[
https://issues.apache.org/jira/browse/HADOOP-12785?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15233514#comment-15233514
]
Mukhadin Buzdov commented on HADOOP-12785:
------------------------------------------
[~jojochuang], please let me share few review comments:
* No need to include in this patch _truststore_ related changes.
* There are tabulation related problems in the patch.
* As for me you've introduced too much complication to exception handling - IMO
it should be just maintainable and implemented in common way.
As a Hadoop admin I will prefer to have standard stack traces to analyze for
sure, but not just suggestions {color:gray}(_explainException()_ method){color}
of what might be a problem cause. Standard LDAP error codes are easy to google,
never had problems with this.
* No unit test changes was needed?
> [Handling exceptions] LdapGroupsMapping.getGroups() do not provide
> information about root cause
> -----------------------------------------------------------------------------------------------
>
> Key: HADOOP-12785
> URL: https://issues.apache.org/jira/browse/HADOOP-12785
> Project: Hadoop Common
> Issue Type: Bug
> Components: security
> Affects Versions: 2.7.1
> Environment: _Operating system_: CentOS Linux 7
> {color:gray}(7.1.1503){color}
> _Platform_: HDP 2.3.4.0, Ambari 2.1.2
> Reporter: Mukhadin Buzdov
> Assignee: Wei-Chiu Chuang
> Priority: Minor
> Labels: easyfix
> Attachments: HADOOP-12785.001.patch
>
>
> _CommunicationException_ and _NamingException_ are not logged in
> _LdapGroupsMapping.getGroups()_.
> {code:title=LdapGroupsMapping.java|borderStyle=solid}
> public synchronized List<String> getGroups(String user) throws IOException {
> List<String> emptyResults = new ArrayList<String>();
> // ...
> try {
> return doGetGroups(user);
> } catch (CommunicationException e) {
> LOG.warn("Connection is closed, will try to reconnect");
> } catch (NamingException e) {
> LOG.warn("Exception trying to get groups for user " + user + ": " +
> e.getMessage());
> return emptyResults;
> }
> //...
> return emptyResults;
> }
> {code}
> {color:red}It is not possible to understand _LDAP_ level failures.{color}
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)