format: no truncating u64 -> usize casts
Every `u64 as usize` cast in clawhdf5-format (115 on wasm32) now goes through addr::to_usize for values read from the file — addresses, lengths, counts, dimensions: FormatError::Overflow where the value does not fit instead of wrapping onto another part of the file on a 32-bit target — or addr::saturating_usize for counts bounded by something in memory (codec progress counters, writer sizes), which fail a bounds check or allocation rather than wrap. A chunk whose offset does not fit lies outside the dataset and is skipped; partial reads treat such an offset as out of the buffers. On 64-bit targets nothing changes. scripts/check-32bit-casts.sh (run by ci-test.sh) lints the wasm32 build with clippy's cast_possible_truncation and fails on any u64 -> usize finding; before this commit it listed 115. Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
This commit is contained in:
@@ -3,6 +3,7 @@
|
||||
#[cfg(not(feature = "std"))]
|
||||
use alloc::{string::String, vec::Vec};
|
||||
|
||||
use crate::addr::to_usize;
|
||||
use crate::datatype::CharacterSet;
|
||||
use crate::error::FormatError;
|
||||
|
||||
@@ -247,7 +248,7 @@ impl LinkMessage {
|
||||
};
|
||||
|
||||
// Link name length
|
||||
let name_len = read_offset(data, pos, name_size_field_width)? as usize;
|
||||
let name_len = to_usize(read_offset(data, pos, name_size_field_width)?)?;
|
||||
pos += name_size_field_width as usize;
|
||||
|
||||
// Link name
|
||||
|
||||
Reference in New Issue
Block a user