h264_refs.c 31.1 KB
Newer Older
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22
/*
 * H.26L/H.264/AVC/JVT/14496-10/... reference picture handling
 * Copyright (c) 2003 Michael Niedermayer <michaelni@gmx.at>
 *
 * This file is part of FFmpeg.
 *
 * FFmpeg is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2.1 of the License, or (at your option) any later version.
 *
 * FFmpeg is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU Lesser General Public
 * License along with FFmpeg; if not, write to the Free Software
 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
 */

/**
23
 * @file
24
 * H.264 / AVC / MPEG-4 part10  reference picture handling.
25 26 27
 * @author Michael Niedermayer <michaelni@gmx.at>
 */

28 29
#include <inttypes.h>

30
#include "libavutil/avassert.h"
31 32
#include "internal.h"
#include "avcodec.h"
33
#include "h264.h"
34
#include "h264dec.h"
35
#include "golomb.h"
36
#include "mpegutils.h"
37 38 39

#include <assert.h>

40 41
static void pic_as_field(H264Ref *pic, const int parity)
{
42
    int i;
43
    for (i = 0; i < FF_ARRAY_ELEMS(pic->data); ++i) {
44
        if (parity == PICT_BOTTOM_FIELD)
45
            pic->data[i]   += pic->linesize[i];
46
        pic->reference      = parity;
47
        pic->linesize[i] *= 2;
48
    }
49 50 51 52 53
    pic->poc = pic->parent->field_poc[parity == PICT_BOTTOM_FIELD];
}

static void ref_from_h264pic(H264Ref *dst, H264Picture *src)
{
54 55
    memcpy(dst->data,     src->f->data,     sizeof(dst->data));
    memcpy(dst->linesize, src->f->linesize, sizeof(dst->linesize));
56 57 58 59
    dst->reference = src->reference;
    dst->poc       = src->poc;
    dst->pic_id    = src->pic_id;
    dst->parent = src;
60 61
}

62
static int split_field_copy(H264Ref *dest, H264Picture *src, int parity, int id_add)
63
{
64
    int match = !!(src->reference & parity);
65 66

    if (match) {
67
        ref_from_h264pic(dest, src);
68
        if (parity != PICT_FRAME) {
69 70 71 72 73 74 75 76 77
            pic_as_field(dest, parity);
            dest->pic_id *= 2;
            dest->pic_id += id_add;
        }
    }

    return match;
}

78
static int build_def_list(H264Ref *def, int def_len,
79
                          H264Picture * const *in, int len, int is_long, int sel)
80 81 82
{
    int  i[2] = { 0 };
    int index = 0;
83

84
    while (i[0] < len || i[1] < len) {
85
        while (i[0] < len && !(in[i[0]] && (in[i[0]]->reference & sel)))
86
            i[0]++;
87
        while (i[1] < len && !(in[i[1]] && (in[i[1]]->reference & (sel ^ 3))))
88
            i[1]++;
89
        if (i[0] < len) {
90
            av_assert0(index < def_len);
91 92
            in[i[0]]->pic_id = is_long ? i[0] : in[i[0]]->frame_num;
            split_field_copy(&def[index++], in[i[0]++], sel, 1);
93
        }
94
        if (i[1] < len) {
95
            av_assert0(index < def_len);
96 97
            in[i[1]]->pic_id = is_long ? i[1] : in[i[1]]->frame_num;
            split_field_copy(&def[index++], in[i[1]++], sel ^ 3, 0);
98 99 100 101 102 103
        }
    }

    return index;
}

104 105
static int add_sorted(H264Picture **sorted, H264Picture * const *src,
                      int len, int limit, int dir)
106
{
107
    int i, best_poc;
108
    int out_i = 0;
109

110 111
    for (;;) {
        best_poc = dir ? INT_MIN : INT_MAX;
112

113 114 115 116 117
        for (i = 0; i < len; i++) {
            const int poc = src[i]->poc;
            if (((poc > limit) ^ dir) && ((poc < best_poc) ^ dir)) {
                best_poc      = poc;
                sorted[out_i] = src[i];
118 119
            }
        }
120
        if (best_poc == (dir ? INT_MIN : INT_MAX))
121
            break;
122
        limit = sorted[out_i++]->poc - dir;
123 124 125 126
    }
    return out_i;
}

127
static int mismatches_ref(const H264Context *h, const H264Picture *pic)
128
{
129
    const AVFrame *f = pic->f;
130 131 132 133 134
    return (h->cur_pic_ptr->f->width  != f->width ||
            h->cur_pic_ptr->f->height != f->height ||
            h->cur_pic_ptr->f->format != f->format);
}

135
static void h264_initialise_ref_list(H264Context *h, H264SliceContext *sl)
136
{
137
    int i, len;
138
    int j;
139

140
    if (sl->slice_type_nos == AV_PICTURE_TYPE_B) {
141
        H264Picture *sorted[32];
142 143 144
        int cur_poc, list;
        int lens[2];

145
        if (FIELD_PICTURE(h))
146
            cur_poc = h->cur_pic_ptr->field_poc[h->picture_structure == PICT_BOTTOM_FIELD];
147
        else
148 149 150 151 152
            cur_poc = h->cur_pic_ptr->poc;

        for (list = 0; list < 2; list++) {
            len  = add_sorted(sorted,       h->short_ref, h->short_ref_count, cur_poc, 1 ^ list);
            len += add_sorted(sorted + len, h->short_ref, h->short_ref_count, cur_poc, 0 ^ list);
153
            av_assert0(len <= 32);
154

155
            len  = build_def_list(sl->ref_list[list], FF_ARRAY_ELEMS(sl->ref_list[0]),
156
                                  sorted, len, 0, h->picture_structure);
157 158
            len += build_def_list(sl->ref_list[list] + len,
                                  FF_ARRAY_ELEMS(sl->ref_list[0]) - len,
159
                                  h->long_ref, 16, 1, h->picture_structure);
160
            av_assert0(len <= 32);
161

162
            if (len < sl->ref_count[list])
163
                memset(&sl->ref_list[list][len], 0, sizeof(H264Ref) * (sl->ref_count[list] - len));
164
            lens[list] = len;
165 166
        }

167
        if (lens[0] == lens[1] && lens[1] > 1) {
168
            for (i = 0; i < lens[0] &&
169 170
                        sl->ref_list[0][i].parent->f->buf[0]->buffer ==
                        sl->ref_list[1][i].parent->f->buf[0]->buffer; i++);
171
            if (i == lens[0]) {
172
                FFSWAP(H264Ref, sl->ref_list[1][0], sl->ref_list[1][1]);
173
            }
174
        }
175
    } else {
176
        len  = build_def_list(sl->ref_list[0], FF_ARRAY_ELEMS(sl->ref_list[0]),
177
                              h->short_ref, h->short_ref_count, 0, h->picture_structure);
178 179
        len += build_def_list(sl->ref_list[0] + len,
                              FF_ARRAY_ELEMS(sl->ref_list[0]) - len,
180
                              h-> long_ref, 16, 1, h->picture_structure);
181
        av_assert0(len <= 32);
182

183
        if (len < sl->ref_count[0])
184
            memset(&sl->ref_list[0][len], 0, sizeof(H264Ref) * (sl->ref_count[0] - len));
185
    }
186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201
#ifdef TRACE
    for (i = 0; i < sl->ref_count[0]; i++) {
        ff_tlog(h->avctx, "List0: %s fn:%d 0x%p\n",
                (sl->ref_list[0][i].parent ? (sl->ref_list[0][i].parent->long_ref ? "LT" : "ST") : "??"),
                sl->ref_list[0][i].pic_id,
                sl->ref_list[0][i].data[0]);
    }
    if (sl->slice_type_nos == AV_PICTURE_TYPE_B) {
        for (i = 0; i < sl->ref_count[1]; i++) {
            ff_tlog(h->avctx, "List1: %s fn:%d 0x%p\n",
                    (sl->ref_list[1][i].parent ? (sl->ref_list[1][i].parent->long_ref ? "LT" : "ST") : "??"),
                    sl->ref_list[1][i].pic_id,
                    sl->ref_list[1][i].data[0]);
        }
    }
#endif
202 203 204

    for (j = 0; j<1+(sl->slice_type_nos == AV_PICTURE_TYPE_B); j++) {
        for (i = 0; i < sl->ref_count[j]; i++) {
205 206
            if (sl->ref_list[j][i].parent) {
                if (mismatches_ref(h, sl->ref_list[j][i].parent)) {
207
                    av_log(h->avctx, AV_LOG_ERROR, "Discarding mismatching reference\n");
208
                    memset(&sl->ref_list[j][i], 0, sizeof(sl->ref_list[j][i]));
209 210 211 212
                }
            }
        }
    }
213 214
    for (i = 0; i < sl->list_count; i++)
        h->default_ref[i] = sl->ref_list[i][0];
215 216
}

217 218 219
/**
 * print short term list
 */
220
static void print_short_term(const H264Context *h)
221 222 223 224 225 226 227 228 229 230 231 232 233 234 235
{
    uint32_t i;
    if (h->avctx->debug & FF_DEBUG_MMCO) {
        av_log(h->avctx, AV_LOG_DEBUG, "short term list:\n");
        for (i = 0; i < h->short_ref_count; i++) {
            H264Picture *pic = h->short_ref[i];
            av_log(h->avctx, AV_LOG_DEBUG, "%"PRIu32" fn:%d poc:%d %p\n",
                   i, pic->frame_num, pic->poc, pic->f->data[0]);
        }
    }
}

/**
 * print long term list
 */
236
static void print_long_term(const H264Context *h)
237 238 239 240 241 242 243 244 245 246 247 248 249
{
    uint32_t i;
    if (h->avctx->debug & FF_DEBUG_MMCO) {
        av_log(h->avctx, AV_LOG_DEBUG, "long term list:\n");
        for (i = 0; i < 16; i++) {
            H264Picture *pic = h->long_ref[i];
            if (pic) {
                av_log(h->avctx, AV_LOG_DEBUG, "%"PRIu32" fn:%d poc:%d %p\n",
                       i, pic->frame_num, pic->poc, pic->f->data[0]);
            }
        }
    }
}
250 251 252 253 254 255 256 257 258 259 260

/**
 * Extract structure information about the picture described by pic_num in
 * the current decoding context (frame or field). Note that pic_num is
 * picture number without wrapping (so, 0<=pic_num<max_pic_num).
 * @param pic_num picture number for which to extract structure information
 * @param structure one of PICT_XXX describing structure of picture
 *                      with pic_num
 * @return frame number (short term) or long term index of picture
 *         described by pic_num
 */
261
static int pic_num_extract(const H264Context *h, int pic_num, int *structure)
262
{
263
    *structure = h->picture_structure;
264
    if (FIELD_PICTURE(h)) {
265 266 267 268 269 270 271 272 273
        if (!(pic_num & 1))
            /* opposite field */
            *structure ^= PICT_FRAME;
        pic_num >>= 1;
    }

    return pic_num;
}

274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298
static void h264_fill_mbaff_ref_list(H264SliceContext *sl)
{
    int list, i, j;
    for (list = 0; list < sl->list_count; list++) {
        for (i = 0; i < sl->ref_count[list]; i++) {
            H264Ref *frame = &sl->ref_list[list][i];
            H264Ref *field = &sl->ref_list[list][16 + 2 * i];

            field[0] = *frame;

            for (j = 0; j < 3; j++)
                field[0].linesize[j] <<= 1;
            field[0].reference = PICT_TOP_FIELD;
            field[0].poc       = field[0].parent->field_poc[0];

            field[1] = field[0];

            for (j = 0; j < 3; j++)
                field[1].data[j] += frame->parent->f->linesize[j];
            field[1].reference = PICT_BOTTOM_FIELD;
            field[1].poc       = field[1].parent->field_poc[1];
        }
    }
}

299
int ff_h264_build_ref_list(H264Context *h, H264SliceContext *sl)
300
{
301
    int list, index, pic_structure;
302 303 304 305

    print_short_term(h);
    print_long_term(h);

306
    h264_initialise_ref_list(h, sl);
307

308
    for (list = 0; list < sl->list_count; list++) {
309
        int pred = sl->curr_pic_num;
310 311 312 313 314 315 316 317 318 319 320 321 322 323

        for (index = 0; index < sl->nb_ref_modifications[list]; index++) {
            unsigned int modification_of_pic_nums_idc = sl->ref_modifications[list][index].op;
            unsigned int                          val = sl->ref_modifications[list][index].val;
            unsigned int pic_id;
            int i;
            H264Picture *ref = NULL;

            switch (modification_of_pic_nums_idc) {
            case 0:
            case 1: {
                const unsigned int abs_diff_pic_num = val + 1;
                int frame_num;

324
                if (abs_diff_pic_num > sl->max_pic_num) {
325 326 327
                    av_log(h->avctx, AV_LOG_ERROR,
                           "abs_diff_pic_num overflow\n");
                    return AVERROR_INVALIDDATA;
328 329
                }

330 331 332 333
                if (modification_of_pic_nums_idc == 0)
                    pred -= abs_diff_pic_num;
                else
                    pred += abs_diff_pic_num;
334
                pred &= sl->max_pic_num - 1;
335 336 337 338 339 340 341 342 343 344

                frame_num = pic_num_extract(h, pred, &pic_structure);

                for (i = h->short_ref_count - 1; i >= 0; i--) {
                    ref = h->short_ref[i];
                    assert(ref->reference);
                    assert(!ref->long_ref);
                    if (ref->frame_num == frame_num &&
                        (ref->reference & pic_structure))
                        break;
345
                }
346 347 348 349 350 351 352 353 354 355
                if (i >= 0)
                    ref->pic_id = pred;
                break;
            }
            case 2: {
                int long_idx;
                pic_id = val; // long_term_pic_idx

                long_idx = pic_num_extract(h, pic_id, &pic_structure);

356
                if (long_idx > 31U) {
357
                    av_log(h->avctx, AV_LOG_ERROR,
358
                           "long_term_pic_idx overflow\n");
359 360
                    return AVERROR_INVALIDDATA;
                }
361 362 363 364 365 366
                ref = h->long_ref[long_idx];
                assert(!(ref && !ref->reference));
                if (ref && (ref->reference & pic_structure)) {
                    ref->pic_id = pic_id;
                    assert(ref->long_ref);
                    i = 0;
367
                } else {
368 369 370 371
                    i = -1;
                }
                break;
            }
372
            default:
373
                av_assert0(0);
374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391 392
            }

            if (i < 0) {
                av_log(h->avctx, AV_LOG_ERROR,
                       "reference picture missing during reorder\n");
                memset(&sl->ref_list[list][index], 0, sizeof(sl->ref_list[0][0])); // FIXME
            } else {
                for (i = index; i + 1 < sl->ref_count[list]; i++) {
                    if (sl->ref_list[list][i].parent &&
                        ref->long_ref == sl->ref_list[list][i].parent->long_ref &&
                        ref->pic_id   == sl->ref_list[list][i].pic_id)
                        break;
                }
                for (; i > index; i--) {
                    sl->ref_list[list][i] = sl->ref_list[list][i - 1];
                }
                ref_from_h264pic(&sl->ref_list[list][index], ref);
                if (FIELD_PICTURE(h)) {
                    pic_as_field(&sl->ref_list[list][index], pic_structure);
393 394 395 396
                }
            }
        }
    }
397 398
    for (list = 0; list < sl->list_count; list++) {
        for (index = 0; index < sl->ref_count[list]; index++) {
399
            if (   !sl->ref_list[list][index].parent
400
                || (!FIELD_PICTURE(h) && (sl->ref_list[list][index].reference&3) != 3)) {
401
                int i;
402
                av_log(h->avctx, AV_LOG_ERROR, "Missing reference picture, default is %d\n", h->default_ref[list].poc);
403
                for (i = 0; i < FF_ARRAY_ELEMS(h->last_pocs); i++)
404
                    h->last_pocs[i] = INT_MIN;
405 406 407 408 409
                if (h->default_ref[list].parent
                    && !(!FIELD_PICTURE(h) && (h->default_ref[list].reference&3) != 3))
                    sl->ref_list[list][index] = h->default_ref[list];
                else
                    return -1;
410
            }
411
            av_assert0(av_buffer_get_ref_count(sl->ref_list[list][index].parent->f->buf[0]) > 0);
412 413 414
        }
    }

415 416
    if (FRAME_MBAFF(h))
        h264_fill_mbaff_ref_list(sl);
417

418
    return 0;
419 420
}

421
int ff_h264_decode_ref_pic_list_reordering(H264SliceContext *sl, void *logctx)
422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438
{
    int list, index;

    sl->nb_ref_modifications[0] = 0;
    sl->nb_ref_modifications[1] = 0;

    for (list = 0; list < sl->list_count; list++) {
        if (!get_bits1(&sl->gb))    // ref_pic_list_modification_flag_l[01]
            continue;

        for (index = 0; ; index++) {
            unsigned int op = get_ue_golomb_31(&sl->gb);

            if (op == 3)
                break;

            if (index >= sl->ref_count[list]) {
439
                av_log(logctx, AV_LOG_ERROR, "reference count overflow\n");
440 441
                return AVERROR_INVALIDDATA;
            } else if (op > 2) {
442
                av_log(logctx, AV_LOG_ERROR,
443 444 445 446
                       "illegal modification_of_pic_nums_idc %u\n",
                       op);
                return AVERROR_INVALIDDATA;
            }
447
            sl->ref_modifications[list][index].val = get_ue_golomb_long(&sl->gb);
448 449 450 451 452 453 454 455
            sl->ref_modifications[list][index].op  = op;
            sl->nb_ref_modifications[list]++;
        }
    }

    return 0;
}

456 457 458 459 460 461 462 463 464 465 466
/**
 * Mark a picture as no longer needed for reference. The refmask
 * argument allows unreferencing of individual fields or the whole frame.
 * If the picture becomes entirely unreferenced, but is being held for
 * display purposes, it is marked as such.
 * @param refmask mask of fields to unreference; the mask is bitwise
 *                anded with the reference marking of pic
 * @return non-zero if pic becomes entirely unreferenced (except possibly
 *         for display purposes) zero if one of the fields remains in
 *         reference
 */
467
static inline int unreference_pic(H264Context *h, H264Picture *pic, int refmask)
468
{
469
    int i;
470
    if (pic->reference &= refmask) {
471 472 473 474
        return 0;
    } else {
        for(i = 0; h->delayed_pic[i]; i++)
            if(pic == h->delayed_pic[i]){
475
                pic->reference = DELAYED_PIC_REF;
476 477 478 479 480 481 482
                break;
            }
        return 1;
    }
}

/**
483
 * Find a H264Picture in the short term reference list by frame number.
484 485 486 487 488 489
 * @param frame_num frame number to search for
 * @param idx the index into h->short_ref where returned picture is found
 *            undefined if no picture found.
 * @return pointer to the found picture, or NULL if no pic with the provided
 *                 frame number is found
 */
490
static H264Picture *find_short(H264Context *h, int frame_num, int *idx)
491
{
492 493
    int i;

494
    for (i = 0; i < h->short_ref_count; i++) {
495
        H264Picture *pic = h->short_ref[i];
496
        if (h->avctx->debug & FF_DEBUG_MMCO)
497
            av_log(h->avctx, AV_LOG_DEBUG, "%d %d %p\n", i, pic->frame_num, pic);
498
        if (pic->frame_num == frame_num) {
499 500 501 502 503 504 505 506 507 508 509 510 511
            *idx = i;
            return pic;
        }
    }
    return NULL;
}

/**
 * Remove a picture from the short term reference list by its index in
 * that list.  This does no checking on the provided index; it is assumed
 * to be valid. Other list entries are shifted down.
 * @param i index into h->short_ref of picture to remove.
 */
512 513
static void remove_short_at_index(H264Context *h, int i)
{
514
    assert(i >= 0 && i < h->short_ref_count);
515
    h->short_ref[i] = NULL;
516
    if (--h->short_ref_count)
517
        memmove(&h->short_ref[i], &h->short_ref[i + 1],
518
                (h->short_ref_count - i) * sizeof(H264Picture*));
519 520 521 522 523
}

/**
 * @return the removed picture or NULL if an error occurs
 */
524
static H264Picture *remove_short(H264Context *h, int frame_num, int ref_mask)
525
{
526
    H264Picture *pic;
527 528
    int i;

529
    if (h->avctx->debug & FF_DEBUG_MMCO)
530
        av_log(h->avctx, AV_LOG_DEBUG, "remove short %d count %d\n", frame_num, h->short_ref_count);
531 532

    pic = find_short(h, frame_num, &i);
533 534 535
    if (pic) {
        if (unreference_pic(h, pic, ref_mask))
            remove_short_at_index(h, i);
536 537 538 539 540 541 542 543 544 545
    }

    return pic;
}

/**
 * Remove a picture from the long term reference list by its index in
 * that list.
 * @return the removed picture or NULL if an error occurs
 */
546
static H264Picture *remove_long(H264Context *h, int i, int ref_mask)
547
{
548
    H264Picture *pic;
549

550 551 552
    pic = h->long_ref[i];
    if (pic) {
        if (unreference_pic(h, pic, ref_mask)) {
553
            assert(h->long_ref[i]->long_ref == 1);
554 555
            h->long_ref[i]->long_ref = 0;
            h->long_ref[i]           = NULL;
556 557 558 559 560 561 562
            h->long_ref_count--;
        }
    }

    return pic;
}

563 564
void ff_h264_remove_all_refs(H264Context *h)
{
565 566
    int i;

567
    for (i = 0; i < 16; i++) {
568 569
        remove_long(h, i, 0);
    }
570
    assert(h->long_ref_count == 0);
571

572
    if (h->short_ref_count && !h->last_pic_for_ec.f->data[0]) {
573
        ff_h264_unref_picture(h, &h->last_pic_for_ec);
574 575
        if (h->short_ref[0]->f->buf[0])
            ff_h264_ref_picture(h, &h->last_pic_for_ec, h->short_ref[0]);
576
    }
577

578
    for (i = 0; i < h->short_ref_count; i++) {
579
        unreference_pic(h, h->short_ref[i], 0);
580
        h->short_ref[i] = NULL;
581
    }
582
    h->short_ref_count = 0;
583

584
    memset(h->default_ref, 0, sizeof(h->default_ref));
585 586
}

587
static void generate_sliding_window_mmcos(H264Context *h)
588
{
589 590
    MMCO *mmco = h->mmco;
    int nb_mmco = 0;
591 592

    if (h->short_ref_count &&
593
        h->long_ref_count + h->short_ref_count >= h->ps.sps->ref_frame_count &&
594
        !(FIELD_PICTURE(h) && !h->first_field && h->cur_pic_ptr->reference)) {
595
        mmco[0].opcode        = MMCO_SHORT2UNUSED;
596
        mmco[0].short_pic_num = h->short_ref[h->short_ref_count - 1]->frame_num;
597
        nb_mmco               = 1;
598
        if (FIELD_PICTURE(h)) {
599
            mmco[0].short_pic_num *= 2;
600 601
            mmco[1].opcode         = MMCO_SHORT2UNUSED;
            mmco[1].short_pic_num  = mmco[0].short_pic_num + 1;
602
            nb_mmco                = 2;
603 604
        }
    }
605

606
    h->nb_mmco = nb_mmco;
607 608
}

609
int ff_h264_execute_ref_pic_marking(H264Context *h)
610
{
611 612
    MMCO *mmco = h->mmco;
    int mmco_count;
613
    int i, av_uninit(j);
614
    int pps_ref_count[2] = {0};
615
    int current_ref_assigned = 0, err = 0;
616
    H264Picture *av_uninit(pic);
617

618 619 620 621
    if (!h->explicit_ref_marking)
        generate_sliding_window_mmcos(h);
    mmco_count = h->nb_mmco;

622
    if ((h->avctx->debug & FF_DEBUG_MMCO) && mmco_count == 0)
623
        av_log(h->avctx, AV_LOG_DEBUG, "no mmco here\n");
624

625
    for (i = 0; i < mmco_count; i++) {
626
        int av_uninit(structure), av_uninit(frame_num);
627 628 629
        if (h->avctx->debug & FF_DEBUG_MMCO)
            av_log(h->avctx, AV_LOG_DEBUG, "mmco:%d %d %d\n", h->mmco[i].opcode,
                   h->mmco[i].short_pic_num, h->mmco[i].long_arg);
630

631 632
        if (mmco[i].opcode == MMCO_SHORT2UNUSED ||
            mmco[i].opcode == MMCO_SHORT2LONG) {
633
            frame_num = pic_num_extract(h, mmco[i].short_pic_num, &structure);
634 635 636 637 638
            pic       = find_short(h, frame_num, &j);
            if (!pic) {
                if (mmco[i].opcode != MMCO_SHORT2LONG ||
                    !h->long_ref[mmco[i].long_arg]    ||
                    h->long_ref[mmco[i].long_arg]->frame_num != frame_num) {
639
                    av_log(h->avctx, h->short_ref_count ? AV_LOG_ERROR : AV_LOG_DEBUG, "mmco: unref short failure\n");
640 641
                    err = AVERROR_INVALIDDATA;
                }
642 643 644 645
                continue;
            }
        }

646
        switch (mmco[i].opcode) {
647
        case MMCO_SHORT2UNUSED:
648 649 650
            if (h->avctx->debug & FF_DEBUG_MMCO)
                av_log(h->avctx, AV_LOG_DEBUG, "mmco: unref short %d count %d\n",
                       h->mmco[i].short_pic_num, h->short_ref_count);
651 652 653 654 655 656 657
            remove_short(h, frame_num, structure ^ PICT_FRAME);
            break;
        case MMCO_SHORT2LONG:
                if (h->long_ref[mmco[i].long_arg] != pic)
                    remove_long(h, mmco[i].long_arg, 0);

                remove_short_at_index(h, j);
658 659 660
                h->long_ref[ mmco[i].long_arg ] = pic;
                if (h->long_ref[mmco[i].long_arg]) {
                    h->long_ref[mmco[i].long_arg]->long_ref = 1;
661 662 663 664
                    h->long_ref_count++;
                }
            break;
        case MMCO_LONG2UNUSED:
665
            j   = pic_num_extract(h, mmco[i].long_arg, &structure);
666 667 668
            pic = h->long_ref[j];
            if (pic) {
                remove_long(h, j, structure ^ PICT_FRAME);
669
            } else if (h->avctx->debug & FF_DEBUG_MMCO)
670
                av_log(h->avctx, AV_LOG_DEBUG, "mmco: unref long failure\n");
671 672
            break;
        case MMCO_LONG:
673
                    // Comment below left from previous code as it is an interesting note.
674 675 676 677 678 679
                    /* First field in pair is in short term list or
                     * at a different long term index.
                     * This is not allowed; see 7.4.3.3, notes 2 and 3.
                     * Report the problem and keep the pair where it is,
                     * and mark this field valid.
                     */
680 681
            if (h->short_ref[0] == h->cur_pic_ptr) {
                av_log(h->avctx, AV_LOG_ERROR, "mmco: cannot assign current picture to short and long at the same time\n");
682
                remove_short_at_index(h, 0);
683
            }
684

685 686 687
            /* make sure the current picture is not already assigned as a long ref */
            if (h->cur_pic_ptr->long_ref) {
                for (j = 0; j < FF_ARRAY_ELEMS(h->long_ref); j++) {
688 689
                    if (h->long_ref[j] == h->cur_pic_ptr) {
                        if (j != mmco[i].long_arg)
690
                            av_log(h->avctx, AV_LOG_ERROR, "mmco: cannot assign current picture to 2 long term references\n");
691
                        remove_long(h, j, 0);
692 693
                    }
                }
694 695
            }

696
            if (h->long_ref[mmco[i].long_arg] != h->cur_pic_ptr) {
697
                av_assert0(!h->cur_pic_ptr->long_ref);
698 699
                remove_long(h, mmco[i].long_arg, 0);

700 701
                h->long_ref[mmco[i].long_arg]           = h->cur_pic_ptr;
                h->long_ref[mmco[i].long_arg]->long_ref = 1;
702 703 704
                h->long_ref_count++;
            }

705
            h->cur_pic_ptr->reference |= h->picture_structure;
706
            current_ref_assigned = 1;
707 708 709 710
            break;
        case MMCO_SET_MAX_LONG:
            assert(mmco[i].long_arg <= 16);
            // just remove the long term which index is greater than new max
711
            for (j = mmco[i].long_arg; j < 16; j++) {
712 713 714 715
                remove_long(h, j, 0);
            }
            break;
        case MMCO_RESET:
716
            while (h->short_ref_count) {
717 718
                remove_short(h, h->short_ref[0]->frame_num, 0);
            }
719
            for (j = 0; j < 16; j++) {
720 721
                remove_long(h, j, 0);
            }
722
            h->poc.frame_num = h->cur_pic_ptr->frame_num = 0;
723
            h->mmco_reset = 1;
724
            h->cur_pic_ptr->mmco_reset = 1;
725 726
            for (j = 0; j < MAX_DELAYED_PIC_COUNT; j++)
                h->last_pocs[j] = INT_MIN;
727 728 729 730 731 732 733 734 735 736 737 738
            break;
        default: assert(0);
        }
    }

    if (!current_ref_assigned) {
        /* Second field of complementary field pair; the first field of
         * which is already referenced. If short referenced, it
         * should be first entry in short_ref. If not, it must exist
         * in long_ref; trying to put it on the short list here is an
         * error in the encoded bit stream (ref: 7.4.3.3, NOTE 2 and 3).
         */
739
        if (h->short_ref_count && h->short_ref[0] == h->cur_pic_ptr) {
740
            /* Just mark the second field valid */
741
            h->cur_pic_ptr->reference |= h->picture_structure;
742 743 744 745 746
        } else if (h->cur_pic_ptr->long_ref) {
            av_log(h->avctx, AV_LOG_ERROR, "illegal short term reference "
                                           "assignment for second field "
                                           "in complementary field pair "
                                           "(first field is long term)\n");
747
            err = AVERROR_INVALIDDATA;
748
        } else {
749 750
            pic = remove_short(h, h->cur_pic_ptr->frame_num, 0);
            if (pic) {
751
                av_log(h->avctx, AV_LOG_ERROR, "illegal short term buffer state detected\n");
752
                err = AVERROR_INVALIDDATA;
753 754
            }

755 756
            if (h->short_ref_count)
                memmove(&h->short_ref[1], &h->short_ref[0],
757
                        h->short_ref_count * sizeof(H264Picture*));
758

759
            h->short_ref[0] = h->cur_pic_ptr;
760
            h->short_ref_count++;
761
            h->cur_pic_ptr->reference |= h->picture_structure;
762 763 764
        }
    }

765
    if (h->long_ref_count + h->short_ref_count > FFMAX(h->ps.sps->ref_frame_count, 1)) {
766 767 768 769 770

        /* We have too many reference frames, probably due to corrupted
         * stream. Need to discard one frame. Prevents overrun of the
         * short_ref and long_ref buffers.
         */
771
        av_log(h->avctx, AV_LOG_ERROR,
772 773
               "number of reference frames (%d+%d) exceeds max (%d; probably "
               "corrupt input), discarding one\n",
774
               h->long_ref_count, h->short_ref_count, h->ps.sps->ref_frame_count);
775
        err = AVERROR_INVALIDDATA;
776 777 778 779 780 781 782 783 784 785 786 787 788 789

        if (h->long_ref_count && !h->short_ref_count) {
            for (i = 0; i < 16; ++i)
                if (h->long_ref[i])
                    break;

            assert(i < 16);
            remove_long(h, i, 0);
        } else {
            pic = h->short_ref[h->short_ref_count - 1];
            remove_short(h, pic->frame_num, 0);
        }
    }

790 791 792
    for (i = 0; i<h->short_ref_count; i++) {
        pic = h->short_ref[i];
        if (pic->invalid_gap) {
793 794
            int d = av_mod_uintp2(h->cur_pic_ptr->frame_num - pic->frame_num, h->ps.sps->log2_max_frame_num);
            if (d > h->ps.sps->ref_frame_count)
795 796 797 798
                remove_short(h, pic->frame_num, 0);
        }
    }

799 800
    print_short_term(h);
    print_long_term(h);
801

802 803 804 805 806
    for (i = 0; i < FF_ARRAY_ELEMS(h->ps.pps_list); i++) {
        if (h->ps.pps_list[i]) {
            const PPS *pps = (const PPS *)h->ps.pps_list[i]->data;
            pps_ref_count[0] = FFMAX(pps_ref_count[0], pps->ref_count[0]);
            pps_ref_count[1] = FFMAX(pps_ref_count[1], pps->ref_count[1]);
807
        }
808
    }
809

810 811
    if (   err >= 0
        && h->long_ref_count==0
812 813
        && (   h->short_ref_count<=2
            || pps_ref_count[0] <= 1 + (h->picture_structure != PICT_FRAME) && pps_ref_count[1] <= 1)
814
        && pps_ref_count[0]<=2 + (h->picture_structure != PICT_FRAME) + (2*!h->has_recovery_point)
815
        && h->cur_pic_ptr->f->pict_type == AV_PICTURE_TYPE_I){
816
        h->cur_pic_ptr->recovered |= 1;
817
        if(!h->avctx->has_b_frames)
818
            h->frame_recovered |= FRAME_RECOVERED_SEI;
819 820
    }

821
    return (h->avctx->err_recognition & AV_EF_EXPLODE) ? err : 0;
822 823
}

824 825
int ff_h264_decode_ref_pic_marking(H264SliceContext *sl, GetBitContext *gb,
                                   const H2645NAL *nal, void *logctx)
826
{
827
    int i;
828
    MMCO *mmco = sl->mmco;
829
    int nb_mmco = 0;
830

831
    if (nal->type == H264_NAL_IDR_SLICE) { // FIXME fields
832
        skip_bits1(gb); // broken_link
833 834
        if (get_bits1(gb)) {
            mmco[0].opcode   = MMCO_LONG;
835
            mmco[0].long_arg = 0;
836
            nb_mmco          = 1;
837
        }
838
        sl->explicit_ref_marking = 1;
839
    } else {
840 841
        sl->explicit_ref_marking = get_bits1(gb);
        if (sl->explicit_ref_marking) {
842 843 844 845
            for (i = 0; i < MAX_MMCO_COUNT; i++) {
                MMCOOpcode opcode = get_ue_golomb_31(gb);

                mmco[i].opcode = opcode;
846
                if (opcode == MMCO_SHORT2UNUSED || opcode == MMCO_SHORT2LONG) {
847
                    mmco[i].short_pic_num =
848
                        (sl->curr_pic_num - get_ue_golomb_long(gb) - 1) &
849
                            (sl->max_pic_num - 1);
850 851
#if 0
                    if (mmco[i].short_pic_num >= h->short_ref_count ||
852
                        !h->short_ref[mmco[i].short_pic_num]) {
853 854 855
                        av_log(s->avctx, AV_LOG_ERROR,
                               "illegal short ref in memory management control "
                               "operation %d\n", mmco);
856
                        return -1;
857 858
                    }
#endif
859
                }
860 861 862 863 864 865
                if (opcode == MMCO_SHORT2LONG || opcode == MMCO_LONG2UNUSED ||
                    opcode == MMCO_LONG || opcode == MMCO_SET_MAX_LONG) {
                    unsigned int long_arg = get_ue_golomb_31(gb);
                    if (long_arg >= 32 ||
                        (long_arg >= 16 && !(opcode == MMCO_SET_MAX_LONG &&
                                             long_arg == 16) &&
866 867
                         !(opcode == MMCO_LONG2UNUSED && FIELD_PICTURE(sl)))) {
                        av_log(logctx, AV_LOG_ERROR,
868 869
                               "illegal long ref in memory management control "
                               "operation %d\n", opcode);
870 871
                        return -1;
                    }
872
                    mmco[i].long_arg = long_arg;
873 874
                }

875
                if (opcode > (unsigned) MMCO_LONG) {
876
                    av_log(logctx, AV_LOG_ERROR,
877 878
                           "illegal memory management control operation %d\n",
                           opcode);
879 880
                    return -1;
                }
881
                if (opcode == MMCO_END)
882 883
                    break;
            }
884
            nb_mmco = i;
885 886 887
        }
    }

888
    sl->nb_mmco = nb_mmco;
889

890 891
    return 0;
}