Skip to content

Bound fixed SQLite transfer ledger controls #1140

Description

@bcdonadio

Observed behavior: The SQLite canonical destination's controlRow bounds payload columns before driver materialization but forwards fixed columns without that byte check. A malformed caller-owned resume target can place a large TEXT value in transfer_runs.schema_ready; SQLite INTEGER affinity does not prohibit it. The value is materialized before the subsequent exact 0/1 validation refuses the target.

Expected behavior: Reject a malformed control scalar before materializing an oversized value, including fields normally written as integers.

Root cause: controlRow constructs size measurements and bounded CASE projections only for columns, not fixed. Current callers use fixed schema_ready and complete; schema_ready lacks a database CHECK limiting its type/value.

How to reproduce: In an isolated SQLite fixture with the transfer ledger schema, store 8,000,000 text characters in schema_ready, then exercise the projection used by controlRow with bounded project_json/manifest_sha and fixed schema_ready. The second-pass reviewer reproduced the full 8MB value crossing the driver before refusal. A production resume regression should assert refusal before fetching that payload.

Impact and severity: P3, resource-bound consistency. The ordinary writer only emits integers; this requires malformed caller-owned resume state. The adapter still refuses immediately afterward, with no wrong result, mutation, durable acknowledgement or privacy leak. This does not invalidate the correctly bounded checkpoint JSON path.

Environment:

Originating feature #618, candidate d338efe965ddfef38054d1a52d2e22d509f035ac, second-pass finding P3-1. Feature PR: #1143. Track outside the fixed Epic #224 inventory; this is not a P2 budget deferral. Suggested correction: apply the same SQL-side control-byte check to fixed columns, or enforce their permitted integer scalar type before fetching them.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Fields

    Priority

    Medium

    Effort

    None yet

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions