Skip to content

Fix out-of-bounds read in dynamic_programming_bellman_word_ram - #1

Merged
fontanf merged 1 commit into
mainfrom
fix-word-ram-final-scan-bound
Sep 23, 2026
Merged

fontanf merged 1 commit into
mainfrom
fix-word-ram-final-scan-bound

Conversation

@fontanf

@fontanf fontanf commented Sep 23, 2026

Copy link
Copy Markdown
Owner

The final scan for the optimal value in dynamic_programming_bellman_word_ram used optimal_value == 0 as its only stopping condition. Weight 0 is always reachable, so when it is the optimal value (no item, or no item fitting in the capacity), the scan went past word 0 and read output.values[-1].

This stops the scan at word 0, and adds a test covering an instance with no item and an instance whose only item is heavier than the capacity.

The final scan for the optimal value used 'optimal_value == 0' as its
only stopping condition. Weight 0 is always reachable, so when it is the
optimal value (no item, or no item fitting in the capacity), the scan
went past word 0 and read 'output.values[-1]'. Stop the scan at word 0.
@fontanf
fontanf merged commit 2ba9d52 into main Sep 23, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant