GH-41246: [C++][Python] Simplify nested field encryption configuration - #45462

Merged
pitrou merged 40 commits into
apache:mainfrom
EnricoMi:nested-field-encryption
Dec 16, 2025
Merged

GH-41246: [C++][Python] Simplify nested field encryption configuration#45462
pitrou merged 40 commits into
apache:mainfrom
EnricoMi:nested-field-encryption

Conversation

@EnricoMi

@EnricoMiEnricoMi commented Feb 7, 2025

Copy link
Copy Markdown
Collaborator

Rationale for this change

Columns can b encrypted with individual keys. For this, the column name have to be set in EncryptionConfiguration::column_keys. This poses the following challenges for columns with nested fields like MapType, ListType, and StructType. Encrypting a column of such type requires providing an encryption key for all nested (leaf) fields. Ideally, the column name should be sufficient (as it is for any other data type) to encrypt all nested fields.

What changes are included in this PR?

The column name can be used to encrypt all nested fields of StrutType, MapType, and ListType columns with the same encryption key. The current column naming scheme can still be used for backward compatibility.

Are these changes tested?

Tested in C++ and Python.

Are there any user-facing changes?

Column encryption can be configured with less code and more intuitive naming.

Documentation and examples updated.

Fixes#41246.

@EnricoMi
EnricoMi requested a review from wgtmac as a code ownerFebruary 7, 2025 11:12
@EnricoMiEnricoMi changed the title GH-41246: [C++][Python] Simplify nested field encryptionGH-41246: [C++][Python] Simplify nested field encryption configurationFeb 7, 2025
@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch from ba57bdc to 611f7a7CompareMarch 10, 2025 06:16

@AlenkaFAlenkaF left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Python tests LGTM - they are vey concise and reflect the C++ tests.

The C++ addition of FileEncryptionProperties::encrypt_schema looks good to me also but will need a check from a C++ developer. @wgtmac mind having a look?

@github-actionsgithub-actionsBot added awaiting committer review Awaiting committer review and removed awaiting review Awaiting review labels Mar 24, 2025
@AlenkaF

Copy link
Copy Markdown
Member

Note, CI Win failures do not look related but there is a linter fix needed:

@@ -257,11 +257,12 @@ void FileEncryptionProperties::encrypt_schema(const SchemaDescriptor& schema) {
// encrypted_column encrypts column 'it' when 'it' is either equal to
// encrypted_column, or 'it' starts with encrypted_column_prefix,
// i.e. encrypted_column followed by a '.'
- while (it != column_path_vec.end() &&
- (it->first == encrypted_column ||
- // C++20: can be replaced with it->first.starts_with(encrypted_column_prefix)
- it->first.compare(0, encrypted_column_prefix_len,
- encrypted_column_prefix) == 0)) {
+ while (
+ it != column_path_vec.end() &&
+ (it->first == encrypted_column ||
+ // C++20: can be replaced with it->first.starts_with(encrypted_column_prefix)
+ it->first.compare(0, encrypted_column_prefix_len, encrypted_column_prefix) ==
+ 0)) {

@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch from 25b39d0 to 0c7ff27CompareMarch 25, 2025 21:13
@AlenkaF

Copy link
Copy Markdown
Member

The C++ failure looks related.

@AlenkaF

Copy link
Copy Markdown
Member

cc @pitrou, this is connected to #45411.

@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch 2 times, most recently from efbc7c8 to 41a3359CompareMarch 27, 2025 05:40
@pitrou

Copy link
Copy Markdown
Member

This adds a user-friendly notation for nested fields:

  • Columns col.key and col.value can be used to reference they key and value nested field of a MapType column. Currently, col.key_value.key and col.key_value.value are required, respectively.

Is this useful? Is there a reasonable use case for using different encryption settings for the map key and value columns, respectively? Otherwise I think we can only keep the following items, which will also simplify the semantics and the implementation:

  • Columns col.element can be used to reference they individual list elements of a ListType column. Currently, col.list.element is required.
  • The actual column name can be used to encrypt all nested fields with the same encryption key.
  • The current column naming scheme can still be used for backward compatibility.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

Is this useful? Is there a reasonable use case for using different encryption settings for the map key and value columns, respectively?

Irrespective of it being useful, it is currently possible to do via col.key_value.key and col.key_value.value. This pull request simplifies that notation consistently with lists and structs.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

Note that I have removed encrypting the individual list elements via col.element as I cannot see a difference in semantics and encryption output between col.element and col. Both notations are equivalent.

Encrypting a single field of a list of structs column can be denoted as col.f1 rather than col.element.f1.

What do you think?

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

@pitrou what are your thoughts on the latest logic / semantics?

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

@pitrou hope you have a moment for this

@pitrou

Copy link
Copy Markdown
Member

I'll be out on vacation, so not before ~10 days I think.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

No worries, enjoy!

@pitrou

Copy link
Copy Markdown
Member

@github-actions crossbow submit preview-docs

@pitroupitrou left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry for the delay. This looks in general, a bunch of minor comments and suggestions below.

Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc Outdated
Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc
Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc Outdated
Comment threadpython/pyarrow/tests/parquet/encryption.py
Comment threadpython/pyarrow/tests/test_dataset_encryption.py Outdated
@github-actions

Copy link
Copy Markdown

Revision: b0ef03f

Submitted crossbow builds: ursacomputing/crossbow @ actions-151fb9c2fa

TaskStatus
preview-docsGitHub Actions

@pitrou

Copy link
Copy Markdown
Member

Ha, sorry, CI fails now that #48338 was merged, you need to stop passing the column path to ColumnEncryptionProperties::Builder.

@pitroupitrou left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the update @EnricoMi !

@pitrou
pitrou merged commit 052e0aa into apache:mainDec 16, 2025
44 of 46 checks passed
@pitroupitrou removed the awaiting committer review Awaiting committer review label Dec 16, 2025
@pitrou

Copy link
Copy Markdown
Member

I'm sorry that it took so long @EnricoMi . Looking forward to more contributions from you!

pitrou added a commit that referenced this pull request Dec 16, 2025
… corpus (#48558)
### Rationale for this change
In #48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that #45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: #48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@conbench-apache-arrow

Copy link
Copy Markdown

After merging your PR, Conbench analyzed the 3 benchmarking runs that have been run so far on merge-commit 052e0aa.

There were no benchmark performance regressions. 🎉

The full Conbench report has more details. It also includes information about 83 possible false positives for unstable benchmarks that are known to sometimes produce them.

pitrou added a commit that referenced this pull request Dec 17, 2025
### Rationale for this change
A `#include` required on Valgrind (due to conditional compilation) was removed in PR #45462.
### Are these changes tested?
Yes, by existing CI jobs.
### Are there any user-facing changes?
No.
* GitHub Issue: #48566
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…uration (apache#45462)
### Rationale for this change
Columns can b encrypted with individual keys. For this, the column name have to be set in `EncryptionConfiguration::column_keys`. This poses the following challenges for columns with nested fields like `MapType`, `ListType`, and `StructType`. Encrypting a column of such type requires providing an encryption key for all nested (leaf) fields. Ideally, the column name should be sufficient (as it is for any other data type) to encrypt all nested fields.
### What changes are included in this PR?
The column name can be used to encrypt all nested fields of `StrutType`, `MapType`, and `ListType` columns with the same encryption key. The current column naming scheme can still be used for backward compatibility.
### Are these changes tested?
Tested in C++ and Python.
### Are there any user-facing changes?
Column encryption can be configured with less code and more intuitive naming.
Documentation and examples updated.
Fixesapache#41246.
* GitHub Issue: apache#41246
Authored-by: Enrico Minack <github@enrico.minack.dev>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…z seed corpus (apache#48558)
### Rationale for this change
In apache#48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that apache#45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
### Rationale for this change
A `#include` required on Valgrind (due to conditional compilation) was removed in PR apache#45462.
### Are these changes tested?
Yes, by existing CI jobs.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48566
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Python][Parquet] Attempt to encrypt column of type 'list' produces OSError

3 participants

@EnricoMi@AlenkaF@pitrou
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

GH-41246: [C++][Python] Simplify nested field encryption configuration - #45462

Merged
pitrou merged 40 commits into
apache:mainfrom
EnricoMi:nested-field-encryption
Dec 16, 2025
Merged

GH-41246: [C++][Python] Simplify nested field encryption configuration#45462
pitrou merged 40 commits into
apache:mainfrom
EnricoMi:nested-field-encryption

Conversation

@EnricoMi

@EnricoMiEnricoMi commented Feb 7, 2025

Copy link
Copy Markdown
Collaborator

Rationale for this change

Columns can b encrypted with individual keys. For this, the column name have to be set in EncryptionConfiguration::column_keys. This poses the following challenges for columns with nested fields like MapType, ListType, and StructType. Encrypting a column of such type requires providing an encryption key for all nested (leaf) fields. Ideally, the column name should be sufficient (as it is for any other data type) to encrypt all nested fields.

What changes are included in this PR?

The column name can be used to encrypt all nested fields of StrutType, MapType, and ListType columns with the same encryption key. The current column naming scheme can still be used for backward compatibility.

Are these changes tested?

Tested in C++ and Python.

Are there any user-facing changes?

Column encryption can be configured with less code and more intuitive naming.

Documentation and examples updated.

Fixes#41246.

@EnricoMi
EnricoMi requested a review from wgtmac as a code ownerFebruary 7, 2025 11:12
@EnricoMiEnricoMi changed the title GH-41246: [C++][Python] Simplify nested field encryptionGH-41246: [C++][Python] Simplify nested field encryption configurationFeb 7, 2025
@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch from ba57bdc to 611f7a7CompareMarch 10, 2025 06:16

@AlenkaFAlenkaF left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Python tests LGTM - they are vey concise and reflect the C++ tests.

The C++ addition of FileEncryptionProperties::encrypt_schema looks good to me also but will need a check from a C++ developer. @wgtmac mind having a look?

@github-actionsgithub-actionsBot added awaiting committer review Awaiting committer review and removed awaiting review Awaiting review labels Mar 24, 2025
@AlenkaF

Copy link
Copy Markdown
Member

Note, CI Win failures do not look related but there is a linter fix needed:

@@ -257,11 +257,12 @@ void FileEncryptionProperties::encrypt_schema(const SchemaDescriptor& schema) {
// encrypted_column encrypts column 'it' when 'it' is either equal to
// encrypted_column, or 'it' starts with encrypted_column_prefix,
// i.e. encrypted_column followed by a '.'
- while (it != column_path_vec.end() &&
- (it->first == encrypted_column ||
- // C++20: can be replaced with it->first.starts_with(encrypted_column_prefix)
- it->first.compare(0, encrypted_column_prefix_len,
- encrypted_column_prefix) == 0)) {
+ while (
+ it != column_path_vec.end() &&
+ (it->first == encrypted_column ||
+ // C++20: can be replaced with it->first.starts_with(encrypted_column_prefix)
+ it->first.compare(0, encrypted_column_prefix_len, encrypted_column_prefix) ==
+ 0)) {

@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch from 25b39d0 to 0c7ff27CompareMarch 25, 2025 21:13
@AlenkaF

Copy link
Copy Markdown
Member

The C++ failure looks related.

@AlenkaF

Copy link
Copy Markdown
Member

cc @pitrou, this is connected to #45411.

@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch 2 times, most recently from efbc7c8 to 41a3359CompareMarch 27, 2025 05:40
@pitrou

Copy link
Copy Markdown
Member

This adds a user-friendly notation for nested fields:

  • Columns col.key and col.value can be used to reference they key and value nested field of a MapType column. Currently, col.key_value.key and col.key_value.value are required, respectively.

Is this useful? Is there a reasonable use case for using different encryption settings for the map key and value columns, respectively? Otherwise I think we can only keep the following items, which will also simplify the semantics and the implementation:

  • Columns col.element can be used to reference they individual list elements of a ListType column. Currently, col.list.element is required.
  • The actual column name can be used to encrypt all nested fields with the same encryption key.
  • The current column naming scheme can still be used for backward compatibility.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

Is this useful? Is there a reasonable use case for using different encryption settings for the map key and value columns, respectively?

Irrespective of it being useful, it is currently possible to do via col.key_value.key and col.key_value.value. This pull request simplifies that notation consistently with lists and structs.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

Note that I have removed encrypting the individual list elements via col.element as I cannot see a difference in semantics and encryption output between col.element and col. Both notations are equivalent.

Encrypting a single field of a list of structs column can be denoted as col.f1 rather than col.element.f1.

What do you think?

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

@pitrou what are your thoughts on the latest logic / semantics?

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

@pitrou hope you have a moment for this

@pitrou

Copy link
Copy Markdown
Member

I'll be out on vacation, so not before ~10 days I think.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

No worries, enjoy!

@pitrou

Copy link
Copy Markdown
Member

@github-actions crossbow submit preview-docs

@pitroupitrou left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry for the delay. This looks in general, a bunch of minor comments and suggestions below.

Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc Outdated
Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc
Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc Outdated
Comment threadpython/pyarrow/tests/parquet/encryption.py
Comment threadpython/pyarrow/tests/test_dataset_encryption.py Outdated
@github-actions

Copy link
Copy Markdown

Revision: b0ef03f

Submitted crossbow builds: ursacomputing/crossbow @ actions-151fb9c2fa

TaskStatus
preview-docsGitHub Actions

@pitrou

Copy link
Copy Markdown
Member

Ha, sorry, CI fails now that #48338 was merged, you need to stop passing the column path to ColumnEncryptionProperties::Builder.

@pitroupitrou left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the update @EnricoMi !

@pitrou
pitrou merged commit 052e0aa into apache:mainDec 16, 2025
44 of 46 checks passed
@pitroupitrou removed the awaiting committer review Awaiting committer review label Dec 16, 2025
@pitrou

Copy link
Copy Markdown
Member

I'm sorry that it took so long @EnricoMi . Looking forward to more contributions from you!

pitrou added a commit that referenced this pull request Dec 16, 2025
… corpus (#48558)
### Rationale for this change
In #48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that #45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: #48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@conbench-apache-arrow

Copy link
Copy Markdown

After merging your PR, Conbench analyzed the 3 benchmarking runs that have been run so far on merge-commit 052e0aa.

There were no benchmark performance regressions. 🎉

The full Conbench report has more details. It also includes information about 83 possible false positives for unstable benchmarks that are known to sometimes produce them.

pitrou added a commit that referenced this pull request Dec 17, 2025
### Rationale for this change
A `#include` required on Valgrind (due to conditional compilation) was removed in PR #45462.
### Are these changes tested?
Yes, by existing CI jobs.
### Are there any user-facing changes?
No.
* GitHub Issue: #48566
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…uration (apache#45462)
### Rationale for this change
Columns can b encrypted with individual keys. For this, the column name have to be set in `EncryptionConfiguration::column_keys`. This poses the following challenges for columns with nested fields like `MapType`, `ListType`, and `StructType`. Encrypting a column of such type requires providing an encryption key for all nested (leaf) fields. Ideally, the column name should be sufficient (as it is for any other data type) to encrypt all nested fields.
### What changes are included in this PR?
The column name can be used to encrypt all nested fields of `StrutType`, `MapType`, and `ListType` columns with the same encryption key. The current column naming scheme can still be used for backward compatibility.
### Are these changes tested?
Tested in C++ and Python.
### Are there any user-facing changes?
Column encryption can be configured with less code and more intuitive naming.
Documentation and examples updated.
Fixesapache#41246.
* GitHub Issue: apache#41246
Authored-by: Enrico Minack <github@enrico.minack.dev>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…z seed corpus (apache#48558)
### Rationale for this change
In apache#48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that apache#45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
### Rationale for this change
A `#include` required on Valgrind (due to conditional compilation) was removed in PR apache#45462.
### Are these changes tested?
Yes, by existing CI jobs.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48566
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Python][Parquet] Attempt to encrypt column of type 'list' produces OSError

3 participants

@EnricoMi@AlenkaF@pitrou
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

GH-41246: [C++][Python] Simplify nested field encryption configuration - #45462

Merged
pitrou merged 40 commits into
apache:mainfrom
EnricoMi:nested-field-encryption
Dec 16, 2025
Merged

GH-41246: [C++][Python] Simplify nested field encryption configuration#45462
pitrou merged 40 commits into
apache:mainfrom
EnricoMi:nested-field-encryption

Conversation

@EnricoMi

@EnricoMiEnricoMi commented Feb 7, 2025

Copy link
Copy Markdown
Collaborator

Rationale for this change

Columns can b encrypted with individual keys. For this, the column name have to be set in EncryptionConfiguration::column_keys. This poses the following challenges for columns with nested fields like MapType, ListType, and StructType. Encrypting a column of such type requires providing an encryption key for all nested (leaf) fields. Ideally, the column name should be sufficient (as it is for any other data type) to encrypt all nested fields.

What changes are included in this PR?

The column name can be used to encrypt all nested fields of StrutType, MapType, and ListType columns with the same encryption key. The current column naming scheme can still be used for backward compatibility.

Are these changes tested?

Tested in C++ and Python.

Are there any user-facing changes?

Column encryption can be configured with less code and more intuitive naming.

Documentation and examples updated.

Fixes#41246.

@EnricoMi
EnricoMi requested a review from wgtmac as a code ownerFebruary 7, 2025 11:12
@EnricoMiEnricoMi changed the title GH-41246: [C++][Python] Simplify nested field encryptionGH-41246: [C++][Python] Simplify nested field encryption configurationFeb 7, 2025
@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch from ba57bdc to 611f7a7CompareMarch 10, 2025 06:16

@AlenkaFAlenkaF left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Python tests LGTM - they are vey concise and reflect the C++ tests.

The C++ addition of FileEncryptionProperties::encrypt_schema looks good to me also but will need a check from a C++ developer. @wgtmac mind having a look?

@github-actionsgithub-actionsBot added awaiting committer review Awaiting committer review and removed awaiting review Awaiting review labels Mar 24, 2025
@AlenkaF

Copy link
Copy Markdown
Member

Note, CI Win failures do not look related but there is a linter fix needed:

@@ -257,11 +257,12 @@ void FileEncryptionProperties::encrypt_schema(const SchemaDescriptor& schema) {
// encrypted_column encrypts column 'it' when 'it' is either equal to
// encrypted_column, or 'it' starts with encrypted_column_prefix,
// i.e. encrypted_column followed by a '.'
- while (it != column_path_vec.end() &&
- (it->first == encrypted_column ||
- // C++20: can be replaced with it->first.starts_with(encrypted_column_prefix)
- it->first.compare(0, encrypted_column_prefix_len,
- encrypted_column_prefix) == 0)) {
+ while (
+ it != column_path_vec.end() &&
+ (it->first == encrypted_column ||
+ // C++20: can be replaced with it->first.starts_with(encrypted_column_prefix)
+ it->first.compare(0, encrypted_column_prefix_len, encrypted_column_prefix) ==
+ 0)) {

@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch from 25b39d0 to 0c7ff27CompareMarch 25, 2025 21:13
@AlenkaF

Copy link
Copy Markdown
Member

The C++ failure looks related.

@AlenkaF

Copy link
Copy Markdown
Member

cc @pitrou, this is connected to #45411.

@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch 2 times, most recently from efbc7c8 to 41a3359CompareMarch 27, 2025 05:40
@pitrou

Copy link
Copy Markdown
Member

This adds a user-friendly notation for nested fields:

  • Columns col.key and col.value can be used to reference they key and value nested field of a MapType column. Currently, col.key_value.key and col.key_value.value are required, respectively.

Is this useful? Is there a reasonable use case for using different encryption settings for the map key and value columns, respectively? Otherwise I think we can only keep the following items, which will also simplify the semantics and the implementation:

  • Columns col.element can be used to reference they individual list elements of a ListType column. Currently, col.list.element is required.
  • The actual column name can be used to encrypt all nested fields with the same encryption key.
  • The current column naming scheme can still be used for backward compatibility.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

Is this useful? Is there a reasonable use case for using different encryption settings for the map key and value columns, respectively?

Irrespective of it being useful, it is currently possible to do via col.key_value.key and col.key_value.value. This pull request simplifies that notation consistently with lists and structs.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

Note that I have removed encrypting the individual list elements via col.element as I cannot see a difference in semantics and encryption output between col.element and col. Both notations are equivalent.

Encrypting a single field of a list of structs column can be denoted as col.f1 rather than col.element.f1.

What do you think?

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

@pitrou what are your thoughts on the latest logic / semantics?

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

@pitrou hope you have a moment for this

@pitrou

Copy link
Copy Markdown
Member

I'll be out on vacation, so not before ~10 days I think.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

No worries, enjoy!

@pitrou

Copy link
Copy Markdown
Member

@github-actions crossbow submit preview-docs

@pitroupitrou left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry for the delay. This looks in general, a bunch of minor comments and suggestions below.

Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc Outdated
Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc
Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc Outdated
Comment threadpython/pyarrow/tests/parquet/encryption.py
Comment threadpython/pyarrow/tests/test_dataset_encryption.py Outdated
@github-actions

Copy link
Copy Markdown

Revision: b0ef03f

Submitted crossbow builds: ursacomputing/crossbow @ actions-151fb9c2fa

TaskStatus
preview-docsGitHub Actions

@pitrou

Copy link
Copy Markdown
Member

Ha, sorry, CI fails now that #48338 was merged, you need to stop passing the column path to ColumnEncryptionProperties::Builder.

@pitroupitrou left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the update @EnricoMi !

@pitrou
pitrou merged commit 052e0aa into apache:mainDec 16, 2025
44 of 46 checks passed
@pitroupitrou removed the awaiting committer review Awaiting committer review label Dec 16, 2025
@pitrou

Copy link
Copy Markdown
Member

I'm sorry that it took so long @EnricoMi . Looking forward to more contributions from you!

pitrou added a commit that referenced this pull request Dec 16, 2025
… corpus (#48558)
### Rationale for this change
In #48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that #45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: #48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@conbench-apache-arrow

Copy link
Copy Markdown

After merging your PR, Conbench analyzed the 3 benchmarking runs that have been run so far on merge-commit 052e0aa.

There were no benchmark performance regressions. 🎉

The full Conbench report has more details. It also includes information about 83 possible false positives for unstable benchmarks that are known to sometimes produce them.

pitrou added a commit that referenced this pull request Dec 17, 2025
### Rationale for this change
A `#include` required on Valgrind (due to conditional compilation) was removed in PR #45462.
### Are these changes tested?
Yes, by existing CI jobs.
### Are there any user-facing changes?
No.
* GitHub Issue: #48566
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…uration (apache#45462)
### Rationale for this change
Columns can b encrypted with individual keys. For this, the column name have to be set in `EncryptionConfiguration::column_keys`. This poses the following challenges for columns with nested fields like `MapType`, `ListType`, and `StructType`. Encrypting a column of such type requires providing an encryption key for all nested (leaf) fields. Ideally, the column name should be sufficient (as it is for any other data type) to encrypt all nested fields.
### What changes are included in this PR?
The column name can be used to encrypt all nested fields of `StrutType`, `MapType`, and `ListType` columns with the same encryption key. The current column naming scheme can still be used for backward compatibility.
### Are these changes tested?
Tested in C++ and Python.
### Are there any user-facing changes?
Column encryption can be configured with less code and more intuitive naming.
Documentation and examples updated.
Fixesapache#41246.
* GitHub Issue: apache#41246
Authored-by: Enrico Minack <github@enrico.minack.dev>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…z seed corpus (apache#48558)
### Rationale for this change
In apache#48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that apache#45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
### Rationale for this change
A `#include` required on Valgrind (due to conditional compilation) was removed in PR apache#45462.
### Are these changes tested?
Yes, by existing CI jobs.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48566
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Python][Parquet] Attempt to encrypt column of type 'list' produces OSError

3 participants

@EnricoMi@AlenkaF@pitrou
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

GH-41246: [C++][Python] Simplify nested field encryption configuration - #45462

Merged
pitrou merged 40 commits into
apache:mainfrom
EnricoMi:nested-field-encryption
Dec 16, 2025
Merged

GH-41246: [C++][Python] Simplify nested field encryption configuration#45462
pitrou merged 40 commits into
apache:mainfrom
EnricoMi:nested-field-encryption

Conversation

@EnricoMi

@EnricoMiEnricoMi commented Feb 7, 2025

Copy link
Copy Markdown
Collaborator

Rationale for this change

Columns can b encrypted with individual keys. For this, the column name have to be set in EncryptionConfiguration::column_keys. This poses the following challenges for columns with nested fields like MapType, ListType, and StructType. Encrypting a column of such type requires providing an encryption key for all nested (leaf) fields. Ideally, the column name should be sufficient (as it is for any other data type) to encrypt all nested fields.

What changes are included in this PR?

The column name can be used to encrypt all nested fields of StrutType, MapType, and ListType columns with the same encryption key. The current column naming scheme can still be used for backward compatibility.

Are these changes tested?

Tested in C++ and Python.

Are there any user-facing changes?

Column encryption can be configured with less code and more intuitive naming.

Documentation and examples updated.

Fixes#41246.

@EnricoMi
EnricoMi requested a review from wgtmac as a code ownerFebruary 7, 2025 11:12
@EnricoMiEnricoMi changed the title GH-41246: [C++][Python] Simplify nested field encryptionGH-41246: [C++][Python] Simplify nested field encryption configurationFeb 7, 2025
@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch from ba57bdc to 611f7a7CompareMarch 10, 2025 06:16

@AlenkaFAlenkaF left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Python tests LGTM - they are vey concise and reflect the C++ tests.

The C++ addition of FileEncryptionProperties::encrypt_schema looks good to me also but will need a check from a C++ developer. @wgtmac mind having a look?

@github-actionsgithub-actionsBot added awaiting committer review Awaiting committer review and removed awaiting review Awaiting review labels Mar 24, 2025
@AlenkaF

Copy link
Copy Markdown
Member

Note, CI Win failures do not look related but there is a linter fix needed:

@@ -257,11 +257,12 @@ void FileEncryptionProperties::encrypt_schema(const SchemaDescriptor& schema) {
// encrypted_column encrypts column 'it' when 'it' is either equal to
// encrypted_column, or 'it' starts with encrypted_column_prefix,
// i.e. encrypted_column followed by a '.'
- while (it != column_path_vec.end() &&
- (it->first == encrypted_column ||
- // C++20: can be replaced with it->first.starts_with(encrypted_column_prefix)
- it->first.compare(0, encrypted_column_prefix_len,
- encrypted_column_prefix) == 0)) {
+ while (
+ it != column_path_vec.end() &&
+ (it->first == encrypted_column ||
+ // C++20: can be replaced with it->first.starts_with(encrypted_column_prefix)
+ it->first.compare(0, encrypted_column_prefix_len, encrypted_column_prefix) ==
+ 0)) {

@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch from 25b39d0 to 0c7ff27CompareMarch 25, 2025 21:13
@AlenkaF

Copy link
Copy Markdown
Member

The C++ failure looks related.

@AlenkaF

Copy link
Copy Markdown
Member

cc @pitrou, this is connected to #45411.

@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch 2 times, most recently from efbc7c8 to 41a3359CompareMarch 27, 2025 05:40
@pitrou

Copy link
Copy Markdown
Member

This adds a user-friendly notation for nested fields:

  • Columns col.key and col.value can be used to reference they key and value nested field of a MapType column. Currently, col.key_value.key and col.key_value.value are required, respectively.

Is this useful? Is there a reasonable use case for using different encryption settings for the map key and value columns, respectively? Otherwise I think we can only keep the following items, which will also simplify the semantics and the implementation:

  • Columns col.element can be used to reference they individual list elements of a ListType column. Currently, col.list.element is required.
  • The actual column name can be used to encrypt all nested fields with the same encryption key.
  • The current column naming scheme can still be used for backward compatibility.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

Is this useful? Is there a reasonable use case for using different encryption settings for the map key and value columns, respectively?

Irrespective of it being useful, it is currently possible to do via col.key_value.key and col.key_value.value. This pull request simplifies that notation consistently with lists and structs.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

Note that I have removed encrypting the individual list elements via col.element as I cannot see a difference in semantics and encryption output between col.element and col. Both notations are equivalent.

Encrypting a single field of a list of structs column can be denoted as col.f1 rather than col.element.f1.

What do you think?

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

@pitrou what are your thoughts on the latest logic / semantics?

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

@pitrou hope you have a moment for this

@pitrou

Copy link
Copy Markdown
Member

I'll be out on vacation, so not before ~10 days I think.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

No worries, enjoy!

@pitrou

Copy link
Copy Markdown
Member

@github-actions crossbow submit preview-docs

@pitroupitrou left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry for the delay. This looks in general, a bunch of minor comments and suggestions below.

Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc Outdated
Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc
Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc Outdated
Comment threadpython/pyarrow/tests/parquet/encryption.py
Comment threadpython/pyarrow/tests/test_dataset_encryption.py Outdated
@github-actions

Copy link
Copy Markdown

Revision: b0ef03f

Submitted crossbow builds: ursacomputing/crossbow @ actions-151fb9c2fa

TaskStatus
preview-docsGitHub Actions

@pitrou

Copy link
Copy Markdown
Member

Ha, sorry, CI fails now that #48338 was merged, you need to stop passing the column path to ColumnEncryptionProperties::Builder.

@pitroupitrou left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the update @EnricoMi !

@pitrou
pitrou merged commit 052e0aa into apache:mainDec 16, 2025
44 of 46 checks passed
@pitroupitrou removed the awaiting committer review Awaiting committer review label Dec 16, 2025
@pitrou

Copy link
Copy Markdown
Member

I'm sorry that it took so long @EnricoMi . Looking forward to more contributions from you!

pitrou added a commit that referenced this pull request Dec 16, 2025
… corpus (#48558)
### Rationale for this change
In #48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that #45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: #48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@conbench-apache-arrow

Copy link
Copy Markdown

After merging your PR, Conbench analyzed the 3 benchmarking runs that have been run so far on merge-commit 052e0aa.

There were no benchmark performance regressions. 🎉

The full Conbench report has more details. It also includes information about 83 possible false positives for unstable benchmarks that are known to sometimes produce them.

pitrou added a commit that referenced this pull request Dec 17, 2025
### Rationale for this change
A `#include` required on Valgrind (due to conditional compilation) was removed in PR #45462.
### Are these changes tested?
Yes, by existing CI jobs.
### Are there any user-facing changes?
No.
* GitHub Issue: #48566
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…uration (apache#45462)
### Rationale for this change
Columns can b encrypted with individual keys. For this, the column name have to be set in `EncryptionConfiguration::column_keys`. This poses the following challenges for columns with nested fields like `MapType`, `ListType`, and `StructType`. Encrypting a column of such type requires providing an encryption key for all nested (leaf) fields. Ideally, the column name should be sufficient (as it is for any other data type) to encrypt all nested fields.
### What changes are included in this PR?
The column name can be used to encrypt all nested fields of `StrutType`, `MapType`, and `ListType` columns with the same encryption key. The current column naming scheme can still be used for backward compatibility.
### Are these changes tested?
Tested in C++ and Python.
### Are there any user-facing changes?
Column encryption can be configured with less code and more intuitive naming.
Documentation and examples updated.
Fixesapache#41246.
* GitHub Issue: apache#41246
Authored-by: Enrico Minack <github@enrico.minack.dev>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…z seed corpus (apache#48558)
### Rationale for this change
In apache#48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that apache#45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
### Rationale for this change
A `#include` required on Valgrind (due to conditional compilation) was removed in PR apache#45462.
### Are these changes tested?
Yes, by existing CI jobs.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48566
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Python][Parquet] Attempt to encrypt column of type 'list' produces OSError

3 participants

@EnricoMi@AlenkaF@pitrou
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

GH-41246: [C++][Python] Simplify nested field encryption configuration - #45462

Merged
pitrou merged 40 commits into
apache:mainfrom
EnricoMi:nested-field-encryption
Dec 16, 2025
Merged

GH-41246: [C++][Python] Simplify nested field encryption configuration#45462
pitrou merged 40 commits into
apache:mainfrom
EnricoMi:nested-field-encryption

Conversation

@EnricoMi

@EnricoMiEnricoMi commented Feb 7, 2025

Copy link
Copy Markdown
Collaborator

Rationale for this change

Columns can b encrypted with individual keys. For this, the column name have to be set in EncryptionConfiguration::column_keys. This poses the following challenges for columns with nested fields like MapType, ListType, and StructType. Encrypting a column of such type requires providing an encryption key for all nested (leaf) fields. Ideally, the column name should be sufficient (as it is for any other data type) to encrypt all nested fields.

What changes are included in this PR?

The column name can be used to encrypt all nested fields of StrutType, MapType, and ListType columns with the same encryption key. The current column naming scheme can still be used for backward compatibility.

Are these changes tested?

Tested in C++ and Python.

Are there any user-facing changes?

Column encryption can be configured with less code and more intuitive naming.

Documentation and examples updated.

Fixes#41246.

@EnricoMi
EnricoMi requested a review from wgtmac as a code ownerFebruary 7, 2025 11:12
@EnricoMiEnricoMi changed the title GH-41246: [C++][Python] Simplify nested field encryptionGH-41246: [C++][Python] Simplify nested field encryption configurationFeb 7, 2025
@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch from ba57bdc to 611f7a7CompareMarch 10, 2025 06:16

@AlenkaFAlenkaF left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Python tests LGTM - they are vey concise and reflect the C++ tests.

The C++ addition of FileEncryptionProperties::encrypt_schema looks good to me also but will need a check from a C++ developer. @wgtmac mind having a look?

@github-actionsgithub-actionsBot added awaiting committer review Awaiting committer review and removed awaiting review Awaiting review labels Mar 24, 2025
@AlenkaF

Copy link
Copy Markdown
Member

Note, CI Win failures do not look related but there is a linter fix needed:

@@ -257,11 +257,12 @@ void FileEncryptionProperties::encrypt_schema(const SchemaDescriptor& schema) {
// encrypted_column encrypts column 'it' when 'it' is either equal to
// encrypted_column, or 'it' starts with encrypted_column_prefix,
// i.e. encrypted_column followed by a '.'
- while (it != column_path_vec.end() &&
- (it->first == encrypted_column ||
- // C++20: can be replaced with it->first.starts_with(encrypted_column_prefix)
- it->first.compare(0, encrypted_column_prefix_len,
- encrypted_column_prefix) == 0)) {
+ while (
+ it != column_path_vec.end() &&
+ (it->first == encrypted_column ||
+ // C++20: can be replaced with it->first.starts_with(encrypted_column_prefix)
+ it->first.compare(0, encrypted_column_prefix_len, encrypted_column_prefix) ==
+ 0)) {

@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch from 25b39d0 to 0c7ff27CompareMarch 25, 2025 21:13
@AlenkaF

Copy link
Copy Markdown
Member

The C++ failure looks related.

@AlenkaF

Copy link
Copy Markdown
Member

cc @pitrou, this is connected to #45411.

@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch 2 times, most recently from efbc7c8 to 41a3359CompareMarch 27, 2025 05:40
@pitrou

Copy link
Copy Markdown
Member

This adds a user-friendly notation for nested fields:

  • Columns col.key and col.value can be used to reference they key and value nested field of a MapType column. Currently, col.key_value.key and col.key_value.value are required, respectively.

Is this useful? Is there a reasonable use case for using different encryption settings for the map key and value columns, respectively? Otherwise I think we can only keep the following items, which will also simplify the semantics and the implementation:

  • Columns col.element can be used to reference they individual list elements of a ListType column. Currently, col.list.element is required.
  • The actual column name can be used to encrypt all nested fields with the same encryption key.
  • The current column naming scheme can still be used for backward compatibility.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

Is this useful? Is there a reasonable use case for using different encryption settings for the map key and value columns, respectively?

Irrespective of it being useful, it is currently possible to do via col.key_value.key and col.key_value.value. This pull request simplifies that notation consistently with lists and structs.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

Note that I have removed encrypting the individual list elements via col.element as I cannot see a difference in semantics and encryption output between col.element and col. Both notations are equivalent.

Encrypting a single field of a list of structs column can be denoted as col.f1 rather than col.element.f1.

What do you think?

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

@pitrou what are your thoughts on the latest logic / semantics?

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

@pitrou hope you have a moment for this

@pitrou

Copy link
Copy Markdown
Member

I'll be out on vacation, so not before ~10 days I think.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

No worries, enjoy!

@pitrou

Copy link
Copy Markdown
Member

@github-actions crossbow submit preview-docs

@pitroupitrou left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry for the delay. This looks in general, a bunch of minor comments and suggestions below.

Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc Outdated
Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc
Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc Outdated
Comment threadpython/pyarrow/tests/parquet/encryption.py
Comment threadpython/pyarrow/tests/test_dataset_encryption.py Outdated
@github-actions

Copy link
Copy Markdown

Revision: b0ef03f

Submitted crossbow builds: ursacomputing/crossbow @ actions-151fb9c2fa

TaskStatus
preview-docsGitHub Actions

@pitrou

Copy link
Copy Markdown
Member

Ha, sorry, CI fails now that #48338 was merged, you need to stop passing the column path to ColumnEncryptionProperties::Builder.

@pitroupitrou left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the update @EnricoMi !

@pitrou
pitrou merged commit 052e0aa into apache:mainDec 16, 2025
44 of 46 checks passed
@pitroupitrou removed the awaiting committer review Awaiting committer review label Dec 16, 2025
@pitrou

Copy link
Copy Markdown
Member

I'm sorry that it took so long @EnricoMi . Looking forward to more contributions from you!

pitrou added a commit that referenced this pull request Dec 16, 2025
… corpus (#48558)
### Rationale for this change
In #48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that #45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: #48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@conbench-apache-arrow

Copy link
Copy Markdown

After merging your PR, Conbench analyzed the 3 benchmarking runs that have been run so far on merge-commit 052e0aa.

There were no benchmark performance regressions. 🎉

The full Conbench report has more details. It also includes information about 83 possible false positives for unstable benchmarks that are known to sometimes produce them.

pitrou added a commit that referenced this pull request Dec 17, 2025
### Rationale for this change
A `#include` required on Valgrind (due to conditional compilation) was removed in PR #45462.
### Are these changes tested?
Yes, by existing CI jobs.
### Are there any user-facing changes?
No.
* GitHub Issue: #48566
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…uration (apache#45462)
### Rationale for this change
Columns can b encrypted with individual keys. For this, the column name have to be set in `EncryptionConfiguration::column_keys`. This poses the following challenges for columns with nested fields like `MapType`, `ListType`, and `StructType`. Encrypting a column of such type requires providing an encryption key for all nested (leaf) fields. Ideally, the column name should be sufficient (as it is for any other data type) to encrypt all nested fields.
### What changes are included in this PR?
The column name can be used to encrypt all nested fields of `StrutType`, `MapType`, and `ListType` columns with the same encryption key. The current column naming scheme can still be used for backward compatibility.
### Are these changes tested?
Tested in C++ and Python.
### Are there any user-facing changes?
Column encryption can be configured with less code and more intuitive naming.
Documentation and examples updated.
Fixesapache#41246.
* GitHub Issue: apache#41246
Authored-by: Enrico Minack <github@enrico.minack.dev>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…z seed corpus (apache#48558)
### Rationale for this change
In apache#48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that apache#45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
### Rationale for this change
A `#include` required on Valgrind (due to conditional compilation) was removed in PR apache#45462.
### Are these changes tested?
Yes, by existing CI jobs.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48566
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Python][Parquet] Attempt to encrypt column of type 'list' produces OSError

3 participants

@EnricoMi@AlenkaF@pitrou
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

GH-41246: [C++][Python] Simplify nested field encryption configuration - #45462

Merged
pitrou merged 40 commits into
apache:mainfrom
EnricoMi:nested-field-encryption
Dec 16, 2025
Merged

GH-41246: [C++][Python] Simplify nested field encryption configuration#45462
pitrou merged 40 commits into
apache:mainfrom
EnricoMi:nested-field-encryption

Conversation

@EnricoMi

@EnricoMiEnricoMi commented Feb 7, 2025

Copy link
Copy Markdown
Collaborator

Rationale for this change

Columns can b encrypted with individual keys. For this, the column name have to be set in EncryptionConfiguration::column_keys. This poses the following challenges for columns with nested fields like MapType, ListType, and StructType. Encrypting a column of such type requires providing an encryption key for all nested (leaf) fields. Ideally, the column name should be sufficient (as it is for any other data type) to encrypt all nested fields.

What changes are included in this PR?

The column name can be used to encrypt all nested fields of StrutType, MapType, and ListType columns with the same encryption key. The current column naming scheme can still be used for backward compatibility.

Are these changes tested?

Tested in C++ and Python.

Are there any user-facing changes?

Column encryption can be configured with less code and more intuitive naming.

Documentation and examples updated.

Fixes#41246.

@EnricoMi
EnricoMi requested a review from wgtmac as a code ownerFebruary 7, 2025 11:12
@EnricoMiEnricoMi changed the title GH-41246: [C++][Python] Simplify nested field encryptionGH-41246: [C++][Python] Simplify nested field encryption configurationFeb 7, 2025
@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch from ba57bdc to 611f7a7CompareMarch 10, 2025 06:16

@AlenkaFAlenkaF left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Python tests LGTM - they are vey concise and reflect the C++ tests.

The C++ addition of FileEncryptionProperties::encrypt_schema looks good to me also but will need a check from a C++ developer. @wgtmac mind having a look?

@github-actionsgithub-actionsBot added awaiting committer review Awaiting committer review and removed awaiting review Awaiting review labels Mar 24, 2025
@AlenkaF

Copy link
Copy Markdown
Member

Note, CI Win failures do not look related but there is a linter fix needed:

@@ -257,11 +257,12 @@ void FileEncryptionProperties::encrypt_schema(const SchemaDescriptor& schema) {
// encrypted_column encrypts column 'it' when 'it' is either equal to
// encrypted_column, or 'it' starts with encrypted_column_prefix,
// i.e. encrypted_column followed by a '.'
- while (it != column_path_vec.end() &&
- (it->first == encrypted_column ||
- // C++20: can be replaced with it->first.starts_with(encrypted_column_prefix)
- it->first.compare(0, encrypted_column_prefix_len,
- encrypted_column_prefix) == 0)) {
+ while (
+ it != column_path_vec.end() &&
+ (it->first == encrypted_column ||
+ // C++20: can be replaced with it->first.starts_with(encrypted_column_prefix)
+ it->first.compare(0, encrypted_column_prefix_len, encrypted_column_prefix) ==
+ 0)) {

@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch from 25b39d0 to 0c7ff27CompareMarch 25, 2025 21:13
@AlenkaF

Copy link
Copy Markdown
Member

The C++ failure looks related.

@AlenkaF

Copy link
Copy Markdown
Member

cc @pitrou, this is connected to #45411.

@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch 2 times, most recently from efbc7c8 to 41a3359CompareMarch 27, 2025 05:40
@pitrou

Copy link
Copy Markdown
Member

This adds a user-friendly notation for nested fields:

  • Columns col.key and col.value can be used to reference they key and value nested field of a MapType column. Currently, col.key_value.key and col.key_value.value are required, respectively.

Is this useful? Is there a reasonable use case for using different encryption settings for the map key and value columns, respectively? Otherwise I think we can only keep the following items, which will also simplify the semantics and the implementation:

  • Columns col.element can be used to reference they individual list elements of a ListType column. Currently, col.list.element is required.
  • The actual column name can be used to encrypt all nested fields with the same encryption key.
  • The current column naming scheme can still be used for backward compatibility.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

Is this useful? Is there a reasonable use case for using different encryption settings for the map key and value columns, respectively?

Irrespective of it being useful, it is currently possible to do via col.key_value.key and col.key_value.value. This pull request simplifies that notation consistently with lists and structs.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

Note that I have removed encrypting the individual list elements via col.element as I cannot see a difference in semantics and encryption output between col.element and col. Both notations are equivalent.

Encrypting a single field of a list of structs column can be denoted as col.f1 rather than col.element.f1.

What do you think?

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

@pitrou what are your thoughts on the latest logic / semantics?

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

@pitrou hope you have a moment for this

@pitrou

Copy link
Copy Markdown
Member

I'll be out on vacation, so not before ~10 days I think.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

No worries, enjoy!

@pitrou

Copy link
Copy Markdown
Member

@github-actions crossbow submit preview-docs

@pitroupitrou left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry for the delay. This looks in general, a bunch of minor comments and suggestions below.

Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc Outdated
Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc
Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc Outdated
Comment threadpython/pyarrow/tests/parquet/encryption.py
Comment threadpython/pyarrow/tests/test_dataset_encryption.py Outdated
@github-actions

Copy link
Copy Markdown

Revision: b0ef03f

Submitted crossbow builds: ursacomputing/crossbow @ actions-151fb9c2fa

TaskStatus
preview-docsGitHub Actions

@pitrou

Copy link
Copy Markdown
Member

Ha, sorry, CI fails now that #48338 was merged, you need to stop passing the column path to ColumnEncryptionProperties::Builder.

@pitroupitrou left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the update @EnricoMi !

@pitrou
pitrou merged commit 052e0aa into apache:mainDec 16, 2025
44 of 46 checks passed
@pitroupitrou removed the awaiting committer review Awaiting committer review label Dec 16, 2025
@pitrou

Copy link
Copy Markdown
Member

I'm sorry that it took so long @EnricoMi . Looking forward to more contributions from you!

pitrou added a commit that referenced this pull request Dec 16, 2025
… corpus (#48558)
### Rationale for this change
In #48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that #45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: #48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@conbench-apache-arrow

Copy link
Copy Markdown

After merging your PR, Conbench analyzed the 3 benchmarking runs that have been run so far on merge-commit 052e0aa.

There were no benchmark performance regressions. 🎉

The full Conbench report has more details. It also includes information about 83 possible false positives for unstable benchmarks that are known to sometimes produce them.

pitrou added a commit that referenced this pull request Dec 17, 2025
### Rationale for this change
A `#include` required on Valgrind (due to conditional compilation) was removed in PR #45462.
### Are these changes tested?
Yes, by existing CI jobs.
### Are there any user-facing changes?
No.
* GitHub Issue: #48566
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…uration (apache#45462)
### Rationale for this change
Columns can b encrypted with individual keys. For this, the column name have to be set in `EncryptionConfiguration::column_keys`. This poses the following challenges for columns with nested fields like `MapType`, `ListType`, and `StructType`. Encrypting a column of such type requires providing an encryption key for all nested (leaf) fields. Ideally, the column name should be sufficient (as it is for any other data type) to encrypt all nested fields.
### What changes are included in this PR?
The column name can be used to encrypt all nested fields of `StrutType`, `MapType`, and `ListType` columns with the same encryption key. The current column naming scheme can still be used for backward compatibility.
### Are these changes tested?
Tested in C++ and Python.
### Are there any user-facing changes?
Column encryption can be configured with less code and more intuitive naming.
Documentation and examples updated.
Fixesapache#41246.
* GitHub Issue: apache#41246
Authored-by: Enrico Minack <github@enrico.minack.dev>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…z seed corpus (apache#48558)
### Rationale for this change
In apache#48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that apache#45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
### Rationale for this change
A `#include` required on Valgrind (due to conditional compilation) was removed in PR apache#45462.
### Are these changes tested?
Yes, by existing CI jobs.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48566
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Python][Parquet] Attempt to encrypt column of type 'list' produces OSError

3 participants

@EnricoMi@AlenkaF@pitrou
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

GH-41246: [C++][Python] Simplify nested field encryption configuration - #45462

Merged
pitrou merged 40 commits into
apache:mainfrom
EnricoMi:nested-field-encryption
Dec 16, 2025
Merged

GH-41246: [C++][Python] Simplify nested field encryption configuration#45462
pitrou merged 40 commits into
apache:mainfrom
EnricoMi:nested-field-encryption

Conversation

@EnricoMi

@EnricoMiEnricoMi commented Feb 7, 2025

Copy link
Copy Markdown
Collaborator

Rationale for this change

Columns can b encrypted with individual keys. For this, the column name have to be set in EncryptionConfiguration::column_keys. This poses the following challenges for columns with nested fields like MapType, ListType, and StructType. Encrypting a column of such type requires providing an encryption key for all nested (leaf) fields. Ideally, the column name should be sufficient (as it is for any other data type) to encrypt all nested fields.

What changes are included in this PR?

The column name can be used to encrypt all nested fields of StrutType, MapType, and ListType columns with the same encryption key. The current column naming scheme can still be used for backward compatibility.

Are these changes tested?

Tested in C++ and Python.

Are there any user-facing changes?

Column encryption can be configured with less code and more intuitive naming.

Documentation and examples updated.

Fixes#41246.

@EnricoMi
EnricoMi requested a review from wgtmac as a code ownerFebruary 7, 2025 11:12
@EnricoMiEnricoMi changed the title GH-41246: [C++][Python] Simplify nested field encryptionGH-41246: [C++][Python] Simplify nested field encryption configurationFeb 7, 2025
@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch from ba57bdc to 611f7a7CompareMarch 10, 2025 06:16

@AlenkaFAlenkaF left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Python tests LGTM - they are vey concise and reflect the C++ tests.

The C++ addition of FileEncryptionProperties::encrypt_schema looks good to me also but will need a check from a C++ developer. @wgtmac mind having a look?

@github-actionsgithub-actionsBot added awaiting committer review Awaiting committer review and removed awaiting review Awaiting review labels Mar 24, 2025
@AlenkaF

Copy link
Copy Markdown
Member

Note, CI Win failures do not look related but there is a linter fix needed:

@@ -257,11 +257,12 @@ void FileEncryptionProperties::encrypt_schema(const SchemaDescriptor& schema) {
// encrypted_column encrypts column 'it' when 'it' is either equal to
// encrypted_column, or 'it' starts with encrypted_column_prefix,
// i.e. encrypted_column followed by a '.'
- while (it != column_path_vec.end() &&
- (it->first == encrypted_column ||
- // C++20: can be replaced with it->first.starts_with(encrypted_column_prefix)
- it->first.compare(0, encrypted_column_prefix_len,
- encrypted_column_prefix) == 0)) {
+ while (
+ it != column_path_vec.end() &&
+ (it->first == encrypted_column ||
+ // C++20: can be replaced with it->first.starts_with(encrypted_column_prefix)
+ it->first.compare(0, encrypted_column_prefix_len, encrypted_column_prefix) ==
+ 0)) {

@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch from 25b39d0 to 0c7ff27CompareMarch 25, 2025 21:13
@AlenkaF

Copy link
Copy Markdown
Member

The C++ failure looks related.

@AlenkaF

Copy link
Copy Markdown
Member

cc @pitrou, this is connected to #45411.

@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch 2 times, most recently from efbc7c8 to 41a3359CompareMarch 27, 2025 05:40
@pitrou

Copy link
Copy Markdown
Member

This adds a user-friendly notation for nested fields:

  • Columns col.key and col.value can be used to reference they key and value nested field of a MapType column. Currently, col.key_value.key and col.key_value.value are required, respectively.

Is this useful? Is there a reasonable use case for using different encryption settings for the map key and value columns, respectively? Otherwise I think we can only keep the following items, which will also simplify the semantics and the implementation:

  • Columns col.element can be used to reference they individual list elements of a ListType column. Currently, col.list.element is required.
  • The actual column name can be used to encrypt all nested fields with the same encryption key.
  • The current column naming scheme can still be used for backward compatibility.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

Is this useful? Is there a reasonable use case for using different encryption settings for the map key and value columns, respectively?

Irrespective of it being useful, it is currently possible to do via col.key_value.key and col.key_value.value. This pull request simplifies that notation consistently with lists and structs.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

Note that I have removed encrypting the individual list elements via col.element as I cannot see a difference in semantics and encryption output between col.element and col. Both notations are equivalent.

Encrypting a single field of a list of structs column can be denoted as col.f1 rather than col.element.f1.

What do you think?

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

@pitrou what are your thoughts on the latest logic / semantics?

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

@pitrou hope you have a moment for this

@pitrou

Copy link
Copy Markdown
Member

I'll be out on vacation, so not before ~10 days I think.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

No worries, enjoy!

@pitrou

Copy link
Copy Markdown
Member

@github-actions crossbow submit preview-docs

@pitroupitrou left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry for the delay. This looks in general, a bunch of minor comments and suggestions below.

Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc Outdated
Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc
Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc Outdated
Comment threadpython/pyarrow/tests/parquet/encryption.py
Comment threadpython/pyarrow/tests/test_dataset_encryption.py Outdated
@github-actions

Copy link
Copy Markdown

Revision: b0ef03f

Submitted crossbow builds: ursacomputing/crossbow @ actions-151fb9c2fa

TaskStatus
preview-docsGitHub Actions

@pitrou

Copy link
Copy Markdown
Member

Ha, sorry, CI fails now that #48338 was merged, you need to stop passing the column path to ColumnEncryptionProperties::Builder.

@pitroupitrou left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the update @EnricoMi !

@pitrou
pitrou merged commit 052e0aa into apache:mainDec 16, 2025
44 of 46 checks passed
@pitroupitrou removed the awaiting committer review Awaiting committer review label Dec 16, 2025
@pitrou

Copy link
Copy Markdown
Member

I'm sorry that it took so long @EnricoMi . Looking forward to more contributions from you!

pitrou added a commit that referenced this pull request Dec 16, 2025
… corpus (#48558)
### Rationale for this change
In #48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that #45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: #48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@conbench-apache-arrow

Copy link
Copy Markdown

After merging your PR, Conbench analyzed the 3 benchmarking runs that have been run so far on merge-commit 052e0aa.

There were no benchmark performance regressions. 🎉

The full Conbench report has more details. It also includes information about 83 possible false positives for unstable benchmarks that are known to sometimes produce them.

pitrou added a commit that referenced this pull request Dec 17, 2025
### Rationale for this change
A `#include` required on Valgrind (due to conditional compilation) was removed in PR #45462.
### Are these changes tested?
Yes, by existing CI jobs.
### Are there any user-facing changes?
No.
* GitHub Issue: #48566
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…uration (apache#45462)
### Rationale for this change
Columns can b encrypted with individual keys. For this, the column name have to be set in `EncryptionConfiguration::column_keys`. This poses the following challenges for columns with nested fields like `MapType`, `ListType`, and `StructType`. Encrypting a column of such type requires providing an encryption key for all nested (leaf) fields. Ideally, the column name should be sufficient (as it is for any other data type) to encrypt all nested fields.
### What changes are included in this PR?
The column name can be used to encrypt all nested fields of `StrutType`, `MapType`, and `ListType` columns with the same encryption key. The current column naming scheme can still be used for backward compatibility.
### Are these changes tested?
Tested in C++ and Python.
### Are there any user-facing changes?
Column encryption can be configured with less code and more intuitive naming.
Documentation and examples updated.
Fixesapache#41246.
* GitHub Issue: apache#41246
Authored-by: Enrico Minack <github@enrico.minack.dev>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…z seed corpus (apache#48558)
### Rationale for this change
In apache#48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that apache#45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
### Rationale for this change
A `#include` required on Valgrind (due to conditional compilation) was removed in PR apache#45462.
### Are these changes tested?
Yes, by existing CI jobs.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48566
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Python][Parquet] Attempt to encrypt column of type 'list' produces OSError

3 participants

@EnricoMi@AlenkaF@pitrou
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

GH-41246: [C++][Python] Simplify nested field encryption configuration - #45462

Merged
pitrou merged 40 commits into
apache:mainfrom
EnricoMi:nested-field-encryption
Dec 16, 2025
Merged

GH-41246: [C++][Python] Simplify nested field encryption configuration#45462
pitrou merged 40 commits into
apache:mainfrom
EnricoMi:nested-field-encryption

Conversation

@EnricoMi

@EnricoMiEnricoMi commented Feb 7, 2025

Copy link
Copy Markdown
Collaborator

Rationale for this change

Columns can b encrypted with individual keys. For this, the column name have to be set in EncryptionConfiguration::column_keys. This poses the following challenges for columns with nested fields like MapType, ListType, and StructType. Encrypting a column of such type requires providing an encryption key for all nested (leaf) fields. Ideally, the column name should be sufficient (as it is for any other data type) to encrypt all nested fields.

What changes are included in this PR?

The column name can be used to encrypt all nested fields of StrutType, MapType, and ListType columns with the same encryption key. The current column naming scheme can still be used for backward compatibility.

Are these changes tested?

Tested in C++ and Python.

Are there any user-facing changes?

Column encryption can be configured with less code and more intuitive naming.

Documentation and examples updated.

Fixes#41246.

@EnricoMi
EnricoMi requested a review from wgtmac as a code ownerFebruary 7, 2025 11:12
@EnricoMiEnricoMi changed the title GH-41246: [C++][Python] Simplify nested field encryptionGH-41246: [C++][Python] Simplify nested field encryption configurationFeb 7, 2025
@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch from ba57bdc to 611f7a7CompareMarch 10, 2025 06:16

@AlenkaFAlenkaF left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Python tests LGTM - they are vey concise and reflect the C++ tests.

The C++ addition of FileEncryptionProperties::encrypt_schema looks good to me also but will need a check from a C++ developer. @wgtmac mind having a look?

@github-actionsgithub-actionsBot added awaiting committer review Awaiting committer review and removed awaiting review Awaiting review labels Mar 24, 2025
@AlenkaF

Copy link
Copy Markdown
Member

Note, CI Win failures do not look related but there is a linter fix needed:

@@ -257,11 +257,12 @@ void FileEncryptionProperties::encrypt_schema(const SchemaDescriptor& schema) {
// encrypted_column encrypts column 'it' when 'it' is either equal to
// encrypted_column, or 'it' starts with encrypted_column_prefix,
// i.e. encrypted_column followed by a '.'
- while (it != column_path_vec.end() &&
- (it->first == encrypted_column ||
- // C++20: can be replaced with it->first.starts_with(encrypted_column_prefix)
- it->first.compare(0, encrypted_column_prefix_len,
- encrypted_column_prefix) == 0)) {
+ while (
+ it != column_path_vec.end() &&
+ (it->first == encrypted_column ||
+ // C++20: can be replaced with it->first.starts_with(encrypted_column_prefix)
+ it->first.compare(0, encrypted_column_prefix_len, encrypted_column_prefix) ==
+ 0)) {

@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch from 25b39d0 to 0c7ff27CompareMarch 25, 2025 21:13
@AlenkaF

Copy link
Copy Markdown
Member

The C++ failure looks related.

@AlenkaF

Copy link
Copy Markdown
Member

cc @pitrou, this is connected to #45411.

@EnricoMi
EnricoMiforce-pushed the nested-field-encryption branch 2 times, most recently from efbc7c8 to 41a3359CompareMarch 27, 2025 05:40
@pitrou

Copy link
Copy Markdown
Member

This adds a user-friendly notation for nested fields:

  • Columns col.key and col.value can be used to reference they key and value nested field of a MapType column. Currently, col.key_value.key and col.key_value.value are required, respectively.

Is this useful? Is there a reasonable use case for using different encryption settings for the map key and value columns, respectively? Otherwise I think we can only keep the following items, which will also simplify the semantics and the implementation:

  • Columns col.element can be used to reference they individual list elements of a ListType column. Currently, col.list.element is required.
  • The actual column name can be used to encrypt all nested fields with the same encryption key.
  • The current column naming scheme can still be used for backward compatibility.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

Is this useful? Is there a reasonable use case for using different encryption settings for the map key and value columns, respectively?

Irrespective of it being useful, it is currently possible to do via col.key_value.key and col.key_value.value. This pull request simplifies that notation consistently with lists and structs.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

Note that I have removed encrypting the individual list elements via col.element as I cannot see a difference in semantics and encryption output between col.element and col. Both notations are equivalent.

Encrypting a single field of a list of structs column can be denoted as col.f1 rather than col.element.f1.

What do you think?

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

@pitrou what are your thoughts on the latest logic / semantics?

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

@pitrou hope you have a moment for this

@pitrou

Copy link
Copy Markdown
Member

I'll be out on vacation, so not before ~10 days I think.

@EnricoMi

Copy link
Copy Markdown
CollaboratorAuthor

No worries, enjoy!

@pitrou

Copy link
Copy Markdown
Member

@github-actions crossbow submit preview-docs

@pitroupitrou left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry for the delay. This looks in general, a bunch of minor comments and suggestions below.

Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc Outdated
Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc
Comment threadcpp/src/arrow/dataset/file_parquet_encryption_test.cc Outdated
Comment threadpython/pyarrow/tests/parquet/encryption.py
Comment threadpython/pyarrow/tests/test_dataset_encryption.py Outdated
@github-actions

Copy link
Copy Markdown

Revision: b0ef03f

Submitted crossbow builds: ursacomputing/crossbow @ actions-151fb9c2fa

TaskStatus
preview-docsGitHub Actions

@pitrou

Copy link
Copy Markdown
Member

Ha, sorry, CI fails now that #48338 was merged, you need to stop passing the column path to ColumnEncryptionProperties::Builder.

@pitroupitrou left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the update @EnricoMi !

@pitrou
pitrou merged commit 052e0aa into apache:mainDec 16, 2025
44 of 46 checks passed
@pitroupitrou removed the awaiting committer review Awaiting committer review label Dec 16, 2025
@pitrou

Copy link
Copy Markdown
Member

I'm sorry that it took so long @EnricoMi . Looking forward to more contributions from you!

pitrou added a commit that referenced this pull request Dec 16, 2025
… corpus (#48558)
### Rationale for this change
In #48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that #45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: #48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@conbench-apache-arrow

Copy link
Copy Markdown

After merging your PR, Conbench analyzed the 3 benchmarking runs that have been run so far on merge-commit 052e0aa.

There were no benchmark performance regressions. 🎉

The full Conbench report has more details. It also includes information about 83 possible false positives for unstable benchmarks that are known to sometimes produce them.

pitrou added a commit that referenced this pull request Dec 17, 2025
### Rationale for this change
A `#include` required on Valgrind (due to conditional compilation) was removed in PR #45462.
### Are these changes tested?
Yes, by existing CI jobs.
### Are there any user-facing changes?
No.
* GitHub Issue: #48566
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…uration (apache#45462)
### Rationale for this change
Columns can b encrypted with individual keys. For this, the column name have to be set in `EncryptionConfiguration::column_keys`. This poses the following challenges for columns with nested fields like `MapType`, `ListType`, and `StructType`. Encrypting a column of such type requires providing an encryption key for all nested (leaf) fields. Ideally, the column name should be sufficient (as it is for any other data type) to encrypt all nested fields.
### What changes are included in this PR?
The column name can be used to encrypt all nested fields of `StrutType`, `MapType`, and `ListType` columns with the same encryption key. The current column naming scheme can still be used for backward compatibility.
### Are these changes tested?
Tested in C++ and Python.
### Are there any user-facing changes?
Column encryption can be configured with less code and more intuitive naming.
Documentation and examples updated.
Fixesapache#41246.
* GitHub Issue: apache#41246
Authored-by: Enrico Minack <github@enrico.minack.dev>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…z seed corpus (apache#48558)
### Rationale for this change
In apache#48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that apache#45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
### Rationale for this change
A `#include` required on Valgrind (due to conditional compilation) was removed in PR apache#45462.
### Are these changes tested?
Yes, by existing CI jobs.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48566
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Python][Parquet] Attempt to encrypt column of type 'list' produces OSError

3 participants

@EnricoMi@AlenkaF@pitrou