compute_fov loads out-of-range int into TCOD_fov_algorithm_t enum (UBSan) #310
Labels
No labels
Alpha Release Requirement
Bugfix
Demo Target
Documentation
Major Feature
Minor Feature
priority:tier1-active
priority:tier2-foundation
priority:tier3-future
priority:tier4-deferred
Refactoring & Cleanup
system:animation
system:documentation
system:grid
system:input
system:performance
system:procgen
system:python-binding
system:rendering
system:ui-hierarchy
Tiny Feature
workflow:blocked
workflow:needs-benchmark
workflow:needs-documentation
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
john/McRogueFace#310
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Found by:
fuzz_fovtarget (W8)Summary
The Python binding for
Grid.compute_fovpasses a raw intalgorithmargument straight through toGridData::computeFOVwithout validating it against theTCOD_fov_algorithm_tenum range. UBSan catches the invalid enum load:(
4294967247is-49reinterpreted as unsigned.)Reproduction
Crash input preserved at:
Root Cause
src/GridData.cpp:136src/UIGridPyMethods.cpp:112Suggested Fix
Validate the int at the binding layer before converting to the enum. Reject (or clamp to a default) anything outside
TCOD_BASIC..TCOD_SYMMETRIC_SHADOWCAST, raising aValueErrorto Python for invalid input.Related
Fail-early principle: validation belongs at the boundary between Python and the C++ engine, not deep in the TCOD call path.