Skip to content

Validate interleave indices before dispatch#10175

Open
fallintoplace wants to merge 1 commit into
apache:mainfrom
fallintoplace:fix-interleave-index-validation
Open

Validate interleave indices before dispatch#10175
fallintoplace wants to merge 1 commit into
apache:mainfrom
fallintoplace:fix-interleave-index-validation

Conversation

@fallintoplace

Copy link
Copy Markdown
Contributor

What changed

interleave(values, indices) now validates every user-provided (array_idx, row_idx) before dispatching to specialized implementations. It returns ArrowError::InvalidArgumentError when an index references a missing input array or a row past the selected array length.

The regression tests cover an out-of-bounds array index, an out-of-bounds row index, and the StringViewArray specialized path that previously could reach direct view indexing.

Why

interleave is a public API, and invalid external indices should be reported as Arrow errors instead of reaching specialized kernels that can panic while indexing arrays or byte views.

Validation

  • cargo fmt --package arrow-select
  • cargo test -p arrow-select out_of_bounds

@github-actions github-actions Bot added the arrow Changes to the arrow crate label Jun 21, 2026
return Ok(new_empty_array(data_type));
}

validate_interleave_indices(values, indices)?;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think the cost of this separate pass will be quite high, other kernels don't do this (or make it optional).

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That makes sense. Would you prefer making this optional, similar to take bounds checking, or keeping the fast path unchanged and documenting that invalid indices may panic?

@alamb

alamb commented Jun 22, 2026

Copy link
Copy Markdown
Contributor

run benchmark interleave_kernels

@adriangbot

Copy link
Copy Markdown

🤖 Arrow criterion benchmark running (GKE) | trigger
Instance: c4a-highmem-16 (12 vCPU / 65 GiB) | Linux bench-c4769695061-611-plqsv 6.12.68+ #1 SMP Sat May 2 07:49:07 UTC 2026 aarch64 GNU/Linux

CPU Details (lscpu)
Architecture:                            aarch64
CPU op-mode(s):                          64-bit
Byte Order:                              Little Endian
CPU(s):                                  16
On-line CPU(s) list:                     0-15
Vendor ID:                               ARM
Model name:                              Neoverse-V2
Model:                                   1
Thread(s) per core:                      1
Core(s) per cluster:                     16
Socket(s):                               -
Cluster(s):                              1
Stepping:                                r0p1
BogoMIPS:                                2000.00
Flags:                                   fp asimd evtstrm aes pmull sha1 sha2 crc32 atomics fphp asimdhp cpuid asimdrdm jscvt fcma lrcpc dcpop sha3 sm3 sm4 asimddp sha512 sve asimdfhm dit uscat ilrcpc flagm sb paca pacg dcpodp sve2 sveaes svepmull svebitperm svesha3 svesm4 flagm2 frint svei8mm svebf16 i8mm bf16 dgh rng bti
L1d cache:                               1 MiB (16 instances)
L1i cache:                               1 MiB (16 instances)
L2 cache:                                32 MiB (16 instances)
L3 cache:                                80 MiB (1 instance)
NUMA node(s):                            1
NUMA node0 CPU(s):                       0-15
Vulnerability Gather data sampling:      Not affected
Vulnerability Indirect target selection: Not affected
Vulnerability Itlb multihit:             Not affected
Vulnerability L1tf:                      Not affected
Vulnerability Mds:                       Not affected
Vulnerability Meltdown:                  Not affected
Vulnerability Mmio stale data:           Not affected
Vulnerability Reg file data sampling:    Not affected
Vulnerability Retbleed:                  Not affected
Vulnerability Spec rstack overflow:      Not affected
Vulnerability Spec store bypass:         Mitigation; Speculative Store Bypass disabled via prctl
Vulnerability Spectre v1:                Mitigation; __user pointer sanitization
Vulnerability Spectre v2:                Mitigation; CSV2, BHB
Vulnerability Srbds:                     Not affected
Vulnerability Tsa:                       Not affected
Vulnerability Tsx async abort:           Not affected
Vulnerability Vmscape:                   Not affected

Comparing fix-interleave-index-validation (1bb432c) to c8eba1a (merge-base) diff
BENCH_NAME=interleave_kernels
BENCH_COMMAND=cargo bench --features=arrow,async,test_common,experimental,object_store --bench interleave_kernels
BENCH_FILTER=
Results will be posted here when complete


File an issue against this benchmark runner

@adriangbot

Copy link
Copy Markdown

🤖 Arrow criterion benchmark completed (GKE) | trigger

Instance: c4a-highmem-16 (12 vCPU / 65 GiB)

CPU Details (lscpu)
Architecture:                            aarch64
CPU op-mode(s):                          64-bit
Byte Order:                              Little Endian
CPU(s):                                  16
On-line CPU(s) list:                     0-15
Vendor ID:                               ARM
Model name:                              Neoverse-V2
Model:                                   1
Thread(s) per core:                      1
Core(s) per cluster:                     16
Socket(s):                               -
Cluster(s):                              1
Stepping:                                r0p1
BogoMIPS:                                2000.00
Flags:                                   fp asimd evtstrm aes pmull sha1 sha2 crc32 atomics fphp asimdhp cpuid asimdrdm jscvt fcma lrcpc dcpop sha3 sm3 sm4 asimddp sha512 sve asimdfhm dit uscat ilrcpc flagm sb paca pacg dcpodp sve2 sveaes svepmull svebitperm svesha3 svesm4 flagm2 frint svei8mm svebf16 i8mm bf16 dgh rng bti
L1d cache:                               1 MiB (16 instances)
L1i cache:                               1 MiB (16 instances)
L2 cache:                                32 MiB (16 instances)
L3 cache:                                80 MiB (1 instance)
NUMA node(s):                            1
NUMA node0 CPU(s):                       0-15
Vulnerability Gather data sampling:      Not affected
Vulnerability Indirect target selection: Not affected
Vulnerability Itlb multihit:             Not affected
Vulnerability L1tf:                      Not affected
Vulnerability Mds:                       Not affected
Vulnerability Meltdown:                  Not affected
Vulnerability Mmio stale data:           Not affected
Vulnerability Reg file data sampling:    Not affected
Vulnerability Retbleed:                  Not affected
Vulnerability Spec rstack overflow:      Not affected
Vulnerability Spec store bypass:         Mitigation; Speculative Store Bypass disabled via prctl
Vulnerability Spectre v1:                Mitigation; __user pointer sanitization
Vulnerability Spectre v2:                Mitigation; CSV2, BHB
Vulnerability Srbds:                     Not affected
Vulnerability Tsa:                       Not affected
Vulnerability Tsx async abort:           Not affected
Vulnerability Vmscape:                   Not affected
Details

group                                                                                        fix-interleave-index-validation        main
-----                                                                                        -------------------------------        ----
interleave dict(20, 0.0) 100 [0..100, 100..230, 450..1000]                                   1.17    749.2±5.17ns        ? ?/sec    1.00    638.4±2.64ns        ? ?/sec
interleave dict(20, 0.0) 1024 [0..100, 100..230, 450..1000, 0..1000]                         1.48      2.8±0.01µs        ? ?/sec    1.00   1860.8±7.70ns        ? ?/sec
interleave dict(20, 0.0) 1024 [0..100, 100..230, 450..1000]                                  1.50      2.7±0.01µs        ? ?/sec    1.00   1815.8±6.47ns        ? ?/sec
interleave dict(20, 0.0) 400 [0..100, 100..230, 450..1000]                                   1.36   1393.0±7.12ns        ? ?/sec    1.00   1022.0±2.76ns        ? ?/sec
interleave dict_distinct 100                                                                 1.09      2.4±0.01µs        ? ?/sec    1.00      2.2±0.01µs        ? ?/sec
interleave dict_distinct 1024                                                                1.10      2.4±0.01µs        ? ?/sec    1.00      2.1±0.00µs        ? ?/sec
interleave dict_distinct 2048                                                                1.09      2.3±0.01µs        ? ?/sec    1.00      2.1±0.01µs        ? ?/sec
interleave dict_sparse(20, 0.0) 100 [0..100, 100..230, 450..1000]                            1.06   1628.9±4.03ns        ? ?/sec    1.00   1534.6±3.37ns        ? ?/sec
interleave dict_sparse(20, 0.0) 1024 [0..100, 100..230, 450..1000, 0..1000]                  1.29      3.9±0.01µs        ? ?/sec    1.00      3.1±0.01µs        ? ?/sec
interleave dict_sparse(20, 0.0) 1024 [0..100, 100..230, 450..1000]                           1.33      3.7±0.01µs        ? ?/sec    1.00      2.7±0.01µs        ? ?/sec
interleave dict_sparse(20, 0.0) 400 [0..100, 100..230, 450..1000]                            1.19      2.3±0.00µs        ? ?/sec    1.00   1944.9±4.80ns        ? ?/sec
interleave i32(0.0) 100 [0..100, 100..230, 450..1000]                                        1.51    319.3±2.21ns        ? ?/sec    1.00    211.7±2.47ns        ? ?/sec
interleave i32(0.0) 1024 [0..100, 100..230, 450..1000, 0..1000]                              2.04   1978.7±3.19ns        ? ?/sec    1.00    968.2±3.27ns        ? ?/sec
interleave i32(0.0) 1024 [0..100, 100..230, 450..1000]                                       1.98   1976.3±2.45ns        ? ?/sec    1.00    999.6±2.77ns        ? ?/sec
interleave i32(0.0) 400 [0..100, 100..230, 450..1000]                                        1.65    861.7±2.84ns        ? ?/sec    1.00    522.2±2.31ns        ? ?/sec
interleave i32(0.5) 100 [0..100, 100..230, 450..1000]                                        1.24    547.4±4.43ns        ? ?/sec    1.00    441.5±4.92ns        ? ?/sec
interleave i32(0.5) 1024 [0..100, 100..230, 450..1000, 0..1000]                              1.36      3.9±0.01µs        ? ?/sec    1.00      2.9±0.01µs        ? ?/sec
interleave i32(0.5) 1024 [0..100, 100..230, 450..1000]                                       1.35      4.0±0.01µs        ? ?/sec    1.00      3.0±0.02µs        ? ?/sec
interleave i32(0.5) 400 [0..100, 100..230, 450..1000]                                        1.25   1658.9±8.00ns        ? ?/sec    1.00   1323.0±6.04ns        ? ?/sec
interleave list<i64>(0.0,0.0,20) 100 [0..100, 100..230, 450..1000]                           1.11    947.2±1.26ns        ? ?/sec    1.00    854.3±7.82ns        ? ?/sec
interleave list<i64>(0.0,0.0,20) 1024 [0..100, 100..230, 450..1000, 0..1000]                 1.14      7.5±0.01µs        ? ?/sec    1.00      6.6±0.02µs        ? ?/sec
interleave list<i64>(0.0,0.0,20) 1024 [0..100, 100..230, 450..1000]                          1.15      7.5±0.02µs        ? ?/sec    1.00      6.5±0.02µs        ? ?/sec
interleave list<i64>(0.0,0.0,20) 400 [0..100, 100..230, 450..1000]                           1.14      3.1±0.00µs        ? ?/sec    1.00      2.7±0.01µs        ? ?/sec
interleave list<i64>(0.1,0.1,20) 100 [0..100, 100..230, 450..1000]                           1.04      2.3±0.03µs        ? ?/sec    1.00      2.2±0.04µs        ? ?/sec
interleave list<i64>(0.1,0.1,20) 1024 [0..100, 100..230, 450..1000, 0..1000]                 1.05     18.7±0.36µs        ? ?/sec    1.00     17.7±0.33µs        ? ?/sec
interleave list<i64>(0.1,0.1,20) 1024 [0..100, 100..230, 450..1000]                          1.04     18.7±0.40µs        ? ?/sec    1.00     17.9±0.42µs        ? ?/sec
interleave list<i64>(0.1,0.1,20) 400 [0..100, 100..230, 450..1000]                           1.04      7.7±0.13µs        ? ?/sec    1.00      7.4±0.14µs        ? ?/sec
interleave list_view<i64>(0.0,0.0,20) 100 [0..100, 100..230, 450..1000]                      1.05      2.3±0.01µs        ? ?/sec    1.00      2.2±0.00µs        ? ?/sec
interleave list_view<i64>(0.0,0.0,20) 1024 [0..100, 100..230, 450..1000, 0..1000]            1.08     14.5±0.02µs        ? ?/sec    1.00     13.4±0.02µs        ? ?/sec
interleave list_view<i64>(0.0,0.0,20) 1024 [0..100, 100..230, 450..1000]                     1.08     14.2±0.02µs        ? ?/sec    1.00     13.2±0.03µs        ? ?/sec
interleave list_view<i64>(0.0,0.0,20) 400 [0..100, 100..230, 450..1000]                      1.06      6.3±0.01µs        ? ?/sec    1.00      5.9±0.02µs        ? ?/sec
interleave list_view<i64>(0.1,0.1,20) 100 [0..100, 100..230, 450..1000]                      1.04      3.8±0.02µs        ? ?/sec    1.00      3.6±0.01µs        ? ?/sec
interleave list_view<i64>(0.1,0.1,20) 1024 [0..100, 100..230, 450..1000, 0..1000]            1.05     25.3±0.15µs        ? ?/sec    1.00     24.2±0.18µs        ? ?/sec
interleave list_view<i64>(0.1,0.1,20) 1024 [0..100, 100..230, 450..1000]                     1.05     25.4±0.15µs        ? ?/sec    1.00     24.2±0.18µs        ? ?/sec
interleave list_view<i64>(0.1,0.1,20) 400 [0..100, 100..230, 450..1000]                      1.03     10.8±0.06µs        ? ?/sec    1.00     10.4±0.05µs        ? ?/sec
interleave list_view_overlapping<i64>(80x,20) 100 [0..100, 100..230, 450..1000]              1.05      2.5±0.01µs        ? ?/sec    1.00      2.4±0.01µs        ? ?/sec
interleave list_view_overlapping<i64>(80x,20) 1024 [0..100, 100..230, 450..1000, 0..1000]    1.15      7.1±0.02µs        ? ?/sec    1.00      6.2±0.02µs        ? ?/sec
interleave list_view_overlapping<i64>(80x,20) 1024 [0..100, 100..230, 450..1000]             1.16      6.9±0.02µs        ? ?/sec    1.00      5.9±0.02µs        ? ?/sec
interleave list_view_overlapping<i64>(80x,20) 400 [0..100, 100..230, 450..1000]              1.14      3.4±0.01µs        ? ?/sec    1.00      3.0±0.01µs        ? ?/sec
interleave ree_i32<dict<u32,utf8>>(64 runs) 100 [0..100, 100..230, 450..1000]                1.13      4.8±0.02µs        ? ?/sec    1.00      4.3±0.02µs        ? ?/sec
interleave ree_i32<dict<u32,utf8>>(64 runs) 1024 [0..100, 100..230, 450..1000, 0..1000]      1.11     22.8±0.08µs        ? ?/sec    1.00     20.6±0.08µs        ? ?/sec
interleave ree_i32<dict<u32,utf8>>(64 runs) 1024 [0..100, 100..230, 450..1000]               1.10     22.4±0.07µs        ? ?/sec    1.00     20.3±0.09µs        ? ?/sec
interleave ree_i32<dict<u32,utf8>>(64 runs) 400 [0..100, 100..230, 450..1000]                1.17     11.2±0.04µs        ? ?/sec    1.00      9.5±0.03µs        ? ?/sec
interleave ree_i32<i64>(64 runs) 100 [0..100, 100..230, 450..1000]                           1.17      3.9±0.01µs        ? ?/sec    1.00      3.3±0.01µs        ? ?/sec
interleave ree_i32<i64>(64 runs) 1024 [0..100, 100..230, 450..1000, 0..1000]                 1.11     21.2±0.08µs        ? ?/sec    1.00     19.2±0.08µs        ? ?/sec
interleave ree_i32<i64>(64 runs) 1024 [0..100, 100..230, 450..1000]                          1.11     20.9±0.08µs        ? ?/sec    1.00     18.8±0.10µs        ? ?/sec
interleave ree_i32<i64>(64 runs) 400 [0..100, 100..230, 450..1000]                           1.13      9.4±0.02µs        ? ?/sec    1.00      8.3±0.02µs        ? ?/sec
interleave str(20, 0.0) 100 [0..100, 100..230, 450..1000]                                    1.15    700.6±1.59ns        ? ?/sec    1.00    607.8±0.99ns        ? ?/sec
interleave str(20, 0.0) 1024 [0..100, 100..230, 450..1000, 0..1000]                          1.19      5.5±0.01µs        ? ?/sec    1.00      4.6±0.01µs        ? ?/sec
interleave str(20, 0.0) 1024 [0..100, 100..230, 450..1000]                                   1.19      5.5±0.01µs        ? ?/sec    1.00      4.6±0.01µs        ? ?/sec
interleave str(20, 0.0) 400 [0..100, 100..230, 450..1000]                                    1.19      2.3±0.00µs        ? ?/sec    1.00   1894.4±4.75ns        ? ?/sec
interleave str(20, 0.5) 100 [0..100, 100..230, 450..1000]                                    1.13    848.6±2.01ns        ? ?/sec    1.00    754.3±2.43ns        ? ?/sec
interleave str(20, 0.5) 1024 [0..100, 100..230, 450..1000, 0..1000]                          1.15      6.8±0.01µs        ? ?/sec    1.00      6.0±0.02µs        ? ?/sec
interleave str(20, 0.5) 1024 [0..100, 100..230, 450..1000]                                   1.14      6.8±0.01µs        ? ?/sec    1.00      6.0±0.02µs        ? ?/sec
interleave str(20, 0.5) 400 [0..100, 100..230, 450..1000]                                    1.14      2.8±0.01µs        ? ?/sec    1.00      2.5±0.01µs        ? ?/sec
interleave str_view(0.0) 100 [0..100, 100..230, 450..1000]                                   1.20    666.0±9.70ns        ? ?/sec    1.00    556.2±0.51ns        ? ?/sec
interleave str_view(0.0) 1024 [0..100, 100..230, 450..1000, 0..1000]                         1.35      3.5±0.01µs        ? ?/sec    1.00      2.6±0.01µs        ? ?/sec
interleave str_view(0.0) 1024 [0..100, 100..230, 450..1000]                                  1.35      3.4±0.01µs        ? ?/sec    1.00      2.5±0.00µs        ? ?/sec
interleave str_view(0.0) 400 [0..100, 100..230, 450..1000]                                   1.29  1604.6±12.45ns        ? ?/sec    1.00   1240.5±3.01ns        ? ?/sec
interleave struct(i32(0.0), i32(0.0) 100 [0..100, 100..230, 450..1000]                       1.54   1011.9±3.32ns        ? ?/sec    1.00    656.0±7.04ns        ? ?/sec
interleave struct(i32(0.0), i32(0.0) 1024 [0..100, 100..230, 450..1000, 0..1000]             2.46      5.3±0.01µs        ? ?/sec    1.00      2.2±0.01µs        ? ?/sec
interleave struct(i32(0.0), i32(0.0) 1024 [0..100, 100..230, 450..1000]                      2.49      5.3±0.00µs        ? ?/sec    1.00      2.1±0.01µs        ? ?/sec
interleave struct(i32(0.0), i32(0.0) 400 [0..100, 100..230, 450..1000]                       2.16      2.5±0.00µs        ? ?/sec    1.00   1150.1±6.13ns        ? ?/sec
interleave struct(i32(0.0), str(20, 0.0) 100 [0..100, 100..230, 450..1000]                   1.36   1413.3±4.92ns        ? ?/sec    1.00   1035.7±4.09ns        ? ?/sec
interleave struct(i32(0.0), str(20, 0.0) 1024 [0..100, 100..230, 450..1000, 0..1000]         1.58      9.3±0.02µs        ? ?/sec    1.00      5.9±0.01µs        ? ?/sec
interleave struct(i32(0.0), str(20, 0.0) 1024 [0..100, 100..230, 450..1000]                  1.59      9.3±0.03µs        ? ?/sec    1.00      5.9±0.01µs        ? ?/sec
interleave struct(i32(0.0), str(20, 0.0) 400 [0..100, 100..230, 450..1000]                   1.54      4.0±0.01µs        ? ?/sec    1.00      2.6±0.01µs        ? ?/sec
interleave struct(str(20, 0.0), str(20, 0.0)) 100 [0..100, 100..230, 450..1000]              1.23   1757.4±3.07ns        ? ?/sec    1.00   1431.1±5.76ns        ? ?/sec
interleave struct(str(20, 0.0), str(20, 0.0)) 1024 [0..100, 100..230, 450..1000, 0..1000]    1.32     12.8±0.03µs        ? ?/sec    1.00      9.6±0.02µs        ? ?/sec
interleave struct(str(20, 0.0), str(20, 0.0)) 1024 [0..100, 100..230, 450..1000]             1.31     12.6±0.03µs        ? ?/sec    1.00      9.6±0.03µs        ? ?/sec
interleave struct(str(20, 0.0), str(20, 0.0)) 400 [0..100, 100..230, 450..1000]              1.32      5.4±0.01µs        ? ?/sec    1.00      4.1±0.01µs        ? ?/sec

Resource Usage

base (merge-base)

Metric Value
Wall time 680.2s
Peak memory 15.6 MiB
Avg memory 14.6 MiB
CPU user 677.4s
CPU sys 0.0s
Peak spill 0 B

branch

Metric Value
Wall time 695.1s
Peak memory 15.4 MiB
Avg memory 14.3 MiB
CPU user 692.8s
CPU sys 0.0s
Peak spill 0 B

File an issue against this benchmark runner

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

arrow Changes to the arrow crate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants