Repository navigation
fix(util): reject LiveDocs backing sets with bits beyond maxDoc - #16768
Open
salvatorecampagna wants to merge 1 commit into
Open
salvatorecampagna wants to merge 1 commit into
salvatorecampagna wants to merge 1 commit into
Conversation
DenseLiveDocs and SparseLiveDocs accept a backing bit set longer than maxDoc, but only `applyMask` bounds on it. A bit set at or beyond maxDoc counts as a document: `deletedCount` goes wrong and two of the iterators emit doc ids that do not exist. Padding with those bits clear is correct today, so reject the set bits rather than the padding. Not reachable through `Lucene90LiveDocsFormat`, which passes exactly maxDoc.
salvatorecampagna
force-pushed
the
fix/livedocs-maxdoc-bounds
branch
from
October 2, 2026 21:25
d54ca26 to
3f5ad03
Compare
salvatorecampagna
marked this pull request as ready for review
October 3, 2026 09:12
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
TL;DR
DenseLiveDocsandSparseLiveDocstake a backing bit set that may be longer thanmaxDoc, but count it at its full length. A bit actually set pastmaxDocmakesdeletedCountwrong and makes two of the iterators return doc ids that don't exist. Both builders now reject that.Summary
Both classes accept a backing set that only has to be at least
maxDoclong whilelength()returnsmaxDoc, and onlyapplyMaskrespects that. So a bit set at or beyondmaxDoccounts as a document:deletedCountgoes wrong, andDenseLiveDocs.liveDocsIteratorandSparseLiveDocs.deletedDocsIteratoremit doc ids that don't exist.buildcan't catch it, deriving the count from an unboundedcardinalitythat still lands in[0, maxDoc].Padding is fine and stays supported, since with those bits clear the counts and iterators already agree with the deletions. So this rejects set bits at or beyond
maxDocrather than requiring exact length, which leaves #16593'sapplyMasksupport alone and means the iterators need no bound:BitSetIteratoronly emits set bits.maxDocis checked first becausenextSetBitindexes the backing set.Nothing in Lucene hits this,
Lucene90LiveDocsFormatalways passes exactlymaxDoc. Shipped in 10.5.0, so it applies tobranch_10x.Testing