Skip to content

[Bug] Self-referential safetensors index repeatedly reloads itself #2052

Description

@agammann

Git commit: b167b942f77ecb17e7f78e163a8c32ff7ac95c10

Operating System & Version: Debian GNU/Linux 12 (bookworm), x86_64, in a Docker container

GGML backends: CPU

Command-line arguments used: sd-cli --mode convert -m ./model.safetensors.index.json -o ./out.gguf

Steps to reproduce:

  1. Build sd-cli from the commit above using the checked-in ggml submodule. The reproduction used GCC 12.2 with -DSD_SERVER_BUILD_FRONTEND=OFF -DSD_WEBP=OFF -DSD_WEBM=OFF -DGGML_NATIVE=OFF.
  2. Create model.safetensors.index.json containing exactly {"weight_map":{"tensor":"model.safetensors.index.json"}}.
  3. Run the command above under a 15-second timeout. The filename in weight_map points back to the index itself.

Expected behavior: The loader rejects a cyclic shard reference with a normal error and exits.

Actual behavior: The CLI repeatedly logs load ./model.safetensors.index.json using safetensors index format. In the tested container it logged 2,587 such loads before the 15-second watchdog killed it (exit 137). With a 256 KiB process stack, the same command segfaulted (exit 139). A control index pointing to a nonexistent .safetensors file instead returned a normal missing-file error (exit 1) under both stack settings.

Logs / error messages / stack trace: Repeated model_loader.cpp:218 - load ... using safetensors index format lines. There was no application error before the watchdog or the bounded-stack segmentation fault. The local reproduction retains both fixture files and full logs.

Additional context / environment details: This occurs during local model-index parsing; no model weights or generation request are needed. The fixture is only a JSON index. This report concerns a robustness bug in handling a malformed input and makes no remote exploit claim.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions