potiuk commented on PR #73625: URL: https://github.com/apache/airflow/pull/73625#issuecomment-5985166858
You're partially right, thanks for pushing on this. The API server doesn't run the full serde for XCom any more: the XCom read path uses `stringify()` (falling back to the JSON decoder), never `airflow.sdk.serde.deserialize`. The problematic use was indeed elsewhere — in the triggerer, when the stored `next_kwargs` are decoded (`models/trigger.py`), along with the back-compat `next_kwargs` conversion. Two other PRs remove exactly that: #73576 adds the resume event to the stored `next_kwargs` without decoding them, and #73577 rebuilds only built-in value types when converting `next_kwargs`. With those in, `DeltaTable` / Iceberg deserialization only happens where Dag-author code already runs, so gating it behind an allow-list doesn't protect a real boundary. I'm closing this in favour of #73576 and #73577. --- Drafted-by: Claude Code (Opus 5); reviewed by @potiuk before posting -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
