Skip to content

fix(serde): resolve persisted parquet paths relative to the configured directory - #945

Open
elijahbenizzy wants to merge 1 commit into
mainfrom
fix/serde-pandas-path-resolution
Open

elijahbenizzy wants to merge 1 commit into
mainfrom
fix/serde-pandas-path-resolution

Conversation

@elijahbenizzy

Copy link
Copy Markdown
Contributor

The pandas serde stored the full joined path of the parquet file in persisted state and passed whatever came back out of state straight to pd.read_parquet. This change records only the file name and, on load, resolves it against the configured pandas_kwargs["path"] directory, rejecting values that resolve outside that directory or that look like URLs.

Behavior notes:

  • Deserialization now requires the same path entry in pandas_kwargs that serialization already required. All built-in persisters pass identical serde_kwargs in both directions, so existing configurations are unaffected.
  • State written by earlier versions (absolute path) still loads as long as it resolves inside the configured directory.

Tests cover round-trip, nested relative directories, legacy absolute paths, and the rejected shapes.

…d directory

The pandas DataFrame serde now records only the parquet file name in persisted
state and resolves it against pandas_kwargs["path"] on load. The resolved path
must land inside that directory; URL-style values and paths resolving outside
it raise ValueError. Absolute paths recorded by earlier versions still load
when they resolve inside the configured directory. Deserialization now
requires the same `path` entry serialization already required.
@elijahbenizzy
elijahbenizzy requested a review from skrawcz October 4, 2026 20:29
@github-actions github-actions Bot added the area/integrations External integrations (LLMs, frameworks) label Oct 4, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/integrations External integrations (LLMs, frameworks)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant