Repository navigation
Fix fuzz builds and RIFF validation; add JSON and metadata tools - #39
Open
gianni-rosato wants to merge 6 commits into
Open
gianni-rosato wants to merge 6 commits into
gianni-rosato wants to merge 6 commits into
Conversation
Initialize the current C options layout, share a one-megapixel budget between the raw and end-to-end fuzzers, and pass it through the Rust and C decoder options. Check raw dimensions without allocating pixels while keeping malformed headers in the fuzzing domain. Correct the Wuffs Meson dependency name so the pinned fallback can be resolved. Keep the build fixes scoped as requested by the original review; do not add CI configuration or unrelated documentation changes. Validation: isolated fuzz budget tests and clippy; all four nightly fuzz targets build and pass seeded ASan smoke runs; default Meson setup resolves Wuffs successfully. References: #36 #36 (review)
Reject a RIFF WebP whose first chunk is not VP8, VP8L or VP8X, including incremental input. Add RGBA PAM output to the pinned libwebp harness and a standalone Python comparison tool that reports acceptance, geometry, visible pixels and RGB beneath zero alpha separately. Record input and output hashes, tool versions, abnormal exits and timeout failures. Preserve declared payload bounds and existing decoder arithmetic rather than introducing the compatibility changes criticized in PR #37. The damaged-input corpus and provenance are published separately in wpd-test-data commit 54b2d0e2876c4ca223e29a47c1871bad1ac6ad56. Validation: first-chunk unit and streamed CLI regressions; exact RGBA and geometry agreement on 49 valid files; 19 damaged files compared with no abnormal decoder exits. References: #37 #37 (review)
Add --info=json with canvas, coding, frame count, loop count, metadata presence and original frame durations, plus --icc-out, --exif-out and --xmp-out for exact metadata bytes. Emit reports once after decoding, pixel output closure and optional MD5 verification succeed. Missing metadata produces an empty file. Validate input/output identities before opening pixel output, including symlinks, hardlinks and redirected Unix streams. Stage metadata in same-directory temporary files before atomic publication, preserve valid destination symlinks, and recheck newly-created filesystem aliases to prevent silent output collisions. Keep reporting out of the ordinary decode loop through compile-time specialization. Add Meson CLI regressions using fixtures published in wpd-test-data commit 54b2d0e2876c4ca223e29a47c1871bad1ac6ad56. Tests cover whole/stream input, binary metadata, repeats, loops, scaling, output failures and filesystem aliases. Validation: 16 CLI cases in assembly and scalar builds (the Linux-only filename-byte case is skipped on APFS); 1,271 existing CLI comparisons agree; text info is unchanged on 49 files in whole and stream modes; paired 30,000-repeat benchmarks show no slowdown in four configurations. References: #38 #38 (review)
Recognize stdin descriptor aliases and symlinks when comparing metadata and pixel destinations against redirected stdin. Reject JSON stdout that aliases the source, including stdin/stdout handles referring to the same file on macOS, before decoding or publishing any metadata. Use bounded staging basenames independent of the destination name, avoid requested destination aliases, and relinquish temporary-file ownership after publication. Preserve arbitrary Unix filename bytes in attached metadata arguments while continuing to validate option names and scalar values as UTF-8. Add regressions for descriptor and JSON aliases, existing and absent filenames at the filesystem component limit, and all three metadata types with attached/separate non-UTF-8 paths. The filesystem bugs are reproduced against the previous CLI using disposable input copies. Validation: 237 assembly and 235 scalar Meson tests and stylecheck pass. All 18 CLI cases pass where applicable on macOS and native Linux; Linux runs the non-UTF-8 extraction case and APFS runs the case-alias case. CLI parser unit tests pass on both platforms. References: #39
Compare metadata, pixel and JSON destinations against the actual reader handle, including non-stdin descriptor inputs. Stat macOS descriptor output handles without truncation to avoid fdesc device-number mismatches. Honor the explicit /dev/null discard sink in stdout collision checks. Add descriptor and symlink regressions that preserve source and existing metadata bytes, plus JSON/discard-sink coverage. Assembly and scalar Meson suites and native macOS/Linux CLI suites pass.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PR #39 Summary
This PR repairs fuzz builds, validates RIFF WebP files, and adds JSON reporting and binary metadata extraction to the CLI.
Key Changes
Testing
Repair fuzz builds against the current C options layout, cap fuzzed image allocations, and reject RIFF WebP files whose first chunk is not VP8, VP8L or VP8X. Add differential comparison tooling and CLI reporting with output handling that prevents metadata from overwriting input or pixel output.
Fixtures
20 binary fixtures, their generator, and provenance notes were committed and pushed separately to wpd-test-data/main, commit 54b2d0e. Update that checkout before running the new CLI tests. Malformed fixtures live in
damaged/; original damaged VP8 payload hashes are preserved.Output preservation review fixes
Validate metadata, pixel, and JSON destinations against the actual opened input handle, including non-stdin descriptor inputs and symlink aliases. On macOS, stat descriptor output handles without truncation rather than relying on synthetic fdesc device numbers. Allow the explicit
/dev/nulldiscard sink to share JSON stdout.The latest validation passed 237 assembly and 235 scalar Meson tests, 22 CLI tests on macOS and native Linux (one platform-specific skip on each), all 49 valid corpus comparisons with libwebp,
scripts/stylecheck.sh, and the new rootruff.sh. The Ruff script and Python formatting are committed separately.Original review references
Incorporates the selected changes and valuable review comments from #36, #37, and #38, particularly build scope, payload boundaries, metadata output preservation, and scalar repeat performance.