fix: reject Paimon reads and writes on iceberg/object/lance tables - #740
Draft
plusplusjiajia wants to merge 1 commit into
Draft
fix: reject Paimon reads and writes on iceberg/object/lance tables#740plusplusjiajia wants to merge 1 commit into
plusplusjiajia wants to merge 1 commit into
Conversation
plusplusjiajia
force-pushed
the
feat/table-type-fail-closed
branch
from
August 23, 2026 15:56
87c7ef8 to
b12d420
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
Follow-up to #733: the default
Catalog::load_tablewrappedget_table's result asLoadedTable::Paimonunconditionally, so a catalog that does not override it skipped the resolver entirely. Beyond that, a table declarediceberg-table,object-tableorlance-tablecould still be read or written as Paimon through several other paths; this PR closes them.Brief change log
Catalog
Catalog::load_tableclassifies from the loaded table's own options and goes through the checkedLoadedTable::externalconstructor, so a catalog that only implementsget_tablefails closedlist_partitionsrefuses external tables.Core storage boundary
CoreOptions::ensure_read_authorized— already called at every path that reads or mutates table storage — now also refuses an engine-served declared type;ensure_engine_can_servekeeps the auth-only half.IncrementalScan::plan,TableCommit::abort(type-only) and the shared write validator gain the missing check.Runtime type immutability
copy_with_optionspins the storedtypethe way it pinsquery-auth.enabled.copy_with_branchandcopy_with_time_travelrefuse external tables before any IO.DataFusion
SHOW CREATE TABLE(no storage IO), and provider construction (validates before registering with the blob-reader registry).