Skip to content

fix: Do not pass undeclared feature view columns to ODFV UDFs - #6527

Merged
ntkathole merged 2 commits into
feast-dev:masterfrom
Vedant-Agarwal:fix/odfv-source-isolation
Jul 30, 2026
Merged

fix: Do not pass undeclared feature view columns to ODFV UDFs#6527
ntkathole merged 2 commits into
feast-dev:masterfrom
Vedant-Agarwal:fix/odfv-source-isolation

Conversation

@Vedant-Agarwal

Copy link
Copy Markdown
Contributor

What

An OnDemandFeatureView's UDF (pandas and python modes) was receiving every feature column in the online response, including features from feature views that the ODFV did not list in its sources. This allowed a UDF to silently depend on an undeclared source.

This filters the UDF input down to the ODFV's declared sources before the transform runs. Join keys, request-source fields and the declared features are kept; only columns from undeclared feature views are removed. substrait already restricts its inputs through its query plan, so it is left as is.

Fixes #6158.

Tests

Three tests were added in test_on_demand_pandas_transformation.py:

  • pandas mode: the UDF sees its declared feature and the entity join key, but not another requested feature view's column.
  • python mode: the same check with the dict input.
  • two ODFVs: one ODFV's UDF does not see the other ODFV's source column, even when that feature view is present only as the other ODFV's input.

Each of these fails on the current code and passes with this change.

Functional test results:

$ pytest tests/unit/test_on_demand_pandas_transformation.py \
    -k "undeclared or other_requested_odfv"
3 passed in 0.52s

ruff and mypy are clean.

Scope

This covers the online path (get_online_features), which is what the issue reports. The offline path (get_historical_features) has the same shape and can be addressed as a follow-up.

@Vedant-Agarwal
Vedant-Agarwal requested a review from a team as a code owner June 15, 2026 20:56
Comment thread sdk/python/feast/utils.py
# stay. substrait filters on its own, so leave it alone.
declared_source_names = {
projection.name
for projection in odfv.source_feature_view_projections.values()

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

FeatureViewProjection can carry a name_alias or version tag, but these comparisons and column names use .name. For an ODFV sourced from an aliased projection, won’t the alias-qualified input be classified as undeclared while alias__feature also escapes the second filter? Should these use projection.name_to_use() instead?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @Sanjays2402 — fair question, so I verified it against this branch (checked out this PR's head) rather than guess.

With an ODFV sourced from an aliased projection:

aliased = driver_stats.with_name("aliased_stats")
# projection.name = 'driver_stats', name_to_use() = 'aliased_stats'

the columns feeding the transform come through as ['driver_stats__conv_rate', 'conv_rate'].name-qualified, not alias-qualified. That's consistent with how source refs are built throughout on_demand_feature_view.py (f"{source_fv_projection.name}__{feature.name}", e.g. the loops around lines 987/1055/1151/1261). So .name matches the real column names here; switching to name_to_use() would build aliased_stats__conv_rate, which isn't present, and would drop the declared feature.

On version_tag: it's only set via from_proto (there's no user-facing setter), and the retrieval path keys source columns by .name regardless — so even a versioned projection's column is still driver_stats__conv_rate.

I'll add a test with an aliased source to lock this behavior in. If you know a path (offline retrieval?) where the input comes through alias-qualified, point me at it and I'll handle that too — I exercised online retrieval here.

@Vedant-Agarwal
Vedant-Agarwal force-pushed the fix/odfv-source-isolation branch from 73a4b10 to 883dc2d Compare July 21, 2026 21:04
@ntkathole
ntkathole force-pushed the fix/odfv-source-isolation branch from 883dc2d to 797ed12 Compare July 30, 2026 08:52
@ntkathole ntkathole changed the title fix: do not pass undeclared feature view columns to ODFV UDFs fix: Do not pass undeclared feature view columns to ODFV UDFs Jul 30, 2026
@codecov-commenter

codecov-commenter commented Jul 30, 2026

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

❌ Patch coverage is 95.00000% with 1 line in your changes missing coverage. Please review.
✅ Project coverage is 46.40%. Comparing base (3c2ae3c) to head (8bb6764).
⚠️ Report is 3 commits behind head on master.

Files with missing lines Patch % Lines
sdk/python/feast/utils.py 95.00% 0 Missing and 1 partial ⚠️
❗ Your organization needs to install the Codecov GitHub app to enable full functionality.
Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##           master    #6527      +/-   ##
==========================================
+ Coverage   46.37%   46.40%   +0.02%     
==========================================
  Files         414      414              
  Lines       50089    50109      +20     
  Branches     7159     7167       +8     
==========================================
+ Hits        23231    23254      +23     
+ Misses      25231    25228       -3     
  Partials     1627     1627              
Flag Coverage Δ
go-feature-server 30.58% <ø> (ø)
python-unit 47.70% <95.00%> (+0.02%) ⬆️
Files with missing lines Coverage Δ
sdk/python/feast/utils.py 77.57% <95.00%> (+0.63%) ⬆️

... and 1 file with indirect coverage changes


Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 3c2ae3c...8bb6764. Read the comment docs.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

An OnDemandFeatureView's UDF was receiving every feature column in the online response, including features from feature views that the ODFV did not list in its sources. That allowed a UDF to silently depend on an undeclared source.

This filters the UDF input down to the ODFV's declared sources before the transform runs, so columns from undeclared feature views are hidden. Join keys, request data and the declared features are kept. substrait already restricts its inputs through its query plan, so it is left as is.

Fixes feast-dev#6158.

Signed-off-by: Vedant Agarwal <vedantagwl10@gmail.com>
Add a regression test that sources a pandas ODFV from an aliased feature
view (with_name) and asserts the declared feature still reaches the UDF
while an unrelated feature view stays hidden. The isolation filter keys
columns by projection.name, which is what the retrieval path emits
regardless of the alias; the test fails if that is switched to name_to_use().

Signed-off-by: Vedant Agarwal <vedantagwl10@gmail.com>
@ntkathole
ntkathole force-pushed the fix/odfv-source-isolation branch from 797ed12 to 8bb6764 Compare July 30, 2026 11:10
@ntkathole
ntkathole merged commit 75b9463 into feast-dev:master Jul 30, 2026
17 of 22 checks passed
jyejare pushed a commit to opendatahub-io/feast that referenced this pull request Aug 5, 2026
…dev#6527)

* fix: do not pass undeclared feature view columns to ODFV UDFs

An OnDemandFeatureView's UDF was receiving every feature column in the online response, including features from feature views that the ODFV did not list in its sources. That allowed a UDF to silently depend on an undeclared source.

This filters the UDF input down to the ODFV's declared sources before the transform runs, so columns from undeclared feature views are hidden. Join keys, request data and the declared features are kept. substrait already restricts its inputs through its query plan, so it is left as is.

Fixes feast-dev#6158.

Signed-off-by: Vedant Agarwal <vedantagwl10@gmail.com>

* test: cover ODFV source isolation for an aliased source

Add a regression test that sources a pandas ODFV from an aliased feature
view (with_name) and asserts the declared feature still reaches the UDF
while an unrelated feature view stays hidden. The isolation filter keys
columns by projection.name, which is what the retrieval path emits
regardless of the alias; the test fails if that is switched to name_to_use().

Signed-off-by: Vedant Agarwal <vedantagwl10@gmail.com>

---------

Signed-off-by: Vedant Agarwal <vedantagwl10@gmail.com>
franciscojavierarceo pushed a commit that referenced this pull request Aug 21, 2026
# [0.66.0](v0.65.0...v0.66.0) (2026-08-21)

### Bug Fixes

* Add connection pre-warming for DynamoDB async client ([89240fa](89240fa)), closes [#6060](#6060)
* Add remote registry client extra ([#6697](#6697)) ([b8dfcb0](b8dfcb0))
* Address review feedback on FIPS cipher suite configuration ([4a35fba](4a35fba))
* Allow remote-registry first apply for new projects ([39d408d](39d408d))
* Avoid importing feast.feature_store at mcp_server import time ([ddb2e9a](ddb2e9a))
* Bump pymssql to >=2.3.6 for macOS arm64 wheel support ([181eb35](181eb35)), closes [#5636](#5636) [#5193](#5193) [#5636](#5636)
* Call ApplySavedDataset RPC instead of ApplyFeatureService in RemoteRegistry.apply_saved_dataset() ([934d341](934d341))
* Catch missing dbt parser dependency in dbt CLI commands ([#6534](#6534)) ([3c2ae3c](3c2ae3c))
* Default authentication to kubernetes auth ([6a4690a](6a4690a))
* Defer feature-freshness thread to post-fork to avoid Gunicorn deadlock ([#6648](#6648)) ([104ad10](104ad10)), closes [#6647](#6647)
* Do not pass undeclared feature view columns to ODFV UDFs ([#6527](#6527)) ([75b9463](75b9463))
* downgrade mcp pin to 1.29.0 and fix CI lockfiles and unit tests ([98e5bca](98e5bca)), closes [#6706](#6706)
* Feast apply silently ignoring ttl updates to None or timedelta(0) ([#6709](#6709)) ([97b0f25](97b0f25)), closes [#6703](#6703)
* Fix mypy TorchTensor type alias error ([#6712](#6712)) ([34de6fa](34de6fa)), closes [#5563](#5563)
* Fixed data source creation form gaps ([5d0f7d6](5d0f7d6))
* Handle parameterized and complex Trino types in type map ([326554d](326554d))
* Isolate default user permissions ([e37adbf](e37adbf))
* Isolate projection join key maps ([d1c709d](d1c709d))
* Map Postgres real to FLOAT instead of DOUBLE ([62db435](62db435))
* Merge shared ODFV source projections in feature resolution ([d269946](d269946)), closes [#6621](#6621)
* More exhaustive athena types ([a9aaefc](a9aaefc))
* Normalize SQL registry read_path to the psycopg3 driver like path ([#6644](#6644)) ([996c6ea](996c6ea)), closes [#6643](#6643)
* **operator:** add spec.services.onlineStore.disabled to opt out of the online store ([d81d4e3](d81d4e3)), closes [#6586](#6586)
* Preinstall DuckDB delta extension for tests ([fd4d49d](fd4d49d)), closes [#6743](#6743)
* Preserve event-time ordering within Redis online_write_batch ([40fb788](40fb788)), closes [#5163](#5163)
* Prevent mutation of cached feature resolution results ([ea17419](ea17419))
* Remote feastRef FeatureStore fails first apply for a new feastProject ([9affee5](9affee5))
* Remove inert subjectaccessreviews and reorganize RBAC rules ([f771ea4](f771ea4))
* Report single-feature-view spark_application materialization success ([a9219d9](a9219d9)), closes [#6673](#6673)
* Reset the global security manager after the permissions fixture ([7667215](7667215))
* Resolve kserve with pip --dry-run instead of installing it ([01da132](01da132)), closes [#6732](#6732)
* Resolve write_to_offline_store feature view with a single registry lookup ([a42dc85](a42dc85)), closes [#4235](#4235)
* Return False from __eq__ on cross-type comparison ([#6637](#6637)) ([0f149a9](0f149a9)), closes [#6636](#6636)
* Reuse IdP-issued client tokens until near expiry ([602d752](602d752))
* Reuse the OIDC JWKS client across requests ([#6683](#6683)) ([a1e6fc2](a1e6fc2))
* Separate CronJob and feature-server ServiceAccounts ([398f643](398f643))
* Serialize UnixTimestamp proto values as raw int64 in remote online store transport ([1e7134f](1e7134f))
* Set FIPS cipher suites before pyarrow.flight import to prevent crash on IBM Power ([979b82a](979b82a))
* Support Entra ID (Azure AD) token claims in OIDC auth ([#6631](#6631)) ([f843c63](f843c63))
* UDF/ODFV source rehydrate (+ Postgres / online cache) ([#6655](#6655)) ([5fd7af7](5fd7af7))
* Updated projects-list.json in order to display newly added projects ([#6657](#6657)) ([3a6a103](3a6a103))
* Use correct image name in multi-arch imagetools push step ([faf85e0](faf85e0))
* Use join keys instead of entity names in ODFV materialization ([#6645](#6645)) ([abffebc](abffebc)), closes [#5965](#5965)
* use matching proto class per feature view list in SqliteOnlineStore.plan() ([adb8c1c](adb8c1c)), closes [#6658](#6658)
* Widen Athena integer type mapping for unsigned ints ([3425783](3425783))

### Features

* Add ConnectionRef to DataSource for pluggable external credential resolution ([28bde01](28bde01))
* Add Feature Service Create in UI ([0399380](0399380))
* Add hybrid to ValidOfflineStoreDBStorePersistenceTypes for HybridOfflineStore support ([#6707](#6707)) ([310ab51](310ab51)), closes [#6701](#6701)
* Add MLflow integration support to Feast operator ([#6611](#6611)) ([52999f1](52999f1))
* Add opt-in filter_by_created_timestamp cutoff to get_historical_features ([#6617](#6617)) ([79b33ce](79b33ce)), closes [#6615](#6615)
* Add optional OIDC token audience and issuer verification ([#6670](#6670)) ([ef307c6](ef307c6))
* Add packaged feature repository support to Feast Operator ([8112b1e](8112b1e)), closes [#6598](#6598)
* add plan() support to DynamoDBOnlineStore ([51ce982](51ce982)), closes [#6658](#6658) [#6659](#6659)
* Added optional namespace/colleciton to datasets ([165fcf2](165fcf2))
* Added SQL registry schema_mode and registry create command ([#6704](#6704)) ([037c4cd](037c4cd))
* Allow users to have protected project on shared registry ([f9923bc](f9923bc))
* Apply Intermediate TLS defaults on API fallback and handle transient errors ([#6587](#6587)) ([43ae993](43ae993))
* **cli:** Updated feast init demo by adding rag template ([#5946](#5946)) ([c8628eb](c8628eb)), closes [#5264](#5264)
* Expose the OIDC JWKS tunables through the operator ([#6690](#6690)) ([fef4e78](fef4e78)), closes [#6683](#6683)
* Making feast vector store with open ai search api compatible ([#6121](#6121)) ([54da19a](54da19a))
* Multi-arch publish for feast operator image ([b221036](b221036))
* OpenLineage lineage enhancements - full object coverage, richer UI, and API-level sync ([#6719](#6719)) ([120a868](120a868))
* **operator:** Add spec.services.initImage for init container image override ([#6598](#6598)) ([ca355cb](ca355cb))
* Pass optional OIDC audience and issuer through the operator ([#6677](#6677)) ([a13ed7b](a13ed7b)), closes [#6670](#6670)
* **server:** Remote Materialization ([#6649](#6649)) ([b7ae488](b7ae488)), closes [#4526](#4526)
* Support Lineage configs via operator ([bf1e54a](bf1e54a))
* Updated datasets UI to support grouping ([7ae64ec](7ae64ec))
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OnDemandFeatureView (pandas/python mode) UDF receives all response columns, not just declared sources

4 participants