Compare commits

...

4 Commits

Author SHA1 Message Date
Gatefixer d28ea445e7 fix: harden legacy update filter barrier 2026-08-08 13:26:46 +00:00
Gatefixer d6809a80f2 fix: scope legacy update materialization fallback 2026-08-08 12:37:38 +00:00
Gatefixer e5a7a092bb fix: avoid offset overflow in filtered updates 2026-08-06 07:56:42 +00:00
Gatefixer 2adbf791fc test: cover wide multi-fragment updates 2026-08-06 07:01:31 +00:00
+359 -1
View File
@@ -3,6 +3,7 @@
use std::sync::Arc;
use arrow_schema::DataType;
use lance::dataset::UpdateBuilder as LanceUpdateBuilder;
use serde::{Deserialize, Serialize};
@@ -84,10 +85,11 @@ pub(crate) async fn execute_update(
let dataset = table.dataset.get().await?;
// 2. Initialize the Lance Core builder
let mut builder = LanceUpdateBuilder::new(dataset);
let mut builder = LanceUpdateBuilder::new(dataset.clone());
// 3. Apply the filter (WHERE clause)
if let Some(predicate) = update.filter {
let predicate = safe_update_filter(&predicate, dataset.as_ref());
builder = builder.update_where(&predicate)?;
}
@@ -109,9 +111,61 @@ pub(crate) async fn execute_update(
})
}
/// Keep vulnerable legacy updates on the early-materialization scan path.
///
/// Late materialization uses `TakeExec` to concatenate values read from multiple
/// fragments. That can overflow a single 32-bit-offset array. Lance's update
/// builder does not currently expose its scanner's materialization controls, so
/// cast the predicate to an integer before comparing it with `1`. Lance's
/// scalar-index extractor does not unwrap non-literal casts, keeping every
/// supported predicate out of the vulnerable late-materialization plan.
///
/// Keep the original SQL verbatim instead of parsing and serializing it. Newlines
/// isolate the generated syntax from a trailing line comment in the predicate.
///
/// This compatibility fallback is intentionally limited to legacy storage. V2
/// readers do not use the affected materialization path and keep their original
/// filter expression and indexed plan.
fn safe_update_filter(predicate: &str, dataset: &lance::Dataset) -> String {
let has_offset_columns = dataset
.schema()
.fields
.iter()
.any(|field| has_32_bit_offsets(&field.data_type()));
if !dataset.manifest().should_use_legacy_format() || !has_offset_columns {
return predicate.to_owned();
}
format!("CAST((\n{predicate}\n) AS INT) = 1")
}
fn has_32_bit_offsets(data_type: &DataType) -> bool {
match data_type {
DataType::Binary
| DataType::Utf8
| DataType::List(_)
| DataType::ListView(_)
| DataType::Map(_, _)
| DataType::Union(_, _) => true,
DataType::FixedSizeList(field, _)
| DataType::LargeList(field)
| DataType::LargeListView(field) => has_32_bit_offsets(field.data_type()),
DataType::Struct(fields) => fields
.iter()
.any(|field| has_32_bit_offsets(field.data_type())),
DataType::Dictionary(_, values) => has_32_bit_offsets(values),
DataType::RunEndEncoded(_, values) => has_32_bit_offsets(values.data_type()),
_ => false,
}
}
#[cfg(test)]
mod tests {
use crate::connect;
use crate::connection::LanceFileVersion;
use crate::database::listing::{ListingDatabaseOptions, NewTableConfig};
use crate::index::{Index, scalar::BTreeIndexBuilder};
use crate::query::QueryBase;
use crate::query::{ExecutableQuery, Select};
use arrow_array::{
@@ -122,9 +176,18 @@ mod tests {
use arrow_data::ArrayDataBuilder;
use arrow_schema::{ArrowError, DataType, Field, Schema, TimeUnit};
use futures::TryStreamExt;
use lance::io::exec::Planner;
use std::sync::Arc;
use std::time::Duration;
fn contains_take(plan: &dyn datafusion_physical_plan::ExecutionPlan) -> bool {
plan.name() == "TakeExec"
|| plan
.children()
.iter()
.any(|child| contains_take(child.as_ref()))
}
#[tokio::test]
async fn test_update_all_types() {
let conn = connect("memory://")
@@ -409,6 +472,301 @@ mod tests {
}
}
#[tokio::test]
async fn test_update_materializes_offset_columns_before_filter() {
let batch = record_batch!(
("id", Int32, [0, 1, 2, 3]),
(
"split",
Utf8,
[Some("test"), None, Some("test"), Some("train")]
),
("payload", Utf8, ["a", "b", "c", "d"])
)
.unwrap();
let conn = connect("memory://")
.database_options(&ListingDatabaseOptions {
new_table_config: NewTableConfig {
data_storage_version: Some(LanceFileVersion::Legacy),
..Default::default()
},
..Default::default()
})
.execute()
.await
.unwrap();
let table = conn
.create_table("offset_table", batch.clone())
.execute()
.await
.unwrap();
table.add(batch).execute().await.unwrap();
table
.create_index(&["split"], Index::BTree(BTreeIndexBuilder::default()))
.execute()
.await
.unwrap();
let dataset = table.dataset().unwrap().get().await.unwrap();
let planner = Planner::new(Arc::new(dataset.schema().into()));
let filter = planner.parse_filter("split = 'test'").unwrap();
let filter = planner.optimize_expr(filter).unwrap();
let mut scanner = dataset.scan();
scanner.with_row_id().filter_expr(filter);
let explanation = scanner.explain_plan(false).await.unwrap();
let plan = scanner.create_plan().await.unwrap();
assert!(
contains_take(plan.as_ref()),
"test setup must late-materialize payload:\n{explanation}"
);
let guarded_filter = super::safe_update_filter("split = 'test'", dataset.as_ref());
let filter = planner.parse_filter(&guarded_filter).unwrap();
let filter = planner.optimize_expr(filter).unwrap();
let mut scanner = dataset.scan();
scanner.with_row_id().filter_expr(filter);
let explanation = scanner.explain_plan(false).await.unwrap();
let plan = scanner.create_plan().await.unwrap();
// Regression test for #1291: the payload must be read by the scan, not
// concatenated across fragments by a late-materializing TakeExec.
assert!(
!contains_take(plan.as_ref()),
"unexpected late materialization:\n{explanation}"
);
let result = table
.update()
.only_if("split = 'test'")
.column("split", "'TEST'")
.execute()
.await
.unwrap();
assert_eq!(result.rows_updated, 4);
assert_eq!(
table
.count_rows(Some("split = 'TEST'".to_string()))
.await
.unwrap(),
4
);
assert_eq!(
table
.count_rows(Some("payload IN ('a', 'b', 'c', 'd')".to_string()))
.await
.unwrap(),
8
);
}
#[tokio::test]
async fn test_update_v2_keeps_indexed_plan() {
let batch = record_batch!(
("id", Int32, [0, 1, 2, 3]),
("split", Utf8, ["test", "train", "test", "train"]),
("payload", Utf8, ["a", "b", "c", "d"])
)
.unwrap();
let conn = connect("memory://")
.database_options(&ListingDatabaseOptions {
new_table_config: NewTableConfig {
data_storage_version: Some(LanceFileVersion::V2_0),
..Default::default()
},
..Default::default()
})
.execute()
.await
.unwrap();
let table = conn
.create_table("v2_offset_table", batch.clone())
.execute()
.await
.unwrap();
table.add(batch).execute().await.unwrap();
table
.create_index(&["split"], Index::BTree(BTreeIndexBuilder::default()))
.execute()
.await
.unwrap();
let dataset = table.dataset().unwrap().get().await.unwrap();
let predicate = "split = 'test'";
let update_filter = super::safe_update_filter(predicate, dataset.as_ref());
assert_eq!(update_filter, predicate);
let planner = Planner::new(Arc::new(dataset.schema().into()));
let filter = planner.parse_filter(&update_filter).unwrap();
let filter = planner.optimize_expr(filter).unwrap();
let mut scanner = dataset.scan();
scanner.with_row_id().filter_expr(filter);
let explanation = scanner.explain_plan(false).await.unwrap();
let plan = scanner.create_plan().await.unwrap();
assert!(
explanation.contains("ScalarIndexQuery"),
"v2 plan unexpectedly lost its scalar index:\n{explanation}"
);
assert!(
!contains_take(plan.as_ref()),
"v2 plan unexpectedly used the legacy TakeExec path:\n{explanation}"
);
let result = table
.update()
.only_if(predicate)
.column("split", "'TEST'")
.execute()
.await
.unwrap();
assert_eq!(result.rows_updated, 4);
}
#[tokio::test]
async fn test_update_accepts_trailing_comment_filter() {
let conn = connect("memory://")
.database_options(&ListingDatabaseOptions {
new_table_config: NewTableConfig {
data_storage_version: Some(LanceFileVersion::Legacy),
..Default::default()
},
..Default::default()
})
.execute()
.await
.unwrap();
let batch = record_batch!(("id", Int32, [1, 2]), ("payload", Utf8, ["a", "b"])).unwrap();
let table = conn
.create_table("trailing_comment", batch)
.execute()
.await
.unwrap();
let predicate = "id = 1 -- valid trailing comment";
assert_eq!(table.count_rows(Some(predicate.into())).await.unwrap(), 1);
let result = table
.update()
.only_if(predicate)
.column("payload", "'updated'")
.execute()
.await
.unwrap();
assert_eq!(result.rows_updated, 1);
assert_eq!(
table
.count_rows(Some("payload = 'updated'".into()))
.await
.unwrap(),
1
);
}
#[tokio::test]
async fn test_update_boolean_index_uses_early_materialization() {
let conn = connect("memory://")
.database_options(&ListingDatabaseOptions {
new_table_config: NewTableConfig {
data_storage_version: Some(LanceFileVersion::Legacy),
..Default::default()
},
..Default::default()
})
.execute()
.await
.unwrap();
let batch = record_batch!(
("flag", Boolean, [true, false]),
("payload", Utf8, ["a", "b"])
)
.unwrap();
let table = conn
.create_table("boolean_index", batch.clone())
.execute()
.await
.unwrap();
table.add(batch).execute().await.unwrap();
table
.create_index(&["flag"], Index::BTree(BTreeIndexBuilder::default()))
.execute()
.await
.unwrap();
let dataset = table.dataset().unwrap().get().await.unwrap();
let guarded_filter = super::safe_update_filter("flag", dataset.as_ref());
let mut scanner = dataset.scan();
scanner.with_row_id().filter(&guarded_filter).unwrap();
let explanation = scanner.explain_plan(false).await.unwrap();
let plan = scanner.create_plan().await.unwrap();
assert!(
!contains_take(plan.as_ref()),
"Boolean predicate retained late materialization:\n{explanation}"
);
assert!(
!explanation.contains("MaterializeIndex"),
"Boolean predicate retained scalar-index extraction:\n{explanation}"
);
let result = table
.update()
.only_if("flag")
.column("payload", "'updated'")
.execute()
.await
.unwrap();
assert_eq!(result.rows_updated, 2);
assert_eq!(
table
.count_rows(Some("payload = 'updated'".into()))
.await
.unwrap(),
2
);
}
#[tokio::test]
async fn test_update_accepts_quoted_reserved_identifier() {
let conn = connect("memory://")
.database_options(&ListingDatabaseOptions {
new_table_config: NewTableConfig {
data_storage_version: Some(LanceFileVersion::Legacy),
..Default::default()
},
..Default::default()
})
.execute()
.await
.unwrap();
let batch =
record_batch!(("select", Int32, [1, 2]), ("payload", Utf8, ["a", "b"])).unwrap();
let table = conn
.create_table("reserved_identifier", batch.clone())
.execute()
.await
.unwrap();
table.add(batch).execute().await.unwrap();
let predicate = "`select` = 1";
assert_eq!(table.count_rows(Some(predicate.into())).await.unwrap(), 2);
let result = table
.update()
.only_if(predicate)
.column("payload", "'updated'")
.execute()
.await
.unwrap();
assert_eq!(result.rows_updated, 2);
assert_eq!(
table
.count_rows(Some("payload = 'updated'".into()))
.await
.unwrap(),
2
);
}
#[tokio::test]
async fn test_update_via_expr() {
let conn = connect("memory://")