Skip to content

Harden h5repack - #6670

Merged
bmribler merged 3 commits into
HDFGroup:developfrom
bmribler:fix_GHSA-gxw2-rpgf-4vp8
Oct 5, 2026
Merged

bmribler merged 3 commits into
HDFGroup:developfrom
bmribler:fix_GHSA-gxw2-rpgf-4vp8

Conversation

@bmribler

@bmribler bmribler commented Sep 13, 2026 •

Copy link
Copy Markdown
Collaborator
  • Tidies some free statements and initializes pointers properly to avoid double free during cleanup
  • Adds missing cleanup to address memory leaks
  • Adds casts to API calls to remove warnings
    • subscript of a pointer to void is a GNU extension [-Wpointer-arith]
    • ISO C forbids taking the address of an expression of type 'void' [-Wpedantic]

@github-actions

github-actions Bot commented Sep 13, 2026 •

Copy link
Copy Markdown
Contributor

Review Checklist

This PR touches the following areas. Each needs a sign-off
from its listed owners before merging.

✅ All areas have been signed off.

@bmribler
bmribler force-pushed the fix_GHSA-gxw2-rpgf-4vp8 branch from 8b30ba4 to 9f58991 Compare September 13, 2026 18:08
Comment thread tools/src/h5repack/h5repack_refs.c Outdated
Fix double free (GHSA-gxw2-rpgf-4vp8) and memory leaks
Remove warnings
    - subscript of a pointer to void is a GNU extension [-Wpointer-arith]
    - ISO C forbids taking the address of an expression of type 'void' [-Wpedantic]
@bmribler
bmribler force-pushed the fix_GHSA-gxw2-rpgf-4vp8 branch from 9f58991 to 4c8f64a Compare September 13, 2026 18:40
@mattjala mattjala moved this from To be triaged to Planning in HDF5 - TRIAGE & TRACK Sep 24, 2026
int k;
named_dt_t *named_dt_head = NULL; /* Pointer to the stack of named datatypes copied */
void *buf = NULL;
void *refbuf = NULL;

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Using void * here is a bit unnecessary and both introduces the potential for type safety problems and then requires some (ugly, IMO) casts later on. This could probably use a little refactoring either to separate the reference types or just use separate sets of variables.

@github-actions

Copy link
Copy Markdown
Contributor

🎉 All checklist items are signed off — @bmribler, this PR is ready to merge.

@github-actions github-actions Bot added the checklist-complete All review checklist areas are signed off label Sep 28, 2026
@bmribler
bmribler marked this pull request as draft October 1, 2026 06:51
@bmribler
bmribler marked this pull request as ready for review October 2, 2026 20:25
@github-actions
github-actions Bot requested a review from mattjala October 2, 2026 20:25
@bmribler
bmribler merged commit 17a229f into HDFGroup:develop Oct 5, 2026
132 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

checklist-complete All review checklist areas are signed off

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants