Skip to content

a frame keeps its context and its pixels past the next grab - #69

Merged
fxd0h merged 5 commits into
mainfrom
fix/wrapper-ctx-refcount
Oct 5, 2026
Merged

fxd0h merged 5 commits into
mainfrom
fix/wrapper-ctx-refcount

Conversation

@fxd0h

@fxd0h fxd0h commented Oct 5, 2026

Copy link
Copy Markdown
Owner

fixes #63, fixes #68

1- c538d14: a Frame or Cursor holds the context, so dropping the DrmTap first no longer frees what their release reads (asan on i915: heap-use-after-free before, clean after)
2- 6fbb7bb: grab_mapped lends the conversion a buffer the frame owns and copies pixels that stay in context memory into one. two live frames no longer share a pointer, and a frame survives a bigger mode: hdmi-a-2 1280x1024 -> 1920x1080 between two grabs was a heap-use-after-free on 0.5.10 and is clean now. a dropped frame leaves its buffer to the next grab. new c function drmtap_frame_owns_data
3- 1cd197a: drmtap_deswizzle returns -EINVAL when a row of 4-byte pixels does not fit dst_stride (on a 2-byte geometry the linear, x and y paths all wrote past dst under asan). a layout it cannot decode still returns -ENOTSUP, and the rest of each row is still left alone

on i915 meteor lake (compressed scanout, egl detile) grab_mapped costs what 0.5.10 did within 0.1 ms, 4.6-4.8 ms at 1080p and 12.0-12.2 ms at 4k, and keeps one frame more resident. no public signature changes.

fxd0h added 3 commits October 5, 2026 09:03
Frame and Cursor held a raw copy of the drmtap_ctx pointer with no lifetime,
so safe code could drop the DrmTap first; drmtap_close freed the context and
Frame::drop then read drm_fd from freed memory in drmtap_gem_close. Under asan
on i915: heap-use-after-free, READ of size 4 at drm_grab.c:77, freed by
drmtap_close.

The context now lives in an Arc that DrmTap, Frame and Cursor share, and
drmtap_close runs when the last one drops. No signature changes, and the auto
traits are unchanged: DrmTap is Send, UnwindSafe and RefUnwindSafe but not
Sync, Frame and Cursor are neither Send nor Sync. The new hardware test runs
clean under asan. Dropping the last Frame or Cursor now runs the close, which
on the privilege-helper path stops the helper; the docs and the changelog say
so.

Fixes #63
A converted frame had its pixels in the context's conversion buffer, and a
frame from the helper's pixel path in the context's receive buffer, so the
next grab overwrote them and a larger frame freed and reallocated that memory
under Frame::data(). On i915 two live frames from grab_mapped returned the
same pointer, and a frame grabbed before a switch to a bigger mode was read
from freed memory (asan).

The wrapper now points the conversion at a buffer the frame owns, through
drmtap_set_output_buffer, clears it right after the grab, and copies pixels
that are still the context's into one. A dropped frame leaves its buffer to
the next grab, so a consumer that drops one frame per grab does not
allocate. Buffers start zeroed, and a frame that reports more bytes than it
was lent is released with EOVERFLOW instead of being read. A frame mapped
straight from the scanout is still a view of it, not a copy. The new C
function drmtap_frame_owns_data tells whether frame->data is memory the
frame releases.

On i915 (Meteor Lake, EGL detile, as root) grab_mapped costs what 0.5.10 did
within 0.1 ms at 1920x1080 and 3840x2160. With glibc forced to map every
allocation fresh, a new buffer per grab cost 7.6 and 29.4 ms, the reused one
4.7 and 12.1. The process keeps one frame more resident.

Fixes #68
drmtap_deswizzle copies 4 bytes per pixel and never checked that a row fits
dst_stride. On a 2-byte geometry (60 pixels on a 120-byte stride, dst sized
dst_stride * height) the linear, X-tiled and Y-tiled paths all wrote past
dst: heap-buffer-overflow under asan. A layout it decodes now returns
-EINVAL before writing; one it cannot decode still returns -ENOTSUP.

The header now says what each row gets: width * 4 bytes, the rest of the row
left as it was, which a caller writing into a rectangle of a wider image
relies on. The stride test goes red without any one of the four checks, and
the padding test on a write past width * 4.
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 48 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 1d5a996d-f4b8-4974-9b57-0987fcac54e2
📥 Commits

Reviewing files that changed from the base of the PR and between 1cd197a and e80e12c.

📒 Files selected for processing (6)
  • CHANGELOG.md
  • bindings/rust/libdrmtap-sys/Cargo.toml
  • bindings/rust/libdrmtap-sys/csrc/drmtap.h
  • bindings/rust/libdrmtap/Cargo.toml
  • include/drmtap.h
  • meson.build

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 2b4be13d-f0fd-4d2b-84db-3e3f9a81be7d
📥 Commits

Reviewing files that changed from the base of the PR and between f5f0a07 and 1cd197a.

⛔ Files ignored due to path filters (1)
  • libdrmtap.map is excluded by !**/*.map
📒 Files selected for processing (11)
  • CHANGELOG.md
  • bindings/rust/libdrmtap-sys/csrc/drm_grab.c
  • bindings/rust/libdrmtap-sys/csrc/drmtap.h
  • bindings/rust/libdrmtap-sys/csrc/pixel_convert.c
  • bindings/rust/libdrmtap-sys/src/lib.rs
  • bindings/rust/libdrmtap/README.md
  • bindings/rust/libdrmtap/src/lib.rs
  • include/drmtap.h
  • src/drm_grab.c
  • src/pixel_convert.c
  • tests/test_deswizzle.c

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (7)
  • GitHub Check: Build & Test (Ubuntu 22.04)
  • GitHub Check: Rust crate (libdrmtap-sys + libdrmtap)
  • GitHub Check: Build & Test (Ubuntu 24.04)
  • GitHub Check: Static Analysis
  • GitHub Check: Analyze (actions)
  • GitHub Check: Analyze (c-cpp)
  • GitHub Check: Analyze (rust)
⚠️ CI failures not shown inline (5)

GitHub Actions: CI / Rust crate (libdrmtap-sys + libdrmtap): a frame keeps its context and its pixels past the next grab

Conclusion: failure

View job details

##[group]Run sys_ver=$(sed -n 's/^version = "\([0-9][0-9.]*\)".*/\1/p' libdrmtap-sys/Cargo.toml | head -1)
 �[36;1msys_ver=$(sed -n 's/^version = "\([0-9][0-9.]*\)".*/\1/p' libdrmtap-sys/Cargo.toml | head -1)�[0m
 �[36;1mpin_ver=$(sed -n 's/.*libdrmtap-sys = { version = "\([0-9][0-9.]*\)".*/\1/p' libdrmtap/Cargo.toml | head -1)�[0m
 �[36;1mif out=$(cargo package -p libdrmtap 2>&1); then�[0m
 �[36;1m  echo "$out"�[0m
 �[36;1melse�[0m
 �[36;1m  echo "$out"�[0m
 �[36;1m  if [ -n "$sys_ver" ] && [ "$pin_ver" = "$sys_ver" ] \�[0m
 �[36;1m     && echo "$out" | grep -qF 'failed to select a version for the requirement' \�[0m
 �[36;1m     && echo "$out" | grep -qF "libdrmtap-sys = \"^${sys_ver}\""; then�[0m
 �[36;1m    echo "::notice::libdrmtap-sys ${sys_ver} not yet on crates.io; wrapper package check deferred until after the sys publish"�[0m
 �[36;1m  else�[0m
 �[36;1m    exit 1�[0m
 �[36;1m  fi�[0m
 �[36;1mfi�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
    Packaging libdrmtap v0.5.10 (/home/runner/work/libdrmtap/libdrmtap/bindings/rust/libdrmtap)
 warning: ignoring example `capture_test` as `../examples/capture_test.rs` is not included in the published package
     Updating crates.io index
     Packaged 7 files, 49.0KiB (16.7KiB compressed)
    Verifying libdrmtap v0.5.10 (/home/runner/work/libdrmtap/libdrmtap/bindings/rust/libdrmtap)
  Downloading crates ...
   Downloaded libdrmtap-sys v0.5.10
    Compiling libdrmtap-sys v0.5.10
    Compiling libdrmtap v0.5.10 (/home/runner/work/libdrmtap/libdrmtap/bindings/rust/target/package/libdrmtap-0.5.10)
 error[E0425]: cannot find function `drmtap_frame_owns_data` in crate `ffi`
    --> src/lib.rs:223:44
     |
 223 |     if raw.data.is_null() || unsafe { ffi::drmtap_frame_owns_data(raw) } != 0 {
     |                                            ^^^^^^^^^^^^^^^^^^^^^^ not found in `ffi`
 For more information about this error, try `rustc --explain E0425`.
 error: could not compile `libdrmtap` (lib) due to 1 previous error
 er...

GitHub Actions: CI / 1_Build & Test (Ubuntu 22.04).txt: a frame keeps its context and its pixels past the next grab

Conclusion: failure

View job details

##[group]Run # -type f on purpose: the versioned .so sits next to meson's
 �[36;1m# -type f on purpose: the versioned .so sits next to meson's�[0m
 �[36;1m# libdrmtap.so.0.4.15.p/ build directory, and a glob matches that too.�[0m
 �[36;1mso="$(find build-release -maxdepth 1 -type f -name 'libdrmtap.so.0.*' | head -1)"�[0m
 �[36;1mtest -n "$so" || { echo "::error::no versioned libdrmtap.so in build-release"; exit 1; }�[0m

GitHub Actions: CI / Build & Test (Ubuntu 22.04): a frame keeps its context and its pixels past the next grab

Conclusion: failure

View job details

##[group]Run # -type f on purpose: the versioned .so sits next to meson's
 �[36;1m# -type f on purpose: the versioned .so sits next to meson's�[0m
 �[36;1m# libdrmtap.so.0.4.15.p/ build directory, and a glob matches that too.�[0m
 �[36;1mso="$(find build-release -maxdepth 1 -type f -name 'libdrmtap.so.0.*' | head -1)"�[0m
 �[36;1mtest -n "$so" || { echo "::error::no versioned libdrmtap.so in build-release"; exit 1; }�[0m

GitHub Actions: CI / 3_Build & Test (Ubuntu 24.04).txt: a frame keeps its context and its pixels past the next grab

Conclusion: failure

View job details

##[group]Run # -type f on purpose: the versioned .so sits next to meson's
 �[36;1m# -type f on purpose: the versioned .so sits next to meson's�[0m
 �[36;1m# libdrmtap.so.0.4.15.p/ build directory, and a glob matches that too.�[0m
 �[36;1mso="$(find build-release -maxdepth 1 -type f -name 'libdrmtap.so.0.*' | head -1)"�[0m
 �[36;1mtest -n "$so" || { echo "::error::no versioned libdrmtap.so in build-release"; exit 1; }�[0m

GitHub Actions: CI / Build & Test (Ubuntu 24.04): a frame keeps its context and its pixels past the next grab

Conclusion: failure

View job details

##[group]Run # -type f on purpose: the versioned .so sits next to meson's
 �[36;1m# -type f on purpose: the versioned .so sits next to meson's�[0m
 �[36;1m# libdrmtap.so.0.4.15.p/ build directory, and a glob matches that too.�[0m
 �[36;1mso="$(find build-release -maxdepth 1 -type f -name 'libdrmtap.so.0.*' | head -1)"�[0m
 �[36;1mtest -n "$so" || { echo "::error::no versioned libdrmtap.so in build-release"; exit 1; }�[0m
🧰 Additional context used
📓 Path-based instructions (4)
Source excerpt:

📄 CodeRabbit inference engine (AGENTS.md)

Files:

  • bindings/rust/libdrmtap-sys/csrc/pixel_convert.c
  • tests/test_deswizzle.c
  • bindings/rust/libdrmtap-sys/csrc/drm_grab.c
  • src/pixel_convert.c
  • src/drm_grab.c
  • include/drmtap.h
  • bindings/rust/libdrmtap-sys/csrc/drmtap.h
Source excerpt: **Language**: C11

📄 CodeRabbit inference engine (CONTRIBUTING.md)

Files:

  • bindings/rust/libdrmtap-sys/csrc/pixel_convert.c
  • tests/test_deswizzle.c
  • bindings/rust/libdrmtap-sys/csrc/drm_grab.c
  • src/pixel_convert.c
  • src/drm_grab.c
Source excerpt: **Language**: C11 Source excerpt: **Headers**: include guards with `#ifndef DRMTAP_*_H`

📄 CodeRabbit inference engine (CONTRIBUTING.md)

Files:

  • include/drmtap.h
  • bindings/rust/libdrmtap-sys/csrc/drmtap.h
Source excerpt: Public API changes → update `include/drmtap.h` comments

📄 CodeRabbit inference engine (AGENTS.md)

Files:

  • include/drmtap.h
🪛 Clang (14.0.6)
bindings/rust/libdrmtap-sys/csrc/pixel_convert.c

[note] 269-269: +2, including nesting penalty of 1, nesting level increased to 2

(clang)


[note] 294-294: +3, including nesting penalty of 2, nesting level increased to 3

(clang)


[note] 299-299: +1, nesting level increased to 2

(clang)


[note] 299-299: +1

(clang)


[note] 304-304: +3, including nesting penalty of 2, nesting level increased to 3

(clang)


[note] 360-360: +2, including nesting penalty of 1, nesting level increased to 2

(clang)

tests/test_deswizzle.c

[warning] 341-341: function 'test_deswizzle_leaves_the_row_padding_alone' has cognitive complexity of 26 (threshold 25)

(readability-function-cognitive-complexity)


[note] 349-349: +1, including nesting penalty of 0, nesting level increased to 1

(clang)


[note] 354-354: +2, including nesting penalty of 1, nesting level increased to 2

(clang)


[note] 354-354: +3, including nesting penalty of 2, nesting level increased to 3

(clang)


[note] 354-354: +1

(clang)


[note] 357-357: +2, including nesting penalty of 1, nesting level increased to 2

(clang)


[note] 357-357: +3, including nesting penalty of 2, nesting level increased to 3

(clang)


[note] 358-358: +2, including nesting penalty of 1, nesting level increased to 2

(clang)


[note] 359-359: +3, including nesting penalty of 2, nesting level increased to 3

(clang)


[note] 360-360: +4, including nesting penalty of 3, nesting level increased to 4

(clang)


[note] 360-360: +5, including nesting penalty of 4, nesting level increased to 5

(clang)


[warning] 349-349: loop variable name 'm' is too short, expected at least 2 characters

(readability-identifier-length)


[warning] 350-350: multiple declarations in a single statement reduces readability

(readability-isolate-declaration)


[warning] 350-350: variable name 'w' is too short, expected at least 3 characters

(readability-identifier-length)


[warning] 350-350: variable name 'h' is too short, expected at least 3 characters

(readability-identifier-length)


[warning] 358-358: loop variable name 'y' is too short, expected at least 2 characters

(readability-identifier-length)


[warning] 359-359: loop variable name 'b' is too short, expected at least 2 characters

(readability-identifier-length)


[warning] 375-375: multiple declarations in a single statement reduces readability

(readability-isolate-declaration)


[warning] 375-375: variable name 'w' is too short, expected at least 3 characters

(readability-identifier-length)


[warning] 375-375: variable name 'h' is too short, expected at least 3 characters

(readability-identifier-length)


[warning] 376-376: multiple declarations in a single statement reduces readability

(readability-isolate-declaration)


[warning] 381-381: loop variable name 'm' is too short, expected at least 2 characters

(readability-identifier-length)

bindings/rust/libdrmtap-sys/csrc/drm_grab.c

[note] 1686-1686: +2, including nesting penalty of 1, nesting level increased to 2

(clang)

src/pixel_convert.c

[note] 269-269: +2, including nesting penalty of 1, nesting level increased to 2

(clang)


[note] 294-294: +3, including nesting penalty of 2, nesting level increased to 3

(clang)


[note] 299-299: +1, nesting level increased to 2

(clang)


[note] 299-299: +1

(clang)


[note] 304-304: +3, including nesting penalty of 2, nesting level increased to 3

(clang)


[note] 360-360: +2, including nesting penalty of 1, nesting level increased to 2

(clang)

src/drm_grab.c

[note] 1686-1686: +2, including nesting penalty of 1, nesting level increased to 2

(clang)

🪛 GitHub Actions: CI / 0_Rust crate (libdrmtap-sys + libdrmtap).txt
bindings/rust/libdrmtap-sys/src/lib.rs

[error] 223-223: The cargo package -p libdrmtap verification failed because ffi::drmtap_frame_owns_data is not found in the ffi crate (E0425).

bindings/rust/libdrmtap/src/lib.rs

[error] 223-223: The cargo package -p libdrmtap verification failed because ffi::drmtap_frame_owns_data is not found in the ffi crate (E0425).

🪛 GitHub Actions: CI / Rust crate (libdrmtap-sys + libdrmtap)
bindings/rust/libdrmtap/src/lib.rs

[error] 223-223: 'cargo package -p libdrmtap' failed to verify the package tarball: Rust compilation error E0425 because ffi::drmtap_frame_owns_data is not found in crate ffi.

🪛 LanguageTool
CHANGELOG.md

[style] ~21-~21: Consider using “who” when you are referring to a person instead of an object.
Context: ... buffer to the next grab, so a consumer that drops one frame per grab does not alloc...

(THAT_WHO)


[grammar] ~24-~24: Ensure spelling is correct
Context: ...e, a compressed scanout through the EGL detile, as root): grab_mapped costs what it ...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)

🔇 Additional comments (12)
bindings/rust/libdrmtap-sys/csrc/pixel_convert.c (1)

250-254: LGTM!

Also applies to: 269-271, 294-296, 304-306, 360-362

src/pixel_convert.c (1)

250-254: LGTM!

Also applies to: 269-271, 294-296, 304-306, 360-362

tests/test_deswizzle.c (1)

341-367: LGTM!

Also applies to: 369-394, 403-404

bindings/rust/libdrmtap/src/lib.rs (2)

379-386: The -ENOSPC retry runs without a conversion buffer guarantee for the first attempt's frame state.

The first drmtap_grab_mapped call can fail with -ENOSPC. In that case do_grab releases the frame internally, so the retry can reuse raw safely. The buffer buf is still Some after the retry. The match then compares raw.data with buf.as_ptr(). They are not equal, so control reaches copy_unowned, and the buffer returns to the spare slot. This path is correct. No change is needed here.


640-643: LGTM!

bindings/rust/libdrmtap-sys/csrc/drmtap.h (1)

273-288: LGTM!

Also applies to: 768-777

include/drmtap.h (1)

273-288: LGTM!

Also applies to: 768-777

bindings/rust/libdrmtap-sys/csrc/drm_grab.c (1)

1686-1692: LGTM!

Also applies to: 1923-1930

src/drm_grab.c (1)

1686-1692: LGTM!

Also applies to: 1923-1930

bindings/rust/libdrmtap-sys/src/lib.rs (1)

160-162: LGTM!

bindings/rust/libdrmtap/README.md (1)

80-83: LGTM!

CHANGELOG.md (1)

9-54: LGTM!


📝 Summary

Summary by CodeRabbit

  • New Features
    • Added a frame ownership query so applications can determine whether pixel data remains valid independently of subsequent captures.
    • Rust frames retain their pixels across later grabs, and the capture context stays open until its last handle is dropped.
  • Bug Fixes
    • Deswizzling now rejects rows that exceed the destination stride before writing, preserving existing row padding.
    • Unsupported Nvidia layouts now return -ENOTSUP instead of being CPU-deswizzled.

Walkthrough

The Rust wrapper now shares context ownership across DrmTap, Frame, and Cursor, and retains frame pixels across subsequent grabs. The C API adds a frame-data ownership query. Deswizzle paths reject rows that exceed the destination stride before writing.

Changes

Frame and context lifetime

Layer / File(s) Summary
Frame-data ownership query
include/drmtap.h, src/drm_grab.c, bindings/rust/libdrmtap-sys/csrc/drmtap.h, bindings/rust/libdrmtap-sys/csrc/drm_grab.c, bindings/rust/libdrmtap-sys/src/lib.rs
The C API and Rust FFI expose drmtap_frame_owns_data(). It reports whether frame data matches the frame’s private mapped buffer.
Shared context and frame-owned pixels
bindings/rust/libdrmtap/src/lib.rs, bindings/rust/libdrmtap/README.md, CHANGELOG.md
DrmTap, Frame, and Cursor share the context through Arc<Ctx>. The wrapper copies context-owned pixels into reusable frame buffers and retains each handle’s context. Tests cover pixel independence, handle lifetime, and spare-buffer reuse.

Deswizzle destination stride

Layer / File(s) Summary
Row-fit checks and API contract
src/pixel_convert.c, bindings/rust/libdrmtap-sys/csrc/pixel_convert.c, include/drmtap.h, bindings/rust/libdrmtap-sys/csrc/drmtap.h, CHANGELOG.md
Supported deswizzle paths return -EINVAL when dst_stride is narrower than width * 4. The API documentation describes row placement and preserved padding.
Error reporting and stride tests
src/drm_grab.c, bindings/rust/libdrmtap-sys/csrc/drm_grab.c, tests/test_deswizzle.c
CPU deswizzle callers report the format, width, and stride for narrow rows. Tests check that padding remains unchanged, narrow destinations are not modified, and unsupported layouts return -ENOTSUP.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Bug fix · Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to 1cd19

This change keeps Rust frames and cursors valid after the capture context is dropped. It also keeps frame pixels intact across later grabs, and it makes undersized deswizzle destinations fail with an error instead of overrunning. No concrete merge-blocking issue was found in the supplied review.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 1cd19

The change strengthens captured-data lifetime and rejects undersized output rows. No introduced security issue was established. Remaining uncertainty concerns hardware-dependent failure behavior and privileged-resource shutdown, which now waits for the last retained handle.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The demonstrated change surface is local capture-process memory and retained device/helper resources. The ownership query only inspects a valid captured frame; it adds no capture operation or privilege grant. The inspected capture authority checks are unchanged in the full PR comparison.

Trust Boundaries and Controls

  • observed — Pixels received through the helper's reused buffer are classified as borrowed and copied by the Rust wrapper. The existing exact-payload-size check rejects incomplete helper frames before their advertised pixel extent is exposed.

Resilience and Maintainability Implications

  • inferred — Context retention and release-before-reuse ordering address the prior dangling-context and borrowed-pixel lifetime conditions. Source inspection supports normal failure and retry containment, but does not establish behavior under forced interruption or hardware-dependent concurrency stress.
🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Out of Scope Changes check ⚠️ Warning The drmtap_deswizzle stride checks and their tests address a destination-row overrun, not the context lifetime in [#63] or frame-data lifetime and aliasing in [#68]. The summary also reports removal… Move the stride-validation and Nvidia deswizzle changes, including related tests and documentation, to a separate change or link an applicable issue. Keep this PR focused on [#63] and [#68].
Docstring Coverage ⚠️ Warning Docstring coverage is 67.65% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 34 functions across 9 files. (2 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title summarizes the main change: frames retain their context and pixels across later grabs.
Description check ✅ Passed The description explains the context-lifetime fix, frame-pixel ownership, deswizzle validation, and reported performance.
Linked Issues check ✅ Passed [#63] DrmTap, Frame, and Cursor share an Arc<Ctx>, so the context closes after the last handle drops and the public Rust signatures remain unchanged. The summary reports tests for a frame outl…
Full details: Out of Scope Changes check

Explanation

The drmtap_deswizzle stride checks and their tests address a destination-row overrun, not the context lifetime in [#63] or frame-data lifetime and aliasing in [#68]. The summary also reports removal of the Nvidia block-linear CPU deswizzler, which changes format support without connection to either linked issue.

Full details: Docstring Coverage

Explanation

Docstring coverage is 67.65% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 34 functions across 9 files. (2 skipped: 2 unsupported.)

✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

I checked each frame beside the stream
And kept its pixels safe from overwrite
I hopped through rows with careful stride
No padding byte was brushed aside
The context stayed until handles slept
Then off I bounced, content and kept

Comment @coderabbitai help to get the list of available commands.

…t grab

Stamps 0.5.11 across the six version sites and dates the changelog section.
The wrapper now needs libdrmtap-sys 0.5.11, the first one with
drmtap_frame_owns_data.
@fxd0h
fxd0h merged commit 5694b73 into main Oct 5, 2026
10 checks passed
@fxd0h
fxd0h deleted the fix/wrapper-ctx-refcount branch October 7, 2026 22:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant