Return-Path: X-Original-To: apmail-hadoop-hdfs-user-archive@minotaur.apache.org Delivered-To: apmail-hadoop-hdfs-user-archive@minotaur.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id 2573B17BDA for ; Fri, 8 May 2015 16:37:03 +0000 (UTC) Received: (qmail 8417 invoked by uid 500); 8 May 2015 16:36:57 -0000 Delivered-To: apmail-hadoop-hdfs-user-archive@hadoop.apache.org Received: (qmail 8301 invoked by uid 500); 8 May 2015 16:36:57 -0000 Mailing-List: contact user-help@hadoop.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: user@hadoop.apache.org Delivered-To: mailing list user@hadoop.apache.org Received: (qmail 8289 invoked by uid 99); 8 May 2015 16:36:57 -0000 Received: from Unknown (HELO spamd3-us-west.apache.org) (209.188.14.142) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 08 May 2015 16:36:57 +0000 Received: from localhost (localhost [127.0.0.1]) by spamd3-us-west.apache.org (ASF Mail Server at spamd3-us-west.apache.org) with ESMTP id A9D46182855 for ; Fri, 8 May 2015 16:36:56 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at spamd3-us-west.apache.org X-Spam-Flag: NO X-Spam-Score: 2.9 X-Spam-Level: ** X-Spam-Status: No, score=2.9 tagged_above=-999 required=6.31 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=3, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=disabled Authentication-Results: spamd3-us-west.apache.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com Received: from mx1-us-east.apache.org ([10.40.0.8]) by localhost (spamd3-us-west.apache.org [10.40.0.10]) (amavisd-new, port 10024) with ESMTP id BMzqCrAmdfJs for ; Fri, 8 May 2015 16:36:41 +0000 (UTC) Received: from mail-ie0-f169.google.com (mail-ie0-f169.google.com [209.85.223.169]) by mx1-us-east.apache.org (ASF Mail Server at mx1-us-east.apache.org) with ESMTPS id 2AE6647548 for ; Fri, 8 May 2015 16:33:15 +0000 (UTC) Received: by iedfl3 with SMTP id fl3so75518235ied.1 for ; Fri, 08 May 2015 09:32:39 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=from:content-type:message-id:mime-version:subject:date:references :to:in-reply-to; bh=N0OVrcIWKLr65SnpktODvvqNZOk6A9JQ/2WHcboHfv4=; b=Fyk4oA1lMS2961yiLuWHZ9KxrDfoS/VrjQXWCvvk0mRAh5VKwQoyw9nN2FNmb+7GF+ qHI9+b3ZCi741MXYvwIp3dUpsZjZCpJhht0KLqSC9iPNYSrypMb7rtSabunSeNu40O9e YaFGSEhVk7Aby7fi9cdSq0YCKZ5onFsTodfPpqkTiVfvJ8dABcQJurxO2XzontQVuAma zAMcj2Uo6wp4qpywdLIri3ZyxM+ZgKLeifT2ybAhNK65+97qvTGaAJprwScHHTH8KV6k 3+3LVb0jnW1Gsx46UH6rta0/ZAclOpPFrDHxDAauMivjPvWUn5w1QNiN8x5skDIg9Eos n/cA== X-Received: by 10.107.7.87 with SMTP id 84mr6153131ioh.76.1431102759579; Fri, 08 May 2015 09:32:39 -0700 (PDT) Received: from [10.0.0.207] (c-50-183-184-166.hsd1.co.comcast.net. [50.183.184.166]) by mx.google.com with ESMTPSA id j2sm3772084ioi.8.2015.05.08.09.32.38 for (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Fri, 08 May 2015 09:32:38 -0700 (PDT) From: Matt Narrell Content-Type: multipart/alternative; boundary="Apple-Mail=_759C6842-EB21-423A-B681-3C3C2ED7304F" Message-Id: <00E7B479-D338-4EE0-B975-8B3C761C87E6@gmail.com> Mime-Version: 1.0 (Mac OS X Mail 8.2 \(2098\)) Subject: Re: Access on HDFS Date: Fri, 8 May 2015 10:32:37 -0600 References: <7A2EDD9B-78D6-4B15-BC7F-4AD5F0AA440D@hortonworks.com> <82307332-BF91-4E48-8FD7-91449E0A64DF@gmail.com> To: user@hadoop.apache.org In-Reply-To: X-Mailer: Apple Mail (2.2098) --Apple-Mail=_759C6842-EB21-423A-B681-3C3C2ED7304F Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 Right, you need write permissions for this user/group r-x is = read/execute only.=20 mn > On May 8, 2015, at 10:26 AM, Pratik Gadiya = wrote: >=20 > @Matt: > [root@vmkdev0022 ~]# hadoop fs -ls -d / > drwxr-xr-x - hdfs hdfs 0 2015-05-08 10:44 / > =20 > @Olivier: > [admin@vmkdev0022 root]$ hadoop fs -mkdir /tptp > mkdir: Permission denied: user=3Dadmin, access=3DWRITE, = inode=3D"/":hdfs:hdfs:drwxr-xr-x > =20 > [admin@vmkdev0022 root]$ groups admin > admin : admin hdfs > =20 > [admin@vmkdev0022 root]$ id admin > uid=3D500(admin) gid=3D500(admin) groups=3D500(admin),498(hdfs) > =20 > =20 > Please suggest what should be the change for the permissions on / or = if there is any other way to resolve this. > =20 > Thanks, > Pratik > From: Matt Narrell [mailto:matt.narrell@gmail.com]=20 > Sent: Friday, May 08, 2015 9:37 PM > To: user@hadoop.apache.org > Subject: Re: Access on HDFS > =20 > It looks like the group permissions on / is set to prohibit writes. > =20 > mn > =20 > On May 8, 2015, at 9:59 AM, Olivier Renault > wrote: > =20 > I meant did you check that user admin is part of the hdfs group on the = namenode.=20 > =20 > Olivier > =20 > =20 > From: Pratik Gadiya > Reply-To: "user@hadoop.apache.org " > Date: Friday, 8 May 2015 16:57 > To: "user@hadoop.apache.org " > Subject: RE: Access on HDFS > =20 > Confirmed, that I have checked it on Namenode. > In addition to that, I have checked on all of the nodes in observed = that superusergroup is set as =E2=80=9Chdfs=E2=80=9D in hdfs-site.xml = for all nodes. > =20 > Thanks, > Pratik Gadiya > =20 > From: Olivier Renault [mailto:orenault@hortonworks.com = ]=20 > Sent: Friday, May 08, 2015 8:59 PM > To: user@hadoop.apache.org > Subject: Re: Access on HDFS > =20 > Could you confirm that you are doing it on the namenode ? ( I tend to = do it on all nodes ) > =20 > Thanks, > Olivier > =20 > =20 > From: Pratik Gadiya > Reply-To: "user@hadoop.apache.org " > Date: Friday, 8 May 2015 16:14 > To: "user@hadoop.apache.org " > Subject: RE: Access on HDFS > =20 > Checked it=E2=80=99s hdfs > =20 > > dfs.permissions.superusergroup > hdfs > > =20 > Thanks, > Pratik > =20 > From: Olivier Renault [mailto:orenault@hortonworks.com = ]=20 > Sent: Friday, May 08, 2015 8:39 PM > To: user@hadoop.apache.org > Subject: Re: Access on HDFS > =20 > You need to double check which group is setup in hdfs-site.xml. The = parameter is: dfs.permissions.superusergroup > =20 > Thanks > Olivier > =20 > From: Pratik Gadiya > Reply-To: "user@hadoop.apache.org " > Date: Friday, 8 May 2015 15:46 > To: "user@hadoop.apache.org " > Subject: Access on HDFS > =20 > Hi All, > =20 > I want to add a user who can create/remove and perform all the = operations on hdfs. > =20 > Here is what I tried: > =20 > 1. Create user: adduser admin > 2. /usr/sbin/usermod -a -G hdfs admin > =20 > And when I try to create a directory on hdfs under =E2=80=9C/=E2=80=9D = it raises error as follows, > [root@vmkdev0021 ~]# id admin > uid=3D500(admin) gid=3D500(admin) groups=3D500(admin),498(hdfs) > =20 > [root@vmkdev0021 ~]# su admin > [admin@vmkdev0021 root]$ hadoop fs -mkdir /input > mkdir: Permission denied: user=3Dadmin, access=3DWRITE, = inode=3D"/":hdfs:hdfs:drwxr-xr-x > =20 > Please let me know how can I overcome this, this is reallly bugging = me. > =20 > With Regards, > Pratik Gadiya > =20 > DISCLAIMER =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D This e-mail may contain = privileged and confidential information which is the property of = Persistent Systems Ltd. It is intended only for the use of the = individual or entity to which it is addressed. If you are not the = intended recipient, you are not authorized to read, retain, copy, print, = distribute or use this message. If you have received this communication = in error, please notify the sender and delete all copies of this = message. Persistent Systems Ltd. does not accept any liability for virus = infected mails. > DISCLAIMER =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D This e-mail may contain = privileged and confidential information which is the property of = Persistent Systems Ltd. It is intended only for the use of the = individual or entity to which it is addressed. If you are not the = intended recipient, you are not authorized to read, retain, copy, print, = distribute or use this message. If you have received this communication = in error, please notify the sender and delete all copies of this = message. Persistent Systems Ltd. does not accept any liability for virus = infected mails.=20 > DISCLAIMER =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D This e-mail may contain = privileged and confidential information which is the property of = Persistent Systems Ltd. It is intended only for the use of the = individual or entity to which it is addressed. If you are not the = intended recipient, you are not authorized to read, retain, copy, print, = distribute or use this message. If you have received this communication = in error, please notify the sender and delete all copies of this = message. Persistent Systems Ltd. does not accept any liability for virus = infected mails.=20 > =20 > DISCLAIMER =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D This e-mail may contain = privileged and confidential information which is the property of = Persistent Systems Ltd. It is intended only for the use of the = individual or entity to which it is addressed. If you are not the = intended recipient, you are not authorized to read, retain, copy, print, = distribute or use this message. If you have received this communication = in error, please notify the sender and delete all copies of this = message. Persistent Systems Ltd. does not accept any liability for virus = infected mails. >=20 --Apple-Mail=_759C6842-EB21-423A-B681-3C3C2ED7304F Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=utf-8 Right, you need write permissions for this user/group r-x is = read/execute only. 

mn

On May 8, 2015, at 10:26 AM, = Pratik Gadiya <pratik_gadiya@persistent.com> wrote:

@Matt:
[root@vmkdev0022 ~]# = hadoop fs -ls -d /
drwxr-xr-x   - hdfs = hdfs          0 2015-05-08 = 10:44 /
 
@Olivier:
[admin@vmkdev0022 root]$ hadoop fs -mkdir /tptp
mkdir: Permission denied: user=3Dadmin, = access=3DWRITE, inode=3D"/":hdfs:hdfs:drwxr-xr-x
 
[admin@vmkdev0022 = root]$ groups admin
admin : admin hdfs
 
[admin@vmkdev0022 = root]$ id admin
uid=3D500(admin) = gid=3D500(admin) groups=3D500(admin),498(hdfs)
 
 
Please suggest what should be the change for the permissions = on / or if there is any other way to resolve this.
 
Thanks,
Pratik
From: Matt Narrell [mailto:matt.narrell@gmail.com] 
Sent: Friday, May 08, 2015 9:37 = PM
To: user@hadoop.apache.org
Subject: Re: Access on HDFS
 
It looks like the group permissions on / is set to prohibit = writes.
 
mn
 
On May 8, 2015, at = 9:59 AM, Olivier Renault <orenault@hortonworks.com> wrote:
 
I meant did you check that user admin is part of the hdfs = group on the namenode. 
 
Olivier
 
 
From: Pratik Gadiya
Reply-To: "user@hadoop.apache.org"
Date: Friday, 8 May 2015 = 16:57
To: "user@hadoop.apache.org"
Subject: RE: Access on HDFS
 
Confirmed, that I have = checked it on Namenode.
In addition to that, I = have checked on all of the nodes in observed that superusergroup is set as =E2=80=9Chdfs=E2=80=9D= in hdfs-site.xml for all nodes.
 
Thanks,
Pratik = Gadiya
 
From: Olivier Renault [mailto:orenault@hortonworks.com] 
Sent: Friday, May 08, 2015 8:59 = PM
To: user@hadoop.apache.org
Subject: Re: Access on = HDFS
 
Could you confirm that you are doing it on the namenode ? ( I = tend to do it on all nodes )
 
Thanks,
Olivier
 
 
From: Pratik Gadiya
Reply-To: "user@hadoop.apache.org"
Date: Friday, 8 May 2015 = 16:14
To: "user@hadoop.apache.org"
Subject: RE: Access on HDFS
 
Checked it=E2=80=99s hdfs
 
    = <property>
      = <name>dfs.permissions.superusergroup</name>
      = <value>hdfs</value>
    = </property>
 
Thanks,
Pratik
 
From: Olivier Renault [mailto:orenault@hortonworks.com] 
Sent: Friday, May 08, 2015 8:39 = PM
To: user@hadoop.apache.org
Subject: Re: Access on = HDFS
 
You need to double check which group is setup in = hdfs-site.xml. The parameter = is: dfs.permissions.superusergroup
 
Thanks
Olivier
 
From: Pratik Gadiya
Reply-To: "user@hadoop.apache.org"
Date: Friday, 8 May 2015 = 15:46
To: "user@hadoop.apache.org"
Subject: Access on HDFS
 
Hi= All,
 
I want to add a user who can create/remove and = perform all the operations on hdfs.
 
Here is what I tried:
 
1.       Create user: adduser admin
2.       /usr/sbin/usermod -a -G hdfs admin
 
And when I try to create a directory on hdfs = under =E2=80=9C/=E2=80=9D it raises error as follows,
[root@vmkdev0021 ~]# id = admin
uid=3D500(admin) gid=3D500(admin) = groups=3D500(admin),498(hdfs)
 
[root@vmkdev0021 ~]# su admin
[admin@vmkdev0021 root]$ hadoop  fs -mkdir = /input
mkdir: Permission denied: user=3Dadmin, = access=3DWRITE, inode=3D"/":hdfs:hdfs:drwxr-xr-x
 
Please let me know how can I overcome this, this = is reallly bugging me.
 
With Regards,
Pratik Gadiya
 
DISCLAIMER =3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D This e-mail may contain privileged and confidential = information which is the property of Persistent Systems Ltd. It is = intended only for the use of the individual or entity to which it is = addressed. If you are not the intended recipient, you are not authorized = to read, retain, copy, print, distribute or use this message. If you = have received this communication in error, please notify the sender and = delete all copies of this message. Persistent Systems Ltd. does not = accept any liability for virus infected mails.
DISCLAIMER =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D This e-mail may = contain privileged and confidential information which is the property of = Persistent Systems Ltd. It is intended only for the use of the = individual or entity to which it is addressed. If you are not the = intended recipient, you are not authorized to read, retain, copy, print, = distribute or use this message. If you have received this communication = in error, please notify the sender and delete all copies of this = message. Persistent Systems Ltd. does not accept any liability for virus = infected mails. 
DISCLAIMER =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D This e-mail may = contain privileged and confidential information which is the property of = Persistent Systems Ltd. It is intended only for the use of the = individual or entity to which it is addressed. If you are not the = intended recipient, you are not authorized to read, retain, copy, print, = distribute or use this message. If you have received this communication = in error, please notify the sender and delete all copies of this = message. Persistent Systems Ltd. does not accept any liability for virus = infected mails. 
 

DISCLAIMER =3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D This e-mail may contain privileged and confidential = information which is the property of Persistent Systems Ltd. It is = intended only for the use of the individual or entity to which it is = addressed. If you are not the intended recipient, you are not authorized = to read, retain, copy, print, distribute or use this message. If you = have received this communication in error, please notify the sender and = delete all copies of this message. Persistent Systems Ltd. does not = accept any liability for virus infected = mails.


= --Apple-Mail=_759C6842-EB21-423A-B681-3C3C2ED7304F--