GH-48335: [C++][Parquet] Fuzz encrypted files - #48336

Merged
pitrou merged 2 commits into
apache:mainfrom
pitrou:fuzz-pq-encryption
Dec 8, 2025
Merged

GH-48335: [C++][Parquet] Fuzz encrypted files#48336
pitrou merged 2 commits into
apache:mainfrom
pitrou:fuzz-pq-encryption

Conversation

@pitrou

@pitroupitrou commented Dec 4, 2025

Copy link
Copy Markdown
Member

Rationale for this change

Currently, if given an encrypted file (whether valid or invalid), the Parquet fuzz target will bail out almost immediately since it does not have any decryption key configured. This prevents the fuzzer from covering any significant part of the Parquet encryption codebase.

What changes are included in this PR?

  1. Improve the fuzz target so as to be able to read encrypted files present in the seed corpus (except those that require a external AAD or external key material)
  2. Generate encrypted files in the seed corpus that the fuzz target is able to successfully decrypt

Are these changes tested?

In expanded unit test, and locally.

Are there any user-facing changes?

No.

std::unique_ptr<ColumnCryptoMetaData> crypto_metadata = col_chunk->crypto_metadata();
if (crypto_metadata != nullptr) {
ParquetException::NYI("Cannot read encrypted bloom filter yet");
ParquetException::NYI("BloomFilter decryption is not yet supported");

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This just ensures the same exception message in used in different places.

: ParquetException(columnPath.c_str()) {}
};

inline const uint8_t* str2bytes(const std::string& str) {

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This was unused.

@github-actionsgithub-actionsBot added awaiting committer review Awaiting committer review and removed awaiting review Awaiting review labels Dec 4, 2025

namespace {

Status FuzzReadData(std::unique_ptr<FileReader> reader) {

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This code is moved away to fuzz_internal.cc so that parquet/arrow/reader.cc does not depend on Parquet encryption.

@pitrou
pitrouforce-pushed the fuzz-pq-encryption branch 2 times, most recently from fe50a06 to eb4c4c8CompareDecember 4, 2025 16:14
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: eb4c4c8

Submitted crossbow builds: ursacomputing/crossbow @ actions-40f4ae6d06

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou
pitrou marked this pull request as ready for review December 4, 2025 16:20
@pitrou
pitrou requested a review from wgtmac as a code ownerDecember 4, 2025 16:20
Comment threadcpp/src/parquet/arrow/generate_fuzz_corpus.cc
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: 219985a

Submitted crossbow builds: ursacomputing/crossbow @ actions-cadb3008d8

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou

Copy link
Copy Markdown
MemberAuthor

@adamreeve@EnricoMi Do you want to take a look at this PR?

@adamreeveadamreeve left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 looks good to me

pitrou added a commit that referenced this pull request Dec 8, 2025
### Rationale for this change
While working on PR #48336 I quickly got irritated by the clumsiness of the Parquet encryption configuration API. This issue attempts to reduce the verbosity of `ColumnEncryptionProperties` construction.
### What changes are included in this PR?
1. Remove unused `column_path` member in `ColumnEncryptionProperties`
2. Add convenience `ColumnEncryptionProperties` factory functions to avoid going through the clumsy `Builder` API
### Are these changes tested?
Yes
### Are there any user-facing changes?
Two deprecated constructors and a removed accessor for an useless property.
**This PR includes breaking changes to public APIs.** (If there are any breaking changes to public APIs, please explain which changes are breaking. If not, you can remove this.)
* GitHub Issue: #48337
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: c72edef

Submitted crossbow builds: ursacomputing/crossbow @ actions-4952d9d2f1

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou
pitrou merged commit fa4e593 into apache:mainDec 8, 2025
46 of 48 checks passed
@pitroupitrou removed the awaiting committer review Awaiting committer review label Dec 8, 2025
@pitrou
pitrou deleted the fuzz-pq-encryption branch December 8, 2025 08:52
@pitrou

Copy link
Copy Markdown
MemberAuthor

Thanks for the review @adamreeve . I hope this will help uncover any latent issues in the decryption codepaths.

pitrou added a commit that referenced this pull request Dec 16, 2025
… corpus (#48558)
### Rationale for this change
In #48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that #45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: #48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@conbench-apache-arrow

Copy link
Copy Markdown

After merging your PR, Conbench analyzed the 3 benchmarking runs that have been run so far on merge-commit fa4e593.

There were no benchmark performance regressions. 🎉

The full Conbench report has more details. It also includes information about 13 possible false positives for unstable benchmarks that are known to sometimes produce them.

Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…48338)
### Rationale for this change
While working on PR apache#48336 I quickly got irritated by the clumsiness of the Parquet encryption configuration API. This issue attempts to reduce the verbosity of `ColumnEncryptionProperties` construction.
### What changes are included in this PR?
1. Remove unused `column_path` member in `ColumnEncryptionProperties`
2. Add convenience `ColumnEncryptionProperties` factory functions to avoid going through the clumsy `Builder` API
### Are these changes tested?
Yes
### Are there any user-facing changes?
Two deprecated constructors and a removed accessor for an useless property.
**This PR includes breaking changes to public APIs.** (If there are any breaking changes to public APIs, please explain which changes are breaking. If not, you can remove this.)
* GitHub Issue: apache#48337
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
### Rationale for this change
Currently, if given an encrypted file (whether valid or invalid), the Parquet fuzz target will bail out almost immediately since it does not have any decryption key configured. This prevents the fuzzer from covering any significant part of the Parquet encryption codebase.
### What changes are included in this PR?
1. Improve the fuzz target so as to be able to read encrypted files present in the seed corpus (except those that require a external AAD or external key material)
2. Generate encrypted files in the seed corpus that the fuzz target is able to successfully decrypt
### Are these changes tested?
In expanded unit test, and locally.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48335
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…z seed corpus (apache#48558)
### Rationale for this change
In apache#48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that apache#45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@pitrou@adamreeve
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

GH-48335: [C++][Parquet] Fuzz encrypted files - #48336

Merged
pitrou merged 2 commits into
apache:mainfrom
pitrou:fuzz-pq-encryption
Dec 8, 2025
Merged

GH-48335: [C++][Parquet] Fuzz encrypted files#48336
pitrou merged 2 commits into
apache:mainfrom
pitrou:fuzz-pq-encryption

Conversation

@pitrou

@pitroupitrou commented Dec 4, 2025

Copy link
Copy Markdown
Member

Rationale for this change

Currently, if given an encrypted file (whether valid or invalid), the Parquet fuzz target will bail out almost immediately since it does not have any decryption key configured. This prevents the fuzzer from covering any significant part of the Parquet encryption codebase.

What changes are included in this PR?

  1. Improve the fuzz target so as to be able to read encrypted files present in the seed corpus (except those that require a external AAD or external key material)
  2. Generate encrypted files in the seed corpus that the fuzz target is able to successfully decrypt

Are these changes tested?

In expanded unit test, and locally.

Are there any user-facing changes?

No.

std::unique_ptr<ColumnCryptoMetaData> crypto_metadata = col_chunk->crypto_metadata();
if (crypto_metadata != nullptr) {
ParquetException::NYI("Cannot read encrypted bloom filter yet");
ParquetException::NYI("BloomFilter decryption is not yet supported");

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This just ensures the same exception message in used in different places.

: ParquetException(columnPath.c_str()) {}
};

inline const uint8_t* str2bytes(const std::string& str) {

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This was unused.

@github-actionsgithub-actionsBot added awaiting committer review Awaiting committer review and removed awaiting review Awaiting review labels Dec 4, 2025

namespace {

Status FuzzReadData(std::unique_ptr<FileReader> reader) {

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This code is moved away to fuzz_internal.cc so that parquet/arrow/reader.cc does not depend on Parquet encryption.

@pitrou
pitrouforce-pushed the fuzz-pq-encryption branch 2 times, most recently from fe50a06 to eb4c4c8CompareDecember 4, 2025 16:14
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: eb4c4c8

Submitted crossbow builds: ursacomputing/crossbow @ actions-40f4ae6d06

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou
pitrou marked this pull request as ready for review December 4, 2025 16:20
@pitrou
pitrou requested a review from wgtmac as a code ownerDecember 4, 2025 16:20
Comment threadcpp/src/parquet/arrow/generate_fuzz_corpus.cc
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: 219985a

Submitted crossbow builds: ursacomputing/crossbow @ actions-cadb3008d8

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou

Copy link
Copy Markdown
MemberAuthor

@adamreeve@EnricoMi Do you want to take a look at this PR?

@adamreeveadamreeve left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 looks good to me

pitrou added a commit that referenced this pull request Dec 8, 2025
### Rationale for this change
While working on PR #48336 I quickly got irritated by the clumsiness of the Parquet encryption configuration API. This issue attempts to reduce the verbosity of `ColumnEncryptionProperties` construction.
### What changes are included in this PR?
1. Remove unused `column_path` member in `ColumnEncryptionProperties`
2. Add convenience `ColumnEncryptionProperties` factory functions to avoid going through the clumsy `Builder` API
### Are these changes tested?
Yes
### Are there any user-facing changes?
Two deprecated constructors and a removed accessor for an useless property.
**This PR includes breaking changes to public APIs.** (If there are any breaking changes to public APIs, please explain which changes are breaking. If not, you can remove this.)
* GitHub Issue: #48337
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: c72edef

Submitted crossbow builds: ursacomputing/crossbow @ actions-4952d9d2f1

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou
pitrou merged commit fa4e593 into apache:mainDec 8, 2025
46 of 48 checks passed
@pitroupitrou removed the awaiting committer review Awaiting committer review label Dec 8, 2025
@pitrou
pitrou deleted the fuzz-pq-encryption branch December 8, 2025 08:52
@pitrou

Copy link
Copy Markdown
MemberAuthor

Thanks for the review @adamreeve . I hope this will help uncover any latent issues in the decryption codepaths.

pitrou added a commit that referenced this pull request Dec 16, 2025
… corpus (#48558)
### Rationale for this change
In #48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that #45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: #48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@conbench-apache-arrow

Copy link
Copy Markdown

After merging your PR, Conbench analyzed the 3 benchmarking runs that have been run so far on merge-commit fa4e593.

There were no benchmark performance regressions. 🎉

The full Conbench report has more details. It also includes information about 13 possible false positives for unstable benchmarks that are known to sometimes produce them.

Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…48338)
### Rationale for this change
While working on PR apache#48336 I quickly got irritated by the clumsiness of the Parquet encryption configuration API. This issue attempts to reduce the verbosity of `ColumnEncryptionProperties` construction.
### What changes are included in this PR?
1. Remove unused `column_path` member in `ColumnEncryptionProperties`
2. Add convenience `ColumnEncryptionProperties` factory functions to avoid going through the clumsy `Builder` API
### Are these changes tested?
Yes
### Are there any user-facing changes?
Two deprecated constructors and a removed accessor for an useless property.
**This PR includes breaking changes to public APIs.** (If there are any breaking changes to public APIs, please explain which changes are breaking. If not, you can remove this.)
* GitHub Issue: apache#48337
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
### Rationale for this change
Currently, if given an encrypted file (whether valid or invalid), the Parquet fuzz target will bail out almost immediately since it does not have any decryption key configured. This prevents the fuzzer from covering any significant part of the Parquet encryption codebase.
### What changes are included in this PR?
1. Improve the fuzz target so as to be able to read encrypted files present in the seed corpus (except those that require a external AAD or external key material)
2. Generate encrypted files in the seed corpus that the fuzz target is able to successfully decrypt
### Are these changes tested?
In expanded unit test, and locally.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48335
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…z seed corpus (apache#48558)
### Rationale for this change
In apache#48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that apache#45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@pitrou@adamreeve
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

GH-48335: [C++][Parquet] Fuzz encrypted files - #48336

Merged
pitrou merged 2 commits into
apache:mainfrom
pitrou:fuzz-pq-encryption
Dec 8, 2025
Merged

GH-48335: [C++][Parquet] Fuzz encrypted files#48336
pitrou merged 2 commits into
apache:mainfrom
pitrou:fuzz-pq-encryption

Conversation

@pitrou

@pitroupitrou commented Dec 4, 2025

Copy link
Copy Markdown
Member

Rationale for this change

Currently, if given an encrypted file (whether valid or invalid), the Parquet fuzz target will bail out almost immediately since it does not have any decryption key configured. This prevents the fuzzer from covering any significant part of the Parquet encryption codebase.

What changes are included in this PR?

  1. Improve the fuzz target so as to be able to read encrypted files present in the seed corpus (except those that require a external AAD or external key material)
  2. Generate encrypted files in the seed corpus that the fuzz target is able to successfully decrypt

Are these changes tested?

In expanded unit test, and locally.

Are there any user-facing changes?

No.

std::unique_ptr<ColumnCryptoMetaData> crypto_metadata = col_chunk->crypto_metadata();
if (crypto_metadata != nullptr) {
ParquetException::NYI("Cannot read encrypted bloom filter yet");
ParquetException::NYI("BloomFilter decryption is not yet supported");

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This just ensures the same exception message in used in different places.

: ParquetException(columnPath.c_str()) {}
};

inline const uint8_t* str2bytes(const std::string& str) {

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This was unused.

@github-actionsgithub-actionsBot added awaiting committer review Awaiting committer review and removed awaiting review Awaiting review labels Dec 4, 2025

namespace {

Status FuzzReadData(std::unique_ptr<FileReader> reader) {

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This code is moved away to fuzz_internal.cc so that parquet/arrow/reader.cc does not depend on Parquet encryption.

@pitrou
pitrouforce-pushed the fuzz-pq-encryption branch 2 times, most recently from fe50a06 to eb4c4c8CompareDecember 4, 2025 16:14
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: eb4c4c8

Submitted crossbow builds: ursacomputing/crossbow @ actions-40f4ae6d06

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou
pitrou marked this pull request as ready for review December 4, 2025 16:20
@pitrou
pitrou requested a review from wgtmac as a code ownerDecember 4, 2025 16:20
Comment threadcpp/src/parquet/arrow/generate_fuzz_corpus.cc
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: 219985a

Submitted crossbow builds: ursacomputing/crossbow @ actions-cadb3008d8

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou

Copy link
Copy Markdown
MemberAuthor

@adamreeve@EnricoMi Do you want to take a look at this PR?

@adamreeveadamreeve left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 looks good to me

pitrou added a commit that referenced this pull request Dec 8, 2025
### Rationale for this change
While working on PR #48336 I quickly got irritated by the clumsiness of the Parquet encryption configuration API. This issue attempts to reduce the verbosity of `ColumnEncryptionProperties` construction.
### What changes are included in this PR?
1. Remove unused `column_path` member in `ColumnEncryptionProperties`
2. Add convenience `ColumnEncryptionProperties` factory functions to avoid going through the clumsy `Builder` API
### Are these changes tested?
Yes
### Are there any user-facing changes?
Two deprecated constructors and a removed accessor for an useless property.
**This PR includes breaking changes to public APIs.** (If there are any breaking changes to public APIs, please explain which changes are breaking. If not, you can remove this.)
* GitHub Issue: #48337
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: c72edef

Submitted crossbow builds: ursacomputing/crossbow @ actions-4952d9d2f1

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou
pitrou merged commit fa4e593 into apache:mainDec 8, 2025
46 of 48 checks passed
@pitroupitrou removed the awaiting committer review Awaiting committer review label Dec 8, 2025
@pitrou
pitrou deleted the fuzz-pq-encryption branch December 8, 2025 08:52
@pitrou

Copy link
Copy Markdown
MemberAuthor

Thanks for the review @adamreeve . I hope this will help uncover any latent issues in the decryption codepaths.

pitrou added a commit that referenced this pull request Dec 16, 2025
… corpus (#48558)
### Rationale for this change
In #48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that #45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: #48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@conbench-apache-arrow

Copy link
Copy Markdown

After merging your PR, Conbench analyzed the 3 benchmarking runs that have been run so far on merge-commit fa4e593.

There were no benchmark performance regressions. 🎉

The full Conbench report has more details. It also includes information about 13 possible false positives for unstable benchmarks that are known to sometimes produce them.

Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…48338)
### Rationale for this change
While working on PR apache#48336 I quickly got irritated by the clumsiness of the Parquet encryption configuration API. This issue attempts to reduce the verbosity of `ColumnEncryptionProperties` construction.
### What changes are included in this PR?
1. Remove unused `column_path` member in `ColumnEncryptionProperties`
2. Add convenience `ColumnEncryptionProperties` factory functions to avoid going through the clumsy `Builder` API
### Are these changes tested?
Yes
### Are there any user-facing changes?
Two deprecated constructors and a removed accessor for an useless property.
**This PR includes breaking changes to public APIs.** (If there are any breaking changes to public APIs, please explain which changes are breaking. If not, you can remove this.)
* GitHub Issue: apache#48337
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
### Rationale for this change
Currently, if given an encrypted file (whether valid or invalid), the Parquet fuzz target will bail out almost immediately since it does not have any decryption key configured. This prevents the fuzzer from covering any significant part of the Parquet encryption codebase.
### What changes are included in this PR?
1. Improve the fuzz target so as to be able to read encrypted files present in the seed corpus (except those that require a external AAD or external key material)
2. Generate encrypted files in the seed corpus that the fuzz target is able to successfully decrypt
### Are these changes tested?
In expanded unit test, and locally.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48335
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…z seed corpus (apache#48558)
### Rationale for this change
In apache#48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that apache#45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@pitrou@adamreeve
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

GH-48335: [C++][Parquet] Fuzz encrypted files - #48336

Merged
pitrou merged 2 commits into
apache:mainfrom
pitrou:fuzz-pq-encryption
Dec 8, 2025
Merged

GH-48335: [C++][Parquet] Fuzz encrypted files#48336
pitrou merged 2 commits into
apache:mainfrom
pitrou:fuzz-pq-encryption

Conversation

@pitrou

@pitroupitrou commented Dec 4, 2025

Copy link
Copy Markdown
Member

Rationale for this change

Currently, if given an encrypted file (whether valid or invalid), the Parquet fuzz target will bail out almost immediately since it does not have any decryption key configured. This prevents the fuzzer from covering any significant part of the Parquet encryption codebase.

What changes are included in this PR?

  1. Improve the fuzz target so as to be able to read encrypted files present in the seed corpus (except those that require a external AAD or external key material)
  2. Generate encrypted files in the seed corpus that the fuzz target is able to successfully decrypt

Are these changes tested?

In expanded unit test, and locally.

Are there any user-facing changes?

No.

std::unique_ptr<ColumnCryptoMetaData> crypto_metadata = col_chunk->crypto_metadata();
if (crypto_metadata != nullptr) {
ParquetException::NYI("Cannot read encrypted bloom filter yet");
ParquetException::NYI("BloomFilter decryption is not yet supported");

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This just ensures the same exception message in used in different places.

: ParquetException(columnPath.c_str()) {}
};

inline const uint8_t* str2bytes(const std::string& str) {

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This was unused.

@github-actionsgithub-actionsBot added awaiting committer review Awaiting committer review and removed awaiting review Awaiting review labels Dec 4, 2025

namespace {

Status FuzzReadData(std::unique_ptr<FileReader> reader) {

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This code is moved away to fuzz_internal.cc so that parquet/arrow/reader.cc does not depend on Parquet encryption.

@pitrou
pitrouforce-pushed the fuzz-pq-encryption branch 2 times, most recently from fe50a06 to eb4c4c8CompareDecember 4, 2025 16:14
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: eb4c4c8

Submitted crossbow builds: ursacomputing/crossbow @ actions-40f4ae6d06

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou
pitrou marked this pull request as ready for review December 4, 2025 16:20
@pitrou
pitrou requested a review from wgtmac as a code ownerDecember 4, 2025 16:20
Comment threadcpp/src/parquet/arrow/generate_fuzz_corpus.cc
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: 219985a

Submitted crossbow builds: ursacomputing/crossbow @ actions-cadb3008d8

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou

Copy link
Copy Markdown
MemberAuthor

@adamreeve@EnricoMi Do you want to take a look at this PR?

@adamreeveadamreeve left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 looks good to me

pitrou added a commit that referenced this pull request Dec 8, 2025
### Rationale for this change
While working on PR #48336 I quickly got irritated by the clumsiness of the Parquet encryption configuration API. This issue attempts to reduce the verbosity of `ColumnEncryptionProperties` construction.
### What changes are included in this PR?
1. Remove unused `column_path` member in `ColumnEncryptionProperties`
2. Add convenience `ColumnEncryptionProperties` factory functions to avoid going through the clumsy `Builder` API
### Are these changes tested?
Yes
### Are there any user-facing changes?
Two deprecated constructors and a removed accessor for an useless property.
**This PR includes breaking changes to public APIs.** (If there are any breaking changes to public APIs, please explain which changes are breaking. If not, you can remove this.)
* GitHub Issue: #48337
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: c72edef

Submitted crossbow builds: ursacomputing/crossbow @ actions-4952d9d2f1

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou
pitrou merged commit fa4e593 into apache:mainDec 8, 2025
46 of 48 checks passed
@pitroupitrou removed the awaiting committer review Awaiting committer review label Dec 8, 2025
@pitrou
pitrou deleted the fuzz-pq-encryption branch December 8, 2025 08:52
@pitrou

Copy link
Copy Markdown
MemberAuthor

Thanks for the review @adamreeve . I hope this will help uncover any latent issues in the decryption codepaths.

pitrou added a commit that referenced this pull request Dec 16, 2025
… corpus (#48558)
### Rationale for this change
In #48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that #45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: #48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@conbench-apache-arrow

Copy link
Copy Markdown

After merging your PR, Conbench analyzed the 3 benchmarking runs that have been run so far on merge-commit fa4e593.

There were no benchmark performance regressions. 🎉

The full Conbench report has more details. It also includes information about 13 possible false positives for unstable benchmarks that are known to sometimes produce them.

Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…48338)
### Rationale for this change
While working on PR apache#48336 I quickly got irritated by the clumsiness of the Parquet encryption configuration API. This issue attempts to reduce the verbosity of `ColumnEncryptionProperties` construction.
### What changes are included in this PR?
1. Remove unused `column_path` member in `ColumnEncryptionProperties`
2. Add convenience `ColumnEncryptionProperties` factory functions to avoid going through the clumsy `Builder` API
### Are these changes tested?
Yes
### Are there any user-facing changes?
Two deprecated constructors and a removed accessor for an useless property.
**This PR includes breaking changes to public APIs.** (If there are any breaking changes to public APIs, please explain which changes are breaking. If not, you can remove this.)
* GitHub Issue: apache#48337
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
### Rationale for this change
Currently, if given an encrypted file (whether valid or invalid), the Parquet fuzz target will bail out almost immediately since it does not have any decryption key configured. This prevents the fuzzer from covering any significant part of the Parquet encryption codebase.
### What changes are included in this PR?
1. Improve the fuzz target so as to be able to read encrypted files present in the seed corpus (except those that require a external AAD or external key material)
2. Generate encrypted files in the seed corpus that the fuzz target is able to successfully decrypt
### Are these changes tested?
In expanded unit test, and locally.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48335
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…z seed corpus (apache#48558)
### Rationale for this change
In apache#48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that apache#45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@pitrou@adamreeve
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

GH-48335: [C++][Parquet] Fuzz encrypted files - #48336

Merged
pitrou merged 2 commits into
apache:mainfrom
pitrou:fuzz-pq-encryption
Dec 8, 2025
Merged

GH-48335: [C++][Parquet] Fuzz encrypted files#48336
pitrou merged 2 commits into
apache:mainfrom
pitrou:fuzz-pq-encryption

Conversation

@pitrou

@pitroupitrou commented Dec 4, 2025

Copy link
Copy Markdown
Member

Rationale for this change

Currently, if given an encrypted file (whether valid or invalid), the Parquet fuzz target will bail out almost immediately since it does not have any decryption key configured. This prevents the fuzzer from covering any significant part of the Parquet encryption codebase.

What changes are included in this PR?

  1. Improve the fuzz target so as to be able to read encrypted files present in the seed corpus (except those that require a external AAD or external key material)
  2. Generate encrypted files in the seed corpus that the fuzz target is able to successfully decrypt

Are these changes tested?

In expanded unit test, and locally.

Are there any user-facing changes?

No.

std::unique_ptr<ColumnCryptoMetaData> crypto_metadata = col_chunk->crypto_metadata();
if (crypto_metadata != nullptr) {
ParquetException::NYI("Cannot read encrypted bloom filter yet");
ParquetException::NYI("BloomFilter decryption is not yet supported");

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This just ensures the same exception message in used in different places.

: ParquetException(columnPath.c_str()) {}
};

inline const uint8_t* str2bytes(const std::string& str) {

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This was unused.

@github-actionsgithub-actionsBot added awaiting committer review Awaiting committer review and removed awaiting review Awaiting review labels Dec 4, 2025

namespace {

Status FuzzReadData(std::unique_ptr<FileReader> reader) {

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This code is moved away to fuzz_internal.cc so that parquet/arrow/reader.cc does not depend on Parquet encryption.

@pitrou
pitrouforce-pushed the fuzz-pq-encryption branch 2 times, most recently from fe50a06 to eb4c4c8CompareDecember 4, 2025 16:14
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: eb4c4c8

Submitted crossbow builds: ursacomputing/crossbow @ actions-40f4ae6d06

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou
pitrou marked this pull request as ready for review December 4, 2025 16:20
@pitrou
pitrou requested a review from wgtmac as a code ownerDecember 4, 2025 16:20
Comment threadcpp/src/parquet/arrow/generate_fuzz_corpus.cc
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: 219985a

Submitted crossbow builds: ursacomputing/crossbow @ actions-cadb3008d8

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou

Copy link
Copy Markdown
MemberAuthor

@adamreeve@EnricoMi Do you want to take a look at this PR?

@adamreeveadamreeve left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 looks good to me

pitrou added a commit that referenced this pull request Dec 8, 2025
### Rationale for this change
While working on PR #48336 I quickly got irritated by the clumsiness of the Parquet encryption configuration API. This issue attempts to reduce the verbosity of `ColumnEncryptionProperties` construction.
### What changes are included in this PR?
1. Remove unused `column_path` member in `ColumnEncryptionProperties`
2. Add convenience `ColumnEncryptionProperties` factory functions to avoid going through the clumsy `Builder` API
### Are these changes tested?
Yes
### Are there any user-facing changes?
Two deprecated constructors and a removed accessor for an useless property.
**This PR includes breaking changes to public APIs.** (If there are any breaking changes to public APIs, please explain which changes are breaking. If not, you can remove this.)
* GitHub Issue: #48337
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: c72edef

Submitted crossbow builds: ursacomputing/crossbow @ actions-4952d9d2f1

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou
pitrou merged commit fa4e593 into apache:mainDec 8, 2025
46 of 48 checks passed
@pitroupitrou removed the awaiting committer review Awaiting committer review label Dec 8, 2025
@pitrou
pitrou deleted the fuzz-pq-encryption branch December 8, 2025 08:52
@pitrou

Copy link
Copy Markdown
MemberAuthor

Thanks for the review @adamreeve . I hope this will help uncover any latent issues in the decryption codepaths.

pitrou added a commit that referenced this pull request Dec 16, 2025
… corpus (#48558)
### Rationale for this change
In #48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that #45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: #48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@conbench-apache-arrow

Copy link
Copy Markdown

After merging your PR, Conbench analyzed the 3 benchmarking runs that have been run so far on merge-commit fa4e593.

There were no benchmark performance regressions. 🎉

The full Conbench report has more details. It also includes information about 13 possible false positives for unstable benchmarks that are known to sometimes produce them.

Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…48338)
### Rationale for this change
While working on PR apache#48336 I quickly got irritated by the clumsiness of the Parquet encryption configuration API. This issue attempts to reduce the verbosity of `ColumnEncryptionProperties` construction.
### What changes are included in this PR?
1. Remove unused `column_path` member in `ColumnEncryptionProperties`
2. Add convenience `ColumnEncryptionProperties` factory functions to avoid going through the clumsy `Builder` API
### Are these changes tested?
Yes
### Are there any user-facing changes?
Two deprecated constructors and a removed accessor for an useless property.
**This PR includes breaking changes to public APIs.** (If there are any breaking changes to public APIs, please explain which changes are breaking. If not, you can remove this.)
* GitHub Issue: apache#48337
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
### Rationale for this change
Currently, if given an encrypted file (whether valid or invalid), the Parquet fuzz target will bail out almost immediately since it does not have any decryption key configured. This prevents the fuzzer from covering any significant part of the Parquet encryption codebase.
### What changes are included in this PR?
1. Improve the fuzz target so as to be able to read encrypted files present in the seed corpus (except those that require a external AAD or external key material)
2. Generate encrypted files in the seed corpus that the fuzz target is able to successfully decrypt
### Are these changes tested?
In expanded unit test, and locally.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48335
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…z seed corpus (apache#48558)
### Rationale for this change
In apache#48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that apache#45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@pitrou@adamreeve
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

GH-48335: [C++][Parquet] Fuzz encrypted files - #48336

Merged
pitrou merged 2 commits into
apache:mainfrom
pitrou:fuzz-pq-encryption
Dec 8, 2025
Merged

GH-48335: [C++][Parquet] Fuzz encrypted files#48336
pitrou merged 2 commits into
apache:mainfrom
pitrou:fuzz-pq-encryption

Conversation

@pitrou

@pitroupitrou commented Dec 4, 2025

Copy link
Copy Markdown
Member

Rationale for this change

Currently, if given an encrypted file (whether valid or invalid), the Parquet fuzz target will bail out almost immediately since it does not have any decryption key configured. This prevents the fuzzer from covering any significant part of the Parquet encryption codebase.

What changes are included in this PR?

  1. Improve the fuzz target so as to be able to read encrypted files present in the seed corpus (except those that require a external AAD or external key material)
  2. Generate encrypted files in the seed corpus that the fuzz target is able to successfully decrypt

Are these changes tested?

In expanded unit test, and locally.

Are there any user-facing changes?

No.

std::unique_ptr<ColumnCryptoMetaData> crypto_metadata = col_chunk->crypto_metadata();
if (crypto_metadata != nullptr) {
ParquetException::NYI("Cannot read encrypted bloom filter yet");
ParquetException::NYI("BloomFilter decryption is not yet supported");

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This just ensures the same exception message in used in different places.

: ParquetException(columnPath.c_str()) {}
};

inline const uint8_t* str2bytes(const std::string& str) {

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This was unused.

@github-actionsgithub-actionsBot added awaiting committer review Awaiting committer review and removed awaiting review Awaiting review labels Dec 4, 2025

namespace {

Status FuzzReadData(std::unique_ptr<FileReader> reader) {

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This code is moved away to fuzz_internal.cc so that parquet/arrow/reader.cc does not depend on Parquet encryption.

@pitrou
pitrouforce-pushed the fuzz-pq-encryption branch 2 times, most recently from fe50a06 to eb4c4c8CompareDecember 4, 2025 16:14
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: eb4c4c8

Submitted crossbow builds: ursacomputing/crossbow @ actions-40f4ae6d06

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou
pitrou marked this pull request as ready for review December 4, 2025 16:20
@pitrou
pitrou requested a review from wgtmac as a code ownerDecember 4, 2025 16:20
Comment threadcpp/src/parquet/arrow/generate_fuzz_corpus.cc
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: 219985a

Submitted crossbow builds: ursacomputing/crossbow @ actions-cadb3008d8

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou

Copy link
Copy Markdown
MemberAuthor

@adamreeve@EnricoMi Do you want to take a look at this PR?

@adamreeveadamreeve left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 looks good to me

pitrou added a commit that referenced this pull request Dec 8, 2025
### Rationale for this change
While working on PR #48336 I quickly got irritated by the clumsiness of the Parquet encryption configuration API. This issue attempts to reduce the verbosity of `ColumnEncryptionProperties` construction.
### What changes are included in this PR?
1. Remove unused `column_path` member in `ColumnEncryptionProperties`
2. Add convenience `ColumnEncryptionProperties` factory functions to avoid going through the clumsy `Builder` API
### Are these changes tested?
Yes
### Are there any user-facing changes?
Two deprecated constructors and a removed accessor for an useless property.
**This PR includes breaking changes to public APIs.** (If there are any breaking changes to public APIs, please explain which changes are breaking. If not, you can remove this.)
* GitHub Issue: #48337
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: c72edef

Submitted crossbow builds: ursacomputing/crossbow @ actions-4952d9d2f1

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou
pitrou merged commit fa4e593 into apache:mainDec 8, 2025
46 of 48 checks passed
@pitroupitrou removed the awaiting committer review Awaiting committer review label Dec 8, 2025
@pitrou
pitrou deleted the fuzz-pq-encryption branch December 8, 2025 08:52
@pitrou

Copy link
Copy Markdown
MemberAuthor

Thanks for the review @adamreeve . I hope this will help uncover any latent issues in the decryption codepaths.

pitrou added a commit that referenced this pull request Dec 16, 2025
… corpus (#48558)
### Rationale for this change
In #48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that #45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: #48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@conbench-apache-arrow

Copy link
Copy Markdown

After merging your PR, Conbench analyzed the 3 benchmarking runs that have been run so far on merge-commit fa4e593.

There were no benchmark performance regressions. 🎉

The full Conbench report has more details. It also includes information about 13 possible false positives for unstable benchmarks that are known to sometimes produce them.

Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…48338)
### Rationale for this change
While working on PR apache#48336 I quickly got irritated by the clumsiness of the Parquet encryption configuration API. This issue attempts to reduce the verbosity of `ColumnEncryptionProperties` construction.
### What changes are included in this PR?
1. Remove unused `column_path` member in `ColumnEncryptionProperties`
2. Add convenience `ColumnEncryptionProperties` factory functions to avoid going through the clumsy `Builder` API
### Are these changes tested?
Yes
### Are there any user-facing changes?
Two deprecated constructors and a removed accessor for an useless property.
**This PR includes breaking changes to public APIs.** (If there are any breaking changes to public APIs, please explain which changes are breaking. If not, you can remove this.)
* GitHub Issue: apache#48337
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
### Rationale for this change
Currently, if given an encrypted file (whether valid or invalid), the Parquet fuzz target will bail out almost immediately since it does not have any decryption key configured. This prevents the fuzzer from covering any significant part of the Parquet encryption codebase.
### What changes are included in this PR?
1. Improve the fuzz target so as to be able to read encrypted files present in the seed corpus (except those that require a external AAD or external key material)
2. Generate encrypted files in the seed corpus that the fuzz target is able to successfully decrypt
### Are these changes tested?
In expanded unit test, and locally.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48335
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…z seed corpus (apache#48558)
### Rationale for this change
In apache#48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that apache#45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@pitrou@adamreeve
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

GH-48335: [C++][Parquet] Fuzz encrypted files - #48336

Merged
pitrou merged 2 commits into
apache:mainfrom
pitrou:fuzz-pq-encryption
Dec 8, 2025
Merged

GH-48335: [C++][Parquet] Fuzz encrypted files#48336
pitrou merged 2 commits into
apache:mainfrom
pitrou:fuzz-pq-encryption

Conversation

@pitrou

@pitroupitrou commented Dec 4, 2025

Copy link
Copy Markdown
Member

Rationale for this change

Currently, if given an encrypted file (whether valid or invalid), the Parquet fuzz target will bail out almost immediately since it does not have any decryption key configured. This prevents the fuzzer from covering any significant part of the Parquet encryption codebase.

What changes are included in this PR?

  1. Improve the fuzz target so as to be able to read encrypted files present in the seed corpus (except those that require a external AAD or external key material)
  2. Generate encrypted files in the seed corpus that the fuzz target is able to successfully decrypt

Are these changes tested?

In expanded unit test, and locally.

Are there any user-facing changes?

No.

std::unique_ptr<ColumnCryptoMetaData> crypto_metadata = col_chunk->crypto_metadata();
if (crypto_metadata != nullptr) {
ParquetException::NYI("Cannot read encrypted bloom filter yet");
ParquetException::NYI("BloomFilter decryption is not yet supported");

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This just ensures the same exception message in used in different places.

: ParquetException(columnPath.c_str()) {}
};

inline const uint8_t* str2bytes(const std::string& str) {

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This was unused.

