Message ID | 20221102210239.1689-2-michael@niedermayer.cc |
---|---|
State | Accepted |
Commit | b74f89caaef2174b0bfb2791ea88e44960dba11f |
Headers | show |
Series | [FFmpeg-devel,1/2] swscale/output: Bias 16bps output calculations to improve non overflowing range | expand |
Context | Check | Description |
---|---|---|
yinshiyou/make_loongarch64 | success | Make finished |
yinshiyou/make_fate_loongarch64 | success | Make fate finished |
andriy/make_x86 | success | Make finished |
andriy/make_fate_x86 | success | Make fate finished |
On Wed, Nov 02, 2022 at 10:02:39PM +0100, Michael Niedermayer wrote: > Fixes: integer overflow > Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> > --- > libswscale/output.c | 25 +++++++++++-------------- > libswscale/x86/output.asm | 16 +++++++++++++++- > 2 files changed, 26 insertions(+), 15 deletions(-) Note, these corner case overflows could affect some of the similary implemented cases that are not depth 16 too ill fix them if issues are replicated [...]
Michael Niedermayer: > On Wed, Nov 02, 2022 at 10:02:39PM +0100, Michael Niedermayer wrote: >> Fixes: integer overflow >> Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> >> --- >> libswscale/output.c | 25 +++++++++++-------------- >> libswscale/x86/output.asm | 16 +++++++++++++++- >> 2 files changed, 26 insertions(+), 15 deletions(-) > > Note, these corner case overflows could affect some of the similary > implemented cases that are not depth 16 too > > ill fix them if issues are replicated > The checkasm-sw_gbrp runs into many overflows (when run under UBSan); e.g. fate.ffmpeg.org tells me of an issue in line 2289. Said line is not touched in your commits. - Andreas
On Wed, Nov 02, 2022 at 10:16:57PM +0100, Andreas Rheinhardt wrote: > Michael Niedermayer: > > On Wed, Nov 02, 2022 at 10:02:39PM +0100, Michael Niedermayer wrote: > >> Fixes: integer overflow > >> Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> > >> --- > >> libswscale/output.c | 25 +++++++++++-------------- > >> libswscale/x86/output.asm | 16 +++++++++++++++- > >> 2 files changed, 26 insertions(+), 15 deletions(-) > > > > Note, these corner case overflows could affect some of the similary > > implemented cases that are not depth 16 too > > > > ill fix them if issues are replicated > > > > The checkasm-sw_gbrp runs into many overflows (when run under UBSan); > e.g. fate.ffmpeg.org tells me of an issue in line 2289. Said line is not > touched in your commits. checkasm-sw_gbrp feeds random data widely outside sane ranges in. the test certainly makes no sense for testing asm. There is no point in matching C for widely invalid cases. Of cousre we shouldnt overflow if any of this can be triggered with valid and real input (which probably can be done in some cases) thx [...]
On Wed, 2 Nov 2022, Michael Niedermayer wrote: > On Wed, Nov 02, 2022 at 10:16:57PM +0100, Andreas Rheinhardt wrote: >> Michael Niedermayer: >>> On Wed, Nov 02, 2022 at 10:02:39PM +0100, Michael Niedermayer wrote: >>>> Fixes: integer overflow >>>> Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> >>>> --- >>>> libswscale/output.c | 25 +++++++++++-------------- >>>> libswscale/x86/output.asm | 16 +++++++++++++++- >>>> 2 files changed, 26 insertions(+), 15 deletions(-) >>> >>> Note, these corner case overflows could affect some of the similary >>> implemented cases that are not depth 16 too >>> >>> ill fix them if issues are replicated >>> >> >> The checkasm-sw_gbrp runs into many overflows (when run under UBSan); >> e.g. fate.ffmpeg.org tells me of an issue in line 2289. Said line is not >> touched in your commits. > > checkasm-sw_gbrp feeds random data widely outside sane ranges in. > the test certainly makes no sense for testing asm. There is no point > in matching C for widely invalid cases. Of cousre we shouldnt overflow > if any of this can be triggered with valid and real input (which probably > can be done in some cases) Patches for the checkasm tests, to make them produce sane input values in the correct ranges, are very much welcome! // Martin
On Wed, Nov 02, 2022 at 10:31:27PM +0100, Michael Niedermayer wrote: > On Wed, Nov 02, 2022 at 10:16:57PM +0100, Andreas Rheinhardt wrote: > > Michael Niedermayer: > > > On Wed, Nov 02, 2022 at 10:02:39PM +0100, Michael Niedermayer wrote: > > >> Fixes: integer overflow > > >> Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> > > >> --- > > >> libswscale/output.c | 25 +++++++++++-------------- > > >> libswscale/x86/output.asm | 16 +++++++++++++++- > > >> 2 files changed, 26 insertions(+), 15 deletions(-) > > > > > > Note, these corner case overflows could affect some of the similary > > > implemented cases that are not depth 16 too > > > > > > ill fix them if issues are replicated > > > > > > > The checkasm-sw_gbrp runs into many overflows (when run under UBSan); > > e.g. fate.ffmpeg.org tells me of an issue in line 2289. Said line is not > > touched in your commits. > > checkasm-sw_gbrp feeds random data widely outside sane ranges in. > the test certainly makes no sense for testing asm. There is no point > in matching C for widely invalid cases. Of cousre we shouldnt overflow > if any of this can be triggered with valid and real input (which probably > can be done in some cases) also to elaborate further, checkasm-sw_gbrp sets everything randomly that includes yuv2rgb matrix values and bits outside the valid input sample range and the resample filter coeffs. [...]
On Wed, Nov 2, 2022 at 2:03 PM Michael Niedermayer <michael@niedermayer.cc> wrote: > Fixes: integer overflow > Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> > --- > libswscale/output.c | 25 +++++++++++-------------- > libswscale/x86/output.asm | 16 +++++++++++++++- > 2 files changed, 26 insertions(+), 15 deletions(-) > > diff --git a/libswscale/output.c b/libswscale/output.c > index df4647adde..5c85bff971 100644 > --- a/libswscale/output.c > +++ b/libswscale/output.c > @@ -2372,18 +2372,15 @@ yuv2gbrp16_full_X_c(SwsContext *c, const int16_t > *lumFilter, > > Y -= c->yuv2rgb_y_offset; > Y *= c->yuv2rgb_y_coeff; > - Y += 1 << 13; > + Y += (1 << 13) - (1 << 29); > R = V * c->yuv2rgb_v2r_coeff; > G = V * c->yuv2rgb_v2g_coeff + U * c->yuv2rgb_u2g_coeff; > B = U * c->yuv2rgb_u2b_coeff; > > - R = av_clip_uintp2(Y + R, 30); > - G = av_clip_uintp2(Y + G, 30); > - B = av_clip_uintp2(Y + B, 30); > + dest16[2][i] = av_clip_uintp2(((Y + R) >> 14) + (1<<15), 16); > + dest16[0][i] = av_clip_uintp2(((Y + G) >> 14) + (1<<15), 16); > + dest16[1][i] = av_clip_uintp2(((Y + B) >> 14) + (1<<15), 16); > > - dest16[0][i] = G >> 14; > - dest16[1][i] = B >> 14; > - dest16[2][i] = R >> 14; > if (hasAlpha) > dest16[3][i] = av_clip_uintp2(A, 30) >> 14; > } > @@ -2448,18 +2445,18 @@ yuv2gbrpf32_full_X_c(SwsContext *c, const int16_t > *lumFilter, > > Y -= c->yuv2rgb_y_offset; > Y *= c->yuv2rgb_y_coeff; > - Y += 1 << 13; > + Y += (1 << 13) - (1 << 29); > R = V * c->yuv2rgb_v2r_coeff; > G = V * c->yuv2rgb_v2g_coeff + U * c->yuv2rgb_u2g_coeff; > B = U * c->yuv2rgb_u2b_coeff; > > - R = av_clip_uintp2(Y + R, 30); > - G = av_clip_uintp2(Y + G, 30); > - B = av_clip_uintp2(Y + B, 30); > + R = av_clip_uintp2(((Y + R) >> 14) + (1<<15), 16); > + G = av_clip_uintp2(((Y + G) >> 14) + (1<<15), 16); > + B = av_clip_uintp2(((Y + B) >> 14) + (1<<15), 16); > > - dest32[0][i] = av_float2int(float_mult * (float)(G >> 14)); > - dest32[1][i] = av_float2int(float_mult * (float)(B >> 14)); > - dest32[2][i] = av_float2int(float_mult * (float)(R >> 14)); > + dest32[0][i] = av_float2int(float_mult * (float)G); > + dest32[1][i] = av_float2int(float_mult * (float)B); > + dest32[2][i] = av_float2int(float_mult * (float)R); > if (hasAlpha) > dest32[3][i] = av_float2int(float_mult * > (float)(av_clip_uintp2(A, 30) >> 14)); > } > diff --git a/libswscale/x86/output.asm b/libswscale/x86/output.asm > index 84e94baaf6..f943a27534 100644 > --- a/libswscale/x86/output.asm > +++ b/libswscale/x86/output.asm > @@ -44,11 +44,13 @@ pd_yuv2gbrp_y_start: times 8 dd (1 << 9) > pd_yuv2gbrp_uv_start: times 8 dd ((1 << 9) - (128 << 19)) > pd_yuv2gbrp_a_start: times 8 dd (1 << 18) > pd_yuv2gbrp16_offset: times 8 dd 0x10000 ;(1 << 16) > -pd_yuv2gbrp16_round13: times 8 dd 0x02000 ;(1 << 13) > +pd_yuv2gbrp16_round13: times 8 dd 0xE0002000 ;(1 << 13) - (1 << 29) > pd_yuv2gbrp16_a_offset: times 8 dd 0x20002000 > pd_yuv2gbrp16_upper30: times 8 dd 0x3FFFFFFF ;(1<<30) - 1 > pd_yuv2gbrp16_upper27: times 8 dd 0x07FFFFFF ;(1<<27) - 1 > +pd_yuv2gbrp16_upper16: times 8 dd 0x0000FFFF ;(1<<16) - 1 > pd_yuv2gbrp16_upper16 doesn't appear to be used anywhere > pd_yuv2gbrp16_upperC: times 8 dd 0xC0000000 > +pd_yuv2gbrp_debias: times 8 dd 0x00008000 ;(1 << 29 - 14) > pb_pack_shuffle8: db 0, 4, 8, 12, \ > -1, -1, -1, -1, \ > -1, -1, -1, -1, \ > @@ -883,14 +885,26 @@ cglobal yuv2%1_full_X, 12, 14, 16, ptr, lumFilter, > lumSrcx, lumFilterSize, chrFi > paddd G, Y > paddd B, Y > > +%if DEPTH < 16 > CLIPP2 R, 30 > CLIPP2 G, 30 > CLIPP2 B, 30 > +%endif > > psrad R, RGB_SHIFT > psrad G, RGB_SHIFT > psrad B, RGB_SHIFT > > +%if DEPTH >= 16 > + paddd R, [pd_yuv2gbrp_debias] > + paddd G, [pd_yuv2gbrp_debias] > + paddd B, [pd_yuv2gbrp_debias] > + > + CLIPP2 R, 16 > + CLIPP2 G, 16 > + CLIPP2 B, 16 > +%endif > + > %if FLOAT > cvtdq2ps R, R > cvtdq2ps G, G > -- > 2.17.1 > > _______________________________________________ > ffmpeg-devel mailing list > ffmpeg-devel@ffmpeg.org > https://ffmpeg.org/mailman/listinfo/ffmpeg-devel > > To unsubscribe, visit link above, or email > ffmpeg-devel-request@ffmpeg.org with subject "unsubscribe". >
On Wed, Nov 2, 2022 at 3:52 PM Mark Reid <mindmark@gmail.com> wrote: > > > On Wed, Nov 2, 2022 at 2:03 PM Michael Niedermayer <michael@niedermayer.cc> > wrote: > >> Fixes: integer overflow >> Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> >> --- >> libswscale/output.c | 25 +++++++++++-------------- >> libswscale/x86/output.asm | 16 +++++++++++++++- >> 2 files changed, 26 insertions(+), 15 deletions(-) >> >> diff --git a/libswscale/output.c b/libswscale/output.c >> index df4647adde..5c85bff971 100644 >> --- a/libswscale/output.c >> +++ b/libswscale/output.c >> @@ -2372,18 +2372,15 @@ yuv2gbrp16_full_X_c(SwsContext *c, const int16_t >> *lumFilter, >> >> Y -= c->yuv2rgb_y_offset; >> Y *= c->yuv2rgb_y_coeff; >> - Y += 1 << 13; >> + Y += (1 << 13) - (1 << 29); >> R = V * c->yuv2rgb_v2r_coeff; >> G = V * c->yuv2rgb_v2g_coeff + U * c->yuv2rgb_u2g_coeff; >> B = U * c->yuv2rgb_u2b_coeff; >> >> - R = av_clip_uintp2(Y + R, 30); >> - G = av_clip_uintp2(Y + G, 30); >> - B = av_clip_uintp2(Y + B, 30); >> + dest16[2][i] = av_clip_uintp2(((Y + R) >> 14) + (1<<15), 16); >> + dest16[0][i] = av_clip_uintp2(((Y + G) >> 14) + (1<<15), 16); >> + dest16[1][i] = av_clip_uintp2(((Y + B) >> 14) + (1<<15), 16); >> >> - dest16[0][i] = G >> 14; >> - dest16[1][i] = B >> 14; >> - dest16[2][i] = R >> 14; >> if (hasAlpha) >> dest16[3][i] = av_clip_uintp2(A, 30) >> 14; >> } >> @@ -2448,18 +2445,18 @@ yuv2gbrpf32_full_X_c(SwsContext *c, const int16_t >> *lumFilter, >> >> Y -= c->yuv2rgb_y_offset; >> Y *= c->yuv2rgb_y_coeff; >> - Y += 1 << 13; >> + Y += (1 << 13) - (1 << 29); >> R = V * c->yuv2rgb_v2r_coeff; >> G = V * c->yuv2rgb_v2g_coeff + U * c->yuv2rgb_u2g_coeff; >> B = U * c->yuv2rgb_u2b_coeff; >> >> - R = av_clip_uintp2(Y + R, 30); >> - G = av_clip_uintp2(Y + G, 30); >> - B = av_clip_uintp2(Y + B, 30); >> + R = av_clip_uintp2(((Y + R) >> 14) + (1<<15), 16); >> + G = av_clip_uintp2(((Y + G) >> 14) + (1<<15), 16); >> + B = av_clip_uintp2(((Y + B) >> 14) + (1<<15), 16); >> >> - dest32[0][i] = av_float2int(float_mult * (float)(G >> 14)); >> - dest32[1][i] = av_float2int(float_mult * (float)(B >> 14)); >> - dest32[2][i] = av_float2int(float_mult * (float)(R >> 14)); >> + dest32[0][i] = av_float2int(float_mult * (float)G); >> + dest32[1][i] = av_float2int(float_mult * (float)B); >> + dest32[2][i] = av_float2int(float_mult * (float)R); >> if (hasAlpha) >> dest32[3][i] = av_float2int(float_mult * >> (float)(av_clip_uintp2(A, 30) >> 14)); >> } >> diff --git a/libswscale/x86/output.asm b/libswscale/x86/output.asm >> index 84e94baaf6..f943a27534 100644 >> --- a/libswscale/x86/output.asm >> +++ b/libswscale/x86/output.asm >> @@ -44,11 +44,13 @@ pd_yuv2gbrp_y_start: times 8 dd (1 << 9) >> pd_yuv2gbrp_uv_start: times 8 dd ((1 << 9) - (128 << 19)) >> pd_yuv2gbrp_a_start: times 8 dd (1 << 18) >> pd_yuv2gbrp16_offset: times 8 dd 0x10000 ;(1 << 16) >> -pd_yuv2gbrp16_round13: times 8 dd 0x02000 ;(1 << 13) >> +pd_yuv2gbrp16_round13: times 8 dd 0xE0002000 ;(1 << 13) - (1 << 29) >> pd_yuv2gbrp16_a_offset: times 8 dd 0x20002000 >> pd_yuv2gbrp16_upper30: times 8 dd 0x3FFFFFFF ;(1<<30) - 1 >> pd_yuv2gbrp16_upper27: times 8 dd 0x07FFFFFF ;(1<<27) - 1 >> +pd_yuv2gbrp16_upper16: times 8 dd 0x0000FFFF ;(1<<16) - 1 >> > > pd_yuv2gbrp16_upper16 doesn't appear to be used anywhere > nevermind, I see where it is used now. > > >> pd_yuv2gbrp16_upperC: times 8 dd 0xC0000000 >> +pd_yuv2gbrp_debias: times 8 dd 0x00008000 ;(1 << 29 - 14) >> pb_pack_shuffle8: db 0, 4, 8, 12, \ >> -1, -1, -1, -1, \ >> -1, -1, -1, -1, \ >> @@ -883,14 +885,26 @@ cglobal yuv2%1_full_X, 12, 14, 16, ptr, lumFilter, >> lumSrcx, lumFilterSize, chrFi >> paddd G, Y >> paddd B, Y >> >> +%if DEPTH < 16 >> CLIPP2 R, 30 >> CLIPP2 G, 30 >> CLIPP2 B, 30 >> +%endif >> >> psrad R, RGB_SHIFT >> psrad G, RGB_SHIFT >> psrad B, RGB_SHIFT >> >> +%if DEPTH >= 16 >> + paddd R, [pd_yuv2gbrp_debias] >> + paddd G, [pd_yuv2gbrp_debias] >> + paddd B, [pd_yuv2gbrp_debias] >> + >> + CLIPP2 R, 16 >> + CLIPP2 G, 16 >> + CLIPP2 B, 16 >> +%endif >> + >> %if FLOAT >> cvtdq2ps R, R >> cvtdq2ps G, G >> -- >> 2.17.1 >> >> _______________________________________________ >> ffmpeg-devel mailing list >> ffmpeg-devel@ffmpeg.org >> https://ffmpeg.org/mailman/listinfo/ffmpeg-devel >> >> To unsubscribe, visit link above, or email >> ffmpeg-devel-request@ffmpeg.org with subject "unsubscribe". >> >
diff --git a/libswscale/output.c b/libswscale/output.c index df4647adde..5c85bff971 100644 --- a/libswscale/output.c +++ b/libswscale/output.c @@ -2372,18 +2372,15 @@ yuv2gbrp16_full_X_c(SwsContext *c, const int16_t *lumFilter, Y -= c->yuv2rgb_y_offset; Y *= c->yuv2rgb_y_coeff; - Y += 1 << 13; + Y += (1 << 13) - (1 << 29); R = V * c->yuv2rgb_v2r_coeff; G = V * c->yuv2rgb_v2g_coeff + U * c->yuv2rgb_u2g_coeff; B = U * c->yuv2rgb_u2b_coeff; - R = av_clip_uintp2(Y + R, 30); - G = av_clip_uintp2(Y + G, 30); - B = av_clip_uintp2(Y + B, 30); + dest16[2][i] = av_clip_uintp2(((Y + R) >> 14) + (1<<15), 16); + dest16[0][i] = av_clip_uintp2(((Y + G) >> 14) + (1<<15), 16); + dest16[1][i] = av_clip_uintp2(((Y + B) >> 14) + (1<<15), 16); - dest16[0][i] = G >> 14; - dest16[1][i] = B >> 14; - dest16[2][i] = R >> 14; if (hasAlpha) dest16[3][i] = av_clip_uintp2(A, 30) >> 14; } @@ -2448,18 +2445,18 @@ yuv2gbrpf32_full_X_c(SwsContext *c, const int16_t *lumFilter, Y -= c->yuv2rgb_y_offset; Y *= c->yuv2rgb_y_coeff; - Y += 1 << 13; + Y += (1 << 13) - (1 << 29); R = V * c->yuv2rgb_v2r_coeff; G = V * c->yuv2rgb_v2g_coeff + U * c->yuv2rgb_u2g_coeff; B = U * c->yuv2rgb_u2b_coeff; - R = av_clip_uintp2(Y + R, 30); - G = av_clip_uintp2(Y + G, 30); - B = av_clip_uintp2(Y + B, 30); + R = av_clip_uintp2(((Y + R) >> 14) + (1<<15), 16); + G = av_clip_uintp2(((Y + G) >> 14) + (1<<15), 16); + B = av_clip_uintp2(((Y + B) >> 14) + (1<<15), 16); - dest32[0][i] = av_float2int(float_mult * (float)(G >> 14)); - dest32[1][i] = av_float2int(float_mult * (float)(B >> 14)); - dest32[2][i] = av_float2int(float_mult * (float)(R >> 14)); + dest32[0][i] = av_float2int(float_mult * (float)G); + dest32[1][i] = av_float2int(float_mult * (float)B); + dest32[2][i] = av_float2int(float_mult * (float)R); if (hasAlpha) dest32[3][i] = av_float2int(float_mult * (float)(av_clip_uintp2(A, 30) >> 14)); } diff --git a/libswscale/x86/output.asm b/libswscale/x86/output.asm index 84e94baaf6..f943a27534 100644 --- a/libswscale/x86/output.asm +++ b/libswscale/x86/output.asm @@ -44,11 +44,13 @@ pd_yuv2gbrp_y_start: times 8 dd (1 << 9) pd_yuv2gbrp_uv_start: times 8 dd ((1 << 9) - (128 << 19)) pd_yuv2gbrp_a_start: times 8 dd (1 << 18) pd_yuv2gbrp16_offset: times 8 dd 0x10000 ;(1 << 16) -pd_yuv2gbrp16_round13: times 8 dd 0x02000 ;(1 << 13) +pd_yuv2gbrp16_round13: times 8 dd 0xE0002000 ;(1 << 13) - (1 << 29) pd_yuv2gbrp16_a_offset: times 8 dd 0x20002000 pd_yuv2gbrp16_upper30: times 8 dd 0x3FFFFFFF ;(1<<30) - 1 pd_yuv2gbrp16_upper27: times 8 dd 0x07FFFFFF ;(1<<27) - 1 +pd_yuv2gbrp16_upper16: times 8 dd 0x0000FFFF ;(1<<16) - 1 pd_yuv2gbrp16_upperC: times 8 dd 0xC0000000 +pd_yuv2gbrp_debias: times 8 dd 0x00008000 ;(1 << 29 - 14) pb_pack_shuffle8: db 0, 4, 8, 12, \ -1, -1, -1, -1, \ -1, -1, -1, -1, \ @@ -883,14 +885,26 @@ cglobal yuv2%1_full_X, 12, 14, 16, ptr, lumFilter, lumSrcx, lumFilterSize, chrFi paddd G, Y paddd B, Y +%if DEPTH < 16 CLIPP2 R, 30 CLIPP2 G, 30 CLIPP2 B, 30 +%endif psrad R, RGB_SHIFT psrad G, RGB_SHIFT psrad B, RGB_SHIFT +%if DEPTH >= 16 + paddd R, [pd_yuv2gbrp_debias] + paddd G, [pd_yuv2gbrp_debias] + paddd B, [pd_yuv2gbrp_debias] + + CLIPP2 R, 16 + CLIPP2 G, 16 + CLIPP2 B, 16 +%endif + %if FLOAT cvtdq2ps R, R cvtdq2ps G, G
Fixes: integer overflow Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> --- libswscale/output.c | 25 +++++++++++-------------- libswscale/x86/output.asm | 16 +++++++++++++++- 2 files changed, 26 insertions(+), 15 deletions(-)