github-actions[bot] commented on code in PR #68243:
URL: https://github.com/apache/doris/pull/68243#discussion_r4119577257
##########
be/src/exprs/aggregate/aggregate_function_topn.h:
##########
@@ -184,7 +185,7 @@ struct AggregateFunctionTopNData {
writer.StartObject();
for (int i = 0; i < std::min((int)counter_vector.size(), top_num);
i++) {
const auto& element = counter_vector[i];
- writer.Key(element.second.c_str());
Review Comment:
[P2] Guard large keys before calling the pinned RapidJSON writer. For a
one-row key consisting of NUL plus 715827882 ASCII bytes, the new length
overload passes 715827883 to Writer::WriteString. RapidJSON computes its
StringBuffer reservation as 2 + length * 6 in 32-bit SizeType, which wraps to
4, then writes the full key through PutUnsafe; this asserts in checked builds
and can overrun the buffer in release builds. ColumnString allows this length,
and the prior C-string call saw an empty key at the leading NUL. Please
preserve the explicit length while preventing this writer overflow (or use a
writer with checked size_t reservation).
##########
be/src/exprs/aggregate/aggregate_function_topn.h:
##########
@@ -184,7 +185,7 @@ struct AggregateFunctionTopNData {
writer.StartObject();
for (int i = 0; i < std::min((int)counter_vector.size(), top_num);
i++) {
const auto& element = counter_vector[i];
- writer.Key(element.second.c_str());
Review Comment:
[P2] Keep JSON output valid for binary bytes after NUL. A key from
unhex('00FF') now passes both bytes to the default RapidJSON writer: it escapes
00 as \\u0000 but copies FF verbatim because UTF-8 validation is off. The
resulting topn string contains invalid UTF-8, so JSON_VALID/JSON_PARSE reject
it; before this call changed, the leading NUL produced an empty but valid JSON
key. The new tests only use ASCII suffixes. Please validate or encode arbitrary
key bytes before emitting JSON, and cover this short case.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]