Skip to content

fix(ffi): reject invalid SoxResampler parameters at creation - #1471

Closed
RaphaelFakhri wants to merge 2 commits into
livekit:mainfrom
RaphaelFakhri:fix/sox-resampler-invalid-params
Closed

RaphaelFakhri wants to merge 2 commits into
livekit:mainfrom
RaphaelFakhri:fix/sox-resampler-invalid-params

Conversation

@RaphaelFakhri

Copy link
Copy Markdown

Summary

SoxResampler accepted parameters that soxr cannot resample with and returned a resampler that failed later. This change validates them at creation and returns an error instead.

  • A zero, negative or non-finite input or output rate created a resampler. The first push then panicked (verified for a zero input rate).
  • Zero channels created a resampler. The first push panicked on an integer division by zero.
  • soxr_create was called with a null error pointer, so a creation failure was never reported and only produced a null soxr_t.

Because these run behind the FFI boundary, a bad value passed from an SDK such as AudioResampler(input_rate=0, ...) aborts the host process instead of raising an error.

Changes

  • Reject non-finite or non-positive sample rates and zero channels in SoxResamplerInner::new.
  • Pass a real error out-parameter to soxr_create and return its message. A null result without a message returns a generic error.
  • Add invalid_parameters_are_rejected to the resampler tests.
  • Add a livekit-ffi patch changeset.

Testing

cargo test -p livekit-ffi --lib resampler

  • Before the fix, invalid_parameters_are_rejected fails and the other resampler tests pass (7 passed, 1 failed).
  • After the fix, all resampler tests pass (8 passed).
  • cargo fmt -p livekit-ffi -- --check reports no changes.

@CLAassistant

CLAassistant commented Sep 29, 2026 •

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

devin-ai-integration[bot]

This comment was marked as resolved.

@RaphaelFakhri

Copy link
Copy Markdown
Author

Valid finding, fixed in the new commit. SoxResamplerInner::new now also checks that both input_rate / output_rate and output_rate / input_rate are finite and greater than zero, and returns the constructor error otherwise. Rates such as input_rate=1e-320 with output_rate=16000 are rejected at creation instead of panicking on the first push. The invalid_parameters_are_rejected test now covers the underflow and overflow cases.

The license/cla check is pending because the Contributor License Agreement is not signed yet.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants