* whisper : guard null source in buffer loader read callback
whisper_init_from_buffer_with_params_no_state installs a read callback that
copies from buf->buffer + current_offset. When the buffer is exhausted (or the
supplied buffer is empty), size_to_copy is 0 and the source pointer can be null;
passing a null pointer to memcpy is undefined behavior even for a zero-length
copy (UBSan: 'null pointer passed as argument 2' at the memcpy). Loading a
crafted/short model through the buffer loader could hit this.
Skip the memcpy when there is nothing to copy. Loading from a null/empty or
truncated buffer now fails gracefully (returns NULL) with no UB.
This addresses bug 1 of #3879. Bug 2 (integer overflow when sizing the mel
filter buffer) is covered by the open PR #3780.
* fixup! whisper : guard null source in buffer loader read callback
---------
Co-authored-by: Ben Younes <2910651+ousamabenyounes@users.noreply.github.com>
* fix: reject invalid n_dims in tensor header to prevent stack-buffer-overflow on malformed model files
* Validate n_dims value in model file loading
Add error handling for invalid n_dims in model file.
* verify hparams loaded from parakeet model bin file
* flexible way to accommodate CI as well security concern & test case addition.
* add bad model for CI tests
* removing whitespaces,couple of nits