tree 606f7ff94a3885b1ba66976a7220a038636fe951
parent af00aec1ad26a1b6d7e757169dd8328e4ac6e66a
author Wan-Teh Chang <wtc@google.com> 1538585784 -0700
committer Wan-Teh Chang <wtc@google.com> 1538599264 +0000

reset_frame_buffers: decrease ref_count correctly.

Right now reset_frame_buffers() blindly resets the ref_count of all
frame buffers to 0, except for the frame buffer referenced by
cm->new_fb_idx. But the pbi->output_frame_index array may also reference
frame buffers. reset_frame_buffers() should not release the references
stored in the pbi->output_frame_index array without also clearing that
array. Since I do not know if reset_frame_buffers() should release the
references stored in pbi->output_frame_index, I decided to play safe and
only release the references stored in cm->ref_frame_map correctly.

BUG=oss-fuzz:10779
BUG=oss-fuzz:10782

Change-Id: I37b56c28e5308a1bcb53c64603deed0a8bb5fc03
