mirror of
https://github.com/opencv/opencv.git
synced 2026-09-28 04:09:42 +03:00
video: fix DISOpticalFlow heap-buffer-overflow with patch_size > border_size - #29715 Fixes #20185. ### What `DISOpticalFlowImpl` pads `I1` of every pyramid level with a **fixed 16 pixel border** (`border_size`), while `PatchInverseSearch` clamps a patch's sample position to: ```cpp float i_lower_limit = bsz - psz + 1.0f; // bsz = border_size, psz = patch_size float i_upper_limit = bsz + dis->h - 1.0f; ``` i.e. a patch may be placed up to `patch_size - 1` pixels outside of the image. `computeSSD()`/`computeSSDMeanNorm()` then read `patch_size` (+1 for bilinear interpolation) rows/columns starting at that clamped position, which stays inside the padded buffer only while `patch_size <= border_size`. `patch_size` is user-settable via `setPatchSize()` with no upper bound relative to the hardcoded `border_size` -- so `setPatchSize()` past 16, or a temporal-candidate flow large enough to push the clamped search against its limit, reads past the end of `I1s_ext` (confirmed via AddressSanitizer: heap-buffer-overflow in `computeSSDMeanNorm`). ### Fix Size the border to whichever is larger, exactly once, at the top of `prepareBuffers()` (where every `I1s_ext[i]` already gets freshly created/padded on every `calc()` call, so this doesn't need any additional cache-invalidation logic): ```cpp border_size = max(16, patch_size); ``` The needed inequality (`border_size >= patch_size`) is independent of image size, so this is sufficient at every pyramid level uniformly. `ocl_prepareBuffers()` does not need the equivalent change: `calc()`'s `CV_OCL_RUN` gate only takes the OpenCL path when `patch_size == 8` exactly, which is always within the hardcoded border, so that path can never reach this overflow. ### On the prior attempt A prior attempt at this exact fix (#29600) was closed by @asmorkalov, who ran its own added regression test and got the same ASan heap-buffer-overflow again ("the patch is not efficient"). I want to be upfront about this rather than just re-submitting the same-looking diff: **I could not reproduce that failure.** I reproduced the original overflow on unfixed 5.x (same crash site / allocator stack as both the original issue report and #29600's own ASan trace), then applied the same one-line fix and ran #29600's own added test 20x plus a new 40-trial randomized stress test (`patch_size` 9-48 -- spanning above and below `border_size=16` -- varying image size, `patch_stride`, flow magnitude up to 120px, and a same-instance second `calc()` call to exercise buffer re-use across a patch-size change) under AddressSanitizer, with zero failures. I don't have a confirmed explanation for the discrepancy -- possibly a stale incremental build on the original attempt's end, since I hit and had to work around exactly that kind of false "no work to do" ninja build-cache issue myself while setting up this reproduction. Flagging this openly rather than asserting certainty either way -- happy to dig further if CI or review surfaces a case this doesn't cover. ### Testing Verified locally with a dedicated ASan-instrumented Debug build (`-fsanitize=address`, separate from the Release build used to verify the rest of today's changes), specifically because an out-of-bounds read like this often just silently returns garbage in a Release build instead of crashing: - Confirmed the crash reproduces on unfixed 5.x, and is gone with the fix, under both `regression_20185_patch_larger_than_border` (from #29600, included here) and a new `regression_20185_stress` test (40 randomized trials) -- both passing cleanly under ASan. - Re-verified both tests pass in the standard Release configuration too. - Full `opencv_test_video` suite (both ASan and Release): no failures attributable to this change; everything else failing needs `opencv_extra` test data (tracking/ECC/optical-flow reference videos/images) not configured in this scoped build. ### PR checklist - [x] I agree to contribute to the project under Apache 2 License. - [x] To the best of my knowledge, the proposed patch is not based on code under GPL or another incompatible license. - [x] The PR is proposed to the proper branch (5.x). - [x] Accuracy tests included (see above). - [x] No public API/behavior change, so no documentation or sample updates needed.
221 lines
7.4 KiB
C++
221 lines
7.4 KiB
C++
/*M///////////////////////////////////////////////////////////////////////////////////////
|
|
//
|
|
// IMPORTANT: READ BEFORE DOWNLOADING, COPYING, INSTALLING OR USING.
|
|
//
|
|
// By downloading, copying, installing or using the software you agree to this license.
|
|
// If you do not agree to this license, do not download, install,
|
|
// copy or use the software.
|
|
//
|
|
//
|
|
// Intel License Agreement
|
|
// For Open Source Computer Vision Library
|
|
//
|
|
// Copyright (C) 2000, Intel Corporation, all rights reserved.
|
|
// Third party copyrights are property of their respective owners.
|
|
//
|
|
// Redistribution and use in source and binary forms, with or without modification,
|
|
// are permitted provided that the following conditions are met:
|
|
//
|
|
// * Redistribution's of source code must retain the above copyright notice,
|
|
// this list of conditions and the following disclaimer.
|
|
//
|
|
// * Redistribution's in binary form must reproduce the above copyright notice,
|
|
// this list of conditions and the following disclaimer in the documentation
|
|
// and/or other materials provided with the distribution.
|
|
//
|
|
// * The name of Intel Corporation may not be used to endorse or promote products
|
|
// derived from this software without specific prior written permission.
|
|
//
|
|
// This software is provided by the copyright holders and contributors "as is" and
|
|
// any express or implied warranties, including, but not limited to, the implied
|
|
// warranties of merchantability and fitness for a particular purpose are disclaimed.
|
|
// In no event shall the Intel Corporation or contributors be liable for any direct,
|
|
// indirect, incidental, special, exemplary, or consequential damages
|
|
// (including, but not limited to, procurement of substitute goods or services;
|
|
// loss of use, data, or profits; or business interruption) however caused
|
|
// and on any theory of liability, whether in contract, strict liability,
|
|
// or tort (including negligence or otherwise) arising in any way out of
|
|
// the use of this software, even if advised of the possibility of such damage.
|
|
//
|
|
//M*/
|
|
|
|
#include "test_precomp.hpp"
|
|
|
|
namespace opencv_test { namespace {
|
|
|
|
static string getDataDir() { return TS::ptr()->get_data_path(); }
|
|
|
|
static string getRubberWhaleFrame1() { return getDataDir() + "optflow/RubberWhale1.png"; }
|
|
|
|
static string getRubberWhaleFrame2() { return getDataDir() + "optflow/RubberWhale2.png"; }
|
|
|
|
static string getRubberWhaleGroundTruth() { return getDataDir() + "optflow/RubberWhale.flo"; }
|
|
|
|
static bool isFlowCorrect(float u) { return !cvIsNaN(u) && (fabs(u) < 1e9); }
|
|
|
|
static float calcRMSE(Mat flow1, Mat flow2)
|
|
{
|
|
float sum = 0;
|
|
int counter = 0;
|
|
const int rows = flow1.rows;
|
|
const int cols = flow1.cols;
|
|
|
|
for (int y = 0; y < rows; ++y)
|
|
{
|
|
for (int x = 0; x < cols; ++x)
|
|
{
|
|
Vec2f flow1_at_point = flow1.at<Vec2f>(y, x);
|
|
Vec2f flow2_at_point = flow2.at<Vec2f>(y, x);
|
|
|
|
float u1 = flow1_at_point[0];
|
|
float v1 = flow1_at_point[1];
|
|
float u2 = flow2_at_point[0];
|
|
float v2 = flow2_at_point[1];
|
|
|
|
if (isFlowCorrect(u1) && isFlowCorrect(u2) && isFlowCorrect(v1) && isFlowCorrect(v2))
|
|
{
|
|
sum += (u1 - u2) * (u1 - u2) + (v1 - v2) * (v1 - v2);
|
|
counter++;
|
|
}
|
|
}
|
|
}
|
|
return (float)sqrt(sum / (1e-9 + counter));
|
|
}
|
|
|
|
bool readRubberWhale(Mat &dst_frame_1, Mat &dst_frame_2, Mat &dst_GT)
|
|
{
|
|
const string frame1_path = getRubberWhaleFrame1();
|
|
const string frame2_path = getRubberWhaleFrame2();
|
|
const string gt_flow_path = getRubberWhaleGroundTruth();
|
|
|
|
dst_frame_1 = imread(frame1_path);
|
|
dst_frame_2 = imread(frame2_path);
|
|
dst_GT = readOpticalFlow(gt_flow_path);
|
|
|
|
if (dst_frame_1.empty() || dst_frame_2.empty() || dst_GT.empty())
|
|
return false;
|
|
else
|
|
return true;
|
|
}
|
|
|
|
TEST(DenseOpticalFlow_DIS, ReferenceAccuracy)
|
|
{
|
|
Mat frame1, frame2, GT;
|
|
ASSERT_TRUE(readRubberWhale(frame1, frame2, GT));
|
|
int presets[] = {DISOpticalFlow::PRESET_ULTRAFAST, DISOpticalFlow::PRESET_FAST, DISOpticalFlow::PRESET_MEDIUM};
|
|
float target_RMSE[] = {0.86f, 0.74f, 0.49f};
|
|
cvtColor(frame1, frame1, COLOR_BGR2GRAY);
|
|
cvtColor(frame2, frame2, COLOR_BGR2GRAY);
|
|
|
|
Ptr<DenseOpticalFlow> algo;
|
|
|
|
// iterate over presets:
|
|
for (int i = 0; i < 3; i++)
|
|
{
|
|
Mat flow;
|
|
algo = DISOpticalFlow::create(presets[i]);
|
|
algo->calc(frame1, frame2, flow);
|
|
ASSERT_EQ(GT.rows, flow.rows);
|
|
ASSERT_EQ(GT.cols, flow.cols);
|
|
EXPECT_LE(calcRMSE(GT, flow), target_RMSE[i]);
|
|
}
|
|
}
|
|
|
|
TEST(DenseOpticalFlow_DIS, InvalidImgSize_CoarsestLevelLessThanZero)
|
|
{
|
|
cv::Ptr<cv::DISOpticalFlow> of = cv::DISOpticalFlow::create();
|
|
const int mat_size = 10;
|
|
|
|
cv::Mat x(mat_size, mat_size, CV_8UC1, 42);
|
|
cv::Mat y(mat_size, mat_size, CV_8UC1, 42);
|
|
cv::Mat flow;
|
|
|
|
ASSERT_THROW(of->calc(x, y, flow), cv::Exception);
|
|
}
|
|
|
|
// make sure that autoSelectPatchSizeAndScales() works properly.
|
|
TEST(DenseOpticalFlow_DIS, InvalidImgSize_CoarsestLevelLessThanFinestLevel)
|
|
{
|
|
cv::Ptr<cv::DISOpticalFlow> of = cv::DISOpticalFlow::create();
|
|
const int mat_size = 80;
|
|
|
|
cv::Mat x(mat_size, mat_size, CV_8UC1, 42);
|
|
cv::Mat y(mat_size, mat_size, CV_8UC1, 42);
|
|
cv::Mat flow;
|
|
|
|
of->calc(x, y, flow);
|
|
|
|
ASSERT_EQ(flow.rows, mat_size);
|
|
ASSERT_EQ(flow.cols, mat_size);
|
|
}
|
|
|
|
TEST(DenseOpticalFlow_VariationalRefinement, ReferenceAccuracy)
|
|
{
|
|
Mat frame1, frame2, GT;
|
|
ASSERT_TRUE(readRubberWhale(frame1, frame2, GT));
|
|
float target_RMSE = 0.86f;
|
|
cvtColor(frame1, frame1, COLOR_BGR2GRAY);
|
|
cvtColor(frame2, frame2, COLOR_BGR2GRAY);
|
|
|
|
Ptr<VariationalRefinement> var_ref;
|
|
var_ref = VariationalRefinement::create();
|
|
var_ref->setAlpha(20.0f);
|
|
var_ref->setDelta(5.0f);
|
|
var_ref->setGamma(10.0f);
|
|
var_ref->setSorIterations(25);
|
|
var_ref->setFixedPointIterations(25);
|
|
Mat flow(frame1.size(), CV_32FC2);
|
|
flow.setTo(0.0f);
|
|
var_ref->calc(frame1, frame2, flow);
|
|
ASSERT_EQ(GT.rows, flow.rows);
|
|
ASSERT_EQ(GT.cols, flow.cols);
|
|
EXPECT_LE(calcRMSE(GT, flow), target_RMSE);
|
|
}
|
|
|
|
TEST(DenseOpticalFlow_DIS, ManualCoarsestScale)
|
|
{
|
|
Mat prev = Mat::zeros(Size(320, 240), CV_8UC1);
|
|
Mat next = Mat::zeros(Size(320, 240), CV_8UC1);
|
|
randu(prev, 0, 255);
|
|
randu(next, 0, 255);
|
|
|
|
Ptr<DISOpticalFlow> dis = DISOpticalFlow::create(DISOpticalFlow::PRESET_FAST);
|
|
|
|
EXPECT_EQ(dis->getCoarsestScale(), -1);
|
|
|
|
Mat flow;
|
|
dis->calc(prev, next, flow);
|
|
EXPECT_FALSE(flow.empty());
|
|
int manual_scale = 3;
|
|
dis->setCoarsestScale(manual_scale);
|
|
EXPECT_EQ(dis->getCoarsestScale(), manual_scale);
|
|
|
|
dis->calc(prev, next, flow);
|
|
EXPECT_FALSE(flow.empty());
|
|
|
|
dis->setCoarsestScale(-1);
|
|
EXPECT_EQ(dis->getCoarsestScale(), -1);
|
|
}
|
|
|
|
// See https://github.com/opencv/opencv/issues/20185
|
|
TEST(DenseOpticalFlow_DIS, regression_20185_patch_larger_than_border)
|
|
{
|
|
Mat prev(240, 320, CV_8UC1), next(240, 320, CV_8UC1);
|
|
theRNG().fill(prev, RNG::UNIFORM, 0, 256);
|
|
theRNG().fill(next, RNG::UNIFORM, 0, 256);
|
|
|
|
Ptr<DISOpticalFlow> dis = DISOpticalFlow::create(DISOpticalFlow::PRESET_MEDIUM);
|
|
dis->setPatchStride(10);
|
|
|
|
Mat flow(prev.size(), CV_32FC2, Scalar(60.f, 60.f));
|
|
ASSERT_NO_THROW(dis->calc(prev, next, flow));
|
|
EXPECT_EQ(flow.size(), prev.size());
|
|
|
|
dis->setPatchSize(25);
|
|
flow.setTo(Scalar(60.f, 60.f));
|
|
ASSERT_NO_THROW(dis->calc(prev, next, flow));
|
|
EXPECT_EQ(flow.size(), prev.size());
|
|
}
|
|
|
|
}} // namespace
|