Zoltán Borók-Nagy created IMPALA-15422:
------------------------------------------

             Summary: WriteDecimalSlot in system-table-scanner.cc falls through 
its switch and writes 16 bytes into 8-byte DECIMAL slots
                 Key: IMPALA-15422
                 URL: https://issues.apache.org/jira/browse/IMPALA-15422
             Project: IMPALA
          Issue Type: Bug
          Components: Backend
            Reporter: Zoltán Borók-Nagy
            Assignee: Zoltán Borók-Nagy


The switch in WriteDecimalSlot() has no break statements:

{code:cpp}
// be/src/exec/system-table-scanner.cc:101
static void WriteDecimalSlot(
    const ColumnType& type, double value, void* slot) {
  bool overflow = false;
  switch (type.GetByteSize()) {
    case 4:
      *reinterpret_cast<Decimal4Value*>(slot) =
          Decimal4Value::FromDouble(type, value, false, &overflow);
    case 8:
      *reinterpret_cast<Decimal8Value*>(slot) =
          Decimal8Value::FromDouble(type, value, false, &overflow);
    case 16:
      *reinterpret_cast<Decimal16Value*>(slot) =
          Decimal16Value::FromDouble(type, value, false, &overflow);
  }
  DCHECK(!overflow);
}
{code}

All DECIMAL columns of sys.impala_query_live are DECIMAL(18,3) 
(DURATION_DECIMAL_PRECISION
/ SCALE in workload-management.h), so GetByteSize() is 8. The 8-byte value is 
written,
then execution falls through and a Decimal16Value is written at the same 
address. The 8
bytes after the slot are overwritten: zeros for non-negative values, 0xFF bytes 
for
negative ones.

Affected columns: TOTAL_TIME_MS, ROW_MATERIALIZATION_TIME_MS, 
READ_IO_WAIT_TOTAL_MS,
READ_IO_WAIT_MEAN_MS, and all EVENT_* timeline columns (written through 
WriteEvent()).

Depending on the tuple layout of the projected columns, the extra bytes 
overwrite one of:
* a neighbouring slot that was already written, which then reads as 0;
* null-indicator bytes, so a NULL value can read as non-NULL;
* memory past the end of the tuple, if the decimal is the last slot.

Found by code inspection. The visible symptom has not been reproduced yet.




--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to