Repository navigation
fix(libvmaf,dnn): vmaf_init double-init guard + vmaf_close pointer-zero + DNN fallback path - #642
Merged
lusoris merged 1 commit intoJun 4, 2026
Conversation
…ntract + DNN fp32 fallback (ADR-1032) Rebased onto master (post-PR#638, PR#641 squash) — resolved UNION conflicts in docs/adr/README.md, docs/rebase-notes.md, docs/state.md only. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris
force-pushed
the
fix/vmaf-init-double-init-guard-vmaf-close-pointer-contract
branch
from
June 4, 2026 04:22
cbeb592 to
74ce2f3
Compare
lusoris
marked this pull request as ready for review
June 4, 2026 04:22
lusoris
deleted the
fix/vmaf-init-double-init-guard-vmaf-close-pointer-contract
branch
June 4, 2026 04:22
lusoris
added a commit
that referenced
this pull request
Jun 4, 2026
…tion vertical halo (ADR-1030) (#639) Rebased onto master (post-PR#638, #641, #642, #637, #640 squash) — resolved UNION conflicts in docs/adr/README.md, docs/rebase-notes.md, docs/state.md; no code conflicts. Co-authored-by: Lusoris <lusoris@pm.me> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
This was referenced Jun 4, 2026
lusoris
added a commit
that referenced
this pull request
Jun 6, 2026
…p32-fallback (#705) PR #642 (ADR-1032) changed vmaf_dnn_session_open to silently fall back to fp32 when the .int8.onnx sibling is missing, but the test was not updated to match. The test was asserting rc < 0 (hard error) while the new policy returns rc == 0 (degraded-but-working fallback). Rename test_session_open_int8_missing_returns_error → test_session_open_int8_missing_falls_back_to_fp32 and flip the assertions to verify the fp32 fallback succeeds and produces a usable session. Fixes CI failure: libvmaf:dnn / test_dnn_session_api FAIL (exit status 1). Co-authored-by: Lusoris <lusoris@pm.me> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
core/src/libvmaf.c):vmaf_initunconditionally overwrote*vmafeven when non-NULL, silently leaking the old context (feature extractor vector, collector, thread pool, DNN session, picture pool, GPU state). Fix: return-EINVALwhen*vmaf != NULL(SEI CERT MEM31-C).core/include/libvmaf/libvmaf.h):vmaf_closefrees its argument but cannot zero the caller's variable; a second call passes a non-NULL freed pointer past the NULL guard (UAF). ABI change would break all consumers; instead the pointer-invalidity contract and null-after-close pattern are documented in the Doxygen block.core/src/dnn/dnn_api.c:107): when.int8.onnxsidecar was absent or failed validation,vmaf_dnn_session_openreturned the error instead of falling through to the fp32 baseline, contrary to the "better degraded than dead" comment. Fix:rc = 0; /* fall through */, preservinghas_sidecar/meta; adds aVMAF_LOG_LEVEL_DEBUGdegradation message.core/test/): six test files declaredVmafContext *vmaf;without initializing to NULL — stack garbage would have triggered the new double-init guard spuriously. Fixed toVmafContext *vmaf = NULL;across all six files.ADR
ADR-1032
ADR-0108 deliverables checklist
meson test -C build --suite=fast(test_vmaf_init_double_init_guard in core/test/test_context.c)changelog.d/fixed/vmaf-init-double-init-guard-vmaf-close-contract-dnn-fp32-fallback.mddocs/rebase-notes.md(top entry: no rebase impact — fork-local fix, no upstream equivalent)Test plan
ninja -C build-wf test/test_context && build-wf/test/test_context— 3 tests pass (including newtest_vmaf_init_double_init_guard)test_feature_collector,test_locale_handling,test_output,test_pic_preallocation— all passtest_opt,test_adm_coverage,test_iqa_helpers) are unrelated to this PR (pdjson dependency); confirmed present on master before this changeFiles changed
core/src/libvmaf.c— double-init guard invmaf_initcore/src/dnn/dnn_api.c— fp32 fallback fix +log.hincludecore/include/libvmaf/libvmaf.h—vmaf_closepointer-contract documentationcore/test/test_context.c— newtest_vmaf_init_double_init_guardtest + NULL-initcore/test/test_feature_collector.c,test_locale_handling.c,test_output.c,test_pic_preallocation.c,test_cuda_pic_preallocation.c— NULL-init sweepdocs/adr/1032-*.md,docs/adr/README.md,docs/rebase-notes.md,docs/state.md,changelog.d/fixed/— deliverables🤖 Generated with Claude Code