Mryange opened a new pull request, #68703:
URL: https://github.com/apache/doris/pull/68703

   ### What problem does this PR solve?
   
   Issue Number: N/A
   
   Problem Summary:
   
   MySQL queries sent over TLS can fail with parser errors near a TLS record 
boundary. Root cause: after removing the MySQL header with `compact()`, the 
receive loop compares the declared payload length against the buffer limit, 
which becomes its capacity, instead of the number of decrypted bytes received. 
If the payload length falls between the current position and capacity, the loop 
skips a required TLS record and exposes unreceived bytes to the parser.
   
   Compare against `result.position()` so the receive loop collects the 
complete payload before processing it.
   
   ### Release note
   
   Fix SQL truncation and parser errors when a MySQL query spans TLS records 
near the receive-buffer boundary.
   
   ### Check List (For Author)
   
   - Test:
       - [x] Manual test
       - Built FE with `./build.sh --fe -j48`; Checkstyle passed.
       - Used a PyMySQL TLS connection to send a COM_QUERY with a 16,380-byte 
payload. Splitting the 16,384-byte MySQL packet after byte 16,380 or 16,383 
produced parser errors before the fix; the same requests produced a result-set 
response after rebuilding and restarting FE with the fix. A complete 
16,384-byte write also succeeded.
       - Repeated with 16,400-byte and 17,000-byte payloads split at bytes 
16,380, 16,383, and 16,384; all produced result-set responses after the fix.
       - `git diff --check` passed. Automated unit and regression tests were 
not run.
   - Behavior changed:
       - [x] Yes. Read all TLS records needed to complete the MySQL payload.
   - Does this need documentation?
       - [x] No.
   
   ### Check List (For Reviewer who merge this PR)
   
   - [ ] Confirm the release note
   - [ ] Confirm test cases
   - [ ] Confirm document
   - [ ] Add branch pick label
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to