Skip to content

fix(libvmaf,dnn): vmaf_init double-init guard + vmaf_close pointer-zero + DNN fallback path - #642

Merged
lusoris merged 1 commit into
masterfrom
fix/vmaf-init-double-init-guard-vmaf-close-pointer-contract
Jun 4, 2026
Merged

lusoris merged 1 commit into
masterfrom
fix/vmaf-init-double-init-guard-vmaf-close-pointer-contract

Conversation

@lusoris

@lusoris lusoris commented Jun 4, 2026

Copy link
Copy Markdown
Contributor

Summary

  • vmaf_init double-init leak (core/src/libvmaf.c): vmaf_init unconditionally overwrote *vmaf even when non-NULL, silently leaking the old context (feature extractor vector, collector, thread pool, DNN session, picture pool, GPU state). Fix: return -EINVAL when *vmaf != NULL (SEI CERT MEM31-C).
  • vmaf_close dangling pointer contract (core/include/libvmaf/libvmaf.h): vmaf_close frees its argument but cannot zero the caller's variable; a second call passes a non-NULL freed pointer past the NULL guard (UAF). ABI change would break all consumers; instead the pointer-invalidity contract and null-after-close pattern are documented in the Doxygen block.
  • DNN fp32 fallback doesn't fall back (core/src/dnn/dnn_api.c:107): when .int8.onnx sidecar was absent or failed validation, vmaf_dnn_session_open returned the error instead of falling through to the fp32 baseline, contrary to the "better degraded than dead" comment. Fix: rc = 0; /* fall through */, preserving has_sidecar/meta; adds a VMAF_LOG_LEVEL_DEBUG degradation message.
  • Test NULL-init sweep (core/test/): six test files declared VmafContext *vmaf; without initializing to NULL — stack garbage would have triggered the new double-init guard spuriously. Fixed to VmafContext *vmaf = NULL; across all six files.

ADR

ADR-1032

ADR-0108 deliverables checklist

  • Research digest: no digest needed: targeted bug-fix
  • Decision matrix: no alternatives: only-one-way fix (ABI constraint rules out signature change for vmaf_close)
  • AGENTS.md invariant: no rebase-sensitive invariants
  • Reproducer: meson test -C build --suite=fast (test_vmaf_init_double_init_guard in core/test/test_context.c)
  • CHANGELOG fragment: changelog.d/fixed/vmaf-init-double-init-guard-vmaf-close-contract-dnn-fp32-fallback.md
  • Rebase note: docs/rebase-notes.md (top entry: no rebase impact — fork-local fix, no upstream equivalent)
  • state.md update: T-VMAF-INIT-DOUBLE-INIT-GUARD-2026-06-04 closed (three bugs, row in Recently closed)

Test plan

  • ninja -C build-wf test/test_context && build-wf/test/test_context — 3 tests pass (including new test_vmaf_init_double_init_guard)
  • test_feature_collector, test_locale_handling, test_output, test_pic_preallocation — all pass
  • Pre-existing link failures (test_opt, test_adm_coverage, test_iqa_helpers) are unrelated to this PR (pdjson dependency); confirmed present on master before this change

Files changed

  • core/src/libvmaf.c — double-init guard in vmaf_init
  • core/src/dnn/dnn_api.c — fp32 fallback fix + log.h include
  • core/include/libvmaf/libvmaf.h — vmaf_close pointer-contract documentation
  • core/test/test_context.c — new test_vmaf_init_double_init_guard test + NULL-init
  • core/test/test_feature_collector.c, test_locale_handling.c, test_output.c, test_pic_preallocation.c, test_cuda_pic_preallocation.c — NULL-init sweep
  • docs/adr/1032-*.md, docs/adr/README.md, docs/rebase-notes.md, docs/state.md, changelog.d/fixed/ — deliverables

🤖 Generated with Claude Code

…ntract + DNN fp32 fallback (ADR-1032)

Rebased onto master (post-PR#638, PR#641 squash) — resolved UNION conflicts
in docs/adr/README.md, docs/rebase-notes.md, docs/state.md only.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@lusoris
lusoris force-pushed the fix/vmaf-init-double-init-guard-vmaf-close-pointer-contract branch from cbeb592 to 74ce2f3 Compare June 4, 2026 04:22
@lusoris
lusoris marked this pull request as ready for review June 4, 2026 04:22
Copilot AI review requested due to automatic review settings June 4, 2026 04:22
@lusoris
lusoris merged commit 1958126 into master Jun 4, 2026
66 of 107 checks passed
@lusoris
lusoris deleted the fix/vmaf-init-double-init-guard-vmaf-close-pointer-contract branch June 4, 2026 04:22
lusoris added a commit that referenced this pull request Jun 4, 2026
…-precedence x2

Rebased onto master (post-PR#638, #641, #642 squash) — resolved UNION
conflicts in docs/rebase-notes.md and docs/state.md only; no code conflicts.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 4, 2026
…-precedence x2 (#637)

Rebased onto master (post-PR#638, #641, #642 squash) — resolved UNION
conflicts in docs/rebase-notes.md and docs/state.md only; no code conflicts.

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 4, 2026
…V queue sync (ADR-1034)

Rebased onto master (post-PR#638, #641, #642, #637 squash) — resolved UNION
conflicts in docs/adr/README.md, docs/rebase-notes.md, docs/state.md only;
no code conflicts.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 4, 2026
…V queue sync (ADR-1034) (#640)

Rebased onto master (post-PR#638, #641, #642, #637 squash) — resolved UNION
conflicts in docs/adr/README.md, docs/rebase-notes.md, docs/state.md only;
no code conflicts.

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 4, 2026
…tion vertical halo (ADR-1030)

Rebased onto master (post-PR#638, #641, #642, #637, #640 squash) — resolved
UNION conflicts in docs/adr/README.md, docs/rebase-notes.md, docs/state.md;
no code conflicts.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 4, 2026
…tion vertical halo (ADR-1030) (#639)

Rebased onto master (post-PR#638, #641, #642, #637, #640 squash) — resolved
UNION conflicts in docs/adr/README.md, docs/rebase-notes.md, docs/state.md;
no code conflicts.

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
@lusoris
lusoris removed the request for review from Copilot June 4, 2026 04:42
lusoris added a commit that referenced this pull request Jun 6, 2026
…p32-fallback (#705)

PR #642 (ADR-1032) changed vmaf_dnn_session_open to silently fall back to fp32
when the .int8.onnx sibling is missing, but the test was not updated to match.
The test was asserting rc < 0 (hard error) while the new policy returns rc == 0
(degraded-but-working fallback).

Rename test_session_open_int8_missing_returns_error →
test_session_open_int8_missing_falls_back_to_fp32 and flip the assertions to
verify the fp32 fallback succeeds and produces a usable session.

Fixes CI failure: libvmaf:dnn / test_dnn_session_api FAIL (exit status 1).

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
@lusoris lusoris added this to the 1.0.0 — First release milestone Sep 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant