-----------------------------------------------------------
This is an automatically generated e-mail. To reply, visit:
https://reviews.apache.org/r/39928/#review105329
-----------------------------------------------------------



sentry-hdfs/sentry-hdfs-namenode-plugin/src/main/java/org/apache/sentry/hdfs/SentryAuthorizationProvider.java
 (line 202)
<https://reviews.apache.org/r/39928/#comment163887>

    Also, I just realized this would mean, if a path is associated with hive 
object but not in prefix: This condition would still pass. Which is not good, 
sentry hdfs sync should only affect paths inside prefix.


- Sravya Tirukkovalur


On Nov. 5, 2015, 5:38 a.m., Hao Hao wrote:
> 
> -----------------------------------------------------------
> This is an automatically generated e-mail. To reply, visit:
> https://reviews.apache.org/r/39928/
> -----------------------------------------------------------
> 
> (Updated Nov. 5, 2015, 5:38 a.m.)
> 
> 
> Review request for sentry, Anne Yu, Lenni Kuff, and Sravya Tirukkovalur.
> 
> 
> Repository: sentry
> 
> 
> Description
> -------
> 
> Paths that are sentry managed should not succesfully chmod/chown/removeACL.
> We should update setGroup/setUser/setPermission and removeAclFeature.
> 
> Old behavior:
> chmod/chown
>     if not under prefix + unmanaged: writes to hdfs.
>     if managed: writes to hdfs.
> Removing acls:
>     if not under prefix + unmanag: removes from hdfs.
>     if managed: removes from hdfs.
> 
> New behavior:
> If not under prefix: writes to/removes from hdfs.
> If else: no op.
> 
> 
> Diffs
> -----
> 
>   
> sentry-hdfs/sentry-hdfs-namenode-plugin/src/main/java/org/apache/sentry/hdfs/SentryAuthorizationProvider.java
>  419ab68e0d03f995c55d229b762453468de47571 
>   
> sentry-hdfs/sentry-hdfs-namenode-plugin/src/test/java/org/apache/sentry/hdfs/TestSentryAuthorizationProvider.java
>  fd5146f079d93687738a522f42beaa59031a4f82 
> 
> Diff: https://reviews.apache.org/r/39928/diff/
> 
> 
> Testing
> -------
> 
> Added several new unit tests for setPermission/setUser/setGroup/removeAcl 
> cases validation.
> 
> 
> Thanks,
> 
> Hao Hao
> 
>

Reply via email to