Prevent cluster internal ClusterState.Custom impls to leak to a client#26232
Merged
s1monw merged 2 commits intoelastic:masterfrom Aug 16, 2017
Merged
Prevent cluster internal ClusterState.Custom impls to leak to a client#26232s1monw merged 2 commits intoelastic:masterfrom
ClusterState.Custom impls to leak to a client#26232s1monw merged 2 commits intoelastic:masterfrom
Conversation
Today a `ClusterState.Custom` can be fetched by a transport client and leaks to the user even if the classes are private etc since the serialized bytes can be reconstructed. This change adds an option to customs to mark them as private such that our clusterstate action will never leak it.
jasontedor
approved these changes
Aug 16, 2017
| assertTrue(state.customs().containsKey("test")); | ||
| } | ||
|
|
||
| private static class TestCustom extends AbstractNamedDiffable<ClusterState.Custom> implements ClusterState.Custom { |
Member
There was a problem hiding this comment.
Extra space:
TestCustom extends
^^
s1monw
added a commit
that referenced
this pull request
Aug 16, 2017
…ent (#26232) Today a `ClusterState.Custom` can be fetched by a transport client and leaks to the user even if the classes are private etc since the serialized bytes can be reconstructed. This change adds an option to customs to mark them as private such that our clusterstate action will never leak it.
s1monw
added a commit
that referenced
this pull request
Aug 16, 2017
…ent (#26232) Today a `ClusterState.Custom` can be fetched by a transport client and leaks to the user even if the classes are private etc since the serialized bytes can be reconstructed. This change adds an option to customs to mark them as private such that our clusterstate action will never leak it.
jasontedor
added a commit
to glefloch/elasticsearch
that referenced
this pull request
Aug 16, 2017
* master: (458 commits) Prevent cluster internal `ClusterState.Custom` impls to leak to a client (elastic#26232) Add packaging test for systemd runtime directive [TEST] Reenable RareClusterStateIt#testDeleteCreateInOneBulk Serialize and expose timeout of acknowledged requests in REST layer (elastic#26189) (refactor) some opportunities to use diamond operator (elastic#25585) [DOCS] Clarified readme for testing a single page Settings: Add keystore.seed auto generated secure setting (elastic#26149) Update version information (elastic#25226) "result" : created -> "result" : "created" (elastic#25446) Set RuntimeDirectory (elastic#23526) Drop upgrade from full cluster restart tests (elastic#26224) Further improve docs for requests_per_second Docs disambiguate reindex's requests_per_second (elastic#26185) [DOCS] Cleanup link for ec2 discovery (elastic#26222) Fix document field equals and hash code test Use holder pattern for lazy deprecation loggers Settings: Add keystore creation to add commands (elastic#26126) Docs: Cleanup docs for ec2 discovery (elastic#26065) Fix NPE when `values` is omitted on percentile_ranks agg (elastic#26046) Several internal improvements to internal test cluster infra (elastic#26214) ...
imotov
reviewed
Aug 16, 2017
Contributor
imotov
left a comment
There was a problem hiding this comment.
I think we should extend this functionality for MetaData.Custom as well, otherwise they will start to diverge and will be confusing.
Collaborator
|
Pinging @elastic/es-distributed |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Today a
ClusterState.Customcan be fetched by a transport client andleaks to the user even if the classes are private etc since the serialized
bytes can be reconstructed. This change adds an option to customs to mark
them as private such that our clusterstate action will never leak it.