[ 
https://issues.apache.org/jira/browse/HADOOP-10213?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13870184#comment-13870184
 ] 

Chris Nauroth commented on HADOOP-10213:
----------------------------------------

Hi, Vinay.  This looks good, but I think we'll need to revert the {{AclEntry}} 
portion of the change.  There are various unit tests that rely on 
{{assertEquals}} or {{assertArrayEquals}} to check that the correct ACL was 
applied to a file.  With this change, those {{assertEquals}} calls would pass 
even if the permissions inside the ACL entries were incorrect.

Even putting aside tests, this is a public user-facing class, and callers 
likely would find it surprising if "user:bruce:rwx" and "user:bruce:---" were 
considered equal.

> setfacl -x should reject attempts to include permissions in the ACL spec.
> -------------------------------------------------------------------------
>
>                 Key: HADOOP-10213
>                 URL: https://issues.apache.org/jira/browse/HADOOP-10213
>             Project: Hadoop Common
>          Issue Type: Bug
>          Components: tools
>    Affects Versions: HDFS ACLs (HDFS-4685)
>            Reporter: Chris Nauroth
>            Assignee: Vinay
>         Attachments: HADOOP-10213.patch
>
>
> When calling setfacl -x to remove ACL entries, it does not make sense for the 
> entries in the ACL spec to contain permissions.  The permissions should be 
> unspecified, and the CLI should return an error if the user attempts to 
> provide permissions.



--
This message was sent by Atlassian JIRA
(v6.1.5#6160)

Reply via email to