Commit Graph
16 Commits
Author SHA1 Message Date
TristanInSec 476677b0f0 Fix OOB reads and infinite loop in TLV and DMAP parsers
pair_ap/pair-tlv.c (pair_tlv_parse):
- Add bounds check before reading type and length bytes (i + 2 > length)
- Fix off-by-one in chunked TLV scan loop (j + 1 < length)
- Add bounds checks inside data copy loop to prevent OOB memcpy
- Add else branch to advance index when size == 0 (prevents infinite loop)

rtsp.c (handle_set_parameter_metadata):
- Require 8 bytes remaining for tag + length fields (off + 8 <= cl)
- Validate value length against remaining buffer before read

Reported-by: Tristan Madani <tristan@talencesecurity.com>
Signed-off-by: Tristan Madani <tristan@talencesecurity.com>
2026-06-16 10:33:18 -04:00
Mike Brady 11052b7896 Lot of changes here.
1. check_classic_mac_basic.yml — update to latest macOS-latest
2. docker-on-push-tag-or-pr — dependant updates
3. FFTConvolver — fix a compilation warning when the DEBUG flag is turned off
4. Reorganise some source files — e.g. move most of the metadata stuff into a subdirectory
5. Remove unused special-purpose AirPlay 2 RC event handler.
6. Reorganise source files and source code relating to the standard event handler.
7. Check configuration settings a little more carefully to offer more meaningful diagnostics.
8. Add password to AirPlay 2 and reorganise initialisation to set AirPlay 2 flags accordingly.  Also, remove redundant airplay_pin.
9. Remove redundant debug facility definitions from common.h
10. Make it possible to omit all the dacp stuff from a build.
11. Make it possible to omit metadata multicast from a build.
12. Add AP2-native metadata by setting bit 50 of features to true.
13. Improve stability when pre-empting an existing play session.
14. Fix a few compiler warnings in the pair_ap library.
15. Ensure that the audio format is known before starting synchronisation.
16. Improve handle_configure to set/clear a new config setting. Doesn’t seem to do anything…
17. Experimentally turn off bit 46 of AirPlay 2 features — seems to stop failing pair-verify attempts.
2026-04-26 10:23:18 +01:00
Mike Brady 60143518c2 This squashed commit comprises a long series of improvements, bug fixes, optimizations, and new feature additions:
- 48,000 frames per second operation,
 - 48k lossless stereo, 5.1 and 7.1 surround sound
 - Multichannel and multi rate operation on ALSA, PipeWire, PulseAudio, FreeBSD, stdout and unix pipe output backends.

Automatic, flexible and controllable output format (rate, sample format and channel count) selection.

Full FFmpeg integration to support transcoding, resampling, and new audio formats.

Better operation on lower powered devices down to e.g. Raspberry Pi B.

Reduced Docker image sizes with a slimmed-down FFmpeg library.

Enhanced timestamp handling for better synchronization.

Improved the sync error calculation.

A new "vernier" resampling and interpolation method for low-power CPUs.

Bug fixes and minor enhancements.

Note -- there are many breaking changes from previous versions of Shairport Sync!
2025-02-23 13:31:17 +00:00
Mike Brady 0f476da0ee Update the pair_ap library. Thanks again to ejurgensen for this code. 2022-09-26 17:24:04 +01:00
Mike Brady 429c5dc002 Add update to ejurgensen's pair_ap library. Thanks as always. 2021-12-08 11:59:09 +00:00
Mike Brady 1032cad684 Update to the latest version of ejurgensen's pair_ap library. With thanks. 2021-11-14 14:13:31 +00:00
Mike Brady 02734e58c2 Merge with the aillwee development branch 2021-09-16 17:54:47 +01:00
ejurgensen 978862c2ec Update pair_ap to 0.8 (fixes incorrect pair-list response) 2021-07-15 23:22:56 +02:00
ejurgensen 1959d2cf0c Update pair_ap to 0.7 (fixes incorrect pair-list response) 2021-07-13 22:28:34 +02:00
Mike Brady 94e47fdf9e Include pair_ap as a simple directory. 2021-07-07 14:11:32 +00:00
Mike Brady 5915c91fc5 Stop including pair_ap as a gi submodule. It will be included as a simple subdirectory instead. 2021-07-07 13:45:11 +00:00
Mike Brady e925e196c8 Changes to allow it to compile in FreeBSD and fix a few issues that were picked up by clang 10. 2021-06-22 13:49:11 +01:00
Mike Brady 3143e9983a Updates to pair_ap 2021-05-23 10:13:14 +01:00
ejurgensen 0aa3b3fee3 Return same pairing errors as other Airplay devices
- 470 on general errors
- TLV-formatet authentication error on incorrect PIN/signature

The latter makes sure clients clear saved credentials, so the user isn't stuck
with a device that keeps using incorrect credentials.
2021-05-07 19:10:07 +02:00
ejurgensen 493e9604d3 Use pair_ap for pairing and rtsp encryption 2021-05-04 20:34:37 +02:00
Mike Brady c862dc5c5b pair_ap added as a submodule 2021-04-27 19:28:55 +01:00