public class org.apache.hadoop.hive.metastore.utils.SecurityUtils extends java.lang.Object
{
private static final org.slf4j.Logger LOG;
public void <init>()
{
org.apache.hadoop.hive.metastore.utils.SecurityUtils v;
v := @this: org.apache.hadoop.hive.metastore.utils.SecurityUtils;
specialinvoke v.<java.lang.Object: void <init>()>();
return;
}
public static org.apache.hadoop.security.UserGroupInformation getUGI() throws javax.security.auth.login.LoginException, java.io.IOException
{
org.apache.hadoop.security.UserGroupInformation v, v, v;
int v;
java.lang.String v;
v = staticinvoke <java.lang.System: java.lang.String getenv(java.lang.String)>("HADOOP_USER_NAME");
if v == null goto label;
v = virtualinvoke v.<java.lang.String: int length()>();
if v <= 0 goto label;
v = staticinvoke <org.apache.hadoop.security.UserGroupInformation: org.apache.hadoop.security.UserGroupInformation getLoginUser()>();
v = staticinvoke <org.apache.hadoop.security.UserGroupInformation: org.apache.hadoop.security.UserGroupInformation createProxyUser(java.lang.String,org.apache.hadoop.security.UserGroupInformation)>(v, v);
return v;
label:
v = staticinvoke <org.apache.hadoop.security.UserGroupInformation: org.apache.hadoop.security.UserGroupInformation getCurrentUser()>();
return v;
}
public static void setZookeeperClientKerberosJaasConfig(java.lang.String, java.lang.String) throws java.io.IOException
{
org.apache.hadoop.hive.metastore.utils.SecurityUtils$JaasConfiguration v;
java.lang.String v, v, v;
v := @parameter: java.lang.String;
v := @parameter: java.lang.String;
staticinvoke <java.lang.System: java.lang.String setProperty(java.lang.String,java.lang.String)>("zookeeper.sasl.clientconfig", "HiveZooKeeperClient");
v = staticinvoke <org.apache.hadoop.security.SecurityUtil: java.lang.String getServerPrincipal(java.lang.String,java.lang.String)>(v, "0.0.0.0");
v = new org.apache.hadoop.hive.metastore.utils.SecurityUtils$JaasConfiguration;
specialinvoke v.<org.apache.hadoop.hive.metastore.utils.SecurityUtils$JaasConfiguration: void <init>(java.lang.String,java.lang.String,java.lang.String)>("HiveZooKeeperClient", v, v);
staticinvoke <javax.security.auth.login.Configuration: void setConfiguration(javax.security.auth.login.Configuration)>(v);
return;
}
public static java.lang.String getTokenStrForm(java.lang.String) throws java.io.IOException
{
java.util.Collection v;
org.apache.hadoop.io.Text v, v, v;
org.apache.hadoop.hive.metastore.security.DelegationTokenSelector v;
org.apache.hadoop.security.token.Token v;
org.apache.hadoop.security.UserGroupInformation v;
java.lang.String v, v;
v := @parameter: java.lang.String;
v = staticinvoke <org.apache.hadoop.security.UserGroupInformation: org.apache.hadoop.security.UserGroupInformation getCurrentUser()>();
v = new org.apache.hadoop.hive.metastore.security.DelegationTokenSelector;
specialinvoke v.<org.apache.hadoop.hive.metastore.security.DelegationTokenSelector: void <init>()>();
if v != null goto label;
v = new org.apache.hadoop.io.Text;
v = v;
specialinvoke v.<org.apache.hadoop.io.Text: void <init>()>();
goto label;
label:
v = new org.apache.hadoop.io.Text;
v = v;
specialinvoke v.<org.apache.hadoop.io.Text: void <init>(java.lang.String)>(v);
label:
v = virtualinvoke v.<org.apache.hadoop.security.UserGroupInformation: java.util.Collection getTokens()>();
v = interfaceinvoke v.<org.apache.hadoop.security.token.TokenSelector: org.apache.hadoop.security.token.Token selectToken(org.apache.hadoop.io.Text,java.util.Collection)>(v, v);
if v == null goto label;
v = virtualinvoke v.<org.apache.hadoop.security.token.Token: java.lang.String encodeToUrlString()>();
goto label;
label:
v = null;
label:
return v;
}
public static void setTokenStr(org.apache.hadoop.security.UserGroupInformation, java.lang.String, java.lang.String) throws java.io.IOException
{
org.apache.hadoop.security.UserGroupInformation v;
java.lang.String v, v;
org.apache.hadoop.security.token.Token v;
v := @parameter: org.apache.hadoop.security.UserGroupInformation;
v := @parameter: java.lang.String;
v := @parameter: java.lang.String;
v = staticinvoke <org.apache.hadoop.hive.metastore.utils.SecurityUtils: org.apache.hadoop.security.token.Token createToken(java.lang.String,java.lang.String)>(v, v);
virtualinvoke v.<org.apache.hadoop.security.UserGroupInformation: boolean addToken(org.apache.hadoop.security.token.Token)>(v);
return;
}
private static org.apache.hadoop.security.token.Token createToken(java.lang.String, java.lang.String) throws java.io.IOException
{
org.apache.hadoop.io.Text v;
java.lang.String v, v;
org.apache.hadoop.security.token.Token v;
v := @parameter: java.lang.String;
v := @parameter: java.lang.String;
v = new org.apache.hadoop.security.token.Token;
specialinvoke v.<org.apache.hadoop.security.token.Token: void <init>()>();
virtualinvoke v.<org.apache.hadoop.security.token.Token: void decodeFromUrlString(java.lang.String)>(v);
v = new org.apache.hadoop.io.Text;
specialinvoke v.<org.apache.hadoop.io.Text: void <init>(java.lang.String)>(v);
virtualinvoke v.<org.apache.hadoop.security.token.Token: void setService(org.apache.hadoop.io.Text)>(v);
return v;
}
public static java.lang.String getUser() throws java.io.IOException
{
javax.security.auth.login.LoginException v;
org.apache.hadoop.security.UserGroupInformation v;
java.io.IOException v;
java.lang.String v;
label:
v = staticinvoke <org.apache.hadoop.hive.metastore.utils.SecurityUtils: org.apache.hadoop.security.UserGroupInformation getUGI()>();
v = virtualinvoke v.<org.apache.hadoop.security.UserGroupInformation: java.lang.String getUserName()>();
label:
return v;
label:
v := @caughtexception;
v = new java.io.IOException;
specialinvoke v.<java.io.IOException: void <init>(java.lang.Throwable)>(v);
throw v;
catch javax.security.auth.login.LoginException from label to label with label;
}
public static org.apache.thrift.transport.TServerSocket getServerSocket(java.lang.String, int) throws org.apache.thrift.transport.TTransportException
{
org.apache.thrift.transport.TServerSocket v;
int v;
java.lang.String v;
java.net.InetSocketAddress v, v, v;
boolean v;
v := @parameter: java.lang.String;
v := @parameter: int;
if v == null goto label;
v = virtualinvoke v.<java.lang.String: boolean isEmpty()>();
if v == 0 goto label;
label:
v = new java.net.InetSocketAddress;
specialinvoke v.<java.net.InetSocketAddress: void <init>(int)>(v);
v = v;
goto label;
label:
v = new java.net.InetSocketAddress;
specialinvoke v.<java.net.InetSocketAddress: void <init>(java.lang.String,int)>(v, v);
v = v;
label:
v = new org.apache.thrift.transport.TServerSocket;
specialinvoke v.<org.apache.thrift.transport.TServerSocket: void <init>(java.net.InetSocketAddress)>(v);
return v;
}
public static org.apache.thrift.transport.TServerSocket getServerSSLSocket(java.lang.String, int, java.lang.String, java.lang.String, java.lang.String, java.lang.String, java.util.List) throws org.apache.thrift.transport.TTransportException, java.net.UnknownHostException
{
java.net.InetAddress v;
java.net.ServerSocket v, v;
boolean v, v, v, v, v, v;
java.net.InetSocketAddress v, v, v;
java.util.List v;
java.lang.Object[] v;
java.lang.String[] v, v, v;
java.util.ArrayList v, v;
int v, v, v;
java.lang.String v, v, v, v, v, v, v, v, v, v, v, v, v, v, v;
org.apache.thrift.transport.TSSLTransportFactory$TSSLTransportParameters v;
org.slf4j.Logger v, v;
java.util.Iterator v;
org.apache.thrift.transport.TServerSocket v;
java.lang.Object v;
v := @parameter: java.lang.String;
v := @parameter: int;
v := @parameter: java.lang.String;
v := @parameter: java.lang.String;
v := @parameter: java.lang.String;
v := @parameter: java.lang.String;
v := @parameter: java.util.List;
v = new org.apache.thrift.transport.TSSLTransportFactory$TSSLTransportParameters;
specialinvoke v.<org.apache.thrift.transport.TSSLTransportFactory$TSSLTransportParameters: void <init>()>();
v = virtualinvoke v.<java.lang.String: boolean isEmpty()>();
if v == 0 goto label;
v = staticinvoke <java.security.KeyStore: java.lang.String getDefaultType()>();
goto label;
label:
v = v;
label:
v = v;
v = virtualinvoke v.<java.lang.String: boolean isEmpty()>();
if v == 0 goto label;
v = staticinvoke <javax.net.ssl.KeyManagerFactory: java.lang.String getDefaultAlgorithm()>();
goto label;
label:
v = v;
label:
virtualinvoke v.<org.apache.thrift.transport.TSSLTransportFactory$TSSLTransportParameters: void setKeyStore(java.lang.String,java.lang.String,java.lang.String,java.lang.String)>(v, v, v, v);
if v == null goto label;
v = virtualinvoke v.<java.lang.String: boolean isEmpty()>();
if v == 0 goto label;
label:
v = new java.net.InetSocketAddress;
specialinvoke v.<java.net.InetSocketAddress: void <init>(int)>(v);
v = v;
goto label;
label:
v = new java.net.InetSocketAddress;
specialinvoke v.<java.net.InetSocketAddress: void <init>(java.lang.String,int)>(v, v);
v = v;
label:
v = virtualinvoke v.<java.net.InetSocketAddress: java.net.InetAddress getAddress()>();
v = staticinvoke <org.apache.thrift.transport.TSSLTransportFactory: org.apache.thrift.transport.TServerSocket getServerSocket(int,int,java.net.InetAddress,org.apache.thrift.transport.TSSLTransportFactory$TSSLTransportParameters)>(v, 0, v, v);
v = virtualinvoke v.<org.apache.thrift.transport.TServerSocket: java.net.ServerSocket getServerSocket()>();
v = v instanceof javax.net.ssl.SSLServerSocket;
if v == 0 goto label;
v = new java.util.ArrayList;
specialinvoke v.<java.util.ArrayList: void <init>()>();
v = interfaceinvoke v.<java.util.List: java.util.Iterator iterator()>();
label:
v = interfaceinvoke v.<java.util.Iterator: boolean hasNext()>();
if v == 0 goto label;
v = interfaceinvoke v.<java.util.Iterator: java.lang.Object next()>();
v = virtualinvoke v.<java.lang.String: java.lang.String trim()>();
v = virtualinvoke v.<java.lang.String: java.lang.String toLowerCase()>();
interfaceinvoke v.<java.util.List: boolean add(java.lang.Object)>(v);
goto label;
label:
v = virtualinvoke v.<org.apache.thrift.transport.TServerSocket: java.net.ServerSocket getServerSocket()>();
v = new java.util.ArrayList;
specialinvoke v.<java.util.ArrayList: void <init>()>();
v = virtualinvoke v.<javax.net.ssl.SSLServerSocket: java.lang.String[] getEnabledProtocols()>();
v = lengthof v;
v = 0;
label:
if v >= v goto label;
v = v[v];
v = virtualinvoke v.<java.lang.String: java.lang.String toLowerCase()>();
v = interfaceinvoke v.<java.util.List: boolean contains(java.lang.Object)>(v);
if v == 0 goto label;
v = <org.apache.hadoop.hive.metastore.utils.SecurityUtils: org.slf4j.Logger LOG>;
v = dynamicinvoke "makeConcatWithConstants" <java.lang.String (java.lang.String)>(v) <java.lang.invoke.StringConcatFactory: java.lang.invoke.CallSite makeConcatWithConstants(java.lang.invoke.MethodHandles$Lookup,java.lang.String,java.lang.invoke.MethodType,java.lang.String,java.lang.Object[])>("Disabling SSL Protocol: \u0001");
interfaceinvoke v.<org.slf4j.Logger: void debug(java.lang.String)>(v);
goto label;
label:
interfaceinvoke v.<java.util.List: boolean add(java.lang.Object)>(v);
label:
v = v + 1;
goto label;
label:
v = newarray (java.lang.String)[0];
v = interfaceinvoke v.<java.util.List: java.lang.Object[] toArray(java.lang.Object[])>(v);
virtualinvoke v.<javax.net.ssl.SSLServerSocket: void setEnabledProtocols(java.lang.String[])>(v);
v = <org.apache.hadoop.hive.metastore.utils.SecurityUtils: org.slf4j.Logger LOG>;
v = virtualinvoke v.<javax.net.ssl.SSLServerSocket: java.lang.String[] getEnabledProtocols()>();
v = staticinvoke <java.util.Arrays: java.lang.String toString(java.lang.Object[])>(v);
v = dynamicinvoke "makeConcatWithConstants" <java.lang.String (java.lang.String)>(v) <java.lang.invoke.StringConcatFactory: java.lang.invoke.CallSite makeConcatWithConstants(java.lang.invoke.MethodHandles$Lookup,java.lang.String,java.lang.invoke.MethodType,java.lang.String,java.lang.Object[])>("SSL Server Socket Enabled Protocols: \u0001");
interfaceinvoke v.<org.slf4j.Logger: void info(java.lang.String)>(v);
label:
return v;
}
public static org.apache.thrift.transport.TTransport getSSLSocket(java.lang.String, int, int, java.lang.String, java.lang.String, java.lang.String, java.lang.String) throws org.apache.thrift.transport.TTransportException
{
int v, v;
java.lang.String v, v, v, v, v, v, v, v;
org.apache.thrift.transport.TSocket v, v;
org.apache.thrift.transport.TSSLTransportFactory$TSSLTransportParameters v;
boolean v, v;
v := @parameter: java.lang.String;
v := @parameter: int;
v := @parameter: int;
v := @parameter: java.lang.String;
v := @parameter: java.lang.String;
v := @parameter: java.lang.String;
v := @parameter: java.lang.String;
v = new org.apache.thrift.transport.TSSLTransportFactory$TSSLTransportParameters;
specialinvoke v.<org.apache.thrift.transport.TSSLTransportFactory$TSSLTransportParameters: void <init>()>();
v = virtualinvoke v.<java.lang.String: boolean isEmpty()>();
if v == 0 goto label;
v = staticinvoke <java.security.KeyStore: java.lang.String getDefaultType()>();
goto label;
label:
v = v;
label:
v = v;
v = virtualinvoke v.<java.lang.String: boolean isEmpty()>();
if v == 0 goto label;
v = staticinvoke <javax.net.ssl.TrustManagerFactory: java.lang.String getDefaultAlgorithm()>();
goto label;
label:
v = v;
label:
virtualinvoke v.<org.apache.thrift.transport.TSSLTransportFactory$TSSLTransportParameters: void setTrustStore(java.lang.String,java.lang.String,java.lang.String,java.lang.String)>(v, v, v, v);
virtualinvoke v.<org.apache.thrift.transport.TSSLTransportFactory$TSSLTransportParameters: void requireClientAuth(boolean)>(1);
v = staticinvoke <org.apache.thrift.transport.TSSLTransportFactory: org.apache.thrift.transport.TSocket getClientSocket(java.lang.String,int,int,org.apache.thrift.transport.TSSLTransportFactory$TSSLTransportParameters)>(v, v, v, v);
v = staticinvoke <org.apache.hadoop.hive.metastore.utils.SecurityUtils: org.apache.thrift.transport.TSocket getSSLSocketWithHttps(org.apache.thrift.transport.TSocket)>(v);
return v;
}
public static org.apache.thrift.transport.THttpClient getThriftHttpsClient(java.lang.String, java.lang.String, java.lang.String, java.lang.String, java.lang.String, org.apache.http.impl.client.HttpClientBuilder) throws org.apache.thrift.transport.TTransportException, java.io.IOException, java.security.KeyStoreException, java.security.NoSuchAlgorithmException, java.security.cert.CertificateException, java.security.KeyManagementException
{
java.lang.Throwable v;
javax.net.ssl.SSLContext v;
org.apache.http.config.RegistryBuilder v, v;
org.apache.thrift.transport.THttpClient v;
org.apache.http.config.Registry v;
java.lang.String v, v, v, v, v;
org.apache.http.conn.ssl.SSLConnectionSocketFactory v;
boolean v;
org.apache.http.impl.client.CloseableHttpClient v;
java.security.KeyStore v;
java.io.FileInputStream v;
org.apache.http.ssl.SSLContextBuilder v, v, v;
org.apache.http.impl.conn.BasicHttpClientConnectionManager v;
char[] v;
org.apache.http.conn.ssl.DefaultHostnameVerifier v;
org.apache.http.impl.client.HttpClientBuilder v;
v := @parameter: java.lang.String;
v := @parameter: java.lang.String;
v := @parameter: java.lang.String;
v := @parameter: java.lang.String;
v := @parameter: java.lang.String;
v := @parameter: org.apache.http.impl.client.HttpClientBuilder;
staticinvoke <com.google.common.base.Preconditions: java.lang.Object checkNotNull(java.lang.Object,java.lang.Object)>(v, "httpClientBuilder should not be null");
if v == null goto label;
v = virtualinvoke v.<java.lang.String: boolean isEmpty()>();
if v == 0 goto label;
label:
v = staticinvoke <java.security.KeyStore: java.lang.String getDefaultType()>();
label:
v = staticinvoke <java.security.KeyStore: java.security.KeyStore getInstance(java.lang.String)>(v);
v = new java.io.FileInputStream;
specialinvoke v.<java.io.FileInputStream: void <init>(java.lang.String)>(v);
label:
v = virtualinvoke v.<java.lang.String: char[] toCharArray()>();
virtualinvoke v.<java.security.KeyStore: void load(java.io.InputStream,char[])>(v, v);
label:
virtualinvoke v.<java.io.FileInputStream: void close()>();
goto label;
label:
v := @caughtexception;
throw v;
label:
v = staticinvoke <org.apache.http.ssl.SSLContexts: org.apache.http.ssl.SSLContextBuilder custom()>();
v = virtualinvoke v.<org.apache.http.ssl.SSLContextBuilder: org.apache.http.ssl.SSLContextBuilder setTrustManagerFactoryAlgorithm(java.lang.String)>(v);
v = virtualinvoke v.<org.apache.http.ssl.SSLContextBuilder: org.apache.http.ssl.SSLContextBuilder loadTrustMaterial(java.security.KeyStore,org.apache.http.ssl.TrustStrategy)>(v, null);
v = virtualinvoke v.<org.apache.http.ssl.SSLContextBuilder: javax.net.ssl.SSLContext build()>();
v = new org.apache.http.conn.ssl.SSLConnectionSocketFactory;
v = new org.apache.http.conn.ssl.DefaultHostnameVerifier;
specialinvoke v.<org.apache.http.conn.ssl.DefaultHostnameVerifier: void <init>(org.apache.http.conn.util.PublicSuffixMatcher)>(null);
specialinvoke v.<org.apache.http.conn.ssl.SSLConnectionSocketFactory: void <init>(javax.net.ssl.SSLContext,javax.net.ssl.HostnameVerifier)>(v, v);
v = staticinvoke <org.apache.http.config.RegistryBuilder: org.apache.http.config.RegistryBuilder create()>();
v = virtualinvoke v.<org.apache.http.config.RegistryBuilder: org.apache.http.config.RegistryBuilder register(java.lang.String,java.lang.Object)>("https", v);
v = virtualinvoke v.<org.apache.http.config.RegistryBuilder: org.apache.http.config.Registry build()>();
v = new org.apache.http.impl.conn.BasicHttpClientConnectionManager;
specialinvoke v.<org.apache.http.impl.conn.BasicHttpClientConnectionManager: void <init>(org.apache.http.config.Lookup)>(v);
virtualinvoke v.<org.apache.http.impl.client.HttpClientBuilder: org.apache.http.impl.client.HttpClientBuilder setConnectionManager(org.apache.http.conn.HttpClientConnectionManager)>(v);
v = new org.apache.thrift.transport.THttpClient;
v = virtualinvoke v.<org.apache.http.impl.client.HttpClientBuilder: org.apache.http.impl.client.CloseableHttpClient build()>();
specialinvoke v.<org.apache.thrift.transport.THttpClient: void <init>(java.lang.String,org.apache.http.client.HttpClient)>(v, v);
return v;
catch java.lang.Throwable from label to label with label;
}
private static org.apache.thrift.transport.TSocket getSSLSocketWithHttps(org.apache.thrift.transport.TSocket) throws org.apache.thrift.transport.TTransportException
{
java.net.Socket v;
javax.net.ssl.SSLParameters v;
org.apache.thrift.transport.TSocket v, v;
v := @parameter: org.apache.thrift.transport.TSocket;
v = virtualinvoke v.<org.apache.thrift.transport.TSocket: java.net.Socket getSocket()>();
v = virtualinvoke v.<javax.net.ssl.SSLSocket: javax.net.ssl.SSLParameters getSSLParameters()>();
virtualinvoke v.<javax.net.ssl.SSLParameters: void setEndpointIdentificationAlgorithm(java.lang.String)>("HTTPS");
virtualinvoke v.<javax.net.ssl.SSLSocket: void setSSLParameters(javax.net.ssl.SSLParameters)>(v);
v = new org.apache.thrift.transport.TSocket;
specialinvoke v.<org.apache.thrift.transport.TSocket: void <init>(java.net.Socket)>(v);
return v;
}
public static void reloginExpiringKeytabUser() throws org.apache.hadoop.hive.metastore.api.MetaException
{
org.slf4j.Logger v;
org.apache.hadoop.hive.metastore.api.MetaException v;
java.io.IOException v;
org.apache.hadoop.security.UserGroupInformation v;
java.lang.String v, v;
boolean v, v;
v = staticinvoke <org.apache.hadoop.security.UserGroupInformation: boolean isSecurityEnabled()>();
if v != 0 goto label;
return;
label:
v = staticinvoke <org.apache.hadoop.security.UserGroupInformation: org.apache.hadoop.security.UserGroupInformation getLoginUser()>();
v = virtualinvoke v.<org.apache.hadoop.security.UserGroupInformation: boolean isFromKeytab()>();
if v == 0 goto label;
virtualinvoke v.<org.apache.hadoop.security.UserGroupInformation: void checkTGTAndReloginFromKeytab()>();
label:
goto label;
label:
v := @caughtexception;
v = virtualinvoke v.<java.io.IOException: java.lang.String getMessage()>();
v = dynamicinvoke "makeConcatWithConstants" <java.lang.String (java.lang.String)>(v) <java.lang.invoke.StringConcatFactory: java.lang.invoke.CallSite makeConcatWithConstants(java.lang.invoke.MethodHandles$Lookup,java.lang.String,java.lang.invoke.MethodType,java.lang.String,java.lang.Object[])>("Error doing relogin using keytab \u0001");
v = <org.apache.hadoop.hive.metastore.utils.SecurityUtils: org.slf4j.Logger LOG>;
interfaceinvoke v.<org.slf4j.Logger: void error(java.lang.String,java.lang.Throwable)>(v, v);
v = new org.apache.hadoop.hive.metastore.api.MetaException;
specialinvoke v.<org.apache.hadoop.hive.metastore.api.MetaException: void <init>(java.lang.String)>(v);
throw v;
label:
return;
catch java.io.IOException from label to label with label;
}
static void <clinit>()
{
org.slf4j.Logger v;
v = staticinvoke <org.slf4j.LoggerFactory: org.slf4j.Logger getLogger(java.lang.Class)>(class "Lorg/apache/hadoop/hive/metastore/utils/SecurityUtils;");
<org.apache.hadoop.hive.metastore.utils.SecurityUtils: org.slf4j.Logger LOG> = v;
return;
}
}