Skip to content

Read only the bytes the type sniffer uses in check_in_media - #226

Merged
abrignoni merged 1 commit into
mainfrom
fix/check-in-media-signature-read
Sep 19, 2026
Merged

abrignoni merged 1 commit into
mainfrom
fix/check-in-media-signature-read

Conversation

@abrignoni

Copy link
Copy Markdown
Owner

check_in_media reads only the bytes the type sniffer looks at instead of the whole media file.

  • For a file on disk the data only feeds guess_mime and guess_extension, and the vendored sniffer uses the first 8,192 bytes, so the sniffer's own get_signature_bytes now does the read. The file is still linked or copied into the report as before.
  • On abe_ios16 the artifacts that check in media read 3.03 GiB whole for 7,992 files; the same files now take 59 MiB. A 2 GiB test video took the run to a 2.30 GB peak and now peaks at 0.15 GB, with the same recorded type.
  • Every LAVA table and TSV came out identical on otto_ios17, cookbook_a11, thisisdfir_takeout, dleapp_imessage_bigsur and whatsapp_macos. New unit test pins the read size and the recorded type and extension.

Same change in all five cores.

🤖 Generated with Claude Code

check_in_media read every media file whole before checking it in. For a
file on disk that data only feeds guess_mime and guess_extension, and the
vendored sniffer looks at no more than the first 8,192 bytes, so a large
video was held in memory in full to identify its type. It now reads those
bytes with the sniffer's own get_signature_bytes. The file is still linked
or copied into the report as before.

On abe_ios16 the artifacts that check in media read 3.03 GiB whole for
7,992 files; the same files now take 59 MiB. A 2 GiB test video checked in
by the WhatsApp artifact took the run to a 2.30 GB peak and now peaks at
0.15 GB, with the same recorded type. Every LAVA table and TSV came out
identical on otto_ios17, cookbook_a11, thisisdfir_takeout,
dleapp_imessage_bigsur and whatsapp_macos. New unit test pins the read size
and the recorded type and extension.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@abrignoni
abrignoni merged commit e4a6f56 into main Sep 19, 2026
8 checks passed
@abrignoni
abrignoni deleted the fix/check-in-media-signature-read branch September 19, 2026 14:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant