[ https://issues.apache.org/jira/browse/YARN-7879?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16350648#comment-16350648 ]
genericqa commented on YARN-7879: --------------------------------- | (/) *{color:green}+1 overall{color}* | \\ \\ || Vote || Subsystem || Runtime || Comment || | {color:blue}0{color} | {color:blue} reexec {color} | {color:blue} 0m 18s{color} | {color:blue} Docker mode activated. {color} | || || || || {color:brown} Prechecks {color} || | {color:green}+1{color} | {color:green} @author {color} | {color:green} 0m 0s{color} | {color:green} The patch does not contain any @author tags. {color} | | {color:green}+1{color} | {color:green} test4tests {color} | {color:green} 0m 0s{color} | {color:green} The patch appears to include 1 new or modified test files. {color} | || || || || {color:brown} trunk Compile Tests {color} || | {color:green}+1{color} | {color:green} mvninstall {color} | {color:green} 15m 13s{color} | {color:green} trunk passed {color} | | {color:green}+1{color} | {color:green} compile {color} | {color:green} 0m 34s{color} | {color:green} trunk passed {color} | | {color:green}+1{color} | {color:green} checkstyle {color} | {color:green} 0m 25s{color} | {color:green} trunk passed {color} | | {color:green}+1{color} | {color:green} mvnsite {color} | {color:green} 0m 37s{color} | {color:green} trunk passed {color} | | {color:green}+1{color} | {color:green} shadedclient {color} | {color:green} 10m 23s{color} | {color:green} branch has no errors when building and testing our client artifacts. {color} | | {color:green}+1{color} | {color:green} findbugs {color} | {color:green} 1m 11s{color} | {color:green} trunk passed {color} | | {color:green}+1{color} | {color:green} javadoc {color} | {color:green} 0m 37s{color} | {color:green} trunk passed {color} | || || || || {color:brown} Patch Compile Tests {color} || | {color:green}+1{color} | {color:green} mvninstall {color} | {color:green} 0m 35s{color} | {color:green} the patch passed {color} | | {color:green}+1{color} | {color:green} compile {color} | {color:green} 0m 30s{color} | {color:green} the patch passed {color} | | {color:green}+1{color} | {color:green} javac {color} | {color:green} 0m 30s{color} | {color:green} the patch passed {color} | | {color:green}+1{color} | {color:green} checkstyle {color} | {color:green} 0m 19s{color} | {color:green} the patch passed {color} | | {color:green}+1{color} | {color:green} mvnsite {color} | {color:green} 0m 33s{color} | {color:green} the patch passed {color} | | {color:green}+1{color} | {color:green} whitespace {color} | {color:green} 0m 0s{color} | {color:green} The patch has no whitespace issues. {color} | | {color:green}+1{color} | {color:green} shadedclient {color} | {color:green} 10m 4s{color} | {color:green} patch has no errors when building and testing our client artifacts. {color} | | {color:green}+1{color} | {color:green} findbugs {color} | {color:green} 1m 14s{color} | {color:green} the patch passed {color} | | {color:green}+1{color} | {color:green} javadoc {color} | {color:green} 0m 34s{color} | {color:green} the patch passed {color} | || || || || {color:brown} Other Tests {color} || | {color:green}+1{color} | {color:green} unit {color} | {color:green} 3m 9s{color} | {color:green} hadoop-yarn-common in the patch passed. {color} | | {color:green}+1{color} | {color:green} asflicense {color} | {color:green} 0m 19s{color} | {color:green} The patch does not generate ASF License warnings. {color} | | {color:black}{color} | {color:black} {color} | {color:black} 46m 28s{color} | {color:black} {color} | \\ \\ || Subsystem || Report/Notes || | Docker | Client=17.05.0-ce Server=17.05.0-ce Image:yetus/hadoop:5b98639 | | JIRA Issue | YARN-7879 | | JIRA Patch URL | https://issues.apache.org/jira/secure/attachment/12908999/YARN-7879.001.patch | | Optional Tests | asflicense compile javac javadoc mvninstall mvnsite unit shadedclient findbugs checkstyle | | uname | Linux b15ac493c66c 4.4.0-64-generic #85-Ubuntu SMP Mon Feb 20 11:50:30 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux | | Build tool | maven | | Personality | /testptch/patchprocess/precommit/personality/provided.sh | | git revision | trunk / 4aef8bd | | maven | version: Apache Maven 3.3.9 | | Default Java | 1.8.0_151 | | findbugs | v3.1.0-RC1 | | Test Results | https://builds.apache.org/job/PreCommit-YARN-Build/19582/testReport/ | | Max. process+thread count | 407 (vs. ulimit of 5000) | | modules | C: hadoop-yarn-project/hadoop-yarn/hadoop-yarn-common U: hadoop-yarn-project/hadoop-yarn/hadoop-yarn-common | | Console output | https://builds.apache.org/job/PreCommit-YARN-Build/19582/console | | Powered by | Apache Yetus 0.8.0-SNAPSHOT http://yetus.apache.org | This message was automatically generated. > NM user is unable to access the application filecache due to permissions > ------------------------------------------------------------------------ > > Key: YARN-7879 > URL: https://issues.apache.org/jira/browse/YARN-7879 > Project: Hadoop YARN > Issue Type: Bug > Affects Versions: 3.1.0 > Reporter: Shane Kumpf > Assignee: Jason Lowe > Priority: Critical > Attachments: YARN-7879.001.patch > > > I noticed the following log entries where localization was being retried on > several MR AM files. > {code} > 2018-02-02 02:53:02,905 INFO > org.apache.hadoop.yarn.server.nodemanager.containermanager.localizer.LocalResourcesTrackerImpl: > Resource > /hadoop-yarn/usercache/hadoopuser/appcache/application_1517539453610_0001/filecache/11/job.jar > is missing, localizing it again > 2018-02-02 02:53:42,908 INFO > org.apache.hadoop.yarn.server.nodemanager.containermanager.localizer.LocalResourcesTrackerImpl: > Resource > /hadoop-yarn/usercache/hadoopuser/appcache/application_1517539453610_0001/filecache/13/job.xml > is missing, localizing it again > {code} > The cluster is configured to use LCE and > {{yarn.nodemanager.linux-container-executor.nonsecure-mode.local-user}} is > set to a user ({{hadoopuser}}) that is in the {{hadoop}} group. The user has > a umask of {{0002}}. The cluser is configured with > {{fs.permissions.umask-mode=022}}, coming from {{core-default}}. Setting the > local-user to {{nobody}}, who is not a login user or in the {{hadoop}} group, > produces the same results. > {code} > [hadoopuser@y7001 ~]$ umask > 0002 > [hadoopuser@y7001 ~]$ id > uid=1003(hadoopuser) gid=1004(hadoopuser) groups=1004(hadoopuser),1001(hadoop) > {code} > The cause of the log entry was tracked down a simple !file.exists call in > {{LocalResourcesTrackerImpl#isResourcePresent}}. > {code} > public boolean isResourcePresent(LocalizedResource rsrc) { > boolean ret = true; > if (rsrc.getState() == ResourceState.LOCALIZED) { > File file = new File(rsrc.getLocalPath().toUri().getRawPath(). > toString()); > if (!file.exists()) { > ret = false; > } else if (dirsHandler != null) { > ret = checkLocalResource(rsrc); > } > } > return ret; > } > {code} > The Resources Tracker runs as the NM user, in this case {{yarn}}. The files > being retried are in the filecache. The directories in the filecache are all > owned by the local-user's primary group and 700 perms, which makes it > unreadable by the {{yarn}} user. > {code} > [root@y7001 ~]# ls -la > /hadoop-yarn/usercache/hadoopuser/appcache/application_1517540536531_0001/filecache > total 0 > drwx--x---. 6 hadoopuser hadoop 46 Feb 2 03:06 . > drwxr-s---. 4 hadoopuser hadoop 73 Feb 2 03:07 .. > drwx------. 2 hadoopuser hadoopuser 61 Feb 2 03:05 10 > drwx------. 3 hadoopuser hadoopuser 21 Feb 2 03:05 11 > drwx------. 2 hadoopuser hadoopuser 45 Feb 2 03:06 12 > drwx------. 2 hadoopuser hadoopuser 41 Feb 2 03:06 13 > {code} > I saw YARN-5287, but that appears to be related to a restrictive umask and > the usercache itself. I was unable to locate any other known issues that > seemed relevent. Is the above already known? a configuration issue? -- This message was sent by Atlassian JIRA (v7.6.3#76005) --------------------------------------------------------------------- To unsubscribe, e-mail: yarn-issues-unsubscr...@hadoop.apache.org For additional commands, e-mail: yarn-issues-h...@hadoop.apache.org