New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[FLINK-20267][runtime] The JaasModule didn't support symbolic links. #14171
Conversation
Thanks a lot for your contribution to the Apache Flink project. I'm the @flinkbot. I help the community Automated ChecksLast check on commit 3617fa7 (Mon Nov 23 11:50:05 UTC 2020) Warnings:
Mention the bot in a comment to re-run the automated checks. Review Progress
Please see the Pull Request Review Guide for a full explanation of the review process. The Bot is tracking the review progress through labels. Labels are applied according to the order of the review items. For consensus, approval by a Flink committer of PMC member is required Bot commandsThe @flinkbot bot supports the following commands:
|
3617fa7
to
4f0bcaf
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for the quick patch @XComp ! It LGTM. Only left a minor thought regarding the test coverage.
flink-runtime/src/main/java/org/apache/flink/runtime/security/modules/JaasModule.java
Show resolved
Hide resolved
flink-runtime/src/test/java/org/apache/flink/runtime/security/modules/JaasModuleTest.java
Outdated
Show resolved
Hide resolved
…This is fixed now. Tests were added to verify the change.
4f0bcaf
to
dd6b808
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks @KarmaGYZ I addressed your changes in dd6b808
.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for creating this PR @XComp. The change itself looks good to me. I had a question for my understanding.
Path jaasConfPath = Files.createTempFile(path, "jaas-", ".conf"); | ||
try (InputStream resourceStream = JaasModule.class.getClassLoader().getResourceAsStream(JAAS_CONF_RESOURCE_NAME)) { | ||
Files.copy(resourceStream, jaasConfPath, StandardCopyOption.REPLACE_EXISTING); | ||
} | ||
jaasConfFile = jaasConfPath.toFile(); | ||
jaasConfFile = new File(workingDir, jaasConfPath.getFileName().toString()); |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Why did you do this change here?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Is it in order to maintain the symlinks in the path?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yes, exactly. I wanted to avoid having a different path than the one the user specified in the configuration. The old implementation would have lead to the resolved path being exposed.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for the clarification @XComp. LGTM. Merging this PR once AZP has passed.
What is the purpose of the change
Directory creation was introduced to JaasModule in FLINK-19252 in case the folder does not exist, yet. Unfortunately, the used logic was not able to deal with symbolic links which caused exception in such cases.
The behavior could be reproduced through a JUnit test and was fixed in this PR. One goal of this change was to have the symbolic link resolution not being exposed outside
generateDefaultConfigFile(String)
to have the passedworkingDir
parameter match the directory path of the returnedFile
instance.Brief change log
Path.toRealPath()
logic to resolve symbolic links.File
instance uses the path containing symbolic link again.Verifying this change
This change added tests and can be verified as follows:
JaasModuleTest.testJaasModuleFilePathIfWorkingDirIsSymLink
was added.Does this pull request potentially affect one of the following parts:
@Public(Evolving)
: noDocumentation