Enforce glTF index contract on decoded indices - #1447
Open
bjornblissing wants to merge 2 commits into
Open
bjornblissing wants to merge 2 commits into
bjornblissing wants to merge 2 commits into
Conversation
`copyDecodedIndices` used `pIndicesAccessor->componentType` to size the index buffer and select the copy branch without validating it. An unrecognized componentType made `computeByteSizeOfComponent()` return 0, so the buffer was sized to zero and the copy switch matched no case, leaving an inconsistent zero-length accessor still advertising a nonzero count. mesh.primitive.indices requires SCALAR type and an unsigned integer componentType, and getIndexAccessorView also rejects normalized accessors. Accept only UNSIGNED_BYTE, UNSIGNED_SHORT, and UNSIGNED_INT. Replace an illegal componentType with one derived from the decoded point count, widen a legal one that is too narrow, and force SCALAR and normalized = false. The copy switch shrinks to the same three types, so the validated and copied sets cannot drift apart.
Cover the glTF index contract enforced when decoding Draco indices: unknown, FLOAT, signed, and normalized componentTypes must be corrected or rejected, and a too-narrow but legal componentType must still be accepted. Each case asserts the resulting accessor satisfies getIndexAccessorView, guarding against regressions in how decoded indices are validated and sized. Reuses the existing CesiumMilkTruck Draco bitstream, so no new binary test data is required.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
copyDecodedIndices(CesiumGltfReader/src/decodeDraco.cpp) usedpIndicesAccessor->componentTypeto size the decoded index buffer and to pick the copy branch, without validating it first. If the accessor declared a componentType that isn't a legal glTF index type (e.g.BYTE,SHORT,FLOAT, or some other unrecognized value),computeByteSizeOfComponent()returned 0, so the index buffer was sized to zero bytes while the accessor still advertised a nonzerocount, and the copyswitchmatched no case, silently copying nothing into that zero-length buffer — leaving behind an inconsistent, corrupted accessor.Per the glTF spec,
mesh.primitive.indicesrequires the accessor to haveSCALARtype and an unsigned integer componentType, andgetIndexAccessorViewadditionally rejects normalized accessors. This PR narrows the accepted componentTypes to exactlyUNSIGNED_BYTE,UNSIGNED_SHORT, andUNSIGNED_INT:typeis forced toSCALARandnormalizedtofalse, matching the spec requirements.switchnow only handles the same three validated types, with thedefaultcase asserting unreachability, so the validated set and the copied set can no longer drift apart.Issue number or link
N/A
Author checklist
CHANGES.mdwith a short summary of my change (for user-facing changes).Testing plan
Steps to reproduce the original issue:
KHR_draco_mesh_compressionextension where the primitive's indices accessor declares a componentType that is not a legal glTF index type (e.g.FLOATor a signed integer type).computeByteSizeOfComponent()returns 0 for that componentType, so the decoded index buffer is allocated with zero bytes while the accessor'scountremains nonzero, and no data is copied into it — producing a corrupted, inconsistent accessor.