Repository navigation
Conversation
lusoris
force-pushed
the
fix/speed-init-too-small
branch
2 times, most recently
from
October 1, 2026 18:11
90786f0 to
c439aa7
Compare
lusoris
force-pushed
the
fix/speed-init-too-small
branch
from
October 2, 2026 05:22
c439aa7 to
3b8f59b
Compare
speed_init_dimensions() returns -EINVAL when a plane holds no complete block after the scale reductions, but speed_init() ignored it, and init_chroma() and the speed_temporal init() ignored speed_init()'s return. Extraction then ran with zero blocks and compute_mean() read past the end of the frame buffer: any 4:2:0 frame under 160 pixels in either dimension crashed speed_chroma, which every vmaf_v1.0.16 model uses. Return both errors so the extractor fails to initialize. The check runs before any allocation. Add tests for speed_init() at 128x72 and 128x80 and for the registered speed_chroma extractor at 256x144. Co-Authored-By: Claude Opus 5.5 <[email protected]>
lusoris
force-pushed
the
fix/speed-init-too-small
branch
from
October 2, 2026 18:38
3b8f59b to
82a481d
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
speed_init_dimensions()detects a plane that is too small to hold one 5x5 block after the scale reductions. It logsSpEED: image too small, operating width or height is 0and returns-EINVAL.speed_init()ignores that return value (speed.c:1076), andinit_chroma()and thespeed_temporalinit()ignorespeed_init()'s return in turn (speed.c:1342and:1575). Extraction then runs with zero blocks:submatrix_widthandsubmatrix_heightwrap, andcompute_mean()reads past the end of the frame buffer (speed.c:683).speed_chromaworks on the chroma planes, so with 4:2:0 input any frame under 160 pixels wide or high reaches this.speed_temporalworks on luma and reaches it under 80 pixels. All eightvmaf_v1.0.16models usespeed_chroma, so measuring a 256x144 rung with, for example, the built-invmaf_v1.0.16_3d0hcrashes.This returns both errors, so the extractor fails to initialize and
vmafstops withproblem reading picturesand a non-zero exit status. The size check runs before any allocation, so nothing leaks, and every size that worked before takes the same path as before.Reproducer, three 256x144 4:2:0 frames:
Under AddressSanitizer the unpatched run reports a heap-buffer-overflow in
compute_mean(); the patched run reports nothing from SpEED.Tests:
test_speed_chromagains two tests.test_speed_init_rejects_frame_below_one_blockexpectsspeed_init()to reject a 128x72 plane without allocating, and to accept 128x80, the smallest plane with one block.test_speed_chroma_init_rejects_144pinitializes the registeredspeed_chromaextractor at 256x144 4:2:0.Against the unpatched
speed.cthe first fails withspeed_init() accepted a plane with no complete block.Validation against upstream
9e48141bd1eb8d2329e09d3744e7c24af53017ca, x86-64 Linux (AVX-512 host), GCC 16.2.1, Meson 1.12.1. Rebased on master 9e48141 (2026-10-02):--feature speed_chroma --feature speed_temporalgives JSON identical to the unpatched build at 320x180, 256x160, 160x256 and 576x324, apart from thefpsfield. None of the Netflix reference pairs uses SpEED, so no golden value can change.Overlap: #1574 and #1551 also edit
speed.c; this adds no conflict with either.