DanielLeens commented on PR #11559:
URL: https://github.com/apache/seatunnel/pull/11559#issuecomment-6000009570

   @SEZ9 Thanks, both asks are addressed in `8909a67fce2`.
   
   1. **Negative case tightened.** Added 
`productionDeserializeSplitShouldRejectSamePackageSubclassOutsideAllowlist`, 
which serializes a `KafkaSourceSplitState`. It is a serializable subclass of 
the allowlisted `KafkaSourceSplit`, lives in the same package, and its class 
name even starts with the allowlisted name, so it passes a package-prefix 
check, a class-name-prefix check and the `instanceof KafkaSourceSplit` guard. 
Only exact-name matching rejects it. The existing `java.util.HashMap` case is 
kept, and both now assert the exact rejection message rather than a substring.
   2. **No more reflection.** `KafkaSourceReader.deserializeSplit` is now 
package-private with a Javadoc note that it is exposed only for tests, and the 
tests call it directly. The reflective helper is removed, and the test Javadoc 
says not to swap the call for the local plain-`ObjectInputStream` helper, which 
never reaches the allowlist.
   
   The allowlist logic itself (`KafkaGateObjectInputStream.isAllowedClass`) is 
unchanged; the only production change is the visibility of that one method.
   
   On local confirmation: I have not run the tests locally. Verification is the 
GitHub CI run on this head; it is queued now and I will not claim the tests 
pass until it finishes.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to