Hadoop HDFS
  1. Hadoop HDFS
  2. HDFS-4162

Some malformed and unquoted HTML strings are returned from datanode web ui

    Details

    • Type: Bug Bug
    • Status: Closed
    • Priority: Minor Minor
    • Resolution: Fixed
    • Affects Version/s: 0.23.4
    • Fix Version/s: 3.0.0, 2.0.3-alpha, 0.23.5
    • Component/s: datanode
    • Labels:
      None

      Description

      When browsing to the datanode at /browseDirectory.jsp, if a path with HTML characters is requested, the resulting error page echos back the input unquoted.

      Example:

      http://localhost:50075/browseDirectory.jsp?dir=/<xss>&go=go&namenodeInfoPort=50070&nnaddr=localhost%3A9000

      Writes an input element as part of the response:

      <input name="dir" type="text" width="50" id"dir" value="/<xss>">

      • The value of the "value" attribute is not quoted.
      • An = must follow the "id" attribute name.
      • Element "input" should have a closing tag.

      The output should be something like:

      <input name="dir" type="text" width="50" id="dir" value="/<xss>"/>

      In addition, if one creates a directory:

      hdfs dfs -put '/some/path/to/<xss>'

      Then browsing to the parent of directory '<xss>' prints unquoted HTML in the directory names.

      1. HDFS-4162-branch-0.23.patch
        7 kB
        Derek Dagit
      2. HDFS-4162.patch
        7 kB
        Derek Dagit

        Activity

        Hide
        Suresh Srinivas added a comment -

        Derek, if you want to work on this, I can assign this issue to you. I will review the patch and commit it.

        Show
        Suresh Srinivas added a comment - Derek, if you want to work on this, I can assign this issue to you. I will review the patch and commit it.
        Hide
        Derek Dagit added a comment -

        Yes, please give me permission to assign this to myself.

        Show
        Derek Dagit added a comment - Yes, please give me permission to assign this to myself.
        Hide
        Suresh Srinivas added a comment -

        Derek I have added you as a HDFS contributor. Now you can assign HDFS jiras to yourself.

        Show
        Suresh Srinivas added a comment - Derek I have added you as a HDFS contributor. Now you can assign HDFS jiras to yourself.
        Hide
        Hadoop QA added a comment -

        +1 overall. Here are the results of testing the latest attachment
        http://issues.apache.org/jira/secure/attachment/12552552/HDFS-4162.patch
        against trunk revision .

        +1 @author. The patch does not contain any @author tags.

        +1 tests included. The patch appears to include 1 new or modified test files.

        +1 javac. The applied patch does not increase the total number of javac compiler warnings.

        +1 javadoc. The javadoc tool did not generate any warning messages.

        +1 eclipse:eclipse. The patch built with eclipse:eclipse.

        +1 findbugs. The patch does not introduce any new Findbugs (version 1.3.9) warnings.

        +1 release audit. The applied patch does not increase the total number of release audit warnings.

        +1 core tests. The patch passed unit tests in hadoop-hdfs-project/hadoop-hdfs.

        +1 contrib tests. The patch passed contrib unit tests.

        Test results: https://builds.apache.org/job/PreCommit-HDFS-Build/3461//testReport/
        Console output: https://builds.apache.org/job/PreCommit-HDFS-Build/3461//console

        This message is automatically generated.

        Show
        Hadoop QA added a comment - +1 overall . Here are the results of testing the latest attachment http://issues.apache.org/jira/secure/attachment/12552552/HDFS-4162.patch against trunk revision . +1 @author . The patch does not contain any @author tags. +1 tests included . The patch appears to include 1 new or modified test files. +1 javac . The applied patch does not increase the total number of javac compiler warnings. +1 javadoc . The javadoc tool did not generate any warning messages. +1 eclipse:eclipse . The patch built with eclipse:eclipse. +1 findbugs . The patch does not introduce any new Findbugs (version 1.3.9) warnings. +1 release audit . The applied patch does not increase the total number of release audit warnings. +1 core tests . The patch passed unit tests in hadoop-hdfs-project/hadoop-hdfs. +1 contrib tests . The patch passed contrib unit tests. Test results: https://builds.apache.org/job/PreCommit-HDFS-Build/3461//testReport/ Console output: https://builds.apache.org/job/PreCommit-HDFS-Build/3461//console This message is automatically generated.
        Hide
        Jing Zhao added a comment -

        The patch looks good while it will be better to format the test code a little bit (e.g., remove unnecessary blank lines in the beginning and end, and make the line length <= 80). +1 for the patch.

        Show
        Jing Zhao added a comment - The patch looks good while it will be better to format the test code a little bit (e.g., remove unnecessary blank lines in the beginning and end, and make the line length <= 80). +1 for the patch.
        Hide
        Derek Dagit added a comment -

        Addressing formatting comments

        Show
        Derek Dagit added a comment - Addressing formatting comments
        Hide
        Derek Dagit added a comment -

        Fixes formatting in new test method

        Show
        Derek Dagit added a comment - Fixes formatting in new test method
        Hide
        Jing Zhao added a comment -

        +1 for the new patches.

        Show
        Jing Zhao added a comment - +1 for the new patches.
        Hide
        Hadoop QA added a comment -

        +1 overall. Here are the results of testing the latest attachment
        http://issues.apache.org/jira/secure/attachment/12552698/HDFS-4162.patch
        against trunk revision .

        +1 @author. The patch does not contain any @author tags.

        +1 tests included. The patch appears to include 1 new or modified test files.

        +1 javac. The applied patch does not increase the total number of javac compiler warnings.

        +1 javadoc. The javadoc tool did not generate any warning messages.

        +1 eclipse:eclipse. The patch built with eclipse:eclipse.

        +1 findbugs. The patch does not introduce any new Findbugs (version 1.3.9) warnings.

        +1 release audit. The applied patch does not increase the total number of release audit warnings.

        +1 core tests. The patch passed unit tests in hadoop-hdfs-project/hadoop-hdfs.

        +1 contrib tests. The patch passed contrib unit tests.

        Test results: https://builds.apache.org/job/PreCommit-HDFS-Build/3466//testReport/
        Console output: https://builds.apache.org/job/PreCommit-HDFS-Build/3466//console

        This message is automatically generated.

        Show
        Hadoop QA added a comment - +1 overall . Here are the results of testing the latest attachment http://issues.apache.org/jira/secure/attachment/12552698/HDFS-4162.patch against trunk revision . +1 @author . The patch does not contain any @author tags. +1 tests included . The patch appears to include 1 new or modified test files. +1 javac . The applied patch does not increase the total number of javac compiler warnings. +1 javadoc . The javadoc tool did not generate any warning messages. +1 eclipse:eclipse . The patch built with eclipse:eclipse. +1 findbugs . The patch does not introduce any new Findbugs (version 1.3.9) warnings. +1 release audit . The applied patch does not increase the total number of release audit warnings. +1 core tests . The patch passed unit tests in hadoop-hdfs-project/hadoop-hdfs. +1 contrib tests . The patch passed contrib unit tests. Test results: https://builds.apache.org/job/PreCommit-HDFS-Build/3466//testReport/ Console output: https://builds.apache.org/job/PreCommit-HDFS-Build/3466//console This message is automatically generated.
        Hide
        Suresh Srinivas added a comment -

        Committed the change to branch-2 and trunk. Thank you Darek.

        Show
        Suresh Srinivas added a comment - Committed the change to branch-2 and trunk. Thank you Darek.
        Hide
        Hudson added a comment -

        Integrated in Hadoop-trunk-Commit #2990 (See https://builds.apache.org/job/Hadoop-trunk-Commit/2990/)
        HDFS-4162. Some malformed and unquoted HTML strings are returned from datanode web ui. Contributed by Darek Dagit. (Revision 1407556)

        Result = SUCCESS
        suresh : http://svn.apache.org/viewcvs.cgi/?root=Apache-SVN&view=rev&rev=1407556
        Files :

        • /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/CHANGES.txt
        • /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/common/JspHelper.java
        • /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/datanode/DatanodeJspHelper.java
        • /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/test/java/org/apache/hadoop/hdfs/server/common/TestJspHelper.java
        Show
        Hudson added a comment - Integrated in Hadoop-trunk-Commit #2990 (See https://builds.apache.org/job/Hadoop-trunk-Commit/2990/ ) HDFS-4162 . Some malformed and unquoted HTML strings are returned from datanode web ui. Contributed by Darek Dagit. (Revision 1407556) Result = SUCCESS suresh : http://svn.apache.org/viewcvs.cgi/?root=Apache-SVN&view=rev&rev=1407556 Files : /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/CHANGES.txt /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/common/JspHelper.java /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/datanode/DatanodeJspHelper.java /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/test/java/org/apache/hadoop/hdfs/server/common/TestJspHelper.java
        Hide
        Thomas Graves added a comment -

        I pulled this into branch-0.23 also.

        Show
        Thomas Graves added a comment - I pulled this into branch-0.23 also.
        Hide
        Suresh Srinivas added a comment -

        Thx Thomas. I was about to do that as well

        Show
        Suresh Srinivas added a comment - Thx Thomas. I was about to do that as well
        Hide
        Hudson added a comment -

        Integrated in Hadoop-Yarn-trunk #32 (See https://builds.apache.org/job/Hadoop-Yarn-trunk/32/)
        HDFS-4162. Some malformed and unquoted HTML strings are returned from datanode web ui. Contributed by Darek Dagit. (Revision 1407556)

        Result = SUCCESS
        suresh : http://svn.apache.org/viewcvs.cgi/?root=Apache-SVN&view=rev&rev=1407556
        Files :

        • /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/CHANGES.txt
        • /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/common/JspHelper.java
        • /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/datanode/DatanodeJspHelper.java
        • /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/test/java/org/apache/hadoop/hdfs/server/common/TestJspHelper.java
        Show
        Hudson added a comment - Integrated in Hadoop-Yarn-trunk #32 (See https://builds.apache.org/job/Hadoop-Yarn-trunk/32/ ) HDFS-4162 . Some malformed and unquoted HTML strings are returned from datanode web ui. Contributed by Darek Dagit. (Revision 1407556) Result = SUCCESS suresh : http://svn.apache.org/viewcvs.cgi/?root=Apache-SVN&view=rev&rev=1407556 Files : /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/CHANGES.txt /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/common/JspHelper.java /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/datanode/DatanodeJspHelper.java /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/test/java/org/apache/hadoop/hdfs/server/common/TestJspHelper.java
        Hide
        Hudson added a comment -

        Integrated in Hadoop-Hdfs-0.23-Build #431 (See https://builds.apache.org/job/Hadoop-Hdfs-0.23-Build/431/)
        HDFS-4162. Some malformed and unquoted HTML strings are returned from datanode web ui. (Darek Dagit via tgraves) (Revision 1407590)

        Result = UNSTABLE
        tgraves : http://svn.apache.org/viewcvs.cgi/?root=Apache-SVN&view=rev&rev=1407590
        Files :

        • /hadoop/common/branches/branch-0.23/hadoop-hdfs-project/hadoop-hdfs/CHANGES.txt
        • /hadoop/common/branches/branch-0.23/hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/common/JspHelper.java
        • /hadoop/common/branches/branch-0.23/hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/datanode/DatanodeJspHelper.java
        • /hadoop/common/branches/branch-0.23/hadoop-hdfs-project/hadoop-hdfs/src/test/java/org/apache/hadoop/hdfs/server/common/TestJspHelper.java
        Show
        Hudson added a comment - Integrated in Hadoop-Hdfs-0.23-Build #431 (See https://builds.apache.org/job/Hadoop-Hdfs-0.23-Build/431/ ) HDFS-4162 . Some malformed and unquoted HTML strings are returned from datanode web ui. (Darek Dagit via tgraves) (Revision 1407590) Result = UNSTABLE tgraves : http://svn.apache.org/viewcvs.cgi/?root=Apache-SVN&view=rev&rev=1407590 Files : /hadoop/common/branches/branch-0.23/hadoop-hdfs-project/hadoop-hdfs/CHANGES.txt /hadoop/common/branches/branch-0.23/hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/common/JspHelper.java /hadoop/common/branches/branch-0.23/hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/datanode/DatanodeJspHelper.java /hadoop/common/branches/branch-0.23/hadoop-hdfs-project/hadoop-hdfs/src/test/java/org/apache/hadoop/hdfs/server/common/TestJspHelper.java
        Hide
        Hudson added a comment -

        Integrated in Hadoop-Hdfs-trunk #1222 (See https://builds.apache.org/job/Hadoop-Hdfs-trunk/1222/)
        HDFS-4162. Some malformed and unquoted HTML strings are returned from datanode web ui. Contributed by Darek Dagit. (Revision 1407556)

        Result = SUCCESS
        suresh : http://svn.apache.org/viewcvs.cgi/?root=Apache-SVN&view=rev&rev=1407556
        Files :

        • /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/CHANGES.txt
        • /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/common/JspHelper.java
        • /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/datanode/DatanodeJspHelper.java
        • /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/test/java/org/apache/hadoop/hdfs/server/common/TestJspHelper.java
        Show
        Hudson added a comment - Integrated in Hadoop-Hdfs-trunk #1222 (See https://builds.apache.org/job/Hadoop-Hdfs-trunk/1222/ ) HDFS-4162 . Some malformed and unquoted HTML strings are returned from datanode web ui. Contributed by Darek Dagit. (Revision 1407556) Result = SUCCESS suresh : http://svn.apache.org/viewcvs.cgi/?root=Apache-SVN&view=rev&rev=1407556 Files : /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/CHANGES.txt /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/common/JspHelper.java /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/datanode/DatanodeJspHelper.java /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/test/java/org/apache/hadoop/hdfs/server/common/TestJspHelper.java
        Hide
        Hudson added a comment -

        Integrated in Hadoop-Mapreduce-trunk #1253 (See https://builds.apache.org/job/Hadoop-Mapreduce-trunk/1253/)
        HDFS-4162. Some malformed and unquoted HTML strings are returned from datanode web ui. Contributed by Darek Dagit. (Revision 1407556)

        Result = FAILURE
        suresh : http://svn.apache.org/viewcvs.cgi/?root=Apache-SVN&view=rev&rev=1407556
        Files :

        • /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/CHANGES.txt
        • /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/common/JspHelper.java
        • /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/datanode/DatanodeJspHelper.java
        • /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/test/java/org/apache/hadoop/hdfs/server/common/TestJspHelper.java
        Show
        Hudson added a comment - Integrated in Hadoop-Mapreduce-trunk #1253 (See https://builds.apache.org/job/Hadoop-Mapreduce-trunk/1253/ ) HDFS-4162 . Some malformed and unquoted HTML strings are returned from datanode web ui. Contributed by Darek Dagit. (Revision 1407556) Result = FAILURE suresh : http://svn.apache.org/viewcvs.cgi/?root=Apache-SVN&view=rev&rev=1407556 Files : /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/CHANGES.txt /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/common/JspHelper.java /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/main/java/org/apache/hadoop/hdfs/server/datanode/DatanodeJspHelper.java /hadoop/common/trunk/hadoop-hdfs-project/hadoop-hdfs/src/test/java/org/apache/hadoop/hdfs/server/common/TestJspHelper.java

          People

          • Assignee:
            Derek Dagit
            Reporter:
            Derek Dagit
          • Votes:
            0 Vote for this issue
            Watchers:
            10 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved:

              Development