This is an automated email from the ASF dual-hosted git repository.
paleolimbot pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/arrow-nanoarrow.git
The following commit(s) were added to refs/heads/main by this push:
new ecba4756 fix: Reject oversized binary view values (#947)
ecba4756 is described below
commit ecba475603d82755856fd1b89bbaaa7fa43d8393
Author: Efe <[email protected]>
AuthorDate: Tue Sep 29 05:08:27 2026 +0300
fix: Reject oversized binary view values (#947)
## Summary
- Reject binary and string view values larger than `INT32_MAX` before
narrowing the length into the Arrow binary-view representation.
- Add a regression test covering the overflow path without allocating a
multi-gigabyte buffer.
Fixes #938
## Testing
- `cmake -S . -B /tmp/arrow-nanoarrow-build-938
-DNANOARROW_BUILD_TESTS=ON` — passed.
- `cmake --build /tmp/arrow-nanoarrow-build-938 --parallel 2` — passed.
- `ctest --test-dir /tmp/arrow-nanoarrow-build-938 --output-on-failure`
— passed (287/287; 3 thread-safety tests skipped by project
configuration).
- `git diff --check` — passed.
AI assistance was used during implementation; the submitted changes were
reviewed and validated against the issue and the project test suite.
Signed-off-by: Efe Gökdemir <[email protected]>
---
src/nanoarrow/common/array_test.cc | 13 +++++++++++++
src/nanoarrow/common/inline_array.h | 4 ++++
2 files changed, 17 insertions(+)
diff --git a/src/nanoarrow/common/array_test.cc
b/src/nanoarrow/common/array_test.cc
index 02550a7e..cd9ac88e 100644
--- a/src/nanoarrow/common/array_test.cc
+++ b/src/nanoarrow/common/array_test.cc
@@ -1267,6 +1267,19 @@ TEST(ArrayTest, ArrayTestAppendToBinaryArrayErrors) {
ArrowArrayRelease(&array);
}
+TEST(ArrayTest, ArrayTestAppendToBinaryViewArrayErrors) {
+ struct ArrowArray array;
+
+ ASSERT_EQ(ArrowArrayInitFromType(&array, NANOARROW_TYPE_BINARY_VIEW),
NANOARROW_OK);
+ EXPECT_EQ(ArrowArrayStartAppending(&array), NANOARROW_OK);
+ struct ArrowBufferView item;
+ item.data.as_char = "";
+ item.size_bytes = static_cast<int64_t>(INT32_MAX) + 1;
+ EXPECT_EQ(ArrowArrayAppendBytes(&array, item), EOVERFLOW);
+
+ ArrowArrayRelease(&array);
+}
+
TEST(ArrayTest, ArrayTestAppendToIntervalArrayYearMonth) {
struct ArrowArray array;
diff --git a/src/nanoarrow/common/inline_array.h
b/src/nanoarrow/common/inline_array.h
index 9bfc6dbd..eaec776e 100644
--- a/src/nanoarrow/common/inline_array.h
+++ b/src/nanoarrow/common/inline_array.h
@@ -584,6 +584,10 @@ static inline ArrowErrorCode ArrowArrayAppendBytes(struct
ArrowArray* array,
if (private_data->storage_type == NANOARROW_TYPE_STRING_VIEW ||
private_data->storage_type == NANOARROW_TYPE_BINARY_VIEW) {
+ if (value.size_bytes > INT32_MAX) {
+ return EOVERFLOW;
+ }
+
struct ArrowBuffer* data_buffer = ArrowArrayBuffer(array, 1);
union ArrowBinaryView bvt;
bvt.inlined.size = (int32_t)value.size_bytes;