Fang-Yu Rao created RANGER-5726:
-----------------------------------
Summary: Ranger server returns an incorrect error message when an
admin tries to revoke a non-existing role from a user
Key: RANGER-5726
URL: https://issues.apache.org/jira/browse/RANGER-5726
Project: Ranger
Issue Type: Bug
Components: Ranger
Reporter: Fang-Yu Rao
We found the Ranger server would return an incorrect error message when an
admin tries to revoke a non-existing role from a user. In what follows I
provide the steps to reproduce the issue in a beeline instance connected to a
version of Hive Server2.
{code}
# This verifies the requesting user is allowed to create a role 'role_100'.
0: jdbc:hive2://ccycloud-1.cdpd102205p01d06.r> create role role_100;
INFO : Compiling
command(queryId=hive_20260716191507_8f9415f3-5035-4d50-8029-ae5f8dee3ecb):
create role role_100
INFO : Semantic Analysis Completed (retrial = false)
INFO : Created Hive schema: Schema(fieldSchemas:null, properties:null)
INFO : Completed compiling
command(queryId=hive_20260716191507_8f9415f3-5035-4d50-8029-ae5f8dee3ecb); Time
taken: 0.03 seconds
INFO : Executing
command(queryId=hive_20260716191507_8f9415f3-5035-4d50-8029-ae5f8dee3ecb):
create role role_100
INFO : Starting task [Stage-0:DDL] in serial mode
INFO : Completed executing
command(queryId=hive_20260716191507_8f9415f3-5035-4d50-8029-ae5f8dee3ecb); Time
taken: 0.037 seconds
INFO : OK
No rows affected (0.083 seconds)
# This verifies the role 'role_100' is dropped.
0: jdbc:hive2://ccycloud-1.cdpd102205p01d06.r> drop role role_100;
INFO : Compiling
command(queryId=hive_20260716191832_75c3783e-3e19-476d-a293-fd513629ddea): drop
role role_100
INFO : Semantic Analysis Completed (retrial = false)
INFO : Created Hive schema: Schema(fieldSchemas:null, properties:null)
INFO : Completed compiling
command(queryId=hive_20260716191832_75c3783e-3e19-476d-a293-fd513629ddea); Time
taken: 0.003 seconds
INFO : Executing
command(queryId=hive_20260716191832_75c3783e-3e19-476d-a293-fd513629ddea): drop
role role_100
INFO : Starting task [Stage-0:DDL] in serial mode
INFO : Completed executing
command(queryId=hive_20260716191832_75c3783e-3e19-476d-a293-fd513629ddea); Time
taken: 0.043 seconds
INFO : OK
No rows affected (0.061 seconds)
# This reproduces the issue.
0: jdbc:hive2://ccycloud-1.cdpd102205p01d06.r> grant role role_100 to user
hdfs;
INFO : Compiling
command(queryId=hive_20260716191903_17958d74-c978-47b5-bbf4-f5cee5cc16e2):
grant role role_100 to user hdfs
INFO : Semantic Analysis Completed (retrial = false)
INFO : Created Hive schema: Schema(fieldSchemas:null, properties:null)
INFO : Completed compiling
command(queryId=hive_20260716191903_17958d74-c978-47b5-bbf4-f5cee5cc16e2); Time
taken: 0.003 seconds
INFO : Executing
command(queryId=hive_20260716191903_17958d74-c978-47b5-bbf4-f5cee5cc16e2):
grant role role_100 to user hdfs
INFO : Starting task [Stage-0:DDL] in serial mode
ERROR : Failed
org.apache.hadoop.hive.ql.security.authorization.plugin.HiveAccessControlException:
java.lang.Exception: HTTP 400 Error: User doesn't have permissions to grant
role role_100
at
org.apache.ranger.authorization.hive.authorizer.RangerHiveAuthorizer.grantRole(RangerHiveAuthorizer.java:585)
~[ranger-hive-plugin-2.8.0.7.3.2.20000-
134.jar:2.8.0.7.3.2.20000-134]
at
org.apache.hadoop.hive.ql.ddl.privilege.role.grant.GrantRoleOperation.execute(GrantRoleOperation.java:53)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.
1.3000.7.3.2.20000-134]
at org.apache.hadoop.hive.ql.ddl.DDLTask.execute(DDLTask.java:84)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at org.apache.hadoop.hive.ql.exec.Task.executeTask(Task.java:213)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at
org.apache.hadoop.hive.ql.exec.TaskRunner.runSequential(TaskRunner.java:105)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at org.apache.hadoop.hive.ql.Executor.launchTask(Executor.java:354)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at org.apache.hadoop.hive.ql.Executor.launchTasks(Executor.java:327)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at org.apache.hadoop.hive.ql.Executor.runTasks(Executor.java:244)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at org.apache.hadoop.hive.ql.Executor.execute(Executor.java:105)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at org.apache.hadoop.hive.ql.Driver.execute(Driver.java:843)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at org.apache.hadoop.hive.ql.Driver.runInternal(Driver.java:695)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at org.apache.hadoop.hive.ql.Driver.run(Driver.java:536)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at org.apache.hadoop.hive.ql.Driver.run(Driver.java:530)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at
org.apache.hadoop.hive.ql.reexec.ReExecDriver.run(ReExecDriver.java:190)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at
org.apache.hive.service.cli.operation.SQLOperation.runQuery(SQLOperation.java:232)
~[hive-service-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-1
34]
at
org.apache.hive.service.cli.operation.SQLOperation$BackgroundWork$1.run(SQLOperation.java:336)
~[hive-service-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7
.3.2.20000-134]
at
java.security.AccessController.doPrivileged(AccessController.java:712) ~[?:?]
at javax.security.auth.Subject.doAs(Subject.java:439) ~[?:?]
at
org.apache.hadoop.security.UserGroupInformation.doAs(UserGroupInformation.java:1964)
~[hadoop-common-3.4.2.7.3.2.20000-134.jar:?]
at
org.apache.hive.service.cli.operation.SQLOperation$BackgroundWork.run(SQLOperation.java:356)
~[hive-service-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3
.2.20000-134]
at
java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:539) ~[?:?]
at java.util.concurrent.FutureTask.run(FutureTask.java:264) ~[?:?]
at
java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:539) ~[?:?]
at java.util.concurrent.FutureTask.run(FutureTask.java:264) ~[?:?]
at
java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1136)
~[?:?]
at
java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:635)
~[?:?]
at java.lang.Thread.run(Thread.java:840) ~[?:?]
Caused by: java.lang.Exception: HTTP 400 Error: User doesn't have permissions
to grant role role_100
at
org.apache.ranger.admin.client.RangerAdminRESTClient.grantRole(RangerAdminRESTClient.java:571)
~[ranger-plugins-common-2.8.0.7.3.2.20000-134.jar:2.8.
0.7.3.2.20000-134]
... 26 more
ERROR : DDLTask failed, DDL Operation: class
org.apache.hadoop.hive.ql.ddl.privilege.role.grant.GrantRoleOperation
org.apache.hadoop.hive.ql.security.authorization.plugin.HiveAccessControlException:
java.lang.Exception: HTTP 400 Error: User doesn't have permissions to grant
role role_100
at
org.apache.ranger.authorization.hive.authorizer.RangerHiveAuthorizer.grantRole(RangerHiveAuthorizer.java:585)
~[ranger-hive-plugin-2.8.0.7.3.2.20000-134.jar:2.8.0.7.3.2.20000-134]
at
org.apache.hadoop.hive.ql.ddl.privilege.role.grant.GrantRoleOperation.execute(GrantRoleOperation.java:53)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at org.apache.hadoop.hive.ql.ddl.DDLTask.execute(DDLTask.java:84)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at org.apache.hadoop.hive.ql.exec.Task.executeTask(Task.java:213)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at
org.apache.hadoop.hive.ql.exec.TaskRunner.runSequential(TaskRunner.java:105)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at org.apache.hadoop.hive.ql.Executor.launchTask(Executor.java:354)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at org.apache.hadoop.hive.ql.Executor.launchTasks(Executor.java:327)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at org.apache.hadoop.hive.ql.Executor.runTasks(Executor.java:244)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at org.apache.hadoop.hive.ql.Executor.execute(Executor.java:105)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at org.apache.hadoop.hive.ql.Driver.execute(Driver.java:843)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at org.apache.hadoop.hive.ql.Driver.runInternal(Driver.java:695)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at org.apache.hadoop.hive.ql.Driver.run(Driver.java:536)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at org.apache.hadoop.hive.ql.Driver.run(Driver.java:530)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at
org.apache.hadoop.hive.ql.reexec.ReExecDriver.run(ReExecDriver.java:190)
~[hive-exec-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at
org.apache.hive.service.cli.operation.SQLOperation.runQuery(SQLOperation.java:232)
~[hive-service-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at
org.apache.hive.service.cli.operation.SQLOperation$BackgroundWork$1.run(SQLOperation.java:336)
~[hive-service-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at
java.security.AccessController.doPrivileged(AccessController.java:712) ~[?:?]
at javax.security.auth.Subject.doAs(Subject.java:439) ~[?:?]
at
org.apache.hadoop.security.UserGroupInformation.doAs(UserGroupInformation.java:1964)
~[hadoop-common-3.4.2.7.3.2.20000-134.jar:?]
at
org.apache.hive.service.cli.operation.SQLOperation$BackgroundWork.run(SQLOperation.java:356)
~[hive-service-3.1.3000.7.3.2.20000-134.jar:3.1.3000.7.3.2.20000-134]
at
java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:539) ~[?:?]
at java.util.concurrent.FutureTask.run(FutureTask.java:264) ~[?:?]
at
java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:539) ~[?:?]
at java.util.concurrent.FutureTask.run(FutureTask.java:264) ~[?:?]
at
java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1136)
~[?:?]
at
java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:635)
~[?:?]
at java.lang.Thread.run(Thread.java:840) ~[?:?]
Caused by: java.lang.Exception: HTTP 400 Error: User doesn't have permissions
to grant role role_100
at
org.apache.ranger.admin.client.RangerAdminRESTClient.grantRole(RangerAdminRESTClient.java:571)
~[ranger-plugins-common-2.8.0.7.3.2.20000-134.jar:2.8.0.7.3.2.20000-134]
at
org.apache.ranger.plugin.service.RangerBasePlugin.grantRole(RangerBasePlugin.java:1061)
~[ranger-plugins-common-2.8.0.7.3.2.20000-134.jar:2.8.0.7.3.2.20000-134]
at
org.apache.ranger.authorization.hive.authorizer.RangerHiveAuthorizer.grantRole(RangerHiveAuthorizer.java:582)
~[ranger-hive-plugin-2.8.0.7.3.2.20000-134.jar:2.8.0.7.3.2.20000-134]
... 26 more
ERROR : FAILED: Execution Error, return code 40000 from
org.apache.hadoop.hive.ql.ddl.DDLTask. java.lang.Exception: HTTP 400 Error:
User doesn't have permissions to grant role role_100
INFO : Completed executing
command(queryId=hive_20260716191903_17958d74-c978-47b5-bbf4-f5cee5cc16e2); Time
taken: 0.028 seconds
INFO : OK
Error: Error while compiling statement: FAILED: Execution Error, return code
40000 from org.apache.hadoop.hive.ql.ddl.DDLTask. java.lang.Exception: HTTP 400
Error: User doesn't have permissions to grant role role_100; Query ID:
hive_20260716191903_17958d74-c978-47b5-bbf4-f5cee5cc16e2
(state=08S01,code=40000)
{code}
--
This message was sent by Atlassian Jira
(v8.20.10#820010)