Skip to content

Validate union index in UnionReader.nextToken() - #816

Open
pjfanning wants to merge 2 commits into
FasterXML:2.21from
pjfanning:tatu-claude/2.21/union-index-bounds
Open

pjfanning wants to merge 2 commits into
FasterXML:2.21from
pjfanning:tatu-claude/2.21/union-index-bounds

Conversation

@pjfanning

Copy link
Copy Markdown
Member

UnionReader.nextToken() used the decoded union index directly, without the range check _decodeIndex() that skipValue() already applies. An out-of-range index (too large, or negative) therefore surfaced as ArrayIndexOutOfBoundsException rather than StreamReadException.

This change makes nextToken() use _decodeIndex() too. Unions with only scalar members were already covered by ScalarDecoder._checkIndex().

Adds AvroUnionIndexBoundsTest, covering index 5 and -1 with both the native and Apache decoders. Without the fix, it fails with ArrayIndexOutOfBoundsException: Index 5 out of bounds for length 2.

🤖 Generated with Claude Code

pjfanning and others added 2 commits September 29, 2026 10:14
`nextToken()` used the decoded union index without the range check that
`skipValue()` already applies, so an out-of-range index surfaced as
`ArrayIndexOutOfBoundsException` instead of `StreamReadException`.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@cowtowncoder cowtowncoder changed the title (avro) Validate union index in UnionReader.nextToken() Validate union index in UnionReader.nextToken() Sep 29, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants