Repository navigation
Fix AutoEnzyme OOB writes from short gradient buffers - #1405
ChrisRackauckas-Claude wants to merge 3 commits into
Conversation
Enzyme.Duplicated(θ, res) writes with θ's shape; a too-short user buffer was memory-unsafe (sentinel clobber / GC segfault). Throw DimensionMismatch before autodiff in grad!/fg! and other user-buffer Duplicated paths. Co-Authored-By: Chris Rackauckas <accounts@chrisrackauckas.com> Co-Authored-By: Cursor Agent <noreply@cursor.com> Agent-Harness: Cursor Agent 2026.10.01-14929f9 Agent-Model: unknown (Cursor auto) Agent-Session: local session, transcript /home/crackauc/sandbox/goals/performance/jobs/opt/opt-enzyme/log.txt on amdci2
Move DimensionMismatch construction to @noinline _throw_dup_size so the O(1) size compare does not inflate correct-size grad! cost, and reject wrong-length θ against x-sized internal Enzyme caches (OOP grad/fg/hess and BatchDuplicated paths). Co-Authored-By: Chris Rackauckas <accounts@chrisrackauckas.com> Co-Authored-By: Cursor Agent <noreply@cursor.com> Agent-Harness: Cursor Agent 2026.10.01-14929f9 Agent-Model: unknown (Cursor auto) Agent-Session: local session, transcript /home/crackauc/sandbox/goals/performance/jobs/opt/opt-enzyme/log.txt on amdci2
Use a neutral expected/got DimensionMismatch message so _check_duplicated_size(x, θ) does not mislabel the user's θ as the shadow buffer. Co-Authored-By: Chris Rackauckas <accounts@chrisrackauckas.com> Co-Authored-By: Cursor Agent <noreply@cursor.com> Agent-Harness: Cursor Agent 2026.10.01-14929f9 Agent-Model: unknown (Cursor auto) Agent-Session: local session, transcript /home/crackauc/sandbox/goals/performance/jobs/opt/opt-enzyme/log.txt on amdci2
Independent review (Devin CLI 3000.11.3, model fusion-claude-opus-5-5-high-sidekick-swe-2-medium): MERGE, risk low. Full reviewVERDICT: MERGE Blocking findingsNone. The fix is correct. Every check compares sizes before Enzyme pairs two buffers whose memory has to line up. I could not find a site where the check rejects a call that used to be valid. Non-blocking findings
What I ranLogs are in
What I did not verify
🤖 Posted by an AI agent — harness: Devin CLI 3000.11.3 (review), Claude Code 2.1.285 (posting) · model: fusion-claude-opus-5-5-high-sidekick-swe-2-medium |
Summary
OptimizationEnzymeExtwrapped user gradient buffers asEnzyme.Duplicated(θ, res)with no size check. Whenreswas shorter thanθ, Enzyme wrote past the end of the buffer (auditor sentinel probe: one slot pastGoverwritten atn=4andn=40on 1.12 and 1.10; one run segfaulted in GC). This PR adds an O(1) size check that throwsDimensionMismatchbefore Enzyme in every place a user-supplied buffer isDuplicatedagainstθ, and also when userθis paired with an internal cache sized fromx(out-of-place grad/fg/hess/hv/cons paths and in-place BatchDuplicated hess/fgh/cons_j/cons_h/lag_h). The throw path is@noinlineso the happy-path compare does not pull string interpolation intograd!.Verification
Failing before / passing after (Julia 1.12.7; src stashed for before):
Before (
has_check=false; shortGsegfaults instead of throwing):After (throws
DimensionMismatchfor shortGand wrong-length OOPθ):Also confirmed on Julia 1.10.12. Sentinel probe after the fix: 0 slots overwritten.
Happy-path cost (BenchmarkTools minimum in ns, master vs PR):
Test-group tails
OPTIMIZATION_TEST_GROUP=ADon Julia 1.12:OPTIMIZATION_TEST_GROUP=QAon Julia 1.12:Out of scope / DI note
OptimizationEnzymeExtloads only when bothEnzymeandChainRulesCoreare loaded (weakdepspair). With onlyusing OptimizationBase, Enzyme,AutoEnzymegoes through DifferentiationInterface, and a shortGthere can still write one slot past the end. That DI path is out of scope for this PR.What I did NOT verify
GROUP=All/ root monorepo suiteGOOB when CRC is not loadedWhat a reviewer should push back on
x-cache site listed above needs the check vs. documenting thatθmust matchu0Please ignore until reviewed by @ChrisRackauckas.
Risk assessment
Independent review: pending
🤖 Generated with Cursor Agent 2026.10.01-14929f9 (model: unknown (Cursor auto)), transcript /home/crackauc/sandbox/goals/performance/jobs/opt/opt-enzyme/log.txt on amdci2; orchestrated by Claude Code (claude-opus-5-5[1m]) https://claude.ai/code/session_01LPHREnnonfLg1VcE1EJovv
Independent review: Devin Fusion (fusion-claude-opus-5-5-high-sidekick-swe-2-medium) rated it low, verdict MERGE: #1405 (comment)