aboutsummaryrefslogtreecommitdiffstats
path: root/libAACdec
diff options
context:
space:
mode:
authorFraunhofer IIS FDK <audio-fdk@iis.fraunhofer.de>2019-09-20 13:58:23 +0200
committerJean-Michel Trivi <jmtrivi@google.com>2019-10-15 15:47:53 -0700
commit40d2a1d8b055ebe17b67195029029ecdc5bc3268 (patch)
tree2fe4f64364ba0261f1417474d2df66a3d9d9f8dd /libAACdec
parentf0e1e3f8c7f835a0faf259ef21a51b55e2cec1f3 (diff)
downloadfdk-aac-40d2a1d8b055ebe17b67195029029ecdc5bc3268.tar.gz
fdk-aac-40d2a1d8b055ebe17b67195029029ecdc5bc3268.tar.bz2
fdk-aac-40d2a1d8b055ebe17b67195029029ecdc5bc3268.zip
Avoid integer overflows with pseudoLR in CAacDecoder_DecodeFrame().
Bug: 131430997 Test: atest DecoderTestXheAac ; atest DecoderTestAacDrc Change-Id: I5c83d72b5c0f4cd1569b648f102c8c549a7a6ac2
Diffstat (limited to 'libAACdec')
-rw-r--r--libAACdec/src/aacdecoder.cpp14
1 files changed, 9 insertions, 5 deletions
diff --git a/libAACdec/src/aacdecoder.cpp b/libAACdec/src/aacdecoder.cpp
index b15fc80..6b5a86c 100644
--- a/libAACdec/src/aacdecoder.cpp
+++ b/libAACdec/src/aacdecoder.cpp
@@ -3388,7 +3388,8 @@ LINKSPEC_CPP AAC_DECODER_ERROR CAacDecoder_DecodeFrame(
* LR) */
if ((aacChannels == 2) && bsPseudoLr) {
int i, offset2;
- const FIXP_SGL invSqrt2 = FL2FXCONST_SGL(0.707106781186547f);
+ const FIXP_SGL invSqrt2 =
+ FL2FXCONST_SGL(0.353553390593273f); /* scaled by -1 */
FIXP_PCM *pTD = pTimeData;
offset2 = timeDataChannelOffset;
@@ -3399,11 +3400,14 @@ LINKSPEC_CPP AAC_DECODER_ERROR CAacDecoder_DecodeFrame(
L = fMult(L, invSqrt2);
R = fMult(R, invSqrt2);
#if (SAMPLE_BITS == 16)
- pTD[0] = FX_DBL2FX_PCM(fAddSaturate(L + R, (FIXP_DBL)0x8000));
- pTD[offset2] = FX_DBL2FX_PCM(fAddSaturate(L - R, (FIXP_DBL)0x8000));
+ pTD[0] = (FIXP_SGL)SATURATE_RIGHT_SHIFT(L + R + (FIXP_DBL)(1 << 14),
+ 15, FRACT_BITS);
+ pTD[offset2] = (FIXP_SGL)SATURATE_RIGHT_SHIFT(
+ L - R + (FIXP_DBL)(1 << 14), 15, FRACT_BITS);
#else
- pTD[0] = FX_DBL2FX_PCM(L + R);
- pTD[offset2] = FX_DBL2FX_PCM(L - R);
+ pTD[0] = SATURATE_LEFT_SHIFT(FX_DBL2FX_PCM(L + R), 1, DFRACT_BITS);
+ pTD[offset2] =
+ SATURATE_LEFT_SHIFT(FX_DBL2FX_PCM(L - R), 1, DFRACT_BITS);
#endif
pTD++;
}