Public bug reported:

[ Impact ]

 * The rocalution 10.0-0ubuntu1 test suite (rocalution-test, run via
   debian/tests/upstream-binaries during dh_auto_test / autopkgtest) contains
   a stack buffer overflow in testing_extract_coarse_mapping()
   (clients/include/testing_local_vector.hpp). The test declares 3-element
   `index` and `map` arrays but calls
   `LocalVector::ExtractCoarseMapping(0, 5, index, 3, &size, map)`, which
   reads/writes 5 elements (end - start = 5) of both arrays. This is
   undefined behaviour: on amd64/arm64 it happens not to corrupt anything
   observable, but on ppc64el the differing stack layout causes the
   overflow to clobber adjacent stack data, crashing the rocalution-test
   binary with a segfault during dh_auto_test and blocking the build/test
   on that architecture, as can be seen on 
(https://launchpadlibrarian.net/878532915/buildlog_ubuntu-stonking-ppc64el.rocalution_10.0-0ubuntu1_BUILDING.txt.gz).
 * Patch 0002-fix-testing_extract_coarse_mapping-stack-overflow.patch
   enlarges `index` and `map` to 5 elements (matching the actual range
   used) and populates `index` with the full 0..4 sequence, eliminating
   the out-of-bounds access while preserving the test's intent. This is a
   test-only fix; no library source, ABI, or public API is touched.

[ Test Plan ]

1. Build:
   - dpkg-buildpackage / sbuild succeeds on amd64, arm64, and ppc64el.
   - dh_auto_test completes without rocalution-test crashing/segfaulting
     on ppc64el.
2. Installability:
   - apt install librocalution1 librocalution1-tests.
   - Reverse dependencies remain installable without rebuild (no ABI
     change).
3. Autopkgtest:
   - Run the autopkgtest suite (Test-Command:
     debian/tests/upstream-binaries librocalution1-tests) on amd64,
     arm64, and ppc64el.
   - Output: <TBD — paste autopkgtest run results here>

[ Where problems could occur ]

 * The change only widens two local test arrays and adds explicit
   initializer values; it does not alter the ExtractCoarseMapping
   implementation itself, so risk is limited to the test binary. A
   plausible regression would be the test now passing a differently
   shaped index array and silently exercising a different code path in
   ExtractCoarseMapping, though the range (0..5) and count (5) passed to
   the call are unchanged, so behaviour of the function under test is
   equivalent.
 * If a future upstream merge reintroduces the original undersized arrays
   during a version bump, the same ppc64el crash could reappear; the
   patch should be re-checked against upstream test sources at that time.

[ Other Info ]

 * No ABI/symbols impact: this is a test-source-only change
   (clients/include/testing_local_vector.hpp), not shipped in any binary
   package's public interface.
 * Forwarded: 
 * Target: resolute 26.10

** Affects: rocalution (Ubuntu)
     Importance: Undecided
         Status: New

** Summary changed:

- testing_extract_coarse_mapping test crash on ppc65el
+ testing_extract_coarse_mapping test crash on ppc64el

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2168844

Title:
  testing_extract_coarse_mapping test crash on ppc64el

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/rocalution/+bug/2168844/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to