fix(arrow/array): validate map builder entry lengths#957
Merged
zeroshade merged 1 commit intoJul 18, 2026
Conversation
fallintoplace
force-pushed
the
fix/map-builder-length-validation
branch
from
July 17, 2026 00:15
1679f66 to
17aefd5
Compare
zeroshade
approved these changes
Jul 18, 2026
zeroshade
left a comment
Member
There was a problem hiding this comment.
Nice hardening. The invariants are correct and match the ListBuilder offset bookkeeping: after N Appends offsets.Len()==Len() (the terminating offset is added later by the list builder), and when an explicit final offset is supplied (Len()+1) requiring it to equal the entry count matches what the list builder would otherwise rely on. keyBuilder/itemBuilder are the struct's field builders, so the struct-length guard correctly catches struct-validity rows with no key/item values, and the *Int32Builder offsets cast is always safe (Map never uses int64 offsets).
Verified on the PR head (17aefd5d):
- The new
TestMapBuilderRejectsInvalidEntryLengthssubtests all pass, and the full./array/suite passes (incl.-race). - No existing map-building path is affected:
./internal/arrjson/,./ipc/,./scalar/,./array/arreflect/all pass andflightsqlvet is clean. All real MapBuilder usages append balanced key+item pairs.
Panics wrap arrow.ErrInvalid consistent with the builder API. LGTM.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rationale for this change
MapBuilder sizes its child struct from the key builder without first checking the item builder. Unequal key and item counts can therefore create malformed map data or defer the failure until later array access.
What changes are included in this PR?
Are these changes tested?
Yes. Tests cover extra keys, extra items, an oversized child struct, too few and too many offsets, and a final offset beyond the available entries. The array package passes normal and race tests.
Are there any user-facing changes?
Malformed map builder state now fails immediately with a descriptive invalid-data panic instead of constructing an inconsistent array or panicking during later access. Valid builder usage is unchanged.