New Defects reported by Coverity Scan for digiKam
scan-admin at coverity.com
scan-admin at coverity.com
Mon Aug 24 07:35:49 BST 2026
Hi,
Please find the latest report on new defect(s) introduced to digiKam found with Coverity Scan.
20 new defect(s) introduced to digiKam found with Coverity Scan.
55 defect(s), reported by Coverity Scan earlier, were marked fixed in the recent build analyzed by Coverity Scan.
New defect(s) Reported-by: Coverity Scan
Showing 20 of 20 defect(s)
** CID 1700495: Uninitialized members (UNINIT_CTOR)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-backend-meta.cpp: 407 in std::ggml_backend_meta_simple_tensor_container::ggml_backend_meta_simple_tensor_container()()
_____________________________________________________________________________________________
*** CID 1700495: Uninitialized members (UNINIT_CTOR)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-backend-meta.cpp: 407 in std::ggml_backend_meta_simple_tensor_container::ggml_backend_meta_simple_tensor_container()()
401 ggml_backend_meta_simple_tensor_container(const ggml_init_params & params, const int n_simple) {
402 ctxs.reserve(n_simple);
403 for (int i = 0; i < n_simple; i++) {
404 ctxs.emplace_back(ggml_init(params));
405 }
406 }
>>> CID 1700495: Uninitialized members (UNINIT_CTOR)
>>> Non-static class member "<error>" is not initialized in this constructor nor in any functions that it calls.
407 ggml_backend_meta_simple_tensor_container() {}
408 };
409
410 struct ggml_backend_meta_buffer_context {
411 // FIXME
412 // Most tensors can simply be stored statically in their own buffer.
** CID 1700494: Uninitialized variables (UNINIT)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/postprocessing/postprocessing_aux.cpp: 150 in LibRaw::wavelet_denoise()()
_____________________________________________________________________________________________
*** CID 1700494: Uninitialized variables (UNINIT)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/postprocessing/postprocessing_aux.cpp: 150 in LibRaw::wavelet_denoise()()
144
145 while (maximum << scale < 0x10000)
146 scale++;
147 maximum <<= --scale;
148 black <<= scale;
149 FORC4 cblack[c] <<= scale;
>>> CID 1700494: Uninitialized variables (UNINIT)
>>> Using uninitialized value "size".
150 fimg = (float *)malloc((size * 3 + iheight + iwidth) * sizeof *fimg);
151 temp = fimg + size * 3;
152 if ((nc = colors) == 3 && filters)
153 nc++;
154 #pragma omp parallel default(shared) private( \
155 i, col, row, thold, lev, lpass, hpass, temp, c) firstprivate(scale, size)
** CID 1700493: Integer handling issues (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4693 in std::ggml_compute_forward_set_i32(const ggml_compute_params *, ggml_tensor *)()
_____________________________________________________________________________________________
*** CID 1700493: Integer handling issues (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4693 in std::ggml_compute_forward_set_i32(const ggml_compute_params *, ggml_tensor *)()
4687 const int ir0 = dr*ith;
4688 const int ir1 = MIN(ir0 + dr, nr);
4689
4690 for (int ir = ir0; ir < ir1; ++ir) {
4691 // src0 and dst are viewed with shape of src1 and offset
4692 // => same indices
>>> CID 1700493: Integer handling issues (DIVIDE_BY_ZERO)
>>> In expression "ir / (ne12 * ne11)", division by expression "ne12 * ne11" which may be zero has undefined behavior.
4693 const int i3 = ir/(ne12*ne11);
4694 const int i2 = (ir - i3*ne12*ne11)/ne11;
4695 const int i1 = (ir - i3*ne12*ne11 - i2*ne11);
4696
4697 ggml_vec_cpy_i32(nc,
4698 (int32_t *) ((char *) dst->data + i3*nb3 + i2*nb2 + i1*nb1 + offset),
** CID 1700492: Performance inefficiencies (COPY_INSTEAD_OF_MOVE)
_____________________________________________________________________________________________
*** CID 1700492: Performance inefficiencies (COPY_INSTEAD_OF_MOVE)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 1521 in <unnamed>::sony_arw6_decode_stream_tile(const unsigned char *, unsigned int)()
1515 sony_arw6_final_green(green, g4[0], guarded_height ? 2 : 4);
1516
1517 SonyArw6DecodedTile out;
1518 out.green = green;
1519 out.red_residual = red_residual;
1520 out.blue_residual = blue_residual;
>>> CID 1700492: Performance inefficiencies (COPY_INSTEAD_OF_MOVE)
>>> "full_green" is copied in call to copy assignment for class "<unnamed>::SonyArw6Plane", when it could be moved instead.
1521 out.full_green = full_green;
1522 return out;
1523 }
1524
1525 } // namespace
1526
** CID 1700491: Performance inefficiencies (COPY_INSTEAD_OF_MOVE)
_____________________________________________________________________________________________
*** CID 1700491: Performance inefficiencies (COPY_INSTEAD_OF_MOVE)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 1520 in <unnamed>::sony_arw6_decode_stream_tile(const unsigned char *, unsigned int)()
1514 SonyArw6Plane full_green =
1515 sony_arw6_final_green(green, g4[0], guarded_height ? 2 : 4);
1516
1517 SonyArw6DecodedTile out;
1518 out.green = green;
1519 out.red_residual = red_residual;
>>> CID 1700491: Performance inefficiencies (COPY_INSTEAD_OF_MOVE)
>>> "blue_residual" is copied in call to copy assignment for class "<unnamed>::SonyArw6Plane", when it could be moved instead.
1520 out.blue_residual = blue_residual;
1521 out.full_green = full_green;
1522 return out;
1523 }
1524
1525 } // namespace
** CID 1700490: Memory - illegal accesses (OVERRUN)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/repack.cpp: 1891 in ggml_gemm_q4_K_8x4_q8_K_generic()
_____________________________________________________________________________________________
*** CID 1700490: Memory - illegal accesses (OVERRUN)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/repack.cpp: 1891 in ggml_gemm_q4_K_8x4_q8_K_generic()
1885 }
1886 for (int sb = 0; sb < 8; sb++) {
1887 uint8_t * mins = (uint8_t *) utmp + 8 + sb * 16;
1888 for(int m = 0; m < 4; m++) {
1889 const int16_t * bsums = a_ptr[l].bsums + (sb * 8) + (m * 4) - ((sb % 2) * 6);
1890 for(int j = 0; j < ncols_interleaved; j++) {
>>> CID 1700490: Memory - illegal accesses (OVERRUN)
>>> Overrunning array of 64 2-byte elements at element index 68 (byte offset 137) by dereferencing pointer "bsums + 0".
1891 sum_minf[m][j] += mins[j] * (bsums[0] + bsums[1]) * GGML_CPU_FP16_TO_FP32(b_ptr[l].dmin[j]) * a_ptr[l].d[m];
1892 }
1893 }
1894 }
1895 }
1896 for (int m = 0; m < 4; m++) {
** CID 1700489: Integer handling issues (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4842 in std::ggml_compute_forward_get_rows_f16(const ggml_compute_params *, ggml_tensor *)()
_____________________________________________________________________________________________
*** CID 1700489: Integer handling issues (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4842 in std::ggml_compute_forward_get_rows_f16(const ggml_compute_params *, ggml_tensor *)()
4836
4837 // row range for this thread
4838 const int ir0 = dr*ith;
4839 const int ir1 = MIN(ir0 + dr, nr);
4840
4841 for (int64_t i = ir0; i < ir1; ++i) {
>>> CID 1700489: Integer handling issues (DIVIDE_BY_ZERO)
>>> In expression "i / (ne11 * ne10)", division by expression "ne11 * ne10" which may be zero has undefined behavior.
4842 const int64_t i12 = i/(ne11*ne10);
4843 const int64_t i11 = (i - i12*ne11*ne10)/ne10;
4844 const int64_t i10 = (i - i12*ne11*ne10 - i11*ne10);
4845 const int64_t i01 = *(int32_t *) ((char *) src1->data + i10*nb10 + i11*nb11 + i12*nb12);
4846
4847 GGML_ASSERT(i01 >= 0 && i01 < ne01);
** CID 1700488: (COPY_INSTEAD_OF_MOVE)
_____________________________________________________________________________________________
*** CID 1700488: (COPY_INSTEAD_OF_MOVE)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 1428 in <unnamed>::sony_arw6_decode_stream_tile(const unsigned char *, unsigned int)()
1422 if (low_start)
1423 {
1424 SonyArw6Plane cropped(low_count, red_residual.cols);
1425 for (int y = 0; y < low_count; y++)
1426 memcpy(cropped.row(y), red_residual.row(y + low_start),
1427 sizeof(int32_t) * size_t(red_residual.cols));
>>> CID 1700488: (COPY_INSTEAD_OF_MOVE)
>>> "cropped" is copied in call to copy assignment for class "<unnamed>::SonyArw6Plane", when it could be moved instead.
1428 red_residual = cropped;
1429 }
1430
1431 std::vector<SonyArw6Plane> b0 =
1432 sony_arw6_decode_packet_arrays(stream, stream_size, dir,
1433 header.coded_width, coded_height, 0, 2);
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 1414 in <unnamed>::sony_arw6_decode_stream_tile(const unsigned char *, unsigned int)()
1408 if (low_start)
1409 {
1410 SonyArw6Plane cropped(low_count, green.cols);
1411 for (int y = 0; y < low_count; y++)
1412 memcpy(cropped.row(y), green.row(y + low_start),
1413 sizeof(int32_t) * size_t(green.cols));
>>> CID 1700488: (COPY_INSTEAD_OF_MOVE)
>>> "cropped" is copied in call to copy assignment for class "<unnamed>::SonyArw6Plane", when it could be moved instead.
1414 green = cropped;
1415 }
1416
1417 std::vector<SonyArw6Plane> r0 =
1418 sony_arw6_decode_packet_arrays(stream, stream_size, dir,
1419 header.coded_width, coded_height, 0, 1);
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 1442 in <unnamed>::sony_arw6_decode_stream_tile(const unsigned char *, unsigned int)()
1436 if (low_start)
1437 {
1438 SonyArw6Plane cropped(low_count, blue_residual.cols);
1439 for (int y = 0; y < low_count; y++)
1440 memcpy(cropped.row(y), blue_residual.row(y + low_start),
1441 sizeof(int32_t) * size_t(blue_residual.cols));
>>> CID 1700488: (COPY_INSTEAD_OF_MOVE)
>>> "cropped" is copied in call to copy assignment for class "<unnamed>::SonyArw6Plane", when it could be moved instead.
1442 blue_residual = cropped;
1443 }
1444
1445 for (int group = 1; group <= 3; group++)
1446 {
1447 const int edge_rows = group == 1 ? 0 : (group == 2 ? 1 : 2);
** CID 1700487: Integer handling issues (SIGN_EXTENSION)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/unpack_thumb.cpp: 317 in LibRaw::unpack_thumb()()
_____________________________________________________________________________________________
*** CID 1700487: Integer handling issues (SIGN_EXTENSION)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/unpack_thumb.cpp: 317 in LibRaw::unpack_thumb()()
311 && i < tiff_ifd[pifd].strip_offsets_count; i++)
312 total_size += tiff_ifd[pifd].strip_byte_counts[i];
313 if (total_size != (unsigned)t_length) // recalculate colors
314 {
315 if (total_size == T.twidth * T.theight * 3)
316 T.tcolors = 3;
>>> CID 1700487: Integer handling issues (SIGN_EXTENSION)
>>> Suspicious implicit sign extension: "this->imgdata.thumbnail.theight" with type "ushort" (16 bits, unsigned) is promoted in "this->imgdata.thumbnail.twidth * this->imgdata.thumbnail.theight" to type "int" (32 bits, signed), then sign-extended to type "long long" (64 bits, signed). If "this->imgdata.thumbnail.twidth * this->imgdata.thumbnail.theight" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1.
317 else if (total_size == T.twidth * T.theight)
318 T.tcolors = 1;
319 }
320 T.tlength = unsigned(total_size);
321 THUMB_SIZE_CHECKTNZ(T.tlength);
322 if (T.thumb)
** CID 1700486: Integer handling issues (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4413 in std::ggml_compute_forward_out_prod_q_f32(const ggml_compute_params *, ggml_tensor *)()
_____________________________________________________________________________________________
*** CID 1700486: Integer handling issues (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4413 in std::ggml_compute_forward_out_prod_q_f32(const ggml_compute_params *, ggml_tensor *)()
4407 // dst[i0,i1,i2,i3] += src0[i0,i01,i2,i3] * src1[i1,i01,i2,i3]
4408
4409 float * wdata = (float *) params->wdata + (ne0 + CACHE_LINE_SIZE_F32) * ith;
4410
4411 for (int64_t ir = ir0; ir < ir1; ++ir) {
4412 // dst indices
>>> CID 1700486: Integer handling issues (DIVIDE_BY_ZERO)
>>> In expression "ir / (ne2 * ne1)", division by expression "ne2 * ne1" which may be zero has undefined behavior.
4413 const int64_t i3 = ir/(ne2*ne1);
4414 const int64_t i2 = (ir - i3*ne2*ne1)/ne1;
4415 const int64_t i1 = (ir - i3*ne2*ne1 - i2*ne1);
4416
4417 const int64_t i02 = i2;
4418 const int64_t i03 = i3;
** CID 1700485: Integer handling issues (BAD_SHIFT)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 643 in <unnamed>::SonyArw6NativeBits::read_bits(int)()
_____________________________________________________________________________________________
*** CID 1700485: Integer handling issues (BAD_SHIFT)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 643 in <unnamed>::SonyArw6NativeBits::read_bits(int)()
637 while (remaining > 0)
638 {
639 if (bit_ <= 0)
640 {
641 load_next_word();
642 if (status)
>>> CID 1700485: Integer handling issues (BAD_SHIFT)
>>> In expression "out << remaining", left shifting by more than 31 bits has undefined behavior. The shift amount, "remaining", is as much as 32.
643 return out << remaining;
644 }
645 const int take = std::min(remaining, bit_);
646 bit_ -= take;
647 out = (out << take) |
648 uint32_t((cur_ >> bit_) & ((uint64_t(1) << take) - 1));
** CID 1700484: Performance inefficiencies (COPY_INSTEAD_OF_MOVE)
_____________________________________________________________________________________________
*** CID 1700484: Performance inefficiencies (COPY_INSTEAD_OF_MOVE)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 1518 in <unnamed>::sony_arw6_decode_stream_tile(const unsigned char *, unsigned int)()
1512 sony_arw6_decode_packet_arrays(stream, stream_size, dir,
1513 header.coded_width, coded_height, 4, 0);
1514 SonyArw6Plane full_green =
1515 sony_arw6_final_green(green, g4[0], guarded_height ? 2 : 4);
1516
1517 SonyArw6DecodedTile out;
>>> CID 1700484: Performance inefficiencies (COPY_INSTEAD_OF_MOVE)
>>> "green" is copied in call to copy assignment for class "<unnamed>::SonyArw6Plane", when it could be moved instead.
1518 out.green = green;
1519 out.red_residual = red_residual;
1520 out.blue_residual = blue_residual;
1521 out.full_green = full_green;
1522 return out;
1523 }
** CID 1700483: Integer handling issues (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4924 in std::ggml_compute_forward_get_rows_f32(const ggml_compute_params *, ggml_tensor *)()
_____________________________________________________________________________________________
*** CID 1700483: Integer handling issues (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4924 in std::ggml_compute_forward_get_rows_f32(const ggml_compute_params *, ggml_tensor *)()
4918
4919 // row range for this thread
4920 const int ir0 = dr*ith;
4921 const int ir1 = MIN(ir0 + dr, nr);
4922
4923 for (int64_t i = ir0; i < ir1; ++i) {
>>> CID 1700483: Integer handling issues (DIVIDE_BY_ZERO)
>>> In expression "i / (ne11 * ne10)", division by expression "ne11 * ne10" which may be zero has undefined behavior.
4924 const int64_t i12 = i/(ne11*ne10);
4925 const int64_t i11 = (i - i12*ne11*ne10)/ne10;
4926 const int64_t i10 = (i - i12*ne11*ne10 - i11*ne10);
4927 const int64_t i01 = *(int32_t *) ((char *) src1->data + i10*nb10 + i11*nb11 + i12*nb12);
4928
4929 GGML_ASSERT(i01 >= 0 && i01 < ne01);
** CID 1700482: Integer handling issues (BAD_SHIFT)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 647 in <unnamed>::SonyArw6NativeBits::read_bits(int)()
_____________________________________________________________________________________________
*** CID 1700482: Integer handling issues (BAD_SHIFT)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 647 in <unnamed>::SonyArw6NativeBits::read_bits(int)()
641 load_next_word();
642 if (status)
643 return out << remaining;
644 }
645 const int take = std::min(remaining, bit_);
646 bit_ -= take;
>>> CID 1700482: Integer handling issues (BAD_SHIFT)
>>> In expression "out << take", left shifting by more than 31 bits has undefined behavior. The shift amount, "take", is as much as 32.
647 out = (out << take) |
648 uint32_t((cur_ >> bit_) & ((uint64_t(1) << take) - 1));
649 remaining -= take;
650 }
651 return out;
652 }
** CID 1700481: Integer handling issues (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4622 in std::ggml_compute_forward_set_f32(const ggml_compute_params *, ggml_tensor *)()
_____________________________________________________________________________________________
*** CID 1700481: Integer handling issues (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4622 in std::ggml_compute_forward_set_f32(const ggml_compute_params *, ggml_tensor *)()
4616 const int ir0 = dr*ith;
4617 const int ir1 = MIN(ir0 + dr, nr);
4618
4619 for (int ir = ir0; ir < ir1; ++ir) {
4620 // src0 and dst are viewed with shape of src1 and offset
4621 // => same indices
>>> CID 1700481: Integer handling issues (DIVIDE_BY_ZERO)
>>> In expression "ir / (ne12 * ne11)", division by expression "ne12 * ne11" which may be zero has undefined behavior.
4622 const int i3 = ir/(ne12*ne11);
4623 const int i2 = (ir - i3*ne12*ne11)/ne11;
4624 const int i1 = (ir - i3*ne12*ne11 - i2*ne11);
4625
4626 ggml_vec_cpy_f32(nc,
4627 (float *) ((char *) dst->data + i3*nb3 + i2*nb2 + i1*nb1 + offset),
** CID 1700480: Control flow issues (DEADCODE)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 483 in <unnamed>::sony_arw6_find_streams(const std::vector<unsigned char, std::allocator<unsigned char>> &, int, int)()
_____________________________________________________________________________________________
*** CID 1700480: Control flow issues (DEADCODE)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 483 in <unnamed>::sony_arw6_find_streams(const std::vector<unsigned char, std::allocator<unsigned char>> &, int, int)()
477 {
478 for (uint32_t index = 0; index < count; index++)
479 {
480 const uint32_t entry = 0x08 + index * 0x18;
481 if (entry + 0x18 > strip_size)
482 {
>>> CID 1700480: Control flow issues (DEADCODE)
>>> Execution cannot reach this statement: "streams.clear();".
483 streams.clear();
484 break;
485 }
486 const uint32_t table_offset = sony_arw6_le32(base + entry);
487 const int tile_x = int(sony_arw6_le32(base + entry + 0x08));
488 const int tile_y = int(sony_arw6_le32(base + entry + 0x0c));
** CID 1700479: Integer handling issues (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4883 in std::ggml_compute_forward_get_rows_bf16(const ggml_compute_params *, ggml_tensor *)()
_____________________________________________________________________________________________
*** CID 1700479: Integer handling issues (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4883 in std::ggml_compute_forward_get_rows_bf16(const ggml_compute_params *, ggml_tensor *)()
4877
4878 // row range for this thread
4879 const int ir0 = dr*ith;
4880 const int ir1 = MIN(ir0 + dr, nr);
4881
4882 for (int64_t i = ir0; i < ir1; ++i) {
>>> CID 1700479: Integer handling issues (DIVIDE_BY_ZERO)
>>> In expression "i / (ne11 * ne10)", division by expression "ne11 * ne10" which may be zero has undefined behavior.
4883 const int64_t i12 = i/(ne11*ne10);
4884 const int64_t i11 = (i - i12*ne11*ne10)/ne10;
4885 const int64_t i10 = (i - i12*ne11*ne10 - i11*ne10);
4886 const int64_t i01 = *(int32_t *) ((char *) src1->data + i10*nb10 + i11*nb11 + i12*nb12);
4887
4888 GGML_ASSERT(i01 >= 0 && i01 < ne01);
** CID 1700478: Integer handling issues (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4801 in std::ggml_compute_forward_get_rows_q(const ggml_compute_params *, ggml_tensor *)()
_____________________________________________________________________________________________
*** CID 1700478: Integer handling issues (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4801 in std::ggml_compute_forward_get_rows_q(const ggml_compute_params *, ggml_tensor *)()
4795
4796 // row range for this thread
4797 const int ir0 = dr*ith;
4798 const int ir1 = MIN(ir0 + dr, nr);
4799
4800 for (int64_t i = ir0; i < ir1; ++i) {
>>> CID 1700478: Integer handling issues (DIVIDE_BY_ZERO)
>>> In expression "i / (ne11 * ne10)", division by expression "ne11 * ne10" which may be zero has undefined behavior.
4801 const int64_t i12 = i/(ne11*ne10);
4802 const int64_t i11 = (i - i12*ne11*ne10)/ne10;
4803 const int64_t i10 = (i - i12*ne11*ne10 - i11*ne10);
4804 const int64_t i01 = *(int32_t *) ((char *) src1->data + i10*nb10 + i11*nb11 + i12*nb12);
4805
4806 GGML_ASSERT(i01 >= 0 && i01 < ne01);
** CID 1700477: Integer handling issues (SIGN_EXTENSION)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/unpack_thumb.cpp: 317 in LibRaw::unpack_thumb()()
_____________________________________________________________________________________________
*** CID 1700477: Integer handling issues (SIGN_EXTENSION)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/unpack_thumb.cpp: 317 in LibRaw::unpack_thumb()()
311 && i < tiff_ifd[pifd].strip_offsets_count; i++)
312 total_size += tiff_ifd[pifd].strip_byte_counts[i];
313 if (total_size != (unsigned)t_length) // recalculate colors
314 {
315 if (total_size == T.twidth * T.theight * 3)
316 T.tcolors = 3;
>>> CID 1700477: Integer handling issues (SIGN_EXTENSION)
>>> Suspicious implicit sign extension: "this->imgdata.thumbnail.twidth" with type "ushort" (16 bits, unsigned) is promoted in "this->imgdata.thumbnail.twidth * this->imgdata.thumbnail.theight" to type "int" (32 bits, signed), then sign-extended to type "long long" (64 bits, signed). If "this->imgdata.thumbnail.twidth * this->imgdata.thumbnail.theight" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1.
317 else if (total_size == T.twidth * T.theight)
318 T.tcolors = 1;
319 }
320 T.tlength = unsigned(total_size);
321 THUMB_SIZE_CHECKTNZ(T.tlength);
322 if (T.thumb)
** CID 1700476: Performance inefficiencies (COPY_INSTEAD_OF_MOVE)
_____________________________________________________________________________________________
*** CID 1700476: Performance inefficiencies (COPY_INSTEAD_OF_MOVE)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 1519 in <unnamed>::sony_arw6_decode_stream_tile(const unsigned char *, unsigned int)()
1513 header.coded_width, coded_height, 4, 0);
1514 SonyArw6Plane full_green =
1515 sony_arw6_final_green(green, g4[0], guarded_height ? 2 : 4);
1516
1517 SonyArw6DecodedTile out;
1518 out.green = green;
>>> CID 1700476: Performance inefficiencies (COPY_INSTEAD_OF_MOVE)
>>> "red_residual" is copied in call to copy assignment for class "<unnamed>::SonyArw6Plane", when it could be moved instead.
1519 out.red_residual = red_residual;
1520 out.blue_residual = blue_residual;
1521 out.full_green = full_green;
1522 return out;
1523 }
1524
________________________________________________________________________________________________________
To view the defects in Coverity Scan visit, https://scan.coverity.com/projects/digikam?tab=overview
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.kde.org/pipermail/digikam-devel/attachments/20260824/926ae94b/attachment-0001.htm>
More information about the Digikam-devel
mailing list