[
https://issues.apache.org/jira/browse/HADOOP-13381?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15385195#comment-15385195
]
Arun Suresh commented on HADOOP-13381:
--------------------------------------
bq. ..assuming we loosen the retry check of response message..
Agreed... I guess that should be fine..
With respect to the race condition, am not really worried.. the worst that can
happen, if we follow the flow I specified in my earlier comment (when multiple
threads call the same KMSClientProvider at a time when the DT has expired), is
that.. simultaneous refreshes of the UGI's credentials will happen, but dont
think there would be any UGI state inconsistency. Besides, the
UGI::addCredential is synchronized on the subject.
> KMS clients running in the same JVM should use updated KMS Delegation Token
> ---------------------------------------------------------------------------
>
> Key: HADOOP-13381
> URL: https://issues.apache.org/jira/browse/HADOOP-13381
> Project: Hadoop Common
> Issue Type: Bug
> Components: kms
> Affects Versions: 2.6.0
> Reporter: Xiao Chen
> Assignee: Xiao Chen
> Priority: Critical
> Attachments: HADOOP-13381.01.patch
>
>
> When {{/tmp}} is setup as an EZ, one may experience YARN log aggregation
> failure after the very first KMS token is expired. The MR job itself runs
> fine though.
> When this happens, YARN NodeManager's log will show
> {{AuthenticationException}} with {{token is expired}} / {{token can't be
> found in cache}}, depending on whether the expired token is removed by the
> background or not.
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]