rich7420 commented on code in PR #11252:
URL: https://github.com/apache/ozone/pull/11252#discussion_r4141832802


##########
hadoop-ozone/integration-test-s3/src/test/java/org/apache/hadoop/ozone/s3/awssdk/v2/AbstractS3SDKV2Tests.java:
##########
@@ -300,6 +306,48 @@ public void testPutObject() {
     assertEquals("\"37b51d194a7513e45b56f6524f2d51f2\"", 
getObjectResponse.eTag());
   }
 
+  @ParameterizedTest
+  @ValueSource(strings = {"follower-stale", "follower-linearizable",
+      "leader-only"})
+  public void testGetObjectWithReadConsistencyHeader(String readConsistency) {

Review Comment:
   > the subsequent S3 read retains its requested consistency and may use a 
follower
   
   Thanks for the update. `GetKeyInfo` still carries S3 authentication, which 
OM validates before read dispatch. Both [ordinary 
credentials](https://github.com/apache/ozone/blob/14d3695df443bc6fd44db331026cc9eeb47e26d1/hadoop-ozone/ozone-manager/src/main/java/org/apache/hadoop/ozone/security/OzoneDelegationTokenSecretManager.java#L361-L376)
 and 
[STS](https://github.com/apache/ozone/blob/14d3695df443bc6fd44db331026cc9eeb47e26d1/hadoop-ozone/ozone-manager/src/main/java/org/apache/hadoop/ozone/security/S3SecurityUtil.java#L70-L79)
 still require the leader there, so changing the bootstrap routing does not 
resolve the subsequent read.
   
   I confirmed the rejection in a component test using the real authentication 
code after a mocked successful bootstrap, with both credential types and both 
follower hints. The resulting `OMNotLeaderException` also disables later 
follower attempts for that client.
   
   Please extend the fix and add a secure HA test that verifies a follower 
serves the metadata read. If secure follower reads are deferred, can we 
document that limitation explicitly?



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to