mov.c 170.4 KB
Newer Older
1
/*
2
 * MOV demuxer
3
 * Copyright (c) 2001 Fabrice Bellard
4
 * Copyright (c) 2009 Baptiste Coudurier <baptiste dot coudurier at gmail dot com>
5
 *
6 7 8
 * first version by Francois Revol <revol@free.fr>
 * seek function by Gael Chardon <gael.dev@4now.net>
 *
9 10 11
 * This file is part of FFmpeg.
 *
 * FFmpeg is free software; you can redistribute it and/or
F
Fabrice Bellard 已提交
12 13
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
14
 * version 2.1 of the License, or (at your option) any later version.
15
 *
16
 * FFmpeg is distributed in the hope that it will be useful,
17
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
F
Fabrice Bellard 已提交
18 19
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
20
 *
F
Fabrice Bellard 已提交
21
 * You should have received a copy of the GNU Lesser General Public
22
 * License along with FFmpeg; if not, write to the Free Software
23
 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
24
 */
25

26
#include <inttypes.h>
27
#include <limits.h>
28
#include <stdint.h>
29

30
#include "libavutil/attributes.h"
31
#include "libavutil/channel_layout.h"
R
Ronald S. Bultje 已提交
32
#include "libavutil/internal.h"
33
#include "libavutil/intreadwrite.h"
34
#include "libavutil/intfloat.h"
35
#include "libavutil/mathematics.h"
36
#include "libavutil/time_internal.h"
37
#include "libavutil/avstring.h"
38
#include "libavutil/dict.h"
39
#include "libavutil/display.h"
40
#include "libavutil/opt.h"
41 42
#include "libavutil/aes.h"
#include "libavutil/sha.h"
43
#include "libavutil/timecode.h"
44
#include "libavcodec/ac3tab.h"
45
#include "avformat.h"
46
#include "internal.h"
47
#include "avio_internal.h"
48
#include "riff.h"
49
#include "isom.h"
50
#include "libavcodec/get_bits.h"
R
Raivo Hool 已提交
51
#include "id3v1.h"
52
#include "mov_chan.h"
53
#include "replaygain.h"
54

55
#if CONFIG_ZLIB
56 57 58
#include <zlib.h>
#endif

59 60
#include "qtpalette.h"

61 62 63
/* those functions parse an atom */
/* links atom IDs to parse functions */
typedef struct MOVParseTableEntry {
64
    uint32_t type;
65
    int (*parse)(MOVContext *ctx, AVIOContext *pb, MOVAtom atom);
66 67
} MOVParseTableEntry;

68
static int mov_read_default(MOVContext *c, AVIOContext *pb, MOVAtom atom);
69
static int mov_read_mfra(MOVContext *c, AVIOContext *f);
70

71 72
static int mov_metadata_track_or_disc_number(MOVContext *c, AVIOContext *pb,
                                             unsigned len, const char *key)
B
Baptiste Coudurier 已提交
73 74 75
{
    char buf[16];

76
    short current, total = 0;
77
    avio_rb16(pb); // unknown
78
    current = avio_rb16(pb);
79 80
    if (len >= 6)
        total = avio_rb16(pb);
81 82 83 84
    if (!total)
        snprintf(buf, sizeof(buf), "%d", current);
    else
        snprintf(buf, sizeof(buf), "%d/%d", current, total);
85
    c->fc->event_flags |= AVFMT_EVENT_FLAG_METADATA_UPDATED;
86
    av_dict_set(&c->fc->metadata, key, buf, 0);
B
Baptiste Coudurier 已提交
87 88 89 90

    return 0;
}

91 92
static int mov_metadata_int8_bypass_padding(MOVContext *c, AVIOContext *pb,
                                            unsigned len, const char *key)
93
{
94 95 96 97
    /* bypass padding bytes */
    avio_r8(pb);
    avio_r8(pb);
    avio_r8(pb);
98

99
    c->fc->event_flags |= AVFMT_EVENT_FLAG_METADATA_UPDATED;
100
    av_dict_set_int(&c->fc->metadata, key, avio_r8(pb), 0);
101

102
    return 0;
103 104
}

105 106
static int mov_metadata_int8_no_padding(MOVContext *c, AVIOContext *pb,
                                        unsigned len, const char *key)
107
{
108
    c->fc->event_flags |= AVFMT_EVENT_FLAG_METADATA_UPDATED;
109
    av_dict_set_int(&c->fc->metadata, key, avio_r8(pb), 0);
110

111
    return 0;
112 113
}

R
Raivo Hool 已提交
114
static int mov_metadata_gnre(MOVContext *c, AVIOContext *pb,
115 116
                             unsigned len, const char *key)
{
R
Raivo Hool 已提交
117
    short genre;
118

R
Raivo Hool 已提交
119
    avio_r8(pb); // unknown
120

R
Raivo Hool 已提交
121 122 123
    genre = avio_r8(pb);
    if (genre < 1 || genre > ID3v1_GENRE_MAX)
        return 0;
124
    c->fc->event_flags |= AVFMT_EVENT_FLAG_METADATA_UPDATED;
125
    av_dict_set(&c->fc->metadata, key, ff_id3v1_genre_str[genre-1], 0);
R
Raivo Hool 已提交
126 127

    return 0;
128 129
}

130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148
static const uint32_t mac_to_unicode[128] = {
    0x00C4,0x00C5,0x00C7,0x00C9,0x00D1,0x00D6,0x00DC,0x00E1,
    0x00E0,0x00E2,0x00E4,0x00E3,0x00E5,0x00E7,0x00E9,0x00E8,
    0x00EA,0x00EB,0x00ED,0x00EC,0x00EE,0x00EF,0x00F1,0x00F3,
    0x00F2,0x00F4,0x00F6,0x00F5,0x00FA,0x00F9,0x00FB,0x00FC,
    0x2020,0x00B0,0x00A2,0x00A3,0x00A7,0x2022,0x00B6,0x00DF,
    0x00AE,0x00A9,0x2122,0x00B4,0x00A8,0x2260,0x00C6,0x00D8,
    0x221E,0x00B1,0x2264,0x2265,0x00A5,0x00B5,0x2202,0x2211,
    0x220F,0x03C0,0x222B,0x00AA,0x00BA,0x03A9,0x00E6,0x00F8,
    0x00BF,0x00A1,0x00AC,0x221A,0x0192,0x2248,0x2206,0x00AB,
    0x00BB,0x2026,0x00A0,0x00C0,0x00C3,0x00D5,0x0152,0x0153,
    0x2013,0x2014,0x201C,0x201D,0x2018,0x2019,0x00F7,0x25CA,
    0x00FF,0x0178,0x2044,0x20AC,0x2039,0x203A,0xFB01,0xFB02,
    0x2021,0x00B7,0x201A,0x201E,0x2030,0x00C2,0x00CA,0x00C1,
    0x00CB,0x00C8,0x00CD,0x00CE,0x00CF,0x00CC,0x00D3,0x00D4,
    0xF8FF,0x00D2,0x00DA,0x00DB,0x00D9,0x0131,0x02C6,0x02DC,
    0x00AF,0x02D8,0x02D9,0x02DA,0x00B8,0x02DD,0x02DB,0x02C7,
};

149
static int mov_read_mac_string(MOVContext *c, AVIOContext *pb, int len,
150 151 152 153 154 155 156
                               char *dst, int dstlen)
{
    char *p = dst;
    char *end = dst+dstlen-1;
    int i;

    for (i = 0; i < len; i++) {
157
        uint8_t t, c = avio_r8(pb);
158 159
        if (c < 0x80 && p < end)
            *p++ = c;
160
        else if (p < end)
161 162 163 164 165 166
            PUT_UTF8(mac_to_unicode[c-0x80], t, if (p < end) *p++ = t;);
    }
    *p = 0;
    return p - dst;
}

A
Anton Khirnov 已提交
167 168 169 170 171
static int mov_read_covr(MOVContext *c, AVIOContext *pb, int type, int len)
{
    AVPacket pkt;
    AVStream *st;
    MOVStreamContext *sc;
172
    enum AVCodecID id;
A
Anton Khirnov 已提交
173 174 175
    int ret;

    switch (type) {
176 177 178
    case 0xd:  id = AV_CODEC_ID_MJPEG; break;
    case 0xe:  id = AV_CODEC_ID_PNG;   break;
    case 0x1b: id = AV_CODEC_ID_BMP;   break;
A
Anton Khirnov 已提交
179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196
    default:
        av_log(c->fc, AV_LOG_WARNING, "Unknown cover type: 0x%x.\n", type);
        avio_skip(pb, len);
        return 0;
    }

    st = avformat_new_stream(c->fc, NULL);
    if (!st)
        return AVERROR(ENOMEM);
    sc = av_mallocz(sizeof(*sc));
    if (!sc)
        return AVERROR(ENOMEM);
    st->priv_data = sc;

    ret = av_get_packet(pb, &pkt, len);
    if (ret < 0)
        return ret;

W
wm4 已提交
197 198 199 200 201 202 203 204
    if (pkt.size >= 8 && id != AV_CODEC_ID_BMP) {
        if (AV_RB64(pkt.data) == 0x89504e470d0a1a0a) {
            id = AV_CODEC_ID_PNG;
        } else {
            id = AV_CODEC_ID_MJPEG;
        }
    }

A
Anton Khirnov 已提交
205 206 207 208 209 210 211 212 213 214 215 216
    st->disposition              |= AV_DISPOSITION_ATTACHED_PIC;

    st->attached_pic              = pkt;
    st->attached_pic.stream_index = st->index;
    st->attached_pic.flags       |= AV_PKT_FLAG_KEY;

    st->codec->codec_type = AVMEDIA_TYPE_VIDEO;
    st->codec->codec_id   = id;

    return 0;
}

217 218 219
static int mov_metadata_loci(MOVContext *c, AVIOContext *pb, unsigned len)
{
    char language[4] = { 0 };
220
    char buf[200], place[100];
221
    uint16_t langcode = 0;
222
    double longitude, latitude, altitude;
223 224
    const char *key = "location";

225 226
    if (len < 4 + 2 + 1 + 1 + 4 + 4 + 4) {
        av_log(c->fc, AV_LOG_ERROR, "loci too short\n");
227
        return AVERROR_INVALIDDATA;
228
    }
229 230 231 232 233 234

    avio_skip(pb, 4); // version+flags
    langcode = avio_rb16(pb);
    ff_mov_lang_to_iso639(langcode, language);
    len -= 6;

235
    len -= avio_get_str(pb, len, place, sizeof(place));
236 237
    if (len < 1) {
        av_log(c->fc, AV_LOG_ERROR, "place name too long\n");
238
        return AVERROR_INVALIDDATA;
239
    }
240 241 242
    avio_skip(pb, 1); // role
    len -= 1;

243
    if (len < 12) {
244
        av_log(c->fc, AV_LOG_ERROR, "no space for coordinates left (%d)\n", len);
245
        return AVERROR_INVALIDDATA;
246
    }
247 248
    longitude = ((int32_t) avio_rb32(pb)) / (float) (1 << 16);
    latitude  = ((int32_t) avio_rb32(pb)) / (float) (1 << 16);
249
    altitude  = ((int32_t) avio_rb32(pb)) / (float) (1 << 16);
250 251

    // Try to output in the same format as the ?xyz field
252 253 254 255 256
    snprintf(buf, sizeof(buf), "%+08.4f%+09.4f",  latitude, longitude);
    if (altitude)
        av_strlcatf(buf, sizeof(buf), "%+f", altitude);
    av_strlcatf(buf, sizeof(buf), "/%s", place);

257 258 259 260 261
    if (*language && strcmp(language, "und")) {
        char key2[16];
        snprintf(key2, sizeof(key2), "%s-%s", key, language);
        av_dict_set(&c->fc->metadata, key2, buf, 0);
    }
262
    c->fc->event_flags |= AVFMT_EVENT_FLAG_METADATA_UPDATED;
263 264 265
    return av_dict_set(&c->fc->metadata, key, buf, 0);
}

266
static int mov_read_udta_string(MOVContext *c, AVIOContext *pb, MOVAtom atom)
267 268
{
    char tmp_key[5];
269
    char key2[32], language[4] = {0};
270
    char *str = NULL;
271
    const char *key = NULL;
272
    uint16_t langcode = 0;
273
    uint32_t data_type = 0, str_size, str_size_alloc;
274
    int (*parse)(MOVContext*, AVIOContext*, unsigned, const char*) = NULL;
275
    int raw = 0;
276
    int num = 0;
277 278

    switch (atom.type) {
279 280
    case MKTAG( '@','P','R','M'): key = "premiere_version"; raw = 1; break;
    case MKTAG( '@','P','R','Q'): key = "quicktime_version"; raw = 1; break;
281 282
    case MKTAG( 'X','M','P','_'):
        if (c->export_xmp) { key = "xmp"; raw = 1; } break;
R
Raivo Hool 已提交
283
    case MKTAG( 'a','A','R','T'): key = "album_artist";    break;
284 285 286 287
    case MKTAG( 'a','k','I','D'): key = "account_type";
        parse = mov_metadata_int8_no_padding; break;
    case MKTAG( 'a','p','I','D'): key = "account_id"; break;
    case MKTAG( 'c','a','t','g'): key = "category"; break;
288 289
    case MKTAG( 'c','p','i','l'): key = "compilation";
        parse = mov_metadata_int8_no_padding; break;
290 291
    case MKTAG( 'c','p','r','t'): key = "copyright"; break;
    case MKTAG( 'd','e','s','c'): key = "description"; break;
292 293
    case MKTAG( 'd','i','s','k'): key = "disc";
        parse = mov_metadata_track_or_disc_number; break;
294 295
    case MKTAG( 'e','g','i','d'): key = "episode_uid";
        parse = mov_metadata_int8_no_padding; break;
R
Raivo Hool 已提交
296 297
    case MKTAG( 'g','n','r','e'): key = "genre";
        parse = mov_metadata_gnre; break;
298 299
    case MKTAG( 'h','d','v','d'): key = "hd_video";
        parse = mov_metadata_int8_no_padding; break;
300
    case MKTAG( 'k','e','y','w'): key = "keywords";  break;
301
    case MKTAG( 'l','d','e','s'): key = "synopsis";  break;
302 303
    case MKTAG( 'l','o','c','i'):
        return mov_metadata_loci(c, pb, atom.size);
304 305
    case MKTAG( 'p','c','s','t'): key = "podcast";
        parse = mov_metadata_int8_no_padding; break;
306 307
    case MKTAG( 'p','g','a','p'): key = "gapless_playback";
        parse = mov_metadata_int8_no_padding; break;
308 309 310 311 312 313 314 315 316
    case MKTAG( 'p','u','r','d'): key = "purchase_date"; break;
    case MKTAG( 'r','t','n','g'): key = "rating";
        parse = mov_metadata_int8_no_padding; break;
    case MKTAG( 's','o','a','a'): key = "sort_album_artist"; break;
    case MKTAG( 's','o','a','l'): key = "sort_album";   break;
    case MKTAG( 's','o','a','r'): key = "sort_artist";  break;
    case MKTAG( 's','o','c','o'): key = "sort_composer"; break;
    case MKTAG( 's','o','n','m'): key = "sort_name";    break;
    case MKTAG( 's','o','s','n'): key = "sort_show";    break;
317 318
    case MKTAG( 's','t','i','k'): key = "media_type";
        parse = mov_metadata_int8_no_padding; break;
B
Baptiste Coudurier 已提交
319
    case MKTAG( 't','r','k','n'): key = "track";
320
        parse = mov_metadata_track_or_disc_number; break;
321
    case MKTAG( 't','v','e','n'): key = "episode_id"; break;
322
    case MKTAG( 't','v','e','s'): key = "episode_sort";
323
        parse = mov_metadata_int8_bypass_padding; break;
324 325
    case MKTAG( 't','v','n','n'): key = "network";   break;
    case MKTAG( 't','v','s','h'): key = "show";      break;
326
    case MKTAG( 't','v','s','n'): key = "season_number";
327
        parse = mov_metadata_int8_bypass_padding; break;
328
    case MKTAG(0xa9,'A','R','T'): key = "artist";    break;
329
    case MKTAG(0xa9,'P','R','D'): key = "producer";  break;
330 331
    case MKTAG(0xa9,'a','l','b'): key = "album";     break;
    case MKTAG(0xa9,'a','u','t'): key = "artist";    break;
332
    case MKTAG(0xa9,'c','h','p'): key = "chapter";   break;
333
    case MKTAG(0xa9,'c','m','t'): key = "comment";   break;
334
    case MKTAG(0xa9,'c','o','m'): key = "composer";  break;
335 336
    case MKTAG(0xa9,'c','p','y'): key = "copyright"; break;
    case MKTAG(0xa9,'d','a','y'): key = "date";      break;
337 338 339
    case MKTAG(0xa9,'d','i','r'): key = "director";  break;
    case MKTAG(0xa9,'d','i','s'): key = "disclaimer"; break;
    case MKTAG(0xa9,'e','d','1'): key = "edit_date"; break;
340
    case MKTAG(0xa9,'e','n','c'): key = "encoder";   break;
341
    case MKTAG(0xa9,'f','m','t'): key = "original_format"; break;
342
    case MKTAG(0xa9,'g','e','n'): key = "genre";     break;
343
    case MKTAG(0xa9,'g','r','p'): key = "grouping";  break;
344
    case MKTAG(0xa9,'h','s','t'): key = "host_computer"; break;
345
    case MKTAG(0xa9,'i','n','f'): key = "comment";   break;
346 347 348
    case MKTAG(0xa9,'l','y','r'): key = "lyrics";    break;
    case MKTAG(0xa9,'m','a','k'): key = "make";      break;
    case MKTAG(0xa9,'m','o','d'): key = "model";     break;
349
    case MKTAG(0xa9,'n','a','m'): key = "title";     break;
350 351 352 353 354
    case MKTAG(0xa9,'o','p','e'): key = "original_artist"; break;
    case MKTAG(0xa9,'p','r','d'): key = "producer";  break;
    case MKTAG(0xa9,'p','r','f'): key = "performers"; break;
    case MKTAG(0xa9,'r','e','q'): key = "playback_requirements"; break;
    case MKTAG(0xa9,'s','r','c'): key = "original_source"; break;
355
    case MKTAG(0xa9,'s','t','3'): key = "subtitle";  break;
356 357
    case MKTAG(0xa9,'s','w','r'): key = "encoder";   break;
    case MKTAG(0xa9,'t','o','o'): key = "encoder";   break;
358 359 360
    case MKTAG(0xa9,'t','r','k'): key = "track";     break;
    case MKTAG(0xa9,'u','r','l'): key = "URL";       break;
    case MKTAG(0xa9,'w','r','n'): key = "warning";   break;
361 362
    case MKTAG(0xa9,'w','r','t'): key = "composer";  break;
    case MKTAG(0xa9,'x','y','z'): key = "location";  break;
363
    }
364
retry:
365
    if (c->itunes_metadata && atom.size > 8) {
366 367
        int data_size = avio_rb32(pb);
        int tag = avio_rl32(pb);
368
        if (tag == MKTAG('d','a','t','a') && data_size <= atom.size) {
369 370
            data_type = avio_rb32(pb); // type
            avio_rb32(pb); // unknown
371 372
            str_size = data_size - 16;
            atom.size -= 16;
A
Anton Khirnov 已提交
373 374 375 376 377 378

            if (atom.type == MKTAG('c', 'o', 'v', 'r')) {
                int ret = mov_read_covr(c, pb, data_type, str_size);
                if (ret < 0) {
                    av_log(c->fc, AV_LOG_ERROR, "Error parsing cover art.\n");
                }
379
                return ret;
380 381 382 383 384 385 386 387 388
            } else if (!key && c->found_hdlr_mdta && c->meta_keys) {
                uint32_t index = AV_RB32(&atom.type);
                if (index < c->meta_keys_count) {
                    key = c->meta_keys[index];
                } else {
                    av_log(c->fc, AV_LOG_WARNING,
                           "The index of 'data' is out of range: %d >= %d.\n",
                           index, c->meta_keys_count);
                }
A
Anton Khirnov 已提交
389
            }
390
        } else return 0;
391
    } else if (atom.size > 4 && key && !c->itunes_metadata && !raw) {
392
        str_size = avio_rb16(pb); // string length
393 394 395
        if (str_size > atom.size) {
            raw = 1;
            avio_seek(pb, -2, SEEK_CUR);
396
            av_log(c->fc, AV_LOG_WARNING, "UDTA parsing failed retrying raw\n");
397 398
            goto retry;
        }
399
        langcode = avio_rb16(pb);
400
        ff_mov_lang_to_iso639(langcode, language);
401 402 403 404
        atom.size -= 4;
    } else
        str_size = atom.size;

405
    if (c->export_all && !key) {
406 407 408 409 410 411
        snprintf(tmp_key, 5, "%.4s", (char*)&atom.type);
        key = tmp_key;
    }

    if (!key)
        return 0;
412
    if (atom.size < 0 || str_size >= INT_MAX/2)
413
        return AVERROR_INVALIDDATA;
414

415
    // Allocates enough space if data_type is a float32 number, otherwise
416
    // worst-case requirement for output string in case of utf8 coded input
417 418
    num = (data_type == 23);
    str_size_alloc = (num ? 512 : (raw ? str_size : str_size * 2)) + 1;
419
    str = av_mallocz(str_size_alloc);
420 421 422
    if (!str)
        return AVERROR(ENOMEM);

B
Baptiste Coudurier 已提交
423
    if (parse)
424
        parse(c, pb, str_size, key);
B
Baptiste Coudurier 已提交
425
    else {
426
        if (!raw && (data_type == 3 || (data_type == 0 && (langcode < 0x400 || langcode == 0x7fff)))) { // MAC Encoded
427
            mov_read_mac_string(c, pb, str_size, str, str_size_alloc);
428 429 430 431 432
        } else if (data_type == 23 && str_size >= 4) {  // BE float32
            float val = av_int2float(avio_rb32(pb));
            if (snprintf(str, str_size_alloc, "%f", val) >= str_size_alloc) {
                av_log(c->fc, AV_LOG_ERROR,
                       "Failed to store the float32 number (%f) in string.\n", val);
G
Ganesh Ajjanagadde 已提交
433
                av_free(str);
434 435
                return AVERROR_INVALIDDATA;
            }
436
        } else {
437 438 439 440
            int ret = ffio_read_size(pb, str, str_size);
            if (ret < 0) {
                av_free(str);
                return ret;
441
            }
442 443
            str[str_size] = 0;
        }
444
        c->fc->event_flags |= AVFMT_EVENT_FLAG_METADATA_UPDATED;
445
        av_dict_set(&c->fc->metadata, key, str, 0);
B
Baptiste Coudurier 已提交
446 447
        if (*language && strcmp(language, "und")) {
            snprintf(key2, sizeof(key2), "%s-%s", key, language);
448
            av_dict_set(&c->fc->metadata, key2, str, 0);
B
Baptiste Coudurier 已提交
449
        }
B
Baptiste Coudurier 已提交
450
    }
451 452
    av_log(c->fc, AV_LOG_TRACE, "lang \"%3s\" ", language);
    av_log(c->fc, AV_LOG_TRACE, "tag \"%s\" value \"%s\" atom \"%.4s\" %d %"PRId64"\n",
453 454 455
            key, str, (char*)&atom.type, str_size_alloc, atom.size);

    av_freep(&str);
456 457
    return 0;
}
458

459
static int mov_read_chpl(MOVContext *c, AVIOContext *pb, MOVAtom atom)
D
David Conrad 已提交
460 461
{
    int64_t start;
D
David Conrad 已提交
462
    int i, nb_chapters, str_len, version;
D
David Conrad 已提交
463
    char str[256+1];
464
    int ret;
D
David Conrad 已提交
465

466 467 468
    if (c->ignore_chapters)
        return 0;

D
David Conrad 已提交
469 470 471
    if ((atom.size -= 5) < 0)
        return 0;

472 473
    version = avio_r8(pb);
    avio_rb24(pb);
D
David Conrad 已提交
474
    if (version)
475 476
        avio_rb32(pb); // ???
    nb_chapters = avio_r8(pb);
D
David Conrad 已提交
477 478 479 480 481

    for (i = 0; i < nb_chapters; i++) {
        if (atom.size < 9)
            return 0;

482 483
        start = avio_rb64(pb);
        str_len = avio_r8(pb);
D
David Conrad 已提交
484 485 486 487

        if ((atom.size -= 9+str_len) < 0)
            return 0;

488 489 490
        ret = ffio_read_size(pb, str, str_len);
        if (ret < 0)
            return ret;
D
David Conrad 已提交
491
        str[str_len] = 0;
492
        avpriv_new_chapter(c->fc, i, (AVRational){1,10000000}, start, AV_NOPTS_VALUE, str);
D
David Conrad 已提交
493 494 495 496
    }
    return 0;
}

497
#define MIN_DATA_ENTRY_BOX_SIZE 12
498
static int mov_read_dref(MOVContext *c, AVIOContext *pb, MOVAtom atom)
499
{
500 501
    AVStream *st;
    MOVStreamContext *sc;
502 503
    int entries, i, j;

504 505 506 507 508
    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;

509 510
    avio_rb32(pb); // version + flags
    entries = avio_rb32(pb);
511 512
    if (entries >  (atom.size - 1) / MIN_DATA_ENTRY_BOX_SIZE + 1 ||
        entries >= UINT_MAX / sizeof(*sc->drefs))
513
        return AVERROR_INVALIDDATA;
514
    av_free(sc->drefs);
515
    sc->drefs_count = 0;
516
    sc->drefs = av_mallocz(entries * sizeof(*sc->drefs));
517 518 519
    if (!sc->drefs)
        return AVERROR(ENOMEM);
    sc->drefs_count = entries;
520

521
    for (i = 0; i < entries; i++) {
522
        MOVDref *dref = &sc->drefs[i];
523
        uint32_t size = avio_rb32(pb);
524
        int64_t next = avio_tell(pb) + size - 4;
525

526
        if (size < 12)
527
            return AVERROR_INVALIDDATA;
528

529 530
        dref->type = avio_rl32(pb);
        avio_rb32(pb); // version + flags
531
        av_log(c->fc, AV_LOG_TRACE, "type %.4s size %d\n", (char*)&dref->type, size);
532 533 534 535 536

        if (dref->type == MKTAG('a','l','i','s') && size > 150) {
            /* macintosh alias record */
            uint16_t volume_len, len;
            int16_t type;
537
            int ret;
538

539
            avio_skip(pb, 10);
540

541
            volume_len = avio_r8(pb);
542
            volume_len = FFMIN(volume_len, 27);
543 544 545
            ret = ffio_read_size(pb, dref->volume, 27);
            if (ret < 0)
                return ret;
546 547
            dref->volume[volume_len] = 0;
            av_log(c->fc, AV_LOG_DEBUG, "volume %s, len %d\n", dref->volume, volume_len);
548

549
            avio_skip(pb, 12);
550

551
            len = avio_r8(pb);
552
            len = FFMIN(len, 63);
553 554 555
            ret = ffio_read_size(pb, dref->filename, 63);
            if (ret < 0)
                return ret;
556 557 558
            dref->filename[len] = 0;
            av_log(c->fc, AV_LOG_DEBUG, "filename %s, len %d\n", dref->filename, len);

559
            avio_skip(pb, 16);
560 561

            /* read next level up_from_alias/down_to_target */
562 563
            dref->nlvl_from = avio_rb16(pb);
            dref->nlvl_to   = avio_rb16(pb);
564 565 566
            av_log(c->fc, AV_LOG_DEBUG, "nlvl from %d, nlvl to %d\n",
                   dref->nlvl_from, dref->nlvl_to);

567
            avio_skip(pb, 16);
568

569
            for (type = 0; type != -1 && avio_tell(pb) < next; ) {
570
                if(avio_feof(pb))
571
                    return AVERROR_EOF;
572 573
                type = avio_rb16(pb);
                len = avio_rb16(pb);
574 575 576
                av_log(c->fc, AV_LOG_DEBUG, "type %d, len %d\n", type, len);
                if (len&1)
                    len += 1;
V
Vittorio Giovara 已提交
577
                if (type == 2) { // absolute path
578
                    av_free(dref->path);
579
                    dref->path = av_mallocz(len+1);
580 581
                    if (!dref->path)
                        return AVERROR(ENOMEM);
582 583 584

                    ret = ffio_read_size(pb, dref->path, len);
                    if (ret < 0) {
585
                        av_freep(&dref->path);
586
                        return ret;
587
                    }
588
                    if (len > volume_len && !strncmp(dref->path, dref->volume, volume_len)) {
589 590 591 592 593
                        len -= volume_len;
                        memmove(dref->path, dref->path+volume_len, len);
                        dref->path[len] = 0;
                    }
                    for (j = 0; j < len; j++)
V
Vittorio Giovara 已提交
594
                        if (dref->path[j] == ':' || dref->path[j] == 0)
595 596
                            dref->path[j] = '/';
                    av_log(c->fc, AV_LOG_DEBUG, "path %s\n", dref->path);
597 598 599 600 601
                } else if (type == 0) { // directory name
                    av_free(dref->dir);
                    dref->dir = av_malloc(len+1);
                    if (!dref->dir)
                        return AVERROR(ENOMEM);
602 603 604

                    ret = ffio_read_size(pb, dref->dir, len);
                    if (ret < 0) {
605
                        av_freep(&dref->dir);
606
                        return ret;
607
                    }
608 609 610 611 612
                    dref->dir[len] = 0;
                    for (j = 0; j < len; j++)
                        if (dref->dir[j] == ':')
                            dref->dir[j] = '/';
                    av_log(c->fc, AV_LOG_DEBUG, "dir %s\n", dref->dir);
613
                } else
614
                    avio_skip(pb, len);
615
            }
616 617 618 619 620
        } else {
            av_log(c->fc, AV_LOG_DEBUG, "Unknown dref type 0x08%x size %d\n",
                   dref->type, size);
            entries--;
            i--;
621
        }
A
Anton Khirnov 已提交
622
        avio_seek(pb, next, SEEK_SET);
623 624 625 626
    }
    return 0;
}

627
static int mov_read_hdlr(MOVContext *c, AVIOContext *pb, MOVAtom atom)
628
{
629
    AVStream *st;
630
    uint32_t type;
631
    uint32_t av_unused ctype;
632
    int64_t title_size;
633
    char *title_str;
634
    int ret;
635

636 637
    avio_r8(pb); /* version */
    avio_rb24(pb); /* flags */
638 639

    /* component type */
640 641
    ctype = avio_rl32(pb);
    type = avio_rl32(pb); /* component subtype */
642

643 644
    av_log(c->fc, AV_LOG_TRACE, "ctype= %.4s (0x%08x)\n", (char*)&ctype, ctype);
    av_log(c->fc, AV_LOG_TRACE, "stype= %.4s\n", (char*)&type);
645

646 647 648 649 650 651 652 653 654
    if (c->fc->nb_streams < 1) {  // meta before first trak
        if (type == MKTAG('m','d','t','a')) {
            c->found_hdlr_mdta = 1;
        }
        return 0;
    }

    st = c->fc->streams[c->fc->nb_streams-1];

655
    if     (type == MKTAG('v','i','d','e'))
656
        st->codec->codec_type = AVMEDIA_TYPE_VIDEO;
657
    else if (type == MKTAG('s','o','u','n'))
658
        st->codec->codec_type = AVMEDIA_TYPE_AUDIO;
659
    else if (type == MKTAG('m','1','a',' '))
660
        st->codec->codec_id = AV_CODEC_ID_MP2;
661
    else if ((type == MKTAG('s','u','b','p')) || (type == MKTAG('c','l','c','p')))
662
        st->codec->codec_type = AVMEDIA_TYPE_SUBTITLE;
663

664 665 666
    avio_rb32(pb); /* component  manufacture */
    avio_rb32(pb); /* component flags */
    avio_rb32(pb); /* component flags mask */
667

668 669 670 671 672
    title_size = atom.size - 24;
    if (title_size > 0) {
        title_str = av_malloc(title_size + 1); /* Add null terminator */
        if (!title_str)
            return AVERROR(ENOMEM);
673 674 675

        ret = ffio_read_size(pb, title_str, title_size);
        if (ret < 0) {
676
            av_freep(&title_str);
677
            return ret;
678
        }
679
        title_str[title_size] = 0;
680 681 682 683
        if (title_str[0]) {
            int off = (!c->isom && title_str[0] == title_size - 1);
            av_dict_set(&st->metadata, "handler_name", title_str + off, 0);
        }
684 685 686
        av_freep(&title_str);
    }

687 688 689
    return 0;
}

690
int ff_mov_read_esds(AVFormatContext *fc, AVIOContext *pb)
691
{
692
    AVStream *st;
693
    int tag;
694

695
    if (fc->nb_streams < 1)
696
        return 0;
697
    st = fc->streams[fc->nb_streams-1];
698

699
    avio_rb32(pb); /* version + flags */
700
    ff_mp4_read_descr(fc, pb, &tag);
701
    if (tag == MP4ESDescrTag) {
702
        ff_mp4_parse_es_descr(pb, NULL);
703
    } else
704
        avio_rb16(pb); /* ID */
705

706
    ff_mp4_read_descr(fc, pb, &tag);
707 708
    if (tag == MP4DecConfigDescrTag)
        ff_mp4_read_dec_config_descr(fc, st, pb);
709 710 711
    return 0;
}

712
static int mov_read_esds(MOVContext *c, AVIOContext *pb, MOVAtom atom)
713
{
714
    return ff_mov_read_esds(c->fc, pb);
715 716
}

717
static int mov_read_dac3(MOVContext *c, AVIOContext *pb, MOVAtom atom)
718 719
{
    AVStream *st;
720
    enum AVAudioServiceType *ast;
721
    int ac3info, acmod, lfeon, bsmod;
722

723 724
    if (c->fc->nb_streams < 1)
        return 0;
725 726
    st = c->fc->streams[c->fc->nb_streams-1];

727
    ast = (enum AVAudioServiceType*)av_stream_new_side_data(st, AV_PKT_DATA_AUDIO_SERVICE_TYPE,
728 729 730 731
                                                            sizeof(*ast));
    if (!ast)
        return AVERROR(ENOMEM);

732
    ac3info = avio_rb24(pb);
733
    bsmod = (ac3info >> 14) & 0x7;
734 735 736
    acmod = (ac3info >> 11) & 0x7;
    lfeon = (ac3info >> 10) & 0x1;
    st->codec->channels = ((int[]){2,1,2,3,3,4,4,5})[acmod] + lfeon;
737 738 739
    st->codec->channel_layout = avpriv_ac3_channel_layout_tab[acmod];
    if (lfeon)
        st->codec->channel_layout |= AV_CH_LOW_FREQUENCY;
740
    *ast = bsmod;
741
    if (st->codec->channels > 1 && bsmod == 0x7)
742 743 744
        *ast = AV_AUDIO_SERVICE_TYPE_KARAOKE;

    st->codec->audio_service_type = *ast;
745 746 747 748

    return 0;
}

749 750 751
static int mov_read_dec3(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    AVStream *st;
752
    enum AVAudioServiceType *ast;
753 754 755 756 757 758
    int eac3info, acmod, lfeon, bsmod;

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];

759
    ast = (enum AVAudioServiceType*)av_stream_new_side_data(st, AV_PKT_DATA_AUDIO_SERVICE_TYPE,
760 761 762 763
                                                            sizeof(*ast));
    if (!ast)
        return AVERROR(ENOMEM);

764 765 766 767 768 769 770 771 772 773 774 775
    /* No need to parse fields for additional independent substreams and its
     * associated dependent substreams since libavcodec's E-AC-3 decoder
     * does not support them yet. */
    avio_rb16(pb); /* data_rate and num_ind_sub */
    eac3info = avio_rb24(pb);
    bsmod = (eac3info >> 12) & 0x1f;
    acmod = (eac3info >>  9) & 0x7;
    lfeon = (eac3info >>  8) & 0x1;
    st->codec->channel_layout = avpriv_ac3_channel_layout_tab[acmod];
    if (lfeon)
        st->codec->channel_layout |= AV_CH_LOW_FREQUENCY;
    st->codec->channels = av_get_channel_layout_nb_channels(st->codec->channel_layout);
776
    *ast = bsmod;
777
    if (st->codec->channels > 1 && bsmod == 0x7)
778 779 780
        *ast = AV_AUDIO_SERVICE_TYPE_KARAOKE;

    st->codec->audio_service_type = *ast;
781 782 783 784

    return 0;
}

785 786 787 788 789 790 791 792 793 794 795 796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839
static int mov_read_ddts(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    const uint32_t ddts_size = 20;
    AVStream *st = NULL;
    uint8_t *buf = NULL;
    uint32_t frame_duration_code = 0;
    uint32_t channel_layout_code = 0;
    GetBitContext gb;

    buf = av_malloc(ddts_size + FF_INPUT_BUFFER_PADDING_SIZE);
    if (!buf) {
        return AVERROR(ENOMEM);
    }
    if (avio_read(pb, buf, ddts_size) < ddts_size) {
        av_free(buf);
        return AVERROR_INVALIDDATA;
    }

    init_get_bits(&gb, buf, 8*ddts_size);

    if (c->fc->nb_streams < 1) {
        return 0;
    }
    st = c->fc->streams[c->fc->nb_streams-1];

    st->codec->sample_rate = get_bits_long(&gb, 32);
    skip_bits_long(&gb, 32); /* max bitrate */
    st->codec->bit_rate = get_bits_long(&gb, 32);
    st->codec->bits_per_coded_sample = get_bits(&gb, 8);
    frame_duration_code = get_bits(&gb, 2);
    skip_bits(&gb, 30); /* various fields */
    channel_layout_code = get_bits(&gb, 16);

    st->codec->frame_size =
            (frame_duration_code == 0) ? 512 :
            (frame_duration_code == 1) ? 1024 :
            (frame_duration_code == 2) ? 2048 :
            (frame_duration_code == 3) ? 4096 : 0;

    if (channel_layout_code > 0xff) {
        av_log(c->fc, AV_LOG_WARNING, "Unsupported DTS audio channel layout");
    }
    st->codec->channel_layout =
            ((channel_layout_code & 0x1) ? AV_CH_FRONT_CENTER : 0) |
            ((channel_layout_code & 0x2) ? AV_CH_FRONT_LEFT : 0) |
            ((channel_layout_code & 0x2) ? AV_CH_FRONT_RIGHT : 0) |
            ((channel_layout_code & 0x4) ? AV_CH_SIDE_LEFT : 0) |
            ((channel_layout_code & 0x4) ? AV_CH_SIDE_RIGHT : 0) |
            ((channel_layout_code & 0x8) ? AV_CH_LOW_FREQUENCY : 0);

    st->codec->channels = av_get_channel_layout_nb_channels(st->codec->channel_layout);

    return 0;
}

840 841 842 843 844 845 846 847 848 849 850
static int mov_read_chan(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    AVStream *st;

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];

    if (atom.size < 16)
        return 0;

851 852 853
    /* skip version and flags */
    avio_skip(pb, 4);

854
    ff_mov_read_chan(c->fc, pb, st, atom.size - 4);
855 856 857 858

    return 0;
}

859 860 861
static int mov_read_wfex(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    AVStream *st;
862
    int ret;
863 864 865 866 867

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];

868
    if ((ret = ff_get_wav_header(c->fc, pb, st->codec, atom.size, 0)) < 0)
869
        av_log(c->fc, AV_LOG_WARNING, "get_wav_header failed\n");
870

871
    return ret;
872 873
}

874
static int mov_read_pasp(MOVContext *c, AVIOContext *pb, MOVAtom atom)
875
{
876 877
    const int num = avio_rb32(pb);
    const int den = avio_rb32(pb);
878 879 880 881 882 883
    AVStream *st;

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];

884 885 886 887 888 889 890
    if ((st->sample_aspect_ratio.den != 1 || st->sample_aspect_ratio.num) && // default
        (den != st->sample_aspect_ratio.den || num != st->sample_aspect_ratio.num)) {
        av_log(c->fc, AV_LOG_WARNING,
               "sample aspect ratio already set to %d:%d, ignoring 'pasp' atom (%d:%d)\n",
               st->sample_aspect_ratio.num, st->sample_aspect_ratio.den,
               num, den);
    } else if (den != 0) {
891 892
        av_reduce(&st->sample_aspect_ratio.num, &st->sample_aspect_ratio.den,
                  num, den, 32767);
893 894 895 896
    }
    return 0;
}

897
/* this atom contains actual media data */
898
static int mov_read_mdat(MOVContext *c, AVIOContext *pb, MOVAtom atom)
899
{
900
    if (atom.size == 0) /* wrong one (MP4) */
901 902 903 904 905
        return 0;
    c->found_mdat=1;
    return 0; /* now go for moov */
}

906 907 908 909 910 911 912 913 914 915 916 917 918 919 920 921 922 923 924 925 926 927 928 929 930 931 932 933
#define DRM_BLOB_SIZE 56

static int mov_read_adrm(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    uint8_t intermediate_key[20];
    uint8_t intermediate_iv[20];
    uint8_t input[64];
    uint8_t output[64];
    uint8_t file_checksum[20];
    uint8_t calculated_checksum[20];
    struct AVSHA *sha;
    int i;
    int ret = 0;
    uint8_t *activation_bytes = c->activation_bytes;
    uint8_t *fixed_key = c->audible_fixed_key;

    c->aax_mode = 1;

    sha = av_sha_alloc();
    if (!sha)
        return AVERROR(ENOMEM);
    c->aes_decrypt = av_aes_alloc();
    if (!c->aes_decrypt) {
        ret = AVERROR(ENOMEM);
        goto fail;
    }

    /* drm blob processing */
A
Andreas Cadhalpun 已提交
934
    avio_read(pb, output, 8); // go to offset 8, absolute position 0x251
935
    avio_read(pb, input, DRM_BLOB_SIZE);
A
Andreas Cadhalpun 已提交
936
    avio_read(pb, output, 4); // go to offset 4, absolute position 0x28d
937 938 939 940 941 942 943 944
    avio_read(pb, file_checksum, 20);

    av_log(c->fc, AV_LOG_INFO, "[aax] file checksum == "); // required by external tools
    for (i = 0; i < 20; i++)
        av_log(sha, AV_LOG_INFO, "%02x", file_checksum[i]);
    av_log(c->fc, AV_LOG_INFO, "\n");

    /* verify activation data */
945 946 947
    if (!activation_bytes) {
        av_log(c->fc, AV_LOG_WARNING, "[aax] activation_bytes option is missing!\n");
        ret = 0;  /* allow ffprobe to continue working on .aax files */
948 949 950 951 952 953 954 955 956 957 958 959 960 961 962 963 964 965 966 967 968 969 970 971 972 973 974 975 976 977 978 979 980 981 982 983 984 985 986 987 988 989 990 991 992 993 994 995 996 997 998 999 1000 1001 1002 1003 1004 1005 1006 1007 1008 1009 1010 1011 1012 1013 1014 1015 1016 1017 1018 1019
        goto fail;
    }
    if (c->activation_bytes_size != 4) {
        av_log(c->fc, AV_LOG_FATAL, "[aax] activation_bytes value needs to be 4 bytes!\n");
        ret = AVERROR(EINVAL);
        goto fail;
    }

    /* verify fixed key */
    if (c->audible_fixed_key_size != 16) {
        av_log(c->fc, AV_LOG_FATAL, "[aax] audible_fixed_key value needs to be 16 bytes!\n");
        ret = AVERROR(EINVAL);
        goto fail;
    }

    /* AAX (and AAX+) key derivation */
    av_sha_init(sha, 160);
    av_sha_update(sha, fixed_key, 16);
    av_sha_update(sha, activation_bytes, 4);
    av_sha_final(sha, intermediate_key);
    av_sha_init(sha, 160);
    av_sha_update(sha, fixed_key, 16);
    av_sha_update(sha, intermediate_key, 20);
    av_sha_update(sha, activation_bytes, 4);
    av_sha_final(sha, intermediate_iv);
    av_sha_init(sha, 160);
    av_sha_update(sha, intermediate_key, 16);
    av_sha_update(sha, intermediate_iv, 16);
    av_sha_final(sha, calculated_checksum);
    if (memcmp(calculated_checksum, file_checksum, 20)) { // critical error
        av_log(c->fc, AV_LOG_ERROR, "[aax] mismatch in checksums!\n");
        ret = AVERROR_INVALIDDATA;
        goto fail;
    }
    av_aes_init(c->aes_decrypt, intermediate_key, 128, 1);
    av_aes_crypt(c->aes_decrypt, output, input, DRM_BLOB_SIZE >> 4, intermediate_iv, 1);
    for (i = 0; i < 4; i++) {
        // file data (in output) is stored in big-endian mode
        if (activation_bytes[i] != output[3 - i]) { // critical error
            av_log(c->fc, AV_LOG_ERROR, "[aax] error in drm blob decryption!\n");
            ret = AVERROR_INVALIDDATA;
            goto fail;
        }
    }
    memcpy(c->file_key, output + 8, 16);
    memcpy(input, output + 26, 16);
    av_sha_init(sha, 160);
    av_sha_update(sha, input, 16);
    av_sha_update(sha, c->file_key, 16);
    av_sha_update(sha, fixed_key, 16);
    av_sha_final(sha, c->file_iv);

fail:
    av_free(sha);

    return ret;
}

// Audible AAX (and AAX+) bytestream decryption
static int aax_filter(uint8_t *input, int size, MOVContext *c)
{
    int blocks = 0;
    unsigned char iv[16];

    memcpy(iv, c->file_iv, 16); // iv is overwritten
    blocks = size >> 4; // trailing bytes are not encrypted!
    av_aes_init(c->aes_decrypt, c->file_key, 128, 1);
    av_aes_crypt(c->aes_decrypt, input, input, blocks, iv, 1);

    return 0;
}

1020
/* read major brand, minor version and compatible brands and store them as metadata */
1021
static int mov_read_ftyp(MOVContext *c, AVIOContext *pb, MOVAtom atom)
1022
{
1023 1024 1025 1026
    uint32_t minor_ver;
    int comp_brand_size;
    char* comp_brands_str;
    uint8_t type[5] = {0};
1027 1028 1029
    int ret = ffio_read_size(pb, type, 4);
    if (ret < 0)
        return ret;
1030

B
Baptiste Coudurier 已提交
1031
    if (strcmp(type, "qt  "))
1032
        c->isom = 1;
1033
    av_log(c->fc, AV_LOG_DEBUG, "ISO: File Type Major Brand: %.4s\n",(char *)&type);
1034
    av_dict_set(&c->fc->metadata, "major_brand", type, 0);
1035
    minor_ver = avio_rb32(pb); /* minor version */
1036
    av_dict_set_int(&c->fc->metadata, "minor_version", minor_ver, 0);
1037 1038 1039

    comp_brand_size = atom.size - 8;
    if (comp_brand_size < 0)
1040
        return AVERROR_INVALIDDATA;
1041 1042 1043
    comp_brands_str = av_malloc(comp_brand_size + 1); /* Add null terminator */
    if (!comp_brands_str)
        return AVERROR(ENOMEM);
1044 1045 1046

    ret = ffio_read_size(pb, comp_brands_str, comp_brand_size);
    if (ret < 0) {
1047
        av_freep(&comp_brands_str);
1048
        return ret;
1049
    }
1050
    comp_brands_str[comp_brand_size] = 0;
1051
    av_dict_set(&c->fc->metadata, "compatible_brands", comp_brands_str, 0);
1052 1053
    av_freep(&comp_brands_str);

1054 1055 1056
    return 0;
}

1057
/* this atom should contain all header atoms */
1058
static int mov_read_moov(MOVContext *c, AVIOContext *pb, MOVAtom atom)
1059
{
1060 1061
    int ret;

1062 1063 1064 1065 1066 1067
    if (c->found_moov) {
        av_log(c->fc, AV_LOG_WARNING, "Found duplicated MOOV Atom. Skipped it\n");
        avio_skip(pb, atom.size);
        return 0;
    }

1068 1069
    if ((ret = mov_read_default(c, pb, atom)) < 0)
        return ret;
1070 1071 1072 1073 1074 1075
    /* we parsed the 'moov' atom, we can terminate the parsing as soon as we find the 'mdat' */
    /* so we don't parse the whole file if over a network */
    c->found_moov=1;
    return 0; /* now go for mdat */
}

1076
static int mov_read_moof(MOVContext *c, AVIOContext *pb, MOVAtom atom)
B
Baptiste Coudurier 已提交
1077
{
1078 1079 1080
    if (!c->has_looked_for_mfra && c->use_mfra_for > 0) {
        c->has_looked_for_mfra = 1;
        if (pb->seekable) {
1081
            int ret;
1082 1083 1084 1085 1086 1087 1088 1089 1090 1091 1092
            av_log(c->fc, AV_LOG_VERBOSE, "stream has moof boxes, will look "
                    "for a mfra\n");
            if ((ret = mov_read_mfra(c, pb)) < 0) {
                av_log(c->fc, AV_LOG_VERBOSE, "found a moof box but failed to "
                        "read the mfra (may be a live ismv)\n");
            }
        } else {
            av_log(c->fc, AV_LOG_VERBOSE, "found a moof box but stream is not "
                    "seekable, can not look for mfra\n");
        }
    }
1093
    c->fragment.moof_offset = c->fragment.implicit_offset = avio_tell(pb) - 8;
1094
    av_log(c->fc, AV_LOG_TRACE, "moof offset %"PRIx64"\n", c->fragment.moof_offset);
B
Baptiste Coudurier 已提交
1095 1096
    return mov_read_default(c, pb, atom);
}
1097

1098
static void mov_metadata_creation_time(AVDictionary **metadata, int64_t time)
1099 1100 1101
{
    char buffer[32];
    if (time) {
1102
        struct tm *ptm, tmbuf;
1103
        time_t timet;
1104 1105
        if(time >= 2082844800)
            time -= 2082844800;  /* seconds between 1904-01-01 and Epoch */
1106
        timet = time;
1107
        ptm = gmtime_r(&timet, &tmbuf);
1108
        if (!ptm) return;
1109 1110
        if (strftime(buffer, sizeof(buffer), "%Y-%m-%d %H:%M:%S", ptm))
            av_dict_set(metadata, "creation_time", buffer, 0);
1111 1112 1113
    }
}

1114
static int mov_read_mdhd(MOVContext *c, AVIOContext *pb, MOVAtom atom)
1115
{
1116 1117 1118
    AVStream *st;
    MOVStreamContext *sc;
    int version;
1119
    char language[4] = {0};
1120
    unsigned lang;
1121
    int64_t creation_time;
1122

1123 1124 1125 1126 1127
    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;

1128 1129 1130 1131 1132
    if (sc->time_scale) {
        av_log(c->fc, AV_LOG_ERROR, "Multiple mdhd?\n");
        return AVERROR_INVALIDDATA;
    }

1133
    version = avio_r8(pb);
1134
    if (version > 1) {
1135
        avpriv_request_sample(c->fc, "Version %d", version);
1136 1137
        return AVERROR_PATCHWELCOME;
    }
1138
    avio_rb24(pb); /* flags */
B
clean  
Baptiste Coudurier 已提交
1139
    if (version == 1) {
1140 1141
        creation_time = avio_rb64(pb);
        avio_rb64(pb);
B
clean  
Baptiste Coudurier 已提交
1142
    } else {
1143 1144
        creation_time = avio_rb32(pb);
        avio_rb32(pb); /* modification time */
B
clean  
Baptiste Coudurier 已提交
1145
    }
1146
    mov_metadata_creation_time(&st->metadata, creation_time);
1147

1148 1149
    sc->time_scale = avio_rb32(pb);
    st->duration = (version == 1) ? avio_rb64(pb) : avio_rb32(pb); /* duration */
1150

1151
    lang = avio_rb16(pb); /* language */
1152
    if (ff_mov_lang_to_iso639(lang, language))
1153
        av_dict_set(&st->metadata, "language", language, 0);
1154
    avio_rb16(pb); /* quality */
1155 1156 1157 1158

    return 0;
}

1159
static int mov_read_mvhd(MOVContext *c, AVIOContext *pb, MOVAtom atom)
1160
{
1161
    int64_t creation_time;
1162 1163
    int version = avio_r8(pb); /* version */
    avio_rb24(pb); /* flags */
1164

B
Baptiste Coudurier 已提交
1165
    if (version == 1) {
1166 1167
        creation_time = avio_rb64(pb);
        avio_rb64(pb);
B
Baptiste Coudurier 已提交
1168
    } else {
1169 1170
        creation_time = avio_rb32(pb);
        avio_rb32(pb); /* modification time */
B
Baptiste Coudurier 已提交
1171
    }
1172
    mov_metadata_creation_time(&c->fc->metadata, creation_time);
1173
    c->time_scale = avio_rb32(pb); /* time scale */
1174

1175
    av_log(c->fc, AV_LOG_TRACE, "time scale = %i\n", c->time_scale);
1176

1177
    c->duration = (version == 1) ? avio_rb64(pb) : avio_rb32(pb); /* duration */
1178 1179
    // set the AVCodecContext duration because the duration of individual tracks
    // may be inaccurate
1180
    if (c->time_scale > 0 && !c->trex_data)
1181
        c->fc->duration = av_rescale(c->duration, AV_TIME_BASE, c->time_scale);
1182
    avio_rb32(pb); /* preferred scale */
1183

1184
    avio_rb16(pb); /* preferred volume */
1185

1186
    avio_skip(pb, 10); /* reserved */
1187

1188
    avio_skip(pb, 36); /* display matrix */
1189

1190 1191 1192 1193 1194 1195 1196
    avio_rb32(pb); /* preview time */
    avio_rb32(pb); /* preview duration */
    avio_rb32(pb); /* poster time */
    avio_rb32(pb); /* selection time */
    avio_rb32(pb); /* selection duration */
    avio_rb32(pb); /* current time */
    avio_rb32(pb); /* next track ID */
1197 1198 1199 1200

    return 0;
}

1201
static int mov_read_enda(MOVContext *c, AVIOContext *pb, MOVAtom atom)
1202
{
1203 1204 1205 1206 1207 1208
    AVStream *st;
    int little_endian;

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
1209

1210
    little_endian = avio_rb16(pb) & 0xFF;
1211
    av_log(c->fc, AV_LOG_TRACE, "enda %d\n", little_endian);
1212
    if (little_endian == 1) {
1213
        switch (st->codec->codec_id) {
1214 1215
        case AV_CODEC_ID_PCM_S24BE:
            st->codec->codec_id = AV_CODEC_ID_PCM_S24LE;
1216
            break;
1217 1218
        case AV_CODEC_ID_PCM_S32BE:
            st->codec->codec_id = AV_CODEC_ID_PCM_S32LE;
1219
            break;
1220 1221
        case AV_CODEC_ID_PCM_F32BE:
            st->codec->codec_id = AV_CODEC_ID_PCM_F32LE;
1222
            break;
1223 1224
        case AV_CODEC_ID_PCM_F64BE:
            st->codec->codec_id = AV_CODEC_ID_PCM_F64LE;
1225
            break;
1226 1227 1228 1229 1230 1231 1232
        default:
            break;
        }
    }
    return 0;
}

1233 1234 1235 1236
static int mov_read_colr(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    AVStream *st;
    char color_parameter_type[5] = { 0 };
1237
    uint16_t color_primaries, color_trc, color_matrix;
1238
    int ret;
1239 1240 1241 1242 1243

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams - 1];

1244 1245 1246
    ret = ffio_read_size(pb, color_parameter_type, 4);
    if (ret < 0)
        return ret;
1247 1248 1249 1250 1251 1252 1253 1254 1255 1256 1257
    if (strncmp(color_parameter_type, "nclx", 4) &&
        strncmp(color_parameter_type, "nclc", 4)) {
        av_log(c->fc, AV_LOG_WARNING, "unsupported color_parameter_type %s\n",
               color_parameter_type);
        return 0;
    }

    color_primaries = avio_rb16(pb);
    color_trc = avio_rb16(pb);
    color_matrix = avio_rb16(pb);

1258
    av_log(c->fc, AV_LOG_TRACE,
1259
           "%s: pri %d trc %d matrix %d",
1260
           color_parameter_type, color_primaries, color_trc, color_matrix);
1261

1262
    if (!strncmp(color_parameter_type, "nclx", 4)) {
1263
        uint8_t color_range = avio_r8(pb) >> 7;
1264
        av_log(c->fc, AV_LOG_TRACE, " full %"PRIu8"", color_range);
1265 1266 1267 1268 1269 1270 1271 1272
        if (color_range)
            st->codec->color_range = AVCOL_RANGE_JPEG;
        else
            st->codec->color_range = AVCOL_RANGE_MPEG;
        /* 14496-12 references JPEG XR specs (rather than the more complete
         * 23001-8) so some adjusting is required */
        if (color_primaries >= AVCOL_PRI_FILM)
            color_primaries = AVCOL_PRI_UNSPECIFIED;
1273 1274
        if ((color_trc >= AVCOL_TRC_LINEAR &&
             color_trc <= AVCOL_TRC_LOG_SQRT) ||
1275 1276 1277 1278 1279 1280 1281
            color_trc >= AVCOL_TRC_BT2020_10)
            color_trc = AVCOL_TRC_UNSPECIFIED;
        if (color_matrix >= AVCOL_SPC_BT2020_NCL)
            color_matrix = AVCOL_SPC_UNSPECIFIED;
        st->codec->color_primaries = color_primaries;
        st->codec->color_trc = color_trc;
        st->codec->colorspace = color_matrix;
1282
    } else if (!strncmp(color_parameter_type, "nclc", 4)) {
1283 1284 1285 1286 1287 1288 1289 1290 1291 1292 1293 1294 1295 1296 1297 1298 1299 1300
        /* color primaries, Table 4-4 */
        switch (color_primaries) {
        case 1: st->codec->color_primaries = AVCOL_PRI_BT709; break;
        case 5: st->codec->color_primaries = AVCOL_PRI_SMPTE170M; break;
        case 6: st->codec->color_primaries = AVCOL_PRI_SMPTE240M; break;
        }
        /* color transfer, Table 4-5 */
        switch (color_trc) {
        case 1: st->codec->color_trc = AVCOL_TRC_BT709; break;
        case 7: st->codec->color_trc = AVCOL_TRC_SMPTE240M; break;
        }
        /* color matrix, Table 4-6 */
        switch (color_matrix) {
        case 1: st->codec->colorspace = AVCOL_SPC_BT709; break;
        case 6: st->codec->colorspace = AVCOL_SPC_BT470BG; break;
        case 7: st->codec->colorspace = AVCOL_SPC_SMPTE240M; break;
        }
    }
1301
    av_log(c->fc, AV_LOG_TRACE, "\n");
1302 1303 1304 1305

    return 0;
}

1306 1307 1308 1309 1310 1311 1312 1313 1314 1315 1316 1317 1318 1319 1320 1321 1322 1323 1324 1325 1326 1327 1328 1329 1330 1331 1332 1333 1334 1335 1336 1337 1338 1339
static int mov_read_fiel(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    AVStream *st;
    unsigned mov_field_order;
    enum AVFieldOrder decoded_field_order = AV_FIELD_UNKNOWN;

    if (c->fc->nb_streams < 1) // will happen with jp2 files
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    if (atom.size < 2)
        return AVERROR_INVALIDDATA;
    mov_field_order = avio_rb16(pb);
    if ((mov_field_order & 0xFF00) == 0x0100)
        decoded_field_order = AV_FIELD_PROGRESSIVE;
    else if ((mov_field_order & 0xFF00) == 0x0200) {
        switch (mov_field_order & 0xFF) {
        case 0x01: decoded_field_order = AV_FIELD_TT;
                   break;
        case 0x06: decoded_field_order = AV_FIELD_BB;
                   break;
        case 0x09: decoded_field_order = AV_FIELD_TB;
                   break;
        case 0x0E: decoded_field_order = AV_FIELD_BT;
                   break;
        }
    }
    if (decoded_field_order == AV_FIELD_UNKNOWN && mov_field_order) {
        av_log(NULL, AV_LOG_ERROR, "Unknown MOV field order 0x%04x\n", mov_field_order);
    }
    st->codec->field_order = decoded_field_order;

    return 0;
}

1340 1341 1342
static int mov_realloc_extradata(AVCodecContext *codec, MOVAtom atom)
{
    int err = 0;
1343
    uint64_t size = (uint64_t)codec->extradata_size + atom.size + 8 + AV_INPUT_BUFFER_PADDING_SIZE;
1344 1345 1346 1347 1348 1349
    if (size > INT_MAX || (uint64_t)atom.size > INT_MAX)
        return AVERROR_INVALIDDATA;
    if ((err = av_reallocp(&codec->extradata, size)) < 0) {
        codec->extradata_size = 0;
        return err;
    }
1350
    codec->extradata_size = size - AV_INPUT_BUFFER_PADDING_SIZE;
1351 1352 1353 1354 1355 1356 1357 1358 1359 1360 1361 1362
    return 0;
}

/* Read a whole atom into the extradata return the size of the atom read, possibly truncated if != atom.size */
static int64_t mov_read_atom_into_extradata(MOVContext *c, AVIOContext *pb, MOVAtom atom,
                                        AVCodecContext *codec, uint8_t *buf)
{
    int64_t result = atom.size;
    int err;

    AV_WB32(buf    , atom.size + 8);
    AV_WL32(buf + 4, atom.type);
1363
    err = ffio_read_size(pb, buf + 8, atom.size);
1364 1365 1366 1367 1368 1369 1370 1371
    if (err < 0) {
        codec->extradata_size -= atom.size;
        return err;
    } else if (err < atom.size) {
        av_log(c->fc, AV_LOG_WARNING, "truncated extradata\n");
        codec->extradata_size -= atom.size - err;
        result = err;
    }
1372
    memset(buf + 8 + err, 0, AV_INPUT_BUFFER_PADDING_SIZE);
1373 1374 1375
    return result;
}

1376
/* FIXME modify qdm2/svq3/h264 decoders to take full atom as extradata */
1377
static int mov_read_extradata(MOVContext *c, AVIOContext *pb, MOVAtom atom,
1378
                              enum AVCodecID codec_id)
1379
{
1380
    AVStream *st;
1381
    uint64_t original_size;
1382
    int err;
1383 1384 1385

    if (c->fc->nb_streams < 1) // will happen with jp2 files
        return 0;
1386
    st = c->fc->streams[c->fc->nb_streams-1];
1387 1388 1389 1390

    if (st->codec->codec_id != codec_id)
        return 0; /* unexpected codec_id - don't mess with extradata */

1391 1392 1393
    original_size = st->codec->extradata_size;
    err = mov_realloc_extradata(st->codec, atom);
    if (err)
1394
        return err;
1395 1396 1397

    err =  mov_read_atom_into_extradata(c, pb, atom, st->codec,  st->codec->extradata + original_size);
    if (err < 0)
1398
        return err;
1399
    return 0; // Note: this is the original behavior to ignore truncation.
1400 1401
}

1402 1403 1404
/* wrapper functions for reading ALAC/AVS/MJPEG/MJPEG2000 extradata atoms only for those codecs */
static int mov_read_alac(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
1405
    return mov_read_extradata(c, pb, atom, AV_CODEC_ID_ALAC);
1406 1407 1408 1409
}

static int mov_read_avss(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
1410
    return mov_read_extradata(c, pb, atom, AV_CODEC_ID_AVS);
1411 1412 1413 1414
}

static int mov_read_jp2h(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
1415
    return mov_read_extradata(c, pb, atom, AV_CODEC_ID_JPEG2000);
1416 1417
}

1418 1419 1420 1421 1422
static int mov_read_dpxe(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    return mov_read_extradata(c, pb, atom, AV_CODEC_ID_R10K);
}

C
Carl Eugen Hoyos 已提交
1423
static int mov_read_avid(MOVContext *c, AVIOContext *pb, MOVAtom atom)
1424
{
1425 1426 1427 1428
    int ret = mov_read_extradata(c, pb, atom, AV_CODEC_ID_AVUI);
    if(ret == 0)
        ret = mov_read_extradata(c, pb, atom, AV_CODEC_ID_DNXHD);
    return ret;
1429 1430
}

1431 1432 1433 1434 1435 1436 1437 1438 1439 1440 1441 1442 1443 1444
static int mov_read_targa_y216(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    int ret = mov_read_extradata(c, pb, atom, AV_CODEC_ID_TARGA_Y216);

    if (!ret && c->fc->nb_streams >= 1) {
        AVCodecContext *avctx = c->fc->streams[c->fc->nb_streams-1]->codec;
        if (avctx->extradata_size >= 40) {
            avctx->height = AV_RB16(&avctx->extradata[36]);
            avctx->width  = AV_RB16(&avctx->extradata[38]);
        }
    }
    return ret;
}

1445 1446
static int mov_read_ares(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
1447 1448 1449 1450 1451 1452 1453 1454 1455 1456 1457
    if (c->fc->nb_streams >= 1) {
        AVCodecContext *codec = c->fc->streams[c->fc->nb_streams-1]->codec;
        if (codec->codec_tag == MKTAG('A', 'V', 'i', 'n') &&
            codec->codec_id == AV_CODEC_ID_H264 &&
            atom.size > 11) {
            avio_skip(pb, 10);
            /* For AVID AVCI50, force width of 1440 to be able to select the correct SPS and PPS */
            if (avio_rb16(pb) == 0xd4d)
                codec->width = 1440;
            return 0;
        }
1458 1459 1460 1461 1462
    }

    return mov_read_avid(c, pb, atom);
}

1463 1464 1465 1466 1467 1468 1469
static int mov_read_aclr(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    int ret = 0;
    int length = 0;
    uint64_t original_size;
    if (c->fc->nb_streams >= 1) {
        AVCodecContext *codec = c->fc->streams[c->fc->nb_streams-1]->codec;
1470 1471
        if (codec->codec_id == AV_CODEC_ID_H264)
            return 0;
1472 1473 1474 1475 1476 1477 1478 1479 1480 1481 1482 1483 1484 1485 1486 1487 1488 1489
        if (atom.size == 16) {
            original_size = codec->extradata_size;
            ret = mov_realloc_extradata(codec, atom);
            if (!ret) {
                length =  mov_read_atom_into_extradata(c, pb, atom, codec, codec->extradata + original_size);
                if (length == atom.size) {
                    const uint8_t range_value = codec->extradata[original_size + 19];
                    switch (range_value) {
                    case 1:
                        codec->color_range = AVCOL_RANGE_MPEG;
                        break;
                    case 2:
                        codec->color_range = AVCOL_RANGE_JPEG;
                        break;
                    default:
                        av_log(c, AV_LOG_WARNING, "ignored unknown aclr value (%d)\n", range_value);
                        break;
                    }
R
Ronald S. Bultje 已提交
1490
                    ff_dlog(c, "color_range: %d\n", codec->color_range);
1491 1492 1493 1494 1495 1496 1497 1498
                } else {
                  /* For some reason the whole atom was not added to the extradata */
                  av_log(c, AV_LOG_ERROR, "aclr not decoded - incomplete atom\n");
                }
            } else {
                av_log(c, AV_LOG_ERROR, "aclr not decoded - unable to add atom to extradata\n");
            }
        } else {
1499
            av_log(c, AV_LOG_WARNING, "aclr not decoded - unexpected size %"PRId64"\n", atom.size);
1500 1501 1502 1503 1504 1505
        }
    }

    return ret;
}

P
Piotr Bandurski 已提交
1506 1507
static int mov_read_svq3(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
1508
    return mov_read_extradata(c, pb, atom, AV_CODEC_ID_SVQ3);
P
Piotr Bandurski 已提交
1509 1510
}

1511
static int mov_read_wave(MOVContext *c, AVIOContext *pb, MOVAtom atom)
R
Roberto Togni 已提交
1512
{
1513
    AVStream *st;
1514
    int ret;
1515 1516 1517 1518

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
R
Roberto Togni 已提交
1519

1520
    if ((uint64_t)atom.size > (1<<30))
1521
        return AVERROR_INVALIDDATA;
1522

1523 1524 1525
    if (st->codec->codec_id == AV_CODEC_ID_QDM2 ||
        st->codec->codec_id == AV_CODEC_ID_QDMC ||
        st->codec->codec_id == AV_CODEC_ID_SPEEX) {
1526
        // pass all frma atom to codec, needed at least for QDMC and QDM2
1527
        av_freep(&st->codec->extradata);
1528
        ret = ff_get_extradata(st->codec, pb, atom.size);
1529 1530
        if (ret < 0)
            return ret;
1531
    } else if (atom.size > 8) { /* to read frma, esds atoms */
1532 1533 1534 1535 1536 1537 1538 1539 1540 1541 1542 1543 1544 1545 1546 1547 1548 1549 1550 1551 1552 1553 1554 1555 1556 1557
        if (st->codec->codec_id == AV_CODEC_ID_ALAC && atom.size >= 24) {
            uint64_t buffer;
            ret = ffio_ensure_seekback(pb, 8);
            if (ret < 0)
                return ret;
            buffer = avio_rb64(pb);
            atom.size -= 8;
            if (  (buffer & 0xFFFFFFFF) == MKBETAG('f','r','m','a')
                && buffer >> 32 <= atom.size
                && buffer >> 32 >= 8) {
                avio_skip(pb, -8);
                atom.size += 8;
            } else if (!st->codec->extradata_size) {
#define ALAC_EXTRADATA_SIZE 36
                st->codec->extradata = av_mallocz(ALAC_EXTRADATA_SIZE + AV_INPUT_BUFFER_PADDING_SIZE);
                if (!st->codec->extradata)
                    return AVERROR(ENOMEM);
                st->codec->extradata_size = ALAC_EXTRADATA_SIZE;
                AV_WB32(st->codec->extradata    , ALAC_EXTRADATA_SIZE);
                AV_WB32(st->codec->extradata + 4, MKTAG('a','l','a','c'));
                AV_WB64(st->codec->extradata + 12, buffer);
                avio_read(pb, st->codec->extradata + 20, 16);
                avio_skip(pb, atom.size - 24);
                return 0;
            }
        }
1558 1559
        if ((ret = mov_read_default(c, pb, atom)) < 0)
            return ret;
1560
    } else
1561
        avio_skip(pb, atom.size);
R
Roberto Togni 已提交
1562 1563 1564
    return 0;
}

1565 1566 1567 1568
/**
 * This function reads atom content and puts data in extradata without tag
 * nor size unlike mov_read_extradata.
 */
1569
static int mov_read_glbl(MOVContext *c, AVIOContext *pb, MOVAtom atom)
1570
{
1571
    AVStream *st;
1572
    int ret;
1573 1574 1575 1576

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
1577

1578
    if ((uint64_t)atom.size > (1<<30))
1579
        return AVERROR_INVALIDDATA;
1580

1581
    if (atom.size >= 10) {
1582
        // Broken files created by legacy versions of libavformat will
1583 1584 1585 1586 1587 1588 1589
        // wrap a whole fiel atom inside of a glbl atom.
        unsigned size = avio_rb32(pb);
        unsigned type = avio_rl32(pb);
        avio_seek(pb, -8, SEEK_CUR);
        if (type == MKTAG('f','i','e','l') && size == atom.size)
            return mov_read_default(c, pb, atom);
    }
1590 1591 1592 1593
    if (st->codec->extradata_size > 1 && st->codec->extradata) {
        av_log(c, AV_LOG_WARNING, "ignoring multiple glbl\n");
        return 0;
    }
1594
    av_freep(&st->codec->extradata);
1595
    ret = ff_get_extradata(st->codec, pb, atom.size);
1596 1597
    if (ret < 0)
        return ret;
1598

1599 1600 1601
    return 0;
}

M
Martin Storsjö 已提交
1602 1603 1604 1605
static int mov_read_dvc1(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    AVStream *st;
    uint8_t profile_level;
1606
    int ret;
M
Martin Storsjö 已提交
1607 1608 1609 1610 1611 1612 1613 1614 1615

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];

    if (atom.size >= (1<<28) || atom.size < 7)
        return AVERROR_INVALIDDATA;

    profile_level = avio_r8(pb);
1616
    if ((profile_level & 0xf0) != 0xc0)
M
Martin Storsjö 已提交
1617 1618 1619
        return 0;

    avio_seek(pb, 6, SEEK_CUR);
1620
    av_freep(&st->codec->extradata);
1621
    ret = ff_get_extradata(st->codec, pb, atom.size - 7);
1622
    if (ret < 0)
1623
        return ret;
1624

M
Martin Storsjö 已提交
1625 1626 1627
    return 0;
}

M
Martin Storsjö 已提交
1628 1629 1630 1631 1632
/**
 * An strf atom is a BITMAPINFOHEADER struct. This struct is 40 bytes itself,
 * but can have extradata appended at the end after the 40 bytes belonging
 * to the struct.
 */
1633
static int mov_read_strf(MOVContext *c, AVIOContext *pb, MOVAtom atom)
M
Martin Storsjö 已提交
1634 1635
{
    AVStream *st;
1636
    int ret;
M
Martin Storsjö 已提交
1637 1638 1639 1640 1641 1642 1643

    if (c->fc->nb_streams < 1)
        return 0;
    if (atom.size <= 40)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];

1644
    if ((uint64_t)atom.size > (1<<30))
1645
        return AVERROR_INVALIDDATA;
M
Martin Storsjö 已提交
1646

1647
    avio_skip(pb, 40);
1648
    av_freep(&st->codec->extradata);
1649
    ret = ff_get_extradata(st->codec, pb, atom.size - 40);
1650 1651 1652
    if (ret < 0)
        return ret;

M
Martin Storsjö 已提交
1653 1654 1655
    return 0;
}

1656
static int mov_read_stco(MOVContext *c, AVIOContext *pb, MOVAtom atom)
1657
{
1658 1659
    AVStream *st;
    MOVStreamContext *sc;
1660
    unsigned int i, entries;
1661

1662 1663 1664 1665 1666
    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;

1667 1668
    avio_r8(pb); /* version */
    avio_rb24(pb); /* flags */
1669

1670
    entries = avio_rb32(pb);
1671

A
Alex Converse 已提交
1672 1673
    if (!entries)
        return 0;
1674

1675
    if (sc->chunk_offsets)
1676
        av_log(c->fc, AV_LOG_WARNING, "Duplicated STCO atom\n");
1677 1678
    av_free(sc->chunk_offsets);
    sc->chunk_count = 0;
1679
    sc->chunk_offsets = av_malloc_array(entries, sizeof(*sc->chunk_offsets));
1680
    if (!sc->chunk_offsets)
1681 1682 1683
        return AVERROR(ENOMEM);
    sc->chunk_count = entries;

1684
    if      (atom.type == MKTAG('s','t','c','o'))
1685
        for (i = 0; i < entries && !pb->eof_reached; i++)
1686
            sc->chunk_offsets[i] = avio_rb32(pb);
1687
    else if (atom.type == MKTAG('c','o','6','4'))
1688
        for (i = 0; i < entries && !pb->eof_reached; i++)
1689
            sc->chunk_offsets[i] = avio_rb64(pb);
1690
    else
1691
        return AVERROR_INVALIDDATA;
1692

1693 1694 1695 1696 1697
    sc->chunk_count = i;

    if (pb->eof_reached)
        return AVERROR_EOF;

1698 1699 1700
    return 0;
}

1701 1702 1703 1704
/**
 * Compute codec id for 'lpcm' tag.
 * See CoreAudioTypes and AudioStreamBasicDescription at Apple.
 */
1705
enum AVCodecID ff_mov_get_lpcm_codec_id(int bps, int flags)
1706
{
1707 1708 1709 1710 1711 1712
    /* lpcm flags:
     * 0x1 = float
     * 0x2 = big-endian
     * 0x4 = signed
     */
    return ff_get_pcm_codec_id(bps, flags & 1, flags & 2, flags & 4 ? -1 : 0);
1713 1714
}

1715 1716 1717 1718 1719 1720 1721 1722 1723 1724 1725 1726 1727 1728 1729 1730 1731 1732 1733
static int mov_codec_id(AVStream *st, uint32_t format)
{
    int id = ff_codec_get_id(ff_codec_movaudio_tags, format);

    if (id <= 0 &&
        ((format & 0xFFFF) == 'm' + ('s' << 8) ||
         (format & 0xFFFF) == 'T' + ('S' << 8)))
        id = ff_codec_get_id(ff_codec_wav_tags, av_bswap32(format) & 0xFFFF);

    if (st->codec->codec_type != AVMEDIA_TYPE_VIDEO && id > 0) {
        st->codec->codec_type = AVMEDIA_TYPE_AUDIO;
    } else if (st->codec->codec_type != AVMEDIA_TYPE_AUDIO &&
               /* skip old asf mpeg4 tag */
               format && format != MKTAG('m','p','4','s')) {
        id = ff_codec_get_id(ff_codec_movvideo_tags, format);
        if (id <= 0)
            id = ff_codec_get_id(ff_codec_bmp_tags, format);
        if (id > 0)
            st->codec->codec_type = AVMEDIA_TYPE_VIDEO;
1734 1735 1736
        else if (st->codec->codec_type == AVMEDIA_TYPE_DATA ||
                    (st->codec->codec_type == AVMEDIA_TYPE_SUBTITLE &&
                    st->codec->codec_id == AV_CODEC_ID_NONE)) {
1737 1738 1739 1740 1741 1742 1743 1744 1745 1746 1747
            id = ff_codec_get_id(ff_codec_movsubtitle_tags, format);
            if (id > 0)
                st->codec->codec_type = AVMEDIA_TYPE_SUBTITLE;
        }
    }

    st->codec->codec_tag = format;

    return id;
}

1748 1749 1750
static void mov_parse_stsd_video(MOVContext *c, AVIOContext *pb,
                                 AVStream *st, MOVStreamContext *sc)
{
1751
    uint8_t codec_name[32];
1752 1753 1754 1755 1756 1757 1758 1759 1760 1761 1762 1763 1764 1765 1766 1767 1768 1769 1770 1771 1772
    unsigned int color_depth, len, j;
    int color_greyscale;
    int color_table_id;

    avio_rb16(pb); /* version */
    avio_rb16(pb); /* revision level */
    avio_rb32(pb); /* vendor */
    avio_rb32(pb); /* temporal quality */
    avio_rb32(pb); /* spatial quality */

    st->codec->width  = avio_rb16(pb); /* width */
    st->codec->height = avio_rb16(pb); /* height */

    avio_rb32(pb); /* horiz resolution */
    avio_rb32(pb); /* vert resolution */
    avio_rb32(pb); /* data size, always 0 */
    avio_rb16(pb); /* frames per samples */

    len = avio_r8(pb); /* codec name, pascal string */
    if (len > 31)
        len = 31;
1773
    mov_read_mac_string(c, pb, len, codec_name, sizeof(codec_name));
1774 1775
    if (len < 31)
        avio_skip(pb, 31 - len);
1776 1777 1778 1779

    if (codec_name[0])
        av_dict_set(&st->metadata, "encoder", codec_name, 0);

1780
    /* codec_tag YV12 triggers an UV swap in rawdec.c */
1781
    if (!memcmp(codec_name, "Planar Y'CbCr 8-bit 4:2:0", 25)) {
1782
        st->codec->codec_tag = MKTAG('I', '4', '2', '0');
1783 1784 1785
        st->codec->width &= ~1;
        st->codec->height &= ~1;
    }
1786 1787
    /* Flash Media Server uses tag H263 with Sorenson Spark */
    if (st->codec->codec_tag == MKTAG('H','2','6','3') &&
1788
        !memcmp(codec_name, "Sorenson H263", 13))
1789 1790 1791 1792
        st->codec->codec_id = AV_CODEC_ID_FLV1;

    st->codec->bits_per_coded_sample = avio_rb16(pb); /* depth */
    color_table_id = avio_rb16(pb); /* colortable id */
1793
    av_log(c->fc, AV_LOG_TRACE, "depth %d, ctab id %d\n",
1794 1795 1796 1797
            st->codec->bits_per_coded_sample, color_table_id);
    /* figure out the palette situation */
    color_depth     = st->codec->bits_per_coded_sample & 0x1F;
    color_greyscale = st->codec->bits_per_coded_sample & 0x20;
1798 1799 1800
    /* Do not create a greyscale palette for cinepak */
    if (color_greyscale && st->codec->codec_id == AV_CODEC_ID_CINEPAK)
        return;
1801 1802 1803 1804 1805

    /* if the depth is 2, 4, or 8 bpp, file is palettized */
    if ((color_depth == 2) || (color_depth == 4) || (color_depth == 8)) {
        /* for palette traversal */
        unsigned int color_start, color_count, color_end;
1806
        unsigned int a, r, g, b;
1807 1808 1809 1810

        if (color_greyscale) {
            int color_index, color_dec;
            /* compute the greyscale palette */
1811
            st->codec->bits_per_coded_sample = color_depth;
1812 1813 1814 1815 1816
            color_count = 1 << color_depth;
            color_index = 255;
            color_dec   = 256 / (color_count - 1);
            for (j = 0; j < color_count; j++) {
                r = g = b = color_index;
1817
                sc->palette[j] = (0xFFU << 24) | (r << 16) | (g << 8) | (b);
1818 1819 1820 1821 1822 1823 1824 1825 1826 1827 1828 1829 1830 1831 1832 1833 1834 1835 1836
                color_index -= color_dec;
                if (color_index < 0)
                    color_index = 0;
            }
        } else if (color_table_id) {
            const uint8_t *color_table;
            /* if flag bit 3 is set, use the default palette */
            color_count = 1 << color_depth;
            if (color_depth == 2)
                color_table = ff_qt_default_palette_4;
            else if (color_depth == 4)
                color_table = ff_qt_default_palette_16;
            else
                color_table = ff_qt_default_palette_256;

            for (j = 0; j < color_count; j++) {
                r = color_table[j * 3 + 0];
                g = color_table[j * 3 + 1];
                b = color_table[j * 3 + 2];
1837
                sc->palette[j] = (0xFFU << 24) | (r << 16) | (g << 8) | (b);
1838 1839 1840 1841 1842 1843 1844 1845
            }
        } else {
            /* load the palette from the file */
            color_start = avio_rb32(pb);
            color_count = avio_rb16(pb);
            color_end   = avio_rb16(pb);
            if ((color_start <= 255) && (color_end <= 255)) {
                for (j = color_start; j <= color_end; j++) {
1846 1847 1848
                    /* each A, R, G, or B component is 16 bits;
                        * only use the top 8 bits */
                    a = avio_r8(pb);
1849 1850 1851 1852 1853 1854 1855
                    avio_r8(pb);
                    r = avio_r8(pb);
                    avio_r8(pb);
                    g = avio_r8(pb);
                    avio_r8(pb);
                    b = avio_r8(pb);
                    avio_r8(pb);
1856
                    sc->palette[j] = (a << 24 ) | (r << 16) | (g << 8) | (b);
1857 1858 1859 1860 1861 1862 1863
                }
            }
        }
        sc->has_palette = 1;
    }
}

1864 1865 1866 1867 1868
static void mov_parse_stsd_audio(MOVContext *c, AVIOContext *pb,
                                 AVStream *st, MOVStreamContext *sc)
{
    int bits_per_sample, flags;
    uint16_t version = avio_rb16(pb);
1869
    AVDictionaryEntry *compatible_brands = av_dict_get(c->fc->metadata, "compatible_brands", NULL, AV_DICT_MATCH_CASE);
1870 1871 1872 1873 1874 1875

    avio_rb16(pb); /* revision level */
    avio_rb32(pb); /* vendor */

    st->codec->channels              = avio_rb16(pb); /* channel count */
    st->codec->bits_per_coded_sample = avio_rb16(pb); /* sample size */
1876
    av_log(c->fc, AV_LOG_TRACE, "audio channels %d\n", st->codec->channels);
1877 1878 1879 1880 1881 1882 1883

    sc->audio_cid = avio_rb16(pb);
    avio_rb16(pb); /* packet size = 0 */

    st->codec->sample_rate = ((avio_rb32(pb) >> 16));

    // Read QT version 1 fields. In version 0 these do not exist.
1884
    av_log(c->fc, AV_LOG_TRACE, "version =%d, isom =%d\n", version, c->isom);
1885 1886 1887
    if (!c->isom ||
        (compatible_brands && strstr(compatible_brands->value, "qt  "))) {

1888 1889 1890 1891 1892 1893 1894 1895 1896 1897 1898 1899 1900 1901 1902 1903 1904 1905 1906 1907
        if (version == 1) {
            sc->samples_per_frame = avio_rb32(pb);
            avio_rb32(pb); /* bytes per packet */
            sc->bytes_per_frame = avio_rb32(pb);
            avio_rb32(pb); /* bytes per sample */
        } else if (version == 2) {
            avio_rb32(pb); /* sizeof struct only */
            st->codec->sample_rate = av_int2double(avio_rb64(pb));
            st->codec->channels    = avio_rb32(pb);
            avio_rb32(pb); /* always 0x7F000000 */
            st->codec->bits_per_coded_sample = avio_rb32(pb);

            flags = avio_rb32(pb); /* lpcm format specific flag */
            sc->bytes_per_frame   = avio_rb32(pb);
            sc->samples_per_frame = avio_rb32(pb);
            if (st->codec->codec_tag == MKTAG('l','p','c','m'))
                st->codec->codec_id =
                    ff_mov_get_lpcm_codec_id(st->codec->bits_per_coded_sample,
                                             flags);
        }
1908 1909 1910 1911 1912 1913 1914 1915 1916
        if (version == 0 || (version == 1 && sc->audio_cid != -2)) {
            /* can't correctly handle variable sized packet as audio unit */
            switch (st->codec->codec_id) {
            case AV_CODEC_ID_MP2:
            case AV_CODEC_ID_MP3:
                st->need_parsing = AVSTREAM_PARSE_FULL;
                break;
            }
        }
1917 1918 1919 1920 1921 1922 1923 1924 1925 1926 1927 1928 1929 1930 1931 1932
    }

    switch (st->codec->codec_id) {
    case AV_CODEC_ID_PCM_S8:
    case AV_CODEC_ID_PCM_U8:
        if (st->codec->bits_per_coded_sample == 16)
            st->codec->codec_id = AV_CODEC_ID_PCM_S16BE;
        break;
    case AV_CODEC_ID_PCM_S16LE:
    case AV_CODEC_ID_PCM_S16BE:
        if (st->codec->bits_per_coded_sample == 8)
            st->codec->codec_id = AV_CODEC_ID_PCM_S8;
        else if (st->codec->bits_per_coded_sample == 24)
            st->codec->codec_id =
                st->codec->codec_id == AV_CODEC_ID_PCM_S16BE ?
                AV_CODEC_ID_PCM_S24BE : AV_CODEC_ID_PCM_S24LE;
1933 1934 1935 1936
        else if (st->codec->bits_per_coded_sample == 32)
             st->codec->codec_id =
                st->codec->codec_id == AV_CODEC_ID_PCM_S16BE ?
                AV_CODEC_ID_PCM_S32BE : AV_CODEC_ID_PCM_S32LE;
1937 1938 1939 1940 1941 1942 1943 1944 1945 1946 1947 1948 1949 1950 1951 1952 1953 1954 1955 1956 1957 1958 1959 1960 1961 1962 1963 1964 1965
        break;
    /* set values for old format before stsd version 1 appeared */
    case AV_CODEC_ID_MACE3:
        sc->samples_per_frame = 6;
        sc->bytes_per_frame   = 2 * st->codec->channels;
        break;
    case AV_CODEC_ID_MACE6:
        sc->samples_per_frame = 6;
        sc->bytes_per_frame   = 1 * st->codec->channels;
        break;
    case AV_CODEC_ID_ADPCM_IMA_QT:
        sc->samples_per_frame = 64;
        sc->bytes_per_frame   = 34 * st->codec->channels;
        break;
    case AV_CODEC_ID_GSM:
        sc->samples_per_frame = 160;
        sc->bytes_per_frame   = 33;
        break;
    default:
        break;
    }

    bits_per_sample = av_get_bits_per_sample(st->codec->codec_id);
    if (bits_per_sample) {
        st->codec->bits_per_coded_sample = bits_per_sample;
        sc->sample_size = (bits_per_sample >> 3) * st->codec->channels;
    }
}

1966 1967
static void mov_parse_stsd_subtitle(MOVContext *c, AVIOContext *pb,
                                    AVStream *st, MOVStreamContext *sc,
1968
                                    int64_t size)
1969 1970 1971 1972 1973 1974 1975 1976 1977 1978 1979
{
    // ttxt stsd contains display flags, justification, background
    // color, fonts, and default styles, so fake an atom to read it
    MOVAtom fake_atom = { .size = size };
    // mp4s contains a regular esds atom
    if (st->codec->codec_tag != AV_RL32("mp4s"))
        mov_read_glbl(c, pb, fake_atom);
    st->codec->width  = sc->width;
    st->codec->height = sc->height;
}

1980 1981 1982 1983 1984 1985 1986 1987 1988
static uint32_t yuv_to_rgba(uint32_t ycbcr)
{
    uint8_t r, g, b;
    int y, cb, cr;

    y  = (ycbcr >> 16) & 0xFF;
    cr = (ycbcr >> 8)  & 0xFF;
    cb =  ycbcr        & 0xFF;

1989 1990 1991
    b = av_clip_uint8((1164 * (y - 16)                     + 2018 * (cb - 128)) / 1000);
    g = av_clip_uint8((1164 * (y - 16) -  813 * (cr - 128) -  391 * (cb - 128)) / 1000);
    r = av_clip_uint8((1164 * (y - 16) + 1596 * (cr - 128)                    ) / 1000);
1992 1993 1994 1995 1996 1997 1998 1999 2000 2001 2002 2003 2004 2005 2006 2007 2008 2009 2010 2011 2012 2013

    return (r << 16) | (g << 8) | b;
}

static int mov_rewrite_dvd_sub_extradata(AVStream *st)
{
    char buf[256] = {0};
    uint8_t *src = st->codec->extradata;
    int i;

    if (st->codec->extradata_size != 64)
        return 0;

    if (st->codec->width > 0 &&  st->codec->height > 0)
        snprintf(buf, sizeof(buf), "size: %dx%d\n",
                 st->codec->width, st->codec->height);
    av_strlcat(buf, "palette: ", sizeof(buf));

    for (i = 0; i < 16; i++) {
        uint32_t yuv = AV_RB32(src + i * 4);
        uint32_t rgba = yuv_to_rgba(yuv);

2014
        av_strlcatf(buf, sizeof(buf), "%06"PRIx32"%s", rgba, i != 15 ? ", " : "");
2015 2016 2017 2018 2019 2020 2021
    }

    if (av_strlcat(buf, "\n", sizeof(buf)) >= sizeof(buf))
        return 0;

    av_freep(&st->codec->extradata);
    st->codec->extradata_size = 0;
2022
    st->codec->extradata = av_mallocz(strlen(buf) + AV_INPUT_BUFFER_PADDING_SIZE);
2023 2024 2025 2026 2027 2028 2029 2030
    if (!st->codec->extradata)
        return AVERROR(ENOMEM);
    st->codec->extradata_size = strlen(buf);
    memcpy(st->codec->extradata, buf, st->codec->extradata_size);

    return 0;
}

L
Luca Barbato 已提交
2031 2032
static int mov_parse_stsd_data(MOVContext *c, AVIOContext *pb,
                                AVStream *st, MOVStreamContext *sc,
2033
                                int64_t size)
L
Luca Barbato 已提交
2034
{
2035 2036
    int ret;

L
Luca Barbato 已提交
2037
    if (st->codec->codec_tag == MKTAG('t','m','c','d')) {
2038
        if ((int)size != size)
L
Luca Barbato 已提交
2039
            return AVERROR(ENOMEM);
2040 2041

        ret = ff_get_extradata(st->codec, pb, size);
2042 2043
        if (ret < 0)
            return ret;
2044 2045 2046 2047 2048 2049
        if (size > 16) {
            MOVStreamContext *tmcd_ctx = st->priv_data;
            int val;
            val = AV_RB32(st->codec->extradata + 4);
            tmcd_ctx->tmcd_flags = val;
            if (val & 1)
2050
                st->codec->flags2 |= AV_CODEC_FLAG2_DROP_FRAME_TIMECODE;
2051 2052
            st->codec->time_base.den = st->codec->extradata[16]; /* number of frame */
            st->codec->time_base.num = 1;
2053 2054 2055 2056 2057 2058 2059
            /* adjust for per frame dur in counter mode */
            if (tmcd_ctx->tmcd_flags & 0x0008) {
                int timescale = AV_RB32(st->codec->extradata + 8);
                int framedur = AV_RB32(st->codec->extradata + 12);
                st->codec->time_base.den *= timescale;
                st->codec->time_base.num *= framedur;
            }
2060 2061 2062 2063 2064 2065 2066 2067 2068 2069 2070 2071 2072 2073 2074 2075 2076 2077 2078 2079
            if (size > 30) {
                uint32_t len = AV_RB32(st->codec->extradata + 18); /* name atom length */
                uint32_t format = AV_RB32(st->codec->extradata + 22);
                if (format == AV_RB32("name") && (int64_t)size >= (int64_t)len + 18) {
                    uint16_t str_size = AV_RB16(st->codec->extradata + 26); /* string length */
                    if (str_size > 0 && size >= (int)str_size + 26) {
                        char *reel_name = av_malloc(str_size + 1);
                        if (!reel_name)
                            return AVERROR(ENOMEM);
                        memcpy(reel_name, st->codec->extradata + 30, str_size);
                        reel_name[str_size] = 0; /* Add null terminator */
                        /* don't add reel_name if emtpy string */
                        if (*reel_name == 0) {
                            av_free(reel_name);
                        } else {
                            av_dict_set(&st->metadata, "reel_name", reel_name,  AV_DICT_DONT_STRDUP_VAL);
                        }
                    }
                }
            }
2080
        }
L
Luca Barbato 已提交
2081 2082 2083 2084 2085 2086 2087
    } else {
        /* other codec type, just skip (rtp, mp4s ...) */
        avio_skip(pb, size);
    }
    return 0;
}

2088 2089 2090 2091 2092 2093 2094 2095 2096 2097 2098
static int mov_finalize_stsd_codec(MOVContext *c, AVIOContext *pb,
                                   AVStream *st, MOVStreamContext *sc)
{
    if (st->codec->codec_type == AVMEDIA_TYPE_AUDIO &&
        !st->codec->sample_rate && sc->time_scale > 1)
        st->codec->sample_rate = sc->time_scale;

    /* special codec parameters handling */
    switch (st->codec->codec_id) {
#if CONFIG_DV_DEMUXER
    case AV_CODEC_ID_DVAUDIO:
V
Vittorio Giovara 已提交
2099 2100 2101 2102 2103
        c->dv_fctx = avformat_alloc_context();
        if (!c->dv_fctx) {
            av_log(c->fc, AV_LOG_ERROR, "dv demux context alloc error\n");
            return AVERROR(ENOMEM);
        }
2104 2105 2106 2107 2108 2109 2110 2111 2112 2113 2114 2115 2116 2117 2118
        c->dv_demux = avpriv_dv_init_demux(c->dv_fctx);
        if (!c->dv_demux) {
            av_log(c->fc, AV_LOG_ERROR, "dv demux context init error\n");
            return AVERROR(ENOMEM);
        }
        sc->dv_audio_container = 1;
        st->codec->codec_id    = AV_CODEC_ID_PCM_S16LE;
        break;
#endif
    /* no ifdef since parameters are always those */
    case AV_CODEC_ID_QCELP:
        st->codec->channels = 1;
        // force sample rate for qcelp when not stored in mov
        if (st->codec->codec_tag != MKTAG('Q','c','l','p'))
            st->codec->sample_rate = 8000;
2119 2120 2121 2122
        // FIXME: Why is the following needed for some files?
        sc->samples_per_frame = 160;
        if (!sc->bytes_per_frame)
            sc->bytes_per_frame = 35;
2123 2124 2125 2126 2127 2128 2129 2130 2131 2132 2133 2134 2135 2136 2137 2138 2139 2140 2141
        break;
    case AV_CODEC_ID_AMR_NB:
        st->codec->channels    = 1;
        /* force sample rate for amr, stsd in 3gp does not store sample rate */
        st->codec->sample_rate = 8000;
        break;
    case AV_CODEC_ID_AMR_WB:
        st->codec->channels    = 1;
        st->codec->sample_rate = 16000;
        break;
    case AV_CODEC_ID_MP2:
    case AV_CODEC_ID_MP3:
        /* force type after stsd for m1a hdlr */
        st->codec->codec_type = AVMEDIA_TYPE_AUDIO;
        break;
    case AV_CODEC_ID_GSM:
    case AV_CODEC_ID_ADPCM_MS:
    case AV_CODEC_ID_ADPCM_IMA_WAV:
    case AV_CODEC_ID_ILBC:
2142 2143 2144
    case AV_CODEC_ID_MACE3:
    case AV_CODEC_ID_MACE6:
    case AV_CODEC_ID_QDM2:
2145 2146 2147 2148 2149 2150 2151 2152
        st->codec->block_align = sc->bytes_per_frame;
        break;
    case AV_CODEC_ID_ALAC:
        if (st->codec->extradata_size == 36) {
            st->codec->channels    = AV_RB8 (st->codec->extradata + 21);
            st->codec->sample_rate = AV_RB32(st->codec->extradata + 32);
        }
        break;
2153
    case AV_CODEC_ID_AC3:
2154
    case AV_CODEC_ID_EAC3:
2155
    case AV_CODEC_ID_MPEG1VIDEO:
2156 2157 2158 2159 2160 2161 2162 2163 2164
    case AV_CODEC_ID_VC1:
        st->need_parsing = AVSTREAM_PARSE_FULL;
        break;
    default:
        break;
    }
    return 0;
}

2165 2166
static int mov_skip_multiple_stsd(MOVContext *c, AVIOContext *pb,
                                  int codec_tag, int format,
2167
                                  int64_t size)
2168 2169 2170 2171 2172 2173
{
    int video_codec_id = ff_codec_get_id(ff_codec_movvideo_tags, format);

    if (codec_tag &&
         (codec_tag != format &&
          (c->fc->video_codec_id ? video_codec_id != c->fc->video_codec_id
2174
                                 : codec_tag != MKTAG('j','p','e','g')))) {
2175 2176 2177 2178 2179 2180 2181 2182
        /* Multiple fourcc, we skip JPEG. This is not correct, we should
         * export it as a separate AVStream but this needs a few changes
         * in the MOV demuxer, patch welcome. */

        av_log(c->fc, AV_LOG_WARNING, "multiple fourcc not supported\n");
        avio_skip(pb, size);
        return 1;
    }
Y
Yusuke Nakamura 已提交
2183 2184 2185 2186
    if ( codec_tag == AV_RL32("avc1") ||
         codec_tag == AV_RL32("hvc1") ||
         codec_tag == AV_RL32("hev1")
    )
2187
        av_log(c->fc, AV_LOG_WARNING, "Concatenated H.264 or H.265 might not play correctly.\n");
2188 2189 2190 2191

    return 0;
}

2192
int ff_mov_read_stsd_entries(MOVContext *c, AVIOContext *pb, int entries)
2193
{
2194 2195
    AVStream *st;
    MOVStreamContext *sc;
2196
    int pseudo_stream_id;
2197

2198 2199 2200 2201 2202
    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;

2203 2204 2205
    for (pseudo_stream_id = 0;
         pseudo_stream_id < entries && !pb->eof_reached;
         pseudo_stream_id++) {
2206
        //Parsing Sample description table
2207
        enum AVCodecID id;
L
Luca Barbato 已提交
2208
        int ret, dref_id = 1;
2209
        MOVAtom a = { AV_RL32("stsd") };
2210
        int64_t start_pos = avio_tell(pb);
2211
        int64_t size = avio_rb32(pb); /* size */
2212
        uint32_t format = avio_rl32(pb); /* data format */
2213

2214
        if (size >= 16) {
2215 2216 2217
            avio_rb32(pb); /* reserved */
            avio_rb16(pb); /* reserved */
            dref_id = avio_rb16(pb);
2218
        }else if (size <= 7){
M
Michael Niedermayer 已提交
2219
            av_log(c->fc, AV_LOG_ERROR, "invalid size %"PRId64" in stsd\n", size);
2220
            return AVERROR_INVALIDDATA;
2221
        }
2222

2223 2224
        if (mov_skip_multiple_stsd(c, pb, st->codec->codec_tag, format,
                                   size - (avio_tell(pb) - start_pos)))
2225
            continue;
2226

2227
        sc->pseudo_stream_id = st->codec->codec_tag ? -1 : pseudo_stream_id;
2228
        sc->dref_id= dref_id;
2229

2230
        id = mov_codec_id(st, format);
2231

2232
        av_log(c->fc, AV_LOG_TRACE,
2233
               "size=%"PRId64" 4CC= %c%c%c%c/0x%08x codec_type=%d\n", size,
2234
                (format >> 0) & 0xff, (format >> 8) & 0xff, (format >> 16) & 0xff,
2235
                (format >> 24) & 0xff, format, st->codec->codec_type);
2236

2237
        if (st->codec->codec_type==AVMEDIA_TYPE_VIDEO) {
2238
            st->codec->codec_id = id;
2239
            mov_parse_stsd_video(c, pb, st, sc);
2240
        } else if (st->codec->codec_type==AVMEDIA_TYPE_AUDIO) {
2241
            st->codec->codec_id = id;
2242
            mov_parse_stsd_audio(c, pb, st, sc);
2243
        } else if (st->codec->codec_type==AVMEDIA_TYPE_SUBTITLE){
2244 2245 2246
            st->codec->codec_id = id;
            mov_parse_stsd_subtitle(c, pb, st, sc,
                                    size - (avio_tell(pb) - start_pos));
2247
        } else {
L
Luca Barbato 已提交
2248 2249 2250 2251
            ret = mov_parse_stsd_data(c, pb, st, sc,
                                      size - (avio_tell(pb) - start_pos));
            if (ret < 0)
                return ret;
2252
        }
Y
Yusuke Nakamura 已提交
2253
        /* this will read extra atoms at the end (wave, alac, damr, avcC, hvcC, SMI ...) */
2254
        a.size = size - (avio_tell(pb) - start_pos);
2255
        if (a.size > 8) {
2256 2257
            if ((ret = mov_read_default(c, pb, a)) < 0)
                return ret;
2258
        } else if (a.size > 0)
2259
            avio_skip(pb, a.size);
2260
    }
2261

2262 2263 2264
    if (pb->eof_reached)
        return AVERROR_EOF;

2265
    return mov_finalize_stsd_codec(c, pb, st, sc);
2266 2267
}

2268
static int mov_read_stsd(MOVContext *c, AVIOContext *pb, MOVAtom atom)
2269 2270 2271
{
    int entries;

2272 2273 2274
    avio_r8(pb); /* version */
    avio_rb24(pb); /* flags */
    entries = avio_rb32(pb);
2275 2276 2277 2278

    return ff_mov_read_stsd_entries(c, pb, entries);
}

2279
static int mov_read_stsc(MOVContext *c, AVIOContext *pb, MOVAtom atom)
2280
{
2281 2282
    AVStream *st;
    MOVStreamContext *sc;
2283
    unsigned int i, entries;
2284

2285 2286 2287 2288 2289
    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;

2290 2291
    avio_r8(pb); /* version */
    avio_rb24(pb); /* flags */
2292

2293
    entries = avio_rb32(pb);
2294

2295
    av_log(c->fc, AV_LOG_TRACE, "track[%i].stsc.entries = %i\n", c->fc->nb_streams-1, entries);
2296

A
Alex Converse 已提交
2297 2298
    if (!entries)
        return 0;
2299
    if (sc->stsc_data)
2300
        av_log(c->fc, AV_LOG_WARNING, "Duplicated STSC atom\n");
2301 2302
    av_free(sc->stsc_data);
    sc->stsc_count = 0;
2303
    sc->stsc_data = av_malloc_array(entries, sizeof(*sc->stsc_data));
2304
    if (!sc->stsc_data)
2305 2306
        return AVERROR(ENOMEM);

2307
    for (i = 0; i < entries && !pb->eof_reached; i++) {
2308 2309 2310
        sc->stsc_data[i].first = avio_rb32(pb);
        sc->stsc_data[i].count = avio_rb32(pb);
        sc->stsc_data[i].id = avio_rb32(pb);
2311
    }
2312 2313 2314 2315 2316 2317

    sc->stsc_count = i;

    if (pb->eof_reached)
        return AVERROR_EOF;

2318 2319 2320
    return 0;
}

2321
static int mov_read_stps(MOVContext *c, AVIOContext *pb, MOVAtom atom)
2322 2323 2324 2325 2326 2327 2328 2329 2330 2331
{
    AVStream *st;
    MOVStreamContext *sc;
    unsigned i, entries;

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;

2332
    avio_rb32(pb); // version + flags
2333

2334
    entries = avio_rb32(pb);
2335
    if (sc->stps_data)
2336
        av_log(c->fc, AV_LOG_WARNING, "Duplicated STPS atom\n");
2337 2338 2339
    av_free(sc->stps_data);
    sc->stps_count = 0;
    sc->stps_data = av_malloc_array(entries, sizeof(*sc->stps_data));
2340 2341 2342
    if (!sc->stps_data)
        return AVERROR(ENOMEM);

2343
    for (i = 0; i < entries && !pb->eof_reached; i++) {
2344
        sc->stps_data[i] = avio_rb32(pb);
2345
        //av_log(c->fc, AV_LOG_TRACE, "stps %d\n", sc->stps_data[i]);
2346 2347
    }

2348 2349 2350 2351 2352
    sc->stps_count = i;

    if (pb->eof_reached)
        return AVERROR_EOF;

2353 2354 2355
    return 0;
}

2356
static int mov_read_stss(MOVContext *c, AVIOContext *pb, MOVAtom atom)
2357
{
2358 2359
    AVStream *st;
    MOVStreamContext *sc;
2360
    unsigned int i, entries;
2361

2362 2363 2364 2365 2366
    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;

2367 2368
    avio_r8(pb); /* version */
    avio_rb24(pb); /* flags */
2369

2370
    entries = avio_rb32(pb);
2371

2372
    av_log(c->fc, AV_LOG_TRACE, "keyframe_count = %d\n", entries);
2373

2374
    if (!entries)
2375 2376
    {
        sc->keyframe_absent = 1;
2377
        if (!st->need_parsing && st->codec->codec_type == AVMEDIA_TYPE_VIDEO)
2378
            st->need_parsing = AVSTREAM_PARSE_HEADERS;
2379
        return 0;
2380
    }
2381
    if (sc->keyframes)
2382
        av_log(c->fc, AV_LOG_WARNING, "Duplicated STSS atom\n");
2383
    if (entries >= UINT_MAX / sizeof(int))
2384
        return AVERROR_INVALIDDATA;
2385
    av_freep(&sc->keyframes);
2386 2387
    sc->keyframe_count = 0;
    sc->keyframes = av_malloc_array(entries, sizeof(*sc->keyframes));
2388
    if (!sc->keyframes)
2389 2390
        return AVERROR(ENOMEM);

2391
    for (i = 0; i < entries && !pb->eof_reached; i++) {
2392
        sc->keyframes[i] = avio_rb32(pb);
2393
        //av_log(c->fc, AV_LOG_TRACE, "keyframes[]=%d\n", sc->keyframes[i]);
2394
    }
2395 2396 2397 2398 2399 2400

    sc->keyframe_count = i;

    if (pb->eof_reached)
        return AVERROR_EOF;

2401 2402 2403
    return 0;
}

2404
static int mov_read_stsz(MOVContext *c, AVIOContext *pb, MOVAtom atom)
2405
{
2406 2407
    AVStream *st;
    MOVStreamContext *sc;
2408 2409 2410
    unsigned int i, entries, sample_size, field_size, num_bytes;
    GetBitContext gb;
    unsigned char* buf;
2411
    int ret;
2412

2413 2414 2415 2416 2417
    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;

2418 2419
    avio_r8(pb); /* version */
    avio_rb24(pb); /* flags */
2420

2421
    if (atom.type == MKTAG('s','t','s','z')) {
2422
        sample_size = avio_rb32(pb);
2423 2424
        if (!sc->sample_size) /* do not overwrite value computed in stsd */
            sc->sample_size = sample_size;
2425
        sc->stsz_sample_size = sample_size;
2426
        field_size = 32;
2427 2428
    } else {
        sample_size = 0;
2429 2430
        avio_rb24(pb); /* reserved */
        field_size = avio_r8(pb);
2431
    }
2432
    entries = avio_rb32(pb);
2433

2434
    av_log(c->fc, AV_LOG_TRACE, "sample_size = %d sample_count = %d\n", sc->sample_size, entries);
2435

2436
    sc->sample_count = entries;
2437 2438 2439
    if (sample_size)
        return 0;

2440 2441
    if (field_size != 4 && field_size != 8 && field_size != 16 && field_size != 32) {
        av_log(c->fc, AV_LOG_ERROR, "Invalid sample field size %d\n", field_size);
2442
        return AVERROR_INVALIDDATA;
2443 2444
    }

A
Alex Converse 已提交
2445 2446
    if (!entries)
        return 0;
2447
    if (entries >= (UINT_MAX - 4) / field_size)
2448
        return AVERROR_INVALIDDATA;
2449
    if (sc->sample_sizes)
2450
        av_log(c->fc, AV_LOG_WARNING, "Duplicated STSZ atom\n");
2451 2452 2453
    av_free(sc->sample_sizes);
    sc->sample_count = 0;
    sc->sample_sizes = av_malloc_array(entries, sizeof(*sc->sample_sizes));
2454
    if (!sc->sample_sizes)
2455 2456
        return AVERROR(ENOMEM);

2457 2458
    num_bytes = (entries*field_size+4)>>3;

2459
    buf = av_malloc(num_bytes+AV_INPUT_BUFFER_PADDING_SIZE);
2460 2461 2462 2463 2464
    if (!buf) {
        av_freep(&sc->sample_sizes);
        return AVERROR(ENOMEM);
    }

2465 2466
    ret = ffio_read_size(pb, buf, num_bytes);
    if (ret < 0) {
2467 2468
        av_freep(&sc->sample_sizes);
        av_free(buf);
2469
        return ret;
2470 2471 2472 2473
    }

    init_get_bits(&gb, buf, 8*num_bytes);

2474
    for (i = 0; i < entries && !pb->eof_reached; i++) {
2475
        sc->sample_sizes[i] = get_bits_long(&gb, field_size);
2476 2477
        sc->data_size += sc->sample_sizes[i];
    }
2478

2479 2480
    sc->sample_count = i;

A
Andreas Cadhalpun 已提交
2481 2482
    av_free(buf);

2483 2484 2485
    if (pb->eof_reached)
        return AVERROR_EOF;

2486 2487 2488
    return 0;
}

2489
static int mov_read_stts(MOVContext *c, AVIOContext *pb, MOVAtom atom)
2490
{
2491 2492
    AVStream *st;
    MOVStreamContext *sc;
2493
    unsigned int i, entries;
2494 2495
    int64_t duration=0;
    int64_t total_sample_count=0;
2496

2497 2498 2499 2500 2501
    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;

2502 2503 2504
    avio_r8(pb); /* version */
    avio_rb24(pb); /* flags */
    entries = avio_rb32(pb);
2505

2506
    av_log(c->fc, AV_LOG_TRACE, "track[%i].stts.entries = %i\n",
2507
            c->fc->nb_streams-1, entries);
2508

2509
    if (sc->stts_data)
2510
        av_log(c->fc, AV_LOG_WARNING, "Duplicated STTS atom\n");
2511
    av_free(sc->stts_data);
2512 2513
    sc->stts_count = 0;
    sc->stts_data = av_malloc_array(entries, sizeof(*sc->stts_data));
2514
    if (!sc->stts_data)
2515
        return AVERROR(ENOMEM);
2516

2517
    for (i = 0; i < entries && !pb->eof_reached; i++) {
M
cleanup  
Michael Niedermayer 已提交
2518 2519
        int sample_duration;
        int sample_count;
2520

2521 2522
        sample_count=avio_rb32(pb);
        sample_duration = avio_rb32(pb);
2523

2524 2525 2526 2527
        if (sample_count < 0) {
            av_log(c->fc, AV_LOG_ERROR, "Invalid sample_count=%d\n", sample_count);
            return AVERROR_INVALIDDATA;
        }
2528 2529 2530
        sc->stts_data[i].count= sample_count;
        sc->stts_data[i].duration= sample_duration;

2531
        av_log(c->fc, AV_LOG_TRACE, "sample_count=%d, sample_duration=%d\n",
2532
                sample_count, sample_duration);
2533

2534 2535 2536 2537 2538 2539
        if (   i+1 == entries
            && i
            && sample_count == 1
            && total_sample_count > 100
            && sample_duration/10 > duration / total_sample_count)
            sample_duration = duration / total_sample_count;
B
Baptiste Coudurier 已提交
2540
        duration+=(int64_t)sample_duration*sample_count;
2541 2542 2543
        total_sample_count+=sample_count;
    }

2544 2545
    sc->stts_count = i;

2546 2547 2548
    sc->duration_for_fps  += duration;
    sc->nb_frames_for_fps += total_sample_count;

2549 2550 2551
    if (pb->eof_reached)
        return AVERROR_EOF;

2552
    st->nb_frames= total_sample_count;
2553
    if (duration)
2554
        st->duration= duration;
2555
    sc->track_end = duration;
2556 2557 2558
    return 0;
}

2559 2560 2561
static void mov_update_dts_shift(MOVStreamContext *sc, int duration)
{
    if (duration < 0) {
2562 2563 2564 2565
        if (duration == INT_MIN) {
            av_log(NULL, AV_LOG_WARNING, "mov_update_dts_shift(): dts_shift set to %d\n", INT_MAX);
            duration++;
        }
2566 2567 2568 2569
        sc->dts_shift = FFMAX(sc->dts_shift, -duration);
    }
}

2570
static int mov_read_ctts(MOVContext *c, AVIOContext *pb, MOVAtom atom)
M
Michael Niedermayer 已提交
2571
{
2572 2573
    AVStream *st;
    MOVStreamContext *sc;
M
Michael Niedermayer 已提交
2574 2575
    unsigned int i, entries;

2576 2577 2578 2579 2580
    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;

2581 2582 2583
    avio_r8(pb); /* version */
    avio_rb24(pb); /* flags */
    entries = avio_rb32(pb);
2584

2585
    av_log(c->fc, AV_LOG_TRACE, "track[%i].ctts.entries = %i\n", c->fc->nb_streams-1, entries);
2586

A
Alex Converse 已提交
2587 2588
    if (!entries)
        return 0;
2589
    if (entries >= UINT_MAX / sizeof(*sc->ctts_data))
2590
        return AVERROR_INVALIDDATA;
A
Andreas Cadhalpun 已提交
2591
    av_freep(&sc->ctts_data);
L
Luca Barbato 已提交
2592
    sc->ctts_data = av_realloc(NULL, entries * sizeof(*sc->ctts_data));
2593
    if (!sc->ctts_data)
2594
        return AVERROR(ENOMEM);
2595

2596
    for (i = 0; i < entries && !pb->eof_reached; i++) {
2597 2598
        int count    =avio_rb32(pb);
        int duration =avio_rb32(pb);
2599 2600 2601

        sc->ctts_data[i].count   = count;
        sc->ctts_data[i].duration= duration;
M
Michael Niedermayer 已提交
2602

2603
        av_log(c->fc, AV_LOG_TRACE, "count=%d, duration=%d\n",
2604 2605
                count, duration);

2606
        if (FFNABS(duration) < -(1<<28) && i+2<entries) {
M
Michael Niedermayer 已提交
2607 2608 2609 2610 2611 2612
            av_log(c->fc, AV_LOG_WARNING, "CTTS invalid\n");
            av_freep(&sc->ctts_data);
            sc->ctts_count = 0;
            return 0;
        }

2613 2614
        if (i+2<entries)
            mov_update_dts_shift(sc, duration);
M
Michael Niedermayer 已提交
2615
    }
2616

2617 2618 2619 2620 2621
    sc->ctts_count = i;

    if (pb->eof_reached)
        return AVERROR_EOF;

2622
    av_log(c->fc, AV_LOG_TRACE, "dts shift %d\n", sc->dts_shift);
2623

M
Michael Niedermayer 已提交
2624 2625 2626
    return 0;
}

2627 2628 2629 2630 2631 2632 2633 2634 2635 2636 2637 2638 2639 2640 2641 2642 2643 2644 2645 2646 2647 2648 2649 2650
static int mov_read_sbgp(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    AVStream *st;
    MOVStreamContext *sc;
    unsigned int i, entries;
    uint8_t version;
    uint32_t grouping_type;

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;

    version = avio_r8(pb); /* version */
    avio_rb24(pb); /* flags */
    grouping_type = avio_rl32(pb);
    if (grouping_type != MKTAG( 'r','a','p',' '))
        return 0; /* only support 'rap ' grouping */
    if (version == 1)
        avio_rb32(pb); /* grouping_type_parameter */

    entries = avio_rb32(pb);
    if (!entries)
        return 0;
2651
    if (sc->rap_group)
2652
        av_log(c->fc, AV_LOG_WARNING, "Duplicated SBGP atom\n");
2653 2654 2655
    av_free(sc->rap_group);
    sc->rap_group_count = 0;
    sc->rap_group = av_malloc_array(entries, sizeof(*sc->rap_group));
2656 2657 2658 2659 2660 2661 2662 2663 2664 2665 2666 2667 2668
    if (!sc->rap_group)
        return AVERROR(ENOMEM);

    for (i = 0; i < entries && !pb->eof_reached; i++) {
        sc->rap_group[i].count = avio_rb32(pb); /* sample_count */
        sc->rap_group[i].index = avio_rb32(pb); /* group_description_index */
    }

    sc->rap_group_count = i;

    return pb->eof_reached ? AVERROR_EOF : 0;
}

2669 2670 2671
static void mov_build_index(MOVContext *mov, AVStream *st)
{
    MOVStreamContext *sc = st->priv_data;
2672
    int64_t current_offset;
2673 2674 2675 2676
    int64_t current_dts = 0;
    unsigned int stts_index = 0;
    unsigned int stsc_index = 0;
    unsigned int stss_index = 0;
2677
    unsigned int stps_index = 0;
2678
    unsigned int i, j;
2679
    uint64_t stream_size = 0;
2680

2681 2682 2683 2684 2685 2686 2687 2688 2689 2690 2691 2692 2693 2694 2695 2696 2697 2698 2699 2700 2701
    if (sc->elst_count) {
        int i, edit_start_index = 0, unsupported = 0;
        int64_t empty_duration = 0; // empty duration of the first edit list entry
        int64_t start_time = 0; // start time of the media

        for (i = 0; i < sc->elst_count; i++) {
            const MOVElst *e = &sc->elst_data[i];
            if (i == 0 && e->time == -1) {
                /* if empty, the first entry is the start time of the stream
                 * relative to the presentation itself */
                empty_duration = e->duration;
                edit_start_index = 1;
            } else if (i == edit_start_index && e->time >= 0) {
                start_time = e->time;
            } else
                unsupported = 1;
        }
        if (unsupported)
            av_log(mov->fc, AV_LOG_WARNING, "multiple edit list entries, "
                   "a/v desync might occur, patch welcome\n");

2702 2703 2704 2705 2706 2707 2708 2709 2710 2711 2712 2713 2714
        /* adjust first dts according to edit list */
        if ((empty_duration || start_time) && mov->time_scale > 0) {
            if (empty_duration)
                empty_duration = av_rescale(empty_duration, sc->time_scale, mov->time_scale);
            sc->time_offset = start_time - empty_duration;
            current_dts = -sc->time_offset;
            if (sc->ctts_count>0 && sc->stts_count>0 &&
                sc->ctts_data[0].duration / FFMAX(sc->stts_data[0].duration, 1) > 16) {
                /* more than 16 frames delay, dts are likely wrong
                   this happens with files created by iMovie */
                sc->wrong_dts = 1;
                st->codec->has_b_frames = 1;
            }
2715
        }
2716 2717
    }

2718
    /* only use old uncompressed audio chunk demuxing when stts specifies it */
2719
    if (!(st->codec->codec_type == AVMEDIA_TYPE_AUDIO &&
2720
          sc->stts_count == 1 && sc->stts_data[0].duration == 1)) {
2721 2722
        unsigned int current_sample = 0;
        unsigned int stts_sample = 0;
2723
        unsigned int sample_size;
2724
        unsigned int distance = 0;
2725 2726
        unsigned int rap_group_index = 0;
        unsigned int rap_group_sample = 0;
2727 2728
        int64_t last_dts = 0;
        int64_t dts_correction = 0;
2729
        int rap_group_present = sc->rap_group_count && sc->rap_group;
2730
        int key_off = (sc->keyframe_count && sc->keyframes[0] > 0) || (sc->stps_count && sc->stps_data[0] > 0);
2731

2732
        current_dts -= sc->dts_shift;
2733
        last_dts     = current_dts;
2734

2735
        if (!sc->sample_count || st->nb_index_entries)
A
Alex Converse 已提交
2736
            return;
2737
        if (sc->sample_count >= UINT_MAX / sizeof(*st->index_entries) - st->nb_index_entries)
2738
            return;
2739 2740 2741 2742
        if (av_reallocp_array(&st->index_entries,
                              st->nb_index_entries + sc->sample_count,
                              sizeof(*st->index_entries)) < 0) {
            st->nb_index_entries = 0;
2743
            return;
2744
        }
2745
        st->index_entries_allocated_size = (st->nb_index_entries + sc->sample_count) * sizeof(*st->index_entries);
2746

2747
        for (i = 0; i < sc->chunk_count; i++) {
2748
            int64_t next_offset = i+1 < sc->chunk_count ? sc->chunk_offsets[i+1] : INT64_MAX;
2749
            current_offset = sc->chunk_offsets[i];
2750
            while (stsc_index + 1 < sc->stsc_count &&
2751
                i + 1 == sc->stsc_data[stsc_index + 1].first)
2752
                stsc_index++;
2753 2754 2755 2756 2757 2758 2759 2760 2761 2762 2763

            if (next_offset > current_offset && sc->sample_size>0 && sc->sample_size < sc->stsz_sample_size &&
                sc->stsc_data[stsc_index].count * (int64_t)sc->stsz_sample_size > next_offset - current_offset) {
                av_log(mov->fc, AV_LOG_WARNING, "STSZ sample size %d invalid (too large), ignoring\n", sc->stsz_sample_size);
                sc->stsz_sample_size = sc->sample_size;
            }
            if (sc->stsz_sample_size>0 && sc->stsz_sample_size < sc->sample_size) {
                av_log(mov->fc, AV_LOG_WARNING, "STSZ sample size %d invalid (too small), ignoring\n", sc->stsz_sample_size);
                sc->stsz_sample_size = sc->sample_size;
            }

2764
            for (j = 0; j < sc->stsc_data[stsc_index].count; j++) {
2765
                int keyframe = 0;
2766 2767
                if (current_sample >= sc->sample_count) {
                    av_log(mov->fc, AV_LOG_ERROR, "wrong sample count\n");
2768
                    return;
2769
                }
2770

2771
                if (!sc->keyframe_absent && (!sc->keyframe_count || current_sample+key_off == sc->keyframes[stss_index])) {
2772
                    keyframe = 1;
2773 2774
                    if (stss_index + 1 < sc->keyframe_count)
                        stss_index++;
2775 2776 2777 2778
                } else if (sc->stps_count && current_sample+key_off == sc->stps_data[stps_index]) {
                    keyframe = 1;
                    if (stps_index + 1 < sc->stps_count)
                        stps_index++;
2779
                }
2780 2781 2782 2783 2784 2785 2786 2787
                if (rap_group_present && rap_group_index < sc->rap_group_count) {
                    if (sc->rap_group[rap_group_index].index > 0)
                        keyframe = 1;
                    if (++rap_group_sample == sc->rap_group[rap_group_index].count) {
                        rap_group_sample = 0;
                        rap_group_index++;
                    }
                }
2788 2789 2790
                if (sc->keyframe_absent
                    && !sc->stps_count
                    && !rap_group_present
2791
                    && (st->codec->codec_type == AVMEDIA_TYPE_AUDIO || (i==0 && j==0)))
2792
                     keyframe = 1;
2793 2794
                if (keyframe)
                    distance = 0;
2795
                sample_size = sc->stsz_sample_size > 0 ? sc->stsz_sample_size : sc->sample_sizes[current_sample];
2796
                if (sc->pseudo_stream_id == -1 ||
2797
                   sc->stsc_data[stsc_index].id - 1 == sc->pseudo_stream_id) {
2798 2799
                    AVIndexEntry *e = &st->index_entries[st->nb_index_entries++];
                    e->pos = current_offset;
2800
                    e->timestamp = current_dts;
2801 2802 2803
                    e->size = sample_size;
                    e->min_distance = distance;
                    e->flags = keyframe ? AVINDEX_KEYFRAME : 0;
2804
                    av_log(mov->fc, AV_LOG_TRACE, "AVIndex stream %d, sample %d, offset %"PRIx64", dts %"PRId64", "
2805
                            "size %d, distance %d, keyframe %d\n", st->index, current_sample,
2806
                            current_offset, current_dts, sample_size, distance, keyframe);
2807
                    if (st->codec->codec_type == AVMEDIA_TYPE_VIDEO && st->nb_index_entries < 100)
2808
                        ff_rfps_add_frame(mov->fc, st, current_dts);
2809
                }
2810

2811
                current_offset += sample_size;
2812
                stream_size += sample_size;
2813 2814 2815 2816 2817 2818 2819 2820 2821 2822 2823

                /* A negative sample duration is invalid based on the spec,
                 * but some samples need it to correct the DTS. */
                if (sc->stts_data[stts_index].duration < 0) {
                    av_log(mov->fc, AV_LOG_WARNING,
                           "Invalid SampleDelta %d in STTS, at %d st:%d\n",
                           sc->stts_data[stts_index].duration, stts_index,
                           st->index);
                    dts_correction += sc->stts_data[stts_index].duration - 1;
                    sc->stts_data[stts_index].duration = 1;
                }
2824
                current_dts += sc->stts_data[stts_index].duration;
2825 2826 2827 2828 2829 2830 2831 2832 2833
                if (!dts_correction || current_dts + dts_correction > last_dts) {
                    current_dts += dts_correction;
                    dts_correction = 0;
                } else {
                    /* Avoid creating non-monotonous DTS */
                    dts_correction += current_dts - last_dts - 1;
                    current_dts = last_dts + 1;
                }
                last_dts = current_dts;
2834 2835 2836 2837 2838 2839 2840 2841 2842
                distance++;
                stts_sample++;
                current_sample++;
                if (stts_index + 1 < sc->stts_count && stts_sample == sc->stts_data[stts_index].count) {
                    stts_sample = 0;
                    stts_index++;
                }
            }
        }
2843 2844
        if (st->duration > 0)
            st->codec->bit_rate = stream_size*8*sc->time_scale/st->duration;
2845
    } else {
2846
        unsigned chunk_samples, total = 0;
2847

2848 2849 2850
        // compute total chunk count
        for (i = 0; i < sc->stsc_count; i++) {
            unsigned count, chunk_count;
2851

2852
            chunk_samples = sc->stsc_data[i].count;
2853 2854
            if (i != sc->stsc_count - 1 &&
                sc->samples_per_frame && chunk_samples % sc->samples_per_frame) {
2855 2856 2857 2858
                av_log(mov->fc, AV_LOG_ERROR, "error unaligned chunk\n");
                return;
            }

2859 2860 2861 2862 2863 2864 2865 2866 2867 2868 2869 2870 2871 2872 2873 2874
            if (sc->samples_per_frame >= 160) { // gsm
                count = chunk_samples / sc->samples_per_frame;
            } else if (sc->samples_per_frame > 1) {
                unsigned samples = (1024/sc->samples_per_frame)*sc->samples_per_frame;
                count = (chunk_samples+samples-1) / samples;
            } else {
                count = (chunk_samples+1023) / 1024;
            }

            if (i < sc->stsc_count - 1)
                chunk_count = sc->stsc_data[i+1].first - sc->stsc_data[i].first;
            else
                chunk_count = sc->chunk_count - (sc->stsc_data[i].first - 1);
            total += chunk_count * count;
        }

2875
        av_log(mov->fc, AV_LOG_TRACE, "chunk count %d\n", total);
2876
        if (total >= UINT_MAX / sizeof(*st->index_entries) - st->nb_index_entries)
2877
            return;
2878 2879 2880 2881
        if (av_reallocp_array(&st->index_entries,
                              st->nb_index_entries + total,
                              sizeof(*st->index_entries)) < 0) {
            st->nb_index_entries = 0;
2882
            return;
2883
        }
2884
        st->index_entries_allocated_size = (st->nb_index_entries + total) * sizeof(*st->index_entries);
2885 2886 2887 2888 2889 2890 2891 2892 2893

        // populate index
        for (i = 0; i < sc->chunk_count; i++) {
            current_offset = sc->chunk_offsets[i];
            if (stsc_index + 1 < sc->stsc_count &&
                i + 1 == sc->stsc_data[stsc_index + 1].first)
                stsc_index++;
            chunk_samples = sc->stsc_data[stsc_index].count;

2894
            while (chunk_samples > 0) {
2895
                AVIndexEntry *e;
2896 2897
                unsigned size, samples;

2898 2899 2900 2901 2902 2903 2904
                if (sc->samples_per_frame > 1 && !sc->bytes_per_frame) {
                    avpriv_request_sample(mov->fc,
                           "Zero bytes per frame, but %d samples per frame",
                           sc->samples_per_frame);
                    return;
                }

2905 2906 2907 2908 2909 2910 2911 2912
                if (sc->samples_per_frame >= 160) { // gsm
                    samples = sc->samples_per_frame;
                    size = sc->bytes_per_frame;
                } else {
                    if (sc->samples_per_frame > 1) {
                        samples = FFMIN((1024 / sc->samples_per_frame)*
                                        sc->samples_per_frame, chunk_samples);
                        size = (samples / sc->samples_per_frame) * sc->bytes_per_frame;
2913
                    } else {
2914 2915
                        samples = FFMIN(1024, chunk_samples);
                        size = samples * sc->sample_size;
2916 2917
                    }
                }
2918

2919 2920 2921 2922 2923 2924 2925 2926 2927 2928
                if (st->nb_index_entries >= total) {
                    av_log(mov->fc, AV_LOG_ERROR, "wrong chunk count %d\n", total);
                    return;
                }
                e = &st->index_entries[st->nb_index_entries++];
                e->pos = current_offset;
                e->timestamp = current_dts;
                e->size = size;
                e->min_distance = 0;
                e->flags = AVINDEX_KEYFRAME;
2929
                av_log(mov->fc, AV_LOG_TRACE, "AVIndex stream %d, chunk %d, offset %"PRIx64", dts %"PRId64", "
2930
                        "size %d, duration %d\n", st->index, i, current_offset, current_dts,
2931 2932 2933
                        size, samples);

                current_offset += size;
2934
                current_dts += samples;
2935
                chunk_samples -= samples;
2936 2937 2938 2939
            }
        }
    }
}
2940

2941 2942 2943 2944 2945 2946 2947 2948 2949 2950 2951 2952 2953 2954 2955 2956 2957 2958 2959 2960 2961 2962 2963 2964 2965 2966 2967 2968 2969
static int test_same_origin(const char *src, const char *ref) {
    char src_proto[64];
    char ref_proto[64];
    char src_auth[256];
    char ref_auth[256];
    char src_host[256];
    char ref_host[256];
    int src_port=-1;
    int ref_port=-1;

    av_url_split(src_proto, sizeof(src_proto), src_auth, sizeof(src_auth), src_host, sizeof(src_host), &src_port, NULL, 0, src);
    av_url_split(ref_proto, sizeof(ref_proto), ref_auth, sizeof(ref_auth), ref_host, sizeof(ref_host), &ref_port, NULL, 0, ref);

    if (strlen(src) == 0) {
        return -1;
    } else if (strlen(src_auth) + 1 >= sizeof(src_auth) ||
        strlen(ref_auth) + 1 >= sizeof(ref_auth) ||
        strlen(src_host) + 1 >= sizeof(src_host) ||
        strlen(ref_host) + 1 >= sizeof(ref_host)) {
        return 0;
    } else if (strcmp(src_proto, ref_proto) ||
               strcmp(src_auth, ref_auth) ||
               strcmp(src_host, ref_host) ||
               src_port != ref_port) {
        return 0;
    } else
        return 1;
}

2970 2971
static int mov_open_dref(MOVContext *c, AVIOContext **pb, const char *src, MOVDref *ref,
                         AVIOInterruptCB *int_cb)
2972
{
2973 2974 2975 2976 2977
    AVOpenCallback open_func = c->fc->open_cb;

    if (!open_func)
        open_func = ffio_open2_wrapper;

2978 2979
    /* try relative path, we do not try the absolute because it can leak information about our
       system to an attacker */
2980
    if (ref->nlvl_to > 0 && ref->nlvl_from > 0) {
2981
        char filename[1025];
2982
        const char *src_path;
2983 2984 2985 2986 2987 2988 2989 2990 2991 2992 2993 2994 2995 2996 2997 2998 2999 3000 3001
        int i, l;

        /* find a source dir */
        src_path = strrchr(src, '/');
        if (src_path)
            src_path++;
        else
            src_path = src;

        /* find a next level down to target */
        for (i = 0, l = strlen(ref->path) - 1; l >= 0; l--)
            if (ref->path[l] == '/') {
                if (i == ref->nlvl_to - 1)
                    break;
                else
                    i++;
            }

        /* compose filename if next level down to target was found */
3002
        if (i == ref->nlvl_to - 1 && src_path - src  < sizeof(filename)) {
3003 3004 3005 3006
            memcpy(filename, src, src_path - src);
            filename[src_path - src] = 0;

            for (i = 1; i < ref->nlvl_from; i++)
3007
                av_strlcat(filename, "../", sizeof(filename));
3008

3009
            av_strlcat(filename, ref->path + l + 1, sizeof(filename));
3010 3011 3012 3013 3014 3015 3016 3017 3018 3019 3020
            if (!c->use_absolute_path && !c->fc->open_cb) {
                int same_origin = test_same_origin(src, filename);

                if (!same_origin) {
                    av_log(c->fc, AV_LOG_ERROR,
                        "Reference with mismatching origin, %s not tried for security reasons, "
                        "set demuxer option use_absolute_path to allow it anyway\n",
                        ref->path);
                    return AVERROR(ENOENT);
                }

3021 3022
                if(strstr(ref->path + l + 1, "..") ||
                   strstr(ref->path + l + 1, ":") ||
3023
                   (ref->nlvl_from > 1 && same_origin < 0) ||
3024
                   (filename[0] == '/' && src_path == src))
3025
                    return AVERROR(ENOENT);
3026
            }
3027

3028 3029
            if (strlen(filename) + 1 == sizeof(filename))
                return AVERROR(ENOENT);
3030
            if (!open_func(c->fc, pb, filename, AVIO_FLAG_READ, int_cb, NULL))
3031 3032
                return 0;
        }
3033 3034
    } else if (c->use_absolute_path) {
        av_log(c->fc, AV_LOG_WARNING, "Using absolute path on user request, "
3035
               "this is a possible security issue\n");
3036 3037 3038 3039
        if (!open_func(c->fc, pb, ref->path, AVIO_FLAG_READ, int_cb, NULL))
            return 0;
    } else if (c->fc->open_cb) {
        if (!open_func(c->fc, pb, ref->path, AVIO_FLAG_READ, int_cb, NULL))
3040
            return 0;
3041 3042 3043 3044 3045
    } else {
        av_log(c->fc, AV_LOG_ERROR,
               "Absolute path %s not tried for security reasons, "
               "set demuxer option use_absolute_path to allow absolute paths\n",
               ref->path);
3046 3047 3048
    }

    return AVERROR(ENOENT);
M
Mans Rullgard 已提交
3049
}
3050

3051 3052 3053 3054 3055 3056 3057 3058 3059 3060
static void fix_timescale(MOVContext *c, MOVStreamContext *sc)
{
    if (sc->time_scale <= 0) {
        av_log(c->fc, AV_LOG_WARNING, "stream %d, timescale not set\n", sc->ffindex);
        sc->time_scale = c->time_scale;
        if (sc->time_scale <= 0)
            sc->time_scale = 1;
    }
}

3061
static int mov_read_trak(MOVContext *c, AVIOContext *pb, MOVAtom atom)
3062 3063 3064
{
    AVStream *st;
    MOVStreamContext *sc;
3065
    int ret;
3066

3067
    st = avformat_new_stream(c->fc, NULL);
B
Baptiste Coudurier 已提交
3068
    if (!st) return AVERROR(ENOMEM);
3069
    st->id = c->fc->nb_streams;
B
Baptiste Coudurier 已提交
3070
    sc = av_mallocz(sizeof(MOVStreamContext));
3071
    if (!sc) return AVERROR(ENOMEM);
3072 3073

    st->priv_data = sc;
3074
    st->codec->codec_type = AVMEDIA_TYPE_DATA;
3075
    sc->ffindex = st->index;
3076

3077 3078 3079 3080
    if ((ret = mov_read_default(c, pb, atom)) < 0)
        return ret;

    /* sanity checks */
3081 3082
    if (sc->chunk_count && (!sc->stts_count || !sc->stsc_count ||
                            (!sc->sample_size && !sc->sample_count))) {
3083 3084
        av_log(c->fc, AV_LOG_ERROR, "stream %d, missing mandatory atoms, broken header\n",
               st->index);
3085 3086
        return 0;
    }
3087

3088
    fix_timescale(c, sc);
3089

3090
    avpriv_set_pts_info(st, 64, 1, sc->time_scale);
3091 3092 3093 3094

    mov_build_index(c, st);

    if (sc->dref_id-1 < sc->drefs_count && sc->drefs[sc->dref_id-1].path) {
3095
        MOVDref *dref = &sc->drefs[sc->dref_id - 1];
3096 3097
        if (mov_open_dref(c, &sc->pb, c->fc->filename, dref,
                          &c->fc->interrupt_callback) < 0)
3098 3099 3100 3101 3102
            av_log(c->fc, AV_LOG_ERROR,
                   "stream %d, error opening alias: path='%s', dir='%s', "
                   "filename='%s', volume='%s', nlvl_from=%d, nlvl_to=%d\n",
                   st->index, dref->path, dref->dir, dref->filename,
                   dref->volume, dref->nlvl_from, dref->nlvl_to);
3103
    } else {
3104
        sc->pb = c->fc->pb;
3105 3106
        sc->pb_is_copied = 1;
    }
3107

3108
    if (st->codec->codec_type == AVMEDIA_TYPE_VIDEO) {
3109 3110
        if (!st->sample_aspect_ratio.num && st->codec->width && st->codec->height &&
            sc->height && sc->width &&
3111 3112 3113
            (st->codec->width != sc->width || st->codec->height != sc->height)) {
            st->sample_aspect_ratio = av_d2q(((double)st->codec->height * sc->width) /
                                             ((double)st->codec->width * sc->height), INT_MAX);
3114 3115
        }

A
Anton Khirnov 已提交
3116
#if FF_API_R_FRAME_RATE
3117 3118 3119
        if (sc->stts_count == 1 || (sc->stts_count == 2 && sc->stts_data[1].count == 1))
            av_reduce(&st->r_frame_rate.num, &st->r_frame_rate.den,
                      sc->time_scale, sc->stts_data[0].duration, INT_MAX);
A
Anton Khirnov 已提交
3120
#endif
3121 3122
    }

R
Reimar Döffinger 已提交
3123 3124
    // done for ai5q, ai52, ai55, ai1q, ai12 and ai15.
    if (!st->codec->extradata_size && st->codec->codec_id == AV_CODEC_ID_H264 &&
3125 3126 3127 3128
        TAG_IS_AVCI(st->codec->codec_tag)) {
        ret = ff_generate_avci_extradata(st);
        if (ret < 0)
            return ret;
R
Reimar Döffinger 已提交
3129 3130
    }

3131
    switch (st->codec->codec_id) {
3132
#if CONFIG_H261_DECODER
3133
    case AV_CODEC_ID_H261:
3134
#endif
3135
#if CONFIG_H263_DECODER
3136
    case AV_CODEC_ID_H263:
3137
#endif
3138
#if CONFIG_MPEG4_DECODER
3139
    case AV_CODEC_ID_MPEG4:
3140
#endif
3141
        st->codec->width = 0; /* let decoder init width/height */
3142 3143 3144
        st->codec->height= 0;
        break;
    }
B
Baptiste Coudurier 已提交
3145

3146 3147 3148 3149 3150 3151 3152
    // If the duration of the mp3 packets is not constant, then they could need a parser
    if (st->codec->codec_id == AV_CODEC_ID_MP3
        && sc->stts_count > 3
        && sc->stts_count*10 > st->nb_frames
        && sc->time_scale == st->codec->sample_rate) {
            st->need_parsing = AVSTREAM_PARSE_FULL;
    }
B
Baptiste Coudurier 已提交
3153 3154
    /* Do not need those anymore. */
    av_freep(&sc->chunk_offsets);
3155
    av_freep(&sc->stsc_data);
B
Baptiste Coudurier 已提交
3156 3157 3158
    av_freep(&sc->sample_sizes);
    av_freep(&sc->keyframes);
    av_freep(&sc->stts_data);
3159
    av_freep(&sc->stps_data);
3160
    av_freep(&sc->elst_data);
3161
    av_freep(&sc->rap_group);
B
Baptiste Coudurier 已提交
3162

3163
    return 0;
3164 3165
}

3166
static int mov_read_ilst(MOVContext *c, AVIOContext *pb, MOVAtom atom)
3167 3168 3169 3170 3171 3172 3173 3174
{
    int ret;
    c->itunes_metadata = 1;
    ret = mov_read_default(c, pb, atom);
    c->itunes_metadata = 0;
    return ret;
}

3175 3176 3177 3178 3179 3180 3181 3182 3183 3184 3185 3186 3187 3188 3189 3190 3191 3192 3193 3194 3195 3196 3197 3198 3199 3200 3201 3202 3203 3204 3205 3206 3207 3208 3209 3210 3211 3212 3213 3214 3215 3216
static int mov_read_keys(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    uint32_t count;
    uint32_t i;

    if (atom.size < 8)
        return 0;

    avio_skip(pb, 4);
    count = avio_rb32(pb);
    if (count > UINT_MAX / sizeof(*c->meta_keys)) {
        av_log(c->fc, AV_LOG_ERROR,
               "The 'keys' atom with the invalid key count: %d\n", count);
        return AVERROR_INVALIDDATA;
    }

    c->meta_keys_count = count + 1;
    c->meta_keys = av_mallocz(c->meta_keys_count * sizeof(*c->meta_keys));
    if (!c->meta_keys)
        return AVERROR(ENOMEM);

    for (i = 1; i <= count; ++i) {
        uint32_t key_size = avio_rb32(pb);
        uint32_t type = avio_rl32(pb);
        if (key_size < 8) {
            av_log(c->fc, AV_LOG_ERROR,
                   "The key# %d in meta has invalid size: %d\n", i, key_size);
            return AVERROR_INVALIDDATA;
        }
        key_size -= 8;
        if (type != MKTAG('m','d','t','a')) {
            avio_skip(pb, key_size);
        }
        c->meta_keys[i] = av_mallocz(key_size + 1);
        if (!c->meta_keys[i])
            return AVERROR(ENOMEM);
        avio_read(pb, c->meta_keys[i], key_size);
    }

    return 0;
}

3217
static int mov_read_custom_2plus(MOVContext *c, AVIOContext *pb, int size)
3218 3219 3220 3221
{
    int64_t end = avio_tell(pb) + size;
    uint8_t *key = NULL, *val = NULL;
    int i;
3222 3223 3224 3225 3226 3227 3228
    AVStream *st;
    MOVStreamContext *sc;

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;
3229 3230 3231 3232

    for (i = 0; i < 2; i++) {
        uint8_t **p;
        uint32_t len, tag;
3233
        int ret;
3234 3235 3236 3237 3238 3239 3240 3241 3242 3243 3244 3245 3246 3247 3248 3249 3250 3251 3252 3253 3254 3255 3256 3257

        if (end - avio_tell(pb) <= 12)
            break;

        len = avio_rb32(pb);
        tag = avio_rl32(pb);
        avio_skip(pb, 4); // flags

        if (len < 12 || len - 12 > end - avio_tell(pb))
            break;
        len -= 12;

        if (tag == MKTAG('n', 'a', 'm', 'e'))
            p = &key;
        else if (tag == MKTAG('d', 'a', 't', 'a') && len > 4) {
            avio_skip(pb, 4);
            len -= 4;
            p = &val;
        } else
            break;

        *p = av_malloc(len + 1);
        if (!*p)
            break;
3258 3259
        ret = ffio_read_size(pb, *p, len);
        if (ret < 0) {
3260
            av_freep(p);
3261
            return ret;
3262
        }
3263 3264 3265 3266
        (*p)[len] = 0;
    }

    if (key && val) {
3267 3268 3269 3270 3271 3272
        if (strcmp(key, "iTunSMPB") == 0) {
            int priming, remainder, samples;
            if(sscanf(val, "%*X %X %X %X", &priming, &remainder, &samples) == 3){
                if(priming>0 && priming<16384)
                    sc->start_pad = priming;
            }
3273 3274
        }
        if (strcmp(key, "cdec") != 0) {
3275 3276 3277 3278
            av_dict_set(&c->fc->metadata, key, val,
                        AV_DICT_DONT_STRDUP_KEY | AV_DICT_DONT_STRDUP_VAL);
            key = val = NULL;
        }
3279 3280 3281 3282 3283 3284 3285 3286 3287 3288 3289 3290 3291 3292 3293 3294 3295 3296 3297 3298 3299 3300 3301 3302 3303 3304 3305 3306 3307 3308 3309
    }

    avio_seek(pb, end, SEEK_SET);
    av_freep(&key);
    av_freep(&val);
    return 0;
}

static int mov_read_custom(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    int64_t end = avio_tell(pb) + atom.size;
    uint32_t tag, len;

    if (atom.size < 8)
        goto fail;

    len = avio_rb32(pb);
    tag = avio_rl32(pb);

    if (len > atom.size)
        goto fail;

    if (tag == MKTAG('m', 'e', 'a', 'n') && len > 12) {
        uint8_t domain[128];
        int domain_len;

        avio_skip(pb, 4); // flags
        len -= 12;

        domain_len = avio_get_str(pb, len, domain, sizeof(domain));
        avio_skip(pb, len - domain_len);
3310
        return mov_read_custom_2plus(c, pb, end - avio_tell(pb));
3311 3312 3313 3314 3315 3316 3317 3318
    }

fail:
    av_log(c->fc, AV_LOG_VERBOSE,
           "Unhandled or malformed custom metadata of size %"PRId64"\n", atom.size);
    return 0;
}

3319
static int mov_read_meta(MOVContext *c, AVIOContext *pb, MOVAtom atom)
3320
{
3321
    while (atom.size > 8) {
3322
        uint32_t tag = avio_rl32(pb);
3323 3324
        atom.size -= 4;
        if (tag == MKTAG('h','d','l','r')) {
A
Anton Khirnov 已提交
3325
            avio_seek(pb, -8, SEEK_CUR);
3326 3327 3328 3329 3330
            atom.size += 8;
            return mov_read_default(c, pb, atom);
        }
    }
    return 0;
3331 3332
}

3333
static int mov_read_tkhd(MOVContext *c, AVIOContext *pb, MOVAtom atom)
3334
{
3335 3336 3337
    int i;
    int width;
    int height;
3338
    int display_matrix[3][3];
3339 3340 3341
    AVStream *st;
    MOVStreamContext *sc;
    int version;
3342
    int flags;
3343 3344 3345 3346 3347

    if (c->fc->nb_streams < 1)
        return 0;
    st = c->fc->streams[c->fc->nb_streams-1];
    sc = st->priv_data;
3348

3349
    version = avio_r8(pb);
3350 3351
    flags = avio_rb24(pb);
    st->disposition |= (flags & MOV_TKHD_FLAG_ENABLED) ? AV_DISPOSITION_DEFAULT : 0;
3352

B
Baptiste Coudurier 已提交
3353
    if (version == 1) {
3354 3355
        avio_rb64(pb);
        avio_rb64(pb);
B
Baptiste Coudurier 已提交
3356
    } else {
3357 3358
        avio_rb32(pb); /* creation time */
        avio_rb32(pb); /* modification time */
B
Baptiste Coudurier 已提交
3359
    }
3360 3361
    st->id = (int)avio_rb32(pb); /* track id (NOT 0 !)*/
    avio_rb32(pb); /* reserved */
3362

3363
    /* highlevel (considering edits) duration in movie timebase */
3364 3365 3366
    (version == 1) ? avio_rb64(pb) : avio_rb32(pb);
    avio_rb32(pb); /* reserved */
    avio_rb32(pb); /* reserved */
3367

3368 3369 3370 3371
    avio_rb16(pb); /* layer */
    avio_rb16(pb); /* alternate group */
    avio_rb16(pb); /* volume */
    avio_rb16(pb); /* reserved */
3372

3373 3374
    //read in the display matrix (outlined in ISO 14496-12, Section 6.2.2)
    // they're kept in fixed point format through all calculations
3375 3376
    // save u,v,z to store the whole matrix in the AV_PKT_DATA_DISPLAYMATRIX
    // side data, but the scale factor is not needed to calculate aspect ratio
3377
    for (i = 0; i < 3; i++) {
3378 3379
        display_matrix[i][0] = avio_rb32(pb);   // 16.16 fixed point
        display_matrix[i][1] = avio_rb32(pb);   // 16.16 fixed point
3380
        display_matrix[i][2] = avio_rb32(pb);   //  2.30 fixed point
3381
    }
3382

3383 3384
    width = avio_rb32(pb);       // 16.16 fixed point track width
    height = avio_rb32(pb);      // 16.16 fixed point track height
3385 3386
    sc->width = width >> 16;
    sc->height = height >> 16;
3387

3388 3389
    // save the matrix and add rotate metadata when it is not the default
    // identity
3390 3391 3392 3393 3394 3395 3396
    if (display_matrix[0][0] != (1 << 16) ||
        display_matrix[1][1] != (1 << 16) ||
        display_matrix[2][2] != (1 << 30) ||
        display_matrix[0][1] || display_matrix[0][2] ||
        display_matrix[1][0] || display_matrix[1][2] ||
        display_matrix[2][0] || display_matrix[2][1]) {
        int i, j;
3397
        double rotate;
3398 3399 3400 3401 3402 3403 3404 3405

        av_freep(&sc->display_matrix);
        sc->display_matrix = av_malloc(sizeof(int32_t) * 9);
        if (!sc->display_matrix)
            return AVERROR(ENOMEM);

        for (i = 0; i < 3; i++)
            for (j = 0; j < 3; j++)
3406
                sc->display_matrix[i * 3 + j] = display_matrix[i][j];
3407 3408 3409 3410 3411 3412 3413 3414 3415 3416

        rotate = av_display_rotation_get(sc->display_matrix);
        if (!isnan(rotate)) {
            char rotate_buf[64];
            rotate = -rotate;
            if (rotate < 0) // for backward compatibility
                rotate += 360;
            snprintf(rotate_buf, sizeof(rotate_buf), "%g", rotate);
            av_dict_set(&st->metadata, "rotate", rotate_buf, 0);
        }
3417 3418
    }

3419
    // transform the display width/height according to the matrix
3420
    // to keep the same scale, use [width height 1<<16]
3421 3422 3423
    if (width && height && sc->display_matrix) {
        double disp_transform[2];

3424
        for (i = 0; i < 2; i++)
G
Ganesh Ajjanagadde 已提交
3425
            disp_transform[i] = hypot(display_matrix[i][0], display_matrix[i][1]);
3426

3427 3428
        if (disp_transform[0] > 0       && disp_transform[1] > 0 &&
            disp_transform[0] < (1<<24) && disp_transform[1] < (1<<24) &&
3429
            fabs((disp_transform[0] / disp_transform[1]) - 1.0) > 0.01)
3430 3431 3432
            st->sample_aspect_ratio = av_d2q(
                disp_transform[0] / disp_transform[1],
                INT_MAX);
3433
    }
3434 3435 3436
    return 0;
}

3437
static int mov_read_tfhd(MOVContext *c, AVIOContext *pb, MOVAtom atom)
B
Baptiste Coudurier 已提交
3438 3439 3440
{
    MOVFragment *frag = &c->fragment;
    MOVTrackExt *trex = NULL;
3441
    MOVFragmentIndex* index = NULL;
3442
    int flags, track_id, i, found = 0;
B
Baptiste Coudurier 已提交
3443

3444 3445
    avio_r8(pb); /* version */
    flags = avio_rb24(pb);
B
Baptiste Coudurier 已提交
3446

3447
    track_id = avio_rb32(pb);
3448
    if (!track_id)
3449
        return AVERROR_INVALIDDATA;
B
Baptiste Coudurier 已提交
3450 3451 3452 3453 3454 3455 3456 3457
    frag->track_id = track_id;
    for (i = 0; i < c->trex_count; i++)
        if (c->trex_data[i].track_id == frag->track_id) {
            trex = &c->trex_data[i];
            break;
        }
    if (!trex) {
        av_log(c->fc, AV_LOG_ERROR, "could not find corresponding trex\n");
3458
        return AVERROR_INVALIDDATA;
B
Baptiste Coudurier 已提交
3459 3460
    }

3461
    frag->base_data_offset = flags & MOV_TFHD_BASE_DATA_OFFSET ?
3462 3463
                             avio_rb64(pb) : flags & MOV_TFHD_DEFAULT_BASE_IS_MOOF ?
                             frag->moof_offset : frag->implicit_offset;
3464 3465 3466 3467 3468 3469 3470 3471
    frag->stsd_id  = flags & MOV_TFHD_STSD_ID ? avio_rb32(pb) : trex->stsd_id;

    frag->duration = flags & MOV_TFHD_DEFAULT_DURATION ?
                     avio_rb32(pb) : trex->duration;
    frag->size     = flags & MOV_TFHD_DEFAULT_SIZE ?
                     avio_rb32(pb) : trex->size;
    frag->flags    = flags & MOV_TFHD_DEFAULT_FLAGS ?
                     avio_rb32(pb) : trex->flags;
3472
    frag->time     = AV_NOPTS_VALUE;
3473 3474 3475 3476 3477 3478 3479 3480 3481 3482 3483 3484 3485 3486 3487 3488 3489
    for (i = 0; i < c->fragment_index_count; i++) {
        int j;
        MOVFragmentIndex* candidate = c->fragment_index_data[i];
        if (candidate->track_id == frag->track_id) {
            av_log(c->fc, AV_LOG_DEBUG,
                   "found fragment index for track %u\n", frag->track_id);
            index = candidate;
            for (j = index->current_item; j < index->item_count; j++) {
                if (frag->implicit_offset == index->items[j].moof_offset) {
                    av_log(c->fc, AV_LOG_DEBUG, "found fragment index entry "
                            "for track %u and moof_offset %"PRId64"\n",
                            frag->track_id, index->items[j].moof_offset);
                    frag->time = index->items[j].time;
                    index->current_item = j + 1;
                    found = 1;
                    break;
                }
3490
            }
3491 3492
            if (found)
                break;
3493 3494
        }
    }
3495 3496 3497 3498 3499
    if (index && !found) {
        av_log(c->fc, AV_LOG_DEBUG, "track %u has a fragment index but "
               "it doesn't have an (in-order) entry for moof_offset "
               "%"PRId64"\n", frag->track_id, frag->implicit_offset);
    }
3500
    av_log(c->fc, AV_LOG_TRACE, "frag flags 0x%x\n", frag->flags);
B
Baptiste Coudurier 已提交
3501 3502 3503
    return 0;
}

3504
static int mov_read_chap(MOVContext *c, AVIOContext *pb, MOVAtom atom)
D
David Conrad 已提交
3505
{
3506
    c->chapter_track = avio_rb32(pb);
D
David Conrad 已提交
3507 3508 3509
    return 0;
}

3510
static int mov_read_trex(MOVContext *c, AVIOContext *pb, MOVAtom atom)
B
Baptiste Coudurier 已提交
3511 3512
{
    MOVTrackExt *trex;
3513
    int err;
B
Baptiste Coudurier 已提交
3514 3515

    if ((uint64_t)c->trex_count+1 >= UINT_MAX / sizeof(*c->trex_data))
3516
        return AVERROR_INVALIDDATA;
3517 3518 3519 3520 3521
    if ((err = av_reallocp_array(&c->trex_data, c->trex_count + 1,
                                 sizeof(*c->trex_data))) < 0) {
        c->trex_count = 0;
        return err;
    }
3522 3523 3524

    c->fc->duration = AV_NOPTS_VALUE; // the duration from mvhd is not representing the whole file when fragments are used.

B
Baptiste Coudurier 已提交
3525
    trex = &c->trex_data[c->trex_count++];
3526 3527 3528 3529 3530 3531 3532
    avio_r8(pb); /* version */
    avio_rb24(pb); /* flags */
    trex->track_id = avio_rb32(pb);
    trex->stsd_id  = avio_rb32(pb);
    trex->duration = avio_rb32(pb);
    trex->size     = avio_rb32(pb);
    trex->flags    = avio_rb32(pb);
B
Baptiste Coudurier 已提交
3533 3534 3535
    return 0;
}

M
Martin Storsjö 已提交
3536 3537 3538 3539 3540 3541 3542 3543 3544 3545 3546 3547 3548 3549 3550 3551 3552 3553 3554 3555 3556 3557 3558 3559 3560 3561 3562 3563 3564 3565
static int mov_read_tfdt(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    MOVFragment *frag = &c->fragment;
    AVStream *st = NULL;
    MOVStreamContext *sc;
    int version, i;

    for (i = 0; i < c->fc->nb_streams; i++) {
        if (c->fc->streams[i]->id == frag->track_id) {
            st = c->fc->streams[i];
            break;
        }
    }
    if (!st) {
        av_log(c->fc, AV_LOG_ERROR, "could not find corresponding track id %d\n", frag->track_id);
        return AVERROR_INVALIDDATA;
    }
    sc = st->priv_data;
    if (sc->pseudo_stream_id + 1 != frag->stsd_id)
        return 0;
    version = avio_r8(pb);
    avio_rb24(pb); /* flags */
    if (version) {
        sc->track_end = avio_rb64(pb);
    } else {
        sc->track_end = avio_rb32(pb);
    }
    return 0;
}

3566
static int mov_read_trun(MOVContext *c, AVIOContext *pb, MOVAtom atom)
B
Baptiste Coudurier 已提交
3567 3568
{
    MOVFragment *frag = &c->fragment;
3569
    AVStream *st = NULL;
3570
    MOVStreamContext *sc;
3571
    MOVStts *ctts_data;
B
Baptiste Coudurier 已提交
3572 3573 3574 3575
    uint64_t offset;
    int64_t dts;
    int data_offset = 0;
    unsigned entries, first_sample_flags = frag->flags;
3576
    int flags, distance, i, err;
B
Baptiste Coudurier 已提交
3577

3578 3579 3580 3581 3582 3583 3584 3585
    for (i = 0; i < c->fc->nb_streams; i++) {
        if (c->fc->streams[i]->id == frag->track_id) {
            st = c->fc->streams[i];
            break;
        }
    }
    if (!st) {
        av_log(c->fc, AV_LOG_ERROR, "could not find corresponding track id %d\n", frag->track_id);
3586
        return AVERROR_INVALIDDATA;
3587
    }
3588
    sc = st->priv_data;
3589
    if (sc->pseudo_stream_id+1 != frag->stsd_id && sc->pseudo_stream_id != -1)
B
Baptiste Coudurier 已提交
3590
        return 0;
3591 3592 3593
    avio_r8(pb); /* version */
    flags = avio_rb24(pb);
    entries = avio_rb32(pb);
3594
    av_log(c->fc, AV_LOG_TRACE, "flags 0x%x entries %d\n", flags, entries);
3595 3596 3597 3598 3599 3600 3601 3602 3603

    /* Always assume the presence of composition time offsets.
     * Without this assumption, for instance, we cannot deal with a track in fragmented movies that meet the following.
     *  1) in the initial movie, there are no samples.
     *  2) in the first movie fragment, there is only one sample without composition time offset.
     *  3) in the subsequent movie fragments, there are samples with composition time offset. */
    if (!sc->ctts_count && sc->sample_count)
    {
        /* Complement ctts table if moov atom doesn't have ctts atom. */
3604
        ctts_data = av_realloc(NULL, sizeof(*sc->ctts_data));
3605
        if (!ctts_data)
B
Baptiste Coudurier 已提交
3606
            return AVERROR(ENOMEM);
3607
        sc->ctts_data = ctts_data;
3608 3609 3610
        sc->ctts_data[sc->ctts_count].count = sc->sample_count;
        sc->ctts_data[sc->ctts_count].duration = 0;
        sc->ctts_count++;
B
Baptiste Coudurier 已提交
3611
    }
3612
    if ((uint64_t)entries+sc->ctts_count >= UINT_MAX/sizeof(*sc->ctts_data))
3613
        return AVERROR_INVALIDDATA;
3614 3615 3616 3617 3618
    if ((err = av_reallocp_array(&sc->ctts_data, entries + sc->ctts_count,
                                 sizeof(*sc->ctts_data))) < 0) {
        sc->ctts_count = 0;
        return err;
    }
3619 3620
    if (flags & MOV_TRUN_DATA_OFFSET)        data_offset        = avio_rb32(pb);
    if (flags & MOV_TRUN_FIRST_SAMPLE_FLAGS) first_sample_flags = avio_rb32(pb);
3621
    dts    = sc->track_end - sc->time_offset;
B
Baptiste Coudurier 已提交
3622 3623
    offset = frag->base_data_offset + data_offset;
    distance = 0;
3624
    av_log(c->fc, AV_LOG_TRACE, "first sample flags 0x%x\n", first_sample_flags);
3625
    for (i = 0; i < entries && !pb->eof_reached; i++) {
B
Baptiste Coudurier 已提交
3626 3627 3628
        unsigned sample_size = frag->size;
        int sample_flags = i ? frag->flags : first_sample_flags;
        unsigned sample_duration = frag->duration;
3629
        int keyframe = 0;
B
Baptiste Coudurier 已提交
3630

3631 3632 3633
        if (flags & MOV_TRUN_SAMPLE_DURATION) sample_duration = avio_rb32(pb);
        if (flags & MOV_TRUN_SAMPLE_SIZE)     sample_size     = avio_rb32(pb);
        if (flags & MOV_TRUN_SAMPLE_FLAGS)    sample_flags    = avio_rb32(pb);
3634 3635 3636
        sc->ctts_data[sc->ctts_count].count = 1;
        sc->ctts_data[sc->ctts_count].duration = (flags & MOV_TRUN_SAMPLE_CTS) ?
                                                  avio_rb32(pb) : 0;
3637
        mov_update_dts_shift(sc, sc->ctts_data[sc->ctts_count].duration);
3638 3639 3640 3641 3642 3643 3644 3645 3646 3647 3648 3649 3650 3651 3652 3653 3654 3655 3656 3657 3658 3659
        if (frag->time != AV_NOPTS_VALUE) {
            if (c->use_mfra_for == FF_MOV_FLAG_MFRA_PTS) {
                int64_t pts = frag->time;
                av_log(c->fc, AV_LOG_DEBUG, "found frag time %"PRId64
                        " sc->dts_shift %d ctts.duration %d"
                        " sc->time_offset %"PRId64" flags & MOV_TRUN_SAMPLE_CTS %d\n", pts,
                        sc->dts_shift, sc->ctts_data[sc->ctts_count].duration,
                        sc->time_offset, flags & MOV_TRUN_SAMPLE_CTS);
                dts = pts - sc->dts_shift;
                if (flags & MOV_TRUN_SAMPLE_CTS) {
                    dts -= sc->ctts_data[sc->ctts_count].duration;
                } else {
                    dts -= sc->time_offset;
                }
                av_log(c->fc, AV_LOG_DEBUG, "calculated into dts %"PRId64"\n", dts);
            } else {
                dts = frag->time;
                av_log(c->fc, AV_LOG_DEBUG, "found frag time %"PRId64
                        ", using it for dts\n", dts);
            }
            frag->time = AV_NOPTS_VALUE;
        }
3660
        sc->ctts_count++;
3661 3662
        if (st->codec->codec_type == AVMEDIA_TYPE_AUDIO)
            keyframe = 1;
3663 3664
        else
            keyframe =
3665 3666 3667
                !(sample_flags & (MOV_FRAG_SAMPLE_FLAG_IS_NON_SYNC |
                                  MOV_FRAG_SAMPLE_FLAG_DEPENDS_YES));
        if (keyframe)
B
Baptiste Coudurier 已提交
3668
            distance = 0;
3669
        err = av_add_index_entry(st, offset, dts, sample_size, distance,
3670 3671 3672
                                 keyframe ? AVINDEX_KEYFRAME : 0);
        if (err < 0) {
            av_log(c->fc, AV_LOG_ERROR, "Failed to add index entry\n");
3673
        }
3674
        av_log(c->fc, AV_LOG_TRACE, "AVIndex stream %d, sample %d, offset %"PRIx64", dts %"PRId64", "
B
Baptiste Coudurier 已提交
3675
                "size %d, distance %d, keyframe %d\n", st->index, sc->sample_count+i,
3676
                offset, dts, sample_size, distance, keyframe);
B
Baptiste Coudurier 已提交
3677
        distance++;
3678
        dts += sample_duration;
B
Baptiste Coudurier 已提交
3679
        offset += sample_size;
3680
        sc->data_size += sample_size;
3681 3682
        sc->duration_for_fps += sample_duration;
        sc->nb_frames_for_fps ++;
B
Baptiste Coudurier 已提交
3683
    }
3684 3685 3686 3687

    if (pb->eof_reached)
        return AVERROR_EOF;

3688
    frag->implicit_offset = offset;
3689 3690 3691 3692 3693 3694 3695 3696 3697 3698 3699 3700 3701 3702 3703 3704 3705 3706 3707 3708 3709 3710 3711 3712 3713 3714 3715 3716 3717 3718 3719 3720 3721 3722 3723 3724 3725 3726 3727 3728 3729 3730 3731 3732 3733 3734 3735 3736 3737 3738 3739 3740 3741 3742 3743 3744 3745 3746 3747 3748 3749 3750 3751 3752 3753 3754 3755 3756 3757 3758 3759 3760 3761 3762 3763 3764 3765 3766 3767 3768 3769 3770 3771 3772 3773 3774 3775 3776 3777 3778 3779 3780 3781 3782 3783 3784 3785 3786 3787 3788

    sc->track_end = dts + sc->time_offset;
    if (st->duration < sc->track_end)
        st->duration = sc->track_end;

    return 0;
}

static int mov_read_sidx(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    int64_t offset = avio_tell(pb) + atom.size, pts;
    uint8_t version;
    unsigned i, track_id;
    AVStream *st = NULL;
    MOVStreamContext *sc;
    MOVFragmentIndex *index = NULL;
    MOVFragmentIndex **tmp;
    AVRational timescale;

    version = avio_r8(pb);
    if (version > 1) {
        avpriv_request_sample(c->fc, "sidx version %u", version);
        return AVERROR_PATCHWELCOME;
    }

    avio_rb24(pb); // flags

    track_id = avio_rb32(pb); // Reference ID
    for (i = 0; i < c->fc->nb_streams; i++) {
        if (c->fc->streams[i]->id == track_id) {
            st = c->fc->streams[i];
            break;
        }
    }
    if (!st) {
        av_log(c->fc, AV_LOG_ERROR, "could not find corresponding track id %d\n", track_id);
        return AVERROR_INVALIDDATA;
    }

    sc = st->priv_data;

    timescale = av_make_q(1, avio_rb32(pb));

    if (version == 0) {
        pts = avio_rb32(pb);
        offset += avio_rb32(pb);
    } else {
        pts = avio_rb64(pb);
        offset += avio_rb64(pb);
    }

    avio_rb16(pb); // reserved

    index = av_mallocz(sizeof(MOVFragmentIndex));
    if (!index)
        return AVERROR(ENOMEM);

    index->track_id = track_id;

    index->item_count = avio_rb16(pb);
    index->items = av_mallocz_array(index->item_count, sizeof(MOVFragmentIndexItem));

    if (!index->items) {
        av_freep(&index);
        return AVERROR(ENOMEM);
    }

    for (i = 0; i < index->item_count; i++) {
        uint32_t size = avio_rb32(pb);
        uint32_t duration = avio_rb32(pb);
        if (size & 0x80000000) {
            avpriv_request_sample(c->fc, "sidx reference_type 1");
            av_freep(&index->items);
            av_freep(&index);
            return AVERROR_PATCHWELCOME;
        }
        avio_rb32(pb); // sap_flags
        index->items[i].moof_offset = offset;
        index->items[i].time = av_rescale_q(pts, st->time_base, timescale);
        offset += size;
        pts += duration;
    }

    st->duration = sc->track_end = pts;

    tmp = av_realloc_array(c->fragment_index_data,
                           c->fragment_index_count + 1,
                           sizeof(MOVFragmentIndex*));
    if (!tmp) {
        av_freep(&index->items);
        av_freep(&index);
        return AVERROR(ENOMEM);
    }

    c->fragment_index_data = tmp;
    c->fragment_index_data[c->fragment_index_count++] = index;

    if (offset == avio_size(pb))
        c->fragment_index_complete = 1;

B
Baptiste Coudurier 已提交
3789 3790 3791
    return 0;
}

3792 3793 3794
/* this atom should be null (from specs), but some buggy files put the 'moov' atom inside it... */
/* like the files created with Adobe Premiere 5.0, for samples see */
/* http://graphics.tudelft.nl/~wouter/publications/soundtests/ */
3795
static int mov_read_wide(MOVContext *c, AVIOContext *pb, MOVAtom atom)
3796 3797 3798 3799 3800
{
    int err;

    if (atom.size < 8)
        return 0; /* continue */
3801
    if (avio_rb32(pb) != 0) { /* 0 sized mdat atom... use the 'wide' atom size */
3802
        avio_skip(pb, atom.size - 4);
3803 3804
        return 0;
    }
3805
    atom.type = avio_rl32(pb);
3806
    atom.size -= 8;
3807
    if (atom.type != MKTAG('m','d','a','t')) {
3808
        avio_skip(pb, atom.size);
3809 3810 3811 3812 3813 3814
        return 0;
    }
    err = mov_read_mdat(c, pb, atom);
    return err;
}

3815
static int mov_read_cmov(MOVContext *c, AVIOContext *pb, MOVAtom atom)
3816
{
3817
#if CONFIG_ZLIB
3818
    AVIOContext ctx;
3819 3820
    uint8_t *cmov_data;
    uint8_t *moov_data; /* uncompressed data */
3821
    long cmov_len, moov_len;
3822
    int ret = -1;
3823

3824 3825
    avio_rb32(pb); /* dcom atom */
    if (avio_rl32(pb) != MKTAG('d','c','o','m'))
3826
        return AVERROR_INVALIDDATA;
3827
    if (avio_rl32(pb) != MKTAG('z','l','i','b')) {
3828
        av_log(c->fc, AV_LOG_ERROR, "unknown compression for cmov atom !\n");
3829
        return AVERROR_INVALIDDATA;
3830
    }
3831 3832
    avio_rb32(pb); /* cmvd atom */
    if (avio_rl32(pb) != MKTAG('c','m','v','d'))
3833
        return AVERROR_INVALIDDATA;
3834
    moov_len = avio_rb32(pb); /* uncompressed size */
3835
    cmov_len = atom.size - 6 * 4;
3836

B
Baptiste Coudurier 已提交
3837
    cmov_data = av_malloc(cmov_len);
3838
    if (!cmov_data)
3839
        return AVERROR(ENOMEM);
B
Baptiste Coudurier 已提交
3840
    moov_data = av_malloc(moov_len);
3841 3842
    if (!moov_data) {
        av_free(cmov_data);
3843
        return AVERROR(ENOMEM);
3844
    }
3845 3846 3847 3848
    ret = ffio_read_size(pb, cmov_data, cmov_len);
    if (ret < 0)
        goto free_and_return;

3849
    if (uncompress (moov_data, (uLongf *) &moov_len, (const Bytef *)cmov_data, cmov_len) != Z_OK)
3850
        goto free_and_return;
3851
    if (ffio_init_context(&ctx, moov_data, moov_len, 0, NULL, NULL, NULL, NULL) != 0)
3852
        goto free_and_return;
3853
    ctx.seekable = AVIO_SEEKABLE_NORMAL;
3854
    atom.type = MKTAG('m','o','o','v');
3855 3856
    atom.size = moov_len;
    ret = mov_read_default(c, &ctx, atom);
3857
free_and_return:
3858 3859 3860
    av_free(moov_data);
    av_free(cmov_data);
    return ret;
3861 3862
#else
    av_log(c->fc, AV_LOG_ERROR, "this file requires zlib support compiled in\n");
3863
    return AVERROR(ENOSYS);
3864
#endif
3865
}
3866

G
Gael Chardon 已提交
3867
/* edit list atom */
3868
static int mov_read_elst(MOVContext *c, AVIOContext *pb, MOVAtom atom)
G
Gael Chardon 已提交
3869
{
3870
    MOVStreamContext *sc;
3871
    int i, edit_count, version;
B
Baptiste Coudurier 已提交
3872

3873
    if (c->fc->nb_streams < 1 || c->ignore_editlist)
3874 3875 3876
        return 0;
    sc = c->fc->streams[c->fc->nb_streams-1]->priv_data;

3877
    version = avio_r8(pb); /* version */
3878 3879
    avio_rb24(pb); /* flags */
    edit_count = avio_rb32(pb); /* entries */
B
Baptiste Coudurier 已提交
3880

3881 3882 3883 3884 3885 3886 3887 3888 3889
    if (!edit_count)
        return 0;
    if (sc->elst_data)
        av_log(c->fc, AV_LOG_WARNING, "Duplicated ELST atom\n");
    av_free(sc->elst_data);
    sc->elst_count = 0;
    sc->elst_data = av_malloc_array(edit_count, sizeof(*sc->elst_data));
    if (!sc->elst_data)
        return AVERROR(ENOMEM);
3890

3891
    av_log(c->fc, AV_LOG_TRACE, "track[%i].edit_count = %i\n", c->fc->nb_streams-1, edit_count);
3892 3893 3894
    for (i = 0; i < edit_count && !pb->eof_reached; i++) {
        MOVElst *e = &sc->elst_data[i];

3895
        if (version == 1) {
3896 3897
            e->duration = avio_rb64(pb);
            e->time     = avio_rb64(pb);
3898
        } else {
3899 3900
            e->duration = avio_rb32(pb); /* segment duration */
            e->time     = (int32_t)avio_rb32(pb); /* media time */
3901
        }
3902
        e->rate = avio_rb32(pb) / 65536.0;
3903
        av_log(c->fc, AV_LOG_TRACE, "duration=%"PRId64" time=%"PRId64" rate=%f\n",
3904
                e->duration, e->time, e->rate);
B
Baptiste Coudurier 已提交
3905
    }
3906
    sc->elst_count = i;
3907

B
Baptiste Coudurier 已提交
3908
    return 0;
G
Gael Chardon 已提交
3909 3910
}

3911
static int mov_read_tmcd(MOVContext *c, AVIOContext *pb, MOVAtom atom)
C
Clément Bœsch 已提交
3912 3913 3914 3915 3916 3917
{
    MOVStreamContext *sc;

    if (c->fc->nb_streams < 1)
        return AVERROR_INVALIDDATA;
    sc = c->fc->streams[c->fc->nb_streams - 1]->priv_data;
3918
    sc->timecode_track = avio_rb32(pb);
C
Clément Bœsch 已提交
3919 3920 3921
    return 0;
}

3922 3923 3924 3925 3926 3927 3928 3929 3930 3931 3932 3933 3934 3935 3936 3937 3938 3939 3940 3941 3942 3943 3944 3945 3946 3947 3948 3949 3950 3951 3952 3953 3954 3955 3956 3957 3958 3959 3960 3961 3962 3963 3964
static int mov_read_uuid(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    int ret;
    uint8_t uuid[16];
    static const uint8_t uuid_isml_manifest[] = {
        0xa5, 0xd4, 0x0b, 0x30, 0xe8, 0x14, 0x11, 0xdd,
        0xba, 0x2f, 0x08, 0x00, 0x20, 0x0c, 0x9a, 0x66
    };

    if (atom.size < sizeof(uuid) || atom.size == INT64_MAX)
        return AVERROR_INVALIDDATA;

    ret = avio_read(pb, uuid, sizeof(uuid));
    if (ret < 0) {
        return ret;
    } else if (ret != sizeof(uuid)) {
        return AVERROR_INVALIDDATA;
    }
    if (!memcmp(uuid, uuid_isml_manifest, sizeof(uuid))) {
        uint8_t *buffer, *ptr;
        char *endptr;
        size_t len = atom.size - sizeof(uuid);

        if (len < 4) {
            return AVERROR_INVALIDDATA;
        }
        ret = avio_skip(pb, 4); // zeroes
        len -= 4;

        buffer = av_mallocz(len + 1);
        if (!buffer) {
            return AVERROR(ENOMEM);
        }
        ret = avio_read(pb, buffer, len);
        if (ret < 0) {
            av_free(buffer);
            return ret;
        } else if (ret != len) {
            av_free(buffer);
            return AVERROR_INVALIDDATA;
        }

        ptr = buffer;
3965
        while ((ptr = av_stristr(ptr, "systemBitrate=\""))) {
3966 3967 3968 3969 3970 3971 3972 3973 3974 3975 3976 3977 3978 3979 3980 3981 3982 3983 3984 3985 3986 3987
            ptr += sizeof("systemBitrate=\"") - 1;
            c->bitrates_count++;
            c->bitrates = av_realloc_f(c->bitrates, c->bitrates_count, sizeof(*c->bitrates));
            if (!c->bitrates) {
                c->bitrates_count = 0;
                av_free(buffer);
                return AVERROR(ENOMEM);
            }
            errno = 0;
            ret = strtol(ptr, &endptr, 10);
            if (ret < 0 || errno || *endptr != '"') {
                c->bitrates[c->bitrates_count - 1] = 0;
            } else {
                c->bitrates[c->bitrates_count - 1] = ret;
            }
        }

        av_free(buffer);
    }
    return 0;
}

3988 3989 3990 3991 3992 3993 3994 3995 3996 3997 3998 3999 4000 4001 4002 4003 4004 4005 4006 4007 4008 4009
static int mov_read_free(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    int ret;
    uint8_t content[16];

    if (atom.size < 8)
        return 0;

    ret = avio_read(pb, content, FFMIN(sizeof(content), atom.size));
    if (ret < 0)
        return ret;

    if (   !c->found_moov
        && !c->found_mdat
        && !memcmp(content, "Anevia\x1A\x1A", 8)
        && c->use_mfra_for == FF_MOV_FLAG_MFRA_AUTO) {
        c->use_mfra_for = FF_MOV_FLAG_MFRA_PTS;
    }

    return 0;
}

4010
static const MOVParseTableEntry mov_default_parse_table[] = {
4011
{ MKTAG('A','C','L','R'), mov_read_aclr },
C
Carl Eugen Hoyos 已提交
4012
{ MKTAG('A','P','R','G'), mov_read_avid },
P
Piotr Bandurski 已提交
4013
{ MKTAG('A','A','L','P'), mov_read_avid },
4014
{ MKTAG('A','R','E','S'), mov_read_ares },
4015
{ MKTAG('a','v','s','s'), mov_read_avss },
D
David Conrad 已提交
4016
{ MKTAG('c','h','p','l'), mov_read_chpl },
4017
{ MKTAG('c','o','6','4'), mov_read_stco },
4018
{ MKTAG('c','o','l','r'), mov_read_colr },
4019 4020
{ MKTAG('c','t','t','s'), mov_read_ctts }, /* composition time to sample */
{ MKTAG('d','i','n','f'), mov_read_default },
4021
{ MKTAG('D','p','x','E'), mov_read_dpxe },
4022 4023 4024 4025
{ MKTAG('d','r','e','f'), mov_read_dref },
{ MKTAG('e','d','t','s'), mov_read_default },
{ MKTAG('e','l','s','t'), mov_read_elst },
{ MKTAG('e','n','d','a'), mov_read_enda },
4026
{ MKTAG('f','i','e','l'), mov_read_fiel },
4027
{ MKTAG('a','d','r','m'), mov_read_adrm },
4028 4029 4030
{ MKTAG('f','t','y','p'), mov_read_ftyp },
{ MKTAG('g','l','b','l'), mov_read_glbl },
{ MKTAG('h','d','l','r'), mov_read_hdlr },
4031
{ MKTAG('i','l','s','t'), mov_read_ilst },
4032
{ MKTAG('j','p','2','h'), mov_read_jp2h },
4033 4034 4035
{ MKTAG('m','d','a','t'), mov_read_mdat },
{ MKTAG('m','d','h','d'), mov_read_mdhd },
{ MKTAG('m','d','i','a'), mov_read_default },
4036
{ MKTAG('m','e','t','a'), mov_read_meta },
4037 4038 4039 4040 4041
{ MKTAG('m','i','n','f'), mov_read_default },
{ MKTAG('m','o','o','f'), mov_read_moof },
{ MKTAG('m','o','o','v'), mov_read_moov },
{ MKTAG('m','v','e','x'), mov_read_default },
{ MKTAG('m','v','h','d'), mov_read_mvhd },
P
Piotr Bandurski 已提交
4042
{ MKTAG('S','M','I',' '), mov_read_svq3 },
4043
{ MKTAG('a','l','a','c'), mov_read_alac }, /* alac specific atom */
4044
{ MKTAG('a','v','c','C'), mov_read_glbl },
4045
{ MKTAG('p','a','s','p'), mov_read_pasp },
4046
{ MKTAG('s','i','d','x'), mov_read_sidx },
4047 4048
{ MKTAG('s','t','b','l'), mov_read_default },
{ MKTAG('s','t','c','o'), mov_read_stco },
4049
{ MKTAG('s','t','p','s'), mov_read_stps },
M
Martin Storsjö 已提交
4050
{ MKTAG('s','t','r','f'), mov_read_strf },
4051 4052 4053 4054 4055
{ MKTAG('s','t','s','c'), mov_read_stsc },
{ MKTAG('s','t','s','d'), mov_read_stsd }, /* sample description */
{ MKTAG('s','t','s','s'), mov_read_stss }, /* sync sample */
{ MKTAG('s','t','s','z'), mov_read_stsz }, /* sample size */
{ MKTAG('s','t','t','s'), mov_read_stts },
4056
{ MKTAG('s','t','z','2'), mov_read_stsz }, /* compact sample size */
4057
{ MKTAG('t','k','h','d'), mov_read_tkhd }, /* track header */
M
Martin Storsjö 已提交
4058
{ MKTAG('t','f','d','t'), mov_read_tfdt },
4059 4060 4061
{ MKTAG('t','f','h','d'), mov_read_tfhd }, /* track fragment header */
{ MKTAG('t','r','a','k'), mov_read_trak },
{ MKTAG('t','r','a','f'), mov_read_default },
4062 4063
{ MKTAG('t','r','e','f'), mov_read_default },
{ MKTAG('t','m','c','d'), mov_read_tmcd },
D
David Conrad 已提交
4064
{ MKTAG('c','h','a','p'), mov_read_chap },
4065 4066
{ MKTAG('t','r','e','x'), mov_read_trex },
{ MKTAG('t','r','u','n'), mov_read_trun },
B
Baptiste Coudurier 已提交
4067
{ MKTAG('u','d','t','a'), mov_read_default },
4068 4069
{ MKTAG('w','a','v','e'), mov_read_wave },
{ MKTAG('e','s','d','s'), mov_read_esds },
4070
{ MKTAG('d','a','c','3'), mov_read_dac3 }, /* AC-3 info */
4071
{ MKTAG('d','e','c','3'), mov_read_dec3 }, /* EAC-3 info */
4072
{ MKTAG('d','d','t','s'), mov_read_ddts }, /* DTS audio descriptor */
4073
{ MKTAG('w','i','d','e'), mov_read_wide }, /* place holder */
4074
{ MKTAG('w','f','e','x'), mov_read_wfex },
4075
{ MKTAG('c','m','o','v'), mov_read_cmov },
4076
{ MKTAG('c','h','a','n'), mov_read_chan }, /* channel layout */
M
Martin Storsjö 已提交
4077
{ MKTAG('d','v','c','1'), mov_read_dvc1 },
4078
{ MKTAG('s','b','g','p'), mov_read_sbgp },
Y
Yusuke Nakamura 已提交
4079
{ MKTAG('h','v','c','C'), mov_read_glbl },
4080
{ MKTAG('u','u','i','d'), mov_read_uuid },
4081
{ MKTAG('C','i','n', 0x8e), mov_read_targa_y216 },
4082
{ MKTAG('f','r','e','e'), mov_read_free },
4083
{ MKTAG('-','-','-','-'), mov_read_custom },
B
Baptiste Coudurier 已提交
4084
{ 0, NULL }
4085 4086
};

4087 4088 4089 4090 4091 4092
static int mov_read_default(MOVContext *c, AVIOContext *pb, MOVAtom atom)
{
    int64_t total_size = 0;
    MOVAtom a;
    int i;

4093 4094 4095 4096 4097 4098
    if (c->atom_depth > 10) {
        av_log(c->fc, AV_LOG_ERROR, "Atoms too deeply nested\n");
        return AVERROR_INVALIDDATA;
    }
    c->atom_depth ++;

4099 4100
    if (atom.size < 0)
        atom.size = INT64_MAX;
4101
    while (total_size + 8 <= atom.size && !avio_feof(pb)) {
4102 4103 4104 4105 4106 4107
        int (*parse)(MOVContext*, AVIOContext*, MOVAtom) = NULL;
        a.size = atom.size;
        a.type=0;
        if (atom.size >= 8) {
            a.size = avio_rb32(pb);
            a.type = avio_rl32(pb);
4108 4109 4110 4111 4112
            if (a.type == MKTAG('f','r','e','e') &&
                a.size >= 8 &&
                c->moov_retry) {
                uint8_t buf[8];
                uint32_t *type = (uint32_t *)buf + 1;
4113 4114
                if (avio_read(pb, buf, 8) != 8)
                    return AVERROR_INVALIDDATA;
4115 4116 4117 4118 4119 4120 4121
                avio_seek(pb, -8, SEEK_CUR);
                if (*type == MKTAG('m','v','h','d') ||
                    *type == MKTAG('c','m','o','v')) {
                    av_log(c->fc, AV_LOG_ERROR, "Detected moov in a free atom.\n");
                    a.type = MKTAG('m','o','o','v');
                }
            }
4122 4123 4124 4125 4126 4127 4128
            if (atom.type != MKTAG('r','o','o','t') &&
                atom.type != MKTAG('m','o','o','v'))
            {
                if (a.type == MKTAG('t','r','a','k') || a.type == MKTAG('m','d','a','t'))
                {
                    av_log(c->fc, AV_LOG_ERROR, "Broken file, trak/mdat not at top-level\n");
                    avio_skip(pb, -8);
4129
                    c->atom_depth --;
4130 4131 4132 4133
                    return 0;
                }
            }
            total_size += 8;
4134
            if (a.size == 1 && total_size + 8 <= atom.size) { /* 64 bit extended size */
4135 4136 4137
                a.size = avio_rb64(pb) - 8;
                total_size += 8;
            }
4138
        }
4139
        av_log(c->fc, AV_LOG_TRACE, "type: %08x '%.4s' parent:'%.4s' sz: %"PRId64" %"PRId64" %"PRId64"\n",
4140 4141
                a.type, (char*)&a.type, (char*)&atom.type, a.size, total_size, atom.size);
        if (a.size == 0) {
4142
            a.size = atom.size - total_size + 8;
4143 4144 4145 4146 4147 4148 4149 4150 4151 4152 4153 4154 4155 4156 4157 4158 4159
        }
        a.size -= 8;
        if (a.size < 0)
            break;
        a.size = FFMIN(a.size, atom.size - total_size);

        for (i = 0; mov_default_parse_table[i].type; i++)
            if (mov_default_parse_table[i].type == a.type) {
                parse = mov_default_parse_table[i].parse;
                break;
            }

        // container is user data
        if (!parse && (atom.type == MKTAG('u','d','t','a') ||
                       atom.type == MKTAG('i','l','s','t')))
            parse = mov_read_udta_string;

4160 4161 4162 4163 4164 4165 4166 4167
        // Supports parsing the QuickTime Metadata Keys.
        // https://developer.apple.com/library/mac/documentation/QuickTime/QTFF/Metadata/Metadata.html
        if (!parse && c->found_hdlr_mdta &&
            atom.type == MKTAG('m','e','t','a') &&
            a.type == MKTAG('k','e','y','s')) {
            parse = mov_read_keys;
        }

4168 4169 4170 4171 4172 4173
        if (!parse) { /* skip leaf atoms data */
            avio_skip(pb, a.size);
        } else {
            int64_t start_pos = avio_tell(pb);
            int64_t left;
            int err = parse(c, pb, a);
4174 4175
            if (err < 0) {
                c->atom_depth --;
4176
                return err;
4177
            }
4178
            if (c->found_moov && c->found_mdat &&
4179
                ((!pb->seekable || c->fc->flags & AVFMT_FLAG_IGNIDX || c->fragment_index_complete) ||
4180
                 start_pos + a.size == avio_size(pb))) {
4181
                if (!pb->seekable || c->fc->flags & AVFMT_FLAG_IGNIDX || c->fragment_index_complete)
4182
                    c->next_root_atom = start_pos + a.size;
4183
                c->atom_depth --;
4184 4185 4186 4187 4188
                return 0;
            }
            left = a.size - avio_tell(pb) + start_pos;
            if (left > 0) /* skip garbage at atom end */
                avio_skip(pb, left);
4189 4190 4191 4192
            else if (left < 0) {
                av_log(c->fc, AV_LOG_WARNING,
                       "overread end of atom '%.4s' by %"PRId64" bytes\n",
                       (char*)&a.type, -left);
4193 4194
                avio_seek(pb, left, SEEK_CUR);
            }
4195 4196 4197 4198 4199 4200 4201 4202
        }

        total_size += a.size;
    }

    if (total_size < atom.size && atom.size < 0x7ffff)
        avio_skip(pb, atom.size - total_size);

4203
    c->atom_depth --;
4204 4205 4206
    return 0;
}

F
Fabrice Bellard 已提交
4207 4208
static int mov_probe(AVProbeData *p)
{
4209
    int64_t offset;
4210
    uint32_t tag;
4211
    int score = 0;
4212
    int moov_offset = -1;
4213

F
Fabrice Bellard 已提交
4214
    /* check file header */
4215
    offset = 0;
4216
    for (;;) {
4217 4218
        /* ignore invalid offset */
        if ((offset + 8) > (unsigned int)p->buf_size)
4219
            break;
4220
        tag = AV_RL32(p->buf + offset + 4);
4221
        switch(tag) {
4222
        /* check for obvious tags */
4223
        case MKTAG('m','o','o','v'):
4224
            moov_offset = offset + 4;
4225 4226 4227
        case MKTAG('m','d','a','t'):
        case MKTAG('p','n','o','t'): /* detect movs with preview pics like ew.mov and april.mov */
        case MKTAG('u','d','t','a'): /* Packet Video PVAuthor adds this and a lot of more junk */
4228
        case MKTAG('f','t','y','p'):
4229 4230 4231 4232
            if (AV_RB32(p->buf+offset) < 8 &&
                (AV_RB32(p->buf+offset) != 1 ||
                 offset + 12 > (unsigned int)p->buf_size ||
                 AV_RB64(p->buf+offset + 8) == 0)) {
4233
                score = FFMAX(score, AVPROBE_SCORE_EXTENSION);
4234
            } else if (tag == MKTAG('f','t','y','p') &&
4235 4236 4237
                       (   AV_RL32(p->buf + offset + 8) == MKTAG('j','p','2',' ')
                        || AV_RL32(p->buf + offset + 8) == MKTAG('j','p','x',' ')
                    )) {
4238
                score = FFMAX(score, 5);
4239 4240 4241
            } else {
                score = AVPROBE_SCORE_MAX;
            }
4242 4243
            offset = FFMAX(4, AV_RB32(p->buf+offset)) + offset;
            break;
4244
        /* those are more common words, so rate then a bit less */
4245 4246 4247 4248 4249
        case MKTAG('e','d','i','w'): /* xdcam files have reverted first tags */
        case MKTAG('w','i','d','e'):
        case MKTAG('f','r','e','e'):
        case MKTAG('j','u','n','k'):
        case MKTAG('p','i','c','t'):
4250 4251 4252
            score  = FFMAX(score, AVPROBE_SCORE_MAX - 5);
            offset = FFMAX(4, AV_RB32(p->buf+offset)) + offset;
            break;
B
Baptiste Coudurier 已提交
4253
        case MKTAG(0x82,0x82,0x7f,0x7d):
4254 4255 4256
        case MKTAG('s','k','i','p'):
        case MKTAG('u','u','i','d'):
        case MKTAG('p','r','f','l'):
4257
            /* if we only find those cause probedata is too small at least rate them */
4258
            score  = FFMAX(score, AVPROBE_SCORE_EXTENSION);
4259
            offset = FFMAX(4, AV_RB32(p->buf+offset)) + offset;
4260 4261
            break;
        default:
4262 4263 4264
            offset = FFMAX(4, AV_RB32(p->buf+offset)) + offset;
        }
    }
4265
    if(score > AVPROBE_SCORE_MAX - 50 && moov_offset != -1) {
4266 4267 4268 4269
        /* moov atom in the header - we should make sure that this is not a
         * MOV-packed MPEG-PS */
        offset = moov_offset;

4270 4271 4272 4273 4274 4275 4276 4277
        while(offset < (p->buf_size - 16)){ /* Sufficient space */
               /* We found an actual hdlr atom */
            if(AV_RL32(p->buf + offset     ) == MKTAG('h','d','l','r') &&
               AV_RL32(p->buf + offset +  8) == MKTAG('m','h','l','r') &&
               AV_RL32(p->buf + offset + 12) == MKTAG('M','P','E','G')){
                av_log(NULL, AV_LOG_WARNING, "Found media data tag MPEG indicating this is a MOV-packed MPEG-PS.\n");
                /* We found a media handler reference atom describing an
                 * MPEG-PS-in-MOV, return a
4278 4279 4280 4281 4282 4283
                 * low score to force expanding the probe window until
                 * mpegps_probe finds what it needs */
                return 5;
            }else
                /* Keep looking */
                offset+=2;
4284
        }
4285
    }
4286 4287

    return score;
F
Fabrice Bellard 已提交
4288 4289
}

D
David Conrad 已提交
4290 4291 4292 4293 4294 4295 4296
// must be done after parsing all trak because there's no order requirement
static void mov_read_chapters(AVFormatContext *s)
{
    MOVContext *mov = s->priv_data;
    AVStream *st = NULL;
    MOVStreamContext *sc;
    int64_t cur_pos;
4297
    int i;
D
David Conrad 已提交
4298 4299 4300 4301 4302 4303 4304 4305 4306 4307 4308 4309 4310

    for (i = 0; i < s->nb_streams; i++)
        if (s->streams[i]->id == mov->chapter_track) {
            st = s->streams[i];
            break;
        }
    if (!st) {
        av_log(s, AV_LOG_ERROR, "Referenced QT chapter track not found\n");
        return;
    }

    st->discard = AVDISCARD_ALL;
    sc = st->priv_data;
4311
    cur_pos = avio_tell(sc->pb);
D
David Conrad 已提交
4312 4313 4314 4315

    for (i = 0; i < st->nb_index_entries; i++) {
        AVIndexEntry *sample = &st->index_entries[i];
        int64_t end = i+1 < st->nb_index_entries ? st->index_entries[i+1].timestamp : st->duration;
4316 4317 4318
        uint8_t *title;
        uint16_t ch;
        int len, title_len;
D
David Conrad 已提交
4319

4320 4321 4322 4323 4324
        if (end < sample->timestamp) {
            av_log(s, AV_LOG_WARNING, "ignoring stream duration which is shorter than chapters\n");
            end = AV_NOPTS_VALUE;
        }

A
Anton Khirnov 已提交
4325
        if (avio_seek(sc->pb, sample->pos, SEEK_SET) != sample->pos) {
D
David Conrad 已提交
4326 4327 4328 4329 4330
            av_log(s, AV_LOG_ERROR, "Chapter %d not found in file\n", i);
            goto finish;
        }

        // the first two bytes are the length of the title
4331
        len = avio_rb16(sc->pb);
D
David Conrad 已提交
4332 4333
        if (len > sample->size-2)
            continue;
4334 4335 4336
        title_len = 2*len + 1;
        if (!(title = av_mallocz(title_len)))
            goto finish;
D
David Conrad 已提交
4337 4338 4339 4340

        // The samples could theoretically be in any encoding if there's an encd
        // atom following, but in practice are only utf-8 or utf-16, distinguished
        // instead by the presence of a BOM
4341 4342 4343 4344 4345 4346 4347 4348 4349 4350 4351
        if (!len) {
            title[0] = 0;
        } else {
            ch = avio_rb16(sc->pb);
            if (ch == 0xfeff)
                avio_get_str16be(sc->pb, len, title, title_len);
            else if (ch == 0xfffe)
                avio_get_str16le(sc->pb, len, title, title_len);
            else {
                AV_WB16(title, ch);
                if (len == 1 || len == 2)
4352
                    title[len] = 0;
4353
                else
4354
                    avio_get_str(sc->pb, INT_MAX, title + 2, len - 1);
4355
            }
D
David Conrad 已提交
4356 4357
        }

4358
        avpriv_new_chapter(s, i, st->time_base, sample->timestamp, end, title);
4359
        av_freep(&title);
D
David Conrad 已提交
4360 4361
    }
finish:
A
Anton Khirnov 已提交
4362
    avio_seek(sc->pb, cur_pos, SEEK_SET);
D
David Conrad 已提交
4363 4364
}

4365
static int parse_timecode_in_framenum_format(AVFormatContext *s, AVStream *st,
4366
                                             uint32_t value, int flags)
4367
{
4368 4369 4370 4371 4372 4373 4374
    AVTimecode tc;
    char buf[AV_TIMECODE_STR_SIZE];
    AVRational rate = {st->codec->time_base.den,
                       st->codec->time_base.num};
    int ret = av_timecode_init(&tc, rate, flags, 0, s);
    if (ret < 0)
        return ret;
4375
    av_dict_set(&st->metadata, "timecode",
4376
                av_timecode_make_string(&tc, buf, value), 0);
4377 4378 4379 4380 4381 4382
    return 0;
}

static int mov_read_timecode_track(AVFormatContext *s, AVStream *st)
{
    MOVStreamContext *sc = st->priv_data;
4383
    int flags = 0;
4384 4385 4386 4387 4388 4389 4390 4391 4392
    int64_t cur_pos = avio_tell(sc->pb);
    uint32_t value;

    if (!st->nb_index_entries)
        return -1;

    avio_seek(sc->pb, st->index_entries->pos, SEEK_SET);
    value = avio_rb32(s->pb);

4393 4394 4395 4396
    if (sc->tmcd_flags & 0x0001) flags |= AV_TIMECODE_FLAG_DROPFRAME;
    if (sc->tmcd_flags & 0x0002) flags |= AV_TIMECODE_FLAG_24HOURSMAX;
    if (sc->tmcd_flags & 0x0004) flags |= AV_TIMECODE_FLAG_ALLOWNEGATIVE;

4397 4398 4399 4400 4401
    /* Assume Counter flag is set to 1 in tmcd track (even though it is likely
     * not the case) and thus assume "frame number format" instead of QT one.
     * No sample with tmcd track can be found with a QT timecode at the moment,
     * despite what the tmcd track "suggests" (Counter flag set to 0 means QT
     * format). */
4402
    parse_timecode_in_framenum_format(s, st, value, flags);
4403 4404 4405 4406 4407

    avio_seek(sc->pb, cur_pos, SEEK_SET);
    return 0;
}

4408 4409 4410 4411 4412 4413 4414 4415 4416
static int mov_read_close(AVFormatContext *s)
{
    MOVContext *mov = s->priv_data;
    int i, j;

    for (i = 0; i < s->nb_streams; i++) {
        AVStream *st = s->streams[i];
        MOVStreamContext *sc = st->priv_data;

4417 4418 4419
        if (!sc)
            continue;

4420 4421 4422 4423 4424 4425
        av_freep(&sc->ctts_data);
        for (j = 0; j < sc->drefs_count; j++) {
            av_freep(&sc->drefs[j].path);
            av_freep(&sc->drefs[j].dir);
        }
        av_freep(&sc->drefs);
4426 4427 4428

        sc->drefs_count = 0;

4429
        if (!sc->pb_is_copied)
4430
            avio_closep(&sc->pb);
4431

4432
        sc->pb = NULL;
4433 4434
        av_freep(&sc->chunk_offsets);
        av_freep(&sc->stsc_data);
4435 4436
        av_freep(&sc->sample_sizes);
        av_freep(&sc->keyframes);
4437
        av_freep(&sc->stts_data);
4438
        av_freep(&sc->stps_data);
4439
        av_freep(&sc->elst_data);
4440
        av_freep(&sc->rap_group);
4441
        av_freep(&sc->display_matrix);
4442 4443 4444
    }

    if (mov->dv_demux) {
4445 4446
        avformat_free_context(mov->dv_fctx);
        mov->dv_fctx = NULL;
4447 4448
    }

4449 4450 4451 4452 4453 4454 4455
    if (mov->meta_keys) {
        for (i = 1; i < mov->meta_keys_count; i++) {
            av_freep(&mov->meta_keys[i]);
        }
        av_freep(&mov->meta_keys);
    }

4456
    av_freep(&mov->trex_data);
4457
    av_freep(&mov->bitrates);
4458

4459 4460 4461 4462 4463 4464 4465
    for (i = 0; i < mov->fragment_index_count; i++) {
        MOVFragmentIndex* index = mov->fragment_index_data[i];
        av_freep(&index->items);
        av_freep(&mov->fragment_index_data[i]);
    }
    av_freep(&mov->fragment_index_data);

4466 4467
    av_freep(&mov->aes_decrypt);

4468 4469 4470
    return 0;
}

4471 4472
static int tmcd_is_referenced(AVFormatContext *s, int tmcd_id)
{
4473
    int i;
4474 4475 4476 4477 4478

    for (i = 0; i < s->nb_streams; i++) {
        AVStream *st = s->streams[i];
        MOVStreamContext *sc = st->priv_data;

4479 4480 4481
        if (st->codec->codec_type == AVMEDIA_TYPE_VIDEO &&
            sc->timecode_track == tmcd_id)
            return 1;
4482 4483 4484 4485 4486 4487 4488 4489 4490 4491 4492 4493 4494 4495 4496 4497 4498 4499 4500 4501 4502 4503 4504
    }
    return 0;
}

/* look for a tmcd track not referenced by any video track, and export it globally */
static void export_orphan_timecode(AVFormatContext *s)
{
    int i;

    for (i = 0; i < s->nb_streams; i++) {
        AVStream *st = s->streams[i];

        if (st->codec->codec_tag  == MKTAG('t','m','c','d') &&
            !tmcd_is_referenced(s, i + 1)) {
            AVDictionaryEntry *tcr = av_dict_get(st->metadata, "timecode", NULL, 0);
            if (tcr) {
                av_dict_set(&s->metadata, "timecode", tcr->value, 0);
                break;
            }
        }
    }
}

4505 4506 4507
static int read_tfra(MOVContext *mov, AVIOContext *f)
{
    MOVFragmentIndex* index = NULL;
4508
    int version, fieldlength, i, j;
4509 4510
    int64_t pos = avio_tell(f);
    uint32_t size = avio_rb32(f);
4511 4512
    void *tmp;

4513
    if (avio_rb32(f) != MKBETAG('t', 'f', 'r', 'a')) {
4514
        return 1;
4515 4516 4517 4518 4519 4520
    }
    av_log(mov->fc, AV_LOG_VERBOSE, "found tfra\n");
    index = av_mallocz(sizeof(MOVFragmentIndex));
    if (!index) {
        return AVERROR(ENOMEM);
    }
4521 4522 4523 4524 4525

    tmp = av_realloc_array(mov->fragment_index_data,
                           mov->fragment_index_count + 1,
                           sizeof(MOVFragmentIndex*));
    if (!tmp) {
4526
        av_freep(&index);
4527
        return AVERROR(ENOMEM);
4528
    }
4529 4530
    mov->fragment_index_data = tmp;
    mov->fragment_index_data[mov->fragment_index_count++] = index;
4531 4532 4533 4534 4535 4536

    version = avio_r8(f);
    avio_rb24(f);
    index->track_id = avio_rb32(f);
    fieldlength = avio_rb32(f);
    index->item_count = avio_rb32(f);
4537 4538
    index->items = av_mallocz_array(
            index->item_count, sizeof(MOVFragmentIndexItem));
4539
    if (!index->items) {
4540
        index->item_count = 0;
4541 4542 4543 4544 4545 4546 4547 4548 4549 4550 4551 4552 4553 4554 4555 4556 4557 4558 4559 4560 4561 4562 4563 4564 4565 4566 4567 4568 4569
        return AVERROR(ENOMEM);
    }
    for (i = 0; i < index->item_count; i++) {
        int64_t time, offset;
        if (version == 1) {
            time   = avio_rb64(f);
            offset = avio_rb64(f);
        } else {
            time   = avio_rb32(f);
            offset = avio_rb32(f);
        }
        index->items[i].time = time;
        index->items[i].moof_offset = offset;
        for (j = 0; j < ((fieldlength >> 4) & 3) + 1; j++)
            avio_r8(f);
        for (j = 0; j < ((fieldlength >> 2) & 3) + 1; j++)
            avio_r8(f);
        for (j = 0; j < ((fieldlength >> 0) & 3) + 1; j++)
            avio_r8(f);
    }

    avio_seek(f, pos + size, SEEK_SET);
    return 0;
}

static int mov_read_mfra(MOVContext *c, AVIOContext *f)
{
    int64_t stream_size = avio_size(f);
    int64_t original_pos = avio_tell(f);
4570
    int64_t seek_ret;
4571 4572
    int32_t mfra_size;
    int ret = -1;
4573 4574 4575 4576
    if ((seek_ret = avio_seek(f, stream_size - 4, SEEK_SET)) < 0) {
        ret = seek_ret;
        goto fail;
    }
4577 4578 4579 4580 4581
    mfra_size = avio_rb32(f);
    if (mfra_size < 0 || mfra_size > stream_size) {
        av_log(c->fc, AV_LOG_DEBUG, "doesn't look like mfra (unreasonable size)\n");
        goto fail;
    }
4582 4583 4584 4585
    if ((seek_ret = avio_seek(f, -mfra_size, SEEK_CUR)) < 0) {
        ret = seek_ret;
        goto fail;
    }
4586 4587 4588 4589 4590 4591 4592 4593 4594
    if (avio_rb32(f) != mfra_size) {
        av_log(c->fc, AV_LOG_DEBUG, "doesn't look like mfra (size mismatch)\n");
        goto fail;
    }
    if (avio_rb32(f) != MKBETAG('m', 'f', 'r', 'a')) {
        av_log(c->fc, AV_LOG_DEBUG, "doesn't look like mfra (tag mismatch)\n");
        goto fail;
    }
    av_log(c->fc, AV_LOG_VERBOSE, "stream has mfra\n");
4595 4596 4597 4598 4599 4600
    do {
        ret = read_tfra(c, f);
        if (ret < 0)
            goto fail;
    } while (!ret);
    ret = 0;
4601
fail:
4602 4603
    seek_ret = avio_seek(f, original_pos, SEEK_SET);
    if (seek_ret < 0) {
4604 4605
        av_log(c->fc, AV_LOG_ERROR,
               "failed to seek back after looking for mfra\n");
4606 4607
        ret = seek_ret;
    }
4608 4609 4610
    return ret;
}

4611
static int mov_read_header(AVFormatContext *s)
4612
{
4613
    MOVContext *mov = s->priv_data;
4614
    AVIOContext *pb = s->pb;
4615
    int j, err;
4616
    MOVAtom atom = { AV_RL32("root") };
4617
    int i;
4618 4619

    mov->fc = s;
4620
    /* .mov and .mp4 aren't streamable anyway (only progressive download if moov is before mdat) */
4621
    if (pb->seekable)
A
Anton Khirnov 已提交
4622
        atom.size = avio_size(pb);
4623
    else
B
Baptiste Coudurier 已提交
4624
        atom.size = INT64_MAX;
4625 4626

    /* check MOV header */
4627 4628 4629
    do {
    if (mov->moov_retry)
        avio_seek(pb, 0, SEEK_SET);
B
Baptiste Coudurier 已提交
4630
    if ((err = mov_read_default(mov, pb, atom)) < 0) {
4631
        av_log(s, AV_LOG_ERROR, "error reading header\n");
4632
        mov_read_close(s);
B
Baptiste Coudurier 已提交
4633 4634
        return err;
    }
4635
    } while (pb->seekable && !mov->found_moov && !mov->moov_retry++);
B
Baptiste Coudurier 已提交
4636 4637
    if (!mov->found_moov) {
        av_log(s, AV_LOG_ERROR, "moov atom not found\n");
4638
        mov_read_close(s);
4639
        return AVERROR_INVALIDDATA;
4640
    }
4641
    av_log(mov->fc, AV_LOG_TRACE, "on_parse_exit_offset=%"PRId64"\n", avio_tell(pb));
4642

4643
    if (pb->seekable) {
4644
        if (mov->chapter_track > 0 && !mov->ignore_chapters)
4645 4646 4647 4648 4649
            mov_read_chapters(s);
        for (i = 0; i < s->nb_streams; i++)
            if (s->streams[i]->codec->codec_tag == AV_RL32("tmcd"))
                mov_read_timecode_track(s, s->streams[i]);
    }
D
David Conrad 已提交
4650

4651 4652 4653 4654
    /* copy timecode metadata from tmcd tracks to the related video streams */
    for (i = 0; i < s->nb_streams; i++) {
        AVStream *st = s->streams[i];
        MOVStreamContext *sc = st->priv_data;
4655
        if (sc->timecode_track > 0) {
4656
            AVDictionaryEntry *tcr;
4657
            int tmcd_st_id = -1;
4658

4659 4660 4661 4662
            for (j = 0; j < s->nb_streams; j++)
                if (s->streams[j]->id == sc->timecode_track)
                    tmcd_st_id = j;

4663
            if (tmcd_st_id < 0 || tmcd_st_id == i)
4664 4665 4666 4667 4668 4669
                continue;
            tcr = av_dict_get(s->streams[tmcd_st_id]->metadata, "timecode", NULL, 0);
            if (tcr)
                av_dict_set(&st->metadata, "timecode", tcr->value, 0);
        }
    }
4670
    export_orphan_timecode(s);
4671

4672 4673 4674
    for (i = 0; i < s->nb_streams; i++) {
        AVStream *st = s->streams[i];
        MOVStreamContext *sc = st->priv_data;
4675
        fix_timescale(mov, sc);
4676
        if(st->codec->codec_type == AVMEDIA_TYPE_AUDIO && st->codec->codec_id == AV_CODEC_ID_AAC) {
4677 4678
            st->skip_samples = sc->start_pad;
        }
4679 4680
        if (st->codec->codec_type == AVMEDIA_TYPE_VIDEO && sc->nb_frames_for_fps > 0 && sc->duration_for_fps > 0)
            av_reduce(&st->avg_frame_rate.num, &st->avg_frame_rate.den,
4681
                      sc->time_scale*(int64_t)sc->nb_frames_for_fps, sc->duration_for_fps, INT_MAX);
4682
        if (st->codec->codec_type == AVMEDIA_TYPE_SUBTITLE) {
V
Vittorio Giovara 已提交
4683
            if (st->codec->width <= 0 || st->codec->height <= 0) {
4684 4685 4686
                st->codec->width  = sc->width;
                st->codec->height = sc->height;
            }
4687 4688 4689 4690
            if (st->codec->codec_id == AV_CODEC_ID_DVD_SUBTITLE) {
                if ((err = mov_rewrite_dvd_sub_extradata(st)) < 0)
                    return err;
            }
4691
        }
4692 4693
    }

4694 4695 4696 4697
    if (mov->trex_data) {
        for (i = 0; i < s->nb_streams; i++) {
            AVStream *st = s->streams[i];
            MOVStreamContext *sc = st->priv_data;
4698
            if (st->duration > 0)
4699 4700 4701 4702
                st->codec->bit_rate = sc->data_size * 8 * sc->time_scale / st->duration;
        }
    }

4703 4704 4705 4706 4707 4708 4709 4710 4711 4712 4713
    if (mov->use_mfra_for > 0) {
        for (i = 0; i < s->nb_streams; i++) {
            AVStream *st = s->streams[i];
            MOVStreamContext *sc = st->priv_data;
            if (sc->duration_for_fps > 0) {
                st->codec->bit_rate = sc->data_size * 8 * sc->time_scale /
                    sc->duration_for_fps;
            }
        }
    }

4714 4715 4716 4717 4718 4719
    for (i = 0; i < mov->bitrates_count && i < s->nb_streams; i++) {
        if (mov->bitrates[i]) {
            s->streams[i]->codec->bit_rate = mov->bitrates[i];
        }
    }

4720 4721
    ff_rfps_calculate(s);

4722 4723
    for (i = 0; i < s->nb_streams; i++) {
        AVStream *st = s->streams[i];
4724
        MOVStreamContext *sc = st->priv_data;
4725

4726 4727 4728 4729 4730 4731 4732 4733 4734 4735 4736 4737 4738 4739 4740 4741 4742 4743 4744 4745 4746 4747 4748 4749 4750 4751 4752
        switch (st->codec->codec_type) {
        case AVMEDIA_TYPE_AUDIO:
            err = ff_replaygain_export(st, s->metadata);
            if (err < 0) {
                mov_read_close(s);
                return err;
            }
            break;
        case AVMEDIA_TYPE_VIDEO:
            if (sc->display_matrix) {
                AVPacketSideData *sd, *tmp;

                tmp = av_realloc_array(st->side_data,
                                       st->nb_side_data + 1, sizeof(*tmp));
                if (!tmp)
                    return AVERROR(ENOMEM);

                st->side_data = tmp;
                st->nb_side_data++;

                sd = &st->side_data[st->nb_side_data - 1];
                sd->type = AV_PKT_DATA_DISPLAYMATRIX;
                sd->size = sizeof(int32_t) * 9;
                sd->data = (uint8_t*)sc->display_matrix;
                sc->display_matrix = NULL;
            }
            break;
4753 4754
        }
    }
4755
    ff_configure_buffers_for_index(s, AV_TIME_BASE);
4756

4757 4758 4759
    return 0;
}

4760
static AVIndexEntry *mov_find_next_sample(AVFormatContext *s, AVStream **st)
4761
{
4762
    AVIndexEntry *sample = NULL;
4763
    int64_t best_dts = INT64_MAX;
4764
    int i;
B
Baptiste Coudurier 已提交
4765
    for (i = 0; i < s->nb_streams; i++) {
4766 4767
        AVStream *avst = s->streams[i];
        MOVStreamContext *msc = avst->priv_data;
4768
        if (msc->pb && msc->current_sample < avst->nb_index_entries) {
4769
            AVIndexEntry *current_sample = &avst->index_entries[msc->current_sample];
4770
            int64_t dts = av_rescale(current_sample->timestamp, AV_TIME_BASE, msc->time_scale);
4771
            av_log(s, AV_LOG_TRACE, "stream %d, sample %d, dts %"PRId64"\n", i, msc->current_sample, dts);
4772 4773
            if (!sample || (!s->pb->seekable && current_sample->pos < sample->pos) ||
                (s->pb->seekable &&
4774
                 ((msc->pb != s->pb && dts < best_dts) || (msc->pb == s->pb &&
B
Baptiste Coudurier 已提交
4775
                 ((FFABS(best_dts - dts) <= AV_TIME_BASE && current_sample->pos < sample->pos) ||
4776
                  (FFABS(best_dts - dts) > AV_TIME_BASE && dts < best_dts)))))) {
4777 4778
                sample = current_sample;
                best_dts = dts;
4779
                *st = avst;
4780
            }
4781 4782
        }
    }
4783 4784 4785
    return sample;
}

4786 4787 4788 4789 4790 4791 4792
static int should_retry(AVIOContext *pb, int error_code) {
    if (error_code == AVERROR_EOF || avio_feof(pb))
        return 0;

    return 1;
}

4793 4794 4795 4796 4797 4798 4799 4800 4801 4802 4803 4804 4805 4806 4807 4808 4809 4810 4811 4812 4813 4814 4815 4816 4817 4818 4819 4820 4821 4822 4823 4824 4825 4826 4827 4828 4829 4830 4831 4832 4833 4834 4835 4836 4837 4838
static int mov_switch_root(AVFormatContext *s, int64_t target)
{
    MOVContext *mov = s->priv_data;
    int i, j;
    int already_read = 0;

    if (avio_seek(s->pb, target, SEEK_SET) != target) {
        av_log(mov->fc, AV_LOG_ERROR, "root atom offset 0x%"PRIx64": partial file\n", target);
        return AVERROR_INVALIDDATA;
    }

    mov->next_root_atom = 0;

    for (i = 0; i < mov->fragment_index_count; i++) {
        MOVFragmentIndex *index = mov->fragment_index_data[i];
        int found = 0;
        for (j = 0; j < index->item_count; j++) {
            MOVFragmentIndexItem *item = &index->items[j];
            if (found) {
                mov->next_root_atom = item->moof_offset;
                break; // Advance to next index in outer loop
            } else if (item->moof_offset == target) {
                index->current_item = FFMIN(j, index->current_item);
                if (item->headers_read)
                    already_read = 1;
                item->headers_read = 1;
                found = 1;
            }
        }
        if (!found)
            index->current_item = 0;
    }

    if (already_read)
        return 0;

    mov->found_mdat = 0;

    if (mov_read_default(mov, s->pb, (MOVAtom){ AV_RL32("root"), INT64_MAX }) < 0 ||
        avio_feof(s->pb))
        return AVERROR_EOF;
    av_log(s, AV_LOG_TRACE, "read fragments, offset 0x%"PRIx64"\n", avio_tell(s->pb));

    return 1;
}

4839 4840 4841 4842 4843 4844 4845
static int mov_read_packet(AVFormatContext *s, AVPacket *pkt)
{
    MOVContext *mov = s->priv_data;
    MOVStreamContext *sc;
    AVIndexEntry *sample;
    AVStream *st = NULL;
    int ret;
4846
    mov->fc = s;
4847 4848
 retry:
    sample = mov_find_next_sample(s, &st);
4849
    if (!sample || (mov->next_root_atom && sample->pos > mov->next_root_atom)) {
4850 4851
        if (!mov->next_root_atom)
            return AVERROR_EOF;
4852 4853
        if ((ret = mov_switch_root(s, mov->next_root_atom)) < 0)
            return ret;
4854 4855
        goto retry;
    }
4856
    sc = st->priv_data;
4857 4858
    /* must be done just before reading, to avoid infinite loop on sample */
    sc->current_sample++;
4859

4860 4861 4862 4863 4864
    if (mov->next_root_atom) {
        sample->pos = FFMIN(sample->pos, mov->next_root_atom);
        sample->size = FFMIN(sample->size, (mov->next_root_atom - sample->pos));
    }

4865
    if (st->discard != AVDISCARD_ALL) {
4866 4867
        int64_t ret64 = avio_seek(sc->pb, sample->pos, SEEK_SET);
        if (ret64 != sample->pos) {
R
Reimar Döffinger 已提交
4868 4869
            av_log(mov->fc, AV_LOG_ERROR, "stream %d, offset 0x%"PRIx64": partial file\n",
                   sc->ffindex, sample->pos);
4870
            sc->current_sample -= should_retry(sc->pb, ret64);
4871
            return AVERROR_INVALIDDATA;
R
Reimar Döffinger 已提交
4872 4873
        }
        ret = av_get_packet(sc->pb, pkt, sample->size);
4874 4875
        if (ret < 0) {
            sc->current_sample -= should_retry(sc->pb, ret);
4876
            return ret;
4877
        }
4878 4879 4880 4881 4882 4883 4884 4885 4886 4887 4888
        if (sc->has_palette) {
            uint8_t *pal;

            pal = av_packet_new_side_data(pkt, AV_PKT_DATA_PALETTE, AVPALETTE_SIZE);
            if (!pal) {
                av_log(mov->fc, AV_LOG_ERROR, "Cannot append palette to packet\n");
            } else {
                memcpy(pal, sc->palette, AVPALETTE_SIZE);
                sc->has_palette = 0;
            }
        }
R
Reimar Döffinger 已提交
4889 4890
#if CONFIG_DV_DEMUXER
        if (mov->dv_demux && sc->dv_audio_container) {
4891
            avpriv_dv_produce_packet(mov->dv_demux, pkt, pkt->data, pkt->size, pkt->pos);
4892
            av_freep(&pkt->data);
R
Reimar Döffinger 已提交
4893
            pkt->size = 0;
4894
            ret = avpriv_dv_get_packet(mov->dv_demux, pkt);
R
Reimar Döffinger 已提交
4895 4896 4897
            if (ret < 0)
                return ret;
        }
4898
#endif
4899 4900
    }

4901
    pkt->stream_index = sc->ffindex;
4902
    pkt->dts = sample->timestamp;
4903
    if (sc->ctts_data && sc->ctts_index < sc->ctts_count) {
4904
        pkt->pts = pkt->dts + sc->dts_shift + sc->ctts_data[sc->ctts_index].duration;
4905
        /* update ctts context */
4906 4907 4908 4909 4910
        sc->ctts_sample++;
        if (sc->ctts_index < sc->ctts_count &&
            sc->ctts_data[sc->ctts_index].count == sc->ctts_sample) {
            sc->ctts_index++;
            sc->ctts_sample = 0;
4911
        }
4912 4913
        if (sc->wrong_dts)
            pkt->dts = AV_NOPTS_VALUE;
4914
    } else {
4915
        int64_t next_dts = (sc->current_sample < st->nb_index_entries) ?
4916 4917
            st->index_entries[sc->current_sample].timestamp : st->duration;
        pkt->duration = next_dts - pkt->dts;
4918
        pkt->pts = pkt->dts;
4919
    }
4920 4921
    if (st->discard == AVDISCARD_ALL)
        goto retry;
4922
    pkt->flags |= sample->flags & AVINDEX_KEYFRAME ? AV_PKT_FLAG_KEY : 0;
4923
    pkt->pos = sample->pos;
4924

4925 4926 4927
    if (mov->aax_mode)
        aax_filter(pkt->data, pkt->size, mov);

4928 4929
    return 0;
}
4930

4931 4932 4933 4934 4935 4936 4937 4938 4939 4940
static int mov_seek_fragment(AVFormatContext *s, AVStream *st, int64_t timestamp)
{
    MOVContext *mov = s->priv_data;
    int i, j;

    if (!mov->fragment_index_complete)
        return 0;

    for (i = 0; i < mov->fragment_index_count; i++) {
        if (mov->fragment_index_data[i]->track_id == st->id) {
4941
            MOVFragmentIndex *index = mov->fragment_index_data[i];
4942 4943 4944 4945 4946 4947 4948 4949 4950 4951 4952 4953 4954 4955
            for (j = index->item_count - 1; j >= 0; j--) {
                if (index->items[j].time <= timestamp) {
                    if (index->items[j].headers_read)
                        return 0;

                    return mov_switch_root(s, index->items[j].moof_offset);
                }
            }
        }
    }

    return 0;
}

4956
static int mov_seek_stream(AVFormatContext *s, AVStream *st, int64_t timestamp, int flags)
4957 4958 4959 4960
{
    MOVStreamContext *sc = st->priv_data;
    int sample, time_sample;
    int i;
4961

4962 4963 4964 4965
    int ret = mov_seek_fragment(s, st, timestamp);
    if (ret < 0)
        return ret;

4966
    sample = av_index_search_timestamp(st, timestamp, flags);
4967
    av_log(s, AV_LOG_TRACE, "stream %d, timestamp %"PRId64", sample %d\n", st->index, timestamp, sample);
4968 4969
    if (sample < 0 && st->nb_index_entries && timestamp < st->index_entries[0].timestamp)
        sample = 0;
4970
    if (sample < 0) /* not sure what to do */
4971
        return AVERROR_INVALIDDATA;
4972
    sc->current_sample = sample;
4973
    av_log(s, AV_LOG_TRACE, "stream %d, found sample %d\n", st->index, sc->current_sample);
4974 4975 4976 4977
    /* adjust ctts index */
    if (sc->ctts_data) {
        time_sample = 0;
        for (i = 0; i < sc->ctts_count; i++) {
4978 4979
            int next = time_sample + sc->ctts_data[i].count;
            if (next > sc->current_sample) {
4980 4981
                sc->ctts_index = i;
                sc->ctts_sample = sc->current_sample - time_sample;
4982
                break;
4983
            }
4984
            time_sample = next;
4985 4986
        }
    }
4987
    return sample;
4988 4989
}

4990
static int mov_read_seek(AVFormatContext *s, int stream_index, int64_t sample_time, int flags)
G
Gael Chardon 已提交
4991
{
4992
    MOVContext *mc = s->priv_data;
4993 4994 4995
    AVStream *st;
    int sample;
    int i;
G
Gael Chardon 已提交
4996

4997
    if (stream_index >= s->nb_streams)
4998
        return AVERROR_INVALIDDATA;
G
Gael Chardon 已提交
4999

5000
    st = s->streams[stream_index];
5001
    sample = mov_seek_stream(s, st, sample_time, flags);
5002
    if (sample < 0)
5003
        return sample;
G
Gael Chardon 已提交
5004

5005 5006 5007
    if (mc->seek_individually) {
        /* adjust seek timestamp to found sample timestamp */
        int64_t seek_timestamp = st->index_entries[sample].timestamp;
G
Gael Chardon 已提交
5008

5009 5010 5011 5012 5013
        for (i = 0; i < s->nb_streams; i++) {
            int64_t timestamp;
            MOVStreamContext *sc = s->streams[i]->priv_data;
            st = s->streams[i];
            st->skip_samples = (sample_time <= 0) ? sc->start_pad : 0;
5014

5015 5016
            if (stream_index == i)
                continue;
G
Gael Chardon 已提交
5017

5018 5019 5020 5021 5022 5023 5024 5025 5026 5027 5028 5029 5030 5031 5032 5033 5034 5035 5036 5037
            timestamp = av_rescale_q(seek_timestamp, s->streams[stream_index]->time_base, st->time_base);
            mov_seek_stream(s, st, timestamp, flags);
        }
    } else {
        for (i = 0; i < s->nb_streams; i++) {
            MOVStreamContext *sc;
            st = s->streams[i];
            sc = st->priv_data;
            sc->current_sample = 0;
        }
        while (1) {
            MOVStreamContext *sc;
            AVIndexEntry *entry = mov_find_next_sample(s, &st);
            if (!entry)
                return AVERROR_INVALIDDATA;
            sc = st->priv_data;
            if (sc->ffindex == stream_index && sc->current_sample == sample)
                break;
            sc->current_sample++;
        }
5038
    }
G
Gael Chardon 已提交
5039 5040 5041
    return 0;
}

5042 5043 5044
#define OFFSET(x) offsetof(MOVContext, x)
#define FLAGS AV_OPT_FLAG_VIDEO_PARAM | AV_OPT_FLAG_DECODING_PARAM
static const AVOption mov_options[] = {
5045 5046
    {"use_absolute_path",
        "allow using absolute path when opening alias, this is a possible security issue",
5047
        OFFSET(use_absolute_path), AV_OPT_TYPE_BOOL, {.i64 = 0},
5048
        0, 1, FLAGS},
5049 5050
    {"seek_streams_individually",
        "Seek each stream individually to the to the closest point",
5051
        OFFSET(seek_individually), AV_OPT_TYPE_BOOL, { .i64 = 1 },
5052
        0, 1, FLAGS},
5053
    {"ignore_editlist", "", OFFSET(ignore_editlist), AV_OPT_TYPE_BOOL, {.i64 = 0},
5054
        0, 1, FLAGS},
5055 5056
    {"ignore_chapters", "", OFFSET(ignore_chapters), AV_OPT_TYPE_BOOL, {.i64 = 0},
        0, 1, FLAGS},
5057 5058
    {"use_mfra_for",
        "use mfra for fragment timestamps",
5059
        OFFSET(use_mfra_for), AV_OPT_TYPE_INT, {.i64 = FF_MOV_FLAG_MFRA_AUTO},
5060
        -1, FF_MOV_FLAG_MFRA_PTS, FLAGS,
5061
        "use_mfra_for"},
5062
    {"auto", "auto", 0, AV_OPT_TYPE_CONST, {.i64 = FF_MOV_FLAG_MFRA_AUTO}, 0, 0,
5063
        FLAGS, "use_mfra_for" },
5064
    {"dts", "dts", 0, AV_OPT_TYPE_CONST, {.i64 = FF_MOV_FLAG_MFRA_DTS}, 0, 0,
5065
        FLAGS, "use_mfra_for" },
5066
    {"pts", "pts", 0, AV_OPT_TYPE_CONST, {.i64 = FF_MOV_FLAG_MFRA_PTS}, 0, 0,
5067
        FLAGS, "use_mfra_for" },
5068
    { "export_all", "Export unrecognized metadata entries", OFFSET(export_all),
5069
        AV_OPT_TYPE_BOOL, { .i64 = 0 }, 0, 1, .flags = FLAGS },
5070
    { "export_xmp", "Export full XMP metadata", OFFSET(export_xmp),
5071
        AV_OPT_TYPE_BOOL, { .i64 = 0 }, 0, 1, .flags = FLAGS },
5072 5073 5074 5075 5076 5077
    { "activation_bytes", "Secret bytes for Audible AAX files", OFFSET(activation_bytes),
        AV_OPT_TYPE_BINARY, .flags = AV_OPT_FLAG_DECODING_PARAM },
    { "audible_fixed_key", // extracted from libAAX_SDK.so and AAXSDKWin.dll files!
        "Fixed key used for handling Audible AAX files", OFFSET(audible_fixed_key),
        AV_OPT_TYPE_BINARY, {.str="77214d4b196a87cd520045fd20a51d67"},
        .flags = AV_OPT_FLAG_DECODING_PARAM },
5078
    { NULL },
5079 5080
};

5081
static const AVClass mov_class = {
5082 5083
    .class_name = "mov,mp4,m4a,3gp,3g2,mj2",
    .item_name  = av_default_item_name,
5084
    .option     = mov_options,
5085 5086
    .version    = LIBAVUTIL_VERSION_INT,
};
5087

5088
AVInputFormat ff_mov_demuxer = {
5089
    .name           = "mov,mp4,m4a,3gp,3g2,mj2",
5090
    .long_name      = NULL_IF_CONFIG_SMALL("QuickTime / MOV"),
5091
    .priv_class     = &mov_class,
5092
    .priv_data_size = sizeof(MOVContext),
5093
    .extensions     = "mov,mp4,m4a,3gp,3g2,mj2",
5094 5095 5096 5097 5098
    .read_probe     = mov_probe,
    .read_header    = mov_read_header,
    .read_packet    = mov_read_packet,
    .read_close     = mov_read_close,
    .read_seek      = mov_read_seek,
5099
    .flags          = AVFMT_NO_BYTE_SEEK,
5100
};