diff --git a/Cargo.lock b/Cargo.lock index 607da3f..b0b8570 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -5513,8 +5513,6 @@ dependencies = [ [[package]] name = "rawler" version = "0.7.2" -source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "04f4cc35c23969a4a834e0b117c7da41ace812eb9053b5effc3fc5c77d114677" dependencies = [ "backtrace", "bitstream-io", diff --git a/Cargo.toml b/Cargo.toml index cf197d0..e5724ed 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -284,3 +284,4 @@ codegen-units = 1 [patch.crates-io] wgpu-hal = { path = "third_party/wgpu-hal-29.0.4" } i-slint-renderer-skia = { path = "third_party/i-slint-renderer-skia-1.17.1" } +rawler = { path = "third_party/rawler-0.7.2" } diff --git a/third_party/README.md b/third_party/README.md index 77da132..2d00f3e 100644 --- a/third_party/README.md +++ b/third_party/README.md @@ -68,3 +68,18 @@ Off Android every path is upstream's: the rotation is always `None`. Unnecessary once Slint's Skia wgpu surface pre-rotates on its own — worth offering upstream, since the linuxkms backend already renders through the same rotate-and-translate in `render_to_canvas`. + +## rawler 0.7.2 — the allocation guard counts samples, not pixels + +`alloc_image_plain!` and `alloc_image_f32_plain!` (`src/pixarray.rs`) panic +on a buffer over 500 M elements or 50 000 along either axis. The width they +are handed is `width × samples per pixel`. A linear DNG therefore hits the +guard at about 16 700 pixels wide, and the 22927 × 8966 panorama +Lightroom writes is refused as ">50000 px wide". The patch raises the +guard to 1.5 G samples and 200 000 per axis. It is still a guard against +a corrupt header, just no longer one that a real photograph trips. + +The copy leaves out `data/testdata`, 13 MB of sample files that only the +crate's own tests read. + +Unnecessary once upstream sizes the guard in pixels, or drops it. diff --git a/third_party/rawler-0.7.2/src/pixarray.rs b/third_party/rawler-0.7.2/src/pixarray.rs index be9e18e..d39c674 100644 --- a/third_party/rawler-0.7.2/src/pixarray.rs +++ b/third_party/rawler-0.7.2/src/pixarray.rs @@ -531,8 +531,10 @@ unsafe impl Sync for Color2DPtr {} #[macro_export] macro_rules! alloc_image_f32_plain { ($width:expr, $height:expr, $dummy: expr) => {{ - if $width * $height > 500000000 || $width > 50000 || $height > 50000 { - panic!("rawler: surely there's no such thing as a >500MP or >50000 px wide/tall image!"); + // DarkRoom: the limit is in *samples*, and a linear DNG passes + // width × 3. Upstream's 50000 refused a 22927-pixel-wide panorama. + if $width * $height > 1_500_000_000 || $width > 200_000 || $height > 200_000 { + panic!("rawler: surely there's no such thing as a >1500M-sample or >200000-sample wide/tall image!"); } if $dummy { $crate::pixarray::PixF32::new_uninit($width, $height) @@ -545,8 +547,10 @@ macro_rules! alloc_image_f32_plain { #[macro_export] macro_rules! alloc_image_plain { ($width:expr, $height:expr, $dummy: expr) => {{ - if $width * $height > 500000000 || $width > 50000 || $height > 50000 { - panic!("rawler: surely there's no such thing as a >500MP or >50000 px wide/tall image!"); + // DarkRoom: the limit is in *samples*, and a linear DNG passes + // width × 3. Upstream's 50000 refused a 22927-pixel-wide panorama. + if $width * $height > 1_500_000_000 || $width > 200_000 || $height > 200_000 { + panic!("rawler: surely there's no such thing as a >1500M-sample or >200000-sample wide/tall image!"); } if $dummy { $crate::pixarray::PixU16::new_uninit($width, $height)