voonhous opened a new pull request, #19956:
URL: https://github.com/apache/hudi/pull/19956
Trino E2E MOR real-time reads fail while deserializing commit metadata in
HoodieAvroUtils.convertToSpecificRecord with:
SecurityException: Forbidden org.apache.hudi.avro.model.HoodieWriteStat!
This class is not trusted to be included in Avro schemas.
Trino bumped Avro to 1.12.2, which the hudi-trino plugin bundles. In 1.12.2
SpecificData.getClass(Schema) goes through ClassUtils.forName, which runs
ClassSecurityValidator and trusts only a few java.* classes by default, so
Hudi's generated SpecificRecord classes are rejected.
Load the nested record class with Class.forName on
SpecificData.getClassName(schema) using the SpecificData class loader, and fail
with a HoodieException if the class is missing. This is safe: the schema is the
target generated class's compiled SCHEMA$, never a schema read off storage, so
it does not reopen the class-injection vector the validator closes.
Add a commit-metadata round trip with nested write stats to HudiUtilTest in
hudi-trino, which runs on Trino's Avro, guarded by an assertion that
ClassSecurityValidator is on the classpath.
### Describe the issue this Pull Request addresses
<!-- Either describe the issue inline here with motivation behind the
changes
(or) link to an issue by including `Closes #<issue-number>` for
context.
If this PR includes changes to the storage format, public APIs,
or has breaking changes, use `!` (e.g., feat!: ...) -->
### Summary and Changelog
<!-- Short, plain-English summary of what users gain or what changed in
behavior.
Followed by a detailed log of all the changes. Highlight if any code
was copied. -->
### Impact
<!-- Describe any public API or user-facing feature change or any
performance impact. -->
### Risk Level
<!-- Accepted values: none, low, medium or high. Other than `none`, explain
the risk.
If medium or high, explain what verification was done to mitigate the
risks. -->
### Documentation Update
<!-- Describe any necessary documentation update if there is any new
feature, config, or user-facing change. If not, put "none".
- The config description must be updated if new configs are added or the
default value of the configs are changed.
- Any new feature or user-facing change requires updating the Hudi website.
Please follow the
[instruction](https://hudi.apache.org/contribute/developer-setup#website)
to make changes to the website. -->
### Contributor's checklist
- [ ] Read through [contributor's
guide](https://hudi.apache.org/contribute/how-to-contribute)
- [ ] Enough context is provided in the sections above
- [ ] Adequate tests were added if applicable
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]