[
https://issues.apache.org/jira/browse/HIVE-19870?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16513562#comment-16513562
]
Peter Vary commented on HIVE-19870:
-----------------------------------
If the goal is to keep permission setting functionality in HCatalog, the patch
4 will do it.
The only change here is swapping the homebrewn
{{FileOutputCommitterContainer.applyGroupAndPerms}} method with the tried and
working {{HdfsUtils.setFullFileStatus}} method - this one was used before
HIVE-16392 -, to set the permissions for the locations, and still used in
{{SessionHiveMetaStoreClient.truncateTempTable}}.
The difference between the two method is:
* In case of non recursive run the HdfsUtils catches every exception and
prints out a warning instead of failing altogether
* In case of recursive run the HdfsUtils calls FsShell to set the permissions
instead of traversing the tree manually and setting it one-by-one
Patch 3 test runs were successfull, patch 4 is only fixes checkstyle errors.
[~stakiar]: Could you please review?
Thanks,
Peter
> HCatalog dynamic partition query can fail, if the table path is managed by
> Sentry
> ---------------------------------------------------------------------------------
>
> Key: HIVE-19870
> URL: https://issues.apache.org/jira/browse/HIVE-19870
> Project: Hive
> Issue Type: Bug
> Reporter: Peter Vary
> Assignee: Peter Vary
> Priority: Major
> Attachments: HIVE-19870.2.patch, HIVE-19870.3.patch,
> HIVE-19870.4.patch, HIVE-19870.patch
>
>
> The central issue is that HCatalog is assuming it needs to handle the storage
> based authorization features. When a job completes, in HCatalog's file
> committing phase it tries to manually set the permissions for the table for
> authorization's sake, which makes it go against auto-authorization managment
> features provided by Sentry.
> The offending code is specifically at
> [https://github.com/apache/hive/blob/master/hcatalog/core/src/main/java/org/apache/hive/hcatalog/mapreduce/FileOutputCommitterContainer.java#L373-L374]
> and
> [https://github.com/apache/hive/blob/master/hcatalog/core/src/main/java/org/apache/hive/hcatalog/mapreduce/FileOutputCommitterContainer.java#L380-L385]
> and
> [https://github.com/apache/hive/blob/master/hcatalog/core/src/main/java/org/apache/hive/hcatalog/mapreduce/FileOutputCommitterContainer.java#L952-L954]
> where you can notice that _after_ it moves the files created by the job into
> their respective partition directories under the final table destination, it
> goes onto trying to perform chmod/chgrp operations which will fail out
--
This message was sent by Atlassian JIRA
(v7.6.3#76005)