apache / apache/arrow-java

ArrowFlightJdbcArray.getArray(index, count) can read past the end of the array slice

Offen Anfängerfreundlich
#1,236 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
Java
Sterne
94
Forks
152
Ø Merge
3 T. 16 Std.
Gemergte PRs (30 T.)
11

Beschreibung

`ArrowFlightJdbcArray.checkBoundaries` validates the caller-supplied index against `startOffset + valuesCount`:

```java
private void checkBoundaries(long index, int count) {
if (index < 0 || index + count > this.startOffset + this.valuesCount) {
throw new ArrayIndexOutOfBoundsException();
}
}
```

but `index` is relative to the start of the array; both call sites add `startOffset` to it only afterwards, e.g.

```java
checkBoundaries(index, count);
return getArrayNoBoundCheck(
this.dataVector, LargeMemoryUtil.checkedCastToInt(this.startOffset + index), count);
```

So the accepted range is too large by exactly `startOffset` elements, and `getArray(index, count)` / `getResultSet(index, count)` will read up to that far past the end of the row's slice.

`AbstractArrowFlightJdbcListVectorAccessor` builds these with the offsets of the list element being read, so any row of a list column that does not start at child offset 0 is affected. Reading within the element count the driver itself advertises then returns values belonging to other rows of the shared child vector, and past the child vector's `valueCount` it returns whatever is in allocated-but-unwritten memory.

Reproducer against an `IntVector` of 127 values, with an array covering elements 5..7:

```java
ArrowFlightJdbcArray array = new ArrowFlightJdbcArray(dataVector, 5, 3);
array.getArray(1, 3); // accepted; returns elements 6, 7, 8 — element 8 is outside the array
```

Every existing test constructs the array with `startOffset` 0, where the wrong bound happens to coincide with the correct one, which is why this is not currently caught.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginne in ArrowFlightJdbcArray.checkBoundaries und prüfe sowohl die Aufrufstellen von getArray(index, count) als auch von getResultSet(index, count). Füge einen Regressionstest mit einem startOffset ungleich null hinzu, etwa unter Verwendung des bereitgestellten IntVector-Slices, und führe die vorhandenen ArrowFlightJdbcArray-Tests aus; abgeschlossen ist die Änderung, wenn Anfragen nicht über den Array-Slice hinaus lesen können.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
java
Bereich
database
Issue-Typ
Bug
Schwierigkeit
2/5
Geschätzter Aufwand
1-3 Stunden
Aktivitätsstatus
Ruhig
Klarheit
Klar beschrieben
Anfängerfreundlichkeit
78/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.