mirror of
https://github.com/kerberos-io/agent.git
synced 2026-09-04 17:08:34 +00:00
Compare commits
4 Commits
v3.6.22
...
fix/loopin
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
d3f53e4b6b | ||
|
|
8ea84d87db | ||
|
|
860acd3a6e | ||
|
|
4b935d97c8 |
@@ -65,6 +65,7 @@ There are a myriad of cameras out there (USB, IP and other cameras), and it migh
|
||||
|
||||
### Contributing
|
||||
|
||||
1. [Security vulnerability reporting](#security-vulnerability-reporting)
|
||||
1. [Contribute with Codespaces](#contribute-with-codespaces)
|
||||
2. [Develop and build](#develop-and-build)
|
||||
3. [Building from source](#building-from-source)
|
||||
@@ -301,6 +302,10 @@ If we talk about video encoders and decoders (codecs) there are 2 major video co
|
||||
|
||||
Conclusion: depending on the use case you might choose one over the other, and you can use both at the same time. For example you can use H264 (main stream) for livestreaming, and H265 (sub stream) for recording. If you wish to play recordings in a cross-platform and cross-browser environment, you might opt for H264 for better support.
|
||||
|
||||
## Security vulnerability reporting
|
||||
|
||||
If you found a potential security vulnerability, please use the private channels described in [SECURITY.md](SECURITY.md). Avoid opening public GitHub issues for sensitive findings.
|
||||
|
||||
## Contribute with Codespaces
|
||||
|
||||
One of the major blockers for letting you contribute to an Open Source project is to set up your local development machine. Why? Because you might already have some tools and libraries installed that are used for other projects, and the libraries you would need for Kerberos Agent, for example FFmpeg, might require a different version. Welcome to dependency hell...
|
||||
|
||||
40
SECURITY.md
Normal file
40
SECURITY.md
Normal file
@@ -0,0 +1,40 @@
|
||||
# Security Policy
|
||||
|
||||
## Supported Versions
|
||||
|
||||
We only provide security fixes for the latest release series on the `master` branch.
|
||||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
Please do **not** open a public GitHub issue for potential security vulnerabilities.
|
||||
|
||||
Use one of the private channels below:
|
||||
|
||||
1. Preferred: GitHub private vulnerability reporting
|
||||
- https://github.com/kerberos-io/agent/security/advisories/new
|
||||
2. Fallback: Email
|
||||
- support@kerberos.io
|
||||
- Optional CC: support@uug.ai
|
||||
|
||||
Please include:
|
||||
|
||||
- A short summary and impact.
|
||||
- Reproduction steps or proof of concept.
|
||||
- Affected version(s), commit hash, or deployment details.
|
||||
- Any proposed mitigation/workaround.
|
||||
- Your preferred attribution name.
|
||||
|
||||
For faster triage, use this subject format in email:
|
||||
|
||||
`[Security][Kerberos Agent] <short title>`
|
||||
|
||||
## Response Expectations
|
||||
|
||||
- Acknowledgement target: within 3 business days.
|
||||
- Triage/update target: within 7 business days after acknowledgement.
|
||||
|
||||
If you do not receive a response in time, please resend your report and include your original timestamp.
|
||||
|
||||
## Disclosure and Credits
|
||||
|
||||
We follow coordinated disclosure. After a fix is available, we will credit reporters unless they prefer to stay anonymous.
|
||||
@@ -22,4 +22,8 @@ https://brianmacdonald.github.io/Ethonate/address#0xf4a759C9436E2280Ea9cdd23d314
|
||||
|
||||
[**Docker Hub**](https://hub.docker.com/r/kerberos/agent) | [**Documentation**](https://doc.kerberos.io) | [**Website**](https://kerberos.io)
|
||||
|
||||
Kerberos Open source (v3) is a cutting edge video surveillance management system made available as Open Source under the MIT License. This means that all the source code is available for you or your company, and you can use, transform and distribute the source code; as long you keep a reference of the original license. Kerberos Open Source (v3) can be used for commercial usage (which was not the case for v2). Read more [about the license here](LICENSE).
|
||||
Kerberos Open source (v3) is a cutting edge video surveillance management system made available as Open Source under the MIT License. This means that all the source code is available for you or your company, and you can use, transform and distribute the source code; as long you keep a reference of the original license. Kerberos Open Source (v3) can be used for commercial usage (which was not the case for v2). Read more [about the license here](LICENSE).
|
||||
|
||||
## Security reporting
|
||||
|
||||
For sensitive vulnerabilities, use private disclosure channels documented in [../SECURITY.md](../SECURITY.md).
|
||||
|
||||
@@ -32,14 +32,23 @@ const MacEpochOffset uint64 = 2082844800
|
||||
// resulting in ~3 second fragments (assuming a typical GOP interval).
|
||||
const FragmentDurationMs = 3000
|
||||
|
||||
// MinNormalGOPMs is the minimum spacing we expect between two consecutive
|
||||
// IDRs of a healthy source (typical encoders produce IDRs every 1000ms or
|
||||
// more). When two keyframes arrive closer than this, we treat the second one
|
||||
// as an upstream restart/loop-seam and force a fresh fragment so the seam
|
||||
// IDR cannot end up as a mid-fragment sync sample. The check only runs when
|
||||
// the current fragment has not yet reached FragmentDurationMs, so it never
|
||||
// fires during normal multi-GOP fragments at intended GOP boundaries.
