Git commit: b167b942f77ecb17e7f78e163a8c32ff7ac95c10
Operating System & Version: Debian GNU/Linux 12 (bookworm), x86_64, in a Docker container
GGML backends: CPU
Command-line arguments used: sd-cli --mode convert -m ./model.safetensors.index.json -o ./out.gguf
Steps to reproduce:
- Build
sd-cli from the commit above using the checked-in ggml submodule. The reproduction used GCC 12.2 with -DSD_SERVER_BUILD_FRONTEND=OFF -DSD_WEBP=OFF -DSD_WEBM=OFF -DGGML_NATIVE=OFF.
- Create
model.safetensors.index.json containing exactly {"weight_map":{"tensor":"model.safetensors.index.json"}}.
- Run the command above under a 15-second timeout. The filename in
weight_map points back to the index itself.
Expected behavior: The loader rejects a cyclic shard reference with a normal error and exits.
Actual behavior: The CLI repeatedly logs load ./model.safetensors.index.json using safetensors index format. In the tested container it logged 2,587 such loads before the 15-second watchdog killed it (exit 137). With a 256 KiB process stack, the same command segfaulted (exit 139). A control index pointing to a nonexistent .safetensors file instead returned a normal missing-file error (exit 1) under both stack settings.
Logs / error messages / stack trace: Repeated model_loader.cpp:218 - load ... using safetensors index format lines. There was no application error before the watchdog or the bounded-stack segmentation fault. The local reproduction retains both fixture files and full logs.
Additional context / environment details: This occurs during local model-index parsing; no model weights or generation request are needed. The fixture is only a JSON index. This report concerns a robustness bug in handling a malformed input and makes no remote exploit claim.
Git commit:
b167b942f77ecb17e7f78e163a8c32ff7ac95c10Operating System & Version: Debian GNU/Linux 12 (bookworm), x86_64, in a Docker container
GGML backends: CPU
Command-line arguments used:
sd-cli --mode convert -m ./model.safetensors.index.json -o ./out.ggufSteps to reproduce:
sd-clifrom the commit above using the checked-inggmlsubmodule. The reproduction used GCC 12.2 with-DSD_SERVER_BUILD_FRONTEND=OFF -DSD_WEBP=OFF -DSD_WEBM=OFF -DGGML_NATIVE=OFF.model.safetensors.index.jsoncontaining exactly{"weight_map":{"tensor":"model.safetensors.index.json"}}.weight_mappoints back to the index itself.Expected behavior: The loader rejects a cyclic shard reference with a normal error and exits.
Actual behavior: The CLI repeatedly logs
load ./model.safetensors.index.json using safetensors index format. In the tested container it logged 2,587 such loads before the 15-second watchdog killed it (exit137). With a 256 KiB process stack, the same command segfaulted (exit139). A control index pointing to a nonexistent.safetensorsfile instead returned a normal missing-file error (exit1) under both stack settings.Logs / error messages / stack trace: Repeated
model_loader.cpp:218 - load ... using safetensors index formatlines. There was no application error before the watchdog or the bounded-stack segmentation fault. The local reproduction retains both fixture files and full logs.Additional context / environment details: This occurs during local model-index parsing; no model weights or generation request are needed. The fixture is only a JSON index. This report concerns a robustness bug in handling a malformed input and makes no remote exploit claim.