mov.c 175.4 KB
Newer Older
1
/*
2
 * MOV demuxer
3
 * Copyright (c) 2001 Fabrice Bellard
4
 * Copyright (c) 2009 Baptiste Coudurier <baptiste dot coudurier at gmail dot com>
5
 *
6 7 8
 * first version by Francois Revol <revol@free.fr>
 * seek function by Gael Chardon <gael.dev@4now.net>
 *
9 10 11
 * This file is part of FFmpeg.
 *
 * FFmpeg is free software; you can redistribute it and/or
F
Fabrice Bellard 已提交
12 13
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
14
 * version 2.1 of the License, or (at your option) any later version.
15
 *
16
 * FFmpeg is distributed in the hope that it will be useful,
17
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
F
Fabrice Bellard 已提交
18 19
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
20
 *
F
Fabrice Bellard 已提交
21
 * You should have received a copy of the GNU Lesser General Public
22
 * License along with FFmpeg; if not, write to the Free Software
23
 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
24
 */
25

26
#include <inttypes.h>
27
#include <limits.h>
28
#include <stdint.h>
29

30
#include "libavutil/attributes.h"
31
#include "libavutil/channel_layout.h"
R
Ronald S. Bultje 已提交
32
#include "libavutil/internal.h"
33
#include "libavutil/intreadwrite.h"
34
#include "libavutil/intfloat.h"
35
#include "libavutil/mathematics.h"
36
#include "libavutil/time_internal.h"
37
#include "libavutil/avstring.h"
38
#include "libavutil/dict.h"
39
#include "libavutil/display.h"
40
#include "libavutil/opt.h"
41
#include "libavutil/aes.h"
42
#include "libavutil/aes_ctr.h"
43
#include "libavutil/sha.h"
44
#include "libavutil/timecode.h"
45
#include "libavcodec/ac3tab.h"
46
#include "avformat.h"
47
#include "internal.h"
48
#include "avio_internal.h"
49
#include "riff.h"
50
#include "isom.h"
51
#include "libavcodec/get_bits.h"
R
Raivo Hool 已提交
52
#include "id3v1.h"
53
#include "mov_chan.h"
54
#include "replaygain.h"
55

56
#if CONFIG_ZLIB
57 58 59
#include <zlib.h>
#endif

60 61
#include "qtpalette.h"

62 63 64
/* those functions parse an atom */
/* links atom IDs to parse functions */
typedef struct MOVParseTableEntry {
65
    uint32_t type;
66
    int (*parse)(MOVContext *ctx, AVIOContext *pb, MOVAtom atom);
67 68
} MOVParseTableEntry;

69
static int mov_read_default(MOVContext *c, AVIOContext *pb, MOVAtom atom);
70
static int mov_read_mfra(MOVContext *c, AVIOContext *f);
71

72 73
static int mov_metadata_track_or_disc_number(MOVContext *c, AVIOContext *pb,
                                             unsigned len, const char *key)
B
Baptiste Coudurier 已提交
74 75 76
{
    char buf[16];

77
    short current, total = 0;
78
    avio_rb16(pb); // unknown
79
    current = avio_rb16(pb);
80 81
    if (len >= 6)
        total = avio_rb16(pb);
82 83 84 85
    if (!total)
        snprintf(buf, sizeof(buf), "%d", current);
    else
        snprintf(buf, sizeof(buf), "%d/%d", current, total);
86
    c->fc->event_flags |= AVFMT_EVENT_FLAG_METADATA_UPDATED;
87
    av_dict_set(&c->fc->metadata, key, buf, 0);
B
Baptiste Coudurier 已提交
88 89 90 91

    return 0;
}

92 93
static int mov_metadata_int8_bypass_padding(MOVContext *c, AVIOContext *pb,
                                            unsigned len, const char *key)
94
{
95 96 97 98
    /* bypass padding bytes */
    avio_r8(pb);
    avio_r8(pb);
    avio_r8(pb);
99

100
    c->fc->event_flags |= AVFMT_EVENT_FLAG_METADATA_UPDATED;
101
    av_dict_set_int(&c->fc->metadata, key, avio_r8(pb), 0);
102

103
    return 0;
104 105
}

106 107
static int mov_metadata_int8_no_padding(MOVContext *c, AVIOContext *pb,
                                        unsigned len, const char *key)
108
{
109
    c->fc->event_flags |= AVFMT_EVENT_FLAG_METADATA_UPDATED;
110
    av_dict_set_int(&c->fc->metadata, key, avio_r8(pb), 0);
111

112
    return 0;
113 114
}

R
Raivo Hool 已提交
115
static int mov_metadata_gnre(MOVContext *c, AVIOContext *pb,
116 117
                             unsigned len, const char *key)
{
R
Raivo Hool 已提交
118
    short genre;
119

R
Raivo Hool 已提交
120
    avio_r8(pb); // unknown
121

R
Raivo Hool 已提交
122 123 124
    genre = avio_r8(pb);
    if (genre < 1 || genre > ID3v1_GENRE_MAX)
        return 0;
125
    c->fc->event_flags |= AVFMT_EVENT_FLAG_METADATA_UPDATED;
126
    av_dict_set(&c->fc->metadata, key, ff_id3v1_genre_str[genre-1], 0);
R
Raivo Hool 已提交
127 128

    return 0;
129 130
}

131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149
static const uint32_t mac_to_unicode[128] = {
    0x00C4,0x00C5,0x00C7,0x00C9,0x00D1,0x00D6,0x00DC,0x00E1,
    0x00E0,0x00E2,0x00E4,0x00E3,0x00E5,0x00E7,0x00E9,0x00E8,
    0x00EA,0x00EB,0x00ED,0x00EC,0x00EE,0x00EF,0x00F1,0x00F3,
    0x00F2,0x00F4,0x00F6,0x00F5,0x00FA,0x00F9,0x00FB,0x00FC,
    0x2020,0x00B0,0x00A2,0x00A3,0x00A7,0x2022,0x00B6,0x00DF,
    0x00AE,0x00A9,0x2122,0x00B4,0x00A8,0x2260,0x00C6,0x00D8,
    0x221E,0x00B1,0x2264,0x2265,0x00A5,0x00B5,0x2202,0x2211,
    0x220F,0x03C0,0x222B,0x00AA,0x00BA,0x03A9,0x00E6,0x00F8,
    0x00BF,0x00A1,0x00AC,0x221A,0x0192,0x2248,0x2206,0x00AB,
    0x00BB,0x2026,0x00A0,0x00C0,0x00C3,0x00D5,0x0152,0x0153,
    0x2013,0x2014,0x201C,0x201D,0x2018,0x2019,0x00F7,0x25CA,
    0x00FF,0x0178,0x2044,0x20AC,0x2039,0x203A,0xFB01,0xFB02,
    0x2021,0x00B7,0x201A,0x201E,0x2030,0x00C2,0x00CA,0x00C1,
    0x00CB,0x00C8,0x00CD,0x00CE,0x00CF,0x00CC,0x00D3,0x00D4,
    0xF8FF,0x00D2,0x00DA,0x00DB,0x00D9,0x0131,0x02C6,0x02DC,
    0x00AF,0x02D8,0x02D9,0x02DA,0x00B8,0x02DD,0x02DB,0x02C7,
};

150
static int mov_read_mac_string(MOVContext *c, AVIOContext *pb, int len,
151 152 153 154 155 156 157
                               char *dst, int dstlen)
{
    char *p = dst;
    char *end = dst+dstlen-1;
    int i;

    for (i = 0; i < len; i++) {
158
        uint8_t t, c = avio_r8(pb);
159 160
        if (c < 0x80 && p < end)
            *p++ = c;
161
        else if (p < end)
162 163 164 165 166 167
            PUT_UTF8(mac_to_unicode[c-0x80], t, if (p < end) *p++ = t;);
    }
    *p = 0;
    return p - dst;
}

A
Anton Khirnov 已提交
168 169 170 171 172
static int mov_read_covr(MOVContext *c, AVIOContext *pb, int type, int len)
{
    AVPacket pkt;
    AVStream *st;
    MOVStreamContext *sc;
173
    enum AVCodecID id;
A
Anton Khirnov 已提交
174 175 176
    int ret;

    switch (type) {
177 178 179
    case 0xd:  id = AV_CODEC_ID_MJPEG; break;
    case 0xe:  id = AV_CODEC_ID_PNG;   break;
    case 0x1b: id = AV_CODEC_ID_BMP;   break;
A
Anton Khirnov 已提交
180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197
    default:
        av_log(c->fc, AV_LOG_WARNING, "Unknown cover type: 0x%x.\n", type);
        avio_skip(pb, len);
        return 0;
    }

    st = avformat_new_stream(c->fc, NULL);
    if (!st)
        return AVERROR(ENOMEM);
    sc = av_mallocz(sizeof(*sc));
    if (!sc)
        return AVERROR(ENOMEM);
    st->priv_data = sc;

    ret = av_get_packet(pb, &pkt, len);
    if (ret < 0)
        return ret;

W
wm4 已提交
198 199 200 201 202 203 204 205
    if (pkt.size >= 8 && id != AV_CODEC_ID_BMP) {
        if (AV_RB64(pkt.data) == 0x89504e470d0a1a0a) {
            id = AV_CODEC_ID_PNG;
        } else {
            id = AV_CODEC_ID_MJPEG;
        }
    }

A
Anton Khirnov 已提交
206 207 208 209 210 211 212 213 214 215 216 217
    st->disposition              |= AV_DISPOSITION_ATTACHED_PIC;

    st->attached_pic              = pkt;
    st->attached_pic.stream_index = st->index;
    st->attached_pic.flags       |= AV_PKT_FLAG_KEY;

    st->codec->codec_type = AVMEDIA_TYPE_VIDEO;
    st->codec->codec_id   = id;

    return 0;
}

218 219 220
static int mov_metadata_loci(MOVContext *c, AVIOContext *pb, unsigned len)
{
    char language[4] = { 0 };
221
    char buf[200], place[100];
222
    uint16_t langcode = 0;
223
    double longitude, latitude, altitude;
224 225
    const char *key = "location";

226 227
    if (len < 4 + 2 + 1 + 1 + 4 + 4 + 4) {
        av_log(c->fc, AV_LOG_ERROR, "loci too short\n");
228
        return AVERROR_INVALIDDATA;
229
    }
230 231 232 233 234 235

    avio_skip(pb, 4); // version+flags
    langcode = avio_rb16(pb);
    ff_mov_lang_to_iso639(langcode, language);
    len -= 6;

236
    len -= avio_get_str(pb, len, place, sizeof(place));
237 238
    if (len < 1) {
        av_log(c->fc, AV_LOG_ERROR, "place name too long\n");
239
        return AVERROR_INVALIDDATA;
240
    }
241 242 243
    avio_skip(pb, 1); // role
    len -= 1;

244
    if (len < 12) {
245
        av_log(c->fc, AV_LOG_ERROR, "no space for coordinates left (%d)\n", len);
246
        return AVERROR_INVALIDDATA;
247
    }
248 249
    longitude = ((int32_t) avio_rb32(pb)) / (float) (1 << 16);
    latitude  = ((int32_t) avio_rb32(pb)) / (float) (1 << 16);
250
    altitude  = ((int32_t) avio_rb32(pb)) / (float) (1 << 16);
251 252

    // Try to output in the same format as the ?xyz field
253 254 255 256 257
    snprintf(buf, sizeof(buf), "%+08.4f%+09.4f",  latitude, longitude);
    if (altitude)
        av_strlcatf(buf, sizeof(buf), "%+f", altitude);
    av_strlcatf(buf, sizeof(buf), "/%s", place);

258 259 260 261 262
    if (*language && strcmp(language, "und")) {
        char key2[16];
        snprintf(key2, sizeof(key2), "%s-%s", key, language);
        av_dict_set(&c->fc->metadata, key2, buf, 0);
    }
263
    c->fc->event_flags |= AVFMT_EVENT_FLAG_METADATA_UPDATED;
264 265 266
    return av_dict_set(&c->fc->metadata, key, buf, 0);
}

267
static int mov_read_udta_string(MOVContext *c, AVIOContext *pb, MOVAtom atom)
268 269
{
    char tmp_key[5];
270
    char key2[32], language[4] = {0};
271
    char *str = NULL;
272
    const char *key = NULL;
273
    uint16_t langcode = 0;
274
    uint32_t data_type = 0, str_size, str_size_alloc;
275
    int (*parse)(MOVContext*, AVIOContext*, unsigned, const char*) = NULL;
276
    int raw = 0;
277
    int num = 0;
278 279

    switch (atom.type) {
280 281
    case MKTAG( '@','P','R','M'): key = "premiere_version"; raw = 1; break;
    case MKTAG( '@','P','R','Q'): key = "quicktime_version"; raw = 1; break;
282 283
    case MKTAG( 'X','M','P','_'):
        if (c->export_xmp) { key = "xmp"; raw = 1; } break;
R
Raivo Hool 已提交
284
    case MKTAG( 'a','A','R','T'): key = "album_artist";    break;
285 286 287 288
    case MKTAG( 'a','k','I','D'): key = "account_type";
        parse = mov_metadata_int8_no_padding; break;
    case MKTAG( 'a','p','I','D'): key = "account_id"; break;
    case MKTAG( 'c','a','t','g'): key = "category"; break;
289 290
    case MKTAG( 'c','p','i','l'): key = "compilation";
        parse = mov_metadata_int8_no_padding; break;
291 292
    case MKTAG( 'c','p','r','t'): key = "copyright"; break;
    case MKTAG( 'd','e','s','c'): key = "description"; break;
293 294
    case MKTAG( 'd','i','s','k'): key = "disc";
        parse = mov_metadata_track_or_disc_number; break;
295 296
    case MKTAG( 'e','g','i','d'): key = "episode_uid";
        parse = mov_metadata_int8_no_padding; break;
R
Raivo Hool 已提交
297 298
    case MKTAG( 'g','n','r','e'): key = "genre";
        parse = mov_metadata_gnre; break;
299 300
    case MKTAG( 'h','d','v','d'): key = "hd_video";
        parse = mov_metadata_int8_no_padding; break;
301
    case MKTAG( 'k','e','y','w'): key = "keywords";  break;
302
    case MKTAG( 'l','d','e','s'): key = "synopsis";  break;
303 304
    case MKTAG( 'l','o','c','i'):
        return mov_metadata_loci(c, pb, atom.size);
305 306
    case MKTAG( 'p','c','s','t'): key = "podcast";
        parse = mov_metadata_int8_no_padding; break;
307 308
    case MKTAG( 'p','g','a','p'): key = "gapless_playback";
        parse = mov_metadata_int8_no_padding; break;
309 310 311 312 313 314 315 316 317
    case MKTAG( 'p','u','r','d'): key = "purchase_date"; break;
    case MKTAG( 'r','t','n','g'): key = "rating";
        parse = mov_metadata_int8_no_padding; break;
    case MKTAG( 's','o','a','a'): key = "sort_album_artist"; break;
    case MKTAG( 's','o','a','l'): key = "sort_album";   break;
    case MKTAG( 's','o','a','r'): key = "sort_artist";  break;
    case MKTAG( 's','o','c','o'): key = "sort_composer"; break;
    case MKTAG( 's','o','n','m'): key = "sort_name";    break;
    case MKTAG( 's','o','s','n'): key = "sort_show";    break;
318 319
    case MKTAG( 's','t','i','k'): key = "media_type";
        parse = mov_metadata_int8_no_padding; break;
B
Baptiste Coudurier 已提交
320
    case MKTAG( 't','r','k','n'): key = "track";
321
        parse = mov_metadata_track_or_disc_number; break;
322
    case MKTAG( 't','v','e','n'): key = "episode_id"; break;
323
    case MKTAG( 't','v','e','s'): key = "episode_sort";
324
        parse = mov_metadata_int8_bypass_padding; break;
325 326
    case MKTAG( 't','v','n','n'): key = "network";   break;
    case MKTAG( 't','v','s','h'): key = "show";      break;
327
    case MKTAG( 't','v','s','n'): key = "season_number";
328
        parse = mov_metadata_int8_bypass_padding; break;
329
    case MKTAG(0xa9,'A','R','T'): key = "artist";    break;
330
    case MKTAG(0xa9,'P','R','D'): key = "producer";  break;
331 332
    case MKTAG(0xa9,'a','l','b'): key = "album";     break;
    case MKTAG(0xa9,'a','u','t'): key = "artist";    break;
333
    case MKTAG(0xa9,'c','h','p'): key = "chapter";   break;
334
    case MKTAG(0xa9,'c','m','t'): key = "comment";   break;
335
    case MKTAG(0xa9,'c','o','m'): key = "composer";  break;
336 337
    case MKTAG(0xa9,'c','p','y'): key = "copyright"; break;
    case MKTAG(0xa9,'d','a','y'): key = "date";      break;
338 339 340
    case MKTAG(0xa9,'d','i','r'): key = "director";  break;
    case MKTAG(0xa9,'d','i','s'): key = "disclaimer"; break;
    case MKTAG(0xa9,'e','d','1'): key = "edit_date"; break;
341
    case MKTAG(0xa9,'e','n','c'): key = "encoder";   break;
342
    case MKTAG(0xa9,'f','m','t'): key = "original_format"; break;
343
    case MKTAG(0xa9,'g','e','n'): key = "genre";     break;
344
    case MKTAG(0xa9,'g','r','p'): key = "grouping";  break;
345
    case MKTAG(0xa9,'h','s','t'): key = "host_computer"; break;
346
    case MKTAG(0xa9,'i','n','f'): key = "comment";   break;
347 348 349
    case MKTAG(0xa9,'l','y','r'): key = "lyrics";    break;
    case MKTAG(0xa9,'m','a','k'): key = "make";      break;
    case MKTAG(0xa9,'m','o','d'): key = "model";     break;
350
    case MKTAG(0xa9,'n','a','m'): key = "title";     break;
351 352 353 354 355
    case MKTAG(0xa9,'o','p','e'): key = "original_artist"; break;
    case MKTAG(0xa9,'p','r','d'): key = "producer";  break;
    case MKTAG(0xa9,'p','r','f'): key = "performers"; break;
    case MKTAG(0xa9,'r','e','q'): key = "playback_requirements"; break;
    case MKTAG(0xa9,'s','r','c'): key = "original_source"; break;
356
    case MKTAG(0xa9,'s','t','3'): key = "subtitle";  break;
357 358
    case MKTAG(0xa9,'s','w','r'): key = "encoder";   break;
    case MKTAG(0xa9,'t','o','o'): key = "encoder";   break;
359 360 361
    case MKTAG(0xa9,'t','r','k'): key = "track";     break;
    case MKTAG(0xa9,'u','r','l'): key = "URL";       break;
    case MKTAG(0xa9,'w','r','n'): key = "warning";   break;
362 363
    case MKTAG(0xa9,'w','r','t'): key = "composer";  break;
    case MKTAG(0xa9,'x','y','z'): key = "location";  break;
364
    }
365
retry:
366
    if (c->itunes_metadata && atom.size > 8) {
367 368
        int data_size = avio_rb32(pb);
        int tag = avio_rl32(pb);
369
        if (tag == MKTAG('d','a','t','a') && data_size <= atom.size) {
370 371
            data_type = avio_rb32(pb); // type
            avio_rb32(pb); // unknown
372 373
            str_size = data_size - 16;
            atom.size -= 16;
A
Anton Khirnov 已提交
374 375 376 377 378 379

            if (atom.type == MKTAG('c', 'o', 'v', 'r')) {
                int ret = mov_read_covr(c, pb, data_type, str_size);
                if (ret < 0) {
                    av_log(c->fc, AV_LOG_ERROR, "Error parsing cover art.\n");
                }
380
                return ret;
381 382 383 384 385 386 387 388 389
            } else if (!key && c->found_hdlr_mdta && c->meta_keys) {
                uint32_t index = AV_RB32(&atom.type);
                if (index < c->meta_keys_count) {
                    key = c->meta_keys[index];
                } else {
                    av_log(c->fc, AV_LOG_WARNING,
                           "The index of 'data' is out of range: %d >= %d.\n",
                           index, c->meta_keys_count);
                }
A
Anton Khirnov 已提交
390
            }
391
        } else return 0;
392
    } else if (atom.size > 4 && key && !c->itunes_metadata && !raw) {
393
        str_size = avio_rb16(pb); // string length
394 395 396
        if (str_size > atom.size) {
            raw = 1;
            avio_seek(pb, -2, SEEK_CUR);
397
            av_log(c->fc, AV_LOG_WARNING, "UDTA parsing failed retrying raw\n");
398 399
            goto retry;
        }
400
        langcode = avio_rb16(pb);
401
        ff_mov_lang_to_iso639(langcode, language);
402 403 404 405
        atom.size -= 4;
    } else
        str_size = atom.size;

406
    if (c->export_all && !key) {
407 408 409 410 411 412
        snprintf(tmp_key, 5, "%.4s", (char*)&atom.type);
        key = tmp_key;
    }

    if (!key)
        return 0;
413
    if (atom.size < 0 || str_size >= INT_MAX/2)
414
        return AVERROR_INVALIDDATA;
415

416
    // Allocates enough space if data_type is a float32 number, otherwise
417
    // worst-case requirement for output string in case of utf8 coded input
418 419
    num = (data_type == 23);
    str_size_alloc = (num ? 512 : (raw ? str_size : str_size * 2)) + 1;
420
    str = av_mallocz(str_size_alloc);
421 422 423
    if (!str)
        return AVERROR(ENOMEM);

B
Baptiste Coudurier 已提交
424
    if (parse)
425
        parse(c, pb, str_size, key);
B
Baptiste Coudurier 已提交
426
    else {
427
        if (!raw && (data_type == 3 || (data_type == 0 && (langcode < 0x400 || langcode == 0x7fff)))) { // MAC Encoded
428
            mov_read_mac_string(c, pb, str_size, str, str_size_alloc);
429 430 431 432 433
        } else if (data_type == 23 && str_size >= 4) {  // BE float32
            float val = av_int2float(avio_rb32(pb));
            if (snprintf(str, str_size_alloc, "%f", val) >= str_size_alloc) {
                av_log(c->fc, AV_LOG_ERROR,
                       "Failed to store the float32 number (%f) in string.\n", val);
G
Ganesh Ajjanagadde 已提交
434
                av_free(str);
435 436
                return AVERROR_INVALIDDATA;
            }
437
        } else {
438 439 440 441
            int ret = ffio_read_size(pb, str, str_size);
            if (ret < 0) {
                av_free(str);
                return ret;
442
            }
443 444
            str[str_size] = 0;
        }
445
        c->fc->event_flags |= AVFMT_EVENT_FLAG_METADATA_UPDATED;
446
        av_dict_set(&c->fc->metadata, key, str, 0);
B
Baptiste Coudurier 已提交
447 448
        if (*language && strcmp(language, "und")) {
            snprintf(key2, sizeof(key2), "%s-%s", key, language);
449
            av_dict_set(&c->fc->metadata, key2, str, 0);
B
Baptiste Coudurier 已提交
450
        }
451 452 453 454 455 456
        if (!strcmp(key, "encoder")) {
            int major, minor, micro;
            if (sscanf(str, "HandBrake %d.%d.%d", &major, &minor, &micro) == 3) {
                c->handbrake_version = 1000000*major + 1000*minor + micro;
            }
        }
B
Baptiste Coudurier 已提交
457
    }
458 459
    av_log(c->fc, AV_LOG_TRACE, "lang \"%3s\" ", language);
    av_log(c->fc, AV_LOG_TRACE, "tag \"%s\" value \"%s\" atom \"%.4s\" %d %"PRId64"\n",
460 461 462
            key, str, (char*)&atom.type, str_size_alloc, atom.size);

    av_freep(&str);
463 464
    return 0;
}
465

466
static int mov_read_chpl(MOVContext *c, AVIOContext *pb, MOVAtom atom)
D
David Conrad 已提交
467 468
{
    int64_t start;
D
David Conrad 已提交
469
    int i, nb_chapters, str_len, version;
D
David Conrad 已提交
470
    char str[256+1];
471
    int ret;
D
David Conrad 已提交
472

473 474 475
    if (c->ignore_chapters)
        return 0;

D
David Conrad 已提交
476 477 478
    if ((atom.size -= 5) < 0)
        return 0;

479 480
    version = avio_r8(pb);
    avio_rb24(pb);
D
David Conrad 已提交
481
    if (version)
482 483
        avio_rb32(pb); // ???
    nb_chapters = avio_r8(pb);
D
David Conrad 已提交
484 485 486 487 488

    for (i = 0; i < nb_chapters; i++) {
        if (atom.size < 9)
            return 0;

489 490
        start = avio_rb64(pb);
        str_len = avio_r8(pb);
D
David Conrad 已提交
491 492 493 494

        if ((atom.size -= 9+str_len) < 0)
            return 0;

495 496 497
        ret = ffio_read_size(pb, str, str_len);
        if (ret < 0)
            return ret;
D
David Conrad 已提交
498
        str[str_len] = 0;
499
        avpriv_new_chapter(c->fc, i, (AVRational){1,10000000}, start, AV_NOPTS_VALUE, str);
D
David Conrad 已提交
500 501 502 503
    }
    return 0;
}

504
#define MIN_DATA_ENTRY_BOX_SIZE 12
505
static int mov_read_dref(MOVContext *c, AVIOContext *pb, MOVAtom atom)
506
{
507 508
    AVStream *st;
    MOVStreamContext *sc;
509 510
    int entries, i, j;

511 512 513 514 515
    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;

516 517
    avio_rb32(pb); // version + flags
    entries = avio_rb32(pb);
518 519
    if (entries >  (atom.size - 1) / MIN_DATA_ENTRY_BOX_SIZE + 1 ||
        entries >= UINT_MAX / sizeof(*sc->drefs))
520
        return AVERROR_INVALIDDATA;
521
    av_free(sc->drefs);
522
    sc->drefs_count = 0;
523
    sc->drefs = av_mallocz(entries * sizeof(*sc->drefs));
524 525 526
    if (!sc->drefs)
        return AVERROR(ENOMEM);
    sc->drefs_count = entries;
527

528
    for (i = 0; i < entries; i++) {
529
        MOVDref *dref = &sc->drefs[i];
530
        uint32_t size = avio_rb32(pb);
531
        int64_t next = avio_tell(pb) + size - 4;
532

533
        if (size < 12)
534
            return AVERROR_INVALIDDATA;
535

536 537
        dref->type = avio_rl32(pb);
        avio_rb32(pb); // version + flags
538
        av_log(c->fc, AV_LOG_TRACE, "type %.4s size %d\n", (char*)&dref->type, size);
539 540 541 542 543

        if (dref->type == MKTAG('a','l','i','s') && size > 150) {
            /* macintosh alias record */
            uint16_t volume_len, len;
            int16_t type;
544
            int ret;
545

546
            avio_skip(pb, 10);
547

548
            volume_len = avio_r8(pb);
549
            volume_len = FFMIN(volume_len, 27);
550 551 552
            ret = ffio_read_size(pb, dref->volume, 27);
            if (ret < 0)
                return ret;
553 554
            dref->volume[volume_len] = 0;
            av_log(c->fc, AV_LOG_DEBUG, "volume %s, len %d\n", dref->volume, volume_len);
555

556
            avio_skip(pb, 12);
557

558
            len = avio_r8(pb);
559
            len = FFMIN(len, 63);
560 561 562
            ret = ffio_read_size(pb, dref->filename, 63);
            if (ret < 0)
                return ret;
563 564 565
            dref->filename[len] = 0;
            av_log(c->fc, AV_LOG_DEBUG, "filename %s, len %d\n", dref->filename, len);

566
            avio_skip(pb, 16);
567 568

            /* read next level up_from_alias/down_to_target */
569 570
            dref->nlvl_from = avio_rb16(pb);
            dref->nlvl_to   = avio_rb16(pb);
571 572 573
            av_log(c->fc, AV_LOG_DEBUG, "nlvl from %d, nlvl to %d\n",
                   dref->nlvl_from, dref->nlvl_to);

574
            avio_skip(pb, 16);
575

576
            for (type = 0; type != -1 && avio_tell(pb) < next; ) {
577
                if(avio_feof(pb))
578
                    return AVERROR_EOF;
579 580
                type = avio_rb16(pb);
                len = avio_rb16(pb);
581 582 583
                av_log(c->fc, AV_LOG_DEBUG, "type %d, len %d\n", type, len);
                if (len&1)
                    len += 1;
V
Vittorio Giovara 已提交
584
                if (type == 2) { // absolute path
585
                    av_free(dref->path);
586
                    dref->path = av_mallocz(len+1);
587 588
                    if (!dref->path)
                        return AVERROR(ENOMEM);
589 590 591

                    ret = ffio_read_size(pb, dref->path, len);
                    if (ret < 0) {
592
                        av_freep(&dref->path);
593
                        return ret;
594
                    }
595
                    if (len > volume_len && !strncmp(dref->path, dref->volume, volume_len)) {
596 597 598 599 600
                        len -= volume_len;
                        memmove(dref->path, dref->path+volume_len, len);
                        dref->path[len] = 0;
                    }
                    for (j = 0; j < len; j++)
V
Vittorio Giovara 已提交
601
                        if (dref->path[j] == ':' || dref->path[j] == 0)
602 603
                            dref->path[j] = '/';
                    av_log(c->fc, AV_LOG_DEBUG, "path %s\n", dref->path);
604 605 606 607 608
                } else if (type == 0) { // directory name
                    av_free(dref->dir);
                    dref->dir = av_malloc(len+1);
                    if (!dref->dir)
                        return AVERROR(ENOMEM);
609 610 611

                    ret = ffio_read_size(pb, dref->dir, len);
                    if (ret < 0) {
612
                        av_freep(&dref->dir);
613
                        return ret;
614
                    }
615 616 617 618 619
                    dref->dir[len] = 0;
                    for (j = 0; j < len; j++)
                        if (dref->dir[j] == ':')
                            dref->dir[j] = '/';
                    av_log(c->fc, AV_LOG_DEBUG, "dir %s\n", dref->dir);
620
                } else
621
                    avio_skip(pb, len);
622
            }
623 624 625 626 627
        } else {
            av_log(c->fc, AV_LOG_DEBUG, "Unknown dref type 0x08%x size %d\n",
                   dref->type, size);
            entries--;
            i--;
628
        }
A
Anton Khirnov 已提交
629
        avio_seek(pb, next, SEEK_SET);
630 631 632 633
    }
    return 0;
}

634
static int mov_read_hdlr(MOVContext *c, AVIOContext *pb, MOVAtom atom)
635
{
636
    AVStream *st;
637
    uint32_t type;
638
    uint32_t av_unused ctype;
639
    int64_t title_size;
640
    char *title_str;
641
    int ret;
642

643 644
    avio_r8(pb); /* version */
    avio_rb24(pb); /* flags */
645 646

    /* component type */
647 648
    ctype = avio_rl32(pb);
    type = avio_rl32(pb); /* component subtype */
649

650 651
    av_log(c->fc, AV_LOG_TRACE, "ctype= %.4s (0x%08x)\n", (char*)&ctype, ctype);
    av_log(c->fc, AV_LOG_TRACE, "stype= %.4s\n", (char*)&type);
652

653
    if (c->trak_index < 0) {  // meta not inside a trak
654 655 656 657 658 659 660 661
        if (type == MKTAG('m','d','t','a')) {
            c->found_hdlr_mdta = 1;
        }
        return 0;
    }

    st = c->fc->streams[c->fc->nb_streams-1];

662
    if     (type == MKTAG('v','i','d','e'))
663
        st->codec->codec_type = AVMEDIA_TYPE_VIDEO;
664
    else if (type == MKTAG('s','o','u','n'))
665
        st->codec->codec_type = AVMEDIA_TYPE_AUDIO;
666
    else if (type == MKTAG('m','1','a',' '))
667
        st->codec->codec_id = AV_CODEC_ID_MP2;
668
    else if ((type == MKTAG('s','u','b','p')) || (type == MKTAG('c','l','c','p')))
669
        st->codec->codec_type = AVMEDIA_TYPE_SUBTITLE;
670

671 672 673
    avio_rb32(pb); /* component  manufacture */
    avio_rb32(pb); /* component flags */
    avio_rb32(pb); /* component flags mask */
674

675 676 677 678 679
    title_size = atom.size - 24;
    if (title_size > 0) {
        title_str = av_malloc(title_size + 1); /* Add null terminator */
        if (!title_str)
            return AVERROR(ENOMEM);
680 681 682

        ret = ffio_read_size(pb, title_str, title_size);
        if (ret < 0) {
683
            av_freep(&title_str);
684
            return ret;
685
        }
686
        title_str[title_size] = 0;
687 688 689 690
        if (title_str[0]) {
            int off = (!c->isom && title_str[0] == title_size - 1);
            av_dict_set(&st->metadata, "handler_name", title_str + off, 0);
        }
691 692 693
        av_freep(&title_str);
    }

694 695 696
    return 0;
}

697
int ff_mov_read_esds(AVFormatContext *fc, AVIOContext *pb)
698
{
699
    AVStream *st;
700
    int tag;
701

702
    if (fc->nb_streams < 1)
703
        return 0;
704
    st = fc->streams[fc->nb_streams-1];
705

706
    avio_rb32(pb); /* version + flags */
707
    ff_mp4_read_descr(fc, pb, &tag);
708
    if (tag == MP4ESDescrTag) {
709
        ff_mp4_parse_es_descr(pb, NULL);
710
    } else
711
        avio_rb16(pb); /* ID */
712

713
    ff_mp4_read_descr(fc, pb, &tag);
714 715
    if (tag == MP4DecConfigDescrTag)
        ff_mp4_read_dec_config_descr(fc, st, pb);
716 717 718
    return 0;
}

719
static int mov_read_esds(MOVContext *c, AVIOContext *pb, MOVAtom atom)
720
{
721
    return ff_mov_read_esds(c->fc, pb);
722 723
}

724
static int mov_read_dac3(MOVContext *c, AVIOContext *pb, MOVAtom atom)
725 726
{
    AVStream *st;
727
    enum AVAudioServiceType *ast;
728
    int ac3info, acmod, lfeon, bsmod;
729

730 731
    if (c->fc->nb_streams < 1)
        return 0;
732 733
    st = c->fc->streams[c->fc->nb_streams-1];

734
    ast = (enum AVAudioServiceType*)av_stream_new_side_data(st, AV_PKT_DATA_AUDIO_SERVICE_TYPE,
735 736 737 738
                                                            sizeof(*ast));
    if (!ast)
        return AVERROR(ENOMEM);

739
    ac3info = avio_rb24(pb);
740
    bsmod = (ac3info >> 14) & 0x7;
741 742 743
    acmod = (ac3info >> 11) & 0x7;
    lfeon = (ac3info >> 10) & 0x1;
    st->codec->channels = ((int[]){2,1,2,3,3,4,4,5})[acmod] + lfeon;
744 745 746
    st->codec->channel_layout = avpriv_ac3_channel_layout_tab[acmod];
    if (lfeon)
        st->codec->channel_layout |= AV_CH_LOW_FREQUENCY;
747
    *ast = bsmod;
748
    if (st->codec->channels > 1 && bsmod == 0x7)
749 750 751
        *ast = AV_AUDIO_SERVICE_TYPE_KARAOKE;

    st->codec->audio_service_type = *ast;
752 753 754 755

    return 0;
}

756 757 758
static int mov_read_dec3(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    AVStream *st;
759
    enum AVAudioServiceType *ast;
760 761 762 763 764 765
    int eac3info, acmod, lfeon, bsmod;

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];

766
    ast = (enum AVAudioServiceType*)av_stream_new_side_data(st, AV_PKT_DATA_AUDIO_SERVICE_TYPE,
767 768 769 770
                                                            sizeof(*ast));
    if (!ast)
        return AVERROR(ENOMEM);

771 772 773 774 775 776 777 778 779 780 781 782
    /* No need to parse fields for additional independent substreams and its
     * associated dependent substreams since libavcodec's E-AC-3 decoder
     * does not support them yet. */
    avio_rb16(pb); /* data_rate and num_ind_sub */
    eac3info = avio_rb24(pb);
    bsmod = (eac3info >> 12) & 0x1f;
    acmod = (eac3info >>  9) & 0x7;
    lfeon = (eac3info >>  8) & 0x1;
    st->codec->channel_layout = avpriv_ac3_channel_layout_tab[acmod];
    if (lfeon)
        st->codec->channel_layout |= AV_CH_LOW_FREQUENCY;
    st->codec->channels = av_get_channel_layout_nb_channels(st->codec->channel_layout);
783
    *ast = bsmod;
784
    if (st->codec->channels > 1 && bsmod == 0x7)
785 786 787
        *ast = AV_AUDIO_SERVICE_TYPE_KARAOKE;

    st->codec->audio_service_type = *ast;
788 789 790 791

    return 0;
}

792 793 794 795 796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846
static int mov_read_ddts(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    const uint32_t ddts_size = 20;
    AVStream *st = NULL;
    uint8_t *buf = NULL;
    uint32_t frame_duration_code = 0;
    uint32_t channel_layout_code = 0;
    GetBitContext gb;

    buf = av_malloc(ddts_size + FF_INPUT_BUFFER_PADDING_SIZE);
    if (!buf) {
        return AVERROR(ENOMEM);
    }
    if (avio_read(pb, buf, ddts_size) < ddts_size) {
        av_free(buf);
        return AVERROR_INVALIDDATA;
    }

    init_get_bits(&gb, buf, 8*ddts_size);

    if (c->fc->nb_streams < 1) {
        return 0;
    }
    st = c->fc->streams[c->fc->nb_streams-1];

    st->codec->sample_rate = get_bits_long(&gb, 32);
    skip_bits_long(&gb, 32); /* max bitrate */
    st->codec->bit_rate = get_bits_long(&gb, 32);
    st->codec->bits_per_coded_sample = get_bits(&gb, 8);
    frame_duration_code = get_bits(&gb, 2);
    skip_bits(&gb, 30); /* various fields */
    channel_layout_code = get_bits(&gb, 16);

    st->codec->frame_size =
            (frame_duration_code == 0) ? 512 :
            (frame_duration_code == 1) ? 1024 :
            (frame_duration_code == 2) ? 2048 :
            (frame_duration_code == 3) ? 4096 : 0;

    if (channel_layout_code > 0xff) {
        av_log(c->fc, AV_LOG_WARNING, "Unsupported DTS audio channel layout");
    }
    st->codec->channel_layout =
            ((channel_layout_code & 0x1) ? AV_CH_FRONT_CENTER : 0) |
            ((channel_layout_code & 0x2) ? AV_CH_FRONT_LEFT : 0) |
            ((channel_layout_code & 0x2) ? AV_CH_FRONT_RIGHT : 0) |
            ((channel_layout_code & 0x4) ? AV_CH_SIDE_LEFT : 0) |
            ((channel_layout_code & 0x4) ? AV_CH_SIDE_RIGHT : 0) |
            ((channel_layout_code & 0x8) ? AV_CH_LOW_FREQUENCY : 0);

    st->codec->channels = av_get_channel_layout_nb_channels(st->codec->channel_layout);

    return 0;
}

847 848 849 850 851 852 853 854 855 856 857
static int mov_read_chan(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    AVStream *st;

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];

    if (atom.size < 16)
        return 0;

858 859 860
    /* skip version and flags */
    avio_skip(pb, 4);

861
    ff_mov_read_chan(c->fc, pb, st, atom.size - 4);
862 863 864 865

    return 0;
}

866 867 868
static int mov_read_wfex(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    AVStream *st;
869
    int ret;
870 871 872 873 874

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];

875
    if ((ret = ff_get_wav_header(c->fc, pb, st->codec, atom.size, 0)) < 0)
876
        av_log(c->fc, AV_LOG_WARNING, "get_wav_header failed\n");
877

878
    return ret;
879 880
}

881
static int mov_read_pasp(MOVContext *c, AVIOContext *pb, MOVAtom atom)
882
{
883 884
    const int num = avio_rb32(pb);
    const int den = avio_rb32(pb);
885 886 887 888 889 890
    AVStream *st;

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];

891 892 893 894 895 896 897
    if ((st->sample_aspect_ratio.den != 1 || st->sample_aspect_ratio.num) && // default
        (den != st->sample_aspect_ratio.den || num != st->sample_aspect_ratio.num)) {
        av_log(c->fc, AV_LOG_WARNING,
               "sample aspect ratio already set to %d:%d, ignoring 'pasp' atom (%d:%d)\n",
               st->sample_aspect_ratio.num, st->sample_aspect_ratio.den,
               num, den);
    } else if (den != 0) {
898 899
        av_reduce(&st->sample_aspect_ratio.num, &st->sample_aspect_ratio.den,
                  num, den, 32767);
900 901 902 903
    }
    return 0;
}

904
/* this atom contains actual media data */
905
static int mov_read_mdat(MOVContext *c, AVIOContext *pb, MOVAtom atom)
906
{
907
    if (atom.size == 0) /* wrong one (MP4) */
908 909 910 911 912
        return 0;
    c->found_mdat=1;
    return 0; /* now go for moov */
}

913 914 915 916 917 918 919 920 921 922 923 924 925 926 927 928 929 930 931 932 933 934 935 936 937 938 939 940
#define DRM_BLOB_SIZE 56

static int mov_read_adrm(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    uint8_t intermediate_key[20];
    uint8_t intermediate_iv[20];
    uint8_t input[64];
    uint8_t output[64];
    uint8_t file_checksum[20];
    uint8_t calculated_checksum[20];
    struct AVSHA *sha;
    int i;
    int ret = 0;
    uint8_t *activation_bytes = c->activation_bytes;
    uint8_t *fixed_key = c->audible_fixed_key;

    c->aax_mode = 1;

    sha = av_sha_alloc();
    if (!sha)
        return AVERROR(ENOMEM);
    c->aes_decrypt = av_aes_alloc();
    if (!c->aes_decrypt) {
        ret = AVERROR(ENOMEM);
        goto fail;
    }

    /* drm blob processing */
A
Andreas Cadhalpun 已提交
941
    avio_read(pb, output, 8); // go to offset 8, absolute position 0x251
942
    avio_read(pb, input, DRM_BLOB_SIZE);
A
Andreas Cadhalpun 已提交
943
    avio_read(pb, output, 4); // go to offset 4, absolute position 0x28d
944 945 946 947 948 949 950 951
    avio_read(pb, file_checksum, 20);

    av_log(c->fc, AV_LOG_INFO, "[aax] file checksum == "); // required by external tools
    for (i = 0; i < 20; i++)
        av_log(sha, AV_LOG_INFO, "%02x", file_checksum[i]);
    av_log(c->fc, AV_LOG_INFO, "\n");

    /* verify activation data */
952 953 954
    if (!activation_bytes) {
        av_log(c->fc, AV_LOG_WARNING, "[aax] activation_bytes option is missing!\n");
        ret = 0;  /* allow ffprobe to continue working on .aax files */
955 956 957 958 959 960 961 962 963 964 965 966 967 968 969 970 971 972 973 974 975 976 977 978 979 980 981 982 983 984 985 986 987 988 989 990 991 992 993 994 995 996 997 998 999 1000 1001 1002 1003 1004 1005 1006 1007 1008 1009 1010 1011 1012 1013 1014 1015 1016 1017 1018 1019 1020 1021 1022 1023 1024 1025 1026
        goto fail;
    }
    if (c->activation_bytes_size != 4) {
        av_log(c->fc, AV_LOG_FATAL, "[aax] activation_bytes value needs to be 4 bytes!\n");
        ret = AVERROR(EINVAL);
        goto fail;
    }

    /* verify fixed key */
    if (c->audible_fixed_key_size != 16) {
        av_log(c->fc, AV_LOG_FATAL, "[aax] audible_fixed_key value needs to be 16 bytes!\n");
        ret = AVERROR(EINVAL);
        goto fail;
    }

    /* AAX (and AAX+) key derivation */
    av_sha_init(sha, 160);
    av_sha_update(sha, fixed_key, 16);
    av_sha_update(sha, activation_bytes, 4);
    av_sha_final(sha, intermediate_key);
    av_sha_init(sha, 160);
    av_sha_update(sha, fixed_key, 16);
    av_sha_update(sha, intermediate_key, 20);
    av_sha_update(sha, activation_bytes, 4);
    av_sha_final(sha, intermediate_iv);
    av_sha_init(sha, 160);
    av_sha_update(sha, intermediate_key, 16);
    av_sha_update(sha, intermediate_iv, 16);
    av_sha_final(sha, calculated_checksum);
    if (memcmp(calculated_checksum, file_checksum, 20)) { // critical error
        av_log(c->fc, AV_LOG_ERROR, "[aax] mismatch in checksums!\n");
        ret = AVERROR_INVALIDDATA;
        goto fail;
    }
    av_aes_init(c->aes_decrypt, intermediate_key, 128, 1);
    av_aes_crypt(c->aes_decrypt, output, input, DRM_BLOB_SIZE >> 4, intermediate_iv, 1);
    for (i = 0; i < 4; i++) {
        // file data (in output) is stored in big-endian mode
        if (activation_bytes[i] != output[3 - i]) { // critical error
            av_log(c->fc, AV_LOG_ERROR, "[aax] error in drm blob decryption!\n");
            ret = AVERROR_INVALIDDATA;
            goto fail;
        }
    }
    memcpy(c->file_key, output + 8, 16);
    memcpy(input, output + 26, 16);
    av_sha_init(sha, 160);
    av_sha_update(sha, input, 16);
    av_sha_update(sha, c->file_key, 16);
    av_sha_update(sha, fixed_key, 16);
    av_sha_final(sha, c->file_iv);

fail:
    av_free(sha);

    return ret;
}

// Audible AAX (and AAX+) bytestream decryption
static int aax_filter(uint8_t *input, int size, MOVContext *c)
{
    int blocks = 0;
    unsigned char iv[16];

    memcpy(iv, c->file_iv, 16); // iv is overwritten
    blocks = size >> 4; // trailing bytes are not encrypted!
    av_aes_init(c->aes_decrypt, c->file_key, 128, 1);
    av_aes_crypt(c->aes_decrypt, input, input, blocks, iv, 1);

    return 0;
}

1027
/* read major brand, minor version and compatible brands and store them as metadata */
1028
static int mov_read_ftyp(MOVContext *c, AVIOContext *pb, MOVAtom atom)
1029
{
1030 1031 1032 1033
    uint32_t minor_ver;
    int comp_brand_size;
    char* comp_brands_str;
    uint8_t type[5] = {0};
1034 1035 1036
    int ret = ffio_read_size(pb, type, 4);
    if (ret < 0)
        return ret;
1037

B
Baptiste Coudurier 已提交
1038
    if (strcmp(type, "qt  "))
1039
        c->isom = 1;
1040
    av_log(c->fc, AV_LOG_DEBUG, "ISO: File Type Major Brand: %.4s\n",(char *)&type);
1041
    av_dict_set(&c->fc->metadata, "major_brand", type, 0);
1042
    minor_ver = avio_rb32(pb); /* minor version */
1043
    av_dict_set_int(&c->fc->metadata, "minor_version", minor_ver, 0);
1044 1045 1046

    comp_brand_size = atom.size - 8;
    if (comp_brand_size < 0)
1047
        return AVERROR_INVALIDDATA;
1048 1049 1050
    comp_brands_str = av_malloc(comp_brand_size + 1); /* Add null terminator */
    if (!comp_brands_str)
        return AVERROR(ENOMEM);
1051 1052 1053

    ret = ffio_read_size(pb, comp_brands_str, comp_brand_size);
    if (ret < 0) {
1054
        av_freep(&comp_brands_str);
1055
        return ret;
1056
    }
1057
    comp_brands_str[comp_brand_size] = 0;
1058
    av_dict_set(&c->fc->metadata, "compatible_brands", comp_brands_str, 0);
1059 1060
    av_freep(&comp_brands_str);

1061 1062 1063
    return 0;
}

1064
/* this atom should contain all header atoms */
1065
static int mov_read_moov(MOVContext *c, AVIOContext *pb, MOVAtom atom)
1066
{
1067 1068
    int ret;

1069 1070 1071 1072 1073 1074
    if (c->found_moov) {
        av_log(c->fc, AV_LOG_WARNING, "Found duplicated MOOV Atom. Skipped it\n");
        avio_skip(pb, atom.size);
        return 0;
    }

1075 1076
    if ((ret = mov_read_default(c, pb, atom)) < 0)
        return ret;
1077 1078 1079 1080 1081 1082
    /* we parsed the 'moov' atom, we can terminate the parsing as soon as we find the 'mdat' */
    /* so we don't parse the whole file if over a network */
    c->found_moov=1;
    return 0; /* now go for mdat */
}

1083
static int mov_read_moof(MOVContext *c, AVIOContext *pb, MOVAtom atom)
B
Baptiste Coudurier 已提交
1084
{
1085 1086 1087
    if (!c->has_looked_for_mfra && c->use_mfra_for > 0) {
        c->has_looked_for_mfra = 1;
        if (pb->seekable) {
1088
            int ret;
1089 1090 1091 1092 1093 1094 1095 1096 1097 1098 1099
            av_log(c->fc, AV_LOG_VERBOSE, "stream has moof boxes, will look "
                    "for a mfra\n");
            if ((ret = mov_read_mfra(c, pb)) < 0) {
                av_log(c->fc, AV_LOG_VERBOSE, "found a moof box but failed to "
                        "read the mfra (may be a live ismv)\n");
            }
        } else {
            av_log(c->fc, AV_LOG_VERBOSE, "found a moof box but stream is not "
                    "seekable, can not look for mfra\n");
        }
    }
1100
    c->fragment.moof_offset = c->fragment.implicit_offset = avio_tell(pb) - 8;
1101
    av_log(c->fc, AV_LOG_TRACE, "moof offset %"PRIx64"\n", c->fragment.moof_offset);
B
Baptiste Coudurier 已提交
1102 1103
    return mov_read_default(c, pb, atom);
}
1104

1105
static void mov_metadata_creation_time(AVDictionary **metadata, int64_t time)
1106 1107 1108
{
    char buffer[32];
    if (time) {
1109
        struct tm *ptm, tmbuf;
1110
        time_t timet;
1111 1112
        if(time >= 2082844800)
            time -= 2082844800;  /* seconds between 1904-01-01 and Epoch */
1113
        timet = time;
1114
        ptm = gmtime_r(&timet, &tmbuf);
1115
        if (!ptm) return;
1116 1117
        if (strftime(buffer, sizeof(buffer), "%Y-%m-%d %H:%M:%S", ptm))
            av_dict_set(metadata, "creation_time", buffer, 0);
1118 1119 1120
    }
}

1121
static int mov_read_mdhd(MOVContext *c, AVIOContext *pb, MOVAtom atom)
1122
{
1123 1124 1125
    AVStream *st;
    MOVStreamContext *sc;
    int version;
1126
    char language[4] = {0};
1127
    unsigned lang;
1128
    int64_t creation_time;
1129

1130 1131 1132 1133 1134
    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;

1135 1136 1137 1138 1139
    if (sc->time_scale) {
        av_log(c->fc, AV_LOG_ERROR, "Multiple mdhd?\n");
        return AVERROR_INVALIDDATA;
    }

1140
    version = avio_r8(pb);
1141
    if (version > 1) {
1142
        avpriv_request_sample(c->fc, "Version %d", version);
1143 1144
        return AVERROR_PATCHWELCOME;
    }
1145
    avio_rb24(pb); /* flags */
B
clean  
Baptiste Coudurier 已提交
1146
    if (version == 1) {
1147 1148
        creation_time = avio_rb64(pb);
        avio_rb64(pb);
B
clean  
Baptiste Coudurier 已提交
1149
    } else {
1150 1151
        creation_time = avio_rb32(pb);
        avio_rb32(pb); /* modification time */
B
clean  
Baptiste Coudurier 已提交
1152
    }
1153
    mov_metadata_creation_time(&st->metadata, creation_time);
1154

1155 1156
    sc->time_scale = avio_rb32(pb);
    st->duration = (version == 1) ? avio_rb64(pb) : avio_rb32(pb); /* duration */
1157

1158
    lang = avio_rb16(pb); /* language */
1159
    if (ff_mov_lang_to_iso639(lang, language))
1160
        av_dict_set(&st->metadata, "language", language, 0);
1161
    avio_rb16(pb); /* quality */
1162 1163 1164 1165

    return 0;
}

1166
static int mov_read_mvhd(MOVContext *c, AVIOContext *pb, MOVAtom atom)
1167
{
1168
    int64_t creation_time;
1169 1170
    int version = avio_r8(pb); /* version */
    avio_rb24(pb); /* flags */
1171

B
Baptiste Coudurier 已提交
1172
    if (version == 1) {
1173 1174
        creation_time = avio_rb64(pb);
        avio_rb64(pb);
B
Baptiste Coudurier 已提交
1175
    } else {
1176 1177
        creation_time = avio_rb32(pb);
        avio_rb32(pb); /* modification time */
B
Baptiste Coudurier 已提交
1178
    }
1179
    mov_metadata_creation_time(&c->fc->metadata, creation_time);
1180
    c->time_scale = avio_rb32(pb); /* time scale */
1181

1182
    av_log(c->fc, AV_LOG_TRACE, "time scale = %i\n", c->time_scale);
1183

1184
    c->duration = (version == 1) ? avio_rb64(pb) : avio_rb32(pb); /* duration */
1185 1186
    // set the AVCodecContext duration because the duration of individual tracks
    // may be inaccurate
1187
    if (c->time_scale > 0 && !c->trex_data)
1188
        c->fc->duration = av_rescale(c->duration, AV_TIME_BASE, c->time_scale);
1189
    avio_rb32(pb); /* preferred scale */
1190

1191
    avio_rb16(pb); /* preferred volume */
1192

1193
    avio_skip(pb, 10); /* reserved */
1194

1195
    avio_skip(pb, 36); /* display matrix */
1196

1197 1198 1199 1200 1201 1202 1203
    avio_rb32(pb); /* preview time */
    avio_rb32(pb); /* preview duration */
    avio_rb32(pb); /* poster time */
    avio_rb32(pb); /* selection time */
    avio_rb32(pb); /* selection duration */
    avio_rb32(pb); /* current time */
    avio_rb32(pb); /* next track ID */
1204 1205 1206 1207

    return 0;
}

1208
static int mov_read_enda(MOVContext *c, AVIOContext *pb, MOVAtom atom)
1209
{
1210 1211 1212 1213 1214 1215
    AVStream *st;
    int little_endian;

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
1216

1217
    little_endian = avio_rb16(pb) & 0xFF;
1218
    av_log(c->fc, AV_LOG_TRACE, "enda %d\n", little_endian);
1219
    if (little_endian == 1) {
1220
        switch (st->codec->codec_id) {
1221 1222
        case AV_CODEC_ID_PCM_S24BE:
            st->codec->codec_id = AV_CODEC_ID_PCM_S24LE;
1223
            break;
1224 1225
        case AV_CODEC_ID_PCM_S32BE:
            st->codec->codec_id = AV_CODEC_ID_PCM_S32LE;
1226
            break;
1227 1228
        case AV_CODEC_ID_PCM_F32BE:
            st->codec->codec_id = AV_CODEC_ID_PCM_F32LE;
1229
            break;
1230 1231
        case AV_CODEC_ID_PCM_F64BE:
            st->codec->codec_id = AV_CODEC_ID_PCM_F64LE;
1232
            break;
1233 1234 1235 1236 1237 1238 1239
        default:
            break;
        }
    }
    return 0;
}

1240 1241 1242 1243
static int mov_read_colr(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    AVStream *st;
    char color_parameter_type[5] = { 0 };
1244
    uint16_t color_primaries, color_trc, color_matrix;
1245
    int ret;
1246 1247 1248 1249 1250

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams - 1];

1251 1252 1253
    ret = ffio_read_size(pb, color_parameter_type, 4);
    if (ret < 0)
        return ret;
1254 1255 1256 1257 1258 1259 1260 1261 1262 1263 1264
    if (strncmp(color_parameter_type, "nclx", 4) &&
        strncmp(color_parameter_type, "nclc", 4)) {
        av_log(c->fc, AV_LOG_WARNING, "unsupported color_parameter_type %s\n",
               color_parameter_type);
        return 0;
    }

    color_primaries = avio_rb16(pb);
    color_trc = avio_rb16(pb);
    color_matrix = avio_rb16(pb);

1265
    av_log(c->fc, AV_LOG_TRACE,
1266
           "%s: pri %d trc %d matrix %d",
1267
           color_parameter_type, color_primaries, color_trc, color_matrix);
1268

1269
    if (!strncmp(color_parameter_type, "nclx", 4)) {
1270
        uint8_t color_range = avio_r8(pb) >> 7;
1271
        av_log(c->fc, AV_LOG_TRACE, " full %"PRIu8"", color_range);
1272 1273 1274 1275 1276 1277 1278 1279
        if (color_range)
            st->codec->color_range = AVCOL_RANGE_JPEG;
        else
            st->codec->color_range = AVCOL_RANGE_MPEG;
        /* 14496-12 references JPEG XR specs (rather than the more complete
         * 23001-8) so some adjusting is required */
        if (color_primaries >= AVCOL_PRI_FILM)
            color_primaries = AVCOL_PRI_UNSPECIFIED;
1280 1281
        if ((color_trc >= AVCOL_TRC_LINEAR &&
             color_trc <= AVCOL_TRC_LOG_SQRT) ||
1282 1283 1284 1285 1286 1287 1288
            color_trc >= AVCOL_TRC_BT2020_10)
            color_trc = AVCOL_TRC_UNSPECIFIED;
        if (color_matrix >= AVCOL_SPC_BT2020_NCL)
            color_matrix = AVCOL_SPC_UNSPECIFIED;
        st->codec->color_primaries = color_primaries;
        st->codec->color_trc = color_trc;
        st->codec->colorspace = color_matrix;
1289
    } else if (!strncmp(color_parameter_type, "nclc", 4)) {
1290 1291 1292 1293 1294 1295 1296 1297 1298 1299 1300 1301 1302 1303 1304 1305 1306 1307
        /* color primaries, Table 4-4 */
        switch (color_primaries) {
        case 1: st->codec->color_primaries = AVCOL_PRI_BT709; break;
        case 5: st->codec->color_primaries = AVCOL_PRI_SMPTE170M; break;
        case 6: st->codec->color_primaries = AVCOL_PRI_SMPTE240M; break;
        }
        /* color transfer, Table 4-5 */
        switch (color_trc) {
        case 1: st->codec->color_trc = AVCOL_TRC_BT709; break;
        case 7: st->codec->color_trc = AVCOL_TRC_SMPTE240M; break;
        }
        /* color matrix, Table 4-6 */
        switch (color_matrix) {
        case 1: st->codec->colorspace = AVCOL_SPC_BT709; break;
        case 6: st->codec->colorspace = AVCOL_SPC_BT470BG; break;
        case 7: st->codec->colorspace = AVCOL_SPC_SMPTE240M; break;
        }
    }
1308
    av_log(c->fc, AV_LOG_TRACE, "\n");
1309 1310 1311 1312

    return 0;
}

1313 1314 1315 1316 1317 1318 1319 1320 1321 1322 1323 1324 1325 1326 1327 1328 1329 1330 1331 1332 1333 1334 1335 1336 1337 1338 1339 1340 1341 1342 1343 1344 1345 1346
static int mov_read_fiel(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    AVStream *st;
    unsigned mov_field_order;
    enum AVFieldOrder decoded_field_order = AV_FIELD_UNKNOWN;

    if (c->fc->nb_streams < 1) // will happen with jp2 files
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    if (atom.size < 2)
        return AVERROR_INVALIDDATA;
    mov_field_order = avio_rb16(pb);
    if ((mov_field_order & 0xFF00) == 0x0100)
        decoded_field_order = AV_FIELD_PROGRESSIVE;
    else if ((mov_field_order & 0xFF00) == 0x0200) {
        switch (mov_field_order & 0xFF) {
        case 0x01: decoded_field_order = AV_FIELD_TT;
                   break;
        case 0x06: decoded_field_order = AV_FIELD_BB;
                   break;
        case 0x09: decoded_field_order = AV_FIELD_TB;
                   break;
        case 0x0E: decoded_field_order = AV_FIELD_BT;
                   break;
        }
    }
    if (decoded_field_order == AV_FIELD_UNKNOWN && mov_field_order) {
        av_log(NULL, AV_LOG_ERROR, "Unknown MOV field order 0x%04x\n", mov_field_order);
    }
    st->codec->field_order = decoded_field_order;

    return 0;
}

1347 1348 1349
static int mov_realloc_extradata(AVCodecContext *codec, MOVAtom atom)
{
    int err = 0;
1350
    uint64_t size = (uint64_t)codec->extradata_size + atom.size + 8 + AV_INPUT_BUFFER_PADDING_SIZE;
1351 1352 1353 1354 1355 1356
    if (size > INT_MAX || (uint64_t)atom.size > INT_MAX)
        return AVERROR_INVALIDDATA;
    if ((err = av_reallocp(&codec->extradata, size)) < 0) {
        codec->extradata_size = 0;
        return err;
    }
1357
    codec->extradata_size = size - AV_INPUT_BUFFER_PADDING_SIZE;
1358 1359 1360 1361 1362 1363 1364 1365 1366 1367 1368 1369
    return 0;
}

