Files
tippecanoe/mvt.hpp
T
Erica FischerandClaude Opus 5 734bba7c78 Fix three latent defects exposed by compiler warnings, and clear the rest (#406)
* Fix variable-length-array and uninitialized-union compiler warnings

Clang warns about every variable-length array in C++ (-Wvla-cxx-extension,
on by default), since VLAs are a compiler extension rather than standard
C++. Replace all 57 of them with std::vector, or with std::string for the
mkstemp() template buffers built from tmpdir. Add -Wvla to WARNING_FLAGS so
new ones don't creep back in.

Separately, mvt_value's numeric_value union is 16 bytes wide (the size of
string_value), but both constructors only wrote the 8 bytes of the member
they were setting, leaving the rest indeterminate. The implicit copy
constructor copies the union as a whole, so copying any non-string value
read uninitialized bytes, which GCC reports as

  mvt.hpp:83:8: warning: 'v.mvt_value::numeric_value. ... .len' may be
  used uninitialized [-Wmaybe-uninitialized]

Give string_value, the widest member, a default member initializer so the
union's full width is initialized however it is later used.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01D8gsGMjK78TQiCGKTZ2PyR

* Fix remaining float-conversion and format-truncation warnings

Clang's -Wimplicit-const-int-float-conversion flagged two comparisons
against LLONG_MAX, which is not representable as a double and rounds up
to 2^63.

In serial.cpp this was a real latent overflow, not just noise: the guard
`extent <= LLONG_MAX` was really `extent <= 2^63`, so an extent of exactly
2^63 passed it and then hit `(long long) extent`, which is undefined for
that value and yields LLONG_MIN in practice -- the opposite of the clamp
the else branch intends. Make the bound exclusive so the conversion is
always in range. Requires a polygon area at the very top of the double
range to reach, but the clamp now behaves as written.

In mbtiles.cpp the value is only a stand-in for infinity on its way into
JSON, so cast explicitly; the emitted number is unchanged.

Separately, g++ at -O0 warned that `char abbrev[20]` can be truncated by
"%lld", which is correct: the most negative long long needs 21 bytes with
the NUL. That branch is only reached when point_count < 1000, so it cannot
happen today, but size the buffer to fit rather than rely on that, and
replace the garbled comment about how the size was derived.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01D8gsGMjK78TQiCGKTZ2PyR

* Clamp the low end of extent before converting to long long too

The upper bound was fixed in the previous commit; the same overflow exists
on the negative side. get_area() returns a signed shoelace area, so inner
rings contribute negatively, and a polygon whose holes outweigh its rings
drives extent below zero. Far enough below and `(long long) extent` is
undefined again.

The bounds are asymmetric, so this is not simply the mirror of the upper
one: LLONG_MIN is exactly -2^63 and converts exactly, so unlike LLONG_MAX
it can be an inclusive bound.

Verified with -fsanitize=float-cast-overflow that the previous form traps
on 2^63 and on doubles just below -2^63, and that this one is clean across
both boundaries, the infinities, and NaN (which falls to LLONG_MAX, as it
did before).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01D8gsGMjK78TQiCGKTZ2PyR

* Add CHANGELOG entries for 2.81.0 and bump the version

CHANGELOG.md was last updated for 2.80.0 (#361), and version.hpp has not
moved since. Twelve PRs have landed in the meantime with no entry: #365,
#368, #375, #382, #384, #385, #391, #395, #397, #399, #400, and #401.

Document all of them, plus this PR, under a single 2.81.0 heading. They are
not given separate version numbers because none of them was ever released
under one -- version.hpp read v2.80.0 throughout -- so assigning a version
per PR would invent release history. 2.81.0 is the version that will
actually carry them.

Where an unreleased PR was corrected by a later one (#384 by #385, #397 by
#399), the pair is described as the single behavior that ships, since the
intermediate behavior was never in a release.

Minor rather than patch bump: the batch adds command-line options.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01D8gsGMjK78TQiCGKTZ2PyR

* Review feedback: enforce the union-width assumption, describe both clamp ends

The comment on mvt_value's union claimed string_value is the widest member.
That is true on LP64 (16 bytes against 8) but not on ILP32, where size_t is
4 and it ties with double and long long. The default member initializer still
covers the full union either way, so the fix held, but the justification did
not travel. Replace the claim with a static_assert that checks it on whatever
target is being built, so a platform where it stops holding is a compile
error rather than silently indeterminate bytes. Verified the assert is not
vacuous by widening the union in a scratch copy and watching it fail.

The changelog described only the upper end of the extent clamp. Describe both:
the old guard admitted everything below LLONG_MIN too.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01D8gsGMjK78TQiCGKTZ2PyR

* Add 2.81.0 changelog entries for the four PRs merged from main

#404, #408, #409, and #410 landed while this branch was open. None of them
bumped version.hpp, so they belong under the same 2.81.0 heading as the rest
of the unreleased work rather than getting versions of their own.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01D8gsGMjK78TQiCGKTZ2PyR

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-08-06 17:06:07 -07:00

258 lines
6.0 KiB
C++

#ifndef MVT_HPP
#define MVT_HPP
#include <sqlite3.h>
#include <string>
#include <string_view>
#include <unordered_map>
#include <set>
#include <vector>
#include <optional>
#include <memory>
#include <cmath>
#include "errors.hpp"
#include "text.hpp"
struct mvt_value;
struct mvt_layer;
enum mvt_operation {
mvt_moveto = 1,
mvt_lineto = 2,
mvt_closepath = 7
};
struct mvt_geometry {
long long x = 0;
long long y = 0;
int /* mvt_operation */ op = 0;
mvt_geometry(int op, long long x, long long y);
bool operator<(mvt_geometry const &s) const {
if (y < s.y || (y == s.y && x < s.x)) {
return true;
} else {
return false;
}
}
bool operator==(mvt_geometry const &s) const {
return y == s.y && x == s.x;
}
};
enum mvt_geometry_type {
mvt_point = 1,
mvt_linestring = 2,
mvt_polygon = 3
};
struct mvt_feature {
std::vector<unsigned> tags{};
std::vector<mvt_geometry> geometry{};
int /* mvt_geometry_type */ type = 0;
unsigned long long id = 0;
bool has_id = false;
int dropped = 0;
size_t seq = 0; // used for ordering in overzoom
mvt_feature() {
has_id = false;
id = 0;
}
};
enum mvt_value_type {
mvt_string,
mvt_float,
mvt_double,
mvt_int,
mvt_uint,
mvt_sint,
mvt_bool,
mvt_null,
mvt_no_such_key,
};
struct mvt_value;
double mvt_value_to_double(mvt_value const &v);
struct mvt_value {
long /* mvt_value_type */ type : 5;
long count : 64 - 5;
std::shared_ptr<std::string> s;
union {
float float_value;
double double_value;
long long int_value;
unsigned long long uint_value;
long long sint_value;
bool bool_value;
int null_value;
// Initializing string_value initializes the union's full width, which
// the static_assert below checks. Setting only a narrower member (a
// double, say) would leave the remaining bytes indeterminate, and the
// implicit copy constructor copies the union as a whole, so those
// bytes get read even when they aren't the member in use.
struct {
size_t off;
size_t len;
} string_value = {0, 0};
} numeric_value;
static_assert(sizeof(numeric_value) == sizeof(numeric_value.string_value),
"string_value must span the whole union, since its default member "
"initializer is what initializes the union");
std::string get_string_value() const {
if (type == mvt_string) {
return std::string(*s, numeric_value.string_value.off, numeric_value.string_value.len);
} else {
return toString();
}
}
std::string_view get_string_view() const {
return std::string_view(s->c_str() + numeric_value.string_value.off, numeric_value.string_value.len);
}
const char *c_str() const {
return s->c_str() + numeric_value.string_value.off;
}
void set_string_value(const std::string_view &val) {
if (s == nullptr) {
s = std::make_shared<std::string>();
}
type = mvt_string;
numeric_value.string_value.off = s->size();
numeric_value.string_value.len = val.size();
s->append(val);
s->push_back('\0');
}
bool is_numeric() const {
return type == mvt_float ||
type == mvt_double ||
type == mvt_int ||
type == mvt_uint ||
type == mvt_sint;
}
double to_double() const {
return mvt_value_to_double(*this);
}
size_t get_count() const {
return count;
}
bool operator<(const mvt_value &o) const;
bool operator==(const mvt_value &o) const;
std::string toString() const;
mvt_value() {
this->type = mvt_double;
this->numeric_value.double_value = 0;
this->count = 0;
}
mvt_value(double v) {
this->type = mvt_double;
this->numeric_value.double_value = v;
this->count = 0;
}
void set_double_count(double v, size_t c) {
this->type = mvt_double;
this->numeric_value.double_value = v;
this->count = c;
}
};
template <>
struct std::hash<mvt_value> {
std::size_t operator()(const mvt_value &k) const {
switch (k.type) {
case mvt_string:
return fnv1a(k.c_str(), 0);
case mvt_float:
return fnv1a(sizeof(float), (void *) &k.numeric_value.float_value);
case mvt_double:
return fnv1a(sizeof(double), (void *) &k.numeric_value.double_value);
case mvt_int:
return fnv1a(sizeof(long long), (void *) &k.numeric_value.int_value);
case mvt_uint:
return fnv1a(sizeof(unsigned long long), (void *) &k.numeric_value.uint_value);
case mvt_sint:
return fnv1a(sizeof(long long), (void *) &k.numeric_value.sint_value);
case mvt_bool:
return fnv1a(sizeof(bool), (void *) &k.numeric_value.bool_value);
case mvt_null:
return fnv1a(sizeof(int), (void *) &k.numeric_value.null_value);
default:
fprintf(stderr, "mvt_value hash can't happen\n");
exit(EXIT_IMPOSSIBLE);
}
}
};
struct mvt_layer {
int version = 0;
std::string name = "";
std::vector<mvt_feature> features{};
std::vector<std::string> keys{};
std::vector<mvt_value> values{};
long long extent = 0;
// Add a key-value pair to a feature, using this layer's constant pool
void tag(mvt_feature &feature, std::string const &key, mvt_value const &value);
// For tracking the key-value constants already used in this layer
std::vector<ssize_t> key_dedup = std::vector<ssize_t>(65536, -1);
std::vector<ssize_t> value_dedup = std::vector<ssize_t>(65536, -1);
int detail() const {
return std::round(std::log(extent) / std::log(2));
}
};
struct mvt_tile {
std::vector<mvt_layer> layers{};
std::string encode();
bool decode(const std::string &message, bool &was_compressed);
};
bool is_compressed(std::string const &data);
int decompress(std::string const &input, std::string &output);
int compress(std::string const &input, std::string &output, bool gz);
int dezig(unsigned n);
mvt_value stringified_to_mvt_value(int type, const char *s, std::shared_ptr<std::string> const &tile_stringpool);
long long mvt_value_to_long_long(mvt_value const &v);
bool is_integer(const char *s, long long *v);
bool is_unsigned_integer(const char *s, unsigned long long *v);
struct serial_val;
serial_val mvt_value_to_serial_val(mvt_value const &v);
void get_bbox(std::vector<mvt_geometry> const &geom,
long long *xmin, long long *ymin, long long *xmax, long long *ymax,
int z, int tx, int ty, int detail);
#endif