aomdec/lightfield_decoder: add some allocation checks

Bug: aomedia:3244
Change-Id: I305cabd8f31c5163f91e05921b6f658e11f5d753
diff --git a/apps/aomdec.c b/apps/aomdec.c
index 341c5bc..9a052ce 100644
--- a/apps/aomdec.c
+++ b/apps/aomdec.c
@@ -731,6 +731,10 @@
     ext_fb_list.num_external_frame_buffers = num_external_frame_buffers;
     ext_fb_list.ext_fb = (struct ExternalFrameBuffer *)calloc(
         num_external_frame_buffers, sizeof(*ext_fb_list.ext_fb));
+    if (!ext_fb_list.ext_fb) {
+      fprintf(stderr, "Failed to allocate ExternalFrameBuffer\n");
+      goto fail;
+    }
     if (aom_codec_set_frame_buffer_functions(&decoder, get_av1_frame_buffer,
                                              release_av1_frame_buffer,
                                              &ext_fb_list)) {
@@ -845,6 +849,11 @@
             }
             scaled_img =
                 aom_img_alloc(NULL, img->fmt, render_width, render_height, 16);
+            if (!scaled_img) {
+              fprintf(stderr, "Failed to allocate scaled image (%d x %d)\n",
+                      render_width, render_height);
+              goto fail;
+            }
             scaled_img->bit_depth = img->bit_depth;
             scaled_img->monochrome = img->monochrome;
             scaled_img->csp = img->csp;
@@ -873,8 +882,12 @@
           output_bit_depth = fixed_output_bit_depth;
         }
         // Shift up or down if necessary
-        if (output_bit_depth != 0)
-          aom_shift_img(output_bit_depth, &img, &img_shifted);
+        if (output_bit_depth != 0) {
+          if (!aom_shift_img(output_bit_depth, &img, &img_shifted)) {
+            fprintf(stderr, "Error allocating image\n");
+            goto fail;
+          }
+        }
 
         aom_input_ctx.width = img->d_w;
         aom_input_ctx.height = img->d_h;
diff --git a/common/tools_common.c b/common/tools_common.c
index bb5ef3c..9f2deba 100644
--- a/common/tools_common.c
+++ b/common/tools_common.c
@@ -481,7 +481,7 @@
          required_fmt != shifted->fmt;
 }
 
-void aom_shift_img(unsigned int output_bit_depth, aom_image_t **img_ptr,
+bool aom_shift_img(unsigned int output_bit_depth, aom_image_t **img_ptr,
                    aom_image_t **img_shifted_ptr) {
   aom_image_t *img = *img_ptr;
   aom_image_t *img_shifted = *img_shifted_ptr;
@@ -501,6 +501,10 @@
     }
     if (!img_shifted) {
       img_shifted = aom_img_alloc(NULL, shifted_fmt, img->d_w, img->d_h, 16);
+      if (!img_shifted) {
+        *img_shifted_ptr = NULL;
+        return false;
+      }
       img_shifted->bit_depth = output_bit_depth;
       img_shifted->monochrome = img->monochrome;
       img_shifted->csp = img->csp;
@@ -513,6 +517,8 @@
     *img_shifted_ptr = img_shifted;
     *img_ptr = img_shifted;
   }
+
+  return true;
 }
 
 // Related to I420, NV12 format has one luma "luminance" plane Y and one plane
diff --git a/common/tools_common.h b/common/tools_common.h
index 8dab323..70e4223 100644
--- a/common/tools_common.h
+++ b/common/tools_common.h
@@ -11,6 +11,7 @@
 #ifndef AOM_COMMON_TOOLS_COMMON_H_
 #define AOM_COMMON_TOOLS_COMMON_H_
 
+#include <stdbool.h>
 #include <stdio.h>
 
 #include "config/aom_config.h"
@@ -178,7 +179,8 @@
 void aom_img_upshift(aom_image_t *dst, const aom_image_t *src, int input_shift);
 void aom_img_downshift(aom_image_t *dst, const aom_image_t *src,
                        int down_shift);
-void aom_shift_img(unsigned int output_bit_depth, aom_image_t **img_ptr,
+// Returns true on success, false on failure.
+bool aom_shift_img(unsigned int output_bit_depth, aom_image_t **img_ptr,
                    aom_image_t **img_shifted_ptr);
 void aom_img_truncate_16_to_8(aom_image_t *dst, const aom_image_t *src);
 
diff --git a/examples/lightfield_decoder.c b/examples/lightfield_decoder.c
index 83a32b2..dae2748 100644
--- a/examples/lightfield_decoder.c
+++ b/examples/lightfield_decoder.c
@@ -306,8 +306,11 @@
         // Write out the tile list.
         if (tile_list_cnt) {
           out = &output;
-          if (output_bit_depth != 0)
-            aom_shift_img(output_bit_depth, &out, &output_shifted);
+          if (output_bit_depth != 0) {
+            if (!aom_shift_img(output_bit_depth, &out, &output_shifted)) {
+              die("Error allocating image");
+            }
+          }
           img_write_to_file(out, outfile, output_format);
           tile_list_writes++;
         }
@@ -338,8 +341,11 @@
                 &output, &tile_idx, &output_bit_depth, &img, output_format);
     if (output_format == YUV1D) {
       out = img;
-      if (output_bit_depth != 0)
-        aom_shift_img(output_bit_depth, &out, &output_shifted);
+      if (output_bit_depth != 0) {
+        if (!aom_shift_img(output_bit_depth, &out, &output_shifted)) {
+          die("Error allocating image");
+        }
+      }
       aom_img_write(out, outfile);
     }
   }
@@ -348,8 +354,11 @@
     // Write out the last tile list.
     if (tile_list_writes < tile_list_cnt) {
       out = &output;
-      if (output_bit_depth != 0)
-        aom_shift_img(output_bit_depth, &out, &output_shifted);
+      if (output_bit_depth != 0) {
+        if (!aom_shift_img(output_bit_depth, &out, &output_shifted)) {
+          die("Error allocating image");
+        }
+      }
       img_write_to_file(out, outfile, output_format);
     }
   }