format: no truncating u64 -> usize casts

Every `u64 as usize` cast in clawhdf5-format (115 on wasm32) now goes
through addr::to_usize for values read from the file — addresses, lengths,
counts, dimensions: FormatError::Overflow where the value does not fit
instead of wrapping onto another part of the file on a 32-bit target — or
addr::saturating_usize for counts bounded by something in memory (codec
progress counters, writer sizes), which fail a bounds check or allocation
rather than wrap. A chunk whose offset does not fit lies outside the
dataset and is skipped; partial reads treat such an offset as out of the
buffers. On 64-bit targets nothing changes.

scripts/check-32bit-casts.sh (run by ci-test.sh) lints the wasm32 build
with clippy's cast_possible_truncation and fails on any u64 -> usize
finding; before this commit it listed 115.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
This commit is contained in:
osobh
2026-09-26 13:33:24 -05:00
co-authored by Claude Opus 5.5
parent 02e89c1d2d
commit b41583113a
27 changed files with 236 additions and 99 deletions
+4 -3
View File
@@ -3,6 +3,7 @@
#[cfg(not(feature = "std"))]
use alloc::string::String;
use crate::addr::to_usize;
use crate::error::FormatError;
/// Parsed HDF5 Local Heap header.
@@ -140,15 +141,15 @@ impl LocalHeap {
/// Read a null-terminated string from the heap's data segment at the given byte offset.
pub fn read_string(&self, file_data: &[u8], string_offset: u64) -> Result<String, FormatError> {
let seg_addr = self.data_segment_address as usize;
let seg_addr = to_usize(self.data_segment_address)?;
let str_start =
seg_addr
.checked_add(string_offset as usize)
.checked_add(to_usize(string_offset)?)
.ok_or(FormatError::Overflow(
"local heap seg_addr + string_offset overflow".into(),
))?;
let seg_end = seg_addr
.checked_add(self.data_segment_size as usize)
.checked_add(to_usize(self.data_segment_size)?)
.ok_or(FormatError::Overflow(
"local heap seg_addr + data_segment_size overflow".into(),
))?;