Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 17 additions & 2 deletions arrow-row/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -1132,14 +1132,20 @@ impl Rows {

/// Returns the row at index `row`
pub fn row(&self, row: usize) -> Row<'_> {
assert!(row + 1 < self.offsets.len());
self.checked_row_end(row);
unsafe { self.row_unchecked(row) }
}

fn checked_row_end(&self, row: usize) -> usize {
row.checked_add(1)
.filter(|end| *end < self.offsets.len())
.expect("row index out of bounds")
}

/// Returns the row at `index` without bounds checking

@alamb alamb May 5, 2026

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As the description points out the reason #9817 has more changes than this PR is:

Note: Rows::row_len and Rows::lengths are not present on the 57_maintenance line, so this backport applies the checked row index validation to Rows::row and includes the row_unchecked safety documentation update from the original PR.

This was introduced in

which was first released in 58.2.0

///
/// # Safety
/// Caller must ensure that `index` is less than the number of offsets (#rows + 1)
/// Caller must ensure that `index + 1` is less than the number of offsets (#rows + 1)
pub unsafe fn row_unchecked(&self, index: usize) -> Row<'_> {
let end = unsafe { self.offsets.get_unchecked(index + 1) };
let start = unsafe { self.offsets.get_unchecked(index) };
Expand Down Expand Up @@ -4283,4 +4289,13 @@ mod tests {
"{empty_rows_size_with_preallocate_data} should be larger than {empty_rows_size_without_preallocate}"
);
}

#[test]
#[should_panic(expected = "row index out of bounds")]
fn row_should_panic_on_overflowing_index() {
let rows = RowConverter::new(vec![SortField::new(DataType::Int32)])
.unwrap()
.empty_rows(0, 0);
rows.row(usize::MAX);
}
}
Loading