New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Check for sweep_axis being an empty string in PJ_geos. #908

Merged
merged 2 commits into from Mar 27, 2018

Conversation

Projects
None yet
3 participants
@schwehr
Contributor

schwehr commented Mar 27, 2018

Found with autofuzz MemorySanitizer: use-of-uninitialized-value

\0 after sweep causes the failure:
+proj=geos +h=17892900000020003z + +sweep^@+

Check for sweep_axis being an empty string in PJ_geos.
Found with autofuzz MemorySanitizer: use-of-uninitialized-value
@@ -206,7 +206,8 @@ PJ *PROJECTION(geos) {
if (sweep_axis == NULL)
Q->flip_axis = 0;
else {
if (sweep_axis[1] != '\0' || (sweep_axis[0] != 'x' && sweep_axis[0] != 'y'))
if (sweep_axis[0] == '\0' || sweep_axis[1] != '\0' ||

This comment has been minimized.

@rouault

rouault Mar 27, 2018

Member

more complicated that needed. You could just invert the 2 clauses of the original condition

if ((sweep_axis[0] != 'x' && sweep_axis[0] != 'y') || sweep_axis[1] != '\0')

This comment has been minimized.

@schwehr

schwehr Mar 27, 2018

Contributor

Thanks! I was thinking along the same lines after doing a patch that followed the local style. I was thinking about strnlen, but I prefer your suggestion.

@kbevers kbevers merged commit 28800e5 into OSGeo:master Mar 27, 2018

3 checks passed

continuous-integration/appveyor/pr AppVeyor build succeeded
Details
continuous-integration/travis-ci/pr The Travis CI build passed
Details
coverage/coveralls Coverage increased (+0.002%) to 75.759%
Details

@kbevers kbevers added this to the 5.1.0 milestone Mar 27, 2018

@schwehr schwehr deleted the schwehr:geos-sweep-b76441686 branch Mar 27, 2018

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment