summaryrefslogtreecommitdiff
path: root/src
diff options
context:
space:
mode:
authorGabriel Schneider <[email protected]>2026-09-29 12:31:47 -0300
committerGabriel Schneider <[email protected]>2026-10-01 00:12:16 -0300
commita5be027a0c05c8950bada14fa2f2e713ce7d6986 (patch)
tree8eecd0fd54ef077baf1239f5f00277329974ee95 /src
parent549cfa40e99c3d1937b742a0dba043281c687c83 (diff)
downloadpardes-a5be027a0c05c8950bada14fa2f2e713ce7d6986.tar.gz
pardes-a5be027a0c05c8950bada14fa2f2e713ce7d6986.zip
A look at a corrupt image fails with an err rather than open a blank pane
An image stb_image could not read opened as an empty image pane, the look succeeding. The bytes' header is now checked at the look (stbi_info_from_memory), and one that is no image it reads fails the look, look: <path>: not an image pardes can read, making no pane. Co-Authored-By: Claude Opus 5.5 <[email protected]>
Diffstat (limited to 'src')
-rw-r--r--src/image.zig17
-rw-r--r--src/look.zig11
-rw-r--r--src/ninep/ctl.zig22
3 files changed, 49 insertions, 1 deletions
diff --git a/src/image.zig b/src/image.zig
index 071a2e2a..7b081ec6 100644
--- a/src/image.zig
+++ b/src/image.zig
@@ -732,11 +732,28 @@ test "native geometry is total at extreme accepted aspect ratios" {
/// call once at startup / exit (stb_image's allocator shim)
pub fn start(io: std.Io, gpa: std.mem.Allocator) void {
zstbi.init(io, gpa);
+ started = true;
}
pub fn stop() void {
+ started = false;
zstbi.deinit();
}
+/// stb_image has its allocator (`start`): before, nothing of it may run.
+var started = false;
+
+extern fn stbi_info_from_memory(buffer: [*]const u8, len: c_int, x: *c_int, y: *c_int, comp: *c_int) c_int;
+
+/// Whether `bytes` are an image `decode` can read, from its header alone.
+pub fn readable(bytes: []const u8) bool {
+ if (bytes.len == 0 or bytes.len > std.math.maxInt(c_int)) return false;
+ var w: c_int = 0;
+ var h: c_int = 0;
+ var c: c_int = 0;
+ if (!started) return true; // ponytail: no stb_image yet (a unit test), so no judging
+ return stbi_info_from_memory(bytes.ptr, @intCast(bytes.len), &w, &h, &c) == 1;
+}
+
/// decode + downscale to RGBA, gpa-owned. Returns null on any failure — the
/// pane then simply shows a blank body.
pub fn decode(gpa: std.mem.Allocator, bytes: []const u8) ?struct { rgba: []u8, w: usize, h: usize } {
diff --git a/src/look.zig b/src/look.zig
index 6f279769..5cf26240 100644
--- a/src/look.zig
+++ b/src/look.zig
@@ -1572,8 +1572,17 @@ pub fn lookAt(p: *Pardes, id: usize, operand: []const u8) void {
.image => |target| {
if (focusPaneByPath(p, target.path, .{})) return;
const free = p.freeSlot() orelse return p.reportError(id, "look", error.NoPaneSlots);
- _ = panes.Image.create(p, free, target.path, &.{}) catch |err|
+ const made = panes.Image.create(p, free, target.path, &.{}) catch |err|
return p.reportError(id, if (@import("Messages.zig").dialReason(err) != null) target.path else "look", err);
+ // One it cannot read (corrupt, truncated, not what its name says)
+ // is said, a failure, rather than shown as a blank pane.
+ if (!@import("image.zig").readable(made.image.?.raw)) {
+ made.vweight = 0;
+ p.unplaced.set(free);
+ var said: [miss_path_cap + 64]u8 = undefined;
+ var cut: [miss_path_cap + "…".len]u8 = undefined;
+ return p.reportFailure(id, std.fmt.bufPrint(&said, "look: {s}: not an image pardes can read", .{missText(target.path, &cut)}) catch "look: not an image pardes can read");
+ }
exec.placeNew(p, id, id, free, .doc);
},
}
diff --git a/src/ninep/ctl.zig b/src/ninep/ctl.zig
index be90bb6f..978ce707 100644
--- a/src/ninep/ctl.zig
+++ b/src/ninep/ctl.zig
@@ -2115,6 +2115,28 @@ test "a language server question that finds nothing, cannot be answered, or is a
try testing.expectEqual(E.INVAL, wr(p, Node.of(img.serial, .body), "text\n").errno());
}
+test "a corrupt image fails its look with an err, and no pane is made" {
+ pardes.image.start(testing.io, testing.allocator);
+ defer pardes.image.stop();
+ const p = try withFile(testing.allocator, "x\n");
+ defer p.deinit();
+ var tmp = testing.tmpDir(.{});
+ defer tmp.cleanup();
+ try tmp.dir.writeFile(testing.io, .{ .sub_path = "bad.png", .data = "\x89PNG not really" });
+ var dir_buf: [4096]u8 = undefined;
+ const dir = dir_buf[0..try tmp.dir.realPath(testing.io, &dir_buf)];
+ var line: [4200]u8 = undefined;
+ var count: usize = 0;
+ for (p.panes) |slot| count += @intFromBool(slot != null);
+ const r = wr(p, root_look, try std.fmt.bufPrint(&line, "{s}/bad.png\n", .{dir}));
+ try testing.expectEqual(E.IO, r.errno());
+ try testing.expect(std.mem.endsWith(u8, r.reply.ename, "bad.png: not an image pardes can read"));
+ p.sync();
+ var after: usize = 0;
+ for (p.panes) |slot| after += @intFromBool(slot != null);
+ try testing.expectEqual(count, after);
+}
+
test "a PDF's body reads its page's text layer, and takes no write" {
if (comptime !pardes.pdf_enabled) return;
const p = try withFile(testing.allocator, "x\n");