已开启
[docs] 修复 aclnnCrypto 文档原型名与示例 IV 缓冲区越界读取 #131
[docs] 修复 aclnnCrypto 文档原型名与示例 IV 缓冲区越界读取 #131
已开启
NUAA_wqy创建于 8 天前
NUAA_wqy
NUAA_wqy
8 天前

描述

reliability/crypto/docs/aclnnCrypto.md 存在三处与 issue #58 对应的问题,本 MR 一并修复:

  1. 函数原型与头文件不一致:文档"函数原型"代码块写作 aclnnCryptoAicpuGetWorkspaceSize / aclnnCryptoAicpu,而 reliability/crypto/op_host/op_api/aclnn_crypto.h 实际声明为 aclnnCryptoGetWorkspaceSize / aclnnCrypto(无 Aicpu 后缀)。读者按文档原型链接会失败。本 MR 将文档原型对齐到头文件声明,与正文描述(第 35 行)及调用示例(aclnnCryptoGetWorkspaceSize / aclnnCrypto)保持一致。
  2. 示例 IV 缓冲区越界读取:iv_shape_data = {32} 但 ivHostData 仅 16 字节,CreateAclTensor 按 shape 计算 32 字节并在 aclrtMemcpy 中从 16 字节 host 向量复制 32 字节,越界读取 16 字节未定义数据,设备侧 IV 含未定义数据,加解密结果不可信。本 MR 将 ivHostData 对齐到 32 字节,从根因消除越界。
  3. CreateAclTensor 缺少 hostData 长度校验:按 issue 建议在 aclrtMalloc / aclrtMemcpy 前增加 hostData 字节数与 shape 字节数的比较,使未来再次出现 shape/hostData 不匹配时快速失败,而非产生越界 memcpy。

变更类型

关联的Issue

Fixes #58

测试

本地静态验证(无 NPU 环境下的可重复验证):

  1. 对照 reliability/crypto/op_host/op_api/aclnn_crypto.h 第 38/52 行声明,确认文档原型代码块现已与头文件一致(aclnnCryptoGetWorkspaceSize / aclnnCrypto)。
  2. 逐个核对 main 中所有 CreateAclTensor 调用点的 hostData.size()*sizeof(T) 与 GetShapeSize(shape)*sizeof(T):
    • keyHostData(16) ↔ key_shape_data={16} ✓
    • inputHostData(msg_len) ↔ input_shape_data={msg_len} ✓
    • ivHostData(32) ↔ iv_shape_data={32} ✓(本次修复后匹配)
    • opConfigHostData(6 × uint32) ↔ shape_op_cfg={6} ✓
    • outputHostData(msg_len) ↔ shape_output={msg_len} ✓
    • yHostData(1 × uint32) ↔ shape_y={1} ✓
    • tagHostData(16) ↔ shape_tag={GCM_TAG_SIZE=16} ✓
      全部调用点满足新增的长度校验,不会被误拦截。
  3. git diff 确认改动仅限 aclnnCrypto.md 一个文件,8 行新增 / 3 行删除,无无关改动。

补充的UT用例:
NA(文档示例修复,无新增 UT)

文档更新

本次即为文档修复。

合入检查

likedislike
合并受阻
NUAA_wqyNUAA_wqy
8 天前 创建了 pull request,commit 6e5783ca
NUAA_wqyNUAA_wqy
8 天前 关联了issue:[Documentation|文档反馈]: Crypto 文档原型名称错误且示例 IV 缓冲区长度不足
atomgit-bot
atomgit-bot
8 天前 评论:

变更摘要

本 PR 修复 reliability/crypto/docs/aclnnCrypto.md 文档中与 issue #58 对应的三处问题,涉及接口原型名不一致、示例中 IV 缓冲区形状与宿主数据长度不匹配导致的越界读取,以及示例 CreateAclTensor 缺少长度校验。改动将该文档的"函数原型"代码块对齐到 reliability/crypto/op_host/op_api/aclnn_crypto.h 的实际声明,将示例 ivHostData 对齐到 32 字节以消除越界,并在内存分配/拷贝前补充 hostData 字节数与 shape 字节数的比较。

主要改动

  • 函数原型对齐头文件声明: 文档"函数原型"代码块由 aclnnCryptoAicpuGetWorkspaceSize / aclnnCryptoAicpu 改为头文件实际声明的 aclnnCryptoGetWorkspaceSize / aclnnCrypto,与正文描述及调用示例一致。
  • 修复示例 IV 缓冲区越界读取: 将示例中 ivHostData 由 16 字节对齐到 32 字节,使其与 iv_shape_data = {32} 匹配,消除 aclrtMemcpy 按 shape 计算 32 字节而从宿主向量复制 32 字节造成的越界读取和未定义 IV 数据。
  • 为示例 CreateAclTensor 增加长度校验: 在 aclrtMalloc / aclrtMemcpy 之前增加 hostData 字节数与 shape 字节数的比较,使 shape 与 hostData 不匹配时快速失败,而非产生越界 memcpy。
likedislike
不准确?
atomgit-bot
atomgit-bot
8 天前 评论:

🤖 本次改动均为数据 / 生成 / 二进制文件(如测试用例、锁文件、媒体资源),没有可审查的代码逻辑,已跳过 AI 代码审查。

likedislike
不准确?
CANN-robot
CANN-robot成员
8 天前 评论:

Hi @NUAA_wqy, welcome to submitting your first PR to ops-ras!

PR Merge Steps

1. CLA Signing

If the current PR label includes cann-cla/yes, it means you have signed the CLA and can proceed to the next step. If the label includes cann-cla/no, please sign the CLA first. If you have any questions, please refer to the FAQ.

2. CI Check

Please comment /compile to trigger the CI pipeline check. If the CI run is successful, the PR will be tagged with ci-pipeline-passed and you can proceed to the next step. If the CI run fails, the PR will be tagged with ci-pipeline-failed, please check the CI logs to fix the issues in the PR. If you have any questions, please refer to the FAQ.

3. Code Review

After CI passes, please refer to the PR Approval Progress and proactively @ the committers in the table to review the code. After approval, committers will comment /lgtm and /approve. Once the lgtm and approved labels are successfully added, the PR will be merged automatically.

likedislike
CANN-robotCANN-robot成员
8 天前 添加了label:cann-cla/yes
CANN-robot
CANN-robot成员
8 天前 评论:

CLA Signature Pass

NUAA_wqy, thanks for your pull request. All authors of the commits have signed the CLA. 👍

likedislike
CANN-robot
CANN-robot成员
8 天前 评论:

Thanks for your pull-request.
The full list of commands accepted by me can be found at here.
You can get sig-info at here.
You can self-configure the PR merge rules for this repository. For more details, please refer to Here.
For more, you also can visit HICANN.


PR Approval Progress

⚠️ This PR does not yet meet the following requirements:lgtm (requires ≥ 2 person(s) per module)、approve (requires ≥ 1 person(s) per module)

Module Approval Details

module lgtm status approve status
repo-cann/ops-ras ❌ (0/2)(You can also ask: 陈兴宇, 柳宗谷, 冯彤, yue-ma, 周奇龙) ❌ (0/1)(You can also ask: 陈兴宇, 唐燕峰, 於欣洁, 冯彤, yue-ma)

💡 Tip:

  • Committer can comment /approve or /lgtm
  • Commenting /approve implies both code review (lgtm) and intent to merge (approve)
likedislike