onnxruntime
6054e361 - Fix over-copy of packed sub-byte tensors in OrtApi::GetValue (#29157)

Commit
89 days ago
Fix over-copy of packed sub-byte tensors in OrtApi::GetValue (#29157) ### Summary OrtApi::GetValue on a sequence of tensors copied elements using element_type->Size() * element_count bytes. For packed sub-byte types (INT4/UINT4, two elements per byte) this is ~2× the real storage size, causing a heap over-read of the source and overflow of the destination. ### Fix In PopulateTensorWithData (onnxruntime/core/session/onnxruntime_c_api.cc), copy the tensor's actual packed size via Tensor::SizeInBytes() instead of element_type->Size() * num_elems, and drop the now-unused elem_size parameter. SizeInBytes() is packing-aware: identical for ≥1-byte types (no behavior change) and correct for sub-byte types. ### Testing - Added CApiTest.CreateGetSeqSubByteTensors: sequences of INT4/UINT4 tensors with an odd length (7 elements → 4 packed bytes), verifying GetValue() round-trips correctly. - Full onnxruntime_shared_lib_test suite passes (185/185); other paths unchanged. - Confirmed under AddressSanitizer: the old formula triggers a heap-buffer-overflow, the new one is clean.
Author
Parents
Loading