Skip to content

Read the count MEOS writes at the start of its int - #114

Merged
estebanzimanyi merged 1 commit into
MobilityDB:mainfrom
estebanzimanyi:fix/read-meos-count-at-offset-zero
Sep 30, 2026
Merged

estebanzimanyi merged 1 commit into
MobilityDB:mainfrom
estebanzimanyi:fix/read-meos-count-at-offset-zero

Conversation

@estebanzimanyi

Copy link
Copy Markdown
Member

Fifteen methods of the object layer read the count a MEOS function writes into an int
out-parameter, or the int it writes into a result buffer, at offset 0 of the four bytes
they allocate: Temporal.time_split and time_split_n, TNumber.value_split and
value_time_split, TPoint.values, stboxes and make_simple, STBox.quad_split_flat,
IntSet.element_n, and value_set of TBool, TInt, TFloat, TText, TGeomPoint and TGeogPoint.

Witness. Each read the int at offset 4 of a four-byte buffer. On the heap buffer
Memory.allocate returns, getInt(4) throws ArrayIndexOutOfBoundsException: Index 4 out of
bounds for length 4, so every one of these methods threw on any input; on the direct
buffer of intset_value_n, IntSet.element_n read the four bytes past it.

Measured. Against the catalog and libmeos of MobilityDB a362004728 with MEOS-API
20efba81be, nine of the fifteen answer, and the tests testValueSet, testValueSplit and
testTimeSplit of TIntTest, testValuesStboxesMakeSimple of TGeomPointTest,
testQuadSplitFlat of STBoxTest and testElementN of IntSetTest state their answers. The
build succeeds and the suites run 106 and 1,805 tests, all passing. The other six stop
further on: value_set of TBool, TFloat, TText, TGeomPoint and TGeogPoint appends to a null
StringBuilder, and value_time_split hands MEOS a null argument.

Why. MEOS writes an int out-parameter at its address, and the object layer reads it there.

Fifteen methods of the object layer read the count a MEOS function writes into an int
out-parameter, or the int it writes into a result buffer, at offset 0 of the four bytes
they allocate: Temporal.time_split and time_split_n, TNumber.value_split and
value_time_split, TPoint.values, stboxes and make_simple, STBox.quad_split_flat,
IntSet.element_n, and value_set of TBool, TInt, TFloat, TText, TGeomPoint and TGeogPoint.

Witness. Each read the int at offset 4 of a four-byte buffer. On the heap buffer
Memory.allocate returns, getInt(4) throws ArrayIndexOutOfBoundsException: Index 4 out of
bounds for length 4, so every one of these methods threw on any input; on the direct
buffer of intset_value_n, IntSet.element_n read the four bytes past it.

Measured. Against the catalog and libmeos of MobilityDB a362004728 with MEOS-API
20efba81be, nine of the fifteen answer, and the tests testValueSet, testValueSplit and
testTimeSplit of TIntTest, testValuesStboxesMakeSimple of TGeomPointTest,
testQuadSplitFlat of STBoxTest and testElementN of IntSetTest state their answers. The
build succeeds and the suites run 106 and 1,805 tests, all passing. The other six stop
further on: value_set of TBool, TFloat, TText, TGeomPoint and TGeogPoint appends to a null
StringBuilder, and value_time_split hands MEOS a null argument.

Why. MEOS writes an int out-parameter at its address, and the object layer reads it there.
@estebanzimanyi
estebanzimanyi merged commit 1619607 into MobilityDB:main Sep 30, 2026
2 checks passed
@estebanzimanyi
estebanzimanyi deleted the fix/read-meos-count-at-offset-zero branch September 30, 2026 13:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant