From 86a2ac94b1c46891bfcfa4d9dffcaa636596c271 Mon Sep 17 00:00:00 2001 From: Miklos Szegedi Date: Wed, 17 Jan 2018 12:56:10 -0800 Subject: [PATCH] YARN-7758. Add an additional check to the validity of container and application ids passed to container-executor. Contributed by Yufei Gu. --- .../main/native/container-executor/impl/container-executor.c | 3 ++- .../src/main/native/container-executor/impl/main.c | 5 +++++ .../src/main/native/container-executor/impl/util.h | 3 ++- 3 files changed, 9 insertions(+), 2 deletions(-) diff --git a/hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-nodemanager/src/main/native/container-executor/impl/container-executor.c b/hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-nodemanager/src/main/native/container-executor/impl/container-executor.c index 1dd9a1a48d8..c1a42ca7a50 100644 --- a/hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-nodemanager/src/main/native/container-executor/impl/container-executor.c +++ b/hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-nodemanager/src/main/native/container-executor/impl/container-executor.c @@ -1068,7 +1068,8 @@ int create_log_dirs(const char *app_id, char * const * log_dirs) { for(log_root=log_dirs; *log_root != NULL; ++log_root) { char *app_log_dir = get_app_log_directory(*log_root, app_id); int result = check_nm_local_dir(nm_uid, *log_root); - if (result != 0) { + if (result != 0 && app_log_dir != NULL) { + free(app_log_dir); app_log_dir = NULL; } if (app_log_dir == NULL) { diff --git a/hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-nodemanager/src/main/native/container-executor/impl/main.c b/hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-nodemanager/src/main/native/container-executor/impl/main.c index 7a4a9d95215..a1b5ebc3422 100644 --- a/hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-nodemanager/src/main/native/container-executor/impl/main.c +++ b/hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-nodemanager/src/main/native/container-executor/impl/main.c @@ -21,6 +21,7 @@ #include "container-executor.h" #include "util.h" #include "get_executable.h" +#include "utils/string-utils.h" #include #include @@ -351,6 +352,10 @@ static int validate_run_as_user_commands(int argc, char **argv, int *operation) } cmd_input.app_id = argv[optind++]; cmd_input.container_id = argv[optind++]; + if (!validate_container_id(cmd_input.container_id)) { + fprintf(ERRORFILE, "Invalid container id %s\n", cmd_input.container_id); + return INVALID_CONTAINER_ID; + } cmd_input.cred_file = argv[optind++]; cmd_input.local_dirs = argv[optind++];// good local dirs as a comma separated list cmd_input.log_dirs = argv[optind++];// good log dirs as a comma separated list diff --git a/hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-nodemanager/src/main/native/container-executor/impl/util.h b/hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-nodemanager/src/main/native/container-executor/impl/util.h index c4979f692eb..c4518d3d42e 100644 --- a/hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-nodemanager/src/main/native/container-executor/impl/util.h +++ b/hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-nodemanager/src/main/native/container-executor/impl/util.h @@ -67,7 +67,8 @@ enum errorcodes { ERROR_SANITIZING_DOCKER_COMMAND = 39, DOCKER_IMAGE_INVALID = 40, // DOCKER_CONTAINER_NAME_INVALID = 41, (NOT USED) - ERROR_COMPILING_REGEX = 42 + ERROR_COMPILING_REGEX = 42, + INVALID_CONTAINER_ID = 43 };