jackylee-ch commented on PR #942:
URL: https://github.com/apache/paimon-rust/pull/942#issuecomment-5911086098

   Addressed. `BranchManager::validate_branch_name` now rejects a target name 
containing `/` or `\` at the shared validation boundary, so `rename_branch` 
(and `create_branch`/`create_branch_from_tag`) fail before any snapshot or 
schema file is moved and the source branch is left intact. Your reproducer now 
returns the path-separator error instead of silently relocating the branch 
under `branch-foo/bar`.
   
   On the `..` path component: rejecting `/` and `\` already precludes it. A 
branch name is placed at the single path segment `branch-<name>`, so with no 
separator allowed the name can never introduce a new segment, and `..` can only 
act as a traversal component when it stands alone between separators. A literal 
name like `..` maps to the ordinary directory `branch-..`, which stays 
discoverable and cannot escape `branch/`. I deliberately did not blanket-reject 
the `..` substring, since that would also reject legitimate names such as 
`v1..v2`.
   
   Added the SQL regression `test_rename_branch_rejects_path_separator`: after 
creating `b1`, `CALL sys.rename_branch(table => 'test_db.t1', from_branch => 
'b1', to_branch => 'foo/bar')` fails with the path-separator error, `b1` is 
still listed by `t1$branches`, and no `foo/bar` branch is produced. The guard 
fires before the filesystem is touched, so it holds whether or not a `foo` 
parent branch already exists. I verified the test is non-vacuous: neutering the 
check makes the rename return `Ok` and the test fail with "expected error, got 
Ok"; restoring it passes.
   
   The `validate_branch_name` hardening is the same one-line boundary shared 
with #939 and #941; whichever lands first, the others rebase cleanly by 
dropping the duplicate commit. Rebased onto current main. `procedures` (34 
tests) and `branch_manager` (18 tests) pass; `clippy -p paimon -p 
paimon-datafusion --all-targets -D warnings` is clean.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to