Skip to content

[format] Validate ORC stripe metadata before reading - #9828

Merged
JingsongLi merged 1 commit into
apache:masterfrom
ArnavBalyan:arnavb/orc-val
Sep 15, 2026
Merged

JingsongLi merged 1 commit into
apache:masterfrom
ArnavBalyan:arnavb/orc-val

Conversation

@ArnavBalyan

Copy link
Copy Markdown
Member

Purpose

  • Paimon reads ORC offset and length metadata without validating values.
  • Malformed stripe metadata can cause read failure due to invalid memory access/out of bound exception.
  • Port ORC-2200 to ensure a clean fix exists on Paimon side.

Tests

  • UT

@JingsongLi JingsongLi left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requirement fit: SUPPORTED. Implementation: CLEAN.

Reviewed e850bb151966. The validation is on the actual ORC stripe-read path, before the footer read/allocation. Rejecting negative, overflowing and out-of-file metadata has practical failure-containment value. The checks are consistent with the upstream ORC-2200 change (apache/orc#2683).

Validation: compiled the changed Java code against cached dependencies and ran RecordReaderImplTest (2 passed). Current head CI is green. A malformed-file round trip through Paimon was not run locally.

No actionable implementation regression found in this review.

@JingsongLi
JingsongLi merged commit 1c894da into apache:master Sep 15, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants