Skip to content

Potential fix for code scanning alert no. 5: Multiplication result converted to larger type - #797

Merged
PabloCarmona merged 3 commits into
masterfrom
alert-fix-cast-int
Sep 30, 2026
Merged

PabloCarmona merged 3 commits into
masterfrom
alert-fix-cast-int

Conversation

@PabloCarmona

Copy link
Copy Markdown
Collaborator

Potential fix for https://github.com/IBM/aihwkit/security/code-scanning/5

To fix this without changing functionality, ensure the multiplication for indexing is done in size_t (the vector index type) rather than int.
Specifically in src/rpucuda/rpu_onesided_device.cpp at the refreshWeights() loop, replace:

  • &refresh_vecs_[j_col * this->x_size_]

with:

  • &refresh_vecs_[static_cast<size_t>(j_col) * static_cast<size_t>(this->x_size_)]

This preserves logic while preventing intermediate int overflow in the multiplication. No new methods or dependencies are needed. No import changes are required.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

@PabloCarmona
PabloCarmona marked this pull request as ready for review September 29, 2026 08:56
PabloCarmona and others added 2 commits September 30, 2026 09:59
…nverted to larger type

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Pablo Carmona Gonzalez <pablocarmonagonzalez@gmail.com>
Signed-off-by: Pablo Carmona Gonzalez <pablocarmonagonzalez@gmail.com>
Signed-off-by: Pablo Carmona Gonzalez <pablocarmonagonzalez@gmail.com>
@PabloCarmona
PabloCarmona merged commit a1d5875 into master Sep 30, 2026
11 checks passed
@PabloCarmona
PabloCarmona deleted the alert-fix-cast-int branch September 30, 2026 11:14
PabloCarmona added a commit that referenced this pull request Sep 30, 2026
…nverted to larger type (#797)

* Potential fix for code scanning alert no. 5: Multiplication result converted to larger type

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Pablo Carmona Gonzalez <pablocarmonagonzalez@gmail.com>

* fix(rpucuda): cast size_t for refresh vector resizing

Signed-off-by: Pablo Carmona Gonzalez <pablocarmonagonzalez@gmail.com>

* fix(periphery): simplify input_range assignment logic

Signed-off-by: Pablo Carmona Gonzalez <pablocarmonagonzalez@gmail.com>

---------

Signed-off-by: Pablo Carmona Gonzalez <pablocarmonagonzalez@gmail.com>
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Pablo Carmona Gonzalez <pablocarmonagonzalez@gmail.com>
PabloCarmona added a commit that referenced this pull request Sep 30, 2026
…nverted to larger type (#802)

* Potential fix for code scanning alert no. 1: Multiplication result converted to larger type

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Pablo Carmona Gonzalez <pablocarmonagonzalez@gmail.com>

* Potential fix for code scanning alert no. 5: Multiplication result converted to larger type (#797)

* Potential fix for code scanning alert no. 5: Multiplication result converted to larger type

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Pablo Carmona Gonzalez <pablocarmonagonzalez@gmail.com>

* fix(rpucuda): cast size_t for refresh vector resizing

Signed-off-by: Pablo Carmona Gonzalez <pablocarmonagonzalez@gmail.com>

* fix(periphery): simplify input_range assignment logic

Signed-off-by: Pablo Carmona Gonzalez <pablocarmonagonzalez@gmail.com>

---------

Signed-off-by: Pablo Carmona Gonzalez <pablocarmonagonzalez@gmail.com>
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Pablo Carmona Gonzalez <pablocarmonagonzalez@gmail.com>

---------

Signed-off-by: Pablo Carmona Gonzalez <pablocarmonagonzalez@gmail.com>
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant