[Bug] Flaky SIGSEGV in VariantParquetTest: Arrow IO thread frees PoolBuffer after the test's memory pool is destroyed
@SteNicholas ya está trabajando en esto.
Desde el 23/9/2026.
Evaluación
Este issue todavía no se ha evaluado.
Descripción
Search before asking
- I searched in the issues and found nothing similar.
Paimon-cpp version
main, observed on commit dc745fe91932dc2cba919fb13639dfc427280006 (the change in that commit only touches realtime/, unrelated to this failure).
Minimal reproduce step
Flaky; observed in CI job gcc-release-x86_64: https://github.com/apache/paimon-cpp/actions/runs/35845901520/job/107134278444
paimon-parquet-format-test crashes with SIGSEGV right after VariantParquetTest.WriteAndReadRoundTrip passes, while VariantParquetTest.ShreddedWriteAndReadRoundTrip is starting:
[ RUN ] VariantParquetTest.ShreddedWriteAndReadRoundTrip
build_support/run-test.sh: line 98: 67868 Segmentation fault (core dumped)
Program terminated with signal SIGSEGV, Segmentation fault.
Thread 1 (Arrow IO thread pool):
#0 arrow::PoolBuffer::~PoolBuffer()
#1 arrow::Future<std::shared_ptr<arrow::Buffer>>::SetResult(...)::{lambda(void*)#1}::_FUN(void*)
#2 arrow::ConcreteFutureImpl::~ConcreteFutureImpl()
#3 std::_Sp_counted_base<...>::_M_release_last_use_cold()
#4 arrow::internal::FnOnce<void ()>::FnImpl<std::_Bind<arrow::detail::ContinueFuture (arrow::Future<std::shared_ptr<arrow::Buffer>>, arrow::io::RandomAccessFile::ReadAsync(arrow::io::IOContext const&, long, long)::{lambda()#1})>>::~FnImpl()
#5 arrow::internal::ThreadPool::LaunchWorkersUnlocked(int)::{lambda()#1} ...
The main thread is already running the next test (VariantShreddingWritePlan::CreateFromPhysicalSchema) and is unrelated to the crash.
What doesn't meet your expectations?
The test binary should not crash. The crash is a use-after-free of the Arrow memory pool in the test fixture:
VariantParquetTest::SetUp()creates a per-test pool adaptor:arrow_pool_ = GetArrowPool(pool_);(src/paimon/format/parquet/variant_parquet_test.cpp). It is destroyed together with the fixture.- Several tests (
WriteAndReadRoundTrip,ShreddedWriteAndReadRoundTrip, and the helper around line 548) open the file for a raw sanity check with the plain Arrow reader:
Only the rawauto file = arrow::io::ReadableFile::Open(file_path_, arrow_pool_.get()); ::parquet::arrow::OpenFile(file.ValueOrDie(), arrow_pool_.get(), &raw_reader);arrow::MemoryPool*is passed, so nothing keeps the adaptor alive. - With Arrow 17,
ArrowReaderProperties::pre_buffer()defaults totrue, soReadTableissuesRandomAccessFile::ReadAsync.ReadableFiledoes not override it, so the base implementation submitsReadAtto the IO thread pool and the resultPoolBufferis allocated fromarrow_pool_. - The IO worker holds the last reference to the future (and therefore the buffer) until its task object is destroyed, which can happen after the reader has consumed the data and the test has finished. When the fixture is torn down first,
~PoolBuffer()callsFree()on the already destroyed adaptor -> SIGSEGV.
Paimon's own read path (ArrowInputStreamAdapter::ReadAsync) is not affected: it uses a callback-based implementation and already retains the pool with the returned buffer (#182). This issue is limited to tests that use arrow::io::ReadableFile with a raw pointer to a short-lived pool.
Anything else?
Possible fixes (test-only):
- Use a process-lifetime Arrow pool for these raw sanity-check readers, e.g.
arrow::default_memory_pool(), instead of the per-fixturearrow_pool_.get(); or - Disable pre-buffering for the raw reader (
ArrowReaderProperties::set_pre_buffer(false)), so no async IO task outlives the test; or - Read through
ArrowInputStreamAdapter, which keeps the pool alive for returned buffers.
Other tests using arrow::io::ReadableFile::Open(..., pool.get()) with a per-test pool may have the same latent issue and should be checked as well.
- Lenguaje dominante
- C++
- Estrellas
- 65
- Forks
- 29
- Merge medio
- 2 d 11 h
- PR fusionados (30 d)
- 79
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de apache/paimon-cpp
-
enhancement
apache/paimon-cpp#381 · 1 asignado ·
-
Dificultad 4/5 3-5 días Aptitud para principiantes 30/100
apache/paimon-cpp#375 · 1 asignado ·
-
enhancement
Dificultad 5/5 Más de una semana Aptitud para principiantes 45/100
apache/paimon-cpp#361 · 1 asignado ·
-
enhancement
Dificultad 4/5 3-5 días Aptitud para principiantes 45/100
apache/paimon-cpp#325 · 1 asignado ·
-
enhancement
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
apache/paimon-cpp#319 · 1 reacción · 1 asignado ·
Todos los issues de apache/paimon-cpp
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
flutter-webrtc/flutter-webrtc#2206 ·
-
litertlm-android AAR ships no consumer ProGuard rules → "mid == null" SIGABRT in minified apps Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
google-ai-edge/LiteRT-LM#3739 ·
-
Component: GLib
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
-
Mute ydb/tests/functional/dstool/test_canonical_requests.py.Test.test_group_take_snapshot in main Abiertoai_reviewed
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
ydb-platform/ydb#53974 · 3 comentarios ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
google/libultrahdr#485 ·