Skip to content

fix(auth): stop BLOB view predicate lookups at LIMIT under query-auth - #1092

Open
plusplusjiajia wants to merge 2 commits into
apache:mainfrom
plusplusjiajia:query-auth-blob-view-limit
Open

plusplusjiajia wants to merge 2 commits into
apache:mainfrom
plusplusjiajia:query-auth-blob-view-limit

Conversation

@plusplusjiajia

@plusplusjiajia plusplusjiajia commented Oct 10, 2026 •

Copy link
Copy Markdown
Member

Purpose

Follow-up to #1089. Under query-auth, predicates on BLOB views can resolve references beyond LIMIT and fail on an upstream row the result never needs. PK merge output and readers that ignore the requested batch size make a decoder batch-size override insufficient.

Brief change log

After merging, row authorization and masking, yield one candidate row at a time before resolving predicate views when LIMIT is set. The downstream predicate and LIMIT stop pulling once enough rows qualify.

Remove the read.batch-size = 1 override and reuse the view-resolution condition in finish_authorized_blobs. File decoding, authorization and masking retain normal batches.

Tests

Retain the append data-evolution regression. Add overlapping-file PK regressions for deduplicate and partial-update, covering masked aliases, descriptor/value reads, projections, batch sizes 1/1024, zero/small limits, rejected candidates and errors when missing references are required.

Default/fulltext REST tests pass (120 each), as do the related core and DataFusion tests, formatting, and all-targets core clippy with the existing nonminimal_bool allowance.

Scope

Deferring output-only views until after BLOB payload predicates and LIMIT remains separate follow-up work. Per-row OR short-circuiting of view lookups is also outside this change.

A query-auth read with BLOB columns resolves the views its predicates
read before LIMIT applies, a whole batch at a time, so it could look up
references past the quota and fail on one no row needed. Read one
candidate at a time in that case, as the unrestricted read already does.
@plusplusjiajia
plusplusjiajia force-pushed the query-auth-blob-view-limit branch from 7ca0b92 to a2a42bb Compare October 10, 2026 08:17
@plusplusjiajia
plusplusjiajia marked this pull request as ready for review October 10, 2026 09:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant