Skip to content

[core] Reject hidden-leading partition values in value-only layout - #10240

Closed
LuciferYang wants to merge 2 commits into
apache:masterfrom
LuciferYang:m/core-056-partition-path
Closed

LuciferYang wants to merge 2 commits into
apache:masterfrom
LuciferYang:m/core-056-partition-path

Conversation

@LuciferYang

Copy link
Copy Markdown
Contributor

Purpose

In a value-only partition layout the write validator rejected only null, empty, "." and "..", so a value such as "x" or ".tmp" was written to a directory whose name starts with "" or ".". The read path treats those directories as hidden and skips them, so the partition and all of its data silently disappeared from scans.

This rejects a partition value whose rendered value-only path segment would be hidden, so the write fails fast instead of producing an unreadable partition. The only exempt value is the table's configured default partition name, because scans un-hide exactly that name (the built-in default __DEFAULT_PARTITION__ itself starts with "_"). The configured name is threaded through the format-table writers, commit, partition-path resolver, registry validator, stats collector, scan, the HiveCatalog partition locations, and the Spark partition DDL paths (ADD / DROP / TRUNCATE / ANALYZE PARTITION and ADD PARTITION ... LOCATION), so a table whose partition.default-name is itself a hidden name can still write and manage its null partition rather than having that DDL rejected. Callers without a table context fall back to the well-known default name. Key-value layout is unchanged, since the component there is "pt=_x" and does not start with a hidden prefix.

Tests

New cases in PartitionPathUtilsTest pin: value-only "_x" and ".x" are rejected; the built-in default partition name and a configured custom default name stay writable while other hidden-leading values remain rejected; and a key-value "pt=_x" component stays visible.

API and Format

No.

Documentation

No.

In a value-only partition layout the write validator rejected only
null, empty, '.' and '..' values, and the escaping kept '_' literal,
so a value like '_x' or '.x' was written to a directory whose name
starts with '_' or '.'. The read path treats such directories as
hidden staging or metadata directories and skips them, so the
partition and all its data silently disappeared from scans.

Reject values whose name would be hidden, except the table's
configured default partition name, which scans un-hide explicitly.
The configured name is threaded through the format-table writers,
commit, partition-path resolver and registry validator, the spark
partition repair and the HiveCatalog partition locations; callers
without a table context fall back to the well-known default name.

Assisted-by: GLM-5.3
@LuciferYang
LuciferYang marked this pull request as draft October 2, 2026 03:19
@LuciferYang LuciferYang closed this Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant