ADRs tagged correctness¶
Auto-generated by scripts/docs/generate-adr-by-tag.sh. Edit ADR Tags: lines to update.
131 ADR(s) carry this tag.
| ID | Title |
|---|---|
| ADR-0131 | Port Netflix#1382 — cuMemFreeAsync → cuMemFree in vmaf_cuda_picture_free |
| ADR-0132 | Port Netflix#1406 — feature_collector mount/unmount model-list bugfix |
| ADR-0135 | Port Netflix#1424 — expose built-in VMAF model-version iterator |
| ADR-0152 | vmaf_read_pictures rejects non-monotonic indices |
| ADR-0153 | float_ms_ssim init rejects input below 176×176 |
| ADR-0154 | vmaf_score_pooled returns -EAGAIN for pending features |
| ADR-0155 | Defer fix for Netflix#955 — i4_adm_cm int32 rounding overflow |
| ADR-0156 | CUDA backend: graceful error propagation (Netflix#1420) |
| ADR-0157 | CUDA preallocation memory leak fix + vmaf_cuda_state_free public API (Netflix#1300) |
| ADR-0228 | Tombstone: heap-buffer-overflow fix in the Y4M 411 to 422jpeg conversion |
| ADR-0358 | CUDA motion correctness — SAD race, pinned-mem leak, and motion2/motion3 precision parity with CPU |
| ADR-0376 | Fix silent error-swallow in Vulkan buffer-invalidate readback functions |
| ADR-0385 | Feature-extractor deduplication by provided-feature names |
| ADR-0438 | CLI parser short-option handler coverage invariant |
| ADR-0460 | Dispatch-strategy registry audit 2026-05-15 |
| ADR-0461 | CLI validates positive dimensions and chroma-alignment on input videos |
| ADR-0552 | Deterministic wavefront reduction for integer_vif_hip horizontal kernels |
| ADR-0556 | Python / MCP / AI silent-fallback audit fixes (2026-05-18) |
| ADR-0564 | Real integer_ssim GPU kernels (CUDA, HIP, SYCL) — replace silent float_ssim substitution |
| ADR-0566 | 0566-hip-vif-per-feature-places4-gate.md |
| ADR-0583 | Add enable_chroma option to the float_ms_ssim extractor |
| ADR-0602 | macOS SIGSEGV in vmaf_write_output — pic_cnt underflow + missing vmaf NULL guard |
| ADR-0606 | macOS SIGSEGV deep-fix in output.c writers (PR #1403 follow-up) |
| ADR-0620 | Scaffold audit P0 — three silent-correctness fixes |
| ADR-0754 | 0754-cuda-ssim-vert-combine-ldg-pinned-leak.md |
| ADR-0775 | DNN ORT Backend Audit Findings |
| ADR-0778 | Picture pool / framesync lifecycle audit and targeted fixes |
| ADR-0795 | Clarify and harden VmafFeatureExtractor.prev_ref thread-safety invariant |
| ADR-0869 | Sanitizer-Pass Cleanup — CAMBI Option-Type Mismatch and AVX{2,512} ADM Signed-Shift UB |
| ADR-0871 | SSIM SIMD dispatch installation must be pthread_once-guarded |
| ADR-0872 | POSIX I/O EINTR-retry + return-value audit on fork-added C |
| ADR-0960 | GPU runtime error-path leak fixes — round 25 (A.1 + A.2 + A.3) |
| ADR-0961 | Controller queue — roll back PullWork on post-update Get failure (round-25 audit B.1) |
| ADR-0962 | Controller fixes — implement StreamJobs snapshot and add reaper stop signal (round-25 audit B.3 + B.4) |
| ADR-0963 | ai/src: guard NaN propagation in eval + tune (round-25 audit C.1 + C.2) |
| ADR-0971 | Test suite: NULL-check malloc in 3 test files (Round 27 audit D.1) |
| ADR-1008 | Fix C lifecycle bugs — pic_cnt double-increment, div-by-zero in pooled score, silent test failures |
| ADR-1009 | Fix Go shutdown / goroutine correctness — WaitForShutdown unconditional block, unbounded GracefulStop |
| ADR-1010 | MCP server JSON parse guards — vmaf output and ffprobe output |
| ADR-1011 | Add static to TU-internal CUDA helper functions — VIF, ADM, motion |
| ADR-1012 | Go queue state-machine guards — PullWork AND-status, ReportResult idempotency |
| ADR-1020 | acq_rel memory ordering on ref-count decrement + mutex-destroy-after-unlock + picture-pool unlock ordering |
| ADR-1022 | Cast dst_buf_read_sz operands to size_t in y4m_input to prevent signed-integer overflow |
| ADR-1023 | MCP server asyncio correctness — async wrappers for blocking I/O |
| ADR-1024 | R6 per-metric scoring guards — PSNR/ADM correctness fixes |
| ADR-1025 | R6 CUDA/HIP kernel correctness fixes |
| ADR-1026 | R6 SYCL kernel correctness — rd-stride OOB and unchecked graph_wait |
| ADR-1030 | HIP adm_decouple dangling body + VIF wavefront 32-bit carry + Metal motion vertical halo |
| ADR-1032 | vmaf_init double-init guard and vmaf_close pointer-contract documentation |
| ADR-1033 | CPU-side scoring NaN/UB guards across PSNR/SSIM/MS-SSIM/ADM/CAMBI/MOTION |
| ADR-1034 | Fix SYCL integer_vif rd_stride OOB on odd widths and integer_motion UV queue sync gap |
| ADR-1038 | MCP cross-surface precision-default and probe-precision drift |
| ADR-1039 | Fix CERT MEM04-C realloc OOM safety in vendored libsvm |
| ADR-1051 | Port upstream batch-threading + picture-pool defaults (dff4082b + 46d3a154) |
| ADR-1057 | Revert float-ADM SIMD dispatch wiring (PR #685) — NEON FMA divergence unfixable in scope |
| ADR-1060 | Round 10 C++23 wave error-path cleanup |
| ADR-1065 | Go staticcheck r10 — poll-loop timer leak and missing body guards |
| ADR-1068 | Fix fast-path data race in gpu_dispatch_env.cpp via atomic publication flag |
| ADR-1073 | Fix vmaf_score_at_index EAGAIN-guard misapplication for model output slots |
| ADR-1075 | MCP HTTP transport POST /v1/score body-validation edge cases |
| ADR-1081 | vmaf_bench correctness — unchecked alloc returns and wall-clock timer |
| ADR-1083 | y4m_input_fetch_frame signed-integer overflow + fread(NULL) UB fixes |
| ADR-1088 | CLI flag-parsing hardening — parse_unsigned overflow/negative guards and --help in cli_parse.cpp |
| ADR-1092 | framesync producer-death deadlock — abort flag + shutdown broadcast |
| ADR-1097 | Atomic file writes for AI-script cache and output files |
| ADR-1100 | Skip GPU-flagged extractors when flags == 0 in vmaf_get_feature_extractor_by_feature_name |
| ADR-1103 | 1103-hip-vif-mirror2-boundary.md |
| ADR-1104 | Remove AVX-512 dispatch from float VIF convolution to restore Netflix golden scores |
| ADR-1121 | SYCL QSV zero-copy — P010 pixel normalization and separate-session decode contract |
| ADR-1191 | Integer ADM rejects CSF configurations its fixed-point storage cannot represent |
| ADR-1194 | One integer-ADM angle_flag predicate for every backend |
| ADR-1199 | Order caller-written CUDA pictures once per frame, at the dispatch point |
| ADR-1202 | GPU SpEED-chroma twins report singularity separately from failure |
| ADR-1203 | psnr_hvs_cuda defaults enable_chroma to true, matching every other backend |
| ADR-1204 | GPU ADM contrast-masking twins clamp the far edge instead of mirroring it |
| ADR-1205 | The ssimulacra2 FMA unification extends to the scalar fallback and every GPU host copy |
| ADR-1206 | Every CUDA parity test also runs against a second, larger fixture |
| ADR-1207 | A test gates every feature's score against the host instruction set |
| ADR-1208 | The ssimulacra2 edge-diff SIMD loops take their difference in double |
| ADR-1209 | --gpumask keeps rejecting negative values; the test script uses a positive mask |
| ADR-1210 | The SYCL integer-ADM contrast-masking kernel mirrors its near edge |
| ADR-1211 | integer_adm_hip stages the luma plane onto the device before launching |
| ADR-1212 | The GPU float_moment twins normalise by the bit-depth scaler on the host |
| ADR-1213 | ciede_hip sizes its chroma staging with the picture's ceil dimensions |
| ADR-1214 | The float-ADM GPU twins ignore adm_csf_scale in Watson mode and share the CPU's option aliases |
| ADR-1215 | The 16-bpc CUDA PSNR kernel takes the plane index the host has always passed |
| ADR-1216 | The GPU motion3 twins apply motion_fps_weight exactly once |
| ADR-1217 | The GPU float-VIF kernels read vif_sigma_nsq and vif_enhn_gain_limit from their options |
| ADR-1218 | The GPU SpEED twins zero the device solution and report singularity from the temporal path |
| ADR-1219 | The HIP and Metal CAMBI twins use the shared TVI bisection and the CPU's border rules |
| ADR-1220 | The GPU float-ADM kernels honour adm_p_norm, adm_bypass_cm and adm_skip_scale0 |
| ADR-1221 | clip_db is a ceiling on the MS-SSIM dB output, not a clamp on the linear score |
| ADR-1224 | CUDA Tile C++ is not adopted; the audit's incidental findings are |
| ADR-1301 | A non-finite SpEED score fails the frame instead of being published |
| ADR-1302 | A non-finite feature score fails the frame, everywhere |
| ADR-1324 | Resolve GPU float-SSIM auto-scale before backend initialization |
| ADR-1325 | Normalize integer ADM Barten weights with one exponent per scale |
| ADR-1326 | Use a fixed-point oracle for SYCL motion-add-UV parity |
| ADR-1334 | Extend MS-SSIM option parity to the Metal twin |
| ADR-1335 | Bind research-digest debt to the trusted merge base |
| ADR-1336 | Tear down CUDA resources in their owning context |
| ADR-1381 | HIP tile loads and the ADM vertical DWT clamp their rows; vif_hip hands frames below 16 pixels to the CPU |
| ADR-1393 | CAMBI's c-values walks clip the window to the frame at every edge |
| ADR-1396 | vmaf_init() treats its handle as output-only again |
| ADR-1398 | CLI accepts odd dimensions for chroma-subsampled raw YUV inputs |
| ADR-1402 | Integer ADM keeps the scale-0 masking centre tap in int32 and clamps the excess in int64 |
| ADR-1413 | Every integer ADM implementation bounds the enhancement gain with the scalar's truncated double product |
| ADR-1472 | The integer ADM weight limits follow from the contrast-masking cube and the largest wavelet coefficient of a scale |
| ADR-1473 | The x86 float ADM wavelet and CSF kernels return the scalar bits and are dispatched; the two reduction kernels are removed |
| ADR-1479 | ciede upsamples 4:2:2 chroma with the horizontal flag for columns and the vertical flag for rows; upstream has the two swapped, and ciede2000 differs by up to 0.153 on 4:2:2 input |
| ADR-1480 | speed_temporal sizes its frame buffers for the prescaled height; upstream sizes them for the source height and reads past them when speed_prescale is above 1 |
| ADR-1481 | an extractor that fails on a worker thread fails the run; upstream drops the worker's error and returns success without the metric |
| ADR-1482 | integer adm on frames of 17 to 32 pixels reads inside the frame and rounds a zero shift with 0; upstream reads index -1 there, and scale 3 differs by up to 0.23 |
| ADR-1483 | a subsampled chroma plane of an odd-sized picture is rounded up; upstream rounds down, and chroma metrics on odd sizes differ by up to 0.83 dB |
| ADR-1484 | float_ms_ssim takes the magnitude of a scale's terms before pow(); upstream raises a negative structure term to a fractional power and returns NaN on anti-correlated frames |
| ADR-1485 | the aggregate PSNR of a plane without error is the per-frame cap; upstream publishes a ceiling 54 dB above it on the 1080p checkerboard chroma |
| ADR-1486 | float_motion scales its scale-1 planes with the stride it was called with; upstream recomputes the stride from the plane width, and motion_add_scale1 with motion_add_uv differs by up to 25 |
| ADR-1494 | adm and float_adm refuse frames below 17x17; upstream's integer ADM crashes there and its float ADM returns values that at 8x8 and 12x9 depend on the heap |
| ADR-1520 | Feature-vector tiny models request their inputs, score at flush, and fail on a missing input |
| ADR-1527 | TransNet V2 runs upstream's 100-frame windows on 0..255 thumbnails and binds its output by position |
| ADR-1540 | The mobilesal extractor pads frames to a multiple of 8 for the saliency students |
| ADR-1558 | A codec-aware sidecar declares how its codec block's scalar slots are normalised |
| ADR-1679 | The Metal IOSurface import reads NV12 and P010 surfaces itself, and the FFmpeg filter imports whole frames |
| ADR-1688 | The SYCL zero-copy path admits only extractors that compute from the shared luma, and names every other one |
| ADR-1761 | The libvmaf_sycl filter retries a failed VA import, then stops naming the frame; each input is imported with its own VA display |
| ADR-1768 | The FFmpeg libvmaf and libvmaf_cuda filters print no pooled score after a mid-run error |
| ADR-1900 | Deterministic verification and state contract for VPL decode retry ceiling |
| ADR-1917 | The integer ADM scale-0 horizontal and vertical weight limit is 43900, set by the CSF stage's 16-bit magnitude |
| ADR-1918 | Samples above 2^bpc - 1 are invalid input; an opt-in check refuses them |
| ADR-2167 | -qpfile on libx264 applies its offsets through quant_offsets |
| ADR-2343 | Reference-exact extractors by default, with a named Netflix compatibility mode |