hadoop-hdfs-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Allen Wittenauer (JIRA)" <j...@apache.org>
Subject [jira] [Comment Edited] (HDFS-11048) Audit Log should escape control characters
Date Thu, 27 Oct 2016 18:28:58 GMT

    [ https://issues.apache.org/jira/browse/HDFS-11048?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15612711#comment-15612711
] 

Allen Wittenauer edited comment on HDFS-11048 at 10/27/16 6:28 PM:
-------------------------------------------------------------------

IMHO, even though it's incompatible, it probably should go into a branch-2 minor (so 2.8.0,
not 2.7.x) with the caveat that the release note needs to be _very explicit_ about what happens
pre- and post- patch so that teams have an idea of what to expect.  e.g., "real world" examples


was (Author: aw):
IMHO, even though it's incompatible, it probably should go into branch-2 with the caveat that
the release note needs to be _very explicit_ about what happens pre- and post- patch so that
teams have an idea of what to expect.  e.g., "real world" examples

> Audit Log should escape control characters
> ------------------------------------------
>
>                 Key: HDFS-11048
>                 URL: https://issues.apache.org/jira/browse/HDFS-11048
>             Project: Hadoop HDFS
>          Issue Type: Bug
>            Reporter: Eric Badger
>            Assignee: Eric Badger
>         Attachments: HDFS-11048.001.patch, HDFS-11048.002.patch
>
>
> Allowing control characters without escaping them allows for spoofing audit log entries
at worst and accidentally breaking log parsing at best.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

---------------------------------------------------------------------
To unsubscribe, e-mail: hdfs-issues-unsubscribe@hadoop.apache.org
For additional commands, e-mail: hdfs-issues-help@hadoop.apache.org


Mime
View raw message