mirror of
https://github.com/i12bp8/TagTinker.git
synced 2026-09-30 23:37:53 +00:00
tx_bmp_open() accepted 24- and 32-bit BMPs of any width, then each source row was read into uint8_t row_buf[128] on the stack. A 24-bit BMP wider than 42 px, or a 1-bit BMP wider than 1024 px, overran it. The decoder also reads one bit per pixel, so 24/32-bit files were misread anyway. A host build of the previous code under AddressSanitizer reports a 132-byte write into the 128-byte buffer for a 24-bit, 43 px wide file. - Accept only 1bpp and the stacked-plane "2bpp" layout, reject zero or over-16-bit sizes, and reject rows wider than TX_BMP_ROW_BUF_SIZE. - Read header fields as uint32_t. Shifting into bit 31 of an int and negating INT32_MIN were undefined. - The result screen showed "Flipped ;)" and played the success sound even when the send failed or was cancelled. Show "Send failed" with the error sound, or "Stopped" with no sound when cancelled with Back. - Check for a stop request after the gap between frames of a sequence. tagtinker_ir_transmit() clears the stop flag on entry, so a Back pressed during the gap was lost and the next frame went out in full. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>