Skip to content

[Python] Directly constructed FunctionOptions segfaults in serialize() #51628

Description

@marinelay

Describe the bug, including details regarding any error messages, version, and platform.

Summary

pyarrow.compute.FunctionOptions can be constructed without arguments, and calling serialize() on that object terminates the interpreter.
I found this while fuzzing Python C extension modules.
I realize the base class is probably not meant to be used directly, but I would expect a Python exception rather than a process crash.

Versions

PyArrow 25.0.1, CPython 3.12.3, Debian 12 x86_64, glibc 2.36
PyArrow 25.0.1, CPython 3.13.5, macOS x86_64

Reproducer

import pyarrow.compute as pc

pc.FunctionOptions().serialize()
Segmentation fault (core dumped)

This is a different entry point from #51041, which covers FunctionOptions.deserialize() on non-Buffer arguments.

ASan/UBSan result

I built PyArrow 25.0.0 from source with Clang 18 using ASan and UBSan instrumentation.
ASan reports a read from address 0x28 while the generated FunctionOptions.serialize() wrapper is adding its traceback:

AddressSanitizer:DEADLYSIGNAL
ERROR: AddressSanitizer: SEGV on unknown address 0x000000000028
The signal is caused by a READ memory access.
Hint: address points to the zero page.

    #0 PyException_GetTraceback
    #1 PyTraceBack_Here
    #2 __Pyx_AddTraceback(...)
       build/_compute.cpp:102581:5
    #3 pyarrow.compute.FunctionOptions.serialize(...)
       build/_compute.cpp:23014:3

SUMMARY: AddressSanitizer: SEGV in PyException_GetTraceback

The sanitizer process exits with code 1 after ASan aborts.
UBSan does not emit a separate diagnostic before the ASan failure.

Component(s)

Python

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions