Skip to content

std.sort.pdq: fix out-of-bounds access in partialInsertionSort - #25253

Merged
andrewrk merged 2 commits into
ziglang:masterfrom
jedisct1:pdqfix
Sep 18, 2025
Merged

andrewrk merged 2 commits into
ziglang:masterfrom
jedisct1:pdqfix

Conversation

@jedisct1

Copy link
Copy Markdown
Contributor

When sorting a sub-range that doesn't start at index 0, the partialInsertionSort function could access indices below the range start.

The loop condition while (j >= 1) didn't respect the arbitrary range boundaries [a, b).

This changes the condition to while (j > a) to ensure indices never go below the range start, fixing the issue where pdqContext would access out-of-bounds indices.

Fixes #25250

When sorting a sub-range that doesn't start at index 0, the
partialInsertionSort function could access indices below the range
start. The loop condition `while (j >= 1)` didn't respect the
arbitrary range boundaries [a, b).

This changes the condition to `while (j > a)` to ensure indices
never go below the range start, fixing the issue where pdqContext
would access out-of-bounds indices.

Fixes ziglang#25250
Comment thread lib/std/sort/pdq.zig Outdated

@andrewrk andrewrk left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you. This will be a nice example to see if it can be caught by integrated fuzzer when that sub-project is further along.

@andrewrk
andrewrk merged commit 6dd0270 into ziglang:master Sep 18, 2025
14 checks passed
@jedisct1
jedisct1 deleted the pdqfix branch September 18, 2025 08:01
alexrp pushed a commit that referenced this pull request Sep 18, 2025
* std.sort.pdq: fix out-of-bounds access in partialInsertionSort

When sorting a sub-range that doesn't start at index 0, the
partialInsertionSort function could access indices below the range
start. The loop condition `while (j >= 1)` didn't respect the
arbitrary range boundaries [a, b).

This changes the condition to `while (j > a)` to ensure indices
never go below the range start, fixing the issue where pdqContext
would access out-of-bounds indices.

Fixes #25250
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

pdq range bug

3 participants