DanielLeens commented on PR #11559:
URL: https://github.com/apache/seatunnel/pull/11559#issuecomment-5661795757

   Both covered:
   
   **1. File unchanged since `4d75844b4a`.** Confirmed — diffed 
`KafkaSourceReader.java` between `4d75844b4a` and the current head `8aff28b16c` 
and it's byte-for-byte identical (empty diff). Neither `2ab2851f03d` nor the 
subsequent dev sync touched it.
   
   **2. Test coverage for the allowlist.** There wasn't one — I checked, and 
the existing round-trip assertions in `KafkaSourceReaderGateTest` 
(`stagedSplitsShouldBeDeduplicatedBySplitId`, 
`snapshotGateAfterOpenShouldPreserveActivatedSplitsAndNoMoreSplits`) go through 
that test class's own private `deserializeSplit` helper, which uses a plain 
`ObjectInputStream` — they're testing the gate-staging/dedup logic, not the 
production allowlist, and never actually exercise 
`KafkaGateObjectInputStream.resolveClass` at all.
   
   Pushed `e2f3eb344f` adding two tests that invoke the real (private, static) 
`KafkaSourceReader.deserializeSplit` reflectively:
   - `productionDeserializeSplitShouldRoundTripKafkaSourceSplit` — positive 
round-trip of a real `KafkaSourceSplit` through the actual production method.
   - `productionDeserializeSplitShouldRejectClassOutsideAllowlist` — serializes 
a `java.util.HashMap` (a real `Serializable` class outside the allowlist) and 
asserts the call throws `IOException` naming the rejected class.
   
   That locks the exact-name allowlist in so a future refactor that widens it 
back to a prefix check fails a test instead of silently reopening the surface.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to