Skip to content

branch-4.1: [fix](fe) Use service-specific Ranger select access types #67206 - #67414

Open
github-actions[bot] wants to merge 1 commit into
branch-4.1from
auto-pick-67206-branch-4.1
Open

branch-4.1: [fix](fe) Use service-specific Ranger select access types #67206#67414
github-actions[bot] wants to merge 1 commit into
branch-4.1from
auto-pick-67206-branch-4.1

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Cherry-picked from #67206

### What problem does this PR solve?



Problem Summary:

`RangerAccessController` hardcoded the Doris uppercase `SELECT` access
type for row-filter and data-mask requests. Ranger-Hive defines this
access type as lowercase `select`. Ordinary authorization could
initially succeed, but after Ranger initialized its optimized
exact-match evaluator, row-filter and data-mask lookups using uppercase
`SELECT` skipped the lowercase policies.

This was reproduced against the unmodified
`apache/doris:all-in-one-4.1.3` image. The query was authorized but
returned unfiltered and unmasked rows:

```text
expected: [[2, NULL]]
actual:   [[1, first], [2, second]]
```

This PR:

- delegates SELECT mapping to each Ranger service while retaining a
concrete uppercase default, preserving compatibility with existing
external subclasses;
- uses lowercase `select` consistently for Ranger-Hive authorization,
row filters, and data masks;
- keeps Ranger connection and process settings in the existing
`ranger-<serviceName>-security.xml` configuration;
- adds unit coverage and an end-to-end `ranger_p2` case covering
lowercase access entries, row filtering, data masking, and a warmed-up
policy evaluator.

### Validation

- `./run-fe-ut.sh --run
org.apache.doris.catalog.authorizer.ranger.hive.RangerHiveAccessControllerTest`:
2 tests passed, 0 failures/errors/skips.
- `./run-regression-test.sh --run --conf <local-ranger-conf> -d
ranger_p2 -s test_ranger_hive_lowercase_access_type`: 1 suite passed, 0
failed, 0 skipped. The FE loaded `ranger-doris_hive-security.xml`, the
catalog did not provide a Ranger URL, and both first and warmed-up
queries returned the filtered and masked result.
@github-actions
github-actions Bot requested a review from yiguolei as a code owner September 2, 2026 01:44
@hello-stephen

Copy link
Copy Markdown
Contributor

Thank you for your contribution to Apache Doris.
Don't know what should be done next? See How to process your PR.

Please clearly describe your PR:

  1. What problem was fixed (it's best to include specific error reporting information). How it was fixed.
  2. Which behaviors were modified. What was the previous behavior, what is it now, why was it modified, and what possible impacts might there be.
  3. What features were added. Why was this function added?
  4. Which code was refactored and why was this part of the code refactored?
  5. Which functions were optimized and what is the difference before and after the optimization?

@hello-stephen

Copy link
Copy Markdown
Contributor

run buildall

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants