Every `u64 as usize` cast in clawhdf5-format (115 on wasm32) now goes through addr::to_usize for values read from the file — addresses, lengths, counts, dimensions: FormatError::Overflow where the value does not fit instead of wrapping onto another part of the file on a 32-bit target — or addr::saturating_usize for counts bounded by something in memory (codec progress counters, writer sizes), which fail a bounds check or allocation rather than wrap. A chunk whose offset does not fit lies outside the dataset and is skipped; partial reads treat such an offset as out of the buffers. On 64-bit targets nothing changes. scripts/check-32bit-casts.sh (run by ci-test.sh) lints the wasm32 build with clippy's cast_possible_truncation and fails on any u64 -> usize finding; before this commit it listed 115. Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
36 lines
1.3 KiB
Bash
Executable File
36 lines
1.3 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# CI check: clawhdf5-format has no truncating `u64 as usize` cast on a 32-bit
|
|
# target. HDF5 addresses and lengths are 64-bit; on wasm32 (or any 32-bit
|
|
# target) such a cast silently wraps an address past 4 GiB onto another part
|
|
# of the file. File values go through `addr::to_usize` (a clean error) and
|
|
# in-memory counts through `addr::saturating_usize`.
|
|
#
|
|
# Lints wasm32-unknown-unknown with clippy's cast_possible_truncation and
|
|
# fails on any u64 -> usize finding (other truncations are not checked here).
|
|
#
|
|
# Usage:
|
|
# ./scripts/check-32bit-casts.sh
|
|
#
|
|
# Prerequisites:
|
|
# rustup target add wasm32-unknown-unknown
|
|
|
|
set -euo pipefail
|
|
|
|
TARGET="wasm32-unknown-unknown"
|
|
echo "==> Checking for truncating u64 -> usize casts in clawhdf5-format ($TARGET)"
|
|
|
|
out=$(cargo clippy -p clawhdf5-format --target "$TARGET" \
|
|
--features plugin-filters --message-format short \
|
|
-- -A clippy::all -W clippy::cast_possible_truncation 2>&1) || {
|
|
echo "$out"
|
|
echo "==> clippy failed" >&2
|
|
exit 1
|
|
}
|
|
found=$(grep -F 'casting `u64` to `usize`' <<<"$out" || true)
|
|
if [ -n "$found" ]; then
|
|
echo "$found"
|
|
echo "==> use addr::to_usize (file values) or addr::saturating_usize (in-memory counts)" >&2
|
|
exit 1
|
|
fi
|
|
echo "==> no truncating u64 -> usize casts"
|