Skip to content

Potential fix for code scanning alert no. 1: Multiplication result converted to larger type - #802

Merged
PabloCarmona merged 3 commits into
masterfrom
alert-autofix-1
Sep 30, 2026
Merged

PabloCarmona merged 3 commits into
masterfrom
alert-autofix-1

Conversation

@PabloCarmona

Copy link
Copy Markdown
Collaborator

Potential fix for https://github.com/IBM/aihwkit/security/code-scanning/1

To fix this class of issue, ensure multiplication is performed in the larger destination type, not in int. In practice: cast one (or both) operands to std::size_t (or std::vector<T>::size_type) before multiplying, so arithmetic is widened prior to evaluation.

Best minimal fix in this file is to change the vector initialization in RPUSimple<T>::dumpExtra so the product is computed as size_t:

  • File: src/rpucuda/rpu.cpp
  • Region: around line 412 in RPUSimple<T>::dumpExtra
  • Replace:
    • V tmp(this->x_size_ * this->d_size_);
  • With:
    • V tmp(static_cast<typename V::size_type>(this->x_size_) * static_cast<typename V::size_type>(this->d_size_));

Using typename V::size_type keeps the type aligned with the vector’s expected size type and avoids assumptions about platform widths.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

@PabloCarmona
PabloCarmona marked this pull request as ready for review September 30, 2026 08:01
PabloCarmona and others added 2 commits September 30, 2026 13:16
…nverted to larger type

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Pablo Carmona Gonzalez <pablocarmonagonzalez@gmail.com>
…nverted to larger type (#797)

* Potential fix for code scanning alert no. 5: Multiplication result converted to larger type

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Pablo Carmona Gonzalez <pablocarmonagonzalez@gmail.com>

* fix(rpucuda): cast size_t for refresh vector resizing

Signed-off-by: Pablo Carmona Gonzalez <pablocarmonagonzalez@gmail.com>

* fix(periphery): simplify input_range assignment logic

Signed-off-by: Pablo Carmona Gonzalez <pablocarmonagonzalez@gmail.com>

---------

Signed-off-by: Pablo Carmona Gonzalez <pablocarmonagonzalez@gmail.com>
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Pablo Carmona Gonzalez <pablocarmonagonzalez@gmail.com>
@PabloCarmona
PabloCarmona merged commit 705ef77 into master Sep 30, 2026
11 checks passed
@PabloCarmona
PabloCarmona deleted the alert-autofix-1 branch September 30, 2026 11:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant