stagefright aacenc: Avoid overflows when calculating normFactor
normFactor is calculated using the saturating L_add function, but if the value added (*psfbPeFactors) is negative, the sum can end up negative. *psfbPeFactors can end up negative if redThrExp is less than *psfbNActiveLines. In cases where *psfbPeFactors ended up negative, normFactor became INT_MIN, causing division by zero later. Change-Id: I00c852e457b22f7eef4d6ed1887629828057206b
This commit is contained in:
@@ -437,7 +437,7 @@ static void correctThresh(PSY_OUT_CHANNEL psyOutChannel[MAX_CHANNELS],
|
||||
for (sfb=0; sfb<psyOutChan->maxSfbPerGroup; sfb++) {
|
||||
Word32 redThrExp = thrExp[ch][sfbGrp+sfb] + redVal;
|
||||
|
||||
if (((*pahFlag < AH_ACTIVE) || (deltaPe > 0)) && (redThrExp > 0) ) {
|
||||
if (((*pahFlag < AH_ACTIVE) || (deltaPe > 0)) && (redThrExp > 0) && (redThrExp >= *psfbNActiveLines)) {
|
||||
|
||||
*psfbPeFactors = (*psfbNActiveLines) * (0x7fffffff / redThrExp);
|
||||
normFactor = L_add(normFactor, *psfbPeFactors);
|
||||
|
||||
Reference in New Issue
Block a user