Conversation
prcwidth=1 (and likewise prcheight=1) yields prc widthexpn=0 via jpc_floorlog2, which is accepted by the positive-value option check. For resolution levels above 0 the encoder then computes cbgwidthexpn = prcwidthexpn - 1 = -1, and the negative exponent makes the precinct/code-block geometry produce zero code blocks, ending in a reachable assertion in jpc_tagtree_create() (SIGABRT) or a negative shift exponent (UB). The decoder already rejects prcwidthexpn < 1 (jpc_dec.c); mirror that bound in cp_create() where the > 15 check already lives, so invalid options are rejected at option-parse time. Fixes jasper-software#422.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes #422 —
prcwidth=1(andprcheight=1) passes the encoder's positive-value option check, butjpc_floorlog2(1) = 0, soprcwidthexpn = 0. For every resolution level above 0 the encoder then computescbgwidthexpn = prcwidthexpn - 1 = -1, the negative exponent drives the code-block-group geometry to produce zero code blocks, andjpc_tagtree_create(0, ...)aborts onassert(numleafsh > 0 && numleafsv > 0)(SIGABRT; a negative shift exponent under UBSan).Fix
The decoder already rejects
prcwidthexpn < 1for every resolution level (jpc_dec.c:837). This adds the mirror bound incp_create(), right where the existing> 15checks live, so the invalid option is rejected at option-parse time with a proper error message.Testing
jasper --input in.pgm --output out.jpc --output-format jpc -O prcwidth=1→runtime error: shift exponent 4294967295 is too large(UBSan) / assertion abort (release)invalid precinct width→jpc_encode failed(graceful)prcwidth=4and default encoding still work normally