Skip to content

Centralize HEIF/AVIF encoded output ownership - #466

Open
gregbenz wants to merge 2 commits into
google:mainfrom
gregbenz:codex/heif-avif-owned-output-current-main
Open

gregbenz wants to merge 2 commits into
google:mainfrom
gregbenz:codex/heif-avif-owned-output-current-main

Conversation

@gregbenz

@gregbenz gregbenz commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Why

HEIF/AVIF encoding currently keeps two output allocations alive when encoding finishes: the writer's growable buffer and a separate uhdr_encode() result buffer reserved as max(64 KiB, 6 * width * height). The encoded bytes are then copied from one buffer to the other.

This change lets the returned compressed image take ownership of the writer's allocation. That removes the speculative result allocation and final copy, reducing peak memory use during HEIF/AVIF encoding. It also allows valid output larger than the old estimate to succeed.

What changed

  • Use the owned-output methods as the single implementation path for HEIF/AVIF encoding.
  • Transfer the writer allocation only after a successful libheif write, using free-compatible cleanup.
  • Keep the existing fixed-buffer C++ overloads as checked adapters over the owned-output path.
  • Leave owned output empty on failure and preserve caller-provided bytes and data_sz when a fixed destination is invalid or too small.
  • Add focused API-0/API-1 AVIF and HEIF coverage for successful copies, failure behavior, output larger than the old estimate, buffer reuse, and null-data validation.

The public C API remains unchanged, and this does not change decoder behavior.

Testing

Validated commit c1e4d0e, rebased onto f3e3622:

  • Warnings-as-errors builds and full CTest with HEIF/AVIF enabled and disabled: 1,119 and 1,096 tests passed, respectively, with 224 expected editor-test skips in each configuration.
  • Focused ASan/UBSan run with halt-on-error enabled: all 23 HEIF/AVIF API, ownership, output-validation, and alpha-preservation tests passed with no skips or diagnostics.
  • The full HEIF/AVIF sanitizer suite completed with 1,119 passes and 224 skips, while reporting existing invalid-enum diagnostics in unchanged negative-test paths. macOS leak detection was unavailable.
  • Existing checks on this head pass, including Windows, Linux, macOS, and Android builds.

@gregbenz
gregbenz force-pushed the codex/heif-avif-owned-output-current-main branch from ce74204 to 6e0c915 Compare September 10, 2026 02:35
@gregbenz
gregbenz force-pushed the codex/heif-avif-owned-output-current-main branch from 6e0c915 to c1e4d0e Compare September 19, 2026 02:34
Retain upstream AVIF and HEIF routing coverage alongside exact output capacity assertions. The AVIF-focused unit tests pass; HEVC-only cases skip without an HEVC encoder.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant