mirror of
https://github.com/OrcaSlicer/OrcaSlicer.git
synced 2026-10-01 21:01:12 +00:00
Harden 3MF Loading Against Malformed Plate IDs and Paint Data (#15959)
* Reject 3MF Plate IDs Below 1 Instead of Indexing Before the Plate List The plate importer copied each plater_id from model_settings.config into the 1-based plate list after checking only the upper bound, so plater_id="0" wrote to plate_data_list[-1] and crashed on load. Both copy sites now reject ids below 1 with the same "invalid plate index" error already used for ids past the end. * Drop Malformed 3MF Paint Data Instead of Reading Past the Bitstream Painted facets are decoded from a bitstream a nibble at a time with no bound check, so a truncated or corrupt paint string in a 3MF (for example split codes with no children behind them) read past the end and crashed on load and slice. A one- or two-side split naming side 3 also indexed past the triangle's vertices. Every nibble read now goes through a bounds-checked reader. Loading validates each triangle's tree and drops a malformed one with a warning, so the stored data, used extruder states and later decoding all agree. deserialize() also unwinds and clears any triangle whose tree is incomplete or malformed, and has_facets() stops at a truncated triangle. Valid streams decode unchanged.
This commit is contained in:
+131
-15
@@ -19,6 +19,7 @@
|
||||
#include <boost/filesystem/operations.hpp>
|
||||
#include <boost/algorithm/string/predicate.hpp>
|
||||
#include <algorithm>
|
||||
#include <functional>
|
||||
|
||||
#include <catch2/catch_tostring.hpp>
|
||||
#include <Eigen/Core>
|
||||
@@ -184,16 +185,13 @@ static bool read_cad_recipe_entry(const std::string& path, std::string& out,
|
||||
return found;
|
||||
}
|
||||
|
||||
// Rewrites the archive at `path` with the recipe entry back under the name it had before the
|
||||
// rename, which is what every project saved by an earlier build looks like on disk. Generated
|
||||
// rather than checked in because a whole project archive is not frozen evidence the way a bare
|
||||
// recipe blob is -- it has to be whatever today's exporter writes, with only the name aged.
|
||||
// miniz cannot rename in place and open_zip_writer truncates, so the entries are held across
|
||||
// the switch.
|
||||
static void rename_cad_recipe_entry_to_legacy(const std::string& path)
|
||||
// Rewrites the archive at `path`, letting `edit` change the name or data of each entry; returns
|
||||
// whether `edit` reported a change for any of them. miniz cannot edit in place and
|
||||
// open_zip_writer truncates, so the entries are held across the switch.
|
||||
static bool rewrite_3mf_entries(const std::string& path, const std::function<bool(std::string& name, std::string& data)>& edit)
|
||||
{
|
||||
std::vector<std::pair<std::string, std::string>> entries;
|
||||
bool renamed = false;
|
||||
bool changed = false;
|
||||
{
|
||||
mz_zip_archive zip;
|
||||
mz_zip_zero_struct(&zip);
|
||||
@@ -208,22 +206,140 @@ static void rename_cad_recipe_entry_to_legacy(const std::string& path)
|
||||
std::string data((size_t) st.m_uncomp_size, '\0');
|
||||
if (st.m_uncomp_size > 0)
|
||||
REQUIRE(mz_zip_reader_extract_to_mem(&zip, i, data.data(), data.size(), 0));
|
||||
if (boost::algorithm::iequals(name, CAD_RECIPE_ENTRY)) {
|
||||
name = LEGACY_CAD_RECIPE_ENTRY;
|
||||
renamed = true;
|
||||
}
|
||||
changed |= edit(name, data);
|
||||
entries.emplace_back(std::move(name), std::move(data));
|
||||
}
|
||||
close_zip_reader(&zip);
|
||||
}
|
||||
// Without this the scenario would degrade silently into re-testing the new name if the
|
||||
// exporter's constant ever moved again: every load below would still pass.
|
||||
REQUIRE(renamed);
|
||||
|
||||
Zipper out(path);
|
||||
for (const auto& e : entries)
|
||||
out.add_entry(e.first, e.second.data(), e.second.size());
|
||||
out.finalize();
|
||||
return changed;
|
||||
}
|
||||
|
||||
// Rewrites the archive at `path` with the recipe entry back under the name it had before the
|
||||
// rename, which is what every project saved by an earlier build looks like on disk. Generated
|
||||
// rather than checked in because a whole project archive is not frozen evidence the way a bare
|
||||
// recipe blob is -- it has to be whatever today's exporter writes, with only the name aged.
|
||||
static void rename_cad_recipe_entry_to_legacy(const std::string& path)
|
||||
{
|
||||
const bool renamed = rewrite_3mf_entries(path, [](std::string& name, std::string&) {
|
||||
if (!boost::algorithm::iequals(name, CAD_RECIPE_ENTRY))
|
||||
return false;
|
||||
name = LEGACY_CAD_RECIPE_ENTRY;
|
||||
return true;
|
||||
});
|
||||
// Without this the scenario would degrade silently into re-testing the new name if the
|
||||
// exporter's constant ever moved again: every load below would still pass.
|
||||
REQUIRE(renamed);
|
||||
}
|
||||
|
||||
// Replaces the first occurrence of `from` in any entry whose name ends with `suffix`.
|
||||
static bool replace_in_3mf_entry(const std::string& path, const std::string& suffix, const std::string& from, const std::string& to)
|
||||
{
|
||||
bool replaced = false;
|
||||
rewrite_3mf_entries(path, [&](std::string& name, std::string& data) {
|
||||
if (replaced || !boost::algorithm::ends_with(name, suffix))
|
||||
return false;
|
||||
if (const size_t pos = data.find(from); pos != std::string::npos) {
|
||||
data.replace(pos, from.size(), to);
|
||||
replaced = true;
|
||||
}
|
||||
return replaced;
|
||||
});
|
||||
return replaced;
|
||||
}
|
||||
|
||||
// Stores a one-plate project holding a cube whose first two facets are painted Extruder2 and
|
||||
// Extruder3, which the exporter writes as paint_color="8" and paint_color="0C".
|
||||
static void store_painted_cube(const std::string& path)
|
||||
{
|
||||
Model model;
|
||||
ModelObject* object = model.add_object();
|
||||
ModelVolume* volume = object->add_volume(make_cube(10., 10., 10.));
|
||||
object->add_instance();
|
||||
{
|
||||
TriangleSelector selector(volume->mesh());
|
||||
selector.set_facet(0, EnforcerBlockerType::Extruder2);
|
||||
selector.set_facet(1, EnforcerBlockerType::Extruder3);
|
||||
REQUIRE(volume->mmu_segmentation_facets.set(selector));
|
||||
}
|
||||
ScopedTemporaryDir backup_dir("orca_paint_src");
|
||||
model.set_backup_path(backup_dir.string());
|
||||
|
||||
DynamicPrintConfig cfg;
|
||||
PlateData plate;
|
||||
plate.plate_index = 0;
|
||||
StoreParams sp;
|
||||
sp.path = path.c_str();
|
||||
sp.model = &model;
|
||||
sp.config = &cfg;
|
||||
sp.strategy = SaveStrategy::Zip64 | SaveStrategy::Silence;
|
||||
sp.plate_data_list.push_back(&plate);
|
||||
REQUIRE(store_bbs_3mf(sp));
|
||||
}
|
||||
|
||||
// Loads `path` through the BBS importer into `model`, releasing the plates it returns. The
|
||||
// importer stages metadata through `backup_dir`, which has to outlive the model.
|
||||
static bool load_project(const std::string& path, Model& model, const ScopedTemporaryDir& backup_dir)
|
||||
{
|
||||
model.set_backup_path(backup_dir.string());
|
||||
DynamicPrintConfig config;
|
||||
ConfigSubstitutionContext ctxt{ ForwardCompatibilitySubstitutionRule::Enable };
|
||||
PlateDataPtrs plates;
|
||||
std::vector<Preset*> project_presets;
|
||||
bool is_bbl_3mf = false, is_orca_3mf = false;
|
||||
Semver file_version;
|
||||
const bool loaded = load_bbs_3mf(path.c_str(), &config, &ctxt, &model, &plates, &project_presets, &is_bbl_3mf,
|
||||
&is_orca_3mf, &file_version, nullptr, LoadStrategy::LoadModel | LoadStrategy::LoadConfig);
|
||||
release_PlateData_list(plates);
|
||||
return loaded;
|
||||
}
|
||||
|
||||
TEST_CASE("A project with a plate id below 1 fails to load", "[3mf][Regression]")
|
||||
{
|
||||
const int plate_id = GENERATE(0, -1);
|
||||
INFO("plater_id " << plate_id);
|
||||
|
||||
ScopedTemporaryFile temp(".3mf");
|
||||
store_painted_cube(temp.string());
|
||||
{
|
||||
ScopedTemporaryDir backup_dir("orca_plate_dst");
|
||||
Model model;
|
||||
REQUIRE(load_project(temp.string(), model, backup_dir));
|
||||
}
|
||||
|
||||
REQUIRE(replace_in_3mf_entry(temp.string(), "model_settings.config", "key=\"plater_id\" value=\"1\"",
|
||||
"key=\"plater_id\" value=\"" + std::to_string(plate_id) + "\""));
|
||||
ScopedTemporaryDir backup_dir("orca_plate_dst");
|
||||
Model model;
|
||||
bool loaded = true;
|
||||
REQUIRE_NOTHROW(loaded = load_project(temp.string(), model, backup_dir));
|
||||
REQUIRE_FALSE(loaded);
|
||||
}
|
||||
|
||||
TEST_CASE("A project with malformed paint data loads without the damaged facet", "[3mf][Regression]")
|
||||
{
|
||||
ScopedTemporaryFile temp(".3mf");
|
||||
store_painted_cube(temp.string());
|
||||
// Split codes with no children behind them: the stream runs out mid-tree.
|
||||
REQUIRE(replace_in_3mf_entry(temp.string(), ".model", "paint_color=\"8\"", "paint_color=\"FFFFFFFFFFFFFFFF3\""));
|
||||
|
||||
ScopedTemporaryDir backup_dir("orca_paint_dst");
|
||||
Model model;
|
||||
REQUIRE(load_project(temp.string(), model, backup_dir));
|
||||
REQUIRE(model.objects.size() == 1);
|
||||
const ModelVolume& volume = *model.objects.front()->volumes.front();
|
||||
const auto& data = volume.mmu_segmentation_facets.get_data();
|
||||
REQUIRE_FALSE(data.used_states[size_t(EnforcerBlockerType::Extruder2)]);
|
||||
REQUIRE(data.used_states[size_t(EnforcerBlockerType::Extruder3)]);
|
||||
|
||||
TriangleSelector selector(volume.mesh());
|
||||
REQUIRE_NOTHROW(selector.deserialize(data));
|
||||
REQUIRE(selector.num_facets(EnforcerBlockerType::Extruder2) == 0);
|
||||
REQUIRE(selector.num_facets(EnforcerBlockerType::Extruder3) == 1);
|
||||
}
|
||||
|
||||
// The recipe lives only in the BBS-native backend, because that is the only one that runs:
|
||||
|
||||
@@ -3,6 +3,8 @@
|
||||
#include "libslic3r/TriangleSelector.hpp"
|
||||
#include "libslic3r/TriangleMesh.hpp"
|
||||
|
||||
#include <algorithm>
|
||||
|
||||
using namespace Slic3r;
|
||||
|
||||
// A sphere gives well over ExtruderMax original facets, so every extruder state can be assigned
|
||||
@@ -123,3 +125,77 @@ TEST_CASE("Extruder states match the CONST_FILAMENTS hex encoding", "[TriangleSe
|
||||
INFO("Hex " << c.hex << " -> extruder " << c.state);
|
||||
REQUIRE(TriangleSelector::has_facets(data, EnforcerBlockerType(c.state)));
|
||||
}
|
||||
|
||||
// Pack 4-bit codes into a bitstream, least significant bit first, in the order the decoder reads them.
|
||||
static std::vector<bool> pack_nibbles(const std::vector<int> &nibbles)
|
||||
{
|
||||
std::vector<bool> bitstream;
|
||||
for (const int nibble : nibbles)
|
||||
for (int bit = 0; bit < 4; ++bit)
|
||||
bitstream.push_back((nibble >> bit) & 1);
|
||||
return bitstream;
|
||||
}
|
||||
|
||||
TEST_CASE("A valid paint stream with nested splits round-trips bit for bit", "[TriangleSelector]")
|
||||
{
|
||||
const TriangleMesh mesh = test_mesh();
|
||||
|
||||
TriangleSelector::TriangleSplittingData data;
|
||||
data.triangles_to_split.emplace_back(0, 0);
|
||||
// A three-side split whose children, in stream order, are: a one-side split (side 2) into two
|
||||
// leaves, a two-side split (side 1) into leaves of states 20, 0 and 8, then two plain leaves.
|
||||
const std::vector<int> triangle_0 = {0b0011,
|
||||
0b1001, 0b1000, 0b0100,
|
||||
0b0110, 0b1100, 0b1111, 20 - 18, 0b0000, 0b1100, 8 - 3,
|
||||
0b1000,
|
||||
0b0100};
|
||||
data.bitstream = pack_nibbles(triangle_0);
|
||||
data.triangles_to_split.emplace_back(5, int(data.bitstream.size()));
|
||||
const std::vector<bool> triangle_5 = pack_nibbles({0b1100, 3 - 3});
|
||||
data.bitstream.insert(data.bitstream.end(), triangle_5.begin(), triangle_5.end());
|
||||
data.reset_used_states();
|
||||
REQUIRE(data.update_used_states(0));
|
||||
|
||||
TriangleSelector restored(mesh);
|
||||
restored.deserialize(data);
|
||||
|
||||
REQUIRE(restored.num_facets(EnforcerBlockerType::Extruder20) == 1);
|
||||
REQUIRE(restored.num_facets(EnforcerBlockerType::Extruder3) == 1);
|
||||
REQUIRE(restored.serialize() == data);
|
||||
}
|
||||
|
||||
TEST_CASE("A truncated or malformed paint stream drops only the damaged triangle", "[TriangleSelector][Regression]")
|
||||
{
|
||||
struct Case { const char *name; std::vector<int> nibbles; };
|
||||
const auto c = GENERATE(values<Case>({
|
||||
{"three-side split missing two children", {0b0011, 0b1000, 0b1000}},
|
||||
{"leaf missing its state nibble", {0b1100}},
|
||||
{"leaf missing its second state nibble", {0b1100, 0b1111}},
|
||||
{"splits nested past the end", {0b0011, 0xF, 0xF, 0xF, 0xF, 0xF, 0xF, 0xF, 0xF,
|
||||
0xF, 0xF, 0xF, 0xF, 0xF, 0xF, 0xF, 0xF}},
|
||||
{"one-side split of the nonexistent side 3", {0b1101, 0b1000, 0b1000}},
|
||||
}));
|
||||
INFO(c.name);
|
||||
|
||||
const TriangleMesh mesh = test_mesh();
|
||||
TriangleSelector intact(mesh);
|
||||
intact.set_facet(0, EnforcerBlockerType::Extruder2);
|
||||
|
||||
// Triangle 0 stays intact, triangle 1 carries the damaged stream.
|
||||
TriangleSelector::TriangleSplittingData data = intact.serialize();
|
||||
data.triangles_to_split.emplace_back(1, int(data.bitstream.size()));
|
||||
const std::vector<bool> damaged = pack_nibbles(c.nibbles);
|
||||
data.bitstream.insert(data.bitstream.end(), damaged.begin(), damaged.end());
|
||||
|
||||
TriangleSelector restored(mesh);
|
||||
REQUIRE_NOTHROW(restored.deserialize(data));
|
||||
// Triangle 1 unwinds completely, so the selector holds exactly the intact paint.
|
||||
REQUIRE(restored.serialize() == intact.serialize());
|
||||
|
||||
REQUIRE_NOTHROW(TriangleSelector::has_facets(data, EnforcerBlockerType::Extruder3));
|
||||
|
||||
TriangleSelector::TriangleSplittingData recomputed = data;
|
||||
recomputed.reset_used_states();
|
||||
REQUIRE_FALSE(recomputed.update_used_states(0));
|
||||
REQUIRE(std::none_of(recomputed.used_states.begin(), recomputed.used_states.end(), [](bool used) { return used; }));
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user