From 72f9a6349cae0eba7caf9e338bee46c1d9baed27 Mon Sep 17 00:00:00 2001 From: Bryan Huh Date: Sun, 8 Nov 2015 16:35:01 -0800 Subject: [PATCH] avformat/cache: Avoid int-overflow in cache compare function cache protocol indexes its cache using AVTreeNodes which require a cmp function for inserting and searching new cache-entries. This cmp function expects a 32-bit int return value (negative, zero, or positive) but the cache cmp function returns an int64_t which can overflow the int, giving negative numbers for when it should be positive, vice versa. This manifests itself only for very large files (e.g. 4GB+) Signed-off-by: Michael Niedermayer --- libavformat/cache.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/libavformat/cache.c b/libavformat/cache.c index 31f63e6b18..d41161d498 100644 --- a/libavformat/cache.c +++ b/libavformat/cache.c @@ -67,7 +67,7 @@ typedef struct Context { static int cmp(const void *key, const void *node) { - return (*(const int64_t *) key) - ((const CacheEntry *) node)->logical_pos; + return FFDIFFSIGN(*(const int64_t *)key, ((const CacheEntry *) node)->logical_pos); } static int cache_open(URLContext *h, const char *arg, int flags, AVDictionary **options)