Skip to content

Validate inline raw initializer size before unpacking - #32866

Draft
danielsongmicrosoft wants to merge 1 commit into
microsoft:mainfrom
danielsongmicrosoft:user/danielsongmicrosoft/onnxruntime-robustness-df213aa3a296
Draft

danielsongmicrosoft wants to merge 1 commit into
microsoft:mainfrom
danielsongmicrosoft:user/danielsongmicrosoft/onnxruntime-robustness-df213aa3a296

Conversation

@danielsongmicrosoft

Copy link
Copy Markdown
Contributor

Summary

  • Validate inline raw initializer bytes against the declared shape before allocation and unpacking.
  • Return a model validation error for mismatched raw data sizes.

Validation

  • Warnings-as-errors build completed successfully.
  • Focused inline raw-data size mismatch tests passed.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused validation is correctly placed before unpacking and has appropriate regression coverage.

Review effort: Balanced
Findings: None

What changed in this PR

Validates inline raw initializer sizes before unpacking, preventing shape/data mismatches from propagating.

Changes:

  • Adds raw-data size validation to UnpackInitializerData.
  • Adds regression coverage and updates the sparse-tensor error expectation.
File Description
onnxruntime/​core/​framework/​tensorprotoutils.cc Validates inline raw data before unpacking.
onnxruntime/​test/​framework/​tensorutils_test.cc Tests rejection of mismatched inline raw data.
onnxruntime/​test/​framework/​sparse_kernels_test.cc Updates the expected validation error.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants