[BUG] Validation of message with `com.google.protobuf.Timestamp` fails with `java.time.DateTimeException` if seconds/nanos exceed `Instant` bounds
还没有人认领这个 Issue。
评估
调研方向
从 src/main/java/build/buf/protovalidate/ProtoAdapter.java 中第 93-104 行附近的 scalarToCel 转换开始,然后使用 seconds 值为 Long.MAX_VALUE 的 Timestamp 重现验证。检查 Timestamp 和 Duration 的极端值,并在验证返回明确的验证错误而不是传播日期或算术异常时,认为工作已完成。
由索引模型根据 Issue 内容生成。
描述
Description
Validation of com.google.protobuf.Timestamp fails with java.time.DateTimeException when the timestamp's seconds or nanoseconds values exceed the bounds that can be represented by Java's Instant class. This occurs when attempting to validate protobuf messages containing timestamps with extreme values like Long.MAX_VALUE for seconds, which cannot be converted to a valid Instant object.
The underlying issue is in ProtoAdapter class:
Similar issue seems to also affect com.google.protobuf.Duration if using extreme nanos values due to the ProtoAdapter implementation linked above.
Steps to Reproduce
- Define a protobuf message with a
google.protobuf.Timestampfield:
syntax = "proto3";
package acme.foo.v1;
import "buf/validate/validate.proto";
message Foo {
google.protobuf.Timestamp bar = 1;
}
- Create a protobuf message instance with timestamp seconds set to
Long.MAX_VALUE:
Foo message = Foo.newBuilder()
.setBar(Timestamp.newBuilder().setSeconds(Long.MAX_VALUE))
.build();
- Attempt to validate the message using protovalidate:
ValidationResult result = validator.validate(message); - Observe the
java.time.DateTimeExceptionbeing thrown during validation
Expected Behavior
The validation should provide a clear validation error indicating the timestamp is out of bounds instead of throwing uncaught java.time.DateTimeException
Actual Behavior
A java.time.DateTimeException is thrown when the validator attempts to convert the protobuf timestamp to a Java Instant object, causing the entire validation process to fail with an unhandled exception rather than a proper validation error.
Screenshots/Logs
java.time.DateTimeException: Instant exceeds minimum or maximum instant
at java.base/java.time.Instant.create(Instant.java:414)
at java.base/java.time.Instant.ofEpochSecond(Instant.java:334)
at build.buf.protovalidate.ProtoAdapter.scalarToCel(ProtoAdapter.java:98)
at build.buf.protovalidate.ProtoAdapter.toCel(ProtoAdapter.java:65)
at build.buf.protovalidate.ObjectValue.value(ObjectValue.java:65)
at build.buf.protovalidate.ValueEvaluator.evaluate(ValueEvaluator.java:74)
at build.buf.protovalidate.FieldEvaluator.evaluate(FieldEvaluator.java:121)
at build.buf.protovalidate.MessageEvaluator.evaluate(MessageEvaluator.java:41)
Environment
- Protovalidate Version: v1.0.1
Possible Solution
The protovalidate ProtoAdapter class or some other part of logic before it should:
- Add bounds checking before attempting to convert protobuf timestamps to Java
Instantobjects or protobuf durations to JavaDurationobjects. - Or catch
DateTimeException(timestamp to Instant case) /ArithmeticException(duration case) during protobuf to Java instance conversion and convert it to a proper validation error
- 主要语言
- Java
- 星标
- 70
- 派生
- 17
- 平均合并
- 2 天 13 小时
- 30 天内合并 PR
- 13
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
bufbuild/protovalidate-java 的其他 Issue
-
难度 3/5 1-2 天 新手友好度 25/100
bufbuild/protovalidate-java#362 · 1 条评论 ·
-
Feature
bufbuild/protovalidate-java#80 · 已指派 1 人 ·
查看 bufbuild/protovalidate-java 的全部 Issue
相似的 Issue
-
documentation
难度 2/5 1-3 小时 新手友好度 65/100
inu-appcenter/memorIN-backend#288 ·
-
难度 2/5 1-3 小时 新手友好度 65/100
-
frontend maui-pilot pilot-ask question
难度 2/5 1-3 小时 新手友好度 75/100
-
难度 2/5 1-3 小时 新手友好度 75/100
-
area/plugin
难度 2/5 1-3 小时 新手友好度 75/100
kestra-io/plugin-kestra#190 ·