fix(encode): publish the output only once the render succeeds - #234
Merged
Merged
Conversation
LeadcodeDev
force-pushed
the
fix/encode-atomic-output
branch
from
September 21, 2026 23:39
8ed0118 to
b6af723
Compare
53 tasks
LeadcodeDev
force-pushed
the
fix/encode-atomic-output
branch
2 times, most recently
from
September 22, 2026 08:34
e9266d1 to
cec3505
Compare
When render_frame_task fails mid-encode (line 613 sets pipe_error and breaks), the code drops stdin and then *waits* for ffmpeg. ffmpeg sees a clean EOF on pipe:0, finalizes the frames it already received, writes the moov atom and exits 0. rustmotion then returns Err, but output_path now holds a structurally valid MP4 containing only the first N frames. Because ffmpeg_args emits -y (line 194), this also silently destroys a previously- good render at the same path. A user scripting rustmotion render who checks only file existence (or whose CI publishes the artifact) ships a truncated video. No code path anywhere in src/cli or src/encode removes the output on failure — only test code calls remove_file on outputs. Fix: On the pipe_error path, call child.kill() and child.wait() before returning, and let _ = std::fs::remove_file(output_path); on both the pipe_error and !status.success() branches. Better still, have ffmpeg write to a sibling scratch path and fs::rename onto output_path only after a clean exit — the same promote-on-success discipline video_audio.rs::partial_wav_path already applies to cached WAVs. Refs #220
LeadcodeDev
force-pushed
the
fix/encode-atomic-output
branch
from
September 22, 2026 08:43
cec3505 to
ca0729d
Compare
LeadcodeDev
added a commit
that referenced
this pull request
Sep 22, 2026
When render_frame_task fails mid-encode (line 613 sets pipe_error and breaks), the code drops stdin and then *waits* for ffmpeg. ffmpeg sees a clean EOF on pipe:0, finalizes the frames it already received, writes the moov atom and exits 0. rustmotion then returns Err, but output_path now holds a structurally valid MP4 containing only the first N frames. Because ffmpeg_args emits -y (line 194), this also silently destroys a previously- good render at the same path. A user scripting rustmotion render who checks only file existence (or whose CI publishes the artifact) ships a truncated video. No code path anywhere in src/cli or src/encode removes the output on failure — only test code calls remove_file on outputs. Fix: On the pipe_error path, call child.kill() and child.wait() before returning, and let _ = std::fs::remove_file(output_path); on both the pipe_error and !status.success() branches. Better still, have ffmpeg write to a sibling scratch path and fs::rename onto output_path only after a clean exit — the same promote-on-success discipline video_audio.rs::partial_wav_path already applies to cached WAVs. Refs #220
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Severity Medium, category correctness. Location:
crates/rustmotion/src/encode/video/ffmpeg.rs:620Impact
When
render_frame_taskfails mid-encode (line 613 setspipe_errorand breaks), the code drops stdin and then waits for ffmpeg. ffmpeg sees a clean EOF onpipe:0, finalizes the frames it already received, writes the moov atom and exits 0. rustmotion then returnsErr, butoutput_pathnow holds a structurally valid MP4 containing only the first N frames. Becauseffmpeg_argsemits-y(line 194), this also silently destroys a previously-good render at the same path. A user scriptingrustmotion renderwho checks only file existence (or whose CI publishes the artifact) ships a truncated video. No code path anywhere insrc/cliorsrc/encoderemoves the output on failure — only test code callsremove_fileon outputs.Fix
On the
pipe_errorpath, callchild.kill()andchild.wait()before returning, andlet _ = std::fs::remove_file(output_path);on both thepipe_errorand!status.success()branches. Better still, have ffmpeg write to a sibling scratch path andfs::renameontooutput_pathonly after a clean exit — the same promote-on-success disciplinevideo_audio.rs::partial_wav_pathalready applies to cached WAVs.Evidence the audit read
Part of the September 2026 audit remediation chantier. Refs #220 (RM-17).