Let rawler decode a linear DNG wider than 16 700 pixels

rawler's allocation guard is sized in samples but worded in pixels, and
a linear DNG passes width × 3. A 22927 × 8966 Lightroom panorama was
refused as ">50000 px wide", and develop fell back silently to the
embedded preview. Route rawler through third_party with the guard at
1.5 G samples and 200 000 per axis.
This commit is contained in:
2026-09-27 17:33:19 -04:00
parent 77a1925bac
commit 72aa7e98bf
4 changed files with 24 additions and 6 deletions
Generated
-2
View File
@@ -5513,8 +5513,6 @@ dependencies = [
[[package]]
name = "rawler"
version = "0.7.2"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "04f4cc35c23969a4a834e0b117c7da41ace812eb9053b5effc3fc5c77d114677"
dependencies = [
"backtrace",
"bitstream-io",
+1
View File
@@ -284,3 +284,4 @@ codegen-units = 1
[patch.crates-io]
wgpu-hal = { path = "third_party/wgpu-hal-29.0.4" }
i-slint-renderer-skia = { path = "third_party/i-slint-renderer-skia-1.17.1" }
rawler = { path = "third_party/rawler-0.7.2" }
+15
View File
@@ -68,3 +68,18 @@ Off Android every path is upstream's: the rotation is always `None`.
Unnecessary once Slint's Skia wgpu surface pre-rotates on its own —
worth offering upstream, since the linuxkms backend already renders
through the same rotate-and-translate in `render_to_canvas`.
## rawler 0.7.2 — the allocation guard counts samples, not pixels
`alloc_image_plain!` and `alloc_image_f32_plain!` (`src/pixarray.rs`) panic
on a buffer over 500 M elements or 50 000 along either axis. The width they
are handed is `width × samples per pixel`. A linear DNG therefore hits the
guard at about 16 700 pixels wide, and the 22927 × 8966 panorama
Lightroom writes is refused as ">50000 px wide". The patch raises the
guard to 1.5 G samples and 200 000 per axis. It is still a guard against
a corrupt header, just no longer one that a real photograph trips.
The copy leaves out `data/testdata`, 13 MB of sample files that only the
crate's own tests read.
Unnecessary once upstream sizes the guard in pixels, or drops it.
+8 -4
View File
@@ -531,8 +531,10 @@ unsafe impl<T, const N: usize> Sync for Color2DPtr<T, N> {}
#[macro_export]
macro_rules! alloc_image_f32_plain {
($width:expr, $height:expr, $dummy: expr) => {{
if $width * $height > 500000000 || $width > 50000 || $height > 50000 {
panic!("rawler: surely there's no such thing as a >500MP or >50000 px wide/tall image!");
// DarkRoom: the limit is in *samples*, and a linear DNG passes
// width × 3. Upstream's 50000 refused a 22927-pixel-wide panorama.
if $width * $height > 1_500_000_000 || $width > 200_000 || $height > 200_000 {
panic!("rawler: surely there's no such thing as a >1500M-sample or >200000-sample wide/tall image!");
}
if $dummy {
$crate::pixarray::PixF32::new_uninit($width, $height)
@@ -545,8 +547,10 @@ macro_rules! alloc_image_f32_plain {
#[macro_export]
macro_rules! alloc_image_plain {
($width:expr, $height:expr, $dummy: expr) => {{
if $width * $height > 500000000 || $width > 50000 || $height > 50000 {
panic!("rawler: surely there's no such thing as a >500MP or >50000 px wide/tall image!");
// DarkRoom: the limit is in *samples*, and a linear DNG passes
// width × 3. Upstream's 50000 refused a 22927-pixel-wide panorama.
if $width * $height > 1_500_000_000 || $width > 200_000 || $height > 200_000 {
panic!("rawler: surely there's no such thing as a >1500M-sample or >200000-sample wide/tall image!");
}
if $dummy {
$crate::pixarray::PixU16::new_uninit($width, $height)