Repository navigation
fix(ffmpeg-patches): libvmaf_sycl filter — free sycl_state on close + NULL-guard QSV chain - #1067
Merged
Merged
Conversation
… NULL-guard QSV chain Two verified defects from the adversarial round-4 audit, in the dedicated libvmaf_sycl filter added by ffmpeg-patches/0005. - sycl_state leak (high): uninit_sycl called vmaf_close() but never vmaf_sycl_state_free(). vmaf_close() explicitly does NOT free the SYCL state (ownership is not transferred), so the state + its USM allocations leaked on every filter close. Now freed explicitly after vmaf_close(); the false "vmaf_close handles it" comment is removed. - QSV NULL deref (med): do_vmaf_sycl walked the QSV zero-copy handle chain (AVFrame->data[3] -> mfxFrameSurface1* -> Data.MemId -> mfxHDLPair* -> ->first) with no NULL guards; a software-fallback QSV surface with no VA backing crashed the filter. All three chain links are now NULL-checked, returning AVERROR(EINVAL) with a clear diagnostic. The patch was regenerated surgically (only these two + blocks in the vf_libvmaf.c hunk + the hunk-header recount 335->353; the configure/Makefile/ allfilters hunks are byte-unchanged). Verified by a full 16-patch `git apply --3way` series replay against n8.1.1 (CLAUDE rule #14). Finding #21 (a redundant but idempotent `check_pkg_config libvmaf_sycl` configure probe) is intentionally left: the probe is idempotent and removing the wrong one risks breaking SYCL detection. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
9 tasks done
lusoris
added a commit
that referenced
this pull request
Sep 26, 2026
Commit 384d97d / PR #1067 clobbered enable_chroma and plane clamping in core/src/feature/metal/integer_psnr_metal.mm while reconciling repository layout (BUG-048). This broke PSNR option parity across GPU backends: - integer_psnr_metal rejected enable_chroma=false with -EINVAL. - On monochrome YUV400P inputs, the extractor unconditionally dispatched and collected 3 planes, triggering out-of-bounds reads and spurious psnr_cb and psnr_cr sub-scores. Restore enable_chroma (default true) and clamp n_planes to 1 for VMAF_PIX_FMT_YUV400P or !enable_chroma. Modularize initialization helper functions (psnr_metal_plane_geometry and alloc_readback_buffers) to adhere to NASA JPL Rule 4 complexity limits (HISS-04). Add device-free contract test test_gpu_psnr_option_parity_contract.py asserting GPU option schema and plane clamping parity across CUDA, SYCL, HIP, and Metal. Add unit tests in test_metal_kernel_registration.c and test_metal_integer_psnr_parity.c. ADR: docs/adr/1322-metal-integer-psnr-enable-chroma-parity.md Signed-off-by: Lusoris <lusoris@pm.me>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Two verified defects from the adversarial round-4 audit in the dedicated
libvmaf_syclFFmpeg filter added byffmpeg-patches/0005.uninit_syclcalledvmaf_close()but nevervmaf_sycl_state_free().vmaf_close()explicitly does not free the SYCL state (ownership isn't transferred), so the state + its USM allocations leaked on every filter close. Freed explicitly now; false comment removed.do_vmaf_syclwalked the QSV zero-copy chain (data[3]→mfxFrameSurface1*→Data.MemId→mfxHDLPair*→->first) with no NULL guards; a software-fallback QSV surface (no VA backing) crashed it. All three links NULL-checked →AVERROR(EINVAL)+ diagnostic.Deferred: finding #21 (a redundant but idempotent
check_pkg_config libvmaf_syclconfigure probe) is intentionally left — removing the wrong one risks breaking SYCL detection for no correctness gain.Reproducer / verification
The patch was regenerated surgically — only the two
+blocks in thevf_libvmaf.chunk + the hunk-header recount (335→353); theconfigure/Makefile/allfiltershunks are byte-unchanged (a fullformat-patch/am --3wayregeneration was rejected because it fuzzed the configure probe>= 3.0.0→2.0.0).Deep-dive deliverables (ADR-0108)
.workingdir2/BUGHUNT_2026-06-27.md).+blocks; regenerate surgically not via format-patch" invariant is in this PR'sdocs/rebase-notes.mdentry.changelog.d/fixed/round4-ffmpeg-patches-audit.md.docs/rebase-notes.md.state.md / golden / patch-stack rule
docs/state.md—T-ROUND4-FFMPEG-PATCHES-2026-06-27Recently-closed row.n8.1.1is CLEAN (16/16 patches).no docs needed: bug fix in an existing ffmpeg filter patch, no user-visible delta.🤖 Generated with Claude Code