Fix plugin EP allocator deleter lifetime - #29770
Merged
Merged
Conversation
Capture the OrtEpFactory pointer directly in plugin allocator release callbacks instead of capturing transient owner objects. This keeps allocator destruction safe when shared or per-session allocator wrappers outlive the object that created the callback.
xadupre
approved these changes
Jul 21, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Cherrypick #29663 so that it can pass CI for 1.28 release.
Summary
This PR fixes an AppVerifier failure seen during ONNX Runtime / onnxruntime_genai shutdown with the plugin EP path:
The bug is in the allocator deleter lifetime. Plugin EP allocators are released later by an
OrtAllocatorUniquePtrcustom deleter, but the deleter was reachingOrtEpFactory::ReleaseAllocatorthrough transient owner captures:Environment::CreateSharedAllocatorImplcapturedep_deviceby reference.PluginExecutionProvider::CreatePreferredAllocatorscapturedthis.The fix captures the required
OrtEpFactory*directly in both deleters and calls:ep_factory->ReleaseAllocator(ep_factory, allocator);This keeps allocator destruction independent from the stack reference / provider object used when the deleter was created, while preserving the same allocator ownership and release API.
Changed files
onnxruntime/core/session/environment.cconnxruntime/core/session/plugin_ep/ep_plugin_provider_interfaces.ccVerification
Built ORT and the TRT-RTX EP repro stack against TRT-RTX 1.6.1.114, then ran the DeepSeek WinML AppVerifier repro.
"appVerifierEnabled": true,"appVerifierFailed": falseorigin/mainnegative control:"appVerifierEnabled": true,"appVerifierFailed": trueThis confirms the invalid pointer read still reproduces on
origin/mainand is removed by the allocator deleter lifetime change.