apache / apache/druid

Race between file reader and writer in FileSessionCredentialsProvider

Open
#6,665 5 comments 0 reactions 0 assignees View on GitHub
Bug stale
Dominant language
Java
Stars
14.1k
Forks
3.8k
Avg merge
2d 31m
Merged PRs (30d)
209

Description

A race is possible between the file updater and the Druid process reading the file. It could be enforced only with mandatory file locking, but file locking is advisory by default in Linux.

If Druid targets only Linux (is it?) probably some Linux-specific code could be added to configure mandatory file locking for `sessionCredentialsFile`.

Contributor guide

Open the contributing guide

Research direction

Start with FileSessionCredentialsProvider and trace how the sessionCredentialsFile is updated and read. Determine whether Druid supports Linux-only file-locking behavior, then define completion as preventing readers from observing a partially updated credentials file and covering the race with an appropriate test.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, linux
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.