Details

    • Type: Improvement
    • Status: Resolved
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 3.0.0-alpha2
    • Fix Version/s: 3.0.0-beta1
    • Component/s: security
    • Labels:
      None
    • Target Version/s:
    • Hadoop Flags:
      Incompatible change
    • Release Note:
      Hide
      <!-- markdown -->
      HDFS-6962 introduced POSIX ACL inheritance feature but it is disable by
      default. Now enable the feature by default. Please be aware any code
      expecting the old ACL inheritance behavior will have to be updated.
      Please see the HDFS Permissions Guide for further details.
      Show
      <!-- markdown --> HDFS-6962 introduced POSIX ACL inheritance feature but it is disable by default. Now enable the feature by default. Please be aware any code expecting the old ACL inheritance behavior will have to be updated. Please see the HDFS Permissions Guide for further details.

      Description

      It is time to enable POSIX ACL inheritance by default.

      1. HDFS-11957.001.patch
        3 kB
        John Zhuge
      2. HDFS-11957.002.patch
        9 kB
        John Zhuge

        Issue Links

          Activity

          Hide
          hudson Hudson added a comment -

          SUCCESS: Integrated in Jenkins build Hadoop-trunk-Commit #12161 (See https://builds.apache.org/job/Hadoop-trunk-Commit/12161/)
          HDFS-11957. Enable POSIX ACL inheritance by default. Contributed by John (jzhuge: rev 312e57b95477ec95e6735f5721c646ad1df019f8)

          • (edit) hadoop-hdfs-project/hadoop-hdfs/src/site/markdown/HdfsPermissionsGuide.md
          • (edit) hadoop-hdfs-project/hadoop-hdfs/src/test/java/org/apache/hadoop/hdfs/server/namenode/FSAclBaseTest.java
          • (edit) hadoop-hdfs-project/hadoop-hdfs/src/test/java/org/apache/hadoop/hdfs/server/namenode/TestFSImageWithAcl.java
          • (edit) hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/DFSConfigKeys.java
          • (edit) hadoop-hdfs-project/hadoop-hdfs/src/test/java/org/apache/hadoop/cli/TestAclCLI.java
          • (edit) hadoop-hdfs-project/hadoop-hdfs/src/main/resources/hdfs-default.xml
          Show
          hudson Hudson added a comment - SUCCESS: Integrated in Jenkins build Hadoop-trunk-Commit #12161 (See https://builds.apache.org/job/Hadoop-trunk-Commit/12161/ ) HDFS-11957 . Enable POSIX ACL inheritance by default. Contributed by John (jzhuge: rev 312e57b95477ec95e6735f5721c646ad1df019f8) (edit) hadoop-hdfs-project/hadoop-hdfs/src/site/markdown/HdfsPermissionsGuide.md (edit) hadoop-hdfs-project/hadoop-hdfs/src/test/java/org/apache/hadoop/hdfs/server/namenode/FSAclBaseTest.java (edit) hadoop-hdfs-project/hadoop-hdfs/src/test/java/org/apache/hadoop/hdfs/server/namenode/TestFSImageWithAcl.java (edit) hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/DFSConfigKeys.java (edit) hadoop-hdfs-project/hadoop-hdfs/src/test/java/org/apache/hadoop/cli/TestAclCLI.java (edit) hadoop-hdfs-project/hadoop-hdfs/src/main/resources/hdfs-default.xml
          Hide
          jzhuge John Zhuge added a comment -

          Committed to trunk. Thanks Andrew Wang for the review!

          Show
          jzhuge John Zhuge added a comment - Committed to trunk. Thanks Andrew Wang for the review!
          Hide
          jzhuge John Zhuge added a comment -

          Committing to trunk tomorrow if there is no objection.

          Show
          jzhuge John Zhuge added a comment - Committing to trunk tomorrow if there is no objection.
          Hide
          andrew.wang Andrew Wang added a comment -

          John, do you think we can get this in?

          Show
          andrew.wang Andrew Wang added a comment - John, do you think we can get this in?
          Hide
          jzhuge John Zhuge added a comment -

          Thanks Andrew Wang!

          Chris Nauroth, what do you think? 3.0 release is a good opportunity for this incompatible change.

          Show
          jzhuge John Zhuge added a comment - Thanks Andrew Wang ! Chris Nauroth , what do you think? 3.0 release is a good opportunity for this incompatible change.
          Hide
          andrew.wang Andrew Wang added a comment -

          +1 LGTM, thanks John!

          Show
          andrew.wang Andrew Wang added a comment - +1 LGTM, thanks John!
          Hide
          jzhuge John Zhuge added a comment -

          TestEditLogTailer failure is unrelated. It also passes for me locally so it looks like a flaky test failure. Filed HDFS-12122.

          Show
          jzhuge John Zhuge added a comment - TestEditLogTailer failure is unrelated. It also passes for me locally so it looks like a flaky test failure. Filed HDFS-12122 .
          Hide
          hadoopqa Hadoop QA added a comment -
          -1 overall



          Vote Subsystem Runtime Comment
          0 reexec 0m 13s Docker mode activated.
                Prechecks
          +1 @author 0m 0s The patch does not contain any @author tags.
          +1 test4tests 0m 0s The patch appears to include 3 new or modified test files.
                trunk Compile Tests
          +1 mvninstall 13m 16s trunk passed
          +1 compile 0m 47s trunk passed
          +1 checkstyle 0m 45s trunk passed
          +1 mvnsite 0m 53s trunk passed
          -1 findbugs 1m 39s hadoop-hdfs-project/hadoop-hdfs in trunk has 10 extant Findbugs warnings.
          +1 javadoc 0m 39s trunk passed
                Patch Compile Tests
          +1 mvninstall 0m 48s the patch passed
          +1 compile 0m 45s the patch passed
          +1 javac 0m 45s the patch passed
          +1 checkstyle 0m 42s the patch passed
          +1 mvnsite 0m 51s the patch passed
          +1 whitespace 0m 0s The patch has no whitespace issues.
          +1 xml 0m 1s The patch has no ill-formed XML file.
          +1 findbugs 1m 47s the patch passed
          +1 javadoc 0m 37s the patch passed
                Other Tests
          -1 unit 66m 10s hadoop-hdfs in the patch failed.
          +1 asflicense 0m 19s The patch does not generate ASF License warnings.
          91m 27s



          Reason Tests
          Failed junit tests hadoop.hdfs.server.namenode.ha.TestEditLogTailer



          Subsystem Report/Notes
          Docker Image:yetus/hadoop:14b5c93
          JIRA Issue HDFS-11957
          JIRA Patch URL https://issues.apache.org/jira/secure/attachment/12876567/HDFS-11957.002.patch
          Optional Tests asflicense compile javac javadoc mvninstall mvnsite unit findbugs checkstyle xml
          uname Linux 9c947cb0b5e5 3.13.0-116-generic #163-Ubuntu SMP Fri Mar 31 14:13:22 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux
          Build tool maven
          Personality /testptch/hadoop/patchprocess/precommit/personality/provided.sh
          git revision trunk / fce7951
          Default Java 1.8.0_131
          findbugs v3.1.0-RC1
          findbugs https://builds.apache.org/job/PreCommit-HDFS-Build/20225/artifact/patchprocess/branch-findbugs-hadoop-hdfs-project_hadoop-hdfs-warnings.html
          unit https://builds.apache.org/job/PreCommit-HDFS-Build/20225/artifact/patchprocess/patch-unit-hadoop-hdfs-project_hadoop-hdfs.txt
          Test Results https://builds.apache.org/job/PreCommit-HDFS-Build/20225/testReport/
          modules C: hadoop-hdfs-project/hadoop-hdfs U: hadoop-hdfs-project/hadoop-hdfs
          Console output https://builds.apache.org/job/PreCommit-HDFS-Build/20225/console
          Powered by Apache Yetus 0.6.0-SNAPSHOT http://yetus.apache.org

          This message was automatically generated.

          Show
          hadoopqa Hadoop QA added a comment - -1 overall Vote Subsystem Runtime Comment 0 reexec 0m 13s Docker mode activated.       Prechecks +1 @author 0m 0s The patch does not contain any @author tags. +1 test4tests 0m 0s The patch appears to include 3 new or modified test files.       trunk Compile Tests +1 mvninstall 13m 16s trunk passed +1 compile 0m 47s trunk passed +1 checkstyle 0m 45s trunk passed +1 mvnsite 0m 53s trunk passed -1 findbugs 1m 39s hadoop-hdfs-project/hadoop-hdfs in trunk has 10 extant Findbugs warnings. +1 javadoc 0m 39s trunk passed       Patch Compile Tests +1 mvninstall 0m 48s the patch passed +1 compile 0m 45s the patch passed +1 javac 0m 45s the patch passed +1 checkstyle 0m 42s the patch passed +1 mvnsite 0m 51s the patch passed +1 whitespace 0m 0s The patch has no whitespace issues. +1 xml 0m 1s The patch has no ill-formed XML file. +1 findbugs 1m 47s the patch passed +1 javadoc 0m 37s the patch passed       Other Tests -1 unit 66m 10s hadoop-hdfs in the patch failed. +1 asflicense 0m 19s The patch does not generate ASF License warnings. 91m 27s Reason Tests Failed junit tests hadoop.hdfs.server.namenode.ha.TestEditLogTailer Subsystem Report/Notes Docker Image:yetus/hadoop:14b5c93 JIRA Issue HDFS-11957 JIRA Patch URL https://issues.apache.org/jira/secure/attachment/12876567/HDFS-11957.002.patch Optional Tests asflicense compile javac javadoc mvninstall mvnsite unit findbugs checkstyle xml uname Linux 9c947cb0b5e5 3.13.0-116-generic #163-Ubuntu SMP Fri Mar 31 14:13:22 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux Build tool maven Personality /testptch/hadoop/patchprocess/precommit/personality/provided.sh git revision trunk / fce7951 Default Java 1.8.0_131 findbugs v3.1.0-RC1 findbugs https://builds.apache.org/job/PreCommit-HDFS-Build/20225/artifact/patchprocess/branch-findbugs-hadoop-hdfs-project_hadoop-hdfs-warnings.html unit https://builds.apache.org/job/PreCommit-HDFS-Build/20225/artifact/patchprocess/patch-unit-hadoop-hdfs-project_hadoop-hdfs.txt Test Results https://builds.apache.org/job/PreCommit-HDFS-Build/20225/testReport/ modules C: hadoop-hdfs-project/hadoop-hdfs U: hadoop-hdfs-project/hadoop-hdfs Console output https://builds.apache.org/job/PreCommit-HDFS-Build/20225/console Powered by Apache Yetus 0.6.0-SNAPSHOT http://yetus.apache.org This message was automatically generated.
          Hide
          jzhuge John Zhuge added a comment -

          Patch 002

          • Update TestAclCLI and TestFSImageWithAcl
          • TestFileContextAcl and TestNameNodeAcl pass without any change
          Show
          jzhuge John Zhuge added a comment - Patch 002 Update TestAclCLI and TestFSImageWithAcl TestFileContextAcl and TestNameNodeAcl pass without any change
          Hide
          jzhuge John Zhuge added a comment -

          Yes Chen Liang, ACL test failures are related.

          Show
          jzhuge John Zhuge added a comment - Yes Chen Liang , ACL test failures are related.
          Hide
          vagarychen Chen Liang added a comment -

          Thanks John Zhuge for the patch. The change itself in v001 patch LGTM, but seems the test failures are related. I only quickly checked TestAclCLI locally, seems the patch might indeed have conflicted the behaviour this test is currently expecting.

          Show
          vagarychen Chen Liang added a comment - Thanks John Zhuge for the patch. The change itself in v001 patch LGTM, but seems the test failures are related. I only quickly checked TestAclCLI locally, seems the patch might indeed have conflicted the behaviour this test is currently expecting.
          Hide
          hadoopqa Hadoop QA added a comment -
          -1 overall



          Vote Subsystem Runtime Comment
          0 reexec 0m 54s Docker mode activated.
          +1 @author 0m 0s The patch does not contain any @author tags.
          -1 test4tests 0m 0s The patch doesn't appear to include any new or modified tests. Please justify why no new tests are needed for this patch. Also please list what manual steps were performed to verify this patch.
          +1 mvninstall 13m 6s trunk passed
          +1 compile 0m 48s trunk passed
          +1 checkstyle 0m 39s trunk passed
          +1 mvnsite 0m 52s trunk passed
          +1 findbugs 1m 37s trunk passed
          +1 javadoc 0m 40s trunk passed
          +1 mvninstall 0m 48s the patch passed
          +1 compile 0m 44s the patch passed
          +1 javac 0m 44s the patch passed
          +1 checkstyle 0m 37s the patch passed
          +1 mvnsite 0m 49s the patch passed
          +1 whitespace 0m 0s The patch has no whitespace issues.
          +1 xml 0m 2s The patch has no ill-formed XML file.
          +1 findbugs 1m 43s the patch passed
          +1 javadoc 0m 37s the patch passed
          -1 unit 65m 46s hadoop-hdfs in the patch failed.
          +1 asflicense 0m 19s The patch does not generate ASF License warnings.
          91m 20s



          Reason Tests
          Failed junit tests hadoop.hdfs.server.namenode.TestFSImageWithAcl
            hadoop.hdfs.web.TestWebHDFSAcl
            hadoop.cli.TestAclCLI
            hadoop.hdfs.TestDFSStripedOutputStreamWithFailure010
            hadoop.hdfs.server.namenode.TestFileContextAcl
            hadoop.hdfs.server.namenode.TestNameNodeAcl
          Timed out junit tests org.apache.hadoop.hdfs.TestReplication



          Subsystem Report/Notes
          Docker Image:yetus/hadoop:14b5c93
          JIRA Issue HDFS-11957
          JIRA Patch URL https://issues.apache.org/jira/secure/attachment/12872277/HDFS-11957.001.patch
          Optional Tests asflicense compile javac javadoc mvninstall mvnsite unit findbugs checkstyle xml
          uname Linux 455c0a184cf8 3.13.0-106-generic #153-Ubuntu SMP Tue Dec 6 15:44:32 UTC 2016 x86_64 x86_64 x86_64 GNU/Linux
          Build tool maven
          Personality /testptch/hadoop/patchprocess/precommit/personality/provided.sh
          git revision trunk / 99634d1
          Default Java 1.8.0_131
          findbugs v3.1.0-RC1
          unit https://builds.apache.org/job/PreCommit-HDFS-Build/19850/artifact/patchprocess/patch-unit-hadoop-hdfs-project_hadoop-hdfs.txt
          Test Results https://builds.apache.org/job/PreCommit-HDFS-Build/19850/testReport/
          modules C: hadoop-hdfs-project/hadoop-hdfs U: hadoop-hdfs-project/hadoop-hdfs
          Console output https://builds.apache.org/job/PreCommit-HDFS-Build/19850/console
          Powered by Apache Yetus 0.5.0-SNAPSHOT http://yetus.apache.org

          This message was automatically generated.

          Show
          hadoopqa Hadoop QA added a comment - -1 overall Vote Subsystem Runtime Comment 0 reexec 0m 54s Docker mode activated. +1 @author 0m 0s The patch does not contain any @author tags. -1 test4tests 0m 0s The patch doesn't appear to include any new or modified tests. Please justify why no new tests are needed for this patch. Also please list what manual steps were performed to verify this patch. +1 mvninstall 13m 6s trunk passed +1 compile 0m 48s trunk passed +1 checkstyle 0m 39s trunk passed +1 mvnsite 0m 52s trunk passed +1 findbugs 1m 37s trunk passed +1 javadoc 0m 40s trunk passed +1 mvninstall 0m 48s the patch passed +1 compile 0m 44s the patch passed +1 javac 0m 44s the patch passed +1 checkstyle 0m 37s the patch passed +1 mvnsite 0m 49s the patch passed +1 whitespace 0m 0s The patch has no whitespace issues. +1 xml 0m 2s The patch has no ill-formed XML file. +1 findbugs 1m 43s the patch passed +1 javadoc 0m 37s the patch passed -1 unit 65m 46s hadoop-hdfs in the patch failed. +1 asflicense 0m 19s The patch does not generate ASF License warnings. 91m 20s Reason Tests Failed junit tests hadoop.hdfs.server.namenode.TestFSImageWithAcl   hadoop.hdfs.web.TestWebHDFSAcl   hadoop.cli.TestAclCLI   hadoop.hdfs.TestDFSStripedOutputStreamWithFailure010   hadoop.hdfs.server.namenode.TestFileContextAcl   hadoop.hdfs.server.namenode.TestNameNodeAcl Timed out junit tests org.apache.hadoop.hdfs.TestReplication Subsystem Report/Notes Docker Image:yetus/hadoop:14b5c93 JIRA Issue HDFS-11957 JIRA Patch URL https://issues.apache.org/jira/secure/attachment/12872277/HDFS-11957.001.patch Optional Tests asflicense compile javac javadoc mvninstall mvnsite unit findbugs checkstyle xml uname Linux 455c0a184cf8 3.13.0-106-generic #153-Ubuntu SMP Tue Dec 6 15:44:32 UTC 2016 x86_64 x86_64 x86_64 GNU/Linux Build tool maven Personality /testptch/hadoop/patchprocess/precommit/personality/provided.sh git revision trunk / 99634d1 Default Java 1.8.0_131 findbugs v3.1.0-RC1 unit https://builds.apache.org/job/PreCommit-HDFS-Build/19850/artifact/patchprocess/patch-unit-hadoop-hdfs-project_hadoop-hdfs.txt Test Results https://builds.apache.org/job/PreCommit-HDFS-Build/19850/testReport/ modules C: hadoop-hdfs-project/hadoop-hdfs U: hadoop-hdfs-project/hadoop-hdfs Console output https://builds.apache.org/job/PreCommit-HDFS-Build/19850/console Powered by Apache Yetus 0.5.0-SNAPSHOT http://yetus.apache.org This message was automatically generated.
          Hide
          jzhuge John Zhuge added a comment -

          Patch 001

          • Update DFS_NAMENODE_POSIX_ACL_INHERITANCE_ENABLED_DEFAULT
          • Update hdfs-default.xml
          • Update doc
          Show
          jzhuge John Zhuge added a comment - Patch 001 Update DFS_NAMENODE_POSIX_ACL_INHERITANCE_ENABLED_DEFAULT Update hdfs-default.xml Update doc

            People

            • Assignee:
              jzhuge John Zhuge
              Reporter:
              jzhuge John Zhuge
            • Votes:
              0 Vote for this issue
              Watchers:
              8 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:

                Development