KAFKA-12866: Avoid root access to Zookeeper#10795
Merged
Merged
Conversation
The broker shouldn't assume create access to the chroot. There are deployement scenarios where the chroot is already created is the only znode which the broker can access.
Member
Author
|
@omkreddy can you have a look at this one? |
Contributor
omkreddy
approved these changes
May 31, 2021
Contributor
|
Good catch @soarez, and thanks for the PR! Test failed without the fix and passed with it. Thanks again. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
https://issues.apache.org/jira/browse/KAFKA-12866
The broker shouldn't assume create access to the chroot. There are
deployement scenarios where the chroot is already created is the only
znode which the broker can access.
To test this, we can use a ZK integration test, and configure zookeeper in the same way the issue is reproduced.
It should be a separate
ZooKeeperTestHarnessto avoid leaving the ACL changes made to ZK root visible to other tests.Rejected alternatives
NoAuthinKafkaZkClient.createRecursiveand assumeNoAuthas success.createChrootIfNecessary = falseinstead of the current non configurable default value of true.Committer Checklist (excluded from commit message)