YARN-11392 Audit Log missing in ClientRMService (#5250). Contributed by Beibei Zhao.

Signed-off-by: Chris Nauroth <cnauroth@apache.org>
This commit is contained in:
curie71 2022-12-28 07:58:53 +08:00 committed by GitHub
parent d25c1be517
commit 9668a85d40
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 11 additions and 37 deletions

View File

@ -405,22 +405,11 @@ public GetApplicationReportResponse getApplicationReport(
throw new ApplicationNotFoundException("Invalid application id: null");
}
UserGroupInformation callerUGI;
try {
callerUGI = UserGroupInformation.getCurrentUser();
} catch (IOException ie) {
LOG.info("Error getting UGI ", ie);
throw RPCUtil.getRemoteException(ie);
}
UserGroupInformation callerUGI = getCallerUgi(applicationId,
AuditConstants.GET_APP_REPORT);
RMApp application = this.rmContext.getRMApps().get(applicationId);
if (application == null) {
// If the RM doesn't have the application, throw
// ApplicationNotFoundException and let client to handle.
throw new ApplicationNotFoundException("Application with id '"
+ applicationId + "' doesn't exist in RM. Please check "
+ "that the job submission was successful.");
}
RMApp application = verifyUserAccessForRMApp(applicationId, callerUGI,
AuditConstants.GET_APP_REPORT, ApplicationAccessType.VIEW_APP, false);
boolean allowAccess = checkAccess(callerUGI, application.getUser(),
ApplicationAccessType.VIEW_APP, application);
@ -880,13 +869,8 @@ public GetClusterMetricsResponse getClusterMetrics(
@Override
public GetApplicationsResponse getApplications(GetApplicationsRequest request)
throws YarnException {
UserGroupInformation callerUGI;
try {
callerUGI = UserGroupInformation.getCurrentUser();
} catch (IOException ie) {
LOG.info("Error getting UGI ", ie);
throw RPCUtil.getRemoteException(ie);
}
UserGroupInformation callerUGI = getCallerUgi(null,
AuditConstants.GET_APPLICATIONS_REQUEST);
Set<String> applicationTypes = getLowerCasedAppTypes(request);
EnumSet<YarnApplicationState> applicationStates =
@ -1048,13 +1032,8 @@ public GetClusterNodesResponse getClusterNodes(GetClusterNodesRequest request)
@Override
public GetQueueInfoResponse getQueueInfo(GetQueueInfoRequest request)
throws YarnException {
UserGroupInformation callerUGI;
try {
callerUGI = UserGroupInformation.getCurrentUser();
} catch (IOException ie) {
LOG.info("Error getting UGI ", ie);
throw RPCUtil.getRemoteException(ie);
}
UserGroupInformation callerUGI = getCallerUgi(null,
AuditConstants.GET_QUEUE_INFO_REQUEST);
GetQueueInfoResponse response =
recordFactory.newRecordInstance(GetQueueInfoResponse.class);
@ -1720,16 +1699,10 @@ public SignalContainerResponse signalToContainer(
SignalContainerRequest request) throws YarnException, IOException {
ContainerId containerId = request.getContainerId();
UserGroupInformation callerUGI;
try {
callerUGI = UserGroupInformation.getCurrentUser();
} catch (IOException ie) {
LOG.info("Error getting UGI ", ie);
throw RPCUtil.getRemoteException(ie);
}
ApplicationId applicationId = containerId.getApplicationAttemptId().
getApplicationId();
UserGroupInformation callerUGI = getCallerUgi(applicationId,
AuditConstants.SIGNAL_CONTAINER);
RMApp application = this.rmContext.getRMApps().get(applicationId);
if (application == null) {
RMAuditLogger.logFailure(callerUGI.getUserName(),

View File

@ -57,6 +57,7 @@ public static class AuditConstants {
public static final String GET_APP_PRIORITY = "Get Application Priority";
public static final String GET_APP_QUEUE = "Get Application Queue";
public static final String GET_APP_ATTEMPTS = "Get Application Attempts";
public static final String GET_APP_REPORT = "Get Application Report";
public static final String GET_APP_ATTEMPT_REPORT
= "Get Application Attempt Report";
public static final String GET_CONTAINERS = "Get Containers";