hadoop-hdfs-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Allen Wittenauer (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (HDFS-11048) Audit Log should escape control characters
Date Mon, 07 Nov 2016 21:42:59 GMT

    [ https://issues.apache.org/jira/browse/HDFS-11048?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15645558#comment-15645558
] 

Allen Wittenauer commented on HDFS-11048:
-----------------------------------------

bq.  I can think of one pretty contrived case where I think this might cause less than ideal
behavior.

That's my point.  I'm looking at this from the point of view of what is in the log.   "\thisfile"
is ambiguous.  That's super bad.

> Audit Log should escape control characters
> ------------------------------------------
>
>                 Key: HDFS-11048
>                 URL: https://issues.apache.org/jira/browse/HDFS-11048
>             Project: Hadoop HDFS
>          Issue Type: Bug
>            Reporter: Eric Badger
>            Assignee: Eric Badger
>             Fix For: 2.8.0, 3.0.0-alpha2
>
>         Attachments: HDFS-11048.001.patch, HDFS-11048.002.patch
>
>
> Allowing control characters without escaping them allows for spoofing audit log entries
at worst and accidentally breaking log parsing at best.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

---------------------------------------------------------------------
To unsubscribe, e-mail: hdfs-issues-unsubscribe@hadoop.apache.org
For additional commands, e-mail: hdfs-issues-help@hadoop.apache.org


Mime
View raw message