================================================================= ==472150==ERROR: AddressSanitizer: stack-buffer-overflow on address 0x745d3bd001d8 at pc 0x745d40615303 bp 0x7fff82afb860 sp 0x7fff82afb008 WRITE of size 4 at 0x745d3bd001d8 thread T0 #0 0x745d40615302 in memcpy ../../../../src/libsanitizer/sanitizer_common/sanitizer_common_interceptors_memintrinsics.inc:115 #1 0x745d3e2e90bf in std::basic_streambuf >::xsgetn(char*, long) (/lib/x86_64-linux-gnu/libstdc++.so.6+0x1670bf) (BuildId: ca77dae775ec87540acd7218fa990c40d1c94ab1) #2 0x745d3e2ac0e9 in std::basic_filebuf >::xsgetn(char*, long) (/lib/x86_64-linux-gnu/libstdc++.so.6+0x12a0e9) (BuildId: ca77dae775ec87540acd7218fa990c40d1c94ab1) #3 0x745d3e2ba140 in std::istream::read(char*, long) (/lib/x86_64-linux-gnu/libstdc++.so.6+0x138140) (BuildId: ca77dae775ec87540acd7218fa990c40d1c94ab1) #4 0x5c0977da4707 in gptj_model_load(std::__cxx11::basic_string, std::allocator > const&, gptj_model&, gpt_vocab&) /workspace/GGML/repos/ggml/examples/gpt-j/main.cpp:321 #5 0x5c0977da9fbe in main /workspace/GGML/repos/ggml/examples/gpt-j/main.cpp:650 #6 0x745d3d9841c9 (/lib/x86_64-linux-gnu/libc.so.6+0x2a1c9) (BuildId: 274eec488d230825a136fa9c4d85370fed7a0a5e) #7 0x745d3d98428a in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x2a28a) (BuildId: 274eec488d230825a136fa9c4d85370fed7a0a5e) #8 0x5c0977d9abc4 in _start (/workspace/GGML/continued/builds/ggml-asan/bin/gpt-j+0x219bc4) (BuildId: 40a7a1260c98f7a2197be9c9902e0a4475ea4bc5) Address 0x745d3bd001d8 is located in stack of thread T0 at offset 472 in frame #0 0x5c0977d9c15b in gptj_model_load(std::__cxx11::basic_string, std::allocator > const&, gptj_model&, gpt_vocab&) /workspace/GGML/repos/ggml/examples/gpt-j/main.cpp:77 This frame has 57 object(s): [48, 49) '' [64, 65) '' [80, 81) '' [96, 97) '' [112, 113) '' [128, 129) '' [144, 145) '' [160, 164) 'magic' (line 88) [176, 180) 'n_vocab' (line 124) [192, 196) 'i' (line 136) [208, 212) 'len' (line 137) [224, 228) 'n_dims' (line 306) [240, 244) 'length' (line 307) [256, 260) 'ttype' (line 308) [272, 280) '' [304, 312) '' [336, 360) 'buf' (line 134) [400, 424) 'params' (line 203) [464, 472) 'ne' (line 319) <== Memory access at offset 472 overflows this variable [496, 528) 'word' (line 133) [560, 592) '' [624, 656) '' [688, 720) '' [752, 784) '' [816, 848) '' [880, 912) '' [944, 976) '' [1008, 1040) '' [1072, 1104) '' [1136, 1168) '' [1200, 1232) '' [1264, 1296) '' [1328, 1360) '' [1392, 1424) '' [1456, 1488) '' [1520, 1552) '' [1584, 1616) '' [1648, 1680) '' [1712, 1744) '' [1776, 1808) '' [1840, 1872) '' [1904, 1936) '' [1968, 2000) '' [2032, 2064) '' [2096, 2128) '' [2160, 2192) '' [2224, 2256) '' [2288, 2320) '' [2352, 2384) '' [2416, 2448) '' [2480, 2512) '' [2544, 2576) '' [2608, 2640) '' [2672, 2704) '' [2736, 2768) '' [2800, 2832) 'name' (line 325) [2864, 3384) 'fin' (line 80) HINT: this may be a false positive if your program uses some custom stack unwind mechanism, swapcontext or vfork (longjmp and C++ exceptions *are* supported) SUMMARY: AddressSanitizer: stack-buffer-overflow ../../../../src/libsanitizer/sanitizer_common/sanitizer_common_interceptors_memintrinsics.inc:115 in memcpy Shadow bytes around the buggy address: 0x745d3bcfff00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x745d3bcfff80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0x745d3bd00000: f1 f1 f1 f1 f1 f1 f8 f2 f8 f2 f8 f2 f8 f2 f8 f2 0x745d3bd00080: f8 f2 01 f2 f8 f2 f8 f2 f8 f2 f8 f2 04 f2 04 f2 0x745d3bd00100: 04 f2 00 f2 f2 f2 00 f2 f2 f2 f8 f8 f8 f2 f2 f2 =>0x745d3bd00180: f2 f2 f8 f8 f8 f2 f2 f2 f2 f2 00[f2]f2 f2 f8 f8 0x745d3bd00200: f8 f8 f2 f2 f2 f2 f8 f8 f8 f8 f2 f2 f2 f2 f8 f8 0x745d3bd00280: f8 f8 f2 f2 f2 f2 f8 f8 f8 f8 f2 f2 f2 f2 f8 f8 0x745d3bd00300: f8 f8 f2 f2 f2 f2 f8 f8 f8 f8 f2 f2 f2 f2 f8 f8 0x745d3bd00380: f8 f8 f2 f2 f2 f2 f8 f8 f8 f8 f2 f2 f2 f2 f8 f8 0x745d3bd00400: f8 f8 f2 f2 f2 f2 f8 f8 f8 f8 f2 f2 f2 f2 f8 f8 Shadow byte legend (one shadow byte represents 8 application bytes): Addressable: 00 Partially addressable: 01 02 03 04 05 06 07 Heap left redzone: fa Freed heap region: fd Stack left redzone: f1 Stack mid redzone: f2 Stack right redzone: f3 Stack after return: f5 Stack use after scope: f8 Global redzone: f9 Global init order: f6 Poisoned by user: f7 Container overflow: fc Array cookie: ac Intra object redzone: bb ASan internal: fe Left alloca redzone: ca Right alloca redzone: cb ==472150==ABORTING