Skip to content

HDFS-17276. Authorize secure QJM edit log fetches using the full principal - #8763

Open
gp1314 wants to merge 1 commit into
apache:trunkfrom
gp1314:HDFS-17276-qjm-principal-authorization
Open

gp1314 wants to merge 1 commit into
apache:trunkfrom
gp1314:HDFS-17276-qjm-principal-authorization

Conversation

@gp1314

@gp1314 gp1314 commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Supersedes #6326, which was closed by the stale bot.

Description of PR

Supersedes #6326, which was closed by the stale bot.

Fix secure QJM edit-log fetch authorization when standard SPNEGO exposes a
short remote user but a full Kerberos principal.

HDFS-16686 moved this path to DfsServlet/JspHelper.
JspHelper#getUGI used request.getRemoteUser(), which can be a short name
under the authentication filter. The JournalNode allow-list uses full
NameNode Kerberos principals, so a valid NameNode request to /getJournal
can be rejected with HTTP 403.

Prefer request.getUserPrincipal().getName() when available, retaining
getRemoteUser() as a fallback.

JIRA: https://issues.apache.org/jira/browse/HDFS-17276

Contains content generated by Codex.

How was this patch tested?

  • git diff --check
  • Not run locally because the test environment is unavailable.
  • GitHub Actions will run for this PR.

For code changes:

  • Does the title of this PR start with the corresponding JIRA issue id?
  • Object storage integration tests: not applicable.
  • No dependencies were added.
  • No LICENSE, LICENSE-binary, or NOTICE-binary updates are applicable.

AI Tooling

@gp1314

gp1314 commented Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

The Jenkins pr-merge check could not run because worker hadoop16 went offline
(AgentOfflineException). GitHub Actions Build passed. Could the Jenkins check
please be retriggered?

@gp1314 gp1314 changed the title HDFS-17276. Authorize secure QJM edit log fetches using the full prin… HDFS-17276. Authorize secure QJM edit log fetches using the full principal Sep 29, 2026
@hadoop-yetus

Copy link
Copy Markdown

🎊 +1 overall

Vote Subsystem Runtime Logfile Comment
+0 🆗 reexec 15m 4s Docker mode activated.
_ Prechecks _
+1 💚 dupname 0m 0s No case conflicting files found.
+0 🆗 codespell 0m 1s codespell was not available.
+0 🆗 detsecrets 0m 1s detect-secrets was not available.
+1 💚 @author 0m 0s The patch does not contain any @author tags.
+1 💚 test4tests 0m 0s The patch appears to include 3 new or modified test files.
_ trunk Compile Tests _
+1 💚 mvninstall 49m 18s trunk passed
+1 💚 compile 1m 47s trunk passed with JDK Ubuntu-21.0.12.1+1-1-24.04.4-Ubuntu
+1 💚 compile 1m 50s trunk passed with JDK Ubuntu-17.0.20.1+1-1-24.04-Ubuntu
+1 💚 checkstyle 1m 57s trunk passed
+1 💚 mvnsite 1m 58s trunk passed
+1 💚 javadoc 1m 34s trunk passed with JDK Ubuntu-21.0.12.1+1-1-24.04.4-Ubuntu
+1 💚 javadoc 1m 32s trunk passed with JDK Ubuntu-17.0.20.1+1-1-24.04-Ubuntu
+1 💚 spotbugs 4m 14s trunk passed
+1 💚 shadedclient 32m 13s branch has no errors when building and testing our client artifacts.
_ Patch Compile Tests _
+1 💚 mvninstall 1m 23s the patch passed
+1 💚 compile 1m 18s the patch passed with JDK Ubuntu-21.0.12.1+1-1-24.04.4-Ubuntu
+1 💚 javac 1m 18s the patch passed
+1 💚 compile 1m 20s the patch passed with JDK Ubuntu-17.0.20.1+1-1-24.04-Ubuntu
+1 💚 javac 1m 20s the patch passed
+1 💚 blanks 0m 0s The patch has no blanks issues.
+1 💚 checkstyle 1m 15s the patch passed
+1 💚 mvnsite 1m 27s the patch passed
+1 💚 javadoc 0m 59s the patch passed with JDK Ubuntu-21.0.12.1+1-1-24.04.4-Ubuntu
+1 💚 javadoc 1m 1s the patch passed with JDK Ubuntu-17.0.20.1+1-1-24.04-Ubuntu
+1 💚 spotbugs 3m 49s the patch passed
+1 💚 shadedclient 30m 56s patch has no errors when building and testing our client artifacts.
_ Other Tests _
+1 💚 unit 223m 18s hadoop-hdfs in the patch passed.
+1 💚 asflicense 0m 54s The patch does not generate ASF License warnings.
377m 25s
Subsystem Report/Notes
Docker ClientAPI=1.56 ServerAPI=1.56 base: https://ci-hadoop.apache.org/job/hadoop-multibranch/job/PR-8763/1/artifact/out/Dockerfile
GITHUB PR #8763
Optional Tests dupname asflicense compile javac javadoc mvninstall mvnsite unit shadedclient spotbugs checkstyle codespell detsecrets
uname Linux d1a5d1d84f71 5.15.0-186-generic #196-Ubuntu SMP Sat Jun 20 16:09:34 UTC 2026 x86_64 x86_64 x86_64 GNU/Linux
Build tool maven
Personality dev-support/bin/hadoop.sh
git revision trunk / 8a4246a
Default Java Ubuntu-17.0.20.1+1-1-24.04-Ubuntu
Multi-JDK versions /usr/lib/jvm/java-21-openjdk-amd64:Ubuntu-21.0.12.1+1-1-24.04.4-Ubuntu /usr/lib/jvm/java-17-openjdk-amd64:Ubuntu-17.0.20.1+1-1-24.04-Ubuntu
Test Results https://ci-hadoop.apache.org/job/hadoop-multibranch/job/PR-8763/1/testReport/
Max. process+thread count 3464 (vs. ulimit of 10000)
modules C: hadoop-hdfs-project/hadoop-hdfs U: hadoop-hdfs-project/hadoop-hdfs
Console output https://ci-hadoop.apache.org/job/hadoop-multibranch/job/PR-8763/1/console
versions git=2.43.0 maven=3.9.15 spotbugs=4.9.7
Powered by Apache Yetus 0.14.1 https://yetus.apache.org

This message was automatically generated.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants