mirror of
https://github.com/OrcaSlicer/OrcaSlicer.git
synced 2026-09-25 18:00:57 +00:00
fix: guard per-filament array reads against short config arrays (#14789)
* fix: guard H2C per-filament array reads against short config arrays The H2C tool-ordering, wipe-tower, and g-code export paths index per-filament config arrays by filament/tool id. A config with fewer entries than the filament count (partial or legacy projects, minimal test configs) makes these reads run past the end of the vector: silent under a normal STL, but UB that aborts under the flatpak build's bounds-checked STL (_GLIBCXX_ASSERTIONS). Route the reads through the existing clamping accessors (get_at, get_filament_category, is_in_same_extruder) and add a small clamp helper for filament_change_length. The guards are no-ops when the arrays are sized to the filament count, so correctly specified configs are unaffected. * fix: size the grouping context's filament_info to the filament count build_filament_group_context built model_info.filament_info by walking filament_type, so a config whose filament_type is shorter than the filament count produced a short vector. FilamentGroup indexes filament_info by filament id, so clamping the individual reads only moved the out-of-bounds access downstream. Loop to filament_nums and read all three fields through get_at, and drop filament_ids entries past the filament count, since the grouping code pairs filament_ids and filament_info by position. Adds a regression test with four filaments and one-entry filament_type / filament_is_support. Without the fix it throws bad_alloc from copying a garbage std::string read past the end. * fix: guard the carousel nozzle-change length reads too The carousel branch added in b90ac13d86/b0dddb4648 reads m_filaments_change_length by tool id without a bounds check, the same pattern this branch already routed through filament_change_length_at a few lines above in both plan_toolchange and plan_tower_new. * fix: guard WipeTower per-filament array reads against short config arrays The BambuStudio WipeTower sync reintroduced raw per-filament array indexing that reads out of bounds when a config leaves an array shorter than the filament count: m_physical_extruder_map in format_line_M104/M109 (indexed even when empty), and m_filament_categories in get_wall_skip_points and get_wall_filament_for_all_layer. Silent on a normal STL, a hard abort under the bounds-checked STL the Flatpak build uses. Bounds-check the physical extruder map before indexing (omitting the T token, as the existing -1 path already does), and route the two raw m_filament_categories reads through the clamping get_filament_category() accessor the surrounding code already uses. No change for correctly-sized configs.
This commit is contained in:
@@ -1349,7 +1349,7 @@ public:
|
||||
// flavor it reaches understands, not the zero dwell the other flavors flush with.
|
||||
buffer += "M400\n";
|
||||
buffer += "M104";
|
||||
if (target_extruder != -1)
|
||||
if (target_extruder != -1 && target_extruder < int(m_physical_extruder_map.size()))
|
||||
buffer += (" T" + std::to_string(m_physical_extruder_map[target_extruder]));
|
||||
buffer += " S" + std::to_string(target_temp) + " N0"; // N0 means the gcode is generated by slicer
|
||||
if (!comment.empty()) buffer += " ;" + comment;
|
||||
@@ -1361,7 +1361,7 @@ public:
|
||||
WipeTowerWriter &format_line_M109(int target_temp, int target_extruder, const std::string &comment = std::string())
|
||||
{
|
||||
std::string buffer = "M109";
|
||||
if (target_extruder != -1)
|
||||
if (target_extruder != -1 && target_extruder < int(m_physical_extruder_map.size()))
|
||||
buffer += (" T" + std::to_string(m_physical_extruder_map[target_extruder]));
|
||||
buffer += " S" + std::to_string(target_temp) + " N0"; // N0 means the gcode is generated by slicer
|
||||
if (!comment.empty()) buffer += " ;" + comment;
|
||||
@@ -3309,7 +3309,7 @@ void WipeTower::get_wall_skip_points(const WipeTowerInfo &layer, int layer_id)
|
||||
if (!cur_block_depth.count(m_filpar[new_filament].category)) cur_block_depth[m_filpar[new_filament].category] = block->start_depth;
|
||||
process_depth = cur_block_depth[m_filpar[new_filament].category];
|
||||
if (is_need_ramming(new_filament, old_filament, layer_id)) {
|
||||
if (m_filament_categories[new_filament] == m_filament_categories[old_filament])
|
||||
if (get_filament_category(new_filament) == get_filament_category(old_filament))
|
||||
process_depth += nozzle_change_depth;
|
||||
else {
|
||||
if (!cur_block_depth.count(m_filpar[old_filament].category)) {
|
||||
@@ -4783,7 +4783,7 @@ int WipeTower::get_wall_filament_for_all_layer()
|
||||
int filament_id = -1;
|
||||
int filament_count = 0;
|
||||
for (auto iter = filament_counts.begin(); iter != filament_counts.end(); ++iter) {
|
||||
if (m_filament_categories[iter->first] == selected_category && iter->second > filament_count) {
|
||||
if (get_filament_category(iter->first) == selected_category && iter->second > filament_count) {
|
||||
filament_id = iter->first;
|
||||
filament_count = iter->second;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user