You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@hive.apache.org by "Mithun Radhakrishnan (JIRA)" <ji...@apache.org> on 2017/10/19 23:19:00 UTC
[jira] [Updated] (HIVE-17853) RetryingMetaStoreClient loses UGI
impersonation-context when reconnecting after timeout
[ https://issues.apache.org/jira/browse/HIVE-17853?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Mithun Radhakrishnan updated HIVE-17853:
----------------------------------------
Description:
The {{RetryingMetaStoreClient}} is used to automatically reconnect to the Hive metastore, after client timeout, transparently to the user.
In case of user impersonation (e.g. Oozie super-user {{oozie}} impersonating a Hadoop user {{mithun}}, to run a workflow), in case of timeout, we find that the reconnect causes the {{UGI.doAs()}} context to be lost. Any further metastore operations will be attempted as the login-user ({{oozie}}), as opposed to the effective user ({{mithun}}).
We should have a fix for this shortly.
was:
The {{RetryingMetaStoreClient}} is used to automatically reconnect to the Hive metastore, after client timeout, transparently to the user.
In case of user impersonation (e.g. Oozie super-user {{oozie}} impersonating a Hadoop user {{mithun}}, to run a workflow), in case of timeout, we find that the reconnect causes the {{UGI.doAs()}} context to be lost. Any further metastore operations will be attempted as the login-user ({{oozie}}), as opposed to the effective user ({{mithunr}}).
We should have a fix for this shortly.
> RetryingMetaStoreClient loses UGI impersonation-context when reconnecting after timeout
> ---------------------------------------------------------------------------------------
>
> Key: HIVE-17853
> URL: https://issues.apache.org/jira/browse/HIVE-17853
> Project: Hive
> Issue Type: Bug
> Components: Metastore
> Affects Versions: 3.0.0, 2.4.0, 2.2.1
> Reporter: Mithun Radhakrishnan
> Assignee: Chris Drome
> Priority: Critical
>
> The {{RetryingMetaStoreClient}} is used to automatically reconnect to the Hive metastore, after client timeout, transparently to the user.
> In case of user impersonation (e.g. Oozie super-user {{oozie}} impersonating a Hadoop user {{mithun}}, to run a workflow), in case of timeout, we find that the reconnect causes the {{UGI.doAs()}} context to be lost. Any further metastore operations will be attempted as the login-user ({{oozie}}), as opposed to the effective user ({{mithun}}).
> We should have a fix for this shortly.
--
This message was sent by Atlassian JIRA
(v6.4.14#64029)