diff --git a/app/Http/Controllers/Admin/DeviceController.php b/app/Http/Controllers/Admin/DeviceController.php index e04a4af..aefa221 100644 --- a/app/Http/Controllers/Admin/DeviceController.php +++ b/app/Http/Controllers/Admin/DeviceController.php @@ -178,8 +178,20 @@ class DeviceController extends Controller $row = $device->photos()->whereKey($photo)->firstOrFail(); abort_unless($origin->ensureLocal($row), 404); - $abs = Storage::disk('local')->path($row->path); - $out = $preview->payload($abs, (string) $device->device_id, (string) ($row->sha256 ?: '')); + $abs = Storage::disk('local')->path((string) $row->path); + try { + $out = $preview->payload($abs, (string) $device->device_id, (string) ($row->sha256 ?: '')); + } catch (\Throwable $e) { + Log::warning('photo preview failed', [ + 'photo_id' => $row->id, + 'path' => $row->path, + 'error' => $e->getMessage(), + ]); + abort(404); + } + if (($out['bytes'] ?? '') === '') { + abort(404); + } if ((string) request()->query('seen', '') === '1') { $this->markPhotoRead($row); } diff --git a/app/Services/PhotoPreview.php b/app/Services/PhotoPreview.php index 2a25277..93da314 100644 --- a/app/Services/PhotoPreview.php +++ b/app/Services/PhotoPreview.php @@ -18,11 +18,19 @@ class PhotoPreview */ public function payload(string $absPath, string $deviceKey, string $sha256): array { - $mime = @mime_content_type($absPath) ?: 'application/octet-stream'; - $raw = (string) file_get_contents($absPath); - if ($raw === '' || ! $this->isHeic($absPath, $mime, $raw)) { + if (! is_file($absPath) || ! is_readable($absPath)) { return [ - 'bytes' => $raw, + 'bytes' => '', + 'mime' => 'application/octet-stream', + 'converted' => false, + ]; + } + + $mime = @mime_content_type($absPath) ?: 'application/octet-stream'; + $head = (string) @file_get_contents($absPath, false, null, 0, 64); + if ($head === '' || ! $this->isHeic($absPath, $mime, $head)) { + return [ + 'bytes' => (string) @file_get_contents($absPath), 'mime' => $mime, 'converted' => false, ]; @@ -49,7 +57,7 @@ class PhotoPreview ]); return [ - 'bytes' => $raw, + 'bytes' => (string) @file_get_contents($absPath), 'mime' => $mime, 'converted' => false, ]; @@ -142,7 +150,16 @@ class PhotoPreview } foreach ($this->convertCommands($src, $dst) as $cmd) { - $result = Process::timeout(45)->run($cmd); + try { + $result = Process::timeout(45)->run($cmd); + } catch (\Throwable $e) { + Log::warning('heic preview convert threw', [ + 'path' => $absPath, + 'cmd' => $cmd[0] ?? '', + 'error' => $e->getMessage(), + ]); + continue; + } if (! $result->successful() || ! is_file($dst) || filesize($dst) < 3) { continue; } @@ -152,6 +169,13 @@ class PhotoPreview } } + return null; + } catch (\Throwable $e) { + Log::warning('heic preview convert threw', [ + 'path' => $absPath, + 'error' => $e->getMessage(), + ]); + return null; } finally { if (is_string($src) && is_file($src)) { diff --git a/tests/Unit/PhotoPreviewTest.php b/tests/Unit/PhotoPreviewTest.php index f03bd11..1af13f2 100644 --- a/tests/Unit/PhotoPreviewTest.php +++ b/tests/Unit/PhotoPreviewTest.php @@ -20,6 +20,21 @@ class PhotoPreviewTest extends TestCase $this->assertFalse($preview->headLooksHeic('')); } + #[Test] + public function heic_convert_process_throw_does_not_bubble(): void + { + Storage::fake('local'); + Process::fake(function () { + throw new \RuntimeException('proc_open is disabled'); + }); + $abs = sys_get_temp_dir().'/preview_'.uniqid().'.heic'; + file_put_contents($abs, "\x00\x00\x00\x18ftypheic\x00\x00\x00\x00mif1"); + $out = (new PhotoPreview)->payload($abs, 'dev-prev', hash('sha256', 'throw')); + $this->assertFalse($out['converted']); + $this->assertNotSame('', $out['bytes']); + @unlink($abs); + } + #[Test] public function heic_without_throwing_when_system_bins_are_outside_basedir(): void {