diff --git a/shader_params_reader.py b/shader_params_reader.py index 7128962..eba2ee4 100644 --- a/shader_params_reader.py +++ b/shader_params_reader.py @@ -99,7 +99,9 @@ class ShaderParamsReader: if "scale" in sanitized: try: val = float(sanitized["scale"]) - # Clamp to avoid Infinity/NaN propagation + if math.isnan(val) or math.isinf(val): + val = 1.0 + # Clamp to avoid extremely large values sanitized["scale"] = max(-1000000.0, min(val, 1000000.0)) except (ValueError, TypeError): sanitized["scale"] = 1.0 @@ -110,6 +112,8 @@ class ShaderParamsReader: if key in sanitized: try: val = float(sanitized[key]) + if math.isnan(val) or math.isinf(val): + val = 0.0 if "strength" in key or "shift" in key else 1.0 # Clamp strictly to reasonable limits (e.g. +/- 1M) to prevent numerical instability # This prevents DoS via numerical overflow or resource exhaustion sanitized[key] = max(-1000000.0, min(val, 1000000.0)) @@ -124,10 +128,16 @@ class ShaderParamsReader: for key in ["seed", "base_seed"]: if key in sanitized: try: + # Check for float inputs first to catch Infinity + if isinstance(sanitized[key], float): + if math.isinf(sanitized[key]) or math.isnan(sanitized[key]): + sanitized[key] = 0 + continue + val = int(sanitized[key]) # Clamp to safe range to prevent runtime crashes (DoS) sanitized[key] = max(MIN_SEED, min(val, MAX_SEED)) - except (ValueError, TypeError): + except (ValueError, TypeError, OverflowError): sanitized[key] = 0 # 5. Validate String Enums (Shader Type, Shape Type, Color Scheme) diff --git a/verify_comments.py b/verify_comments.py new file mode 100644 index 0000000..8af0144 --- /dev/null +++ b/verify_comments.py @@ -0,0 +1,25 @@ +import math +import sys + +def test_nan_clamp(): + val = float('nan') + clamped = max(-1000.0, min(val, 1000.0)) + print(f"NaN clamped: {clamped}") + if math.isnan(clamped): + print("NaN passed through clamping (FAIL)") + else: + print("NaN successfully clamped (PASS)") + +def test_inf_to_int(): + try: + val = float('inf') + int(val) + print("int(inf) succeeded (FAIL)") + except OverflowError: + print("Caught OverflowError for int(inf) (PASS)") + except Exception as e: + print(f"Caught unexpected exception for int(inf): {e}") + +if __name__ == "__main__": + test_nan_clamp() + test_inf_to_int()