Return a panic inside the decoder as an error, not as the end of the thread
rawler panics on some input rather than returning Err — a DNG whose IFD claims a >50000 px image, which the reference library has: a 521 MB stitched panorama, IMG_4181-Pano.dng. On a worker thread a panic is the end of the thread, so the face sweep that met it stopped thirteen seconds in, three sweeps running on the tablet and three on the desktop, with "17301 image(s) to index" as the last word. FR-RAW-4 says a malformed file must not abort a batch, and that is this crate's promise whatever the library beneath it does: every entry point that calls into rawler now runs under catch_unwind, and a file that panics the decoder is one failed file with the panic's message in the error. Verified on the panorama itself: metadata reads, decode returns the error, the thread survives. The crash hook still records the panic, which is right — it is a defect in a dependency and the record is how it gets reported.
This commit is contained in:
@@ -285,6 +285,10 @@ pub fn probe(header: &[u8]) -> Option<Format> {
|
||||
/// TRACES: FR-CAT-5 | M-12
|
||||
/// Read capture metadata without decoding sensor data.
|
||||
pub fn metadata(bytes: &[u8]) -> Result<Metadata, DecodeError> {
|
||||
error::guarded("metadata", || metadata_unguarded(bytes))
|
||||
}
|
||||
|
||||
fn metadata_unguarded(bytes: &[u8]) -> Result<Metadata, DecodeError> {
|
||||
use rawler::rawsource::RawSource;
|
||||
|
||||
// rawler has no decoder for a plain JPEG, so without this every JPEG in a
|
||||
@@ -510,6 +514,10 @@ pub(crate) fn parse_exif_offset(s: &str) -> Option<i32> {
|
||||
/// Only develop and export should call it; culling and the grid must not
|
||||
/// (FR-CULL-1).
|
||||
pub fn decode(bytes: &[u8]) -> Result<RawImage, DecodeError> {
|
||||
error::guarded("decode", || decode_unguarded(bytes))
|
||||
}
|
||||
|
||||
fn decode_unguarded(bytes: &[u8]) -> Result<RawImage, DecodeError> {
|
||||
use rawler::rawsource::RawSource;
|
||||
|
||||
let source = RawSource::new_from_slice(bytes);
|
||||
|
||||
Reference in New Issue
Block a user