[ 
https://issues.apache.org/jira/browse/HADOOP-14521?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16080574#comment-16080574
 ] 

Rushabh S Shah commented on HADOOP-14521:
-----------------------------------------

bq. I tried to ran TestAclsEndToEnd before and after applying this patch on 
branch-2.8. It was passing before, failing after.
HADOOP-14563 fixed the failing test issue.
We deployed this change internally in our cluster and found out the client is 
not retrying on {{addDelegationTokens}} call.
The reason is following piece of code.
{code:title=KMSClientProvider.java|borderStyle=solid}
@Override
  public Token<?>[] addDelegationTokens(final String renewer,
      Credentials credentials) throws IOException {
  ....
      } catch (Exception e) {
        throw new IOException(e);  ---> Catching any Exception and throwing 
IOException.
      }
    }
    return tokens;
  }
{code}
All the other calls checks whether the exception is {{IOException}} then 
rethrow IOException otherwise wrap the actual exception in IOException and 
rethrow that.
Will put up a new patch including this fix.


> KMS client needs retry logic
> ----------------------------
>
>                 Key: HADOOP-14521
>                 URL: https://issues.apache.org/jira/browse/HADOOP-14521
>             Project: Hadoop Common
>          Issue Type: Improvement
>    Affects Versions: 2.6.0
>            Reporter: Rushabh S Shah
>            Assignee: Rushabh S Shah
>         Attachments: HADOOP-14521.09.patch, HDFS-11804-branch-2.8.patch, 
> HDFS-11804-trunk-1.patch, HDFS-11804-trunk-2.patch, HDFS-11804-trunk-3.patch, 
> HDFS-11804-trunk-4.patch, HDFS-11804-trunk-5.patch, HDFS-11804-trunk-6.patch, 
> HDFS-11804-trunk-7.patch, HDFS-11804-trunk-8.patch, HDFS-11804-trunk.patch
>
>
> The kms client appears to have no retry logic – at all.  It's completely 
> decoupled from the ipc retry logic.  This has major impacts if the KMS is 
> unreachable for any reason, including but not limited to network connection 
> issues, timeouts, the +restart during an upgrade+.
> This has some major ramifications:
> # Jobs may fail to submit, although oozie resubmit logic should mask it
> # Non-oozie launchers may experience higher rates if they do not already have 
> retry logic.
> # Tasks reading EZ files will fail, probably be masked by framework reattempts
> # EZ file creation fails after creating a 0-length file – client receives 
> EDEK in the create response, then fails when decrypting the EDEK
> # Bulk hadoop fs copies, and maybe distcp, will prematurely fail



--
This message was sent by Atlassian JIRA
(v6.4.14#64029)

---------------------------------------------------------------------
To unsubscribe, e-mail: common-issues-unsubscr...@hadoop.apache.org
For additional commands, e-mail: common-issues-h...@hadoop.apache.org

Reply via email to