docs: h5rs check inherits the library's header-check gap
Measured on the CVE corpus: check --data passes 33 of 180 files, and h5dump 1.14.6 rejects 26 of those. Recorded under the open "Header checks" gap and in the crate README. Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
This commit is contained in:
+4
-2
@@ -142,8 +142,10 @@
|
||||
that raw data lies inside the file without overlaps. Every problem is
|
||||
printed with its address; exit 1 when there are any. libhdf5's h5check
|
||||
reads only the 1.8 format. On the conformance corpus it passes all 418
|
||||
files that both clawhdf5 and h5py read in full, and flags 149 of the
|
||||
180 CVE reproducers.
|
||||
files that both clawhdf5 and h5py read in full, and `check --data` flags
|
||||
147 of the 180 files of the CVE corpus (tank, 2026-09-26). It inherits
|
||||
the library's tolerance, though: 26 of the 33 it passes are files
|
||||
h5dump 1.14.6 rejects (see `docs/known-issues.md`, header checks).
|
||||
- Values over `--max-bytes` (default 1 GiB) are reported instead of read;
|
||||
a panic is caught and reported as an internal error (exit 3).
|
||||
`scripts/h5rs-fuzz.sh` runs every subcommand over a corpus (default the
|
||||
|
||||
Reference in New Issue
Block a user