[
https://issues.apache.org/jira/browse/KNOX-2469?focusedWorklogId=512374&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-512374
]
ASF GitHub Bot logged work on KNOX-2469:
----------------------------------------
Author: ASF GitHub Bot
Created on: 16/Nov/20 13:48
Start Date: 16/Nov/20 13:48
Worklog Time Spent: 10m
Work Description: jameschen1519 commented on a change in pull request
#383:
URL: https://github.com/apache/knox/pull/383#discussion_r524277885
##########
File path:
gateway-server/src/main/java/org/apache/knox/gateway/services/security/impl/DefaultKeystoreService.java
##########
@@ -513,12 +513,14 @@ private synchronized boolean isKeyStoreAvailable(final
Path keyStoreFilePath, St
// Package private for unit test access
// We need this to be synchronized to prevent multiple threads from using at
once
synchronized KeyStore createKeyStore(Path keystoreFilePath, String
keystoreType, char[] password) throws KeystoreServiceException {
- if (Files.notExists(keystoreFilePath)) {
- // Ensure the parent directory exists...
- try {
+ // Ensure the parent directory exists...
+ // This is symlink safe.
+ Path parentPath = keystoreFilePath.getParent();
Review comment:
A pre-existing test has been edited to include the symlink test; passes
when run locally with "mvn package -pl gateway-server -am".
----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
For queries about this service, please contact Infrastructure at:
[email protected]
Issue Time Tracking
-------------------
Worklog Id: (was: 512374)
Remaining Estimate: 167h (was: 167h 10m)
Time Spent: 1h (was: 50m)
> Knox keystore directory creation fails when following a symlink
> ---------------------------------------------------------------
>
> Key: KNOX-2469
> URL: https://issues.apache.org/jira/browse/KNOX-2469
> Project: Apache Knox
> Issue Type: Bug
> Components: Server
> Affects Versions: 1.4.0, 1.5.0
> Reporter: James Chen
> Priority: Minor
> Labels: easy-fix, patch-available
> Fix For: 1.4.0, 1.5.0
>
> Attachments: 0001-Fixing-Knox-symlink.patch
>
> Original Estimate: 168h
> Time Spent: 1h
> Remaining Estimate: 167h
>
> At the moment, if the keystore path does not exist, Knox attempts to create
> the parent directories of the keystore path recursively. However, there is an
> edge case, as described in JDK-8130464, where the directory creation fails if
> the final, parent directory of the keystore path is a symlink. This causes a
> failure during startup.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)