potiuk commented on PR #5020: URL: https://github.com/apache/calcite/pull/5020#issuecomment-5035431457
Thanks @rubenada for driving this and combining the initial drafts. I read both this and #5115 against the threat-model rubric — the normative core (attacker model, P1–P4, the surprising-vs-unsurprising class-loading rule) is the same in both, and #5115 consolidates it a bit tighter: it drops the STRIDE table (which carried a couple of internal tensions — pushed-down SQL injection framed as both in- and out-of-scope, and the Janino/UDF row describing the boundary as input-sanitization rather than the actual class-loading gate), reframes DoS as a hardening goal rather than per-report vulnerabilities, and splits the concrete sink list into a separate living doc. Since you've already offered to move forward with @vlsi's #5115, that reads as the right call to me too — so this one can probably be closed in favor of #5115. I've layered three additive suggestions on top of #5115 — an inputs table, a downstream-responsibilities section, and a closed triage-disposition set — in vlsi/calcite#3, for you both to take or leave. Thanks again for pushing this forward — the model's in good shape. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
