head 1.2; access; symbols pkgsrc-2026Q3:1.1.0.8 pkgsrc-2026Q3-base:1.1 pkgsrc-2026Q2:1.1.0.6 pkgsrc-2026Q2-base:1.1 pkgsrc-2026Q1:1.1.0.4 pkgsrc-2026Q1-base:1.1 pkgsrc-2025Q4:1.1.0.2; locks; strict; comment @ * @; 1.2 date 2026.10.02.05.07.45; author adam; state dead; branches; next 1.1; commitid MUkYSjmK3YoDqRXG; 1.1 date 2026.02.17.01.53.46; author gutteridge; state Exp; branches 1.1.2.1; next ; commitid fTRLOoz9TVmpEFuG; 1.1.2.1 date 2026.02.17.01.53.46; author maya; state dead; branches; next 1.1.2.2; commitid dGzvAstqnXeaiSuG; 1.1.2.2 date 2026.02.18.15.57.51; author maya; state Exp; branches; next ; commitid dGzvAstqnXeaiSuG; desc @@ 1.2 log @libvpx: updated to 1.17.0 1.17.0 "Yellowbilled Duck" This release includes a new encoder control to validate high bitdepth input, additional Neon and AVX2/AVX512 optimizations, support for the C11 standard, and numerous bug fixes. - Upgrading: This release is ABI compatible with the previous release. ISO C11 standard is now enforced for C files. SVC is now strictly disallowed for 2-pass encoding; enabling it will return VPX_CODEC_INVALID_PARAM. VP9 High Bitdepth (HBD) input validation is now enabled by default. If the input contains values outside the valid range, the encoder will return VPX_CODEC_INVALID_PARAM. Use the new VP9E_SET_VALIDATE_HBD_INPUT control (or vpxenc --validate-hbd-input=0) to disable this validation. VP9 now sets the returned image width (w) and height (h) to the actual width and height, rather than the stride and aligned height. This is a behavior change that may affect applications relying on w being equal to the stride or h being the aligned height. Strict validation has been added to some APIs: - Encoders (VP8/VP9) now reject input images with unequal U and V strides. - vpx_img_alloc() and vpx_img_wrap() now strictly validate the image format. - External rate control (RTC) API now validates configuration inputs. - VP9 SVC now validates spatial layer ID input. - Enhancement: Added Arm Neon DotProd subpel variance paths. Optimized Neon HBD sadx4d and sad_skipx4d functions. Added AVX2/AVX512 implementations for various vpx_highbd predictor functions. Added support for MSVC v145 (Visual Studio 2026). Added configure option --disable-x86-asm. - Bug fixes: Fix to heap buffer overflow / out-of-bounds write in vp9_postproc, vp8-multi-res-encoding, vpx_setup_noise, set_mb_ssim_rdmult_scaling, vp9_change_config (resolution change), vp9_dec_alloc_row_mt_mem (decode coeffs), and vp8_sixtap_predict (LoongArch). Fix to integer overflow in vp9-svc (layer resolution, duration), set_mb_ssim_rdmult_scaling, vp8_encode_frame, calc_pframe_target_size, y4minput buffer size calculations, and get_token_alloc. Fix to VP8 decoder crash on flush with no fragments. Fix to VP8 decoder potential hang/slowdown with corrupt partition 0 size. Fix to VP9 decoder crash with invalid reference frame index. Fix to VP9 highbitdepth encoder format mismatch. Fix to VP9 float-to-int overflow in validate_config (EOS count) and with zero bitrate. Fix to VP8 decoder multithreading corruption flag reset at start of frame. Fix to VP8 decoder accepting inter frames on resolution change before keyframe. Fix to VP8 encoder reference frame dimension validation. Fix to VP8 encoder temporal layer ID validation. Fix to VP8 encoder missing setjmp in VP8E_SET_SCALEMODE. Fix to VP9 SVC encoder crash with dynamic resize and cyclic refresh (aq_mode=3). Fix to VP9 1-pass rate control last_boosted_qindex clamping and VP9E_SET_QUANTIZER_ONE_PASS validation. Fix to NV12 x_chroma_shift calculation in vpx_image and image2yuvconfig. Fix to AVX-512 CPU feature detection on older x86 CPUs. Fix to x86_abi_support.asm placing read-only data tables in .rdata for Windows. Fix to configure disabling _FORTIFY_SOURCE on Linux. Fix to file leaks on error paths in vpxdec and video reader/writer utilities. Fix to crash/undefined behavior in vpx_img_flip with formats without alpha. @ text @$NetBSD: patch-vp9_vp9__cx__iface.c,v 1.1 2026/02/17 01:53:46 gutteridge Exp $ Apply upstream commit related to CVE-2026-2447. https://github.com/webmproject/libvpx/commit/d5f35ac8d93cba7f7a3f7ddb8f9dc8bd28f785e1 --- vp9/vp9_cx_iface.c.orig 2026-01-08 16:01:40.000000000 +0000 +++ vp9/vp9_cx_iface.c @@@@ -8,7 +8,9 @@@@ * be found in the AUTHORS file in the root of the source tree. */ +#include #include +#include #include #include #include @@@@ -122,6 +124,7 @@@@ struct vpx_codec_alg_priv { VP9_COMP *cpi; unsigned char *cx_data; size_t cx_data_sz; + // pending_cx_data either is a null pointer or points into the cx_data buffer. unsigned char *pending_cx_data; size_t pending_cx_data_sz; int pending_frame_count; @@@@ -1252,8 +1255,12 @@@@ static int write_superframe_index(vpx_codec_alg_priv_t // Write the index index_sz = 2 + (mag + 1) * ctx->pending_frame_count; - if (ctx->pending_cx_data_sz + index_sz < ctx->cx_data_sz) { - uint8_t *x = ctx->pending_cx_data + ctx->pending_cx_data_sz; + unsigned char *cx_data_end = ctx->cx_data + ctx->cx_data_sz; + unsigned char *pending_cx_data_end = + ctx->pending_cx_data + ctx->pending_cx_data_sz; + ptrdiff_t space_remaining = cx_data_end - pending_cx_data_end; + if (index_sz <= space_remaining) { + uint8_t *x = pending_cx_data_end; int i, j; #ifdef TEST_SUPPLEMENTAL_SUPERFRAME_DATA uint8_t marker_test = 0xc0; @@@@ -1284,6 +1291,8 @@@@ static int write_superframe_index(vpx_codec_alg_priv_t #ifdef TEST_SUPPLEMENTAL_SUPERFRAME_DATA index_sz += index_sz_test; #endif + } else { + index_sz = 0; } return index_sz; } @@@@ -1612,9 +1621,12 @@@@ static vpx_codec_err_t encoder_encode(vpx_codec_alg_pr ctx->pending_frame_sizes[ctx->pending_frame_count++] = size; ctx->pending_frame_magnitude |= size; ctx->pending_cx_data_sz += size; - // write the superframe only for the case when - if (!ctx->output_cx_pkt_cb.output_cx_pkt) + // write the superframe only for the case when the callback function + // for getting per-layer packets is not registered. + if (!ctx->output_cx_pkt_cb.output_cx_pkt) { size += write_superframe_index(ctx); + assert(size <= cx_data_sz); + } pkt.data.frame.buf = ctx->pending_cx_data; pkt.data.frame.sz = ctx->pending_cx_data_sz; ctx->pending_cx_data = NULL; @ 1.1 log @libvpx: apply upstream commit related to CVE-2026-2447 @ text @d1 1 a1 1 $NetBSD$ @ 1.1.2.1 log @file patch-vp9_vp9__cx__iface.c was added on branch pkgsrc-2025Q4 on 2026-02-18 15:57:51 +0000 @ text @d1 64 @ 1.1.2.2 log @Pullup ticket #7051 - requested by gutteridge multimedia/libvpx: Security fix Revisions pulled up: - multimedia/libvpx/Makefile 1.109-1.110 - multimedia/libvpx/distinfo 1.55-1.56 - multimedia/libvpx/patches/patch-libs.mk 1.8 - multimedia/libvpx/patches/patch-vp9_vp9__cx__iface.c 1.1 --- Module Name: pkgsrc Committed By: adam Date: Mon Feb 16 11:30:11 UTC 2026 Modified Files: pkgsrc/multimedia/libvpx: Makefile distinfo pkgsrc/multimedia/libvpx/patches: patch-libs.mk Log Message: libvpx: updated to 1.16.0 v1.16.0 "Xenonetta Duck" This release includes Arm SVE2 and Neon optimizations for 12-tap filters, AVX512 implementations for SAD, support for per-frame and per-spatial-layer PSNR calculation, and numerous bug fixes. - Upgrading: This release is ABI incompatible with the previous release. Unit tests require C++17 to build. Support for 32-bit iOS targets (armv7, armv7s, and i386) has been removed. - Enhancement: Optimized Arm SVE2 and Neon implementations for 12-tap convolution filters. Optimized Neon High Bitdepth (HBD) SAD and sad_avg functions. Added Arm Neon DotProd and I8MM implementations for vpx_convolve12. Added AVX512 implementations for SAD64 and sad_skip functions. Added SSSE3 and AVX2 implementations for 12-tap temporal filter prediction. Added support for per-frame and per-spatial-layer PSNR calculation. Adjusted temporal filter strength to improve visual quality and reduce block artifacts. Added support for darwin24 (macOS 15) and darwin25 (macOS 26). libwebm is upgraded to commit b4f01ea. - Bug fixes: Fix to heap buffer overflow in vp9_deblock, vp9_post_proc_frame, and vp9_pack_bitstream. Fix to integer overflow in vp9_highbd_post_proc, vp9_rc_regulate_q, tiny_ssim, and vp9_calc_pframe_target_size_one_pass_cbr. Fix to use-of-uninitialized-value in vp9_highbd_post_proc, mfqe, and vp8_datarate_test. Fix to out-of-bounds in log_tile_cols_from_picsize_level. Fix to double free on initialization failure in vpx_codec_enc_init_multi. Fix to division-by-zero crash in vpxenc with 0 FPS numerator input. Fix to various build failures for Arm/SVE2, macOS cross-compilation, and Xcode 16. --- Module Name: pkgsrc Committed By: gutteridge Date: Tue Feb 17 01:53:46 UTC 2026 Modified Files: pkgsrc/multimedia/libvpx: Makefile distinfo Added Files: pkgsrc/multimedia/libvpx/patches: patch-vp9_vp9__cx__iface.c Log Message: libvpx: apply upstream commit related to CVE-2026-2447 @ text @a0 64 $NetBSD: patch-vp9_vp9__cx__iface.c,v 1.1 2026/02/17 01:53:46 gutteridge Exp $ Apply upstream commit related to CVE-2026-2447. https://github.com/webmproject/libvpx/commit/d5f35ac8d93cba7f7a3f7ddb8f9dc8bd28f785e1 --- vp9/vp9_cx_iface.c.orig 2026-01-08 16:01:40.000000000 +0000 +++ vp9/vp9_cx_iface.c @@@@ -8,7 +8,9 @@@@ * be found in the AUTHORS file in the root of the source tree. */ +#include #include +#include #include #include #include @@@@ -122,6 +124,7 @@@@ struct vpx_codec_alg_priv { VP9_COMP *cpi; unsigned char *cx_data; size_t cx_data_sz; + // pending_cx_data either is a null pointer or points into the cx_data buffer. unsigned char *pending_cx_data; size_t pending_cx_data_sz; int pending_frame_count; @@@@ -1252,8 +1255,12 @@@@ static int write_superframe_index(vpx_codec_alg_priv_t // Write the index index_sz = 2 + (mag + 1) * ctx->pending_frame_count; - if (ctx->pending_cx_data_sz + index_sz < ctx->cx_data_sz) { - uint8_t *x = ctx->pending_cx_data + ctx->pending_cx_data_sz; + unsigned char *cx_data_end = ctx->cx_data + ctx->cx_data_sz; + unsigned char *pending_cx_data_end = + ctx->pending_cx_data + ctx->pending_cx_data_sz; + ptrdiff_t space_remaining = cx_data_end - pending_cx_data_end; + if (index_sz <= space_remaining) { + uint8_t *x = pending_cx_data_end; int i, j; #ifdef TEST_SUPPLEMENTAL_SUPERFRAME_DATA uint8_t marker_test = 0xc0; @@@@ -1284,6 +1291,8 @@@@ static int write_superframe_index(vpx_codec_alg_priv_t #ifdef TEST_SUPPLEMENTAL_SUPERFRAME_DATA index_sz += index_sz_test; #endif + } else { + index_sz = 0; } return index_sz; } @@@@ -1612,9 +1621,12 @@@@ static vpx_codec_err_t encoder_encode(vpx_codec_alg_pr ctx->pending_frame_sizes[ctx->pending_frame_count++] = size; ctx->pending_frame_magnitude |= size; ctx->pending_cx_data_sz += size; - // write the superframe only for the case when - if (!ctx->output_cx_pkt_cb.output_cx_pkt) + // write the superframe only for the case when the callback function + // for getting per-layer packets is not registered. + if (!ctx->output_cx_pkt_cb.output_cx_pkt) { size += write_superframe_index(ctx); + assert(size <= cx_data_sz); + } pkt.data.frame.buf = ctx->pending_cx_data; pkt.data.frame.sz = ctx->pending_cx_data_sz; ctx->pending_cx_data = NULL; @