Files
TagTinker/scenes
HoggorminoandClaude Opus 5 692e436fe5 Bound BMP rows to the row buffer and show failed sends
tx_bmp_open() accepted 24- and 32-bit BMPs of any width, then each source
row was read into uint8_t row_buf[128] on the stack. A 24-bit BMP wider
than 42 px, or a 1-bit BMP wider than 1024 px, overran it. The decoder
also reads one bit per pixel, so 24/32-bit files were misread anyway.
A host build of the previous code under AddressSanitizer reports a
132-byte write into the 128-byte buffer for a 24-bit, 43 px wide file.

- Accept only 1bpp and the stacked-plane "2bpp" layout, reject zero or
  over-16-bit sizes, and reject rows wider than TX_BMP_ROW_BUF_SIZE.
- Read header fields as uint32_t. Shifting into bit 31 of an int and
  negating INT32_MIN were undefined.
- The result screen showed "Flipped ;)" and played the success sound
  even when the send failed or was cancelled. Show "Send failed" with
  the error sound, or "Stopped" with no sound when cancelled with Back.
- Check for a stop request after the gap between frames of a sequence.
  tagtinker_ir_transmit() clears the stop flag on entry, so a Back
  pressed during the gap was lost and the next frame went out in full.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-16 17:10:50 +02:00
..