@github-actionsgithub-actionsBot added awaiting committer review Awaiting committer review and removed awaiting review Awaiting review labels Dec 4, 2025

namespace {

Status FuzzReadData(std::unique_ptr<FileReader> reader) {

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This code is moved away to fuzz_internal.cc so that parquet/arrow/reader.cc does not depend on Parquet encryption.

@pitrou
pitrouforce-pushed the fuzz-pq-encryption branch 2 times, most recently from fe50a06 to eb4c4c8CompareDecember 4, 2025 16:14
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: eb4c4c8

Submitted crossbow builds: ursacomputing/crossbow @ actions-40f4ae6d06

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou
pitrou marked this pull request as ready for review December 4, 2025 16:20
@pitrou
pitrou requested a review from wgtmac as a code ownerDecember 4, 2025 16:20
Comment threadcpp/src/parquet/arrow/generate_fuzz_corpus.cc
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: 219985a

Submitted crossbow builds: ursacomputing/crossbow @ actions-cadb3008d8

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou

Copy link
Copy Markdown
MemberAuthor

@adamreeve@EnricoMi Do you want to take a look at this PR?

@adamreeveadamreeve left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 looks good to me

pitrou added a commit that referenced this pull request Dec 8, 2025
### Rationale for this change
While working on PR #48336 I quickly got irritated by the clumsiness of the Parquet encryption configuration API. This issue attempts to reduce the verbosity of `ColumnEncryptionProperties` construction.
### What changes are included in this PR?
1. Remove unused `column_path` member in `ColumnEncryptionProperties`
2. Add convenience `ColumnEncryptionProperties` factory functions to avoid going through the clumsy `Builder` API
### Are these changes tested?
Yes
### Are there any user-facing changes?
Two deprecated constructors and a removed accessor for an useless property.
**This PR includes breaking changes to public APIs.** (If there are any breaking changes to public APIs, please explain which changes are breaking. If not, you can remove this.)
* GitHub Issue: #48337
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: c72edef

Submitted crossbow builds: ursacomputing/crossbow @ actions-4952d9d2f1

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou
pitrou merged commit fa4e593 into apache:mainDec 8, 2025
46 of 48 checks passed
@pitroupitrou removed the awaiting committer review Awaiting committer review label Dec 8, 2025
@pitrou
pitrou deleted the fuzz-pq-encryption branch December 8, 2025 08:52
@pitrou

Copy link
Copy Markdown
MemberAuthor

Thanks for the review @adamreeve . I hope this will help uncover any latent issues in the decryption codepaths.

pitrou added a commit that referenced this pull request Dec 16, 2025
… corpus (#48558)
### Rationale for this change
In #48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that #45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: #48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@conbench-apache-arrow

Copy link
Copy Markdown

After merging your PR, Conbench analyzed the 3 benchmarking runs that have been run so far on merge-commit fa4e593.

There were no benchmark performance regressions. 🎉

The full Conbench report has more details. It also includes information about 13 possible false positives for unstable benchmarks that are known to sometimes produce them.

Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…48338)
### Rationale for this change
While working on PR apache#48336 I quickly got irritated by the clumsiness of the Parquet encryption configuration API. This issue attempts to reduce the verbosity of `ColumnEncryptionProperties` construction.
### What changes are included in this PR?
1. Remove unused `column_path` member in `ColumnEncryptionProperties`
2. Add convenience `ColumnEncryptionProperties` factory functions to avoid going through the clumsy `Builder` API
### Are these changes tested?
Yes
### Are there any user-facing changes?
Two deprecated constructors and a removed accessor for an useless property.
**This PR includes breaking changes to public APIs.** (If there are any breaking changes to public APIs, please explain which changes are breaking. If not, you can remove this.)
* GitHub Issue: apache#48337
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
### Rationale for this change
Currently, if given an encrypted file (whether valid or invalid), the Parquet fuzz target will bail out almost immediately since it does not have any decryption key configured. This prevents the fuzzer from covering any significant part of the Parquet encryption codebase.
### What changes are included in this PR?
1. Improve the fuzz target so as to be able to read encrypted files present in the seed corpus (except those that require a external AAD or external key material)
2. Generate encrypted files in the seed corpus that the fuzz target is able to successfully decrypt
### Are these changes tested?
In expanded unit test, and locally.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48335
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…z seed corpus (apache#48558)
### Rationale for this change
In apache#48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that apache#45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@pitrou@adamreeve
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

GH-48335: [C++][Parquet] Fuzz encrypted files - #48336

Merged
pitrou merged 2 commits into
apache:mainfrom
pitrou:fuzz-pq-encryption
Dec 8, 2025
Merged

GH-48335: [C++][Parquet] Fuzz encrypted files#48336
pitrou merged 2 commits into
apache:mainfrom
pitrou:fuzz-pq-encryption

Conversation

@pitrou

@pitroupitrou commented Dec 4, 2025

Copy link
Copy Markdown
Member

Rationale for this change

Currently, if given an encrypted file (whether valid or invalid), the Parquet fuzz target will bail out almost immediately since it does not have any decryption key configured. This prevents the fuzzer from covering any significant part of the Parquet encryption codebase.

What changes are included in this PR?

  1. Improve the fuzz target so as to be able to read encrypted files present in the seed corpus (except those that require a external AAD or external key material)
  2. Generate encrypted files in the seed corpus that the fuzz target is able to successfully decrypt

Are these changes tested?

In expanded unit test, and locally.

Are there any user-facing changes?

No.

std::unique_ptr<ColumnCryptoMetaData> crypto_metadata = col_chunk->crypto_metadata();
if (crypto_metadata != nullptr) {
ParquetException::NYI("Cannot read encrypted bloom filter yet");
ParquetException::NYI("BloomFilter decryption is not yet supported");

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This just ensures the same exception message in used in different places.

: ParquetException(columnPath.c_str()) {}
};

inline const uint8_t* str2bytes(const std::string& str) {

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This was unused.

@github-actionsgithub-actionsBot added awaiting committer review Awaiting committer review and removed awaiting review Awaiting review labels Dec 4, 2025

namespace {

Status FuzzReadData(std::unique_ptr<FileReader> reader) {

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This code is moved away to fuzz_internal.cc so that parquet/arrow/reader.cc does not depend on Parquet encryption.

@pitrou
pitrouforce-pushed the fuzz-pq-encryption branch 2 times, most recently from fe50a06 to eb4c4c8CompareDecember 4, 2025 16:14
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: eb4c4c8

Submitted crossbow builds: ursacomputing/crossbow @ actions-40f4ae6d06

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou
pitrou marked this pull request as ready for review December 4, 2025 16:20
@pitrou
pitrou requested a review from wgtmac as a code ownerDecember 4, 2025 16:20
Comment threadcpp/src/parquet/arrow/generate_fuzz_corpus.cc
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: 219985a

Submitted crossbow builds: ursacomputing/crossbow @ actions-cadb3008d8

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou

Copy link
Copy Markdown
MemberAuthor

@adamreeve@EnricoMi Do you want to take a look at this PR?

@adamreeveadamreeve left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍 looks good to me

pitrou added a commit that referenced this pull request Dec 8, 2025
### Rationale for this change
While working on PR #48336 I quickly got irritated by the clumsiness of the Parquet encryption configuration API. This issue attempts to reduce the verbosity of `ColumnEncryptionProperties` construction.
### What changes are included in this PR?
1. Remove unused `column_path` member in `ColumnEncryptionProperties`
2. Add convenience `ColumnEncryptionProperties` factory functions to avoid going through the clumsy `Builder` API
### Are these changes tested?
Yes
### Are there any user-facing changes?
Two deprecated constructors and a removed accessor for an useless property.
**This PR includes breaking changes to public APIs.** (If there are any breaking changes to public APIs, please explain which changes are breaking. If not, you can remove this.)
* GitHub Issue: #48337
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@pitrou

Copy link
Copy Markdown
MemberAuthor

@github-actions crossbow submit -g cpp

@github-actions

Copy link
Copy Markdown

Revision: c72edef

Submitted crossbow builds: ursacomputing/crossbow @ actions-4952d9d2f1

TaskStatus
example-cpp-minimal-build-staticGitHub Actions
example-cpp-minimal-build-static-system-dependencyGitHub Actions
example-cpp-tutorialGitHub Actions
test-build-cpp-fuzzGitHub Actions
test-conda-cppGitHub Actions
test-conda-cpp-valgrindGitHub Actions
test-cuda-cpp-ubuntu-22.04-cuda-11.7.1GitHub Actions
test-cuda-cpp-ubuntu-24.04-cuda-13.0.2GitHub Actions
test-debian-12-cpp-amd64GitHub Actions
test-debian-12-cpp-i386GitHub Actions
test-fedora-42-cppGitHub Actions
test-ubuntu-22.04-cppGitHub Actions
test-ubuntu-22.04-cpp-20GitHub Actions
test-ubuntu-22.04-cpp-bundledGitHub Actions
test-ubuntu-22.04-cpp-emscriptenGitHub Actions
test-ubuntu-22.04-cpp-no-threadingGitHub Actions
test-ubuntu-24.04-cppGitHub Actions
test-ubuntu-24.04-cpp-bundled-offlineGitHub Actions
test-ubuntu-24.04-cpp-gcc-13-bundledGitHub Actions
test-ubuntu-24.04-cpp-gcc-14GitHub Actions
test-ubuntu-24.04-cpp-minimal-with-formatsGitHub Actions
test-ubuntu-24.04-cpp-thread-sanitizerGitHub Actions

@pitrou
pitrou merged commit fa4e593 into apache:mainDec 8, 2025
46 of 48 checks passed
@pitroupitrou removed the awaiting committer review Awaiting committer review label Dec 8, 2025
@pitrou
pitrou deleted the fuzz-pq-encryption branch December 8, 2025 08:52
@pitrou

Copy link
Copy Markdown
MemberAuthor

Thanks for the review @adamreeve . I hope this will help uncover any latent issues in the decryption codepaths.

pitrou added a commit that referenced this pull request Dec 16, 2025
… corpus (#48558)
### Rationale for this change
In #48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that #45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: #48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
@conbench-apache-arrow

Copy link
Copy Markdown

After merging your PR, Conbench analyzed the 3 benchmarking runs that have been run so far on merge-commit fa4e593.

There were no benchmark performance regressions. 🎉

The full Conbench report has more details. It also includes information about 13 possible false positives for unstable benchmarks that are known to sometimes produce them.

Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…48338)
### Rationale for this change
While working on PR apache#48336 I quickly got irritated by the clumsiness of the Parquet encryption configuration API. This issue attempts to reduce the verbosity of `ColumnEncryptionProperties` construction.
### What changes are included in this PR?
1. Remove unused `column_path` member in `ColumnEncryptionProperties`
2. Add convenience `ColumnEncryptionProperties` factory functions to avoid going through the clumsy `Builder` API
### Are these changes tested?
Yes
### Are there any user-facing changes?
Two deprecated constructors and a removed accessor for an useless property.
**This PR includes breaking changes to public APIs.** (If there are any breaking changes to public APIs, please explain which changes are breaking. If not, you can remove this.)
* GitHub Issue: apache#48337
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
### Rationale for this change
Currently, if given an encrypted file (whether valid or invalid), the Parquet fuzz target will bail out almost immediately since it does not have any decryption key configured. This prevents the fuzzer from covering any significant part of the Parquet encryption codebase.
### What changes are included in this PR?
1. Improve the fuzz target so as to be able to read encrypted files present in the seed corpus (except those that require a external AAD or external key material)
2. Generate encrypted files in the seed corpus that the fuzz target is able to successfully decrypt
### Are these changes tested?
In expanded unit test, and locally.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48335
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Mottl pushed a commit to Mottl/arrow that referenced this pull request May 26, 2026
…z seed corpus (apache#48558)
### Rationale for this change
In apache#48336 we skipped encrypted nested columns because it was too cumbersome to configure (each leaf column had to be configured independently).
Now that apache#45462 has been merged we can configure nested columns the same way as non-nested ones.
### Are these changes tested?
Manually and later by OSS-Fuzz.
### Are there any user-facing changes?
No.
* GitHub Issue: apache#48557
Authored-by: Antoine Pitrou <antoine@python.org>
Signed-off-by: Antoine Pitrou <antoine@python.org>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@pitrou@adamreeve