andygrove opened a new issue, #6175:
URL: https://github.com/apache/datafusion-comet/issues/6175

   `CometNativeUDF.register` loads any shared library at any path the caller 
names, on the driver and
   then on every executor, with the full privileges of the JVM process. There 
is no configuration an
   operator can set to turn the feature off or to limit which paths may be 
loaded.
   
   Options:
   
   - `spark.comet.nativeUdf.enabled`, checked in `register` on the driver and 
in the planner on the
     executor, so a plan built elsewhere cannot bypass it. Whether it defaults 
to on (the feature is
     already opt-in by API call) or off (loading native code should need an 
operator's consent) is
     the main question for this issue.
   - `spark.comet.nativeUdf.allowedPaths`, a list of directory prefixes. Paths 
would be canonicalized
     before the check so `..` and symlinks cannot escape it.
   
   The executor-side check matters as much as the driver-side one: the library 
path travels in the
   `NativeScalarUdf` proto, so the executor must not trust that the driver 
checked it.
   
   Follow-up to #4459.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to