Repository navigation
docs: add DataFusion security guidance - #26064
Conversation
|
@efegokdemir can you please confirm that you have reviewed the description and documentation of this PR? The description seems like it may be unreviewed LLM output -- for example this line seems unrelated to this PR (and you can install it if you follow the README directions).
|
|
We are working on better AI policies |
|
I reviewed the PR description and the new documentation page. I removed the unrelated Sphinx installation note from the testing section and retained only the documentation check that was run. AI assistance is disclosed in the PR description. |
|
@efegokdemir The description of the PR not renders correctly after last update. |
alamb
left a comment
There was a problem hiding this comment.
Thank you @efegokdemir -- this is looking close, I left some suggestions
|
Updated in |
alamb
left a comment
There was a problem hiding this comment.
Looks good -- thank you @efegokdemir
Signed-off-by: Efe Gökdemir <gokdemirefe1903@gmail.com>
|
Fixed the Sphinx reference warning in |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #26064 +/- ##
==========================================
+ Coverage 82.69% 82.74% +0.05%
==========================================
Files 1147 1147
Lines 447204 449767 +2563
Branches 447204 449767 +2563
==========================================
+ Hits 369793 372154 +2361
+ Misses 55001 54944 -57
- Partials 22410 22669 +259 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
Thank you @efegokdemir and @samueleresca |
Which issue does this PR close?
Rationale for this change
Applications embedding DataFusion may accept SQL from users, but the library guide does not explain security-relevant defaults or how available controls contribute to hardening.
What changes are included in this PR?
Adds a library guide covering SQL statement restrictions, opt-in local-file access, query memory limits, spill storage location and size limits, and the authorization and isolation responsibilities of the hosting application.
What is the testing strategy for this PR?
./ci/scripts/doc_prettier_check.sh(passed after the documentation update).Are there any user-facing changes?
Adds a “Securing DataFusion” page to the Library User Guide and links it from the guide and documentation navigation. The page now explains that memory limits do not cap spill disk use and names the runtime settings for controlling temporary storage.
AI assistance was used in preparing this contribution.