Commit 8ae386707 for llama.cpp

commit 8ae386707bed05f02354dbfc6fa5ee0cf58e5f0f
Author: Jasmine-tim <403568753@qq.com>
Date:   Fri Oct 9 21:57:33 2026 +0800

    ggml: fix OOB write in ggml_acc with negative offset (#30135)

    ggml_acc_impl narrowed a size_t offset to int32_t without checking that it
    fits, so a large offset could truncate to a negative int32_t. The forward
    then sign-extended it to a huge size_t and the bounds assertion wrapped,
    allowing an OOB write below the dst buffer. Check the offset before the
    narrowing, matching the existing check in ggml_set_impl.

diff --git a/ggml/src/ggml.c b/ggml/src/ggml.c
index 9bcabdbd3..882cdf4a5 100644
--- a/ggml/src/ggml.c
+++ b/ggml/src/ggml.c
@@ -2199,6 +2199,7 @@ static struct ggml_tensor * ggml_acc_impl(

     struct ggml_tensor * result = inplace ? ggml_view_tensor(ctx, a) : ggml_dup_tensor(ctx, a);

+    GGML_ASSERT(offset < (size_t)(1 << 30));
     int32_t params[] = { nb1, nb2, nb3, offset, inplace ? 1 : 0 };
     ggml_set_op_params(result, params, sizeof(params));