New Defects reported by Coverity Scan for digiKam

scan-admin at coverity.com scan-admin at coverity.com
Mon Aug 24 07:35:49 BST 2026


Hi,

Please find the latest report on new defect(s) introduced to digiKam found with Coverity Scan.

20 new defect(s) introduced to digiKam found with Coverity Scan.
55 defect(s), reported by Coverity Scan earlier, were marked fixed in the recent build analyzed by Coverity Scan.

New defect(s) Reported-by: Coverity Scan
Showing 20 of 20 defect(s)


** CID 1700495:       Uninitialized members  (UNINIT_CTOR)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-backend-meta.cpp: 407           in std::ggml_backend_meta_simple_tensor_container::ggml_backend_meta_simple_tensor_container()()


_____________________________________________________________________________________________
*** CID 1700495:         Uninitialized members  (UNINIT_CTOR)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-backend-meta.cpp: 407             in std::ggml_backend_meta_simple_tensor_container::ggml_backend_meta_simple_tensor_container()()
401         ggml_backend_meta_simple_tensor_container(const ggml_init_params & params, const int n_simple) {
402             ctxs.reserve(n_simple);
403             for (int i = 0; i < n_simple; i++) {
404                 ctxs.emplace_back(ggml_init(params));
405             }
406         }
>>>     CID 1700495:         Uninitialized members  (UNINIT_CTOR)
>>>     Non-static class member "<error>" is not initialized in this constructor nor in any functions that it calls.
407         ggml_backend_meta_simple_tensor_container() {}
408     };
409     
410     struct ggml_backend_meta_buffer_context {
411         // FIXME
412         // Most tensors can simply be stored statically in their own buffer.

** CID 1700494:       Uninitialized variables  (UNINIT)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/postprocessing/postprocessing_aux.cpp: 150           in LibRaw::wavelet_denoise()()


_____________________________________________________________________________________________
*** CID 1700494:         Uninitialized variables  (UNINIT)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/postprocessing/postprocessing_aux.cpp: 150             in LibRaw::wavelet_denoise()()
144     
145       while (maximum << scale < 0x10000)
146         scale++;
147       maximum <<= --scale;
148       black <<= scale;
149       FORC4 cblack[c] <<= scale;
>>>     CID 1700494:         Uninitialized variables  (UNINIT)
>>>     Using uninitialized value "size".
150       fimg = (float *)malloc((size * 3 + iheight + iwidth) * sizeof *fimg);
151       temp = fimg + size * 3;
152       if ((nc = colors) == 3 && filters)
153         nc++;
154     #pragma omp parallel default(shared) private(                                  \
155         i, col, row, thold, lev, lpass, hpass, temp, c) firstprivate(scale, size)

** CID 1700493:       Integer handling issues  (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4693           in std::ggml_compute_forward_set_i32(const ggml_compute_params *, ggml_tensor *)()


_____________________________________________________________________________________________
*** CID 1700493:         Integer handling issues  (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4693             in std::ggml_compute_forward_set_i32(const ggml_compute_params *, ggml_tensor *)()
4687         const int ir0 = dr*ith;
4688         const int ir1 = MIN(ir0 + dr, nr);
4689     
4690         for (int ir = ir0; ir < ir1; ++ir) {
4691             // src0 and dst are viewed with shape of src1 and offset
4692             // => same indices
>>>     CID 1700493:         Integer handling issues  (DIVIDE_BY_ZERO)
>>>     In expression "ir / (ne12 * ne11)", division by expression "ne12 * ne11" which may be zero has undefined behavior.
4693             const int i3 = ir/(ne12*ne11);
4694             const int i2 = (ir - i3*ne12*ne11)/ne11;
4695             const int i1 = (ir - i3*ne12*ne11 - i2*ne11);
4696     
4697             ggml_vec_cpy_i32(nc,
4698                     (int32_t *) ((char *)  dst->data + i3*nb3  + i2*nb2  + i1*nb1  + offset),

** CID 1700492:       Performance inefficiencies  (COPY_INSTEAD_OF_MOVE)


_____________________________________________________________________________________________
*** CID 1700492:         Performance inefficiencies  (COPY_INSTEAD_OF_MOVE)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 1521             in <unnamed>::sony_arw6_decode_stream_tile(const unsigned char *, unsigned int)()
1515           sony_arw6_final_green(green, g4[0], guarded_height ? 2 : 4);
1516     
1517       SonyArw6DecodedTile out;
1518       out.green = green;
1519       out.red_residual = red_residual;
1520       out.blue_residual = blue_residual;
>>>     CID 1700492:         Performance inefficiencies  (COPY_INSTEAD_OF_MOVE)
>>>     "full_green" is copied in call to copy assignment for class "<unnamed>::SonyArw6Plane", when it could be moved instead.
1521       out.full_green = full_green;
1522       return out;
1523     }
1524     
1525     } // namespace
1526     

** CID 1700491:       Performance inefficiencies  (COPY_INSTEAD_OF_MOVE)


_____________________________________________________________________________________________
*** CID 1700491:         Performance inefficiencies  (COPY_INSTEAD_OF_MOVE)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 1520             in <unnamed>::sony_arw6_decode_stream_tile(const unsigned char *, unsigned int)()
1514       SonyArw6Plane full_green =
1515           sony_arw6_final_green(green, g4[0], guarded_height ? 2 : 4);
1516     
1517       SonyArw6DecodedTile out;
1518       out.green = green;
1519       out.red_residual = red_residual;
>>>     CID 1700491:         Performance inefficiencies  (COPY_INSTEAD_OF_MOVE)
>>>     "blue_residual" is copied in call to copy assignment for class "<unnamed>::SonyArw6Plane", when it could be moved instead.
1520       out.blue_residual = blue_residual;
1521       out.full_green = full_green;
1522       return out;
1523     }
1524     
1525     } // namespace

** CID 1700490:       Memory - illegal accesses  (OVERRUN)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/repack.cpp: 1891           in ggml_gemm_q4_K_8x4_q8_K_generic()


_____________________________________________________________________________________________
*** CID 1700490:         Memory - illegal accesses  (OVERRUN)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/repack.cpp: 1891             in ggml_gemm_q4_K_8x4_q8_K_generic()
1885                     }
1886                     for (int sb = 0; sb < 8; sb++) {
1887                         uint8_t * mins = (uint8_t *) utmp + 8 + sb * 16;
1888                         for(int m = 0; m < 4; m++) {
1889                             const int16_t * bsums = a_ptr[l].bsums + (sb * 8) + (m * 4) - ((sb % 2) * 6);
1890                             for(int j = 0; j < ncols_interleaved; j++) {
>>>     CID 1700490:         Memory - illegal accesses  (OVERRUN)
>>>     Overrunning array of 64 2-byte elements at element index 68 (byte offset 137) by dereferencing pointer "bsums + 0".
1891                                 sum_minf[m][j] += mins[j] * (bsums[0] + bsums[1]) * GGML_CPU_FP16_TO_FP32(b_ptr[l].dmin[j]) * a_ptr[l].d[m];
1892                             }
1893                         }
1894                     }
1895                 }
1896                 for (int m = 0; m < 4; m++) {

** CID 1700489:       Integer handling issues  (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4842           in std::ggml_compute_forward_get_rows_f16(const ggml_compute_params *, ggml_tensor *)()


_____________________________________________________________________________________________
*** CID 1700489:         Integer handling issues  (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4842             in std::ggml_compute_forward_get_rows_f16(const ggml_compute_params *, ggml_tensor *)()
4836     
4837         // row range for this thread
4838         const int ir0 = dr*ith;
4839         const int ir1 = MIN(ir0 + dr, nr);
4840     
4841         for (int64_t i = ir0; i < ir1; ++i) {
>>>     CID 1700489:         Integer handling issues  (DIVIDE_BY_ZERO)
>>>     In expression "i / (ne11 * ne10)", division by expression "ne11 * ne10" which may be zero has undefined behavior.
4842             const int64_t i12 = i/(ne11*ne10);
4843             const int64_t i11 = (i - i12*ne11*ne10)/ne10;
4844             const int64_t i10 = (i - i12*ne11*ne10 - i11*ne10);
4845             const int64_t i01 = *(int32_t *) ((char *) src1->data + i10*nb10 + i11*nb11 + i12*nb12);
4846     
4847             GGML_ASSERT(i01 >= 0 && i01 < ne01);

** CID 1700488:         (COPY_INSTEAD_OF_MOVE)


_____________________________________________________________________________________________
*** CID 1700488:           (COPY_INSTEAD_OF_MOVE)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 1428             in <unnamed>::sony_arw6_decode_stream_tile(const unsigned char *, unsigned int)()
1422       if (low_start)
1423       {
1424         SonyArw6Plane cropped(low_count, red_residual.cols);
1425         for (int y = 0; y < low_count; y++)
1426           memcpy(cropped.row(y), red_residual.row(y + low_start),
1427                  sizeof(int32_t) * size_t(red_residual.cols));
>>>     CID 1700488:           (COPY_INSTEAD_OF_MOVE)
>>>     "cropped" is copied in call to copy assignment for class "<unnamed>::SonyArw6Plane", when it could be moved instead.
1428         red_residual = cropped;
1429       }
1430     
1431       std::vector<SonyArw6Plane> b0 =
1432           sony_arw6_decode_packet_arrays(stream, stream_size, dir,
1433                                          header.coded_width, coded_height, 0, 2);
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 1414             in <unnamed>::sony_arw6_decode_stream_tile(const unsigned char *, unsigned int)()
1408       if (low_start)
1409       {
1410         SonyArw6Plane cropped(low_count, green.cols);
1411         for (int y = 0; y < low_count; y++)
1412           memcpy(cropped.row(y), green.row(y + low_start),
1413                  sizeof(int32_t) * size_t(green.cols));
>>>     CID 1700488:           (COPY_INSTEAD_OF_MOVE)
>>>     "cropped" is copied in call to copy assignment for class "<unnamed>::SonyArw6Plane", when it could be moved instead.
1414         green = cropped;
1415       }
1416     
1417       std::vector<SonyArw6Plane> r0 =
1418           sony_arw6_decode_packet_arrays(stream, stream_size, dir,
1419                                          header.coded_width, coded_height, 0, 1);
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 1442             in <unnamed>::sony_arw6_decode_stream_tile(const unsigned char *, unsigned int)()
1436       if (low_start)
1437       {
1438         SonyArw6Plane cropped(low_count, blue_residual.cols);
1439         for (int y = 0; y < low_count; y++)
1440           memcpy(cropped.row(y), blue_residual.row(y + low_start),
1441                  sizeof(int32_t) * size_t(blue_residual.cols));
>>>     CID 1700488:           (COPY_INSTEAD_OF_MOVE)
>>>     "cropped" is copied in call to copy assignment for class "<unnamed>::SonyArw6Plane", when it could be moved instead.
1442         blue_residual = cropped;
1443       }
1444     
1445       for (int group = 1; group <= 3; group++)
1446       {
1447         const int edge_rows = group == 1 ? 0 : (group == 2 ? 1 : 2);

** CID 1700487:       Integer handling issues  (SIGN_EXTENSION)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/unpack_thumb.cpp: 317           in LibRaw::unpack_thumb()()


_____________________________________________________________________________________________
*** CID 1700487:         Integer handling issues  (SIGN_EXTENSION)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/unpack_thumb.cpp: 317             in LibRaw::unpack_thumb()()
311     				&& i < tiff_ifd[pifd].strip_offsets_count; i++)
312                   total_size += tiff_ifd[pifd].strip_byte_counts[i];
313                 if (total_size != (unsigned)t_length) // recalculate colors
314                 {
315                   if (total_size == T.twidth * T.theight * 3)
316                     T.tcolors = 3;
>>>     CID 1700487:         Integer handling issues  (SIGN_EXTENSION)
>>>     Suspicious implicit sign extension: "this->imgdata.thumbnail.theight" with type "ushort" (16 bits, unsigned) is promoted in "this->imgdata.thumbnail.twidth * this->imgdata.thumbnail.theight" to type "int" (32 bits, signed), then sign-extended to type "long long" (64 bits, signed).  If "this->imgdata.thumbnail.twidth * this->imgdata.thumbnail.theight" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1.
317                   else if (total_size == T.twidth * T.theight)
318                     T.tcolors = 1;
319                 }
320                 T.tlength = unsigned(total_size);
321                 THUMB_SIZE_CHECKTNZ(T.tlength);
322                 if (T.thumb)

** CID 1700486:       Integer handling issues  (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4413           in std::ggml_compute_forward_out_prod_q_f32(const ggml_compute_params *, ggml_tensor *)()


_____________________________________________________________________________________________
*** CID 1700486:         Integer handling issues  (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4413             in std::ggml_compute_forward_out_prod_q_f32(const ggml_compute_params *, ggml_tensor *)()
4407         //         dst[i0,i1,i2,i3] += src0[i0,i01,i2,i3] * src1[i1,i01,i2,i3]
4408     
4409         float * wdata = (float *) params->wdata + (ne0 + CACHE_LINE_SIZE_F32) * ith;
4410     
4411         for (int64_t ir = ir0; ir < ir1; ++ir) {
4412             // dst indices
>>>     CID 1700486:         Integer handling issues  (DIVIDE_BY_ZERO)
>>>     In expression "ir / (ne2 * ne1)", division by expression "ne2 * ne1" which may be zero has undefined behavior.
4413             const int64_t i3 = ir/(ne2*ne1);
4414             const int64_t i2 = (ir - i3*ne2*ne1)/ne1;
4415             const int64_t i1 = (ir - i3*ne2*ne1 - i2*ne1);
4416     
4417             const int64_t i02 = i2;
4418             const int64_t i03 = i3;

** CID 1700485:       Integer handling issues  (BAD_SHIFT)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 643           in <unnamed>::SonyArw6NativeBits::read_bits(int)()


_____________________________________________________________________________________________
*** CID 1700485:         Integer handling issues  (BAD_SHIFT)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 643             in <unnamed>::SonyArw6NativeBits::read_bits(int)()
637         while (remaining > 0)
638         {
639           if (bit_ <= 0)
640           {
641             load_next_word();
642             if (status)
>>>     CID 1700485:         Integer handling issues  (BAD_SHIFT)
>>>     In expression "out << remaining", left shifting by more than 31 bits has undefined behavior.  The shift amount, "remaining", is as much as 32.
643               return out << remaining;
644           }
645           const int take = std::min(remaining, bit_);
646           bit_ -= take;
647           out = (out << take) |
648                 uint32_t((cur_ >> bit_) & ((uint64_t(1) << take) - 1));

** CID 1700484:       Performance inefficiencies  (COPY_INSTEAD_OF_MOVE)


_____________________________________________________________________________________________
*** CID 1700484:         Performance inefficiencies  (COPY_INSTEAD_OF_MOVE)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 1518             in <unnamed>::sony_arw6_decode_stream_tile(const unsigned char *, unsigned int)()
1512           sony_arw6_decode_packet_arrays(stream, stream_size, dir,
1513                                          header.coded_width, coded_height, 4, 0);
1514       SonyArw6Plane full_green =
1515           sony_arw6_final_green(green, g4[0], guarded_height ? 2 : 4);
1516     
1517       SonyArw6DecodedTile out;
>>>     CID 1700484:         Performance inefficiencies  (COPY_INSTEAD_OF_MOVE)
>>>     "green" is copied in call to copy assignment for class "<unnamed>::SonyArw6Plane", when it could be moved instead.
1518       out.green = green;
1519       out.red_residual = red_residual;
1520       out.blue_residual = blue_residual;
1521       out.full_green = full_green;
1522       return out;
1523     }

** CID 1700483:       Integer handling issues  (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4924           in std::ggml_compute_forward_get_rows_f32(const ggml_compute_params *, ggml_tensor *)()


_____________________________________________________________________________________________
*** CID 1700483:         Integer handling issues  (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4924             in std::ggml_compute_forward_get_rows_f32(const ggml_compute_params *, ggml_tensor *)()
4918     
4919         // row range for this thread
4920         const int ir0 = dr*ith;
4921         const int ir1 = MIN(ir0 + dr, nr);
4922     
4923         for (int64_t i = ir0; i < ir1; ++i) {
>>>     CID 1700483:         Integer handling issues  (DIVIDE_BY_ZERO)
>>>     In expression "i / (ne11 * ne10)", division by expression "ne11 * ne10" which may be zero has undefined behavior.
4924             const int64_t i12 = i/(ne11*ne10);
4925             const int64_t i11 = (i - i12*ne11*ne10)/ne10;
4926             const int64_t i10 = (i - i12*ne11*ne10 - i11*ne10);
4927             const int64_t i01 = *(int32_t *) ((char *) src1->data + i10*nb10 + i11*nb11 + i12*nb12);
4928     
4929             GGML_ASSERT(i01 >= 0 && i01 < ne01);

** CID 1700482:       Integer handling issues  (BAD_SHIFT)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 647           in <unnamed>::SonyArw6NativeBits::read_bits(int)()


_____________________________________________________________________________________________
*** CID 1700482:         Integer handling issues  (BAD_SHIFT)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 647             in <unnamed>::SonyArw6NativeBits::read_bits(int)()
641             load_next_word();
642             if (status)
643               return out << remaining;
644           }
645           const int take = std::min(remaining, bit_);
646           bit_ -= take;
>>>     CID 1700482:         Integer handling issues  (BAD_SHIFT)
>>>     In expression "out << take", left shifting by more than 31 bits has undefined behavior.  The shift amount, "take", is as much as 32.
647           out = (out << take) |
648                 uint32_t((cur_ >> bit_) & ((uint64_t(1) << take) - 1));
649           remaining -= take;
650         }
651         return out;
652       }

** CID 1700481:       Integer handling issues  (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4622           in std::ggml_compute_forward_set_f32(const ggml_compute_params *, ggml_tensor *)()


_____________________________________________________________________________________________
*** CID 1700481:         Integer handling issues  (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4622             in std::ggml_compute_forward_set_f32(const ggml_compute_params *, ggml_tensor *)()
4616         const int ir0 = dr*ith;
4617         const int ir1 = MIN(ir0 + dr, nr);
4618     
4619         for (int ir = ir0; ir < ir1; ++ir) {
4620             // src0 and dst are viewed with shape of src1 and offset
4621             // => same indices
>>>     CID 1700481:         Integer handling issues  (DIVIDE_BY_ZERO)
>>>     In expression "ir / (ne12 * ne11)", division by expression "ne12 * ne11" which may be zero has undefined behavior.
4622             const int i3 = ir/(ne12*ne11);
4623             const int i2 = (ir - i3*ne12*ne11)/ne11;
4624             const int i1 = (ir - i3*ne12*ne11 - i2*ne11);
4625     
4626             ggml_vec_cpy_f32(nc,
4627                     (float *) ((char *)  dst->data + i3*nb3  + i2*nb2  + i1*nb1  + offset),

** CID 1700480:       Control flow issues  (DEADCODE)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 483           in <unnamed>::sony_arw6_find_streams(const std::vector<unsigned char, std::allocator<unsigned char>> &, int, int)()


_____________________________________________________________________________________________
*** CID 1700480:         Control flow issues  (DEADCODE)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 483             in <unnamed>::sony_arw6_find_streams(const std::vector<unsigned char, std::allocator<unsigned char>> &, int, int)()
477       {
478         for (uint32_t index = 0; index < count; index++)
479         {
480           const uint32_t entry = 0x08 + index * 0x18;
481           if (entry + 0x18 > strip_size)
482           {
>>>     CID 1700480:         Control flow issues  (DEADCODE)
>>>     Execution cannot reach this statement: "streams.clear();".
483             streams.clear();
484             break;
485           }
486           const uint32_t table_offset = sony_arw6_le32(base + entry);
487           const int tile_x = int(sony_arw6_le32(base + entry + 0x08));
488           const int tile_y = int(sony_arw6_le32(base + entry + 0x0c));

** CID 1700479:       Integer handling issues  (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4883           in std::ggml_compute_forward_get_rows_bf16(const ggml_compute_params *, ggml_tensor *)()


_____________________________________________________________________________________________
*** CID 1700479:         Integer handling issues  (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4883             in std::ggml_compute_forward_get_rows_bf16(const ggml_compute_params *, ggml_tensor *)()
4877     
4878         // row range for this thread
4879         const int ir0 = dr*ith;
4880         const int ir1 = MIN(ir0 + dr, nr);
4881     
4882         for (int64_t i = ir0; i < ir1; ++i) {
>>>     CID 1700479:         Integer handling issues  (DIVIDE_BY_ZERO)
>>>     In expression "i / (ne11 * ne10)", division by expression "ne11 * ne10" which may be zero has undefined behavior.
4883             const int64_t i12 = i/(ne11*ne10);
4884             const int64_t i11 = (i - i12*ne11*ne10)/ne10;
4885             const int64_t i10 = (i - i12*ne11*ne10 - i11*ne10);
4886             const int64_t i01 = *(int32_t *) ((char *) src1->data + i10*nb10 + i11*nb11 + i12*nb12);
4887     
4888             GGML_ASSERT(i01 >= 0 && i01 < ne01);

** CID 1700478:       Integer handling issues  (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4801           in std::ggml_compute_forward_get_rows_q(const ggml_compute_params *, ggml_tensor *)()


_____________________________________________________________________________________________
*** CID 1700478:         Integer handling issues  (DIVIDE_BY_ZERO)
/home/gilles/Devel/9.x/core/utilities/searchwindow/thirdparty/llama.cpp/ggml/src/ggml-cpu/ops.cpp: 4801             in std::ggml_compute_forward_get_rows_q(const ggml_compute_params *, ggml_tensor *)()
4795     
4796         // row range for this thread
4797         const int ir0 = dr*ith;
4798         const int ir1 = MIN(ir0 + dr, nr);
4799     
4800         for (int64_t i = ir0; i < ir1; ++i) {
>>>     CID 1700478:         Integer handling issues  (DIVIDE_BY_ZERO)
>>>     In expression "i / (ne11 * ne10)", division by expression "ne11 * ne10" which may be zero has undefined behavior.
4801             const int64_t i12 = i/(ne11*ne10);
4802             const int64_t i11 = (i - i12*ne11*ne10)/ne10;
4803             const int64_t i10 = (i - i12*ne11*ne10 - i11*ne10);
4804             const int64_t i01 = *(int32_t *) ((char *) src1->data + i10*nb10 + i11*nb11 + i12*nb12);
4805     
4806             GGML_ASSERT(i01 >= 0 && i01 < ne01);

** CID 1700477:       Integer handling issues  (SIGN_EXTENSION)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/unpack_thumb.cpp: 317           in LibRaw::unpack_thumb()()


_____________________________________________________________________________________________
*** CID 1700477:         Integer handling issues  (SIGN_EXTENSION)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/unpack_thumb.cpp: 317             in LibRaw::unpack_thumb()()
311     				&& i < tiff_ifd[pifd].strip_offsets_count; i++)
312                   total_size += tiff_ifd[pifd].strip_byte_counts[i];
313                 if (total_size != (unsigned)t_length) // recalculate colors
314                 {
315                   if (total_size == T.twidth * T.theight * 3)
316                     T.tcolors = 3;
>>>     CID 1700477:         Integer handling issues  (SIGN_EXTENSION)
>>>     Suspicious implicit sign extension: "this->imgdata.thumbnail.twidth" with type "ushort" (16 bits, unsigned) is promoted in "this->imgdata.thumbnail.twidth * this->imgdata.thumbnail.theight" to type "int" (32 bits, signed), then sign-extended to type "long long" (64 bits, signed).  If "this->imgdata.thumbnail.twidth * this->imgdata.thumbnail.theight" is greater than 0x7FFFFFFF, the upper bits of the result will all be 1.
317                   else if (total_size == T.twidth * T.theight)
318                     T.tcolors = 1;
319                 }
320                 T.tlength = unsigned(total_size);
321                 THUMB_SIZE_CHECKTNZ(T.tlength);
322                 if (T.thumb)

** CID 1700476:       Performance inefficiencies  (COPY_INSTEAD_OF_MOVE)


_____________________________________________________________________________________________
*** CID 1700476:         Performance inefficiencies  (COPY_INSTEAD_OF_MOVE)
/home/gilles/Devel/9.x/core/libs/rawengine/libraw/src/decoders/sony_arw6.cpp: 1519             in <unnamed>::sony_arw6_decode_stream_tile(const unsigned char *, unsigned int)()
1513                                          header.coded_width, coded_height, 4, 0);
1514       SonyArw6Plane full_green =
1515           sony_arw6_final_green(green, g4[0], guarded_height ? 2 : 4);
1516     
1517       SonyArw6DecodedTile out;
1518       out.green = green;
>>>     CID 1700476:         Performance inefficiencies  (COPY_INSTEAD_OF_MOVE)
>>>     "red_residual" is copied in call to copy assignment for class "<unnamed>::SonyArw6Plane", when it could be moved instead.
1519       out.red_residual = red_residual;
1520       out.blue_residual = blue_residual;
1521       out.full_green = full_green;
1522       return out;
1523     }
1524     


________________________________________________________________________________________________________
To view the defects in Coverity Scan visit, https://scan.coverity.com/projects/digikam?tab=overview

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.kde.org/pipermail/digikam-devel/attachments/20260824/926ae94b/attachment-0001.htm>


More information about the Digikam-devel mailing list