KAFKA-20769: ListDeserializer can silently deserialize a corrupted entry when the input is truncated mid-entry - #22755
Merged
mjsax merged 1 commit intoJul 24, 2026
Conversation
|
A label of 'needs-attention' was automatically added to this PR in order to raise the |
mjsax
reviewed
Jul 21, 2026
SEPURI-SAI-KRISHNA
force-pushed
the
KAFKA-20769-listdeserializer-truncated-entry
branch
from
July 22, 2026 10:49
e482eac to
1a3711a
Compare
mjsax
reviewed
Jul 22, 2026
mjsax
reviewed
Jul 22, 2026
mjsax
reviewed
Jul 22, 2026
mjsax
reviewed
Jul 22, 2026
mjsax
left a comment
Member
There was a problem hiding this comment.
Thanks. Overall LGTM. I would just remove impl specific comments on the unit tests -- if anybody would change back to read() the test would fail and highlight the problem anyway.
…try when the input is truncated mid-entry
SEPURI-SAI-KRISHNA
force-pushed
the
KAFKA-20769-listdeserializer-truncated-entry
branch
from
July 22, 2026 17:00
1a3711a to
9e322bb
Compare
Contributor
Author
|
Thanks @mjsax addressed all the comments: reworded the two test comments to describe the behavior rather than the read/readFully mechanics. Let me know if there's anything else, otherwise this should be good to go. |
mjsax
approved these changes
Jul 22, 2026
mjsax
pushed a commit
that referenced
this pull request
Jul 24, 2026
…try when the input is truncated mid-entry (#22755) ListDeserializer.deserialize is using DataInputStream.read(byte[]) which may return "early" if the stream is shorter than expected (ie, cannot fill the provided `byte[]` array) w/o error. This can lead to a corrupted deserialization result. This PR switches to DataInputStream.readFully, which throws EOFException when the buffer cannot be filled. Reviewers: Matthias J. Sax <matthias@confluent.io>
Member
|
Thanks for the fix. Merged to |
mjsax
pushed a commit
that referenced
this pull request
Jul 24, 2026
…try when the input is truncated mid-entry (#22755) ListDeserializer.deserialize is using DataInputStream.read(byte[]) which may return "early" if the stream is shorter than expected (ie, cannot fill the provided `byte[]` array) w/o error. This can lead to a corrupted deserialization result. This PR switches to DataInputStream.readFully, which throws EOFException when the buffer cannot be filled. Reviewers: Matthias J. Sax <matthias@confluent.io>
nileshkumar3
pushed a commit
to nileshkumar3/kafka
that referenced
this pull request
Jul 25, 2026
…try when the input is truncated mid-entry (apache#22755) ListDeserializer.deserialize is using DataInputStream.read(byte[]) which may return "early" if the stream is shorter than expected (ie, cannot fill the provided `byte[]` array) w/o error. This can lead to a corrupted deserialization result. This PR switches to DataInputStream.readFully, which throws EOFException when the buffer cannot be filled. Reviewers: Matthias J. Sax <matthias@confluent.io>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
ListDeserializer.deserialize is using DataInputStream.read(byte[]) which
may return "early" if the stream is shorter than expected (ie, cannot
fill the provided
byte[]array) w/o error. This can lead to acorrupted deserialization result.
This PR switches to DataInputStream.readFully, which throws EOFException
when the buffer cannot be filled.
Reviewers: Matthias J. Sax matthias@confluent.io