DanielLeens commented on PR #11559: URL: https://github.com/apache/seatunnel/pull/11559#issuecomment-6000009570
@SEZ9 Thanks, both asks are addressed in `8909a67fce2`. 1. **Negative case tightened.** Added `productionDeserializeSplitShouldRejectSamePackageSubclassOutsideAllowlist`, which serializes a `KafkaSourceSplitState`. It is a serializable subclass of the allowlisted `KafkaSourceSplit`, lives in the same package, and its class name even starts with the allowlisted name, so it passes a package-prefix check, a class-name-prefix check and the `instanceof KafkaSourceSplit` guard. Only exact-name matching rejects it. The existing `java.util.HashMap` case is kept, and both now assert the exact rejection message rather than a substring. 2. **No more reflection.** `KafkaSourceReader.deserializeSplit` is now package-private with a Javadoc note that it is exposed only for tests, and the tests call it directly. The reflective helper is removed, and the test Javadoc says not to swap the call for the local plain-`ObjectInputStream` helper, which never reaches the allowlist. The allowlist logic itself (`KafkaGateObjectInputStream.isAllowedClass`) is unchanged; the only production change is the visibility of that one method. On local confirmation: I have not run the tests locally. Verification is the GitHub CI run on this head; it is queued now and I will not claim the tests pass until it finishes. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
