]> rtime.felk.cvut.cz Git - frescor/ffmpeg.git/blob - libavformat/asf.c
check fragment offset and size
[frescor/ffmpeg.git] / libavformat / asf.c
1 /*
2  * ASF compatible demuxer
3  * Copyright (c) 2000, 2001 Fabrice Bellard.
4  *
5  * This file is part of FFmpeg.
6  *
7  * FFmpeg is free software; you can redistribute it and/or
8  * modify it under the terms of the GNU Lesser General Public
9  * License as published by the Free Software Foundation; either
10  * version 2.1 of the License, or (at your option) any later version.
11  *
12  * FFmpeg is distributed in the hope that it will be useful,
13  * but WITHOUT ANY WARRANTY; without even the implied warranty of
14  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
15  * Lesser General Public License for more details.
16  *
17  * You should have received a copy of the GNU Lesser General Public
18  * License along with FFmpeg; if not, write to the Free Software
19  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
20  */
21 #include "avformat.h"
22 #include "riff.h"
23 #include "mpegaudio.h"
24 #include "asf.h"
25 #include "common.h"
26
27 #undef NDEBUG
28 #include <assert.h>
29
30 #define FRAME_HEADER_SIZE 17
31 // Fix Me! FRAME_HEADER_SIZE may be different.
32
33 static const GUID index_guid = {
34     0x90, 0x08, 0x00, 0x33, 0xb1, 0xe5, 0xcf, 0x11, 0x89, 0xf4, 0x00, 0xa0, 0xc9, 0x03, 0x49, 0xcb
35 };
36
37 /**********************************/
38 /* decoding */
39
40 //#define DEBUG
41
42 #ifdef DEBUG
43 #define PRINT_IF_GUID(g,cmp) \
44 if (!memcmp(g, &cmp, sizeof(GUID))) \
45     printf("(GUID: %s) ", #cmp)
46
47 static void print_guid(const GUID *g)
48 {
49     int i;
50     PRINT_IF_GUID(g, asf_header);
51     else PRINT_IF_GUID(g, file_header);
52     else PRINT_IF_GUID(g, stream_header);
53     else PRINT_IF_GUID(g, audio_stream);
54     else PRINT_IF_GUID(g, audio_conceal_none);
55     else PRINT_IF_GUID(g, video_stream);
56     else PRINT_IF_GUID(g, video_conceal_none);
57     else PRINT_IF_GUID(g, command_stream);
58     else PRINT_IF_GUID(g, comment_header);
59     else PRINT_IF_GUID(g, codec_comment_header);
60     else PRINT_IF_GUID(g, codec_comment1_header);
61     else PRINT_IF_GUID(g, data_header);
62     else PRINT_IF_GUID(g, index_guid);
63     else PRINT_IF_GUID(g, head1_guid);
64     else PRINT_IF_GUID(g, head2_guid);
65     else PRINT_IF_GUID(g, my_guid);
66     else PRINT_IF_GUID(g, ext_stream_header);
67     else PRINT_IF_GUID(g, extended_content_header);
68     else PRINT_IF_GUID(g, ext_stream_embed_stream_header);
69     else PRINT_IF_GUID(g, ext_stream_audio_stream);
70     else
71         printf("(GUID: unknown) ");
72     for(i=0;i<16;i++)
73         printf(" 0x%02x,", (*g)[i]);
74     printf("}\n");
75 }
76 #undef PRINT_IF_GUID
77 #endif
78
79 static void get_guid(ByteIOContext *s, GUID *g)
80 {
81     assert(sizeof(*g) == 16);
82     get_buffer(s, g, sizeof(*g));
83 }
84
85 #if 0
86 static void get_str16(ByteIOContext *pb, char *buf, int buf_size)
87 {
88     int len, c;
89     char *q;
90
91     len = get_le16(pb);
92     q = buf;
93     while (len > 0) {
94         c = get_le16(pb);
95         if ((q - buf) < buf_size - 1)
96             *q++ = c;
97         len--;
98     }
99     *q = '\0';
100 }
101 #endif
102
103 static void get_str16_nolen(ByteIOContext *pb, int len, char *buf, int buf_size)
104 {
105     char* q = buf;
106     len /= 2;
107     while (len--) {
108         uint8_t tmp;
109         PUT_UTF8(get_le16(pb), tmp, if (q - buf < buf_size - 1) *q++ = tmp;)
110     }
111     *q = '\0';
112 }
113
114 static int asf_probe(AVProbeData *pd)
115 {
116     /* check file header */
117     if (pd->buf_size <= 32)
118         return 0;
119
120     if (!memcmp(pd->buf, &asf_header, sizeof(GUID)))
121         return AVPROBE_SCORE_MAX;
122     else
123         return 0;
124 }
125
126 static int asf_read_header(AVFormatContext *s, AVFormatParameters *ap)
127 {
128     ASFContext *asf = s->priv_data;
129     GUID g;
130     ByteIOContext *pb = &s->pb;
131     AVStream *st;
132     ASFStream *asf_st;
133     int size, i;
134     int64_t gsize;
135
136     get_guid(pb, &g);
137     if (memcmp(&g, &asf_header, sizeof(GUID)))
138         goto fail;
139     get_le64(pb);
140     get_le32(pb);
141     get_byte(pb);
142     get_byte(pb);
143     memset(&asf->asfid2avid, -1, sizeof(asf->asfid2avid));
144     for(;;) {
145         get_guid(pb, &g);
146         gsize = get_le64(pb);
147 #ifdef DEBUG
148         printf("%08"PRIx64": ", url_ftell(pb) - 24);
149         print_guid(&g);
150         printf("  size=0x%"PRIx64"\n", gsize);
151 #endif
152         if (gsize < 24)
153             goto fail;
154         if (!memcmp(&g, &file_header, sizeof(GUID))) {
155             get_guid(pb, &asf->hdr.guid);
156             asf->hdr.file_size          = get_le64(pb);
