From 032f2249a3a5152d26c139985cb54f9f8ae5da3c Mon Sep 17 00:00:00 2001 From: ispyisail Date: Wed, 23 Sep 2026 16:25:39 +1200 Subject: [PATCH] Reject non-finite values in QET::attributeIsAReal() Reviving the still-relevant third of #682 (closed 2026-09-18 purely to clear a review backlog, not on merit). Investigated fresh against current master rather than merged wholesale -- two of the original PR's three findings turned out to already be resolved independently: - Element::valideXml() and Terminal::valideXml() already reject a non-finite x/y (qIsFinite checks, with comments citing this exact class of bug) -- added by someone else since #682 was written. Verified live: a project with x="nan" on an element loads and exports cleanly on current master, 3.1s, no hang. - The illegal-XML-control-byte segfault in QDomDocument::setContent() does not reproduce either. Tested both bytes from the original report (0x00, 0x0E) against a real Qt6 build: both are now refused cleanly (XmlParsingFailed, exit 0), no crash. Qt6's QDom parses differently to the Qt5 one #682 was written and tested against. What's still genuinely open: QET::attributeIsAReal() itself -- QString::toDouble()'s output parameter reports success for "nan"/ "inf"/"-inf", and this shared helper (26+ call sites across the codebase, per #682's own count) had no finiteness check independent of element.cpp/terminal.cpp's own since-added ones. Confirmed several call sites are not behind either of those two gates -- notably elementpicturefactory.cpp's line/rect/ellipse/circle/arc parsing for a symbol's own drawing (a corrupted .elmt, not just a corrupted project file), which was and remains reachable through this helper alone. Qt 6.10.2, ctest 13/13. Co-Authored-By: Claude Sonnet 5 --- sources/qet.cpp | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/sources/qet.cpp b/sources/qet.cpp index 060bce7b2..2260d5d3a 100644 --- a/sources/qet.cpp +++ b/sources/qet.cpp @@ -20,6 +20,7 @@ #include "qeticons.h" #include "shortcutmanager.h" +#include #include #include #include @@ -244,6 +245,12 @@ bool QET::attributeIsAReal( bool ok; qreal tmp = e.attribute(nom_attribut).toDouble(&ok); if (!ok) return(false); + // QString::toDouble() sets ok=true for "nan"/"inf"/"-inf" -- these + // parse successfully but are not usable coordinates. A non-finite + // element/terminal position reaches Conductor::shape() during load + // and hangs there at 100% CPU inside QPainterPathStroker::createStroke(), + // confirmed with gdb: not a blocked wait, genuine unbounded computation. + if (!std::isfinite(tmp)) return(false); if (reel != nullptr) *reel = tmp; return(true); }