[ 
https://issues.apache.org/jira/browse/CASSANDRA-20208?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17914347#comment-17914347
 ] 

Stefan Miklosovic commented on CASSANDRA-20208:
-----------------------------------------------

[CASSANDRA-20208-5.0|https://github.com/instaclustr/cassandra/tree/CASSANDRA-20208-5.0]
{noformat}
java17_pre-commit_tests                         
  ✓ j17_build                                        3m 57s
  ✓ j17_cqlsh_dtests_py311                           6m 43s
  ✓ j17_cqlsh_dtests_py38                            6m 42s
  ✓ j17_cqlshlib_cython_tests                        7m 38s
  ✓ j17_cqlshlib_tests                                7m 2s
  ✓ j17_dtests_latest                                43m 3s
  ✓ j17_jvm_dtests                                  21m 50s
  ✓ j17_unit_tests                                  16m 34s
  ✓ j17_utests_latest                                17m 9s
  ✓ j17_utests_oa                                   16m 45s
  ✕ j17_cqlsh_dtests_py311_vnode                     7m 48s
      cqlsh_tests.test_cqlsh_copy.TestCqlshCopy 
test_bulk_round_trip_with_timeouts
  ✕ j17_cqlsh_dtests_py38_vnode                      7m 46s
      cqlsh_tests.test_cqlsh_copy.TestCqlshCopy 
test_bulk_round_trip_with_timeouts
  ✕ j17_dtests                                      32m 51s
      refresh_test.TestRefresh test_refresh_deadlock_startup
  ✕ j17_dtests_vnode                                40m 43s
      bootstrap_test.TestBootstrap test_decommissioned_wiped_node_can_join
  ✕ j17_jvm_dtests_latest_vnode                     15m 50s
      org.apache.cassandra.distributed.test.ReadSpeculationTest speculateTest
{noformat}

[java17_pre-commit_tests|https://app.circleci.com/pipelines/github/instaclustr/cassandra/5226/workflows/2d38246a-c4a5-4c31-8347-0c1907a8cb1b]


> audit_logging_options parameters are not sanitized when loaded from a 
> configuration file on startup
> ---------------------------------------------------------------------------------------------------
>
>                 Key: CASSANDRA-20208
>                 URL: https://issues.apache.org/jira/browse/CASSANDRA-20208
>             Project: Apache Cassandra
>          Issue Type: Bug
>          Components: Observability/Logging
>            Reporter: Dmitry Konstantinov
>            Assignee: Stefan Miklosovic
>            Priority: Normal
>             Fix For: 4.1.x, 5.0.x, 5.x
>
>         Attachments: audit_filtering_state.png
>
>          Time Spent: 10m
>  Remaining Estimate: 0h
>
> based on the discussion in 
> [https://lists.apache.org/thread/3whc30bqfcr1vgwv73zwlv74l2v3c0gt]
> a configuration like this:
> {code:java}
> audit_logging_options:
>   enabled: true
>   logger:
>     - class_name: FileAuditLogger
>   included_categories: DCL, ERROR, AUTH {code}
> is not sanitized when it is loaded on startup from cassandra.yaml file - 
> spaces here are remaining: " ERROR", " AUTH" after parsing. As a result the 
> audit logs filtering works not in a way as a user may expect and it is hard 
> to troubleshoot:
> !audit_filtering_state.png|width=400!
> When we run nodetool enableauditlog the following logic is invoked: 
> [https://github.com/apache/cassandra/blob/cassandra-4.1.7/src/java/org/apache/cassandra/service/StorageService.java#L6459]
>  which rebuild AuditLogOptions using builder API.AuditLogOption.build() has 
> sanitisation logic which does the trimming: 
> [https://github.com/apache/cassandra/blob/trunk/src/java/org/apache/cassandra/audit/AuditLogOptions.java#L235]
>  
> org.apache.cassandra.config.Config#audit_logging_options is created a generic 
> reflective code which does not use the builder, so there is no trimming 
> during a startup.
> It can be fixed by adding sanitisation during the startup parsing too to make 
> the behaviour more consistent and less error prone.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to