plusplusjiajia opened a new pull request, #9929:
URL: https://github.com/apache/paimon/pull/9929

   ### Purpose
   
   `QueryAuthSplit` carries the row filter and the column masks. It implements 
`Split` but is not a
   `DataSplit`, and `AbstractDataTableScan#plan()` wraps every split once a 
table has rules, so
   `ChainGroupReadTable` (3 casts) and `ChainTableStreamScan#groupByPartition` 
throw
   `ClassCastException` on a chain table with rules. #9925 fixed the same 
problem in
   `DataEvolutionBatchScan`.
   
   Chain splits are built from the underlying `DataSplit`s, so the wrapper is 
removed before building
   and put back afterwards. Unwrapping without restoring would drop the rules 
and return unmasked,
   unfiltered rows instead of failing. The chain reads route on what the 
wrapper carries and pass the
   wrapper itself to `fallbackRead`, an `AbstractDataTableRead`, which already 
applies the rules.
   
   Unlike #9925, chain split building merges N branch splits into M chain 
splits, so the result is
   captured from the inputs and re-applied to the outputs rather than rewrapped 
1:1.
   
   `QueryAuthSplit.unwrap` is added as the single place to look through the 
wrapper.
   
   ### Tests
   
   `ChainTableFileStoreTableTest`, 5 cases over a real `CatalogEnvironment` 
with only
   `Catalog#authTableQuery` stubbed. Batch and streaming starting plans keep 
the wrapper with
   `authResult` intact; an end-to-end read returns only the filtered rows with 
the column masked; with
   no rules nothing is wrapped and the rows are unchanged.
   
   Reverting the fix fails 4 of the 5 with the original `ClassCastException`. 
Making the re-apply step
   return unwrapped splits — dropping the rules without crashing — also fails 
4, including the
   end-to-end read returning unmasked rows.
   
   38/38 with `ChainTableDeletionVectorReadTest` and 
`FallbackReadFileStoreTableTest`.
   
   ### Out of scope
   
   `QueryAuthSplit` is also unhandled in the Flink source, 
`HiveSplitGenerator`, and the Spark
   `StreamHelper` / `SplitUtils` path — some fail the cast, some silently drop 
the split. Follow-ups.
   
   `IndexBootstrap` and `AbstractStartingScanner` look affected but are not: 
the former forces
   `query-auth.enabled=false` on the table it scans, the latter runs before 
`convertPlan`.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to