airborne12 opened a new pull request, #68673:
URL: https://github.com/apache/doris/pull/68673
### What problem does this PR solve?
Issue Number: None
Related PR: #68559 (master)
Problem Summary:
`SET PASSWORD` and `ALTER USER` used the account name alone to apply
root-only rules. A host-specific `root@'<host>'` account was therefore treated
as the built-in `root@'%'` identity. This backport uses
`UserIdentity.isRootUser()` for the target and current identities.
`branch-4.2` does not implement `ACCOUNT_LOCK`; the backport retains that
behavior. The master regression's lock/unlock success statements are replaced
with assertions of the existing unsupported-operation error.
### Release note
`SET PASSWORD` and `ALTER USER` now treat only `root@'%'` as the built-in
root account. A grant-authorized user can manage a host-specific account named
`root`.
### Check List (For Author)
- Test:
- [x] Regression test
- [x] Unit Test
- [ ] Manual test
- Behavior changed:
- [x] Yes. Host-specific accounts named `root` follow ordinary account
privilege rules.
- Does this need documentation?
- [x] No. This corrects an existing privilege check.
### Backport audit
Source commit: `bf985295aac18521553bdd6a84700f23f138406a`; backport commit:
`07206525e9c8863a0995938dcbdb267c0bdfa260`.
| Source file | Source hunk | Result |
| --- | --- | --- |
| `AlterUserInfo.java` | `@@ -30 +29,0 @@ import
org.apache.doris.common.UserException;` | Ported: remove unused `Auth` import. |
| `AlterUserInfo.java` | `@@ -121 +120 @@ public class AlterUserInfo {` |
N-A: 4.2 rejects `ACCOUNT_LOCK` before the master-only root lock check;
existing rejection is retained. |
| `AlterUserInfo.java` | `@@ -141,3 +140 @@ public class AlterUserInfo {` |
Adapted: use the full target and current identities in 4.2's existing privilege
path. |
| `SetPassVarOp.java` | `@@ -28 +27,0 @@ import
org.apache.doris.common.UserException;` | Ported: remove unused `Auth` import. |
| `SetPassVarOp.java` | `@@ -72 +71 @@ public class SetPassVarOp extends
SetVarOp {` | Ported: use `isRootUser()` for the password target. |
| `AccountLockTest.java` | `@@ -190,0 +191,14 @@ public class
AccountLockTest extends TestWithFeService {` | N-A: 4.2 has no account-lock
implementation or this test class. |
| `SystemRootUserTest.java` | `@@ -0,0 +1,108 @@` | Adapted: all five
behavior tests are present; shortened the class comment. |
| `test_system_user.groovy` | `@@ -102,0 +103,32 @@
suite("test_system_user","p0,auth") {` | Adapted: preserves password and
privilege assertions; asserts 4.2's unsupported lock response. |
`git range-diff` confirms the intended differences: 4.2's `ClusterNamespace`
root-name check was replaced with full identity comparison; the unsupported
lock check and master-only `AccountLockTest` were omitted; the regression lock
steps now assert rejection. The added unit tests retain the source behavior
coverage.
Validation on this commit:
- `./build.sh --fe`: passed.
- FE unit tests: 25 tests across `SystemRootUserTest`, `SetPasswordTest`,
`AlterUserStmtTest`, `AlterUserCommandTest`, `SetPasswordParseTest`,
`EncryptSQLTest`, and `AuthTest`; zero failures.
- Isolated cloud regression: `account_p0/test_system_user`,
`test_root_user`, and `test_set_password`: one suite each, zero failures.
`test_alter_user` was not selected by the p0 filter and is not counted.
- Complete PR diff English check: passed, no data exceptions.
- Merged-tree Checkstyle preflight: passed against `origin/branch-4.2` at
`7e4909b904ff49fc799e5a4efa02f03fe4a8638d`.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]