Skip to content

Validate mbarrier arrive-count upper bound - #3368

Open
dajiaohuang wants to merge 1 commit into
tile-ai:mainfrom
dajiaohuang:fix/3030-mbarrier-count-upper-bound
Open

dajiaohuang wants to merge 1 commit into
tile-ai:mainfrom
dajiaohuang:fix/3030-mbarrier-count-upper-bound

Conversation

@dajiaohuang

@dajiaohuang dajiaohuang commented Oct 1, 2026 •

Copy link
Copy Markdown

Summary

  • Enforce the PTX mbarrier.init arrive-count range [1, 2^20 - 1] for both CTA and cluster barrier allocations.
  • Add frontend regressions for the largest valid count, the first invalid count, and an invalid list entry.

This follows up on #3030. Merged #3112 rejected non-positive values; a positive value of 2^20 was still forwarded to codegen. The upper bound is specified in the NVIDIA PTX ISA 9.0.

Validation

  • Ruff check/format, Python syntax compilation, and git diff --check pass.
  • Focused pytest collection stops in TileLang's conftest because this checkout lacks �uild/lib and �uild/tvm; no test cases ran.

Summary

This PR adds an upper-bound check for arrive_count in alloc_barrier and alloc_cluster_barrier. Both functions accept counts from 1 through 2**20 - 1 and reject larger counts.

The regression test covers the maximum valid count and invalid counts above the limit, including shaped counts.

Validation

The supplied PR context reports that Ruff check and format, Python syntax compilation, and git diff --check pass. Focused pytest collection stopped in TileLang’s conftest because build/lib and build/tvm are missing. No test cases ran.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

👋 Hi! Thank you for contributing to the TileLang project.

Please remember to run pre-commit run --all-files in the root directory of the project to ensure your changes are properly linted and formatted. This will help ensure your contribution passes the format check.

We appreciate you taking this step! Our team will review your contribution, and we look forward to your awesome work! 🚀

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: tile-ai/tilelang/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 147413e9-d0f7-4d3d-852f-568d6931f013

📥 Commits

Reviewing files that changed from the base of the PR and between 994b44e and 0af7b81.

📒 Files selected for processing (2)
  • testing/python/language/test_tilelang_language_alloc.py
  • tilelang/language/allocate.py

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

Barrier allocation functions now reject arrive counts above 2**20 - 1. Tests cover both functions, including oversized counts and the maximum supported count.

Changes

Barrier arrive count limits

Layer / File(s) Summary
Enforce arrive-count bounds
tilelang/language/allocate.py
A shared maximum defines the supported range. Both barrier allocation functions reject counts above it, and their documentation states the inclusive range.
Test arrive-count bounds
testing/python/language/test_tilelang_language_alloc.py
The test kernel accepts either barrier allocator. Tests check oversized scalar and shaped counts and verify that the maximum supported count traces successfully.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Suggested reviewers: leiwang1999

Merge Risk: ⚪ Minimal · up to 0af7b

The allocator changes and boundary-test assertions align with the stated arrive-count range. The focused tests could not run in this checkout, so normal CI should confirm them before merge.

Security Architecture Review

Security architecture risk: ⚪ Minimal · up to 0af7b

The change strengthens an existing input limit without adding access, privileges, or external exposure. Unsupported counts are rejected before barrier allocation.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The demonstrated exposure is caller-supplied arrive counts entering the two Python barrier allocators and then code-generation metadata. The change narrows that path; the supplied evidence does not establish remote reachability or tenant-level exposure.

Trust Boundaries and Controls

  • observed — For ordinary scalar integers and stable integer lists, either range violation raises before buffer allocation or barrier_init publication. The added upper-bound control therefore does not create a partial barrier-state path for those invalid inputs.

Resilience and Maintainability Implications

  • observed — Non-integer inputs are materialized twice: validation uses the first traversal, while allocation and metadata use the second. One-shot or stateful iterables can therefore produce different values. This consistency weakness predates the PR, lies beyond the declared integer-list contract, and is not an introduced architecture concern.

Hardening Proposals

  • proposed — If broader iterable support is intended, normalize once and use the validated snapshot for allocation and metadata emission. This would address the pre-existing consistency gap, not a newly introduced exposure.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 37.50% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 8 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: validating the mbarrier arrive-count upper bound.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant