airborne12 opened a new pull request, #68663:
URL: https://github.com/apache/doris/pull/68663
### What problem does this PR solve?
Related PR: apache/doris#68555. Backports merge commit
`66d1bf5de4480b2d04f4e1775574bbd9a53de05e` to `branch-4.2`.
Problem Summary:
Column-level GRANT and REVOKE checked `GRANT_PRIV` but did not require the
grantor to hold the delegated privilege on the table or each requested column.
This change applies the source fix and its unit and regression coverage. The
only adaptation removes a redundant `Rule 6` comment.
### Release note
Column-level GRANT/REVOKE now requires the grantor to hold the delegated
privilege on the table or on each specified column. The administrator bypass is
unchanged.
### Check List (For Author)
- [x] Regression test: `account_p0/test_grant_col_priv` passed on an
isolated branch-4.2 cloud cluster.
- [x] Unit Test: `GrantTablePrivilegeCommandTest` passed, 8 tests, 0
failures.
- [ ] Manual test
- [ ] No need to test or manual test.
Validation: `./build.sh --fe` passed. The complete PR diff passed the
English-description checker. The merged-tree FE Checkstyle preflight passed for
head `293a50da9e830e650f8d61321c0bf1d781b446fb` against `origin/branch-4.2` at
`7e4909b904ff49fc799e5a4efa02f03fe4a8638d`. The generated regression output
matched the committed golden file byte for byte.
- Behavior changed:
- [x] Yes. Unauthorized column grants and revokes are rejected.
- Does this need documentation?
- [x] No. The existing SQL privilege rules remain the same; this
enforces them.
### Source hunk audit
`FE command` =
`fe/fe-core/src/main/java/org/apache/doris/nereids/trees/plans/commands/GrantTablePrivilegeCommand.java`
`FE test` =
`fe/fe-core/src/test/java/org/apache/doris/nereids/trees/plans/commands/GrantTablePrivilegeCommandTest.java`
`Golden` = `regression-test/data/account_p0/test_grant_col_priv.out`
`Suite` = `regression-test/suites/account_p0/test_grant_col_priv.groovy`
| Source file | Source `@@` hunk | Disposition | Note |
| --- | --- | --- | --- |
| FE command | `-29,0 +30` | Ported | Import. |
| FE command | `-135,0 +137` | Ported | Grantor predicate. |
| FE command | `-156,2 +158,2` | Ported | Column privilege check. |
| FE command | `-165,0 +168,19` | Adapted | Preserved validation; removed
the redundant `Rule 6` comment. |
| FE test | `-20,0 +21` | Ported | Import. |
| FE test | `-22,0 +24` | Ported | Import. |
| FE test | `-106,0 +109,85` | Ported | Five new privilege cases. |
| Golden | `-0,0 +1,7` | Ported verbatim | Generated output. |
| Suite | `-0,0 +1,109` | Ported verbatim | Full source regression. |
`git range-diff` pairs the source and backport as one commit; its only code
difference is the removed comment. The backport commit message adds the source
SHA and validation details.
### Check List (For Reviewer who merge this PR)
- [ ] Confirm the release note
- [ ] Confirm test cases
- [ ] Confirm document
- [ ] Add branch pick label
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]