Return-Path: Delivered-To: apmail-hadoop-common-commits-archive@www.apache.org Received: (qmail 49881 invoked from network); 4 Mar 2011 04:44:28 -0000 Received: from hermes.apache.org (HELO mail.apache.org) (140.211.11.3) by minotaur.apache.org with SMTP; 4 Mar 2011 04:44:28 -0000 Received: (qmail 1623 invoked by uid 500); 4 Mar 2011 04:44:28 -0000 Delivered-To: apmail-hadoop-common-commits-archive@hadoop.apache.org Received: (qmail 1557 invoked by uid 500); 4 Mar 2011 04:44:28 -0000 Mailing-List: contact common-commits-help@hadoop.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: common-dev@hadoop.apache.org Delivered-To: mailing list common-commits@hadoop.apache.org Received: (qmail 1541 invoked by uid 99); 4 Mar 2011 04:44:27 -0000 Received: from nike.apache.org (HELO nike.apache.org) (192.87.106.230) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 04 Mar 2011 04:44:27 +0000 X-ASF-Spam-Status: No, hits=-2000.0 required=5.0 tests=ALL_TRUSTED X-Spam-Check-By: apache.org Received: from [140.211.11.4] (HELO eris.apache.org) (140.211.11.4) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 04 Mar 2011 04:44:25 +0000 Received: by eris.apache.org (Postfix, from userid 65534) id B01402388B42; Fri, 4 Mar 2011 04:44:04 +0000 (UTC) Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Subject: svn commit: r1077683 - in /hadoop/common/branches/branch-0.20-security-patches/src/mapred/org/apache/hadoop/mapred: LinuxTaskController.java TaskController.java Date: Fri, 04 Mar 2011 04:44:04 -0000 To: common-commits@hadoop.apache.org From: omalley@apache.org X-Mailer: svnmailer-1.0.8 Message-Id: <20110304044404.B01402388B42@eris.apache.org> X-Virus-Checked: Checked by ClamAV on apache.org Author: omalley Date: Fri Mar 4 04:44:04 2011 New Revision: 1077683 URL: http://svn.apache.org/viewvc?rev=1077683&view=rev Log: commit b9e954c8cf62cbb6117ef5a97628ab58eb531453 Author: Devaraj Das Date: Fri Sep 17 00:37:12 2010 -0700 : Fixes task log servlet vulnerabilities via symlinks. Contributed by Todd Lipcon and Devaraj Das. +++ b/YAHOO-CHANGES.txt + : Fixes task log servlet vulnerabilities via symlinks. + (Todd Lipcon and Devaraj Das) + + , : Write task initialization to avoid race conditions + leading to privilege escalation and resource leakage by performing more acti + as the user. Owen O'Malley, Devaraj Das, Chris Douglas + Modified: hadoop/common/branches/branch-0.20-security-patches/src/mapred/org/apache/hadoop/mapred/LinuxTaskController.java hadoop/common/branches/branch-0.20-security-patches/src/mapred/org/apache/hadoop/mapred/TaskController.java Modified: hadoop/common/branches/branch-0.20-security-patches/src/mapred/org/apache/hadoop/mapred/LinuxTaskController.java URL: http://svn.apache.org/viewvc/hadoop/common/branches/branch-0.20-security-patches/src/mapred/org/apache/hadoop/mapred/LinuxTaskController.java?rev=1077683&r1=1077682&r2=1077683&view=diff ============================================================================== --- hadoop/common/branches/branch-0.20-security-patches/src/mapred/org/apache/hadoop/mapred/LinuxTaskController.java (original) +++ hadoop/common/branches/branch-0.20-security-patches/src/mapred/org/apache/hadoop/mapred/LinuxTaskController.java Fri Mar 4 04:44:04 2011 @@ -317,5 +317,10 @@ class LinuxTaskController extends TaskCo } } } + + @Override + public String getRunAsUser(JobConf conf) { + return conf.getUser(); + } } Modified: hadoop/common/branches/branch-0.20-security-patches/src/mapred/org/apache/hadoop/mapred/TaskController.java URL: http://svn.apache.org/viewvc/hadoop/common/branches/branch-0.20-security-patches/src/mapred/org/apache/hadoop/mapred/TaskController.java?rev=1077683&r1=1077682&r2=1077683&view=diff ============================================================================== --- hadoop/common/branches/branch-0.20-security-patches/src/mapred/org/apache/hadoop/mapred/TaskController.java (original) +++ hadoop/common/branches/branch-0.20-security-patches/src/mapred/org/apache/hadoop/mapred/TaskController.java Fri Mar 4 04:44:04 2011 @@ -169,6 +169,13 @@ public abstract class TaskController imp } } } + + /** + * Returns the local unix user that a given job will run as. + */ + public String getRunAsUser(JobConf conf) { + return System.getProperty("user.name"); + } //Write the JVM command line to a file under the specified directory // Note that the JVM will be launched using a setuid executable, and