Skip to content

fix(metadata): prevent table page offset overflow - #2824

Merged
openai0229 merged 2 commits into
OtterMind:mainfrom
HandSonic:fix/table-page-overflow
Sep 15, 2026
Merged

openai0229 merged 2 commits into
OtterMind:mainfrom
HandSonic:fix/table-page-overflow

Conversation

@HandSonic

@HandSonic HandSonic commented Aug 30, 2026 •

Copy link
Copy Markdown
Contributor

Related issue

N/A - no matching issue was found.

Summary

Cached relational table pagination calculated (pageNo - 1) * pageSize with int arithmetic. Accepted maximum-bound requests wrapped to negative indexes and reached subList, raising IndexOutOfBoundsException. This change derives the offset and end with long, returns an empty out-of-range page, and only converts indexes after proving they fit the table list.

Affected surfaces

  • Frontend / Web
  • Backend / API / Storage
  • Database plugin / Driver
  • JCEF / Desktop packaging
  • CI / Build / Release
  • Documentation only

Verification

  • Current-main reproduction: original test suite ran 3 tests; maximum pageNo / pageSize produced IndexOutOfBoundsException: fromIndex = -200000 before the fix.
  • After main integration, owning reactor tests and package passed: domain-core 304, SPI 147, tools 77, domain-api 27; 555 total, zero failures/errors/skips.
  • Command: mvn -B -ntp -f chat2db-community-server/pom.xml -pl :chat2db-community-domain-core -am -Dmaven.test.skip=false -DskipTests=false '-Dsurefire.includes=**/*Test.java' -Dsurefire.failIfNoSpecifiedTests=false -Dmaven.test.failure.ignore=false package. Test JVM home/temp were isolated.
  • Executable backend package passed. Playwright CLI created an actual SQLite connection through the UI and verified eight real API cases: normal pages, ordinary out-of-range pages, two overflow boundaries, search totals, search plus overflow, empty search results, then reload.
  • The two integrated PR files are byte-identical to the Web-tested version. Current-head CI is available in PR checks.
  • Extreme page numbers were sent as browser HTTP requests; this is not claimed as a normally reachable UI pagination action.

Risk and compatibility

  • Public API or stored data: No API or storage format changes.
  • Database or driver compatibility: Applies only to local cached table list slicing; metadata retrieval is unchanged.
  • Network, privacy, or security: N/A.
  • Community / Local / Pro boundary: Shared Community metadata service.
  • Backward compatibility: Normal pages preserve their existing ordering, totals, and contents; out-of-range pages remain empty.

Reviewer map

  • Start here: DbTableServiceImpl.pageQuery and the maximum-bound case in DbMetadataAccessPolicyTest.
  • Failure condition: an accepted page request produces a negative list index, or normal page slicing changes.
  • Rollback or disable path: Revert commit 785fe519d8cf776ed9c3d47f0d55e19e59b60c5e; no migration is required.

Contributor declaration

  • I linked the Issue that defines this change.
  • I tested the affected behavior and reported the actual results above.
  • I did not include credentials, private data, or generated build output.
  • I disclosed substantial AI assistance below, or this PR contains no substantial AI-generated code.

AI assistance: OpenAI Codex assisted with diagnosis, implementation, deterministic tests, verification, and adversarial review.

@HandSonic
HandSonic force-pushed the fix/table-page-overflow branch from d41de44 to 785fe51 Compare September 3, 2026 18:20
@openai0229
openai0229 merged commit 777b060 into OtterMind:main Sep 15, 2026
18 of 19 checks passed
@openai0229 openai0229 moved this from In Review to Done in Chat2DB Community Sep 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants