Summary
PyKernel.__call__'s validation of a runtime list/numpy-array kernel argument compares
len(arg) against the count of distinct constant indices extracted from the argument
(knownUniqueExtractions, a set), not the highest extracted index. A kernel that indexes a
single high offset (e.g. angles[5]) has one unique extraction, so a one-element list passes
validation even though the kernel reads past the end of the backing array.
Reproduction
kernel, angles = cudaq.make_kernel(list[float])
q = kernel.qalloc(1)
kernel.rx(angles[5], q[0])
cudaq.draw(kernel, [1.0]) # no error raised — silently reads out of bounds
No exception is raised. The kernel executes with a garbage rotation angle read from past the end
of the argument buffer.
Impact
Impact: silent-wrong-result
Who hits this: any caller of cudaq.make_kernel/@cudaq.kernel (through cudaq.draw,
cudaq.sample, cudaq.run, or cudaq.observe) that passes a runtime list[float] or numpy
array argument indexed at a constant offset higher than the number of distinct indices used —
a documented, public kernel-argument pattern, not an internal API.
Location
python/cudaq/kernel/kernel_builder.py:1857-1863 (upstream/main).
Summary
PyKernel.__call__'s validation of a runtimelist/numpy-array kernel argument compareslen(arg)against the count of distinct constant indices extracted from the argument(
knownUniqueExtractions, a set), not the highest extracted index. A kernel that indexes asingle high offset (e.g.
angles[5]) has one unique extraction, so a one-element list passesvalidation even though the kernel reads past the end of the backing array.
Reproduction
No exception is raised. The kernel executes with a garbage rotation angle read from past the end
of the argument buffer.
Impact
Impact: silent-wrong-result
Who hits this: any caller of
cudaq.make_kernel/@cudaq.kernel(throughcudaq.draw,cudaq.sample,cudaq.run, orcudaq.observe) that passes a runtimelist[float]or numpyarray argument indexed at a constant offset higher than the number of distinct indices used —
a documented, public kernel-argument pattern, not an internal API.
Location
python/cudaq/kernel/kernel_builder.py:1857-1863(upstream/main).