----------------------------------------------------------- This is an automatically generated e-mail. To reply, visit: https://reviews.apache.org/r/70510/#review214785 -----------------------------------------------------------
Fix it, then Ship it! agents-common/src/main/java/org/apache/ranger/plugin/policyresourcematcher/RangerPolicyResourceMatcher.java Line 32 (original), 32 (patched) <https://reviews.apache.org/r/70510/#comment301043> Consider adding ANCESTOR_WITH_WILDCARDS (the new enum element) as the last entry (a practice from good old C/C++ days). - Madhan Neethiraj On April 21, 2019, 6:34 p.m., Abhay Kulkarni wrote: > > ----------------------------------------------------------- > This is an automatically generated e-mail. To reply, visit: > https://reviews.apache.org/r/70510/ > ----------------------------------------------------------- > > (Updated April 21, 2019, 6:34 p.m.) > > > Review request for ranger, Bolke de Bruin and Madhan Neethiraj. > > > Bugs: RANGER-2405 > https://issues.apache.org/jira/browse/RANGER-2405 > > > Repository: ranger > > > Description > ------- > > With RANGER-1781, Ranger supports resource policies with valid, but partial > hierarchies specified as the resource. However, during policy evaluation, a > partial hierarchy is treated as a complete hierarchy with the unspecified > part of the resource hierarchy as having been specified with an all-matching > wildcard value (that is, as an asterisk). This leads to such policy matching > an accessed resource which has more resource levels than in the policy, and > is more permissive than the policy specification. > > Policy resource matching algorithm is enhanced to differentiate between > absence of a resource value and resource value of asterisk. > > > Diffs > ----- > > > agents-common/src/main/java/org/apache/ranger/plugin/policyengine/RangerPolicyEngineImpl.java > be256a9ba > > agents-common/src/main/java/org/apache/ranger/plugin/policyevaluator/RangerDefaultPolicyEvaluator.java > f1e999aaf > > agents-common/src/main/java/org/apache/ranger/plugin/policyresourcematcher/RangerDefaultPolicyResourceMatcher.java > 12a1c1c9e > > agents-common/src/main/java/org/apache/ranger/plugin/policyresourcematcher/RangerPolicyResourceMatcher.java > 4696d84da > > agents-common/src/test/java/org/apache/ranger/plugin/policyengine/TestPolicyEngine.java > e019e6218 > > agents-common/src/test/java/org/apache/ranger/plugin/resourcematcher/TestDefaultPolicyResourceMatcher.java > 1755233d5 > > agents-common/src/test/resources/policyengine/test_policyengine_hive_with_partial_resource_policies.json > PRE-CREATION > > agents-common/src/test/resources/resourcematcher/test_defaultpolicyresourcematcher.json > 211e0ed9d > > agents-common/src/test/resources/resourcematcher/test_defaultpolicyresourcematcher_for_hive_policy.json > ddb171d1c > > > Diff: https://reviews.apache.org/r/70510/diff/1/ > > > Testing > ------- > > Developed unit tests for this scenario and ran all unit tests successfully. > > > Thanks, > > Abhay Kulkarni > >
