tagwriter's RIFF parser allocates whatever size a chunk header claims #216
Closed
opened 2026-08-24 09:44:58 +00:00 by logan
·
2 comments
No Branch/Tag Specified
main
fix/146-stub-etxtbsy
fix/175-wizard-follows-the-library
fix/231-setter-rollback
fix/197-duplicate-column-label
docs/225-fixtures-wav-tags
docs/220-skill-check-scope
test/217-fixture-names-in-queue-selection
fix/216-riff-parse-allocation
fix/170-queue-header-action-names
fix/210-nav-sheet-scroll-affordance
docs/50-readme-landing-page
feat/65-art-prefetch-ahead
feat/71-more-as-a-bottom-sheet
feat/54-native-touch-feel
feat/67-entity-links-into-menus
test/196-visual-tier-gates
fix/138-ui-test-storage-leak
fix/104-wav-tags-read
fix/207-sheet-scroll-affordance
fix/204-ui-visual-update-filter
pi-agent-backlog-automation
63-touch-model-phase-2
63-android-touch-model
186-touch-targets-settings
186-touch-targets-page-header
187-seek-bar-hit-area
189-190-explore-correctness
135-android-underrun-instrumentation
51-android-small-screens
fix/171-phone-queue-scrim
fix/137-touch-only-affordances
fix/154-nested-css-check
feat/58-mini-player-progress-line
fix/66-album-page-scrolls-as-one
60-context-menu-action-sheet
64-android-system-volume
59-slim-the-mini-player
55-queue-as-a-screen
feat/57-drop-the-android-top-bar
feat/62-jobs-as-a-notification
fix/53-seek-bar-never-moves
fix/159-android-task-app-id
fix/52-android-activity-recreation-restarts-the-process
fix/150-expand-button-under-the-art
feat/42-inline-volume-and-centred-transport
fix/156-queue-selection-fixture-order
fix/151-fuse-the-scroll-guard-and-the-write
fix/43-queue-panel-selection
fix/143-top-bar-fits-its-window
feat/27-jobs-into-settings
feat/25-configurable-sidebar-tabs
feat/6-global-back-forward
fix/72-active-view-broadcast
fix/69-page-header-action-overflow
fix/quick-wins-batch
fix/118-in-library-clear
fix/61-mini-player-plain-text
fix/68-hover-affordances-pointer
fix/119-dev-headless-port
fix/130-issue-claim-user
fix/131-codegen-check-scope
feat/28-autotag-match-on-album
feat/17-demote-version-selector
feat/38-ownership-visibility
ci/115-manual-release
feat/34-icon-language
feat/7-full-tracklist-toggle
fix/16-tagwriter-totals
fix/unclaim-ca-certs
fix/unclaim-shell
ci/unclaim-on-close
docs/closing-keyword
docs/retire-stale-planning-docs
docs/issue-driven-workflow
integration/small-fixes
fix/small-issue-batch
fix/queue-toggle-state
fix/drag-count-badge
fix/album-card-year
fix/album-tracklist-heading
fix/seek-bar-clock-width
fix/explore-art-scanner-requests
chore/workflow-guardrails
v0.7.0
v0.6.0
v0.5.0
v0.4.0
v0.3.1
v0.3.0
v0.2.3
v0.2.2
v0.2.1
v0.2.0
v0.1.0
v0.0.1
v0.0.0
Labels
Clear labels
Area/Design
Area/Downloads
Area/Explore
Area/Library-UI
Area/Metadata
Area/Packaging
Area/Player
Area/Queue
Area/Settings
Area/Shell-Nav
Compat/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Platform/Android
Platform/Desktop
Breaking change that won't be backward compatible
Something is not working
Documentation changes
Improve existing functionality
New functionality
This is security issue
Issue or pull request related to testing
Priority
Critical
1
The priority is critical
Priority
High
2
The priority is high
Priority
Medium
3
The priority is medium
Priority
Low
4
The priority is low
Reviewed
Confirmed
1
Issue has been confirmed
Reviewed
Duplicate
2
This issue or pull request already exists
Reviewed
Invalid
3
Invalid issue
Reviewed
Won't Fix
3
This issue won't be fixed
Status
Blocked
1
Something is blocking this issue or pull request
Status
Need More Info
2
Feedback is required to reproduce issue or to continue work
Status
Abandoned
3
Somebody has started to work on this but abandoned work
Status
In Progress
Somebody is actively working on this right now
Milestone
No items
No Milestone
Projects
Clear projects
No projects
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: yonlu/yellowjacket#216
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Finding
Tripped over while giving
metadataa RIFF reader for #104.riff.Parse— which wastagwriter.parseRIFFuntil that change, andis still only called by the tag writer — sizes its buffer from the
chunk header:
chunkSizeis four bytes read off the file, so a truncated ormalformed WAV can declare a 4 GB chunk in a 2 kB file and the parser
allocates 4 GB before discovering there is nothing to read into it.
The error is correct; the allocation happens first.
Reproduction
Write a WAV whose
datachunk header declares0xFFFFFFF0and thenends, and call
writeWavTagson it. The read fails withunexpected EOF, having asked the allocator for ~4 GB on the way.Why it has not bitten
The writer only runs on files the user has asked to tag, and a real
WAV's headers are honest. #104's read path is the one that touches
every file in the library on every scan, and it does not have this
shape:
riff.ID3Chunkcopies withio.CopyNinto abytes.Buffer, soit grows with what actually arrives.
Direction
The same treatment in
Parse, or a ceiling from the file's own size(it takes an
io.Readertoday, so a size is not to hand —ID3Chunk'sio.CopyNis the cheaper answer and needs nothing new).Priority Low: it needs a malformed file and a deliberate tag write,
and the failure is an allocation rather than a wrong answer. Filing it
because it is the sort of thing that is invisible until a user's disk
has a bad sector in a file they then edit.
Picking this up on
fix/216-riff-parse-allocation.Approach is the cheaper of the two the issue names:
riff.Parsecopiesthe chunk body with
io.CopyNinto abytes.Buffer, exactly asriff.ID3Chunkbeside it already does, so the buffer grows with whatarrives rather than with what the four-byte header claims. Nothing new
is needed and the reader stays an
io.Reader.The regression test measures rather than asserts the error, because the
error is identical on a build that allocates the gigabyte first —
runtime.MemStats.TotalAllocacross aParseof a file whosedatachunk declares 1 GiB and then ends.
PR #224 is open for this and CI is green (run 18009 on
a113b7b:checksuccess,e2esuccess).riff.Parsecopies the chunk body withio.CopyNinto abytes.Buffernow, matchingriff.ID3Chunkbeside it, so the buffer grows with what arrives rather than with what the four-byte header claims — the issue's own cheaper answer, needing nothing new.The regression test measures instead of asserting the error, because the error is the same on a build that allocates first:
runtime.MemStats.TotalAllocacross aParseof a 42-byte container whosedatachunk claims 1 GiB read 1,073,750,920 bytes before the fix and under 1 MiB after.Not merging; leaving
Status/In Progresson.