** Description changed: [ Impact ] - * The rocalution 10.0-0ubuntu1 test suite (rocalution-test, run via - debian/tests/upstream-binaries during dh_auto_test / autopkgtest) contains - a stack buffer overflow in testing_extract_coarse_mapping() - (clients/include/testing_local_vector.hpp). The test declares 3-element - `index` and `map` arrays but calls - `LocalVector::ExtractCoarseMapping(0, 5, index, 3, &size, map)`, which - reads/writes 5 elements (end - start = 5) of both arrays. This is - undefined behaviour: on amd64/arm64 it happens not to corrupt anything - observable, but on ppc64el the differing stack layout causes the - overflow to clobber adjacent stack data, crashing the rocalution-test - binary with a segfault during dh_auto_test and blocking the build/test - on that architecture, as can be seen on (https://launchpadlibrarian.net/878532915/buildlog_ubuntu-stonking-ppc64el.rocalution_10.0-0ubuntu1_BUILDING.txt.gz). - * Patch 0002-fix-testing_extract_coarse_mapping-stack-overflow.patch - enlarges `index` and `map` to 5 elements (matching the actual range - used) and populates `index` with the full 0..4 sequence, eliminating - the out-of-bounds access while preserving the test's intent. This is a - test-only fix; no library source, ABI, or public API is touched. + * The rocalution 10.0-0ubuntu1 test suite (rocalution-test, run via + debian/tests/upstream-binaries during dh_auto_test / autopkgtest) contains + a stack buffer overflow in testing_extract_coarse_mapping() + (clients/include/testing_local_vector.hpp). The test declares 3-element + `index` and `map` arrays but calls + `LocalVector::ExtractCoarseMapping(0, 5, index, 3, &size, map)`, which + reads/writes 5 elements (end - start = 5) of both arrays. This is + undefined behaviour: on amd64/arm64 it happens not to corrupt anything + observable, but on ppc64el the differing stack layout causes the + overflow to clobber adjacent stack data, crashing the rocalution-test + binary with a segfault during dh_auto_test and blocking the build/test + on that architecture, as can be seen on (https://launchpadlibrarian.net/878532915/buildlog_ubuntu-stonking-ppc64el.rocalution_10.0-0ubuntu1_BUILDING.txt.gz). + * Patch 0002-fix-testing_extract_coarse_mapping-stack-overflow.patch + enlarges `index` and `map` to 5 elements (matching the actual range + used) and populates `index` with the full 0..4 sequence, eliminating + the out-of-bounds access while preserving the test's intent. This is a + test-only fix; no library source, ABI, or public API is touched. [ Test Plan ] 1. Build: - - dpkg-buildpackage / sbuild succeeds on amd64, arm64, and ppc64el. - - dh_auto_test completes without rocalution-test crashing/segfaulting - on ppc64el. + - dpkg-buildpackage / sbuild succeeds on amd64, arm64, and ppc64el. + - dh_auto_test completes without rocalution-test crashing/segfaulting + on ppc64el. 2. Installability: - - apt install librocalution1 librocalution1-tests. - - Reverse dependencies remain installable without rebuild (no ABI - change). + - apt install librocalution1 librocalution1-tests. + - Reverse dependencies remain installable without rebuild (no ABI + change). 3. Autopkgtest: - - Run the autopkgtest suite (Test-Command: - debian/tests/upstream-binaries librocalution1-tests) on amd64, - arm64, and ppc64el. - - Output: <TBD — paste autopkgtest run results here> + - Run the autopkgtest suite (Test-Command: + debian/tests/upstream-binaries librocalution1-tests) on amd64, + arm64, and ppc64el. + - Output: <TBD — paste autopkgtest run results here> [ Where problems could occur ] - * The change only widens two local test arrays and adds explicit - initializer values; it does not alter the ExtractCoarseMapping - implementation itself, so risk is limited to the test binary. A - plausible regression would be the test now passing a differently - shaped index array and silently exercising a different code path in - ExtractCoarseMapping, though the range (0..5) and count (5) passed to - the call are unchanged, so behaviour of the function under test is - equivalent. - * If a future upstream merge reintroduces the original undersized arrays - during a version bump, the same ppc64el crash could reappear; the - patch should be re-checked against upstream test sources at that time. + * The change only widens two local test arrays and adds explicit + initializer values; it does not alter the ExtractCoarseMapping + implementation itself, so risk is limited to the test binary. A + plausible regression would be the test now passing a differently + shaped index array and silently exercising a different code path in + ExtractCoarseMapping, though the range (0..5) and count (5) passed to + the call are unchanged, so behaviour of the function under test is + equivalent. + * If a future upstream merge reintroduces the original undersized arrays + during a version bump, the same ppc64el crash could reappear; the + patch should be re-checked against upstream test sources at that time. [ Other Info ] - * No ABI/symbols impact: this is a test-source-only change - (clients/include/testing_local_vector.hpp), not shipped in any binary - package's public interface. - * Forwarded: - * Target: resolute 26.10 + * No ABI/symbols impact: this is a test-source-only change + (clients/include/testing_local_vector.hpp), not shipped in any binary + package's public interface. + * Forwarded: https://github.com/ROCm/rocm-libraries/issues/12703 + * Target: resolute 26.10
-- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2168844 Title: testing_extract_coarse_mapping test crash on ppc64el To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/rocalution/+bug/2168844/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
