Skip to content

fix: RangeError flood when the MSE staging buffer overflows - #2381

Open
paolostivanin wants to merge 1 commit into
AlexxIT:masterfrom
paolostivanin:master
Open

fix: RangeError flood when the MSE staging buffer overflows#2381
paolostivanin wants to merge 1 commit into
AlexxIT:masterfrom
paolostivanin:master

Conversation

@paolostivanin

Copy link
Copy Markdown

video-rtc.js buffers incoming websocket frames into a fixed 2 MiB Uint8Array while the SourceBuffer is busy, and drains it on updateend. Two gaps make that wedge permanently:

  • if the drain's appendBuffer throws (QuotaExceededError is the common one, when a mobile browser backgrounds the tab and the decoder stops evicting), the exception is swallowed and bufLen is never reset. No update cycle was started, so updateend never fires again and the drain is never re-entered.
  • ondata then always takes the buffering branch, and buf.set(b, bufLen) has no bounds check. Once bufLen passes 2 MiB it throws "RangeError: offset is out of bounds" on every frame that arrives, at stream frame rate, until the socket closes.

Observed as ~150 errors/second reported back to the server by Home Assistant's frontend error reporter.

Reset bufLen when the drain fails, and bound-check the staging append, dropping the backlog and restarting the update cycle so the stream can resync on the next keyframe.

video-rtc.js buffers incoming websocket frames into a fixed 2 MiB
Uint8Array while the SourceBuffer is busy, and drains it on updateend.
Two gaps make that wedge permanently:

- if the drain's appendBuffer throws (QuotaExceededError is the common
  one, when a mobile browser backgrounds the tab and the decoder stops
  evicting), the exception is swallowed and bufLen is never reset. No
  update cycle was started, so updateend never fires again and the
  drain is never re-entered.
- ondata then always takes the buffering branch, and buf.set(b, bufLen)
  has no bounds check. Once bufLen passes 2 MiB it throws
  "RangeError: offset is out of bounds" on every frame that arrives,
  at stream frame rate, until the socket closes.

Observed as ~150 errors/second reported back to the server by Home
Assistant's frontend error reporter.

Reset bufLen when the drain fails, and bound-check the staging append,
dropping the backlog and restarting the update cycle so the stream can
resync on the next keyframe.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant