gpt2_model_load: using CPU backend ================================================================= ==325537==ERROR: AddressSanitizer: stack-buffer-overflow on address 0x74253f300258 at pc 0x742543cee303 bp 0x7ffda66c0170 sp 0x7ffda66bf918 WRITE of size 4 at 0x74253f300258 thread T0 #0 0x742543cee302 in memcpy ../../../../src/libsanitizer/sanitizer_common/sanitizer_common_interceptors_memintrinsics.inc:115 #1 0x7425418e90bf in std::basic_streambuf >::xsgetn(char*, long) (/lib/x86_64-linux-gnu/libstdc++.so.6+0x1670bf) (BuildId: ca77dae775ec87540acd7218fa990c40d1c94ab1) #2 0x7425418ac0e9 in std::basic_filebuf >::xsgetn(char*, long) (/lib/x86_64-linux-gnu/libstdc++.so.6+0x12a0e9) (BuildId: ca77dae775ec87540acd7218fa990c40d1c94ab1) #3 0x7425418ba140 in std::istream::read(char*, long) (/lib/x86_64-linux-gnu/libstdc++.so.6+0x138140) (BuildId: ca77dae775ec87540acd7218fa990c40d1c94ab1) #4 0x5ba4d4bd65ce in gpt2_model_load(std::__cxx11::basic_string, std::allocator > const&, gpt2_model&, gpt_vocab&, int, int) /workspace/GGML/repos/ggml/examples/gpt-2/main-backend.cpp:376 #5 0x5ba4d4bdc78b in main /workspace/GGML/repos/ggml/examples/gpt-2/main-backend.cpp:818 #6 0x742540f841c9 (/lib/x86_64-linux-gnu/libc.so.6+0x2a1c9) (BuildId: 274eec488d230825a136fa9c4d85370fed7a0a5e) #7 0x742540f8428a in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x2a28a) (BuildId: 274eec488d230825a136fa9c4d85370fed7a0a5e) #8 0x5ba4d4bcbda4 in _start (/workspace/GGML/repos/ggml/build-asan-explicit/bin/gpt-2-backend+0x21eda4) (BuildId: faf777c34f952bcf78181c4a19b97accd58a18cf) Address 0x74253f300258 is located in stack of thread T0 at offset 600 in frame #0 0x5ba4d4bcd3f1 in gpt2_model_load(std::__cxx11::basic_string, std::allocator > const&, gpt2_model&, gpt_vocab&, int, int) /workspace/GGML/repos/ggml/examples/gpt-2/main-backend.cpp:103 This frame has 65 object(s): [48, 49) '' [64, 65) '' [80, 81) '' [96, 97) '' [112, 113) '' [128, 129) '' [144, 145) '' [160, 164) 'magic' (line 114) [176, 180) 'n_vocab' (line 148) [192, 196) 'i' (line 160) [208, 212) 'len' (line 161) [224, 228) 'n_dims' (line 361) [240, 244) 'length' (line 362) [256, 260) 'ttype' (line 363) [272, 280) '' [304, 312) '' [336, 360) 'buf' (line 158) [400, 424) 'params' (line 189) [464, 488) 'params' (line 318) [528, 552) 'read_buf' (line 358) [592, 600) 'ne' (line 374) <== Memory access at offset 600 overflows this variable [624, 656) 'word' (line 157) [688, 720) '' [752, 784) '' [816, 848) '' [880, 912) '' [944, 976) '' [1008, 1040) '' [1072, 1104) '' [1136, 1168) '' [1200, 1232) '' [1264, 1296) '' [1328, 1360) '' [1392, 1424) '' [1456, 1488) '' [1520, 1552) '' [1584, 1616) '' [1648, 1680) '' [1712, 1744) '' [1776, 1808) '' [1840, 1872) '' [1904, 1936) '' [1968, 2000) '' [2032, 2064) '' [2096, 2128) '' [2160, 2192) '' [2224, 2256) '' [2288, 2320) '' [2352, 2384) '' [2416, 2448) '' [2480, 2512) '' [2544, 2576) '' [2608, 2640) '' [2672, 2704) '' [2736, 2768) '' [2800, 2832) '' [2864, 2896) '' [2928, 2960) '' [2992, 3024) '' [3056, 3088) '' [3120, 3152) '' [3184, 3216) '' [3248, 3280) '' [3312, 3344) 'name' (line 380) [3376, 3896) 'fin' (line 106) HINT: this may be a false positive if your program uses some custom stack unwind mechanism, swapcontext or vfork (longjmp and C++ exceptions *are* supported) SUMMARY: AddressSanitizer: stack-buffer-overflow ../../../../src/libsanitizer/sanitizer_common/sanitizer_common_interceptors_memintrinsics.inc:115 in memcpy Shadow bytes around the buggy address: 0x74253f2fff80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x74253f300000: f1 f1 f1 f1 f1 f1 f8 f2 f8 f2 f8 f2 f8 f2 f8 f2 0x74253f300080: f8 f2 01 f2 f8 f2 f8 f2 f8 f2 f8 f2 04 f2 04 f2 0x74253f300100: 04 f2 00 f2 f2 f2 00 f2 f2 f2 f8 f8 f8 f2 f2 f2 0x74253f300180: f2 f2 f8 f8 f8 f2 f2 f2 f2 f2 f8 f8 f8 f2 f2 f2 =>0x74253f300200: f2 f2 00 00 00 f2 f2 f2 f2 f2 00[f2]f2 f2 f8 f8 0x74253f300280: f8 f8 f2 f2 f2 f2 f8 f8 f8 f8 f2 f2 f2 f2 f8 f8 0x74253f300300: f8 f8 f2 f2 f2 f2 f8 f8 f8 f8 f2 f2 f2 f2 f8 f8 0x74253f300380: f8 f8 f2 f2 f2 f2 f8 f8 f8 f8 f2 f2 f2 f2 f8 f8 0x74253f300400: f8 f8 f2 f2 f2 f2 f8 f8 f8 f8 f2 f2 f2 f2 f8 f8 0x74253f300480: f8 f8 f2 f2 f2 f2 f8 f8 f8 f8 f2 f2 f2 f2 f8 f8 Shadow byte legend (one shadow byte represents 8 application bytes): Addressable: 00 Partially addressable: 01 02 03 04 05 06 07 Heap left redzone: fa Freed heap region: fd Stack left redzone: f1 Stack mid redzone: f2 Stack right redzone: f3 Stack after return: f5 Stack use after scope: f8 Global redzone: f9 Global init order: f6 Poisoned by user: f7 Container overflow: fc Array cookie: ac Intra object redzone: bb ASan internal: fe Left alloca redzone: ca Right alloca redzone: cb ==325537==ABORTING