Fix out-of-range integer brng reading past brng_list - #177
vchamarthi wants to merge 5 commits into
Conversation
|
@vchamarthi Seems it can still be broken for We should fix that here too |
With no stream yet, irk_get_brng_and_stream_mkl returned -1, which then indexed brng_list out of bounds and left the state holding uninitialized memory.
Fixed in 6d3fa4b. It's broader than Is defaulting to MT19937 OK, or would you rather |
Defaulting to MT19937 seems fine |
| * Extended the `memcpy`-based fast path of `shuffle` to multi-dimensional `ndarray` inputs whose first-axis items are contiguous, which is also much faster than the previous buffered path [gh-159](https://github.com/IntelPython/mkl_random/pull/159) | ||
|
|
||
| ### Fixed | ||
| * Fixed an out-of-range integer `brng` indexing `brng_list` past its end, which returned uninitialized memory as random values; it now warns and falls back to `MT19937` |
Issue
brng_listhasBRNG_KINDS= 11 entries,irk_brng_tdefines 0–10. The integerpath of
_parse_brng_token_coerced the user value straight toirk_brng_t, whichonly checks it fits the enum's underlying integer type. The seeding routines then
index
brng_list[brng].brng=11returned uninitialized memory, no warning, no error:brng=15raised an oneMKL error;brng=-1was accepted as a negative index.Separately,
if (brng):treatedbrng=0as unset, but0isMT19937:How found
Coverity Scan CID 653949,
OVERRUN: "Overrunning callee's array of size 11 bypassing argument
__pyx_v_brng_token(which evaluates to 15) in call toirk_randomseed_mkl". Confirmed againstrandomkit.h:50,randomkit.cpp:111andthe
.pyxcall path, then reproduced per-process on a build ofmaster. Thebrng=0bug surfaced while writing the boundary test.Distinct from the
_seed_implOUT_OF_BOUNDSfinding already dismissed incoverity/README.md, which is the tuple unpack and is a false positive.Fix
BRNG_KINDSfromrandomkit.hso the bound tracks the C table.MT19937,as an unrecognized generator name already does.
brng is not Noneinstead of truthiness, sobrng=0is honoured.Tests
5 out-of-range values assert warn plus fallback;
0and10assert accepted,silent, and equal to the same generator selected by name.