apache / apache/iceberg-python

Implementation classes named in table properties are imported and instantiated without a type check

Aberta
#3,932 0 comentários 0 reações 0 responsáveis Ver no GitHub
bug
Linguagem predominante
Python
Estrelas
1.1k
Forks
581
Merge médio
1d 17h
PRs com merge (30d)
78

Descrição

Three properties name a class that PyIceberg imports and calls:

| Property | Resolved by | Called as |
|---|---|---|
| `py-io-impl` | `_import_file_io` (`pyiceberg/io/__init__.py`) | `class_(properties)` |
| `write.py-location-provider.impl` | `_import_location_provider` (`pyiceberg/table/locations.py`) | `class_(table_location, table_properties)` |
| `s3.retry-strategy-impl` | `_import_retry_strategy` (`pyiceberg/io/pyarrow.py`) | `class_()` |

Each follows the same pattern:

```python
module = importlib.import_module(module_name)
class_ = getattr(module, class_name)
return class_(...)
```

None of the three checks that the resolved object is the type it is about to be used as — there is no `issubclass` against `FileIO`, `LocationProvider`, or `S3RetryStrategy`. Any importable dotted name resolves and is called, with the property map passed as an argument in two of the three cases.

All three properties are read from the merged table property map, so their values can originate in a table's metadata rather than in the operator's catalog configuration.

---
Issue investigation generated via claude, reviewed by Sung, Kevin, Fokko.

Guia de contribuição

Nenhum guia de contribuição indexado para este repositório

Direção de pesquisa

Comece com _import_file_io em pyiceberg/io/__init__.py, _import_location_provider em pyiceberg/table/locations.py e _import_retry_strategy em pyiceberg/io/pyarrow.py. Rastreie como cada propriedade é resolvida e invocada e, em seguida, verifique se somente subclasses de FileIO, LocationProvider ou S3RetryStrategy são aceitas antes da instanciação; considera-se concluído quando os três caminhos rejeitarem classes importáveis não relacionadas.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
python
Domínio
security
Tipo de issue
Bug
Dificuldade
3/5
Tempo estimado
1-2 dias
Status de atividade
Ativa
Clareza
Razoavelmente clara
Facilidade para iniciantes
68/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.