LuciferYang opened a new issue, #978:
URL: https://github.com/apache/iceberg-cpp/issues/978

   ## Summary
   
   `ReferenceVisitor::GetReferencedFieldIds` (exported via `ICEBERG_EXPORT`) 
crashes with a SIGSEGV when the expression tree contains a bound `COUNT(*)`. 
`ReferenceVisitor::Aggregate` runs 
`referenced_field_ids_.insert(aggregate->reference()->field_id())`, but a 
`COUNT(*)` aggregate has a null term, so `reference()` returns `nullptr` and 
`->field_id()` dereferences it.
   
   ## Root Cause
   
   `CountStarAggregate` is constructed with a null term 
(`src/iceberg/expression/aggregate.cc`), and `BoundAggregate::reference()` 
returns `term() ? term()->reference() : nullptr`, so it is `nullptr` for 
`COUNT(*)`. `src/iceberg/expression/binder.cc` dereferences it with no guard. 
`Visit()` routes any bound aggregate to `Aggregate()`, so binding 
`Expressions::CountStar()` and calling `GetReferencedFieldIds` segfaults. 
`COUNT(col)` / `MAX` / `MIN` have non-null terms and are unaffected.
   
   ## Impact
   
   No in-tree scan path passes aggregates to `GetReferencedFieldIds` today 
(`table_scan.cc` and `manifest_group.cc` pass row filters), so the crash lands 
on a library consumer that does aggregate pushdown through the exported API. 
`COUNT(*)` is the most common aggregate, and binding it is a supported, tested 
workflow (`aggregate_test.cc`). Java's `ReferenceVisitor` base throws 
`UnsupportedOperationException` on aggregates, a catchable error; the C++ port 
instead crashes the process.
   
   ## Proposed Fix
   
   Insert the field id only when `reference()` is non-null. `COUNT(*)` then 
contributes no field ids, which is the correct result for field projection 
(counting rows reads no columns).
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to