[
https://issues.apache.org/jira/browse/HADOOP-20010?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Jose Luis López reassigned HADOOP-20010:
----------------------------------------
Assignee: Jose Luis López
> ExpiredTokenRemover should use ExitUtil instead of Runtime.exit
> ---------------------------------------------------------------
>
> Key: HADOOP-20010
> URL: https://issues.apache.org/jira/browse/HADOOP-20010
> Project: Hadoop Common
> Issue Type: Bug
> Components: security
> Reporter: Jose Luis López
> Assignee: Jose Luis López
> Priority: Major
>
> {{AbstractDelegationTokenSecretManager.ExpiredTokenRemover.run()}} catches
> every {{Throwable}} and calls {{Runtime.getRuntime().exit(-1)}}. This has two
> problems:
> # *It bypasses {{ExitUtil}}.* Tests that call
> {{ExitUtil.disableSystemExit()}} can't intercept it, so the JVM is killed
> instead. In {{TestZKDelegationTokenSecretManager}} and
> {{TestZKDelegationTokenSecretManagerImpl}}, a token manager leaked by a
> failing test keeps its remover thread running after {{tearDown()}} closes the
> ZooKeeper {{TestingServer}}. On its next pass the thread hits
> {{ConnectionLoss}}, which is wrapped in a {{RuntimeException}}, and kills the
> surefire fork. The original test failure is lost.
> # *It exits during a normal shutdown.* {{stopThreads()}} sets {{running =
> false}} and then interrupts the thread. With a ZooKeeper-backed store, the
> interrupt can surface as a {{RuntimeException}} instead of an
> {{InterruptedException}}, and that terminates the process while it is being
> stopped.
> *Proposed fix:*
> * Call {{ExitUtil.terminate(-1, t)}} instead of
> {{Runtime.getRuntime().exit(-1)}}.
> * If {{running}} is already false, log the exception and return instead of
> exiting.
> * Make {{TestZKDelegationTokenSecretManager}} disable system exit and fail in
> {{tearDown()}} if {{ExitUtil.terminate}} was called.
> *Tests:* two new tests in {{TestDelegationToken}}:
> * A remover failure while running calls {{ExitUtil.terminate(-1, ...)}}.
> * A failure while {{stopThreads()}} is running does not.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]