hechao-ustc opened a new pull request, #545:
URL: https://github.com/apache/paimon-rust/pull/545

   <!--
   Thank you very much for contributing to Paimon Rust - we are happy that you 
want to help us improve it. To help the community review your contribution in 
the best possible way, please go through the checklist below, which will get 
the contribution into a shape in which it can be best reviewed.
   
   ## Contribution Checklist
   
     - Make sure that the pull request corresponds to a [GitHub 
issue](https://github.com/apache/paimon-rust/issues). Exceptions are made for 
typos in documentation or comments, which need no issue.
   
     - Fill out the template below to describe the changes contributed by the 
pull request. That will give reviewers the context they need to do the review.
   
     - Make sure that the change passes the automated tests, i.e., `cargo test` 
passes.
   
     - Each pull request should address only one issue, not mix up code from 
multiple issues.
   
   **(The sections below can be removed for hotfixes or typos)**
   -->
   
   ### Purpose
   
   <!-- Linking this pull request to the issue -->
   `read_timestamp_value` performs unchecked multiplication `(* 1_000 / * 
1_000_000)` on the millis value read from `.row` files when converting to 
microsecond or nanosecond precision. A corrupt or malicious file can supply an 
arbitrary i64 (e.g. `i64::MAX`), causing a panic in debug builds or silent 
wrapping in release builds. This PR replaces bare arithmetic with checked_mul + 
checked_add, returning `Error::DataInvalid` on overflow.
   
   <!-- What is the purpose of the change -->
   
   ### Brief change log
   - Microsecond and Nanosecond arms of read_timestamp_value: replaced bare 
operators with `checked_mul` + `checked_add` + `ok_or_else`,  returning 
`DataInvalid` with millis and nanos context on overflow 
   
   <!-- Please describe the changes made in this pull request and explain how 
they address the issue -->
   
   ### Tests
   
   <!-- List unit tests or integration cases to verify this change -->
   - `cargo clippy --all-targets --workspace --features fulltext,vortex -- -D 
warnings`
   - `cargo test -p paimon --all-targets --features fulltext,vortex`
   
   ### API and Format
   
   <!-- Does this change affect API or storage format -->
   
   ### Documentation
   
   <!-- Does this change introduce a new feature or require documentation 
updates -->
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to