Skip to content

Conversation

@aaneja
Copy link
Contributor

@aaneja aaneja commented Oct 30, 2025

for access control checks

Motivation and Context

This is a partial fix for #26466

Impact

UPDATE, DELETE and ANALYZE queries will have their relevant columns passed to the SAC APIs
Without this, empty column lists were being passed

Test Plan

New unit test added

Contributor checklist

  • Please make sure your submission complies with our contributing guide, in particular code style and commit standards.
  • PR description addresses the issue accurately and concisely. If the change is non-trivial, a GitHub Issue is referenced.
  • Documented new properties (with its default value), SQL syntax, functions, or other functionality.
  • If release notes are required, they follow the release notes guidelines.
  • Adequate tests were added if applicable.
  • CI passed.
  • If adding new dependencies, verified they have an OpenSSF Scorecard score of 5.0 or higher (or obtained explicit TSC approval for lower scores).

Release Notes

== NO RELEASE NOTE ==
…nd ANALYZE queries

for access control checks
@prestodb-ci prestodb-ci added the from:IBM PR from IBM label Oct 30, 2025
@prestodb-ci prestodb-ci requested review from a team, pramodsatya and sh-shamsan and removed request for a team October 30, 2025 15:41
@sourcery-ai
Copy link
Contributor

sourcery-ai bot commented Oct 30, 2025

Reviewer's Guide

This PR enhances the UtilizedColumnsAnalyzer to treat UPDATE, DELETE, and ANALYZE statements as unsupported AST nodes—triggering a fallback that includes all table columns in access control checks—and updates the unit tests to cover this fallback behavior and properly merge column references.

Sequence diagram for fallback column utilization in UPDATE, DELETE, ANALYZE

sequenceDiagram
    participant "UtilizedColumnsAnalyzer"
    participant "SAC API"
    participant "Table"
    "UtilizedColumnsAnalyzer"->>"Table": Detect UPDATE/DELETE/ANALYZE node
    "UtilizedColumnsAnalyzer"->>"Table": Retrieve all columns
    "UtilizedColumnsAnalyzer"->>"SAC API": Pass all columns for access control check
    "SAC API"-->>"UtilizedColumnsAnalyzer": Access control result
Loading

Class diagram for updated UtilizedColumnsAnalyzer node handling

classDiagram
    class UtilizedColumnsAnalyzer {
        +visitUpdate(node, context)
        +visitDelete(node, context)
        +visitAnalyze(node, context)
        +notSupportedNode(node)
        handleRelation(relation, context, children)
    }
    UtilizedColumnsAnalyzer : visitUpdate() calls notSupportedNode()
    UtilizedColumnsAnalyzer : visitDelete() calls notSupportedNode()
    UtilizedColumnsAnalyzer : visitAnalyze() calls notSupportedNode()
    UtilizedColumnsAnalyzer : notSupportedNode() throws NotSupportedException
    class NotSupportedException
    UtilizedColumnsAnalyzer --> NotSupportedException
Loading

File-Level Changes

Change Details Files
Handle UPDATE/DELETE/ANALYZE as unsupported nodes to trigger fallback to all columns
  • override visitUpdate to delegate to notSupportedNode
  • override visitDelete to delegate to notSupportedNode
  • override visitAnalyze to delegate to notSupportedNode
  • extract fallback logic into notSupportedNode throwing NotSupportedException
presto-main-base/src/main/java/com/facebook/presto/sql/analyzer/UtilizedColumnsAnalyzer.java
Add unit test verifying fallback to all columns for unsupported nodes
  • introduce testFallsBackToAllColumnsForUnsupportedNodes covering UPDATE, DELETE, ANALYZE cases
  • define expected column sets for simple and nested queries
  • invoke assertUtilizedTableColumns to assert fallback behavior
presto-main-base/src/test/java/com/facebook/presto/sql/analyzer/TestUtilizedColumnsAnalyzer.java
Adjust assertion logic to merge utilized column references correctly
  • replace direct assertEquals on raw map with mergedMap computation using streams
  • implement merging of nested maps and sets to consolidate duplicate entries
  • update final assertEquals to compare mergedMap against expected
presto-main-base/src/test/java/com/facebook/presto/sql/analyzer/TestUtilizedColumnsAnalyzer.java

Possibly linked issues


Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

Copy link
Contributor

@sourcery-ai sourcery-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey there - I've reviewed your changes and they look great!


Sourcery is free for open source - if you like our reviews please consider sharing them ✨
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.
@aaneja aaneja changed the title fix(analyzer) : Default to utilizing all columns for UPDATE, DELETE and ANALYZE queries Oct 30, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

from:IBM PR from IBM

2 participants