Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .github/workflows/required-aggregator.yml
Original file line number Diff line number Diff line change
Expand Up @@ -68,6 +68,8 @@ jobs:
'Windows MSVC+CUDA',
'Windows MSVC+SYCL',
'CodeQL',
// ADR-1389: CodeQL (Actions) runs unconditionally on every PR and
// master push to guarantee SAST coverage across 100% of commits.
'CodeQL (Actions)',
'CodeQL (C/C++)',
'CodeQL (Python)',
Expand Down
7 changes: 7 additions & 0 deletions .github/workflows/rule-enforcement.yml
Original file line number Diff line number Diff line change
Expand Up @@ -845,6 +845,13 @@ jobs:
# daemon is reachable.
run: bash scripts/ci/tests/test-check-container-source.sh

- name: No unallowlisted non-header includes in core/test
# CodeQL alert cpp/include-non-header guard. Unit tests under core/test
# must use internal headers and link seams rather than unity-including .c/.cpp.
run: |
bash scripts/ci/check-no-non-header-includes.sh
bash scripts/ci/tests/test-check-no-non-header-includes.sh

- name: One-shot release-please fields must not outlive the first release
run: |
# ADR-1151. `release-as` and `bootstrap-sha` are one-shot cutover
Expand Down
20 changes: 3 additions & 17 deletions .github/workflows/security-scans.yml
Original file line number Diff line number Diff line change
Expand Up @@ -221,6 +221,9 @@ jobs:
# .github/workflows/*.yml for token-permission, injection, and pinning
# issues. GitHub's default setup was auto-enabling this on the side; make
# it explicit here so the job history is versioned with the repo.
# ADR-1389: Make CodeQL (Actions) run unconditionally on every PR and master push
# so that OSSF Scorecard's SAST check detects a SAST tool run on 100% of commits
# (including docs-only PRs) cheaply (~15-20s) without weakening any gate.
codeql-actions:
if: github.event_name != 'pull_request' || github.event.pull_request.draft == false
# required-aggregator
Expand All @@ -234,29 +237,12 @@ jobs:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- name: Plan CI impact (ADR-1140)
id: impact
env:
EVENT_NAME: ${{ github.event_name }}
BASE_SHA: ${{ github.event.pull_request.base.sha || github.event.before }}
HEAD_SHA: ${{ github.event.pull_request.head.sha || github.sha }}
run: |
python3 scripts/ci/plan-ci-impact.py --event "$EVENT_NAME" \
--base "$BASE_SHA" --head "$HEAD_SHA" --github-output "$GITHUB_OUTPUT"
- name: Not impacted — CodeQL (Actions) skipped by plan
if: steps.impact.outputs.actions != 'true'
env:
MODE: ${{ steps.impact.outputs.mode }}
REASON: ${{ steps.impact.outputs.reason }}
run: echo "::notice::actions not impacted (mode=$MODE reason=$REASON) — CodeQL (Actions) satisfied without running (ADR-1140)"
- uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
if: steps.impact.outputs.actions == 'true'
with:
languages: actions
queries: security-and-quality
config-file: ./.github/codeql-config.yml
- uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.2
if: steps.impact.outputs.actions == 'true'
with:
category: "/language:actions"

Expand Down
14 changes: 14 additions & 0 deletions .pre-commit-config.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -266,6 +266,20 @@ repos:
pass_filenames: false
always_run: true

- id: check-no-non-header-includes
name: Guard against non-header includes in core/test
entry: scripts/ci/check-no-non-header-includes.sh
language: script
files: '^core/test/.*\.(c|cpp)$'
pass_filenames: true

- id: test-check-no-non-header-includes
name: Unit test for check-no-non-header-includes.sh
entry: bash scripts/ci/tests/test-check-no-non-header-includes.sh
language: system
files: '^scripts/ci/(check-no-non-header-includes\.sh|tests/test-check-no-non-header-includes\.sh)$'
pass_filenames: false

- id: reuse-lint
name: REUSE 3.3 license and copyright compliance (BUG-003)
entry: reuse lint
Expand Down
17 changes: 17 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -477,6 +477,23 @@
unchanged.


- **CodeQL include-non-header alert #1309 resolved with internal test accessors and CI guard.**
`core/test/test_feature_backend_twin.c` linked directly against `libvmaf` instead
of unity-including `core/src/libvmaf.c`. Narrow internal accessors
(`vmaf_backend_twin_verdict_for_test`, `vmaf_context_fake_backend_for_test`,
`vmaf_context_set_gpumask_for_test`, `vmaf_context_append_registered_feature_extractor_for_test`,
and `vmaf_context_resolve_context_fallbacks_for_test`) are declared in
`core/src/libvmaf_priv.h` with static definitions in `core/src/libvmaf.c`. A new
`scripts/ci/check-no-non-header-includes.sh` check runs in pre-commit and CI to
prevent non-header source file inclusions under `core/test/`.
- **Scorecard SAST alert #6 resolved by running CodeQL Actions universally on every PR.**
Scorecard's `sastToolInCheckRuns` evaluates PR head commits across the last 30 commits
on master. Under [ADR-1389](docs/adr/1389-codeql-actions-universal-pr-sast.md),
`CodeQL (Actions)` now runs unconditionally on all pull requests and pushes,
providing 100% commit SAST coverage across docs-only and non-code PRs with
negligible (~15–20s) overhead, and is enforced in the required checks aggregator.


- **`float_motion_cuda` emits `motion3`, like the CPU `float_motion`.** The
CUDA twin wrote `motion` and `motion2` only, so `--backend cuda --feature
float_motion` lost `VMAF_feature_motion3_score` without a warning. It now
Expand Down
15 changes: 15 additions & 0 deletions changelog.d/fixed/code-scanning-include-and-sast.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
- **CodeQL include-non-header alert #1309 resolved with internal test accessors and CI guard.**
`core/test/test_feature_backend_twin.c` linked directly against `libvmaf` instead
of unity-including `core/src/libvmaf.c`. Narrow internal accessors
(`vmaf_backend_twin_verdict_for_test`, `vmaf_context_fake_backend_for_test`,
`vmaf_context_set_gpumask_for_test`, `vmaf_context_append_registered_feature_extractor_for_test`,
and `vmaf_context_resolve_context_fallbacks_for_test`) are declared in
`core/src/libvmaf_priv.h` with static definitions in `core/src/libvmaf.c`. A new
`scripts/ci/check-no-non-header-includes.sh` check runs in pre-commit and CI to
prevent non-header source file inclusions under `core/test/`.
- **Scorecard SAST alert #6 resolved by running CodeQL Actions universally on every PR.**
Scorecard's `sastToolInCheckRuns` evaluates PR head commits across the last 30 commits
on master. Under [ADR-1389](docs/adr/1389-codeql-actions-universal-pr-sast.md),
`CodeQL (Actions)` now runs unconditionally on all pull requests and pushes,
providing 100% commit SAST coverage across docs-only and non-code PRs with
negligible (~15–20s) overhead, and is enforced in the required checks aggregator.
72 changes: 72 additions & 0 deletions core/src/libvmaf.c
Original file line number Diff line number Diff line change
Expand Up @@ -4099,4 +4099,76 @@ int vmaf_context_flush_for_test(VmafContext *vmaf)
return vmaf ? flush_context(vmaf) : -EINVAL;
}

int vmaf_backend_twin_verdict_for_test(const VmafFeatureExtractor *twin, const VmafDictionary *opts,
const VmafPictureConfiguration *pic_cfg,
const char **unsupported_option)
{
return backend_twin_verdict(twin, opts, pic_cfg, unsupported_option);
}

unsigned vmaf_context_fake_backend_for_test(VmafContext *vmaf, void *token)
{
if (!vmaf)
return 0;
#if defined(HAVE_SYCL)
vmaf->sycl.state = token;
return VMAF_FEATURE_EXTRACTOR_SYCL;
#elif defined(HAVE_CUDA)
vmaf->cuda.state.ctx = (CUcontext)token;
return VMAF_FEATURE_EXTRACTOR_CUDA;
#elif defined(HAVE_HIP)
vmaf->hip.state = token;
return VMAF_FEATURE_EXTRACTOR_HIP;
#elif defined(HAVE_METAL)
vmaf->metal.state = token;
return VMAF_FEATURE_EXTRACTOR_METAL;
#else
(void)token;
return 0;
#endif
}

void vmaf_context_set_gpumask_for_test(VmafContext *vmaf, unsigned gpumask)
{
if (vmaf)
vmaf->cfg.gpumask = gpumask;
}

int vmaf_context_append_registered_feature_extractor_for_test(VmafContext *vmaf,
const VmafFeatureExtractor *fex,
bool allow_context_fallback)
{
if (!vmaf || !fex)
return -EINVAL;
VmafFeatureExtractorContext *ctx = NULL;
int err = vmaf_feature_extractor_context_create(&ctx, fex, NULL);
if (err)
return err;
ctx->allow_context_fallback = allow_context_fallback;
RegisteredFeatureExtractors *rfe = &(vmaf->registered_feature_extractors);
err = feature_extractor_vector_append(rfe, ctx, 0);
if (err) {
(void)vmaf_feature_extractor_context_destroy(ctx);
return err;
}
#ifdef HAVE_CUDA
vmaf->rfe_hw_flags_dirty = true;
#endif
return 0;
}

int vmaf_context_resolve_context_fallbacks_for_test(VmafContext *vmaf,
const VmafPictureConfiguration *pic_cfg)
{
if (!vmaf)
return -EINVAL;
if (pic_cfg) {
vmaf->pic_params.w = pic_cfg->pic_params.w;
vmaf->pic_params.h = pic_cfg->pic_params.h;
vmaf->pic_params.bpc = pic_cfg->pic_params.bpc;
vmaf->pic_params.pix_fmt = pic_cfg->pic_params.pix_fmt;
}
return resolve_context_fallbacks(vmaf);
}

/* NOLINTEND(modernize-use-nullptr) */
21 changes: 21 additions & 0 deletions core/src/libvmaf_priv.h
Original file line number Diff line number Diff line change
Expand Up @@ -22,10 +22,16 @@

#ifdef __cplusplus
using VmafContext = struct VmafContext;
using VmafFeatureExtractor = struct VmafFeatureExtractor;
using VmafDictionary = struct VmafDictionary;
using VmafPictureConfiguration = struct VmafPictureConfiguration;

extern "C" {
#else
typedef struct VmafContext VmafContext;
typedef struct VmafFeatureExtractor VmafFeatureExtractor;
typedef struct VmafDictionary VmafDictionary;
typedef struct VmafPictureConfiguration VmafPictureConfiguration;
#endif

/*
Expand All @@ -44,6 +50,21 @@ bool vmaf_context_has_thread_pool(const VmafContext *vmaf);
int vmaf_context_flush_threaded_for_test(VmafContext *vmaf);
int vmaf_context_flush_for_test(VmafContext *vmaf);

/*
* Test accessors for ADR-1359 device-twin lookup, gpumask gating,
* registered feature extractor inspection, and context fallback resolution.
*/
int vmaf_backend_twin_verdict_for_test(const VmafFeatureExtractor *twin, const VmafDictionary *opts,
const VmafPictureConfiguration *pic_cfg,
const char **unsupported_option);
unsigned vmaf_context_fake_backend_for_test(VmafContext *vmaf, void *token);
void vmaf_context_set_gpumask_for_test(VmafContext *vmaf, unsigned gpumask);
int vmaf_context_append_registered_feature_extractor_for_test(VmafContext *vmaf,
const VmafFeatureExtractor *fex,
bool allow_context_fallback);
int vmaf_context_resolve_context_fallbacks_for_test(VmafContext *vmaf,
const VmafPictureConfiguration *pic_cfg);

#ifdef __cplusplus
}
#endif
Expand Down
12 changes: 5 additions & 7 deletions core/test/meson.build
Original file line number Diff line number Diff line change
Expand Up @@ -464,16 +464,14 @@ test_feature_collector = executable('test_feature_collector',
)

# ADR-1359: device-twin lookup for a CPU extractor name and the registered-
# extractor report. White-box (includes libvmaf.c) like test_feature_collector;
# a stand-in state pointer selects the compiled backend without a device.
# extractor report. Calls internal test accessors in libvmaf_priv.h to assert
# twin verdicts, gpumask behavior, and context fallbacks.
test_feature_backend_twin = executable('test_feature_backend_twin',
['test.c', 'test_feature_backend_twin.c', '../src/metadata_handler.cpp', rev_target],
['test.c', 'test_feature_backend_twin.c'],
include_directories : [libvmaf_inc, test_inc, include_directories('../src/feature/'), include_directories('../src')],
link_with : [get_option('default_library') == 'both' ? libvmaf.get_static_lib() : libvmaf,
log_cpp23_lib],
link_with : [get_option('default_library') == 'both' ? libvmaf.get_static_lib() : libvmaf],
c_args : vmaf_cflags_common,
dependencies: [pthread_dependency, predict_test_dependencies],
objects : [libsvm_static_lib.extract_all_objects(recursive: true)] + wave8_cpp23_objects,
dependencies: [pthread_dependency],
)

# Finding R2-10: flush_context terminal-flush ordering. White-box test that
Expand Down
Loading
Loading