Repository navigation
Update module github.com/Eyevinn/mp4ff to v0.57.0 - #108
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v0.56.0→v0.57.0Release Notes
Eyevinn/mp4ff (github.com/Eyevinn/mp4ff)
v0.57.0Compare Source
Added
saizversions 1 and 2 (16- and 32-bit sizes, ISO/IEC 14496-12:2026) aredecoded and encoded, and
SaizBox.AddSampleInfopicks the lowest versionthat fits, so samples with more than 39 subsamples can be encrypted.
GenerateFtypadds thesaiebrand for them andCheckBrandschecks itConstants for
ftyp/stypbrands from ISOBMFF, MP4, CMAF, DASH and codecspecifications (
mp4.BrandIso6,mp4.BrandCmfc,mp4.BrandLmsg, ...), andHasCompatibleBrandonFtypBoxandStypBoxInitSegment.GenerateFtyp,InitSegment.SetFtypandMediaSegment.GenerateStypset ftyp/styp brands from the content: lowestisoN brand, codec brands, CMAF brands, and DASH
msdh/msix/lmsgFile.CheckBrandsreports ftyp/styp brands that the content contradicts orthat miss spec recommendations, as
BrandIssueerrors and warnings, alsoavailable as
mp4ff-info -brandsExperimental paint-model subtitle boxes:
stpc/wvtcsample entries, andttmn/vttn(no change) andttmb(TTML body only) samples, also handledby
mp4ff-subslister. The 4CCs are unregistered and may changeFragment.AppendFullSamples,TrunBox.AppendFullSamples,SampleAccessor.AppendSamplesandAppendSampleRangeextract samples intocaller-provided storage, so reused slices avoid allocation. Implementations
of
SampleAccessoroutside mp4ff must add the two methodsFragment.Samplesiterates over the full samples of a track withoutallocating
hevc.ParseSPSNALUnitWithVPSparses an SPS with a map of the VPSs it mayrefer to, so that a multilayer extension SPS gets the chroma format, picture
size, conformance window and bit depths that it does not signal itself
inherited from the
rep_format()of its VPS.hevc.ParseSPSNALUnitisunchanged and leaves those values unset, since the SPS payload can be parsed
without them
hevc.SPSexposesNuhLayerID,ExtOrMaxSubLayersMinus1,MultiLayerExtSpsFlag,UpdateRepFormatFlag,SpsRepFormatIdx,InferScalingListFlagandScalingListRefLayerID, andhevc.RepFormatexposes
SeparateColourPlaneFlag,ConformanceWindowFlagandConformanceWindowRsotBoxfor the Redundant Sample Original Timing Box (rsot) ofISO/IEC 14496-12:2026 Section 8.8.18, a
trafchild that documents that thefirst sample of a track fragment is a copy of the previous sample and how long
that sample has already run (
ElapsedDuration), and that the fragment's lastsample was truncated to fit and how long it was meant to last
(
OriginalDuration). Either duration may be signalled on its own, andCreateRsotBoxsets the flags from the non-zero arguments. It is reachable asTrafBox.RsotAudioSampleEntryBox.NormalizeQuickTimerewrites a QuickTime-shaped audiosample entry (sound sample description version 1 or 2, QuickTime residue in
the version 0 reserved fields, or a wave-wrapped esds) to the plain ISO
version 0 form with the esds as a direct child. Entries without a reachable
esds, and wave boxes holding anything besides their recognized decoder-init
atoms, are left untouched
CloneBoxreturns a deep copy of a box (via an encode/decode round trip),so a box tree that shares parts with another structure can be mutated
safely — for example handing
InitProtect(which rewrites the stsd sampleentry in place) an init segment built from a cached, shared trak
Fragment.AddFullSamplesadds many samples to a fragment at once. Adjacentsample slices (such as the output of
GetFullSamples) are coalesced intoruns that are added as mdat data parts, so the payload is never copied and
contiguous input becomes a single part. Any data already in the mdat is
closed into a part first, so samples can be added before or after with
AddFullSample. Since the samples are referenced rather than copied, theirbuffers must be kept alive and unmodified until the fragment is encoded. The
output is byte-identical to adding the samples one by one with
AddFullSamplemp4.Defragmentandmp4.DefragmentTracksconvert a fragmented file to aprogressive one: sample tables (stts, ctts, stsc, stsz, stss, stco/co64)
are synthesized from the fragment metadata while sample data and sample
descriptions are preserved. Every track is rebased so that its first tfdt
becomes media time zero, edit-list media times are shifted along, a final
edit with zero segment duration (open-ended in a fragmented file, where the
movie duration is unknown) is resolved to the remaining media duration so
progressive readers do not apply it as a zero-length edit, and a track
starting later than the earliest one keeps its presentation alignment
through an empty edit; a trivial identity edit list is dropped.
The output ftyp has major brand mp42, the lowest isoN brand the output
needs, the codec brands, and the ISO/IEC 14496-15 brands of the input. Per-sample encryption auxiliary information (senc or
saiz/saio; constant-IV full-sample encryption without such data passes
through losslessly), unsupported edit lists, zero timescales, truncated
byte ranges, and payloads larger than the input file are rejected
mp4.Defragmentandmp4.DefragmentTracksresolve overlapping fragments:when a fragment's tfdt re-declares an earlier decode time (a
retransmission), the fragment appearing later in the file wins and the
superseded samples are dropped at sample granularity, whether or not the
re-sent bytes are identical. Every abandoned time range must be declared
again by surviving fragments, so no declared content is ever silently
dropped. Ambiguous overlaps fail closed: cuts inside a sample, abandoned
time ranges that no surviving later fragment declares again, and
overlapping files whose fragments use absolute base data offsets are
rejected
mp4.Defragmentandmp4.DefragmentTracksaccept hybrid files that carryprogressive samples in the moov before the first fragment: the progressive
samples come first with their chunk structure preserved (also when stco
offsets are not monotone), and the fragment samples are appended.
Fragments may supersede progressive samples under the same
later-declarer-wins and coverage rules as fragment overlaps, and hostile
sample tables are validated before any count-proportional allocation
SttsBox.SampleDurations,CttsBox.CompositionTimeOffsets, andStssBox.SampleIsSyncexpand a whole sample table into one value persample, validating the entries against the declared sample count
mp4ff-defragmentcommand line tool exposing the defragmentation withoptional track selection
Changed
SaizBox.DefaultSampleInfoSizeis auint32andSaizBox.SampleInfoa[]uint32, to hold the sizes of saiz versions 1 and 2CreateFtypgivescmfc+[cmfc, iso6]andCreateStypgivescmfs+[cmfs, cmff, cmfl, msdh]: the major brand is repeated anddashis droppedslicesanditerwrites, like
WriteToFilealready does.Encodemakes about one write callper box, so writing straight to a file cost a syscall per box: affects
mp4ff-encrypt,mp4ff-decrypt,mp4ff-crop,mp4ff-mvhevcand theadd-sidx,combine-segs,initcreator,ivf-to-mp4,resegmenterandsegmenterexamples. Output bytes are unchangedcovering when to use a buffered
Encodeand when a reusedbits.FixedSliceWriterwithEncodeSWis betterWriteToFilebuffers its output instead of writing straight to the file.The many small boxes of a moof cost one write syscall each without it, while
a large mdat payload is unaffected, since a write larger than the buffer goes
directly to the file. Output bytes are unchanged
SttsBox.GetDecodeTimereturns an error instead of panicking with index outof range when the stts entries cover fewer samples than the requested sample
number (a file whose stts and stsz disagree), or when called with sampleNr 0.
Signature change:
GetDecodeTime(sampleNr uint32) (decTime uint64, dur uint32)→
GetDecodeTime(sampleNr uint32) (decTime uint64, dur uint32, err error).SttsBox.GetSampleNrAtTimereturns an error instead of panicking for anstts box without entries
TrunBox.GetFullSamplesreturns an error when the trun-declared samplesizes point outside the mdat data (a truncated or corrupt file), instead
of panicking with index out of range. Signature change:
GetFullSamples(...) []FullSample→GetFullSamples(...) ([]FullSample, error).Fragment.GetFullSamples(unchanged signature) propagates the errorStscBox.GetChunkreturns an error instead of panicking for chunk numbersthat no stsc entry covers. Signature change:
GetChunk(chunkNr uint32) Chunk→GetChunk(chunkNr uint32) (Chunk, error)stsz,stts,ctts,stco,co64,stss) bulk-readseach table with one slice-reader call instead of one call per entry, roughly
halving moov parse time for long progressive files
of once per sample (cenc) or per protected subsample range (cbcs), making
fragment encryption roughly 40% (cenc) / 18% (cbcs) faster. A bad key
length is now reported by
NewFragmentEncryptorinstead of by the firstsample encryption
Fixed
CreateEmptyTrak/AddEmptyTrackpick the media header from the handlertype:
subt,stppandclcptracks getsthd, andstppgets handlersubtSampleAccessor.GetSample,GetSampleRangeandGetSamplesallocated the sample size a trun claimed before checking it against the mdat
anything but 1, 2 or 4 bytes when encoding hvcC, lhvC and vvcC
(
ErrInvalidLengthSize), and differing lhvC and hvcC sizes in a sampleentry.
mp4ff-nallisterrejects VVC tracks without 4-byte lengthshevc.SplitNalusByLayerIDpanicked on 32-bit platforms for a length field of2^31 or more
DecodeSgpd/DecodeSgpdSRdid not bound the per-entrydescription_lengthagainst the bytes left in the
sgpdbox, and the sample group entrydecoders size their slices from it. A 32-byte box declaring
description_length = 0xfffffff0for analstentry allocated 4GB inDecodeAlstSampleGroupEntry. The length is now checked against what is leftof the box before the entry is decoded
avc.ParsePPSNALUnitskipped the six 4x4 picture scaling lists whenpic_scaling_matrix_present_flagwas set buttransform_8x8_mode_flagwasnot, since the read loop was nested inside the 8x8 mode check. The lists are
always present when a picture scaling matrix is signalled; only the two or
six extra 8x8 lists depend on 8x8 mode, so such a PPS misparsed
second_chroma_qp_index_offsetand then failed the trailing-bits check. As aconsequence,
chroma_format_idcfrom the SPS is now only looked up when 8x8mode makes the list count depend on it, so a PPS whose SPS is not in the map
no longer fails in the cases where the SPS is not needed
num_ref_idx_l0_active_minus1,num_ref_idx_l1_active_minus1and their PPS defaults outside the range 0 to14 that the spec allows. The values were stored in a
uint8without a check,so a stream declaring 255 made
parsePredWeightTableallocate azero-length slice while its loop guard still ran, and parsing panicked with
an index out of range. All four read sites now check the bound and return an
error naming the syntax element, its value and the legal range
hevc.ParseSPSNALUnitmisparsed a non-base-layer SPS that uses themultilayer extension form, as MV-HEVC and SHVC enhancement layers do. Such an
SPS signals
sps_ext_or_max_sub_layers_minus1instead ofsps_max_sub_layers_minus1and then omitsprofile_tier_level(), the chromaformat, the picture size, the conformance window and the bit depths, and it
carries
sps_infer_scaling_list_flag. The parser always took the base-layerbranch, so it read those absent fields from the following bits and typically
failed with
EOF.nuh_layer_idis now taken from the NAL unit header andthe two forms are parsed accordingly
rep_format()in the VPS extension droppedseparate_colour_plane_vps_flagand the conformance window, and left the chroma format and bit depths unset
for a
rep_format()withchroma_and_bit_depth_vps_present_flagequal tozero instead of inferring them from the preceding one
DecodeContainerChildrenandDecodeContainerChildrenSRreported a wrappedparent size for a box too small to hold the fixed fields before its children,
as
dref,stsd,trepandmetacan be. Such a box is now rejected upfront, naming the declared and the minimum size
DecodeEsdsSRderived its descriptor size fromhdr.Size-12without a lengthcheck, wrapping for a shorter box. Both the check and the size now measure the
payload, which is also correct for an extended-size header
DecodeContainerChildrennow checks the child position against thecontainer end before decoding each child, matching
DecodeContainerChildrenSR. A container truncated exactly on a childboundary is reported instead of silently decoding short, and an empty
container box no longer consumes its next sibling
ftypandstypboxes with a payload shorter than 8 bytes are rejected atdecode instead of panicking.
MajorBrandandMinorVersionslice the payloadat fixed offsets, so a short box made
Infopanic, including inmp4ff-infoIsSyncSampleFlagsonly inspectedsample_depends_onand ignoredsample_is_non_sync_sample, so flags that mark a sample non-sync while alsosaying
sample_depends_on = 2were reported as a sync sample. It nowrequires both indications to agree, like
Sample.IsSyncalways has, and nolonger accepts the reserved
sample_depends_on = 3.Sample.IsSyncisunchanged in behaviour and now delegates to it, so the two cannot drift
apart again
monolithic data, so the two can be combined in any order and are written in
the order they were added. Adding a part on top of monolithic data no longer
panics with "cannot mix sample parts with monolithic sample data", and data
added with
AddSampleDataon top of data parts is no longer silentlydropped at encode time, which produced a fragment whose trun declared
samples that were never written.
MdatBox.SetDatareplaces the wholepayload and so now also drops any data parts
NewSdtpEntrypacked thesampleDependedOnargument into both two-bitdependency fields and dropped
sampleDependsOn, so every entry it builtcarried a wrong sample_depends_on value. Note that entries built with the
broken constructor re-encode byte-identically; only newly constructed
entries change
TrakBox.GetSampleDataindexed its result slice with the absolute samplenumber instead of the offset within the requested interval, panicking with
index out of range for any interval not starting at sample 1
TrunBox.GetSampleInterval(and therebyFragment.GetSampleInterval)returns an error instead of panicking when the requested interval points
outside the mdat data
File.CopySampleDatareturns an error instead of panicking when a chunkoffset or sample size in the sample tables points outside the mdat data.
This is the progressive-file counterpart of the fragmented
truncaseMdatBox.ReadDataandMdatBox.CopyDatarejected valid ranges ending atthe very end of the mdat payload, so reading the last sample (or the full
payload) failed with "invalid range provided". They now also reject a start
before the mdat payload, which previously underflowed and panicked
mp4ff-nallister,mp4ff-pslisterandmp4ff-subslisterpanicked insteadof reporting an error on a progressive file with sample tables pointing
outside the mdat data
CttsBox.GetCompositionTimeOffsetpanicked for a sample beyond the entriesof the box, which a file with a ctts and stsz that disagree on the sample
count triggers. Such a sample now gets composition time offset 0
TrakBox.GetSampleDatapanicked for an sdtp with fewer entries than thetrack has samples. The sample flags from a missing sdtp entry are now left
at their default
StscBox.GetContainingChunksandStscBox.ChunkNrFromSampleNrpanickedwith index out of range for an stsc without entries (which is valid, and
what init segments have) and divided by zero for an entry with
samplesPerChunk == 0. Both now return an error
StscBox.GetSampleDescriptionIDandStszBox.GetSampleSizeindexed outsidetheir tables for out-of-range chunk and sample numbers
StszBox.GetTotalSampleSizevalidated the sample interval againstSampleNumberbut indexedSampleSize, so a box where the two disagreepanicked
mp4ff-croppanicked on a file whose ctts, stts, stsc or stsz does notcover all samples of the track, and reported only the last of several
cropping errors
CryptSampleCenc,DecryptSampleCbcsandEncryptSampleCbcspanicked forsubsample patterns whose byte counts reach outside the sample. Nothing ties
the senc byte counts to the actual sample sizes, and big counts could also
wrap in uint32. They now return an error
DecryptFragmentandDecryptFragmentWithKeyspanicked when the senc boxheld subsample information for a different number of samples than the trun
declares
avcandhevcpackages trusted the4-byte nalu length fields of a sample, so a bad length field made them slice
outside the sample and panic. A length field close to 2^32 also wrapped when
added to the position, which defeated the check in
avc.GetNalusFromSampleand in
GetAVCProtectRanges/GetHEVCProtectRanges. Affected areFindNaluTypes,FindNaluTypesUpToFirstVideoNALU/...Nalu,ContainsNaluType,IsIDRSample,IsRAPSample,HasParameterSets,GetParameterSets,GetNalusFromSampleandConvertSampleToByteStreamavc.ContainsNaluType(and therebyavc.IsIDRSample) lacked the guardagainst samples shorter than 4 bytes that the other scanning functions have,
so the loop limit underflowed and the first read went outside the sample
DecodeStssSRandDecodeSttsSRreturned a zero-filled table and no errorwhen the reader held fewer bytes than the declared entry count; all
sample-table decoders now report truncated input as an error, before
allocating the table
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.