rjgoyln opened a new pull request, #11464:
URL: https://github.com/apache/ozone/pull/11464

   ## What changes were proposed in this pull request?
   
   `BaseHttpServer` never sets a host on `HttpServer2.Builder`, so `_HOST` in 
the SPNEGO principal is expanded from the first endpoint, which is the bind 
address. The S3 Gateway secret endpoint reads 
`ozone.s3g.webadmin.http-bind-host` directly for the same purpose.
   
   A bind host is not the name a keytab was issued for. The IPv6 wildcard that 
HDDS-16307 made usable gives `HTTP/[0:0:0:0:0:0:0:0]@REALM`, and an 
interface-specific bind host gives whatever it reverse-resolves to. Only the 
IPv4 wildcard works today, because `SecurityUtil.getServerPrincipal` 
special-cases the literal `0.0.0.0`; the JIRA description is inaccurate on that 
point.
   
   - `BaseHttpServer` passes the builder the host of the advertised HTTP, then 
HTTPS, address when it is not a wildcard, otherwise the canonical local 
hostname.
   - `S3GatewayWebAdminServer` expands the secret endpoint principal from the 
same host.
   
   The fallback is what Hadoop already substitutes for `0.0.0.0`, so 
deployments that leave the `*-address` properties at their `0.0.0.0:<port>` 
defaults keep their current principal; failing startup on a wildcard bind host 
instead would have broken exactly that default. OM, SCM and Recon expand 
`_HOST` for their RPC login from the advertised RPC address, so the secret 
endpoint was the only other principal built from a listener address.
   
   ## What is the link to the Apache JIRA?
   
   https://issues.apache.org/jira/browse/HDDS-16347
   
   ## How was this patch tested?
   
   Unit tests in `TestBaseHttpServer` cover the host resolution for unset, 
wildcard, hostname and IPv6-literal advertised addresses, and the SPNEGO 
filter's resulting `kerberos.principal` for bind hosts `0.0.0.0`, `::` and 
`127.0.0.1`; `TestS3GatewayHttpServers` covers the secret endpoint with an IPv6 
wildcard bind host. Without the production change the principal assertions fail 
with `HTTP/<local hostname>@`, `HTTP/[0:0:0:0:0:0:0:0]@`, `HTTP/localhost@` and 
`HTTP/::@` respectively.
   
   Generated-by: Claude Code (Fable 5.1)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to