okumin commented on code in PR #6812:
URL: https://github.com/apache/hive/pull/6812#discussion_r4185817870


##########
standalone-metastore/metastore-rest-catalog/src/main/java/org/apache/iceberg/rest/IcebergAuthorizer.java:
##########
@@ -161,4 +165,100 @@ void validateStageCreateTable(String catalogName, 
Namespace namespace, Map<Strin
       throw new IllegalStateException("Failed to check privileges 
stage-create", e);
     }
   }
+
+  /**
+   * Enforces authorization for REGISTER_TABLE. The request's {@code 
metadataLocation} must be authorized, since
+   * REGISTER_TABLE is otherwise an arbitrary-file-read primitive that returns 
any metadata file's contents to the
+   * caller. The {@code location()} embedded in that metadata file (which 
becomes the table's HMS
+   * {@code StorageDescriptor.location}) is not checked here: it is authorized 
transitively by HMS's own
+   * CREATE_TABLE authorization when {@code CatalogHandlers.registerTable} 
creates the metastore table.
+   *
+   * <p>When no {@code HiveAuthorizer} is configured, falls back to requiring 
the metadata location to be
+   * contained in the namespace's external root, since there is no policy to 
otherwise decide whether the caller
+   * may read an arbitrary location with service credentials.
+   *
+   * @param catalogName the Hive catalog name
+   * @param namespace the Iceberg namespace
+   * @param namespaceMetadata the Iceberg namespace metadata
+   * @param request the register table request
+   * @throws ForbiddenException if the location is not authorized, or not 
contained in the namespace
+   * @throws IllegalStateException if the authorization plugin fails
+   */
+  void validateRegisterTable(String catalogName, Namespace namespace, 
Map<String, String> namespaceMetadata,
+      RegisterTableRequest request) {
+    Preconditions.checkArgument(namespace.levels().length == 1, "Hive does not 
support multi-level namespaces");
+    var databaseName = namespace.level(0);
+    var commandString = "register table " + request.name();
+    checkLocationAuthorized(catalogName, databaseName, namespaceMetadata, 
request.metadataLocation(), commandString);
+  }
+
+  /**
+   * Enforces authorization for DROP_TABLE with {@code purge=true}. Purge 
deletes every file referenced by the
+   * table's current metadata using the catalog's shared, service-level {@code 
FileIO}, so the location must be
+   * authorized like any other DFS_URI access.
+   *
+   * <p>Unlike {@link #validateRegisterTable}, there is no 
namespace-containment fallback here: the structural
+   * fence in {@code HiveCatalog.dropTable} already restricts purge deletions 
to files under the table's own
+   * location regardless of whether a {@code HiveAuthorizer} is configured, so 
a deployment without one relies on
+   * that fence rather than this check.
+   *
+   * @param catalogName the Hive catalog name
+   * @param identifier the table identifier being dropped
+   * @param location the table's current location
+   * @throws ForbiddenException if the location is not authorized
+   * @throws IllegalStateException if the authorization plugin fails
+   */
+  void validateDropTablePurge(String catalogName, TableIdentifier identifier, 
String location) {
+    var authorizer = authorizerSupplier.get();
+    if (authorizer == null) {
+      LOG.info("No pre-event listener is configured for catalog {}, skipping 
drop-table-purge authorization for {}",
+          catalogName, identifier);
+      return;
+    }
+
+    var inputs = Collections.singletonList(
+        new 
HivePrivilegeObject(HivePrivilegeObject.HivePrivilegeObjectType.DFS_URI, 
location));
+    var builder = new HiveAuthzContext.Builder();
+    builder.setCommandString("drop table " + identifier.name());
+    try {
+      authorizer.checkPrivileges(HiveOperationType.DROPTABLE, inputs, 
Collections.emptyList(), builder.build());

Review Comment:
   I am checking whether DFS_URI should be validated as an input, an output, or 
both. I hit an issue where Iceberg REST -> HDFS access doesn't work. I'm 
checking why. I guess this is not a problem with HIVE-30002 but an issue on the 
master branch.
   
   ```
   hive-metastore-server-0: 2026-10-05T15:23:33,177  WARN [qtp515442419-53] 
fs.FileSystem: Failed to initialize filesystem 
hdfs://zookage/apps/hive-warehouse/test/metadata/00000-b8ac910f-489a-438d-8c67-67c748a2123e.metadata.json:
 java.lang.IllegalArgumentException: java.net.UnknownHostException: zookage
   hive-metastore-server-0: 2026-10-05T15:23:33,177  WARN [qtp515442419-53] 
util.Tasks: Retrying task after failure: sleepTimeMs=108 
java.net.UnknownHostException: zookage
   hive-metastore-server-0: java.lang.IllegalArgumentException: 
java.net.UnknownHostException: zookage
   hive-metastore-server-0:     at 
org.apache.hadoop.security.SecurityUtil.buildTokenService(SecurityUtil.java:479)
   hive-metastore-server-0:     at 
org.apache.hadoop.hdfs.NameNodeProxiesClient.createProxyWithClientProtocol(NameNodeProxiesClient.java:134)
   ```



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to