yading@11: /* yading@11: * MMS protocol common definitions. yading@11: * Copyright (c) 2006,2007 Ryan Martell yading@11: * Copyright (c) 2007 Björn Axelsson yading@11: * Copyright (c) 2010 Zhentan Feng yading@11: * yading@11: * This file is part of FFmpeg. yading@11: * yading@11: * FFmpeg is free software; you can redistribute it and/or yading@11: * modify it under the terms of the GNU Lesser General Public yading@11: * License as published by the Free Software Foundation; either yading@11: * version 2.1 of the License, or (at your option) any later version. yading@11: * yading@11: * FFmpeg is distributed in the hope that it will be useful, yading@11: * but WITHOUT ANY WARRANTY; without even the implied warranty of yading@11: * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU yading@11: * Lesser General Public License for more details. yading@11: * yading@11: * You should have received a copy of the GNU Lesser General Public yading@11: * License along with FFmpeg; if not, write to the Free Software yading@11: * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA yading@11: */ yading@11: #include "mms.h" yading@11: #include "asf.h" yading@11: #include "libavutil/intreadwrite.h" yading@11: yading@11: #define MMS_MAX_STREAMS 256 /**< arbitrary sanity check value */ yading@11: yading@11: int ff_mms_read_header(MMSContext *mms, uint8_t *buf, const int size) yading@11: { yading@11: char *pos; yading@11: int size_to_copy; yading@11: int remaining_size = mms->asf_header_size - mms->asf_header_read_size; yading@11: size_to_copy = FFMIN(size, remaining_size); yading@11: pos = mms->asf_header + mms->asf_header_read_size; yading@11: memcpy(buf, pos, size_to_copy); yading@11: if (mms->asf_header_read_size == mms->asf_header_size) { yading@11: av_freep(&mms->asf_header); // which contains asf header yading@11: } yading@11: mms->asf_header_read_size += size_to_copy; yading@11: return size_to_copy; yading@11: } yading@11: yading@11: int ff_mms_read_data(MMSContext *mms, uint8_t *buf, const int size) yading@11: { yading@11: int read_size; yading@11: read_size = FFMIN(size, mms->remaining_in_len); yading@11: memcpy(buf, mms->read_in_ptr, read_size); yading@11: mms->remaining_in_len -= read_size; yading@11: mms->read_in_ptr += read_size; yading@11: return read_size; yading@11: } yading@11: yading@11: int ff_mms_asf_header_parser(MMSContext *mms) yading@11: { yading@11: uint8_t *p = mms->asf_header; yading@11: uint8_t *end; yading@11: int flags, stream_id; yading@11: mms->stream_num = 0; yading@11: yading@11: if (mms->asf_header_size < sizeof(ff_asf_guid) * 2 + 22 || yading@11: memcmp(p, ff_asf_header, sizeof(ff_asf_guid))) { yading@11: av_log(NULL, AV_LOG_ERROR, yading@11: "Corrupt stream (invalid ASF header, size=%d)\n", yading@11: mms->asf_header_size); yading@11: return AVERROR_INVALIDDATA; yading@11: } yading@11: yading@11: end = mms->asf_header + mms->asf_header_size; yading@11: yading@11: p += sizeof(ff_asf_guid) + 14; yading@11: while(end - p >= sizeof(ff_asf_guid) + 8) { yading@11: uint64_t chunksize; yading@11: if (!memcmp(p, ff_asf_data_header, sizeof(ff_asf_guid))) { yading@11: chunksize = 50; // see Reference [2] section 5.1 yading@11: } else { yading@11: chunksize = AV_RL64(p + sizeof(ff_asf_guid)); yading@11: } yading@11: if (!chunksize || chunksize > end - p) { yading@11: av_log(NULL, AV_LOG_ERROR, yading@11: "Corrupt stream (header chunksize %"PRId64" is invalid)\n", yading@11: chunksize); yading@11: return AVERROR_INVALIDDATA; yading@11: } yading@11: if (!memcmp(p, ff_asf_file_header, sizeof(ff_asf_guid))) { yading@11: /* read packet size */ yading@11: if (end - p > sizeof(ff_asf_guid) * 2 + 68) { yading@11: mms->asf_packet_len = AV_RL32(p + sizeof(ff_asf_guid) * 2 + 64); yading@11: if (mms->asf_packet_len <= 0 || mms->asf_packet_len > sizeof(mms->in_buffer)) { yading@11: av_log(NULL, AV_LOG_ERROR, yading@11: "Corrupt stream (too large pkt_len %d)\n", yading@11: mms->asf_packet_len); yading@11: return AVERROR_INVALIDDATA; yading@11: } yading@11: } yading@11: } else if (!memcmp(p, ff_asf_stream_header, sizeof(ff_asf_guid))) { yading@11: flags = AV_RL16(p + sizeof(ff_asf_guid)*3 + 24); yading@11: stream_id = flags & 0x7F; yading@11: //The second condition is for checking CS_PKT_STREAM_ID_REQUEST packet size, yading@11: //we can calcuate the packet size by stream_num. yading@11: //Please see function send_stream_selection_request(). yading@11: if (mms->stream_num < MMS_MAX_STREAMS && yading@11: 46 + mms->stream_num * 6 < sizeof(mms->out_buffer)) { yading@11: mms->streams = av_fast_realloc(mms->streams, yading@11: &mms->nb_streams_allocated, yading@11: (mms->stream_num + 1) * sizeof(MMSStream)); yading@11: mms->streams[mms->stream_num].id = stream_id; yading@11: mms->stream_num++; yading@11: } else { yading@11: av_log(NULL, AV_LOG_ERROR, yading@11: "Corrupt stream (too many A/V streams)\n"); yading@11: return AVERROR_INVALIDDATA; yading@11: } yading@11: } else if (!memcmp(p, ff_asf_ext_stream_header, sizeof(ff_asf_guid))) { yading@11: if (end - p >= 88) { yading@11: int stream_count = AV_RL16(p + 84), ext_len_count = AV_RL16(p + 86); yading@11: uint64_t skip_bytes = 88; yading@11: while (stream_count--) { yading@11: if (end - p < skip_bytes + 4) { yading@11: av_log(NULL, AV_LOG_ERROR, yading@11: "Corrupt stream (next stream name length is not in the buffer)\n"); yading@11: return AVERROR_INVALIDDATA; yading@11: } yading@11: skip_bytes += 4 + AV_RL16(p + skip_bytes + 2); yading@11: } yading@11: while (ext_len_count--) { yading@11: if (end - p < skip_bytes + 22) { yading@11: av_log(NULL, AV_LOG_ERROR, yading@11: "Corrupt stream (next extension system info length is not in the buffer)\n"); yading@11: return AVERROR_INVALIDDATA; yading@11: } yading@11: skip_bytes += 22 + AV_RL32(p + skip_bytes + 18); yading@11: } yading@11: if (end - p < skip_bytes) { yading@11: av_log(NULL, AV_LOG_ERROR, yading@11: "Corrupt stream (the last extension system info length is invalid)\n"); yading@11: return AVERROR_INVALIDDATA; yading@11: } yading@11: if (chunksize - skip_bytes > 24) yading@11: chunksize = skip_bytes; yading@11: } yading@11: } else if (!memcmp(p, ff_asf_head1_guid, sizeof(ff_asf_guid))) { yading@11: chunksize = 46; // see references [2] section 3.4. This should be set 46. yading@11: } yading@11: p += chunksize; yading@11: } yading@11: yading@11: return 0; yading@11: }