Skip to content

Guard SubbinSizes::exclusive_scan against negative delta - #3885

Merged
SimonHeybrock merged 4 commits into
mainfrom
fix-subbin-sizes-exclusive-scan-negative-delta
Apr 15, 2026
Merged

SimonHeybrock merged 4 commits into
mainfrom
fix-subbin-sizes-exclusive-scan-negative-delta

Conversation

@SimonHeybrock

Copy link
Copy Markdown
Member

Summary

  • SubbinSizes::exclusive_scan had a potential out-of-bounds read when x.offset() < offset() (negative delta). The >= osize check does not catch negative indices, leading to UB.
  • Analysis of the binning pipeline confirms this cannot happen in practice: varying offsets only arise via sorted input coordinates, which guarantees non-decreasing offsets along the accumulation dimension. Existing results are unaffected.
  • Added a std::logic_error guard so the UB becomes an explicit error if assumptions ever break.

Closes #3879

🤖 Generated with Claude Code

Add a check that throws std::logic_error if x.offset() < offset(),
which would cause an out-of-bounds read at a negative index.

Analysis of the binning pipeline confirms this cannot happen in
practice (sorted-input preconditions guarantee non-decreasing offsets),
so existing results are unaffected. The guard turns latent UB into an
explicit error if assumptions ever break.

Closes #3879

Co-Authored-By: Claude Opus 4.6 <[email protected]>
@SimonHeybrock
SimonHeybrock enabled auto-merge April 13, 2026 08:56
@SimonHeybrock
SimonHeybrock merged commit 839ff74 into main Apr 15, 2026
4 checks passed
@SimonHeybrock
SimonHeybrock deleted the fix-subbin-sizes-exclusive-scan-negative-delta branch April 15, 2026 08:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SubbinSizes::exclusive_scan out-of-bounds read with negative index

3 participants