3 KiB
libvorbis (Ogg Vorbis) — 5-MOAD Scan Result: CLEAN
Target: xiph/vorbis Source: https://github.com/xiph/vorbis Scan Date: 2026-03-31 Language: C
MOAD-0001 — CWE-407: Algorithmic Complexity (list membership in loop)
Candidates investigated
lib/floor1.c — floor1_look() neighbor search (lines 233–252)
Double loop: outer over n-2 posts (n ≤ VIF_POSIT+2 = 65), inner over i+2
prior posts. O(n²) = O(63²) = ~3969 ops. Runs once per codec setup call, not
per frame. Bounded absolutely by spec constant VIF_POSIT=63. Not actionable.
lib/res0.c — _01class() / _2class() partition threshold scan (lines 441–444, 505–508)
For each partition value, a linear scan through possible_partitions to find
our threshold bracket. Outer loop is over partvals (n/grouping, where n is
residue length and grouping is typically 32). Inner scan is at most
possible_partitions-1 ≤ 63 (6-bit field per spec). Both dimensions are
codec-spec bounded. In practice: 64 partvals × 63 partitions = 4032 comparisons
per frame. Not an O(N²) growth pattern over user-controlled input. Not actionable.
lib/psy.c — noise_normalize() qsort call
Sorts up to n floats per partition band. Uses qsort (O(n log n)). CLEAN.
lib/floor1.c — per-frame floor1_forward_block() neighbor update (lines 680–689)
Two inner loops over posts positions when a new split post is accepted. Both
break immediately on first mismatch — amortized O(posts) total across all splits
per frame. Not O(posts²). CLEAN.
lib/vorbisfile.c — serialno scan (lines 840–841, 1373–1374)
Linear scan of vf->serialnos[link] inside page-reading loop. vf->links is
the number of chained bitstreams in the file — typically 1–3 for real files.
Seek-path only, not hot decode path. CLEAN.
Verdict: CLEAN — no CWE-407 defects
MOAD-0002 — Intertangle: shared mutable global state / god object
No mutable process-global state in the encode/decode path. All per-session state
lives in vorbis_dsp_state, vorbis_block, vorbis_info — caller-owned structs.
lib/misc.c global tracking (pointers, global_bytes) is #ifdef DEBUG_MALLOC
only — not compiled in production. mapping0.c seq/total statics are inside
#if 0 dead code block. CLEAN.
MOAD-0003 — Leaked Context: ThreadLocal / thread-scoped request identity
No pthread_getspecific, __thread, thread_local, or equivalent in any
encode/decode path. Pure C library with caller-owned state. CLEAN.
MOAD-0004 — CWE-312: credentials or keys logged verbatim
Pure audio codec library. No auth flows, HTTP headers, API keys, or credential handling anywhere in our codebase. CLEAN.
MOAD-0005 — Thundering Herd: unsynchronized cache get+null+compute+put
No caching with unsynchronized double-checked access. lib/floor0.c/floor1.c
memo arrays are stack-local per-block, passed explicitly. lib/smallft.c
trigcache is computed once during drft_init in single-threaded setup, never
updated after initialization. CLEAN.