157             asf->hdr.create_time        = get_le64(pb);
158             asf->nb_packets             = get_le64(pb);
159             asf->hdr.send_time          = get_le64(pb);
160             asf->hdr.play_time          = get_le64(pb);
161             asf->hdr.preroll            = get_le32(pb);
162             asf->hdr.ignore             = get_le32(pb);
163             asf->hdr.flags              = get_le32(pb);
164             asf->hdr.min_pktsize        = get_le32(pb);
165             asf->hdr.max_pktsize        = get_le32(pb);
166             asf->hdr.max_bitrate        = get_le32(pb);
167             asf->packet_size = asf->hdr.max_pktsize;
168         } else if (!memcmp(&g, &stream_header, sizeof(GUID))) {
169             int type, type_specific_size, sizeX;
170             uint64_t total_size;
171             unsigned int tag1;
172             int64_t pos1, pos2;
173             int test_for_ext_stream_audio;
174
175             pos1 = url_ftell(pb);
176
177             st = av_new_stream(s, 0);
178             if (!st)
179                 goto fail;
180             av_set_pts_info(st, 32, 1, 1000); /* 32 bit pts in ms */
181             asf_st = av_mallocz(sizeof(ASFStream));
182             if (!asf_st)
183                 goto fail;
184             st->priv_data = asf_st;
185             st->start_time = asf->hdr.preroll;
186             if(!(asf->hdr.flags & 0x01)) { // if we aren't streaming...
187                 st->duration = asf->hdr.send_time /
188                     (10000000 / 1000) - st->start_time;
189             }
190             get_guid(pb, &g);
191
192             test_for_ext_stream_audio = 0;
193             if (!memcmp(&g, &audio_stream, sizeof(GUID))) {
194                 type = CODEC_TYPE_AUDIO;
195             } else if (!memcmp(&g, &video_stream, sizeof(GUID))) {
196                 type = CODEC_TYPE_VIDEO;
197             } else if (!memcmp(&g, &command_stream, sizeof(GUID))) {
198                 type = CODEC_TYPE_UNKNOWN;
199             } else if (!memcmp(&g, &ext_stream_embed_stream_header, sizeof(GUID))) {
200                 test_for_ext_stream_audio = 1;
201                 type = CODEC_TYPE_UNKNOWN;
202             } else {
203                 goto fail;
204             }
205             get_guid(pb, &g);
206             total_size = get_le64(pb);
207             type_specific_size = get_le32(pb);
208             get_le32(pb);
209             st->id = get_le16(pb) & 0x7f; /* stream id */
210             // mapping of asf ID to AV stream ID;
211             asf->asfid2avid[st->id] = s->nb_streams - 1;
212
213             get_le32(pb);
214
215             if (test_for_ext_stream_audio) {
216                 get_guid(pb, &g);
217                 if (!memcmp(&g, &ext_stream_audio_stream, sizeof(GUID))) {
218                     type = CODEC_TYPE_AUDIO;
219                     get_guid(pb, &g);
220                     get_le32(pb);
221                     get_le32(pb);
222                     get_le32(pb);
223                     get_guid(pb, &g);
224                     get_le32(pb);
225                 }
226             }
227
228             st->codec->codec_type = type;
229             if (type == CODEC_TYPE_AUDIO) {
230                 get_wav_header(pb, st->codec, type_specific_size);
231                 st->need_parsing = 1;
232                 /* We have to init the frame size at some point .... */
233                 pos2 = url_ftell(pb);
234                 if (gsize > (pos2 + 8 - pos1 + 24)) {
235                     asf_st->ds_span = get_byte(pb);
236                     asf_st->ds_packet_size = get_le16(pb);
237                     asf_st->ds_chunk_size = get_le16(pb);
238                     get_le16(pb); //ds_data_size
239                     get_byte(pb); //ds_silence_data
240                 }
241                 //printf("Descrambling: ps:%d cs:%d ds:%d s:%d  sd:%d\n",
242                 //       asf_st->ds_packet_size, asf_st->ds_chunk_size,
243                 //       asf_st->ds_data_size, asf_st->ds_span, asf_st->ds_silence_data);
244                 if (asf_st->ds_span > 1) {
245                     if (!asf_st->ds_chunk_size
246                         || (asf_st->ds_packet_size/asf_st->ds_chunk_size <= 1)
247                         || asf_st->ds_packet_size % asf_st->ds_chunk_size)
248                         asf_st->ds_span = 0; // disable descrambling
249                 }
250                 switch (st->codec->codec_id) {
251                 case CODEC_ID_MP3:
252                     st->codec->frame_size = MPA_FRAME_SIZE;
253                     break;
254                 case CODEC_ID_PCM_S16LE:
255                 case CODEC_ID_PCM_S16BE:
256                 case CODEC_ID_PCM_U16LE:
257                 case CODEC_ID_PCM_U16BE:
258                 case CODEC_ID_PCM_S8:
259                 case CODEC_ID_PCM_U8:
260                 case CODEC_ID_PCM_ALAW:
261                 case CODEC_ID_PCM_MULAW:
262                     st->codec->frame_size = 1;
263                     break;
264                 default:
265                     /* This is probably wrong, but it prevents a crash later */
266                     st->codec->frame_size = 1;
267                     break;
268                 }
269             } else if (type == CODEC_TYPE_VIDEO) {
270                 get_le32(pb);
271                 get_le32(pb);
272                 get_byte(pb);
273                 size = get_le16(pb); /* size */
274                 sizeX= get_le32(pb); /* size */
275                 st->codec->width = get_le32(pb);
276                 st->codec->height = get_le32(pb);
277                 /* not available for asf */
278                 get_le16(pb); /* panes */
279                 st->codec->bits_per_sample = get_le16(pb); /* depth */
280                 tag1 = get_le32(pb);
281                 url_fskip(pb, 20);
282 //                av_log(NULL, AV_LOG_DEBUG, "size:%d tsize:%d sizeX:%d\n", size, total_size, sizeX);
283                 size= sizeX;
284                 if (size > 40) {
285                     st->codec->extradata_size = size - 40;
286                     st->codec->extradata = av_mallocz(st->codec->extradata_size + FF_INPUT_BUFFER_PADDING_SIZE);
287                     get_buffer(pb, st->codec->extradata, st->codec->extradata_size);
288                 }
289
290         /* Extract palette from extradata if bpp <= 8 */
291         /* This code assumes that extradata contains only palette */
292         /* This is true for all paletted codecs implemented in ffmpeg */
293         if (st->codec->extradata_size && (st->codec->bits_per_sample <= 8)) {
294             st->codec->palctrl = av_mallocz(sizeof(AVPaletteControl));
295 #ifdef WORDS_BIGENDIAN
296             for (i = 0; i < FFMIN(st->codec->extradata_size, AVPALETTE_SIZE)/4; i++)
297                 st->codec->palctrl->palette[i] = bswap_32(((uint32_t*)st->codec->extradata)[i]);
298 #else
299             memcpy(st->codec->palctrl->palette, st->codec->extradata,
300                    FFMIN(st->codec->extradata_size, AVPALETTE_SIZE));
301 #endif
302             st->codec->palctrl->palette_changed = 1;
303         }
304
305                 st->codec->codec_tag = tag1;
306                 st->codec->codec_id = codec_get_id(codec_bmp_tags, tag1);
307                 if(tag1 == MKTAG('D', 'V', 'R', ' '))
308                     st->need_parsing = 1;
309             }
310             pos2 = url_ftell(pb);
311             url_fskip(pb, gsize - (pos2 - pos1 + 24));
312         } else if (!memcmp(&g, &data_header, sizeof(GUID))) {
313             asf->data_object_offset = url_ftell(pb);
314             // if not streaming, gsize is not unlimited (how?), and there is enough space in the file..
315             if (!(asf->hdr.flags & 0x01) && gsize != (uint64_t)-1 && gsize >= 24) {
316                 asf->data_object_size = gsize - 24;
317             } else {
318                 asf->data_object_size = (uint64_t)-1;
319             }
320             break;
321         } else if (!memcmp(&g, &comment_header, sizeof(GUID))) {
322             int len1, len2, len3, len4, len5;
323
324             len1 = get_le16(pb);
325             len2 = get_le16(pb);
326             len3 = get_le16(pb);
327             len4 = get_le16(pb);
328             len5 = get_le16(pb);
329             get_str16_nolen(pb, len1, s->title    , sizeof(s->title));
330             get_str16_nolen(pb, len2, s->author   , sizeof(s->author));
331             get_str16_nolen(pb, len3, s->copyright, sizeof(s->copyright));
332             get_str16_nolen(pb, len4, s->comment  , sizeof(s->comment));
333             url_fskip(pb, len5);
334        } else if (!memcmp(&g, &extended_content_header, sizeof(GUID))) {
335                 int desc_count, i;
336
337                 desc_count = get_le16(pb);
338                 for(i=0;i<desc_count;i++)
339                 {
340                         int name_len,value_type,value_len;
341                         uint64_t value_num = 0;
342                         char name[1024];
343
344                         name_len = get_le16(pb);
345                         get_str16_nolen(pb, name_len, name, sizeof(name));
346                         value_type = get_le16(pb);
347                         value_len = get_le16(pb);
348                         if ((value_type == 0) || (value_type == 1)) // unicode or byte
349                         {
350                                 if     (!strcmp(name,"WM/AlbumTitle")) get_str16_nolen(pb, value_len, s->album, sizeof(s->album));
351                                 else if(!strcmp(name,"WM/Genre"     )) get_str16_nolen(pb, value_len, s->genre, sizeof(s->genre));
352                                 else url_fskip(pb, value_len);
353                         }
354                         if ((value_type >= 2) && (value_type <= 5)) // boolean or DWORD or QWORD or WORD
355                         {
356                                 if (value_type==2) value_num = get_le32(pb);
357                                 if (value_type==3) value_num = get_le32(pb);
358                                 if (value_type==4) value_num = get_le64(pb);
359                                 if (value_type==5) value_num = get_le16(pb);
360                                 if (!strcmp(name,"WM/Track"      )) s->track = value_num + 1;
361                                 if (!strcmp(name,"WM/TrackNumber")) s->track = value_num;
362                         }
363                 }
364         } else if (!memcmp(&g, &ext_stream_header, sizeof(GUID))) {
365             int ext_len, payload_ext_ct, stream_ct;
366             uint32_t ext_d;
367             int64_t pos_ex_st;
368             pos_ex_st = url_ftell(pb);
369
370             get_le64(pb);
371             get_le64(pb);
372             get_le32(pb);
373             get_le32(pb);
374             get_le32(pb);
375             get_le32(pb);
376             get_le32(pb);
377             get_le32(pb);
378             get_le32(pb);
379             get_le32(pb);
380             get_le16(pb);
381             get_le16(pb);
382             get_le64(pb);
383             stream_ct = get_le16(pb);
384             payload_ext_ct = get_le16(pb);
385
386             for (i=0; i<stream_ct; i++){
387                 get_le16(pb);
388                 ext_len = get_le16(pb);
389                 url_fseek(pb, ext_len, SEEK_CUR);
390             }
391
392             for (i=0; i<payload_ext_ct; i++){
393                 get_guid(pb, &g);
394                 ext_d=get_le16(pb);
395                 ext_len=get_le32(pb);
396                 url_fseek(pb, ext_len, SEEK_CUR);
397             }
398
399             // there could be a optional stream properties object to follow
400             // if so the next iteration will pick it up
401         } else if (!memcmp(&g, &head1_guid, sizeof(GUID))) {
402             int v1, v2;
403             get_guid(pb, &g);
404             v1 = get_le32(pb);
405             v2 = get_le16(pb);
406 #if 0
407         } else if (!memcmp(&g, &codec_comment_header, sizeof(GUID))) {
408             int len, v1, n, num;
409             char str[256], *q;
410             char tag[16];
411
412             get_guid(pb, &g);
413             print_guid(&g);
414
415             n = get_le32(pb);
416             for(i=0;i<n;i++) {
417                 num = get_le16(pb); /* stream number */
418                 get_str16(pb, str, sizeof(str));
419                 get_str16(pb, str, sizeof(str));
420                 len = get_le16(pb);
421                 q = tag;
422                 while (len > 0) {
423                     v1 = get_byte(pb);
424                     if ((q - tag) < sizeof(tag) - 1)
425                         *q++ = v1;
426                     len--;
427                 }
428                 *q = '\0';
429             }
430 #endif
431         } else if (url_feof(pb)) {
432             goto fail;
433         } else {
434             url_fseek(pb, gsize - 24, SEEK_CUR);
435         }
436     }
437     get_guid(pb, &g);
438     get_le64(pb);
439     get_byte(pb);
440     get_byte(pb);
441     if (url_feof(pb))
442         goto fail;
443     asf->data_offset = url_ftell(pb);
444     asf->packet_size_left = 0;
445
446     return 0;
447
448  fail:
449      for(i=0;i<s->nb_streams;i++) {
450         AVStream *st = s->streams[i];
451         if (st) {
452             av_free(st->priv_data);
453             av_free(st->codec->extradata);
454         }
455         av_free(st);
456     }
457     return -1;
458 }
459
460 #define DO_2BITS(bits, var, defval) \
461     switch (bits & 3) \
462     { \
463     case 3: var = get_le32(pb); rsize += 4; break; \
464     case 2: var = get_le16(pb); rsize += 2; break; \
465     case 1: var = get_byte(pb); rsize++; break; \
466     default: var = defval; break; \
467     }
468
469 static int asf_get_packet(AVFormatContext *s)
470 {
471     ASFContext *asf = s->priv_data;
472     ByteIOContext *pb = &s->pb;
473     uint32_t packet_length, padsize;
474     int rsize = 9;
475     int c;
476
477     c = get_byte(pb);
478     if (c != 0x82) {
479         if (!url_feof(pb))
480             av_log(s, AV_LOG_ERROR, "ff asf bad header %x  at:%"PRId64"\n", c, url_ftell(pb));
481     }
482     if ((c & 0x0f) == 2) { // always true for now
483         if (get_le16(pb) != 0) {
484             if (!url_feof(pb))
485                 av_log(s, AV_LOG_ERROR, "ff asf bad non zero\n");
486             return AVERROR_IO;
487         }
488         rsize+=2;
489 /*    }else{
490         if (!url_feof(pb))
491             printf("ff asf bad header %x  at:%"PRId64"\n", c, url_ftell(pb));
492         return AVERROR_IO;*/
493     }
494
495     asf->packet_flags = get_byte(pb);
496     asf->packet_property = get_byte(pb);
497
498     DO_2BITS(asf->packet_flags >> 5, packet_length, asf->packet_size);
499     DO_2BITS(asf->packet_flags >> 1, padsize, 0); // sequence ignored
500     DO_2BITS(asf->packet_flags >> 3, padsize, 0); // padding length
501
502     //the following checks prevent overflows and infinite loops
503     if(packet_length >= (1U<<29)){
504         av_log(s, AV_LOG_ERROR, "invalid packet_length %d at:%"PRId64"\n", packet_length, url_ftell(pb));
505         return 0; // FIXME this should be -1
506     }
507     if(padsize >= (1U<<29)){
508         av_log(s, AV_LOG_ERROR, "invalid padsize %d at:%"PRId64"\n", padsize, url_ftell(pb));
509         return 0; // FIXME this should be -1
510     }
511
512     asf->packet_timestamp = get_le32(pb);
513     get_le16(pb); /* duration */
514     // rsize has at least 11 bytes which have to be present
515
516     if (asf->packet_flags & 0x01) {
517         asf->packet_segsizetype = get_byte(pb); rsize++;
518         asf->packet_segments = asf->packet_segsizetype & 0x3f;
519     } else {
520         asf->packet_segments = 1;
521         asf->packet_segsizetype = 0x80;
522     }
523     asf->packet_size_left = packet_length - padsize - rsize;
524     if (packet_length < asf->hdr.min_pktsize)
525         padsize += asf->hdr.min_pktsize - packet_length;
526     asf->packet_padsize = padsize;
527 #ifdef DEBUG
528     printf("packet: size=%d padsize=%d  left=%d\n", asf->packet_size, asf->packet_padsize, asf->packet_size_left);
529 #endif
530     return 0;
531 }
532
533 /**
534  *
535  * @return <0 if error
536  */
537 static int asf_read_frame_header(AVFormatContext *s){
538     ASFContext *asf = s->priv_data;
539     ByteIOContext *pb = &s->pb;
540     int rsize = 1;
541     int num = get_byte(pb);
542
543     asf->packet_segments--;
544     asf->packet_key_frame = num >> 7;
545     asf->stream_index = asf->asfid2avid[num & 0x7f];
546     // sequence should be ignored!
547     DO_2BITS(asf->packet_property >> 4, asf->packet_seq, 0);
548     DO_2BITS(asf->packet_property >> 2, asf->packet_frag_offset, 0);
549     DO_2BITS(asf->packet_property, asf->packet_replic_size, 0);
550 //printf("key:%d stream:%d seq:%d offset:%d replic_size:%d\n", asf->packet_key_frame, asf->stream_index, asf->packet_seq, //asf->packet_frag_offset, asf->packet_replic_size);
551     if (asf->packet_replic_size >= 8) {
552         asf->packet_obj_size = get_le32(pb);
553         if(asf->packet_obj_size >= (1<<24) || asf->packet_obj_size <= 0){
554             av_log(s, AV_LOG_ERROR, "packet_obj_size invalid\n");
555             return -1;
556         }
557         asf->packet_frag_timestamp = get_le32(pb); // timestamp
558         url_fskip(pb, asf->packet_replic_size - 8);
559         rsize += asf->packet_replic_size; // FIXME - check validity
560     } else if (asf->packet_replic_size==1){
561         // multipacket - frag_offset is begining timestamp
562         asf->packet_time_start = asf->packet_frag_offset;
563         asf->packet_frag_offset = 0;
564         asf->packet_frag_timestamp = asf->packet_timestamp;
565
566         asf->packet_time_delta = get_byte(pb);
567         rsize++;
568     }else if(asf->packet_replic_size!=0){
569         av_log(s, AV_LOG_ERROR, "unexpected packet_replic_size of %d\n", asf->packet_replic_size);
570         return -1;
571     }
572     if (asf->packet_flags & 0x01) {
573         DO_2BITS(asf->packet_segsizetype >> 6, asf->packet_frag_size, 0); // 0 is illegal
574         //printf("Fragsize %d\n", asf->packet_frag_size);
575     } else {
576         asf->packet_frag_size = asf->packet_size_left - rsize;
577         //printf("Using rest  %d %d %d\n", asf->packet_frag_size, asf->packet_size_left, rsize);
578     }
579     if (asf->packet_replic_size == 1) {
580         asf->packet_multi_size = asf->packet_frag_size;
581         if (asf->packet_multi_size > asf->packet_size_left)
582             return -1;
583     }
584     asf->packet_size_left -= rsize;
585     //printf("___objsize____  %d   %d    rs:%d\n", asf->packet_obj_size, asf->packet_frag_offset, rsize);
586
587     return 0;
588 }
589
590 static int asf_read_packet(AVFormatContext *s, AVPacket *pkt)
591 {
592     ASFContext *asf = s->priv_data;
593     ASFStream *asf_st = 0;
594     ByteIOContext *pb = &s->pb;
595     //static int pc = 0;
596     for (;;) {
597         if (asf->packet_size_left < FRAME_HEADER_SIZE
598             || asf->packet_segments < 1) {
599             //asf->packet_size_left <= asf->packet_padsize) {
600             int ret = asf->packet_size_left + asf->packet_padsize;
