Skip to content

[fix](fe) Restrict frontend config updates to root in cloud mode - #66478

Open
gavinchou wants to merge 4 commits into
apache:masterfrom
gavinchou:gavin-fix-cloud-root-admin-set-config
Open

[fix](fe) Restrict frontend config updates to root in cloud mode#66478
gavinchou wants to merge 4 commits into
apache:masterfrom
gavinchou:gavin-fix-cloud-root-admin-set-config

Conversation

@gavinchou

Copy link
Copy Markdown
Contributor

What problem does this PR solve?

Issue Number: None

Related PR: None

Problem Summary:

The Nereids migration of ADMIN SET FRONTEND CONFIG retained the global ADMIN privilege check but omitted the cloud-mode root-only restriction from the legacy DDL executor. This PR restores that restriction: in cloud mode, an ordinary admin is rejected and root remains allowed. Non-cloud behavior is unchanged.

Release note

Restrict ADMIN SET FRONTEND CONFIG to root in cloud mode.

Check List (For Author)

  • Test

    • Regression test
    • Unit Test
      • AdminSetFrontendConfigCommandTest#testCloudAdminCannotSetFrontendConfig
      • FE build with build.sh --fe
    • Manual test (add detailed scripts or steps below)
    • No need to test or manual test. Explain why:
      • This is a refactor/code format and no logic has been changed.
      • Previous test can cover this change.
      • No code files have been changed.
      • Other reason
  • Behavior changed:

    • No.
    • Yes. In cloud mode, non-root admin users can no longer update FE runtime configuration.
  • Does this need documentation?

    • No.
    • Yes.

Check List (For Reviewer who merge this PR)

  • Confirm the release note
  • Confirm test cases
  • Confirm document
  • Add branch pick label

Restore the cloud-mode root-only authorization check for ADMIN SET FRONTEND CONFIG that existed in the legacy DDL executor. The Nereids command retained the global ADMIN privilege check but omitted the root restriction.

Add a regression test that verifies an ordinary admin is rejected while root remains allowed in cloud mode.
@hello-stephen

Copy link
Copy Markdown
Contributor

Thank you for your contribution to Apache Doris.
Don't know what should be done next? See How to process your PR.

Please clearly describe your PR:

  1. What problem was fixed (it's best to include specific error reporting information). How it was fixed.
  2. Which behaviors were modified. What was the previous behavior, what is it now, why was it modified, and what possible impacts might there be.
  3. What features were added. Why was this function added?
  4. Which code was refactored and why was this part of the code refactored?
  5. Which functions were optimized and what is the difference before and after the optimization?

@gavinchou

Copy link
Copy Markdown
Contributor Author

run buildall

@gavinchou

Copy link
Copy Markdown
Contributor Author

run buildall

@hello-stephen

Copy link
Copy Markdown
Contributor

FE UT Coverage Report

Increment line coverage 0.00% (0/3) 🎉
Increment coverage report
Complete coverage report

@gavinchou

Copy link
Copy Markdown
Contributor Author

run buildall

@hello-stephen

Copy link
Copy Markdown
Contributor
TPC-H: Total hot run time: 29058 ms
machine: 'aliyun_ecs.c7a.8xlarge_32C64G'
scripts: https://github.com/apache/doris/tree/master/tools/tpch-tools
Tpch sf100 test result on commit 3c8219a420c9c201cc24360266238cbef0d8f3c0, data reload: false

------ Round 1 ----------------------------------
============================================
q1	17699	4131	4059	4059
q2	2006	329	200	200
q3	10354	1444	802	802
q4	4681	472	340	340
q5	7519	839	560	560
q6	185	177	141	141
q7	764	801	601	601
q8	9323	1567	1551	1551
q9	5329	4087	4138	4087
q10	6797	1637	1363	1363
q11	507	365	334	334
q12	750	576	454	454
q13	18077	3315	2738	2738
q14	263	259	243	243
q15	q16	737	728	653	653
q17	990	1160	955	955
q18	6510	5639	5594	5594
q19	1339	1312	1048	1048
q20	777	657	607	607
q21	6011	2641	2420	2420
q22	439	360	308	308
Total cold run time: 101057 ms
Total hot run time: 29058 ms

----- Round 2, with runtime_filter_mode=off -----
============================================
q1	4323	4339	4411	4339
q2	287	330	209	209
q3	4592	5356	4387	4387
q4	2192	2280	1417	1417
q5	4278	4163	4149	4149
q6	226	176	140	140
q7	1810	1593	1795	1593
q8	2675	2205	2141	2141
q9	7505	7557	7241	7241
q10	4336	4339	3911	3911
q11	580	402	364	364
q12	717	741	530	530
q13	3196	3526	2948	2948
q14	318	313	286	286
q15	q16	696	743	630	630
q17	1396	1340	1330	1330
q18	12121	11032	11861	11032
q19	1236	1152	1171	1152
q20	2241	2225	1955	1955
q21	5875	4992	4924	4924
q22	558	482	422	422
Total cold run time: 61158 ms
Total hot run time: 55100 ms

@hello-stephen

Copy link
Copy Markdown
Contributor
TPC-DS: Total hot run time: 166632 ms
machine: 'aliyun_ecs.c7a.8xlarge_32C64G'
scripts: https://github.com/apache/doris/tree/master/tools/tpcds-tools
TPC-DS sf100 test result on commit 3c8219a420c9c201cc24360266238cbef0d8f3c0, data reload: false

query5	4305	597	455	455
query6	465	211	203	203
query7	4858	599	336	336
query8	327	166	150	150
query9	8773	4055	4097	4055
query10	468	362	324	324
query11	5758	2179	1938	1938
query12	153	99	100	99
query13	1243	582	424	424
query14	6103	4337	3988	3988
query14_1	3824	3792	3804	3792
query15	198	194	175	175
query16	975	492	497	492
query17	931	675	557	557
query18	2449	473	337	337
query19	204	189	150	150
query20	103	100	101	100
query21	226	158	131	131
query22	13099	13018	12916	12916
query23	15850	15118	14545	14545
query23_1	14747	14759	14831	14759
query24	7663	1701	1223	1223
query24_1	1264	1239	1255	1239
query25	540	452	376	376
query26	1316	348	217	217
query27	2622	607	400	400
query28	4555	2055	2035	2035
query29	1056	600	519	519
query30	341	262	226	226
query31	1185	1130	1062	1062
query32	114	65	63	63
query33	523	321	252	252
query34	1200	1138	650	650
query35	736	753	642	642
query36	787	774	697	697
query37	157	112	103	103
query38	1841	1785	1673	1673
query39	838	821	789	789
query39_1	803	802	801	801
query40	257	166	154	154
query41	71	69	69	69
query42	97	97	96	96
query43	319	320	293	293
query44	1475	785	781	781
query45	192	181	169	169
query46	1060	1142	716	716
query47	1559	1540	1464	1464
query48	425	416	308	308
query49	588	414	311	311
query50	1084	439	341	341
query51	10362	10452	10374	10374
query52	91	93	77	77
query53	263	283	200	200
query54	301	250	251	250
query55	77	78	71	71
query56	303	318	302	302
query57	1008	1013	931	931
query58	302	274	265	265
query59	1622	1627	1384	1384
query60	328	290	269	269
query61	178	181	175	175
query62	400	331	273	273
query63	242	212	203	203
query64	3039	1162	861	861
query65	3881	3802	3792	3792
query66	1834	461	355	355
query67	28180	28208	27932	27932
query68	3280	1550	1045	1045
query69	410	305	272	272
query70	889	799	775	775
query71	365	343	316	316
query72	3064	2678	2318	2318
query73	804	797	449	449
query74	4636	4500	4279	4279
query75	2370	2343	1985	1985
query76	2404	1154	744	744
query77	337	368	273	273
query78	11264	11155	10558	10558
query79	1364	1137	775	775
query80	1290	533	464	464
query81	526	328	282	282
query82	625	174	138	138
query83	404	327	299	299
query84	330	162	130	130
query85	1000	611	539	539
query86	404	240	223	223
query87	2002	1977	1850	1850
query88	3774	2852	2791	2791
query89	398	337	279	279
query90	1907	207	208	207
query91	209	190	165	165
query92	63	61	61	61
query93	1631	1660	1075	1075
query94	711	374	291	291
query95	797	602	483	483
query96	1056	782	341	341
query97	2467	2443	2347	2347
query98	199	193	180	180
query99	744	726	607	607
Total cold run time: 254081 ms
Total hot run time: 166632 ms

@hello-stephen

Copy link
Copy Markdown
Contributor
ClickBench: Total hot run time: 23.84 s
machine: 'aliyun_ecs.c7a.8xlarge_32C64G'
scripts: https://github.com/apache/doris/tree/master/tools/clickbench-tools
ClickBench test result on commit 3c8219a420c9c201cc24360266238cbef0d8f3c0, data reload: false

query1	0.00	0.00	0.01
query2	0.09	0.04	0.05
query3	0.26	0.13	0.13
query4	1.61	0.14	0.14
query5	0.26	0.22	0.22
query6	1.16	0.81	0.81
query7	0.03	0.01	0.00
query8	0.06	0.04	0.04
query9	0.37	0.32	0.31
query10	0.55	0.55	0.58
query11	0.19	0.14	0.14
query12	0.17	0.15	0.14
query13	0.46	0.44	0.47
query14	1.02	1.00	0.99
query15	0.63	0.58	0.58
query16	0.33	0.34	0.31
query17	1.10	1.14	1.08
query18	0.21	0.20	0.20
query19	2.02	1.90	2.02
query20	0.01	0.02	0.01
query21	15.42	0.19	0.14
query22	4.95	0.05	0.05
query23	16.14	0.31	0.12
query24	2.90	0.43	0.31
query25	0.11	0.04	0.04
query26	0.72	0.20	0.16
query27	0.04	0.04	0.04
query28	3.49	0.75	0.36
query29	12.50	4.09	3.24
query30	0.27	0.16	0.15
query31	2.77	0.57	0.32
query32	3.23	0.58	0.49
query33	3.22	3.13	3.22
query34	15.82	3.95	3.25
query35	3.23	3.22	3.22
query36	0.55	0.43	0.45
query37	0.09	0.06	0.06
query38	0.05	0.04	0.04
query39	0.04	0.04	0.04
query40	0.17	0.15	0.14
query41	0.09	0.04	0.03
query42	0.04	0.02	0.03
query43	0.05	0.04	0.03
Total cold run time: 96.42 s
Total hot run time: 23.84 s

@hello-stephen

Copy link
Copy Markdown
Contributor

FE Regression Coverage Report

Increment line coverage 33.33% (1/3) 🎉
Increment coverage report
Complete coverage report

1 similar comment
@hello-stephen

Copy link
Copy Markdown
Contributor

FE Regression Coverage Report

Increment line coverage 33.33% (1/3) 🎉
Increment coverage report
Complete coverage report

@gavinchou

Copy link
Copy Markdown
Contributor Author

run buildall

@hello-stephen

Copy link
Copy Markdown
Contributor
TPC-H: Total hot run time: 28781 ms
machine: 'aliyun_ecs.c7a.8xlarge_32C64G'
scripts: https://github.com/apache/doris/tree/master/tools/tpch-tools
Tpch sf100 test result on commit 26d1faa5e1d3184b1d491e674e87b3d342b0bb92, data reload: false

------ Round 1 ----------------------------------
============================================
q1	17636	3912	3923	3912
q2	2059	322	202	202
q3	10285	1398	797	797
q4	4683	465	344	344
q5	7534	840	554	554
q6	176	169	134	134
q7	758	813	595	595
q8	9322	1648	1604	1604
q9	5549	4054	4023	4023
q10	6735	1619	1350	1350
q11	518	353	317	317
q12	724	564	457	457
q13	18105	3627	2723	2723
q14	257	271	244	244
q15	q16	725	726	661	661
q17	911	994	901	901
q18	6501	5601	5578	5578
q19	1154	1301	1018	1018
q20	786	704	574	574
q21	5567	2547	2496	2496
q22	428	354	297	297
Total cold run time: 100413 ms
Total hot run time: 28781 ms

----- Round 2, with runtime_filter_mode=off -----
============================================
q1	4278	4207	4185	4185
q2	273	320	207	207
q3	4502	4902	4375	4375
q4	2182	2245	1432	1432
q5	4220	4085	4123	4085
q6	229	176	129	129
q7	1690	1559	1407	1407
q8	2603	2218	2077	2077
q9	7289	7221	7259	7221
q10	4313	4251	3843	3843
q11	556	402	369	369
q12	711	714	501	501
q13	3171	3447	2997	2997
q14	296	294	277	277
q15	q16	687	718	653	653
q17	1328	1277	1325	1277
q18	12218	11072	11813	11072
q19	1171	1141	1155	1141
q20	2262	2247	1937	1937
q21	5642	4771	4866	4771
q22	510	451	408	408
Total cold run time: 60131 ms
Total hot run time: 54364 ms

@hello-stephen

Copy link
Copy Markdown
Contributor
TPC-DS: Total hot run time: 166189 ms
machine: 'aliyun_ecs.c7a.8xlarge_32C64G'
scripts: https://github.com/apache/doris/tree/master/tools/tpcds-tools
TPC-DS sf100 test result on commit 26d1faa5e1d3184b1d491e674e87b3d342b0bb92, data reload: false

query5	4359	597	461	461
query6	462	222	204	204
query7	4845	579	348	348
query8	319	158	144	144
query9	8784	3997	4010	3997
query10	501	359	309	309
query11	5899	2180	1999	1999
query12	150	101	104	101
query13	1245	535	389	389
query14	6081	4226	3915	3915
query14_1	3790	3754	3752	3752
query15	197	196	181	181
query16	1033	506	450	450
query17	915	709	566	566
query18	2435	471	342	342
query19	211	181	150	150
query20	101	99	103	99
query21	229	154	136	136
query22	12949	12992	12846	12846
query23	15786	15043	14441	14441
query23_1	14697	14645	14636	14636
query24	7572	1709	1247	1247
query24_1	1283	1260	1252	1252
query25	573	458	381	381
query26	1335	371	212	212
query27	2612	630	391	391
query28	4553	2059	2009	2009
query29	1113	625	503	503
query30	346	263	224	224
query31	1174	1116	1062	1062
query32	116	66	65	65
query33	558	317	255	255
query34	1167	1151	641	641
query35	737	751	649	649
query36	757	800	675	675
query37	164	107	94	94
query38	1935	1800	1698	1698
query39	833	820	793	793
query39_1	786	794	791	791
query40	256	171	151	151
query41	72	69	73	69
query42	104	95	95	95
query43	315	327	284	284
query44	1428	778	751	751
query45	190	180	171	171
query46	1104	1193	745	745
query47	1594	1569	1500	1500
query48	396	412	313	313
query49	599	413	304	304
query50	1073	432	346	346
query51	10645	10359	10606	10359
query52	91	98	85	85
query53	263	289	201	201
query54	321	264	239	239
query55	77	76	69	69
query56	322	323	299	299
query57	1027	1037	952	952
query58	306	271	263	263
query59	1509	1568	1351	1351
query60	346	312	253	253
query61	158	150	142	142
query62	406	319	267	267
query63	233	193	199	193
query64	2870	1057	881	881
query65	3877	3833	3801	3801
query66	1877	483	360	360
query67	28212	28170	28009	28009
query68	3241	1597	986	986
query69	414	291	256	256
query70	885	776	804	776
query71	359	339	303	303
query72	3021	2649	2298	2298
query73	849	746	435	435
query74	4623	4495	4299	4299
query75	2362	2332	1992	1992
query76	2353	1132	745	745
query77	336	362	264	264
query78	11156	11181	10554	10554
query79	1395	1142	708	708
query80	1282	566	482	482
query81	569	329	281	281
query82	665	169	136	136
query83	372	331	302	302
query84	324	156	132	132
query85	979	606	549	549
query86	421	235	229	229
query87	1970	1961	1841	1841
query88	3723	2838	2792	2792
query89	411	312	277	277
query90	1889	203	193	193
query91	202	196	164	164
query92	65	65	55	55
query93	1736	1509	933	933
query94	724	355	319	319
query95	791	501	480	480
query96	1076	780	370	370
query97	2470	2470	2335	2335
query98	196	188	186	186
query99	742	743	620	620
Total cold run time: 254002 ms
Total hot run time: 166189 ms

@hello-stephen

Copy link
Copy Markdown
Contributor
ClickBench: Total hot run time: 23.94 s
machine: 'aliyun_ecs.c7a.8xlarge_32C64G'
scripts: https://github.com/apache/doris/tree/master/tools/clickbench-tools
ClickBench test result on commit 26d1faa5e1d3184b1d491e674e87b3d342b0bb92, data reload: false

query1	0.00	0.00	0.01
query2	0.09	0.05	0.04
query3	0.26	0.14	0.14
query4	1.61	0.14	0.13
query5	0.24	0.23	0.22
query6	1.16	0.79	0.85
query7	0.04	0.01	0.00
query8	0.06	0.04	0.04
query9	0.39	0.31	0.31
query10	0.55	0.53	0.56
query11	0.19	0.14	0.14
query12	0.17	0.14	0.14
query13	0.46	0.46	0.47
query14	0.99	1.00	1.00
query15	0.61	0.59	0.57
query16	0.31	0.32	0.32
query17	1.10	1.07	1.10
query18	0.21	0.20	0.20
query19	2.08	1.95	1.94
query20	0.02	0.02	0.01
query21	15.44	0.22	0.14
query22	4.87	0.05	0.06
query23	16.13	0.30	0.13
query24	2.94	0.43	0.34
query25	0.11	0.06	0.04
query26	0.73	0.22	0.16
query27	0.05	0.03	0.04
query28	3.44	0.72	0.35
query29	12.55	3.99	3.18
query30	0.27	0.16	0.18
query31	2.76	0.54	0.32
query32	3.22	0.60	0.48
query33	3.25	3.20	3.25
query34	15.69	4.04	3.29
query35	3.23	3.24	3.27
query36	0.54	0.42	0.41
query37	0.10	0.07	0.07
query38	0.05	0.04	0.04
query39	0.04	0.03	0.03
query40	0.18	0.14	0.14
query41	0.08	0.03	0.03
query42	0.04	0.03	0.03
query43	0.04	0.03	0.04
Total cold run time: 96.29 s
Total hot run time: 23.94 s

@hello-stephen

Copy link
Copy Markdown
Contributor

FE UT Coverage Report

Increment line coverage 100.00% (3/3) 🎉
Increment coverage report
Complete coverage report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants