[ 
https://issues.apache.org/jira/browse/HIVE-19870?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16513562#comment-16513562
 ] 

Peter Vary commented on HIVE-19870:
-----------------------------------

If the goal is to keep permission setting functionality in HCatalog, the patch 
4 will do it.
The only change here is swapping the homebrewn 
{{FileOutputCommitterContainer.applyGroupAndPerms}} method with the tried and 
working {{HdfsUtils.setFullFileStatus}} method - this one was used before  
HIVE-16392 -, to set the permissions for the locations, and still used in 
{{SessionHiveMetaStoreClient.truncateTempTable}}.
The difference between the two method is:
 * In case of non recursive run the HdfsUtils catches every exception and 
prints out a warning instead of failing altogether
 * In case of recursive run the HdfsUtils calls FsShell to set the permissions 
instead of traversing the tree manually and setting it one-by-one

Patch 3 test runs were successfull, patch 4 is only fixes checkstyle errors.

[~stakiar]: Could you please review?

Thanks,
 Peter

> HCatalog dynamic partition query can fail, if the table path is managed by 
> Sentry
> ---------------------------------------------------------------------------------
>
>                 Key: HIVE-19870
>                 URL: https://issues.apache.org/jira/browse/HIVE-19870
>             Project: Hive
>          Issue Type: Bug
>            Reporter: Peter Vary
>            Assignee: Peter Vary
>            Priority: Major
>         Attachments: HIVE-19870.2.patch, HIVE-19870.3.patch, 
> HIVE-19870.4.patch, HIVE-19870.patch
>
>
> The central issue is that HCatalog is assuming it needs to handle the storage 
> based authorization features. When a job completes, in HCatalog's file 
> committing phase it tries to manually set the permissions for the table for 
> authorization's sake, which makes it go against auto-authorization managment 
> features provided by Sentry.
> The offending code is specifically at 
> [https://github.com/apache/hive/blob/master/hcatalog/core/src/main/java/org/apache/hive/hcatalog/mapreduce/FileOutputCommitterContainer.java#L373-L374]
> and
> [https://github.com/apache/hive/blob/master/hcatalog/core/src/main/java/org/apache/hive/hcatalog/mapreduce/FileOutputCommitterContainer.java#L380-L385]
> and
> [https://github.com/apache/hive/blob/master/hcatalog/core/src/main/java/org/apache/hive/hcatalog/mapreduce/FileOutputCommitterContainer.java#L952-L954]
> where you can notice that _after_ it moves the files created by the job into 
> their respective partition directories under the final table destination, it 
> goes onto trying to perform chmod/chgrp operations which will fail out



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

Reply via email to