Skip to content

Commit ca2ba48

Browse files
phil-oppclaude
andcommitted
Increase device_info name buffer to avoid stack corruption on CUDA
The name buffer in device_info matched ArrayFire's documented minimum size of 64 bytes, but af_device_info takes no length arguments and the CUDA backend ignores it. Its sanitize loop runs a fixed 256 iterations without stopping at the NUL terminator, so it reads d_name[0..256] and writes up to d_name[255] on every call, regardless of the actual device name length. That overflows the 64-byte buffer by ~193 bytes, clobbering the adjacent buffers, spilled registers, the stack cookie and the return address. Enlarge the name buffer to 1024 bytes so the call is safe against every 3.8.x backend, independent of any upstream fix. The other three buffers are left at their documented sizes; no overflow has been demonstrated for them, and they are no longer in the blast radius. Backend-side bug: arrayfire/arrayfire#3712 Fixes #384 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
1 parent bd3be3e commit ca2ba48

1 file changed

Lines changed: 8 additions & 1 deletion

File tree

src/core/device.rs

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -107,7 +107,14 @@ pub fn info_string(verbose: bool) -> String {
107107
/// # Return Values
108108
/// A tuple of `String` indicating the name, platform, toolkit and compute.
109109
pub fn device_info() -> (String, String, String, String) {
110-
let mut name: [c_char; 64] = [0; 64];
110+
// The documented minimum size for the name buffer is 64 bytes, but
111+
// `af_device_info` takes no length arguments and the CUDA backend writes up
112+
// to 257 bytes into it, corrupting the caller's stack on every call.
113+
// libarrayfire is linked dynamically and this crate never checks its
114+
// version, so an upstream fix is not on its own a reason to shrink this
115+
// back: the library resolved at runtime may still be an affected build.
116+
// See https://github.com/arrayfire/arrayfire/issues/3712
117+
let mut name: [c_char; 1024] = [0; 1024];
111118
let mut platform: [c_char; 10] = [0; 10];
112119
let mut toolkit: [c_char; 64] = [0; 64];
113120
let mut compute: [c_char; 10] = [0; 10];

0 commit comments

Comments
 (0)