Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
102 changes: 102 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,102 @@
<!---
Licensed to the Apache Software Foundation (ASF) under one
or more contributor license agreements. See the NOTICE file
distributed with this work for additional information
regarding copyright ownership. The ASF licenses this file
to you under the Apache License, Version 2.0 (the
"License"); you may not use this file except in compliance
with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing,
software distributed under the License is distributed on an
"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
KIND, either express or implied. See the License for the
specific language governing permissions and limitations
under the License.
-->

# Security Policy

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The goal of this file is to write down what I think have been implicit assumptions. But since they haven't been written down, I am not sure if everyone has the same assumptions


This document outlines the security model for Apache DataFusion and how to
report vulnerabilities.

This model also applies to the [datafusion-cli] command line tool, which is
a thin wrapper around the DataFusion library.

## Security Model

DataFusion is a low level library, designed to be embedded in applications
that have their own security model. This section describes DataFusion's own
model: what counts as a bug versus a vulnerability.

In general, crashes, panics, hangs, and excessive resource consumption
(memory, CPU, or disk) are treated as **bugs**, not vulnerabilities, unless
they are **exploitable** and could let an attacker:

* Execute arbitrary code (Remote Code Execution), or
* Exfiltrate sensitive information from process memory (Information Disclosure).

If the exploitation path is unclear, please report the issue as a bug rather
than a vulnerability. The sections below describe what DataFusion treats as
trusted input in a few specific areas.

### SQL and DataFrame Queries

SQL and DataFrame queries are executable code, comparable to a scripting
language: a query can legitimately read files, open network connections
(e.g. via `CREATE EXTERNAL TABLE`), and consume significant CPU, memory, or
disk. Running such a query is not, on its own, a vulnerability.

It is the embedding application's responsibility to decide whether a query is
safe to run (e.g. validating externally supplied SQL text or URLs) and to
sandbox untrusted queries at the OS/container level if needed. APIs such as
[`SQLOptions::with_allow_dml`] can help restrict what a query is allowed to
do, but do not guarantee that all input is safe to execute.

### Data Files

Format readers (e.g. Parquet, CSV, JSON, Avro, and Arrow IPC) assume a
well-formed file from a trusted writer; use the [arrow validation APIs] to
validate an untrusted file's structure. Issues due to malformed files, and
well-formed files that contain unexpected or adversarial *data*, are bugs rather
than vulnerabilities, as explained above.

### Serialized Plans

Serialized plans, such as [Substrait] and [`datafusion-proto`], are treated
as trusted input. If received from an untrusted source, they should be
validated before being passed to DataFusion for execution.

### Extensions and Other Uses of Public APIs

Code that uses DataFusion's public extension APIs (e.g. user defined functions,
`TableProvider`, `ExecutionPlan`) is trusted to uphold their contracts (for
example, that any `ArrayRef` is a valid Arrow array). Issues arising from
violating the API contracts are not considered a DataFusion vulnerability.

## Reporting a Bug

We treat all bugs seriously and welcome help fixing them. If you find a bug
that does not meet the criteria for a security vulnerability, please report it
in the [public issue tracker](https://github.com/apache/datafusion/issues/).

## Reporting a Vulnerability

For security vulnerabilities **do not file a public issue.** Follow the [ASF
security reporting process] by emailing
[security@apache.org](mailto:security@apache.org).

Include in your report:

- A clear description and minimal reproducer.
- Affected crates and versions.
- Potential impact.

[datafusion-cli]: https://datafusion.apache.org/user-guide/cli/index.html
[`sqloptions::with_allow_dml`]: https://docs.rs/datafusion/latest/datafusion/execution/context/struct.SQLOptions.html#method.with_allow_dml
[arrow validation apis]: https://docs.rs/arrow/latest/arrow/array/struct.ArrayData.html#method.validate_full
[substrait]: https://docs.rs/datafusion-substrait/latest/datafusion_substrait/
[`datafusion-proto`]: https://docs.rs/datafusion-proto/latest/datafusion_proto/
[asf security reporting process]: https://www.apache.org/security/#reporting-a-vulnerability
8 changes: 8 additions & 0 deletions datafusion/proto/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -59,6 +59,14 @@
//! [datafusion-substrait]: https://docs.rs/datafusion-substrait/latest/datafusion_substrait
//! [substrait.io]: https://substrait.io
//!
//! # Security
//!
//! Serialized plans are treated as trusted input. The application must validate
//! untrusted inputs as this crate does not validate that a plan is safe to
//! execute. See the [DataFusion Security Model] for more details.
//!
//! [DataFusion Security Model]: https://github.com/apache/datafusion/blob/main/SECURITY.md#serialized-plans
//!
//! # Example: Serializing [`Expr`]s
//! ```
//! # use datafusion_common::Result;
Expand Down
14 changes: 11 additions & 3 deletions datafusion/substrait/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -48,15 +48,23 @@
//! # See Also
//!
//! Substrait does not (yet) support the full range of plans and expressions
//! that DataFusion offers. See the [datafusion-proto] crate for a DataFusion
//! specific format that does support of the full range.
//! that DataFusion offers. See the [datafusion-proto] crate for a DataFusion

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

drive by cleanup

//! specific format that does support the full range.
//!
//! [datafusion-proto]: https://docs.rs/datafusion-proto/latest/datafusion_proto
//!
//! Note that generated types such as [`substrait::proto::Plan`] and
//! Note that generated types such as [`substrait::proto::Plan`] and
//! [`substrait::proto::Rel`] can be serialized / deserialized to bytes, JSON and
//! other formats using [prost] and the rest of the Rust protobuf ecosystem.
//!
//! # Security
//!
//! Substrait plans are treated as trusted input. The application must validate
//! untrusted inputs as this crate does not validate that a plan is safe to
//! execute. See the [DataFusion Security Model] for more details.
//!
//! [DataFusion Security Model]: https://github.com/apache/datafusion/blob/main/SECURITY.md#serialized-plans
//!
//! # Example: Serializing [`LogicalPlan`]s
//! ```
//! # use datafusion::prelude::*;
Expand Down
Loading