Josh Elser created ACCUMULO-3831:
------------------------------------

             Summary: Race condition in automatic kerberos user creation 
results in error message
                 Key: ACCUMULO-3831
                 URL: https://issues.apache.org/jira/browse/ACCUMULO-3831
             Project: Accumulo
          Issue Type: Bug
          Components: tserver
         Environment: Kerberos
            Reporter: Josh Elser
            Assignee: Josh Elser
             Fix For: 1.8.0, 1.7.1


{noformat}
User already exists in ZooKeeper
        org.apache.zookeeper.KeeperException$NodeExistsException: 
KeeperErrorCode = NodeExists for 
/accumulo/cdb82c8b-3519-4139-843f-3c0aadc6ba01/users/aHJ0XzU=
                at 
org.apache.zookeeper.KeeperException.create(KeeperException.java:119)
                at 
org.apache.zookeeper.KeeperException.create(KeeperException.java:51)
                at org.apache.zookeeper.ZooKeeper.create(ZooKeeper.java:783)
                at 
org.apache.accumulo.fate.zookeeper.ZooUtil.putData(ZooUtil.java:288)
                at 
org.apache.accumulo.fate.zookeeper.ZooUtil.putPrivatePersistentData(ZooUtil.java:420)
                at 
org.apache.accumulo.fate.zookeeper.ZooReaderWriter.putPrivatePersistentData(ZooReaderWriter.java:79)
                at 
org.apache.accumulo.server.security.handler.KerberosAuthenticator.createUserNodeInZk(KerberosAuthenticator.java:87)
                at 
org.apache.accumulo.server.security.handler.KerberosAuthenticator.createUser(KerberosAuthenticator.java:158)
                at 
org.apache.accumulo.server.security.SecurityOperation._createUser(SecurityOperation.java:627)
                at 
org.apache.accumulo.server.security.SecurityOperation.createUser(SecurityOperation.java:614)
                at 
org.apache.accumulo.server.security.AuditedSecurityOperation.createUser(AuditedSecurityOperation.java:228)
                at 
org.apache.accumulo.server.client.ClientServiceHandler.createLocalUser(ClientServiceHandler.java:178)
                at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
                at 
sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57)
                at 
sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
                at java.lang.reflect.Method.invoke(Method.java:606)
                at 
org.apache.accumulo.core.trace.wrappers.RpcServerInvocationHandler.invoke(RpcServerInvocationHandler.java:46)
                at 
org.apache.accumulo.server.rpc.RpcWrapper$1.invoke(RpcWrapper.java:47)
                at com.sun.proxy.$Proxy20.createLocalUser(Unknown Source)
                at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
                at 
sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57)
                at 
sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
                at java.lang.reflect.Method.invoke(Method.java:606)
                at 
org.apache.accumulo.server.rpc.TCredentialsUpdatingInvocationHandler.invokeMethod(TCredentialsUpdatingInvocationHandler.java:154)
                at 
org.apache.accumulo.server.rpc.TCredentialsUpdatingInvocationHandler.invoke(TCredentialsUpdatingInvocationHandler.java:58)
                at com.sun.proxy.$Proxy20.createLocalUser(Unknown Source)
                at 
org.apache.accumulo.core.client.impl.thrift.ClientService$Processor$createLocalUser.getResult(ClientService.java:2469)
                at 
org.apache.accumulo.core.client.impl.thrift.ClientService$Processor$createLocalUser.getResult(ClientService.java:2453)
                at 
org.apache.thrift.ProcessFunction.process(ProcessFunction.java:39)
                at 
org.apache.thrift.TBaseProcessor.process(TBaseProcessor.java:39)
                at 
org.apache.accumulo.server.rpc.UGIAssumingProcessor.process(UGIAssumingProcessor.java:102)
                at 
org.apache.accumulo.server.rpc.TimedProcessor.process(TimedProcessor.java:63)
                at 
org.apache.thrift.server.TThreadPoolServer$WorkerProcess.run(TThreadPoolServer.java:225)
                at 
java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)
                at 
java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)
                at 
org.apache.accumulo.fate.util.LoggingRunnable.run(LoggingRunnable.java:35)
                at java.lang.Thread.run(Thread.java:745)
{noformat}

Saw this in the monitor. A couple of concerns

* The same user coming in twice in parallel could result in two servers hitting 
the same codepath for the same user. This is expected (don't create an error 
message).
* Need to make sure that the above case doesn't result in one user seeing an 
error.

The above stacktrace can only happen when a user first accesses the system. 
After that, it's just existence checks on ZK which are idempotent.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to