Observed behavior: The SQLite canonical destination's controlRow bounds payload columns before driver materialization but forwards fixed columns without that byte check. A malformed caller-owned resume target can place a large TEXT value in transfer_runs.schema_ready; SQLite INTEGER affinity does not prohibit it. The value is materialized before the subsequent exact 0/1 validation refuses the target.
Expected behavior: Reject a malformed control scalar before materializing an oversized value, including fields normally written as integers.
Root cause: controlRow constructs size measurements and bounded CASE projections only for columns, not fixed. Current callers use fixed schema_ready and complete; schema_ready lacks a database CHECK limiting its type/value.
How to reproduce: In an isolated SQLite fixture with the transfer ledger schema, store 8,000,000 text characters in schema_ready, then exercise the projection used by controlRow with bounded project_json/manifest_sha and fixed schema_ready. The second-pass reviewer reproduced the full 8MB value crossing the driver before refusal. A production resume regression should assert refusal before fetching that payload.
Impact and severity: P3, resource-bound consistency. The ordinary writer only emits integers; this requires malformed caller-owned resume state. The adapter still refuses immediately afterward, with no wrong result, mutation, durable acknowledgement or privacy leak. This does not invalidate the correctly bounded checkpoint JSON path.
Environment:
Originating feature #618, candidate d338efe965ddfef38054d1a52d2e22d509f035ac, second-pass finding P3-1. Feature PR: #1143. Track outside the fixed Epic #224 inventory; this is not a P2 budget deferral. Suggested correction: apply the same SQL-side control-byte check to fixed columns, or enforce their permitted integer scalar type before fetching them.
Observed behavior: The SQLite canonical destination's
controlRowbounds payload columns before driver materialization but forwardsfixedcolumns without that byte check. A malformed caller-owned resume target can place a large TEXT value intransfer_runs.schema_ready; SQLite INTEGER affinity does not prohibit it. The value is materialized before the subsequent exact 0/1 validation refuses the target.Expected behavior: Reject a malformed control scalar before materializing an oversized value, including fields normally written as integers.
Root cause:
controlRowconstructs size measurements and bounded CASE projections only forcolumns, notfixed. Current callers use fixedschema_readyandcomplete;schema_readylacks a database CHECK limiting its type/value.How to reproduce: In an isolated SQLite fixture with the transfer ledger schema, store 8,000,000 text characters in
schema_ready, then exercise the projection used bycontrolRowwith boundedproject_json/manifest_shaand fixedschema_ready. The second-pass reviewer reproduced the full 8MB value crossing the driver before refusal. A production resume regression should assert refusal before fetching that payload.Impact and severity: P3, resource-bound consistency. The ordinary writer only emits integers; this requires malformed caller-owned resume state. The adapter still refuses immediately afterward, with no wrong result, mutation, durable acknowledgement or privacy leak. This does not invalidate the correctly bounded checkpoint JSON path.
Environment:
Originating feature #618, candidate
d338efe965ddfef38054d1a52d2e22d509f035ac, second-pass finding P3-1. Feature PR: #1143. Track outside the fixed Epic #224 inventory; this is not a P2 budget deferral. Suggested correction: apply the same SQL-side control-byte check to fixed columns, or enforce their permitted integer scalar type before fetching them.