Repository navigation
fix(test): run the GPU pool UAF test without MALLOC_PERTURB_ so it cannot fill the host's memory - #2547
Merged
Conversation
lusoris
added a commit
that referenced
this pull request
Oct 7, 2026
…nnot fill the host's memory (#2547) * fix(test): run the GPU pool UAF test without MALLOC_PERTURB_ so it cannot fill the host's memory test_gpu_picture_pool_uaf asks the pool for about 192 GB to reach the allocation-failure cleanup. Meson sets a random MALLOC_PERTURB_ for each test, so glibc writes every byte it hands out; on a host with vm.overcommit_memory = 1 the request succeeds and the fill takes all RAM and swap. The test now runs with MALLOC_PERTURB_=0; its two cases are unchanged. * docs(state): cite PR #2547 in the GPU pool test row
lusoris
force-pushed
the
fix/gpu-pool-uaf-test-perturb
branch
from
October 7, 2026 23:36
1e3fade to
6fed045
Compare
lusoris
added a commit
that referenced
this pull request
Oct 8, 2026
…2548 landed twice Signed-off-by: Lusoris <lusoris@proton.me> #2548 landed the merge train's squash of its first revision, which still carried its own MALLOC_PERTURB_=0 entry for test_gpu_picture_pool_uaf and a state row for the same bug; #2547 had already landed both. core/test/meson.build now lists the entry once (#2547's), docs/state.md keeps T-GPU-POOL-UAF-TEST-FILLS-HOST-MEMORY-2026-10-08 only, and the #2548 changelog and rebase-note fragments no longer claim that fix.
This was referenced Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
test_gpu_picture_pool_uaf(suitefast) can take all of a host's RAM and swap. It now runs withMALLOC_PERTURB_=0, and its two cases are unchanged.The test asks
vmaf_gpu_picture_pool_init()for 0x7FFFFFFF pictures, about 192 GB, to reach the allocation-failure cleanup. Meson sets a randomMALLOC_PERTURB_for every test, so glibc fills each allocation it returns. On a host withvm.overcommit_memory = 1the request succeeds and the fill writes every byte of it. On the RC workstation (60 GB RAM + 60 GB swap) the merge train's stack gate timed out on it after 91 s (local gate failed on the stack of 5 (fast tests fail ...: test_gpu_picture_pool_uaf TIMEOUT 90.9s), 00:47 on 2026-10-08). A local gate run timed out after 32 s; both runs fill swap while they last.Meson keeps an explicit
MALLOC_PERTURB_=0and does not set its own value (mesonbuild/mtest.py: "Setting MALLOC_PERTURB_="0" will completely disable this feature"). The allocation is then not touched. The failure path and its two cases still run.Type
fix— bug fixtest— test-onlyChecklist
make format && make lintis green locally (the commit hooks pass).MALLOC_PERTURB_=88in a 3 GiB memory scope (systemd-run --scope -p MemoryMax=3G) is OOM-killed (137) after 3 s; withMALLOC_PERTURB_=0both cases pass at once.meson introspect --testson this branch shows the test's environment withMALLOC_PERTURB_: 0./cross-backend-diff. — not applicable..c/.hfile with a license header. — not applicable.Bug-status hygiene (ADR-0165)
docs/state.md:T-GPU-POOL-UAF-TEST-FILLS-HOST-MEMORY-2026-10-08opened and closed here (PR fix(test): run the GPU pool UAF test without MALLOC_PERTURB_ so it cannot fill the host's memory #2547).Netflix golden-data gate (ADR-0024)
assertAlmostEqual(...)score in the Netflix golden Python tests.Cross-backend numerical results
Not applicable: no score path changed.
Deep-dive deliverables (ADR-0108)
AGENTS.mdinvariant note — no rebase-sensitive invariants.Reproducer