You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@hive.apache.org by "Changshu Liu (JIRA)" <ji...@apache.org> on 2018/04/08 20:14:00 UTC
[jira] [Assigned] (HIVE-13532) MapredLocalTask should use the same
security settings as remote task
[ https://issues.apache.org/jira/browse/HIVE-13532?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Changshu Liu reassigned HIVE-13532:
-----------------------------------
Assignee: Changshu Liu (was: feiwei)
> MapredLocalTask should use the same security settings as remote task
> --------------------------------------------------------------------
>
> Key: HIVE-13532
> URL: https://issues.apache.org/jira/browse/HIVE-13532
> Project: Hive
> Issue Type: Bug
> Affects Versions: 1.1.0
> Environment: HADOOP_PROXY_USER is set.
> Reporter: Zhiwen Sun
> Assignee: Changshu Liu
> Priority: Major
>
> Map join set HADOOP_USER_NAME should be realuser's username.
> Current, hive set HADOOP_USER_NAME env for mapjoin local process according:
> {quote}
> String endUserName = Utils.getUGI().getShortUserName();
> {quote}
> suppose set HADOOP_PROXY_USER=abc in shell.
> map join local job will have following env:
> {quote}
> HADOOP_USER_NAME=abc
> HADOOP_PROXY_NAME=abc
> {quote}
> this will cause such exception:
> {quote}
> java.io.IOException: org.apache.hadoop.ipc.RemoteException(org.apache.hadoop.security.authorize.AuthorizationException): User: abc is not allowed to impersonate
> {quote}
> I think we should set HADOOP_USER_NAME to realuser:
> {quote}
> String endUserName = Utils.getUGI().getRealUser().getShortUserName();
> {quote}
--
This message was sent by Atlassian JIRA
(v7.6.3#76005)