** Description changed:

  [ Impact ]
  
   * The rocalution 10.0-0ubuntu1 test suite (rocalution-test, run via
     debian/tests/upstream-binaries during dh_auto_test / autopkgtest) contains
     a stack buffer overflow in testing_extract_coarse_mapping()
     (clients/include/testing_local_vector.hpp). The test declares 3-element
     `index` and `map` arrays but calls
     `LocalVector::ExtractCoarseMapping(0, 5, index, 3, &size, map)`, which
     reads/writes 5 elements (end - start = 5) of both arrays. This is
     undefined behaviour: on amd64/arm64 it happens not to corrupt anything
     observable, but on ppc64el the differing stack layout causes the
     overflow to clobber adjacent stack data, crashing the rocalution-test
     binary with a segfault during dh_auto_test and blocking the build/test
     on that architecture, as can be seen on 
(https://launchpadlibrarian.net/878532915/buildlog_ubuntu-stonking-ppc64el.rocalution_10.0-0ubuntu1_BUILDING.txt.gz).
   * Patch 0002-fix-testing_extract_coarse_mapping-stack-overflow.patch
     enlarges `index` and `map` to 5 elements (matching the actual range
     used) and populates `index` with the full 0..4 sequence, eliminating
     the out-of-bounds access while preserving the test's intent. This is a
     test-only fix; no library source, ABI, or public API is touched.
  
  [ Test Plan ]
  
  1. Build:
     - dpkg-buildpackage / sbuild succeeds on amd64, arm64, and ppc64el.
     - dh_auto_test completes without rocalution-test crashing/segfaulting
       on ppc64el.
  2. Installability:
     - apt install librocalution1 librocalution1-tests.
     - Reverse dependencies remain installable without rebuild (no ABI
       change).
  3. Autopkgtest:
     - Run the autopkgtest suite (Test-Command:
       debian/tests/upstream-binaries librocalution1-tests) on amd64,
       arm64, and ppc64el.
     - Output: <TBD — paste autopkgtest run results here>
  
  [ Where problems could occur ]
  
   * The change only widens two local test arrays and adds explicit
     initializer values; it does not alter the ExtractCoarseMapping
     implementation itself, so risk is limited to the test binary. A
     plausible regression would be the test now passing a differently
     shaped index array and silently exercising a different code path in
     ExtractCoarseMapping, though the range (0..5) and count (5) passed to
     the call are unchanged, so behaviour of the function under test is
     equivalent.
   * If a future upstream merge reintroduces the original undersized arrays
     during a version bump, the same ppc64el crash could reappear; the
     patch should be re-checked against upstream test sources at that time.
  
  [ Other Info ]
  
   * No ABI/symbols impact: this is a test-source-only change
     (clients/include/testing_local_vector.hpp), not shipped in any binary
     package's public interface.
   * Forwarded: https://github.com/ROCm/rocm-libraries/issues/12703
-  * Target: resolute 26.10
+  * Target: stonking 26.10

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2168844

Title:
  testing_extract_coarse_mapping test crash on ppc64el

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/rocalution/+bug/2168844/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to