uschindler commented on PR #16478:
URL: https://github.com/apache/lucene/pull/16478#issuecomment-5685647097

   Hi,
   I think IOException is correct here, because all the othr code throws this. 
Changing that to CorruptIndexException would need more refactoring and should 
be a separate PR. I don't think this is relevant here.
   
   Actually the patch looks fine. According to Lucene's 
https://github.com/apache/lucene/blob/main/SECURITY.md it is not a security 
issue, because modified or hostile are not treated as security issue, because 
index files are trusted 
(https://github.com/apache/lucene/blob/main/SECURITY.md#index-files-are-trusted).
 As this does not seem to be performance relevant, it falls under 
https://github.com/apache/lucene/blob/main/SECURITY.md#reporting-out-of-scope-issues-publicly
   
   So:
   +1 to add this (with IOException) - for consistency.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to