Skip to content

branch-4.1: [fix](fe) Use service-specific Ranger select access types #67206 - #67414

Open
github-actions[bot] wants to merge 1 commit into
branch-4.1from
auto-pick-67206-branch-4.1
Open

branch-4.1: [fix](fe) Use service-specific Ranger select access types #67206#67414
github-actions[bot] wants to merge 1 commit into
branch-4.1from
auto-pick-67206-branch-4.1

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Cherry-picked from #67206

@hello-stephen

Copy link
Copy Markdown
Contributor

Thank you for your contribution to Apache Doris.
Don't know what should be done next? See How to process your PR.

Please clearly describe your PR:

  1. What problem was fixed (it's best to include specific error reporting information). How it was fixed.
  2. Which behaviors were modified. What was the previous behavior, what is it now, why was it modified, and what possible impacts might there be.
  3. What features were added. Why was this function added?
  4. Which code was refactored and why was this part of the code refactored?
  5. Which functions were optimized and what is the difference before and after the optimization?

@hello-stephen

Copy link
Copy Markdown
Contributor

run buildall

### What problem does this PR solve?
Problem Summary:
`RangerAccessController` hardcoded the Doris uppercase `SELECT` access
type for row-filter and data-mask requests. Ranger-Hive defines this
access type as lowercase `select`. Ordinary authorization could
initially succeed, but after Ranger initialized its optimized
exact-match evaluator, row-filter and data-mask lookups using uppercase
`SELECT` skipped the lowercase policies.
This was reproduced against the unmodified
`apache/doris:all-in-one-4.1.3` image. The query was authorized but
returned unfiltered and unmasked rows:
```text
expected: [[2, NULL]]
actual: [[1, first], [2, second]]
```
This PR:
- delegates SELECT mapping to each Ranger service while retaining a
concrete uppercase default, preserving compatibility with existing
external subclasses;
- uses lowercase `select` consistently for Ranger-Hive authorization,
row filters, and data masks;
- keeps Ranger connection and process settings in the existing
`ranger-<serviceName>-security.xml` configuration;
- adds unit coverage and an end-to-end `ranger_p2` case covering
lowercase access entries, row filtering, data masking, and a warmed-up
policy evaluator.
### Validation
- `./run-fe-ut.sh --run
org.apache.doris.catalog.authorizer.ranger.hive.RangerHiveAccessControllerTest`:
2 tests passed, 0 failures/errors/skips.
- `./run-regression-test.sh --run --conf <local-ranger-conf> -d
ranger_p2 -s test_ranger_hive_lowercase_access_type`: 1 suite passed, 0
failed, 0 skipped. The FE loaded `ranger-doris_hive-security.xml`, the
catalog did not provide a Ranger URL, and both first and warmed-up
queries returned the filtered and masked result.
@yiguolei
yiguoleiforce-pushed the auto-pick-67206-branch-4.1 branch from b8c18de to 1509634CompareSeptember 5, 2026 14:03
@yiguolei

Copy link
Copy Markdown
Contributor

run buildall

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@hello-stephen@yiguolei@CalvinKirs