hadoop-hdfs-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Haohui Mai (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (HDFS-5623) NameNode: add tests for skipping ACL enforcement when permission checks are disabled, user is superuser or user is member of supergroup.
Date Tue, 25 Feb 2014 01:27:20 GMT

    [ https://issues.apache.org/jira/browse/HDFS-5623?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13911093#comment-13911093
] 

Haohui Mai commented on HDFS-5623:
----------------------------------

The patch mostly looks good, but I suggest getting rid of {{assertDirPermissionDenied}} and
{{assertDirPermissionGranted}}. It's easy to add them back when it is needed, but it is not
so trivial to remove them since they are public methods.

> NameNode: add tests for skipping ACL enforcement when permission checks are disabled,
user is superuser or user is member of supergroup.
> ----------------------------------------------------------------------------------------------------------------------------------------
>
>                 Key: HDFS-5623
>                 URL: https://issues.apache.org/jira/browse/HDFS-5623
>             Project: Hadoop HDFS
>          Issue Type: Sub-task
>          Components: namenode
>    Affects Versions: HDFS ACLs (HDFS-4685)
>            Reporter: Chris Nauroth
>            Assignee: Chris Nauroth
>         Attachments: HDFS-5623.1.patch
>
>
> The existing permission checks are skipped under the following conditions:
> * {{dfs.permissions.enabled}} is set to false.  (There are several exceptions stated
in the documentation.)
> * The user is the super-user.
> * The user is a member of the super-user group.
> Add tests verifying that ACL enforcement is also skipped for all of these cases.



--
This message was sent by Atlassian JIRA
(v6.1.5#6160)

Mime
View raw message