Skip to content

Reject oversized GROUPING masks during analysis #26135

Description

@alexandrefimov

Describe the bug

GROUPING can panic during analysis of GROUPING SETS with 65 distinct grouping columns, even when GROUPING has only one argument.

The analyzer constructs the mask using 1 << group_by_idx. A column at bit 64 causes a shift overflow in a checked build. The physical grouping-set representation already has a 64-bit capacity limit.

To reproduce

Generate the SQL below and run its output in a debug DataFusion CLI:

n = 65
cols = ", ".join(f"c{i} INTEGER" for i in range(n))
keys = ", ".join(f"c{i}" for i in range(n))
row = ", ".join(str(i + 1) for i in range(n))
print(f"CREATE TABLE wide_keys ({cols});")
print(f"INSERT INTO wide_keys VALUES ({row});")
print(f"SELECT GROUPING(c0), COUNT(*) FROM wide_keys "
      f"GROUP BY GROUPING SETS (({keys}), ());")

Expected behavior

Return NotImplemented before constructing an unrepresentable grouping-set mask. Ordinary GROUP BY with 65 columns should continue to allow GROUPING to return zero.

Additional context

Reproduced through core API regression tests on commit 1fa378d380fa7e494aae1085945f8b048e9376c3.

Activity

  1. aryan9948 commented on Oct 8, 2026

    @aryan9948

    Hi @alexandrefimov, I'd like to work on this issue. I saw that you already have a fix and regression tests prepared locally. If the issue is still available, I'd be happy to take it up and work on the fix/tests. Could you assign it to me?

  2. changed the title [-]GROUPING can panic with 65 grouping columns[/-] [+]Reject oversized GROUPING masks during analysis[/+] on Oct 8, 2026
  3. alexandrefimov commented on Oct 8, 2026

    @alexandrefimov
    ContributorAuthor

    A fix is already in PR #26137. Thanks for offering to help.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions