Restore HEIC support through system decoders - #50
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Qodana for GoIt seems all right 👌 No new problems were found according to the checks applied 💡 Qodana analysis was run in the pull request mode: only the changed files were checked Contact Qodana teamContact us at qodana-support@jetbrains.com
|
|
First review/CI fixes pushed in d3005e9.
Verification: Still investigating: hosted macOS returns opaque alpha for premultiplied fixtures. A temporary tagged test-only probe captures the effect of removing the The initial Codex code/security reviews are still running. A fresh review will be requested for the final head after their findings are addressed. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1282f13d7a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Codex findings fixed in 9287768; all three original inline findings have observed red/green regressions and are addressed in their threads.
Local verification: make verify-build; focused UI HEIC/drop/file-state/shutdown race tests; HEIC/similarity/nativeguards race tests. GoLand inspected all fourteen changed Go files, including weak warnings. Only two pre-existing duplicated transition sequences in filestate_test.go remain; they exercise distinct invariants and already have the exact test-file Qodana duplication exclusion. Hosted evidence before this push: all Linux race partitions and validation passed on 07ecc15; all three Windows cache regressions passed after the previous fixes. The inspected post-suppression Qodana SARIF for run 35783733218 is empty, CodeQL passes, and security review completed on 07ecc15 without inline findings. These do not substitute for fresh checks on 9287768. Outstanding native qualification: hosted Windows lacks the Microsoft HEIF decoder (0x80040154); both macOS architectures render the original premultiplied-alpha fixtures incorrectly. The user has been asked about a qualified Windows runner and whether explicit macOS refusal of these files is acceptable. Required cases remain enabled. Fresh code/security review and CI are required for this head. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9287768222
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Follow-up ordering fix pushed in 65aa995. Lead review reproduced a merge-mode edge case where a repeated visible URI caused both skipped followers to be saved after its first occurrence. The new regression observed Retained positions now distinguish occurrences of the same visible source. Removing one occurrence updates the retained order as well. The regression checks both the merge and subsequent removal; HEIC, app-state, viewer-state and batch-removal race tests pass. On the preceding head 9287768, all Linux race partitions and validation passed, Qodana's root post-suppression SARIF had zero findings, CodeQL had no open PR alerts, and security review completed without findings. Both macOS architectures now pass the inherited-sandbox regression and native HEIC analysis. The remaining native CI failures are unchanged: missing Microsoft codecs on the hosted Windows runner and incorrect premultiplied-alpha rendition on macOS. Fresh reviews and CI are required for 65aa995. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 65aa9956a3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Review corrections pushed in 85fa03a:
Verification: observed red/green regressions for all confirmed behavior defects, focused UI/imaging race suites, installed-libheif native corpus/primary/transform/header checks, actual Linux archive installation and GIO launch tests for both architectures, nativeguard tooling tests, Windows cross-vet, make verify-build, and GoLand inspections including weak warnings. No new decoder, model, or native library is bundled. No original native corpus expectation or isolation requirement was weakened. The Arch-guide report was rejected with the existing parser contract and passing no-VERSION_ID guide test. All locally verified findings have detailed thread replies; macOS alpha and Linux native CI threads remain open pending hosted evidence. The previous head's post-suppression Qodana SARIF is empty and Linux race/validation/CodeQL passed, but fresh checks and reviews are required for this head. Hosted Windows still has no registered Microsoft HEIF decoder, and this repository has no self-hosted runners. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 85fa03aa18
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5fc689674e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Final verification record for
The loop is blocked by Windows native qualification. Windows job 106972927211 fails because the hosted runner cannot activate Microsoft's HEIF decoder ( This record supersedes pending final-head checks in the implementation plan without creating another commit that would invalidate the reviews. No merge or release was performed; the separately tracked package/target and AVIF provenance qualification work remains open. |
|
Review loop completed for 7d67e7f (2026-09-23).
Windows/Store native, installed-package, codec-recovery and final-package qualification remain closed pre-release tasks by the maintainer's accepted post-rollout testing decision. This does not claim the deferred runtime tests passed. Existing automated packaging/WACK checks remain enabled. This commit-bound record completes the pending review-loop evidence in todos.md and the implementation plan without creating another commit that would invalidate the fresh reviews. Working tree is clean. No merge or release was performed. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7d67e7ff7f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if !v.heic.capability.State().Known { | ||
| // Shutdown suppresses queued UI delivery, including invalidation | ||
| // persistence. Reconcile before Fyne flushes preferences at OnStopped. | ||
| preferences.ClearHEICObservation(v.app) | ||
| } |
There was a problem hiding this comment.
Persist completed HEIC checks during shutdown
If a capability check finishes and changes Observation but its queued UI delivery has not run when the app closes, stopHEIC marks the work stopped, causing that delivery to return without persisting the result. This branch clears unknown state but does nothing for a newly known result, so, for example, an old available observation survives even after a manual check proved the removed codec unavailable; the next launch then admits HEIC files using stale capability. Save the current observation when State().Known is true, and clear it otherwise, before Fyne's final preferences flush.
Useful? React with 👍 / 👎.
| transformed, err := inspectContainer(data) | ||
| if err != nil { | ||
| return Result{}, err | ||
| } |
There was a problem hiding this comment.
Reject non-HEVC primaries in the Linux adapter
For a generic mif1 HEIF, this call validates the container but discards the primary item type returned by primaryItemProperties, then lets libheif decode whatever installed plugin handles it. Consequently an AV1- or other codec-backed generic HEIF without an explicit avif brand can be accepted on Linux, while the Windows and Darwin adapters reject primaries other than hvc1 or grid and runtime support is intended for HEVC-backed HEIF. Validate the primary item type before crossing the C boundary.
Useful? React with 👍 / 👎.
What does this change do, and why?
Restore optional HEIC/HEIF viewing through system decoders: ImageIO on macOS, Microsoft's installed HEIF/HEVC WIC extensions on Windows, and installed libheif on Linux. PicFetch remembers capability, offers a Settings recheck and offline installation guide, and uses the shared image path for browsing, thumbnails, comparison, exports, clipboard, mosaics, metadata and content analysis.
Decoding runs in bounded, cancellable child processes. The adapters preserve primary-image selection, orientation, available EXIF metadata and supported transparency. Metadata probes avoid full image creation on macOS and pixel decoding on Linux. No decoder binary or new Go module dependency is bundled.
Mixed scans continue discovering ordinary formats while the initial HEIC check runs. Unavailable sources retain their collection positions, including repeated occurrences, within a separate retention budget. Provider loss preserves collection membership and shows the HEIC guide instead of substituting a neighboring image. Shutdown joins workers and clears invalidated observations. Linux archives include a per-user desktop installer; associations, manuals and third-party notices describe optional HEIC support.
Design and evidence:
docs/heic-system-decoding.mdandplans/2026-09-22-system-heic.md. The branch also includes the existing PicFetch promo production record.How was this tested?
make verify-buildand native-guard inventory tests pass. Changed code has reviewed GoLand inspections, including weak warnings.a00e98a, all four Linux race partitions, Linux native guards and both Intel/Apple Silicon native suites pass, including original alpha fixtures, metadata/probe checks, worker restrictions and real analysis. Windows cache and picker regressions pass.a00e98a, Qodana's root post-suppression SARIF had zero findings, CodeQL had no open PR alerts, and fresh Codex code/security reviews completed without new findings. On7d67e7f, fresh Codex code/security reviews completed without findings, complete CI passed (including Windows/Store), Qodana's root post-suppression SARIF has zero findings, and CodeQL has no open PR alerts. All 19 review threads are resolved.gioprerequisite, and that package passed after installing the tool in the disposable container.Hosted Windows remains x64. Because that image lacks Microsoft HEIF/HEVC codecs, both Windows and Store test suites explicitly use
-skip-heic-codecs, available only for Windows/Store suites in GitHub Actions. Six exact codec-dependent test names are excluded; worker restrictions, alpha metadata and portable regressions remain covered. Local native qualification and Linux/macOS CI stay strict. The maintainer explicitly accepted Windows/Store native, installed-package, codec-recovery and final-package qualification as testing after rollout; those are closed pre-release items, not claims that unexecuted tests passed. Existing automated packaging/WACK checks remain enabled. The corresponding runner review thread is resolved under this approved scope. Other separately tracked AVIF provenance/release work remains outside this disposition.Checklist
7d67e7f)lang.Land both translation bundlesARCHITECTURE.mddescribes the new package and integrationtodos.mdand the implementation plan