Qualcomm: reject a delegate whose QNN graph I/O does not match its si… - #22239
Conversation
…gnature At runtime the delegate binds its arguments positionally, walking the tensor lists recovered from the context binary and consuming one argument per tensor the name prefixes mark as bindable. A graph that publishes more bindable I/O than the program passes therefore reads past the end of the argument list on device, where all it leaves behind is a fault address and two counts. Everything needed to catch that is already in hand at the end of _build_op_wrappers: nodes_to_wrappers holds every tensor that will be serialized into the binary, under the names the runtime will read, and the delegated program carries the signature those names have to agree with. Compare them there and report the offending names, rather than letting the disagreement reach a device. The comparison uses the runtime's own rules so the two cannot drift: an "input_"-prefixed tensor binds an input, an "output_"-prefixed tensor binds an output, and anything carrying "mutbuf_" is skipped, since mutable buffers are threaded through separately and never consume an argument. Prebuilt context binaries return earlier in the same function and never reach the check; preprocess_multimethod runs it once per program against that program's own signature; tensor-dump mode promotes native tensors to APP_READ without giving them an output_ prefix, so they are excluded too. Checked against ten real lowerings -- single input/output, multi-input, multi-output, partially-consumed multi-output and a mutable buffer, each in fp16 and quantized -- with no false positives. The unit tests drive the comparison directly with stub wrapper names, covering the matching case, a mutable buffer that must not consume an argument, and a surplus on either side. One case is worth knowing about: a model returning the same tensor twice has two user_outputs but one output_-prefixed wrapper, so this fires. That is a real defect today, since the runtime's output loop never fills the second argument, and the fix belongs on the runtime side rather than in weakening the check. Authored with assistance from Claude Code.
🔗 Helpful Links🧪 See artifacts and rendered test results at hud.pytorch.org/pr/pytorch/executorch/22239
Note: Links to docs will display an error until the docs builds have been completed. This comment was automatically generated by Dr. CI and updates every 15 minutes. |
This PR needs a
|
winskuo-quic
left a comment
There was a problem hiding this comment.
LGTM. Thanks for the PR.
May I know how I could reproduce this error?
Repro on current main, no custom op needed: class ValuesOnly(torch.nn.Module): topk returns (values, indices); the model reads only values, so the signature has 1 output. But is_graph_output() is asked per op rather than per output, so the builder publishes both: QNN declares 1 graph inputs and 2 graph outputs; signature declares 1 user inputs and 1 user outputs #22011 fixes the cause , with it applied the same model lowers clean and the check doesn't fire. Verified both ways. |
…gnature
At runtime the delegate binds its arguments positionally, walking the tensor lists recovered from the context binary and consuming one argument per tensor the name prefixes mark as bindable. A graph that publishes more bindable I/O than the program passes therefore reads past the end of the argument list on device, where all it leaves behind is a fault address and two counts.
Everything needed to catch that is already in hand at the end of _build_op_wrappers: nodes_to_wrappers holds every tensor that will be serialized into the binary, under the names the runtime will read, and the delegated program carries the signature those names have to agree with. Compare them there and report the offending names, rather than letting the disagreement reach a device.
The comparison uses the runtime's own rules so the two cannot drift: an "input_"-prefixed tensor binds an input, an "output_"-prefixed tensor binds an output, and anything carrying "mutbuf_" is skipped, since mutable buffers are threaded through separately and never consume an argument. Prebuilt context binaries return earlier in the same function and never reach the check; preprocess_multimethod runs it once per program against that program's own signature; tensor-dump mode promotes native tensors to APP_READ without giving them an output_ prefix, so they are excluded too.
Checked against ten real lowerings -- single input/output, multi-input, multi-output, partially-consumed multi-output and a mutable buffer, each in fp16 and quantized -- with no false positives. The unit tests drive the comparison directly with stub wrapper names, covering the matching case, a mutable buffer that must not consume an argument, and a surplus on either side.
One case is worth knowing about: a model returning the same tensor twice has two user_outputs but one output_-prefixed wrapper, so this fires. That is a real defect today, since the runtime's output loop never fills the second argument, and the fix belongs on the runtime side rather than in weakening the check.