apache / apache/kyuubi

[Bug] kyuubi using --proxy-user GSS init failed when hive.metastore.token.signature not empty

Open
#5,230 8 comments 0 reactions 0 assignees View on GitHub
kind:bug priority:major
Dominant language
Scala
Stars
2.4k
Forks
1k
PR merge metrics
No merged PRs in 30d

Description

### Code of Conduct

- [X] I agree to follow this project's [Code of Conduct](https://www.apache.org/foundation/policies/conduct)

### Search before asking

- [X] I have searched in the [issues](https://github.com/apache/kyuubi/issues?q=is%3Aissue) and found no similar issues.

### Describe the bug

According to the PR https://github.com/apache/spark/pull/42760, if the hive.metastore.token.signature parameter is not empty, we may also encounter authentication failures in Kyuubi.

1. Set the configuration bellow
```

hive.metastore.token.signature
HIVE_DELEGATION_TOKEN

```
3. Start kyuubi server with `hive`
4. Connet kyuubi with proxy user ,
5. Run sql `insert into test11 values('a');`

then the user will be `hive` to execute hdfs command

### Affects Version(s)

master

### Kyuubi Server Log Output

_No response_

### Kyuubi Engine Log Output

_No response_

### Kyuubi Server Configurations

```yaml

hive.metastore.token.signature
HIVE_DELEGATION_TOKEN

```

### Kyuubi Engine Configurations

_No response_

### Additional context

_No response_

### Are you willing to submit PR?

- [X] Yes. I would be willing to submit a PR with guidance from the Kyuubi community to fix.
- [ ] No. I cannot submit a PR at this time.

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the failure with hive.metastore.token.signature set to HIVE_DELEGATION_TOKEN, a Kyuubi server started with Hive, a proxy-user connection, and the reported INSERT statement. Trace the GSS initialization and HDFS command identity, then verify that the proxy user rather than hive executes the command; no source file or test is named in the report.

Written by the indexing model from the issue text.

Assessment

Tech stack
hadoop, scala, spark
Domain
authentication, backend, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.