Skip to content

Conversation

@Seaven
Copy link
Contributor

@Seaven Seaven commented Dec 24, 2025

Why I'm doing:

What I'm doing:

Fixes #issue

What type of PR is this:

  • BugFix
  • Feature
  • Enhancement
  • Refactor
  • UT
  • Doc
  • Tool

Does this PR entail a change in behavior?

  • Yes, this PR will result in a change in behavior.
  • No, this PR will not result in a change in behavior.

If yes, please specify the type of change:

  • Interface/UI changes: syntax, type conversion, expression evaluation, display information
  • Parameter changes: default values, similar parameters but with different default values
  • Policy changes: use new policy to replace old one, functionality automatically enabled
  • Feature removed
  • Miscellaneous: upgrade & downgrade compatibility, etc.

Checklist:

  • I have added test cases for my bug fix or my new feature
  • This pr needs user documentation (for new or modified features or behaviors)
    • I have added documentation for my new feature or new function
  • This is a backport pr

Bugfix cherry-pick branch check:

  • I have checked the version labels which the pr will be auto-backported to the target branch
    • 4.0
    • 3.5
    • 3.4
    • 3.3

Note

Behavioral tweak in StmtExecutor

  • For QueryStatement/InsertStmt/CreateTableAsSelectStmt, when Config.enable_sql_blacklist is on, skip verifying against the SQL blacklist if the context is a statistics connection or job; otherwise proceed as before.
  • Adds a debug log indicating the blacklist check is skipped for such statistics contexts.

Scope: FE query execution path around blacklist validation. Risk: Low; limited to statistics contexts.

Written by Cursor Bugbot for commit 646ecda. This will update automatically on new commits. Configure here.

@mergify mergify bot assigned Seaven Dec 24, 2025
@alvin-celerdata
Copy link
Contributor

@cursor review

if (context.isStatisticsConnection() || context.isStatisticsJob()) {
// For statistics connection or job, we trust it and skip sql blacklist check
LOG.debug("skip sql blacklist check for statistics connection or job. stmt: {}",
origStmt.originStmt);
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

NullPointerException when accessing origStmt for statistics logging

The code accesses origStmt.originStmt for debug logging when context.isStatisticsConnection() or context.isStatisticsJob() is true, but origStmt can be null since parsedStmt.getOrigStmt() may return null. The original code had the null check as the first condition, but the new statistics check happens before verifying origStmt != null, causing a potential NullPointerException.

Fix in Cursor Fix in Web

@sonarqubecloud
Copy link

@github-actions
Copy link

[Java-Extensions Incremental Coverage Report]

pass : 0 / 0 (0%)

@github-actions
Copy link

[FE Incremental Coverage Report]

fail : 2 / 3 (66.67%)

file detail

path covered_line new_line coverage not_covered_line_detail
🔵 com/starrocks/qe/StmtExecutor.java 2 3 66.67% [779]

@github-actions
Copy link

[BE Incremental Coverage Report]

pass : 0 / 0 (0%)

@Seaven Seaven enabled auto-merge (squash) December 26, 2025 03:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants