Validate input rank/size for BifurcationDetector before indexing (#31701)
## Description
`BifurcationDetector` unconditionally reads and/or writes element `[0]`
of several tensors without first checking that they contain enough
elements to do so safely:
- `src_tokens`, `cur_tokens`, and `pred_tokens` are treated as flat 1-D
sequences, both via `Shape().GetDims()[0]` (their reported "length") and
via linear `DataRaw()` indexing. A 0-D (scalar) input has no dimensions,
so `GetDims()[0]` is an out-of-range access on an empty span.
- `prev_suffix_match_idx` is read at index `[0]`, and the output tensor
that mirrors its shape is written at index `[0]`, regardless of how many
elements it actually has. A 0-element input backs both of those accesses
with an empty/null buffer.
This adds explicit validation for these inputs before they are used,
returning a failure `Status` (via `ORT_RETURN_IF_NOT`) rather than
proceeding to index into a buffer that may not have enough elements:
- `src_tokens`, `cur_tokens`, and `pred_tokens` (when present) must be
1-D tensors.
- `prev_suffix_match_idx` must contain exactly one element (consistent
with how it, and the output that mirrors its shape, are used elsewhere
in the kernel).
## Testing
Added regression tests to
`onnxruntime/test/contrib_ops/bifurcation_detector_op_test.cc` covering:
- A 0-element `prev_suffix_match_idx`, both with and without
`pred_tokens` present.
- A scalar (0-D) `src_tokens`, `cur_tokens`, and `pred_tokens`, each
rejected individually.
All existing tests continue to pass unchanged.
`BifurcationDetector` is CPU-only; no other execution provider
implements this operator.
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 77dcaf1b-748a-4379-94a7-478f7a924d73