[ 
https://issues.apache.org/jira/browse/HDFS-3509?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13421890#comment-13421890
 ] 

Daryn Sharp commented on HDFS-3509:
-----------------------------------

I think we need to see if the change to use real user needs to be pushed down 
lower, perhaps into {{SecurityUtil.openSecureHttpConnection}} or deeper.  
Otherwise it looks like things such as fetchdt aren't going to work and will 
need a copy-n-paste (ick) of the logic.  I'm noticing this because the trunk 
patch for HDFS-3553 is intersecting with this patch.
                
> WebHdfsFilesystem does not work within a proxyuser doAs call in secure mode
> ---------------------------------------------------------------------------
>
>                 Key: HDFS-3509
>                 URL: https://issues.apache.org/jira/browse/HDFS-3509
>             Project: Hadoop HDFS
>          Issue Type: Bug
>    Affects Versions: 2.0.0-alpha
>            Reporter: Alejandro Abdelnur
>            Assignee: Alejandro Abdelnur
>            Priority: Critical
>         Attachments: HDFS-3509-branch1.patch, HDFS-3509.patch
>
>
> It does not find kerberos credentials in the context (the UGI is logged in 
> from a keytab) and it fails with the following trace:
> {code}
> java.lang.IllegalStateException: unknown char '<'(60) in 
> org.mortbay.util.ajax.JSON$ReaderSource@23245e75
>       at org.mortbay.util.ajax.JSON.handleUnknown(JSON.java:788)
>       at org.mortbay.util.ajax.JSON.parse(JSON.java:777)
>       at org.mortbay.util.ajax.JSON.parse(JSON.java:603)
>       at org.mortbay.util.ajax.JSON.parse(JSON.java:183)
>       at 
> org.apache.hadoop.hdfs.web.WebHdfsFileSystem.jsonParse(WebHdfsFileSystem.java:259)
>       at 
> org.apache.hadoop.hdfs.web.WebHdfsFileSystem.validateResponse(WebHdfsFileSystem.java:268)
>       at 
> org.apache.hadoop.hdfs.web.WebHdfsFileSystem.run(WebHdfsFileSystem.java:427)
>       at 
> org.apache.hadoop.hdfs.web.WebHdfsFileSystem.getDelegationToken(WebHdfsFileSystem.java:722)
> {code}

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: 
https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

Reply via email to