Conversation
h5bench_overwrite.c and h5bench_append.c allocate the 2D and 3D fill buffers as jagged arrays (data_2D_FLOAT as float**, each row a separate malloc; data_3D_FLOAT as float***, each plane a separate row-pointer array, each row a separate malloc) and then pass the outer pointer directly to H5Dwrite. H5Dwrite expects a single contiguous buffer of element-size * total-element-count bytes. With a jagged array it dereferences the first row correctly, then walks straight past the end of that row's allocation into adjacent memory and treats whatever it finds as the next dim_2 (or dim_3) elements. The sanitizers workflow I am about to land flagged this as a heap-buffer-overflow on the very first 2D run. Fix: keep the [i][j] / [i][j][k] indexing for the fill loops (the surrounding code stays unchanged) but back the row and plane pointers with one contiguous allocation per type and pass that contiguous block to H5Dwrite. The free path simplifies to three or four frees per branch instead of the nested per-row loop. No behavior change for the 1D path. No behavior change for the contents of the data written; only the storage layout in memory changes so the write reads from valid memory throughout.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
`h5bench_overwrite.c` and `h5bench_append.c` allocate the 2D and 3D fill buffers as jagged arrays (`float **` and `float ***`, with each row a separate malloc) and then pass the outer pointer directly to `H5Dwrite`. HDF5 expects one contiguous buffer of `element_size * total_elements` bytes; it reads the first row correctly, then walks straight past the end of that row's allocation into adjacent memory.
The sanitizers workflow (next PR up) caught this as a heap-buffer-overflow on the very first 2D run.
Fix
Keep the `[i][j]` / `[i][j][k]` indexing in the fill loops, but back the row and plane pointers with one contiguous allocation per type and pass that contiguous block to `H5Dwrite`. The free path collapses from a nested per-row loop to a few frees per branch.
Test plan