Skip to content

Update module github.com/Eyevinn/mp4ff to v0.57.0 - #108

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/github.com-eyevinn-mp4ff-0.x
Oct 6, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/github.com-eyevinn-mp4ff-0.x

Conversation

@renovate

@renovate renovate Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
github.com/Eyevinn/mp4ff v0.56.0 → v0.57.0 age confidence

Release Notes

Eyevinn/mp4ff (github.com/Eyevinn/mp4ff)

v0.57.0

Compare Source

Added
  • saiz versions 1 and 2 (16- and 32-bit sizes, ISO/IEC 14496-12:2026) are
    decoded and encoded, and SaizBox.AddSampleInfo picks the lowest version
    that fits, so samples with more than 39 subsamples can be encrypted.
    GenerateFtyp adds the saie brand for them and CheckBrands checks it

  • Constants for ftyp/styp brands from ISOBMFF, MP4, CMAF, DASH and codec
    specifications (mp4.BrandIso6, mp4.BrandCmfc, mp4.BrandLmsg, ...), and
    HasCompatibleBrand on FtypBox and StypBox

  • InitSegment.GenerateFtyp, InitSegment.SetFtyp and
    MediaSegment.GenerateStyp set ftyp/styp brands from the content: lowest
    isoN brand, codec brands, CMAF brands, and DASH msdh/msix/lmsg

  • File.CheckBrands reports ftyp/styp brands that the content contradicts or
    that miss spec recommendations, as BrandIssue errors and warnings, also
    available as mp4ff-info -brands

  • Experimental paint-model subtitle boxes: stpc/wvtc sample entries, and
    ttmn/vttn (no change) and ttmb (TTML body only) samples, also handled
    by mp4ff-subslister. The 4CCs are unregistered and may change

  • Fragment.AppendFullSamples, TrunBox.AppendFullSamples,
    SampleAccessor.AppendSamples and AppendSampleRange extract samples into
    caller-provided storage, so reused slices avoid allocation. Implementations
    of SampleAccessor outside mp4ff must add the two methods

  • Fragment.Samples iterates over the full samples of a track without
    allocating

  • hevc.ParseSPSNALUnitWithVPS parses an SPS with a map of the VPSs it may
    refer to, so that a multilayer extension SPS gets the chroma format, picture
    size, conformance window and bit depths that it does not signal itself
    inherited from the rep_format() of its VPS. hevc.ParseSPSNALUnit is
    unchanged and leaves those values unset, since the SPS payload can be parsed
    without them

  • hevc.SPS exposes NuhLayerID, ExtOrMaxSubLayersMinus1,
    MultiLayerExtSpsFlag, UpdateRepFormatFlag, SpsRepFormatIdx,
    InferScalingListFlag and ScalingListRefLayerID, and hevc.RepFormat
    exposes SeparateColourPlaneFlag, ConformanceWindowFlag and
    ConformanceWindow

  • RsotBox for the Redundant Sample Original Timing Box (rsot) of
    ISO/IEC 14496-12:2026 Section 8.8.18, a traf child that documents that the
    first sample of a track fragment is a copy of the previous sample and how long
    that sample has already run (ElapsedDuration), and that the fragment's last
    sample was truncated to fit and how long it was meant to last
    (OriginalDuration). Either duration may be signalled on its own, and
    CreateRsotBox sets the flags from the non-zero arguments. It is reachable as
    TrafBox.Rsot

  • AudioSampleEntryBox.NormalizeQuickTime rewrites a QuickTime-shaped audio
    sample entry (sound sample description version 1 or 2, QuickTime residue in
    the version 0 reserved fields, or a wave-wrapped esds) to the plain ISO
    version 0 form with the esds as a direct child. Entries without a reachable
    esds, and wave boxes holding anything besides their recognized decoder-init
    atoms, are left untouched

  • CloneBox returns a deep copy of a box (via an encode/decode round trip),
    so a box tree that shares parts with another structure can be mutated
    safely — for example handing InitProtect (which rewrites the stsd sample
    entry in place) an init segment built from a cached, shared trak

  • Fragment.AddFullSamples adds many samples to a fragment at once. Adjacent
    sample slices (such as the output of GetFullSamples) are coalesced into
    runs that are added as mdat data parts, so the payload is never copied and
    contiguous input becomes a single part. Any data already in the mdat is
    closed into a part first, so samples can be added before or after with
    AddFullSample. Since the samples are referenced rather than copied, their
    buffers must be kept alive and unmodified until the fragment is encoded. The
    output is byte-identical to adding the samples one by one with
    AddFullSample

  • mp4.Defragment and mp4.DefragmentTracks convert a fragmented file to a
    progressive one: sample tables (stts, ctts, stsc, stsz, stss, stco/co64)
    are synthesized from the fragment metadata while sample data and sample
    descriptions are preserved. Every track is rebased so that its first tfdt
    becomes media time zero, edit-list media times are shifted along, a final
    edit with zero segment duration (open-ended in a fragmented file, where the
    movie duration is unknown) is resolved to the remaining media duration so
    progressive readers do not apply it as a zero-length edit, and a track
    starting later than the earliest one keeps its presentation alignment
    through an empty edit; a trivial identity edit list is dropped.
    The output ftyp has major brand mp42, the lowest isoN brand the output
    needs, the codec brands, and the ISO/IEC 14496-15 brands of the input. Per-sample encryption auxiliary information (senc or
    saiz/saio; constant-IV full-sample encryption without such data passes
    through losslessly), unsupported edit lists, zero timescales, truncated
    byte ranges, and payloads larger than the input file are rejected

  • mp4.Defragment and mp4.DefragmentTracks resolve overlapping fragments:
    when a fragment's tfdt re-declares an earlier decode time (a
    retransmission), the fragment appearing later in the file wins and the
    superseded samples are dropped at sample granularity, whether or not the
    re-sent bytes are identical. Every abandoned time range must be declared
    again by surviving fragments, so no declared content is ever silently
    dropped. Ambiguous overlaps fail closed: cuts inside a sample, abandoned
    time ranges that no surviving later fragment declares again, and
    overlapping files whose fragments use absolute base data offsets are
    rejected

  • mp4.Defragment and mp4.DefragmentTracks accept hybrid files that carry
    progressive samples in the moov before the first fragment: the progressive
    samples come first with their chunk structure preserved (also when stco
    offsets are not monotone), and the fragment samples are appended.
    Fragments may supersede progressive samples under the same
    later-declarer-wins and coverage rules as fragment overlaps, and hostile
    sample tables are validated before any count-proportional allocation

  • SttsBox.SampleDurations, CttsBox.CompositionTimeOffsets, and
    StssBox.SampleIsSync expand a whole sample table into one value per
    sample, validating the entries against the declared sample count

  • mp4ff-defragment command line tool exposing the defragmentation with
    optional track selection

Changed
  • SaizBox.DefaultSampleInfoSize is a uint32 and SaizBox.SampleInfo a
    []uint32, to hold the sizes of saiz versions 1 and 2
  • CreateFtyp gives cmfc + [cmfc, iso6] and CreateStyp gives
    cmfs + [cmfs, cmff, cmfl, msdh]: the major brand is repeated and dash is dropped
  • Minimum Go version bumped from 1.19 to 1.23, for slices and iter
  • The commands and examples that create their own output file now buffer their
    writes, like WriteToFile already does. Encode makes about one write call
    per box, so writing straight to a file cost a syscall per box: affects
    mp4ff-encrypt, mp4ff-decrypt, mp4ff-crop, mp4ff-mvhevc and the
    add-sidx, combine-segs, initcreator, ivf-to-mp4, resegmenter and
    segmenter examples. Output bytes are unchanged
  • New package documentation section "Writing files and segments efficiently"
    covering when to use a buffered Encode and when a reused
    bits.FixedSliceWriter with EncodeSW is better
  • WriteToFile buffers its output instead of writing straight to the file.
    The many small boxes of a moof cost one write syscall each without it, while
    a large mdat payload is unaffected, since a write larger than the buffer goes
    directly to the file. Output bytes are unchanged
  • SttsBox.GetDecodeTime returns an error instead of panicking with index out
    of range when the stts entries cover fewer samples than the requested sample
    number (a file whose stts and stsz disagree), or when called with sampleNr 0.
    Signature change: GetDecodeTime(sampleNr uint32) (decTime uint64, dur uint32)
    → GetDecodeTime(sampleNr uint32) (decTime uint64, dur uint32, err error).
    SttsBox.GetSampleNrAtTime returns an error instead of panicking for an
    stts box without entries
  • TrunBox.GetFullSamples returns an error when the trun-declared sample
    sizes point outside the mdat data (a truncated or corrupt file), instead
    of panicking with index out of range. Signature change:
    GetFullSamples(...) []FullSample → GetFullSamples(...) ([]FullSample, error).
    Fragment.GetFullSamples (unchanged signature) propagates the error
  • StscBox.GetChunk returns an error instead of panicking for chunk numbers
    that no stsc entry covers. Signature change:
    GetChunk(chunkNr uint32) Chunk → GetChunk(chunkNr uint32) (Chunk, error)
  • Sample-table decode (stsz, stts, ctts, stco, co64, stss) bulk-reads
    each table with one slice-reader call instead of one call per entry, roughly
    halving moov parse time for long progressive files
  • Fragment encryption and decryption expand the AES key once per run instead
    of once per sample (cenc) or per protected subsample range (cbcs), making
    fragment encryption roughly 40% (cenc) / 18% (cbcs) faster. A bad key
    length is now reported by NewFragmentEncryptor instead of by the first
    sample encryption
Fixed
  • CreateEmptyTrak/AddEmptyTrack pick the media header from the handler
    type: subt, stpp and clcp tracks get sthd, and stpp gets handler subt
  • The streaming SampleAccessor.GetSample, GetSampleRange and GetSamples
    allocated the sample size a trun claimed before checking it against the mdat
  • Invalid NALU length sizes are rejected: the 3-byte size in lhvC and vvcC,
    anything but 1, 2 or 4 bytes when encoding hvcC, lhvC and vvcC
    (ErrInvalidLengthSize), and differing lhvC and hvcC sizes in a sample
    entry. mp4ff-nallister rejects VVC tracks without 4-byte lengths
  • hevc.SplitNalusByLayerID panicked on 32-bit platforms for a length field of
    2^31 or more
  • DecodeSgpd/DecodeSgpdSR did not bound the per-entry description_length
    against the bytes left in the sgpd box, and the sample group entry
    decoders size their slices from it. A 32-byte box declaring
    description_length = 0xfffffff0 for an alst entry allocated 4GB in
    DecodeAlstSampleGroupEntry. The length is now checked against what is left
    of the box before the entry is decoded
  • avc.ParsePPSNALUnit skipped the six 4x4 picture scaling lists when
    pic_scaling_matrix_present_flag was set but transform_8x8_mode_flag was
    not, since the read loop was nested inside the 8x8 mode check. The lists are
    always present when a picture scaling matrix is signalled; only the two or
    six extra 8x8 lists depend on 8x8 mode, so such a PPS misparsed
    second_chroma_qp_index_offset and then failed the trailing-bits check. As a
    consequence, chroma_format_idc from the SPS is now only looked up when 8x8
    mode makes the list count depend on it, so a PPS whose SPS is not in the map
    no longer fails in the cases where the SPS is not needed
  • HEVC slice header and PPS parsing accepted num_ref_idx_l0_active_minus1,
    num_ref_idx_l1_active_minus1 and their PPS defaults outside the range 0 to
    14 that the spec allows. The values were stored in a uint8 without a check,
    so a stream declaring 255 made parsePredWeightTable allocate a
    zero-length slice while its loop guard still ran, and parsing panicked with
    an index out of range. All four read sites now check the bound and return an
    error naming the syntax element, its value and the legal range
  • hevc.ParseSPSNALUnit misparsed a non-base-layer SPS that uses the
    multilayer extension form, as MV-HEVC and SHVC enhancement layers do. Such an
    SPS signals sps_ext_or_max_sub_layers_minus1 instead of
    sps_max_sub_layers_minus1 and then omits profile_tier_level(), the chroma
    format, the picture size, the conformance window and the bit depths, and it
    carries sps_infer_scaling_list_flag. The parser always took the base-layer
    branch, so it read those absent fields from the following bits and typically
    failed with EOF. nuh_layer_id is now taken from the NAL unit header and
    the two forms are parsed accordingly
  • rep_format() in the VPS extension dropped separate_colour_plane_vps_flag
    and the conformance window, and left the chroma format and bit depths unset
    for a rep_format() with chroma_and_bit_depth_vps_present_flag equal to
    zero instead of inferring them from the preceding one
  • DecodeContainerChildren and DecodeContainerChildrenSR reported a wrapped
    parent size for a box too small to hold the fixed fields before its children,
    as dref, stsd, trep and meta can be. Such a box is now rejected up
    front, naming the declared and the minimum size
  • DecodeEsdsSR derived its descriptor size from hdr.Size-12 without a length
    check, wrapping for a shorter box. Both the check and the size now measure the
    payload, which is also correct for an extended-size header
  • DecodeContainerChildren now checks the child position against the
    container end before decoding each child, matching
    DecodeContainerChildrenSR. A container truncated exactly on a child
    boundary is reported instead of silently decoding short, and an empty
    container box no longer consumes its next sibling
  • ftyp and styp boxes with a payload shorter than 8 bytes are rejected at
    decode instead of panicking. MajorBrand and MinorVersion slice the payload
    at fixed offsets, so a short box made Info panic, including in mp4ff-info
  • IsSyncSampleFlags only inspected sample_depends_on and ignored
    sample_is_non_sync_sample, so flags that mark a sample non-sync while also
    saying sample_depends_on = 2 were reported as a sync sample. It now
    requires both indications to agree, like Sample.IsSync always has, and no
    longer accepts the reserved sample_depends_on = 3. Sample.IsSync is
    unchanged in behaviour and now delegates to it, so the two cannot drift
    apart again
  • The mdat payload is now the concatenation of its data parts and its
    monolithic data, so the two can be combined in any order and are written in
    the order they were added. Adding a part on top of monolithic data no longer
    panics with "cannot mix sample parts with monolithic sample data", and data
    added with AddSampleData on top of data parts is no longer silently
    dropped at encode time, which produced a fragment whose trun declared
    samples that were never written. MdatBox.SetData replaces the whole
    payload and so now also drops any data parts
  • NewSdtpEntry packed the sampleDependedOn argument into both two-bit
    dependency fields and dropped sampleDependsOn, so every entry it built
    carried a wrong sample_depends_on value. Note that entries built with the
    broken constructor re-encode byte-identically; only newly constructed
    entries change
  • TrakBox.GetSampleData indexed its result slice with the absolute sample
    number instead of the offset within the requested interval, panicking with
    index out of range for any interval not starting at sample 1
  • TrunBox.GetSampleInterval (and thereby Fragment.GetSampleInterval)
    returns an error instead of panicking when the requested interval points
    outside the mdat data
  • File.CopySampleData returns an error instead of panicking when a chunk
    offset or sample size in the sample tables points outside the mdat data.
    This is the progressive-file counterpart of the fragmented trun case
  • MdatBox.ReadData and MdatBox.CopyData rejected valid ranges ending at
    the very end of the mdat payload, so reading the last sample (or the full
    payload) failed with "invalid range provided". They now also reject a start
    before the mdat payload, which previously underflowed and panicked
  • mp4ff-nallister, mp4ff-pslister and mp4ff-subslister panicked instead
    of reporting an error on a progressive file with sample tables pointing
    outside the mdat data
  • CttsBox.GetCompositionTimeOffset panicked for a sample beyond the entries
    of the box, which a file with a ctts and stsz that disagree on the sample
    count triggers. Such a sample now gets composition time offset 0
  • TrakBox.GetSampleData panicked for an sdtp with fewer entries than the
    track has samples. The sample flags from a missing sdtp entry are now left
    at their default
  • StscBox.GetContainingChunks and StscBox.ChunkNrFromSampleNr panicked
    with index out of range for an stsc without entries (which is valid, and
    what init segments have) and divided by zero for an entry with
    samplesPerChunk == 0. Both now return an error
  • StscBox.GetSampleDescriptionID and StszBox.GetSampleSize indexed outside
    their tables for out-of-range chunk and sample numbers
  • StszBox.GetTotalSampleSize validated the sample interval against
    SampleNumber but indexed SampleSize, so a box where the two disagree
    panicked
  • mp4ff-crop panicked on a file whose ctts, stts, stsc or stsz does not
    cover all samples of the track, and reported only the last of several
    cropping errors
  • CryptSampleCenc, DecryptSampleCbcs and EncryptSampleCbcs panicked for
    subsample patterns whose byte counts reach outside the sample. Nothing ties
    the senc byte counts to the actual sample sizes, and big counts could also
    wrap in uint32. They now return an error
  • DecryptFragment and DecryptFragmentWithKeys panicked when the senc box
    held subsample information for a different number of samples than the trun
    declares
  • The nalu scanning functions in the avc and hevc packages trusted the
    4-byte nalu length fields of a sample, so a bad length field made them slice
    outside the sample and panic. A length field close to 2^32 also wrapped when
    added to the position, which defeated the check in avc.GetNalusFromSample
    and in GetAVCProtectRanges/GetHEVCProtectRanges. Affected are
    FindNaluTypes, FindNaluTypesUpToFirstVideoNALU/...Nalu,
    ContainsNaluType, IsIDRSample, IsRAPSample, HasParameterSets,
    GetParameterSets, GetNalusFromSample and ConvertSampleToByteStream
  • avc.ContainsNaluType (and thereby avc.IsIDRSample) lacked the guard
    against samples shorter than 4 bytes that the other scanning functions have,
    so the loop limit underflowed and the first read went outside the sample
  • DecodeStssSR and DecodeSttsSR returned a zero-filled table and no error
    when the reader held fewer bytes than the declared entry count; all
    sample-table decoders now report truncated input as an error, before
    allocating the table

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot enabled auto-merge (squash) October 6, 2026 10:50
@renovate
renovate Bot merged commit 8393459 into main Oct 6, 2026
10 checks passed
@renovate
renovate Bot deleted the renovate/github.com-eyevinn-mp4ff-0.x branch October 6, 2026 10:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants