Conversation
|
|
There was a problem hiding this comment.
🟡 Changes recommended
The decoder change still allocates miniblock scratch space unconditionally (including for single-value pages) and the new guard should account for required min_delta_ bytes, leaving a remaining allocation-DoS gap that should be closed.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
This PR hardens the C++ Parquet DELTA_BINARY_PACKED decoder against corrupt page headers that can otherwise drive disproportionate memory allocations and produce misleading EOF errors, aligning behavior with the security/robustness goals described in GH-50314.
Changes:
- Add header validation in
DeltaBitPackDecoder::InitHeaderto reject pages whose miniblock count is incompatible with the remaining input bytes and emit a more actionableParquetException. - Add new encoding tests to cover the single-value page path and the corrupt-header rejection case (including allocation behavior via
ProxyMemoryPool).
File summaries
| File | Description |
|---|---|
| cpp/src/parquet/decoder.cc | Adds early validation/error reporting for invalid DELTA_BINARY_PACKED miniblock headers (and aims to prevent oversized allocations). |
| cpp/src/parquet/encoding_test.cc | Adds regression tests for single-value decoding and for rejecting invalid miniblock-width headers without allocating. |
Review details
- Files reviewed: 2/2 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
|
There was a problem hiding this comment.
🟢 Approval recommended
The changes directly address the allocation-before-validation issue with clear guards and are covered by focused regression tests.
Review details
- Files reviewed: 2/2 changed files
- Comments generated: 0 new
- Review effort level: Lite
|
|
bb561d0 to
18ae360
Compare
…ders InitHeader() sizes the bit-width buffer from the header's miniblock count without tying it to the page size, so a 10-byte page claiming 2^20 miniblocks allocates 1 MiB before failing. InitBlock() reads one bit-width byte per miniblock, so such a page can never decode. Signed-off-by: 1fanwang <1fannnw@gmail.com>
Single-value pages never initialize a block, so leave the bit-width buffer unallocated. Account for the required min-delta byte when validating block metadata, and use cumulative allocation counts in the regression tests. Signed-off-by: 1fanwang <1fannnw@gmail.com>
InitHeader subtracted one byte for min delta, so a two-byte min delta with no bit widths still allocated the aligned scratch buffer and then failed with Decode bit-width EOF. Consume min delta first, then reject when remaining bytes cannot hold the declared miniblock widths. Signed-off-by: 1fanwang <1fannnw@gmail.com>
18ae360 to
fca97c6
Compare
|
|

Rationale for this change
A corrupt DELTA_BINARY_PACKED page can ask for a miniblock buffer much larger than the page. A single-value page never needs that buffer. A truncated page whose min delta spans more than one byte could still allocate, then fail with Decode bit-width EOF.
Fixes #50314.
What changes are included in this PR?
Skip the bit-width buffer for single-value pages. For every other page, read min delta first, then reject an impossible miniblock count before allocating.
Are these changes tested?
The decoder tests cover a single-value page with an oversized miniblock count, a one-byte leftover after the header, and a two-byte min delta with no bit-width byte.
Without the min-delta check, the two-byte case failed with:
With it:
The rest of parquet-encoding-test also passed. In-memory column reader tests passed. File-backed reader tests need PARQUET_TEST_DATA and were not run here.
Are there any user-facing changes?
Invalid headers fail before allocation. Valid single-value pages decode without a miniblock buffer.
New Contributor's Guide |
Contributing Overview |
AI-generated Code Guidance
Was AI used for this PR?
AI assisted with the code, regression tests, and description.
PR code and description written by:
Reviewed before submission by: