voonhous opened a new pull request, #19956:
URL: https://github.com/apache/hudi/pull/19956

   Trino E2E MOR real-time reads fail while deserializing commit metadata in 
HoodieAvroUtils.convertToSpecificRecord with:
   SecurityException: Forbidden org.apache.hudi.avro.model.HoodieWriteStat! 
This class is not trusted to be included in Avro schemas.
   
   Trino bumped Avro to 1.12.2, which the hudi-trino plugin bundles. In 1.12.2 
SpecificData.getClass(Schema) goes through ClassUtils.forName, which runs 
ClassSecurityValidator and trusts only a few java.* classes by default, so 
Hudi's generated SpecificRecord classes are rejected.
   
   Load the nested record class with Class.forName on 
SpecificData.getClassName(schema) using the SpecificData class loader, and fail 
with a HoodieException if the class is missing. This is safe: the schema is the 
target generated class's compiled SCHEMA$, never a schema read off storage, so 
it does not reopen the class-injection vector the validator closes.
   
   Add a commit-metadata round trip with nested write stats to HudiUtilTest in 
hudi-trino, which runs on Trino's Avro, guarded by an assertion that 
ClassSecurityValidator is on the classpath.
   
   ### Describe the issue this Pull Request addresses
   
   <!-- Either describe the issue inline here with motivation behind the 
changes 
        (or) link to an issue by including `Closes #<issue-number>` for 
context. 
        If this PR includes changes to the storage format, public APIs,
        or has breaking changes, use `!` (e.g., feat!: ...) -->
   
   ### Summary and Changelog
   
   <!-- Short, plain-English summary of what users gain or what changed in 
behavior.
        Followed by a detailed log of all the changes. Highlight if any code 
was copied. -->
   
   ### Impact
   
   <!-- Describe any public API or user-facing feature change or any 
performance impact. -->
   
   ### Risk Level
   
   <!-- Accepted values: none, low, medium or high. Other than `none`, explain 
the risk.
        If medium or high, explain what verification was done to mitigate the 
risks. -->
   
   ### Documentation Update
   
   <!-- Describe any necessary documentation update if there is any new 
feature, config, or user-facing change. If not, put "none".
   
   - The config description must be updated if new configs are added or the 
default value of the configs are changed.
   - Any new feature or user-facing change requires updating the Hudi website. 
Please follow the 
     [instruction](https://hudi.apache.org/contribute/developer-setup#website) 
to make changes to the website. -->
   
   ### Contributor's checklist
   
   - [ ] Read through [contributor's 
guide](https://hudi.apache.org/contribute/how-to-contribute)
   - [ ] Enough context is provided in the sections above
   - [ ] Adequate tests were added if applicable
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to