jackylee-ch commented on PR #941:
URL: https://github.com/apache/paimon-rust/pull/941#issuecomment-5943284860

   Addressed.
   
   **[P1] Validate each logical name before existence/deletion.** 
`proc_delete_branch` now calls the shared `BranchManager::validate_branch_name` 
on each comma-separated name *before* the configured-branch guard and before 
`branch_exists`/`drop_branch`. That validator now delegates to the 
catalog/table reader contract (rejects blank, `.`/`..`, path separators and 
control characters) and keeps the manager's main/numeric rules. So `branch => 
'prod/schema'` is rejected up front instead of slipping past the literal `prod` 
comparison and recursively deleting `branch-prod/schema`.
   
   Regression `test_delete_branch_rejects_path_separated_name`: with 
`scan.primary-branch='prod'` and a real `prod` branch, `CALL 
sys.delete_branch(..., branch => 'prod/schema')` fails, `prod` stays in 
`$branches`, and `table.copy_with_branch("prod")` still opens it. Unit coverage 
`test_validate_branch_name_rejects_reader_unopenable_names` pins 
`.`/`..`/separator/control-char rejection. I verified non-vacuity: dropping the 
pre-validation makes the `prod/schema` deletion succeed and the test fail; 
restoring it passes.
   
   Normal deletion and the sequential batch semantics are unchanged. Rebased 
onto current main. `procedures` (36 tests) and `branch_manager` (20 tests) 
pass; `clippy -p paimon -p paimon-datafusion --all-targets --features 
fulltext,vortex -D warnings` is clean.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to