Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 6 additions & 5 deletions .cppcheck-suppressions.txt
Original file line number Diff line number Diff line change
Expand Up @@ -6,11 +6,12 @@
# so every other exclusion this file used to carry has been retired and the
# findings behind them fixed in the source.

# NOTE: do not write a bare "#" line in this file. cppcheck 2.13 -- the version
# CI installs from the Ubuntu 24.04 archive -- strips the leading "#" and then
# fails to parse the empty remainder with "Failed to add suppression. No id.",
# which aborts the whole run. Blank lines are fine; comment lines must carry
# text. Measured against 2.13.0 in a container.
# NOTE: do not write a bare "#" line in this file. cppcheck 2.13 strips the
# leading "#" and then fails to parse the empty remainder with "Failed to add
# suppression. No id.", which aborts the whole run. Blank lines are fine;
# comment lines must carry text. Measured against 2.13.0 in a container. CI now
# installs 2.19 from the Ubuntu 26.04 archive, which does not have that bug, but
# the rule costs nothing and keeps the file usable with either version.

# Generated / fetched at build time.
*:build/*
Expand Down
14 changes: 1 addition & 13 deletions .github/workflows/lint-and-format.yml
Original file line number Diff line number Diff line change
Expand Up @@ -563,19 +563,7 @@ jobs:
# Variable `ARC_RUNNERS_ENABLED=true` flips this job to the in-cluster
# `arc-runners` scale set; default `false` keeps GitHub-hosted. If the
# ARC pool is degraded, flip the var off and re-trigger CI.
# This lane alone stays on ubuntu-24.04 while the rest of the matrix is
# on 26.04. The image decides the analyser: 24.04's archive carries
# cppcheck 2.13 and 26.04's carries 2.19, with no older version
# available there. 2.19's value-flow analysis reports 90 findings
# this tree has never seen, all in the vendored libsvm predictor
# core/src/svm.cpp: 88 mallocs dereferenced without a NULL check,
# plus the Cache class owning raw storage with neither a copy
# constructor nor an assignment operator. They are real and they are
# in scope under ADR-1142, which is why they are not suppressed:
# T-CI-CPPCHECK-219-LIBSVM-FINDINGS-2026-09-19 tracks fixing them and
# moving this lane, and that work belongs with a Netflix golden-data
# run because svm.cpp computes the VMAF prediction.
runs-on: ${{ vars.ARC_RUNNERS_ENABLED == 'true' && 'arc-runners' || 'ubuntu-24.04' }}
runs-on: ${{ vars.ARC_RUNNERS_ENABLED == 'true' && 'arc-runners' || 'ubuntu-26.04' }}
# Bumped 15→30 min on 2026-05-09: GitHub-hosted runner queue
# saturation pushed Cppcheck past 15 min on ~all PRs and master.
# Last green run on master took 5 min; the new ceiling absorbs
Expand Down
13 changes: 13 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -27275,6 +27275,19 @@ backtick code spans.
- Move four merged-fix rows (T-HIP-PSNR-CHROMA-MCP-PARITY-2026-06-20, T-CI-TOX-PY311-SCIPY-118-2026-06-20, T-NEON-FMA-FLOAT-ADM-DWT2-2026-06-06, T-CI-DOCKER-SMOKE-NO-OUTPUT-2026-06-13) out of Open bugs in docs/state.md.


- **Every allocation in the bundled libsvm predictor is checked, and the whole
file now meets the project's size limit.** A newer cppcheck, which arrived
with the newer CI runner image, found 88 places where a `malloc` result was
used without testing it, plus a cache class that owned raw memory while
allowing itself to be copied. The allocation helper now reports and stops on
failure, matching what the same file already did for its reallocations, and
the copy is a compile error rather than a double free. Splitting the file's
long functions came with that, and every one was split along a seam its own
comments already marked. Scores are unchanged: all 48 frames of the Netflix
reference pair are byte-identical at maximum precision, as are both
checkerboard pairs.


- **Heap buffer overflow loading a model whose support-vector data
forges the end-of-vector sentinel.** `SVMModelParser::parse_support_vectors()`
read each feature index straight from the file with no validation.
Expand Down
11 changes: 11 additions & 0 deletions changelog.d/fixed/svm-checked-allocation.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
- **Every allocation in the bundled libsvm predictor is checked, and the whole
file now meets the project's size limit.** A newer cppcheck, which arrived
with the newer CI runner image, found 88 places where a `malloc` result was
used without testing it, plus a cache class that owned raw memory while
allowing itself to be copied. The allocation helper now reports and stops on
failure, matching what the same file already did for its reallocations, and
the copy is a compile error rather than a double free. Splitting the file's
long functions came with that, and every one was split along a seam its own
comments already marked. Scores are unchanged: all 48 frames of the Netflix
reference pair are byte-identical at maximum precision, as are both
checkerboard pairs.
Loading
Loading