Skip to content

bound composite left and top to coordinate limit - #4564

Merged
lovell merged 1 commit into
lovell:mainfrom
metsw24-max:composite-offset-bound
Jul 5, 2026
Merged

bound composite left and top to coordinate limit#4564
lovell merged 1 commit into
lovell:mainfrom
metsw24-max:composite-offset-bound

Conversation

@metsw24-max

Copy link
Copy Markdown
Contributor

Composite offsets truncate to 32-bit in native

The per-overlay left and top are validated with is.integer only, so any safe integer up to 2^53 is accepted, but AttrAsInt32 narrows them before they reach the vips_composite position arrays. An offset such as left: 4294967301 silently becomes 5, placing the overlay somewhere other than requested, while 2147483648 wraps negative and the overlay is dropped off-canvas with no error.

Bounded both to -100000000..100000000, the same coordinate limit the sibling extract/create/raw options already use. Negative offsets stay valid, so partly off-edge overlays are unaffected; only values that would truncate are now rejected up front. Regression cases added alongside the existing invalid left/top tests.

@lovell
lovell merged commit c19059b into lovell:main Jul 5, 2026
32 checks passed
@lovell

lovell commented Jul 5, 2026

Copy link
Copy Markdown
Owner

Thank you

@lovell lovell added this to the v0.35.4 milestone Jul 5, 2026
dadezzz pushed a commit to dadezzz/university_notes that referenced this pull request Aug 30, 2026
This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [sharp](https://sharp.pixelplumbing.com) ([source](https://github.com/lovell/sharp), [changelog](https://github.com/lovell/sharp/blob/main/docs/src/content/docs/changelog.md)) | [`0.35.3` → `0.35.4`](https://renovatebot.com/diffs/npm/sharp/0.35.3/0.35.4) | ![age](https://developer.mend.io/api/mc/badges/age/npm/sharp/0.35.4?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/sharp/0.35.3/0.35.4?slim=true) |

---

### Release Notes

<details>
<summary>lovell/sharp (sharp)</summary>

### [`v0.35.4`](https://github.com/lovell/sharp/releases/tag/v0.35.4)

[Compare Source](lovell/sharp@v0.35.3...v0.35.4)

<https://github.com/lovell/sharp-libvips/releases/tag/v1.3.3>

- Bound resize dimensions to coordinate limit.

- Bound composite left and top to coordinate limit.
  [#&#8203;4564](lovell/sharp#4564)
  [@&#8203;metsw24-max](https://github.com/metsw24-max)

- Round palette bit depth up for png and gif colours.
  [#&#8203;4569](lovell/sharp#4569)
  [@&#8203;metsw24-max](https://github.com/metsw24-max)

- Ensure tiff.subifd input option is used.
  [#&#8203;4572](lovell/sharp#4572)
  [@&#8203;metsw24-max](https://github.com/metsw24-max)

- Ensure `info.pages` is correct when limiting input page range.
  [#&#8203;4578](lovell/sharp#4578)
  [@&#8203;metsw24-max](https://github.com/metsw24-max)

- Improve support for input Streams finishing before output is requested.
  [#&#8203;4584](lovell/sharp#4584)
  [@&#8203;Jaybhade](https://github.com/Jaybhade)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC41MC4zIiwidXBkYXRlZEluVmVyIjoiNDQuNTAuMyIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants