bug: ReferenceVisitor::GetReferencedFieldIds dereferences null on a bound COUNT(*)
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
調査の方向性
src/iceberg/expression/binder.ccから始め、特にReferenceVisitor::Aggregateを確認し、BoundAggregate::reference()がCOUNT(*)をどのように扱っているかを、src/iceberg/expression/aggregate.ccでの集約の構築と比較してください。aggregate_test.ccにある既存の集約のカバレッジを確認してください。バインドされたCOUNT(*)に対してGetReferencedFieldIdsを呼び出してもクラッシュせず、フィールドIDを一つも追加しなくなれば完了です。
索引モデルが issue の本文から書いたものです。
説明
Summary
ReferenceVisitor::GetReferencedFieldIds (exported via ICEBERG_EXPORT) crashes with a SIGSEGV when the expression tree contains a bound COUNT(*). ReferenceVisitor::Aggregate runs referenced_field_ids_.insert(aggregate->reference()->field_id()), but a COUNT(*) aggregate has a null term, so reference() returns nullptr and ->field_id() dereferences it.
Root Cause
CountStarAggregate is constructed with a null term (src/iceberg/expression/aggregate.cc), and BoundAggregate::reference() returns term() ? term()->reference() : nullptr, so it is nullptr for COUNT(*). src/iceberg/expression/binder.cc dereferences it with no guard. Visit() routes any bound aggregate to Aggregate(), so binding Expressions::CountStar() and calling GetReferencedFieldIds segfaults. COUNT(col) / MAX / MIN have non-null terms and are unaffected.
Impact
No in-tree scan path passes aggregates to GetReferencedFieldIds today (table_scan.cc and manifest_group.cc pass row filters), so the crash lands on a library consumer that does aggregate pushdown through the exported API. COUNT(*) is the most common aggregate, and binding it is a supported, tested workflow (aggregate_test.cc). Java's ReferenceVisitor base throws UnsupportedOperationException on aggregates, a catchable error; the C++ port instead crashes the process.
Proposed Fix
Insert the field id only when reference() is non-null. COUNT(*) then contributes no field ids, which is the correct result for field projection (counting rows reads no columns).
- 主要言語
- C++
- スター
- 226
- フォーク
- 132
- 平均マージ
- 1日 11時間
- マージ済み PR(30日)
- 27
環境構築
このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
apache/iceberg-cpp のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
apache/iceberg-cpp#977 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
apache/iceberg-cpp#973 ·
メンテナーはふだん 1 日以内に返信
-
bug: expression JSON deserialization throws an uncaught exception on a non-string "type"/"term"オープン
難易度 3/5 1〜2日 初心者へのやさしさ 75/100
apache/iceberg-cpp#979 ·
メンテナーはふだん 1 日以内に返信
-
難易度 5/5 1週間以上 初心者へのやさしさ 20/100
apache/iceberg-cpp#959 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 4/5 3〜5日 初心者へのやさしさ 45/100
apache/iceberg-cpp#955 · コメント 3 件 · リアクション 1 件 ·
メンテナーはふだん 1 日以内に返信
apache/iceberg-cpp の issue をすべて見る
似ている issue
-
HasBacktrace Priority-Critical
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
azerothcore/azerothcore-wotlk#27921 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
yhirose/cpp-peglib#344 ·
-
bug-unconfirmed
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
shadps4-emu/shadps4-qtlauncher#453 ·
メンテナーはふだん 2 日以内に返信