vorbis: refuse streams with more than two channels

Tremor is built here with CHANNELS 2: synthesis produces no PCM
for a stream with more channels, so a 5.1 file "played" as nothing
at all. It was still set up in full first, which took 416 to 880 KB
of the codec heap for the 5.1 and 7.1 files tried, and wrote one
entry per channel into arrays sized for two.

Refuse such a stream when its identification header is read. The
codec then returns an error at once, with under 8 KB of heap used.

Checked with perfsim on the Sansa Clip+ model, not on a device:
six 5.1 and 7.1 files are refused, and 13 stereo and mono files
give the same PCM hashes as before.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Michael Giacomelli 2026-10-05 19:53:02 -04:00
parent 9477e371a3
commit d084219b9a

View file

@ -131,6 +131,11 @@ static int _vorbis_unpack_info(vorbis_info *vi,oggpack_buffer *opb){
if(vi->rate<1)goto err_out;
if(vi->channels<1)goto err_out;
/* This build decodes at most CHANNELS channels (synthesis.c produces no
PCM for more, and several arrays are sized by it). Refuse the stream
here, before its setup is unpacked: a 5.1 stream's codebooks alone
can take several hundred KB of the codec heap for no output. */
if(vi->channels>CHANNELS)goto err_out;
if(ci->blocksizes[0]<64)goto err_out;
if(ci->blocksizes[1]<ci->blocksizes[0])goto err_out;
if(ci->blocksizes[1]>8192)goto err_out;