Skip to content

Account for string payloads in initializer size limits - #32867

Open
danielsongmicrosoft wants to merge 1 commit into
microsoft:mainfrom
danielsongmicrosoft:user/danielsongmicrosoft/onnxruntime-robustness-2db75c322aca
Open

danielsongmicrosoft wants to merge 1 commit into
microsoft:mainfrom
danielsongmicrosoft:user/danielsongmicrosoft/onnxruntime-robustness-2db75c322aca

Conversation

@danielsongmicrosoft

Copy link
Copy Markdown
Contributor

Summary

  • Include string object storage and payload bytes in embedded initializer size limits.
  • Use overflow-safe cumulative accounting while preserving normal and exact-boundary payloads.

Validation

  • Warnings-as-errors build completed successfully.
  • Focused string initializer boundary tests passed.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Comment thread onnxruntime/core/framework/tensorprotoutils.h

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Two tests incorrectly assume a specific sizeof(std::string), causing portability and coverage problems.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
What changed in this PR

Adds string object and payload accounting to embedded initializer size validation.

Changes:

  • Adds overflow-safe cumulative string payload checks.
  • Preserves the existing default limit via an overload.
  • Adds boundary and normal-payload tests.
File Description
onnxruntime/​core/​framework/​tensorprotoutils.cc Implements string payload accounting.
onnxruntime/​core/​framework/​tensorprotoutils.h Declares configurable-limit overload.
onnxruntime/​test/​framework/​tensorutils_test.cc Adds string initializer limit tests.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread onnxruntime/test/framework/tensorutils_test.cc Outdated
Comment thread onnxruntime/test/framework/tensorutils_test.cc Outdated
@danielsongmicrosoft
danielsongmicrosoft force-pushed the user/danielsongmicrosoft/onnxruntime-robustness-2db75c322aca branch from 9d9de4a to 796e2e0 Compare September 28, 2026 19:43
@danielsongmicrosoft
danielsongmicrosoft marked this pull request as ready for review September 28, 2026 19:55
@danielsongmicrosoft
danielsongmicrosoft force-pushed the user/danielsongmicrosoft/onnxruntime-robustness-2db75c322aca branch from 796e2e0 to 7508098 Compare September 28, 2026 20:03

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants