New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Avoid infinite loop on corrupt stream recording #96881
Avoid infinite loop on corrupt stream recording #96881
Conversation
Hey there @hunterjm, @allenporter, mind taking a look at this pull request as it has been labeled with an integration ( Code owner commandsCode owners of
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks, @uvjustin 👍
@@ -151,7 +151,7 @@ def find_moov(mp4_io: BufferedIOBase) -> int: | |||
while 1: | |||
mp4_io.seek(index) | |||
box_header = mp4_io.read(8) | |||
if len(box_header) != 8: | |||
if len(box_header) != 8 or box_header[0:4] == b"\x00\x00\x00\x00": |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
On a general note, this looks like something that should be in a separate library, not in Home Assistant Core 🤷♂️
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We've discussed moving this out of core, and I think we generally agreed it makes sense, but haven't made the plan in more detail or executed on it yet.
* Avoid infinite loop on corrupt stream recording * Update tests
Proposed change
The find_moov function in stream can enter an infinite loop if it encounters corrupt data and reads a box size of 0. This PR adds a check to make sure that the size field is not 0.
Type of change
Additional information
Checklist
black --fast homeassistant tests
)If user exposed functionality or configuration variables are added/changed:
If the code communicates with devices, web services, or third-party tools:
Updated and included derived files by running:
python3 -m script.hassfest
.requirements_all.txt
.Updated by running
python3 -m script.gen_requirements_all
..coveragerc
.To help with the load of incoming pull requests: