nishat-06 opened a new pull request, #8687:
URL: https://github.com/apache/hadoop/pull/8687
### Description of PR
SecureShuffleUtils.verifyHash checks the caller-supplied MAC against the
recomputed HMAC with WritableComparator.compareBytes, which returns as soon as
two bytes differ. The NodeManager ShuffleHandler takes that MAC straight from
the inbound UrlHash request header, and the reducer Fetcher verifies the
ReplyHash the same way through verifyReply, so anyone able to reach the shuffle
port gets a timing oracle on a keyed MAC and can recover a valid hash byte by
byte to read another job's map outputs. This switches the check to
MessageDigest.isEqual, the constant-time compare already used for
delegation-token and auth-signature verification elsewhere in the tree.
### How was this patch tested?
Added TestSecureShuffleUtils in the mapreduce-client-core security package
covering verifyReply accepting a matching hash and rejecting a tampered or
truncated one, and ran it plus the existing TestFetcher against the module
build on JDK 17 (both green). Checkstyle on the touched files is clean.
### For code changes:
- [ ] Does the title of this PR start with the corresponding JIRA issue id
(e.g. 'HADOOP-17799. Your PR title ...')?
- [ ] Object storage: Have the integration tests been executed and the
endpoint
declared according to the connector-specific documentation? *Note:
Automated CI
testing doesn't cover all cases so manual testing with cloud storage
is still
required.*
- [ ] If adding new dependencies to the code, are these dependencies
licensed in a way that is compatible for inclusion under [ASF
2.0](http://www.apache.org/legal/resolved.html#category-a)?
- [ ] If applicable, have you updated the `LICENSE`, `LICENSE-binary`,
`NOTICE-binary` files?
### AI Tooling
If an AI tool was used:
- [ ] The PR includes the phrase "Contains content generated by <tool>"
where <tool> is the name of the AI tool used.
- [ ] My use of AI contributions follows the ASF legal policy
https://www.apache.org/legal/generative-tooling.html
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]