93f1019ead
The streaming reader's NUL check only walked completed lines collected from streamLinesFromFile, so a binary blob whose first newline lay past the byte budget (videos, archives, packed JSON) left collectedLines empty and slipped through to the firstLineExceedsLimit branch — which emitted the decoded preview as text instead of the intended refusal. Sniff firstLinePreview alongside collectedLines so the existing refusal fires uniformly. Also added a regression test that uses a 256 KiB blob with no 0x0A bytes to actually exercise the firstLineExceedsLimit path — the previous 6-byte test fit in one collected line and never covered the bug. Fixes #3448