diff --git a/poetry.lock b/poetry.lock index ff8558c0b..12d984128 100644 --- a/poetry.lock +++ b/poetry.lock @@ -1,4 +1,4 @@ -# This file is automatically @generated by Poetry 2.2.1 and should not be changed by hand. +# This file is automatically @generated by Poetry 2.3.2 and should not be changed by hand. [[package]] name = "astroid" @@ -437,7 +437,7 @@ name = "cryptography" version = "49.0.0" description = "cryptography is a package which provides cryptographic recipes and primitives to Python developers." optional = true -python-versions = ">=3.9, !=3.9.0, !=3.9.1" +python-versions = "!=3.9.0,!=3.9.1,>=3.9" groups = ["main"] files = [ {file = "cryptography-49.0.0-cp311-abi3-macosx_11_0_arm64.whl", hash = "sha256:966fe0e9c67490071f14c0d2b1cb2dfb3023c5ce39457343931415f08382f2db"}, @@ -1833,7 +1833,7 @@ name = "six" version = "1.17.0" description = "Python 2 and 3 compatibility utilities" optional = false -python-versions = ">=2.7, !=3.0.*, !=3.1.*, !=3.2.*" +python-versions = "!=3.0.*,!=3.1.*,!=3.2.*,>=2.7" groups = ["main"] files = [ {file = "six-1.17.0-py2.py3-none-any.whl", hash = "sha256:4721f391ed90541fddacab5acf947aa0d3dc7d27b2e1e8eda2be8970586c3274"}, @@ -1882,48 +1882,53 @@ files = [ [[package]] name = "thrift" -version = "0.24.0" +version = "0.25.0" description = "Python bindings for the Apache Thrift RPC system" optional = false python-versions = "*" groups = ["main"] files = [ - {file = "thrift-0.24.0-cp310-cp310-macosx_10_9_x86_64.whl", hash = "sha256:efe85c4508adaf6c9e6f7fac2b1c3c9beb4b39b19c375519966335a70b28e64a"}, - {file = "thrift-0.24.0-cp310-cp310-macosx_11_0_arm64.whl", hash = "sha256:a2baaec0c5cd7ba3eace54b26d81fdf0f5a85010468687cf4a131871d65abfed"}, - {file = "thrift-0.24.0-cp310-cp310-manylinux2014_aarch64.manylinux_2_17_aarch64.whl", hash = "sha256:cad27a826e86739a79a327e6afae5a9bea36aeed2989c4318fc2943b6cfad095"}, - {file = "thrift-0.24.0-cp310-cp310-manylinux2014_x86_64.manylinux_2_17_x86_64.whl", hash = "sha256:9e26ca0f346e5ec2b6be9778573fb2e9d8b3eb162dbce94e61906176158b448b"}, - {file = "thrift-0.24.0-cp310-cp310-musllinux_1_2_aarch64.whl", hash = "sha256:498ae392090d7ae17ab59ebd8dfabda76528eeb22d3890a57c9f226003d7ed6e"}, - {file = "thrift-0.24.0-cp310-cp310-musllinux_1_2_x86_64.whl", hash = "sha256:acbd02baacfa0d2017f85b189ed69cd6baa522785d1ad86476eb7ce8cd16d063"}, - {file = "thrift-0.24.0-cp310-cp310-win_amd64.whl", hash = "sha256:887a10d718d85275da70fe4e9d4740268ae2854f205fb5869909d24cc5576b79"}, - {file = "thrift-0.24.0-cp311-cp311-macosx_10_9_x86_64.whl", hash = "sha256:873c93d8496cf71589efd3128ddc5af0be350e6c1a0e615475d840eaa54f6124"}, - {file = "thrift-0.24.0-cp311-cp311-macosx_11_0_arm64.whl", hash = "sha256:048d768e5822c436e8920b987d89a6a26e4d438ddf2de4b9d3f81444cd03cd04"}, - {file = "thrift-0.24.0-cp311-cp311-manylinux2014_aarch64.manylinux_2_17_aarch64.whl", hash = "sha256:2592bb0bf232d0808583626a7a8d71e265851e974c182967d67dde1f16902aee"}, - {file = "thrift-0.24.0-cp311-cp311-manylinux2014_x86_64.manylinux_2_17_x86_64.whl", hash = "sha256:ca1b1ba00151565dc4e6673c924debd557aaf25b2790f1570b3430cb35503671"}, - {file = "thrift-0.24.0-cp311-cp311-musllinux_1_2_aarch64.whl", hash = "sha256:afb7977ccb8ecd7b1520a5141de64b58e94712528a26c10ac8f5b4ef220112a5"}, - {file = "thrift-0.24.0-cp311-cp311-musllinux_1_2_x86_64.whl", hash = "sha256:c8d37a4311a87bda4bd2b8e4137eec638c18e3a57d11a1011bd98a8867523860"}, - {file = "thrift-0.24.0-cp311-cp311-win_amd64.whl", hash = "sha256:fbf461351940ddaa85bf8c2ee1754c9cfdd33bb78322e635e1ea5cd3947ae49a"}, - {file = "thrift-0.24.0-cp312-cp312-macosx_10_13_x86_64.whl", hash = "sha256:306e0fe3c96b300471c19cec60bd6816064fd93d04713488ef07120aff84653b"}, - {file = "thrift-0.24.0-cp312-cp312-macosx_11_0_arm64.whl", hash = "sha256:8ac42199ea2a6fc6275b0aeec32ae09e7f9edb43890ff9a1af5e34191fb422cc"}, - {file = "thrift-0.24.0-cp312-cp312-manylinux2014_aarch64.manylinux_2_17_aarch64.whl", hash = "sha256:8cdd5f927eb98d0e8f00ab148b0cb66ae2598a396e907bd2b6febcbdcc46d80c"}, - {file = "thrift-0.24.0-cp312-cp312-manylinux2014_x86_64.manylinux_2_17_x86_64.whl", hash = "sha256:134cd1a0d80f928377808348d1f9f647284ada093573beaa47040bed5507e219"}, - {file = "thrift-0.24.0-cp312-cp312-musllinux_1_2_aarch64.whl", hash = "sha256:518199062feabfc0982767a0f7bceccb4fd1b485654f75e02913837444c3c130"}, - {file = "thrift-0.24.0-cp312-cp312-musllinux_1_2_x86_64.whl", hash = "sha256:d8c5de86af2a44641d423624c71c554a691d9f80c8b87709f15c7f98ccc6aeac"}, - {file = "thrift-0.24.0-cp312-cp312-win_amd64.whl", hash = "sha256:2f82bb16c4f2009dbc4fc9374604f05e998fb33be6a7787e095cea9842ecfa1d"}, - {file = "thrift-0.24.0-cp313-cp313-macosx_10_13_x86_64.whl", hash = "sha256:ebb8b389142d67554d0de814dd6c1d62b962751f68721537efca429c57b09327"}, - {file = "thrift-0.24.0-cp313-cp313-macosx_11_0_arm64.whl", hash = "sha256:18e7693f1bcef45937ad31a02564add55dec754710d42afc8ee3fc26ecf13028"}, - {file = "thrift-0.24.0-cp313-cp313-manylinux2014_aarch64.manylinux_2_17_aarch64.whl", hash = "sha256:937b398c311799fd5eddaeaffbd275510c68ead597eb1897e5e8113542fb2b50"}, - {file = "thrift-0.24.0-cp313-cp313-manylinux2014_x86_64.manylinux_2_17_x86_64.whl", hash = "sha256:b89a83d4e9ae6029e14f6f7c73305044bf02739d729c6aa8025ef3b6faef0ec0"}, - {file = "thrift-0.24.0-cp313-cp313-musllinux_1_2_aarch64.whl", hash = "sha256:6381093f2c54e0f108554004a8cac3f1ef7ba99d6c5a9909c0eb64f450142685"}, - {file = "thrift-0.24.0-cp313-cp313-musllinux_1_2_x86_64.whl", hash = "sha256:28e034658d724aaa66007babb258ef12f0294036812fc449d7ce6fd15b07100f"}, - {file = "thrift-0.24.0-cp313-cp313-win_amd64.whl", hash = "sha256:f4a44391ae1e32817553639b2991b0753d84487259fe87f8111c956c6bdebf43"}, - {file = "thrift-0.24.0-cp314-cp314-macosx_10_15_x86_64.whl", hash = "sha256:7beb05268c76895f7c3130ce747a8a8cf35558fbc7f464f994e20a0c92181cbd"}, - {file = "thrift-0.24.0-cp314-cp314-macosx_11_0_arm64.whl", hash = "sha256:f40bdfbaf8d2795b1593bb75b4d9c77831bbe96a1ef59da4634ccc125a17dca5"}, - {file = "thrift-0.24.0-cp314-cp314-manylinux2014_aarch64.manylinux_2_17_aarch64.whl", hash = "sha256:272624d36faa7bee01b94e5da5efc7305d9d3da57d005382c93fcbde8c3edf6a"}, - {file = "thrift-0.24.0-cp314-cp314-manylinux2014_x86_64.manylinux_2_17_x86_64.whl", hash = "sha256:7bc91ae93005bc16c7362edcb58818a547850b9b52fe9b8075cc6b8922bcde2d"}, - {file = "thrift-0.24.0-cp314-cp314-musllinux_1_2_aarch64.whl", hash = "sha256:c05bb4eac921836c12cdf30c237283df8a42aff6540f7970cd72c5959b139970"}, - {file = "thrift-0.24.0-cp314-cp314-musllinux_1_2_x86_64.whl", hash = "sha256:e5da6b391828d46df9471f22181374760a91773b7e07ad7eb44f351c90580662"}, - {file = "thrift-0.24.0-cp314-cp314-win_amd64.whl", hash = "sha256:829db909a053d4064cb9fe574cc1f5994c24d727f61cdf6446ca774cd3ba5268"}, - {file = "thrift-0.24.0.tar.gz", hash = "sha256:9ef601c49e988475ff0e741d8e1b45feec23b48514e524341efc274191f1789c"}, + {file = "thrift-0.25.0-cp310-cp310-macosx_10_9_x86_64.whl", hash = "sha256:fd15b187a30609ace159f036f7af4469e1a0dacfeb590d283300ff9cdfb3b1f5"}, + {file = "thrift-0.25.0-cp310-cp310-macosx_11_0_arm64.whl", hash = "sha256:2b0c492d975703ce006108c570b7adb61f573a6b667d676918d0122bee9392f2"}, + {file = "thrift-0.25.0-cp310-cp310-manylinux2014_aarch64.manylinux_2_17_aarch64.whl", hash = "sha256:579d891d2af0065cec44a3ed68e7a821f58aff3250af71109e13fee3775c7aaf"}, + {file = "thrift-0.25.0-cp310-cp310-manylinux2014_x86_64.manylinux_2_17_x86_64.whl", hash = "sha256:51597cdb871998acea9f5b24b7b1eefc3a03d71f5d2190f897052fc9ed2bf7a8"}, + {file = "thrift-0.25.0-cp310-cp310-musllinux_1_2_aarch64.whl", hash = "sha256:21cfb2d32539f43efd728db6a30cdd692c2559a9f47c19ef8a864df27c06b9d1"}, + {file = "thrift-0.25.0-cp310-cp310-musllinux_1_2_x86_64.whl", hash = "sha256:0c3a63dd22977ecf96f412be78a563225ac2d81d9ca224ea2c52248884f36a20"}, + {file = "thrift-0.25.0-cp310-cp310-win_amd64.whl", hash = "sha256:9726fc48f5487c4c2706cfb54444e3e518188ac6a43bef533151c6bd6450cad6"}, + {file = "thrift-0.25.0-cp310-cp310-win_arm64.whl", hash = "sha256:2b0ef8aa9773c8009550559d27a39ba01b999627f37cfcb3cccb9579349140ae"}, + {file = "thrift-0.25.0-cp311-cp311-macosx_10_9_x86_64.whl", hash = "sha256:dc1ca37e289c7056f12c0acef8449ab036daa74fa396cdedb10eabbf79fd6a15"}, + {file = "thrift-0.25.0-cp311-cp311-macosx_11_0_arm64.whl", hash = "sha256:894763113e191dd38424c3ec73a156d89c7d3fece5436af3e51e219ec15698d6"}, + {file = "thrift-0.25.0-cp311-cp311-manylinux2014_aarch64.manylinux_2_17_aarch64.whl", hash = "sha256:a7b9081f378a39982e22f0ea7fa74ce9fb0179bb28e2ebc45707c3b66718de4f"}, + {file = "thrift-0.25.0-cp311-cp311-manylinux2014_x86_64.manylinux_2_17_x86_64.whl", hash = "sha256:b968801fcf0974e3702130e372fd63c1cb96b67948d2dc4237cdee3d157face0"}, + {file = "thrift-0.25.0-cp311-cp311-musllinux_1_2_aarch64.whl", hash = "sha256:91f5207e83c2129e1a03a75a9b01ce9c4fb0fb9ff18e53cb78ffc618d594085d"}, + {file = "thrift-0.25.0-cp311-cp311-musllinux_1_2_x86_64.whl", hash = "sha256:91e667bd8ff58de4505fe463105655892b5b46e3ac00d1987d4258834e94ab1e"}, + {file = "thrift-0.25.0-cp311-cp311-win_amd64.whl", hash = "sha256:49b3efa6388c76fde87d542428fa1aebc86d6b855bfde4bb006c932974c1c5bc"}, + {file = "thrift-0.25.0-cp311-cp311-win_arm64.whl", hash = "sha256:8a781b043d628bc5ffd4f9a14589d7bd5086121f52f674c0007e31a74cd0958d"}, + {file = "thrift-0.25.0-cp312-cp312-macosx_10_13_x86_64.whl", hash = "sha256:23d8a6f8ae12836e86b22cb24f2d9533a6f6b8bee76aee5bb8b9d9579abd507d"}, + {file = "thrift-0.25.0-cp312-cp312-macosx_11_0_arm64.whl", hash = "sha256:47527c984a449c584b550f57a6e4d623473fcdcbf1fa5405b546be239bfc607a"}, + {file = "thrift-0.25.0-cp312-cp312-manylinux2014_aarch64.manylinux_2_17_aarch64.whl", hash = "sha256:4ba6f27475c453df37cdf5f57b5937cf175d166d2a10dc5273d2a47d22c4329d"}, + {file = "thrift-0.25.0-cp312-cp312-manylinux2014_x86_64.manylinux_2_17_x86_64.whl", hash = "sha256:436b8d1ad069a90b18ca1d745f2a2fc9b70329317ba77eb67ff28e82de186930"}, + {file = "thrift-0.25.0-cp312-cp312-musllinux_1_2_aarch64.whl", hash = "sha256:f0c827fe55ad69eb10950628887e05720cb4f08a754835e27370bf50ca62b760"}, + {file = "thrift-0.25.0-cp312-cp312-musllinux_1_2_x86_64.whl", hash = "sha256:41a12e5f3bcc0465ee4489ed0d74766933a7d16e5881f7245f225a4f04dc6be1"}, + {file = "thrift-0.25.0-cp312-cp312-win_amd64.whl", hash = "sha256:a6fb3fe5670d97e7cc8035504b82980d40efb978bde0e97b85e7cd08ba229404"}, + {file = "thrift-0.25.0-cp312-cp312-win_arm64.whl", hash = "sha256:bb12066efe3b19c44c05f97dbdd10c32317e1bd64e1aa98ec7d11f669a11f874"}, + {file = "thrift-0.25.0-cp313-cp313-macosx_10_13_x86_64.whl", hash = "sha256:5e92406068afacb25ea04f2734ba6aaefedae86deb6700f28d6c9f73660021b2"}, + {file = "thrift-0.25.0-cp313-cp313-macosx_11_0_arm64.whl", hash = "sha256:68f685a14655a8546e9f733dfee948008749b69aa861b5c2ae5e87bb69cb8515"}, + {file = "thrift-0.25.0-cp313-cp313-manylinux2014_aarch64.manylinux_2_17_aarch64.whl", hash = "sha256:05ca4e36325b508976dcf2e98831297844e11151e5acbcc51c569b92a95d746a"}, + {file = "thrift-0.25.0-cp313-cp313-manylinux2014_x86_64.manylinux_2_17_x86_64.whl", hash = "sha256:aa0cfa1db4d2129114d9548c4fc7e85680013aa442692377606b6305d236a1c0"}, + {file = "thrift-0.25.0-cp313-cp313-musllinux_1_2_aarch64.whl", hash = "sha256:d0cac032e150dbde529456ac1f91af96e5eededcf097683ffcb2e875e6da4ef3"}, + {file = "thrift-0.25.0-cp313-cp313-musllinux_1_2_x86_64.whl", hash = "sha256:60c0961232ec9049635138991631ac063220325c2537482d5b26979d2bf17f5d"}, + {file = "thrift-0.25.0-cp313-cp313-win_amd64.whl", hash = "sha256:2dfc192cfebdca42cbdaaec7b2f6fea0d3cd4c0f9053bf1a3fdd7a65fa30c535"}, + {file = "thrift-0.25.0-cp313-cp313-win_arm64.whl", hash = "sha256:9d48ef7804a8e7f5e28dc2c495d8b61da14314c9d615bdafdf28dd40e596b666"}, + {file = "thrift-0.25.0-cp314-cp314-macosx_10_15_x86_64.whl", hash = "sha256:8eca5abeeb38d7948175b1b4254a8799c9c8fd9cd2c5ce5c9b9aa64709c2ae86"}, + {file = "thrift-0.25.0-cp314-cp314-macosx_11_0_arm64.whl", hash = "sha256:c38e9dd1d79e77acccea314cbfac27a13cab7ca7d1c96e81d7bfb3d2cc3e2d20"}, + {file = "thrift-0.25.0-cp314-cp314-manylinux2014_aarch64.manylinux_2_17_aarch64.whl", hash = "sha256:b78d0274daa64f34257f7ccf4e1cc83567595ff90be09e267292ee633277a497"}, + {file = "thrift-0.25.0-cp314-cp314-manylinux2014_x86_64.manylinux_2_17_x86_64.whl", hash = "sha256:2a10a8d58cd34267bc06ee9a5274ded53b5be5da5765544be7734f5a096d4dfc"}, + {file = "thrift-0.25.0-cp314-cp314-musllinux_1_2_aarch64.whl", hash = "sha256:674238ae8ea086c7c48f08562d18bb842f9f8789507ab0441f60eed676d3e0da"}, + {file = "thrift-0.25.0-cp314-cp314-musllinux_1_2_x86_64.whl", hash = "sha256:6b42e755f38a536abfb3691ecc2850cdb61fe60848dd1ef434da26ac6dc31547"}, + {file = "thrift-0.25.0-cp314-cp314-win_amd64.whl", hash = "sha256:779da544bd3ce68ebb17a21b01db638a8e6c5a65f878e54374c90278e64d98ae"}, + {file = "thrift-0.25.0-cp314-cp314-win_arm64.whl", hash = "sha256:07aa3ccd64304f77b315e4087b7ebf8e537935c070612fc5ad12c8076085ef3a"}, + {file = "thrift-0.25.0.tar.gz", hash = "sha256:e85615ae9245f5622a5e36a9d2d867e1e7b17a8ca467b257dece5dc1642ccd73"}, ] [package.extras] @@ -2052,4 +2057,4 @@ pyarrow = ["pyarrow", "pyarrow", "pyarrow"] [metadata] lock-version = "2.1" python-versions = "^3.10" -content-hash = "e68813b0ffe8e64773075827abc976e3db852a0096a6a381731617b80ff75e7b" +content-hash = "3518b48720f707b632d3603ee66e781f7ae3b91eb0f238348589962b96148bf5" diff --git a/pyproject.toml b/pyproject.toml index 38263823d..797f56bb2 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -21,10 +21,26 @@ python = "^3.10" # a wheel and never runs setup.py on DBR LTS -- the build-time break cannot # trigger. The `DBR LTS Install` CI check (.github/workflows/dbr-lts-install.yml) # installs the built artifact on real DBR LTS clusters and is the authoritative -# gate for this. Cap at <0.25.0: thrift is pre-1.0, each 0.x minor can carry -# breaking changes or packaging regressions (see 0.23.0), so bump this -# deliberately once a new minor ships and the DBR-LTS gate proves it safe. -thrift = "~=0.24.0" +# gate for this. +# +# Ceiling raised to <0.26.0 for 0.25.0 (released 2026-09-30, THRIFT-6067 series +# follow-up), which fixes 61 CVEs across language bindings, several affecting +# the Python binding this connector uses (see #969), e.g. CVE-2026-66858 +# (skip() recursion-limit bypass in the Python accelerator) and CVE-2026-85494 +# (framed transport / binary protocol size a read buffer from a peer-declared +# length with no effective maximum). 0.25.0 ships the same prebuilt wheel +# matrix as 0.24.0 (manylinux2014/macOS/musl/Windows, cp310-cp314), so the +# DBR LTS build-time risk above does not apply; the `DBR LTS Install` CI gate +# remains the authoritative check. thrift is pre-1.0, so keep this ceiling one +# minor ahead and bump deliberately once a newer minor ships and the DBR-LTS +# gate proves it safe -- do not use an open-ended `^`/`>=` constraint. +# +# NOTE: 0.25.0 also changes TBinaryProtocol's default `string_length_limit` +# from unbounded to ~15.6 MiB (see the explicit `string_length_limit=None` / +# `container_length_limit=None` passed in thrift_backend.py's protocol +# construction, which preserves the connector's pre-0.25 unbounded behavior +# for its own already-bounded, trusted-server result stream). +thrift = ">=0.24.0,<0.26.0" pandas = [ { version = ">=1.2.5,<4.0.0", python = ">=3.10,<3.13" }, { version = ">=2.2.3,<4.0.0", python = ">=3.13" } diff --git a/src/databricks/sql/backend/thrift_backend.py b/src/databricks/sql/backend/thrift_backend.py index fcf363cf0..8c6cb69e7 100644 --- a/src/databricks/sql/backend/thrift_backend.py +++ b/src/databricks/sql/backend/thrift_backend.py @@ -76,6 +76,19 @@ TIMESTAMP_AS_STRING_CONFIG = "spark.thriftserver.arrowBasedRowSet.timestampAsString" DEFAULT_SOCKET_TIMEOUT = float(900) +# thrift>=0.25.0 changed TBinaryProtocol's default string_length_limit from +# unbounded (None) to DEFAULT_STRING_LENGTH_LIMIT (DEFAULT_MAX_FRAME_SIZE, +# ~15.6 MiB) as part of its CVE-2026-85494 fix (peer-declared length with no +# effective maximum). That default is sized for untrusted/unbounded peers; +# this connector already bounds its own result stream via the TLS-verified, +# server-negotiated `buffer_size_bytes` (default 100 MiB, see client.py's +# DEFAULT_RESULT_BUFFER_SIZE_BYTES) and the inline Arrow batches in +# TFetchResultsResp routinely exceed thrift's new ~15.6 MiB cap. Pass these +# explicitly so upgrading thrift does not silently cap -- or regress -- the +# connector's own, already-bounded result size behavior. +THRIFT_BINARY_PROTOCOL_STRING_LENGTH_LIMIT = None +THRIFT_BINARY_PROTOCOL_CONTAINER_LENGTH_LIMIT = None + # see Connection.__init__ for parameter descriptions. # - Min/Max avoids unsustainable configs (sane values are far more constrained) # - 900s attempts-duration lines up w ODBC/JDBC drivers (for cluster startup > 10 mins) @@ -237,7 +250,11 @@ def __init__( self._transport.setTimeout(timeout and (float(timeout) * 1000.0)) self._transport.setCustomHeaders(dict(http_headers)) - protocol = thrift.protocol.TBinaryProtocol.TBinaryProtocol(self._transport) + protocol = thrift.protocol.TBinaryProtocol.TBinaryProtocol( + self._transport, + string_length_limit=THRIFT_BINARY_PROTOCOL_STRING_LENGTH_LIMIT, + container_length_limit=THRIFT_BINARY_PROTOCOL_CONTAINER_LENGTH_LIMIT, + ) self._client = TCLIService.Client(protocol) try: diff --git a/tests/unit/test_thrift_backend.py b/tests/unit/test_thrift_backend.py index ddcb378ff..17a86464d 100644 --- a/tests/unit/test_thrift_backend.py +++ b/tests/unit/test_thrift_backend.py @@ -204,6 +204,67 @@ def test_headers_are_set(self, t_http_client_class): {"header": "value"} ) + @patch("databricks.sql.auth.thrift_http_client.THttpClient") + def test_binary_protocol_preserves_unbounded_string_and_container_limits( + self, t_http_client_class + ): + """thrift>=0.25.0 changed TBinaryProtocol's default string_length_limit + from unbounded (None) to ~15.6 MiB (DEFAULT_STRING_LENGTH_LIMIT) as part + of its CVE-2026-85494 fix. The connector must pass these limits through + explicitly so a thrift upgrade cannot silently cap -- or regress -- the + size of result data (e.g. inline Arrow batches) it can read, since the + connector already governs its own result size via buffer_size_bytes. + """ + import thrift.protocol.TBinaryProtocol + + with patch( + "thrift.protocol.TBinaryProtocol.TBinaryProtocol" + ) as mock_protocol_class: + ThriftDatabricksClient( + "foo", + 123, + "bar", + [], + auth_provider=AuthProvider(), + ssl_options=SSLOptions(), + http_client=MagicMock(), + ) + + _, kwargs = mock_protocol_class.call_args + self.assertIsNone(kwargs.get("string_length_limit")) + self.assertIsNone(kwargs.get("container_length_limit")) + + def test_binary_protocol_reads_result_larger_than_thrift_default_limit(self): + """Guard against relying on thrift's new (>=0.25.0) default + string_length_limit of ~15.6 MiB, which is smaller than the + connector's own DEFAULT_RESULT_BUFFER_SIZE_BYTES (100 MiB). A field + larger than thrift's default limit, but within the connector's own + result-size bound, must still read successfully. + """ + from thrift.transport import TTransport + from thrift.protocol import TBinaryProtocol + + from databricks.sql.backend.thrift_backend import ( + THRIFT_BINARY_PROTOCOL_STRING_LENGTH_LIMIT, + THRIFT_BINARY_PROTOCOL_CONTAINER_LENGTH_LIMIT, + ) + + oversized_payload = b"x" * ( + 20 * 1024 * 1024 + ) # 20 MiB > thrift's ~15.6 MiB default + + write_buffer = TTransport.TMemoryBuffer() + TBinaryProtocol.TBinaryProtocol(write_buffer).writeBinary(oversized_payload) + + read_buffer = TTransport.TMemoryBuffer(write_buffer.getvalue()) + protocol = TBinaryProtocol.TBinaryProtocol( + read_buffer, + string_length_limit=THRIFT_BINARY_PROTOCOL_STRING_LENGTH_LIMIT, + container_length_limit=THRIFT_BINARY_PROTOCOL_CONTAINER_LENGTH_LIMIT, + ) + + self.assertEqual(protocol.readBinary(), oversized_payload) + def test_proxy_headers_are_set(self): from databricks.sql.common.http_utils import create_basic_proxy_auth_headers