sadanand48 opened a new pull request, #8741:
URL: https://github.com/apache/hadoop/pull/8741

   
   <!--
     Thanks for sending a pull request!
       1. If this is your first time, please read our contributor guidelines: 
https://cwiki.apache.org/confluence/display/HADOOP/How+To+Contribute
       2. Make sure your PR title starts with JIRA issue id, e.g., 
'HADOOP-17799. Your PR title ...'.
   -->
   
   ### Description of PR
   When HDFS Trash is enabled, rm is executed as an internal rename to .Trash 
using Options.Rename.TO_TRASH.
    Today, external authorization plugins (for example Ranger via 
checkPermissionWithContext) receive operationName=rename, but do not get an 
explicit trash-intent signal. As a result, rm (to trash) and mv appear 
identical from authorization/audit context.
   
   This JIRA proposes adding and propagating a dedicated context flag (for 
example renameToTrash) in INodeAttributeProvider.AuthorizationContext so 
external enforcers can distinguish:
   
   rm with trash enabled -> operationName=rename, renameToTrash=true
   mv -> operationName=rename, renameToTrash=false
   rm skipTrash > operationName=delete
   Scope (HDFS side)
   
   Add renameToTrash field to AuthorizationContext and its builder/accessors.
   Propagate the flag through FSPermissionChecker when building context for 
checkPermissionWithContext.
   In FSNamesystem.renameTo(..., Options.Rename... options), set the flag based 
on presence of Options.Rename.TO_TRASH, and clear it in finally to avoid 
ThreadLocal leakage.
   
   
   ### How was this patch tested?
   Unit tests
   
   ### For code changes:
   
   - [ ] Does the title of this PR start with the corresponding JIRA issue id 
(e.g. 'HADOOP-17799. Your PR title ...')?
   - [ ] Object storage: Have the integration tests been executed and the 
endpoint
         declared according to the connector-specific documentation? *Note: 
Automated CI
         testing doesn't cover all cases so manual testing with cloud storage 
is still
         required.*
   - [ ] If adding new dependencies to the code, are these dependencies 
licensed in a way that is compatible for inclusion under [ASF 
2.0](http://www.apache.org/legal/resolved.html#category-a)?
   - [ ] If applicable, have you updated the `LICENSE`, `LICENSE-binary`, 
`NOTICE-binary` files?
   
   ### AI Tooling
   
   If an AI tool was used:
   
   - [ ] The PR includes the phrase "Contains content generated by <tool>"
         where <tool> is the name of the AI tool used.
   - [ ] My use of AI contributions follows the ASF legal policy
         https://www.apache.org/legal/generative-tooling.html
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to