Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Contribute to GitLab
Sign in / Register
Toggle navigation
F
ffmpeg.wasm-core
Project
Project
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
Linshizhi
ffmpeg.wasm-core
Commits
a9401981
Commit
a9401981
authored
Mar 17, 2012
by
Ronald S. Bultje
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
cabac: add overread protection to BRANCHLESS_GET_CABAC().
Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind
parent
448dc425
Show whitespace changes
Inline
Side-by-side
Showing
2 changed files
with
22 additions
and
11 deletions
+22
-11
cabac.h
libavcodec/x86/cabac.h
+10
-5
h264_i386.h
libavcodec/x86/h264_i386.h
+12
-6
No files found.
libavcodec/x86/cabac.h
View file @
a9401981
...
@@ -51,7 +51,7 @@
...
@@ -51,7 +51,7 @@
"xor "tmp" , "ret" \n\t"
"xor "tmp" , "ret" \n\t"
#endif
/* HAVE_FAST_CMOV */
#endif
/* HAVE_FAST_CMOV */
#define BRANCHLESS_GET_CABAC(ret, statep, low, lowword, range, tmp, tmpbyte, byte) \
#define BRANCHLESS_GET_CABAC(ret, statep, low, lowword, range, tmp, tmpbyte, byte
, end
) \
"movzbl "statep" , "ret" \n\t"\
"movzbl "statep" , "ret" \n\t"\
"mov "range" , "tmp" \n\t"\
"mov "range" , "tmp" \n\t"\
"and $0xC0 , "range" \n\t"\
"and $0xC0 , "range" \n\t"\
...
@@ -64,9 +64,12 @@
...
@@ -64,9 +64,12 @@
"shl %%cl , "low" \n\t"\
"shl %%cl , "low" \n\t"\
"mov "tmpbyte" , "statep" \n\t"\
"mov "tmpbyte" , "statep" \n\t"\
"test "lowword" , "lowword" \n\t"\
"test "lowword" , "lowword" \n\t"\
" jnz
1
f \n\t"\
" jnz
2
f \n\t"\
"mov "byte" , %%"REG_c" \n\t"\
"mov "byte" , %%"REG_c" \n\t"\
"cmp "end" , %%"REG_c" \n\t"\
"jge 1f \n\t"\
"add"OPSIZE" $2 , "byte" \n\t"\
"add"OPSIZE" $2 , "byte" \n\t"\
"1: \n\t"\
"movzwl (%%"REG_c") , "tmp" \n\t"\
"movzwl (%%"REG_c") , "tmp" \n\t"\
"lea -1("low") , %%ecx \n\t"\
"lea -1("low") , %%ecx \n\t"\
"xor "low" , %%ecx \n\t"\
"xor "low" , %%ecx \n\t"\
...
@@ -79,7 +82,7 @@
...
@@ -79,7 +82,7 @@
"add $7 , %%ecx \n\t"\
"add $7 , %%ecx \n\t"\
"shl %%cl , "tmp" \n\t"\
"shl %%cl , "tmp" \n\t"\
"add "tmp" , "low" \n\t"\
"add "tmp" , "low" \n\t"\
"
1
: \n\t"
"
2
: \n\t"
#if HAVE_7REGS && !defined(BROKEN_RELOCATIONS)
#if HAVE_7REGS && !defined(BROKEN_RELOCATIONS)
#define get_cabac_inline get_cabac_inline_x86
#define get_cabac_inline get_cabac_inline_x86
...
@@ -90,10 +93,12 @@ static av_always_inline int get_cabac_inline_x86(CABACContext *c,
...
@@ -90,10 +93,12 @@ static av_always_inline int get_cabac_inline_x86(CABACContext *c,
__asm__
volatile
(
__asm__
volatile
(
BRANCHLESS_GET_CABAC
(
"%0"
,
"(%4)"
,
"%1"
,
"%w1"
,
BRANCHLESS_GET_CABAC
(
"%0"
,
"(%4)"
,
"%1"
,
"%w1"
,
"%2"
,
"%3"
,
"%b3"
,
"%a6(%5)"
)
"%2"
,
"%3"
,
"%b3"
,
"%a6(%5)"
,
"%a7(%5)"
)
:
"=&r"
(
bit
),
"+&r"
(
c
->
low
),
"+&r"
(
c
->
range
),
"=&q"
(
tmp
)
:
"=&r"
(
bit
),
"+&r"
(
c
->
low
),
"+&r"
(
c
->
range
),
"=&q"
(
tmp
)
:
"r"
(
state
),
"r"
(
c
),
:
"r"
(
state
),
"r"
(
c
),
"i"
(
offsetof
(
CABACContext
,
bytestream
))
"i"
(
offsetof
(
CABACContext
,
bytestream
)),
"i"
(
offsetof
(
CABACContext
,
bytestream_end
))
:
"%"
REG_c
,
"memory"
:
"%"
REG_c
,
"memory"
);
);
return
bit
&
1
;
return
bit
&
1
;
...
...
libavcodec/x86/h264_i386.h
View file @
a9401981
...
@@ -49,14 +49,16 @@ static int decode_significance_x86(CABACContext *c, int max_coeff,
...
@@ -49,14 +49,16 @@ static int decode_significance_x86(CABACContext *c, int max_coeff,
"3:
\n\t
"
"3:
\n\t
"
BRANCHLESS_GET_CABAC
(
"%4"
,
"(%1)"
,
"%3"
,
"%w3"
,
BRANCHLESS_GET_CABAC
(
"%4"
,
"(%1)"
,
"%3"
,
"%w3"
,
"%5"
,
"%k0"
,
"%b0"
,
"%a11(%6)"
)
"%5"
,
"%k0"
,
"%b0"
,
"%a11(%6)"
,
"%a12(%6)"
)
"test $1, %4
\n\t
"
"test $1, %4
\n\t
"
" jz 4f
\n\t
"
" jz 4f
\n\t
"
"add %10, %1
\n\t
"
"add %10, %1
\n\t
"
BRANCHLESS_GET_CABAC
(
"%4"
,
"(%1)"
,
"%3"
,
"%w3"
,
BRANCHLESS_GET_CABAC
(
"%4"
,
"(%1)"
,
"%3"
,
"%w3"
,
"%5"
,
"%k0"
,
"%b0"
,
"%a11(%6)"
)
"%5"
,
"%k0"
,
"%b0"
,
"%a11(%6)"
,
"%a12(%6)"
)
"sub %10, %1
\n\t
"
"sub %10, %1
\n\t
"
"mov %2, %0
\n\t
"
"mov %2, %0
\n\t
"
...
@@ -83,7 +85,8 @@ static int decode_significance_x86(CABACContext *c, int max_coeff,
...
@@ -83,7 +85,8 @@ static int decode_significance_x86(CABACContext *c, int max_coeff,
:
"=&q"
(
coeff_count
),
"+r"
(
significant_coeff_ctx_base
),
"+m"
(
index
),
:
"=&q"
(
coeff_count
),
"+r"
(
significant_coeff_ctx_base
),
"+m"
(
index
),
"+&r"
(
c
->
low
),
"=&r"
(
bit
),
"+&r"
(
c
->
range
)
"+&r"
(
c
->
low
),
"=&r"
(
bit
),
"+&r"
(
c
->
range
)
:
"r"
(
c
),
"m"
(
minusstart
),
"m"
(
end
),
"m"
(
minusindex
),
"m"
(
last_off
),
:
"r"
(
c
),
"m"
(
minusstart
),
"m"
(
end
),
"m"
(
minusindex
),
"m"
(
last_off
),
"i"
(
offsetof
(
CABACContext
,
bytestream
))
"i"
(
offsetof
(
CABACContext
,
bytestream
)),
"i"
(
offsetof
(
CABACContext
,
bytestream_end
))
:
"%"
REG_c
,
"memory"
:
"%"
REG_c
,
"memory"
);
);
return
coeff_count
;
return
coeff_count
;
...
@@ -106,7 +109,8 @@ static int decode_significance_8x8_x86(CABACContext *c,
...
@@ -106,7 +109,8 @@ static int decode_significance_8x8_x86(CABACContext *c,
"add %9, %6
\n\t
"
"add %9, %6
\n\t
"
BRANCHLESS_GET_CABAC
(
"%4"
,
"(%6)"
,
"%3"
,
"%w3"
,
BRANCHLESS_GET_CABAC
(
"%4"
,
"(%6)"
,
"%3"
,
"%w3"
,
"%5"
,
"%k0"
,
"%b0"
,
"%a12(%7)"
)
"%5"
,
"%k0"
,
"%b0"
,
"%a12(%7)"
,
"%a13(%7)"
)
"mov %1, %k6
\n\t
"
"mov %1, %k6
\n\t
"
"test $1, %4
\n\t
"
"test $1, %4
\n\t
"
...
@@ -116,7 +120,8 @@ static int decode_significance_8x8_x86(CABACContext *c,
...
@@ -116,7 +120,8 @@ static int decode_significance_8x8_x86(CABACContext *c,
"add %11, %6
\n\t
"
"add %11, %6
\n\t
"
BRANCHLESS_GET_CABAC
(
"%4"
,
"(%6)"
,
"%3"
,
"%w3"
,
BRANCHLESS_GET_CABAC
(
"%4"
,
"(%6)"
,
"%3"
,
"%w3"
,
"%5"
,
"%k0"
,
"%b0"
,
"%a12(%7)"
)
"%5"
,
"%k0"
,
"%b0"
,
"%a12(%7)"
,
"%a13(%7)"
)
"mov %2, %0
\n\t
"
"mov %2, %0
\n\t
"
"mov %1, %k6
\n\t
"
"mov %1, %k6
\n\t
"
...
@@ -141,7 +146,8 @@ static int decode_significance_8x8_x86(CABACContext *c,
...
@@ -141,7 +146,8 @@ static int decode_significance_8x8_x86(CABACContext *c,
"=&r"
(
bit
),
"+&r"
(
c
->
range
),
"=&r"
(
state
)
"=&r"
(
bit
),
"+&r"
(
c
->
range
),
"=&r"
(
state
)
:
"r"
(
c
),
"m"
(
minusindex
),
"m"
(
significant_coeff_ctx_base
),
:
"r"
(
c
),
"m"
(
minusindex
),
"m"
(
significant_coeff_ctx_base
),
"m"
(
sig_off
),
"m"
(
last_coeff_ctx_base
),
"m"
(
sig_off
),
"m"
(
last_coeff_ctx_base
),
"i"
(
offsetof
(
CABACContext
,
bytestream
))
"i"
(
offsetof
(
CABACContext
,
bytestream
)),
"i"
(
offsetof
(
CABACContext
,
bytestream_end
))
:
"%"
REG_c
,
"memory"
:
"%"
REG_c
,
"memory"
);
);
return
coeff_count
;
return
coeff_count
;
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment