Skip to content

Fix fuzz builds and RIFF validation; add JSON and metadata tools - #39

Open
gianni-rosato wants to merge 6 commits into
mainfrom
fix-fuzz-parser-cli
Open

gianni-rosato wants to merge 6 commits into
mainfrom
fix-fuzz-parser-cli

Conversation

@gianni-rosato

@gianni-rosato gianni-rosato commented Oct 10, 2026 •

Copy link
Copy Markdown
Member

PR #39 Summary

This PR repairs fuzz builds, validates RIFF WebP files, and adds JSON reporting and binary metadata extraction to the CLI.

Key Changes

  • Initialize fuzz decoder options, cap fuzzed image allocations, and fix the Wuffs dependency name.
  • Reject files whose first RIFF chunk is not VP8, VP8L, or VP8X.
  • Add a tool to compare decoder results with libwebp, including frame geometry and pixel differences.
  • Add JSON image information and exact ICC, EXIF, and XMP metadata extraction.
  • Check output paths and stage metadata before publishing to protect input and pixel output files.

Testing

  • Add fuzz allocation budget tests and a first chunk validation regression.
  • Add CLI reporting tests for JSON, metadata extraction, streaming, path aliases, and filename handling.
  • Add RGBA PAM output to the libwebp harness for decoder comparisons.

Repair fuzz builds against the current C options layout, cap fuzzed image allocations, and reject RIFF WebP files whose first chunk is not VP8, VP8L or VP8X. Add differential comparison tooling and CLI reporting with output handling that prevents metadata from overwriting input or pixel output.

Fixtures

20 binary fixtures, their generator, and provenance notes were committed and pushed separately to wpd-test-data/main, commit 54b2d0e. Update that checkout before running the new CLI tests. Malformed fixtures live in damaged/; original damaged VP8 payload hashes are preserved.

Output preservation review fixes

Validate metadata, pixel, and JSON destinations against the actual opened input handle, including non-stdin descriptor inputs and symlink aliases. On macOS, stat descriptor output handles without truncation rather than relying on synthetic fdesc device numbers. Allow the explicit /dev/null discard sink to share JSON stdout.

The latest validation passed 237 assembly and 235 scalar Meson tests, 22 CLI tests on macOS and native Linux (one platform-specific skip on each), all 49 valid corpus comparisons with libwebp, scripts/stylecheck.sh, and the new root ruff.sh. The Ruff script and Python formatting are committed separately.

Original review references

Incorporates the selected changes and valuable review comments from #36, #37, and #38, particularly build scope, payload boundaries, metadata output preservation, and scalar repeat performance.

Initialize the current C options layout, share a one-megapixel budget
between the raw and end-to-end fuzzers, and pass it through the Rust and
C decoder options. Check raw dimensions without allocating pixels while
keeping malformed headers in the fuzzing domain. Correct the Wuffs
Meson dependency name so the pinned fallback can be resolved.

Keep the build fixes scoped as requested by the original review; do not
add CI configuration or unrelated documentation changes.

Validation: isolated fuzz budget tests and clippy; all four nightly
fuzz targets build and pass seeded ASan smoke runs; default Meson setup
resolves Wuffs successfully.

References:
#36
#36 (review)
Reject a RIFF WebP whose first chunk is not VP8, VP8L or VP8X, including
incremental input. Add RGBA PAM output to the pinned libwebp harness and
a standalone Python comparison tool that reports acceptance, geometry,
visible pixels and RGB beneath zero alpha separately. Record input and
output hashes, tool versions, abnormal exits and timeout failures.

Preserve declared payload bounds and existing decoder arithmetic rather
than introducing the compatibility changes criticized in PR #37.
The damaged-input corpus and provenance are published separately in
wpd-test-data commit 54b2d0e2876c4ca223e29a47c1871bad1ac6ad56.

Validation: first-chunk unit and streamed CLI regressions; exact RGBA
and geometry agreement on 49 valid files; 19 damaged files compared
with no abnormal decoder exits.

References:
#37
#37 (review)
Add --info=json with canvas, coding, frame count, loop count, metadata
presence and original frame durations, plus --icc-out, --exif-out and
--xmp-out for exact metadata bytes. Emit reports once after decoding,
pixel output closure and optional MD5 verification succeed. Missing
metadata produces an empty file.

Validate input/output identities before opening pixel output, including
symlinks, hardlinks and redirected Unix streams. Stage metadata in
same-directory temporary files before atomic publication, preserve
valid destination symlinks, and recheck newly-created filesystem aliases
to prevent silent output collisions. Keep reporting out of the ordinary
decode loop through compile-time specialization.

Add Meson CLI regressions using fixtures published in wpd-test-data
commit 54b2d0e2876c4ca223e29a47c1871bad1ac6ad56. Tests cover whole/stream
input, binary metadata, repeats, loops, scaling, output failures and
filesystem aliases.

Validation: 16 CLI cases in assembly and scalar builds (the Linux-only
filename-byte case is skipped on APFS); 1,271 existing CLI comparisons
agree; text info is unchanged on 49 files in whole and stream modes;
paired 30,000-repeat benchmarks show no slowdown in four configurations.

References:
#38
#38 (review)
Recognize stdin descriptor aliases and symlinks when comparing metadata
and pixel destinations against redirected stdin. Reject JSON stdout
that aliases the source, including stdin/stdout handles referring to the
same file on macOS, before decoding or publishing any metadata.

Use bounded staging basenames independent of the destination name, avoid
requested destination aliases, and relinquish temporary-file ownership
after publication. Preserve arbitrary Unix filename bytes in attached
metadata arguments while continuing to validate option names and scalar
values as UTF-8.

Add regressions for descriptor and JSON aliases, existing and absent
filenames at the filesystem component limit, and all three metadata
types with attached/separate non-UTF-8 paths. The filesystem bugs are
reproduced against the previous CLI using disposable input copies.

Validation: 237 assembly and 235 scalar Meson tests and stylecheck pass.
All 18 CLI cases pass where applicable on macOS and native Linux; Linux
runs the non-UTF-8 extraction case and APFS runs the case-alias case.
CLI parser unit tests pass on both platforms.

References: #39
@gianni-rosato gianni-rosato self-assigned this Oct 11, 2026
Compare metadata, pixel and JSON destinations against the actual reader handle, including non-stdin descriptor inputs. Stat macOS descriptor output handles without truncation to avoid fdesc device-number mismatches. Honor the explicit /dev/null discard sink in stdout collision checks.

Add descriptor and symlink regressions that preserve source and existing metadata bytes, plus JSON/discard-sink coverage. Assembly and scalar Meson suites and native macOS/Linux CLI suites pass.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant