Paths taken from table metadata are used without containment checks against the table location
Maintainer antworten meist innerhalb von 1 Tag
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Anfängerfreundlichkeit
- 56/100
Rechercherichtung
Start in pyiceberg/catalog/init.py at Catalog.purge_table and trace delete_data_files, then inspect LocationProvider.init in pyiceberg/table/locations.py and the WRITE_DATA_PATH and WRITE_METADATA_PATH handling. Determine how containment should be checked without breaking documented redirected locations. Done means paths outside the table location cannot be acted on, with regression coverage for both deletion and write-path cases.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
Two places where a path read from table metadata is acted on without any check that it falls under the table's own location.
1. purge_table deletes whatever paths the manifests name
Catalog.purge_table (pyiceberg/catalog/__init__.py) walks every snapshot, collects manifests, manifest lists and previous metadata files, and calls delete_data_files(io, manifests_to_delete). The file_path entries inside those manifests are followed as given. Nothing constrains them to the table's location, so a manifest naming a path elsewhere in the warehouse results in a delete against that path, performed with the credentials of whoever ran the purge.
2. write.data.path and write.metadata.path are accepted verbatim
if path := table_properties.get(TableProperties.WRITE_DATA_PATH):
self.data_path = path.rstrip("/")
else:
self.data_path = f"{self.table_location.rstrip('/')}/data"
LocationProvider.__init__ (pyiceberg/table/locations.py) takes the configured value as-is. Subsequent writes for that table go wherever it points, again with the writing principal's credentials.
Note that redirecting the write location is the documented purpose of these two properties, so the gap is the absence of a containment check rather than the fact that the properties are honoured at all.
Issue investigation generated via claude, reviewed by Sung, Kevin, Fokko.
- Vorherrschende Sprache
- Python
- Sterne
- 1.1k
- Forks
- 606
- Ø Merge
- 1 T. 11 Std.
- Gemergte PRs (30 T.)
- 75
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Hat eine Pull-Request-Vorlage
- Kein Beitragsleitfaden
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus apache/iceberg-python
-
View does not expose metadata_location: RestCatalog.load_view discards it from the server's responseEvtl. vergeben @Soumo-git-hub hat das vor 2 Tagen übernommen. Offenkind:bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 84/100
apache/iceberg-python#4073 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 70/100
apache/iceberg-python#4010 · 3 Kommentare · 1 Reaktion ·
Maintainer antworten meist innerhalb von 1 Tag
-
to_bytes silently rescales a Decimal with a negative scaleEvtl. vergeben @Rodrigo-Palma hat das vor 18 Tagen übernommen. Offen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
apache/iceberg-python#3996 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Deletion vector bitmap count is read from the blob and used as a loop bound without validationEvtl. vergeben @ghoshp83 hat das vor 18 Tagen übernommen. Offenbug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
apache/iceberg-python#3979 ·
Maintainer antworten meist innerhalb von 1 Tag
-
FsspecFileIO: `_adls` mutates shared properties, so a second storage account gets the first account's filesystemEvtl. vergeben @krishnakaanchan-png hat das vor 35 Tagen übernommen. Offen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
apache/iceberg-python#3885 ·
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in apache/iceberg-python
Ähnliche Issues
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 83/100
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 86/100
FuRongJun-1999/dsh-memory#65 ·
Maintainer antworten meist innerhalb von 1 Tag
-
ci needs-ac
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
Ikalus1988/MisakaNet#2930 ·
Maintainer antworten meist innerhalb von 1 Tag
-
bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
Qiskit/qiskit-aer#2466 ·
-
area/cli
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100