jackylee-ch opened a new pull request, #923:
URL: https://github.com/apache/paimon-rust/pull/923

   `paimon_predicate_and`/`_or`/`_not` dereferenced their input pointers with 
no null check. A leaf constructor returns `{predicate: null, error}` on a bad 
column, non-UTF-8 name, or bad datum, so a caller that composes `x AND y` and 
forwards such a null crashed the host process (SIGSEGV / UB) instead of getting 
a clean null back.
   
   Each combinator now guards its inputs: on a null input it frees any non-null 
sibling — honoring the documented "consumes both inputs" contract, so nothing 
leaks — and returns null. This matches the null tolerance already in 
`paimon_predicate_free` and `paimon_read_builder_with_filter`. The C ABI is 
unchanged.
   
   Added `test_predicate_combinators_reject_null_without_crashing`, which 
segfaults on the pre-fix code and passes after.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to