gguf : reject tensor size that wraps after padding (#26979)
GGML_PAD(nbytes, alignment) wraps to 0 when nbytes is within (alignment - 1) of SIZE_MAX, which silently bypassed the size overflow guard in gguf_init_from_reader. Reject the tensor before padding when nbytes + (alignment - 1) would overflow. Adds a test-gguf handcrafted case (F32, ne = [4, 2^30-1, 2^30+1, 1]) whose ggml_nbytes = 2^64 - 16 lands in the wrap window. Fails on master, passes with the guard.
X
Xiang Chen committed
a6ea155d3d38b3f6f43d0c0dc29c2d592413ef44
Parent: d3954b9
Committed by GitHub <noreply@github.com>
on 9/29/2026, 8:46:20 PM