fix(mapper): unmap fused-away scans; tolerate unmapped SEMI_MASKER targets - #1079
Merged
Merged
Conversation
…rgets The ice-disk fused rel scan in mapExtend absorbs the child SCAN_NODE_TABLE and discards its physical operator, leaving a dangling entry in logicalOpToPhysicalOpMap. A later SEMI_MASKER targeting that scan then dereferenced freed memory, surfacing as 'unordered_map::at: key not found' when the reused object held masks for a different table (#1068). Erase the stale child-scan mapping in fused branches that drop prevOperator, look up SEMI targets with find() instead of at(), skip table masks a target does not hold, and drop maskers that attach nothing (result-preserving pass-through). Adds an ice-disk regression case (SEMI_MASKER over a fused bound scan) that crashes pre-fix and returns correct rows post-fix.
adsharma
force-pushed
the
fix-1068-fused-scan-semi-masker
branch
from
September 29, 2026 19:51
935b69d to
e8bdd00
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #1068.
Root cause
unordered_map::at: key not foundwas a use-after-free in physical plan mapping:SEMI_MASKER(keyed e.g. oni._ID) targeting the bound-nodeSCAN_NODE_TABLEon the other side of the join.mapExtend's fused ice-disk path absorbs the child scan into theScanRelTableand discards its separately mapped physical operator, leaving a dangling entry inlogicalOpToPhysicalOpMap.mapSemiMaskerthen dereferenced the freed pointer (observed reallocated as a different scan at the same address), soinitMask's mask-table lookup threw.Reproduced on a v0.21.0 build (fails on both
EXPLAINand execution); current HEAD only hid it via a later join-order change.Changes
src/processor/map/map_extend.cpp: erase the stale child-scan mapping in fused branches that dropprevOperator.src/processor/map/map_semi_masker.cpp: look up SEMI targets withfind()instead ofat(), skip per-table masks a target doesn't hold, and drop maskers that attach nothing (result-preserving pass-through).test/test_files/ice_disk/ice_disk_complex_queries.test: newSemiMaskerOnFusedBoundScanregression case producing the exact crashing shape.Verification
ice_diske2e suite passes (except pre-existingice_disk_large_node_scanfailure from the missingice-disk-large-testdataset in this checkout).clang-format-18clean on both edited files.