jarredhj0214 opened a new pull request, #13364: URL: https://github.com/apache/gravitino/pull/13364
### What changes were proposed in this pull request? This PR adds an authorizer-level `ReentrantReadWriteLock` around the in-memory JCasbin enforcer state used by `JcasbinAuthorizer`. The lock makes role policy reload atomically visible to authorization reads: - Authorization reads and policy inspections use the shared read lock. - Role policy replacement, invalidation, loaded-role cache cleanup, and grouping bind/prune use the write lock. - Metadata id resolution and DB queries remain outside the write lock. It also adds a regression test that simulates concurrent authorization requests arriving while a role policy reload is in progress. ### Why are the changes needed? `SyncedEnforcer` makes individual JCasbin method calls thread-safe, but role policy reload is a multi-call sequence: ```text remove old role policies add new role policies mark role as loaded ``` A concurrent `enforce()` can observe the transient state after the old policies are removed and before the new policies are added, causing a false denial. This was observed as intermittent `loadTable` authorization failures where retrying shortly afterwards succeeded. This PR ensures that concurrent authorization reads wait for the reload sequence to complete instead of reading the intermediate empty policy state. Fixes #13363 ### Does this PR introduce any user-facing change? No. It does not change authorization semantics or grant/revoke behavior. It only makes the existing in-memory policy state transition atomic from the perspective of authorization reads. ### How was this patch tested? ```bash JAVA_HOME=/Users/hujie3/.gradle/jdks/amazon_com_inc_-17-x86_64-os_x/amazon-corretto-17.jdk/Contents/Home ./gradlew :server-common:test --tests org.apache.gravitino.server.authorization.jcasbin.TestJcasbinAuthorizer ``` Result: ```text BUILD SUCCESSFUL ``` -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
