[Python] `call_tabular_function()` segfaults for some wrong typed `func_registry` values

Aperta Adatta ai principianti
#51,228 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
82/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
cpp, python
Ambito
backend

Direzione di ricerca

Inizia da pyarrow/src/arrow/python/udf.cc:655, in CallTabularFunction(), e riproduci il crash con la chiamata Python fornita usando i valori di func_registry del tipo errato elencati. Esegui il riproduttore con UBSan o con la wheel interessata e verifica che gli input che non sono FunctionRegistry sollevino costantemente TypeError senza terminare l’interprete.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Component: Python Type: bug
Describe the bug, including details regarding any error messages, version, and platform.
Summary

The behavior of pyarrow.compute.call_tabular_function() depends on the value supplied as a wrong typed func_registry.

Some values, including 0.0, 1, and -1, terminate the interpreter with SIGSEGV.
Most other tested wrong type values do not crash and instead reach the normal missing function ArrowKeyError path.

I think all non-FunctionRegistry values should be handled consistently without terminating the process, preferably by raising TypeError.

I found this while fuzzing Python C extension modules.

Versions

PyArrow 25.0.0, CPython 3.12.3, Ubuntu 24.04 x86_64, glibc 2.39.

Reproducer
import pyarrow.compute as pc

pc.call_tabular_function("", None, 0.0)
Segmentation fault (core dumped)
Input validation behavior

I kept the function name and args=None unchanged and independently varied only func_registry on the same binary wheel.

Result Tested func_registry values
SIGSEGV True, 1, -1, 0.0, 1j, dict
ArrowKeyError from the missing function name None, False, 0, inf, nan, 0j, str, bytes, bytearray, list, tuple, set,object()
ASan/UBSan result

An earlier instrumented variant using the same wrong-typed registry path reported a misaligned member call in CallTabularFunction():

pyarrow/src/arrow/python/udf.cc:655:3: runtime error:
member call on misaligned address 0x00010c3298eb
for type 'arrow::compute::FunctionRegistry', which requires 8 byte alignment

    #0 arrow::py::CallTabularFunction(...)
       pyarrow/src/arrow/python/udf.cc:655:3
    #1 pyarrow._compute.call_tabular_function(...)
       build/_compute.cpp:70892:92

SUMMARY: UndefinedBehaviorSanitizer: undefined-behavior
pyarrow/src/arrow/python/udf.cc:655:3

The sanitizer process exits with code 1 at the first UBSan diagnostic.
ASan does not emit a separate diagnostic when UBSan is configured to stop at that first error.

Component(s)

Python

Lingua principale
C++
Stelle
17.1k
Fork
4.3k
Merge medio
3g 13h
PR unite (30g)
93

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di apache/arrow

Tutte le issue di apache/arrow

Issue simili

Altre issue su C++

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.