Caideyipi opened a new pull request, #17624:
URL: https://github.com/apache/iotdb/pull/17624

   ## Description
   This PR hardens LOAD TSFILE execution by adding explicit authorization 
checks and limiting user-issued load sources to
     configured allowed directories.
   
     Main changes:
   
     - Add a new system privilege LOAD_TSFILE.
         - Register it in PrivilegeType, AuthUtils, table-model privilege 
mapping, audit operation mapping, and SQL grammar.
         - Allow GRANT/REVOKE LOAD_TSFILE parsing in both tree and table 
authorization paths.
     - Enforce LOAD_TSFILE privilege for user-issued LOAD TSFILE.
         - TreeAccessCheckVisitor.visitLoadFile now checks global LOAD_TSFILE 
privilege.
         - Table-model StatementAnalyzer.visitLoadTsFile also checks missing 
LOAD_TSFILE privilege before analysis.
     - Restrict source paths for user-issued LOAD TSFILE.
         - Add load_tsfile_allowed_dirs config.
         - If unset, the allowed source directories default to IoTDB internal 
load TsFile directories.
         - Canonicalize source paths before validation to reject paths outside 
the configured allowlist, including
           traversal-style paths.
     - Preserve internal load flows.
         - Add unchecked constructors/factory methods for internal paths such 
as pipe receiver loading, active load,
           scheduler retry, and type-conversion retry paths.
     - Strengthen write-permission checks during load analysis.
         - Reuse tree write-data permission validation.
         - Ensure write permission is checked even when auto-create/verify 
schema is disabled.
     - Add tests covering:
         - LOAD TSFILE requires the new LOAD_TSFILE privilege.
         - LOAD_TSFILE can be granted/revoked by the authorization parser.
         - Source files outside load_tsfile_allowed_dirs are rejected.
         - Sub-statements preserve database information under the new path 
validation behavior.
   
   <!--
   In each section, please describe design decisions made, including:
    - Choice of algorithms
    - Behavioral aspects. What configuration values are acceptable? How are 
corner cases and error 
       conditions handled, such as when there are insufficient resources?
    - Class organization and design (how the logic is split between classes, 
inheritance, composition, 
       design patterns)
    - Method organization and design (how the logic is split between methods, 
parameters and return types)
    - Naming (class, method, API, configuration, HTTP endpoint, names of 
emitted metrics)
   -->
   
   
   <!-- It's good to describe an alternative design (or mention an alternative 
name) for every design 
   (or naming) decision point and compare the alternatives with the designs 
that you've implemented 
   (or the names you've chosen) to highlight the advantages of the chosen 
designs and names. -->
   
   <!-- If there was a discussion of the design of the feature implemented in 
this PR elsewhere 
   (e. g. a "Proposal" issue, any other issue, or a thread in the development 
mailing list), 
   link to that discussion from this PR description and explain what have 
changed in your final design 
   compared to your original proposal or the consensus version in the end of 
the discussion. 
   If something hasn't changed since the original discussion, you can omit a 
detailed discussion of 
   those aspects of the design here, perhaps apart from brief mentioning for 
the sake of readability 
   of this PR description. -->
   
   <!-- Some of the aspects mentioned above may be omitted for simple and small 
changes. -->
   
   <hr>
   
   This PR has:
   - [ ] been self-reviewed.
       - [ ] concurrent read
       - [ ] concurrent write
       - [ ] concurrent read and write 
   - [ ] added documentation for new or modified features or behaviors.
   - [ ] added Javadocs for most classes and all non-trivial methods. 
   - [ ] added or updated version, __license__, or notice information
   - [ ] added comments explaining the "why" and the intent of the code 
wherever would not be obvious 
     for an unfamiliar reader.
   - [ ] added unit tests or modified existing tests to cover new code paths, 
ensuring the threshold 
     for code coverage.
   - [ ] added integration tests.
   - [ ] been tested in a test IoTDB cluster.
   
   <!-- Check the items by putting "x" in the brackets for the done things. Not 
all of these items 
   apply to every PR. Remove the items which are not done or not relevant to 
the PR. None of the items 
   from the checklist above are strictly necessary, but it would be very 
helpful if you at least 
   self-review the PR. -->
   
   <hr>
   
   ##### Key changed/added classes (or packages if there are too many classes) 
in this PR
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to