apache / apache/iceberg-python

Implementation classes named in table properties are imported and instantiated without a type check

Đang mở
#3,932 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
bug
Ngôn ngữ chính
Python
Star
1.1k
Fork
581
Merge trung bình
1 ngày 17 giờ
Pull request đã merge (30 ngày)
77

Mô tả

Three properties name a class that PyIceberg imports and calls:

| Property | Resolved by | Called as |
|---|---|---|
| `py-io-impl` | `_import_file_io` (`pyiceberg/io/__init__.py`) | `class_(properties)` |
| `write.py-location-provider.impl` | `_import_location_provider` (`pyiceberg/table/locations.py`) | `class_(table_location, table_properties)` |
| `s3.retry-strategy-impl` | `_import_retry_strategy` (`pyiceberg/io/pyarrow.py`) | `class_()` |

Each follows the same pattern:

```python
module = importlib.import_module(module_name)
class_ = getattr(module, class_name)
return class_(...)
```

None of the three checks that the resolved object is the type it is about to be used as — there is no `issubclass` against `FileIO`, `LocationProvider`, or `S3RetryStrategy`. Any importable dotted name resolves and is called, with the property map passed as an argument in two of the three cases.

All three properties are read from the merged table property map, so their values can originate in a table's metadata rather than in the operator's catalog configuration.

---
Issue investigation generated via claude, reviewed by Sung, Kevin, Fokko.

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Hướng nghiên cứu

Bắt đầu với _import_file_io trong pyiceberg/io/__init__.py, _import_location_provider trong pyiceberg/table/locations.py và _import_retry_strategy trong pyiceberg/io/pyarrow.py. Theo dõi cách từng thuộc tính được phân giải và gọi, sau đó xác minh rằng chỉ các lớp con của FileIO, LocationProvider hoặc S3RetryStrategy được chấp nhận trước khi khởi tạo; hoàn tất nghĩa là cả ba đường dẫn đều từ chối các lớp có thể import không liên quan.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
python
Lĩnh vực
security
Loại issue
Lỗi
Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức độ hoạt động
Sôi nổi
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
68/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.