Problem
nsparse deserializes binary index files that may be corrupt or truncated. The readers validate defensively, and ~120 negative-path assertions cover that. But those tests only assert an exception is thrown — not that no out-of-bounds read, overflow, or misaligned access happened first. For an in-process native library, a memory error is much worse than an exception. CI builds Release only and runs no sanitizers.
Proposal
- Add an ASan+UBSan job over the existing
ctest suite (-fsanitize=address,undefined, RelWithDebInfo). UBSan matters as much as ASan here: overflow and misalignment are what binary parsing produces. Open questions: add an NSPARSE_ENABLE_SANITIZERS option? generic-only, or one SIMD build too, for tail-element OOB in vectorized kernels? per-PR or nightly?
- Later: a libFuzzer harness over the CSR/mmap readers;
tests/csr_interchange_test_util.h already builds such files.
Happy to implement (1).
Problem
nsparsedeserializes binary index files that may be corrupt or truncated. The readers validate defensively, and ~120 negative-path assertions cover that. But those tests only assert an exception is thrown — not that no out-of-bounds read, overflow, or misaligned access happened first. For an in-process native library, a memory error is much worse than an exception. CI buildsReleaseonly and runs no sanitizers.Proposal
ctestsuite (-fsanitize=address,undefined,RelWithDebInfo). UBSan matters as much as ASan here: overflow and misalignment are what binary parsing produces. Open questions: add anNSPARSE_ENABLE_SANITIZERSoption? generic-only, or one SIMD build too, for tail-element OOB in vectorized kernels? per-PR or nightly?tests/csr_interchange_test_util.halready builds such files.Happy to implement (1).