Arawoof06 opened a new pull request, #1237:
URL: https://github.com/apache/arrow-java/pull/1237

   ## What's Changed
   
   checkBoundaries validates the caller index against startOffset + 
valuesCount, but index is relative to the start of the array and both call 
sites add startOffset to it only after the check, so the accepted range is too 
long by exactly startOffset elements. getArray and getResultSet then read that 
far past the end of the row's slice. AbstractArrowFlightJdbcListVectorAccessor 
constructs these from the offsets of the list element being read, so any row of 
a list column not starting at child offset 0 hands back values belonging to 
neighbouring rows of the shared child vector, and past the child's valueCount 
whatever is in allocated-but-unwritten memory. The bound belongs on the 
relative index, so it is compared against valuesCount instead; that is the same 
expression as today when startOffset is 0, which is why the existing tests all 
pass unchanged and only the offset case gets tighter. Added a regression test 
for each of the two entry points, both of which fail on main.
   
   Closes #1236.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to