Uploaded image for project: 'Hadoop HDFS'
  1. Hadoop HDFS
  2. HDFS-10378

FSDirAttrOp#setOwner throws ACE with misleading message

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Minor
    • Resolution: Invalid
    • 2.8.0
    • None
    • namenode

    Description

      Calling setOwner as a non-super user does trigger AccessControlException, however, the message "Permission denied. user=user1967821757 is not the owner of inode=child" is wrong. Expect this message: "Non-super user cannot change owner".

      Output of patched unit test TestPermission.testFilePermission:

      2016-05-06 16:45:44,915 [main] INFO  security.TestPermission (TestPermission.java:testFilePermission(280)) - GOOD: got org.apache.hadoop.security.AccessControlException: Permission denied. user=user1967821757 is not the owner of inode=child1
      	at org.apache.hadoop.hdfs.server.namenode.FSPermissionChecker.checkOwner(FSPermissionChecker.java:273)
      	at org.apache.hadoop.hdfs.server.namenode.FSPermissionChecker.checkPermission(FSPermissionChecker.java:250)
      	at org.apache.hadoop.hdfs.server.namenode.FSPermissionChecker.checkPermission(FSPermissionChecker.java:190)
      	at org.apache.hadoop.hdfs.server.namenode.FSDirectory.checkPermission(FSDirectory.java:1642)
      	at org.apache.hadoop.hdfs.server.namenode.FSDirectory.checkPermission(FSDirectory.java:1626)
      	at org.apache.hadoop.hdfs.server.namenode.FSDirectory.checkOwner(FSDirectory.java:1595)
      	at org.apache.hadoop.hdfs.server.namenode.FSDirAttrOp.setOwner(FSDirAttrOp.java:88)
      	at org.apache.hadoop.hdfs.server.namenode.FSNamesystem.setOwner(FSNamesystem.java:1717)
      	at org.apache.hadoop.hdfs.server.namenode.NameNodeRpcServer.setOwner(NameNodeRpcServer.java:835)
      	at org.apache.hadoop.hdfs.protocolPB.ClientNamenodeProtocolServerSideTranslatorPB.setOwner(ClientNamenodeProtocolServerSideTranslatorPB.java:481)
      	at org.apache.hadoop.hdfs.protocol.proto.ClientNamenodeProtocolProtos$ClientNamenodeProtocol$2.callBlockingMethod(ClientNamenodeProtocolProtos.java)
      	at org.apache.hadoop.ipc.ProtobufRpcEngine$Server$ProtoBufRpcInvoker.call(ProtobufRpcEngine.java:665)
      	at org.apache.hadoop.ipc.RPC$Server.call(RPC.java:989)
      	at org.apache.hadoop.ipc.Server$Handler$1.run(Server.java:2423)
      	at org.apache.hadoop.ipc.Server$Handler$1.run(Server.java:2419)
      	at java.security.AccessController.doPrivileged(Native Method)
      	at javax.security.auth.Subject.doAs(Subject.java:415)
      	at org.apache.hadoop.security.UserGroupInformation.doAs(UserGroupInformation.java:1755)
      	at org.apache.hadoop.ipc.Server$Handler.run(Server.java:2417)
      

      Will upload the unit test patch shortly.

      Attachments

        1. HDFS-10378.001.patch
          4 kB
          John Zhuge
        2. HDFS-10378.002.patch
          8 kB
          John Zhuge
        3. HDFS-10378.003.patch
          7 kB
          John Zhuge
        4. HDFS-10378-unit.patch
          1 kB
          John Zhuge

        Activity

          People

            jzhuge John Zhuge
            jzhuge John Zhuge
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: