jackylee-ch opened a new pull request, #9991: URL: https://github.com/apache/paimon/pull/9991
### Purpose `deserialize` pointed a `BinaryRow` of `numFields` fields at a buffer of whatever length the stream asked for. Below the fixed-length part, fields fall outside the buffer, and `MemorySegment.getLong` is a bare `UNSAFE.getLong`: a 3-field row whose length prefix I rewrote from 32 to 24 deserialized with no error and returned `1` for the field written as `-7`. A serialized row is at least its fixed-length part, so a shorter length is now an `IOException` — checked, so the sort buffer still deletes its spill channel, and not `EOFException`, which `SimpleObjectsCache` reads as end-of-list. This is the read path behind every `ObjectSerializer`, so it covers commit messages and manifests, not just spill files. Still unbounded above; `DataInputView` has no remaining-byte count to bound it. `mapFromPages` is unchanged — `checkSkipReadForFixLengthPart` already keeps that read in the page. ### Tests `BinaryRowSerializerLengthTest`. Reverting the check: ``` Tests run: 3, Failures: 3 java.lang.NegativeArraySizeException: -1 Expecting code to raise a throwable. ``` `paimon-common`: 12903 run, 0 failures. `paimon-core`: 5611 run, 0 failures. One comparison against a final field; no measurement taken. Written with Claude Code; verification is mine. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
