forked from unom/punktfunk
`obu_size` is a leb128 read straight out of the stream — bounded only by `u32::MAX`, and tied to nothing about how many bytes are actually present. `read_obu` then built the OBU with an unchecked `&data[start_offset..start_offset + obu_size]`, so any access unit whose last OBU declared more payload than remained panicked with `range end index .. out of range for slice of length ..`. That is a bounds check rather than arithmetic, so it panics in release too, and it aborts whichever thread is decoding. It reaches every native AV1 rung: pf-vkdecode, pf-dxvadec and pf-vaadec are all re-exports of `pf_bitstream::av1::Av1Planner`, whose `plan_au` hands raw access-unit bytes straight to this function. `PUNKTFUNK_AU_FAULT=truncate` produces the shape, and so does any AU delivered short over the wire. This was a hole in an otherwise consistent posture, not a missing idea: `plan_au` degrades every other malformation to `TruncatedAu`/`Parse`, and pf-vkdecode already re-validates `obu.end > au.len()` a layer up. Bound it once, where all three rungs route through. The checked end is reused for `bytes_used`, so the slice and the advance can no longer disagree. Both tests fail without the guard — the parser one reproduces the original panic verbatim (`range end index 10600 out of range for slice of length 5293`). Recorded as PROVENANCE.md deviation 14. Not filed upstream.