apache / apache/arrow

[C++][Parquet] Fix undefined behavior in memcpy with nullptr for empty ByteArray

Open
#48,744 0 comments 0 reactions 1 assignee Claimed by @rynewang View on GitHub
Component: C++ Component: Parquet
Dominant language
C++
Stars
17.1k
Forks
4.3k
Avg merge
3d 13h
Merged PRs (30d)
88

Description

### Describe the enhancement requested

As noted by @wgtmac in https://github.com/apache/arrow/pull/48717#discussion_r2665550214:

> Since it allows `ptr` to be nullptr for empty string, following `Copy` may be a UB if min is an empty string with nullptr.
>
> ```cpp
> template <>
> inline void TypedStatisticsImpl::Copy(const ByteArray& src, ByteArray* dst,
> ResizableBuffer* buffer) {
> if (dst->ptr == src.ptr) return;
> PARQUET_THROW_NOT_OK(buffer->Resize(src.len, false));
> std::memcpy(buffer->mutable_data(), src.ptr, src.len);
> *dst = ByteArray(src.len, buffer->data());
> }
> ```

When `ByteArray` has `len=0` and `ptr=nullptr` (the default-constructed state per `types.h:649`), calling `std::memcpy` with a nullptr source is undefined behavior according to the C++ standard, even when the size is 0.

This issue also exists in other places:
- `DictDecoderImpl::SetDict` in `decoder.cc:1061`
- Test utilities in `statistics_test.cc` and `column_writer_test.cc`

### Component(s)

C++, Parquet

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.