bug: ListTypeFromJson hits undefined behavior when a list type has no "element"
Los mantenedores suelen responder en 2 días
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 78/100
Línea de trabajo
Empieza en ListTypeFromJson en src/iceberg/json_serde.cc, donde el tipo de elemento se lee con el accesor const json[kElement]. MapTypeFromJson en el mismo archivo ya lee key y value mediante GetJsonValue, así que copia ese patrón para kElement. Está terminado cuando un objeto de tipo lista sin "element" devuelve JsonParseError en lugar de provocar comportamiento indefinido, lo que puedes comprobar con la reproducción del issue.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Summary
ListTypeFromJson in src/iceberg/json_serde.cc reads the element type with the const json[kElement] accessor and never checks that the key exists. For a list type object without "element", nlohmann's const operator[] is undefined behavior: with assertions enabled it aborts on JSON_ASSERT(it != m_data.m_value.object->end()), and under NDEBUG it dereferences the end iterator.
Reproduction
auto json = R"({"type":"list","element-id":1,"element-required":true})"_json;
auto result = TypeFromJson(json);
// Debug build: Assertion failed: (it != m_data.m_value.object->end()), function operator[], file json.hpp
Impact
Every list type goes through TypeFromJson, so a schema with a list-typed field that lacks "element" hits this whether the list is top level or nested in a struct, map or list. SchemaFromJson reaches it when parsing table metadata schemas, the add-schema table update, and the REST CreateTableRequest. Per SECURITY-THREAT-MODEL.md catalog-supplied metadata is trusted input, so this is a robustness issue rather than a security one.
Proposed Fix
Read the key with GetJsonValue<nlohmann::json>(json, kElement), the way MapTypeFromJson reads key and value, so a missing key returns JsonParseError.
Raised in https://github.com/apache/iceberg-cpp/pull/982#pullrequestreview-5477946927.
- Lenguaje dominante
- C++
- Estrellas
- 226
- Forks
- 133
- Merge medio
- 3 d 13 h
- PR fusionados (30 d)
- 27
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de apache/iceberg-cpp
-
bug: ReferenceVisitor::GetReferencedFieldIds dereferences null on a bound COUNT(*)Posiblemente ocupada @LuciferYang la tomó hace 10 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
apache/iceberg-cpp#978 ·
Los mantenedores suelen responder en 2 días
-
bug: InMemoryCatalog skips the namespace existence check in CreateTable and RegisterTablePosiblemente ocupada @LuciferYang la tomó hace 10 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
apache/iceberg-cpp#977 ·
Los mantenedores suelen responder en 2 días
-
Support Iceberg table encryption (Java-compatible)Posiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abierto
Dificultad 5/5 Más de una semana Aptitud para principiantes 8/100
apache/iceberg-cpp#988 · 1 comentario ·
Los mantenedores suelen responder en 2 días
-
bug: expression JSON deserialization throws an uncaught exception on a non-string "type"/"term"Posiblemente ocupada @LuciferYang la tomó hace 10 días. Abierto
Dificultad 3/5 1-2 días Aptitud para principiantes 75/100
apache/iceberg-cpp#979 ·
Los mantenedores suelen responder en 2 días
-
Dificultad 5/5 Más de una semana Aptitud para principiantes 20/100
apache/iceberg-cpp#959 · 1 comentario ·
Los mantenedores suelen responder en 2 días
Todos los issues de apache/iceberg-cpp
Issues similares
-
Incorrect Link in README.mdPosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 95/100
flameshot-org/flameshot#4996 ·
Los mantenedores suelen responder en 2 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 64/100
utopia-rise/godot-jvm#1004 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
Los mantenedores suelen responder en 3 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
Los mantenedores suelen responder en 1 día
-
chore(build): TxCoordinator.cpp uses the deprecated shared_ptr atomic free functionsPosiblemente ocupada @w5jwp la tomó hoy. Abierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 84/100
aethersdr/AetherSDR#6368 · 1 comentario ·
Los mantenedores suelen responder en 1 día