apache / apache/arrow-java

Byte-array elements leak in `FromSchemaByteArray()`

Open Beginner friendly
#1,205 0 comments 0 reactions 0 assignees View on GitHub
Type: bug
Dominant language
Java
Stars
94
Forks
152
Avg merge
3d 16h
Merged PRs (30d)
11

Description

### Describe the bug, including details regarding any error messages, version, and platform.

I found a possible JNI array leak in `FromSchemaByteArray()` when the serialized schema cannot be parsed.

File: `dataset/src/main/cpp/jni_util.cc`

Function: `FromSchemaByteArray`

Relevant code:

```cpp
jbyte* schemaBytes_data =
env->GetByteArrayElements(schemaBytes, nullptr);
auto serialized_schema = std::make_shared(
reinterpret_cast(schemaBytes_data),
schemaBytes_len);
arrow::io::BufferReader buf_reader(serialized_schema);

ARROW_ASSIGN_OR_RAISE(
std::shared_ptr schema,
arrow::ipc::ReadSchema(&buf_reader, &in_memo))

env->ReleaseByteArrayElements(
schemaBytes, schemaBytes_data, JNI_ABORT);
return schema;
```

`GetByteArrayElements()` returns a pointer that must be paired with
`ReleaseByteArrayElements()`.

`ARROW_ASSIGN_OR_RAISE` returns immediately when `ReadSchema()` returns an
error. On that path, the release below the macro is skipped, so the acquired
array elements remain unreleased:

```text
GetByteArrayElements succeeds
-> ReadSchema returns an error
-> ARROW_ASSIGN_OR_RAISE returns
-> ReleaseByteArrayElements is skipped
```

The function is used by the public native `createDataset()` method:

```cpp
schema = JniGetOrThrow(
FromSchemaByteArray(env, schema_bytes));
```

Malformed, corrupted, or incompatible serialized schema bytes can therefore
reach this path. Repeated failed calls can retain copied array buffers or keep
Java arrays pinned, depending on the JVM implementation.

Suggested fix: release the elements before propagating the parse result, for
example:

```cpp
auto schema_result =
arrow::ipc::ReadSchema(&buf_reader, &in_memo);

env->ReleaseByteArrayElements(
schemaBytes, schemaBytes_data, JNI_ABORT);

return schema_result;
```

An RAII guard for `schemaBytes_data` would also ensure release if additional
early returns are introduced later.

Contributor guide

Open the contributing guide

Research direction

Start in dataset/src/main/cpp/jni_util.cc at FromSchemaByteArray() and inspect the GetByteArrayElements, ReadSchema, and ReleaseByteArrayElements flow. Verify the release also occurs when parsing fails, then exercise the malformed or incompatible schema path through createDataset(); done means the acquired JNI array elements are released on both success and error paths.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp, java
Domain
backend
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
85/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.