diff options
| author | Paul Schwabauer <paul@schwabauer.co> | 2026-03-21 19:34:18 +0100 |
|---|---|---|
| committer | GitHub <noreply@github.com> | 2026-03-21 18:34:18 +0000 |
| commit | b6bf97e2f199ae9c947e3b192b690c1d6257517b (patch) | |
| tree | c99ab26452b61e8eb75ea11b5860339f862bb1b5 /soh/src/code/debug_malloc.c | |
| parent | 43f77c13fb9bddf318f445345bd23b5bd2d1ee7a (diff) | |
Fix ADPCM sample buffer overread in audio synthesis (#6364)
The sampleDataStartPad and aligned variables existed solely to satisfy
the N64 RSP DMA requirement that source addresses be 16-byte aligned.
On PC, aLoadBuffer is a plain memcpy with no such constraint.
The alignment dance caused aLoadBuffer to read up to 15 bytes before
sampleData and up to 8+ bytes past the end of the sample buffer. On
platforms with strict allocator guard pages (e.g. OpenBSD), this
triggers a SIGSEGV.
A second issue remains after removing the alignment dance: nFramesToDecode
is derived from sample counts (loopEnd), but size is not always a multiple
of frameSize. loopEnd and size are derived independently during encoding
and can disagree on the final partial frame, leaving nFramesToDecode *
frameSize exceeding the remaining bytes in the buffer.
Remove sampleDataStartPad and aligned entirely. Clamp the load to
min(nFramesToDecode * frameSize, audioFontSample->size - sampleDataOffset).
The ADPCM decoder operates on DMEM, so a partial last frame in DMEM
produces at most a negligible artifact at sound termination.
Diffstat (limited to 'soh/src/code/debug_malloc.c')
0 files changed, 0 insertions, 0 deletions
