Fix three latent defects exposed by compiler warnings, and clear the rest (#406)

* Fix variable-length-array and uninitialized-union compiler warnings

Clang warns about every variable-length array in C++ (-Wvla-cxx-extension,
on by default), since VLAs are a compiler extension rather than standard
C++. Replace all 57 of them with std::vector, or with std::string for the
mkstemp() template buffers built from tmpdir. Add -Wvla to WARNING_FLAGS so
new ones don't creep back in.

Separately, mvt_value's numeric_value union is 16 bytes wide (the size of
string_value), but both constructors only wrote the 8 bytes of the member
they were setting, leaving the rest indeterminate. The implicit copy
constructor copies the union as a whole, so copying any non-string value
read uninitialized bytes, which GCC reports as

  mvt.hpp:83:8: warning: 'v.mvt_value::numeric_value. ... .len' may be
  used uninitialized [-Wmaybe-uninitialized]

Give string_value, the widest member, a default member initializer so the
union's full width is initialized however it is later used.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01D8gsGMjK78TQiCGKTZ2PyR

* Fix remaining float-conversion and format-truncation warnings

Clang's -Wimplicit-const-int-float-conversion flagged two comparisons
against LLONG_MAX, which is not representable as a double and rounds up
to 2^63.

In serial.cpp this was a real latent overflow, not just noise: the guard
`extent <= LLONG_MAX` was really `extent <= 2^63`, so an extent of exactly
2^63 passed it and then hit `(long long) extent`, which is undefined for
that value and yields LLONG_MIN in practice -- the opposite of the clamp
the else branch intends. Make the bound exclusive so the conversion is
always in range. Requires a polygon area at the very top of the double
range to reach, but the clamp now behaves as written.

In mbtiles.cpp the value is only a stand-in for infinity on its way into
JSON, so cast explicitly; the emitted number is unchanged.

Separately, g++ at -O0 warned that `char abbrev[20]` can be truncated by
"%lld", which is correct: the most negative long long needs 21 bytes with
the NUL. That branch is only reached when point_count < 1000, so it cannot
happen today, but size the buffer to fit rather than rely on that, and
replace the garbled comment about how the size was derived.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01D8gsGMjK78TQiCGKTZ2PyR

* Clamp the low end of extent before converting to long long too

The upper bound was fixed in the previous commit; the same overflow exists
on the negative side. get_area() returns a signed shoelace area, so inner
rings contribute negatively, and a polygon whose holes outweigh its rings
drives extent below zero. Far enough below and `(long long) extent` is
undefined again.

The bounds are asymmetric, so this is not simply the mirror of the upper
one: LLONG_MIN is exactly -2^63 and converts exactly, so unlike LLONG_MAX
it can be an inclusive bound.

Verified with -fsanitize=float-cast-overflow that the previous form traps
on 2^63 and on doubles just below -2^63, and that this one is clean across
both boundaries, the infinities, and NaN (which falls to LLONG_MAX, as it
did before).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01D8gsGMjK78TQiCGKTZ2PyR

* Add CHANGELOG entries for 2.81.0 and bump the version

CHANGELOG.md was last updated for 2.80.0 (#361), and version.hpp has not
moved since. Twelve PRs have landed in the meantime with no entry: #365,
#368, #375, #382, #384, #385, #391, #395, #397, #399, #400, and #401.

Document all of them, plus this PR, under a single 2.81.0 heading. They are
not given separate version numbers because none of them was ever released
under one -- version.hpp read v2.80.0 throughout -- so assigning a version
per PR would invent release history. 2.81.0 is the version that will
actually carry them.

Where an unreleased PR was corrected by a later one (#384 by #385, #397 by
#399), the pair is described as the single behavior that ships, since the
intermediate behavior was never in a release.

Minor rather than patch bump: the batch adds command-line options.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01D8gsGMjK78TQiCGKTZ2PyR

* Review feedback: enforce the union-width assumption, describe both clamp ends

The comment on mvt_value's union claimed string_value is the widest member.
That is true on LP64 (16 bytes against 8) but not on ILP32, where size_t is
4 and it ties with double and long long. The default member initializer still
covers the full union either way, so the fix held, but the justification did
not travel. Replace the claim with a static_assert that checks it on whatever
target is being built, so a platform where it stops holding is a compile
error rather than silently indeterminate bytes. Verified the assert is not
vacuous by widening the union in a scratch copy and watching it fail.

The changelog described only the upper end of the extent clamp. Describe both:
the old guard admitted everything below LLONG_MIN too.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01D8gsGMjK78TQiCGKTZ2PyR

* Add 2.81.0 changelog entries for the four PRs merged from main

#404, #408, #409, and #410 landed while this branch was open. None of them
bumped version.hpp, so they belong under the same 2.81.0 heading as the rest
of the unreleased work rather than getting versions of their own.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01D8gsGMjK78TQiCGKTZ2PyR

---------

Co-authored-by: Claude <noreply@anthropic.com>
This commit is contained in:
Erica Fischer
2026-08-06 17:06:07 -07:00
committed by GitHub
co-authored by Claude Opus 5
parent 1820630392
commit 734bba7c78
9 changed files with 236 additions and 165 deletions
+68
View File
@@ -1,3 +1,71 @@
# 2.81.0
* Add `--drop-by-attribute-as-needed=`*attribute* to drop the features with
the lowest values of a numeric attribute from oversized tiles, and
`--drop-by-attribute-order=desc` to drop the highest values instead.
Features exactly at the threshold are kept rather than dropped. (#384, #385)
* Add `--exclude-all-tile-geometries` to tile-join, to produce tiles that
carry only attributes. (#382)
* Generate each tool's usage message from the same option table that
`getopt_long()` reads, so the hand-written lists in tile-join,
tippecanoe-overzoom, tippecanoe-json-tool, tippecanoe-decode, and
tippecanoe-enumerate can no longer fall behind the options actually
accepted. Options previously reachable only by their short names are now
listed. tippecanoe-overzoom reports a missing `-o` instead of passing a
null pointer to `fopen()`, and tippecanoe prints its usage when run with
no arguments. (#409)
* Fix the radix sort used by `--prefer-radix-sort`. A bucket written out
directly rather than through the merge was written one byte longer than
its length prefix claimed, desynchronizing everything read from the
geometry after it. Subdividing could also recurse forever once it ran out
of files to split with, shifting by the full width of the index and
writing past the end of the arrays of buckets. Radix-sorted output is now
checked against the in-memory sort rather than against a stored copy. (#404)
* Read FlatGeobuf integer and float properties as numbers. They were tagged
with types that the rest of tippecanoe does not treat as numeric, so they
were reported in tilestats as "mixed", with quoted values and no min or
max, and warned when used as a feature ID. ULong properties are now also
read as unsigned rather than signed. (#395)
* Respect the `-t` temporary directory option in sorting operations, which
previously always used the system temporary directory. (#368)
* Keep `--generate-variable-depth-tile-pyramid` from silently dropping
features whose explicit per-feature `minzoom` is deeper than the zoom at
which their region becomes a leaf. Such a feature was excluded from the
leaf tile while its children were never generated, so it appeared at no
zoom at all. (#397, #399)
* Drop a polygon hole that no remaining ring can parent, instead of failing
the whole run. Degenerate input could abort tiling over a single
unrepresentable sliver. (#401)
* Clamp the feature extent to the `long long` range before converting it,
at both ends. The previous `extent <= LLONG_MAX` guard was doubly wrong:
`LLONG_MAX` is not representable as a double and rounds up, so an extent
at the very top of the range overflowed the conversion and came out as the
most negative value rather than the largest, and the guard admitted
everything below `LLONG_MIN` as well, which overflowed the other way. Areas
are signed, so holes that outweigh their rings can reach the low end. (#406)
* Initialize the full width of the `mvt_value` numeric union, which left the
bytes of the wider unused member indeterminate even though the implicit
copy constructor copies the union as a whole. (#406)
* Replace all variable-length arrays with `std::vector` and `std::string`,
and build with `-Wvla`. VLAs are a compiler extension rather than standard
C++, and clang warns about every one of them by default. (#406)
* Remove the unused Dockerfiles, Travis configuration, and lambda
directory. (#365)
* Correct README statements that disagreed with the code. Among them, `-aD`
and `-aS` were documented the wrong way round,
`--limit-base-zoom-to-maximum-zoom` was given as `-Pb` rather than `-pb`,
and the dot-dropping description had both the fraction and the zoom
direction backwards: tippecanoe keeps 1/2.5 of the dots at zooms below the
base zoom, rather than dropping that share above it. (#410)
* Generate `man/tippecanoe.1` with go-md2man rather than md2man-roff, which
is packaged only as a Ruby gem and so had let the page drift out of date.
The page now has a proper header and a NAME section, so `man -k` and
`whatis` can find it, and no longer silently drops or mangles text the old
converter mishandled. CI checks it against README.md. (#408)
* Documentation fixes: correct three misspellings in the README and man
page, repair the dead All Streets link, and tag more README code blocks
with their language. (#375, #391, #400)
# 2.80.0
* Remove undocumented command-line options