Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

bug: ReferenceVisitor::GetReferencedFieldIds dereferences null on a bound COUNT(*)

オープン 初心者向け
#978 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
2/5
見積もり時間
1〜3時間
初心者へのやさしさ
82/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
cpp
領域
backend

調査の方向性

src/iceberg/expression/binder.ccから始め、特にReferenceVisitor::Aggregateを確認し、BoundAggregate::reference()がCOUNT(*)をどのように扱っているかを、src/iceberg/expression/aggregate.ccでの集約の構築と比較してください。aggregate_test.ccにある既存の集約のカバレッジを確認してください。バインドされたCOUNT(*)に対してGetReferencedFieldIdsを呼び出してもクラッシュせず、フィールドIDを一つも追加しなくなれば完了です。

索引モデルが issue の本文から書いたものです。

説明

Summary

ReferenceVisitor::GetReferencedFieldIds (exported via ICEBERG_EXPORT) crashes with a SIGSEGV when the expression tree contains a bound COUNT(*). ReferenceVisitor::Aggregate runs referenced_field_ids_.insert(aggregate->reference()->field_id()), but a COUNT(*) aggregate has a null term, so reference() returns nullptr and ->field_id() dereferences it.

Root Cause

CountStarAggregate is constructed with a null term (src/iceberg/expression/aggregate.cc), and BoundAggregate::reference() returns term() ? term()->reference() : nullptr, so it is nullptr for COUNT(*). src/iceberg/expression/binder.cc dereferences it with no guard. Visit() routes any bound aggregate to Aggregate(), so binding Expressions::CountStar() and calling GetReferencedFieldIds segfaults. COUNT(col) / MAX / MIN have non-null terms and are unaffected.

Impact

No in-tree scan path passes aggregates to GetReferencedFieldIds today (table_scan.cc and manifest_group.cc pass row filters), so the crash lands on a library consumer that does aggregate pushdown through the exported API. COUNT(*) is the most common aggregate, and binding it is a supported, tested workflow (aggregate_test.cc). Java's ReferenceVisitor base throws UnsupportedOperationException on aggregates, a catchable error; the C++ port instead crashes the process.

Proposed Fix

Insert the field id only when reference() is non-null. COUNT(*) then contributes no field ids, which is the correct result for field projection (counting rows reads no columns).

主要言語
C++
スター
226
フォーク
132
平均マージ
1日 11時間
マージ済み PR(30日)
27

環境構築

このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

apache/iceberg-cpp のほかの issue

apache/iceberg-cpp の issue をすべて見る

似ている issue

C++ の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。