/* Read a whole atom into the extradata return the size of the atom read, possibly truncated if != atom.size */
static int64_t mov_read_atom_into_extradata(MOVContext *c, AVIOContext *pb, MOVAtom atom,
                                        AVCodecContext *codec, uint8_t *buf)
{
    int64_t result = atom.size;
    int err;

    AV_WB32(buf    , atom.size + 8);
    AV_WL32(buf + 4, atom.type);
1370
    err = ffio_read_size(pb, buf + 8, atom.size);
1371 1372 1373 1374 1375 1376 1377 1378
    if (err < 0) {
        codec->extradata_size -= atom.size;
        return err;
    } else if (err < atom.size) {
        av_log(c->fc, AV_LOG_WARNING, "truncated extradata\n");
        codec->extradata_size -= atom.size - err;
        result = err;
    }
1379
    memset(buf + 8 + err, 0, AV_INPUT_BUFFER_PADDING_SIZE);
1380 1381 1382
    return result;
}

1383
/* FIXME modify qdm2/svq3/h264 decoders to take full atom as extradata */
1384
static int mov_read_extradata(MOVContext *c, AVIOContext *pb, MOVAtom atom,
1385
                              enum AVCodecID codec_id)
1386
{
1387
    AVStream *st;
1388
    uint64_t original_size;
1389
    int err;
1390 1391 1392

    if (c->fc->nb_streams < 1) // will happen with jp2 files
        return 0;
1393
    st = c->fc->streams[c->fc->nb_streams-1];
1394 1395 1396 1397

    if (st->codec->codec_id != codec_id)
        return 0; /* unexpected codec_id - don't mess with extradata */

1398 1399 1400
    original_size = st->codec->extradata_size;
    err = mov_realloc_extradata(st->codec, atom);
    if (err)
1401
        return err;
1402 1403 1404

    err =  mov_read_atom_into_extradata(c, pb, atom, st->codec,  st->codec->extradata + original_size);
    if (err < 0)
1405
        return err;
1406
    return 0; // Note: this is the original behavior to ignore truncation.
1407 1408
}

1409 1410 1411
/* wrapper functions for reading ALAC/AVS/MJPEG/MJPEG2000 extradata atoms only for those codecs */
static int mov_read_alac(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
1412
    return mov_read_extradata(c, pb, atom, AV_CODEC_ID_ALAC);
1413 1414 1415 1416
}

static int mov_read_avss(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
1417
    return mov_read_extradata(c, pb, atom, AV_CODEC_ID_AVS);
1418 1419 1420 1421
}

static int mov_read_jp2h(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
1422
    return mov_read_extradata(c, pb, atom, AV_CODEC_ID_JPEG2000);
1423 1424
}

1425 1426 1427 1428 1429
static int mov_read_dpxe(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    return mov_read_extradata(c, pb, atom, AV_CODEC_ID_R10K);
}

C
Carl Eugen Hoyos 已提交
1430
static int mov_read_avid(MOVContext *c, AVIOContext *pb, MOVAtom atom)
1431
{
1432 1433 1434 1435
    int ret = mov_read_extradata(c, pb, atom, AV_CODEC_ID_AVUI);
    if(ret == 0)
        ret = mov_read_extradata(c, pb, atom, AV_CODEC_ID_DNXHD);
    return ret;
1436 1437
}

1438 1439 1440 1441 1442 1443 1444 1445 1446 1447 1448 1449 1450 1451
static int mov_read_targa_y216(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    int ret = mov_read_extradata(c, pb, atom, AV_CODEC_ID_TARGA_Y216);

    if (!ret && c->fc->nb_streams >= 1) {
        AVCodecContext *avctx = c->fc->streams[c->fc->nb_streams-1]->codec;
        if (avctx->extradata_size >= 40) {
            avctx->height = AV_RB16(&avctx->extradata[36]);
            avctx->width  = AV_RB16(&avctx->extradata[38]);
        }
    }
    return ret;
}

1452 1453
static int mov_read_ares(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
1454 1455 1456 1457 1458 1459 1460 1461 1462 1463 1464
    if (c->fc->nb_streams >= 1) {
        AVCodecContext *codec = c->fc->streams[c->fc->nb_streams-1]->codec;
        if (codec->codec_tag == MKTAG('A', 'V', 'i', 'n') &&
            codec->codec_id == AV_CODEC_ID_H264 &&
            atom.size > 11) {
            avio_skip(pb, 10);
            /* For AVID AVCI50, force width of 1440 to be able to select the correct SPS and PPS */
            if (avio_rb16(pb) == 0xd4d)
                codec->width = 1440;
            return 0;
        }
1465 1466 1467 1468 1469
    }

    return mov_read_avid(c, pb, atom);
}

1470 1471 1472 1473 1474 1475 1476
static int mov_read_aclr(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    int ret = 0;
    int length = 0;
    uint64_t original_size;
    if (c->fc->nb_streams >= 1) {
        AVCodecContext *codec = c->fc->streams[c->fc->nb_streams-1]->codec;
1477 1478
        if (codec->codec_id == AV_CODEC_ID_H264)
            return 0;
1479 1480 1481 1482 1483 1484 1485 1486 1487 1488 1489 1490 1491 1492 1493 1494 1495 1496
        if (atom.size == 16) {
            original_size = codec->extradata_size;
            ret = mov_realloc_extradata(codec, atom);
            if (!ret) {
                length =  mov_read_atom_into_extradata(c, pb, atom, codec, codec->extradata + original_size);
                if (length == atom.size) {
                    const uint8_t range_value = codec->extradata[original_size + 19];
                    switch (range_value) {
                    case 1:
                        codec->color_range = AVCOL_RANGE_MPEG;
                        break;
                    case 2:
                        codec->color_range = AVCOL_RANGE_JPEG;
                        break;
                    default:
                        av_log(c, AV_LOG_WARNING, "ignored unknown aclr value (%d)\n", range_value);
                        break;
                    }
R
Ronald S. Bultje 已提交
1497
                    ff_dlog(c, "color_range: %d\n", codec->color_range);
1498 1499 1500 1501 1502 1503 1504 1505
                } else {
                  /* For some reason the whole atom was not added to the extradata */
                  av_log(c, AV_LOG_ERROR, "aclr not decoded - incomplete atom\n");
                }
            } else {
                av_log(c, AV_LOG_ERROR, "aclr not decoded - unable to add atom to extradata\n");
            }
        } else {
1506
            av_log(c, AV_LOG_WARNING, "aclr not decoded - unexpected size %"PRId64"\n", atom.size);
1507 1508 1509 1510 1511 1512
        }
    }

    return ret;
}

P
Piotr Bandurski 已提交
1513 1514
static int mov_read_svq3(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
1515
    return mov_read_extradata(c, pb, atom, AV_CODEC_ID_SVQ3);
P
Piotr Bandurski 已提交
1516 1517
}

1518
static int mov_read_wave(MOVContext *c, AVIOContext *pb, MOVAtom atom)
R
Roberto Togni 已提交
1519
{
1520
    AVStream *st;
1521
    int ret;
1522 1523 1524 1525

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
R
Roberto Togni 已提交
1526

1527
    if ((uint64_t)atom.size > (1<<30))
1528
        return AVERROR_INVALIDDATA;
1529

1530 1531 1532
    if (st->codec->codec_id == AV_CODEC_ID_QDM2 ||
        st->codec->codec_id == AV_CODEC_ID_QDMC ||
        st->codec->codec_id == AV_CODEC_ID_SPEEX) {
1533
        // pass all frma atom to codec, needed at least for QDMC and QDM2
1534
        av_freep(&st->codec->extradata);
1535
        ret = ff_get_extradata(st->codec, pb, atom.size);
1536 1537
        if (ret < 0)
            return ret;
1538
    } else if (atom.size > 8) { /* to read frma, esds atoms */
1539 1540 1541 1542 1543 1544 1545 1546 1547 1548 1549 1550 1551 1552 1553 1554 1555 1556 1557 1558 1559 1560 1561 1562 1563 1564
        if (st->codec->codec_id == AV_CODEC_ID_ALAC && atom.size >= 24) {
            uint64_t buffer;
            ret = ffio_ensure_seekback(pb, 8);
            if (ret < 0)
                return ret;
            buffer = avio_rb64(pb);
            atom.size -= 8;
            if (  (buffer & 0xFFFFFFFF) == MKBETAG('f','r','m','a')
                && buffer >> 32 <= atom.size
                && buffer >> 32 >= 8) {
                avio_skip(pb, -8);
                atom.size += 8;
            } else if (!st->codec->extradata_size) {
#define ALAC_EXTRADATA_SIZE 36
                st->codec->extradata = av_mallocz(ALAC_EXTRADATA_SIZE + AV_INPUT_BUFFER_PADDING_SIZE);
                if (!st->codec->extradata)
                    return AVERROR(ENOMEM);
                st->codec->extradata_size = ALAC_EXTRADATA_SIZE;
                AV_WB32(st->codec->extradata    , ALAC_EXTRADATA_SIZE);
                AV_WB32(st->codec->extradata + 4, MKTAG('a','l','a','c'));
                AV_WB64(st->codec->extradata + 12, buffer);
                avio_read(pb, st->codec->extradata + 20, 16);
                avio_skip(pb, atom.size - 24);
                return 0;
            }
        }
1565 1566
        if ((ret = mov_read_default(c, pb, atom)) < 0)
            return ret;
1567
    } else
1568
        avio_skip(pb, atom.size);
R
Roberto Togni 已提交
1569 1570 1571
    return 0;
}

1572 1573 1574 1575
/**
 * This function reads atom content and puts data in extradata without tag
 * nor size unlike mov_read_extradata.
 */
1576
static int mov_read_glbl(MOVContext *c, AVIOContext *pb, MOVAtom atom)
1577
{
1578
    AVStream *st;
1579
    int ret;
1580 1581 1582 1583

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
1584

1585
    if ((uint64_t)atom.size > (1<<30))
1586
        return AVERROR_INVALIDDATA;
1587

1588
    if (atom.size >= 10) {
1589
        // Broken files created by legacy versions of libavformat will
1590 1591 1592 1593 1594 1595 1596
        // wrap a whole fiel atom inside of a glbl atom.
        unsigned size = avio_rb32(pb);
        unsigned type = avio_rl32(pb);
        avio_seek(pb, -8, SEEK_CUR);
        if (type == MKTAG('f','i','e','l') && size == atom.size)
            return mov_read_default(c, pb, atom);
    }
1597 1598 1599 1600
    if (st->codec->extradata_size > 1 && st->codec->extradata) {
        av_log(c, AV_LOG_WARNING, "ignoring multiple glbl\n");
        return 0;
    }
1601
    av_freep(&st->codec->extradata);
1602
    ret = ff_get_extradata(st->codec, pb, atom.size);
1603 1604
    if (ret < 0)
        return ret;
1605

1606 1607 1608
    return 0;
}

M
Martin Storsjö 已提交
1609 1610 1611 1612
static int mov_read_dvc1(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    AVStream *st;
    uint8_t profile_level;
1613
    int ret;
M
Martin Storsjö 已提交
1614 1615 1616 1617 1618 1619 1620 1621 1622

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];

    if (atom.size >= (1<<28) || atom.size < 7)
        return AVERROR_INVALIDDATA;

    profile_level = avio_r8(pb);
1623
    if ((profile_level & 0xf0) != 0xc0)
M
Martin Storsjö 已提交
1624 1625 1626
        return 0;

    avio_seek(pb, 6, SEEK_CUR);
1627
    av_freep(&st->codec->extradata);
1628
    ret = ff_get_extradata(st->codec, pb, atom.size - 7);
1629
    if (ret < 0)
1630
        return ret;
1631

M
Martin Storsjö 已提交
1632 1633 1634
    return 0;
}

M
Martin Storsjö 已提交
1635 1636 1637 1638 1639
/**
 * An strf atom is a BITMAPINFOHEADER struct. This struct is 40 bytes itself,
 * but can have extradata appended at the end after the 40 bytes belonging
 * to the struct.
 */
1640
static int mov_read_strf(MOVContext *c, AVIOContext *pb, MOVAtom atom)
M
Martin Storsjö 已提交
1641 1642
{
    AVStream *st;
1643
    int ret;
M
Martin Storsjö 已提交
1644 1645 1646 1647 1648 1649 1650

    if (c->fc->nb_streams < 1)
        return 0;
    if (atom.size <= 40)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];

1651
    if ((uint64_t)atom.size > (1<<30))
1652
        return AVERROR_INVALIDDATA;
M
Martin Storsjö 已提交
1653

1654
    avio_skip(pb, 40);
1655
    av_freep(&st->codec->extradata);
1656
    ret = ff_get_extradata(st->codec, pb, atom.size - 40);
1657 1658 1659
    if (ret < 0)
        return ret;

M
Martin Storsjö 已提交
1660 1661 1662
    return 0;
}

1663
static int mov_read_stco(MOVContext *c, AVIOContext *pb, MOVAtom atom)
1664
{
1665 1666
    AVStream *st;
    MOVStreamContext *sc;
1667
    unsigned int i, entries;
1668

1669 1670 1671 1672 1673
    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;

1674 1675
    avio_r8(pb); /* version */
    avio_rb24(pb); /* flags */
1676

1677
    entries = avio_rb32(pb);
1678

A
Alex Converse 已提交
1679 1680
    if (!entries)
        return 0;
1681

1682
    if (sc->chunk_offsets)
1683
        av_log(c->fc, AV_LOG_WARNING, "Duplicated STCO atom\n");
1684 1685
    av_free(sc->chunk_offsets);
    sc->chunk_count = 0;
1686
    sc->chunk_offsets = av_malloc_array(entries, sizeof(*sc->chunk_offsets));
1687
    if (!sc->chunk_offsets)
1688 1689 1690
        return AVERROR(ENOMEM);
    sc->chunk_count = entries;

1691
    if      (atom.type == MKTAG('s','t','c','o'))
1692
        for (i = 0; i < entries && !pb->eof_reached; i++)
1693
            sc->chunk_offsets[i] = avio_rb32(pb);
1694
    else if (atom.type == MKTAG('c','o','6','4'))
1695
        for (i = 0; i < entries && !pb->eof_reached; i++)
1696
            sc->chunk_offsets[i] = avio_rb64(pb);
1697
    else
1698
        return AVERROR_INVALIDDATA;
1699

1700 1701 1702 1703 1704
    sc->chunk_count = i;

    if (pb->eof_reached)
        return AVERROR_EOF;

1705 1706 1707
    return 0;
}

1708 1709 1710 1711
/**
 * Compute codec id for 'lpcm' tag.
 * See CoreAudioTypes and AudioStreamBasicDescription at Apple.
 */
1712
enum AVCodecID ff_mov_get_lpcm_codec_id(int bps, int flags)
1713
{
1714 1715 1716 1717 1718 1719
    /* lpcm flags:
     * 0x1 = float
     * 0x2 = big-endian
     * 0x4 = signed
     */
    return ff_get_pcm_codec_id(bps, flags & 1, flags & 2, flags & 4 ? -1 : 0);
1720 1721
}

1722 1723 1724 1725 1726 1727 1728 1729 1730 1731 1732 1733 1734 1735 1736 1737 1738 1739 1740
static int mov_codec_id(AVStream *st, uint32_t format)
{
    int id = ff_codec_get_id(ff_codec_movaudio_tags, format);

    if (id <= 0 &&
        ((format & 0xFFFF) == 'm' + ('s' << 8) ||
         (format & 0xFFFF) == 'T' + ('S' << 8)))
        id = ff_codec_get_id(ff_codec_wav_tags, av_bswap32(format) & 0xFFFF);

    if (st->codec->codec_type != AVMEDIA_TYPE_VIDEO && id > 0) {
        st->codec->codec_type = AVMEDIA_TYPE_AUDIO;
    } else if (st->codec->codec_type != AVMEDIA_TYPE_AUDIO &&
               /* skip old asf mpeg4 tag */
               format && format != MKTAG('m','p','4','s')) {
        id = ff_codec_get_id(ff_codec_movvideo_tags, format);
        if (id <= 0)
            id = ff_codec_get_id(ff_codec_bmp_tags, format);
        if (id > 0)
            st->codec->codec_type = AVMEDIA_TYPE_VIDEO;
1741 1742 1743
        else if (st->codec->codec_type == AVMEDIA_TYPE_DATA ||
                    (st->codec->codec_type == AVMEDIA_TYPE_SUBTITLE &&
                    st->codec->codec_id == AV_CODEC_ID_NONE)) {
1744 1745 1746 1747 1748 1749 1750 1751 1752 1753 1754
            id = ff_codec_get_id(ff_codec_movsubtitle_tags, format);
            if (id > 0)
                st->codec->codec_type = AVMEDIA_TYPE_SUBTITLE;
        }
    }

    st->codec->codec_tag = format;

    return id;
}

1755 1756 1757
static void mov_parse_stsd_video(MOVContext *c, AVIOContext *pb,
                                 AVStream *st, MOVStreamContext *sc)
{
1758
    uint8_t codec_name[32];
1759 1760 1761 1762 1763 1764
    int64_t stsd_start;
    unsigned int len;

    /* The first 16 bytes of the video sample description are already
     * read in ff_mov_read_stsd_entries() */
    stsd_start = avio_tell(pb) - 16;
1765 1766 1767 1768 1769 1770 1771 1772 1773 1774 1775 1776 1777 1778 1779 1780 1781 1782

    avio_rb16(pb); /* version */
    avio_rb16(pb); /* revision level */
    avio_rb32(pb); /* vendor */
    avio_rb32(pb); /* temporal quality */
    avio_rb32(pb); /* spatial quality */

    st->codec->width  = avio_rb16(pb); /* width */
    st->codec->height = avio_rb16(pb); /* height */

    avio_rb32(pb); /* horiz resolution */
    avio_rb32(pb); /* vert resolution */
    avio_rb32(pb); /* data size, always 0 */
    avio_rb16(pb); /* frames per samples */

    len = avio_r8(pb); /* codec name, pascal string */
    if (len > 31)
        len = 31;
1783
    mov_read_mac_string(c, pb, len, codec_name, sizeof(codec_name));
1784 1785
    if (len < 31)
        avio_skip(pb, 31 - len);
1786 1787 1788 1789

    if (codec_name[0])
        av_dict_set(&st->metadata, "encoder", codec_name, 0);

1790
    /* codec_tag YV12 triggers an UV swap in rawdec.c */
1791
    if (!memcmp(codec_name, "Planar Y'CbCr 8-bit 4:2:0", 25)) {
1792
        st->codec->codec_tag = MKTAG('I', '4', '2', '0');
1793 1794 1795
        st->codec->width &= ~1;
        st->codec->height &= ~1;
    }
1796 1797
    /* Flash Media Server uses tag H263 with Sorenson Spark */
    if (st->codec->codec_tag == MKTAG('H','2','6','3') &&
1798
        !memcmp(codec_name, "Sorenson H263", 13))
1799 1800 1801
        st->codec->codec_id = AV_CODEC_ID_FLV1;

    st->codec->bits_per_coded_sample = avio_rb16(pb); /* depth */
1802 1803 1804 1805 1806

    avio_seek(pb, stsd_start, SEEK_SET);

    if (ff_get_qtpalette(st->codec->codec_id, pb, sc->palette)) {
        st->codec->bits_per_coded_sample &= 0x1F;
1807 1808 1809 1810
        sc->has_palette = 1;
    }
}

1811 1812 1813 1814
static void mov_parse_stsd_audio(MOVContext *c, AVIOContext *pb,
                                 AVStream *st, MOVStreamContext *sc)
{
    int bits_per_sample, flags;
1815
    uint16_t version = avio_rb16(pb);
1816
    AVDictionaryEntry *compatible_brands = av_dict_get(c->fc->metadata, "compatible_brands", NULL, AV_DICT_MATCH_CASE);
1817 1818 1819 1820 1821 1822

    avio_rb16(pb); /* revision level */
    avio_rb32(pb); /* vendor */

    st->codec->channels              = avio_rb16(pb); /* channel count */
    st->codec->bits_per_coded_sample = avio_rb16(pb); /* sample size */
1823
    av_log(c->fc, AV_LOG_TRACE, "audio channels %d\n", st->codec->channels);
1824 1825 1826 1827 1828 1829 1830

    sc->audio_cid = avio_rb16(pb);
    avio_rb16(pb); /* packet size = 0 */

    st->codec->sample_rate = ((avio_rb32(pb) >> 16));

    // Read QT version 1 fields. In version 0 these do not exist.
1831
    av_log(c->fc, AV_LOG_TRACE, "version =%d, isom =%d\n", version, c->isom);
1832 1833 1834
    if (!c->isom ||
        (compatible_brands && strstr(compatible_brands->value, "qt  "))) {

1835 1836 1837 1838 1839 1840 1841 1842 1843 1844 1845 1846 1847 1848 1849 1850 1851 1852 1853 1854
        if (version == 1) {
            sc->samples_per_frame = avio_rb32(pb);
            avio_rb32(pb); /* bytes per packet */
            sc->bytes_per_frame = avio_rb32(pb);
            avio_rb32(pb); /* bytes per sample */
        } else if (version == 2) {
            avio_rb32(pb); /* sizeof struct only */
            st->codec->sample_rate = av_int2double(avio_rb64(pb));
            st->codec->channels    = avio_rb32(pb);
            avio_rb32(pb); /* always 0x7F000000 */
            st->codec->bits_per_coded_sample = avio_rb32(pb);

            flags = avio_rb32(pb); /* lpcm format specific flag */
            sc->bytes_per_frame   = avio_rb32(pb);
            sc->samples_per_frame = avio_rb32(pb);
            if (st->codec->codec_tag == MKTAG('l','p','c','m'))
                st->codec->codec_id =
                    ff_mov_get_lpcm_codec_id(st->codec->bits_per_coded_sample,
                                             flags);
        }
1855 1856 1857 1858 1859 1860 1861 1862 1863
        if (version == 0 || (version == 1 && sc->audio_cid != -2)) {
            /* can't correctly handle variable sized packet as audio unit */
            switch (st->codec->codec_id) {
            case AV_CODEC_ID_MP2:
            case AV_CODEC_ID_MP3:
                st->need_parsing = AVSTREAM_PARSE_FULL;
                break;
            }
        }
1864 1865
    }

1866
    if (sc->format == 0) {
1867 1868 1869 1870 1871 1872
        if (st->codec->bits_per_coded_sample == 8)
            st->codec->codec_id = mov_codec_id(st, MKTAG('r','a','w',' '));
        else if (st->codec->bits_per_coded_sample == 16)
            st->codec->codec_id = mov_codec_id(st, MKTAG('t','w','o','s'));
    }

1873 1874 1875 1876 1877 1878 1879 1880 1881 1882 1883 1884 1885 1886
    switch (st->codec->codec_id) {
    case AV_CODEC_ID_PCM_S8:
    case AV_CODEC_ID_PCM_U8:
        if (st->codec->bits_per_coded_sample == 16)
            st->codec->codec_id = AV_CODEC_ID_PCM_S16BE;
        break;
    case AV_CODEC_ID_PCM_S16LE:
    case AV_CODEC_ID_PCM_S16BE:
        if (st->codec->bits_per_coded_sample == 8)
            st->codec->codec_id = AV_CODEC_ID_PCM_S8;
        else if (st->codec->bits_per_coded_sample == 24)
            st->codec->codec_id =
                st->codec->codec_id == AV_CODEC_ID_PCM_S16BE ?
                AV_CODEC_ID_PCM_S24BE : AV_CODEC_ID_PCM_S24LE;
1887 1888 1889 1890
        else if (st->codec->bits_per_coded_sample == 32)
             st->codec->codec_id =
                st->codec->codec_id == AV_CODEC_ID_PCM_S16BE ?
                AV_CODEC_ID_PCM_S32BE : AV_CODEC_ID_PCM_S32LE;
1891 1892 1893 1894 1895 1896 1897 1898 1899 1900 1901 1902 1903 1904 1905 1906 1907 1908 1909 1910 1911 1912 1913 1914 1915 1916 1917 1918 1919
        break;
    /* set values for old format before stsd version 1 appeared */
    case AV_CODEC_ID_MACE3:
        sc->samples_per_frame = 6;
        sc->bytes_per_frame   = 2 * st->codec->channels;
        break;
    case AV_CODEC_ID_MACE6:
        sc->samples_per_frame = 6;
        sc->bytes_per_frame   = 1 * st->codec->channels;
        break;
    case AV_CODEC_ID_ADPCM_IMA_QT:
        sc->samples_per_frame = 64;
        sc->bytes_per_frame   = 34 * st->codec->channels;
        break;
    case AV_CODEC_ID_GSM:
        sc->samples_per_frame = 160;
        sc->bytes_per_frame   = 33;
        break;
    default:
        break;
    }

    bits_per_sample = av_get_bits_per_sample(st->codec->codec_id);
    if (bits_per_sample) {
        st->codec->bits_per_coded_sample = bits_per_sample;
        sc->sample_size = (bits_per_sample >> 3) * st->codec->channels;
    }
}

1920 1921
static void mov_parse_stsd_subtitle(MOVContext *c, AVIOContext *pb,
                                    AVStream *st, MOVStreamContext *sc,
1922
                                    int64_t size)
1923 1924 1925 1926 1927 1928 1929 1930 1931 1932 1933
{
    // ttxt stsd contains display flags, justification, background
    // color, fonts, and default styles, so fake an atom to read it
    MOVAtom fake_atom = { .size = size };
    // mp4s contains a regular esds atom
    if (st->codec->codec_tag != AV_RL32("mp4s"))
        mov_read_glbl(c, pb, fake_atom);
    st->codec->width  = sc->width;
    st->codec->height = sc->height;
}

1934 1935 1936 1937 1938 1939 1940 1941 1942
static uint32_t yuv_to_rgba(uint32_t ycbcr)
{
    uint8_t r, g, b;
    int y, cb, cr;

    y  = (ycbcr >> 16) & 0xFF;
    cr = (ycbcr >> 8)  & 0xFF;
    cb =  ycbcr        & 0xFF;

1943 1944 1945
    b = av_clip_uint8((1164 * (y - 16)                     + 2018 * (cb - 128)) / 1000);
    g = av_clip_uint8((1164 * (y - 16) -  813 * (cr - 128) -  391 * (cb - 128)) / 1000);
    r = av_clip_uint8((1164 * (y - 16) + 1596 * (cr - 128)                    ) / 1000);
1946 1947 1948 1949 1950 1951 1952 1953 1954 1955 1956 1957 1958 1959 1960 1961 1962 1963 1964 1965 1966 1967

    return (r << 16) | (g << 8) | b;
}

static int mov_rewrite_dvd_sub_extradata(AVStream *st)
{
    char buf[256] = {0};
    uint8_t *src = st->codec->extradata;
    int i;

    if (st->codec->extradata_size != 64)
        return 0;

    if (st->codec->width > 0 &&  st->codec->height > 0)
        snprintf(buf, sizeof(buf), "size: %dx%d\n",
                 st->codec->width, st->codec->height);
    av_strlcat(buf, "palette: ", sizeof(buf));

    for (i = 0; i < 16; i++) {
        uint32_t yuv = AV_RB32(src + i * 4);
        uint32_t rgba = yuv_to_rgba(yuv);

1968
        av_strlcatf(buf, sizeof(buf), "%06"PRIx32"%s", rgba, i != 15 ? ", " : "");
1969 1970 1971 1972 1973 1974 1975
    }

    if (av_strlcat(buf, "\n", sizeof(buf)) >= sizeof(buf))
        return 0;

    av_freep(&st->codec->extradata);
    st->codec->extradata_size = 0;
1976
    st->codec->extradata = av_mallocz(strlen(buf) + AV_INPUT_BUFFER_PADDING_SIZE);
1977 1978 1979 1980 1981 1982 1983 1984
    if (!st->codec->extradata)
        return AVERROR(ENOMEM);
    st->codec->extradata_size = strlen(buf);
    memcpy(st->codec->extradata, buf, st->codec->extradata_size);

    return 0;
}

L
Luca Barbato 已提交
1985 1986
static int mov_parse_stsd_data(MOVContext *c, AVIOContext *pb,
                                AVStream *st, MOVStreamContext *sc,
1987
                                int64_t size)
L
Luca Barbato 已提交
1988
{
1989 1990
    int ret;

L
Luca Barbato 已提交
1991
    if (st->codec->codec_tag == MKTAG('t','m','c','d')) {
1992
        if ((int)size != size)
L
Luca Barbato 已提交
1993
            return AVERROR(ENOMEM);
1994 1995

        ret = ff_get_extradata(st->codec, pb, size);
1996 1997
        if (ret < 0)
            return ret;
1998 1999 2000 2001 2002 2003
        if (size > 16) {
            MOVStreamContext *tmcd_ctx = st->priv_data;
            int val;
            val = AV_RB32(st->codec->extradata + 4);
            tmcd_ctx->tmcd_flags = val;
            if (val & 1)
2004
                st->codec->flags2 |= AV_CODEC_FLAG2_DROP_FRAME_TIMECODE;
2005 2006
            st->codec->time_base.den = st->codec->extradata[16]; /* number of frame */
            st->codec->time_base.num = 1;
2007 2008 2009 2010 2011 2012 2013
            /* adjust for per frame dur in counter mode */
            if (tmcd_ctx->tmcd_flags & 0x0008) {
                int timescale = AV_RB32(st->codec->extradata + 8);
                int framedur = AV_RB32(st->codec->extradata + 12);
                st->codec->time_base.den *= timescale;
                st->codec->time_base.num *= framedur;
            }
2014 2015 2016 2017 2018 2019 2020 2021 2022 2023 2024 2025 2026 2027 2028 2029 2030 2031 2032 2033
            if (size > 30) {
                uint32_t len = AV_RB32(st->codec->extradata + 18); /* name atom length */
                uint32_t format = AV_RB32(st->codec->extradata + 22);
                if (format == AV_RB32("name") && (int64_t)size >= (int64_t)len + 18) {
                    uint16_t str_size = AV_RB16(st->codec->extradata + 26); /* string length */
                    if (str_size > 0 && size >= (int)str_size + 26) {
                        char *reel_name = av_malloc(str_size + 1);
                        if (!reel_name)
                            return AVERROR(ENOMEM);
                        memcpy(reel_name, st->codec->extradata + 30, str_size);
                        reel_name[str_size] = 0; /* Add null terminator */
                        /* don't add reel_name if emtpy string */
                        if (*reel_name == 0) {
                            av_free(reel_name);
                        } else {
                            av_dict_set(&st->metadata, "reel_name", reel_name,  AV_DICT_DONT_STRDUP_VAL);
                        }
                    }
                }
            }
2034
        }
L
Luca Barbato 已提交
2035 2036 2037 2038 2039 2040 2041
    } else {
        /* other codec type, just skip (rtp, mp4s ...) */
        avio_skip(pb, size);
    }
    return 0;
}

2042 2043 2044 2045 2046 2047 2048 2049 2050 2051 2052
static int mov_finalize_stsd_codec(MOVContext *c, AVIOContext *pb,
                                   AVStream *st, MOVStreamContext *sc)
{
    if (st->codec->codec_type == AVMEDIA_TYPE_AUDIO &&
        !st->codec->sample_rate && sc->time_scale > 1)
        st->codec->sample_rate = sc->time_scale;

    /* special codec parameters handling */
    switch (st->codec->codec_id) {
#if CONFIG_DV_DEMUXER
    case AV_CODEC_ID_DVAUDIO:
V
Vittorio Giovara 已提交
2053 2054 2055 2056 2057
        c->dv_fctx = avformat_alloc_context();
        if (!c->dv_fctx) {
            av_log(c->fc, AV_LOG_ERROR, "dv demux context alloc error\n");
            return AVERROR(ENOMEM);
        }
2058 2059 2060 2061 2062 2063 2064 2065 2066 2067 2068 2069 2070 2071 2072
        c->dv_demux = avpriv_dv_init_demux(c->dv_fctx);
        if (!c->dv_demux) {
            av_log(c->fc, AV_LOG_ERROR, "dv demux context init error\n");
            return AVERROR(ENOMEM);
        }
        sc->dv_audio_container = 1;
        st->codec->codec_id    = AV_CODEC_ID_PCM_S16LE;
        break;
#endif
    /* no ifdef since parameters are always those */
    case AV_CODEC_ID_QCELP:
        st->codec->channels = 1;
        // force sample rate for qcelp when not stored in mov
        if (st->codec->codec_tag != MKTAG('Q','c','l','p'))
            st->codec->sample_rate = 8000;
2073 2074 2075 2076
        // FIXME: Why is the following needed for some files?
        sc->samples_per_frame = 160;
        if (!sc->bytes_per_frame)
            sc->bytes_per_frame = 35;
2077 2078 2079 2080 2081 2082 2083 2084 2085 2086 2087 2088 2089 2090 2091 2092 2093 2094 2095
        break;
    case AV_CODEC_ID_AMR_NB:
        st->codec->channels    = 1;
        /* force sample rate for amr, stsd in 3gp does not store sample rate */
        st->codec->sample_rate = 8000;
        break;
    case AV_CODEC_ID_AMR_WB:
        st->codec->channels    = 1;
        st->codec->sample_rate = 16000;
        break;
    case AV_CODEC_ID_MP2:
    case AV_CODEC_ID_MP3:
        /* force type after stsd for m1a hdlr */
        st->codec->codec_type = AVMEDIA_TYPE_AUDIO;
        break;
    case AV_CODEC_ID_GSM:
    case AV_CODEC_ID_ADPCM_MS:
    case AV_CODEC_ID_ADPCM_IMA_WAV:
    case AV_CODEC_ID_ILBC:
2096 2097 2098
    case AV_CODEC_ID_MACE3:
    case AV_CODEC_ID_MACE6:
    case AV_CODEC_ID_QDM2:
2099 2100 2101 2102 2103 2104 2105 2106
        st->codec->block_align = sc->bytes_per_frame;
        break;
    case AV_CODEC_ID_ALAC:
        if (st->codec->extradata_size == 36) {
            st->codec->channels    = AV_RB8 (st->codec->extradata + 21);
            st->codec->sample_rate = AV_RB32(st->codec->extradata + 32);
        }
        break;
2107
    case AV_CODEC_ID_AC3:
2108
    case AV_CODEC_ID_EAC3:
2109
    case AV_CODEC_ID_MPEG1VIDEO:
2110 2111 2112 2113 2114 2115 2116 2117 2118
    case AV_CODEC_ID_VC1:
        st->need_parsing = AVSTREAM_PARSE_FULL;
        break;
    default:
        break;
    }
    return 0;
}

2119 2120
static int mov_skip_multiple_stsd(MOVContext *c, AVIOContext *pb,
                                  int codec_tag, int format,
2121
                                  int64_t size)
2122 2123 2124 2125 2126 2127
{
    int video_codec_id = ff_codec_get_id(ff_codec_movvideo_tags, format);

    if (codec_tag &&
         (codec_tag != format &&
          (c->fc->video_codec_id ? video_codec_id != c->fc->video_codec_id
2128
                                 : codec_tag != MKTAG('j','p','e','g')))) {
2129 2130 2131 2132 2133 2134 2135 2136
        /* Multiple fourcc, we skip JPEG. This is not correct, we should
         * export it as a separate AVStream but this needs a few changes
         * in the MOV demuxer, patch welcome. */

        av_log(c->fc, AV_LOG_WARNING, "multiple fourcc not supported\n");
        avio_skip(pb, size);
        return 1;
    }
Y
Yusuke Nakamura 已提交
2137 2138 2139 2140
    if ( codec_tag == AV_RL32("avc1") ||
         codec_tag == AV_RL32("hvc1") ||
         codec_tag == AV_RL32("hev1")
    )
2141
        av_log(c->fc, AV_LOG_WARNING, "Concatenated H.264 or H.265 might not play correctly.\n");
2142 2143 2144 2145

    return 0;
}

2146
int ff_mov_read_stsd_entries(MOVContext *c, AVIOContext *pb, int entries)
2147
{
2148 2149
    AVStream *st;
    MOVStreamContext *sc;
2150
    int pseudo_stream_id;
2151

2152 2153 2154 2155 2156
    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;

2157 2158 2159
    for (pseudo_stream_id = 0;
         pseudo_stream_id < entries && !pb->eof_reached;
         pseudo_stream_id++) {
2160
        //Parsing Sample description table
2161
        enum AVCodecID id;
L
Luca Barbato 已提交
2162
        int ret, dref_id = 1;
2163
        MOVAtom a = { AV_RL32("stsd") };
2164
        int64_t start_pos = avio_tell(pb);
2165
        int64_t size    = avio_rb32(pb); /* size */
2166
        uint32_t format = avio_rl32(pb); /* data format */
2167

2168
        if (size >= 16) {
2169 2170 2171
            avio_rb32(pb); /* reserved */
            avio_rb16(pb); /* reserved */
            dref_id = avio_rb16(pb);
2172
        }else if (size <= 7){
M
Michael Niedermayer 已提交
2173
            av_log(c->fc, AV_LOG_ERROR, "invalid size %"PRId64" in stsd\n", size);
2174
            return AVERROR_INVALIDDATA;
2175
        }
2176

2177 2178
        if (mov_skip_multiple_stsd(c, pb, st->codec->codec_tag, format,
                                   size - (avio_tell(pb) - start_pos)))
2179
            continue;
2180

2181
        sc->pseudo_stream_id = st->codec->codec_tag ? -1 : pseudo_stream_id;
2182
        sc->dref_id= dref_id;
2183
        sc->format = format;
2184

2185
        id = mov_codec_id(st, format);
2186

2187
        av_log(c->fc, AV_LOG_TRACE,
2188
               "size=%"PRId64" 4CC= %c%c%c%c/0x%08x codec_type=%d\n", size,
2189
                (format >> 0) & 0xff, (format >> 8) & 0xff, (format >> 16) & 0xff,
2190
                (format >> 24) & 0xff, format, st->codec->codec_type);
2191

2192
        if (st->codec->codec_type==AVMEDIA_TYPE_VIDEO) {
2193
            st->codec->codec_id = id;
2194
            mov_parse_stsd_video(c, pb, st, sc);
2195
        } else if (st->codec->codec_type==AVMEDIA_TYPE_AUDIO) {
2196
            st->codec->codec_id = id;
2197
            mov_parse_stsd_audio(c, pb, st, sc);
2198
        } else if (st->codec->codec_type==AVMEDIA_TYPE_SUBTITLE){
2199 2200 2201
            st->codec->codec_id = id;
            mov_parse_stsd_subtitle(c, pb, st, sc,
                                    size - (avio_tell(pb) - start_pos));
2202
        } else {
L
Luca Barbato 已提交
2203 2204 2205 2206
            ret = mov_parse_stsd_data(c, pb, st, sc,
                                      size - (avio_tell(pb) - start_pos));
            if (ret < 0)
                return ret;
2207
        }
Y
Yusuke Nakamura 已提交
2208
        /* this will read extra atoms at the end (wave, alac, damr, avcC, hvcC, SMI ...) */
2209
        a.size = size - (avio_tell(pb) - start_pos);
2210
        if (a.size > 8) {
2211 2212
            if ((ret = mov_read_default(c, pb, a)) < 0)
                return ret;
2213
        } else if (a.size > 0)
2214
            avio_skip(pb, a.size);
2215
    }
2216

2217 2218 2219
    if (pb->eof_reached)
        return AVERROR_EOF;

2220
    return mov_finalize_stsd_codec(c, pb, st, sc);
2221 2222
}

2223
static int mov_read_stsd(MOVContext *c, AVIOContext *pb, MOVAtom atom)
2224 2225 2226
{
    int entries;

2227 2228 2229
    avio_r8(pb); /* version */
    avio_rb24(pb); /* flags */
    entries = avio_rb32(pb);
2230 2231 2232 2233

    return ff_mov_read_stsd_entries(c, pb, entries);
}

2234
static int mov_read_stsc(MOVContext *c, AVIOContext *pb, MOVAtom atom)
2235
{
2236 2237
    AVStream *st;
    MOVStreamContext *sc;
2238
    unsigned int i, entries;
2239

2240 2241 2242 2243 2244
    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;

2245 2246
    avio_r8(pb); /* version */
    avio_rb24(pb); /* flags */
2247

2248
    entries = avio_rb32(pb);
2249

2250
    av_log(c->fc, AV_LOG_TRACE, "track[%i].stsc.entries = %i\n", c->fc->nb_streams-1, entries);
2251

A
Alex Converse 已提交
2252 2253
    if (!entries)
        return 0;
2254
    if (sc->stsc_data)
2255
        av_log(c->fc, AV_LOG_WARNING, "Duplicated STSC atom\n");
2256 2257
    av_free(sc->stsc_data);
    sc->stsc_count = 0;
2258
    sc->stsc_data = av_malloc_array(entries, sizeof(*sc->stsc_data));
2259
    if (!sc->stsc_data)
2260 2261
        return AVERROR(ENOMEM);

2262
    for (i = 0; i < entries && !pb->eof_reached; i++) {
2263 2264 2265
        sc->stsc_data[i].first = avio_rb32(pb);
        sc->stsc_data[i].count = avio_rb32(pb);
        sc->stsc_data[i].id = avio_rb32(pb);
2266
    }
2267 2268 2269 2270 2271 2272

    sc->stsc_count = i;

    if (pb->eof_reached)
        return AVERROR_EOF;

2273 2274 2275
    return 0;
}

2276
static int mov_read_stps(MOVContext *c, AVIOContext *pb, MOVAtom atom)
2277 2278 2279 2280 2281 2282 2283 2284 2285 2286
{
    AVStream *st;
    MOVStreamContext *sc;
    unsigned i, entries;

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;

2287
    avio_rb32(pb); // version + flags
2288

2289
    entries = avio_rb32(pb);
2290
    if (sc->stps_data)
2291
        av_log(c->fc, AV_LOG_WARNING, "Duplicated STPS atom\n");
2292 2293 2294
    av_free(sc->stps_data);
    sc->stps_count = 0;
    sc->stps_data = av_malloc_array(entries, sizeof(*sc->stps_data));
2295 2296 2297
    if (!sc->stps_data)
        return AVERROR(ENOMEM);

2298
    for (i = 0; i < entries && !pb->eof_reached; i++) {
2299
        sc->stps_data[i] = avio_rb32(pb);
2300
        //av_log(c->fc, AV_LOG_TRACE, "stps %d\n", sc->stps_data[i]);
2301 2302
    }

2303 2304 2305 2306 2307
    sc->stps_count = i;

    if (pb->eof_reached)
        return AVERROR_EOF;

2308 2309 2310
    return 0;
}

2311
static int mov_read_stss(MOVContext *c, AVIOContext *pb, MOVAtom atom)
2312
{
2313 2314
    AVStream *st;
    MOVStreamContext *sc;
2315
    unsigned int i, entries;
2316

2317 2318 2319 2320 2321
    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;

2322 2323
    avio_r8(pb); /* version */
    avio_rb24(pb); /* flags */
2324

2325
    entries = avio_rb32(pb);
2326

2327
    av_log(c->fc, AV_LOG_TRACE, "keyframe_count = %d\n", entries);
2328

2329
    if (!entries)
2330 2331
    {
        sc->keyframe_absent = 1;
2332
        if (!st->need_parsing && st->codec->codec_type == AVMEDIA_TYPE_VIDEO)
2333
            st->need_parsing = AVSTREAM_PARSE_HEADERS;
2334
        return 0;
2335
    }
2336
    if (sc->keyframes)
2337
        av_log(c->fc, AV_LOG_WARNING, "Duplicated STSS atom\n");
2338
    if (entries >= UINT_MAX / sizeof(int))
2339
        return AVERROR_INVALIDDATA;
2340
    av_freep(&sc->keyframes);
2341 2342
    sc->keyframe_count = 0;
    sc->keyframes = av_malloc_array(entries, sizeof(*sc->keyframes));
2343
    if (!sc->keyframes)
2344 2345
        return AVERROR(ENOMEM);

2346
    for (i = 0; i < entries && !pb->eof_reached; i++) {
2347
        sc->keyframes[i] = avio_rb32(pb);
2348
        //av_log(c->fc, AV_LOG_TRACE, "keyframes[]=%d\n", sc->keyframes[i]);
2349
    }
2350 2351 2352 2353 2354 2355

    sc->keyframe_count = i;

    if (pb->eof_reached)
        return AVERROR_EOF;

2356 2357 2358
    return 0;
}

2359
static int mov_read_stsz(MOVContext *c, AVIOContext *pb, MOVAtom atom)
2360
{
2361 2362
    AVStream *st;
    MOVStreamContext *sc;
2363 2364 2365
    unsigned int i, entries, sample_size, field_size, num_bytes;
    GetBitContext gb;
    unsigned char* buf;
2366
    int ret;
2367

2368 2369 2370 2371 2372
    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;

2373 2374
    avio_r8(pb); /* version */
    avio_rb24(pb); /* flags */
2375

2376
    if (atom.type == MKTAG('s','t','s','z')) {
2377
        sample_size = avio_rb32(pb);
2378 2379
        if (!sc->sample_size) /* do not overwrite value computed in stsd */
            sc->sample_size = sample_size;
2380
        sc->stsz_sample_size = sample_size;
2381
        field_size = 32;
2382 2383
    } else {
        sample_size = 0;
2384 2385
        avio_rb24(pb); /* reserved */
        field_size = avio_r8(pb);
2386
    }
2387
    entries = avio_rb32(pb);
2388

2389
    av_log(c->fc, AV_LOG_TRACE, "sample_size = %d sample_count = %d\n", sc->sample_size, entries);
2390

2391
    sc->sample_count = entries;
2392 2393 2394
    if (sample_size)
        return 0;

2395 2396
    if (field_size != 4 && field_size != 8 && field_size != 16 && field_size != 32) {
        av_log(c->fc, AV_LOG_ERROR, "Invalid sample field size %d\n", field_size);
2397
        return AVERROR_INVALIDDATA;
2398 2399
    }

A
Alex Converse 已提交
2400 2401
    if (!entries)
        return 0;
2402
    if (entries >= (UINT_MAX - 4) / field_size)
2403
        return AVERROR_INVALIDDATA;
2404
    if (sc->sample_sizes)
2405
        av_log(c->fc, AV_LOG_WARNING, "Duplicated STSZ atom\n");
2406 2407 2408
    av_free(sc->sample_sizes);
    sc->sample_count = 0;
    sc->sample_sizes = av_malloc_array(entries, sizeof(*sc->sample_sizes));
2409
    if (!sc->sample_sizes)
2410 2411
        return AVERROR(ENOMEM);

2412 2413
    num_bytes = (entries*field_size+4)>>3;

2414
    buf = av_malloc(num_bytes+AV_INPUT_BUFFER_PADDING_SIZE);
2415 2416 2417 2418 2419
    if (!buf) {
        av_freep(&sc->sample_sizes);
        return AVERROR(ENOMEM);
    }

2420 2421
    ret = ffio_read_size(pb, buf, num_bytes);
    if (ret < 0) {
2422 2423
        av_freep(&sc->sample_sizes);
        av_free(buf);
2424
        return ret;
2425 2426 2427 2428
    }

    init_get_bits(&gb, buf, 8*num_bytes);

2429
    for (i = 0; i < entries && !pb->eof_reached; i++) {
2430
        sc->sample_sizes[i] = get_bits_long(&gb, field_size);
2431 2432
        sc->data_size += sc->sample_sizes[i];
    }
2433

2434 2435
    sc->sample_count = i;

A
Andreas Cadhalpun 已提交
2436 2437
    av_free(buf);

2438 2439 2440
    if (pb->eof_reached)
        return AVERROR_EOF;

2441 2442 2443
    return 0;
}

2444
static int mov_read_stts(MOVContext *c, AVIOContext *pb, MOVAtom atom)
2445
{
2446 2447
    AVStream *st;
    MOVStreamContext *sc;
2448
    unsigned int i, entries;
2449 2450
    int64_t duration=0;
    int64_t total_sample_count=0;
2451

2452 2453 2454 2455 2456
    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;

2457 2458 2459
    avio_r8(pb); /* version */
    avio_rb24(pb); /* flags */
    entries = avio_rb32(pb);
2460

2461
    av_log(c->fc, AV_LOG_TRACE, "track[%i].stts.entries = %i\n",
2462
            c->fc->nb_streams-1, entries);
2463

2464
    if (sc->stts_data)
2465
        av_log(c->fc, AV_LOG_WARNING, "Duplicated STTS atom\n");
2466
    av_free(sc->stts_data);
2467 2468
    sc->stts_count = 0;
    sc->stts_data = av_malloc_array(entries, sizeof(*sc->stts_data));
2469
    if (!sc->stts_data)
2470
        return AVERROR(ENOMEM);
2471

2472
    for (i = 0; i < entries && !pb->eof_reached; i++) {
M
cleanup  
Michael Niedermayer 已提交
2473 2474
        int sample_duration;
        int sample_count;
2475

2476 2477
        sample_count=avio_rb32(pb);
        sample_duration = avio_rb32(pb);
2478

2479 2480 2481 2482
        if (sample_count < 0) {
            av_log(c->fc, AV_LOG_ERROR, "Invalid sample_count=%d\n", sample_count);
            return AVERROR_INVALIDDATA;
        }
2483 2484 2485
        sc->stts_data[i].count= sample_count;
        sc->stts_data[i].duration= sample_duration;

2486
        av_log(c->fc, AV_LOG_TRACE, "sample_count=%d, sample_duration=%d\n",
2487
                sample_count, sample_duration);
2488

2489 2490 2491 2492 2493 2494
        if (   i+1 == entries
            && i
            && sample_count == 1
            && total_sample_count > 100
            && sample_duration/10 > duration / total_sample_count)
            sample_duration = duration / total_sample_count;
B
Baptiste Coudurier 已提交
2495
        duration+=(int64_t)sample_duration*sample_count;
2496 2497 2498
        total_sample_count+=sample_count;
    }

2499 2500
    sc->stts_count = i;

2501 2502 2503
    sc->duration_for_fps  += duration;
    sc->nb_frames_for_fps += total_sample_count;

2504 2505 2506
    if (pb->eof_reached)
        return AVERROR_EOF;

2507
    st->nb_frames= total_sample_count;
2508
    if (duration)
2509
        st->duration= duration;
2510
    sc->track_end = duration;
2511 2512 2513
    return 0;
}

2514 2515 2516
static void mov_update_dts_shift(MOVStreamContext *sc, int duration)
{
    if (duration < 0) {
2517 2518 2519 2520
        if (duration == INT_MIN) {
            av_log(NULL, AV_LOG_WARNING, "mov_update_dts_shift(): dts_shift set to %d\n", INT_MAX);
            duration++;
        }
2521 2522 2523 2524
        sc->dts_shift = FFMAX(sc->dts_shift, -duration);
    }
}

2525
static int mov_read_ctts(MOVContext *c, AVIOContext *pb, MOVAtom atom)
M
Michael Niedermayer 已提交
2526
{
2527 2528
    AVStream *st;
    MOVStreamContext *sc;
M
Michael Niedermayer 已提交
2529 2530
    unsigned int i, entries;

2531 2532 2533 2534 2535
    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;

2536 2537 2538
    avio_r8(pb); /* version */
    avio_rb24(pb); /* flags */
    entries = avio_rb32(pb);
2539

2540
    av_log(c->fc, AV_LOG_TRACE, "track[%i].ctts.entries = %i\n", c->fc->nb_streams-1, entries);
2541

A
Alex Converse 已提交
2542 2543
    if (!entries)
        return 0;
2544
    if (entries >= UINT_MAX / sizeof(*sc->ctts_data))
2545
        return AVERROR_INVALIDDATA;
A
Andreas Cadhalpun 已提交
2546
    av_freep(&sc->ctts_data);
L
Luca Barbato 已提交
2547
    sc->ctts_data = av_realloc(NULL, entries * sizeof(*sc->ctts_data));
2548
    if (!sc->ctts_data)
2549
        return AVERROR(ENOMEM);
2550

2551
    for (i = 0; i < entries && !pb->eof_reached; i++) {
2552 2553
        int count    =avio_rb32(pb);
        int duration =avio_rb32(pb);
2554 2555 2556

        sc->ctts_data[i].count   = count;
        sc->ctts_data[i].duration= duration;
M
Michael Niedermayer 已提交
2557

2558
        av_log(c->fc, AV_LOG_TRACE, "count=%d, duration=%d\n",
2559 2560
                count, duration);

2561
        if (FFNABS(duration) < -(1<<28) && i+2<entries) {
M
Michael Niedermayer 已提交
2562 2563 2564 2565 2566 2567
            av_log(c->fc, AV_LOG_WARNING, "CTTS invalid\n");
            av_freep(&sc->ctts_data);
            sc->ctts_count = 0;
            return 0;
        }

2568 2569
        if (i+2<entries)
            mov_update_dts_shift(sc, duration);
M
Michael Niedermayer 已提交
2570
    }
2571

2572 2573 2574 2575 2576
    sc->ctts_count = i;

    if (pb->eof_reached)
        return AVERROR_EOF;

2577
    av_log(c->fc, AV_LOG_TRACE, "dts shift %d\n", sc->dts_shift);
2578

M
Michael Niedermayer 已提交
2579 2580 2581
    return 0;
}

2582 2583 2584 2585 2586 2587 2588 2589 2590 2591 2592 2593 2594 2595 2596 2597 2598 2599 2600 2601 2602 2603 2604 2605
static int mov_read_sbgp(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    AVStream *st;
    MOVStreamContext *sc;
    unsigned int i, entries;
    uint8_t version;
    uint32_t grouping_type;

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;

    version = avio_r8(pb); /* version */
    avio_rb24(pb); /* flags */
    grouping_type = avio_rl32(pb);
    if (grouping_type != MKTAG( 'r','a','p',' '))
        return 0; /* only support 'rap ' grouping */
    if (version == 1)
        avio_rb32(pb); /* grouping_type_parameter */

    entries = avio_rb32(pb);
    if (!entries)
        return 0;
2606
    if (sc->rap_group)
2607
        av_log(c->fc, AV_LOG_WARNING, "Duplicated SBGP atom\n");
2608 2609 2610
    av_free(sc->rap_group);
    sc->rap_group_count = 0;
    sc->rap_group = av_malloc_array(entries, sizeof(*sc->rap_group));
2611 2612 2613 2614 2615 2616 2617 2618 2619 2620 2621 2622 2623
    if (!sc->rap_group)
        return AVERROR(ENOMEM);

    for (i = 0; i < entries && !pb->eof_reached; i++) {
        sc->rap_group[i].count = avio_rb32(pb); /* sample_count */
        sc->rap_group[i].index = avio_rb32(pb); /* group_description_index */
    }

    sc->rap_group_count = i;

    return pb->eof_reached ? AVERROR_EOF : 0;
}

2624 2625 2626
static void mov_build_index(MOVContext *mov, AVStream *st)
{
    MOVStreamContext *sc = st->priv_data;
2627
    int64_t current_offset;
2628 2629 2630 2631
    int64_t current_dts = 0;
    unsigned int stts_index = 0;
    unsigned int stsc_index = 0;
    unsigned int stss_index = 0;
2632
    unsigned int stps_index = 0;
2633
    unsigned int i, j;
2634
    uint64_t stream_size = 0;
2635

2636 2637 2638 2639 2640 2641 2642 2643 2644 2645 2646 2647 2648 2649 2650 2651 2652 2653 2654 2655 2656
    if (sc->elst_count) {
        int i, edit_start_index = 0, unsupported = 0;
        int64_t empty_duration = 0; // empty duration of the first edit list entry
        int64_t start_time = 0; // start time of the media

        for (i = 0; i < sc->elst_count; i++) {
            const MOVElst *e = &sc->elst_data[i];
            if (i == 0 && e->time == -1) {
                /* if empty, the first entry is the start time of the stream
                 * relative to the presentation itself */
                empty_duration = e->duration;
                edit_start_index = 1;
            } else if (i == edit_start_index && e->time >= 0) {
                start_time = e->time;
            } else
                unsupported = 1;
        }
        if (unsupported)
            av_log(mov->fc, AV_LOG_WARNING, "multiple edit list entries, "
                   "a/v desync might occur, patch welcome\n");

2657 2658 2659 2660 2661 2662 2663 2664 2665 2666 2667 2668 2669
        /* adjust first dts according to edit list */
        if ((empty_duration || start_time) && mov->time_scale > 0) {
            if (empty_duration)
                empty_duration = av_rescale(empty_duration, sc->time_scale, mov->time_scale);
            sc->time_offset = start_time - empty_duration;
            current_dts = -sc->time_offset;
            if (sc->ctts_count>0 && sc->stts_count>0 &&
                sc->ctts_data[0].duration / FFMAX(sc->stts_data[0].duration, 1) > 16) {
                /* more than 16 frames delay, dts are likely wrong
                   this happens with files created by iMovie */
                sc->wrong_dts = 1;
                st->codec->has_b_frames = 1;
            }
2670
        }
2671 2672
    }

2673
    /* only use old uncompressed audio chunk demuxing when stts specifies it */
2674
    if (!(st->codec->codec_type == AVMEDIA_TYPE_AUDIO &&
2675
          sc->stts_count == 1 && sc->stts_data[0].duration == 1)) {
2676 2677
        unsigned int current_sample = 0;
        unsigned int stts_sample = 0;
2678
        unsigned int sample_size;
2679
        unsigned int distance = 0;
2680 2681
        unsigned int rap_group_index = 0;
        unsigned int rap_group_sample = 0;
2682 2683
        int64_t last_dts = 0;
        int64_t dts_correction = 0;
2684
        int rap_group_present = sc->rap_group_count && sc->rap_group;
2685
        int key_off = (sc->keyframe_count && sc->keyframes[0] > 0) || (sc->stps_count && sc->stps_data[0] > 0);
2686

2687
        current_dts -= sc->dts_shift;
2688
        last_dts     = current_dts;
2689

2690
        if (!sc->sample_count || st->nb_index_entries)
A
Alex Converse 已提交
2691
            return;
2692
        if (sc->sample_count >= UINT_MAX / sizeof(*st->index_entries) - st->nb_index_entries)
2693
            return;
2694 2695 2696 2697
        if (av_reallocp_array(&st->index_entries,
                              st->nb_index_entries + sc->sample_count,
                              sizeof(*st->index_entries)) < 0) {
            st->nb_index_entries = 0;
2698
            return;
2699
        }
2700
        st->index_entries_allocated_size = (st->nb_index_entries + sc->sample_count) * sizeof(*st->index_entries);
2701

2702
        for (i = 0; i < sc->chunk_count; i++) {
2703
            int64_t next_offset = i+1 < sc->chunk_count ? sc->chunk_offsets[i+1] : INT64_MAX;
2704
            current_offset = sc->chunk_offsets[i];
2705
            while (stsc_index + 1 < sc->stsc_count &&
2706
                i + 1 == sc->stsc_data[stsc_index + 1].first)
2707
                stsc_index++;
2708 2709 2710 2711 2712 2713 2714 2715 2716 2717 2718

            if (next_offset > current_offset && sc->sample_size>0 && sc->sample_size < sc->stsz_sample_size &&
                sc->stsc_data[stsc_index].count * (int64_t)sc->stsz_sample_size > next_offset - current_offset) {
                av_log(mov->fc, AV_LOG_WARNING, "STSZ sample size %d invalid (too large), ignoring\n", sc->stsz_sample_size);
                sc->stsz_sample_size = sc->sample_size;
            }
            if (sc->stsz_sample_size>0 && sc->stsz_sample_size < sc->sample_size) {
                av_log(mov->fc, AV_LOG_WARNING, "STSZ sample size %d invalid (too small), ignoring\n", sc->stsz_sample_size);
                sc->stsz_sample_size = sc->sample_size;
            }

2719
            for (j = 0; j < sc->stsc_data[stsc_index].count; j++) {
2720
                int keyframe = 0;
2721 2722
                if (current_sample >= sc->sample_count) {
                    av_log(mov->fc, AV_LOG_ERROR, "wrong sample count\n");
2723
                    return;
2724
                }
2725

2726
                if (!sc->keyframe_absent && (!sc->keyframe_count || current_sample+key_off == sc->keyframes[stss_index])) {
2727
                    keyframe = 1;
2728 2729
                    if (stss_index + 1 < sc->keyframe_count)
                        stss_index++;
2730 2731 2732 2733
                } else if (sc->stps_count && current_sample+key_off == sc->stps_data[stps_index]) {
                    keyframe = 1;
                    if (stps_index + 1 < sc->stps_count)
                        stps_index++;
2734
                }
2735 2736 2737 2738 2739 2740 2741 2742
                if (rap_group_present && rap_group_index < sc->rap_group_count) {
                    if (sc->rap_group[rap_group_index].index > 0)
                        keyframe = 1;
                    if (++rap_group_sample == sc->rap_group[rap_group_index].count) {
                        rap_group_sample = 0;
                        rap_group_index++;
                    }
                }
2743 2744 2745
                if (sc->keyframe_absent
                    && !sc->stps_count
                    && !rap_group_present
2746
                    && (st->codec->codec_type == AVMEDIA_TYPE_AUDIO || (i==0 && j==0)))
2747
                     keyframe = 1;
2748 2749
                if (keyframe)
                    distance = 0;
2750
                sample_size = sc->stsz_sample_size > 0 ? sc->stsz_sample_size : sc->sample_sizes[current_sample];
2751
                if (sc->pseudo_stream_id == -1 ||
2752
                   sc->stsc_data[stsc_index].id - 1 == sc->pseudo_stream_id) {
2753 2754
                    AVIndexEntry *e = &st->index_entries[st->nb_index_entries++];
                    e->pos = current_offset;
2755
                    e->timestamp = current_dts;
2756 2757 2758
                    e->size = sample_size;
                    e->min_distance = distance;
                    e->flags = keyframe ? AVINDEX_KEYFRAME : 0;
2759
                    av_log(mov->fc, AV_LOG_TRACE, "AVIndex stream %d, sample %d, offset %"PRIx64", dts %"PRId64", "
2760
                            "size %d, distance %d, keyframe %d\n", st->index, current_sample,
2761
                            current_offset, current_dts, sample_size, distance, keyframe);
2762
                    if (st->codec->codec_type == AVMEDIA_TYPE_VIDEO && st->nb_index_entries < 100)
2763
                        ff_rfps_add_frame(mov->fc, st, current_dts);
2764
                }
2765

2766
                current_offset += sample_size;
2767
                stream_size += sample_size;
2768 2769 2770 2771 2772 2773 2774 2775 2776 2777 2778

                /* A negative sample duration is invalid based on the spec,
                 * but some samples need it to correct the DTS. */
                if (sc->stts_data[stts_index].duration < 0) {
                    av_log(mov->fc, AV_LOG_WARNING,
                           "Invalid SampleDelta %d in STTS, at %d st:%d\n",
                           sc->stts_data[stts_index].duration, stts_index,
                           st->index);
                    dts_correction += sc->stts_data[stts_index].duration - 1;
                    sc->stts_data[stts_index].duration = 1;
                }
2779
                current_dts += sc->stts_data[stts_index].duration;
2780 2781 2782 2783 2784 2785 2786 2787 2788
                if (!dts_correction || current_dts + dts_correction > last_dts) {
                    current_dts += dts_correction;
                    dts_correction = 0;
                } else {
                    /* Avoid creating non-monotonous DTS */
                    dts_correction += current_dts - last_dts - 1;
                    current_dts = last_dts + 1;
                }
                last_dts = current_dts;
2789 2790 2791 2792 2793 2794 2795 2796 2797
                distance++;
                stts_sample++;
                current_sample++;
                if (stts_index + 1 < sc->stts_count && stts_sample == sc->stts_data[stts_index].count) {
                    stts_sample = 0;
                    stts_index++;
                }
            }
        }
2798 2799
        if (st->duration > 0)
            st->codec->bit_rate = stream_size*8*sc->time_scale/st->duration;
2800
    } else {
2801
        unsigned chunk_samples, total = 0;
2802

2803 2804 2805
        // compute total chunk count
        for (i = 0; i < sc->stsc_count; i++) {
            unsigned count, chunk_count;
2806

2807
            chunk_samples = sc->stsc_data[i].count;
2808 2809
            if (i != sc->stsc_count - 1 &&
                sc->samples_per_frame && chunk_samples % sc->samples_per_frame) {
2810 2811 2812 2813
                av_log(mov->fc, AV_LOG_ERROR, "error unaligned chunk\n");
                return;
            }

2814 2815 2816 2817 2818 2819 2820 2821 2822 2823 2824 2825 2826 2827 2828 2829
            if (sc->samples_per_frame >= 160) { // gsm
                count = chunk_samples / sc->samples_per_frame;
            } else if (sc->samples_per_frame > 1) {
                unsigned samples = (1024/sc->samples_per_frame)*sc->samples_per_frame;
                count = (chunk_samples+samples-1) / samples;
            } else {
                count = (chunk_samples+1023) / 1024;
            }

            if (i < sc->stsc_count - 1)
                chunk_count = sc->stsc_data[i+1].first - sc->stsc_data[i].first;
            else
                chunk_count = sc->chunk_count - (sc->stsc_data[i].first - 1);
            total += chunk_count * count;
        }

2830
        av_log(mov->fc, AV_LOG_TRACE, "chunk count %d\n", total);
2831
        if (total >= UINT_MAX / sizeof(*st->index_entries) - st->nb_index_entries)
2832
            return;
2833 2834 2835 2836
        if (av_reallocp_array(&st->index_entries,
                              st->nb_index_entries + total,
                              sizeof(*st->index_entries)) < 0) {
            st->nb_index_entries = 0;
2837
            return;
2838
        }
2839
        st->index_entries_allocated_size = (st->nb_index_entries + total) * sizeof(*st->index_entries);
2840 2841 2842 2843 2844 2845 2846 2847 2848

        // populate index
        for (i = 0; i < sc->chunk_count; i++) {
            current_offset = sc->chunk_offsets[i];
            if (stsc_index + 1 < sc->stsc_count &&
                i + 1 == sc->stsc_data[stsc_index + 1].first)
                stsc_index++;
            chunk_samples = sc->stsc_data[stsc_index].count;

2849
            while (chunk_samples > 0) {
2850
                AVIndexEntry *e;
2851 2852
                unsigned size, samples;

2853 2854 2855 2856 2857 2858 2859
                if (sc->samples_per_frame > 1 && !sc->bytes_per_frame) {
                    avpriv_request_sample(mov->fc,
                           "Zero bytes per frame, but %d samples per frame",
                           sc->samples_per_frame);
                    return;
                }

2860 2861 2862 2863 2864 2865 2866 2867
                if (sc->samples_per_frame >= 160) { // gsm
                    samples = sc->samples_per_frame;
                    size = sc->bytes_per_frame;
                } else {
                    if (sc->samples_per_frame > 1) {
                        samples = FFMIN((1024 / sc->samples_per_frame)*
                                        sc->samples_per_frame, chunk_samples);
                        size = (samples / sc->samples_per_frame) * sc->bytes_per_frame;
2868
                    } else {
2869 2870
                        samples = FFMIN(1024, chunk_samples);
                        size = samples * sc->sample_size;
2871 2872
                    }
                }
2873

2874 2875 2876 2877 2878 2879 2880 2881 2882 2883
                if (st->nb_index_entries >= total) {
                    av_log(mov->fc, AV_LOG_ERROR, "wrong chunk count %d\n", total);
                    return;
                }
                e = &st->index_entries[st->nb_index_entries++];
                e->pos = current_offset;
                e->timestamp = current_dts;
                e->size = size;
                e->min_distance = 0;
                e->flags = AVINDEX_KEYFRAME;
2884
                av_log(mov->fc, AV_LOG_TRACE, "AVIndex stream %d, chunk %d, offset %"PRIx64", dts %"PRId64", "
2885
                        "size %d, duration %d\n", st->index, i, current_offset, current_dts,
2886 2887 2888
                        size, samples);

                current_offset += size;
2889
                current_dts += samples;
2890
                chunk_samples -= samples;
2891 2892 2893 2894
            }
        }
    }
}
2895

2896 2897 2898 2899 2900 2901 2902 2903 2904 2905 2906 2907 2908 2909 2910 2911 2912 2913 2914 2915 2916 2917 2918 2919 2920 2921 2922 2923 2924
static int test_same_origin(const char *src, const char *ref) {
    char src_proto[64];
    char ref_proto[64];
    char src_auth[256];
    char ref_auth[256];
    char src_host[256];
    char ref_host[256];
    int src_port=-1;
    int ref_port=-1;

    av_url_split(src_proto, sizeof(src_proto), src_auth, sizeof(src_auth), src_host, sizeof(src_host), &src_port, NULL, 0, src);
    av_url_split(ref_proto, sizeof(ref_proto), ref_auth, sizeof(ref_auth), ref_host, sizeof(ref_host), &ref_port, NULL, 0, ref);

    if (strlen(src) == 0) {
        return -1;
    } else if (strlen(src_auth) + 1 >= sizeof(src_auth) ||
        strlen(ref_auth) + 1 >= sizeof(ref_auth) ||
        strlen(src_host) + 1 >= sizeof(src_host) ||
        strlen(ref_host) + 1 >= sizeof(ref_host)) {
        return 0;
    } else if (strcmp(src_proto, ref_proto) ||
               strcmp(src_auth, ref_auth) ||
               strcmp(src_host, ref_host) ||
               src_port != ref_port) {
        return 0;
    } else
        return 1;
}

2925
static int mov_open_dref(MOVContext *c, AVIOContext **pb, const char *src, MOVDref *ref)
2926
{
2927 2928
    /* try relative path, we do not try the absolute because it can leak information about our
       system to an attacker */
2929
    if (ref->nlvl_to > 0 && ref->nlvl_from > 0) {
2930
        char filename[1025];
2931
        const char *src_path;
2932 2933 2934 2935 2936 2937 2938 2939 2940 2941 2942 2943 2944 2945 2946 2947 2948 2949 2950
        int i, l;

        /* find a source dir */
        src_path = strrchr(src, '/');
        if (src_path)
            src_path++;
        else
            src_path = src;

        /* find a next level down to target */
        for (i = 0, l = strlen(ref->path) - 1; l >= 0; l--)
            if (ref->path[l] == '/') {
                if (i == ref->nlvl_to - 1)
                    break;
                else
                    i++;
            }

        /* compose filename if next level down to target was found */
2951
        if (i == ref->nlvl_to - 1 && src_path - src  < sizeof(filename)) {
2952 2953 2954 2955
            memcpy(filename, src, src_path - src);
            filename[src_path - src] = 0;

            for (i = 1; i < ref->nlvl_from; i++)
2956
                av_strlcat(filename, "../", sizeof(filename));
2957

2958
            av_strlcat(filename, ref->path + l + 1, sizeof(filename));
2959
            if (!c->use_absolute_path) {
2960 2961 2962 2963 2964 2965 2966 2967 2968 2969
                int same_origin = test_same_origin(src, filename);

                if (!same_origin) {
                    av_log(c->fc, AV_LOG_ERROR,
                        "Reference with mismatching origin, %s not tried for security reasons, "
                        "set demuxer option use_absolute_path to allow it anyway\n",
                        ref->path);
                    return AVERROR(ENOENT);
                }

2970 2971
                if(strstr(ref->path + l + 1, "..") ||
                   strstr(ref->path + l + 1, ":") ||
2972
                   (ref->nlvl_from > 1 && same_origin < 0) ||
2973
                   (filename[0] == '/' && src_path == src))
2974
                    return AVERROR(ENOENT);
2975
            }
2976

2977 2978
            if (strlen(filename) + 1 == sizeof(filename))
                return AVERROR(ENOENT);
2979
            if (!c->fc->io_open(c->fc, pb, filename, AVIO_FLAG_READ, NULL))
2980 2981
                return 0;
        }
2982 2983
    } else if (c->use_absolute_path) {
        av_log(c->fc, AV_LOG_WARNING, "Using absolute path on user request, "
2984
               "this is a possible security issue\n");
2985
        if (!c->fc->io_open(c->fc, pb, ref->path, AVIO_FLAG_READ, NULL))
2986
            return 0;
2987 2988 2989 2990 2991
    } else {
        av_log(c->fc, AV_LOG_ERROR,
               "Absolute path %s not tried for security reasons, "
               "set demuxer option use_absolute_path to allow absolute paths\n",
               ref->path);
2992 2993 2994
    }

    return AVERROR(ENOENT);
M
Mans Rullgard 已提交
2995
}
2996

2997 2998 2999 3000 3001 3002 3003 3004 3005 3006
static void fix_timescale(MOVContext *c, MOVStreamContext *sc)
{
    if (sc->time_scale <= 0) {
        av_log(c->fc, AV_LOG_WARNING, "stream %d, timescale not set\n", sc->ffindex);
        sc->time_scale = c->time_scale;
        if (sc->time_scale <= 0)
            sc->time_scale = 1;
    }
}

3007
static int mov_read_trak(MOVContext *c, AVIOContext *pb, MOVAtom atom)
3008 3009 3010
{
    AVStream *st;
    MOVStreamContext *sc;
3011
    int ret;
3012

3013
    st = avformat_new_stream(c->fc, NULL);
B
Baptiste Coudurier 已提交
3014
    if (!st) return AVERROR(ENOMEM);
3015
    st->id = c->fc->nb_streams;
B
Baptiste Coudurier 已提交
3016
    sc = av_mallocz(sizeof(MOVStreamContext));
3017
    if (!sc) return AVERROR(ENOMEM);
3018 3019

    st->priv_data = sc;
3020
    st->codec->codec_type = AVMEDIA_TYPE_DATA;
3021
    sc->ffindex = st->index;
3022
    c->trak_index = st->index;
3023

3024 3025 3026
    if ((ret = mov_read_default(c, pb, atom)) < 0)
        return ret;

3027 3028
    c->trak_index = -1;

3029
    /* sanity checks */
3030 3031
    if (sc->chunk_count && (!sc->stts_count || !sc->stsc_count ||
                            (!sc->sample_size && !sc->sample_count))) {
3032 3033
        av_log(c->fc, AV_LOG_ERROR, "stream %d, missing mandatory atoms, broken header\n",
               st->index);
3034 3035
        return 0;
    }
3036

3037
    fix_timescale(c, sc);
3038

3039
    avpriv_set_pts_info(st, 64, 1, sc->time_scale);
3040 3041 3042 3043

    mov_build_index(c, st);

    if (sc->dref_id-1 < sc->drefs_count && sc->drefs[sc->dref_id-1].path) {
3044
        MOVDref *dref = &sc->drefs[sc->dref_id - 1];
3045
        if (c->enable_drefs) {
3046
            if (mov_open_dref(c, &sc->pb, c->fc->filename, dref) < 0)
3047 3048 3049 3050 3051 3052 3053 3054 3055 3056 3057
                av_log(c->fc, AV_LOG_ERROR,
                       "stream %d, error opening alias: path='%s', dir='%s', "
                       "filename='%s', volume='%s', nlvl_from=%d, nlvl_to=%d\n",
                       st->index, dref->path, dref->dir, dref->filename,
                       dref->volume, dref->nlvl_from, dref->nlvl_to);
        } else {
            av_log(c->fc, AV_LOG_WARNING,
                   "Skipped opening external track: "
                   "stream %d, alias: path='%s', dir='%s', "
                   "filename='%s', volume='%s', nlvl_from=%d, nlvl_to=%d."
                   "Set enable_drefs to allow this.\n",
3058 3059
                   st->index, dref->path, dref->dir, dref->filename,
                   dref->volume, dref->nlvl_from, dref->nlvl_to);
3060
        }
3061
    } else {
3062
        sc->pb = c->fc->pb;
3063 3064
        sc->pb_is_copied = 1;
    }
3065

3066
    if (st->codec->codec_type == AVMEDIA_TYPE_VIDEO) {
3067 3068
        if (!st->sample_aspect_ratio.num && st->codec->width && st->codec->height &&
            sc->height && sc->width &&
3069 3070 3071
            (st->codec->width != sc->width || st->codec->height != sc->height)) {
            st->sample_aspect_ratio = av_d2q(((double)st->codec->height * sc->width) /
                                             ((double)st->codec->width * sc->height), INT_MAX);
3072 3073
        }

A
Anton Khirnov 已提交
3074
#if FF_API_R_FRAME_RATE
3075 3076 3077
        if (sc->stts_count == 1 || (sc->stts_count == 2 && sc->stts_data[1].count == 1))
            av_reduce(&st->r_frame_rate.num, &st->r_frame_rate.den,
                      sc->time_scale, sc->stts_data[0].duration, INT_MAX);
A
Anton Khirnov 已提交
3078
#endif
3079 3080
    }

R
Reimar Döffinger 已提交
3081 3082
    // done for ai5q, ai52, ai55, ai1q, ai12 and ai15.
    if (!st->codec->extradata_size && st->codec->codec_id == AV_CODEC_ID_H264 &&
3083 3084 3085 3086
        TAG_IS_AVCI(st->codec->codec_tag)) {
        ret = ff_generate_avci_extradata(st);
        if (ret < 0)
            return ret;
R
Reimar Döffinger 已提交
3087 3088
    }

3089
    switch (st->codec->codec_id) {
3090
#if CONFIG_H261_DECODER
3091
    case AV_CODEC_ID_H261:
3092
#endif
3093
#if CONFIG_H263_DECODER
3094
    case AV_CODEC_ID_H263:
3095
#endif
3096
#if CONFIG_MPEG4_DECODER
3097
    case AV_CODEC_ID_MPEG4:
3098
#endif
3099
        st->codec->width = 0; /* let decoder init width/height */
3100 3101 3102
        st->codec->height= 0;
        break;
    }
B
Baptiste Coudurier 已提交
3103

3104 3105 3106 3107 3108 3109 3110
    // If the duration of the mp3 packets is not constant, then they could need a parser
    if (st->codec->codec_id == AV_CODEC_ID_MP3
        && sc->stts_count > 3
        && sc->stts_count*10 > st->nb_frames
        && sc->time_scale == st->codec->sample_rate) {
            st->need_parsing = AVSTREAM_PARSE_FULL;
    }
B
Baptiste Coudurier 已提交
3111 3112
    /* Do not need those anymore. */
    av_freep(&sc->chunk_offsets);
3113
    av_freep(&sc->stsc_data);
B
Baptiste Coudurier 已提交
3114 3115 3116
    av_freep(&sc->sample_sizes);
    av_freep(&sc->keyframes);
    av_freep(&sc->stts_data);
3117
    av_freep(&sc->stps_data);
3118
    av_freep(&sc->elst_data);
3119
    av_freep(&sc->rap_group);
B
Baptiste Coudurier 已提交
3120

3121
    return 0;
3122 3123
}

3124
static int mov_read_ilst(MOVContext *c, AVIOContext *pb, MOVAtom atom)
3125 3126 3127 3128 3129 3130 3131 3132
{
    int ret;
    c->itunes_metadata = 1;
    ret = mov_read_default(c, pb, atom);
    c->itunes_metadata = 0;
    return ret;
}

3133 3134 3135 3136 3137 3138 3139 3140 3141 3142 3143 3144 3145 3146 3147 3148 3149 3150 3151 3152 3153 3154 3155 3156 3157 3158 3159 3160 3161 3162 3163 3164 3165 3166 3167 3168 3169 3170 3171 3172 3173 3174
static int mov_read_keys(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    uint32_t count;
    uint32_t i;

    if (atom.size < 8)
        return 0;

    avio_skip(pb, 4);
    count = avio_rb32(pb);
    if (count > UINT_MAX / sizeof(*c->meta_keys)) {
        av_log(c->fc, AV_LOG_ERROR,
               "The 'keys' atom with the invalid key count: %d\n", count);
        return AVERROR_INVALIDDATA;
    }

    c->meta_keys_count = count + 1;
    c->meta_keys = av_mallocz(c->meta_keys_count * sizeof(*c->meta_keys));
    if (!c->meta_keys)
        return AVERROR(ENOMEM);

    for (i = 1; i <= count; ++i) {
        uint32_t key_size = avio_rb32(pb);
        uint32_t type = avio_rl32(pb);
        if (key_size < 8) {
            av_log(c->fc, AV_LOG_ERROR,
                   "The key# %d in meta has invalid size: %d\n", i, key_size);
            return AVERROR_INVALIDDATA;
        }
        key_size -= 8;
        if (type != MKTAG('m','d','t','a')) {
            avio_skip(pb, key_size);
        }
        c->meta_keys[i] = av_mallocz(key_size + 1);
        if (!c->meta_keys[i])
            return AVERROR(ENOMEM);
        avio_read(pb, c->meta_keys[i], key_size);
    }

    return 0;
}

3175
static int mov_read_custom_2plus(MOVContext *c, AVIOContext *pb, int64_t size)
3176 3177 3178 3179
{
    int64_t end = avio_tell(pb) + size;
    uint8_t *key = NULL, *val = NULL;
    int i;
3180 3181 3182 3183 3184 3185 3186
    AVStream *st;
    MOVStreamContext *sc;

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;
3187 3188 3189 3190

    for (i = 0; i < 2; i++) {
        uint8_t **p;
        uint32_t len, tag;
3191
        int ret;
3192 3193 3194 3195 3196 3197 3198 3199 3200 3201 3202 3203 3204 3205 3206 3207 3208 3209 3210 3211 3212 3213 3214 3215

        if (end - avio_tell(pb) <= 12)
            break;

        len = avio_rb32(pb);
        tag = avio_rl32(pb);
        avio_skip(pb, 4); // flags

        if (len < 12 || len - 12 > end - avio_tell(pb))
            break;
        len -= 12;

        if (tag == MKTAG('n', 'a', 'm', 'e'))
            p = &key;
        else if (tag == MKTAG('d', 'a', 't', 'a') && len > 4) {
            avio_skip(pb, 4);
            len -= 4;
            p = &val;
        } else
            break;

        *p = av_malloc(len + 1);
        if (!*p)
            break;
3216 3217
        ret = ffio_read_size(pb, *p, len);
        if (ret < 0) {
3218
            av_freep(p);
3219
            return ret;
3220
        }
3221 3222 3223 3224
        (*p)[len] = 0;
    }

    if (key && val) {
3225 3226 3227 3228 3229 3230
        if (strcmp(key, "iTunSMPB") == 0) {
            int priming, remainder, samples;
            if(sscanf(val, "%*X %X %X %X", &priming, &remainder, &samples) == 3){
                if(priming>0 && priming<16384)
                    sc->start_pad = priming;
            }
3231 3232
        }
        if (strcmp(key, "cdec") != 0) {
3233 3234 3235 3236
            av_dict_set(&c->fc->metadata, key, val,
                        AV_DICT_DONT_STRDUP_KEY | AV_DICT_DONT_STRDUP_VAL);
            key = val = NULL;
        }
3237 3238 3239 3240 3241 3242 3243 3244 3245 3246 3247 3248 3249 3250 3251 3252 3253 3254 3255 3256 3257 3258 3259 3260 3261 3262 3263 3264 3265 3266 3267
    }

    avio_seek(pb, end, SEEK_SET);
    av_freep(&key);
    av_freep(&val);
    return 0;
}

static int mov_read_custom(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    int64_t end = avio_tell(pb) + atom.size;
    uint32_t tag, len;

    if (atom.size < 8)
        goto fail;

    len = avio_rb32(pb);
    tag = avio_rl32(pb);

    if (len > atom.size)
        goto fail;

    if (tag == MKTAG('m', 'e', 'a', 'n') && len > 12) {
        uint8_t domain[128];
        int domain_len;

        avio_skip(pb, 4); // flags
        len -= 12;

        domain_len = avio_get_str(pb, len, domain, sizeof(domain));
        avio_skip(pb, len - domain_len);
3268
        return mov_read_custom_2plus(c, pb, end - avio_tell(pb));
3269 3270 3271 3272 3273 3274 3275 3276
    }

fail:
    av_log(c->fc, AV_LOG_VERBOSE,
           "Unhandled or malformed custom metadata of size %"PRId64"\n", atom.size);
    return 0;
}

3277
static int mov_read_meta(MOVContext *c, AVIOContext *pb, MOVAtom atom)
3278
{
3279
    while (atom.size > 8) {
3280
        uint32_t tag = avio_rl32(pb);
3281 3282
        atom.size -= 4;
        if (tag == MKTAG('h','d','l','r')) {
A
Anton Khirnov 已提交
3283
            avio_seek(pb, -8, SEEK_CUR);
3284 3285 3286 3287 3288
            atom.size += 8;
            return mov_read_default(c, pb, atom);
        }
    }
    return 0;
3289 3290
}

3291
static int mov_read_tkhd(MOVContext *c, AVIOContext *pb, MOVAtom atom)
3292
{
3293 3294 3295
    int i;
    int width;
    int height;
3296
    int display_matrix[3][3];
3297 3298 3299
    AVStream *st;
    MOVStreamContext *sc;
    int version;
3300
    int flags;
3301 3302 3303 3304 3305

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;
3306

3307
    version = avio_r8(pb);
3308 3309
    flags = avio_rb24(pb);
    st->disposition |= (flags & MOV_TKHD_FLAG_ENABLED) ? AV_DISPOSITION_DEFAULT : 0;
3310

B
Baptiste Coudurier 已提交
3311
    if (version == 1) {
3312 3313
        avio_rb64(pb);
        avio_rb64(pb);
B
Baptiste Coudurier 已提交
3314
    } else {
3315 3316
        avio_rb32(pb); /* creation time */
        avio_rb32(pb); /* modification time */
B
Baptiste Coudurier 已提交
3317
    }
3318 3319
    st->id = (int)avio_rb32(pb); /* track id (NOT 0 !)*/
    avio_rb32(pb); /* reserved */
3320

3321
    /* highlevel (considering edits) duration in movie timebase */
3322 3323 3324
    (version == 1) ? avio_rb64(pb) : avio_rb32(pb);
    avio_rb32(pb); /* reserved */
    avio_rb32(pb); /* reserved */
3325

3326 3327 3328 3329
    avio_rb16(pb); /* layer */
    avio_rb16(pb); /* alternate group */
    avio_rb16(pb); /* volume */
    avio_rb16(pb); /* reserved */
3330

3331 3332
    //read in the display matrix (outlined in ISO 14496-12, Section 6.2.2)
    // they're kept in fixed point format through all calculations
3333 3334
    // save u,v,z to store the whole matrix in the AV_PKT_DATA_DISPLAYMATRIX
    // side data, but the scale factor is not needed to calculate aspect ratio
3335
    for (i = 0; i < 3; i++) {
3336 3337
        display_matrix[i][0] = avio_rb32(pb);   // 16.16 fixed point
        display_matrix[i][1] = avio_rb32(pb);   // 16.16 fixed point
3338
        display_matrix[i][2] = avio_rb32(pb);   //  2.30 fixed point
3339
    }
3340

3341 3342
    width = avio_rb32(pb);       // 16.16 fixed point track width
    height = avio_rb32(pb);      // 16.16 fixed point track height
3343 3344
    sc->width = width >> 16;
    sc->height = height >> 16;
3345

3346 3347
    // save the matrix and add rotate metadata when it is not the default
    // identity
3348 3349 3350 3351 3352 3353 3354
    if (display_matrix[0][0] != (1 << 16) ||
        display_matrix[1][1] != (1 << 16) ||
        display_matrix[2][2] != (1 << 30) ||
        display_matrix[0][1] || display_matrix[0][2] ||
        display_matrix[1][0] || display_matrix[1][2] ||
        display_matrix[2][0] || display_matrix[2][1]) {
        int i, j;
3355
        double rotate;
3356 3357 3358 3359 3360 3361 3362 3363

        av_freep(&sc->display_matrix);
        sc->display_matrix = av_malloc(sizeof(int32_t) * 9);
        if (!sc->display_matrix)
            return AVERROR(ENOMEM);

        for (i = 0; i < 3; i++)
            for (j = 0; j < 3; j++)
3364
                sc->display_matrix[i * 3 + j] = display_matrix[i][j];
3365 3366 3367 3368 3369 3370 3371 3372 3373 3374

        rotate = av_display_rotation_get(sc->display_matrix);
        if (!isnan(rotate)) {
            char rotate_buf[64];
            rotate = -rotate;
            if (rotate < 0) // for backward compatibility
                rotate += 360;
            snprintf(rotate_buf, sizeof(rotate_buf), "%g", rotate);
            av_dict_set(&st->metadata, "rotate", rotate_buf, 0);
        }
3375 3376
    }

3377
    // transform the display width/height according to the matrix
3378
    // to keep the same scale, use [width height 1<<16]
3379 3380 3381
    if (width && height && sc->display_matrix) {
        double disp_transform[2];

3382
        for (i = 0; i < 2; i++)
G
Ganesh Ajjanagadde 已提交
3383
            disp_transform[i] = hypot(display_matrix[i][0], display_matrix[i][1]);
3384

3385 3386
        if (disp_transform[0] > 0       && disp_transform[1] > 0 &&
            disp_transform[0] < (1<<24) && disp_transform[1] < (1<<24) &&
3387
            fabs((disp_transform[0] / disp_transform[1]) - 1.0) > 0.01)
3388 3389 3390
            st->sample_aspect_ratio = av_d2q(
                disp_transform[0] / disp_transform[1],
                INT_MAX);
3391
    }
3392 3393 3394
    return 0;
}

3395
static int mov_read_tfhd(MOVContext *c, AVIOContext *pb, MOVAtom atom)
B
Baptiste Coudurier 已提交
3396 3397 3398
{
    MOVFragment *frag = &c->fragment;
    MOVTrackExt *trex = NULL;
3399
    MOVFragmentIndex* index = NULL;
3400
    int flags, track_id, i, found = 0;
B
Baptiste Coudurier 已提交
3401

3402 3403
    avio_r8(pb); /* version */
    flags = avio_rb24(pb);
B
Baptiste Coudurier 已提交
3404

3405
    track_id = avio_rb32(pb);
3406
    if (!track_id)
3407
        return AVERROR_INVALIDDATA;
B
Baptiste Coudurier 已提交
3408 3409 3410 3411 3412 3413 3414 3415
    frag->track_id = track_id;
    for (i = 0; i < c->trex_count; i++)
        if (c->trex_data[i].track_id == frag->track_id) {
            trex = &c->trex_data[i];
            break;
        }
    if (!trex) {
        av_log(c->fc, AV_LOG_ERROR, "could not find corresponding trex\n");
3416
        return AVERROR_INVALIDDATA;
B
Baptiste Coudurier 已提交
3417 3418
    }

3419
    frag->base_data_offset = flags & MOV_TFHD_BASE_DATA_OFFSET ?
3420 3421
                             avio_rb64(pb) : flags & MOV_TFHD_DEFAULT_BASE_IS_MOOF ?
                             frag->moof_offset : frag->implicit_offset;
3422 3423 3424 3425 3426 3427 3428 3429
    frag->stsd_id  = flags & MOV_TFHD_STSD_ID ? avio_rb32(pb) : trex->stsd_id;

    frag->duration = flags & MOV_TFHD_DEFAULT_DURATION ?
                     avio_rb32(pb) : trex->duration;
    frag->size     = flags & MOV_TFHD_DEFAULT_SIZE ?
                     avio_rb32(pb) : trex->size;
    frag->flags    = flags & MOV_TFHD_DEFAULT_FLAGS ?
                     avio_rb32(pb) : trex->flags;
3430
    frag->time     = AV_NOPTS_VALUE;
3431 3432 3433 3434 3435 3436 3437 3438 3439 3440 3441 3442 3443 3444 3445 3446 3447
    for (i = 0; i < c->fragment_index_count; i++) {
        int j;
        MOVFragmentIndex* candidate = c->fragment_index_data[i];
        if (candidate->track_id == frag->track_id) {
            av_log(c->fc, AV_LOG_DEBUG,
                   "found fragment index for track %u\n", frag->track_id);
            index = candidate;
            for (j = index->current_item; j < index->item_count; j++) {
                if (frag->implicit_offset == index->items[j].moof_offset) {
                    av_log(c->fc, AV_LOG_DEBUG, "found fragment index entry "
                            "for track %u and moof_offset %"PRId64"\n",
                            frag->track_id, index->items[j].moof_offset);
                    frag->time = index->items[j].time;
                    index->current_item = j + 1;
                    found = 1;
                    break;
                }
3448
            }
3449 3450
            if (found)
                break;
3451 3452
        }
    }
3453 3454 3455 3456 3457
    if (index && !found) {
        av_log(c->fc, AV_LOG_DEBUG, "track %u has a fragment index but "
               "it doesn't have an (in-order) entry for moof_offset "
               "%"PRId64"\n", frag->track_id, frag->implicit_offset);
    }
3458
    av_log(c->fc, AV_LOG_TRACE, "frag flags 0x%x\n", frag->flags);
B
Baptiste Coudurier 已提交
3459 3460 3461
    return 0;
}

3462
static int mov_read_chap(MOVContext *c, AVIOContext *pb, MOVAtom atom)
D
David Conrad 已提交
3463
{
3464
    c->chapter_track = avio_rb32(pb);
D
David Conrad 已提交
3465 3466 3467
    return 0;
}

3468
static int mov_read_trex(MOVContext *c, AVIOContext *pb, MOVAtom atom)
B
Baptiste Coudurier 已提交
3469 3470
{
    MOVTrackExt *trex;
3471
    int err;
B
Baptiste Coudurier 已提交
3472 3473

    if ((uint64_t)c->trex_count+1 >= UINT_MAX / sizeof(*c->trex_data))
3474
        return AVERROR_INVALIDDATA;
3475 3476 3477 3478 3479
    if ((err = av_reallocp_array(&c->trex_data, c->trex_count + 1,
                                 sizeof(*c->trex_data))) < 0) {
        c->trex_count = 0;
        return err;
    }
3480 3481 3482

    c->fc->duration = AV_NOPTS_VALUE; // the duration from mvhd is not representing the whole file when fragments are used.

B
Baptiste Coudurier 已提交
3483
    trex = &c->trex_data[c->trex_count++];
3484 3485 3486 3487 3488 3489 3490
    avio_r8(pb); /* version */
    avio_rb24(pb); /* flags */
    trex->track_id = avio_rb32(pb);
    trex->stsd_id  = avio_rb32(pb);
    trex->duration = avio_rb32(pb);
    trex->size     = avio_rb32(pb);
    trex->flags    = avio_rb32(pb);
B
Baptiste Coudurier 已提交
3491 3492 3493
    return 0;
}

M
Martin Storsjö 已提交
3494 3495 3496 3497 3498 3499 3500 3501 3502 3503 3504 3505 3506 3507 3508 3509 3510 3511 3512 3513 3514 3515 3516 3517 3518 3519 3520 3521 3522 3523
static int mov_read_tfdt(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    MOVFragment *frag = &c->fragment;
    AVStream *st = NULL;
    MOVStreamContext *sc;
    int version, i;

    for (i = 0; i < c->fc->nb_streams; i++) {
        if (c->fc->streams[i]->id == frag->track_id) {
            st = c->fc->streams[i];
            break;
        }
    }
    if (!st) {
        av_log(c->fc, AV_LOG_ERROR, "could not find corresponding track id %d\n", frag->track_id);
        return AVERROR_INVALIDDATA;
    }
    sc = st->priv_data;
    if (sc->pseudo_stream_id + 1 != frag->stsd_id)
        return 0;
    version = avio_r8(pb);
    avio_rb24(pb); /* flags */
    if (version) {
        sc->track_end = avio_rb64(pb);
    } else {
        sc->track_end = avio_rb32(pb);
    }
    return 0;
}

3524
static int mov_read_trun(MOVContext *c, AVIOContext *pb, MOVAtom atom)
B
Baptiste Coudurier 已提交
3525 3526
{
    MOVFragment *frag = &c->fragment;
3527
    AVStream *st = NULL;
3528
    MOVStreamContext *sc;
3529
    MOVStts *ctts_data;
B
Baptiste Coudurier 已提交
3530 3531 3532 3533
    uint64_t offset;
    int64_t dts;
    int data_offset = 0;
    unsigned entries, first_sample_flags = frag->flags;
3534
    int flags, distance, i, err;
B
Baptiste Coudurier 已提交
3535

3536 3537 3538 3539 3540 3541 3542 3543
    for (i = 0; i < c->fc->nb_streams; i++) {
        if (c->fc->streams[i]->id == frag->track_id) {
            st = c->fc->streams[i];
            break;
        }
    }
    if (!st) {
        av_log(c->fc, AV_LOG_ERROR, "could not find corresponding track id %d\n", frag->track_id);
3544
        return AVERROR_INVALIDDATA;
3545
    }
3546
    sc = st->priv_data;
3547
    if (sc->pseudo_stream_id+1 != frag->stsd_id && sc->pseudo_stream_id != -1)
B
Baptiste Coudurier 已提交
3548
        return 0;
3549 3550 3551
    avio_r8(pb); /* version */
    flags = avio_rb24(pb);
    entries = avio_rb32(pb);
3552
    av_log(c->fc, AV_LOG_TRACE, "flags 0x%x entries %d\n", flags, entries);
3553 3554 3555 3556 3557 3558 3559 3560 3561

    /* Always assume the presence of composition time offsets.
     * Without this assumption, for instance, we cannot deal with a track in fragmented movies that meet the following.
     *  1) in the initial movie, there are no samples.
     *  2) in the first movie fragment, there is only one sample without composition time offset.
     *  3) in the subsequent movie fragments, there are samples with composition time offset. */
    if (!sc->ctts_count && sc->sample_count)
    {
        /* Complement ctts table if moov atom doesn't have ctts atom. */
3562
        ctts_data = av_realloc(NULL, sizeof(*sc->ctts_data));
3563
        if (!ctts_data)
B
Baptiste Coudurier 已提交
3564
            return AVERROR(ENOMEM);
3565
        sc->ctts_data = ctts_data;
3566 3567 3568
        sc->ctts_data[sc->ctts_count].count = sc->sample_count;
        sc->ctts_data[sc->ctts_count].duration = 0;
        sc->ctts_count++;
B
Baptiste Coudurier 已提交
3569
    }
3570
    if ((uint64_t)entries+sc->ctts_count >= UINT_MAX/sizeof(*sc->ctts_data))
3571
        return AVERROR_INVALIDDATA;
3572 3573 3574 3575 3576
    if ((err = av_reallocp_array(&sc->ctts_data, entries + sc->ctts_count,
                                 sizeof(*sc->ctts_data))) < 0) {
        sc->ctts_count = 0;
        return err;
    }
3577 3578
    if (flags & MOV_TRUN_DATA_OFFSET)        data_offset        = avio_rb32(pb);
    if (flags & MOV_TRUN_FIRST_SAMPLE_FLAGS) first_sample_flags = avio_rb32(pb);
3579
    dts    = sc->track_end - sc->time_offset;
B
Baptiste Coudurier 已提交
3580 3581
    offset = frag->base_data_offset + data_offset;
    distance = 0;
3582
    av_log(c->fc, AV_LOG_TRACE, "first sample flags 0x%x\n", first_sample_flags);
3583
    for (i = 0; i < entries && !pb->eof_reached; i++) {
B
Baptiste Coudurier 已提交
3584 3585 3586
        unsigned sample_size = frag->size;
        int sample_flags = i ? frag->flags : first_sample_flags;
        unsigned sample_duration = frag->duration;
3587
        int keyframe = 0;
B
Baptiste Coudurier 已提交
3588

3589 3590 3591
        if (flags & MOV_TRUN_SAMPLE_DURATION) sample_duration = avio_rb32(pb);
        if (flags & MOV_TRUN_SAMPLE_SIZE)     sample_size     = avio_rb32(pb);
        if (flags & MOV_TRUN_SAMPLE_FLAGS)    sample_flags    = avio_rb32(pb);
3592 3593 3594
        sc->ctts_data[sc->ctts_count].count = 1;
        sc->ctts_data[sc->ctts_count].duration = (flags & MOV_TRUN_SAMPLE_CTS) ?
                                                  avio_rb32(pb) : 0;
3595
        mov_update_dts_shift(sc, sc->ctts_data[sc->ctts_count].duration);
3596 3597 3598 3599 3600 3601 3602 3603 3604 3605 3606 3607 3608 3609 3610 3611 3612 3613 3614 3615 3616 3617
        if (frag->time != AV_NOPTS_VALUE) {
            if (c->use_mfra_for == FF_MOV_FLAG_MFRA_PTS) {
                int64_t pts = frag->time;
                av_log(c->fc, AV_LOG_DEBUG, "found frag time %"PRId64
                        " sc->dts_shift %d ctts.duration %d"
                        " sc->time_offset %"PRId64" flags & MOV_TRUN_SAMPLE_CTS %d\n", pts,
                        sc->dts_shift, sc->ctts_data[sc->ctts_count].duration,
                        sc->time_offset, flags & MOV_TRUN_SAMPLE_CTS);
                dts = pts - sc->dts_shift;
                if (flags & MOV_TRUN_SAMPLE_CTS) {
                    dts -= sc->ctts_data[sc->ctts_count].duration;
                } else {
                    dts -= sc->time_offset;
                }
                av_log(c->fc, AV_LOG_DEBUG, "calculated into dts %"PRId64"\n", dts);
            } else {
                dts = frag->time;
                av_log(c->fc, AV_LOG_DEBUG, "found frag time %"PRId64
                        ", using it for dts\n", dts);
            }
            frag->time = AV_NOPTS_VALUE;
        }
3618
        sc->ctts_count++;
3619 3620
        if (st->codec->codec_type == AVMEDIA_TYPE_AUDIO)
            keyframe = 1;
3621 3622
        else
            keyframe =
3623 3624 3625
                !(sample_flags & (MOV_FRAG_SAMPLE_FLAG_IS_NON_SYNC |
                                  MOV_FRAG_SAMPLE_FLAG_DEPENDS_YES));
        if (keyframe)
B
Baptiste Coudurier 已提交
3626
            distance = 0;
3627
        err = av_add_index_entry(st, offset, dts, sample_size, distance,
3628 3629 3630
                                 keyframe ? AVINDEX_KEYFRAME : 0);
        if (err < 0) {
            av_log(c->fc, AV_LOG_ERROR, "Failed to add index entry\n");
3631
        }
3632
        av_log(c->fc, AV_LOG_TRACE, "AVIndex stream %d, sample %d, offset %"PRIx64", dts %"PRId64", "
B
Baptiste Coudurier 已提交
3633
                "size %d, distance %d, keyframe %d\n", st->index, sc->sample_count+i,
3634
                offset, dts, sample_size, distance, keyframe);
B
Baptiste Coudurier 已提交
3635
        distance++;
3636
        dts += sample_duration;
B
Baptiste Coudurier 已提交
3637
        offset += sample_size;
3638
        sc->data_size += sample_size;
3639 3640
        sc->duration_for_fps += sample_duration;
        sc->nb_frames_for_fps ++;
B
Baptiste Coudurier 已提交
3641
    }
3642 3643 3644 3645

    if (pb->eof_reached)
        return AVERROR_EOF;

3646
    frag->implicit_offset = offset;
3647 3648 3649 3650 3651 3652 3653 3654 3655 3656 3657 3658 3659 3660 3661 3662 3663 3664 3665 3666 3667 3668 3669 3670 3671 3672 3673 3674 3675 3676 3677 3678 3679 3680 3681 3682 3683 3684 3685 3686 3687 3688 3689 3690 3691 3692 3693 3694 3695 3696 3697 3698 3699 3700 3701 3702 3703 3704 3705 3706 3707 3708 3709 3710 3711 3712 3713 3714 3715 3716 3717 3718 3719 3720 3721 3722 3723 3724 3725 3726 3727 3728 3729 3730 3731 3732 3733 3734 3735 3736 3737 3738 3739 3740 3741 3742 3743 3744 3745 3746

    sc->track_end = dts + sc->time_offset;
    if (st->duration < sc->track_end)
        st->duration = sc->track_end;

    return 0;
}

static int mov_read_sidx(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    int64_t offset = avio_tell(pb) + atom.size, pts;
    uint8_t version;
    unsigned i, track_id;
    AVStream *st = NULL;
    MOVStreamContext *sc;
    MOVFragmentIndex *index = NULL;
    MOVFragmentIndex **tmp;
    AVRational timescale;

    version = avio_r8(pb);
    if (version > 1) {
        avpriv_request_sample(c->fc, "sidx version %u", version);
        return AVERROR_PATCHWELCOME;
    }

    avio_rb24(pb); // flags

    track_id = avio_rb32(pb); // Reference ID
    for (i = 0; i < c->fc->nb_streams; i++) {
        if (c->fc->streams[i]->id == track_id) {
            st = c->fc->streams[i];
            break;
        }
    }
    if (!st) {
        av_log(c->fc, AV_LOG_ERROR, "could not find corresponding track id %d\n", track_id);
        return AVERROR_INVALIDDATA;
    }

    sc = st->priv_data;

    timescale = av_make_q(1, avio_rb32(pb));

    if (version == 0) {
        pts = avio_rb32(pb);
        offset += avio_rb32(pb);
    } else {
        pts = avio_rb64(pb);
        offset += avio_rb64(pb);
    }

    avio_rb16(pb); // reserved

    index = av_mallocz(sizeof(MOVFragmentIndex));
    if (!index)
        return AVERROR(ENOMEM);

    index->track_id = track_id;

    index->item_count = avio_rb16(pb);
    index->items = av_mallocz_array(index->item_count, sizeof(MOVFragmentIndexItem));

    if (!index->items) {
        av_freep(&index);
        return AVERROR(ENOMEM);
    }

    for (i = 0; i < index->item_count; i++) {
        uint32_t size = avio_rb32(pb);
        uint32_t duration = avio_rb32(pb);
        if (size & 0x80000000) {
            avpriv_request_sample(c->fc, "sidx reference_type 1");
            av_freep(&index->items);
            av_freep(&index);
            return AVERROR_PATCHWELCOME;
        }
        avio_rb32(pb); // sap_flags
        index->items[i].moof_offset = offset;
        index->items[i].time = av_rescale_q(pts, st->time_base, timescale);
        offset += size;
        pts += duration;
    }

    st->duration = sc->track_end = pts;

    tmp = av_realloc_array(c->fragment_index_data,
                           c->fragment_index_count + 1,
                           sizeof(MOVFragmentIndex*));
    if (!tmp) {
        av_freep(&index->items);
        av_freep(&index);
        return AVERROR(ENOMEM);
    }

    c->fragment_index_data = tmp;
    c->fragment_index_data[c->fragment_index_count++] = index;

    if (offset == avio_size(pb))
        c->fragment_index_complete = 1;

B
Baptiste Coudurier 已提交
3747 3748 3749
    return 0;
}

3750 3751 3752
/* this atom should be null (from specs), but some buggy files put the 'moov' atom inside it... */
/* like the files created with Adobe Premiere 5.0, for samples see */
/* http://graphics.tudelft.nl/~wouter/publications/soundtests/ */
3753
static int mov_read_wide(MOVContext *c, AVIOContext *pb, MOVAtom atom)
3754 3755 3756 3757 3758
{
    int err;

    if (atom.size < 8)
        return 0; /* continue */
3759
    if (avio_rb32(pb) != 0) { /* 0 sized mdat atom... use the 'wide' atom size */
3760
        avio_skip(pb, atom.size - 4);
3761 3762
        return 0;
    }
3763
    atom.type = avio_rl32(pb);
3764
    atom.size -= 8;
3765
    if (atom.type != MKTAG('m','d','a','t')) {
3766
        avio_skip(pb, atom.size);
3767 3768 3769 3770 3771 3772
        return 0;
    }
    err = mov_read_mdat(c, pb, atom);
    return err;
}

3773
static int mov_read_cmov(MOVContext *c, AVIOContext *pb, MOVAtom atom)
3774
{
3775
#if CONFIG_ZLIB
3776
    AVIOContext ctx;
3777 3778
    uint8_t *cmov_data;
    uint8_t *moov_data; /* uncompressed data */
3779
    long cmov_len, moov_len;
3780
    int ret = -1;
3781

3782 3783
    avio_rb32(pb); /* dcom atom */
    if (avio_rl32(pb) != MKTAG('d','c','o','m'))
3784
        return AVERROR_INVALIDDATA;
3785
    if (avio_rl32(pb) != MKTAG('z','l','i','b')) {
3786
        av_log(c->fc, AV_LOG_ERROR, "unknown compression for cmov atom !\n");
3787
        return AVERROR_INVALIDDATA;
3788
    }
3789 3790
    avio_rb32(pb); /* cmvd atom */
    if (avio_rl32(pb) != MKTAG('c','m','v','d'))
3791
        return AVERROR_INVALIDDATA;
3792
    moov_len = avio_rb32(pb); /* uncompressed size */
3793
    cmov_len = atom.size - 6 * 4;
3794

B
Baptiste Coudurier 已提交
3795
    cmov_data = av_malloc(cmov_len);
3796
    if (!cmov_data)
3797
        return AVERROR(ENOMEM);
B
Baptiste Coudurier 已提交
3798
    moov_data = av_malloc(moov_len);
3799 3800
    if (!moov_data) {
        av_free(cmov_data);
3801
        return AVERROR(ENOMEM);
3802
    }
3803 3804 3805 3806
    ret = ffio_read_size(pb, cmov_data, cmov_len);
    if (ret < 0)
        goto free_and_return;

3807
    if (uncompress (moov_data, (uLongf *) &moov_len, (const Bytef *)cmov_data, cmov_len) != Z_OK)
3808
        goto free_and_return;
3809
    if (ffio_init_context(&ctx, moov_data, moov_len, 0, NULL, NULL, NULL, NULL) != 0)
3810
        goto free_and_return;
3811
    ctx.seekable = AVIO_SEEKABLE_NORMAL;
3812
    atom.type = MKTAG('m','o','o','v');
3813 3814
    atom.size = moov_len;
    ret = mov_read_default(c, &ctx, atom);
3815
free_and_return:
3816 3817 3818
    av_free(moov_data);
    av_free(cmov_data);
    return ret;
3819 3820
#else
    av_log(c->fc, AV_LOG_ERROR, "this file requires zlib support compiled in\n");
3821
    return AVERROR(ENOSYS);
3822
#endif
3823
}
3824

G
Gael Chardon 已提交
3825
/* edit list atom */
3826
static int mov_read_elst(MOVContext *c, AVIOContext *pb, MOVAtom atom)
G
Gael Chardon 已提交
3827
{
3828
    MOVStreamContext *sc;
3829
    int i, edit_count, version;
B
Baptiste Coudurier 已提交
3830

3831
    if (c->fc->nb_streams < 1 || c->ignore_editlist)
3832 3833 3834
        return 0;
    sc = c->fc->streams[c->fc->nb_streams-1]->priv_data;

3835
    version = avio_r8(pb); /* version */
3836 3837
    avio_rb24(pb); /* flags */
    edit_count = avio_rb32(pb); /* entries */
B
Baptiste Coudurier 已提交
3838

3839 3840 3841 3842 3843 3844 3845 3846 3847
    if (!edit_count)
        return 0;
    if (sc->elst_data)
        av_log(c->fc, AV_LOG_WARNING, "Duplicated ELST atom\n");
    av_free(sc->elst_data);
    sc->elst_count = 0;
    sc->elst_data = av_malloc_array(edit_count, sizeof(*sc->elst_data));
    if (!sc->elst_data)
        return AVERROR(ENOMEM);
3848

3849
    av_log(c->fc, AV_LOG_TRACE, "track[%i].edit_count = %i\n", c->fc->nb_streams-1, edit_count);
3850 3851 3852
    for (i = 0; i < edit_count && !pb->eof_reached; i++) {
        MOVElst *e = &sc->elst_data[i];

3853
        if (version == 1) {
3854 3855
            e->duration = avio_rb64(pb);
            e->time     = avio_rb64(pb);
3856
        } else {
3857 3858
            e->duration = avio_rb32(pb); /* segment duration */
            e->time     = (int32_t)avio_rb32(pb); /* media time */
3859
        }
3860
        e->rate = avio_rb32(pb) / 65536.0;
3861
        av_log(c->fc, AV_LOG_TRACE, "duration=%"PRId64" time=%"PRId64" rate=%f\n",
3862
                e->duration, e->time, e->rate);
B
Baptiste Coudurier 已提交
3863
    }
3864
    sc->elst_count = i;
3865

B
Baptiste Coudurier 已提交
3866
    return 0;
G
Gael Chardon 已提交
3867 3868
}

3869
static int mov_read_tmcd(MOVContext *c, AVIOContext *pb, MOVAtom atom)
C
Clément Bœsch 已提交
3870 3871 3872 3873 3874 3875
{
    MOVStreamContext *sc;

    if (c->fc->nb_streams < 1)
        return AVERROR_INVALIDDATA;
    sc = c->fc->streams[c->fc->nb_streams - 1]->priv_data;
3876
    sc->timecode_track = avio_rb32(pb);
C
Clément Bœsch 已提交
3877 3878 3879
    return 0;
}

3880 3881 3882 3883 3884 3885 3886 3887
static int mov_read_uuid(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    int ret;
    uint8_t uuid[16];
    static const uint8_t uuid_isml_manifest[] = {
        0xa5, 0xd4, 0x0b, 0x30, 0xe8, 0x14, 0x11, 0xdd,
        0xba, 0x2f, 0x08, 0x00, 0x20, 0x0c, 0x9a, 0x66
    };
3888 3889 3890 3891
    static const uint8_t uuid_xmp[] = {
        0xbe, 0x7a, 0xcf, 0xcb, 0x97, 0xa9, 0x42, 0xe8,
        0x9c, 0x71, 0x99, 0x94, 0x91, 0xe3, 0xaf, 0xac
    };
3892 3893 3894 3895 3896 3897 3898 3899 3900 3901 3902 3903 3904 3905 3906 3907 3908 3909 3910 3911 3912 3913 3914 3915 3916 3917 3918 3919 3920 3921 3922 3923 3924 3925 3926

    if (atom.size < sizeof(uuid) || atom.size == INT64_MAX)
        return AVERROR_INVALIDDATA;

    ret = avio_read(pb, uuid, sizeof(uuid));
    if (ret < 0) {
        return ret;
    } else if (ret != sizeof(uuid)) {
        return AVERROR_INVALIDDATA;
    }
    if (!memcmp(uuid, uuid_isml_manifest, sizeof(uuid))) {
        uint8_t *buffer, *ptr;
        char *endptr;
        size_t len = atom.size - sizeof(uuid);

        if (len < 4) {
            return AVERROR_INVALIDDATA;
        }
        ret = avio_skip(pb, 4); // zeroes
        len -= 4;

        buffer = av_mallocz(len + 1);
        if (!buffer) {
            return AVERROR(ENOMEM);
        }
        ret = avio_read(pb, buffer, len);
        if (ret < 0) {
            av_free(buffer);
            return ret;
        } else if (ret != len) {
            av_free(buffer);
            return AVERROR_INVALIDDATA;
        }

        ptr = buffer;
3927
        while ((ptr = av_stristr(ptr, "systemBitrate=\""))) {
3928 3929 3930 3931 3932 3933 3934 3935 3936 3937 3938 3939 3940 3941 3942 3943 3944
            ptr += sizeof("systemBitrate=\"") - 1;
            c->bitrates_count++;
            c->bitrates = av_realloc_f(c->bitrates, c->bitrates_count, sizeof(*c->bitrates));
            if (!c->bitrates) {
                c->bitrates_count = 0;
                av_free(buffer);
                return AVERROR(ENOMEM);
            }
            errno = 0;
            ret = strtol(ptr, &endptr, 10);
            if (ret < 0 || errno || *endptr != '"') {
                c->bitrates[c->bitrates_count - 1] = 0;
            } else {
                c->bitrates[c->bitrates_count - 1] = ret;
            }
        }

3945 3946 3947 3948 3949 3950 3951 3952 3953 3954 3955 3956 3957 3958 3959 3960 3961 3962 3963 3964 3965
        av_free(buffer);
    } else if (!memcmp(uuid, uuid_xmp, sizeof(uuid))) {
        uint8_t *buffer;
        size_t len = atom.size - sizeof(uuid);

        buffer = av_mallocz(len + 1);
        if (!buffer) {
            return AVERROR(ENOMEM);
        }
        ret = avio_read(pb, buffer, len);
        if (ret < 0) {
            av_free(buffer);
            return ret;
        } else if (ret != len) {
            av_free(buffer);
            return AVERROR_INVALIDDATA;
        }
        if (c->export_xmp) {
            buffer[len] = '\0';
            av_dict_set(&c->fc->metadata, "xmp", buffer, 0);
        }
3966 3967 3968 3969 3970
        av_free(buffer);
    }
    return 0;
}

3971 3972 3973 3974 3975 3976 3977 3978 3979 3980 3981 3982 3983 3984 3985 3986 3987 3988 3989 3990 3991 3992
static int mov_read_free(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    int ret;
    uint8_t content[16];

    if (atom.size < 8)
        return 0;

    ret = avio_read(pb, content, FFMIN(sizeof(content), atom.size));
    if (ret < 0)
        return ret;

    if (   !c->found_moov
        && !c->found_mdat
        && !memcmp(content, "Anevia\x1A\x1A", 8)
        && c->use_mfra_for == FF_MOV_FLAG_MFRA_AUTO) {
        c->use_mfra_for = FF_MOV_FLAG_MFRA_PTS;
    }

    return 0;
}

3993 3994 3995 3996 3997 3998 3999 4000 4001 4002 4003 4004 4005 4006 4007 4008 4009 4010 4011 4012 4013 4014 4015 4016 4017 4018 4019 4020 4021 4022
static int mov_read_frma(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    uint32_t format = avio_rl32(pb);
    MOVStreamContext *sc;
    enum AVCodecID id;
    AVStream *st;

