Reject non-finite values in QET::attributeIsAReal()

Reviving the still-relevant third of #682 (closed 2026-09-18 purely to
clear a review backlog, not on merit). Investigated fresh against
current master rather than merged wholesale -- two of the original
PR's three findings turned out to already be resolved independently:

- Element::valideXml() and Terminal::valideXml() already reject a
  non-finite x/y (qIsFinite checks, with comments citing this exact
  class of bug) -- added by someone else since #682 was written.
  Verified live: a project with x="nan" on an element loads and
  exports cleanly on current master, 3.1s, no hang.
- The illegal-XML-control-byte segfault in QDomDocument::setContent()
  does not reproduce either. Tested both bytes from the original
  report (0x00, 0x0E) against a real Qt6 build: both are now refused
  cleanly (XmlParsingFailed, exit 0), no crash. Qt6's QDom parses
  differently to the Qt5 one #682 was written and tested against.

What's still genuinely open: QET::attributeIsAReal() itself --
QString::toDouble()'s output parameter reports success for "nan"/
"inf"/"-inf", and this shared helper (26+ call sites across the
codebase, per #682's own count) had no finiteness check independent of
element.cpp/terminal.cpp's own since-added ones. Confirmed several
call sites are not behind either of those two gates -- notably
elementpicturefactory.cpp's line/rect/ellipse/circle/arc parsing for a
symbol's own drawing (a corrupted .elmt, not just a corrupted project
file), which was and remains reachable through this helper alone.

Qt 6.10.2, ctest 13/13.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
ispyisail
2026-09-23 16:25:39 +12:00
parent 6d8459d647
commit 032f2249a3
+7
View File
@@ -20,6 +20,7 @@
#include "qeticons.h"
#include "shortcutmanager.h"
#include <cmath>
#include <limits>
#include <QBuffer>
#include <QColorDialog>
@@ -244,6 +245,12 @@ bool QET::attributeIsAReal(
bool ok;
qreal tmp = e.attribute(nom_attribut).toDouble(&ok);
if (!ok) return(false);
// QString::toDouble() sets ok=true for "nan"/"inf"/"-inf" -- these
// parse successfully but are not usable coordinates. A non-finite
// element/terminal position reaches Conductor::shape() during load
// and hangs there at 100% CPU inside QPainterPathStroker::createStroke(),
// confirmed with gdb: not a blocked wait, genuine unbounded computation.
if (!std::isfinite(tmp)) return(false);
if (reel != nullptr) *reel = tmp;
return(true);
}