Skip to content

Fix panic on filter regions with coordinates outside the i32 range - #1089

Open
jschwe wants to merge 1 commit into
linebender:mainfrom
jschwe:fix_panic_on_overflow
Open

jschwe wants to merge 1 commit into
linebender:mainfrom
jschwe:fix_panic_on_overflow

Conversation

@jschwe

@jschwe jschwe commented Jul 3, 2026

Copy link
Copy Markdown

NonZeroRect::to_int_rect panics when the rect has coordinates outside the i32 range.
Instead, add a clamped_int_rect helper, which performs the clamping without panicking.
Adds a test, which panics before this fix.

Background: We started fuzzing servo more intensively recently, and resvg is a source of panics. This PR fixes one such panic. There are a couple more crashes pending.

NonZeroRect::to_int_rect panics when the rect has coordinates outside
the i32 range.
Instead add a clamped_int_rect helper, which performs the clamping without panicking.
@luisbg

luisbg commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

The panic this fixes no longer exists in main. Regression test passes.

#989 got there first, by replacing the panicking bbox.to_int_rect() with IntRect::from_xywh(...)?.

But we shouldn't close this PR because the two fixes are not equivalent:

Want to rewrite the PR?

@Its-Just-Nans

Copy link
Copy Markdown
Contributor

linebender/tiny-skia#182 is another fix (which fix the underlying crate)

@luisbg

luisbg commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

The issue this PR tries to fix was resolved by #989 .

I checked by applying this PR's regression test alone to current main, with none of its source changes and it passes. The <desc> in the test SVG says "the filtered element is invisible, but the app should not panic", and that's exactly what main does now.

We should close this PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants