Skip to content

Commit c7944b3

Browse files
GH-51354: [C++][Parquet] Update bundled Apache Thrift to 0.24.0 (#51559)
### Rationale for this change The bundled Apache Thrift dependency (0.22.0) is affected by CVE-2026-55969, an integer overflow vulnerability in `TTransport::checkReadBytesAvailable()` that could bypass message size checks when reading maliciously crafted Thrift-encoded data. Arrow's Parquet module relies on Thrift's compact protocol to deserialize Parquet file metadata, so this is relevant to Arrow. ### What changes are included in this PR? - Bump the bundled Apache Thrift version from 0.22.0 to 0.24.0 in `cpp/thirdparty/versions.txt` (including the SHA256 checksum). - Remove the Clang-only `thrift-3187.patch` and its application logic in `ThirdpartyToolchain.cmake`. This patch pre-applied Thrift's upstream fix for THRIFT-3268 (a compiler warning), which has since been merged into Thrift itself and is already included in 0.24.0. Keeping the patch would make `git apply`/`patch` fail during the bundled build with Clang. ### Are these changes tested? - Verified that `thrift-0.24.0.tar.gz` downloads correctly and its SHA256 checksum matches the value published at downloads.apache.org. - Confirmed the CVE fix is present in Thrift 0.24.0 by diffing `TProtocol.h`, `TCompactProtocol.h`, `TBinaryProtocol.h`, and `TTransport.h` against 0.22.0. - Confirmed `thrift-3187.patch` no longer applies cleanly against 0.24.0 sources (already fixed upstream), which is why it was removed rather than kept as a no-op. - Built Arrow C++ locally on macOS (arm64, AppleClang) with `-DARROW_PARQUET=ON -DARROW_BUILD_TESTS=ON -DThrift_SOURCE=BUNDLED`, on top of the latest `main` (after rebasing), and ran the following Parquet tests. All of them passed with no failures (some tests were skipped, e.g. those requiring Snappy, which was not enabled in my build): `parquet-internals-test`, `parquet-file-deserialize-test`, `parquet-schema-test`, `parquet-reader-test`, `parquet-writer-test`, `parquet-arrow-reader-writer-test`, `parquet-arrow-metadata-test`, `parquet-arrow-index-test`, and `parquet-arrow-internals-test`. - Not tested locally: the removed patch was only applied for `CMAKE_CXX_COMPILER_ID STREQUAL "Clang"`, which my AppleClang build does not hit, so building the bundled Thrift with Clang on Linux relies on CI. I also did not test encryption, Windows/MSVC, or the Python/R packaging builds locally. ### Are there any user-facing changes? No. * GitHub Issue: #51354 --- Disclosure: this change was prepared with the assistance of an AI coding tool (Claude Code). I reviewed the diff, verified the CVE fix and checksum myself, and ran the test suite locally before opening this PR. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Authored-by: Hanayoshi-8744 <201203709+Hanayoshi-8744@users.noreply.github.com> Signed-off-by: Sutou Kouhei <kou@clear-code.com>
1 parent 6c82e24 commit c7944b3

3 files changed

Lines changed: 2 additions & 185 deletions

File tree

‎cpp/cmake_modules/ThirdpartyToolchain.cmake‎

Lines changed: 0 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -1816,29 +1816,8 @@ function(build_thrift)
18161816
if(CMAKE_VERSION VERSION_LESS 3.26)
18171817
message(FATAL_ERROR "Require CMake 3.26 or later for building bundled Apache Thrift")
18181818
endif()
1819-
set(THRIFT_PATCH_COMMAND)
1820-
if(CMAKE_CXX_COMPILER_ID STREQUAL "Clang")
1821-
find_program(PATCH patch)
1822-
if(PATCH)
1823-
list(APPEND
1824-
THRIFT_PATCH_COMMAND
1825-
${PATCH}
1826-
-p1
1827-
-i)
1828-
else()
1829-
find_program(GIT git)
1830-
if(GIT)
1831-
list(APPEND THRIFT_PATCH_COMMAND ${GIT} apply)
1832-
endif()
1833-
endif()
1834-
if(THRIFT_PATCH_COMMAND)
1835-
# https://github.com/apache/thrift/pull/3187
1836-
list(APPEND THRIFT_PATCH_COMMAND ${CMAKE_CURRENT_LIST_DIR}/thrift-3187.patch)
1837-
endif()
1838-
endif()
18391819
fetchcontent_declare(thrift
18401820
${FC_DECLARE_COMMON_OPTIONS}
1841-
PATCH_COMMAND ${THRIFT_PATCH_COMMAND}
18421821
URL ${THRIFT_SOURCE_URL}
18431822
URL_HASH "SHA256=${ARROW_THRIFT_BUILD_SHA256_CHECKSUM}")
18441823

‎cpp/cmake_modules/thrift-3187.patch‎

Lines changed: 0 additions & 162 deletions
This file was deleted.

‎cpp/thirdparty/versions.txt‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -110,8 +110,8 @@ ARROW_SUBSTRAIT_BUILD_VERSION=v0.44.0
110110
ARROW_SUBSTRAIT_BUILD_SHA256_CHECKSUM=f989a862f694e7dbb695925ddb7c4ce06aa6c51aca945105c075139aed7e55a2
111111
ARROW_S2N_TLS_BUILD_VERSION=v1.7.0
112112
ARROW_S2N_TLS_BUILD_SHA256_CHECKSUM=a6e8228e238239bb3c17b1eda3ed702bcbb2eaebc792eac4d754cc5619b0ea06
113-
ARROW_THRIFT_BUILD_VERSION=0.22.0
114-
ARROW_THRIFT_BUILD_SHA256_CHECKSUM=794a0e455787960d9f27ab92c38e34da27e8deeda7a5db0e59dc64a00df8a1e5
113+
ARROW_THRIFT_BUILD_VERSION=0.24.0
114+
ARROW_THRIFT_BUILD_SHA256_CHECKSUM=e0fa5839a4c5c1d631b0931cf2c554ebbfa4e2fee3a9fb3ffd4f82ce4396c6e4
115115
ARROW_URIPARSER_BUILD_VERSION=1.0.2
116116
ARROW_URIPARSER_BUILD_SHA256_CHECKSUM=dd2e4843f43de6f5aedf430e530f1e2d159eba8ca4d64c2787af1c20f707a9e4
117117
ARROW_UTF8PROC_BUILD_VERSION=v2.10.0

0 commit comments

Comments
 (0)