1 /*
2  * "Real" compatible demuxer.
3  * Copyright (c) 2000, 2001 Fabrice Bellard
4  *
5  * This file is part of FFmpeg.
6  *
7  * FFmpeg is free software; you can redistribute it and/or
8  * modify it under the terms of the GNU Lesser General Public
9  * License as published by the Free Software Foundation; either
10  * version 2.1 of the License, or (at your option) any later version.
11  *
12  * FFmpeg is distributed in the hope that it will be useful,
13  * but WITHOUT ANY WARRANTY; without even the implied warranty of
14  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
15  * Lesser General Public License for more details.
16  *
17  * You should have received a copy of the GNU Lesser General Public
18  * License along with FFmpeg; if not, write to the Free Software
19  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
20  */
21 
22 #include <inttypes.h>
23 
24 #include "libavutil/avassert.h"
25 #include "libavutil/channel_layout.h"
26 #include "libavutil/internal.h"
27 #include "libavutil/intreadwrite.h"
28 #include "libavutil/dict.h"
29 #include "avformat.h"
30 #include "avio_internal.h"
31 #include "demux.h"
32 #include "internal.h"
33 #include "rmsipr.h"
34 #include "rm.h"
35 
36 #define DEINT_ID_GENR MKTAG('g', 'e', 'n', 'r') ///< interleaving for Cooker/ATRAC
37 #define DEINT_ID_INT0 MKTAG('I', 'n', 't', '0') ///< no interleaving needed
38 #define DEINT_ID_INT4 MKTAG('I', 'n', 't', '4') ///< interleaving for 28.8
39 #define DEINT_ID_SIPR MKTAG('s', 'i', 'p', 'r') ///< interleaving for Sipro
40 #define DEINT_ID_VBRF MKTAG('v', 'b', 'r', 'f') ///< VBR case for AAC
41 #define DEINT_ID_VBRS MKTAG('v', 'b', 'r', 's') ///< VBR case for AAC
42 
43 struct RMStream {
44     AVPacket pkt;      ///< place to store merged video frame / reordered audio data
45     int videobufsize;  ///< current assembled frame size
46     int videobufpos;   ///< position for the next slice in the video buffer
47     int curpic_num;    ///< picture number of current frame
48     int cur_slice, slices;
49     int64_t pktpos;    ///< first slice position in file
50     /// Audio descrambling matrix parameters
51     int64_t audiotimestamp; ///< Audio packet timestamp
52     int sub_packet_cnt; // Subpacket counter, used while reading
53     int sub_packet_size, sub_packet_h, coded_framesize; ///< Descrambling parameters from container
54     int audio_framesize; /// Audio frame size from container
55     int sub_packet_lengths[16]; /// Length of each subpacket
56     int32_t deint_id;  ///< deinterleaver used in audio stream
57 };
58 
59 typedef struct RMDemuxContext {
60     int nb_packets;
61     int old_format;
62     int current_stream;
63     int remaining_len;
64     int audio_stream_num; ///< Stream number for audio packets
65     int audio_pkt_cnt; ///< Output packet counter
66     int data_end;
67 } RMDemuxContext;
68 
get_strl(AVIOContext *pb, char *buf, int buf_size, int len)69 static inline void get_strl(AVIOContext *pb, char *buf, int buf_size, int len)
70 {
71     int read = avio_get_str(pb, len, buf, buf_size);
72 
73     if (read > 0)
74         avio_skip(pb, len - read);
75 }
76 
get_str8(AVIOContext *pb, char *buf, int buf_size)77 static void get_str8(AVIOContext *pb, char *buf, int buf_size)
78 {
79     get_strl(pb, buf, buf_size, avio_r8(pb));
80 }
81 
rm_read_extradata(AVFormatContext *s, AVIOContext *pb, AVCodecParameters *par, unsigned size)82 static int rm_read_extradata(AVFormatContext *s, AVIOContext *pb, AVCodecParameters *par, unsigned size)
83 {
84     if (size >= 1<<24) {
85         av_log(s, AV_LOG_ERROR, "extradata size %u too large\n", size);
86         return -1;
87     }
88     return ff_get_extradata(s, par, pb, size);
89 }
90 
rm_read_metadata(AVFormatContext *s, AVIOContext *pb, int wide)91 static void rm_read_metadata(AVFormatContext *s, AVIOContext *pb, int wide)
92 {
93     char buf[1024];
94     int i;
95 
96     for (i=0; i<FF_ARRAY_ELEMS(ff_rm_metadata); i++) {
97         int len = wide ? avio_rb16(pb) : avio_r8(pb);
98         if (len > 0) {
99             get_strl(pb, buf, sizeof(buf), len);
100             av_dict_set(&s->metadata, ff_rm_metadata[i], buf, 0);
101         }
102     }
103 }
104 
ff_rm_alloc_rmstream(void)105 RMStream *ff_rm_alloc_rmstream (void)
106 {
107     RMStream *rms = av_mallocz(sizeof(RMStream));
108     if (!rms)
109         return NULL;
110     rms->curpic_num = -1;
111     return rms;
112 }
113 
ff_rm_free_rmstream(RMStream *rms)114 void ff_rm_free_rmstream (RMStream *rms)
115 {
116     if (!rms)
117         return;
118 
119     av_packet_unref(&rms->pkt);
120 }
121 
rm_read_audio_stream_info(AVFormatContext *s, AVIOContext *pb, AVStream *st, RMStream *ast, int read_all)122 static int rm_read_audio_stream_info(AVFormatContext *s, AVIOContext *pb,
123                                      AVStream *st, RMStream *ast, int read_all)
124 {
125     FFStream *const sti = ffstream(st);
126     char buf[256];
127     uint32_t version;
128     int ret;
129 
130     /* ra type header */
131     version = avio_rb16(pb); /* version */
132     if (version == 3) {
133         unsigned bytes_per_minute;
134         int header_size = avio_rb16(pb);
135         int64_t startpos = avio_tell(pb);
136         avio_skip(pb, 8);
137         bytes_per_minute = avio_rb16(pb);
138         avio_skip(pb, 4);
139         rm_read_metadata(s, pb, 0);
140         if ((startpos + header_size) >= avio_tell(pb) + 2) {
141             // fourcc (should always be "lpcJ")
142             avio_r8(pb);
143             get_str8(pb, buf, sizeof(buf));
144         }
145         // Skip extra header crap (this should never happen)
146         if ((startpos + header_size) > avio_tell(pb))
147             avio_skip(pb, header_size + startpos - avio_tell(pb));
148         if (bytes_per_minute)
149             st->codecpar->bit_rate = 8LL * bytes_per_minute / 60;
150         st->codecpar->sample_rate = 8000;
151         st->codecpar->ch_layout = (AVChannelLayout)AV_CHANNEL_LAYOUT_MONO;
152         st->codecpar->codec_type = AVMEDIA_TYPE_AUDIO;
153         st->codecpar->codec_id = AV_CODEC_ID_RA_144;
154         ast->deint_id = DEINT_ID_INT0;
155     } else {
156         int flavor, sub_packet_h, coded_framesize, sub_packet_size;
157         int codecdata_length;
158         unsigned bytes_per_minute;
159         /* old version (4) */
160         avio_skip(pb, 2); /* unused */
161         avio_rb32(pb); /* .ra4 */
162         avio_rb32(pb); /* data size */
163         avio_rb16(pb); /* version2 */
164         avio_rb32(pb); /* header size */
165         flavor= avio_rb16(pb); /* add codec info / flavor */
166         coded_framesize = avio_rb32(pb); /* coded frame size */
167         if (coded_framesize < 0)
168             return AVERROR_INVALIDDATA;
169         ast->coded_framesize = coded_framesize;
170 
171         avio_rb32(pb); /* ??? */
172         bytes_per_minute = avio_rb32(pb);
173         if (version == 4) {
174             if (bytes_per_minute)
175                 st->codecpar->bit_rate = 8LL * bytes_per_minute / 60;
176         }
177         avio_rb32(pb); /* ??? */
178         ast->sub_packet_h = sub_packet_h = avio_rb16(pb); /* 1 */
179         st->codecpar->block_align= avio_rb16(pb); /* frame size */
180         ast->sub_packet_size = sub_packet_size = avio_rb16(pb); /* sub packet size */
181         avio_rb16(pb); /* ??? */
182         if (version == 5) {
183             avio_rb16(pb); avio_rb16(pb); avio_rb16(pb);
184         }
185         st->codecpar->sample_rate = avio_rb16(pb);
186         avio_rb32(pb);
187         st->codecpar->ch_layout.nb_channels = avio_rb16(pb);
188         if (version == 5) {
189             ast->deint_id = avio_rl32(pb);
190             avio_read(pb, buf, 4);
191             buf[4] = 0;
192         } else {
193             AV_WL32(buf, 0);
194             get_str8(pb, buf, sizeof(buf)); /* desc */
195             ast->deint_id = AV_RL32(buf);
196             get_str8(pb, buf, sizeof(buf)); /* desc */
197         }
198         st->codecpar->codec_type = AVMEDIA_TYPE_AUDIO;
199         st->codecpar->codec_tag  = AV_RL32(buf);
200         st->codecpar->codec_id   = ff_codec_get_id(ff_rm_codec_tags,
201                                                    st->codecpar->codec_tag);
202 
203         switch (st->codecpar->codec_id) {
204         case AV_CODEC_ID_AC3:
205             sti->need_parsing = AVSTREAM_PARSE_FULL;
206             break;
207         case AV_CODEC_ID_RA_288:
208             st->codecpar->extradata_size= 0;
209             av_freep(&st->codecpar->extradata);
210             ast->audio_framesize = st->codecpar->block_align;
211             st->codecpar->block_align = coded_framesize;
212             break;
213         case AV_CODEC_ID_COOK:
214             sti->need_parsing = AVSTREAM_PARSE_HEADERS;
215         case AV_CODEC_ID_ATRAC3:
216         case AV_CODEC_ID_SIPR:
217             if (read_all) {
218                 codecdata_length = 0;
219             } else {
220                 avio_rb16(pb); avio_r8(pb);
221                 if (version == 5)
222                     avio_r8(pb);
223                 codecdata_length = avio_rb32(pb);
224                 if((unsigned)codecdata_length > INT_MAX - AV_INPUT_BUFFER_PADDING_SIZE){
225                     av_log(s, AV_LOG_ERROR, "codecdata_length too large\n");
226                     return -1;
227                 }
228             }
229 
230             ast->audio_framesize = st->codecpar->block_align;
231             if (st->codecpar->codec_id == AV_CODEC_ID_SIPR) {
232                 if (flavor > 3) {
233                     av_log(s, AV_LOG_ERROR, "bad SIPR file flavor %d\n",
234                            flavor);
235                     return -1;
236                 }
237                 st->codecpar->block_align = ff_sipr_subpk_size[flavor];
238                 sti->need_parsing = AVSTREAM_PARSE_FULL_RAW;
239             } else {
240                 if(sub_packet_size <= 0){
241                     av_log(s, AV_LOG_ERROR, "sub_packet_size is invalid\n");
242                     return -1;
243                 }
244                 st->codecpar->block_align = ast->sub_packet_size;
245             }
246             if ((ret = rm_read_extradata(s, pb, st->codecpar, codecdata_length)) < 0)
247                 return ret;
248 
249             break;
250         case AV_CODEC_ID_AAC:
251             avio_rb16(pb); avio_r8(pb);
252             if (version == 5)
253                 avio_r8(pb);
254             codecdata_length = avio_rb32(pb);
255             if((unsigned)codecdata_length > INT_MAX - AV_INPUT_BUFFER_PADDING_SIZE){
256                 av_log(s, AV_LOG_ERROR, "codecdata_length too large\n");
257                 return -1;
258             }
259             if (codecdata_length >= 1) {
260                 avio_r8(pb);
261                 if ((ret = rm_read_extradata(s, pb, st->codecpar, codecdata_length - 1)) < 0)
262                     return ret;
263             }
264             break;
265         }
266         switch (ast->deint_id) {
267         case DEINT_ID_INT4:
268             if (ast->coded_framesize > ast->audio_framesize ||
269                 sub_packet_h <= 1 ||
270                 ast->coded_framesize * (uint64_t)sub_packet_h > (2 + (sub_packet_h & 1)) * ast->audio_framesize)
271                 return AVERROR_INVALIDDATA;
272             if (ast->coded_framesize * (uint64_t)sub_packet_h != 2*ast->audio_framesize) {
273                 avpriv_request_sample(s, "mismatching interleaver parameters");
274                 return AVERROR_INVALIDDATA;
275             }
276             break;
277         case DEINT_ID_GENR:
278             if (ast->sub_packet_size <= 0 ||
279                 ast->sub_packet_size > ast->audio_framesize)
280                 return AVERROR_INVALIDDATA;
281             if (ast->audio_framesize % ast->sub_packet_size)
282                 return AVERROR_INVALIDDATA;
283             break;
284         case DEINT_ID_SIPR:
285         case DEINT_ID_INT0:
286         case DEINT_ID_VBRS:
287         case DEINT_ID_VBRF:
288             break;
289         default:
290             av_log(s, AV_LOG_ERROR ,"Unknown interleaver %"PRIX32"\n", ast->deint_id);
291             return AVERROR_INVALIDDATA;
292         }
293         if (ast->deint_id == DEINT_ID_INT4 ||
294             ast->deint_id == DEINT_ID_GENR ||
295             ast->deint_id == DEINT_ID_SIPR) {
296             if (st->codecpar->block_align <= 0 ||
297                 ast->audio_framesize * (uint64_t)sub_packet_h > (unsigned)INT_MAX ||
298                 ast->audio_framesize * sub_packet_h < st->codecpar->block_align)
299                 return AVERROR_INVALIDDATA;
300             if (av_new_packet(&ast->pkt, ast->audio_framesize * sub_packet_h) < 0)
301                 return AVERROR(ENOMEM);
302         }
303 
304         if (read_all) {
305             avio_r8(pb);
306             avio_r8(pb);
307             avio_r8(pb);
308             rm_read_metadata(s, pb, 0);
309         }
310     }
311     return 0;
312 }
313 
ff_rm_read_mdpr_codecdata(AVFormatContext *s, AVIOContext *pb, AVStream *st, RMStream *rst, unsigned int codec_data_size, const uint8_t *mime)314 int ff_rm_read_mdpr_codecdata(AVFormatContext *s, AVIOContext *pb,
315                               AVStream *st, RMStream *rst,
316                               unsigned int codec_data_size, const uint8_t *mime)
317 {
318     unsigned int v;
319     int size;
320     int64_t codec_pos;
321     int ret;
322 
323     if (codec_data_size > INT_MAX)
324         return AVERROR_INVALIDDATA;
325     if (codec_data_size == 0)
326         return 0;
327 
328     // Duplicate tags
329     if (   st->codecpar->codec_type != AVMEDIA_TYPE_UNKNOWN
330         && st->codecpar->codec_type != AVMEDIA_TYPE_DATA)
331         return AVERROR_INVALIDDATA;
332 
333     avpriv_set_pts_info(st, 64, 1, 1000);
334     codec_pos = avio_tell(pb);
335     v = avio_rb32(pb);
336 
337     if (v == MKTAG(0xfd, 'a', 'r', '.')) {
338         /* ra type header */
339         if (rm_read_audio_stream_info(s, pb, st, rst, 0))
340             return -1;
341     } else if (v == MKBETAG('L', 'S', 'D', ':')) {
342         avio_seek(pb, -4, SEEK_CUR);
343         if ((ret = rm_read_extradata(s, pb, st->codecpar, codec_data_size)) < 0)
344             return ret;
345 
346         st->codecpar->codec_type = AVMEDIA_TYPE_AUDIO;
347         st->codecpar->codec_tag  = AV_RL32(st->codecpar->extradata);
348         st->codecpar->codec_id   = ff_codec_get_id(ff_rm_codec_tags,
349                                                 st->codecpar->codec_tag);
350     } else if(mime && !strcmp(mime, "logical-fileinfo")){
351         int stream_count, rule_count, property_count, i;
352         ff_remove_stream(s, st);
353         if (avio_rb16(pb) != 0) {
354             av_log(s, AV_LOG_WARNING, "Unsupported version\n");
355             goto skip;
356         }
357         stream_count = avio_rb16(pb);
358         avio_skip(pb, 6*stream_count);
359         rule_count = avio_rb16(pb);
360         avio_skip(pb, 2*rule_count);
361         property_count = avio_rb16(pb);
362         for(i=0; i<property_count; i++){
363             uint8_t name[128], val[128];
364             avio_rb32(pb);
365             if (avio_rb16(pb) != 0) {
366                 av_log(s, AV_LOG_WARNING, "Unsupported Name value property version\n");
367                 goto skip; //FIXME skip just this one
368             }
369             get_str8(pb, name, sizeof(name));
370             switch(avio_rb32(pb)) {
371             case 2: get_strl(pb, val, sizeof(val), avio_rb16(pb));
372                 av_dict_set(&s->metadata, name, val, 0);
373                 break;
374             default: avio_skip(pb, avio_rb16(pb));
375             }
376         }
377     } else {
378         int fps;
379         if (avio_rl32(pb) != MKTAG('V', 'I', 'D', 'O')) {
380         fail1:
381             av_log(s, AV_LOG_WARNING, "Unsupported stream type %08x\n", v);
382             goto skip;
383         }
384         st->codecpar->codec_tag = avio_rl32(pb);
385         st->codecpar->codec_id  = ff_codec_get_id(ff_rm_codec_tags,
386                                                   st->codecpar->codec_tag);
387         av_log(s, AV_LOG_TRACE, "%"PRIX32" %X\n",
388                st->codecpar->codec_tag, MKTAG('R', 'V', '2', '0'));
389         if (st->codecpar->codec_id == AV_CODEC_ID_NONE)
390             goto fail1;
391         st->codecpar->width  = avio_rb16(pb);
392         st->codecpar->height = avio_rb16(pb);
393         avio_skip(pb, 2); // looks like bits per sample
394         avio_skip(pb, 4); // always zero?
395         st->codecpar->codec_type = AVMEDIA_TYPE_VIDEO;
396         ffstream(st)->need_parsing = AVSTREAM_PARSE_TIMESTAMPS;
397         fps = avio_rb32(pb);
398 
399         if ((ret = rm_read_extradata(s, pb, st->codecpar, codec_data_size - (avio_tell(pb) - codec_pos))) < 0)
400             return ret;
401 
402         if (fps > 0) {
403             av_reduce(&st->avg_frame_rate.den, &st->avg_frame_rate.num,
404                       0x10000, fps, (1 << 30) - 1);
405 #if FF_API_R_FRAME_RATE
406             st->r_frame_rate = st->avg_frame_rate;
407 #endif
408         } else if (s->error_recognition & AV_EF_EXPLODE) {
409             av_log(s, AV_LOG_ERROR, "Invalid framerate\n");
410             return AVERROR_INVALIDDATA;
411         }
412     }
413 
414 skip:
415     /* skip codec info */
416     size = avio_tell(pb) - codec_pos;
417     if (codec_data_size >= size) {
418         avio_skip(pb, codec_data_size - size);
419     } else {
420         av_log(s, AV_LOG_WARNING, "codec_data_size %u < size %d\n", codec_data_size, size);
421     }
422 
423     return 0;
424 }
425 
426 /** this function assumes that the demuxer has already seeked to the start
427  * of the INDX chunk, and will bail out if not. */
rm_read_index(AVFormatContext *s)428 static int rm_read_index(AVFormatContext *s)
429 {
430     AVIOContext *pb = s->pb;
431     unsigned int size, n_pkts, str_id, next_off, n, pos, pts;
432     AVStream *st;
433 
434     do {
435         if (avio_rl32(pb) != MKTAG('I','N','D','X'))
436             return -1;
437         size     = avio_rb32(pb);
438         if (size < 20)
439             return -1;
440         avio_skip(pb, 2);
441         n_pkts   = avio_rb32(pb);
442         str_id   = avio_rb16(pb);
443         next_off = avio_rb32(pb);
444         for (n = 0; n < s->nb_streams; n++)
445             if (s->streams[n]->id == str_id) {
446                 st = s->streams[n];
447                 break;
448             }
449         if (n == s->nb_streams) {
450             av_log(s, AV_LOG_ERROR,
451                    "Invalid stream index %d for index at pos %"PRId64"\n",
452                    str_id, avio_tell(pb));
453             goto skip;
454         } else if ((avio_size(pb) - avio_tell(pb)) / 14 < n_pkts) {
455             av_log(s, AV_LOG_ERROR,
456                    "Nr. of packets in packet index for stream index %d "
457                    "exceeds filesize (%"PRId64" at %"PRId64" = %"PRId64")\n",
458                    str_id, avio_size(pb), avio_tell(pb),
459                    (avio_size(pb) - avio_tell(pb)) / 14);
460             goto skip;
461         }
462 
463         for (n = 0; n < n_pkts; n++) {
464             if (avio_feof(pb))
465                 return AVERROR_INVALIDDATA;
466             avio_skip(pb, 2);
467             pts = avio_rb32(pb);
468             pos = avio_rb32(pb);
469             avio_skip(pb, 4); /* packet no. */
470 
471             av_add_index_entry(st, pos, pts, 0, 0, AVINDEX_KEYFRAME);
472         }
473 
474 skip:
475         if (next_off && avio_tell(pb) < next_off &&
476             avio_seek(pb, next_off, SEEK_SET) < 0) {
477             av_log(s, AV_LOG_ERROR,
478                    "Non-linear index detected, not supported\n");
479             return -1;
480         }
481     } while (next_off);
482 
483     return 0;
484 }
485 
rm_read_header_old(AVFormatContext *s)486 static int rm_read_header_old(AVFormatContext *s)
487 {
488     RMDemuxContext *rm = s->priv_data;
489     AVStream *st;
490 
491     rm->old_format = 1;
492     st = avformat_new_stream(s, NULL);
493     if (!st)
494         return -1;
495     st->priv_data = ff_rm_alloc_rmstream();
496     if (!st->priv_data)
497         return AVERROR(ENOMEM);
498     return rm_read_audio_stream_info(s, s->pb, st, st->priv_data, 1);
499 }
500 
rm_read_multi(AVFormatContext *s, AVIOContext *pb, AVStream *st, char *mime)501 static int rm_read_multi(AVFormatContext *s, AVIOContext *pb,
502                          AVStream *st, char *mime)
503 {
504     int number_of_streams = avio_rb16(pb);
505     int number_of_mdpr;
506     int i, ret;
507     unsigned size2;
508     for (i = 0; i<number_of_streams; i++)
509         avio_rb16(pb);
510     number_of_mdpr = avio_rb16(pb);
511     if (number_of_mdpr != 1) {
512         avpriv_request_sample(s, "MLTI with multiple (%d) MDPR", number_of_mdpr);
513     }
514     for (i = 0; i < number_of_mdpr; i++) {
515         AVStream *st2;
516         if (i > 0) {
517             st2 = avformat_new_stream(s, NULL);
518             if (!st2) {
519                 ret = AVERROR(ENOMEM);
520                 return ret;
521             }
522             st2->id = st->id + (i<<16);
523             st2->codecpar->bit_rate = st->codecpar->bit_rate;
524             st2->start_time = st->start_time;
525             st2->duration   = st->duration;
526             st2->codecpar->codec_type = AVMEDIA_TYPE_DATA;
527             st2->priv_data = ff_rm_alloc_rmstream();
528             if (!st2->priv_data)
529                 return AVERROR(ENOMEM);
530         } else
531             st2 = st;
532 
533         size2 = avio_rb32(pb);
534         ret = ff_rm_read_mdpr_codecdata(s, s->pb, st2, st2->priv_data,
535                                         size2, NULL);
536         if (ret < 0)
537             return ret;
538     }
539     return 0;
540 }
541 
rm_read_header(AVFormatContext *s)542 static int rm_read_header(AVFormatContext *s)
543 {
544     RMDemuxContext *rm = s->priv_data;
545     AVStream *st;
546     AVIOContext *pb = s->pb;
547     unsigned int tag;
548     int tag_size;
549     unsigned int start_time, duration;
550     unsigned int data_off = 0, indx_off = 0;
551     char buf[128], mime[128];
552     int flags = 0;
553     int ret;
554     unsigned size, v;
555     int64_t codec_pos;
556 
557     tag = avio_rl32(pb);
558     if (tag == MKTAG('.', 'r', 'a', 0xfd)) {
559         /* very old .ra format */
560         return rm_read_header_old(s);
561     } else if (tag != MKTAG('.', 'R', 'M', 'F')) {
562         return AVERROR(EIO);
563     }
564 
565     tag_size = avio_rb32(pb);
566     if (tag_size < 0)
567         return AVERROR_INVALIDDATA;
568     avio_skip(pb, tag_size - 8);
569 
570     for(;;) {
571         if (avio_feof(pb))
572             return AVERROR_INVALIDDATA;
573         tag = avio_rl32(pb);
574         tag_size = avio_rb32(pb);
575         avio_rb16(pb);
576         av_log(s, AV_LOG_TRACE, "tag=%s size=%d\n",
577                av_fourcc2str(tag), tag_size);
578         if (tag_size < 10 && tag != MKTAG('D', 'A', 'T', 'A'))
579             return AVERROR_INVALIDDATA;
580         switch(tag) {
581         case MKTAG('P', 'R', 'O', 'P'):
582             /* file header */
583             avio_rb32(pb); /* max bit rate */
584             avio_rb32(pb); /* avg bit rate */
585             avio_rb32(pb); /* max packet size */
586             avio_rb32(pb); /* avg packet size */
587             avio_rb32(pb); /* nb packets */
588             duration = avio_rb32(pb); /* duration */
589             s->duration = av_rescale(duration, AV_TIME_BASE, 1000);
590             avio_rb32(pb); /* preroll */
591             indx_off = avio_rb32(pb); /* index offset */
592             data_off = avio_rb32(pb); /* data offset */
593             avio_rb16(pb); /* nb streams */
594             flags = avio_rb16(pb); /* flags */
595             break;
596         case MKTAG('C', 'O', 'N', 'T'):
597             rm_read_metadata(s, pb, 1);
598             break;
599         case MKTAG('M', 'D', 'P', 'R'):
600             st = avformat_new_stream(s, NULL);
601             if (!st)
602                 return AVERROR(ENOMEM);
603             st->id = avio_rb16(pb);
604             avio_rb32(pb); /* max bit rate */
605             st->codecpar->bit_rate = avio_rb32(pb); /* bit rate */
606             avio_rb32(pb); /* max packet size */
607             avio_rb32(pb); /* avg packet size */
608             start_time = avio_rb32(pb); /* start time */
609             avio_rb32(pb); /* preroll */
610             duration = avio_rb32(pb); /* duration */
611             st->start_time = start_time;
612             st->duration = duration;
613             if(duration>0)
614                 s->duration = AV_NOPTS_VALUE;
615             get_str8(pb, buf, sizeof(buf)); /* desc */
616             get_str8(pb, mime, sizeof(mime)); /* mimetype */
617             st->codecpar->codec_type = AVMEDIA_TYPE_DATA;
618             st->priv_data = ff_rm_alloc_rmstream();
619             if (!st->priv_data)
620                 return AVERROR(ENOMEM);
621 
622             size = avio_rb32(pb);
623             codec_pos = avio_tell(pb);
624 
625             ffio_ensure_seekback(pb, 4);
626             v = avio_rb32(pb);
627             if (v == MKBETAG('M', 'L', 'T', 'I')) {
628                 ret = rm_read_multi(s, s->pb, st, mime);
629                 if (ret < 0)
630                     return ret;
631                 avio_seek(pb, codec_pos + size, SEEK_SET);
632             } else {
633                 avio_skip(pb, -4);
634                 ret = ff_rm_read_mdpr_codecdata(s, s->pb, st, st->priv_data,
635                                                 size, mime);
636                 if (ret < 0)
637                     return ret;
638             }
639 
640             break;
641         case MKTAG('D', 'A', 'T', 'A'):
642             goto header_end;
643         default:
644             /* unknown tag: skip it */
645             avio_skip(pb, tag_size - 10);
646             break;
647         }
648     }
649  header_end:
650     rm->nb_packets = avio_rb32(pb); /* number of packets */
651     if (!rm->nb_packets && (flags & 4))
652         rm->nb_packets = 3600 * 25;
653     avio_rb32(pb); /* next data header */
654 
655     if (!data_off)
656         data_off = avio_tell(pb) - 18;
657     if (indx_off && (pb->seekable & AVIO_SEEKABLE_NORMAL) &&
658         !(s->flags & AVFMT_FLAG_IGNIDX) &&
659         avio_seek(pb, indx_off, SEEK_SET) >= 0) {
660         rm_read_index(s);
661         avio_seek(pb, data_off + 18, SEEK_SET);
662     }
663 
664     return 0;
665 }
666 
get_num(AVIOContext *pb, int *len)667 static int get_num(AVIOContext *pb, int *len)
668 {
669     int n, n1;
670 
671     n = avio_rb16(pb);
672     (*len)-=2;
673     n &= 0x7FFF;
674     if (n >= 0x4000) {
675         return n - 0x4000;
676     } else {
677         n1 = avio_rb16(pb);
678         (*len)-=2;
679         return (n << 16) | n1;
680     }
681 }
682 
683 /* multiple of 20 bytes for ra144 (ugly) */
684 #define RAW_PACKET_SIZE 1000
685 
rm_sync(AVFormatContext *s, int64_t *timestamp, int *flags, int *stream_index, int64_t *pos)686 static int rm_sync(AVFormatContext *s, int64_t *timestamp, int *flags, int *stream_index, int64_t *pos){
687     RMDemuxContext *rm = s->priv_data;
688     AVIOContext *pb = s->pb;
689     AVStream *st;
690     uint32_t state=0xFFFFFFFF;
691 
692     while(!avio_feof(pb)){
693         int len, num, i;
694         int mlti_id;
695         *pos= avio_tell(pb) - 3;
696         if(rm->remaining_len > 0){
697             num= rm->current_stream;
698             mlti_id = 0;
699             len= rm->remaining_len;
700             *timestamp = AV_NOPTS_VALUE;
701             *flags= 0;
702         }else{
703             state= (state<<8) + avio_r8(pb);
704 
705             if(state == MKBETAG('I', 'N', 'D', 'X')){
706                 int n_pkts;
707                 int64_t expected_len;
708                 len = avio_rb32(pb);
709                 avio_skip(pb, 2);
710                 n_pkts = avio_rb32(pb);
711                 expected_len = 20 + n_pkts * 14LL;
712 
713                 if (len == 20 && expected_len <= INT_MAX)
714                     /* some files don't add index entries to chunk size... */
715                     len = expected_len;
716                 else if (len != expected_len)
717                     av_log(s, AV_LOG_WARNING,
718                            "Index size %d (%d pkts) is wrong, should be %"PRId64".\n",
719                            len, n_pkts, expected_len);
720                 if(len < 14)
721                     continue;
722                 len -= 14; // we already read part of the index header
723                 goto skip;
724             } else if (state == MKBETAG('D','A','T','A')) {
725                 av_log(s, AV_LOG_WARNING,
726                        "DATA tag in middle of chunk, file may be broken.\n");
727             }
728 
729             if(state > (unsigned)0xFFFF || state <= 12)
730                 continue;
731             len=state - 12;
732             state= 0xFFFFFFFF;
733 
734             num = avio_rb16(pb);
735             *timestamp = avio_rb32(pb);
736             mlti_id = (avio_r8(pb) >> 1) - 1;
737             mlti_id = FFMAX(mlti_id, 0) << 16;
738             *flags = avio_r8(pb); /* flags */
739         }
740         for(i=0;i<s->nb_streams;i++) {
741             st = s->streams[i];
742             if (mlti_id + num == st->id)
743                 break;
744         }
745         if (i == s->nb_streams) {
746 skip:
747             /* skip packet if unknown number */
748             avio_skip(pb, len);
749             rm->remaining_len = 0;
750             continue;
751         }
752         *stream_index= i;
753 
754         return len;
755     }
756     return -1;
757 }
758 
rm_assemble_video_frame(AVFormatContext *s, AVIOContext *pb, RMDemuxContext *rm, RMStream *vst, AVPacket *pkt, int len, int *pseq, int64_t *timestamp)759 static int rm_assemble_video_frame(AVFormatContext *s, AVIOContext *pb,
760                                    RMDemuxContext *rm, RMStream *vst,
761                                    AVPacket *pkt, int len, int *pseq,
762                                    int64_t *timestamp)
763 {
764     int hdr;
765     int seq = 0, pic_num = 0, len2 = 0, pos = 0; //init to silence compiler warning
766     int type;
767     int ret;
768 
769     hdr = avio_r8(pb); len--;
770     type = hdr >> 6;
771 
772     if(type != 3){  // not frame as a part of packet
773         seq = avio_r8(pb); len--;
774     }
775     if(type != 1){  // not whole frame
776         len2 = get_num(pb, &len);
777         pos  = get_num(pb, &len);
778         pic_num = avio_r8(pb); len--;
779     }
780     if(len<0) {
781         av_log(s, AV_LOG_ERROR, "Insufficient data\n");
782         return -1;
783     }
784     rm->remaining_len = len;
785     if(type&1){     // frame, not slice
786         if(type == 3){  // frame as a part of packet
787             len= len2;
788             *timestamp = pos;
789         }
790         if(rm->remaining_len < len) {
791             av_log(s, AV_LOG_ERROR, "Insufficient remaining len\n");
792             return -1;
793         }
794         rm->remaining_len -= len;
795         if ((ret = av_new_packet(pkt, len + 9)) < 0)
796             return ret;
797         pkt->data[0] = 0;
798         AV_WL32(pkt->data + 1, 1);
799         AV_WL32(pkt->data + 5, 0);
800         if ((ret = avio_read(pb, pkt->data + 9, len)) != len) {
801             av_packet_unref(pkt);
802             av_log(s, AV_LOG_ERROR, "Failed to read %d bytes\n", len);
803             return ret < 0 ? ret : AVERROR(EIO);
804         }
805         return 0;
806     }
807     //now we have to deal with single slice
808 
809     *pseq = seq;
810     if((seq & 0x7F) == 1 || vst->curpic_num != pic_num){
811         if (len2 > ffio_limit(pb, len2)) {
812             av_log(s, AV_LOG_ERROR, "Impossibly sized packet\n");
813             return AVERROR_INVALIDDATA;
814         }
815         vst->slices = ((hdr & 0x3F) << 1) + 1;
816         vst->videobufsize = len2 + 8*vst->slices + 1;
817         av_packet_unref(&vst->pkt); //FIXME this should be output.
818         if ((ret = av_new_packet(&vst->pkt, vst->videobufsize)) < 0)
819             return ret;
820         vst->videobufpos = 8*vst->slices + 1;
821         vst->cur_slice = 0;
822         vst->curpic_num = pic_num;
823         vst->pktpos = avio_tell(pb);
824     }
825     if(type == 2)
826         len = FFMIN(len, pos);
827 
828     if(++vst->cur_slice > vst->slices) {
829         av_log(s, AV_LOG_ERROR, "cur slice %d, too large\n", vst->cur_slice);
830         return 1;
831     }
832     if(!vst->pkt.data)
833         return AVERROR(ENOMEM);
834     AV_WL32(vst->pkt.data - 7 + 8*vst->cur_slice, 1);
835     AV_WL32(vst->pkt.data - 3 + 8*vst->cur_slice, vst->videobufpos - 8*vst->slices - 1);
836     if(vst->videobufpos + len > vst->videobufsize) {
837         av_log(s, AV_LOG_ERROR, "outside videobufsize\n");
838         return 1;
839     }
840     if (avio_read(pb, vst->pkt.data + vst->videobufpos, len) != len)
841         return AVERROR(EIO);
842     vst->videobufpos += len;
843     rm->remaining_len-= len;
844 
845     if (type == 2 || vst->videobufpos == vst->videobufsize) {
846         vst->pkt.data[0] = vst->cur_slice-1;
847         av_packet_move_ref(pkt, &vst->pkt);
848         if(vst->slices != vst->cur_slice) //FIXME find out how to set slices correct from the begin
849             memmove(pkt->data + 1 + 8*vst->cur_slice, pkt->data + 1 + 8*vst->slices,
850                 vst->videobufpos - 1 - 8*vst->slices);
851         av_shrink_packet(pkt, vst->videobufpos + 8*(vst->cur_slice - vst->slices));
852         pkt->pts = AV_NOPTS_VALUE;
853         pkt->pos = vst->pktpos;
854         vst->slices = 0;
855         return 0;
856     }
857 
858     return 1;
859 }
860 
861 static inline void
rm_ac3_swap_bytes(AVStream *st, AVPacket *pkt)862 rm_ac3_swap_bytes (AVStream *st, AVPacket *pkt)
863 {
864     uint8_t *ptr;
865     int j;
866 
867     if (st->codecpar->codec_id == AV_CODEC_ID_AC3) {
868         ptr = pkt->data;
869         for (j=0;j<pkt->size;j+=2) {
870             FFSWAP(int, ptr[0], ptr[1]);
871             ptr += 2;
872         }
873     }
874 }
875 
readfull(AVFormatContext *s, AVIOContext *pb, uint8_t *dst, int n)876 static int readfull(AVFormatContext *s, AVIOContext *pb, uint8_t *dst, int n) {
877     int ret = avio_read(pb, dst, n);
878     if (ret != n) {
879         if (ret >= 0) memset(dst + ret, 0, n - ret);
880         else          memset(dst      , 0, n);
881         av_log(s, AV_LOG_ERROR, "Failed to fully read block\n");
882     }
883     return ret;
884 }
885 
886 int
ff_rm_parse_packet(AVFormatContext *s, AVIOContext *pb, AVStream *st, RMStream *ast, int len, AVPacket *pkt, int *seq, int flags, int64_t timestamp)887 ff_rm_parse_packet (AVFormatContext *s, AVIOContext *pb,
888                     AVStream *st, RMStream *ast, int len, AVPacket *pkt,
889                     int *seq, int flags, int64_t timestamp)
890 {
891     RMDemuxContext *rm = s->priv_data;
892     int ret;
893 
894     if (st->codecpar->codec_type == AVMEDIA_TYPE_VIDEO) {
895         rm->current_stream= st->id;
896         ret = rm_assemble_video_frame(s, pb, rm, ast, pkt, len, seq, &timestamp);
897         if(ret)
898             return ret < 0 ? ret : -1; //got partial frame or error
899     } else if (st->codecpar->codec_type == AVMEDIA_TYPE_AUDIO) {
900         if ((ast->deint_id == DEINT_ID_GENR) ||
901             (ast->deint_id == DEINT_ID_INT4) ||
902             (ast->deint_id == DEINT_ID_SIPR)) {
903             int x;
904             int sps = ast->sub_packet_size;
905             int cfs = ast->coded_framesize;
906             int h = ast->sub_packet_h;
907             int y = ast->sub_packet_cnt;
908             int w = ast->audio_framesize;
909 
910             if (flags & 2)
911                 y = ast->sub_packet_cnt = 0;
912             if (!y)
913                 ast->audiotimestamp = timestamp;
914 
915             switch (ast->deint_id) {
916                 case DEINT_ID_INT4:
917                     for (x = 0; x < h/2; x++)
918                         readfull(s, pb, ast->pkt.data+x*2*w+y*cfs, cfs);
919                     break;
920                 case DEINT_ID_GENR:
921                     for (x = 0; x < w/sps; x++)
922                         readfull(s, pb, ast->pkt.data+sps*(h*x+((h+1)/2)*(y&1)+(y>>1)), sps);
923                     break;
924                 case DEINT_ID_SIPR:
925                     readfull(s, pb, ast->pkt.data + y * w, w);
926                     break;
927             }
928 
929             if (++(ast->sub_packet_cnt) < h)
930                 return -1;
931             if (ast->deint_id == DEINT_ID_SIPR)
932                 ff_rm_reorder_sipr_data(ast->pkt.data, h, w);
933 
934              ast->sub_packet_cnt = 0;
935              rm->audio_stream_num = st->index;
936             if (st->codecpar->block_align <= 0) {
937                 av_log(s, AV_LOG_ERROR, "Invalid block alignment %d\n", st->codecpar->block_align);
938                 return AVERROR_INVALIDDATA;
939             }
940              rm->audio_pkt_cnt = h * w / st->codecpar->block_align;
941         } else if ((ast->deint_id == DEINT_ID_VBRF) ||
942                    (ast->deint_id == DEINT_ID_VBRS)) {
943             int x;
944             rm->audio_stream_num = st->index;
945             ast->sub_packet_cnt = (avio_rb16(pb) & 0xf0) >> 4;
946             if (ast->sub_packet_cnt) {
947                 for (x = 0; x < ast->sub_packet_cnt; x++)
948                     ast->sub_packet_lengths[x] = avio_rb16(pb);
949                 rm->audio_pkt_cnt = ast->sub_packet_cnt;
950                 ast->audiotimestamp = timestamp;
951             } else
952                 return -1;
953         } else {
954             ret = av_get_packet(pb, pkt, len);
955             if (ret < 0)
956                 return ret;
957             rm_ac3_swap_bytes(st, pkt);
958         }
959     } else {
960         ret = av_get_packet(pb, pkt, len);
961         if (ret < 0)
962             return ret;
963     }
964 
965     pkt->stream_index = st->index;
966 
967     pkt->pts = timestamp;
968     if (flags & 2)
969         pkt->flags |= AV_PKT_FLAG_KEY;
970 
971     return st->codecpar->codec_type == AVMEDIA_TYPE_AUDIO ? rm->audio_pkt_cnt : 0;
972 }
973 
974 int
ff_rm_retrieve_cache(AVFormatContext *s, AVIOContext *pb, AVStream *st, RMStream *ast, AVPacket *pkt)975 ff_rm_retrieve_cache (AVFormatContext *s, AVIOContext *pb,
976                       AVStream *st, RMStream *ast, AVPacket *pkt)
977 {
978     RMDemuxContext *rm = s->priv_data;
979     int ret;
980 
981     av_assert0 (rm->audio_pkt_cnt > 0);
982 
983     if (ast->deint_id == DEINT_ID_VBRF ||
984         ast->deint_id == DEINT_ID_VBRS) {
985         ret = av_get_packet(pb, pkt, ast->sub_packet_lengths[ast->sub_packet_cnt - rm->audio_pkt_cnt]);
986         if (ret < 0)
987             return ret;
988     } else {
989         ret = av_new_packet(pkt, st->codecpar->block_align);
990         if (ret < 0)
991             return ret;
992         memcpy(pkt->data, ast->pkt.data + st->codecpar->block_align * //FIXME avoid this
993                (ast->sub_packet_h * ast->audio_framesize / st->codecpar->block_align - rm->audio_pkt_cnt),
994                st->codecpar->block_align);
995     }
996     rm->audio_pkt_cnt--;
997     if ((pkt->pts = ast->audiotimestamp) != AV_NOPTS_VALUE) {
998         ast->audiotimestamp = AV_NOPTS_VALUE;
999         pkt->flags = AV_PKT_FLAG_KEY;
1000     } else
1001         pkt->flags = 0;
1002     pkt->stream_index = st->index;
1003 
1004     return rm->audio_pkt_cnt;
1005 }
1006 
rm_read_packet(AVFormatContext *s, AVPacket *pkt)1007 static int rm_read_packet(AVFormatContext *s, AVPacket *pkt)
1008 {
1009     RMDemuxContext *rm = s->priv_data;
1010     AVStream *st = NULL; // init to silence compiler warning
1011     int i, res, seq = 1;
1012     int64_t timestamp, pos, len;
1013     int flags;
1014 
1015     for (;;) {
1016         if (rm->audio_pkt_cnt) {
1017             // If there are queued audio packet return them first
1018             st = s->streams[rm->audio_stream_num];
1019             res = ff_rm_retrieve_cache(s, s->pb, st, st->priv_data, pkt);
1020             if(res < 0)
1021                 return res;
1022             flags = 0;
1023         } else {
1024             if (rm->old_format) {
1025                 RMStream *ast;
1026 
1027                 st = s->streams[0];
1028                 ast = st->priv_data;
1029                 timestamp = AV_NOPTS_VALUE;
1030                 len = !ast->audio_framesize ? RAW_PACKET_SIZE :
1031                     ast->coded_framesize * (int64_t)ast->sub_packet_h / 2;
1032                 if (len > INT_MAX)
1033                     return AVERROR_INVALIDDATA;
1034                 flags = (seq++ == 1) ? 2 : 0;
1035                 pos = avio_tell(s->pb);
1036             } else {
1037                 len = rm_sync(s, &timestamp, &flags, &i, &pos);
1038                 if (len > 0)
1039                     st = s->streams[i];
1040             }
1041 
1042             if (avio_feof(s->pb))
1043                 return AVERROR_EOF;
1044             if (len <= 0)
1045                 return AVERROR(EIO);
1046 
1047             res = ff_rm_parse_packet (s, s->pb, st, st->priv_data, len, pkt,
1048                                       &seq, flags, timestamp);
1049             if (res < -1)
1050                 return res;
1051             if((flags&2) && (seq&0x7F) == 1)
1052                 av_add_index_entry(st, pos, timestamp, 0, 0, AVINDEX_KEYFRAME);
1053             if (res)
1054                 continue;
1055         }
1056 
1057         if(  (st->discard >= AVDISCARD_NONKEY && !(flags&2))
1058            || st->discard >= AVDISCARD_ALL){
1059             av_packet_unref(pkt);
1060         } else
1061             break;
1062     }
1063 
1064     return 0;
1065 }
1066 
rm_read_close(AVFormatContext *s)1067 static int rm_read_close(AVFormatContext *s)
1068 {
1069     int i;
1070 
1071     for (i=0;i<s->nb_streams;i++)
1072         ff_rm_free_rmstream(s->streams[i]->priv_data);
1073 
1074     return 0;
1075 }
1076 
rm_probe(const AVProbeData *p)1077 static int rm_probe(const AVProbeData *p)
1078 {
1079     /* check file header */
1080     if ((p->buf[0] == '.' && p->buf[1] == 'R' &&
1081          p->buf[2] == 'M' && p->buf[3] == 'F' &&
1082          p->buf[4] == 0 && p->buf[5] == 0) ||
1083         (p->buf[0] == '.' && p->buf[1] == 'r' &&
1084          p->buf[2] == 'a' && p->buf[3] == 0xfd))
1085         return AVPROBE_SCORE_MAX;
1086     else
1087         return 0;
1088 }
1089 
rm_read_dts(AVFormatContext *s, int stream_index, int64_t *ppos, int64_t pos_limit)1090 static int64_t rm_read_dts(AVFormatContext *s, int stream_index,
1091                                int64_t *ppos, int64_t pos_limit)
1092 {
1093     RMDemuxContext *rm = s->priv_data;
1094     int64_t pos, dts;
1095     int stream_index2, flags, len, h;
1096 
1097     pos = *ppos;
1098 
1099     if(rm->old_format)
1100         return AV_NOPTS_VALUE;
1101 
1102     if (avio_seek(s->pb, pos, SEEK_SET) < 0)
1103         return AV_NOPTS_VALUE;
1104 
1105     rm->remaining_len=0;
1106     for(;;){
1107         int seq=1;
1108         AVStream *st;
1109 
1110         len = rm_sync(s, &dts, &flags, &stream_index2, &pos);
1111         if(len<0)
1112             return AV_NOPTS_VALUE;
1113 
1114         st = s->streams[stream_index2];
1115         if (st->codecpar->codec_type == AVMEDIA_TYPE_VIDEO) {
1116             h= avio_r8(s->pb); len--;
1117             if(!(h & 0x40)){
1118                 seq = avio_r8(s->pb); len--;
1119             }
1120         }
1121 
1122         if((flags&2) && (seq&0x7F) == 1){
1123             av_log(s, AV_LOG_TRACE, "%d %d-%d %"PRId64" %d\n",
1124                     flags, stream_index2, stream_index, dts, seq);
1125             av_add_index_entry(st, pos, dts, 0, 0, AVINDEX_KEYFRAME);
1126             if(stream_index2 == stream_index)
1127                 break;
1128         }
1129 
1130         avio_skip(s->pb, len);
1131     }
1132     *ppos = pos;
1133     return dts;
1134 }
1135 
rm_read_seek(AVFormatContext *s, int stream_index, int64_t pts, int flags)1136 static int rm_read_seek(AVFormatContext *s, int stream_index,
1137                         int64_t pts, int flags)
1138 {
1139     RMDemuxContext *rm = s->priv_data;
1140 
1141     if (ff_seek_frame_binary(s, stream_index, pts, flags) < 0)
1142         return -1;
1143     rm->audio_pkt_cnt = 0;
1144     return 0;
1145 }
1146 
1147 
1148 const AVInputFormat ff_rm_demuxer = {
1149     .name           = "rm",
1150     .long_name      = NULL_IF_CONFIG_SMALL("RealMedia"),
1151     .priv_data_size = sizeof(RMDemuxContext),
1152     .flags_internal = FF_FMT_INIT_CLEANUP,
1153     .read_probe     = rm_probe,
1154     .read_header    = rm_read_header,
1155     .read_packet    = rm_read_packet,
1156     .read_close     = rm_read_close,
1157     .read_timestamp = rm_read_dts,
1158     .read_seek      = rm_read_seek,
1159 };
1160 
1161 const AVInputFormat ff_rdt_demuxer = {
1162     .name           = "rdt",
1163     .long_name      = NULL_IF_CONFIG_SMALL("RDT demuxer"),
1164     .priv_data_size = sizeof(RMDemuxContext),
1165     .read_close     = rm_read_close,
1166     .flags          = AVFMT_NOFILE,
1167 };
1168 
ivr_probe(const AVProbeData *p)1169 static int ivr_probe(const AVProbeData *p)
1170 {
1171     if (memcmp(p->buf, ".R1M\x0\x1\x1", 7) &&
1172         memcmp(p->buf, ".REC", 4))
1173         return 0;
1174 
1175     return AVPROBE_SCORE_MAX;
1176 }
1177 
ivr_read_header(AVFormatContext *s)1178 static int ivr_read_header(AVFormatContext *s)
1179 {
1180     unsigned tag, type, len, tlen, value;
1181     int i, j, n, count, nb_streams = 0, ret;
1182     uint8_t key[256], val[256];
1183     AVIOContext *pb = s->pb;
1184     AVStream *st;
1185     int64_t pos, offset=0, temp;
1186 
1187     pos = avio_tell(pb);
1188     tag = avio_rl32(pb);
1189     if (tag == MKTAG('.','R','1','M')) {
1190         if (avio_rb16(pb) != 1)
1191             return AVERROR_INVALIDDATA;
1192         if (avio_r8(pb) != 1)
1193             return AVERROR_INVALIDDATA;
1194         len = avio_rb32(pb);
1195         avio_skip(pb, len);
1196         avio_skip(pb, 5);
1197         temp = avio_rb64(pb);
1198         while (!avio_feof(pb) && temp) {
1199             offset = temp;
1200             temp = avio_rb64(pb);
1201         }
1202         if (offset <= 0)
1203             return AVERROR_INVALIDDATA;
1204         avio_skip(pb, offset - avio_tell(pb));
1205         if (avio_r8(pb) != 1)
1206             return AVERROR_INVALIDDATA;
1207         len = avio_rb32(pb);
1208         avio_skip(pb, len);
1209         if (avio_r8(pb) != 2)
1210             return AVERROR_INVALIDDATA;
1211         avio_skip(pb, 16);
1212         pos = avio_tell(pb);
1213         tag = avio_rl32(pb);
1214     }
1215 
1216     if (tag != MKTAG('.','R','E','C'))
1217         return AVERROR_INVALIDDATA;
1218 
1219     if (avio_r8(pb) != 0)
1220         return AVERROR_INVALIDDATA;
1221     count = avio_rb32(pb);
1222     for (i = 0; i < count; i++) {
1223         if (avio_feof(pb))
1224             return AVERROR_INVALIDDATA;
1225 
1226         type = avio_r8(pb);
1227         tlen = avio_rb32(pb);
1228         avio_get_str(pb, tlen, key, sizeof(key));
1229         len = avio_rb32(pb);
1230         if (type == 5) {
1231             avio_get_str(pb, len, val, sizeof(val));
1232             av_log(s, AV_LOG_DEBUG, "%s = '%s'\n", key, val);
1233         } else if (type == 4) {
1234             av_log(s, AV_LOG_DEBUG, "%s = '0x", key);
1235             for (j = 0; j < len; j++) {
1236                 if (avio_feof(pb))
1237                     return AVERROR_INVALIDDATA;
1238                 av_log(s, AV_LOG_DEBUG, "%X", avio_r8(pb));
1239             }
1240             av_log(s, AV_LOG_DEBUG, "'\n");
1241         } else if (len == 4 && type == 3 && !strncmp(key, "StreamCount", tlen)) {
1242             nb_streams = value = avio_rb32(pb);
1243         } else if (len == 4 && type == 3) {
1244             value = avio_rb32(pb);
1245             av_log(s, AV_LOG_DEBUG, "%s = %d\n", key, value);
1246         } else {
1247             av_log(s, AV_LOG_DEBUG, "Skipping unsupported key: %s\n", key);
1248             avio_skip(pb, len);
1249         }
1250     }
1251 
1252     for (n = 0; n < nb_streams; n++) {
1253         if (!(st = avformat_new_stream(s, NULL)) ||
1254             !(st->priv_data = ff_rm_alloc_rmstream()))
1255             return AVERROR(ENOMEM);
1256 
1257         if (avio_r8(pb) != 1)
1258             return AVERROR_INVALIDDATA;
1259 
1260         count = avio_rb32(pb);
1261         for (i = 0; i < count; i++) {
1262             if (avio_feof(pb))
1263                 return AVERROR_INVALIDDATA;
1264 
1265             type = avio_r8(pb);
1266             tlen  = avio_rb32(pb);
1267             avio_get_str(pb, tlen, key, sizeof(key));
1268             len  = avio_rb32(pb);
1269             if (type == 5) {
1270                 avio_get_str(pb, len, val, sizeof(val));
1271                 av_log(s, AV_LOG_DEBUG, "%s = '%s'\n", key, val);
1272             } else if (type == 4 && !strncmp(key, "OpaqueData", tlen)) {
1273                 ret = ffio_ensure_seekback(pb, 4);
1274                 if (ret < 0)
1275                     return ret;
1276                 if (avio_rb32(pb) == MKBETAG('M', 'L', 'T', 'I')) {
1277                     ret = rm_read_multi(s, pb, st, NULL);
1278                 } else {
1279                     if (avio_feof(pb))
1280                         return AVERROR_INVALIDDATA;
1281                     avio_seek(pb, -4, SEEK_CUR);
1282                     ret = ff_rm_read_mdpr_codecdata(s, pb, st, st->priv_data, len, NULL);
1283                 }
1284 
1285                 if (ret < 0)
1286                     return ret;
1287             } else if (type == 4) {
1288                 int j;
1289 
1290                 av_log(s, AV_LOG_DEBUG, "%s = '0x", key);
1291                 for (j = 0; j < len; j++) {
1292                     if (avio_feof(pb))
1293                         return AVERROR_INVALIDDATA;
1294                     av_log(s, AV_LOG_DEBUG, "%X", avio_r8(pb));
1295                 }
1296                 av_log(s, AV_LOG_DEBUG, "'\n");
1297             } else if (len == 4 && type == 3 && !strncmp(key, "Duration", tlen)) {
1298                 st->duration = avio_rb32(pb);
1299             } else if (len == 4 && type == 3) {
1300                 value = avio_rb32(pb);
1301                 av_log(s, AV_LOG_DEBUG, "%s = %d\n", key, value);
1302             } else {
1303                 av_log(s, AV_LOG_DEBUG, "Skipping unsupported key: %s\n", key);
1304                 avio_skip(pb, len);
1305             }
1306         }
1307     }
1308 
1309     if (avio_r8(pb) != 6)
1310         return AVERROR_INVALIDDATA;
1311     avio_skip(pb, 12);
1312     avio_seek(pb, avio_rb64(pb) + pos, SEEK_SET);
1313     if (avio_r8(pb) != 8)
1314         return AVERROR_INVALIDDATA;
1315     avio_skip(pb, 8);
1316 
1317     return 0;
1318 }
1319 
ivr_read_packet(AVFormatContext *s, AVPacket *pkt)1320 static int ivr_read_packet(AVFormatContext *s, AVPacket *pkt)
1321 {
1322     RMDemuxContext *rm = s->priv_data;
1323     int ret = AVERROR_EOF, opcode;
1324     AVIOContext *pb = s->pb;
1325     unsigned size, index;
1326     int64_t pos, pts;
1327 
1328     if (avio_feof(pb) || rm->data_end)
1329         return AVERROR_EOF;
1330 
1331     pos = avio_tell(pb);
1332 
1333     for (;;) {
1334         if (rm->audio_pkt_cnt) {
1335             // If there are queued audio packet return them first
1336             AVStream *st;
1337 
1338             st = s->streams[rm->audio_stream_num];
1339             ret = ff_rm_retrieve_cache(s, pb, st, st->priv_data, pkt);
1340             if (ret < 0) {
1341                 return ret;
1342             }
1343         } else {
1344             if (rm->remaining_len) {
1345                 avio_skip(pb, rm->remaining_len);
1346                 rm->remaining_len = 0;
1347             }
1348 
1349             if (avio_feof(pb))
1350                 return AVERROR_EOF;
1351 
1352             opcode = avio_r8(pb);
1353             if (opcode == 2) {
1354                 AVStream *st;
1355                 int seq = 1;
1356 
1357                 pts = avio_rb32(pb);
1358                 index = avio_rb16(pb);
1359                 if (index >= s->nb_streams)
1360                     return AVERROR_INVALIDDATA;
1361 
1362                 avio_skip(pb, 4);
1363                 size = avio_rb32(pb);
1364                 avio_skip(pb, 4);
1365 
1366                 if (size < 1 || size > INT_MAX/4) {
1367                     av_log(s, AV_LOG_ERROR, "size %u is invalid\n", size);
1368                     return AVERROR_INVALIDDATA;
1369                 }
1370 
1371                 st = s->streams[index];
1372                 ret = ff_rm_parse_packet(s, pb, st, st->priv_data, size, pkt,
1373                                          &seq, 0, pts);
1374                 if (ret < -1) {
1375                     return ret;
1376                 } else if (ret) {
1377                     continue;
1378                 }
1379 
1380                 pkt->pos = pos;
1381                 pkt->pts = pts;
1382                 pkt->stream_index = index;
1383             } else if (opcode == 7) {
1384                 pos = avio_rb64(pb);
1385                 if (!pos) {
1386                     rm->data_end = 1;
1387                     return AVERROR_EOF;
1388                 }
1389             } else {
1390                 av_log(s, AV_LOG_ERROR, "Unsupported opcode=%d at %"PRIX64"\n", opcode, avio_tell(pb) - 1);
1391                 return AVERROR(EIO);
1392             }
1393         }
1394 
1395         break;
1396     }
1397 
1398     return ret;
1399 }
1400 
1401 const AVInputFormat ff_ivr_demuxer = {
1402     .name           = "ivr",
1403     .long_name      = NULL_IF_CONFIG_SMALL("IVR (Internet Video Recording)"),
1404     .priv_data_size = sizeof(RMDemuxContext),
1405     .flags_internal = FF_FMT_INIT_CLEANUP,
1406     .read_probe     = ivr_probe,
1407     .read_header    = ivr_read_header,
1408     .read_packet    = ivr_read_packet,
1409     .read_close     = rm_read_close,
1410     .extensions     = "ivr",
1411 };
1412