Search in sources :

Example 1 with TokenIdentifier

use of in project flink by apache.

the class Utils method setTokensFor.

public static void setTokensFor(ContainerLaunchContext amContainer, List<Path> paths, Configuration conf) throws IOException {
    Credentials credentials = new Credentials();
    // for HDFS
    TokenCache.obtainTokensForNamenodes(credentials, paths.toArray(new Path[0]), conf);
    // for HBase
    obtainTokenForHBase(credentials, conf);
    // for user
    UserGroupInformation currUsr = UserGroupInformation.getCurrentUser();
    Collection<Token<? extends TokenIdentifier>> usrTok = currUsr.getTokens();
    for (Token<? extends TokenIdentifier> token : usrTok) {
        final Text id = new Text(token.getIdentifier());"Adding user token " + id + " with " + token);
        credentials.addToken(id, token);
    try (DataOutputBuffer dob = new DataOutputBuffer()) {
        if (LOG.isDebugEnabled()) {
            LOG.debug("Wrote tokens. Credentials buffer length: " + dob.getLength());
        ByteBuffer securityTokens = ByteBuffer.wrap(dob.getData(), 0, dob.getLength());
Also used : Path(org.apache.hadoop.fs.Path) TokenIdentifier( DataOutputBuffer( Token( Text( ByteBuffer(java.nio.ByteBuffer) Credentials( UserGroupInformation(

Example 2 with TokenIdentifier

use of in project hadoop by apache.

the class DataNode method checkReadAccess.

private void checkReadAccess(final ExtendedBlock block) throws IOException {
    // Make sure this node has registered for the block pool.
    try {
    } catch (IOException e) {
        // if it has not registered with the NN, throw an exception back.
        throw new org.apache.hadoop.ipc.RetriableException("Datanode not registered. Try again later.");
    if (isBlockTokenEnabled) {
        Set<TokenIdentifier> tokenIds = UserGroupInformation.getCurrentUser().getTokenIdentifiers();
        if (tokenIds.size() != 1) {
            throw new IOException("Can't continue since none or more than one " + "BlockTokenIdentifier is found.");
        for (TokenIdentifier tokenId : tokenIds) {
            BlockTokenIdentifier id = (BlockTokenIdentifier) tokenId;
            if (LOG.isDebugEnabled()) {
                LOG.debug("Got: " + id.toString());
            blockPoolTokenSecretManager.checkAccess(id, null, block, BlockTokenIdentifier.AccessMode.READ);
Also used : TokenIdentifier( BlockTokenIdentifier( BlockTokenIdentifier( IOException(

Example 3 with TokenIdentifier

use of in project hadoop by apache.

the class TestTokenAspect method testGetRemoteToken.

public void testGetRemoteToken() throws IOException, URISyntaxException {
    Configuration conf = new Configuration();
    DummyFs fs = spy(new DummyFs());
    Token<TokenIdentifier> token = new Token<TokenIdentifier>(new byte[0], new byte[0], DummyFs.TOKEN_KIND, new Text(""));
    fs.initialize(new URI("dummyfs://"), conf);
    // Select a token, store and renew it
    assertNotNull(Whitebox.getInternalState(fs.tokenAspect, "dtRenewer"));
    assertNotNull(Whitebox.getInternalState(fs.tokenAspect, "action"));
Also used : TokenIdentifier( Configuration(org.apache.hadoop.conf.Configuration) Token( Text( URI( Test(org.junit.Test)

Example 4 with TokenIdentifier

use of in project hadoop by apache.

the class TestTokenAspect method testCachedInitialization.

public void testCachedInitialization() throws IOException, URISyntaxException {
    Configuration conf = new Configuration();
    DummyFs fs = spy(new DummyFs());
    Token<TokenIdentifier> token = new Token<TokenIdentifier>(new byte[0], new byte[0], DummyFs.TOKEN_KIND, new Text(""));
    fs.emulateSecurityEnabled = true;
    fs.initialize(new URI("dummyfs://"), conf);
    verify(fs, times(1)).getDelegationToken(null);
    verify(fs, times(1)).setDelegationToken(token);
    // For the second iteration, the token should be cached.
    verify(fs, times(1)).getDelegationToken(null);
    verify(fs, times(1)).setDelegationToken(token);
Also used : TokenIdentifier( Configuration(org.apache.hadoop.conf.Configuration) Token( Text( URI( Test(org.junit.Test)

Example 5 with TokenIdentifier

use of in project hadoop by apache.

the class TestTokenAspect method testInitWithUGIToken.

public void testInitWithUGIToken() throws IOException, URISyntaxException {
    Configuration conf = new Configuration();
    DummyFs fs = spy(new DummyFs());
    Token<TokenIdentifier> token = new Token<TokenIdentifier>(new byte[0], new byte[0], DummyFs.TOKEN_KIND, new Text(""));
    fs.ugi.addToken(new Token<TokenIdentifier>(new byte[0], new byte[0], new Text("Other token"), new Text("")));
    assertEquals("wrong tokens in user", 2, fs.ugi.getTokens().size());
    fs.emulateSecurityEnabled = true;
    fs.initialize(new URI("dummyfs://"), conf);
    // Select a token from ugi (not from the remote host), store it but don't
    // renew it
    verify(fs, never()).getDelegationToken(anyString());
    assertNull(Whitebox.getInternalState(fs.tokenAspect, "dtRenewer"));
    assertNull(Whitebox.getInternalState(fs.tokenAspect, "action"));
Also used : TokenIdentifier( Configuration(org.apache.hadoop.conf.Configuration) Token( Text( URI( Test(org.junit.Test)


TokenIdentifier ( Token ( Text ( Credentials ( IOException ( Test (org.junit.Test)11 Configuration (org.apache.hadoop.conf.Configuration)7 URI ( ByteBuffer (java.nio.ByteBuffer)5 DataOutputBuffer ( UserGroupInformation ( HashMap (java.util.HashMap)4 AMRMTokenIdentifier ( InetSocketAddress ( TestTokenIdentifier (org.apache.hadoop.ipc.TestRpcBase.TestTokenIdentifier)3 File ( ArrayList (java.util.ArrayList)2 Collection (java.util.Collection)2 AuthenticationToken ( MockFileSystem (org.apache.hadoop.fs.FileSystemTestHelper.MockFileSystem)2