Repository navigation
Fix uninitialized read in lut_map on networks with dangling nodes - #707
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #707 +/- ##
=======================================
Coverage 84.08% 84.09%
=======================================
Files 191 191
Lines 29575 29579 +4
=======================================
+ Hits 24867 24873 +6
+ Misses 4708 4706 -2 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
It seems to include various unrelated changes. Can you trim those or split into other PRs to help me review? |
|
Also FYI I'm going to update fmt to a newer version (12.1.0). |
`cut() = default` leaves `_length`, `_cend` and `_end` indeterminate. A default-constructed cut is reachable: `cut_set` and `lut_cut_set` hold an array of them and `best()` returns `*_pcuts[0]` whether or not any cut has been inserted. `lut_map_impl::compute_share_mapping_init` iterates over every node index and calls `best()`, and a node unreachable from the outputs is never visited by the cut enumerator, so its cut set is empty and the following `for ( auto leaf : cut )` in `compute_cut_data` walks a garbage end pointer and indexes `cuts[leaf]` with whatever it finds. Networks with unreachable nodes are not exotic: ABC's `&dch -f; &put` leaves the choice-class members in as ordinary AND nodes, so every AIG written by the standard `strash; &get; &dch -f; &put; write_aiger` front end has them (cavlc: 1271 ANDs written, 647 reachable). Give the default constructor a defined empty state, and add a lut_mapper test that maps a six-gate AIG whose last four gates drive no output.
8d96a76 to
f512088
Compare
Sorry for the mess. That was of course unintended. I got quite some local changes into the PR on accident. It's cleaned up now. |
lut_map on networks with dangling nodes
|
Maybe it is a negligible overhead, but isn't setting the constructor to |
|
That’s a fair point. I benchmarked both approaches on five EPFL circuits and found small, mixed differences in total mapping time, with no consistent advantage either way. Initializing only the first cut in |
e543cc3 to
3586273
Compare
Area-oriented
lut_mapcan read uninitialized memory and crash when a network contains nodes unreachable from its outputs, because mapping initialization accesses those nodes' empty cut sets throughbest(). Initialize only the first cut's leaf range and metadata incut_set::clear()andlut_cut_set::clear(), keeping the defaultcutconstructor and providing a defined empty cut after construction or clearing. The dangling-node regression and new tests for fresh and cleared, previously populated cut sets pass locally alongside the cut-enumeration tests (30 test cases, 218 assertions).