Fang-Yu Rao created IMPALA-15341:
------------------------------------

             Summary: Preserve the fields of accessType and action in Ranger 
AuthzAuditEvent for CREATE/DROP and GRANT/REVOKE ROLE operations
                 Key: IMPALA-15341
                 URL: https://issues.apache.org/jira/browse/IMPALA-15341
             Project: IMPALA
          Issue Type: Improvement
          Components: Frontend
            Reporter: Fang-Yu Rao
            Assignee: Fang-Yu Rao


After IMPALA-14956 and IMPALA-15323, Impala produces Ranger audit events for 
GRANT/REVOKE ROLE and CREATE/DROP ROLE statements. However, as observed in 
RANGER-5594, the fields of accessType and action in Ranger AuthzAuditEvent are 
solely determined by the provided accessType.

 

Take CREATE ROLE for instance, the field of 'accessType' will be "CREATE" and 
the field of 'action' will be "create". According to my current understanding, 
this is because
 - at 
[https://github.com/apache/impala/blob/fe5217c/fe/src/main/java/org/apache/impala/authorization/ranger/RangerBufferAuditHandler.java#L132],
 when constructing the AuthzAuditEvent, we call 
RangerDefaultAuditHandler#getAuthzEvents() 
([https://github.com/apache/ranger/blob/2ad565f/agents-common/src/main/java/org/apache/ranger/plugin/audit/RangerDefaultAuditHandler.java#L102])
 that switched the values of these 2 fields 
([https://github.com/apache/ranger/blob/2ad565f/agents-common/src/main/java/org/apache/ranger/plugin/audit/RangerDefaultAuditHandler.java#L124]
 and 
[https://github.com/apache/ranger/blob/2ad565f/agents-common/src/main/java/org/apache/ranger/plugin/audit/RangerDefaultAuditHandler.java#L127])
 (https://issues.apache.org/jira/browse/RANGER-5594 was created for this), and 
then
 - at 
[https://github.com/apache/impala/blob/fe5217c/fe/src/main/java/org/apache/impala/authorization/ranger/RangerBufferAuditHandler.java#L140],
 we uppercase the field of 'accessType' in the AuthzAuditEvent using the value 
of 'accessType' in the given RangerAccessResult of the method 
createAuditEvent(RangerAccessResult result).

We observed a similar thing (or issue?) as described above in Apache Hive, but 
it looks like this was worked around by calling 
auditEvent.setAccessType(action) at 
[https://github.com/apache/ranger/blob/2ad565f/hive-agent/src/main/java/org/apache/ranger/authorization/hive/authorizer/RangerHiveAuditHandler.java#L210]
 in RangerHiveAuditHandler#createAuditEvent().

Before we have a fix for RANGER-5594, it may be good for us to adopt the 
workaround as well in Impala.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to