78 lines
3 KiB
Markdown
78 lines
3 KiB
Markdown
# libvorbis (Ogg Vorbis) — 5-MOAD Scan Result: CLEAN
|
||
|
||
**Target:** xiph/vorbis
|
||
**Source:** https://github.com/xiph/vorbis
|
||
**Scan Date:** 2026-03-31
|
||
**Language:** C
|
||
|
||
---
|
||
|
||
## MOAD-0001 — CWE-407: Algorithmic Complexity (list membership in loop)
|
||
|
||
### Candidates investigated
|
||
|
||
**`lib/floor1.c` — `floor1_look()` neighbor search (lines 233–252)**
|
||
|
||
Double loop: outer over `n-2` posts (n ≤ VIF_POSIT+2 = 65), inner over `i+2`
|
||
prior posts. O(n²) = O(63²) = ~3969 ops. Runs once per codec setup call, not
|
||
per frame. Bounded absolutely by spec constant VIF_POSIT=63. Not actionable.
|
||
|
||
**`lib/res0.c` — `_01class()` / `_2class()` partition threshold scan (lines 441–444, 505–508)**
|
||
|
||
For each partition value, a linear scan through `possible_partitions` to find
|
||
our threshold bracket. Outer loop is over `partvals` (n/grouping, where n is
|
||
residue length and grouping is typically 32). Inner scan is at most
|
||
`possible_partitions-1` ≤ 63 (6-bit field per spec). Both dimensions are
|
||
codec-spec bounded. In practice: 64 partvals × 63 partitions = 4032 comparisons
|
||
per frame. Not an O(N²) growth pattern over user-controlled input. Not actionable.
|
||
|
||
**`lib/psy.c` — `noise_normalize()` qsort call**
|
||
|
||
Sorts up to `n` floats per partition band. Uses qsort (O(n log n)). CLEAN.
|
||
|
||
**`lib/floor1.c` — per-frame `floor1_forward_block()` neighbor update (lines 680–689)**
|
||
|
||
Two inner loops over `posts` positions when a new split post is accepted. Both
|
||
break immediately on first mismatch — amortized O(posts) total across all splits
|
||
per frame. Not O(posts²). CLEAN.
|
||
|
||
**`lib/vorbisfile.c` — serialno scan (lines 840–841, 1373–1374)**
|
||
|
||
Linear scan of `vf->serialnos[link]` inside page-reading loop. `vf->links` is
|
||
the number of chained bitstreams in the file — typically 1–3 for real files.
|
||
Seek-path only, not hot decode path. CLEAN.
|
||
|
||
### Verdict: CLEAN — no CWE-407 defects
|
||
|
||
---
|
||
|
||
## MOAD-0002 — Intertangle: shared mutable global state / god object
|
||
|
||
No mutable process-global state in the encode/decode path. All per-session state
|
||
lives in `vorbis_dsp_state`, `vorbis_block`, `vorbis_info` — caller-owned structs.
|
||
`lib/misc.c` global tracking (`pointers`, `global_bytes`) is `#ifdef DEBUG_MALLOC`
|
||
only — not compiled in production. `mapping0.c` `seq`/`total` statics are inside
|
||
`#if 0` dead code block. CLEAN.
|
||
|
||
---
|
||
|
||
## MOAD-0003 — Leaked Context: ThreadLocal / thread-scoped request identity
|
||
|
||
No `pthread_getspecific`, `__thread`, `thread_local`, or equivalent in any
|
||
encode/decode path. Pure C library with caller-owned state. CLEAN.
|
||
|
||
---
|
||
|
||
## MOAD-0004 — CWE-312: credentials or keys logged verbatim
|
||
|
||
Pure audio codec library. No auth flows, HTTP headers, API keys, or credential
|
||
handling anywhere in our codebase. CLEAN.
|
||
|
||
---
|
||
|
||
## MOAD-0005 — Thundering Herd: unsynchronized cache get+null+compute+put
|
||
|
||
No caching with unsynchronized double-checked access. `lib/floor0.c`/`floor1.c`
|
||
memo arrays are stack-local per-block, passed explicitly. `lib/smallft.c`
|
||
trigcache is computed once during `drft_init` in single-threaded setup, never
|
||
updated after initialization. CLEAN.
|