Hacktoberfest 2026 : les issues que les mainteneurs ont marquées pour octobre, ouvertes et accessibles aux débutants. Parcourir les issues Hacktoberfest

Paths taken from table metadata are used without containment checks against the table location

Ouverte
#3,973 1 commentaire 0 réactions 0 personnes assignées Voir sur GitHub

Personne n'a encore pris cette issue.

Évaluation

Difficulté
4/5
Temps estimé
3-5 jours
Accessibilité débutants
56/100
Type d'issue
Bug
Clarté
Plutôt claire
Activité
Active
Stack technique
python
Domaine
databases, security

Piste de recherche

Start in pyiceberg/catalog/init.py at Catalog.purge_table and trace delete_data_files, then inspect LocationProvider.init in pyiceberg/table/locations.py and the WRITE_DATA_PATH and WRITE_METADATA_PATH handling. Determine how containment should be checked without breaking documented redirected locations. Done means paths outside the table location cannot be acted on, with regression coverage for both deletion and write-path cases.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Description

bug

Two places where a path read from table metadata is acted on without any check that it falls under the table's own location.

1. purge_table deletes whatever paths the manifests name

Catalog.purge_table (pyiceberg/catalog/__init__.py) walks every snapshot, collects manifests, manifest lists and previous metadata files, and calls delete_data_files(io, manifests_to_delete). The file_path entries inside those manifests are followed as given. Nothing constrains them to the table's location, so a manifest naming a path elsewhere in the warehouse results in a delete against that path, performed with the credentials of whoever ran the purge.

2. write.data.path and write.metadata.path are accepted verbatim

if path := table_properties.get(TableProperties.WRITE_DATA_PATH):
    self.data_path = path.rstrip("/")
else:
    self.data_path = f"{self.table_location.rstrip('/')}/data"

LocationProvider.__init__ (pyiceberg/table/locations.py) takes the configured value as-is. Subsequent writes for that table go wherever it points, again with the writing principal's credentials.

Note that redirecting the write location is the documented purpose of these two properties, so the gap is the absence of a containment check rather than the fact that the properties are honoured at all.


Issue investigation generated via claude, reviewed by Sung, Kevin, Fokko.

Langage dominant
Python
Étoiles
1.1k
Forks
589
Merge moyen
2 j 11 h
PR mergées (30 j)
75

Guide de contribution

Aucun guide de contribution indexé pour ce dépôt

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Autres issues de apache/iceberg-python

Toutes les issues de apache/iceberg-python

Issues similaires

Plus d'issues Python

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.