mms.c 6.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153
  1. /*
  2. * MMS protocol common definitions.
  3. * Copyright (c) 2006,2007 Ryan Martell
  4. * Copyright (c) 2007 Björn Axelsson
  5. * Copyright (c) 2010 Zhentan Feng <spyfeng at gmail dot com>
  6. *
  7. * This file is part of FFmpeg.
  8. *
  9. * FFmpeg is free software; you can redistribute it and/or
  10. * modify it under the terms of the GNU Lesser General Public
  11. * License as published by the Free Software Foundation; either
  12. * version 2.1 of the License, or (at your option) any later version.
  13. *
  14. * FFmpeg is distributed in the hope that it will be useful,
  15. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  16. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  17. * Lesser General Public License for more details.
  18. *
  19. * You should have received a copy of the GNU Lesser General Public
  20. * License along with FFmpeg; if not, write to the Free Software
  21. * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
  22. */
  23. #include "mms.h"
  24. #include "asf.h"
  25. #include "libavutil/intreadwrite.h"
  26. #if FF_API_MAX_STREAMS
  27. #define MMS_MAX_STREAMS MAX_STREAMS
  28. #else
  29. #define MMS_MAX_STREAMS 256 /**< arbitrary sanity check value */
  30. #endif
  31. int ff_mms_read_header(MMSContext *mms, uint8_t *buf, const int size)
  32. {
  33. char *pos;
  34. int size_to_copy;
  35. int remaining_size = mms->asf_header_size - mms->asf_header_read_size;
  36. size_to_copy = FFMIN(size, remaining_size);
  37. pos = mms->asf_header + mms->asf_header_read_size;
  38. memcpy(buf, pos, size_to_copy);
  39. if (mms->asf_header_read_size == mms->asf_header_size) {
  40. av_freep(&mms->asf_header); // which contains asf header
  41. }
  42. mms->asf_header_read_size += size_to_copy;
  43. return size_to_copy;
  44. }
  45. int ff_mms_read_data(MMSContext *mms, uint8_t *buf, const int size)
  46. {
  47. int read_size;
  48. read_size = FFMIN(size, mms->remaining_in_len);
  49. memcpy(buf, mms->read_in_ptr, read_size);
  50. mms->remaining_in_len -= read_size;
  51. mms->read_in_ptr += read_size;
  52. return read_size;
  53. }
  54. int ff_mms_asf_header_parser(MMSContext *mms)
  55. {
  56. uint8_t *p = mms->asf_header;
  57. uint8_t *end;
  58. int flags, stream_id;
  59. mms->stream_num = 0;
  60. if (mms->asf_header_size < sizeof(ff_asf_guid) * 2 + 22 ||
  61. memcmp(p, ff_asf_header, sizeof(ff_asf_guid))) {
  62. av_log(NULL, AV_LOG_ERROR,
  63. "Corrupt stream (invalid ASF header, size=%d)\n",
  64. mms->asf_header_size);
  65. return AVERROR_INVALIDDATA;
  66. }
  67. end = mms->asf_header + mms->asf_header_size;
  68. p += sizeof(ff_asf_guid) + 14;
  69. while(end - p >= sizeof(ff_asf_guid) + 8) {
  70. uint64_t chunksize;
  71. if (!memcmp(p, ff_asf_data_header, sizeof(ff_asf_guid))) {
  72. chunksize = 50; // see Reference [2] section 5.1
  73. } else {
  74. chunksize = AV_RL64(p + sizeof(ff_asf_guid));
  75. }
  76. if (!chunksize || chunksize > end - p) {
  77. av_log(NULL, AV_LOG_ERROR,
  78. "Corrupt stream (header chunksize %"PRId64" is invalid)\n",
  79. chunksize);
  80. return AVERROR_INVALIDDATA;
  81. }
  82. if (!memcmp(p, ff_asf_file_header, sizeof(ff_asf_guid))) {
  83. /* read packet size */
  84. if (end - p > sizeof(ff_asf_guid) * 2 + 68) {
  85. mms->asf_packet_len = AV_RL32(p + sizeof(ff_asf_guid) * 2 + 64);
  86. if (mms->asf_packet_len <= 0 || mms->asf_packet_len > sizeof(mms->in_buffer)) {
  87. av_log(NULL, AV_LOG_ERROR,
  88. "Corrupt stream (too large pkt_len %d)\n",
  89. mms->asf_packet_len);
  90. return AVERROR_INVALIDDATA;
  91. }
  92. }
  93. } else if (!memcmp(p, ff_asf_stream_header, sizeof(ff_asf_guid))) {
  94. flags = AV_RL16(p + sizeof(ff_asf_guid)*3 + 24);
  95. stream_id = flags & 0x7F;
  96. //The second condition is for checking CS_PKT_STREAM_ID_REQUEST packet size,
  97. //we can calcuate the packet size by stream_num.
  98. //Please see function send_stream_selection_request().
  99. if (mms->stream_num < MMS_MAX_STREAMS &&
  100. 46 + mms->stream_num * 6 < sizeof(mms->out_buffer)) {
  101. mms->streams = av_fast_realloc(mms->streams,
  102. &mms->nb_streams_allocated,
  103. (mms->stream_num + 1) * sizeof(MMSStream));
  104. mms->streams[mms->stream_num].id = stream_id;
  105. mms->stream_num++;
  106. } else {
  107. av_log(NULL, AV_LOG_ERROR,
  108. "Corrupt stream (too many A/V streams)\n");
  109. return AVERROR_INVALIDDATA;
  110. }
  111. } else if (!memcmp(p, ff_asf_ext_stream_header, sizeof(ff_asf_guid))) {
  112. if (end - p >= 88) {
  113. int stream_count = AV_RL16(p + 84), ext_len_count = AV_RL16(p + 86);
  114. uint64_t skip_bytes = 88;
  115. while (stream_count--) {
  116. if (end - p < skip_bytes + 4) {
  117. av_log(NULL, AV_LOG_ERROR,
  118. "Corrupt stream (next stream name length is not in the buffer)\n");
  119. return AVERROR_INVALIDDATA;
  120. }
  121. skip_bytes += 4 + AV_RL16(p + skip_bytes + 2);
  122. }
  123. while (ext_len_count--) {
  124. if (end - p < skip_bytes + 22) {
  125. av_log(NULL, AV_LOG_ERROR,
  126. "Corrupt stream (next extension system info length is not in the buffer)\n");
  127. return AVERROR_INVALIDDATA;
  128. }
  129. skip_bytes += 22 + AV_RL32(p + skip_bytes + 18);
  130. }
  131. if (end - p < skip_bytes) {
  132. av_log(NULL, AV_LOG_ERROR,
  133. "Corrupt stream (the last extension system info length is invalid)\n");
  134. return AVERROR_INVALIDDATA;
  135. }
  136. if (chunksize - skip_bytes > 24)
  137. chunksize = skip_bytes;
  138. }
  139. } else if (!memcmp(p, ff_asf_head1_guid, sizeof(ff_asf_guid))) {
  140. chunksize = 46; // see references [2] section 3.4. This should be set 46.
  141. }
  142. p += chunksize;
  143. }
  144. return 0;
  145. }