The vision prep pass decoded pages with bare `image::load_from_memory`, which applies no allocation bound. `max_pixels` only downscales after a full decode, so a tiny WebP/JPEG header declaring huge dimensions could OOM the blocking worker — the same decompression-bomb the OCR backend already guards against. Manga pages are commonly WebP/JPEG, where the format's own self-limits are weaker than PNG's. Route the decode through `decode_within`, applying an `image::Limits` alloc cap sized from the shared `ocr_max_decode_pixels` (ANALYSIS_OCR_MAX_DECODE_PIXELS). Add real-WebP bomb coverage asserting both the helper and the end-to-end Undecodable fallback. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2.4 KiB
2.4 KiB