brushkit-preview 0.7.0

Tip bitmaps for .abr, .brush and .brushset files: sampled tips, synthesized computed tips, Procreate Shape.png and contact sheets
Documentation
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
#![allow(dead_code)]

use std::path::{Path, PathBuf};

pub fn brush_archive(name: &str) -> Vec<u8> {
    use plist::{Dictionary, Uid, Value};
    let mut settings = Dictionary::new();
    settings.insert("name".into(), Value::Uid(Uid::new(2)));
    let mut top = Dictionary::new();
    top.insert("root".into(), Value::Uid(Uid::new(1)));
    let mut root = Dictionary::new();
    root.insert("$version".into(), Value::Integer(100_000.into()));
    root.insert("$archiver".into(), Value::String("NSKeyedArchiver".into()));
    root.insert(
        "$objects".into(),
        Value::Array(vec![
            Value::String("$null".into()),
            Value::Dictionary(settings),
            Value::String(name.into()),
        ]),
    );
    root.insert("$top".into(), Value::Dictionary(top));
    let mut out = Vec::new();
    Value::Dictionary(root)
        .to_writer_binary(&mut out)
        .expect("binary plist");
    out
}

pub fn brushset_plist(name: &str, uuids: &[&str]) -> Vec<u8> {
    use plist::{Dictionary, Value};
    let mut dict = Dictionary::new();
    dict.insert("name".into(), Value::String(name.into()));
    dict.insert(
        "brushes".into(),
        Value::Array(uuids.iter().map(|u| Value::String((*u).into())).collect()),
    );
    let mut out = Vec::new();
    Value::Dictionary(dict)
        .to_writer_binary(&mut out)
        .expect("binary plist");
    out
}

pub fn crc32(data: &[u8]) -> u32 {
    let mut crc: u32 = 0xFFFF_FFFF;
    for &b in data {
        crc ^= b as u32;
        for _ in 0..8 {
            let mask = (crc & 1).wrapping_neg();
            crc = (crc >> 1) ^ (0xEDB8_8320 & mask);
        }
    }
    !crc
}

pub fn adler32(data: &[u8]) -> u32 {
    let (mut a, mut b) = (1u32, 0u32);
    for &byte in data {
        a = (a + byte as u32) % 65521;
        b = (b + a) % 65521;
    }
    (b << 16) | a
}

/// IHDR color types.
const GRAY: u8 = 0;
const RGBA: u8 = 6;

/// A PNG written by hand whose IHDR declares `width` x `height` at `bit_depth`
/// and `color_type`, and whose IDAT holds `scanlines` (filter bytes included)
/// in one stored DEFLATE block. The declared size need not match the rows. The
/// fuzz seeds embed these bytes, so they must not change when the png encoder
/// does.
fn png_file(width: u32, height: u32, bit_depth: u8, color_type: u8, scanlines: &[u8]) -> Vec<u8> {
    let len = u16::try_from(scanlines.len()).expect("scanlines fit one stored block");
    let mut zlib = vec![0x78, 0x01, 1];
    zlib.extend_from_slice(&len.to_le_bytes());
    zlib.extend_from_slice(&(!len).to_le_bytes());
    zlib.extend_from_slice(scanlines);
    zlib.extend_from_slice(&adler32(scanlines).to_be_bytes());

    let mut ihdr = Vec::new();
    ihdr.extend_from_slice(&width.to_be_bytes());
    ihdr.extend_from_slice(&height.to_be_bytes());
    ihdr.extend_from_slice(&[bit_depth, color_type, 0, 0, 0]);

    let mut png = b"\x89PNG\r\n\x1a\n".to_vec();
    for (kind, data) in [(b"IHDR", ihdr), (b"IDAT", zlib), (b"IEND", Vec::new())] {
        png.extend_from_slice(&(data.len() as u32).to_be_bytes());
        let start = png.len();
        png.extend_from_slice(kind);
        png.extend_from_slice(&data);
        let crc = crc32(&png[start..]);
        png.extend_from_slice(&crc.to_be_bytes());
    }
    png
}

/// `height` unfiltered rows of `width` 8-bit gray pixels of `fill`.
fn gray_scanlines(width: u32, height: u32, fill: u8) -> Vec<u8> {
    let mut scanlines = Vec::new();
    for _ in 0..height {
        scanlines.push(0);
        scanlines.extend(std::iter::repeat_n(fill, width as usize));
    }
    scanlines
}

/// An 8-bit grayscale PNG of `width` x `height` pixels of `fill`.
pub fn gray_png(width: u32, height: u32, fill: u8) -> Vec<u8> {
    png_file(width, height, 8, GRAY, &gray_scanlines(width, height, fill))
}

pub fn real_4x4_png() -> Vec<u8> {
    gray_png(4, 4, 128)
}

/// A PNG whose IHDR declares `w` x `h` at `bit_depth` and `color_type` but
/// whose IDAT holds only 4 x 4 gray pixels.
fn bomb_png(w: u32, h: u32, bit_depth: u8, color_type: u8) -> Vec<u8> {
    png_file(w, h, bit_depth, color_type, &gray_scanlines(4, 4, 128))
}

pub fn dimension_bomb_png(w: u32, h: u32) -> Vec<u8> {
    bomb_png(w, h, 8, GRAY)
}

/// A [`dimension_bomb_png`] whose IHDR declares RGBA at `bit_depth` 8 or 16,
/// so each pixel decodes to four or eight bytes.
pub fn rgba_dimension_bomb_png(w: u32, h: u32, bit_depth: u8) -> Vec<u8> {
    bomb_png(w, h, bit_depth, RGBA)
}

/// A baseline JPEG written by hand that declares `width` x `height` with
/// `components` channels (1 is grayscale, 3 is YCbCr) and holds one 8x8 block
/// of scan data per channel. At 8x8 or smaller it decodes to solid mid-gray.
/// Each Huffman table holds one 1-bit code: every block is a zero DC and an
/// immediate end-of-block.
pub fn baseline_jpeg(width: u32, height: u32, components: u8) -> Vec<u8> {
    partial_scan_jpeg(
        width,
        height,
        &vec![0x11; usize::from(components)],
        components,
    )
}

/// `baseline_jpeg` with one component per `sampling` byte (0xHV), whose one
/// scan holds only the first `scan` of them, as a non-interleaved JPEG's first
/// scan does.
pub fn partial_scan_jpeg(width: u32, height: u32, sampling: &[u8], scan: u8) -> Vec<u8> {
    hand_written_jpeg(0xC0, width, height, sampling, scan)
}

/// `baseline_jpeg` as a progressive JPEG with one component per `sampling`
/// byte (0xHV): one DC scan whose blocks are each a zero DC, so it decodes to
/// solid mid-gray at any size.
pub fn progressive_jpeg(width: u32, height: u32, sampling: &[u8]) -> Vec<u8> {
    let components = u8::try_from(sampling.len()).expect("a few components");
    hand_written_jpeg(0xC2, width, height, sampling, components)
}

/// A JPEG whose frame header has marker `sof` (0xC0, 0xC1 or 0xC2) and whose
/// one scan holds the first `scan` components of the frame.
pub fn hand_written_jpeg(sof: u8, width: u32, height: u32, sampling: &[u8], scan: u8) -> Vec<u8> {
    let components = u8::try_from(sampling.len()).expect("a few components");
    assert!(matches!(components, 1 | 3), "grayscale or YCbCr only");
    let progressive = sof == 0xC2;
    let width = u16::try_from(width).expect("JPEG width is 16-bit");
    let height = u16::try_from(height).expect("JPEG height is 16-bit");
    let mut jpeg = vec![0xFF, 0xD8];
    jpeg.extend_from_slice(&[0xFF, 0xDB, 0x00, 0x43, 0x00]);
    jpeg.extend_from_slice(&[1; 64]);
    jpeg.extend_from_slice(&[0xFF, sof, 0x00, 8 + 3 * components, 8]);
    jpeg.extend_from_slice(&height.to_be_bytes());
    jpeg.extend_from_slice(&width.to_be_bytes());
    jpeg.push(components);
    for (id, &factors) in (1..).zip(sampling) {
        jpeg.extend_from_slice(&[id, factors, 0]);
    }
    for class in [0x00, 0x10] {
        jpeg.extend_from_slice(&[0xFF, 0xC4, 0x00, 0x14, class, 1]);
        jpeg.extend_from_slice(&[0; 15]);
        jpeg.push(0);
    }
    jpeg.extend_from_slice(&[0xFF, 0xDA, 0x00, 6 + 2 * scan, scan]);
    for id in 1..=scan {
        jpeg.extend_from_slice(&[id, 0x00]);
    }
    let spectral_end = if progressive { 0 } else { 0x3F };
    jpeg.extend_from_slice(&[0, spectral_end, 0]);
    // The first MCU: a zero bit per DC and, in a baseline scan, one per
    // end-of-block, padded with one bits to the byte.
    let bits_per_block = if progressive { 1 } else { 2 };
    let blocks: u32 = sampling[..usize::from(scan)]
        .iter()
        .map(|&factors| u32::from(factors >> 4) * u32::from(factors & 0xF))
        .sum();
    let bits = bits_per_block * blocks;
    let bytes = bits.div_ceil(8);
    jpeg.extend(std::iter::repeat_n(0, bytes as usize - 1));
    jpeg.push((0xFFu16 >> (bits - 8 * (bytes - 1))) as u8);
    jpeg.extend_from_slice(&[0xFF, 0xD9]);
    jpeg
}

/// An XML plist that opens `depth` nested arrays and never closes them.
pub fn depth_bomb_plist_xml(depth: usize) -> Vec<u8> {
    let mut s = String::from(
        "<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n\
         <!DOCTYPE plist PUBLIC \"-//Apple//DTD PLIST 1.0//EN\" \
         \"http://www.apple.com/DTDs/PropertyList-1.0.dtd\">\n\
         <plist version=\"1.0\">\n",
    );
    s.push_str(&"<array>".repeat(depth));
    s.into_bytes()
}

/// A binary plist in `brushset.plist` shape whose `payload` is `count`
/// references to one `bytes_each` byte data object. The writer shares equal
/// scalars, so the file holds the bytes once and the tree holds them `count`
/// times.
pub fn shared_data_plist(count: usize, bytes_each: usize) -> Vec<u8> {
    use plist::{Dictionary, Value};
    let mut dict = Dictionary::new();
    dict.insert("name".into(), Value::String("Shared data".into()));
    dict.insert(
        "brushes".into(),
        Value::Array(vec![Value::String("a".into())]),
    );
    dict.insert(
        "payload".into(),
        Value::Array(vec![Value::Data(vec![b'x'; bytes_each]); count]),
    );
    let mut out = Vec::new();
    Value::Dictionary(dict)
        .to_writer_binary(&mut out)
        .expect("binary plist");
    out
}

/// A binary plist in `brushset.plist` shape whose `payload` is `levels`
/// nested arrays, each holding `fanout` references to the one array below it,
/// down to one string. Written by hand because the plist writer does not
/// share collections: the file holds `levels + 8` objects and expands to
/// `fanout ^ levels` strings, [`shared_array_values`] values in all.
pub const fn shared_array_values(levels: usize, fanout: usize) -> usize {
    // The root dictionary, its three keys, the set name, the member array and
    // its one member, then one array or string per node of the reference tree.
    let mut values = 7;
    let mut level = 0;
    while level <= levels {
        values += fanout.pow(level as u32);
        level += 1;
    }
    values
}

pub fn shared_arrays_plist(levels: usize, fanout: usize) -> Vec<u8> {
    fn marker(kind: u8, count: usize) -> Vec<u8> {
        if count < 15 {
            vec![kind | count as u8]
        } else {
            let mut out = vec![kind | 0xF, 0x12];
            out.extend_from_slice(&u32::try_from(count).expect("count fits").to_be_bytes());
            out
        }
    }
    let string = |s: &str| {
        let mut out = marker(0x50, s.len());
        out.extend_from_slice(s.as_bytes());
        out
    };
    let reference = |index: usize| u16::try_from(index).expect("reference fits").to_be_bytes();
    let array = |refs: &[usize]| {
        let mut out = marker(0xA0, refs.len());
        for r in refs {
            out.extend_from_slice(&reference(*r));
        }
        out
    };
    let dict = |pairs: &[(usize, usize)]| {
        let mut out = marker(0xD0, pairs.len());
        for (k, _) in pairs {
            out.extend_from_slice(&reference(*k));
        }
        for (_, v) in pairs {
            out.extend_from_slice(&reference(*v));
        }
        out
    };
    let top = 7 + levels;
    let mut objects = vec![
        dict(&[(1, 2), (3, 4), (6, top)]),
        string("name"),
        string("Shared arrays"),
        string("brushes"),
        array(&[5]),
        string("a"),
        string("payload"),
        string("x"),
    ];
    for below in 7..top {
        objects.push(array(&vec![below; fanout]));
    }

    let mut out = b"bplist00".to_vec();
    let mut offsets = Vec::new();
    for object in &objects {
        offsets.extend_from_slice(&(out.len() as u32).to_be_bytes());
        out.extend_from_slice(object);
    }
    let table = out.len() as u64;
    out.extend_from_slice(&offsets);
    out.extend_from_slice(&[0; 6]);
    out.extend_from_slice(&[4, 2]); // Offset and reference sizes in bytes.
    out.extend_from_slice(&(objects.len() as u64).to_be_bytes());
    out.extend_from_slice(&0u64.to_be_bytes()); // Root object.
    out.extend_from_slice(&table.to_be_bytes());
    out
}

/// A zip of `entries` in order, written by hand with stored entries and fixed
/// header fields. The fuzz seeds embed these bytes, so they must not change
/// when the zip crate or its deflate backend does.
pub fn zip_with(entries: &[(&str, &[u8])]) -> Vec<u8> {
    let mut zip = Vec::new();
    let mut directory = Vec::new();
    for (path, bytes) in entries {
        let offset = u32::try_from(zip.len()).expect("zip fits in 4 GiB");
        let size = u32::try_from(bytes.len()).expect("entry fits in 4 GiB");
        // The fields both headers share: version needed 1.0, no flags, stored,
        // dated 1980-01-01 00:00, then the CRC, both sizes, the name length and
        // no extra field.
        let mut fields = Vec::new();
        for half in [10u16, 0, 0, 0, 0x21] {
            fields.extend_from_slice(&half.to_le_bytes());
        }
        for word in [crc32(bytes), size, size] {
            fields.extend_from_slice(&word.to_le_bytes());
        }
        fields.extend_from_slice(&(path.len() as u16).to_le_bytes());
        fields.extend_from_slice(&0u16.to_le_bytes());

        zip.extend_from_slice(b"PK\x03\x04");
        zip.extend_from_slice(&fields);
        zip.extend_from_slice(path.as_bytes());
        zip.extend_from_slice(bytes);

        directory.extend_from_slice(b"PK\x01\x02");
        directory.extend_from_slice(&10u16.to_le_bytes()); // Made by MS-DOS, version 1.0.
        directory.extend_from_slice(&fields);
        // No comment, disk 0, no internal or external attributes.
        directory.extend_from_slice(&[0; 2 + 2 + 2 + 4]);
        directory.extend_from_slice(&offset.to_le_bytes());
        directory.extend_from_slice(path.as_bytes());
    }
    let count = u16::try_from(entries.len()).expect("entry count fits in u16");
    let directory_offset = zip.len() as u32;
    let directory_size = directory.len() as u32;
    zip.extend_from_slice(&directory);
    zip.extend_from_slice(b"PK\x05\x06");
    zip.extend_from_slice(&[0; 4]); // This disk and the directory's disk.
    zip.extend_from_slice(&count.to_le_bytes());
    zip.extend_from_slice(&count.to_le_bytes());
    zip.extend_from_slice(&directory_size.to_le_bytes());
    zip.extend_from_slice(&directory_offset.to_le_bytes());
    zip.extend_from_slice(&0u16.to_le_bytes()); // No comment.
    zip
}

/// One sampled tip for [`samp_abr`]: `width` x `height` raw 8-bit pixels of
/// `fill`. A `corrupt` tip declares RLE instead, so its first row byte count
/// (two `fill` bytes) overruns the payload and decoding fails.
pub struct SampTip {
    pub width: u32,
    pub height: u32,
    pub fill: u8,
    pub corrupt: bool,
}

/// A v6 `.abr` whose single `samp` block holds `tips` in order. The entries
/// carry no uuid, so the parser lists the brushes in reverse block order.
pub fn samp_abr(tips: &[SampTip]) -> Vec<u8> {
    let mut payload = Vec::new();
    for tip in tips {
        let mut entry = Vec::new();
        entry.extend_from_slice(&0u32.to_be_bytes());
        for bound in [0, 0, tip.height as i32, tip.width as i32] {
            entry.extend_from_slice(&bound.to_be_bytes());
        }
        entry.extend_from_slice(&8u16.to_be_bytes());
        entry.push(u8::from(tip.corrupt));
        entry.extend(std::iter::repeat_n(
            tip.fill,
            (tip.width * tip.height) as usize,
        ));
        payload.extend_from_slice(&(entry.len() as u32).to_be_bytes());
        payload.extend_from_slice(&entry);
        payload.resize(payload.len().next_multiple_of(4), 0);
    }

    let mut file = Vec::new();
    file.extend_from_slice(&6u16.to_be_bytes());
    file.extend_from_slice(&2u16.to_be_bytes());
    file.extend_from_slice(b"8BIMsamp");
    file.extend_from_slice(&(payload.len() as u32).to_be_bytes());
    file.extend_from_slice(&payload);
    file
}

/// A v2 `.abr` whose entries hold `tips` in order, RLE-compressed with one
/// repeat run per row, so `width` is at most 128. A `corrupt` tip carries only
/// its row byte counts and fails to decode. The parser lists the brushes in
/// reverse entry order.
pub fn legacy_abr(tips: &[SampTip]) -> Vec<u8> {
    let mut file = Vec::new();
    file.extend_from_slice(&2u16.to_be_bytes());
    file.extend_from_slice(&(tips.len() as u16).to_be_bytes());
    for tip in tips {
        let mut entry = Vec::new();
        // Misc, spacing, an empty name, anti-aliasing and the i16 bounds.
        entry.extend_from_slice(&[0; 4 + 2 + 4 + 1 + 8]);
        for bound in [0, 0, tip.height as i32, tip.width as i32] {
            entry.extend_from_slice(&bound.to_be_bytes());
        }
        entry.extend_from_slice(&8u16.to_be_bytes());
        entry.push(1);
        for _ in 0..tip.height {
            entry.extend_from_slice(&2u16.to_be_bytes());
        }
        if !tip.corrupt {
            for _ in 0..tip.height {
                entry.extend_from_slice(&[(1 - tip.width as i32) as u8, tip.fill]);
            }
        }
        file.extend_from_slice(&2u16.to_be_bytes());
        file.extend_from_slice(&(entry.len() as u32).to_be_bytes());
        file.extend_from_slice(&entry);
    }
    file
}

pub const TIP_A: &str = "a1b2c3d4-e5f6-7890-abcd-ef1234567890";
pub const TIP_B: &str = "a1b2c3d4-e5f6-7890-abcd-ef1234567891";
pub const TIP_C: &str = "a1b2c3d4-e5f6-7890-abcd-ef1234567892";

/// One preset of [`desc_abr`].
pub enum DescPreset<'a> {
    /// A sampled preset `(name, samp uuid)`.
    Sampled(&'a str, &'a str),
    /// A computed preset with a 30 px round tip.
    Computed(&'a str),
}

/// A v10 `.abr` with a `samp` block of `records`, `(uuid, readable)` each, and
/// a `desc` block of `presets` in order. The layout follows
/// `build_dual_desc_block` in the abr parser tests. An unreadable record has a
/// bitmap depth no header accepts. With no records there is no `samp` block.
pub fn desc_abr(records: &[(&str, bool)], presets: &[DescPreset]) -> Vec<u8> {
    fn u32_be(buf: &mut Vec<u8>, value: u32) {
        buf.extend_from_slice(&value.to_be_bytes());
    }
    fn ostype(buf: &mut Vec<u8>, key: &[u8; 4]) {
        u32_be(buf, 0);
        buf.extend_from_slice(key);
    }
    fn named(buf: &mut Vec<u8>, key: &[u8]) {
        u32_be(buf, key.len() as u32);
        buf.extend_from_slice(key);
    }
    fn text(buf: &mut Vec<u8>, value: &str) {
        buf.extend_from_slice(b"TEXT");
        let units: Vec<u16> = value.encode_utf16().collect();
        u32_be(buf, units.len() as u32 + 1);
        for unit in units.iter().chain([&0]) {
            buf.extend_from_slice(&unit.to_be_bytes());
        }
    }
    fn object(buf: &mut Vec<u8>, class_id: &[u8], item_count: u32) {
        buf.extend_from_slice(b"Objc");
        u32_be(buf, 1);
        buf.extend_from_slice(&0u16.to_be_bytes());
        named(buf, class_id);
        u32_be(buf, item_count);
    }
    fn block(file: &mut Vec<u8>, kind: &[u8; 4], payload: &[u8]) {
        file.extend_from_slice(b"8BIM");
        file.extend_from_slice(kind);
        u32_be(file, payload.len() as u32);
        file.extend_from_slice(payload);
        file.resize(file.len().next_multiple_of(4), 0);
    }

    let mut samp = Vec::new();
    for &(uuid, readable) in records {
        let (side, depth): (u32, u16) = (4, if readable { 8 } else { 0x20 });
        let mut body = vec![b'$'];
        body.extend_from_slice(uuid.as_bytes());
        body.push(0);
        body.extend_from_slice(&[0; 200]);
        for bound in [0, 0, side, side] {
            u32_be(&mut body, bound);
        }
        body.extend_from_slice(&depth.to_be_bytes());
        body.push(0);
        body.extend(std::iter::repeat_n(0x80, (side * side) as usize));
        u32_be(&mut samp, body.len() as u32);
        samp.extend_from_slice(&body);
        samp.resize(samp.len().next_multiple_of(4), 0);
    }

    let mut desc = Vec::new();
    u32_be(&mut desc, 16);
    u32_be(&mut desc, 1);
    desc.extend_from_slice(&0u16.to_be_bytes());
    ostype(&mut desc, b"null");
    u32_be(&mut desc, 1);
    ostype(&mut desc, b"Brsh");
    desc.extend_from_slice(b"VlLs");
    u32_be(&mut desc, presets.len() as u32);
    for preset in presets {
        object(&mut desc, b"brushPreset", 2);
        ostype(&mut desc, b"Nm  ");
        match preset {
            DescPreset::Sampled(name, uuid) => {
                text(&mut desc, name);
                named(&mut desc, b"sampledData");
                text(&mut desc, uuid);
            }
            DescPreset::Computed(name) => {
                text(&mut desc, name);
                ostype(&mut desc, b"Brsh");
                object(&mut desc, b"computedBrush", 1);
                ostype(&mut desc, b"Dmtr");
                desc.extend_from_slice(b"UntF#Pxl");
                desc.extend_from_slice(&30f64.to_be_bytes());
            }
        }
    }

    let mut file = Vec::new();
    file.extend_from_slice(&10u16.to_be_bytes());
    file.extend_from_slice(&2u16.to_be_bytes());
    if !records.is_empty() {
        block(&mut file, b"samp", &samp);
    }
    block(&mut file, b"desc", &desc);
    file
}

/// Every `.abr`, `.brush` and `.brushset` file under `directory`, recursively.
pub fn corpus_files(directory: &Path, files: &mut Vec<PathBuf>) {
    for entry in std::fs::read_dir(directory).expect("read corpus directory") {
        let path = entry.unwrap().path();
        if path.is_dir() {
            corpus_files(&path, files);
        } else if path
            .extension()
            .and_then(|ext| ext.to_str())
            .is_some_and(|ext| matches!(ext.to_lowercase().as_str(), "abr" | "brush" | "brushset"))
        {
            files.push(path);
        }
    }
}