fix: guard against stale instance ids in PartPlate instance scans (#14523)

Deleting an object's instance leaves a stale (obj_id, instance_id) pair in
PartPlate::obj_to_instance_set until it is pruned. object_list_changed() runs
during the delete path and calls has_printable_instances(), which guarded only
obj_id and then indexed object->instances[instance_id] on the now-shorter
vector, dereferencing a garbage ModelInstance* and crashing with SIGSEGV. The
reported fault address (0x12a) matches a member read on that bad pointer.

Reuse the existing valid_instance() helper, which bounds-checks both obj_id and
instance_id, at every obj_to_instance_set scan that was missing the instance-id
check: has_printable_instances(), printable_instance_size(),
is_all_instances_unprintable(), get_extruders_under_cli(),
duplicate_all_instance() and set_pos_and_size() (the last had no bounds check at
all). valid_instance() is made const so the const CLI scan can call it.

Fixes #14159
This commit is contained in:
Kris Austin
2026-07-11 17:41:22 +08:00
committed by GitHub
parent e56cdd707f
commit 4b7182b048
2 changed files with 13 additions and 9 deletions
+1 -1
View File
@@ -167,7 +167,7 @@ private:
wxCoord m_name_texture_height;
void init();
bool valid_instance(int obj_id, int instance_id);
bool valid_instance(int obj_id, int instance_id) const;
void generate_print_polygon(ExPolygon &print_polygon);
void generate_exclude_polygon(ExPolygon &exclude_polygon);
void generate_logo_polygon(ExPolygon &logo_polygon);