boostorg / boostorg/polygon

Use-after-free on 64-bit coordinates

Open
#89 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
C++
Stars
70
Forks
75
PR merge metrics
No merged PRs in 30d

Description

```
#include
#include
#include

namespace bp = boost::polygon;

typedef int64_t Coord;
typedef bp::point_data Vec2;
typedef bp::polygon_data Polygon;
typedef bp::polygon_set_data PolySet;

int main()
{
const Vec2 pts[] = {
Vec2(0,0),
Vec2(-219215130788,1374389535),
Vec2(-195163313930,204784040673), // BAD
//Vec2(-195163313929,204784040673), // OK
};

Polygon poly;
set_points(poly, std::cbegin(pts), std::cend(pts));
PolySet pset;
pset.insert(poly);
std::vector c;
pset.get_trapezoids(c);
}
```

Compile with -fsantitize=address to see the use-after-free error, although my glibc complains even without it.

Note that these coordinates are all less than 40 bits.

The suggestions in #36 (use gmp_override.hpp) and #39 (update 64-bit coordinate_traits) do not help.

What does help is changing the last line of evalAtXforYlazy() to `return roundl(evalAtXforYret)`. I do not understand the code well enough to say whether this is a good idea in general.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.