R5 — Media3Engine builds EditedMediaItem/Composition unguarded on the HandlerThread; a picker-reachable spec throws there #14
Closed
opened 2026-08-23 03:44:43 +00:00 by JMR-dev
·
0 comments
No Branch/Tag Specified
main
fix/102-picker-back-press-overshoot
fix/268-saf-picker-determinism
feat/ogg-vorbis-libvorbis
feat/expedited-conversion-work
fix/gate-cache-in-worktrees
chore/gate-runs-shellcheck
test/publish-delete-arm-real-provider
docs/e8-instrumented-coverage
docs/api37-carrier-count-drift
docs/e7-second-constraint
test/publish-to-a-real-saf-destination
fix/api37-report-match-line
fix/api37-task-snapshot-crash
test/join-failure-message-on-device
docs/e2e-read-findings-e7
test/cancelling-a-running-export
test/reattach-to-a-running-job
test/content-uri-reaches-ffmpeg
fix/launcher-wiring-waits-for-the-pick
fix/cancel-tests-need-a-slower-encode
test/cancelling-a-running-join
test/cancelling-a-running-session
test/notification-cancel-action
test/ffmpeg-progress-is-observed
test/fallback-asserts-the-path
test/flac-and-opus-assert-their-format
docs/e2e-read-findings
docs/wave4-coverage-numbers
fix/injectable-startup-sweep-scope
test/session-outcome-seam
test/launcher-callback-identity
test/theme-follows-system-dark
test/audio-drop-arm
fix/rotation-waits-for-recreation
fix/convert-guards-on-ready
test/retry-save-mime
test/hardware-progress-reaches-workmanager
test/ffprobe-mapping-seam
test/device-codec-enumeration-seam
test/unknown-container-row
test/null-message-fallbacks
test/cancel-reaches-workmanager
docs/coverage-wave3-recovery
test/concat-engine-seam
docs/coverage-wave3
test/mediaprobe-merge-seam
test/adaptive-shell-wiring
test/aac-audio-args
test/notification-progress-text
test/media3-muxer-guard
test/hardware-fallback-and-cancellation
test/unprobeable-join-clip
test/one-branch-outcomes
test/foreground-type-regimes
fix/bound-wedge-diagnostics
docs/coverage-wave2
test/screen-wiring
test/viewmodel-setters
test/join-state-mapping
test/conversion-state-mapping
test/dedupe-user-messages
fix/restore-stack-merges
test/refused-jobs
test/concatworker-failure-arms
test/container-capabilities-audio
test/readspec-enum-fallbacks
test/outputpublisher-seams
test/mediaprobe-track-seam
test/outputpublisher-partial-branches
test/fake-provider-scaffolding
docs/coverage-read-findings
chore/gitignore-kotlin
test/bound-the-hangs
docs/coverage-remeasure
ci/baseline-counter-precision
fix/invalid-suggestion-chip
ci/wedged-leg-report
fix/reattachment-overwrites-pick
test/theme-live-branches
fix/failed-save-retry
fix/empty-composition-crash
ci/advisory-failure-report
docs/seven-run-counts
test/release-permission-guard
ci/build-workflow-permissions
docs/api37-point-release
docs/benchmark-populate-path
fix/dead-assertion-probe-test
ci/actionlint
test/device-codecs-encode-consequence
fix/sdkmanager-pipefail
docs/readme-restart-claim
fix/saf-picker-root-discovery
fix/probe-dispatcher-seam
test/media3engine-mime-tables
test/mediaprobe-pure-helpers
fix/codec-vocabulary-drift
docs/robolectric-rationale-correction
docs/api37-advisory-counts
test/r38-8-saf-e2e
test/r38-7-join-states
test/r38-6-conversion-states
test/r38-5-state-seam
fix/jacoco-robolectric-coverage
docs/instrumented-tests-correction
test/r38-2-filecard
test/r38-4-advanced-picker
test/r38-3-pickers
tools/file-issue-script
tools/api-37-emulator
fix/review-app-gaps
docs/review-corrections
No results found.
Labels
Clear labels
above-cut
accessibility
backlog
bug
confirmed
documentation
duplicate
enhancement
good first issue
help wanted
invalid
plausible
question
sev:high
sev:low
sev:medium
wontfix
Worked autonomously overnight: local, JVM-verifiable, no product decision
Barrier affecting people with disabilities
Held for manual review: product/UX call, CI/workflow, hardware, or unverifiable here
Something isn't working
Reviewer demonstrated the defect
Improvements or additions to documentation
This issue or pull request already exists
New feature or request
Good for newcomers
Extra attention is needed
This doesn't seem right
Reviewer could not fully demonstrate it; treat as unproven
Further information is requested
High severity
Low severity
Medium severity
This will not be worked on
Milestone
No items
No Milestone
Projects
Clear projects
No projects
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: JMR-dev/LibreMediaConverter#14
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Finding R5 from the overnight max-effort review (Fable lead, Opus sub-agents). Full report:
scratchpad/overnight/REVIEW.md.R5 — Media3Engine builds EditedMediaItem/Composition unguarded on the HandlerThread; a picker-reachable spec throws there
severity: medium
verdict: CONFIRMED (reachability demonstrated on the JVM; process-death consequence read, not executed)
where: app/src/main/java/org/libremediaconverter/convert/Media3Engine.kt:80-90 (file unchanged tonight; this answers the audit's own D14 open question about the other native boundaries)
scenario: Audio-only input (MP3) + Advanced picker Container=MP4, Video=H.265, Audio=NONE: CopyPlanner yields (Drop, Drop); ContainerCapabilities.validate says Valid (the COPY form is correctly rejected, the H264/H265 form is not); router sends it to MEDIA3. EditedMediaItem's constructor checkState("Audio and video cannot both be removed") throws IllegalStateException at :83 — on the media3-transformer HandlerThread, outside both runCatching blocks, invisible to the worker's catch(Throwable) and leaving the continuation permanently unresumed; an uncaught handler-thread exception kills the process.
evidence: JVM probe in reviewer clone: plan=(Drop,Drop), validation=Valid, engine=MEDIA3 for H265+NONE and H264+NONE; Invalid for COPY+NONE. checkState read from media3-transformer-1.11.0-sources.jar EditedMediaItem.java:368-369. Lead re-read Media3Engine.kt:71-100 and confirmed lines 80-90 sit between the two runCatching blocks. FFmpegEngine and ConcatEngine checked clean (every call inside worker catch(Throwable), including FFmpegEngine's init).
fix: Widen the existing runCatching to cover the builders (backstop). Separately decide whether validate() should reject encode-video-into-a-file-with-no-video-track as it already does for COPY — that is the real defect.
risk: Guard-widening is behaviour-neutral on success. The validation change newly refuses a picker-enabled combination -> needs its own test. Plan/validate/route chain is JVM-testable; the actual throw needs an instrumented test.
Cut:
below— held for manual review: product decision, CI/workflow, hardware, or PLAUSIBLE verdict.🤖 Generated with Claude Code