mirror of
https://github.com/felt/tippecanoe.git
synced 2026-10-02 08:25:40 +02:00
Fix three latent defects exposed by compiler warnings, and clear the rest (#406)
* Fix variable-length-array and uninitialized-union compiler warnings Clang warns about every variable-length array in C++ (-Wvla-cxx-extension, on by default), since VLAs are a compiler extension rather than standard C++. Replace all 57 of them with std::vector, or with std::string for the mkstemp() template buffers built from tmpdir. Add -Wvla to WARNING_FLAGS so new ones don't creep back in. Separately, mvt_value's numeric_value union is 16 bytes wide (the size of string_value), but both constructors only wrote the 8 bytes of the member they were setting, leaving the rest indeterminate. The implicit copy constructor copies the union as a whole, so copying any non-string value read uninitialized bytes, which GCC reports as mvt.hpp:83:8: warning: 'v.mvt_value::numeric_value. ... .len' may be used uninitialized [-Wmaybe-uninitialized] Give string_value, the widest member, a default member initializer so the union's full width is initialized however it is later used. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01D8gsGMjK78TQiCGKTZ2PyR * Fix remaining float-conversion and format-truncation warnings Clang's -Wimplicit-const-int-float-conversion flagged two comparisons against LLONG_MAX, which is not representable as a double and rounds up to 2^63. In serial.cpp this was a real latent overflow, not just noise: the guard `extent <= LLONG_MAX` was really `extent <= 2^63`, so an extent of exactly 2^63 passed it and then hit `(long long) extent`, which is undefined for that value and yields LLONG_MIN in practice -- the opposite of the clamp the else branch intends. Make the bound exclusive so the conversion is always in range. Requires a polygon area at the very top of the double range to reach, but the clamp now behaves as written. In mbtiles.cpp the value is only a stand-in for infinity on its way into JSON, so cast explicitly; the emitted number is unchanged. Separately, g++ at -O0 warned that `char abbrev[20]` can be truncated by "%lld", which is correct: the most negative long long needs 21 bytes with the NUL. That branch is only reached when point_count < 1000, so it cannot happen today, but size the buffer to fit rather than rely on that, and replace the garbled comment about how the size was derived. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01D8gsGMjK78TQiCGKTZ2PyR * Clamp the low end of extent before converting to long long too The upper bound was fixed in the previous commit; the same overflow exists on the negative side. get_area() returns a signed shoelace area, so inner rings contribute negatively, and a polygon whose holes outweigh its rings drives extent below zero. Far enough below and `(long long) extent` is undefined again. The bounds are asymmetric, so this is not simply the mirror of the upper one: LLONG_MIN is exactly -2^63 and converts exactly, so unlike LLONG_MAX it can be an inclusive bound. Verified with -fsanitize=float-cast-overflow that the previous form traps on 2^63 and on doubles just below -2^63, and that this one is clean across both boundaries, the infinities, and NaN (which falls to LLONG_MAX, as it did before). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01D8gsGMjK78TQiCGKTZ2PyR * Add CHANGELOG entries for 2.81.0 and bump the version CHANGELOG.md was last updated for 2.80.0 (#361), and version.hpp has not moved since. Twelve PRs have landed in the meantime with no entry: #365, #368, #375, #382, #384, #385, #391, #395, #397, #399, #400, and #401. Document all of them, plus this PR, under a single 2.81.0 heading. They are not given separate version numbers because none of them was ever released under one -- version.hpp read v2.80.0 throughout -- so assigning a version per PR would invent release history. 2.81.0 is the version that will actually carry them. Where an unreleased PR was corrected by a later one (#384 by #385, #397 by #399), the pair is described as the single behavior that ships, since the intermediate behavior was never in a release. Minor rather than patch bump: the batch adds command-line options. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01D8gsGMjK78TQiCGKTZ2PyR * Review feedback: enforce the union-width assumption, describe both clamp ends The comment on mvt_value's union claimed string_value is the widest member. That is true on LP64 (16 bytes against 8) but not on ILP32, where size_t is 4 and it ties with double and long long. The default member initializer still covers the full union either way, so the fix held, but the justification did not travel. Replace the claim with a static_assert that checks it on whatever target is being built, so a platform where it stops holding is a compile error rather than silently indeterminate bytes. Verified the assert is not vacuous by widening the union in a scratch copy and watching it fail. The changelog described only the upper end of the extent clamp. Describe both: the old guard admitted everything below LLONG_MIN too. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01D8gsGMjK78TQiCGKTZ2PyR * Add 2.81.0 changelog entries for the four PRs merged from main #404, #408, #409, and #410 landed while this branch was open. None of them bumped version.hpp, so they belong under the same 2.81.0 heading as the rest of the unreleased work rather than getting versions of their own. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01D8gsGMjK78TQiCGKTZ2PyR --------- Co-authored-by: Claude <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
1820630392
commit
734bba7c78
@@ -1,3 +1,71 @@
|
||||
# 2.81.0
|
||||
|
||||
* Add `--drop-by-attribute-as-needed=`*attribute* to drop the features with
|
||||
the lowest values of a numeric attribute from oversized tiles, and
|
||||
`--drop-by-attribute-order=desc` to drop the highest values instead.
|
||||
Features exactly at the threshold are kept rather than dropped. (#384, #385)
|
||||
* Add `--exclude-all-tile-geometries` to tile-join, to produce tiles that
|
||||
carry only attributes. (#382)
|
||||
* Generate each tool's usage message from the same option table that
|
||||
`getopt_long()` reads, so the hand-written lists in tile-join,
|
||||
tippecanoe-overzoom, tippecanoe-json-tool, tippecanoe-decode, and
|
||||
tippecanoe-enumerate can no longer fall behind the options actually
|
||||
accepted. Options previously reachable only by their short names are now
|
||||
listed. tippecanoe-overzoom reports a missing `-o` instead of passing a
|
||||
null pointer to `fopen()`, and tippecanoe prints its usage when run with
|
||||
no arguments. (#409)
|
||||
* Fix the radix sort used by `--prefer-radix-sort`. A bucket written out
|
||||
directly rather than through the merge was written one byte longer than
|
||||
its length prefix claimed, desynchronizing everything read from the
|
||||
geometry after it. Subdividing could also recurse forever once it ran out
|
||||
of files to split with, shifting by the full width of the index and
|
||||
writing past the end of the arrays of buckets. Radix-sorted output is now
|
||||
checked against the in-memory sort rather than against a stored copy. (#404)
|
||||
* Read FlatGeobuf integer and float properties as numbers. They were tagged
|
||||
with types that the rest of tippecanoe does not treat as numeric, so they
|
||||
were reported in tilestats as "mixed", with quoted values and no min or
|
||||
max, and warned when used as a feature ID. ULong properties are now also
|
||||
read as unsigned rather than signed. (#395)
|
||||
* Respect the `-t` temporary directory option in sorting operations, which
|
||||
previously always used the system temporary directory. (#368)
|
||||
* Keep `--generate-variable-depth-tile-pyramid` from silently dropping
|
||||
features whose explicit per-feature `minzoom` is deeper than the zoom at
|
||||
which their region becomes a leaf. Such a feature was excluded from the
|
||||
leaf tile while its children were never generated, so it appeared at no
|
||||
zoom at all. (#397, #399)
|
||||
* Drop a polygon hole that no remaining ring can parent, instead of failing
|
||||
the whole run. Degenerate input could abort tiling over a single
|
||||
unrepresentable sliver. (#401)
|
||||
* Clamp the feature extent to the `long long` range before converting it,
|
||||
at both ends. The previous `extent <= LLONG_MAX` guard was doubly wrong:
|
||||
`LLONG_MAX` is not representable as a double and rounds up, so an extent
|
||||
at the very top of the range overflowed the conversion and came out as the
|
||||
most negative value rather than the largest, and the guard admitted
|
||||
everything below `LLONG_MIN` as well, which overflowed the other way. Areas
|
||||
are signed, so holes that outweigh their rings can reach the low end. (#406)
|
||||
* Initialize the full width of the `mvt_value` numeric union, which left the
|
||||
bytes of the wider unused member indeterminate even though the implicit
|
||||
copy constructor copies the union as a whole. (#406)
|
||||
* Replace all variable-length arrays with `std::vector` and `std::string`,
|
||||
and build with `-Wvla`. VLAs are a compiler extension rather than standard
|
||||
C++, and clang warns about every one of them by default. (#406)
|
||||
* Remove the unused Dockerfiles, Travis configuration, and lambda
|
||||
directory. (#365)
|
||||
* Correct README statements that disagreed with the code. Among them, `-aD`
|
||||
and `-aS` were documented the wrong way round,
|
||||
`--limit-base-zoom-to-maximum-zoom` was given as `-Pb` rather than `-pb`,
|
||||
and the dot-dropping description had both the fraction and the zoom
|
||||
direction backwards: tippecanoe keeps 1/2.5 of the dots at zooms below the
|
||||
base zoom, rather than dropping that share above it. (#410)
|
||||
* Generate `man/tippecanoe.1` with go-md2man rather than md2man-roff, which
|
||||
is packaged only as a Ruby gem and so had let the page drift out of date.
|
||||
The page now has a proper header and a NAME section, so `man -k` and
|
||||
`whatis` can find it, and no longer silently drops or mangles text the old
|
||||
converter mishandled. CI checks it against README.md. (#408)
|
||||
* Documentation fixes: correct three misspellings in the README and man
|
||||
page, repair the dead All Streets link, and tag more README code blocks
|
||||
with their language. (#375, #391, #400)
|
||||
|
||||
# 2.80.0
|
||||
|
||||
* Remove undocumented command-line options
|
||||
|
||||
Reference in New Issue
Block a user