chore: Tier 2 quick wins — version skew, docs, cleanup, overflow-safe bounds
CI / test (push) Failing after 14s
CI / test (push) Failing after 14s
- Fix version skew: clawhdf5-py (pyproject.toml 1.93.0 -> 2.1.0) and packages/clawhdf5-node (package.json 2.0.0 -> 2.1.0) were both behind the actual crate version. - Correct stale ROADMAP.md claims: the TypeScript bridge already has a complete napi-rs package (not "no package.json"); CI/CD is now wired up via .gitea/workflows/ci.yml. - Fix CLAUDE.md: clawhdf5-gpu uses wgpu with hand-written WGSL compute shaders, not CubeCL. - chunked_read.rs: drop 12 unnecessary chunk_dimensions[..rank].to_vec() allocations — all three callees already accept &[u32]. - btree_v1.rs: add an overflow-safe ensure_len(data, offset, needed) helper (checked_add) and use it at the two plain-arithmetic bounds guards, closing a usize-overflow edge case reachable from a crafted near-usize::MAX B-tree offset. Add a regression test. - Clarify that the integrity hashes in clawhdf5-agent/provenance.rs (FNV-1a) and clawhdf5-format/provenance.rs (SHA-256) are unkeyed and only detect accidental corruption, not tampering — doc-only change. - README.md: document that the mpi-io feature's read/write paths are root-read+broadcast / gather-to-rank-0, not true collective I/O.
This commit is contained in:
@@ -2,6 +2,9 @@
|
||||
//! data-integrity verification.
|
||||
//!
|
||||
//! Enable with the `provenance` Cargo feature (on by default).
|
||||
//!
|
||||
//! The hash is unkeyed, so this detects accidental corruption only — it is
|
||||
//! not a tamper-evidence or authenticity guarantee. See [`verify_dataset`].
|
||||
|
||||
#[cfg(not(feature = "std"))]
|
||||
use alloc::{format, string::String, vec::Vec};
|
||||
@@ -115,6 +118,11 @@ pub enum VerifyResult {
|
||||
///
|
||||
/// `file_data` is the entire HDF5 file bytes; `header` is the parsed object
|
||||
/// header for the dataset of interest.
|
||||
///
|
||||
/// This only detects *accidental* corruption. The hash is unkeyed and stored
|
||||
/// alongside the data it protects, so anyone able to modify the dataset can
|
||||
/// also recompute and overwrite `_provenance_sha256` — a `VerifyResult::Ok`
|
||||
/// is not a tamper-evidence or authenticity guarantee.
|
||||
pub fn verify_dataset(
|
||||
file_data: &[u8],
|
||||
header: &ObjectHeader,
|
||||
|
||||
Reference in New Issue
Block a user