Repository navigation
fix: reject null list slots and empty geohashes - #42
Merged
Merged
Conversation
mailletf
force-pushed
the
fix/reject-degenerate-inputs
branch
from
September 1, 2026 18:33
5db1d0a to
842112c
Compare
mailletf
force-pushed
the
perf/parallel-polygon-cover
branch
2 times, most recently
from
September 1, 2026 18:54
4b47991 to
3eda41c
Compare
mailletf
force-pushed
the
fix/reject-degenerate-inputs
branch
from
September 1, 2026 18:54
842112c to
6419e79
Compare
mailletf
force-pushed
the
perf/parallel-polygon-cover
branch
from
September 16, 2026 19:13
3eda41c to
8ae07d8
Compare
mailletf
force-pushed
the
fix/reject-degenerate-inputs
branch
from
September 16, 2026 19:13
6419e79 to
94bd11a
Compare
Member
Author
|
This change is part of the following stack: Change managed by git-spice. |
This was referenced Sep 16, 2026
mailletf
force-pushed
the
perf/parallel-polygon-cover
branch
from
September 16, 2026 19:16
8ae07d8 to
3b93442
Compare
A null slot in geohash_lists was read straight through its offsets and silently became an empty group. With pyarrow-produced data a null slot happens to have equal offsets, but the Arrow spec lets them span arbitrary positions of the values buffer, so foreign-written data could expand undefined bytes as geohashes. Null geog_ids and null list elements already error; null list slots now do too. Squashed with: - fix: reject the empty geohash instead of decoding the whole world Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
mailletf
force-pushed
the
fix/reject-degenerate-inputs
branch
from
September 16, 2026 19:19
94bd11a to
61b9687
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two pre-existing input-validation gaps surfaced by an adversarial review of the stack (they pre-date PRs #31–#40, so they get their own PR on top):
geohash_listsslots inexpand_geohash_mapping_arrowwere silently read through their offsets and became empty groups. pyarrow happens to write equal offsets under a null slot, but the Arrow spec allows them to span arbitrary positions of the values buffer, so foreign-written data could expand undefined bytes as geohashes. Null geog_ids and null list elements already errored; null list slots now do too.""decodes to the whole-world bbox in thegeohashcrate, so an empty value from an upstream join quietly became a planet-sized polygon (or expansion sample). Every decode of user input now goes through a checked wrapper that refuses it — list, Arrow, and expansion entry points.Both come with Rust and Python tests.
🤖 Generated with Claude Code