From 55e0e7e9cf2ede678122fb5a08a783c66ba5ae9b Mon Sep 17 00:00:00 2001 From: osobh Date: Sat, 26 Sep 2026 11:53:46 -0500 Subject: [PATCH] docs: conformance numbers after the review fixes (598 of 697 ok) cve-2025-44905 now reads as h5py reads it (the v1 chunk B-tree lookup), leaving 5 our-errors: cve-2025-2308, cve-2025-44904 and bad_nbit_parms_walk (corrupt data HDF5 2.0 reads through a bug), and the Blosc2 and ZFP filters. The five unloadable-cache-image files stay ok, now with the library behaving as the probe reports. Co-Authored-By: Claude Opus 5.5 (1M context) --- CHANGELOG.md | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 253e9a0..da05b6a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -3,10 +3,13 @@ ## Unreleased ### Remaining conformance errors (2026-09-26) -Conformance on tank, `conformance/run.sh --no-fetch`: 597 of 697 files -ok (575 before). Of the 6 our-errors left, 4 are corrupt data HDF5 2.0 +Conformance on tank, `conformance/run.sh --no-fetch`: 598 of 697 files +ok (575 before). Of the 5 our-errors left, 3 are corrupt data HDF5 2.0 reads only through a bug (listed in `CONFORMANCE.md`), 2 are the Blosc2 and -ZFP filters; the 2 mismatches are the known h5py big-endian VL bug. +ZFP filters; the 2 mismatches are the known h5py big-endian VL bug. The +five files whose cache image libhdf5 cannot load (`cve-2025-6269-*`, +`cve-2025-6516`) count as ok because the library, like libhdf5, opens them +and fails their objects (see below). - **Metadata cache images are read.** A file written with a metadata cache image keeps its metadata cache entries in an image block the superblock extension points at, and libhdf5 reads them in place of the file's own