Skip to content

ADRs tagged correctness

Auto-generated by scripts/docs/generate-adr-by-tag.sh. Edit ADR Tags: lines to update.

131 ADR(s) carry this tag.

ID Title
ADR-0131 Port Netflix#1382 — cuMemFreeAsync → cuMemFree in vmaf_cuda_picture_free
ADR-0132 Port Netflix#1406 — feature_collector mount/unmount model-list bugfix
ADR-0135 Port Netflix#1424 — expose built-in VMAF model-version iterator
ADR-0152 vmaf_read_pictures rejects non-monotonic indices
ADR-0153 float_ms_ssim init rejects input below 176×176
ADR-0154 vmaf_score_pooled returns -EAGAIN for pending features
ADR-0155 Defer fix for Netflix#955 — i4_adm_cm int32 rounding overflow
ADR-0156 CUDA backend: graceful error propagation (Netflix#1420)
ADR-0157 CUDA preallocation memory leak fix + vmaf_cuda_state_free public API (Netflix#1300)
ADR-0228 Tombstone: heap-buffer-overflow fix in the Y4M 411 to 422jpeg conversion
ADR-0358 CUDA motion correctness — SAD race, pinned-mem leak, and motion2/motion3 precision parity with CPU
ADR-0376 Fix silent error-swallow in Vulkan buffer-invalidate readback functions
ADR-0385 Feature-extractor deduplication by provided-feature names
ADR-0438 CLI parser short-option handler coverage invariant
ADR-0460 Dispatch-strategy registry audit 2026-05-15
ADR-0461 CLI validates positive dimensions and chroma-alignment on input videos
ADR-0552 Deterministic wavefront reduction for integer_vif_hip horizontal kernels
ADR-0556 Python / MCP / AI silent-fallback audit fixes (2026-05-18)
ADR-0564 Real integer_ssim GPU kernels (CUDA, HIP, SYCL) — replace silent float_ssim substitution
ADR-0566 0566-hip-vif-per-feature-places4-gate.md
ADR-0583 Add enable_chroma option to the float_ms_ssim extractor
ADR-0602 macOS SIGSEGV in vmaf_write_output — pic_cnt underflow + missing vmaf NULL guard
ADR-0606 macOS SIGSEGV deep-fix in output.c writers (PR #1403 follow-up)
ADR-0620 Scaffold audit P0 — three silent-correctness fixes
ADR-0754 0754-cuda-ssim-vert-combine-ldg-pinned-leak.md
ADR-0775 DNN ORT Backend Audit Findings
ADR-0778 Picture pool / framesync lifecycle audit and targeted fixes
ADR-0795 Clarify and harden VmafFeatureExtractor.prev_ref thread-safety invariant
ADR-0869 Sanitizer-Pass Cleanup — CAMBI Option-Type Mismatch and AVX{2,512} ADM Signed-Shift UB
ADR-0871 SSIM SIMD dispatch installation must be pthread_once-guarded
ADR-0872 POSIX I/O EINTR-retry + return-value audit on fork-added C
ADR-0960 GPU runtime error-path leak fixes — round 25 (A.1 + A.2 + A.3)
ADR-0961 Controller queue — roll back PullWork on post-update Get failure (round-25 audit B.1)
ADR-0962 Controller fixes — implement StreamJobs snapshot and add reaper stop signal (round-25 audit B.3 + B.4)
ADR-0963 ai/src: guard NaN propagation in eval + tune (round-25 audit C.1 + C.2)
ADR-0971 Test suite: NULL-check malloc in 3 test files (Round 27 audit D.1)
ADR-1008 Fix C lifecycle bugs — pic_cnt double-increment, div-by-zero in pooled score, silent test failures
ADR-1009 Fix Go shutdown / goroutine correctness — WaitForShutdown unconditional block, unbounded GracefulStop
ADR-1010 MCP server JSON parse guards — vmaf output and ffprobe output
ADR-1011 Add static to TU-internal CUDA helper functions — VIF, ADM, motion
ADR-1012 Go queue state-machine guards — PullWork AND-status, ReportResult idempotency
ADR-1020 acq_rel memory ordering on ref-count decrement + mutex-destroy-after-unlock + picture-pool unlock ordering
ADR-1022 Cast dst_buf_read_sz operands to size_t in y4m_input to prevent signed-integer overflow
ADR-1023 MCP server asyncio correctness — async wrappers for blocking I/O
ADR-1024 R6 per-metric scoring guards — PSNR/ADM correctness fixes
ADR-1025 R6 CUDA/HIP kernel correctness fixes
ADR-1026 R6 SYCL kernel correctness — rd-stride OOB and unchecked graph_wait
ADR-1030 HIP adm_decouple dangling body + VIF wavefront 32-bit carry + Metal motion vertical halo
ADR-1032 vmaf_init double-init guard and vmaf_close pointer-contract documentation
ADR-1033 CPU-side scoring NaN/UB guards across PSNR/SSIM/MS-SSIM/ADM/CAMBI/MOTION
ADR-1034 Fix SYCL integer_vif rd_stride OOB on odd widths and integer_motion UV queue sync gap
ADR-1038 MCP cross-surface precision-default and probe-precision drift
ADR-1039 Fix CERT MEM04-C realloc OOM safety in vendored libsvm
ADR-1051 Port upstream batch-threading + picture-pool defaults (dff4082b + 46d3a154)
ADR-1057 Revert float-ADM SIMD dispatch wiring (PR #685) — NEON FMA divergence unfixable in scope
ADR-1060 Round 10 C++23 wave error-path cleanup
ADR-1065 Go staticcheck r10 — poll-loop timer leak and missing body guards
ADR-1068 Fix fast-path data race in gpu_dispatch_env.cpp via atomic publication flag
ADR-1073 Fix vmaf_score_at_index EAGAIN-guard misapplication for model output slots
ADR-1075 MCP HTTP transport POST /v1/score body-validation edge cases
ADR-1081 vmaf_bench correctness — unchecked alloc returns and wall-clock timer
ADR-1083 y4m_input_fetch_frame signed-integer overflow + fread(NULL) UB fixes
ADR-1088 CLI flag-parsing hardening — parse_unsigned overflow/negative guards and --help in cli_parse.cpp
ADR-1092 framesync producer-death deadlock — abort flag + shutdown broadcast
ADR-1097 Atomic file writes for AI-script cache and output files
ADR-1100 Skip GPU-flagged extractors when flags == 0 in vmaf_get_feature_extractor_by_feature_name
ADR-1103 1103-hip-vif-mirror2-boundary.md
ADR-1104 Remove AVX-512 dispatch from float VIF convolution to restore Netflix golden scores
ADR-1121 SYCL QSV zero-copy — P010 pixel normalization and separate-session decode contract
ADR-1191 Integer ADM rejects CSF configurations its fixed-point storage cannot represent
ADR-1194 One integer-ADM angle_flag predicate for every backend
ADR-1199 Order caller-written CUDA pictures once per frame, at the dispatch point
ADR-1202 GPU SpEED-chroma twins report singularity separately from failure
ADR-1203 psnr_hvs_cuda defaults enable_chroma to true, matching every other backend
ADR-1204 GPU ADM contrast-masking twins clamp the far edge instead of mirroring it
ADR-1205 The ssimulacra2 FMA unification extends to the scalar fallback and every GPU host copy
ADR-1206 Every CUDA parity test also runs against a second, larger fixture
ADR-1207 A test gates every feature's score against the host instruction set
ADR-1208 The ssimulacra2 edge-diff SIMD loops take their difference in double
ADR-1209 --gpumask keeps rejecting negative values; the test script uses a positive mask
ADR-1210 The SYCL integer-ADM contrast-masking kernel mirrors its near edge
ADR-1211 integer_adm_hip stages the luma plane onto the device before launching
ADR-1212 The GPU float_moment twins normalise by the bit-depth scaler on the host
ADR-1213 ciede_hip sizes its chroma staging with the picture's ceil dimensions
ADR-1214 The float-ADM GPU twins ignore adm_csf_scale in Watson mode and share the CPU's option aliases
ADR-1215 The 16-bpc CUDA PSNR kernel takes the plane index the host has always passed
ADR-1216 The GPU motion3 twins apply motion_fps_weight exactly once
ADR-1217 The GPU float-VIF kernels read vif_sigma_nsq and vif_enhn_gain_limit from their options
ADR-1218 The GPU SpEED twins zero the device solution and report singularity from the temporal path
ADR-1219 The HIP and Metal CAMBI twins use the shared TVI bisection and the CPU's border rules
ADR-1220 The GPU float-ADM kernels honour adm_p_norm, adm_bypass_cm and adm_skip_scale0
ADR-1221 clip_db is a ceiling on the MS-SSIM dB output, not a clamp on the linear score
ADR-1224 CUDA Tile C++ is not adopted; the audit's incidental findings are
ADR-1301 A non-finite SpEED score fails the frame instead of being published
ADR-1302 A non-finite feature score fails the frame, everywhere
ADR-1324 Resolve GPU float-SSIM auto-scale before backend initialization
ADR-1325 Normalize integer ADM Barten weights with one exponent per scale
ADR-1326 Use a fixed-point oracle for SYCL motion-add-UV parity
ADR-1334 Extend MS-SSIM option parity to the Metal twin
ADR-1335 Bind research-digest debt to the trusted merge base
ADR-1336 Tear down CUDA resources in their owning context
ADR-1381 HIP tile loads and the ADM vertical DWT clamp their rows; vif_hip hands frames below 16 pixels to the CPU
ADR-1393 CAMBI's c-values walks clip the window to the frame at every edge
ADR-1396 vmaf_init() treats its handle as output-only again
ADR-1398 CLI accepts odd dimensions for chroma-subsampled raw YUV inputs
ADR-1402 Integer ADM keeps the scale-0 masking centre tap in int32 and clamps the excess in int64
ADR-1413 Every integer ADM implementation bounds the enhancement gain with the scalar's truncated double product
ADR-1472 The integer ADM weight limits follow from the contrast-masking cube and the largest wavelet coefficient of a scale
ADR-1473 The x86 float ADM wavelet and CSF kernels return the scalar bits and are dispatched; the two reduction kernels are removed
ADR-1479 ciede upsamples 4:2:2 chroma with the horizontal flag for columns and the vertical flag for rows; upstream has the two swapped, and ciede2000 differs by up to 0.153 on 4:2:2 input
ADR-1480 speed_temporal sizes its frame buffers for the prescaled height; upstream sizes them for the source height and reads past them when speed_prescale is above 1
ADR-1481 an extractor that fails on a worker thread fails the run; upstream drops the worker's error and returns success without the metric
ADR-1482 integer adm on frames of 17 to 32 pixels reads inside the frame and rounds a zero shift with 0; upstream reads index -1 there, and scale 3 differs by up to 0.23
ADR-1483 a subsampled chroma plane of an odd-sized picture is rounded up; upstream rounds down, and chroma metrics on odd sizes differ by up to 0.83 dB
ADR-1484 float_ms_ssim takes the magnitude of a scale's terms before pow(); upstream raises a negative structure term to a fractional power and returns NaN on anti-correlated frames
ADR-1485 the aggregate PSNR of a plane without error is the per-frame cap; upstream publishes a ceiling 54 dB above it on the 1080p checkerboard chroma
ADR-1486 float_motion scales its scale-1 planes with the stride it was called with; upstream recomputes the stride from the plane width, and motion_add_scale1 with motion_add_uv differs by up to 25
ADR-1494 adm and float_adm refuse frames below 17x17; upstream's integer ADM crashes there and its float ADM returns values that at 8x8 and 12x9 depend on the heap
ADR-1520 Feature-vector tiny models request their inputs, score at flush, and fail on a missing input
ADR-1527 TransNet V2 runs upstream's 100-frame windows on 0..255 thumbnails and binds its output by position
ADR-1540 The mobilesal extractor pads frames to a multiple of 8 for the saliency students
ADR-1558 A codec-aware sidecar declares how its codec block's scalar slots are normalised
ADR-1679 The Metal IOSurface import reads NV12 and P010 surfaces itself, and the FFmpeg filter imports whole frames
ADR-1688 The SYCL zero-copy path admits only extractors that compute from the shared luma, and names every other one
ADR-1761 The libvmaf_sycl filter retries a failed VA import, then stops naming the frame; each input is imported with its own VA display
ADR-1768 The FFmpeg libvmaf and libvmaf_cuda filters print no pooled score after a mid-run error
ADR-1900 Deterministic verification and state contract for VPL decode retry ceiling
ADR-1917 The integer ADM scale-0 horizontal and vertical weight limit is 43900, set by the CSF stage's 16-bit magnitude
ADR-1918 Samples above 2^bpc - 1 are invalid input; an opt-in check refuses them
ADR-2167 -qpfile on libx264 applies its offsets through quant_offsets
ADR-2343 Reference-exact extractors by default, with a named Netflix compatibility mode