|
||||
const MinNormalGOPMs = 950
|
||||
// MinNormalGOPMs is the maximum spacing between two consecutive IDRs that
|
||||
// we still consider an anomalous "loop/restart seam". When two keyframes
|
||||
// arrive closer than this, we treat the second one as an upstream
|
||||
// restart/loop-seam and force a fresh fragment so the seam IDR cannot end
|
||||
// up as a mid-fragment sync sample. The check only runs when the current
|
||||
// fragment has not yet reached FragmentDurationMs.
|
||||
//
|
||||
// This must be set well below the smallest plausible *legitimate* GOP
|
||||
// length. Typical IP cameras use GOP intervals of 1000-2000 ms, and the
|
||||
// arrival timing of consecutive IDRs can jitter by a few hundred ms due to
|
||||
// network/RTSP buffering. A threshold close to 1 s (e.g. 950) caused
|
||||
// false positives on cameras with ~1 s GOPs (warnings like
|
||||
// "gap=800 ms / 300 ms / 200 ms" while the stream itself was healthy).
|
||||
// 400 ms is comfortably below any realistic GOP yet still catches the
|
||||
// virtual-rtsp / ffmpeg loop-seam pattern (seam IDRs typically arrive
|
||||
// 100-200 ms after the prior IDR).
|
||||
const MinNormalGOPMs = 400
|
||||
|
||||
type MP4 struct {
|
||||
// FileName is the name of the file
|
||||
@@ -66,6 +75,7 @@ type MP4 struct {
|
||||
FragmentStartRawPTS uint64 // Raw PTS for timing when to flush fragments
|
||||
FragmentStartDTS uint64 // Accumulated VideoTotalDuration at fragment start (matches tfdt)
|
||||
LastKeyframeRawPTS uint64 // Raw PTS of the most recently seen keyframe (in any fragment)
|
||||
LastKeyframeGapMs uint64 // Gap (ms) between the previous two consecutive keyframes
|
||||
MoofBoxes int64 // Number of moof boxes in the file
|
||||
MoofBoxSizes []int64 // Sizes of each moof box
|
||||
SegmentDurations []uint64 // Duration of each segment in timescale units
|
||||
@@ -326,13 +336,23 @@ func (mp4 *MP4) AddSampleToTrack(trackID uint32, isKeyframe bool, data []byte, p
|
||||
// fragment with a "media corruption" error because the inner IDR resets
|
||||
// frame_num/POC inside what they expect to be a single GOP. Force a
|
||||
// fragment boundary whenever two consecutive keyframes arrive much
|
||||
// closer than a normal GOP (here: < 500 ms apart). This isolates the
|
||||
// seam IDR into its own fragment so each fragment stays a clean GOP.
|
||||
if !shouldFlush && trackID == uint32(mp4.VideoTrack) && mp4.Start &&
|
||||
mp4.LastKeyframeRawPTS > 0 && pts > mp4.LastKeyframeRawPTS &&
|
||||
pts-mp4.LastKeyframeRawPTS < MinNormalGOPMs {
|
||||
log.Log.Warning(fmt.Sprintf("mp4.AddSampleToTrack(): forcing fragment flush at unexpectedly close keyframe (gap=%d ms, fragment elapsed=%d ms) - likely upstream loop/restart discontinuity", pts-mp4.LastKeyframeRawPTS, elapsed))
|
||||
shouldFlush = true
|
||||
// closer than a normal GOP.
|
||||
//
|
||||
// We only flag this as a seam when it is a *sudden* anomaly: the
|
||||
// previous keyframe gap must have been healthy (>= MinNormalGOPMs).
|
||||
// This avoids false positives on cameras that legitimately emit
|
||||
// short-interval IDRs (short GOP, motion-triggered recovery IDRs,
|
||||
// all-intra streams) where every keyframe would otherwise be flagged
|
||||
// in a cascade, producing many tiny fragments and log spam.
|
||||
if trackID == uint32(mp4.VideoTrack) && mp4.Start &&
|
||||
mp4.LastKeyframeRawPTS > 0 && pts > mp4.LastKeyframeRawPTS {
|
||||
gap := pts - mp4.LastKeyframeRawPTS
|
||||
if !shouldFlush && gap < MinNormalGOPMs &&
|
||||
(mp4.LastKeyframeGapMs == 0 || mp4.LastKeyframeGapMs >= MinNormalGOPMs) {
|
||||
log.Log.Warning(fmt.Sprintf("mp4.AddSampleToTrack(): forcing fragment flush at unexpectedly close keyframe (gap=%d ms, fragment elapsed=%d ms) - likely upstream loop/restart discontinuity", gap, elapsed))
|
||||
shouldFlush = true
|
||||
}
|
||||
mp4.LastKeyframeGapMs = gap
|
||||
}
|
||||
if trackID == uint32(mp4.VideoTrack) {
|
||||
mp4.LastKeyframeRawPTS = pts
|
||||
|
||||
@@ -51,8 +51,11 @@ func TestMP4LoopSeamIsolation(t *testing.T) {
|
||||
|
||||
// 17 seconds of normal content (last "good" IDR at sec 17).
|
||||
emit(17*30, 30)
|
||||
// Seam: IDR arrives ~867ms after previous (vs normal 1000ms).
|
||||
pts -= 100
|
||||
// Seam: IDR arrives ~150ms after previous (vs normal ~1000ms).
|
||||
// This matches the realistic virtual-rtsp / ffmpeg `-stream_loop`
|
||||
// loop boundary, where the new clip's first IDR is emitted shortly
|
||||
// after the previous clip's final IDR.
|
||||
pts -= 820
|
||||
emit(13*30, 30)
|
||||
|
||||
mp4Video.Close(&models.Config{Signing: &models.Signing{PrivateKey: ""}})
|
||||
|
||||
Reference in New Issue
Block a user