This is an automated email from the ASF dual-hosted git repository.
rubenada pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/calcite-site.git
The following commit(s) were added to refs/heads/main by this push:
new d1c1a5408 Add security threat model
d1c1a5408 is described below
commit d1c1a54082b7d1069297363c0cf2399af111b7d4
Author: Ruben Quesada Lopez <[email protected]>
AuthorDate: Thu Jul 30 11:02:11 2026 +0100
Add security threat model
---
docs/adapter.html | 20 +
docs/algebra.html | 20 +
docs/arrow_adapter.html | 23 ++
docs/babel_reference.html | 23 ++
docs/cassandra_adapter.html | 23 ++
docs/druid_adapter.html | 23 ++
docs/elasticsearch_adapter.html | 23 ++
docs/file_adapter.html | 23 ++
docs/geode_adapter.html | 23 ++
docs/history.html | 25 +-
docs/howto.html | 22 +-
docs/index.html | 20 +
docs/innodb_adapter.html | 23 ++
docs/kafka_adapter.html | 23 ++
docs/lattice.html | 20 +
docs/materialized_views.html | 20 +
docs/model.html | 20 +
docs/os_adapter.html | 23 ++
docs/pig_adapter.html | 23 ++
docs/powered_by.html | 23 ++
docs/redis_adapter.html | 23 ++
docs/reference.html | 20 +
docs/security_threat_model.html | 846 ++++++++++++++++++++++++++++++++++++++++
docs/spatial.html | 20 +
docs/stream.html | 20 +
docs/tutorial.html | 20 +
26 files changed, 1390 insertions(+), 2 deletions(-)
diff --git a/docs/adapter.html b/docs/adapter.html
index 70360b924..89250c773 100644
--- a/docs/adapter.html
+++ b/docs/adapter.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -1020,6 +1022,24 @@ is computed only once.</p>
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/algebra.html b/docs/algebra.html
index 9d818ef03..cb09ece54 100644
--- a/docs/algebra.html
+++ b/docs/algebra.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -1329,6 +1331,24 @@ call and then call its <code class="language-plaintext
highlighter-rouge">over()
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/arrow_adapter.html b/docs/arrow_adapter.html
index c2b608712..8ec669e2a 100644
--- a/docs/arrow_adapter.html
+++ b/docs/arrow_adapter.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -206,6 +208,9 @@ a table called <code class="language-plaintext
highlighter-rouge">test</code>.</
+
+
+
@@ -396,6 +401,24 @@ a table called <code class="language-plaintext
highlighter-rouge">test</code>.</
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/babel_reference.html b/docs/babel_reference.html
index 0545c7f27..c4f83a2a4 100644
--- a/docs/babel_reference.html
+++ b/docs/babel_reference.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -265,6 +267,9 @@ form. This grammar covers only the modified or added
statements in Calcite’s b
+
+
+
@@ -455,6 +460,24 @@ form. This grammar covers only the modified or added
statements in Calcite’s b
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/cassandra_adapter.html b/docs/cassandra_adapter.html
index 2d12ecb81..e250cd97f 100644
--- a/docs/cassandra_adapter.html
+++ b/docs/cassandra_adapter.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -231,6 +233,9 @@ prove useful.</p>
+
+
+
@@ -421,6 +426,24 @@ prove useful.</p>
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/druid_adapter.html b/docs/druid_adapter.html
index 3f1835cde..0dfff8d5d 100644
--- a/docs/druid_adapter.html
+++ b/docs/druid_adapter.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -407,6 +409,9 @@ and the two tables in Druid (<code
class="language-plaintext highlighter-rouge">
+
+
+
@@ -597,6 +602,24 @@ and the two tables in Druid (<code
class="language-plaintext highlighter-rouge">
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/elasticsearch_adapter.html b/docs/elasticsearch_adapter.html
index d8f71b9ce..91cd1f346 100644
--- a/docs/elasticsearch_adapter.html
+++ b/docs/elasticsearch_adapter.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -268,6 +270,9 @@ Also, types are not supported (this adapter only supports
indices).</p>
+
+
+
@@ -458,6 +463,24 @@ Also, types are not supported (this adapter only supports
indices).</p>
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/file_adapter.html b/docs/file_adapter.html
index f7157d03f..efe1aa843 100644
--- a/docs/file_adapter.html
+++ b/docs/file_adapter.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -453,6 +455,9 @@ files) and being able to form URLs dynamically to push down
filters.</p>
+
+
+
@@ -643,6 +648,24 @@ files) and being able to form URLs dynamically to push
down filters.</p>
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/geode_adapter.html b/docs/geode_adapter.html
index bdfd8fc3e..09533d741 100644
--- a/docs/geode_adapter.html
+++ b/docs/geode_adapter.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -297,6 +299,9 @@ prove useful.</p>
+
+
+
@@ -487,6 +492,24 @@ prove useful.</p>
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/history.html b/docs/history.html
index 28c1f155a..6b3d97309 100644
--- a/docs/history.html
+++ b/docs/history.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -13053,6 +13055,9 @@ conflicts in multithreaded usage</li>
+
+
+
@@ -13062,7 +13067,7 @@ conflicts in multithreaded usage</li>
- <a href="/docs/howto.html" class="prev">Previous</a>
+ <a href="/docs/security_threat_model.html"
class="prev">Previous</a>
</div>
<div class="right align-left">
@@ -13263,6 +13268,24 @@ conflicts in multithreaded usage</li>
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/howto.html b/docs/howto.html
index 2150157c5..8b29aa556 100644
--- a/docs/howto.html
+++ b/docs/howto.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -1334,7 +1336,7 @@ Best regards,
- <a href="/docs/history.html" class="next">Next</a>
+ <a href="/docs/security_threat_model.html" class="next">Next</a>
</div>
</div>
@@ -1526,6 +1528,24 @@ Best regards,
<li class="current"><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/index.html b/docs/index.html
index e5d05920b..555857469 100644
--- a/docs/index.html
+++ b/docs/index.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -425,6 +427,24 @@ more details in the <a href="reference.html">SQL
reference</a>
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/innodb_adapter.html b/docs/innodb_adapter.html
index cd60bade1..1834e472a 100644
--- a/docs/innodb_adapter.html
+++ b/docs/innodb_adapter.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -479,6 +481,9 @@ leveraging cost based optimization.</p>
+
+
+
@@ -669,6 +674,24 @@ leveraging cost based optimization.</p>
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/kafka_adapter.html b/docs/kafka_adapter.html
index 533e851b9..b6f26c1b8 100644
--- a/docs/kafka_adapter.html
+++ b/docs/kafka_adapter.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -230,6 +232,9 @@ sqlline> <span class="o">!</span>connect
jdbc:calcite:model<span class="o">=<
+
+
+
@@ -420,6 +425,24 @@ sqlline> <span class="o">!</span>connect
jdbc:calcite:model<span class="o">=<
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/lattice.html b/docs/lattice.html
index 209dbbd41..141cf7040 100644
--- a/docs/lattice.html
+++ b/docs/lattice.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -655,6 +657,24 @@ data is changed.</li>
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/materialized_views.html b/docs/materialized_views.html
index d3a2a9be2..bace4ae86 100644
--- a/docs/materialized_views.html
+++ b/docs/materialized_views.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -662,6 +664,24 @@ Additionally, the rule can rewrite expressions rooted at
an Aggregate operator,
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/model.html b/docs/model.html
index bffb62a65..10b3b979c 100644
--- a/docs/model.html
+++ b/docs/model.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -1040,6 +1042,24 @@ when you want to pass the column as a measure
argument.</p>
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/os_adapter.html b/docs/os_adapter.html
index f6b82e679..4d355823d 100644
--- a/docs/os_adapter.html
+++ b/docs/os_adapter.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -417,6 +419,9 @@ into <a
href="https://github.com/julianhyde/sqlline">sqlline</a>
+
+
+
@@ -607,6 +612,24 @@ into <a
href="https://github.com/julianhyde/sqlline">sqlline</a>
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/pig_adapter.html b/docs/pig_adapter.html
index 7dfad3861..0d4afa187 100644
--- a/docs/pig_adapter.html
+++ b/docs/pig_adapter.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -211,6 +213,9 @@ So, Piglet is basically the opposite of the Pig adapter.</p>
+
+
+
@@ -401,6 +406,24 @@ So, Piglet is basically the opposite of the Pig
adapter.</p>
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/powered_by.html b/docs/powered_by.html
index b8f197c3a..fb25b1844 100644
--- a/docs/powered_by.html
+++ b/docs/powered_by.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -297,6 +299,9 @@ graph database.</p>
+
+
+
@@ -507,6 +512,24 @@ graph database.</p>
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/redis_adapter.html b/docs/redis_adapter.html
index c8b7ccfd4..d2c31a645 100644
--- a/docs/redis_adapter.html
+++ b/docs/redis_adapter.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -371,6 +373,9 @@ More Redis features need to be further refined: for example
HyperLogLog and Pub/
+
+
+
@@ -561,6 +566,24 @@ More Redis features need to be further refined: for
example HyperLogLog and Pub/
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/reference.html b/docs/reference.html
index cbea5483e..e658eb2c7 100644
--- a/docs/reference.html
+++ b/docs/reference.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -8661,6 +8663,24 @@ instantiated. Each object can hold different values.</p>
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/security_threat_model.html b/docs/security_threat_model.html
new file mode 100644
index 000000000..795910022
--- /dev/null
+++ b/docs/security_threat_model.html
@@ -0,0 +1,846 @@
+<!DOCTYPE HTML>
+<html lang="en-US">
+<head>
+<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
+ <meta charset="UTF-8">
+ <title>Security threat model</title>
+ <meta name="viewport" content="width=device-width,initial-scale=1">
+ <meta name="generator" content="Jekyll v4.4.1">
+ <link rel="stylesheet" href="/css/screen.css">
+ <link rel="icon" type="image/x-icon" href="/favicon.ico">
+ <!-- Matomo -->
+ <script>
+ var _paq = window._paq = window._paq || [];
+ /* tracker methods like "setCustomDimension" should be called before
"trackPageView" */
+ _paq.push(["setDoNotTrack", true]);
+ _paq.push(["disableCookies"]);
+ _paq.push(['trackPageView']);
+ _paq.push(['enableLinkTracking']);
+ (function() {
+ var u="https://analytics.apache.org/";
+ _paq.push(['setTrackerUrl', u+'matomo.php']);
+ _paq.push(['setSiteId', '64']);
+ var d=document, g=d.createElement('script'),
s=d.getElementsByTagName('script')[0];
+ g.async=true; g.src=u+'matomo.js'; s.parentNode.insertBefore(g,s);
+ })();
+ </script>
+ <!-- End Matomo Code -->
+</head>
+
+
+<body class="wrap">
+ <header role="banner">
+ <div class="grid">
+ <div class="unit center-on-mobiles">
+ <h1>
+ <a href="/">
+ <span class="sr-only">Apache Calcite</span>
+ <img src="/img/logo.svg" alt="Calcite Logo">
+ </a>
+ </h1>
+ </div>
+ <nav class="main-nav">
+ <ul>
+ <li class="">
+ <a href="/">Home</a>
+ </li>
+ <li class="">
+ <a href="/downloads/">Download</a>
+ </li>
+ <li class="">
+ <a href="/community/">Community</a>
+ </li>
+ <li class="">
+ <a href="/develop/">Develop</a>
+ </li>
+ <li class="">
+ <a href="/news/">News</a>
+ </li>
+ <li class="current">
+ <a href="/docs/">Docs</a>
+ </li>
+</ul>
+
+ </nav>
+ </div>
+</header>
+
+
+ <section class="docs">
+ <div class="grid">
+
+ <div class="docs-nav-mobile unit whole show-on-mobiles">
+ <select onchange="if (this.value) window.location.href=this.value">
+ <option value="">Navigate the docs…</option>
+ <optgroup label="Overview">
+ </optgroup>
+ <optgroup label="Advanced">
+ </optgroup>
+ <optgroup label="Avatica">
+ </optgroup>
+ <optgroup label="Reference">
+ </optgroup>
+ <optgroup label="Security">
+ </optgroup>
+ <optgroup label="Meta">
+ </optgroup>
+
+ </select>
+</div>
+
+
+ <div class="unit four-fifths">
+ <article>
+ <h1>Security threat model</h1>
+ <!--
+
+-->
+
+<p>Calcite is an embedded library: it runs inside a host application’s JVM and
+exposes no network port of its own. This threat model covers what an attacker
+who reaches that embedded engine over a JDBC connection can and cannot do.</p>
+
+<p>Calcite treats the behaviors below as security vulnerabilities, so that
+reporters and committers triage them the same way. A report that
+contradicts this model is a feature request or a documentation gap, not a
+vulnerability.</p>
+
+<ul id="markdown-toc">
+ <li><a href="#attacker-and-trust-boundary"
id="markdown-toc-attacker-and-trust-boundary">Attacker and trust
boundary</a></li>
+ <li><a href="#assets" id="markdown-toc-assets">Assets</a></li>
+ <li><a href="#inputs" id="markdown-toc-inputs">Inputs</a></li>
+ <li><a href="#security-properties"
id="markdown-toc-security-properties">Security properties</a></li>
+ <li><a href="#always-a-vulnerability"
id="markdown-toc-always-a-vulnerability">Always a vulnerability</a></li>
+ <li><a href="#not-a-vulnerability" id="markdown-toc-not-a-vulnerability">Not
a vulnerability</a></li>
+ <li><a href="#downstream-responsibilities"
id="markdown-toc-downstream-responsibilities">Downstream
responsibilities</a></li>
+ <li>
+<a href="#surprising-vs-unsurprising-class-loading"
id="markdown-toc-surprising-vs-unsurprising-class-loading">Surprising vs
unsurprising class loading</a> <ul>
+ <li><a href="#triage-rule-for-class-loading-sinks"
id="markdown-toc-triage-rule-for-class-loading-sinks">Triage rule for
class-loading sinks</a></li>
+ </ul>
+ </li>
+ <li><a href="#denial-of-service" id="markdown-toc-denial-of-service">Denial
of service</a></li>
+ <li><a href="#triage-dispositions"
id="markdown-toc-triage-dispositions">Triage dispositions</a></li>
+</ul>
+
+<h2 id="attacker-and-trust-boundary">Attacker and trust boundary</h2>
+
+<p>One attacker profile: a <em>query author</em> who reaches Calcite over a
JDBC
+connection.</p>
+
+<p>The attacker can:</p>
+
+<ul>
+ <li>set any connection property to any value: <code
class="language-plaintext highlighter-rouge">model</code>, <code
class="language-plaintext highlighter-rouge">parserFactory</code>,
+<code class="language-plaintext highlighter-rouge">schemaFactory</code>, <code
class="language-plaintext highlighter-rouge">fun</code>, <code
class="language-plaintext highlighter-rouge">typeSystem</code>, <code
class="language-plaintext highlighter-rouge">dataSource</code>, <code
class="language-plaintext highlighter-rouge">jdbcUrl</code>, and the
+rest;</li>
+ <li>execute any SQL, including DDL.</li>
+</ul>
+
+<p>The attacker cannot:</p>
+
+<ul>
+ <li>change JVM system properties;</li>
+ <li>change the classpath (add or replace classes or JARs).</li>
+</ul>
+
+<p>Out of scope by definition: the configuration and behavior of a
+third-party driver or service that a <a href="/docs/model.html">model</a>
+points at. If a model references h2, h2’s own settings and behavior are
+h2’s concern, not Calcite’s.</p>
+
+<h2 id="assets">Assets</h2>
+
+<ul>
+ <li>the host running Calcite: no code execution, and no file access beyond
+what an adapter is configured to perform;</li>
+ <li>the internal network reachable from that host: no attacker-directed
+outbound requests.</li>
+</ul>
+
+<h2 id="inputs">Inputs</h2>
+
+<p>Everything the attacker controls resolves to one of P1–P4 or to an explicit
+carve-out below. A report that reaches a sink not covered here is a model gap
+(see <a href="#triage-dispositions">Triage dispositions</a>).</p>
+
+<div class="scroll-table-style"><table>
+ <thead>
+ <tr>
+ <th>Input</th>
+ <th>How it is supplied</th>
+ <th>What it feeds</th>
+ <th>Governing rule</th>
+ </tr>
+ </thead>
+ <tbody>
+ <tr>
+ <td>SQL text, including DDL</td>
+ <td>any statement on the connection</td>
+ <td>parser → validator → planner → generated code</td>
+ <td>P1–P4; parser nesting depth is a DoS surface (see <a
href="#denial-of-service">Denial of service</a>)</td>
+ </tr>
+ <tr>
+ <td>Class-naming connection properties — <code class="language-plaintext
highlighter-rouge">schemaFactory</code>, <code class="language-plaintext
highlighter-rouge">parserFactory</code>, <code class="language-plaintext
highlighter-rouge">typeSystem</code>, <code class="language-plaintext
highlighter-rouge">metaTableFactory</code>, <code class="language-plaintext
highlighter-rouge">metaColumnFactory</code>
+</td>
+ <td>connection property or <code class="language-plaintext
highlighter-rouge">model</code>
+</td>
+ <td>a class loaded through a Calcite SPI</td>
+ <td>
+<a href="#surprising-vs-unsurprising-class-loading">Surprising vs unsurprising
class loading</a> (P1)</td>
+ </tr>
+ <tr>
+ <td>
+<code class="language-plaintext highlighter-rouge">tableFactory</code> and
function classes</td>
+ <td><code class="language-plaintext highlighter-rouge">model</code></td>
+ <td>a class loaded through a Calcite table or function SPI</td>
+ <td>Surprising vs unsurprising class loading (P1)</td>
+ </tr>
+ <tr>
+ <td>
+<code class="language-plaintext highlighter-rouge">dataSource</code>, <code
class="language-plaintext highlighter-rouge">jdbcDriver</code>
+</td>
+ <td>connection property or <code class="language-plaintext
highlighter-rouge">model</code>
+</td>
+ <td>a class loaded through a standard-Java SPI (<code
class="language-plaintext highlighter-rouge">javax.sql.DataSource</code>, <code
class="language-plaintext highlighter-rouge">java.sql.Driver</code>)</td>
+ <td>Surprising vs unsurprising class loading (P1); the host it then
dials is P3</td>
+ </tr>
+ <tr>
+ <td><code class="language-plaintext highlighter-rouge">fun</code></td>
+ <td>connection property</td>
+ <td>selects built-in function libraries by name</td>
+ <td>no class loading; ordinary SQL semantics under P1–P4</td>
+ </tr>
+ <tr>
+ <td>
+<code class="language-plaintext highlighter-rouge">model</code> — inline JSON,
a <code class="language-plaintext highlighter-rouge">file:</code> path, or a
URL</td>
+ <td>connection property</td>
+ <td>schema/table factories and adapter operands</td>
+ <td>P1 (factories via SPI), P2 (local-file operands), P3 (a URL model,
or a URL-fetching adapter)</td>
+ </tr>
+ <tr>
+ <td>A serialized RelNode plan (<code class="language-plaintext
highlighter-rouge">RelJson</code>) — types and operators</td>
+ <td>any path that reconstructs a plan from attacker input</td>
+ <td>type and operator class resolution</td>
+ <td>Surprising vs unsurprising class loading (P1)</td>
+ </tr>
+ <tr>
+ <td>Adapter operands — e.g. a file/CSV/JSON path, or the os-adapter</td>
+ <td>
+<code class="language-plaintext highlighter-rouge">model</code> or SQL</td>
+ <td>the adapter’s configured resource</td>
+ <td>P2 for a configured local path (opt-in ⇒ not a vulnerability); the
os-adapter is opt-in (not a vulnerability)</td>
+ </tr>
+ </tbody>
+</table></div>
+
+<h2 id="security-properties">Security properties</h2>
+
+<ul>
+ <li>
+<strong>P1: no code execution.</strong> Neither connecting nor running SQL may
+execute code outside Calcite’s query-processing semantics. This covers
+<code class="language-plaintext highlighter-rouge">Runtime.exec</code> and
<code class="language-plaintext highlighter-rouge">ProcessBuilder</code>, and
the weaker primitive of loading
+an attacker-named class so that its static initializer, constructor, or
+an accessed static field runs. Exception: the os-adapter.</li>
+ <li>
+<strong>P2: no incidental file access.</strong> Neither connecting nor running
+SQL may read or create a file, except where a file-oriented adapter or
+table function reads the local path it was explicitly configured with. The
+carve-out covers local filesystem paths only; a file adapter that fetches a
+URL (<code class="language-plaintext highlighter-rouge">http://</code>, <code
class="language-plaintext highlighter-rouge">https://</code>) is making a
network request and falls under P3.</li>
+ <li>
+<strong>P3: no server-side request forgery.</strong> Neither connecting nor
+running SQL may open a network connection to an attacker-chosen host.</li>
+ <li>
+<strong>P4: no escape from the configured schemas.</strong> Neither connecting
nor
+running SQL may read data outside the schemas the connection exposes. A query
+that reaches another schema, a file, or a catalog that the connection’s root
+schema does not make visible is a vulnerability.</li>
+</ul>
+
+<h2 id="always-a-vulnerability">Always a vulnerability</h2>
+
+<ol>
+ <li>
+<strong>Code execution</strong> that results from connecting or running SQL,
except
+through the os-adapter. The bar is the primitive, not a full chain: a
+reachable sink that loads an attacker-named class qualifies, because
+class loading runs the static initializer before any type check.</li>
+ <li>
+<strong>Arbitrary file read or write</strong> that no explicitly-configured
file
+adapter was asked to perform.</li>
+ <li>
+<strong>Server-side request forgery</strong>, forcing Calcite to connect to a
+host the attacker chooses (internal services, cloud metadata endpoints,
+port scans).</li>
+ <li>
+<strong>Reading beyond the configured schemas</strong>, reaching another
schema,
+a file, or a catalog that the connection’s root schema does not make
+visible.</li>
+</ol>
+
+<h2 id="not-a-vulnerability">Not a vulnerability</h2>
+
+<ul>
+ <li>The os-adapter running OS commands. It exists to do that, and an operator
+must add it on purpose.</li>
+ <li>A file, CSV, or JSON adapter reading the local path it was configured
+with. Opt-in, by the same reasoning as the os-adapter.</li>
+ <li>Anything that needs a changed system property or classpath. Both are
+outside the attacker’s reach by assumption.</li>
+ <li>The behavior of a third-party driver once Calcite has connected to the
+endpoint it was configured with.</li>
+ <li>SQL that Calcite pushes down to a configured backend. Calcite generates
the
+text and sends it to the endpoint the operator configured, and the query
+author can already reach that endpoint’s data through the visible schemas. A
+pushdown bug that reads beyond the configured schemas is P4 and a
+vulnerability; the generated SQL reaching the configured backend is not.</li>
+ <li>Cross-tenant reads that follow from the embedder exposing more than one
+principal’s schemas on a single connection. Calcite has no authentication or
+authorization; scoping each connection’s root schema to what its principal may
+see is the embedder’s job. P4 applies where the user submits only SQL; a user
+who also sets connection properties configures their own schema
visibility.</li>
+</ul>
+
+<h2 id="downstream-responsibilities">Downstream responsibilities</h2>
+
+<p>Calcite is embedded, so several controls belong to the host or the operator,
+not to the library. A finding that lands in one of these is not a Calcite
+vulnerability.</p>
+
+<ul>
+ <li>
+<strong>Transport and identity.</strong> Calcite opens no socket. TLS, the
network
+perimeter, authentication, and authorization live in the host. A host that
+lets an untrusted principal set connection properties hands that principal the
+full capability in <a href="#attacker-and-trust-boundary">Attacker and trust
boundary</a>.</li>
+ <li>
+<strong>Schema scoping.</strong> Scope each connection’s root schema to what
its principal
+may see; Calcite has no authentication or authorization. Cross-tenant reads
+across schemas exposed on one connection are the embedder’s to prevent (see
+<a href="#not-a-vulnerability">Not a vulnerability</a>).</li>
+ <li>
+<strong>Adapter selection.</strong> Add the os-adapter and the file, CSV, or
JSON adapters
+only where the query author is trusted to reach what they expose.</li>
+ <li>
+<strong>Classpath.</strong> The operator owns the classpath. Calcite gates
class loading by
+SPI; which classes are present is the operator’s trust decision.</li>
+ <li>
+<strong>What a <code class="language-plaintext highlighter-rouge">model</code>
points at.</strong> A third-party driver or service a <code
class="language-plaintext highlighter-rouge">model</code>
+references is configured and patched by the operator; its behavior past the
+connection boundary is out of this model.</li>
+</ul>
+
+<h2 id="surprising-vs-unsurprising-class-loading">Surprising vs unsurprising
class loading</h2>
+
+<p>Calcite loads a class named in a connection property or in SQL only to use
it
+through a specific SPI: a schema factory, table factory, function, operator,
+data source, or driver. The security boundary follows that contract, not a
+blanket trust of the classpath or of SQL.</p>
+
+<ul>
+ <li>
+<strong>Unsurprising.</strong> The class implements the SPI interface for the
position it
+was named in, and Calcite invokes it through that interface. This is working
+as designed, even when the class is otherwise dangerous. The operator who
+placed the class on the classpath, and the author of the class, own that
+contract.</li>
+ <li>
+<strong>Surprising.</strong> Naming a class runs the class’s own code (a static
+initializer, constructor, method, or static-field read) even though it
+does not implement the SPI for that position. <code class="language-plaintext
highlighter-rouge">java.lang.Runtime</code>,
+<code class="language-plaintext
highlighter-rouge">org.springframework.boot.SpringApplication</code>, and <code
class="language-plaintext highlighter-rouge">javax.naming.InitialContext</code>
+are surprising in a <code class="language-plaintext
highlighter-rouge">SchemaFactory</code> slot. Surprising class loading is
always a
+vulnerability.</li>
+</ul>
+
+<p>This boundary lets three goals hold at once:</p>
+
+<ul>
+ <li>untrusted classes may sit on the classpath; a dangerous class that does
+not implement a Calcite SPI is never instantiated by name, so the operator
+need not audit every class;</li>
+ <li>SQL may be arbitrary; it can name SPI classes, but only SPI
+implementations run, and only through their SPI;</li>
+ <li>a reasonable-looking query cannot trigger an unexpected process launch,
file
+read, or network call, because the interface gate rejects the classes that
+would cause one.</li>
+</ul>
+
+<p>The same rule governs any path that reconstructs objects or loads classes
from
+attacker-controlled input, including JSON plan deserialization.</p>
+
+<p><strong>Mechanism.</strong> Load with <code class="language-plaintext
highlighter-rouge">Class.forName(name, false, loader)</code>, check
+<code class="language-plaintext
highlighter-rouge">pluginClass.isAssignableFrom(clazz)</code>, and only then
initialize and instantiate.
+A class that fails the check never runs its static initializer.</p>
+
+<p><strong>Standard-Java SPIs.</strong> The gate is tightest when the SPI is a
Calcite interface
+(<code class="language-plaintext highlighter-rouge">SchemaFactory</code>,
<code class="language-plaintext highlighter-rouge">TableFactory</code>, <code
class="language-plaintext highlighter-rouge">Function</code>, <code
class="language-plaintext highlighter-rouge">SqlOperator</code>): only a class
+written to be a Calcite plugin passes. Two positions name a standard Java
+interface instead, <code class="language-plaintext
highlighter-rouge">dataSource</code> (<code class="language-plaintext
highlighter-rouge">javax.sql.DataSource</code>) and <code
class="language-plaintext highlighter-rouge">jdbcDriver</code>
+(<code class="language-plaintext highlighter-rouge">java.sql.Driver</code>),
which many unrelated libraries implement. The
+interface gate still blocks the surprising case, since <code
class="language-plaintext highlighter-rouge">java.lang.Runtime</code>
+implements neither, so naming a <code class="language-plaintext
highlighter-rouge">DataSource</code> or <code class="language-plaintext
highlighter-rouge">Driver</code> implementation is the
+documented feature, not a vulnerability. An allowlist of permitted
+implementations is optional hardening for these positions, not a security
+boundary. The host a driver then connects to is governed by P3, independently
of
+which class is named.</p>
+
+<h3 id="triage-rule-for-class-loading-sinks">Triage rule for class-loading
sinks</h3>
+
+<p>A reachable sink that loads an attacker-named class is a vulnerability on
+its own. A reporter need not demonstrate end-to-end remote code execution
+on a specific classpath: the demonstrated primitive (a static
+initializer, a constructor, or a static-field read on an attacker-named
+class) is enough to require a fix. The fix loads with
+<code class="language-plaintext highlighter-rouge">initialize=false</code>,
gates on the expected interface (or an allowlist), and
+then instantiates.</p>
+
+<h2 id="denial-of-service">Denial of service</h2>
+
+<p>A single query should not be able to exhaust the host. This is in scope as a
+hardening goal. The controls are not all in place yet, so treat the gaps below
+as known limitations rather than per-report vulnerabilities until the controls
+land.</p>
+
+<ul>
+ <li>
+<strong>Planning.</strong> A crafted query can drive the planner into a
combinatorial
+blow-up. The fix is a set of bounds: a planning deadline, a cap on rule
+firings, and a cap on the number of explored alternatives. Calcite already
+carries a <code class="language-plaintext highlighter-rouge">CancelFlag</code>
in the planner context, so a deadline can build on it;
+the firing and size caps are new.</li>
+ <li>
+<strong>Execution.</strong> Catastrophic regex backtracking in <code
class="language-plaintext highlighter-rouge">LIKE</code>, <code
class="language-plaintext highlighter-rouge">SIMILAR TO</code>, or
+<code class="language-plaintext highlighter-rouge">RLIKE</code>, or an
unbounded join, exhausts resources at run time. Planning bounds
+do not help here; the mitigation is a match-time limit or a backtracking-free
+regex engine.</li>
+ <li>
+<strong>Parsing.</strong> Deeply nested expressions can overflow the parser
stack. The
+mitigation is a nesting-depth limit.</li>
+</ul>
+
+<p>Once the planning bounds exist, a single reasonably-sized query that exceeds
+them is a configuration choice, not a vulnerability.</p>
+
+<h2 id="triage-dispositions">Triage dispositions</h2>
+
+<p>Every security report against Calcite resolves to exactly one of:</p>
+
+<ul>
+ <li>
+<strong>Valid</strong> — violates P1–P4, or matches an item in
+<a href="#always-a-vulnerability">Always a vulnerability</a>. Gets a fix. A
demonstrated
+class-loading primitive qualifies on its own (see
+<a href="#triage-rule-for-class-loading-sinks">Triage rule for class-loading
sinks</a>);
+it need not be chained to end-to-end RCE.</li>
+ <li>
+<strong>Not a vulnerability (by design)</strong> — matches an item in
+<a href="#not-a-vulnerability">Not a vulnerability</a>: the os-adapter, an
opt-in
+file/CSV/JSON adapter reading its configured path, third-party driver or
+pushed-down SQL behavior past the connection, or cross-tenant reads that
+follow from the embedder’s schema exposure. Close with a pointer to this
+model.</li>
+ <li>
+<strong>Out of model</strong> — requires a capability the attacker does not
have (changing
+a JVM system property or the classpath), or lands in a layer this model
+assigns to the host (network transport, TLS, authentication, authorization).
+Close; redirect to the operator or embedder.</li>
+ <li>
+<strong>Known limitation</strong> — a <a href="#denial-of-service">Denial of
service</a> gap whose
+control has not landed yet. Tracked as hardening, not a per-report
+vulnerability, until the bound exists.</li>
+ <li>
+<strong>Duplicate</strong> — the same sink or root cause is already tracked in
an open
+Jira. Link and close.</li>
+ <li>
+<strong>Model gap</strong> — plausible, but this model does not clearly place
it in or out.
+Escalate to the PMC to decide, then update this document with the ruling so
+the next report of its kind is no longer a gap.</li>
+</ul>
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+ <div class="section-nav">
+ <div class="left align-right">
+
+
+
+ <a href="/docs/howto.html" class="prev">Previous</a>
+
+ </div>
+ <div class="right align-left">
+
+
+
+
+
+ <a href="/docs/history.html" class="next">Next</a>
+
+ </div>
+ </div>
+ <div class="clear"></div>
+
+
+ </article>
+ </div>
+
+ <div class="unit one-fifth hide-on-mobiles">
+ <aside>
+
+ <h4>Overview</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/index.html">Background</a></li>
+
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/tutorial.html">Tutorial</a></li>
+
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/algebra.html">Algebra</a></li>
+
+
+</ul>
+
+
+ <h4>Advanced</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/adapter.html">Adapters</a></li>
+
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/spatial.html">Spatial</a></li>
+
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/stream.html">Streaming</a></li>
+
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/materialized_views.html">Materialized
Views</a></li>
+
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/lattice.html">Lattices</a></li>
+
+
+</ul>
+
+
+ <h4>Avatica</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/avatica_overview.html">Overview</a></li>
+
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/avatica_roadmap.html">Roadmap</a></li>
+
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/avatica_json_reference.html">JSON
Reference</a></li>
+
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/avatica_protobuf_reference.html">Protobuf
Reference</a></li>
+
+
+</ul>
+
+
+ <h4>Reference</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/reference.html">SQL language</a></li>
+
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/model.html">JSON/YAML models</a></li>
+
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/howto.html">HOWTO</a></li>
+
+
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class="current"><a href="/docs/security_threat_model.html">Security
threat model</a></li>
+
+
+</ul>
+
+
+ <h4>Meta</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/history.html">History</a></li>
+
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/powered_by.html">Powered by Calcite</a></li>
+
+
+
+
+
+
+
+
+
+ <li class=""><a href="/javadocAggregate">API</a></li>
+
+
+</ul>
+
+
+ </aside>
+</div>
+
+
+ <div class="clear"></div>
+
+ </div>
+ </section>
+
+
+ <footer role="contentinfo">
+ <div id="poweredby">
+ <a href="http://www.apache.org/">
+ <span class="sr-only">Apache</span>
+ <img src="https://www.apache.org/img/asf_logo.png" width="147"
height="77" alt="Apache Logo"></a>
+ </div>
+ <div id="copyright">
+ <p>The contents of this website are Copyright © 2026
+ <a href="https://www.apache.org/">Apache Software Foundation</a>
+ under the terms of
+ the <a href="https://www.apache.org/licenses/">
+ Apache License v2</a>. Apache Calcite and its logo are
+ trademarks of the Apache Software Foundation.
+ </p>
+ <p>
+ <a
href="https://privacy.apache.org/policies/privacy-policy-public.html">Privacy
Policy</a>
+ </p>
+ </div>
+</footer>
+
+ <script>
+ var anchorForId = function (id) {
+ var anchor = document.createElement("a");
+ anchor.className = "header-link";
+ anchor.href = "#" + id;
+ anchor.innerHTML = "<span class=\"sr-only\">Permalink</span><i class=\"fa
fa-link\"></i>";
+ anchor.title = "Permalink";
+ return anchor;
+ };
+
+ var linkifyAnchors = function (level, containingElement) {
+ var headers = containingElement.getElementsByTagName("h" + level);
+ for (var h = 0; h < headers.length; h++) {
+ var header = headers[h];
+
+ if (typeof header.id !== "undefined" && header.id !== "") {
+ header.appendChild(anchorForId(header.id));
+ }
+ }
+ };
+
+ document.onreadystatechange = function () {
+ if (this.readyState === "complete") {
+ var contentBlock = document.getElementsByClassName("docs")[0] ||
document.getElementsByClassName("news")[0];
+ if (!contentBlock) {
+ return;
+ }
+ for (var level = 1; level <= 6; level++) {
+ linkifyAnchors(level, contentBlock);
+ }
+ }
+ };
+</script>
+
+
+</body>
+</html>
diff --git a/docs/spatial.html b/docs/spatial.html
index 39b1e5b00..edea2ecfb 100644
--- a/docs/spatial.html
+++ b/docs/spatial.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -481,6 +483,24 @@ when the specification wasn’t clear. Thank you to these
awesome projects.</p>
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/stream.html b/docs/stream.html
index 05c449571..2764a4c82 100644
--- a/docs/stream.html
+++ b/docs/stream.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -1336,6 +1338,24 @@ MillWheel: Fault-Tolerant Stream Processing at Internet
Scale</a>.</li>
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>
diff --git a/docs/tutorial.html b/docs/tutorial.html
index b4658f5d9..e81bdddf8 100644
--- a/docs/tutorial.html
+++ b/docs/tutorial.html
@@ -80,6 +80,8 @@
</optgroup>
<optgroup label="Reference">
</optgroup>
+ <optgroup label="Security">
+ </optgroup>
<optgroup label="Meta">
</optgroup>
@@ -993,6 +995,24 @@ The <a href="adapter.html">adapter specification</a>
describes the APIs involved
<li class=""><a href="/docs/howto.html">HOWTO</a></li>
+</ul>
+
+
+ <h4>Security</h4>
+
+
+<ul>
+
+
+
+
+
+
+
+
+ <li class=""><a href="/docs/security_threat_model.html">Security threat
model</a></li>
+
+
</ul>