Skip to content

PyKernel.__call__ validates a runtime list argument's length against the wrong quantity #5424

Description

@udsy19

Summary

PyKernel.__call__'s validation of a runtime list/numpy-array kernel argument compares
len(arg) against the count of distinct constant indices extracted from the argument
(knownUniqueExtractions, a set), not the highest extracted index. A kernel that indexes a
single high offset (e.g. angles[5]) has one unique extraction, so a one-element list passes
validation even though the kernel reads past the end of the backing array.

Reproduction

kernel, angles = cudaq.make_kernel(list[float])
q = kernel.qalloc(1)
kernel.rx(angles[5], q[0])
cudaq.draw(kernel, [1.0])   # no error raised — silently reads out of bounds

No exception is raised. The kernel executes with a garbage rotation angle read from past the end
of the argument buffer.

Impact

Impact: silent-wrong-result
Who hits this: any caller of cudaq.make_kernel/@cudaq.kernel (through cudaq.draw,
cudaq.sample, cudaq.run, or cudaq.observe) that passes a runtime list[float] or numpy
array argument indexed at a constant offset higher than the number of distinct indices used —
a documented, public kernel-argument pattern, not an internal API.

Location

python/cudaq/kernel/kernel_builder.py:1857-1863 (upstream/main).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions