From mboxrd@z Thu Jan  1 00:00:00 1970
Return-Path: <ffmpeg-devel-bounces@ffmpeg.org>
Received: from ffbox0-bg.mplayerhq.hu (ffbox0-bg.ffmpeg.org [79.124.17.100])
	by master.gitmailbox.com (Postfix) with ESMTPS id 4727E4D05C
	for <ffmpegdev@gitmailbox.com>; Mon, 17 Mar 2025 17:49:58 +0000 (UTC)
Received: from [127.0.1.1] (localhost [127.0.0.1])
	by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTP id 48258687C07;
	Mon, 17 Mar 2025 19:49:31 +0200 (EET)
Received: from mail-wm1-f51.google.com (mail-wm1-f51.google.com
 [209.85.128.51])
 by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTPS id 55F59687BA3
 for <ffmpeg-devel@ffmpeg.org>; Mon, 17 Mar 2025 19:49:23 +0200 (EET)
Received: by mail-wm1-f51.google.com with SMTP id
 5b1f17b1804b1-4393dc02b78so15427975e9.3
 for <ffmpeg-devel@ffmpeg.org>; Mon, 17 Mar 2025 10:49:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=gmail.com; s=20230601; t=1742233762; x=1742838562; darn=ffmpeg.org;
 h=content-transfer-encoding:mime-version:references:in-reply-to
 :message-id:date:subject:cc:to:from:from:to:cc:subject:date
 :message-id:reply-to;
 bh=/irI8iOz1ZwNbO2pvNP3X8gUPD9HCfKso9Vx8V2m+zI=;
 b=gqPWh25X6+DryRfNS3aR7cHqgWqVxdyxE8ElRFSSeaRZk2XFseBKyDuJSSYNC752OK
 lY8v2ExnXMgV9oF/Sws2CgC4yzA0zQtIUs6rb0v38aofs+L5jF5iEyuD0SwaIiYDiAuw
 aIuok19LA8xpY5UMGOPaw2cUQ5l15JOBHMDe01/ZsNG5DyBSmHrScia4ZSiNR6No/aSb
 uzzV91LYLUaQJOWrYb5VyxgSWbw7BpHmiz/i/Stwgg3kgA0W4reZFeyeYotLbBFUNnj1
 tic8xgkt4TzixFCrilYUAuaRPjTmujDQjw7s5KzNdelhCCxSgkC+yUWB8b8fSiEvX7S/
 cYxA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20230601; t=1742233762; x=1742838562;
 h=content-transfer-encoding:mime-version:references:in-reply-to
 :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc
 :subject:date:message-id:reply-to;
 bh=/irI8iOz1ZwNbO2pvNP3X8gUPD9HCfKso9Vx8V2m+zI=;
 b=G5hPayfE+UvR1wFOunUCZO1BMNTdiPTFgBoeaWBFOXnXretI+2Mc7DvBOo78ORfU0I
 MMMyF0rHiuwe4bSw7WFIuFeTEm6GASiGQQMvDsZmlhXz1CZqUl7qDIrLJqfI0hE3uTv9
 AUbCOlTUFctiCgxuV6KuqXgn37I/3hv70PZHepD12P7KO4Oflk+1XIsDSDy0iRL/aMPJ
 vSRV8v/KnwsM06MfaSc+q+FfV2uF350663+zHRzB72QwB1dnYZ/464i3eyTBbnWmeJXd
 7+hoUb2SXWWGe+2DzvKcTM/vxkmFFJFMnxDyzPX2AQzugTnUAzqviRItBgKgIw9sJYwL
 gj8Q==
X-Gm-Message-State: AOJu0Yzol7E6/8jOmrCk8IfUqxJ2NjdJDU+J6kNW3CcykBiMCjZmGvZb
 aWnT+8jeRuIPIpCm8wpnDWodHF4AWlXrcsSxY9ogWPZBCAdjg3APbagRdssS
X-Gm-Gg: ASbGnctlHQf0h2MREckXJ2ZDurV2Uu60hCH0VnEZhOVBPwcgN9kzkHf92cZUo4GpLqA
 tirszuIgDZCnoy3zkpUs4LmdIYKcq7R0MAXR2+pWZTpppyahxEfR3dUSYFVyVYxPzUyv8+0lXG+
 shy2d2ifUvsKiY486DUYyuQe22+Ws66crFxCRX+IAfNSiqc+x9X8kVORdgHqEPYwx293jJTDd+X
 tC4OTaG61OyoTvMhMNpoUT/8eRgSOGx3ovaT329BpDR42kht2t35rtEammrwgPAxysk6DYg2TrJ
 y1YANxQO0TaMd3tu4tRN9DqxRku2OWZ3pMj3lJhd4F0DzXGJOoeKSHenEjsLOhuJ1AsBtyvisjS
 zGT2U4iPJ8LnsgGorVU4j6nulszTQNA==
X-Google-Smtp-Source: AGHT+IGVfBQXM/PZpN9TnG6XlolZ50gaaGFxIm4kPHqYDL6lpiWx+Zk6smNdZM8eR2lveWBkrpgFww==
X-Received: by 2002:a05:600c:470d:b0:439:8c80:6af4 with SMTP id
 5b1f17b1804b1-43d1eccc289mr129170325e9.19.1742233762213; 
 Mon, 17 Mar 2025 10:49:22 -0700 (PDT)
Received: from flagship3.deu.mlau.at (p54bc8686.dip0.t-ipconnect.de.
 [84.188.134.134]) by smtp.gmail.com with ESMTPSA id
 ffacd0b85a97d-395c7df35ecsm15809347f8f.16.2025.03.17.10.49.21
 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
 Mon, 17 Mar 2025 10:49:21 -0700 (PDT)
From: Manuel Lauss <manuel.lauss@gmail.com>
To: ffmpeg-devel@ffmpeg.org
Date: Mon, 17 Mar 2025 18:49:04 +0100
Message-ID: <20250317174917.6872-3-manuel.lauss@gmail.com>
X-Mailer: git-send-email 2.49.0
In-Reply-To: <20250317174917.6872-1-manuel.lauss@gmail.com>
References: <20250317174917.6872-1-manuel.lauss@gmail.com>
MIME-Version: 1.0
Subject: [FFmpeg-devel] [PATCH v3 02/14] avcodec/sanm: FOBJ left/top are
 signed values
X-BeenThere: ffmpeg-devel@ffmpeg.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: FFmpeg development discussions and patches <ffmpeg-devel.ffmpeg.org>
List-Unsubscribe: <https://ffmpeg.org/mailman/options/ffmpeg-devel>,
 <mailto:ffmpeg-devel-request@ffmpeg.org?subject=unsubscribe>
List-Archive: <https://ffmpeg.org/pipermail/ffmpeg-devel>
List-Post: <mailto:ffmpeg-devel@ffmpeg.org>
List-Help: <mailto:ffmpeg-devel-request@ffmpeg.org?subject=help>
List-Subscribe: <https://ffmpeg.org/mailman/listinfo/ffmpeg-devel>,
 <mailto:ffmpeg-devel-request@ffmpeg.org?subject=subscribe>
Reply-To: FFmpeg development discussions and patches <ffmpeg-devel@ffmpeg.org>
Cc: Manuel Lauss <manuel.lauss@gmail.com>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: ffmpeg-devel-bounces@ffmpeg.org
Sender: "ffmpeg-devel" <ffmpeg-devel-bounces@ffmpeg.org>
Archived-At: <https://master.gitmailbox.com/ffmpegdev/20250317174917.6872-3-manuel.lauss@gmail.com/>
List-Archive: <https://master.gitmailbox.com/ffmpegdev/>
List-Post: <mailto:ffmpegdev@gitmailbox.com>

The left/top parameters of a FOBJ are signed values.  Adjust
codec1 code accordingly to not draw outside the buffer area.
Rebel Assault 1 makes heavy use of this.

Signed-off-by: Manuel Lauss <manuel.lauss@gmail.com>
---
v2, v3: no changes

 libavcodec/sanm.c | 33 ++++++++++++++++++---------------
 1 file changed, 18 insertions(+), 15 deletions(-)

diff --git a/libavcodec/sanm.c b/libavcodec/sanm.c
index 49ac9bebfe..65ca525b9d 100644
--- a/libavcodec/sanm.c
+++ b/libavcodec/sanm.c
@@ -558,18 +558,18 @@ static int rle_decode(SANMVideoContext *ctx, uint8_t *dst, const int out_size)
 static int old_codec1(SANMVideoContext *ctx, int top,
                       int left, int width, int height)
 {
-    uint8_t *dst = ((uint8_t *)ctx->frm0) + left + top * ctx->pitch;
-    int i, j, len, flag, code, val, pos, end;
+    int i, j, len, flag, code, val, end, pxoff;
+    const int maxpxo = ctx->height * ctx->pitch;
+    uint8_t *dst = (uint8_t *)ctx->frm0;
 
     for (i = 0; i < height; i++) {
-        pos = 0;
-
         if (bytestream2_get_bytes_left(&ctx->gb) < 2)
             return AVERROR_INVALIDDATA;
 
         len = bytestream2_get_le16u(&ctx->gb);
         end = bytestream2_tell(&ctx->gb) + len;
 
+        pxoff = left + ((top + i) * ctx->pitch);
         while (bytestream2_tell(&ctx->gb) < end) {
             if (bytestream2_get_bytes_left(&ctx->gb) < 2)
                 return AVERROR_INVALIDDATA;
@@ -577,25 +577,28 @@ static int old_codec1(SANMVideoContext *ctx, int top,
             code = bytestream2_get_byteu(&ctx->gb);
             flag = code & 1;
             code = (code >> 1) + 1;
-            if (pos + code > width)
-                return AVERROR_INVALIDDATA;
             if (flag) {
                 val = bytestream2_get_byteu(&ctx->gb);
-                if (val)
-                    memset(dst + pos, val, code);
-                pos += code;
+                if (val) {
+                    for (j = 0; j < code; j++) {
+                        if (pxoff >= 0 && pxoff < maxpxo)
+                            *(dst + pxoff) = val;
+                        pxoff++;
+                    }
+                } else {
+                    pxoff += code;
+                }
             } else {
                 if (bytestream2_get_bytes_left(&ctx->gb) < code)
                     return AVERROR_INVALIDDATA;
                 for (j = 0; j < code; j++) {
                     val = bytestream2_get_byteu(&ctx->gb);
-                    if (val)
-                        dst[pos] = val;
-                    pos++;
+                    if ((pxoff >= 0) && (pxoff < maxpxo) && val)
+                        *(dst + pxoff) = val;
+                    pxoff++;
                 }
             }
         }
-        dst += ctx->pitch;
     }
     ctx->rotate_code = 0;
 
@@ -1236,8 +1239,8 @@ static int old_codec48(SANMVideoContext *ctx, int width, int height)
 static int process_frame_obj(SANMVideoContext *ctx)
 {
     uint16_t codec = bytestream2_get_le16u(&ctx->gb);
-    uint16_t left  = bytestream2_get_le16u(&ctx->gb);
-    uint16_t top   = bytestream2_get_le16u(&ctx->gb);
+    int16_t  left  = bytestream2_get_le16u(&ctx->gb);
+    int16_t  top   = bytestream2_get_le16u(&ctx->gb);
     uint16_t w     = bytestream2_get_le16u(&ctx->gb);
     uint16_t h     = bytestream2_get_le16u(&ctx->gb);
 
-- 
2.49.0

_______________________________________________
ffmpeg-devel mailing list
ffmpeg-devel@ffmpeg.org
https://ffmpeg.org/mailman/listinfo/ffmpeg-devel

To unsubscribe, visit link above, or email
ffmpeg-devel-request@ffmpeg.org with subject "unsubscribe".