* [FFmpeg-devel] [PATCH] lavc/vvc: Fix derivation of inverse LMCS idx
@ 2025-02-02 12:10 Frank Plowman
2025-02-19 20:33 ` Frank Plowman
0 siblings, 1 reply; 3+ messages in thread
From: Frank Plowman @ 2025-02-02 12:10 UTC (permalink / raw)
To: ffmpeg-devel; +Cc: Frank Plowman, nuomi2021
The clamping of idxYInv from H.266(V3) section 8.8.2.3 was missing.
This could lead to OOB reads from lmcs->pivot or input_pivot.
I also changed the derivation of the forward LMCS idx to use a shift
rather than a division for speed and as this is actually how the
variable is declared in the specification (8.7.5.2).
Signed-off-by: Frank Plowman <post@frankplowman.com>
---
libavcodec/vvc/ps.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/libavcodec/vvc/ps.c b/libavcodec/vvc/ps.c
index 01b4615eda..fae6655cc0 100644
--- a/libavcodec/vvc/ps.c
+++ b/libavcodec/vvc/ps.c
@@ -786,7 +786,7 @@ static int lmcs_derive_lut(VVCLMCS *lmcs, const H266RawAPS *rlmcs, const H266Raw
//derive lmcs_fwd_lut
for (uint16_t sample = 0; sample < max; sample++) {
- const int idx_y = sample / org_cw;
+ const int idx_y = sample >> shift;
const uint16_t fwd_sample = lmcs_derive_lut_sample(sample, lmcs->pivot,
input_pivot, scale_coeff, idx_y, max);
if (bit_depth > 8)
@@ -802,6 +802,7 @@ static int lmcs_derive_lut(VVCLMCS *lmcs, const H266RawAPS *rlmcs, const H266Raw
uint16_t inv_sample;
while (i <= lmcs->max_bin_idx && sample >= lmcs->pivot[i + 1])
i++;
+ i = FFMIN(i, LMCS_MAX_BIN_SIZE - 1);
inv_sample = lmcs_derive_lut_sample(sample, input_pivot, lmcs->pivot,
inv_scale_coeff, i, max);
--
2.47.0
_______________________________________________
ffmpeg-devel mailing list
ffmpeg-devel@ffmpeg.org
https://ffmpeg.org/mailman/listinfo/ffmpeg-devel
To unsubscribe, visit link above, or email
ffmpeg-devel-request@ffmpeg.org with subject "unsubscribe".
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [FFmpeg-devel] [PATCH] lavc/vvc: Fix derivation of inverse LMCS idx
2025-02-02 12:10 [FFmpeg-devel] [PATCH] lavc/vvc: Fix derivation of inverse LMCS idx Frank Plowman
@ 2025-02-19 20:33 ` Frank Plowman
2025-02-22 4:25 ` Nuo Mi
0 siblings, 1 reply; 3+ messages in thread
From: Frank Plowman @ 2025-02-19 20:33 UTC (permalink / raw)
To: ffmpeg-devel; +Cc: nuomi2021
Ping
On 02/02/2025 12:10, Frank Plowman wrote:
> The clamping of idxYInv from H.266(V3) section 8.8.2.3 was missing.
> This could lead to OOB reads from lmcs->pivot or input_pivot.
>
> I also changed the derivation of the forward LMCS idx to use a shift
> rather than a division for speed and as this is actually how the
> variable is declared in the specification (8.7.5.2).
>
> Signed-off-by: Frank Plowman <post@frankplowman.com>
> ---
> libavcodec/vvc/ps.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
>
> diff --git a/libavcodec/vvc/ps.c b/libavcodec/vvc/ps.c
> index 01b4615eda..fae6655cc0 100644
> --- a/libavcodec/vvc/ps.c
> +++ b/libavcodec/vvc/ps.c
> @@ -786,7 +786,7 @@ static int lmcs_derive_lut(VVCLMCS *lmcs, const H266RawAPS *rlmcs, const H266Raw
>
> //derive lmcs_fwd_lut
> for (uint16_t sample = 0; sample < max; sample++) {
> - const int idx_y = sample / org_cw;
> + const int idx_y = sample >> shift;
> const uint16_t fwd_sample = lmcs_derive_lut_sample(sample, lmcs->pivot,
> input_pivot, scale_coeff, idx_y, max);
> if (bit_depth > 8)
> @@ -802,6 +802,7 @@ static int lmcs_derive_lut(VVCLMCS *lmcs, const H266RawAPS *rlmcs, const H266Raw
> uint16_t inv_sample;
> while (i <= lmcs->max_bin_idx && sample >= lmcs->pivot[i + 1])
> i++;
> + i = FFMIN(i, LMCS_MAX_BIN_SIZE - 1);
>
> inv_sample = lmcs_derive_lut_sample(sample, input_pivot, lmcs->pivot,
> inv_scale_coeff, i, max);
_______________________________________________
ffmpeg-devel mailing list
ffmpeg-devel@ffmpeg.org
https://ffmpeg.org/mailman/listinfo/ffmpeg-devel
To unsubscribe, visit link above, or email
ffmpeg-devel-request@ffmpeg.org with subject "unsubscribe".
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [FFmpeg-devel] [PATCH] lavc/vvc: Fix derivation of inverse LMCS idx
2025-02-19 20:33 ` Frank Plowman
@ 2025-02-22 4:25 ` Nuo Mi
0 siblings, 0 replies; 3+ messages in thread
From: Nuo Mi @ 2025-02-22 4:25 UTC (permalink / raw)
To: Frank Plowman; +Cc: ffmpeg-devel
On Thu, Feb 20, 2025 at 4:33 AM Frank Plowman <post@frankplowman.com> wrote:
> Ping
>
Sorry for missing this.
Thank you for the patch, applied
>
> On 02/02/2025 12:10, Frank Plowman wrote:
> > The clamping of idxYInv from H.266(V3) section 8.8.2.3 was missing.
> > This could lead to OOB reads from lmcs->pivot or input_pivot.
> >
> > I also changed the derivation of the forward LMCS idx to use a shift
> > rather than a division for speed and as this is actually how the
> > variable is declared in the specification (8.7.5.2).
> >
> > Signed-off-by: Frank Plowman <post@frankplowman.com>
> > ---
> > libavcodec/vvc/ps.c | 3 ++-
> > 1 file changed, 2 insertions(+), 1 deletion(-)
> >
> > diff --git a/libavcodec/vvc/ps.c b/libavcodec/vvc/ps.c
> > index 01b4615eda..fae6655cc0 100644
> > --- a/libavcodec/vvc/ps.c
> > +++ b/libavcodec/vvc/ps.c
> > @@ -786,7 +786,7 @@ static int lmcs_derive_lut(VVCLMCS *lmcs, const
> H266RawAPS *rlmcs, const H266Raw
> >
> > //derive lmcs_fwd_lut
> > for (uint16_t sample = 0; sample < max; sample++) {
> > - const int idx_y = sample / org_cw;
> > + const int idx_y = sample >> shift;
> > const uint16_t fwd_sample = lmcs_derive_lut_sample(sample,
> lmcs->pivot,
> > input_pivot, scale_coeff, idx_y, max);
> > if (bit_depth > 8)
> > @@ -802,6 +802,7 @@ static int lmcs_derive_lut(VVCLMCS *lmcs, const
> H266RawAPS *rlmcs, const H266Raw
> > uint16_t inv_sample;
> > while (i <= lmcs->max_bin_idx && sample >= lmcs->pivot[i + 1])
> > i++;
> > + i = FFMIN(i, LMCS_MAX_BIN_SIZE - 1);
> >
> > inv_sample = lmcs_derive_lut_sample(sample, input_pivot,
> lmcs->pivot,
> > inv_scale_coeff, i, max);
>
>
_______________________________________________
ffmpeg-devel mailing list
ffmpeg-devel@ffmpeg.org
https://ffmpeg.org/mailman/listinfo/ffmpeg-devel
To unsubscribe, visit link above, or email
ffmpeg-devel-request@ffmpeg.org with subject "unsubscribe".
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2025-02-22 4:25 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-02-02 12:10 [FFmpeg-devel] [PATCH] lavc/vvc: Fix derivation of inverse LMCS idx Frank Plowman
2025-02-19 20:33 ` Frank Plowman
2025-02-22 4:25 ` Nuo Mi
Git Inbox Mirror of the ffmpeg-devel mailing list - see https://ffmpeg.org/mailman/listinfo/ffmpeg-devel
This inbox may be cloned and mirrored by anyone:
git clone --mirror https://master.gitmailbox.com/ffmpegdev/0 ffmpegdev/git/0.git
# If you have public-inbox 1.1+ installed, you may
# initialize and index your mirror using the following commands:
public-inbox-init -V2 ffmpegdev ffmpegdev/ https://master.gitmailbox.com/ffmpegdev \
ffmpegdev@gitmailbox.com
public-inbox-index ffmpegdev
Example config snippet for mirrors.
AGPL code for this site: git clone https://public-inbox.org/public-inbox.git