Skip to content

fix(arrow/array): validate map builder entry lengths#957

Merged
zeroshade merged 1 commit into
apache:mainfrom
fallintoplace:fix/map-builder-length-validation
Jul 18, 2026
Merged

fix(arrow/array): validate map builder entry lengths#957
zeroshade merged 1 commit into
apache:mainfrom
fallintoplace:fix/map-builder-length-validation

Conversation

@fallintoplace

@fallintoplace fallintoplace commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

Rationale for this change

MapBuilder sizes its child struct from the key builder without first checking the item builder. Unequal key and item counts can therefore create malformed map data or defer the failure until later array access.

What changes are included in this PR?

  • Reject unequal key and item builder lengths before array construction resets the builders.
  • Reject a child struct length that exceeds the entry count.
  • Validate that the offset count matches the map count.
  • Validate any explicitly supplied final offset against the available entries.
  • Report invariant failures as panics wrapping arrow.ErrInvalid, consistent with the builder API.

Are these changes tested?

Yes. Tests cover extra keys, extra items, an oversized child struct, too few and too many offsets, and a final offset beyond the available entries. The array package passes normal and race tests.

Are there any user-facing changes?

Malformed map builder state now fails immediately with a descriptive invalid-data panic instead of constructing an inconsistent array or panicking during later access. Valid builder usage is unchanged.

@fallintoplace
fallintoplace requested a review from zeroshade as a code owner July 16, 2026 12:59
@fallintoplace
fallintoplace force-pushed the fix/map-builder-length-validation branch from 1679f66 to 17aefd5 Compare July 17, 2026 00:15

@zeroshade zeroshade left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice hardening. The invariants are correct and match the ListBuilder offset bookkeeping: after N Appends offsets.Len()==Len() (the terminating offset is added later by the list builder), and when an explicit final offset is supplied (Len()+1) requiring it to equal the entry count matches what the list builder would otherwise rely on. keyBuilder/itemBuilder are the struct's field builders, so the struct-length guard correctly catches struct-validity rows with no key/item values, and the *Int32Builder offsets cast is always safe (Map never uses int64 offsets).

Verified on the PR head (17aefd5d):

  • The new TestMapBuilderRejectsInvalidEntryLengths subtests all pass, and the full ./array/ suite passes (incl. -race).
  • No existing map-building path is affected: ./internal/arrjson/, ./ipc/, ./scalar/, ./array/arreflect/ all pass and flightsql vet is clean. All real MapBuilder usages append balanced key+item pairs.

Panics wrap arrow.ErrInvalid consistent with the builder API. LGTM.

@zeroshade
zeroshade merged commit 621a4ed into apache:main Jul 18, 2026
23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants