Hadoop HDFS
  1. Hadoop HDFS
  2. HDFS-1010

HDFSProxy: Retrieve group information from UnixUserGroupInformation instead of LdapEntry

    Details

    • Type: Bug Bug
    • Status: Closed
    • Priority: Major Major
    • Resolution: Fixed
    • Affects Version/s: 0.20.1, 0.22.0
    • Fix Version/s: 0.21.0
    • Component/s: contrib/hdfsproxy
    • Labels:
      None
    • Hadoop Flags:
      Reviewed

      Description

      LdapIpFilter in HDFSProxy shouldn't refer to the userClass attribute for group information, instead should retrieve the group association for the user based on the Unix ugi.

      1. HDFS-1010-bp-y20s.patch
        4 kB
        Srikanth Sundarrajan
      2. HDFS-1010-bp-y20.patch
        6 kB
        Srikanth Sundarrajan
      3. HDFS-1010.patch
        6 kB
        Srikanth Sundarrajan

        Issue Links

          Activity

          Hide
          Srikanth Sundarrajan added a comment -

          Patch obsoletes userClass attribute in ldap (referred in LdapIpDirFilter).

          Namenode figures out the applicable group for the user. This is not required to be done explicitly in hdfsproxy.

          Backport 20 (HDFS-1010-bp-y20.patch); This is now retrieved directly from the system (through shell). Not for commit

          Show
          Srikanth Sundarrajan added a comment - Patch obsoletes userClass attribute in ldap (referred in LdapIpDirFilter). Namenode figures out the applicable group for the user. This is not required to be done explicitly in hdfsproxy. Backport 20 ( HDFS-1010 -bp-y20.patch); This is now retrieved directly from the system (through shell). Not for commit
          Hide
          Srikanth Sundarrajan added a comment -

          Patch for HDFS-481 need to be applied before this patch

          Show
          Srikanth Sundarrajan added a comment - Patch for HDFS-481 need to be applied before this patch
          Hide
          Hadoop QA added a comment -

          -1 overall. Here are the results of testing the latest attachment
          http://issues.apache.org/jira/secure/attachment/12439267/HDFS-1010-bp-y20.patch
          against trunk revision 925004.

          +1 @author. The patch does not contain any @author tags.

          +1 tests included. The patch appears to include 3 new or modified tests.

          -1 patch. The patch command could not apply the patch.

          Console output: http://hudson.zones.apache.org/hudson/job/Hdfs-Patch-h5.grid.sp2.yahoo.net/273/console

          This message is automatically generated.

          Show
          Hadoop QA added a comment - -1 overall. Here are the results of testing the latest attachment http://issues.apache.org/jira/secure/attachment/12439267/HDFS-1010-bp-y20.patch against trunk revision 925004. +1 @author. The patch does not contain any @author tags. +1 tests included. The patch appears to include 3 new or modified tests. -1 patch. The patch command could not apply the patch. Console output: http://hudson.zones.apache.org/hudson/job/Hdfs-Patch-h5.grid.sp2.yahoo.net/273/console This message is automatically generated.
          Hide
          Srikanth Sundarrajan added a comment -

          Backport patch. Not for commit. Removed reference to userClass attribute.

          Show
          Srikanth Sundarrajan added a comment - Backport patch. Not for commit. Removed reference to userClass attribute.
          Hide
          Srikanth Sundarrajan added a comment -

          Note: Patch for HDFS-481 and HDFS-1009 need to be applied before this patch can be applied.

          Output from test-patch & test-contrib

          [exec] +1 overall.
          [exec]
          [exec] +1 @author. The patch does not contain any @author tags.
          [exec]
          [exec] +1 tests included. The patch appears to include 3 new or modified tests.
          [exec]
          [exec] +1 javadoc. The javadoc tool did not generate any warning messages.
          [exec]
          [exec] +1 javac. The applied patch does not increase the total number of javac compiler warnings.
          [exec]
          [exec] +1 findbugs. The patch does not introduce any new Findbugs warnings.
          [exec]
          [exec] +1 release audit. The applied patch does not increase the total number of release audit warnings.

          test-contrib:

          [cactus] Tomcat 5.x is stopped

          BUILD SUCCESSFUL
          Total time: 4 minutes 35 seconds

          Show
          Srikanth Sundarrajan added a comment - Note: Patch for HDFS-481 and HDFS-1009 need to be applied before this patch can be applied. Output from test-patch & test-contrib [exec] +1 overall. [exec] [exec] +1 @author. The patch does not contain any @author tags. [exec] [exec] +1 tests included. The patch appears to include 3 new or modified tests. [exec] [exec] +1 javadoc. The javadoc tool did not generate any warning messages. [exec] [exec] +1 javac. The applied patch does not increase the total number of javac compiler warnings. [exec] [exec] +1 findbugs. The patch does not introduce any new Findbugs warnings. [exec] [exec] +1 release audit. The applied patch does not increase the total number of release audit warnings. test-contrib: [cactus] Tomcat 5.x is stopped BUILD SUCCESSFUL Total time: 4 minutes 35 seconds
          Hide
          Tsz Wo Nicholas Sze added a comment -

          +1

          Show
          Tsz Wo Nicholas Sze added a comment - +1
          Hide
          Tsz Wo Nicholas Sze added a comment -

          I have committed this. Thanks, Srikanth!

          Show
          Tsz Wo Nicholas Sze added a comment - I have committed this. Thanks, Srikanth!
          Hide
          Hudson added a comment -

          Integrated in Hadoop-Hdfs-trunk-Commit #233 (See http://hudson.zones.apache.org/hudson/job/Hadoop-Hdfs-trunk-Commit/233/)
          . hdfsproxy: Retrieve groups from UnixUserGroupInformation instead of LdapEntry. Contributed by Srikanth Sundarrajan

          Show
          Hudson added a comment - Integrated in Hadoop-Hdfs-trunk-Commit #233 (See http://hudson.zones.apache.org/hudson/job/Hadoop-Hdfs-trunk-Commit/233/ ) . hdfsproxy: Retrieve groups from UnixUserGroupInformation instead of LdapEntry. Contributed by Srikanth Sundarrajan

            People

            • Assignee:
              Srikanth Sundarrajan
              Reporter:
              Srikanth Sundarrajan
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:

                Development