roryqi opened a new issue, #13504: URL: https://github.com/apache/gravitino/issues/13504
### Version main branch ### Describe what's wrong When granting, revoking, or overriding privileges for a role, `PermissionManager` catches every `NoSuchEntityException` thrown by `store.update(...)` and converts it to `NoSuchRoleException`. However, updating a role also resolves the IDs of its securable objects. If a catalog, schema, table, function, or another metadata object cannot be resolved, that `NoSuchEntityException` is incorrectly reported as a missing role. This masks the actual failure and makes authorization and HA consistency problems difficult to diagnose. ### Error message and/or stacktrace A privilege update for an existing role can incorrectly return: ```text NoSuchRoleException: Role <role> does not exist in the metalake <metalake> ``` even when the missing entity is the target metadata object. ### How to reproduce 1. Create a role. 2. Confirm that the role can be retrieved. 3. Grant a privilege on a nonexistent or temporarily unavailable metadata object. 4. Observe that the operation reports `NoSuchRoleException` instead of `NoSuchMetadataObjectException`. ### Additional context `RoleMetaService.updateRole` resolves securable-object IDs while executing the role updater. Exceptions from that resolution propagate through `EntityStore.update` and are caught as though the role lookup itself failed. The fix should preserve `NoSuchRoleException` for an actually missing role, while mapping missing securable objects to `NoSuchMetadataObjectException` and preserving the original cause. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