601             //printf("PacketLeftSize:%d  Pad:%d Pos:%"PRId64"\n", asf->packet_size_left, asf->packet_padsize, url_ftell(pb));
602             assert(ret>=0);
603             /* fail safe */
604             url_fskip(pb, ret);
605
606             ret= (url_ftell(&s->pb) - s->data_offset) % asf->packet_size;
607             if(asf->hdr.max_pktsize == asf->hdr.min_pktsize && ret){
608                 av_log(s, AV_LOG_ERROR, "packet end missaligned skiping %d\n", ret);
609                 url_fskip(pb, asf->packet_size - ret);
610             }
611
612             asf->packet_pos= url_ftell(&s->pb);
613             if (asf->data_object_size != (uint64_t)-1 &&
614                 (asf->packet_pos - asf->data_object_offset >= asf->data_object_size))
615                 return AVERROR_IO; /* Do not exceed the size of the data object */
616             ret = asf_get_packet(s);
617             //printf("READ ASF PACKET  %d   r:%d   c:%d\n", ret, asf->packet_size_left, pc++);
618             if (ret < 0 || url_feof(pb))
619                 return AVERROR_IO;
620             asf->packet_time_start = 0;
621             continue;
622         }
623         if (asf->packet_time_start == 0) {
624             if(asf_read_frame_header(s) < 0){
625                 asf->packet_segments= 0;
626                 continue;
627             }
628             if (asf->stream_index < 0
629                 || s->streams[asf->stream_index]->discard >= AVDISCARD_ALL
630                 || (!asf->packet_key_frame && s->streams[asf->stream_index]->discard >= AVDISCARD_NONKEY)
631                 ) {
632                 asf->packet_time_start = 0;
633                 /* unhandled packet (should not happen) */
634                 url_fskip(pb, asf->packet_frag_size);
635                 asf->packet_size_left -= asf->packet_frag_size;
636                 if(asf->stream_index < 0)
637                     av_log(s, AV_LOG_ERROR, "ff asf skip %d (unknown stream)\n", asf->packet_frag_size);
638                 continue;
639             }
640             asf->asf_st = s->streams[asf->stream_index]->priv_data;
641         }
642         asf_st = asf->asf_st;
643
644         if ((asf->packet_frag_offset != asf_st->frag_offset
645              || (asf->packet_frag_offset
646                  && asf->packet_seq != asf_st->seq)) // seq should be ignored
647            ) {
648             /* cannot continue current packet: free it */
649             // FIXME better check if packet was already allocated
650             av_log(s, AV_LOG_INFO, "ff asf parser skips: %d - %d     o:%d - %d    %d %d   fl:%d\n",
651                    asf_st->pkt.size,
652                    asf->packet_obj_size,
653                    asf->packet_frag_offset, asf_st->frag_offset,
654                    asf->packet_seq, asf_st->seq, asf->packet_frag_size);
655             if (asf_st->pkt.size)
656                 av_free_packet(&asf_st->pkt);
657             asf_st->frag_offset = 0;
658             if (asf->packet_frag_offset != 0) {
659                 url_fskip(pb, asf->packet_frag_size);
660                 av_log(s, AV_LOG_INFO, "ff asf parser skipping %db\n", asf->packet_frag_size);
661                 asf->packet_size_left -= asf->packet_frag_size;
662                 continue;
663             }
664         }
665         if (asf->packet_replic_size == 1) {
666             // frag_offset is here used as the begining timestamp
667             asf->packet_frag_timestamp = asf->packet_time_start;
668             asf->packet_time_start += asf->packet_time_delta;
669             asf->packet_obj_size = asf->packet_frag_size = get_byte(pb);
670             asf->packet_size_left--;
671             asf->packet_multi_size--;
672             if (asf->packet_multi_size < asf->packet_obj_size)
673             {
674                 asf->packet_time_start = 0;
675                 url_fskip(pb, asf->packet_multi_size);
676                 asf->packet_size_left -= asf->packet_multi_size;
677                 continue;
678             }
679             asf->packet_multi_size -= asf->packet_obj_size;
680             //printf("COMPRESS size  %d  %d  %d   ms:%d\n", asf->packet_obj_size, asf->packet_frag_timestamp, asf->packet_size_left, asf->packet_multi_size);
681         }
682         if (asf_st->frag_offset == 0) {
683             /* new packet */
684             av_new_packet(&asf_st->pkt, asf->packet_obj_size);
685             asf_st->seq = asf->packet_seq;
686             asf_st->pkt.pts = asf->packet_frag_timestamp;
687             asf_st->pkt.stream_index = asf->stream_index;
688             asf_st->pkt.pos =
689             asf_st->packet_pos= asf->packet_pos;
690 //printf("new packet: stream:%d key:%d packet_key:%d audio:%d size:%d\n",
691 //asf->stream_index, asf->packet_key_frame, asf_st->pkt.flags & PKT_FLAG_KEY,
692 //s->streams[asf->stream_index]->codec->codec_type == CODEC_TYPE_AUDIO, asf->packet_obj_size);
693             if (s->streams[asf->stream_index]->codec->codec_type == CODEC_TYPE_AUDIO)
694                 asf->packet_key_frame = 1;
695             if (asf->packet_key_frame)
696                 asf_st->pkt.flags |= PKT_FLAG_KEY;
697         }
698
699         /* read data */
700         //printf("READ PACKET s:%d  os:%d  o:%d,%d  l:%d   DATA:%p\n",
701         //       asf->packet_size, asf_st->pkt.size, asf->packet_frag_offset,
702         //       asf_st->frag_offset, asf->packet_frag_size, asf_st->pkt.data);
703         asf->packet_size_left -= asf->packet_frag_size;
704         if (asf->packet_size_left < 0)
705             continue;
706
707         if(   asf->packet_frag_offset >= asf_st->pkt.size
708            || asf->packet_frag_size > asf_st->pkt.size - asf->packet_frag_offset){
709             av_log(s, AV_LOG_ERROR, "packet fragment position invalid %u,%u not in %u\n",
710                 asf->packet_frag_offset, asf->packet_frag_size, asf_st->pkt.size);
711             continue;
712         }
713
714         get_buffer(pb, asf_st->pkt.data + asf->packet_frag_offset,
715                    asf->packet_frag_size);
716         asf_st->frag_offset += asf->packet_frag_size;
717         /* test if whole packet is read */
718         if (asf_st->frag_offset == asf_st->pkt.size) {
719             /* return packet */
720             if (asf_st->ds_span > 1) {
721               if(asf_st->pkt.size != asf_st->ds_packet_size * asf_st->ds_span){
722                     av_log(s, AV_LOG_ERROR, "pkt.size != ds_packet_size * ds_span\n");
723               }else{
724                 /* packet descrambling */
725                 uint8_t *newdata = av_malloc(asf_st->pkt.size);
726                 if (newdata) {
727                     int offset = 0;
728                     while (offset < asf_st->pkt.size) {
729                         int off = offset / asf_st->ds_chunk_size;
730                         int row = off / asf_st->ds_span;
731                         int col = off % asf_st->ds_span;
732                         int idx = row + col * asf_st->ds_packet_size / asf_st->ds_chunk_size;
733                         //printf("off:%d  row:%d  col:%d  idx:%d\n", off, row, col, idx);
734
735                         assert(offset + asf_st->ds_chunk_size <= asf_st->pkt.size);
736                         assert(idx+1 <= asf_st->pkt.size / asf_st->ds_chunk_size);
737                         memcpy(newdata + offset,
738                                asf_st->pkt.data + idx * asf_st->ds_chunk_size,
739                                asf_st->ds_chunk_size);
740                         offset += asf_st->ds_chunk_size;
741                     }
742                     av_free(asf_st->pkt.data);
743                     asf_st->pkt.data = newdata;
744                 }
745               }
746             }
747             asf_st->frag_offset = 0;
748             *pkt= asf_st->pkt;
749             //printf("packet %d %d\n", asf_st->pkt.size, asf->packet_frag_size);
750             asf_st->pkt.size = 0;
751             asf_st->pkt.data = 0;
752             break; // packet completed
753         }
754     }
755     return 0;
756 }
757
758 static int asf_read_close(AVFormatContext *s)
759 {
760     int i;
761
762     for(i=0;i<s->nb_streams;i++) {
763         AVStream *st = s->streams[i];
764         av_free(st->priv_data);
765     av_free(st->codec->palctrl);
766     }
767     return 0;
768 }
769
770 // Added to support seeking after packets have been read
771 // If information is not reset, read_packet fails due to
772 // leftover information from previous reads
773 static void asf_reset_header(AVFormatContext *s)
774 {
775     ASFContext *asf = s->priv_data;
776     ASFStream *asf_st;
777     int i;
778
779     asf->packet_nb_frames = 0;
780     asf->packet_size_left = 0;
781     asf->packet_segments = 0;
782     asf->packet_flags = 0;
783     asf->packet_property = 0;
784     asf->packet_timestamp = 0;
785     asf->packet_segsizetype = 0;
786     asf->packet_segments = 0;
787     asf->packet_seq = 0;
788     asf->packet_replic_size = 0;
789     asf->packet_key_frame = 0;
790     asf->packet_padsize = 0;
791     asf->packet_frag_offset = 0;
792     asf->packet_frag_size = 0;
793     asf->packet_frag_timestamp = 0;
794     asf->packet_multi_size = 0;
795     asf->packet_obj_size = 0;
796     asf->packet_time_delta = 0;
797     asf->packet_time_start = 0;
798
799     for(i=0; i<s->nb_streams; i++){
800         asf_st= s->streams[i]->priv_data;
801         av_free_packet(&asf_st->pkt);
802         asf_st->frag_offset=0;
803         asf_st->seq=0;
804     }
805     asf->asf_st= NULL;
806 }
807
808 static int64_t asf_read_pts(AVFormatContext *s, int stream_index, int64_t *ppos, int64_t pos_limit)
809 {
810     ASFContext *asf = s->priv_data;
811     AVPacket pkt1, *pkt = &pkt1;
812     ASFStream *asf_st;
813     int64_t pts;
814     int64_t pos= *ppos;
815     int i;
816     int64_t start_pos[s->nb_streams];
817
818     for(i=0; i<s->nb_streams; i++){
819         start_pos[i]= pos;
820     }
821
822     pos= (pos+asf->packet_size-1-s->data_offset)/asf->packet_size*asf->packet_size+ s->data_offset;
823     *ppos= pos;
824     url_fseek(&s->pb, pos, SEEK_SET);
825
826 //printf("asf_read_pts\n");
827     asf_reset_header(s);
828     for(;;){
829         if (av_read_frame(s, pkt) < 0){
830             av_log(s, AV_LOG_INFO, "seek failed\n");
831             return AV_NOPTS_VALUE;
832         }
833
834         pts= pkt->pts;
835
836         av_free_packet(pkt);
837         if(pkt->flags&PKT_FLAG_KEY){
838             i= pkt->stream_index;
839
840             asf_st= s->streams[i]->priv_data;
841
842             assert((asf_st->packet_pos - s->data_offset) % asf->packet_size == 0);
843             pos= asf_st->packet_pos;
844
845             av_add_index_entry(s->streams[i], pos, pts, pkt->size, pos - start_pos[i] + 1, AVINDEX_KEYFRAME);
846             start_pos[i]= asf_st->packet_pos + 1;
847
848             if(pkt->stream_index == stream_index)
849                break;
850         }
851     }
852
853     *ppos= pos;
854 //printf("found keyframe at %"PRId64" stream %d stamp:%"PRId64"\n", *ppos, stream_index, pts);
855
856     return pts;
857 }
858
859 static void asf_build_simple_index(AVFormatContext *s, int stream_index)
860 {
861     GUID g;
862     ASFContext *asf = s->priv_data;
863     int64_t gsize, itime;
864     int64_t pos, current_pos, index_pts;
865     int i;
866     int pct,ict;
867
868     current_pos = url_ftell(&s->pb);
869
870     url_fseek(&s->pb, asf->data_object_offset + asf->data_object_size, SEEK_SET);
871     get_guid(&s->pb, &g);
872     if (!memcmp(&g, &index_guid, sizeof(GUID))) {
873         gsize = get_le64(&s->pb);
874         get_guid(&s->pb, &g);
875         itime=get_le64(&s->pb);
876         pct=get_le32(&s->pb);
877         ict=get_le32(&s->pb);
878         av_log(NULL, AV_LOG_DEBUG, "itime:0x%"PRIx64", pct:%d, ict:%d\n",itime,pct,ict);
879
880         for (i=0;i<ict;i++){
881             int pktnum=get_le32(&s->pb);
882             int pktct =get_le16(&s->pb);
883             av_log(NULL, AV_LOG_DEBUG, "pktnum:%d, pktct:%d\n", pktnum, pktct);
884
885             pos=s->data_offset + asf->packet_size*(int64_t)pktnum;
886             index_pts=av_rescale(itime, i, 10000);
887
888             av_add_index_entry(s->streams[stream_index], pos, index_pts, asf->packet_size, 0, AVINDEX_KEYFRAME);
889         }
890         asf->index_read= 1;
891     }
892     url_fseek(&s->pb, current_pos, SEEK_SET);
893 }
894
895 static int asf_read_seek(AVFormatContext *s, int stream_index, int64_t pts, int flags)
896 {
897     ASFContext *asf = s->priv_data;
898     AVStream *st = s->streams[stream_index];
899     int64_t pos;
900     int index;
901
902     if (asf->packet_size <= 0)
903         return -1;
904
905     if (!asf->index_read)
906         asf_build_simple_index(s, stream_index);
907
908     if(!(asf->index_read && st->index_entries)){
909         if(av_seek_frame_binary(s, stream_index, pts, flags)<0)
910             return -1;
911     }else{
912         index= av_index_search_timestamp(st, pts, flags);
913         if(index<0)
914             return -1;
915
916         /* find the position */
917         pos = st->index_entries[index].pos;
918         pts = st->index_entries[index].timestamp;
919
920     // various attempts to find key frame have failed so far
921     //    asf_reset_header(s);
922     //    url_fseek(&s->pb, pos, SEEK_SET);
923     //    key_pos = pos;
924     //     for(i=0;i<16;i++){
925     //         pos = url_ftell(&s->pb);
926     //         if (av_read_frame(s, &pkt) < 0){
927     //             av_log(s, AV_LOG_INFO, "seek failed\n");
928     //             return -1;
929     //         }
930     //         asf_st = s->streams[stream_index]->priv_data;
931     //         pos += st->parser->frame_offset;
932     //
933     //         if (pkt.size > b) {
934     //             b = pkt.size;
935     //             key_pos = pos;
936     //         }
937     //
938     //         av_free_packet(&pkt);
939     //     }
940
941         /* do the seek */
942         av_log(NULL, AV_LOG_DEBUG, "SEEKTO: %"PRId64"\n", pos);
943         url_fseek(&s->pb, pos, SEEK_SET);
944     }
945     asf_reset_header(s);
946     return 0;
947 }
948
949 AVInputFormat asf_demuxer = {
950     "asf",
951     "asf format",
952     sizeof(ASFContext),
953     asf_probe,
954     asf_read_header,
955     asf_read_packet,
956     asf_read_close,
957     asf_read_seek,
958     asf_read_pts,
959 };