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams - 1];
    sc = st->priv_data;

    switch (sc->format)
    {
    case MKTAG('e','n','c','v'):        // encrypted video
    case MKTAG('e','n','c','a'):        // encrypted audio
        id = mov_codec_id(st, format);
        if (st->codec->codec_id != AV_CODEC_ID_NONE &&
            st->codec->codec_id != id) {
            av_log(c->fc, AV_LOG_WARNING,
                   "ignoring 'frma' atom of '%.4s', stream has codec id %d\n",
                   (char*)&format, st->codec->codec_id);
            break;
        }

        st->codec->codec_id = id;
        sc->format = format;
        break;

    default:
4023 4024 4025 4026 4027
        if (format != sc->format) {
            av_log(c->fc, AV_LOG_WARNING,
                   "ignoring 'frma' atom of '%.4s', stream format is '%.4s'\n",
                   (char*)&format, (char*)&sc->format);
        }
4028 4029 4030 4031 4032 4033 4034 4035 4036 4037 4038 4039 4040 4041 4042 4043 4044 4045 4046 4047 4048 4049 4050 4051 4052 4053 4054 4055 4056 4057 4058 4059 4060 4061 4062 4063 4064 4065 4066 4067 4068 4069 4070 4071 4072 4073 4074 4075 4076 4077 4078 4079 4080 4081 4082 4083 4084 4085 4086 4087 4088 4089 4090 4091 4092 4093 4094 4095 4096 4097 4098 4099 4100 4101 4102 4103 4104 4105 4106 4107 4108 4109 4110 4111 4112 4113 4114 4115 4116 4117 4118 4119 4120 4121 4122 4123 4124 4125 4126 4127 4128 4129 4130 4131 4132 4133 4134 4135 4136 4137 4138 4139 4140 4141 4142 4143 4144 4145 4146 4147 4148 4149 4150 4151 4152
        break;
    }

    return 0;
}

static int mov_read_senc(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    AVStream *st;
    MOVStreamContext *sc;
    size_t auxiliary_info_size;

    if (c->decryption_key_len == 0 || c->fc->nb_streams < 1)
        return 0;

    st = c->fc->streams[c->fc->nb_streams - 1];
    sc = st->priv_data;

    if (sc->cenc.aes_ctr) {
        av_log(c->fc, AV_LOG_ERROR, "duplicate senc atom\n");
        return AVERROR_INVALIDDATA;
    }

    avio_r8(pb); /* version */
    sc->cenc.use_subsamples = avio_rb24(pb) & 0x02; /* flags */

    avio_rb32(pb);        /* entries */

    if (atom.size < 8) {
        av_log(c->fc, AV_LOG_ERROR, "senc atom size %"PRId64" too small\n", atom.size);
        return AVERROR_INVALIDDATA;
    }

    /* save the auxiliary info as is */
    auxiliary_info_size = atom.size - 8;

    sc->cenc.auxiliary_info = av_malloc(auxiliary_info_size);
    if (!sc->cenc.auxiliary_info) {
        return AVERROR(ENOMEM);
    }

    sc->cenc.auxiliary_info_end = sc->cenc.auxiliary_info + auxiliary_info_size;

    sc->cenc.auxiliary_info_pos = sc->cenc.auxiliary_info;

    if (avio_read(pb, sc->cenc.auxiliary_info, auxiliary_info_size) != auxiliary_info_size) {
        av_log(c->fc, AV_LOG_ERROR, "failed to read the auxiliary info");
        return AVERROR_INVALIDDATA;
    }

    /* initialize the cipher */
    sc->cenc.aes_ctr = av_aes_ctr_alloc();
    if (!sc->cenc.aes_ctr) {
        return AVERROR(ENOMEM);
    }

    return av_aes_ctr_init(sc->cenc.aes_ctr, c->decryption_key);
}

static int cenc_filter(MOVContext *c, MOVStreamContext *sc, uint8_t *input, int size)
{
    uint32_t encrypted_bytes;
    uint16_t subsample_count;
    uint16_t clear_bytes;
    uint8_t* input_end = input + size;

    /* read the iv */
    if (AES_CTR_IV_SIZE > sc->cenc.auxiliary_info_end - sc->cenc.auxiliary_info_pos) {
        av_log(c->fc, AV_LOG_ERROR, "failed to read iv from the auxiliary info\n");
        return AVERROR_INVALIDDATA;
    }

    av_aes_ctr_set_iv(sc->cenc.aes_ctr, sc->cenc.auxiliary_info_pos);
    sc->cenc.auxiliary_info_pos += AES_CTR_IV_SIZE;

    if (!sc->cenc.use_subsamples)
    {
        /* decrypt the whole packet */
        av_aes_ctr_crypt(sc->cenc.aes_ctr, input, input, size);
        return 0;
    }

    /* read the subsample count */
    if (sizeof(uint16_t) > sc->cenc.auxiliary_info_end - sc->cenc.auxiliary_info_pos) {
        av_log(c->fc, AV_LOG_ERROR, "failed to read subsample count from the auxiliary info\n");
        return AVERROR_INVALIDDATA;
    }

    subsample_count = AV_RB16(sc->cenc.auxiliary_info_pos);
    sc->cenc.auxiliary_info_pos += sizeof(uint16_t);

    for (; subsample_count > 0; subsample_count--)
    {
        if (6 > sc->cenc.auxiliary_info_end - sc->cenc.auxiliary_info_pos) {
            av_log(c->fc, AV_LOG_ERROR, "failed to read subsample from the auxiliary info\n");
            return AVERROR_INVALIDDATA;
        }

        /* read the number of clear / encrypted bytes */
        clear_bytes = AV_RB16(sc->cenc.auxiliary_info_pos);
        sc->cenc.auxiliary_info_pos += sizeof(uint16_t);
        encrypted_bytes = AV_RB32(sc->cenc.auxiliary_info_pos);
        sc->cenc.auxiliary_info_pos += sizeof(uint32_t);

        if ((uint64_t)clear_bytes + encrypted_bytes > input_end - input) {
            av_log(c->fc, AV_LOG_ERROR, "subsample size exceeds the packet size left\n");
            return AVERROR_INVALIDDATA;
        }

        /* skip the clear bytes */
        input += clear_bytes;

        /* decrypt the encrypted bytes */
        av_aes_ctr_crypt(sc->cenc.aes_ctr, input, input, encrypted_bytes);
        input += encrypted_bytes;
    }

    if (input < input_end) {
        av_log(c->fc, AV_LOG_ERROR, "leftover packet bytes after subsample processing\n");
        return AVERROR_INVALIDDATA;
    }

    return 0;
}

4153
static const MOVParseTableEntry mov_default_parse_table[] = {
4154
{ MKTAG('A','C','L','R'), mov_read_aclr },
C
Carl Eugen Hoyos 已提交
4155
{ MKTAG('A','P','R','G'), mov_read_avid },
P
Piotr Bandurski 已提交
4156
{ MKTAG('A','A','L','P'), mov_read_avid },
4157
{ MKTAG('A','R','E','S'), mov_read_ares },
4158
{ MKTAG('a','v','s','s'), mov_read_avss },
D
David Conrad 已提交
4159
{ MKTAG('c','h','p','l'), mov_read_chpl },
4160
{ MKTAG('c','o','6','4'), mov_read_stco },
4161
{ MKTAG('c','o','l','r'), mov_read_colr },
4162 4163
{ MKTAG('c','t','t','s'), mov_read_ctts }, /* composition time to sample */
{ MKTAG('d','i','n','f'), mov_read_default },
4164
{ MKTAG('D','p','x','E'), mov_read_dpxe },
4165 4166 4167 4168
{ MKTAG('d','r','e','f'), mov_read_dref },
{ MKTAG('e','d','t','s'), mov_read_default },
{ MKTAG('e','l','s','t'), mov_read_elst },
{ MKTAG('e','n','d','a'), mov_read_enda },
4169
{ MKTAG('f','i','e','l'), mov_read_fiel },
4170
{ MKTAG('a','d','r','m'), mov_read_adrm },
4171 4172 4173
{ MKTAG('f','t','y','p'), mov_read_ftyp },
{ MKTAG('g','l','b','l'), mov_read_glbl },
{ MKTAG('h','d','l','r'), mov_read_hdlr },
4174
{ MKTAG('i','l','s','t'), mov_read_ilst },
4175
{ MKTAG('j','p','2','h'), mov_read_jp2h },
4176 4177 4178
{ MKTAG('m','d','a','t'), mov_read_mdat },
{ MKTAG('m','d','h','d'), mov_read_mdhd },
{ MKTAG('m','d','i','a'), mov_read_default },
4179
{ MKTAG('m','e','t','a'), mov_read_meta },
4180 4181 4182 4183 4184
{ MKTAG('m','i','n','f'), mov_read_default },
{ MKTAG('m','o','o','f'), mov_read_moof },
{ MKTAG('m','o','o','v'), mov_read_moov },
{ MKTAG('m','v','e','x'), mov_read_default },
{ MKTAG('m','v','h','d'), mov_read_mvhd },
P
Piotr Bandurski 已提交
4185
{ MKTAG('S','M','I',' '), mov_read_svq3 },
4186
{ MKTAG('a','l','a','c'), mov_read_alac }, /* alac specific atom */
4187
{ MKTAG('a','v','c','C'), mov_read_glbl },
4188
{ MKTAG('p','a','s','p'), mov_read_pasp },
4189
{ MKTAG('s','i','d','x'), mov_read_sidx },
4190 4191
{ MKTAG('s','t','b','l'), mov_read_default },
{ MKTAG('s','t','c','o'), mov_read_stco },
4192
{ MKTAG('s','t','p','s'), mov_read_stps },
M
Martin Storsjö 已提交
4193
{ MKTAG('s','t','r','f'), mov_read_strf },
4194 4195 4196 4197 4198
{ MKTAG('s','t','s','c'), mov_read_stsc },
{ MKTAG('s','t','s','d'), mov_read_stsd }, /* sample description */
{ MKTAG('s','t','s','s'), mov_read_stss }, /* sync sample */
{ MKTAG('s','t','s','z'), mov_read_stsz }, /* sample size */
{ MKTAG('s','t','t','s'), mov_read_stts },
4199
{ MKTAG('s','t','z','2'), mov_read_stsz }, /* compact sample size */
4200
{ MKTAG('t','k','h','d'), mov_read_tkhd }, /* track header */
M
Martin Storsjö 已提交
4201
{ MKTAG('t','f','d','t'), mov_read_tfdt },
4202 4203 4204
{ MKTAG('t','f','h','d'), mov_read_tfhd }, /* track fragment header */
{ MKTAG('t','r','a','k'), mov_read_trak },
{ MKTAG('t','r','a','f'), mov_read_default },
4205 4206
{ MKTAG('t','r','e','f'), mov_read_default },
{ MKTAG('t','m','c','d'), mov_read_tmcd },
D
David Conrad 已提交
4207
{ MKTAG('c','h','a','p'), mov_read_chap },
4208 4209
{ MKTAG('t','r','e','x'), mov_read_trex },
{ MKTAG('t','r','u','n'), mov_read_trun },
B
Baptiste Coudurier 已提交
4210
{ MKTAG('u','d','t','a'), mov_read_default },
4211 4212
{ MKTAG('w','a','v','e'), mov_read_wave },
{ MKTAG('e','s','d','s'), mov_read_esds },
4213
{ MKTAG('d','a','c','3'), mov_read_dac3 }, /* AC-3 info */
4214
{ MKTAG('d','e','c','3'), mov_read_dec3 }, /* EAC-3 info */
4215
{ MKTAG('d','d','t','s'), mov_read_ddts }, /* DTS audio descriptor */
4216
{ MKTAG('w','i','d','e'), mov_read_wide }, /* place holder */
4217
{ MKTAG('w','f','e','x'), mov_read_wfex },
4218
{ MKTAG('c','m','o','v'), mov_read_cmov },
4219
{ MKTAG('c','h','a','n'), mov_read_chan }, /* channel layout */
M
Martin Storsjö 已提交
4220
{ MKTAG('d','v','c','1'), mov_read_dvc1 },
4221
{ MKTAG('s','b','g','p'), mov_read_sbgp },
Y
Yusuke Nakamura 已提交
4222
{ MKTAG('h','v','c','C'), mov_read_glbl },
4223
{ MKTAG('u','u','i','d'), mov_read_uuid },
4224
{ MKTAG('C','i','n', 0x8e), mov_read_targa_y216 },
4225
{ MKTAG('f','r','e','e'), mov_read_free },
4226
{ MKTAG('-','-','-','-'), mov_read_custom },
4227 4228 4229
{ MKTAG('s','i','n','f'), mov_read_default },
{ MKTAG('f','r','m','a'), mov_read_frma },
{ MKTAG('s','e','n','c'), mov_read_senc },
B
Baptiste Coudurier 已提交
4230
{ 0, NULL }
4231 4232
};

4233 4234 4235 4236 4237 4238
static int mov_read_default(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    int64_t total_size = 0;
    MOVAtom a;
    int i;

4239 4240 4241 4242 4243 4244
    if (c->atom_depth > 10) {
        av_log(c->fc, AV_LOG_ERROR, "Atoms too deeply nested\n");
        return AVERROR_INVALIDDATA;
    }
    c->atom_depth ++;

4245 4246
    if (atom.size < 0)
        atom.size = INT64_MAX;
4247
    while (total_size + 8 <= atom.size && !avio_feof(pb)) {
4248 4249 4250 4251 4252 4253
        int (*parse)(MOVContext*, AVIOContext*, MOVAtom) = NULL;
        a.size = atom.size;
        a.type=0;
        if (atom.size >= 8) {
            a.size = avio_rb32(pb);
            a.type = avio_rl32(pb);
4254 4255 4256 4257 4258
            if (a.type == MKTAG('f','r','e','e') &&
                a.size >= 8 &&
                c->moov_retry) {
                uint8_t buf[8];
                uint32_t *type = (uint32_t *)buf + 1;
4259 4260
                if (avio_read(pb, buf, 8) != 8)
                    return AVERROR_INVALIDDATA;
4261 4262 4263 4264 4265 4266 4267
                avio_seek(pb, -8, SEEK_CUR);
                if (*type == MKTAG('m','v','h','d') ||
                    *type == MKTAG('c','m','o','v')) {
                    av_log(c->fc, AV_LOG_ERROR, "Detected moov in a free atom.\n");
                    a.type = MKTAG('m','o','o','v');
                }
            }
4268 4269 4270 4271 4272 4273 4274
            if (atom.type != MKTAG('r','o','o','t') &&
                atom.type != MKTAG('m','o','o','v'))
            {
                if (a.type == MKTAG('t','r','a','k') || a.type == MKTAG('m','d','a','t'))
                {
                    av_log(c->fc, AV_LOG_ERROR, "Broken file, trak/mdat not at top-level\n");
                    avio_skip(pb, -8);
4275
                    c->atom_depth --;
4276 4277 4278 4279
                    return 0;
                }
            }
            total_size += 8;
4280
            if (a.size == 1 && total_size + 8 <= atom.size) { /* 64 bit extended size */
4281 4282 4283
                a.size = avio_rb64(pb) - 8;
                total_size += 8;
            }
4284
        }
4285
        av_log(c->fc, AV_LOG_TRACE, "type: %08x '%.4s' parent:'%.4s' sz: %"PRId64" %"PRId64" %"PRId64"\n",
4286 4287
                a.type, (char*)&a.type, (char*)&atom.type, a.size, total_size, atom.size);
        if (a.size == 0) {
4288
            a.size = atom.size - total_size + 8;
4289 4290 4291 4292 4293 4294 4295 4296 4297 4298 4299 4300 4301 4302 4303 4304 4305
        }
        a.size -= 8;
        if (a.size < 0)
            break;
        a.size = FFMIN(a.size, atom.size - total_size);

        for (i = 0; mov_default_parse_table[i].type; i++)
            if (mov_default_parse_table[i].type == a.type) {
                parse = mov_default_parse_table[i].parse;
                break;
            }

        // container is user data
        if (!parse && (atom.type == MKTAG('u','d','t','a') ||
                       atom.type == MKTAG('i','l','s','t')))
            parse = mov_read_udta_string;

4306 4307 4308 4309 4310 4311 4312 4313
        // Supports parsing the QuickTime Metadata Keys.
        // https://developer.apple.com/library/mac/documentation/QuickTime/QTFF/Metadata/Metadata.html
        if (!parse && c->found_hdlr_mdta &&
            atom.type == MKTAG('m','e','t','a') &&
            a.type == MKTAG('k','e','y','s')) {
            parse = mov_read_keys;
        }

4314 4315 4316 4317 4318 4319
        if (!parse) { /* skip leaf atoms data */
            avio_skip(pb, a.size);
        } else {
            int64_t start_pos = avio_tell(pb);
            int64_t left;
            int err = parse(c, pb, a);
4320 4321
            if (err < 0) {
                c->atom_depth --;
4322
                return err;
4323
            }
4324
            if (c->found_moov && c->found_mdat &&
4325
                ((!pb->seekable || c->fc->flags & AVFMT_FLAG_IGNIDX || c->fragment_index_complete) ||
4326
                 start_pos + a.size == avio_size(pb))) {
4327
                if (!pb->seekable || c->fc->flags & AVFMT_FLAG_IGNIDX || c->fragment_index_complete)
4328
                    c->next_root_atom = start_pos + a.size;
4329
                c->atom_depth --;
4330 4331 4332 4333 4334
                return 0;
            }
            left = a.size - avio_tell(pb) + start_pos;
            if (left > 0) /* skip garbage at atom end */
                avio_skip(pb, left);
4335 4336 4337 4338
            else if (left < 0) {
                av_log(c->fc, AV_LOG_WARNING,
                       "overread end of atom '%.4s' by %"PRId64" bytes\n",
                       (char*)&a.type, -left);
4339 4340
                avio_seek(pb, left, SEEK_CUR);
            }
4341 4342 4343 4344 4345 4346 4347 4348
        }

        total_size += a.size;
    }

    if (total_size < atom.size && atom.size < 0x7ffff)
        avio_skip(pb, atom.size - total_size);

4349
    c->atom_depth --;
4350 4351 4352
    return 0;
}

F
Fabrice Bellard 已提交
4353 4354
static int mov_probe(AVProbeData *p)
{
4355
    int64_t offset;
4356
    uint32_t tag;
4357
    int score = 0;
4358
    int moov_offset = -1;
4359

F
Fabrice Bellard 已提交
4360
    /* check file header */
4361
    offset = 0;
4362
    for (;;) {
4363 4364
        /* ignore invalid offset */
        if ((offset + 8) > (unsigned int)p->buf_size)
4365
            break;
4366
        tag = AV_RL32(p->buf + offset + 4);
4367
        switch(tag) {
4368
        /* check for obvious tags */
4369
        case MKTAG('m','o','o','v'):
4370
            moov_offset = offset + 4;
4371 4372 4373
        case MKTAG('m','d','a','t'):
        case MKTAG('p','n','o','t'): /* detect movs with preview pics like ew.mov and april.mov */
        case MKTAG('u','d','t','a'): /* Packet Video PVAuthor adds this and a lot of more junk */
4374
        case MKTAG('f','t','y','p'):
4375 4376 4377 4378
            if (AV_RB32(p->buf+offset) < 8 &&
                (AV_RB32(p->buf+offset) != 1 ||
                 offset + 12 > (unsigned int)p->buf_size ||
                 AV_RB64(p->buf+offset + 8) == 0)) {
4379
                score = FFMAX(score, AVPROBE_SCORE_EXTENSION);
4380
            } else if (tag == MKTAG('f','t','y','p') &&
4381 4382 4383
                       (   AV_RL32(p->buf + offset + 8) == MKTAG('j','p','2',' ')
                        || AV_RL32(p->buf + offset + 8) == MKTAG('j','p','x',' ')
                    )) {
4384
                score = FFMAX(score, 5);
4385 4386 4387
            } else {
                score = AVPROBE_SCORE_MAX;
            }
4388 4389
            offset = FFMAX(4, AV_RB32(p->buf+offset)) + offset;
            break;
4390
        /* those are more common words, so rate then a bit less */
4391 4392 4393 4394 4395
        case MKTAG('e','d','i','w'): /* xdcam files have reverted first tags */
        case MKTAG('w','i','d','e'):
        case MKTAG('f','r','e','e'):
        case MKTAG('j','u','n','k'):
        case MKTAG('p','i','c','t'):
4396 4397 4398
            score  = FFMAX(score, AVPROBE_SCORE_MAX - 5);
            offset = FFMAX(4, AV_RB32(p->buf+offset)) + offset;
            break;
B
Baptiste Coudurier 已提交
4399
        case MKTAG(0x82,0x82,0x7f,0x7d):
4400 4401 4402
        case MKTAG('s','k','i','p'):
        case MKTAG('u','u','i','d'):
        case MKTAG('p','r','f','l'):
4403
            /* if we only find those cause probedata is too small at least rate them */
4404
            score  = FFMAX(score, AVPROBE_SCORE_EXTENSION);
4405
            offset = FFMAX(4, AV_RB32(p->buf+offset)) + offset;
4406 4407
            break;
        default:
4408 4409 4410
            offset = FFMAX(4, AV_RB32(p->buf+offset)) + offset;
        }
    }
4411
    if(score > AVPROBE_SCORE_MAX - 50 && moov_offset != -1) {
4412 4413 4414 4415
        /* moov atom in the header - we should make sure that this is not a
         * MOV-packed MPEG-PS */
        offset = moov_offset;

4416 4417 4418 4419 4420 4421 4422 4423
        while(offset < (p->buf_size - 16)){ /* Sufficient space */
               /* We found an actual hdlr atom */
            if(AV_RL32(p->buf + offset     ) == MKTAG('h','d','l','r') &&
               AV_RL32(p->buf + offset +  8) == MKTAG('m','h','l','r') &&
               AV_RL32(p->buf + offset + 12) == MKTAG('M','P','E','G')){
                av_log(NULL, AV_LOG_WARNING, "Found media data tag MPEG indicating this is a MOV-packed MPEG-PS.\n");
                /* We found a media handler reference atom describing an
                 * MPEG-PS-in-MOV, return a
4424 4425 4426 4427 4428 4429
                 * low score to force expanding the probe window until
                 * mpegps_probe finds what it needs */
                return 5;
            }else
                /* Keep looking */
                offset+=2;
4430
        }
4431
    }
4432 4433

    return score;
F
Fabrice Bellard 已提交
4434 4435
}

D
David Conrad 已提交
4436 4437 4438 4439 4440 4441 4442
// must be done after parsing all trak because there's no order requirement
static void mov_read_chapters(AVFormatContext *s)
{
    MOVContext *mov = s->priv_data;
    AVStream *st = NULL;
    MOVStreamContext *sc;
    int64_t cur_pos;
4443
    int i;
D
David Conrad 已提交
4444 4445 4446 4447 4448 4449 4450 4451 4452 4453 4454 4455 4456

    for (i = 0; i < s->nb_streams; i++)
        if (s->streams[i]->id == mov->chapter_track) {
            st = s->streams[i];
            break;
        }
    if (!st) {
        av_log(s, AV_LOG_ERROR, "Referenced QT chapter track not found\n");
        return;
    }

    st->discard = AVDISCARD_ALL;
    sc = st->priv_data;
4457
    cur_pos = avio_tell(sc->pb);
D
David Conrad 已提交
4458 4459 4460 4461

    for (i = 0; i < st->nb_index_entries; i++) {
        AVIndexEntry *sample = &st->index_entries[i];
        int64_t end = i+1 < st->nb_index_entries ? st->index_entries[i+1].timestamp : st->duration;
4462 4463 4464
        uint8_t *title;
        uint16_t ch;
        int len, title_len;
D
David Conrad 已提交
4465

4466 4467 4468 4469 4470
        if (end < sample->timestamp) {
            av_log(s, AV_LOG_WARNING, "ignoring stream duration which is shorter than chapters\n");
            end = AV_NOPTS_VALUE;
        }

A
Anton Khirnov 已提交
4471
        if (avio_seek(sc->pb, sample->pos, SEEK_SET) != sample->pos) {
D
David Conrad 已提交
4472 4473 4474 4475 4476
            av_log(s, AV_LOG_ERROR, "Chapter %d not found in file\n", i);
            goto finish;
        }

        // the first two bytes are the length of the title
4477
        len = avio_rb16(sc->pb);
D
David Conrad 已提交
4478 4479
        if (len > sample->size-2)
            continue;
4480 4481 4482
        title_len = 2*len + 1;
        if (!(title = av_mallocz(title_len)))
            goto finish;
D
David Conrad 已提交
4483 4484 4485 4486

        // The samples could theoretically be in any encoding if there's an encd
        // atom following, but in practice are only utf-8 or utf-16, distinguished
        // instead by the presence of a BOM
4487 4488 4489 4490 4491 4492 4493 4494 4495 4496 4497
        if (!len) {
            title[0] = 0;
        } else {
            ch = avio_rb16(sc->pb);
            if (ch == 0xfeff)
                avio_get_str16be(sc->pb, len, title, title_len);
            else if (ch == 0xfffe)
                avio_get_str16le(sc->pb, len, title, title_len);
            else {
                AV_WB16(title, ch);
                if (len == 1 || len == 2)
4498
                    title[len] = 0;
4499
                else
4500
                    avio_get_str(sc->pb, INT_MAX, title + 2, len - 1);
4501
            }
D
David Conrad 已提交
4502 4503
        }

4504
        avpriv_new_chapter(s, i, st->time_base, sample->timestamp, end, title);
4505
        av_freep(&title);
D
David Conrad 已提交
4506 4507
    }
finish:
A
Anton Khirnov 已提交
4508
    avio_seek(sc->pb, cur_pos, SEEK_SET);
D
David Conrad 已提交
4509 4510
}

4511
static int parse_timecode_in_framenum_format(AVFormatContext *s, AVStream *st,
4512
                                             uint32_t value, int flags)
4513
{
4514 4515 4516 4517 4518 4519 4520
    AVTimecode tc;
    char buf[AV_TIMECODE_STR_SIZE];
    AVRational rate = {st->codec->time_base.den,
                       st->codec->time_base.num};
    int ret = av_timecode_init(&tc, rate, flags, 0, s);
    if (ret < 0)
        return ret;
4521
    av_dict_set(&st->metadata, "timecode",
4522
                av_timecode_make_string(&tc, buf, value), 0);
4523 4524 4525 4526 4527 4528
    return 0;
}

static int mov_read_timecode_track(AVFormatContext *s, AVStream *st)
{
    MOVStreamContext *sc = st->priv_data;
4529
    int flags = 0;
4530 4531 4532 4533 4534 4535 4536 4537 4538
    int64_t cur_pos = avio_tell(sc->pb);
    uint32_t value;

    if (!st->nb_index_entries)
        return -1;

    avio_seek(sc->pb, st->index_entries->pos, SEEK_SET);
    value = avio_rb32(s->pb);

4539 4540 4541 4542
    if (sc->tmcd_flags & 0x0001) flags |= AV_TIMECODE_FLAG_DROPFRAME;
    if (sc->tmcd_flags & 0x0002) flags |= AV_TIMECODE_FLAG_24HOURSMAX;
    if (sc->tmcd_flags & 0x0004) flags |= AV_TIMECODE_FLAG_ALLOWNEGATIVE;

4543 4544 4545 4546 4547
    /* Assume Counter flag is set to 1 in tmcd track (even though it is likely
     * not the case) and thus assume "frame number format" instead of QT one.
     * No sample with tmcd track can be found with a QT timecode at the moment,
     * despite what the tmcd track "suggests" (Counter flag set to 0 means QT
     * format). */
4548
    parse_timecode_in_framenum_format(s, st, value, flags);
4549 4550 4551 4552 4553

    avio_seek(sc->pb, cur_pos, SEEK_SET);
    return 0;
}

4554 4555 4556 4557 4558 4559 4560 4561 4562
static int mov_read_close(AVFormatContext *s)
{
    MOVContext *mov = s->priv_data;
    int i, j;

    for (i = 0; i < s->nb_streams; i++) {
        AVStream *st = s->streams[i];
        MOVStreamContext *sc = st->priv_data;

4563 4564 4565
        if (!sc)
            continue;

4566 4567 4568 4569 4570 4571
        av_freep(&sc->ctts_data);
        for (j = 0; j < sc->drefs_count; j++) {
            av_freep(&sc->drefs[j].path);
            av_freep(&sc->drefs[j].dir);
        }
        av_freep(&sc->drefs);
4572 4573 4574

        sc->drefs_count = 0;

4575
        if (!sc->pb_is_copied)
4576
            ff_format_io_close(s, &sc->pb);
4577

4578
        sc->pb = NULL;
4579 4580
        av_freep(&sc->chunk_offsets);
        av_freep(&sc->stsc_data);
4581 4582
        av_freep(&sc->sample_sizes);
        av_freep(&sc->keyframes);
4583
        av_freep(&sc->stts_data);
4584
        av_freep(&sc->stps_data);
4585
        av_freep(&sc->elst_data);
4586
        av_freep(&sc->rap_group);
4587
        av_freep(&sc->display_matrix);
4588 4589 4590

        av_freep(&sc->cenc.auxiliary_info);
        av_aes_ctr_free(sc->cenc.aes_ctr);
4591 4592 4593
    }

    if (mov->dv_demux) {
4594 4595
        avformat_free_context(mov->dv_fctx);
        mov->dv_fctx = NULL;
4596 4597
    }

4598 4599 4600 4601 4602 4603 4604
    if (mov->meta_keys) {
        for (i = 1; i < mov->meta_keys_count; i++) {
            av_freep(&mov->meta_keys[i]);
        }
        av_freep(&mov->meta_keys);
    }

4605
    av_freep(&mov->trex_data);
4606
    av_freep(&mov->bitrates);
4607

4608 4609 4610 4611 4612 4613 4614
    for (i = 0; i < mov->fragment_index_count; i++) {
        MOVFragmentIndex* index = mov->fragment_index_data[i];
        av_freep(&index->items);
        av_freep(&mov->fragment_index_data[i]);
    }
    av_freep(&mov->fragment_index_data);

4615 4616
    av_freep(&mov->aes_decrypt);

4617 4618 4619
    return 0;
}

4620 4621
static int tmcd_is_referenced(AVFormatContext *s, int tmcd_id)
{
4622
    int i;
4623 4624 4625 4626 4627

    for (i = 0; i < s->nb_streams; i++) {
        AVStream *st = s->streams[i];
        MOVStreamContext *sc = st->priv_data;

4628 4629 4630
        if (st->codec->codec_type == AVMEDIA_TYPE_VIDEO &&
            sc->timecode_track == tmcd_id)
            return 1;
4631 4632 4633 4634 4635 4636 4637 4638 4639 4640 4641 4642 4643 4644 4645 4646 4647 4648 4649 4650 4651 4652 4653
    }
    return 0;
}

/* look for a tmcd track not referenced by any video track, and export it globally */
static void export_orphan_timecode(AVFormatContext *s)
{
    int i;

    for (i = 0; i < s->nb_streams; i++) {
        AVStream *st = s->streams[i];

        if (st->codec->codec_tag  == MKTAG('t','m','c','d') &&
            !tmcd_is_referenced(s, i + 1)) {
            AVDictionaryEntry *tcr = av_dict_get(st->metadata, "timecode", NULL, 0);
            if (tcr) {
                av_dict_set(&s->metadata, "timecode", tcr->value, 0);
                break;
            }
        }
    }
}

4654 4655 4656
static int read_tfra(MOVContext *mov, AVIOContext *f)
{
    MOVFragmentIndex* index = NULL;
4657
    int version, fieldlength, i, j;
4658 4659
    int64_t pos = avio_tell(f);
    uint32_t size = avio_rb32(f);
4660 4661
    void *tmp;

4662
    if (avio_rb32(f) != MKBETAG('t', 'f', 'r', 'a')) {
4663
        return 1;
4664 4665 4666 4667 4668 4669
    }
    av_log(mov->fc, AV_LOG_VERBOSE, "found tfra\n");
    index = av_mallocz(sizeof(MOVFragmentIndex));
    if (!index) {
        return AVERROR(ENOMEM);
    }
4670 4671 4672 4673 4674

    tmp = av_realloc_array(mov->fragment_index_data,
                           mov->fragment_index_count + 1,
                           sizeof(MOVFragmentIndex*));
    if (!tmp) {
4675
        av_freep(&index);
4676
        return AVERROR(ENOMEM);
4677
    }
4678 4679
    mov->fragment_index_data = tmp;
    mov->fragment_index_data[mov->fragment_index_count++] = index;
4680 4681 4682 4683 4684 4685

    version = avio_r8(f);
    avio_rb24(f);
    index->track_id = avio_rb32(f);
    fieldlength = avio_rb32(f);
    index->item_count = avio_rb32(f);
4686 4687
    index->items = av_mallocz_array(
            index->item_count, sizeof(MOVFragmentIndexItem));
4688
    if (!index->items) {
4689
        index->item_count = 0;
4690 4691 4692 4693 4694 4695 4696 4697 4698 4699 4700 4701 4702 4703 4704 4705 4706 4707 4708 4709 4710 4711 4712 4713 4714 4715 4716 4717 4718
        return AVERROR(ENOMEM);
    }
    for (i = 0; i < index->item_count; i++) {
        int64_t time, offset;
        if (version == 1) {
            time   = avio_rb64(f);
            offset = avio_rb64(f);
        } else {
            time   = avio_rb32(f);
            offset = avio_rb32(f);
        }
        index->items[i].time = time;
        index->items[i].moof_offset = offset;
        for (j = 0; j < ((fieldlength >> 4) & 3) + 1; j++)
            avio_r8(f);
        for (j = 0; j < ((fieldlength >> 2) & 3) + 1; j++)
            avio_r8(f);
        for (j = 0; j < ((fieldlength >> 0) & 3) + 1; j++)
            avio_r8(f);
    }

    avio_seek(f, pos + size, SEEK_SET);
    return 0;
}

static int mov_read_mfra(MOVContext *c, AVIOContext *f)
{
    int64_t stream_size = avio_size(f);
    int64_t original_pos = avio_tell(f);
4719
    int64_t seek_ret;
4720 4721
    int32_t mfra_size;
    int ret = -1;
4722 4723 4724 4725
    if ((seek_ret = avio_seek(f, stream_size - 4, SEEK_SET)) < 0) {
        ret = seek_ret;
        goto fail;
    }
4726 4727 4728 4729 4730
    mfra_size = avio_rb32(f);
    if (mfra_size < 0 || mfra_size > stream_size) {
        av_log(c->fc, AV_LOG_DEBUG, "doesn't look like mfra (unreasonable size)\n");
        goto fail;
    }
4731 4732 4733 4734
    if ((seek_ret = avio_seek(f, -mfra_size, SEEK_CUR)) < 0) {
        ret = seek_ret;
        goto fail;
    }
4735 4736 4737 4738 4739 4740 4741 4742 4743
    if (avio_rb32(f) != mfra_size) {
        av_log(c->fc, AV_LOG_DEBUG, "doesn't look like mfra (size mismatch)\n");
        goto fail;
    }
    if (avio_rb32(f) != MKBETAG('m', 'f', 'r', 'a')) {
        av_log(c->fc, AV_LOG_DEBUG, "doesn't look like mfra (tag mismatch)\n");
        goto fail;
    }
    av_log(c->fc, AV_LOG_VERBOSE, "stream has mfra\n");
4744 4745 4746 4747 4748 4749
    do {
        ret = read_tfra(c, f);
        if (ret < 0)
            goto fail;
    } while (!ret);
    ret = 0;
4750
fail:
4751 4752
    seek_ret = avio_seek(f, original_pos, SEEK_SET);
    if (seek_ret < 0) {
4753 4754
        av_log(c->fc, AV_LOG_ERROR,
               "failed to seek back after looking for mfra\n");
4755 4756
        ret = seek_ret;
    }
4757 4758 4759
    return ret;
}

4760
static int mov_read_header(AVFormatContext *s)
4761
{
4762
    MOVContext *mov = s->priv_data;
4763
    AVIOContext *pb = s->pb;
4764
    int j, err;
4765
    MOVAtom atom = { AV_RL32("root") };
4766
    int i;
4767

4768 4769 4770 4771 4772 4773
    if (mov->decryption_key_len != 0 && mov->decryption_key_len != AES_CTR_KEY_SIZE) {
        av_log(s, AV_LOG_ERROR, "Invalid decryption key len %d expected %d\n",
            mov->decryption_key_len, AES_CTR_KEY_SIZE);
        return AVERROR(EINVAL);
    }

4774
    mov->fc = s;
4775
    mov->trak_index = -1;
4776
    /* .mov and .mp4 aren't streamable anyway (only progressive download if moov is before mdat) */
4777
    if (pb->seekable)
A
Anton Khirnov 已提交
4778
        atom.size = avio_size(pb);
4779
    else
B
Baptiste Coudurier 已提交
4780
        atom.size = INT64_MAX;
4781 4782

    /* check MOV header */
4783 4784 4785
    do {
    if (mov->moov_retry)
        avio_seek(pb, 0, SEEK_SET);
B
Baptiste Coudurier 已提交
4786
    if ((err = mov_read_default(mov, pb, atom)) < 0) {
4787
        av_log(s, AV_LOG_ERROR, "error reading header\n");
4788
        mov_read_close(s);
B
Baptiste Coudurier 已提交
4789 4790
        return err;
    }
4791
    } while (pb->seekable && !mov->found_moov && !mov->moov_retry++);
B
Baptiste Coudurier 已提交
4792 4793
    if (!mov->found_moov) {
        av_log(s, AV_LOG_ERROR, "moov atom not found\n");
4794
        mov_read_close(s);
4795
        return AVERROR_INVALIDDATA;
4796
    }
4797
    av_log(mov->fc, AV_LOG_TRACE, "on_parse_exit_offset=%"PRId64"\n", avio_tell(pb));
4798

4799
    if (pb->seekable) {
4800
        if (mov->chapter_track > 0 && !mov->ignore_chapters)
4801 4802 4803 4804 4805
            mov_read_chapters(s);
        for (i = 0; i < s->nb_streams; i++)
            if (s->streams[i]->codec->codec_tag == AV_RL32("tmcd"))
                mov_read_timecode_track(s, s->streams[i]);
    }
D
David Conrad 已提交
4806

4807 4808 4809 4810
    /* copy timecode metadata from tmcd tracks to the related video streams */
    for (i = 0; i < s->nb_streams; i++) {
        AVStream *st = s->streams[i];
        MOVStreamContext *sc = st->priv_data;
4811
        if (sc->timecode_track > 0) {
4812
            AVDictionaryEntry *tcr;
4813
            int tmcd_st_id = -1;
4814

4815 4816 4817 4818
            for (j = 0; j < s->nb_streams; j++)
                if (s->streams[j]->id == sc->timecode_track)
                    tmcd_st_id = j;

4819
            if (tmcd_st_id < 0 || tmcd_st_id == i)
4820 4821 4822 4823 4824 4825
                continue;
            tcr = av_dict_get(s->streams[tmcd_st_id]->metadata, "timecode", NULL, 0);
            if (tcr)
                av_dict_set(&st->metadata, "timecode", tcr->value, 0);
        }
    }
4826
    export_orphan_timecode(s);
4827

4828 4829 4830
    for (i = 0; i < s->nb_streams; i++) {
        AVStream *st = s->streams[i];
        MOVStreamContext *sc = st->priv_data;
4831
        fix_timescale(mov, sc);
4832
        if(st->codec->codec_type == AVMEDIA_TYPE_AUDIO && st->codec->codec_id == AV_CODEC_ID_AAC) {
4833 4834
            st->skip_samples = sc->start_pad;
        }
4835 4836
        if (st->codec->codec_type == AVMEDIA_TYPE_VIDEO && sc->nb_frames_for_fps > 0 && sc->duration_for_fps > 0)
            av_reduce(&st->avg_frame_rate.num, &st->avg_frame_rate.den,
4837
                      sc->time_scale*(int64_t)sc->nb_frames_for_fps, sc->duration_for_fps, INT_MAX);
4838
        if (st->codec->codec_type == AVMEDIA_TYPE_SUBTITLE) {
V
Vittorio Giovara 已提交
4839
            if (st->codec->width <= 0 || st->codec->height <= 0) {
4840 4841 4842
                st->codec->width  = sc->width;
                st->codec->height = sc->height;
            }
4843 4844 4845 4846
            if (st->codec->codec_id == AV_CODEC_ID_DVD_SUBTITLE) {
                if ((err = mov_rewrite_dvd_sub_extradata(st)) < 0)
                    return err;
            }
4847
        }
4848
        if (mov->handbrake_version &&
4849
            mov->handbrake_version <= 1000000*0 + 1000*10 + 2 &&  // 0.10.2
4850 4851 4852 4853 4854
            st->codec->codec_id == AV_CODEC_ID_MP3
        ) {
            av_log(s, AV_LOG_VERBOSE, "Forcing full parsing for mp3 stream\n");
            st->need_parsing = AVSTREAM_PARSE_FULL;
        }
4855 4856
    }

4857 4858 4859 4860
    if (mov->trex_data) {
        for (i = 0; i < s->nb_streams; i++) {
            AVStream *st = s->streams[i];
            MOVStreamContext *sc = st->priv_data;
4861
            if (st->duration > 0)
4862 4863 4864 4865
                st->codec->bit_rate = sc->data_size * 8 * sc->time_scale / st->duration;
        }
    }

4866 4867 4868 4869 4870 4871 4872 4873 4874 4875 4876
    if (mov->use_mfra_for > 0) {
        for (i = 0; i < s->nb_streams; i++) {
            AVStream *st = s->streams[i];
            MOVStreamContext *sc = st->priv_data;
            if (sc->duration_for_fps > 0) {
                st->codec->bit_rate = sc->data_size * 8 * sc->time_scale /
                    sc->duration_for_fps;
            }
        }
    }

4877 4878 4879 4880 4881 4882
    for (i = 0; i < mov->bitrates_count && i < s->nb_streams; i++) {
        if (mov->bitrates[i]) {
            s->streams[i]->codec->bit_rate = mov->bitrates[i];
        }
    }

4883 4884
    ff_rfps_calculate(s);

4885 4886
    for (i = 0; i < s->nb_streams; i++) {
        AVStream *st = s->streams[i];
4887
        MOVStreamContext *sc = st->priv_data;
4888

4889 4890 4891 4892 4893 4894 4895 4896 4897 4898 4899 4900 4901 4902 4903 4904 4905 4906 4907 4908 4909 4910 4911 4912 4913 4914 4915
        switch (st->codec->codec_type) {
        case AVMEDIA_TYPE_AUDIO:
            err = ff_replaygain_export(st, s->metadata);
            if (err < 0) {
                mov_read_close(s);
                return err;
            }
            break;
        case AVMEDIA_TYPE_VIDEO:
            if (sc->display_matrix) {
                AVPacketSideData *sd, *tmp;

                tmp = av_realloc_array(st->side_data,
                                       st->nb_side_data + 1, sizeof(*tmp));
                if (!tmp)
                    return AVERROR(ENOMEM);

                st->side_data = tmp;
                st->nb_side_data++;

                sd = &st->side_data[st->nb_side_data - 1];
                sd->type = AV_PKT_DATA_DISPLAYMATRIX;
                sd->size = sizeof(int32_t) * 9;
                sd->data = (uint8_t*)sc->display_matrix;
                sc->display_matrix = NULL;
            }
            break;
4916 4917
        }
    }
4918
    ff_configure_buffers_for_index(s, AV_TIME_BASE);
4919

4920 4921 4922
    return 0;
}

4923
static AVIndexEntry *mov_find_next_sample(AVFormatContext *s, AVStream **st)
4924
{
4925
    AVIndexEntry *sample = NULL;
4926
    int64_t best_dts = INT64_MAX;
4927
    int i;
B
Baptiste Coudurier 已提交
4928
    for (i = 0; i < s->nb_streams; i++) {
4929 4930
        AVStream *avst = s->streams[i];
        MOVStreamContext *msc = avst->priv_data;
4931
        if (msc->pb && msc->current_sample < avst->nb_index_entries) {
4932
            AVIndexEntry *current_sample = &avst->index_entries[msc->current_sample];
4933
            int64_t dts = av_rescale(current_sample->timestamp, AV_TIME_BASE, msc->time_scale);
4934
            av_log(s, AV_LOG_TRACE, "stream %d, sample %d, dts %"PRId64"\n", i, msc->current_sample, dts);
4935 4936
            if (!sample || (!s->pb->seekable && current_sample->pos < sample->pos) ||
                (s->pb->seekable &&
4937
                 ((msc->pb != s->pb && dts < best_dts) || (msc->pb == s->pb &&
B
Baptiste Coudurier 已提交
4938
                 ((FFABS(best_dts - dts) <= AV_TIME_BASE && current_sample->pos < sample->pos) ||
4939
                  (FFABS(best_dts - dts) > AV_TIME_BASE && dts < best_dts)))))) {
4940 4941
                sample = current_sample;
                best_dts = dts;
4942
                *st = avst;
4943
            }
4944 4945
        }
    }
4946 4947 4948
    return sample;
}

4949 4950 4951 4952 4953 4954 4955
static int should_retry(AVIOContext *pb, int error_code) {
    if (error_code == AVERROR_EOF || avio_feof(pb))
        return 0;

    return 1;
}

4956 4957 4958 4959 4960 4961 4962 4963 4964 4965 4966 4967 4968 4969 4970 4971 4972 4973 4974 4975 4976 4977 4978 4979 4980 4981 4982 4983 4984 4985 4986 4987 4988 4989 4990 4991 4992 4993 4994 4995 4996 4997 4998 4999 5000 5001
static int mov_switch_root(AVFormatContext *s, int64_t target)
{
    MOVContext *mov = s->priv_data;
    int i, j;
    int already_read = 0;

    if (avio_seek(s->pb, target, SEEK_SET) != target) {
        av_log(mov->fc, AV_LOG_ERROR, "root atom offset 0x%"PRIx64": partial file\n", target);
        return AVERROR_INVALIDDATA;
    }

    mov->next_root_atom = 0;

    for (i = 0; i < mov->fragment_index_count; i++) {
        MOVFragmentIndex *index = mov->fragment_index_data[i];
        int found = 0;
        for (j = 0; j < index->item_count; j++) {
            MOVFragmentIndexItem *item = &index->items[j];
            if (found) {
                mov->next_root_atom = item->moof_offset;
                break; // Advance to next index in outer loop
            } else if (item->moof_offset == target) {
                index->current_item = FFMIN(j, index->current_item);
                if (item->headers_read)
                    already_read = 1;
                item->headers_read = 1;
                found = 1;
            }
        }
        if (!found)
            index->current_item = 0;
    }

    if (already_read)
        return 0;

    mov->found_mdat = 0;

    if (mov_read_default(mov, s->pb, (MOVAtom){ AV_RL32("root"), INT64_MAX }) < 0 ||
        avio_feof(s->pb))
        return AVERROR_EOF;
    av_log(s, AV_LOG_TRACE, "read fragments, offset 0x%"PRIx64"\n", avio_tell(s->pb));

    return 1;
}

5002 5003 5004 5005 5006 5007 5008
static int mov_read_packet(AVFormatContext *s, AVPacket *pkt)
{
    MOVContext *mov = s->priv_data;
    MOVStreamContext *sc;
    AVIndexEntry *sample;
    AVStream *st = NULL;
    int ret;
5009
    mov->fc = s;
5010 5011
 retry:
    sample = mov_find_next_sample(s, &st);
5012
    if (!sample || (mov->next_root_atom && sample->pos > mov->next_root_atom)) {
5013 5014
        if (!mov->next_root_atom)
            return AVERROR_EOF;
5015 5016
        if ((ret = mov_switch_root(s, mov->next_root_atom)) < 0)
            return ret;
5017 5018
        goto retry;
    }
5019
    sc = st->priv_data;
5020 5021
    /* must be done just before reading, to avoid infinite loop on sample */
    sc->current_sample++;
5022

5023 5024 5025 5026 5027
    if (mov->next_root_atom) {
        sample->pos = FFMIN(sample->pos, mov->next_root_atom);
        sample->size = FFMIN(sample->size, (mov->next_root_atom - sample->pos));
    }

5028
    if (st->discard != AVDISCARD_ALL) {
5029 5030
        int64_t ret64 = avio_seek(sc->pb, sample->pos, SEEK_SET);
        if (ret64 != sample->pos) {
R
Reimar Döffinger 已提交
5031 5032
            av_log(mov->fc, AV_LOG_ERROR, "stream %d, offset 0x%"PRIx64": partial file\n",
                   sc->ffindex, sample->pos);
5033
            sc->current_sample -= should_retry(sc->pb, ret64);
5034
            return AVERROR_INVALIDDATA;
R
Reimar Döffinger 已提交
5035 5036
        }
        ret = av_get_packet(sc->pb, pkt, sample->size);
5037 5038
        if (ret < 0) {
            sc->current_sample -= should_retry(sc->pb, ret);
5039
            return ret;
5040
        }
5041 5042 5043 5044 5045 5046 5047 5048 5049 5050 5051
        if (sc->has_palette) {
            uint8_t *pal;

            pal = av_packet_new_side_data(pkt, AV_PKT_DATA_PALETTE, AVPALETTE_SIZE);
            if (!pal) {
                av_log(mov->fc, AV_LOG_ERROR, "Cannot append palette to packet\n");
            } else {
                memcpy(pal, sc->palette, AVPALETTE_SIZE);
                sc->has_palette = 0;
            }
        }
R
Reimar Döffinger 已提交
5052 5053
#if CONFIG_DV_DEMUXER
        if (mov->dv_demux && sc->dv_audio_container) {
5054
            avpriv_dv_produce_packet(mov->dv_demux, pkt, pkt->data, pkt->size, pkt->pos);
5055
            av_freep(&pkt->data);
R
Reimar Döffinger 已提交
5056
            pkt->size = 0;
5057
            ret = avpriv_dv_get_packet(mov->dv_demux, pkt);
R
Reimar Döffinger 已提交
5058 5059 5060
            if (ret < 0)
                return ret;
        }
5061
#endif
5062 5063
    }

5064
    pkt->stream_index = sc->ffindex;
5065
    pkt->dts = sample->timestamp;
5066
    if (sc->ctts_data && sc->ctts_index < sc->ctts_count) {
5067
        pkt->pts = pkt->dts + sc->dts_shift + sc->ctts_data[sc->ctts_index].duration;
5068
        /* update ctts context */
5069 5070 5071 5072 5073
        sc->ctts_sample++;
        if (sc->ctts_index < sc->ctts_count &&
            sc->ctts_data[sc->ctts_index].count == sc->ctts_sample) {
            sc->ctts_index++;
            sc->ctts_sample = 0;
5074
        }
5075 5076
        if (sc->wrong_dts)
            pkt->dts = AV_NOPTS_VALUE;
5077
    } else {
5078
        int64_t next_dts = (sc->current_sample < st->nb_index_entries) ?
5079 5080
            st->index_entries[sc->current_sample].timestamp : st->duration;
        pkt->duration = next_dts - pkt->dts;
5081
        pkt->pts = pkt->dts;
5082
    }
5083 5084
    if (st->discard == AVDISCARD_ALL)
        goto retry;
5085
    pkt->flags |= sample->flags & AVINDEX_KEYFRAME ? AV_PKT_FLAG_KEY : 0;
5086
    pkt->pos = sample->pos;
5087

5088 5089 5090
    if (mov->aax_mode)
        aax_filter(pkt->data, pkt->size, mov);

5091 5092 5093 5094 5095 5096 5097
    if (sc->cenc.aes_ctr) {
        ret = cenc_filter(mov, sc, pkt->data, pkt->size);
        if (ret) {
            return ret;
        }
    }

5098 5099
    return 0;
}
5100

5101 5102 5103 5104 5105 5106 5107 5108 5109 5110
static int mov_seek_fragment(AVFormatContext *s, AVStream *st, int64_t timestamp)
{
    MOVContext *mov = s->priv_data;
    int i, j;

    if (!mov->fragment_index_complete)
        return 0;

    for (i = 0; i < mov->fragment_index_count; i++) {
        if (mov->fragment_index_data[i]->track_id == st->id) {
5111
            MOVFragmentIndex *index = mov->fragment_index_data[i];
5112 5113 5114 5115 5116 5117 5118 5119 5120 5121 5122 5123 5124 5125
            for (j = index->item_count - 1; j >= 0; j--) {
                if (index->items[j].time <= timestamp) {
                    if (index->items[j].headers_read)
                        return 0;

                    return mov_switch_root(s, index->items[j].moof_offset);
                }
            }
        }
    }

    return 0;
}

5126
static int mov_seek_stream(AVFormatContext *s, AVStream *st, int64_t timestamp, int flags)
5127 5128 5129 5130
{
    MOVStreamContext *sc = st->priv_data;
    int sample, time_sample;
    int i;
5131

5132 5133 5134 5135
    int ret = mov_seek_fragment(s, st, timestamp);
    if (ret < 0)
        return ret;

5136
    sample = av_index_search_timestamp(st, timestamp, flags);
5137
    av_log(s, AV_LOG_TRACE, "stream %d, timestamp %"PRId64", sample %d\n", st->index, timestamp, sample);
5138 5139
    if (sample < 0 && st->nb_index_entries && timestamp < st->index_entries[0].timestamp)
        sample = 0;
5140
    if (sample < 0) /* not sure what to do */
5141
        return AVERROR_INVALIDDATA;
5142
    sc->current_sample = sample;
5143
    av_log(s, AV_LOG_TRACE, "stream %d, found sample %d\n", st->index, sc->current_sample);
5144 5145 5146 5147
    /* adjust ctts index */
    if (sc->ctts_data) {
        time_sample = 0;
        for (i = 0; i < sc->ctts_count; i++) {
5148 5149
            int next = time_sample + sc->ctts_data[i].count;
            if (next > sc->current_sample) {
5150 5151
                sc->ctts_index = i;
                sc->ctts_sample = sc->current_sample - time_sample;
5152
                break;
5153
            }
5154
            time_sample = next;
5155 5156
        }
    }
5157
    return sample;
5158 5159
}

5160
static int mov_read_seek(AVFormatContext *s, int stream_index, int64_t sample_time, int flags)
G
Gael Chardon 已提交
5161
{
5162
    MOVContext *mc = s->priv_data;
5163 5164 5165
    AVStream *st;
    int sample;
    int i;
G
Gael Chardon 已提交
5166

5167
    if (stream_index >= s->nb_streams)
5168
        return AVERROR_INVALIDDATA;
G
Gael Chardon 已提交
5169

5170
    st = s->streams[stream_index];
5171
    sample = mov_seek_stream(s, st, sample_time, flags);
5172
    if (sample < 0)
5173
        return sample;
G
Gael Chardon 已提交
5174

5175 5176 5177
    if (mc->seek_individually) {
        /* adjust seek timestamp to found sample timestamp */
        int64_t seek_timestamp = st->index_entries[sample].timestamp;
G
Gael Chardon 已提交
5178

5179 5180 5181 5182 5183
        for (i = 0; i < s->nb_streams; i++) {
            int64_t timestamp;
            MOVStreamContext *sc = s->streams[i]->priv_data;
            st = s->streams[i];
            st->skip_samples = (sample_time <= 0) ? sc->start_pad : 0;
5184

5185 5186
            if (stream_index == i)
                continue;
G
Gael Chardon 已提交
5187

5188 5189 5190 5191 5192 5193 5194 5195 5196 5197 5198 5199 5200 5201 5202 5203 5204 5205 5206 5207
            timestamp = av_rescale_q(seek_timestamp, s->streams[stream_index]->time_base, st->time_base);
            mov_seek_stream(s, st, timestamp, flags);
        }
    } else {
        for (i = 0; i < s->nb_streams; i++) {
            MOVStreamContext *sc;
            st = s->streams[i];
            sc = st->priv_data;
            sc->current_sample = 0;
        }
        while (1) {
            MOVStreamContext *sc;
            AVIndexEntry *entry = mov_find_next_sample(s, &st);
            if (!entry)
                return AVERROR_INVALIDDATA;
            sc = st->priv_data;
            if (sc->ffindex == stream_index && sc->current_sample == sample)
                break;
            sc->current_sample++;
        }
5208
    }
G
Gael Chardon 已提交
5209 5210 5211
    return 0;
}

5212 5213 5214
#define OFFSET(x) offsetof(MOVContext, x)
#define FLAGS AV_OPT_FLAG_VIDEO_PARAM | AV_OPT_FLAG_DECODING_PARAM
static const AVOption mov_options[] = {
5215 5216
    {"use_absolute_path",
        "allow using absolute path when opening alias, this is a possible security issue",
5217
        OFFSET(use_absolute_path), AV_OPT_TYPE_BOOL, {.i64 = 0},
5218
        0, 1, FLAGS},
5219 5220
    {"seek_streams_individually",
        "Seek each stream individually to the to the closest point",
5221
        OFFSET(seek_individually), AV_OPT_TYPE_BOOL, { .i64 = 1 },
5222
        0, 1, FLAGS},
5223
    {"ignore_editlist", "", OFFSET(ignore_editlist), AV_OPT_TYPE_BOOL, {.i64 = 0},
5224
        0, 1, FLAGS},
5225 5226
    {"ignore_chapters", "", OFFSET(ignore_chapters), AV_OPT_TYPE_BOOL, {.i64 = 0},
        0, 1, FLAGS},
5227 5228
    {"use_mfra_for",
        "use mfra for fragment timestamps",
5229
        OFFSET(use_mfra_for), AV_OPT_TYPE_INT, {.i64 = FF_MOV_FLAG_MFRA_AUTO},
5230
        -1, FF_MOV_FLAG_MFRA_PTS, FLAGS,
5231
        "use_mfra_for"},
5232
    {"auto", "auto", 0, AV_OPT_TYPE_CONST, {.i64 = FF_MOV_FLAG_MFRA_AUTO}, 0, 0,
5233
        FLAGS, "use_mfra_for" },
5234
    {"dts", "dts", 0, AV_OPT_TYPE_CONST, {.i64 = FF_MOV_FLAG_MFRA_DTS}, 0, 0,
5235
        FLAGS, "use_mfra_for" },
5236
    {"pts", "pts", 0, AV_OPT_TYPE_CONST, {.i64 = FF_MOV_FLAG_MFRA_PTS}, 0, 0,
5237
        FLAGS, "use_mfra_for" },
5238
    { "export_all", "Export unrecognized metadata entries", OFFSET(export_all),
5239
        AV_OPT_TYPE_BOOL, { .i64 = 0 }, 0, 1, .flags = FLAGS },
5240
    { "export_xmp", "Export full XMP metadata", OFFSET(export_xmp),
5241
        AV_OPT_TYPE_BOOL, { .i64 = 0 }, 0, 1, .flags = FLAGS },
5242 5243 5244 5245 5246 5247
    { "activation_bytes", "Secret bytes for Audible AAX files", OFFSET(activation_bytes),
        AV_OPT_TYPE_BINARY, .flags = AV_OPT_FLAG_DECODING_PARAM },
    { "audible_fixed_key", // extracted from libAAX_SDK.so and AAXSDKWin.dll files!
        "Fixed key used for handling Audible AAX files", OFFSET(audible_fixed_key),
        AV_OPT_TYPE_BINARY, {.str="77214d4b196a87cd520045fd20a51d67"},
        .flags = AV_OPT_FLAG_DECODING_PARAM },
5248
    { "decryption_key", "The media decryption key (hex)", OFFSET(decryption_key), AV_OPT_TYPE_BINARY, .flags = AV_OPT_FLAG_DECODING_PARAM },
5249 5250
    { "enable_drefs", "Enable external track support.", OFFSET(enable_drefs), AV_OPT_TYPE_BOOL,
        {.i64 = 0}, 0, 1, FLAGS },
5251

5252
    { NULL },
5253 5254
};

5255
static const AVClass mov_class = {
5256 5257
    .class_name = "mov,mp4,m4a,3gp,3g2,mj2",
    .item_name  = av_default_item_name,
5258
    .option     = mov_options,
5259 5260
    .version    = LIBAVUTIL_VERSION_INT,
};
5261

5262
AVInputFormat ff_mov_demuxer = {
5263
    .name           = "mov,mp4,m4a,3gp,3g2,mj2",
5264
    .long_name      = NULL_IF_CONFIG_SMALL("QuickTime / MOV"),
5265
    .priv_class     = &mov_class,
5266
    .priv_data_size = sizeof(MOVContext),
5267
    .extensions     = "mov,mp4,m4a,3gp,3g2,mj2",
5268 5269 5270 5271 5272
    .read_probe     = mov_probe,
    .read_header    = mov_read_header,
    .read_packet    = mov_read_packet,
    .read_close     = mov_read_close,
    .read_seek      = mov_read_seek,
5273
    .flags          = AVFMT_NO_BYTE_SEEK,
5274
};