From 91e7812fb23c59f87dc79dd5798edf9b61aad422 Mon Sep 17 00:00:00 2001 From: Alakh Chandarana <36898190+alakhpc@users.noreply.github.com> Date: Sun, 11 Jan 2026 16:45:18 -0500 Subject: [PATCH 1/3] fix --- src/input-format.ts | 5 +- src/matroska/ebml.ts | 108 +++++++++++++++++++++++-------- src/matroska/matroska-demuxer.ts | 4 +- 3 files changed, 85 insertions(+), 32 deletions(-) diff --git a/src/input-format.ts b/src/input-format.ts index 1748f27..1c0e292 100644 --- a/src/input-format.ts +++ b/src/input-format.ts @@ -154,10 +154,11 @@ export class MatroskaInputFormat extends InputFormat { return false; } - const dataSize = readElementSize(headerSlice); - if (dataSize === null) { + const dataSizeResult = readElementSize(headerSlice); + if (dataSizeResult === null || dataSizeResult.size === null) { return false; // Miss me with that shit } + const dataSize = dataSizeResult.size; let dataSlice = input._reader.requestSlice(headerSlice.filePos, dataSize); if (dataSlice instanceof Promise) dataSlice = await dataSlice; diff --git a/src/matroska/ebml.ts b/src/matroska/ebml.ts index eb27c40..0df632d 100644 --- a/src/matroska/ebml.ts +++ b/src/matroska/ebml.ts @@ -470,6 +470,11 @@ export const MIN_HEADER_SIZE = 2; // 1-byte ID and 1-byte size export const MAX_HEADER_SIZE = 2 * MAX_VAR_INT_SIZE; // 8-byte ID and 8-byte size export const readVarIntSize = (slice: FileSlice) => { + // Check if we have at least one byte to read + if (slice.remainingLength < 1) { + return null; + } + const firstByte = readU8(slice); slice.skip(-1); @@ -484,10 +489,20 @@ export const readVarIntSize = (slice: FileSlice) => { mask >>= 1; } + // Check if we have enough bytes to read the full varint + if (slice.remainingLength < width) { + return null; + } + return width; }; export const readVarInt = (slice: FileSlice) => { + // Check if we have at least one byte + if (slice.remainingLength < 1) { + return null; + } + // Read the first byte to determine the width of the variable-length integer const firstByte = readU8(slice); @@ -503,6 +518,13 @@ export const readVarInt = (slice: FileSlice) => { mask >>= 1; } + // Check if we have enough bytes remaining for the full varint + if (slice.remainingLength < width - 1) { + // Not enough bytes, rewind and return null + slice.skip(-1); + return null; + } + // First byte's value needs the marker bit cleared let value = firstByte & (mask - 1); @@ -567,37 +589,69 @@ export const readElementId = (slice: FileSlice) => { return id; }; -export const readElementSize = (slice: FileSlice) => { - let size: number | null = readU8(slice); - - if (size === 0xff) { - size = null; - } else { - slice.skip(-1); - size = readVarInt(slice); - - // In some (livestreamed) files, this is the value of the size field. While this technically is just a very - // large number, it is intended to behave like the reserved size 0xFF, meaning the size is undefined. We - // catch the number here. Note that it cannot be perfectly represented as a double, but the comparison works - // nonetheless. - // eslint-disable-next-line no-loss-of-precision - if (size === 0x00ffffffffffffff) { - size = null; - } - } - - return size; -}; - -export const readElementHeader = (slice: FileSlice) => { - const id = readElementId(slice); - if (id === null) { +/** + * Reads the size field of an EBML element. + * + * @returns + * - `{ size: number }` - Successfully read a definite size + * - `{ size: null }` - Successfully read an undefined size (0xFF marker, used in streaming) + * - `null` - Couldn't read (insufficient bytes or invalid data) + */ +export const readElementSize = (slice: FileSlice): { size: number | null } | null => { + // Need at least 1 byte to read the size + if (slice.remainingLength < 1) { return null; } - const size = readElementSize(slice); + const firstByte = readU8(slice); - return { id, size }; + if (firstByte === 0xff) { + // Legitimate undefined size marker + return { size: null }; + } + + slice.skip(-1); + const size = readVarInt(slice); + + if (size === null) { + // Couldn't read the varint (insufficient bytes or invalid) + return null; + } + + // In some (livestreamed) files, this is the value of the size field. While this technically is just a very + // large number, it is intended to behave like the reserved size 0xFF, meaning the size is undefined. We + // catch the number here. Note that it cannot be perfectly represented as a double, but the comparison works + // nonetheless. + // eslint-disable-next-line no-loss-of-precision + if (size === 0x00ffffffffffffff) { + return { size: null }; + } + + return { size }; +}; + +export const readElementHeader = (slice: FileSlice) => { + // We need at least MIN_HEADER_SIZE bytes to read a header + if (slice.remainingLength < MIN_HEADER_SIZE) { + return null; + } + + const startPos = slice.filePos; + + const id = readElementId(slice); + if (id === null) { + slice.filePos = startPos; + return null; + } + + const sizeResult = readElementSize(slice); + if (sizeResult === null) { + // Couldn't read size - rewind to start + slice.filePos = startPos; + return null; + } + + return { id, size: sizeResult.size }; }; export const readAsciiString = (slice: FileSlice, length: number) => { diff --git a/src/matroska/matroska-demuxer.ts b/src/matroska/matroska-demuxer.ts index db421b6..ab2db28 100644 --- a/src/matroska/matroska-demuxer.ts +++ b/src/matroska/matroska-demuxer.ts @@ -908,9 +908,7 @@ export class MatroskaDemuxer extends Demuxer { } readContiguousElements(slice: FileSlice, stopIds?: number[]) { - const startIndex = slice.filePos; - - while (slice.filePos - startIndex <= slice.length - MIN_HEADER_SIZE) { + while (slice.remainingLength >= MIN_HEADER_SIZE) { const startPos = slice.filePos; const foundElement = this.traverseElement(slice, stopIds); From 7b036fe8ac12ee86b0bd5f0fb640eb6fff4d12c4 Mon Sep 17 00:00:00 2001 From: Vanilagy <1696106+Vanilagy@users.noreply.github.com> Date: Mon, 12 Jan 2026 11:59:37 +0100 Subject: [PATCH 2/3] Fix some things --- src/input-format.ts | 7 ++--- src/matroska/ebml.ts | 51 +++++++++++--------------------- src/matroska/matroska-demuxer.ts | 12 ++++---- 3 files changed, 26 insertions(+), 44 deletions(-) diff --git a/src/input-format.ts b/src/input-format.ts index 1c0e292..db1e5b7 100644 --- a/src/input-format.ts +++ b/src/input-format.ts @@ -154,11 +154,10 @@ export class MatroskaInputFormat extends InputFormat { return false; } - const dataSizeResult = readElementSize(headerSlice); - if (dataSizeResult === null || dataSizeResult.size === null) { + const dataSize = readElementSize(headerSlice); + if (typeof dataSize !== 'number') { return false; // Miss me with that shit } - const dataSize = dataSizeResult.size; let dataSlice = input._reader.requestSlice(headerSlice.filePos, dataSize); if (dataSlice instanceof Promise) dataSlice = await dataSlice; @@ -172,7 +171,7 @@ export class MatroskaInputFormat extends InputFormat { const { id, size } = header; const dataStartPos = dataSlice.filePos; - if (size === null) return false; + if (size === undefined) return false; switch (id) { case EBMLId.EBMLVersion: { diff --git a/src/matroska/ebml.ts b/src/matroska/ebml.ts index 0df632d..891adab 100644 --- a/src/matroska/ebml.ts +++ b/src/matroska/ebml.ts @@ -7,7 +7,7 @@ */ import { MediaCodec } from '../codec'; -import { assertNever, textDecoder, textEncoder } from '../misc'; +import { assert, assertNever, textDecoder, textEncoder } from '../misc'; import { FileSlice, readBytes, Reader, readF32Be, readF64Be, readU8 } from '../reader'; import { Writer } from '../writer'; @@ -470,7 +470,6 @@ export const MIN_HEADER_SIZE = 2; // 1-byte ID and 1-byte size export const MAX_HEADER_SIZE = 2 * MAX_VAR_INT_SIZE; // 8-byte ID and 8-byte size export const readVarIntSize = (slice: FileSlice) => { - // Check if we have at least one byte to read if (slice.remainingLength < 1) { return null; } @@ -498,7 +497,6 @@ export const readVarIntSize = (slice: FileSlice) => { }; export const readVarInt = (slice: FileSlice) => { - // Check if we have at least one byte if (slice.remainingLength < 1) { return null; } @@ -518,10 +516,8 @@ export const readVarInt = (slice: FileSlice) => { mask >>= 1; } - // Check if we have enough bytes remaining for the full varint if (slice.remainingLength < width - 1) { - // Not enough bytes, rewind and return null - slice.skip(-1); + // Not enough bytes return null; } @@ -585,19 +581,16 @@ export const readElementId = (slice: FileSlice) => { return null; } + if (slice.remainingLength < size) { + return null; // It don't fit + } + const id = readUnsignedInt(slice, size); return id; }; -/** - * Reads the size field of an EBML element. - * - * @returns - * - `{ size: number }` - Successfully read a definite size - * - `{ size: null }` - Successfully read an undefined size (0xFF marker, used in streaming) - * - `null` - Couldn't read (insufficient bytes or invalid data) - */ -export const readElementSize = (slice: FileSlice): { size: number | null } | null => { +/** Returns `undefined` to indicate the EBML undefined size. Returns `null` if the size couldn't be read. */ +export const readElementSize = (slice: FileSlice): number | undefined | null => { // Need at least 1 byte to read the size if (slice.remainingLength < 1) { return null; @@ -606,15 +599,13 @@ export const readElementSize = (slice: FileSlice): { size: number | null } | nul const firstByte = readU8(slice); if (firstByte === 0xff) { - // Legitimate undefined size marker - return { size: null }; + return undefined; } slice.skip(-1); const size = readVarInt(slice); if (size === null) { - // Couldn't read the varint (insufficient bytes or invalid) return null; } @@ -624,34 +615,26 @@ export const readElementSize = (slice: FileSlice): { size: number | null } | nul // nonetheless. // eslint-disable-next-line no-loss-of-precision if (size === 0x00ffffffffffffff) { - return { size: null }; + return undefined; } - return { size }; + return size; }; export const readElementHeader = (slice: FileSlice) => { - // We need at least MIN_HEADER_SIZE bytes to read a header - if (slice.remainingLength < MIN_HEADER_SIZE) { - return null; - } - - const startPos = slice.filePos; + assert(slice.remainingLength >= MIN_HEADER_SIZE); const id = readElementId(slice); if (id === null) { - slice.filePos = startPos; return null; } - const sizeResult = readElementSize(slice); - if (sizeResult === null) { - // Couldn't read size - rewind to start - slice.filePos = startPos; + const size = readElementSize(slice); + if (size === null) { return null; } - return { id, size: sizeResult.size }; + return { id, size }; }; export const readAsciiString = (slice: FileSlice, length: number) => { @@ -774,8 +757,8 @@ export const CODEC_STRING_MAP: Partial> = { 'webvtt': 'S_TEXT/WEBVTT', }; -export function assertDefinedSize(size: number | null): asserts size is number { - if (size === null) { +export function assertDefinedSize(size: number | undefined): asserts size is number { + if (size === undefined) { throw new Error('Undefined element size is used in a place where it is not supported.'); } }; diff --git a/src/matroska/matroska-demuxer.ts b/src/matroska/matroska-demuxer.ts index ab2db28..feffbff 100644 --- a/src/matroska/matroska-demuxer.ts +++ b/src/matroska/matroska-demuxer.ts @@ -364,7 +364,7 @@ export class MatroskaDemuxer extends Demuxer { // doesn't contain any of the clusters that follow it. In the case, we apply the following logic: if // we find a top-level cluster, attribute it to the previous segment. - if (size === null) { + if (size === undefined) { // Just in case this is one of those weird sizeless clusters, let's do our best and still try to // determine its size. const nextElementPos = await searchForNextElementId( @@ -389,7 +389,7 @@ export class MatroskaDemuxer extends Demuxer { })(); } - async readSegment(segmentDataStart: number, dataSize: number | null) { + async readSegment(segmentDataStart: number, dataSize: number | undefined) { this.currentSegment = { seekHeadSeen: false, infoSeen: false, @@ -406,7 +406,7 @@ export class MatroskaDemuxer extends Demuxer { cuePoints: [], dataStartPos: segmentDataStart, - elementEndPos: dataSize === null + elementEndPos: dataSize === undefined ? null // Assume it goes until the end of the file : segmentDataStart + dataSize, clusterSeekStartPos: segmentDataStart, @@ -483,7 +483,7 @@ export class MatroskaDemuxer extends Demuxer { break; // Stop at the first cluster } - if (size === null) { + if (size === undefined) { break; } else { currentPos = dataStartPos + size; @@ -606,7 +606,7 @@ export class MatroskaDemuxer extends Demuxer { let size = elementHeader.size; const dataStartPos = headerSlice.filePos; - if (size === null) { + if (size === undefined) { // The cluster's size is undefined (can happen in livestreamed files). We'd still like to know the size of // it, so we have no other choice but to iterate over the EBML structure until we find an element at level // 0 or 1, indicating the end of the cluster (all elements inside the cluster are at level 2). @@ -2220,7 +2220,7 @@ abstract class MatroskaTrackBacking implements InputTrackBacking { } } - if (size === null) { + if (size === undefined) { // Undefined element size (can happen in livestreamed files). In this case, we need to do some // searching to determine the actual size of the element. From d6b518b9fd6fe2442add14b64a1d0991812e96e0 Mon Sep 17 00:00:00 2001 From: Vanilagy <1696106+Vanilagy@users.noreply.github.com> Date: Mon, 12 Jan 2026 14:07:43 +0100 Subject: [PATCH 3/3] Fix thing --- src/matroska/matroska-demuxer.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/matroska/matroska-demuxer.ts b/src/matroska/matroska-demuxer.ts index feffbff..2d7c9f9 100644 --- a/src/matroska/matroska-demuxer.ts +++ b/src/matroska/matroska-demuxer.ts @@ -346,7 +346,7 @@ export class MatroskaDemuxer extends Demuxer { } else if (id === EBMLId.Segment) { // Segment found! await this.readSegment(dataStartPos, size); - if (size === null) { + if (size === undefined) { // Segment sizes can be undefined (common in livestreamed files), so assume this is the last // and only segment break;