Skip to content

KAFKA-20769: ListDeserializer can silently deserialize a corrupted entry when the input is truncated mid-entry - #22755

Merged
mjsax merged 1 commit into
apache:trunkfrom
SEPURI-SAI-KRISHNA:KAFKA-20769-listdeserializer-truncated-entry
Jul 24, 2026
Merged

mjsax merged 1 commit into
apache:trunkfrom
SEPURI-SAI-KRISHNA:KAFKA-20769-listdeserializer-truncated-entry

Conversation

@SEPURI-SAI-KRISHNA

@SEPURI-SAI-KRISHNA SEPURI-SAI-KRISHNA commented Jul 4, 2026 •

Copy link
Copy Markdown
Contributor

ListDeserializer.deserialize is using DataInputStream.read(byte[]) which
may return "early" if the stream is shorter than expected (ie, cannot
fill the provided byte[] array) w/o error. This can lead to a
corrupted deserialization result.

This PR switches to DataInputStream.readFully, which throws EOFException
when the buffer cannot be filled.

Reviewers: Matthias J. Sax matthias@confluent.io

@github-actions github-actions Bot added triage PRs from the community clients small Small PRs labels Jul 4, 2026
@github-actions

Copy link
Copy Markdown

A label of 'needs-attention' was automatically added to this PR in order to raise the
attention of the committers. Once this issue has been triaged, the triage label
should be removed to prevent this automation from happening again.

@mjsax mjsax added ci-approved and removed triage PRs from the community needs-attention labels Jul 21, 2026
@SEPURI-SAI-KRISHNA
SEPURI-SAI-KRISHNA force-pushed the KAFKA-20769-listdeserializer-truncated-entry branch from e482eac to 1a3711a Compare July 22, 2026 10:49

@mjsax mjsax left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks. Overall LGTM. I would just remove impl specific comments on the unit tests -- if anybody would change back to read() the test would fail and highlight the problem anyway.

@SEPURI-SAI-KRISHNA
SEPURI-SAI-KRISHNA force-pushed the KAFKA-20769-listdeserializer-truncated-entry branch from 1a3711a to 9e322bb Compare July 22, 2026 17:00
@SEPURI-SAI-KRISHNA

Copy link
Copy Markdown
Contributor Author

Thanks @mjsax addressed all the comments: reworded the two test comments to describe the behavior rather than the read/readFully mechanics. Let me know if there's anything else, otherwise this should be good to go.

@mjsax
mjsax merged commit c0579db into apache:trunk Jul 24, 2026
35 of 38 checks passed
mjsax pushed a commit that referenced this pull request Jul 24, 2026
…try when the input is truncated mid-entry (#22755)

ListDeserializer.deserialize is using DataInputStream.read(byte[]) which
may return "early" if the stream is shorter than expected (ie, cannot
fill  the provided `byte[]` array) w/o error. This can lead to a
corrupted  deserialization result.

This PR switches to DataInputStream.readFully, which throws EOFException
when the buffer cannot be filled.

Reviewers: Matthias J. Sax <matthias@confluent.io>
@mjsax

mjsax commented Jul 24, 2026

Copy link
Copy Markdown
Member

Thanks for the fix. Merged to trunk and cherry-picked to 4.3 and 4.2 branches.

mjsax pushed a commit that referenced this pull request Jul 24, 2026
…try when the input is truncated mid-entry (#22755)

ListDeserializer.deserialize is using DataInputStream.read(byte[]) which
may return "early" if the stream is shorter than expected (ie, cannot
fill  the provided `byte[]` array) w/o error. This can lead to a
corrupted  deserialization result.

This PR switches to DataInputStream.readFully, which throws EOFException
when the buffer cannot be filled.

Reviewers: Matthias J. Sax <matthias@confluent.io>
nileshkumar3 pushed a commit to nileshkumar3/kafka that referenced this pull request Jul 25, 2026
…try when the input is truncated mid-entry (apache#22755)

ListDeserializer.deserialize is using DataInputStream.read(byte[]) which
may return "early" if the stream is shorter than expected (ie, cannot
fill  the provided `byte[]` array) w/o error. This can lead to a
corrupted  deserialization result.

This PR switches to DataInputStream.readFully, which throws EOFException
when the buffer cannot be filled.

Reviewers: Matthias J. Sax <matthias@confluent.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

Sponsor
SponsoredKunjungi sekarang
Promo