Copilot commented on code in PR #3861:
URL: https://github.com/apache/avro/pull/3861#discussion_r3565214952


##########
lang/py/avro/io.py:
##########
@@ -214,11 +222,34 @@ def read(self, n: int) -> bytes:
         """
         if n < 0:
             raise avro.errors.InvalidAvroBinaryEncoding(f"Requested {n} bytes 
to read, expected positive integer.")
+        if n > self._MAX_UNCHECKED_READ:
+            remaining = self.bytes_remaining()
+            if remaining is not None and n > remaining:
+                raise avro.errors.InvalidAvroBinaryEncoding(f"Requested {n} 
bytes to read, but only {remaining} remain.")
         read_bytes = self.reader.read(n)
         if len(read_bytes) != n:
             raise avro.errors.InvalidAvroBinaryEncoding(f"Read 
{len(read_bytes)} bytes, expected {n} bytes")
         return read_bytes
 
+    def bytes_remaining(self) -> Optional[int]:
+        """
+        Return the number of bytes still available to read, or ``None`` when
+        that count is not known (a non-seekable reader, or one whose position
+        cannot be obtained). Used to reject a declared length or collection
+        block count that exceeds the data actually available before allocating
+        for it.
+        """
+        reader = self.reader
+        try:
+            pos = reader.tell()
+            reader.seek(0, os.SEEK_END)
+            end = reader.tell()
+            reader.seek(pos)
+        except (OSError, ValueError, AttributeError):
+            # Not seekable, or the position/size could not be determined.
+            return None
+        return end - pos

Review Comment:
   `bytes_remaining()` can leave the underlying reader positioned at EOF if an 
exception occurs after `seek(0, SEEK_END)` (e.g., `tell()` or the restore 
`seek(pos)` fails). That can corrupt subsequent decoding. Also, the function 
assumes `tell()` returns an `int`; if it returns a non-int sentinel, `end - 
pos` will raise `TypeError`. Consider restoring the original position in a 
`finally` block and validating `pos`/`end` types before subtracting.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to