Fix out-of-bounds memory access in reflection_pad3d
Fixes #145258
Problem
reflection_pad3d accessed padding[0-5] before validating the array had 6 elements, causing out-of-bounds reads and crashes with invalid input.
# Before: crash or undefined behavior
torch.nn.functional.reflection_pad3d(tensor, (1,))
# After: clear error
RuntimeError: padding size is expected to be 6, but got: 1Root Cause
The validation check existed but ran after accessing array elements:
int64_t pad_left = padding[0]; // Accesses padding[0-5] first
// ...
check_valid_input<3>(input, padding); // Validates too lateSolution
Moved check_valid_input<3> before array access. Also updated reflection_pad3d_backward error message to show actual padding size.
Testing
Added tests for invalid padding sizes: empty (), length 1, 5, and 7. All existing tests pass.
Security
This issue can be reproduced using AddressSanitizer. While this is not a critical security vulnerability, fixing this improves stability and provides clear error messages instead of mysterious crashes when users make mistakes.
Previous Behavior
reflection_pad3d assumed that padding always contained 6 values and directly accessed padding[0] through padding[5]. When a shorter tuple was provided, this could result in out-of-bounds memory access, leading to undefined behavior such as segmentation faults, crashes, or other unpredictable results.
Examples:
torch.nn.functional.reflection_pad3d(torch.randn(1, 1, 3, 3, 3), ())
torch.nn.functional.reflection_pad3d(torch.randn(1, 1, 3, 3, 3), (1,))
torch.nn.functional.reflection_pad3d(torch.randn(1, 1, 3, 3, 3), (1, 1, 1, 1, 1))Possible outcomes included:
- Segmentation faults
- Out-of-bounds memory reads
- Undefined behavior
- Unpredictable crashes or incorrect results
New Behavior
The implementation now validates the length of the padding tuple before accessing its elements. If the tuple does not contain exactly 6 values, a clear error is raised:
RuntimeError: padding size is expected to be 6, but got: <actual_size>
Examples:
RuntimeError: padding size is expected to be 6, but got: 0
RuntimeError: padding size is expected to be 6, but got: 1
RuntimeError: padding size is expected to be 6, but got: 5
@pytorchbot label "module: nn" "module: cpp" "module: error checking" "module: crash" "topic: fuzzer"
Pull Request resolved: #185614
Approved by: https://github.com/soulitzer