[ 
https://issues.apache.org/jira/browse/HADOOP-19906?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18091014#comment-18091014
 ] 

ASF GitHub Bot commented on HADOOP-19906:
-----------------------------------------

steveloughran commented on code in PR #8522:
URL: https://github.com/apache/hadoop/pull/8522#discussion_r3462461977


##########
hadoop-common-project/hadoop-auth/src/main/java/org/apache/hadoop/security/authentication/util/SubjectUtil.java:
##########
@@ -335,9 +400,33 @@ public static <T> T doAs(
   /**
    * Maps to Subject.current() if available, otherwise maps to 
Subject.getSubject().
    *
+   * <p>On JDK 22+ also consults the Hadoop-managed
+   * {@link #CURRENT_SUBJECT_TL InheritableThreadLocal} so that platform 
Threads which
+   * inherited a Subject from a parent's {@link #callAs} scope continue to 
observe it.
+   * The JDK API {@code Subject.current()} (backed by {@code ScopedValue}) is 
consulted
+   * first, so any future virtual-thread / {@code StructuredTaskScope} usage 
that propagates
+   * the {@code ScopedValue} keeps working without falling back to the TLS 
layer.

Review Comment:
   not sure what TLS stands for here; replace it with something other than an 
acronym. UGI is already complex enough



##########
hadoop-common-project/hadoop-auth/src/test/java/org/apache/hadoop/security/authentication/util/TestSubjectPropagation.java:
##########
@@ -0,0 +1,179 @@
+/**
+ * Licensed to the Apache Software Foundation (ASF) under one
+ * or more contributor license agreements.  See the NOTICE file
+ * distributed with this work for additional information
+ * regarding copyright ownership.  The ASF licenses this file
+ * to you under the Apache License, Version 2.0 (the
+ * "License"); you may not use this file except in compliance
+ * with the License.  You may obtain a copy of the License at
+ *
+ *     http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+
+package org.apache.hadoop.security.authentication.util;
+
+import static org.junit.jupiter.api.Assertions.assertEquals;
+import static org.junit.jupiter.api.Assertions.assertNull;
+
+import org.junit.jupiter.api.Test;
+
+import java.util.concurrent.ExecutorService;
+import java.util.concurrent.Executors;
+import java.util.concurrent.TimeUnit;
+import java.util.concurrent.atomic.AtomicReference;
+import javax.security.auth.Subject;
+
+/**
+ * Verifies the JDK22+ Subject-propagation cascade restored by the
+ * {@link InheritableThreadLocal}-based mechanism in
+ * {@link SubjectUtil#callAs(Subject, java.util.concurrent.Callable)}.
+ *
+ * <p>The mechanism relies solely on Hadoop's own InheritableThreadLocal layer 
and
+ * the JVM's standard {@code Thread.<init>}-time {@code 
InheritableThreadLocal} copy.
+ * No special {@code Thread} subclass is required: any platform thread ({@link 
Thread},
+ * {@link java.util.concurrent.ForkJoinWorkerThread}, Netty's
+ * {@code FastThreadLocalThread}, …) constructed inside a {@code 
SubjectUtil.callAs}
+ * scope inherits the active Subject and observes it via {@link 
SubjectUtil#current()}.
+ */
+public class TestSubjectPropagation {
+
+  /** Plain Thread inside callAs sees parent's Subject via 
SubjectUtil.current(). */
+  @Test
+  public void testPlainThreadInheritsSubjectViaSubjectUtilCallAs() {
+    Subject parent = new Subject();
+    AtomicReference<Subject> seen = new AtomicReference<>();
+    SubjectUtil.callAs(parent, () -> {
+      Thread t = new Thread(() -> seen.set(SubjectUtil.current()), 
"plain-child");
+      t.start();
+      t.join(50000);
+      return null;
+    });
+    assertEquals(parent, seen.get(),

Review Comment:
   nit: use assertJ  for new tests



##########
hadoop-common-project/hadoop-auth/src/test/java/org/apache/hadoop/security/authentication/util/TestSubjectPropagation.java:
##########
@@ -0,0 +1,179 @@
+/**
+ * Licensed to the Apache Software Foundation (ASF) under one
+ * or more contributor license agreements.  See the NOTICE file
+ * distributed with this work for additional information
+ * regarding copyright ownership.  The ASF licenses this file
+ * to you under the Apache License, Version 2.0 (the
+ * "License"); you may not use this file except in compliance
+ * with the License.  You may obtain a copy of the License at
+ *
+ *     http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+
+package org.apache.hadoop.security.authentication.util;
+
+import static org.junit.jupiter.api.Assertions.assertEquals;
+import static org.junit.jupiter.api.Assertions.assertNull;
+
+import org.junit.jupiter.api.Test;
+
+import java.util.concurrent.ExecutorService;
+import java.util.concurrent.Executors;
+import java.util.concurrent.TimeUnit;
+import java.util.concurrent.atomic.AtomicReference;
+import javax.security.auth.Subject;
+
+/**
+ * Verifies the JDK22+ Subject-propagation cascade restored by the
+ * {@link InheritableThreadLocal}-based mechanism in
+ * {@link SubjectUtil#callAs(Subject, java.util.concurrent.Callable)}.
+ *
+ * <p>The mechanism relies solely on Hadoop's own InheritableThreadLocal layer 
and
+ * the JVM's standard {@code Thread.<init>}-time {@code 
InheritableThreadLocal} copy.
+ * No special {@code Thread} subclass is required: any platform thread ({@link 
Thread},
+ * {@link java.util.concurrent.ForkJoinWorkerThread}, Netty's
+ * {@code FastThreadLocalThread}, …) constructed inside a {@code 
SubjectUtil.callAs}
+ * scope inherits the active Subject and observes it via {@link 
SubjectUtil#current()}.
+ */
+public class TestSubjectPropagation {
+
+  /** Plain Thread inside callAs sees parent's Subject via 
SubjectUtil.current(). */
+  @Test
+  public void testPlainThreadInheritsSubjectViaSubjectUtilCallAs() {
+    Subject parent = new Subject();
+    AtomicReference<Subject> seen = new AtomicReference<>();
+    SubjectUtil.callAs(parent, () -> {
+      Thread t = new Thread(() -> seen.set(SubjectUtil.current()), 
"plain-child");
+      t.start();
+      t.join(50000);
+      return null;
+    });
+    assertEquals(parent, seen.get(),
+        "A plain Thread (no Hadoop wrapper) constructed inside callAs must see 
the parent's Subject");
+  }
+
+  /**
+   * Plain Thread submitted to a {@link 
java.util.concurrent.ThreadPoolExecutor} inside callAs
+   * sees parent's Subject. Mimics the ubiquitous Spark / HiveServer2 / 
generic long-running JVM
+   * pattern of submitting work into a long-lived pool from inside a UGI 
{@code doAs} scope.
+   */
+  @Test
+  public void testPlainThreadInThreadPoolExecutorInheritsSubject() throws 
Exception {
+    Subject parent = new Subject();
+    AtomicReference<Subject> seen = new AtomicReference<>();
+    ExecutorService pool = Executors.newFixedThreadPool(2, r -> new Thread(r, 
"plain-pool"));
+    try {
+      SubjectUtil.callAs(parent, () -> {
+        pool.submit(() -> seen.set(SubjectUtil.current()))
+            .get(5, TimeUnit.SECONDS);
+        return null;
+      });
+    } finally {
+      pool.shutdownNow();
+      pool.awaitTermination(5, TimeUnit.SECONDS);
+    }
+    assertEquals(parent, seen.get(),
+        "A plain Thread pool worker must see the parent's Subject via 
InheritableThreadLocal cascade");
+  }
+
+  /**
+   * Transitive cascade: pool worker created inside callAs scope inherits the 
Subject
+   * permanently; even after the original callAs scope exits, the worker still 
sees the
+   * Subject and propagates it to any child Thread it creates. Matches 
pre-JDK22
+   * {@code inheritedAccessControlContext} cascading semantics.
+   */
+  @Test
+  public void testTransitiveCascadeViaPlainPoolAfterCallAsExits() throws 
Exception {
+    Subject parent = new Subject();
+    AtomicReference<Subject> seen = new AtomicReference<>();
+    ExecutorService pool = Executors.newFixedThreadPool(1, r -> new Thread(r, 
"plain-pool"));
+    try {
+      // Step 1: create the worker INSIDE the callAs scope so it inherits the 
Subject's TLS.

Review Comment:
   good test and explanation; wouldn't have even considered this situation 
myself





> Alternative to SubjectInheritingThread to restore Subject propagation
> ---------------------------------------------------------------------
>
>                 Key: HADOOP-19906
>                 URL: https://issues.apache.org/jira/browse/HADOOP-19906
>             Project: Hadoop Common
>          Issue Type: Bug
>          Components: security
>    Affects Versions: 3.5.0, 3.4.3
>            Reporter: Cheng Pan
>            Priority: Major
>              Labels: pull-request-available
>




--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to