Details
-
Improvement
-
Status: Closed
-
Major
-
Resolution: Fixed
-
None
-
None
-
None
-
Incompatible change, Reviewed
-
UNIX-style sticky bit implemented for HDFS directories. When the sticky bit is set on a directory, files in that directory may be deleted or renamed only by a superuser or the file's owner.
Description
Our users (especially Pig) heavily use /tmp for temporary storage.
Permission are set to 777.
However, this means any users can rename and also remove (by moving to .Trash) other users directories and files.
It would be nice if we can have a sticky bit like unix.
Copy&Pasted from manpage.
STICKY DIRECTORIES
When the sticky bit is set on a directory, files in that directory may be unlinked or renamed only by
root or their owner. Without the sticky bit, anyone able to write to the directory can delete or rename
files. The sticky bit is commonly found on directories, such as /tmp, that are world-writable.
Attachments
Attachments
Issue Links
- relates to
-
HADOOP-4487 Security features for Hadoop
-
- Closed
-