roryqi opened a new issue, #13504:
URL: https://github.com/apache/gravitino/issues/13504

   ### Version
   
   main branch
   
   ### Describe what's wrong
   
   When granting, revoking, or overriding privileges for a role, 
`PermissionManager` catches every `NoSuchEntityException` thrown by 
`store.update(...)` and converts it to `NoSuchRoleException`.
   
   However, updating a role also resolves the IDs of its securable objects. If 
a catalog, schema, table, function, or another metadata object cannot be 
resolved, that `NoSuchEntityException` is incorrectly reported as a missing 
role.
   
   This masks the actual failure and makes authorization and HA consistency 
problems difficult to diagnose.
   
   ### Error message and/or stacktrace
   
   A privilege update for an existing role can incorrectly return:
   
   ```text
   NoSuchRoleException: Role <role> does not exist in the metalake <metalake>
   ```
   
   even when the missing entity is the target metadata object.
   
   ### How to reproduce
   
   1. Create a role.
   2. Confirm that the role can be retrieved.
   3. Grant a privilege on a nonexistent or temporarily unavailable metadata 
object.
   4. Observe that the operation reports `NoSuchRoleException` instead of 
`NoSuchMetadataObjectException`.
   
   ### Additional context
   
   `RoleMetaService.updateRole` resolves securable-object IDs while executing 
the role updater. Exceptions from that resolution propagate through 
`EntityStore.update` and are caught as though the role lookup itself failed.
   
   The fix should preserve `NoSuchRoleException` for an actually missing role, 
while mapping missing securable objects to `NoSuchMetadataObjectException` and 
preserving the original cause.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to