Repository navigation
Bound the stripe statistics index in startNextStripe and getStripeStatistics - #34
Merged
PedroTadim merged 1 commit intoOct 8, 2026
Conversation
…tistics Same change as ClickHouse#33 on ClickHouse/2.3.1 (2195561). A Metadata section with fewer entries than the footer has stripes (for example after a corrupt PostScript metadataLength) made RowReaderImpl::startNextStripe read stripe_stats(currentStripe_) out of bounds when a search argument was set. Entries are matched to stripes only by position, so startNextStripe now evaluates stripe statistics only when there is one entry per stripe; otherwise it reads the stripe without stripe-level filtering, as for a file with no Metadata. getStripeStatistics throws ParseError on a count mismatch and InvalidArgument on an out-of-range stripe index. On main it reads stripe_stats(stripeIndex) before the stripe footer, so both checks go right after the metadata check. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Same change as #33 on
ClickHouse/2.3.1, formain.What changes were proposed in this pull request?
RowReaderImpl::startNextStripeevaluates the stripe statistics only whenstripe_stats_size() == stripes_size(); otherwise the stripes are read without stripe-level filtering, as for a file with no Metadata.ReaderImpl::getStripeStatisticsthrowsParseErroron that count mismatch andInvalidArgumentfor an out-of-range stripe index.The only difference from #33: on
main,getStripeStatisticsreadsstripe_stats(stripeIndex)before the stripe footer, so both checks go right after themetadata == nullptrcheck.Why are the changes needed?
A Metadata section can parse into fewer entries than the footer has stripes (ClickHouse/ClickHouse#124238), and both functions then index
stripe_statsout of range.How was this patch tested?
Standalone Debug build of
main, before and after, with the crafted files from ClickHouse/ClickHouse#124315:id < 5: before, protobufCHECK failed: (index) < (current_size_)on both files; after, the same rows as a valid file.getStripeStatistics: before, the same protobuf check for a bad index or a file with no entries, and stripe 1's entry returned for stripe 0 of the two-stripe file; after,ParseError/InvalidArgument, and valid files still return their statistics.orc-test: 740/740 before and after.The issue's own reproducer is already rejected on
main(Failed to parse the metadata), so only the crafted files reach these reads here.Was this patch authored or co-authored using generative AI tooling?
Generated-by: Claude Opus 5.5