Public bug reported: [ Impact ]
* The rocalution 10.0-0ubuntu1 test suite (rocalution-test, run via debian/tests/upstream-binaries during dh_auto_test / autopkgtest) contains a stack buffer overflow in testing_extract_coarse_mapping() (clients/include/testing_local_vector.hpp). The test declares 3-element `index` and `map` arrays but calls `LocalVector::ExtractCoarseMapping(0, 5, index, 3, &size, map)`, which reads/writes 5 elements (end - start = 5) of both arrays. This is undefined behaviour: on amd64/arm64 it happens not to corrupt anything observable, but on ppc64el the differing stack layout causes the overflow to clobber adjacent stack data, crashing the rocalution-test binary with a segfault during dh_auto_test and blocking the build/test on that architecture, as can be seen on (https://launchpadlibrarian.net/878532915/buildlog_ubuntu-stonking-ppc64el.rocalution_10.0-0ubuntu1_BUILDING.txt.gz). * Patch 0002-fix-testing_extract_coarse_mapping-stack-overflow.patch enlarges `index` and `map` to 5 elements (matching the actual range used) and populates `index` with the full 0..4 sequence, eliminating the out-of-bounds access while preserving the test's intent. This is a test-only fix; no library source, ABI, or public API is touched. [ Test Plan ] 1. Build: - dpkg-buildpackage / sbuild succeeds on amd64, arm64, and ppc64el. - dh_auto_test completes without rocalution-test crashing/segfaulting on ppc64el. 2. Installability: - apt install librocalution1 librocalution1-tests. - Reverse dependencies remain installable without rebuild (no ABI change). 3. Autopkgtest: - Run the autopkgtest suite (Test-Command: debian/tests/upstream-binaries librocalution1-tests) on amd64, arm64, and ppc64el. - Output: <TBD — paste autopkgtest run results here> [ Where problems could occur ] * The change only widens two local test arrays and adds explicit initializer values; it does not alter the ExtractCoarseMapping implementation itself, so risk is limited to the test binary. A plausible regression would be the test now passing a differently shaped index array and silently exercising a different code path in ExtractCoarseMapping, though the range (0..5) and count (5) passed to the call are unchanged, so behaviour of the function under test is equivalent. * If a future upstream merge reintroduces the original undersized arrays during a version bump, the same ppc64el crash could reappear; the patch should be re-checked against upstream test sources at that time. [ Other Info ] * No ABI/symbols impact: this is a test-source-only change (clients/include/testing_local_vector.hpp), not shipped in any binary package's public interface. * Forwarded: * Target: resolute 26.10 ** Affects: rocalution (Ubuntu) Importance: Undecided Status: New ** Summary changed: - testing_extract_coarse_mapping test crash on ppc65el + testing_extract_coarse_mapping test crash on ppc64el -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2168844 Title: testing_extract_coarse_mapping test crash on ppc64el To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/rocalution/+bug/2168844/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
