[ https://issues.apache.org/jira/browse/HADOOP-14521?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16080574#comment-16080574 ]
Rushabh S Shah commented on HADOOP-14521: ----------------------------------------- bq. I tried to ran TestAclsEndToEnd before and after applying this patch on branch-2.8. It was passing before, failing after. HADOOP-14563 fixed the failing test issue. We deployed this change internally in our cluster and found out the client is not retrying on {{addDelegationTokens}} call. The reason is following piece of code. {code:title=KMSClientProvider.java|borderStyle=solid} @Override public Token<?>[] addDelegationTokens(final String renewer, Credentials credentials) throws IOException { .... } catch (Exception e) { throw new IOException(e); ---> Catching any Exception and throwing IOException. } } return tokens; } {code} All the other calls checks whether the exception is {{IOException}} then rethrow IOException otherwise wrap the actual exception in IOException and rethrow that. Will put up a new patch including this fix. > KMS client needs retry logic > ---------------------------- > > Key: HADOOP-14521 > URL: https://issues.apache.org/jira/browse/HADOOP-14521 > Project: Hadoop Common > Issue Type: Improvement > Affects Versions: 2.6.0 > Reporter: Rushabh S Shah > Assignee: Rushabh S Shah > Attachments: HADOOP-14521.09.patch, HDFS-11804-branch-2.8.patch, > HDFS-11804-trunk-1.patch, HDFS-11804-trunk-2.patch, HDFS-11804-trunk-3.patch, > HDFS-11804-trunk-4.patch, HDFS-11804-trunk-5.patch, HDFS-11804-trunk-6.patch, > HDFS-11804-trunk-7.patch, HDFS-11804-trunk-8.patch, HDFS-11804-trunk.patch > > > The kms client appears to have no retry logic – at all. It's completely > decoupled from the ipc retry logic. This has major impacts if the KMS is > unreachable for any reason, including but not limited to network connection > issues, timeouts, the +restart during an upgrade+. > This has some major ramifications: > # Jobs may fail to submit, although oozie resubmit logic should mask it > # Non-oozie launchers may experience higher rates if they do not already have > retry logic. > # Tasks reading EZ files will fail, probably be masked by framework reattempts > # EZ file creation fails after creating a 0-length file – client receives > EDEK in the create response, then fails when decrypting the EDEK > # Bulk hadoop fs copies, and maybe distcp, will prematurely fail -- This message was sent by Atlassian JIRA (v6.4.14#64029) --------------------------------------------------------------------- To unsubscribe, e-mail: common-issues-unsubscr...@hadoop.apache.org For additional commands, e-mail: common-issues-h...@hadoop.apache.org