format: no truncating u64 -> usize casts
Every `u64 as usize` cast in clawhdf5-format (115 on wasm32) now goes through addr::to_usize for values read from the file — addresses, lengths, counts, dimensions: FormatError::Overflow where the value does not fit instead of wrapping onto another part of the file on a 32-bit target — or addr::saturating_usize for counts bounded by something in memory (codec progress counters, writer sizes), which fail a bounds check or allocation rather than wrap. A chunk whose offset does not fit lies outside the dataset and is skipped; partial reads treat such an offset as out of the buffers. On 64-bit targets nothing changes. scripts/check-32bit-casts.sh (run by ci-test.sh) lints the wasm32 build with clippy's cast_possible_truncation and fails on any u64 -> usize finding; before this commit it listed 115. Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
This commit is contained in:
@@ -18,6 +18,7 @@ use alloc::collections::BTreeMap;
|
||||
#[cfg(feature = "std")]
|
||||
use std::collections::HashMap;
|
||||
|
||||
use crate::addr::to_usize;
|
||||
use crate::chunk_cache::ChunkCoord;
|
||||
use crate::chunked_read::ChunkInfo;
|
||||
|
||||
@@ -167,7 +168,15 @@ impl ChunkLayout {
|
||||
|
||||
for (_coord, ci) in index.iter() {
|
||||
let coord: ChunkCoord = ci.offsets.iter().take(rank).copied().collect();
|
||||
let chunk_offsets: Vec<usize> = coord.iter().map(|&o| o as usize).collect();
|
||||
// `ds_dims` are `usize`: a chunk at an offset past `usize::MAX`
|
||||
// (only on a 32-bit target) lies outside the dataset.
|
||||
let Ok(chunk_offsets) = coord
|
||||
.iter()
|
||||
.map(|&o| to_usize(o))
|
||||
.collect::<Result<Vec<usize>, _>>()
|
||||
else {
|
||||
continue;
|
||||
};
|
||||
|
||||
let copies = if rank == 0 {
|
||||
// Scalar dataset — single copy
|
||||
|
||||
Reference in New Issue
Block a user