Skip to content

Fix crashes when using variable-length data after closing another handle of the same dataset - #6722

Open
headtr1ck wants to merge 3 commits into
HDFGroup:developfrom
headtr1ck:fix-vlen-stale-file
Open

headtr1ck wants to merge 3 commits into
HDFGroup:developfrom
headtr1ck:fix-vlen-stale-file

Conversation

@headtr1ck

@headtr1ck headtr1ck commented Oct 8, 2026 •

Copy link
Copy Markdown

Describe your changes

A dataset's datatype is shared by all open handles of the dataset, and its variable-length types store the file of the handle that opened the dataset first. After that file handle is closed, e.g. when the same file was opened twice, converting variable-length data through another handle of the dataset crashes in H5F_addr_decode(). H5T_patch_vlen_file() repairs this, but only for a top-level variable-length type and only before reading or writing data.

Issue ticket number (GitHub or JIRA)

Fixes #6721 (see also h5py/h5py#2920 and pydata/xarray#11692)

Checklist before requesting a review

  • My code conforms to the guidelines in CONTRIBUTING.md
  • I made an entry in release_docs/CHANGELOG.md (bug fixes, new features)
  • I added a test (bug fixes, new features)

[This is Claude Code on behalf of Michael Niklas]

🤖 Generated with Claude Code

headtr1ck and others added 2 commits October 8, 2026 13:27
A dataset's datatype is shared by all open handles of the dataset, and
H5T_set_loc() stamps the file of the handle that opened it first into every
variable-length type it can reach, also below compound members and array base
types. H5T_patch_vlen_file() repairs that file before reading or writing
data, but only for a variable-length type at the top level. After the file
of the first handle was closed, reading through another handle therefore
crashed in H5F_addr_decode() for a variable-length string in a compound type
(h5py/h5py#2920). Walk the same subtypes as H5T_set_loc() instead.

Based on the analysis and patch in https://github.com/beitler/hdf5-vlen.

Co-authored-by: anton <2046752+beitler@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
H5D_get_create_plist() and the storage initialization of H5D__alloc_storage()
and H5D__set_extent() convert the fill value with the dataset's shared
datatype, without repairing the file of its variable-length types first as
H5Dread() and H5Dwrite() do. After the file of the handle that opened the
dataset first was closed, this crashed in H5F_addr_decode() for a dataset with
a variable-length fill value. netCDF-C calls H5Dget_create_plist() when
opening a file, so it crashed when opening a netCDF-4 file with string
variables again after closing one of several handles to it.

Add a test that uses variable-length data through a dataset handle after
closing another handle of the same dataset, for these cases and for the
variable-length type in a compound type from the previous commit.

Co-authored-by: Claude <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Claude <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Review Checklist

This PR touches the following areas. Each needs a sign-off
from its listed owners before merging.

Comment thread release_docs/CHANGELOG.md

### Fixed crashes when using variable-length data after closing another handle of the same dataset

A dataset's datatype is shared by all open handles of the dataset, and its variable-length types refer to the file of the handle that opened the dataset first. After that file handle was closed, other handles of the same dataset, e.g. from opening the same file twice, still converted variable-length data with the closed file, which crashed in `H5F_addr_decode()`. `H5T_patch_vlen_file()` repaired the file only for a variable-length type at the top level of the datatype, and only when reading or writing data, but not for variable-length types nested in compound or array types, or when converting a variable-length fill value in `H5Dget_create_plist()` or while initializing storage, e.g. in `H5Dset_extent()`. Opening a netCDF-4 file with string variables calls `H5Dget_create_plist()`, so this crashed netCDF-C and netCDF4-python when a file was opened again after closing one of several handles to it. `H5T_patch_vlen_file()` now repairs nested variable-length types as well, and is also called before converting fill values.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

e.g. -> e.g.,

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: To be triaged

Development

Successfully merging this pull request may close these issues.

Use-after-free of a closed file in variable-length conversions through another handle of the same dataset

2 participants