_rb32(pb);
631             if (v == MKBETAG('M', 'L', 'T', 'I')) {
632                 ret = rm_read_multi(s, s->pb, st, mime);
633                 if (ret < 0)
634                     goto fail;
635                 avio_seek(pb, codec_pos + size, SEEK_SET);
636             } else {
637                 avio_skip(pb, -4);
638                 ret = ff_rm_read_mdpr_codecdata(s, s->pb, st, st->priv_data,
639                                                 size, mime);
640                 if (ret < 0)
641                     goto fail;
642             }
643 
644             break;
645         case MKTAG('D', 'A', 'T', 'A'):
646             goto header_end;
647         default:
648             /* unknown tag: skip it */
649             avio_skip(pb, tag_size - 10);
650             break;
651         }
652     }
653  header_end:
654     rm->nb_packets = avio_rb32(pb); /* number of packets */
655     if (!rm->nb_packets && (flags & 4))
656         rm->nb_packets = 3600 * 25;
657     avio_rb32(pb); /* next data header */
658 
659     if (!data_off)
660         data_off = avio_tell(pb) - 18;
661     if (indx_off && (pb->seekable & AVIO_SEEKABLE_NORMAL) &&
662         !(s->flags & AVFMT_FLAG_IGNIDX) &&
663         avio_seek(pb, indx_off, SEEK_SET) >= 0) {
664         rm_read_index(s);
665         avio_seek(pb, data_off + 18, SEEK_SET);
666     }
667 
668     return 0;
669 
670 fail:
671     rm_read_close(s);
672     return ret;
673 }
674 
get_num(AVIOContext * pb,int * len)675 static int get_num(AVIOContext *pb, int *len)
676 {
677     int n, n1;
678 
679     n = avio_rb16(pb);
680     (*len)-=2;
681     n &= 0x7FFF;
682     if (n >= 0x4000) {
683         return n - 0x4000;
684     } else {
685         n1 = avio_rb16(pb);
686         (*len)-=2;
687         return (n << 16) | n1;
688     }
689 }
690 
691 /* multiple of 20 bytes for ra144 (ugly) */
692 #define RAW_PACKET_SIZE 1000
693 
rm_sync(AVFormatContext * s,int64_t * timestamp,int * flags,int * stream_index,int64_t * pos)694 static int rm_sync(AVFormatContext *s, int64_t *timestamp, int *flags, int *stream_index, int64_t *pos){
695     RMDemuxContext *rm = s->priv_data;
696     AVIOContext *pb = s->pb;
697     AVStream *st;
698     uint32_t state=0xFFFFFFFF;
699 
700     while(!avio_feof(pb)){
701         int len, num, i;
702         int mlti_id;
703         *pos= avio_tell(pb) - 3;
704         if(rm->remaining_len > 0){
705             num= rm->current_stream;
706             mlti_id = 0;
707             len= rm->remaining_len;
708             *timestamp = AV_NOPTS_VALUE;
709             *flags= 0;
710         }else{
711             state= (state<<8) + avio_r8(pb);
712 
713             if(state == MKBETAG('I', 'N', 'D', 'X')){
714                 int n_pkts;
715                 int64_t expected_len;
716                 len = avio_rb32(pb);
717                 avio_skip(pb, 2);
718                 n_pkts = avio_rb32(pb);
719                 expected_len = 20 + n_pkts * 14LL;
720 
721                 if (len == 20 && expected_len <= INT_MAX)
722                     /* some files don't add index entries to chunk size... */
723                     len = expected_len;
724                 else if (len != expected_len)
725                     av_log(s, AV_LOG_WARNING,
726                            "Index size %d (%d pkts) is wrong, should be %"PRId64".\n",
727                            len, n_pkts, expected_len);
728                 if(len < 14)
729                     continue;
730                 len -= 14; // we already read part of the index header
731                 goto skip;
732             } else if (state == MKBETAG('D','A','T','A')) {
733                 av_log(s, AV_LOG_WARNING,
734                        "DATA tag in middle of chunk, file may be broken.\n");
735             }
736 
737             if(state > (unsigned)0xFFFF || state <= 12)
738                 continue;
739             len=state - 12;
740             state= 0xFFFFFFFF;
741 
742             num = avio_rb16(pb);
743             *timestamp = avio_rb32(pb);
744             mlti_id = (avio_r8(pb) >> 1) - 1;
745             mlti_id = FFMAX(mlti_id, 0) << 16;
746             *flags = avio_r8(pb); /* flags */
747         }
748         for(i=0;i<s->nb_streams;i++) {
749             st = s->streams[i];
750             if (mlti_id + num == st->id)
751                 break;
752         }
753         if (i == s->nb_streams) {
754 skip:
755             /* skip packet if unknown number */
756             avio_skip(pb, len);
757             rm->remaining_len = 0;
758             continue;
759         }
760         *stream_index= i;
761 
762         return len;
763     }
764     return -1;
765 }
766 
rm_assemble_video_frame(AVFormatContext * s,AVIOContext * pb,RMDemuxContext * rm,RMStream * vst,AVPacket * pkt,int len,int * pseq,int64_t * timestamp)767 static int rm_assemble_video_frame(AVFormatContext *s, AVIOContext *pb,
768                                    RMDemuxContext *rm, RMStream *vst,
769                                    AVPacket *pkt, int len, int *pseq,
770                                    int64_t *timestamp)
771 {
772     int hdr;
773     int seq = 0, pic_num = 0, len2 = 0, pos = 0; //init to silence compiler warning
774     int type;
775     int ret;
776 
777     hdr = avio_r8(pb); len--;
778     type = hdr >> 6;
779 
780     if(type != 3){  // not frame as a part of packet
781         seq = avio_r8(pb); len--;
782     }
783     if(type != 1){  // not whole frame
784         len2 = get_num(pb, &len);
785         pos  = get_num(pb, &len);
786         pic_num = avio_r8(pb); len--;
787     }
788     if(len<0) {
789         av_log(s, AV_LOG_ERROR, "Insufficient data\n");
790         return -1;
791     }
792     rm->remaining_len = len;
793     if(type&1){     // frame, not slice
794         if(type == 3){  // frame as a part of packet
795             len= len2;
796             *timestamp = pos;
797         }
798         if(rm->remaining_len < len) {
799             av_log(s, AV_LOG_ERROR, "Insufficient remaining len\n");
800             return -1;
801         }
802         rm->remaining_len -= len;
803         if ((ret = av_new_packet(pkt, len + 9)) < 0)
804             return ret;
805         pkt->data[0] = 0;
806         AV_WL32(pkt->data + 1, 1);
807         AV_WL32(pkt->data + 5, 0);
808         if ((ret = avio_read(pb, pkt->data + 9, len)) != len) {
809             av_packet_unref(pkt);
810             av_log(s, AV_LOG_ERROR, "Failed to read %d bytes\n", len);
811             return ret < 0 ? ret : AVERROR(EIO);
812         }
813         return 0;
814     }
815     //now we have to deal with single slice
816 
817     *pseq = seq;
818     if((seq & 0x7F) == 1 || vst->curpic_num != pic_num){
819         if (len2 > ffio_limit(pb, len2)) {
820             av_log(s, AV_LOG_ERROR, "Impossibly sized packet\n");
821             return AVERROR_INVALIDDATA;
822         }
823         vst->slices = ((hdr & 0x3F) << 1) + 1;
824         vst->videobufsize = len2 + 8*vst->slices + 1;
825         av_packet_unref(&vst->pkt); //FIXME this should be output.
826         if ((ret = av_new_packet(&vst->pkt, vst->videobufsize)) < 0)
827             return ret;
828         vst->videobufpos = 8*vst->slices + 1;
829         vst->cur_slice = 0;
830         vst->curpic_num = pic_num;
831         vst->pktpos = avio_tell(pb);
832     }
833     if(type == 2)
834         len = FFMIN(len, pos);
835 
836     if(++vst->cur_slice > vst->slices) {
837         av_log(s, AV_LOG_ERROR, "cur slice %d, too large\n", vst->cur_slice);
838         return 1;
839     }
840     if(!vst->pkt.data)
841         return AVERROR(ENOMEM);
842     AV_WL32(vst->pkt.data - 7 + 8*vst->cur_slice, 1);
843     AV_WL32(vst->pkt.data - 3 + 8*vst->cur_slice, vst->videobufpos - 8*vst->slices - 1);
844     if(vst->videobufpos + len > vst->videobufsize) {
845         av_log(s, AV_LOG_ERROR, "outside videobufsize\n");
846         return 1;
847     }
848     if (avio_read(pb, vst->pkt.data + vst->videobufpos, len) != len)
849         return AVERROR(EIO);
850     vst->videobufpos += len;
851     rm->remaining_len-= len;
852 
853     if (type == 2 || vst->videobufpos == vst->videobufsize) {
854         vst->pkt.data[0] = vst->cur_slice-1;
855         av_packet_move_ref(pkt, &vst->pkt);
856         if(vst->slices != vst->cur_slice) //FIXME find out how to set slices correct from the begin
857             memmove(pkt->data + 1 + 8*vst->cur_slice, pkt->data + 1 + 8*vst->slices,
858                 vst->videobufpos - 1 - 8*vst->slices);
859         av_shrink_packet(pkt, vst->videobufpos + 8*(vst->cur_slice - vst->slices));
860         pkt->pts = AV_NOPTS_VALUE;
861         pkt->pos = vst->pktpos;
862         vst->slices = 0;
863         return 0;
864     }
865 
866     return 1;
867 }
868 
869 static inline void
rm_ac3_swap_bytes(AVStream * st,AVPacket * pkt)870 rm_ac3_swap_bytes (AVStream *st, AVPacket *pkt)
871 {
872     uint8_t *ptr;
873     int j;
874 
875     if (st->codecpar->codec_id == AV_CODEC_ID_AC3) {
876         ptr = pkt->data;
877         for (j=0;j<pkt->size;j+=2) {
878             FFSWAP(int, ptr[0], ptr[1]);
879             ptr += 2;
880         }
881     }
882 }
883 
readfull(AVFormatContext * s,AVIOContext * pb,uint8_t * dst,int n)884 static int readfull(AVFormatContext *s, AVIOContext *pb, uint8_t *dst, int n) {
885     int ret = avio_read(pb, dst, n);
886     if (ret != n) {
887         if (ret >= 0) memset(dst + ret, 0, n - ret);
888         else          memset(dst      , 0, n);
889         av_log(s, AV_LOG_ERROR, "Failed to fully read block\n");
890     }
891     return ret;
892 }
893 
894 int
ff_rm_parse_packet(AVFormatContext * s,AVIOContext * pb,AVStream * st,RMStream * ast,int len,AVPacket * pkt,int * seq,int flags,int64_t timestamp)895 ff_rm_parse_packet (AVFormatContext *s, AVIOContext *pb,
896                     AVStream *st, RMStream *ast, int len, AVPacket *pkt,
897                     int *seq, int flags, int64_t timestamp)
898 {
899     RMDemuxContext *rm = s->priv_data;
900     int ret;
901 
902     if (st->codecpar->codec_type == AVMEDIA_TYPE_VIDEO) {
903         rm->current_stream= st->id;
904         ret = rm_assemble_video_frame(s, pb, rm, ast, pkt, len, seq, &timestamp);
905         if(ret)
906             return ret < 0 ? ret : -1; //got partial frame or error
907     } else if (st->codecpar->codec_type == AVMEDIA_TYPE_AUDIO) {
908         if ((ast->deint_id == DEINT_ID_GENR) ||
909             (ast->deint_id == DEINT_ID_INT4) ||
910             (ast->deint_id == DEINT_ID_SIPR)) {
911             int x;
912             int sps = ast->sub_packet_size;
913             int cfs = ast->coded_framesize;
914             int h = ast->sub_packet_h;
915             int y = ast->sub_packet_cnt;
916             int w = ast->audio_framesize;
917 
918             if (flags & 2)
919                 y = ast->sub_packet_cnt = 0;
920             if (!y)
921                 ast->audiotimestamp = timestamp;
922 
923             switch (ast->deint_id) {
924                 case DEINT_ID_INT4:
925                     for (x = 0; x < h/2; x++)
926                         readfull(s, pb, ast->pkt.data+x*2*w+y*cfs, cfs);
927                     break;
928                 case DEINT_ID_GENR:
929                     for (x = 0; x < w/sps; x++)
930                         readfull(s, pb, ast->pkt.data+sps*(h*x+((h+1)/2)*(y&1)+(y>>1)), sps);
931                     break;
932                 case DEINT_ID_SIPR:
933                     readfull(s, pb, ast->pkt.data + y * w, w);
934                     break;
935             }
936 
937             if (++(ast->sub_packet_cnt) < h)
938                 return -1;
939             if (ast->deint_id == DEINT_ID_SIPR)
940                 ff_rm_reorder_sipr_data(ast->pkt.data, h, w);
941 
942              ast->sub_packet_cnt = 0;
943              rm->audio_stream_num = st->index;
944             if (st->codecpar->block_align <= 0) {
945                 av_log(s, AV_LOG_ERROR, "Invalid block alignment %d\n", st->codecpar->block_align);
946                 return AVERROR_INVALIDDATA;
947             }
948              rm->audio_pkt_cnt = h * w / st->codecpar->block_align;
949         } else if ((ast->deint_id == DEINT_ID_VBRF) ||
950                    (ast->deint_id == DEINT_ID_VBRS)) {
951             int x;
952             rm->audio_stream_num = st->index;
953             ast->sub_packet_cnt = (avio_rb16(pb) & 0xf0) >> 4;
954             if (ast->sub_packet_cnt) {
955                 for (x = 0; x < ast->sub_packet_cnt; x++)
956                     ast->sub_packet_lengths[x] = avio_rb16(pb);
957                 rm->audio_pkt_cnt = ast->sub_packet_cnt;
958                 ast->audiotimestamp = timestamp;
959             } else
960                 return -1;
961         } else {
962             ret = av_get_packet(pb, pkt, len);
963             if (ret < 0)
964                 return ret;
965             rm_ac3_swap_bytes(st, pkt);
966         }
967     } else {
968         ret = av_get_packet(pb, pkt, len);
969         if (ret < 0)
970             return ret;
971     }
972 
973     pkt->stream_index = st->index;
974 
975     pkt->pts = timestamp;
976     if (flags & 2)
977         pkt->flags |= AV_PKT_FLAG_KEY;
978 
979     return st->codecpar->codec_type == AVMEDIA_TYPE_AUDIO ? rm->audio_pkt_cnt : 0;
980 }
981 
982 int
ff_rm_retrieve_cache(AVFormatContext * s,AVIOContext * pb,AVStream * st,RMStream * ast,AVPacket * pkt)983 ff_rm_retrieve_cache (AVFormatContext *s, AVIOContext *pb,
984                       AVStream *st, RMStream *ast, AVPacket *pkt)
985 {
986     RMDemuxContext *rm = s->priv_data;
987     int ret;
988 
989     av_assert0 (rm->audio_pkt_cnt > 0);
990 
991     if (ast->deint_id == DEINT_ID_VBRF ||
992         ast->deint_id == DEINT_ID_VBRS) {
993         ret = av_get_packet(pb, pkt, ast->sub_packet_lengths[ast->sub_packet_cnt - rm->audio_pkt_cnt]);
994         if (ret < 0)
995             return ret;
996     } else {
997         ret = av_new_packet(pkt, st->codecpar->block_align);
998         if (ret < 0)
999             return ret;
1000         memcpy(pkt->data, ast->pkt.data + st->codecpar->block_align * //FIXME avoid this
1001                (ast->sub_packet_h * ast->audio_framesize / st->codecpar->block_align - rm->audio_pkt_cnt),
1002                st->codecpar->block_align);
1003     }
1004     rm->audio_pkt_cnt--;
1005     if ((pkt->pts = ast->audiotimestamp) != AV_NOPTS_VALUE) {
1006         ast->audiotimestamp = AV_NOPTS_VALUE;
1007         pkt->flags = AV_PKT_FLAG_KEY;
1008     } else
1009         pkt->flags = 0;
1010     pkt->stream_index = st->index;
1011 
1012     return rm->audio_pkt_cnt;
1013 }
1014 
rm_read_packet(AVFormatContext * s,AVPacket * pkt)1015 static int rm_read_packet(AVFormatContext *s, AVPacket *pkt)
1016 {
1017     RMDemuxContext *rm = s->priv_data;
1018     AVStream *st = NULL; // init to silence compiler warning
1019     int i, res, seq = 1;
1020     int64_t timestamp, pos, len;
1021     int flags;
1022 
1023     for (;;) {
1024         if (rm->audio_pkt_cnt) {
1025             // If there are queued audio packet return them first
1026             st = s->streams[rm->audio_stream_num];
1027             res = ff_rm_retrieve_cache(s, s->pb, st, st->priv_data, pkt);
1028             if(res < 0)
1029                 return res;
1030             flags = 0;
1031         } else {
1032             if (rm->old_format) {
1033                 RMStream *ast;
1034 
1035                 st = s->streams[0];
1036                 ast = st->priv_data;
1037                 timestamp = AV_NOPTS_VALUE;
1038                 len = !ast->audio_framesize ? RAW_PACKET_SIZE :
1039                     ast->coded_framesize * (int64_t)ast->sub_packet_h / 2;
1040                 if (len > INT_MAX)
1041                     return AVERROR_INVALIDDATA;
1042                 flags = (seq++ == 1) ? 2 : 0;
1043                 pos = avio_tell(s->pb);
1044             } else {
1045                 len = rm_sync(s, &timestamp, &flags, &i, &pos);
1046                 if (len > 0)
1047                     st = s->streams[i];
1048             }
1049 
1050             if (avio_feof(s->pb))
1051                 return AVERROR_EOF;
1052             if (len <= 0)
1053                 return AVERROR(EIO);
1054 
1055             res = ff_rm_parse_packet (s, s->pb, st, st->priv_data, len, pkt,
1056                                       &seq, flags, timestamp);
1057             if (res < -1)
1058                 return res;
1059             if((flags&2) && (seq&0x7F) == 1)
1060                 av_add_index_entry(st, pos, timestamp, 0, 0, AVINDEX_KEYFRAME);
1061             if (res)
1062                 continue;
1063         }
1064 
1065         if(  (st->discard >= AVDISCARD_NONKEY && !(flags&2))
1066            || st->discard >= AVDISCARD_ALL){
1067             av_packet_unref(pkt);
1068         } else
1069             break;
1070     }
1071 
1072     return 0;
1073 }
1074 
rm_read_close(AVFormatContext * s)1075 static int rm_read_close(AVFormatContext *s)
1076 {
1077     int i;
1078 
1079     for (i=0;i<s->nb_streams;i++)
1080         ff_rm_free_rmstream(s->streams[i]->priv_data);
1081 
1082     return 0;
1083 }
1084 
rm_probe(const AVProbeData * p)1085 static int rm_probe(const AVProbeData *p)
1086 {
1087     /* check file header */
1088     if ((p->buf[0] == '.' && p->buf[1] == 'R' &&
1089          p->buf[2] == 'M' && p->buf[3] == 'F' &&
1090          p->buf[4] == 0 && p->buf[5] == 0) ||
1091         (p->buf[0] == '.' && p->buf[1] == 'r' &&
1092          p->buf[2] == 'a' && p->buf[3] == 0xfd))
1093         return AVPROBE_SCORE_MAX;
1094     else
1095         return 0;
1096 }
1097 
rm_read_dts(AVFormatContext * s,int stream_index,int64_t * ppos,int64_t pos_limit)1098 static int64_t rm_read_dts(AVFormatContext *s, int stream_index,
1099                                int64_t *ppos, int64_t pos_limit)
1100 {
1101     RMDemuxContext *rm = s->priv_data;
1102     int64_t pos, dts;
1103     int stream_index2, flags, len, h;
1104 
1105     pos = *ppos;
1106 
1107     if(rm->old_format)
1108         return AV_NOPTS_VALUE;
1109 
1110     if (avio_seek(s->pb, pos, SEEK_SET) < 0)
1111         return AV_NOPTS_VALUE;
1112 
1113     rm->remaining_len=0;
1114     for(;;){
1115         int seq=1;
1116         AVStream *st;
1117 
1118         len = rm_sync(s, &dts, &flags, &stream_index2, &pos);
1119         if(len<0)
1120             return AV_NOPTS_VALUE;
1121 
1122         st = s->streams[stream_index2];
1123         if (st->codecpar->codec_type == AVMEDIA_TYPE_VIDEO) {
1124             h= avio_r8(s->pb); len--;
1125             if(!(h & 0x40)){
1126                 seq = avio_r8(s->pb); len--;
1127             }
1128         }
1129 
1130         if((flags&2) && (seq&0x7F) == 1){
1131             av_log(s, AV_LOG_TRACE, "%d %d-%d %"PRId64" %d\n",
1132                     flags, stream_index2, stream_index, dts, seq);
1133             av_add_index_entry(st, pos, dts, 0, 0, AVINDEX_KEYFRAME);
1134             if(stream_index2 == stream_index)
1135                 break;
1136         }
1137 
1138         avio_skip(s->pb, len);
1139     }
1140     *ppos = pos;
1141     return dts;
1142 }
1143 
rm_read_seek(AVFormatContext * s,int stream_index,int64_t pts,int flags)1144 static int rm_read_seek(AVFormatContext *s, int stream_index,
1145                         int64_t pts, int flags)
1146 {
1147     RMDemuxContext *rm = s->priv_data;
1148 
1149     if (ff_seek_frame_binary(s, stream_index, pts, flags) < 0)
1150         return -1;
1151     rm->audio_pkt_cnt = 0;
1152     return 0;
1153 }
1154 
1155 
1156 AVInputFormat ff_rm_demuxer = {
1157     .name           = "rm",
1158     .long_name      = NULL_IF_CONFIG_SMALL("RealMedia"),
1159     .priv_data_size = sizeof(RMDemuxContext),
1160     .read_probe     = rm_probe,
1161     .read_header    = rm_read_header,
1162     .read_packet    = rm_read_packet,
1163     .read_close     = rm_read_close,
1164     .read_timestamp = rm_read_dts,
1165     .read_seek      = rm_read_seek,
1166 };
1167 
1168 AVInputFormat ff_rdt_demuxer = {
1169     .name           = "rdt",
1170     .long_name      = NULL_IF_CONFIG_SMALL("RDT demuxer"),
1171     .priv_data_size = sizeof(RMDemuxContext),
1172     .read_close     = rm_read_close,
1173     .flags          = AVFMT_NOFILE,
1174 };
1175 
ivr_probe(const AVProbeData * p)1176 static int ivr_probe(const AVProbeData *p)
1177 {
1178     if (memcmp(p->buf, ".R1M\x0\x1\x1", 7) &&
1179         memcmp(p->buf, ".REC", 4))
1180         return 0;
1181 
1182     return AVPROBE_SCORE_MAX;
1183 }
1184 
ivr_read_header(AVFormatContext * s)1185 static int ivr_read_header(AVFormatContext *s)
1186 {
1187     unsigned tag, type, len, tlen, value;
1188     int i, j, n, count, nb_streams = 0, ret;
1189     uint8_t key[256], val[256];
1190     AVIOContext *pb = s->pb;
1191     AVStream *st;
1192     int64_t pos, offset=0, temp;
1193 
1194     pos = avio_tell(pb);
1195     tag = avio_rl32(pb);
1196     if (tag == MKTAG('.','R','1','M')) {
1197         if (avio_rb16(pb) != 1)
1198             return AVERROR_INVALIDDATA;
1199         if (avio_r8(pb) != 1)
1200             return AVERROR_INVALIDDATA;
1201         len = avio_rb32(pb);
1202         avio_skip(pb, len);
1203         avio_skip(pb, 5);
1204         temp = avio_rb64(pb);
1205         while (!avio_feof(pb) && temp) {
1206             offset = temp;
1207             temp = avio_rb64(pb);
1208         }
1209         if (offset <= 0)
1210             return AVERROR_INVALIDDATA;
1211         avio_skip(pb, offset - avio_tell(pb));
1212         if (avio_r8(pb) != 1)
1213             return AVERROR_INVALIDDATA;
1214         len = avio_rb32(pb);
1215         avio_skip(pb, len);
1216         if (avio_r8(pb) != 2)
1217             return AVERROR_INVALIDDATA;
1218         avio_skip(pb, 16);
1219         pos = avio_tell(pb);
1220         tag = avio_rl32(pb);
1221     }
1222 
1223     if (tag != MKTAG('.','R','E','C'))
1224         return AVERROR_INVALIDDATA;
1225 
1226     if (avio_r8(pb) != 0)
1227         return AVERROR_INVALIDDATA;
1228     count = avio_rb32(pb);
1229     for (i = 0; i < count; i++) {
1230         if (avio_feof(pb))
1231             return AVERROR_INVALIDDATA;
1232 
1233         type = avio_r8(pb);
1234         tlen = avio_rb32(pb);
1235         avio_get_str(pb, tlen, key, sizeof(key));
1236         len = avio_rb32(pb);
1237         if (type == 5) {
1238             avio_get_str(pb, len, val, sizeof(val));
1239             av_log(s, AV_LOG_DEBUG, "%s = '%s'\n", key, val);
1240         } else if (type == 4) {
1241             av_log(s, AV_LOG_DEBUG, "%s = '0x", key);
1242             for (j = 0; j < len; j++) {
1243                 if (avio_feof(pb))
1244                     return AVERROR_INVALIDDATA;
1245                 av_log(s, AV_LOG_DEBUG, "%X", avio_r8(pb));
1246             }
1247             av_log(s, AV_LOG_DEBUG, "'\n");
1248         } else if (len == 4 && type == 3 && !strncmp(key, "StreamCount", tlen)) {
1249             nb_streams = value = avio_rb32(pb);
1250         } else if (len == 4 && type == 3) {
1251             value = avio_rb32(pb);
1252             av_log(s, AV_LOG_DEBUG, "%s = %d\n", key, value);
1253         } else {
1254             av_log(s, AV_LOG_DEBUG, "Skipping unsupported key: %s\n", key);
1255             avio_skip(pb, len);
1256         }
1257     }
1258 
1259     for (n = 0; n < nb_streams; n++) {
1260         if (!(st = avformat_new_stream(s, NULL)) ||
1261             !(st->priv_data = ff_rm_alloc_rmstream())) {
1262             ret = AVERROR(ENOMEM);
1263             goto fail;
1264         }
1265 
1266         if (avio_r8(pb) != 1)
1267             goto invalid_data;
1268 
1269         count = avio_rb32(pb);
1270         for (i = 0; i < count; i++) {
1271             if (avio_feof(pb))
1272                 goto invalid_data;
1273 
1274             type = avio_r8(pb);
1275             tlen  = avio_rb32(pb);
1276             avio_get_str(pb, tlen, key, sizeof(key));
1277             len  = avio_rb32(pb);
1278             if (type == 5) {
1279                 avio_get_str(pb, len, val, sizeof(val));
1280                 av_log(s, AV_LOG_DEBUG, "%s = '%s'\n", key, val);
1281             } else if (type == 4 && !strncmp(key, "OpaqueData", tlen)) {
1282                 ret = ffio_ensure_seekback(pb, 4);
1283                 if (ret < 0)
1284                     goto fail;
1285                 if (avio_rb32(pb) == MKBETAG('M', 'L', 'T', 'I')) {
1286                     ret = rm_read_multi(s, pb, st, NULL);
1287                 } else {
1288                     if (avio_feof(pb))
1289                         goto invalid_data;
1290                     avio_seek(pb, -4, SEEK_CUR);
1291                     ret = ff_rm_read_mdpr_codecdata(s, pb, st, st->priv_data, len, NULL);
1292                 }
1293 
1294                 if (ret < 0)
1295                     goto fail;
1296             } else if (type == 4) {
1297                 int j;
1298 
1299                 av_log(s, AV_LOG_DEBUG, "%s = '0x", key);
1300                 for (j = 0; j < len; j++) {
1301                     if (avio_feof(pb))
1302                         goto invalid_data;
1303                     av_log(s, AV_LOG_DEBUG, "%X", avio_r8(pb));
1304                 }
1305                 av_log(s, AV_LOG_DEBUG, "'\n");
1306             } else if (len == 4 && type == 3 && !strncmp(key, "Duration", tlen)) {
1307                 st->duration = avio_rb32(pb);
1308             } else if (len == 4 && type == 3) {
1309                 value = avio_rb32(pb);
1310                 av_log(s, AV_LOG_DEBUG, "%s = %d\n", key, value);
1311             } else {
1312                 av_log(s, AV_LOG_DEBUG, "Skipping unsupported key: %s\n", key);
1313                 avio_skip(pb, len);
1314             }
1315         }
1316     }
1317 
1318     if (avio_r8(pb) != 6)
1319         goto invalid_data;
1320     avio_skip(pb, 12);
1321     avio_seek(pb, avio_rb64(pb) + pos, SEEK_SET);
1322     if (avio_r8(pb) != 8)
1323         goto invalid_data;
1324     avio_skip(pb, 8);
1325 
1326     return 0;
1327 invalid_data:
1328     ret = AVERROR_INVALIDDATA;
1329 fail:
1330     rm_read_close(s);
1331     return ret;
1332 }
1333 
ivr_read_packet(AVFormatContext * s,AVPacket * pkt)1334 static int ivr_read_packet(AVFormatContext *s, AVPacket *pkt)
1335 {
1336     RMDemuxContext *rm = s->priv_data;
1337     int ret = AVERROR_EOF, opcode;
1338     AVIOContext *pb = s->pb;
1339     unsigned size, index;
1340     int64_t pos, pts;
1341 
1342     if (avio_feof(pb) || rm->data_end)
1343         return AVERROR_EOF;
1344 
1345     pos = avio_tell(pb);
1346 
1347     for (;;) {
1348         if (rm->audio_pkt_cnt) {
1349             // If there are queued audio packet return them first
1350             AVStream *st;
1351 
1352             st = s->streams[rm->audio_stream_num];
1353             ret = ff_rm_retrieve_cache(s, pb, st, st->priv_data, pkt);
1354             if (ret < 0) {
1355                 return ret;
1356             }
1357         } else {
1358             if (rm->remaining_len) {
1359                 avio_skip(pb, rm->remaining_len);
1360                 rm->remaining_len = 0;
1361             }
1362 
1363             if (avio_feof(pb))
1364                 return AVERROR_EOF;
1365 
1366             opcode = avio_r8(pb);
1367             if (opcode == 2) {
1368                 AVStream *st;
1369                 int seq = 1;
1370 
1371                 pts = avio_rb32(pb);
1372                 index = avio_rb16(pb);
1373                 if (index >= s->nb_streams)
1374                     return AVERROR_INVALIDDATA;
1375 
1376                 avio_skip(pb, 4);
1377                 size = avio_rb32(pb);
1378                 avio_skip(pb, 4);
1379 
1380                 if (size < 1 || size > INT_MAX/4) {
1381                     av_log(s, AV_LOG_ERROR, "size %u is invalid\n", size);
1382                     return AVERROR_INVALIDDATA;
1383                 }
1384 
1385                 st = s->streams[index];
1386                 ret = ff_rm_parse_packet(s, pb, st, st->priv_data, size, pkt,
1387                                          &seq, 0, pts);
1388                 if (ret < -1) {
1389                     return ret;
1390                 } else if (ret) {
1391                     continue;
1392                 }
1393 
1394                 pkt->pos = pos;
1395                 pkt->pts = pts;
1396                 pkt->stream_index = index;
1397             } else if (opcode == 7) {
1398                 pos = avio_rb64(pb);
1399                 if (!pos) {
1400                     rm->data_end = 1;
1401                     return AVERROR_EOF;
1402                 }
1403             } else {
1404                 av_log(s, AV_LOG_ERROR, "Unsupported opcode=%d at %"PRIX64"\n", opcode, avio_tell(pb) - 1);
1405                 return AVERROR(EIO);
1406             }
1407         }
1408 
1409         break;
1410     }
1411 
1412     return ret;
1413 }
1414 
1415 AVInputFormat ff_ivr_demuxer = {
1416     .name           = "ivr",
1417     .long_name      = NULL_IF_CONFIG_SMALL("IVR (Internet Video Recording)"),
1418     .priv_data_size = sizeof(RMDemuxContext),
1419     .read_probe     = ivr_probe,
1420     .read_header    = ivr_read_header,
1421     .read_packet    = ivr_read_packet,
1422     .read_close     = rm_read_close,
1423     .extensions     = "ivr",
1424 };
1425