docs: h5rs check inherits the library's header-check gap
Measured on the CVE corpus: check --data passes 33 of 180 files, and h5dump 1.14.6 rejects 26 of those. Recorded under the open "Header checks" gap and in the crate README. Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
This commit is contained in:
+4
-2
@@ -142,8 +142,10 @@
|
|||||||
that raw data lies inside the file without overlaps. Every problem is
|
that raw data lies inside the file without overlaps. Every problem is
|
||||||
printed with its address; exit 1 when there are any. libhdf5's h5check
|
printed with its address; exit 1 when there are any. libhdf5's h5check
|
||||||
reads only the 1.8 format. On the conformance corpus it passes all 418
|
reads only the 1.8 format. On the conformance corpus it passes all 418
|
||||||
files that both clawhdf5 and h5py read in full, and flags 149 of the
|
files that both clawhdf5 and h5py read in full, and `check --data` flags
|
||||||
180 CVE reproducers.
|
147 of the 180 files of the CVE corpus (tank, 2026-09-26). It inherits
|
||||||
|
the library's tolerance, though: 26 of the 33 it passes are files
|
||||||
|
h5dump 1.14.6 rejects (see `docs/known-issues.md`, header checks).
|
||||||
- Values over `--max-bytes` (default 1 GiB) are reported instead of read;
|
- Values over `--max-bytes` (default 1 GiB) are reported instead of read;
|
||||||
a panic is caught and reported as an internal error (exit 3).
|
a panic is caught and reported as an internal error (exit 3).
|
||||||
`scripts/h5rs-fuzz.sh` runs every subcommand over a corpus (default the
|
`scripts/h5rs-fuzz.sh` runs every subcommand over a corpus (default the
|
||||||
|
|||||||
@@ -207,7 +207,11 @@ B-tree chunk indexes, and version 3 superblocks).
|
|||||||
|
|
||||||
What it does not check: free-space manager and shared-message (SOHM) table
|
What it does not check: free-space manager and shared-message (SOHM) table
|
||||||
checksums, global heap collections other than those a value read touches,
|
checksums, global heap collections other than those a value read touches,
|
||||||
and objects reachable only by external links.
|
and objects reachable only by external links. It validates with
|
||||||
|
clawhdf5's parsers, so it accepts what they accept: some header damage that
|
||||||
|
libhdf5 refuses goes unreported (of the 180 files of the HDF Group's CVE
|
||||||
|
corpus, `check --data` passes 33, and h5dump 1.14.6 rejects 26 of those;
|
||||||
|
tank, 2026-09-26).
|
||||||
|
|
||||||
## Robustness
|
## Robustness
|
||||||
|
|
||||||
|
|||||||
@@ -135,7 +135,11 @@ fill-value item that did is fixed).
|
|||||||
- **Filters:** blosc, blosc2, bitshuffle, bzip2, LZF and zfp are not
|
- **Filters:** blosc, blosc2, bitshuffle, bzip2, LZF and zfp are not
|
||||||
implemented.
|
implemented.
|
||||||
- **Header checks:** on 12 CVE datasets libhdf5 rejects a corrupt header and
|
- **Header checks:** on 12 CVE datasets libhdf5 rejects a corrupt header and
|
||||||
we read data anyway. We need stricter header checks.
|
we read data anyway. We need stricter header checks. The same gap shows in
|
||||||
|
`h5rs check`, which validates with the library's parsers: of the 180
|
||||||
|
files of the CVE corpus, `check --data` passes 33, and h5dump 1.14.6
|
||||||
|
rejects 26 of those (measured on tank, 2026-09-26, with
|
||||||
|
`h5rs check --data F` and `h5dump F` per file).
|
||||||
- **Writer:**
|
- **Writer:**
|
||||||
- Nested groups beyond one level: path-like names are now refused, not
|
- Nested groups beyond one level: path-like names are now refused, not
|
||||||
created.
|
created.
|
||||||
|
|||||||
Reference in New Issue
Block a user