bug: ListTypeFromJson hits undefined behavior when a list type has no "element"
维护者通常 2 天内回复
评估
调研方向
从 src/iceberg/json_serde.cc 中的 ListTypeFromJson 开始,它通过 const 访问器 json[kElement] 读取元素类型。同一文件中的 MapTypeFromJson 已经通过 GetJsonValue 读取 key 和 value,因此为 kElement 复制这一模式。当缺少 "element" 的列表类型对象返回 JsonParseError,而不是触发未定义行为时即完成,可以用 issue 中的复现步骤进行验证。
由索引模型根据 Issue 内容生成。
描述
Summary
ListTypeFromJson in src/iceberg/json_serde.cc reads the element type with the const json[kElement] accessor and never checks that the key exists. For a list type object without "element", nlohmann's const operator[] is undefined behavior: with assertions enabled it aborts on JSON_ASSERT(it != m_data.m_value.object->end()), and under NDEBUG it dereferences the end iterator.
Reproduction
auto json = R"({"type":"list","element-id":1,"element-required":true})"_json;
auto result = TypeFromJson(json);
// Debug build: Assertion failed: (it != m_data.m_value.object->end()), function operator[], file json.hpp
Impact
Every list type goes through TypeFromJson, so a schema with a list-typed field that lacks "element" hits this whether the list is top level or nested in a struct, map or list. SchemaFromJson reaches it when parsing table metadata schemas, the add-schema table update, and the REST CreateTableRequest. Per SECURITY-THREAT-MODEL.md catalog-supplied metadata is trusted input, so this is a robustness issue rather than a security one.
Proposed Fix
Read the key with GetJsonValue<nlohmann::json>(json, kElement), the way MapTypeFromJson reads key and value, so a missing key returns JsonParseError.
Raised in https://github.com/apache/iceberg-cpp/pull/982#pullrequestreview-5477946927.
- 主要语言
- C++
- 星标
- 226
- 派生
- 133
- 平均合并
- 3 天 13 小时
- 30 天内合并 PR
- 27
环境准备
这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
apache/iceberg-cpp 的其他 Issue
-
bug: ReferenceVisitor::GetReferencedFieldIds dereferences null on a bound COUNT(*)可能已有人在做 @LuciferYang 于 9 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 82/100
apache/iceberg-cpp#978 ·
维护者通常 2 天内回复
-
bug: InMemoryCatalog skips the namespace existence check in CreateTable and RegisterTable可能已有人在做 @LuciferYang 于 9 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 78/100
apache/iceberg-cpp#977 ·
维护者通常 2 天内回复
-
Support Iceberg table encryption (Java-compatible)可能已有人在做 关联的 PR 仍在进行中或已合并。 未关闭
难度 5/5 一周以上 新手友好度 8/100
apache/iceberg-cpp#988 · 1 条评论 ·
维护者通常 2 天内回复
-
bug: expression JSON deserialization throws an uncaught exception on a non-string "type"/"term"可能已有人在做 @LuciferYang 于 9 天前认领。 未关闭
难度 3/5 1-2 天 新手友好度 75/100
apache/iceberg-cpp#979 ·
维护者通常 2 天内回复
-
难度 5/5 一周以上 新手友好度 20/100
apache/iceberg-cpp#959 · 1 条评论 ·
维护者通常 2 天内回复
查看 apache/iceberg-cpp 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 64/100
utopia-rise/godot-jvm#1004 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 70/100
维护者通常 3 天内回复
-
难度 2/5 1-3 小时 新手友好度 70/100
维护者通常 1 天内回复
-
new contributor
难度 2/5 1-3 小时 新手友好度 65/100
维护者通常 1 天内回复
-
Component: R
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复