- Add HBD typedefs and function pointer arrays to codec_t in ihevcd_structs.h
- Add HBD function pointers to func_selector_t in ihevcd_function_selector.h
- Initialize generic HBD function pointers in ihevcd_function_selector_generic.c
- Invoke ihevcd_init_function_ptr_generic in ARM and x86 function selectors
QP can be negative in HBD path.
- Change pu1_pic_qp and pu1_qp to WORD8 type
- Rename pu1_pic_qp and pu1_qp to pi1_pic_qp and pi1_qp
- Update offset accesses to pi1_qp and pi1_pic_qp across deblocking,
boundary strength, and slice parsing
When parsing PPS in ihevcd_parse_pps(), the scratch buffer
ps_codec->s_parse.ps_pps_base + MAX_PPS_CNT - 1 was not reset to zero,
unlike ihevcd_parse_sps(). In streams with concatenated sequences where
an earlier sequence set pps_extension_present_flag and range extension
flags, subsequent sequences without PPS extensions would retain the stale
flags. This caused the parser to attempt reading non-existent range
extension syntax, leading to bitstream parsing failure.
- In ihevcd_parse_pps(), reset the scratch PPS structure to zero upon
entry while preserving pi2_scaling_mat and ps_tile pointers.
- In both ihevcd_parse_pps() and ihevcd_parse_sps(), explicitly zero all
extension flags when pps_extension_present_flag / sps_extension_present_flag
is 0.
Test: ./hevc_dec_tests
TAG=agy
CONV=476d1054-10ff-4f19-88d5-a1c8dae7b57f
(cherry picked from commit 4bf5819c62)
In ihevcd_copy_slice_hdr(), copying the previous slice header for dependent
slices copied i2_ctb_x and i2_ctb_y. If parsing was aborted or delayed,
the incomplete slice header retained the previous slice's coordinates,
causing concurrent worker threads in ihevcd_slice_hdr_update() to prematurely
switch to the invalid slice header. Reset i2_ctb_x and i2_ctb_y to -1
after copying.
In ihevcd_parse_slice_header(), initialize i2_ctb_x and i2_ctb_y to -1
immediately following memset so that slices rejected prior to coordinate
parsing do not retain valid-looking (0, 0) coordinates.
In ihevcd_parse_pic_init(), only skip reinitializing slice header 1 if
the first slice was missing in the current picture.
Test: ./hevc_dec_tests
Test: ./hevc_dec_fuzzer /work/misc/oss-fuzz/build/out/libhevc/crash-b74b07ae377d7450614e4534c86155d1d2999e13
TAG=agy
CONV=cfdfe257-7362-41c9-b5be-18261f1c6a3d
ihevcd_parse_sei() truncated the declared SEI payload size to the bytes
remaining with MIN() instead of rejecting it. The payload parsers do not
consult that size, so ihevcd_parse_mastering_disp_params_sei() read its
full 24-byte structure out of a one-byte payload and ran past the end of
the bitstream buffer.
When parsing SEI payloads before any valid SPS has been decoded,
ihevcd_parse_sei_payload scanned ps_codec->ps_sps_base using a loop
that could step past the array bounds and dereference an invalid pointer.
Initialize ps_sps to NULL, check each entry's validity within bounds,
and return safely if no valid SPS is present.
- For CTB size 16 in 4:2:2, sub-block width is 0, causing the Top
and Current SAO blocks to be skipped.
- Fix Top-Right neighbor in Left block to read from picture buffer
when ctb_size == 16 and ctb_y != 0, while keeping line buffer for
larger CTBs (32, 64).
- Fix Bottom-Left neighbor in Left block to read from picture buffer
when ctb_size == 16 to avoid uninitialized backup buffer access.
- Generalize Top-Left block condition to (8 * v_samp_factor).
Test: ./hevcdec
Change-Id: I013e44e024258f2f84690fdc0109210129042245
- In 4:2:2 chroma format, transform blocks are partitioned into
two square sub-TUs (subtu_idx == 0 and subtu_idx == 1).
- Fix neighbor availability bitfield mapping for sub-TU 0 and sub-TU 1
based on trans_size (8, 16, 32).
- Add reference documentation from ITU-T H.265 Section 7.3.8.8 and
Section 8.4.4.2.2.
Test: ./hevcdec
Change-Id: I013e44e024258f2f84690fdc0109201129042155
Earlier condition was correctly hardcoded for 420 with
luma ctb size as 16. Updated the condition to scale for
other chroma factors with vert, and horz subsample factor.
Change-Id: I013e67e024258f2f84690fdcc01b4cd52f0fac52
With SIMD optimizations updated and enabled for 422 and 444 chroma formats,
the fallback override in ihevcd_init_function_ptr_rext_generic is no longer
necessary.
Test: ./build
Remove generic C overrides for chroma and luma intra prediction in ihevcd_init_function_ptr_rext_generic to allow architecture-specific assembly and SIMD intrinsics to be used during 422 and 444 decoding.
Previously, when 422 or 444 chroma formats were encountered, all
function pointers were overridden to generic C implementations due to
lack of support in optimized assemblies/intrinsics for certain
components.
This change introduces `ihevcd_init_function_ptr_rext` which:
- First initializes all function pointers with architecture-optimized
versions.
- Explicitly overrides only the components not yet optimized for 422/444 formats (intra prediction, SAO, deblocking and chroma padding) to point
back to their C implementations.
This allows other fully-compatible modules (e.g: inter prediction modes, transform/reconstruction, format conversion) to benefit from SIMD
optimizations on 422/444 formats without degrading YUV 420 decoding.
Test: ./hevcdec
Change-Id: I013e44e024258f2f84690fdc0109200129042145
- disable_boundary_filter flag was not reset within the TU loop. This
caused the flag to remain sticky at 1 for all subsequent TUs in the
CTB once set by any TU.
- Transform-skip blocks larger than 4x4, the scaling/dequantization
matrix is bypassed and the scaling factor is set to a constant of 16
as per HEVC specification section 8.6.3.
- Bypassing the inverse transform for transform-skip blocks requires
applying a scaling of tsShift (Rec. ITU-T H.265 Section 8.6.2
Eq 8-296: tsShift = 5 + log2_trans_size) and descaling of bdShift
(Eq 8-295: bdShift = 20 - bit_depth).
Net shift: shift_ts = bdShift - tsShift
(20 - bit_depth) - (5 + log2_trans_size)
15 - bit_depth - log2_trans_size.
Test: ./hevcdec
Change-Id: I40411c04ab00d7e23842eb1d033c4543e4ec75e9
For clips with chroma format idc 444/422 and output format selected to
420, after decoding during chroma sampling conversion from 444/422 to
420, neighbor filtering is done currently. This is updated to area.
Test: ./hevcdec
Change-Id: I024886655084051093858c5c40a94c0373c64813
According to the ITU Specs (9.3.3.11) the statCoeff for
persistent rice adaptation must only be updated when the
parsing of coeff_abs_level_remaining is actually triggered.
Earlier, the i1_update_stats was incorrectly placed outside,
resulting stateCoeff getting incorrectly updated for the
first coefficient of every sub-block, and corrupting it.
Test: ./hevcdec
Change-Id: I7535ced74c18f55a7aff31d1c6d6d68f4a28f2cd
Bypass wrappers functions for memcpy and memset, calling standard
C library functions directly. This allows _FORTIFY_SOURCE to
perform compile-time safety checks.
Bug: 514722372
Test: ./hevcdec
Change-Id: Id9faf0919ecedfd1833d40a7fbf6ddac454628b4
For 16x16 CTB sizes in chroma processing, au4_idx_tl[5] and
au4_idx_tl[6] can be set to -1 at picture boundaries. Added guards to
check that the index is valid (> idx_tl) before dereferencing the slice
header list.
Bug: 516422427
Test: ./hevc_dec_fuzzer
Change-Id: I40411c04ab00d7e23843eb1d033c6953e3ec76e9
Corrected the static SAO buffer size calculation to match the
partitioned buffer bounds. Luma requires 4x and Chroma requires 8x
MAX_CTB_SIZE * MAX_CTB_SIZE, which is now correctly summed to allocate
12x MAX_CTB_SIZE * MAX_CTB_SIZE bytes per process thread.
Bug: 484436016
Test: ./hevc_dec_fuzzer
Change-Id: I40411c04ab00d7e23843eb1d033d4943e3ec76a9
- reduce unused memory allocations
- revert unrequired alignments done to widths and height in format
conversion leaf functions
- pass correct strides and base address to leaf functions
fixes oss-fuzz-520748344
Change-Id: I8b783d1dae8c53b68a6d3a32dbc3ffb16376851e
Reverted some of the unnecessary changes from commit: f6ef16b0f9
- Restored the format conversion structure prior to f6ef16b0f9
- No need to handle odd stride for 420 and 422 output.
- Dimensions for output format 444 and 400 format can be odd
Tested with few YUV444 and YUV400 odd dimension clips
To generate:
$ ffmpeg -f lavfi -i testsrc=s=511x511 -c:v libx265 -pix_fmt yuv444p -t 1 -tag:v hvc1 y444_511x511.hevc
$ ffmpeg -f lavfi -i testsrc=s=511x511 -c:v libx265 -pix_fmt gray -t 1 -tag:v hvc1 y400_511x511.hevc
To decode using hevcdec for YUV420 output format
$ hevcdec -i y444_511x511.hevc -o y444_511x511.yuv --save_output 1 --num_frames -1 --chroma_format YUV_420P --enable_yuv_format 31
$ hevcdec -i y400_511x511.hevc -o y400_511x511.yuv --save_output 1 --num_frames -1 --chroma_format YUV_420P --enable_yuv_format 31
To decode using hevcdec for YUV444 output format
$ hevcdec -i y444_511x511.hevc -o y444_511x511.yuv --save_output 1 --num_frames -1 --chroma_format YUV_444P --enable_yuv_format 31
To decode using hevcdec for YUV400 output format
$ hevcdec -i y400_511x511.hevc -o y400_511x511.yuv --save_output 1 --num_frames -1 --chroma_format GRAY --enable_yuv_format 31
Display resulting output using ffplay by passing `-f rawvideo -pixel_format yuv420p -video_size 511x511`
Change pixel_format to yuv420p/yuv444p/gray based on decoder chroma_format argument
Decoding streams with odd resolutions previously caused integer truncation
during right-shift or division operations, leading to incorrect buffer size
and stride calculations.
This is fixed by applying the ALIGN2 macro to width and height across buffer
metrics, dimension queries, and outargs to safely pad boundaries.
Test: ./hevcdec
Change-Id: I5c432aa63b0975b76baa5e59a816278087b65215
Apply 0xAAAAAAAA mask for vertical chroma deblocking on YUV422 and YUV444.
Apply 0xAAAAAAAA mask for horizontal chroma deblocking on YUV444.
Add array indexing shifts for YUV422/YUV444 when log2_ctb_size != 6.
Test: ./hevcdec
Change-Id: I40411c04ab00d7e23843eb1d033c5943e3ec75e9
- Deleted ihevcd_sao_ctb implementation and declaration.
- Removed code under #else of SAO_PROCESS_SHIFT_CTB in ihevcd_process_slice.c.
- Removed code under #if FRAME_ILF_PAD and simplified checks assuming FRAME_ILF_PAD is 0.
- Deleted ihevcd_ilf_padding.c and removed it from Android.bp and libhevcdec.cmake.
- Removed SAO_PROCESS_SHIFT_CTB definition in ihevcd_defs.h.
- Removed FRAME_ILF_PAD definition in ihevcd_defs.h.
TAG=agy
CONV=ceba65ba-1766-4f4d-84f0-f7c3804a90fe
The function was processing all rows of chroma, while 420p only requires half the rows.
This caused an OOB write when writing to the destination buffer.
Fixed by skipping every other row of source chroma.
TAG=agy
Bug: ossfuzz:515832483
CONV=731dcda4-96d6-4402-b14c-f727e9983c85