Skip to content

HDDS-16308. Validate advertised addresses before startup, registration, and publication - #11272

Draft
rjgoyln wants to merge 5 commits into
apache:masterfrom
rjgoyln:HDDS-16308
Draft

rjgoyln wants to merge 5 commits into
apache:masterfrom
rjgoyln:HDDS-16308

Conversation

@rjgoyln

@rjgoyln rjgoyln commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

What changes were proposed in this pull request?

Wildcard, link-local, and scoped addresses can bind successfully but do not identify reachable endpoints. Zone identifiers are also invalid in X.509 certificate IP SANs. Previously, these values were accepted as advertised addresses and only failed later during connection or certificate issuance.

Unbracketed IPv6 literals are ambiguous when a port may follow. For example, 2001:db8::1:9862 can represent either host 2001:db8::1 on port 9862 or a complete IPv6 literal using the default port. Since #11130, the latter is silently accepted.

This patch:

  • Rejects wildcard, link-local, and scoped hosts in ozone.scm.names, SCM and OM per-node addresses, ozone.recon.address, and hdds.datanode.hostname, reporting the property and configured value.
  • Rejects unbracketed IPv6 literals wherever a port may follow.
  • Uses HddsUtils.getHostPortString for the remaining advertised peer identities, as deferred from HDDS-16307. Construct listeners from separate host and port values #11130.

Loopback remains allowed for single-host deployments, so isValidInetForCsr is not reused.

Non-HA SCM *.address properties and the unsuffixed ozone.om.address retain only the bracket rule. SCM rewrites its RPC addresses with the bound host after startup, while ozone.om.address defaults to 0.0.0.0:9862 and may be read by clients such as ozone local. Wildcard listeners should instead use *.bind.host or *.http-bind-host.

What is the link to the Apache JIRA?

https://issues.apache.org/jira/browse/HDDS-16308

How was this patch tested?

Unit tests cover accepted hosts (DNS names, IPv4, global IPv6, loopback, and bracketed authorities) and rejected cases (wildcard, link-local, scoped, prefixed, bracketed wildcard, and unbracketed authorities). Each rejection test fails without the production change.

Additional tests guard against over-rejection of bare :: bind hosts, host-only per-node SCM literals, the default ozone.om.address used by the non-HA client failover proxy, and wildcard non-HA SCM *.address properties.

The following integration tests pass:

  • TestLocalOzoneClusterRuntime
  • TestSecureOzoneCluster
  • TestDelegationToken
  • TestOzoneManagerConfiguration
  • TestMiniOzoneCluster

These cover startup scenarios where one component reads configuration rewritten by another server.

Behavior change

IPv6 literals must now be bracketed wherever a port may follow (e.g. ozone.scm.client.address = [2001:db8::1]), reversing the bare-literal behavior accepted by HDDS-15773 and HDDS-16307. Per-node OM addresses also reject 0.0.0.0; wildcard listeners must use the appropriate bind-host properties.

Generated by Claude Code (Opus 5).

…n, and publication

A wildcard, link-local, or scoped address is valid to bind but names no
endpoint a peer can reach, and a zone identifier cannot be encoded in an
X.509 certificate. Nothing rejected such a value where it is read as an
advertised address, so the misconfiguration surfaced later as a failure to
connect, or as a certificate the peer cannot use.

The textual form of a configured authority is a separate gap. Both readings
of an unbracketed IPv6 literal are valid literals, so an operator who means
a host and a port gets the whole literal as the host and the property's
default port, with no error anywhere.

Advertised properties are the ones a peer or client resolves and that never
serve as a bind address. The unsuffixed ozone.om.address is excluded: it
ships as 0.0.0.0:9862 and a non-HA OM binds to it.
A bracketed literal reaches the address with its brackets stripped, so
[::] configured as an advertised host was taken for a hostname and passed
every check while the bare form was rejected.

A value that can never be advertised should also say so directly, rather
than first be asked for brackets that leave it rejected.

The SCM block-client, security-service and datanode address properties are
read as peer identities on the non-HA path as well, so they are checked
alongside ozone.scm.client.address and ozone.scm.names.
Copilot AI lite review requested due to automatic review settings September 19, 2026 14:00

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Correct the ambiguous IPv6 peer-address serialization in OmUtils.java before approval.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

This PR validates advertised network addresses and improves IPv6 host/port formatting across SCM, OM, Recon, and related configuration paths.

Changes:

  • Rejects invalid wildcard, link-local, scoped, and ambiguous IPv6 advertised addresses.
  • Applies validation across SCM, OM, Recon, and datanode paths.
  • Updates IPv6 formatting and expands unit coverage.

A critical issue remains in OmUtils.java: valid bracketed IPv6 OM peer addresses are serialized ambiguously.

File Summary
hadoop-ozone/​ozone-manager/​src/​main/​java/​org/​apache/​hadoop/​ozone/​om/​ha/​OMHANodeDetails.java Formats IPv6 OM log addresses.
hadoop-ozone/​common/​src/​test/​java/​org/​apache/​hadoop/​ozone/​TestOmUtils.java Tests OM address validation.
hadoop-ozone/​common/​src/​test/​java/​org/​apache/​hadoop/​ozone/​om/​helpers/​TestOMNodeDetails.java Tests IPv6 OM formatting.
hadoop-ozone/​common/​src/​main/​java/​org/​apache/​hadoop/​ozone/​OmUtils.java Validates OM advertised addresses and builds peer identities.
hadoop-hdds/​server-scm/​src/​test/​java/​org/​apache/​hadoop/​hdds/​scm/​TestHddsServerUtils.java Tests SCM and Recon validation.
hadoop-hdds/​server-scm/​src/​main/​java/​org/​apache/​hadoop/​hdds/​scm/​ha/​SCMNodeDetails.java Uses shared RPC address formatting.
hadoop-hdds/​server-scm/​src/​main/​java/​org/​apache/​hadoop/​hdds/​scm/​ha/​SCMHANodeDetails.java Formats SCM HA log addresses.
hadoop-hdds/​framework/​src/​main/​java/​org/​apache/​hadoop/​hdds/​utils/​HddsServerUtil.java Validates SCM and Recon endpoints.
hadoop-hdds/​common/​src/​test/​java/​org/​apache/​hadoop/​hdds/​TestHddsUtils.java Tests address validation and parsing.
hadoop-hdds/​common/​src/​test/​java/​org/​apache/​hadoop/​hdds/​scm/​ha/​TestSCMNodeInfo.java Tests SCM validation.
hadoop-hdds/​common/​src/​main/​java/​org/​apache/​hadoop/​hdds/​scm/​ha/​SCMNodeInfo.java Validates SCM advertised addresses.
hadoop-hdds/​common/​src/​main/​java/​org/​apache/​hadoop/​hdds/​NodeDetails.java Brackets IPv6 RPC addresses.
hadoop-hdds/​common/​src/​main/​java/​org/​apache/​hadoop/​hdds/​HddsUtils.java Adds address validation and IPv6 authority checks.
hadoop-hdds/​client/​src/​test/​java/​org/​apache/​hadoop/​hdds/​scm/​client/​TestHddsClientUtils.java Tests IPv6 client address rejection.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines 174 to 175
return host.get() + ":" + getPortNumberFromConfigKeys(conf, confKey)
.orElse(OZONE_OM_PORT_DEFAULT);
# Conflicts:
#	hadoop-hdds/common/src/test/java/org/apache/hadoop/hdds/TestHddsUtils.java
#	hadoop-ozone/common/src/main/java/org/apache/hadoop/ozone/OmUtils.java
A non-HA SCM rewrites its four *.address properties with its bound host once
its RPC servers start, and the unsuffixed ozone.om.address is the non-HA OM's
own RPC address with a wildcard default. A process that shares such a
configuration, like `ozone local`, and a non-HA client relying on the default
read the wildcard back and were rejected, so those properties keep only the
bracket rule.

A per-node OM address is advertised to the other OMs, so the tests that used
0.0.0.0 there to mean "this host" now use localhost.
HDDS-16307 added this case with a bare literal under a property a port may
follow, which this change rejects as ambiguous. The test is about the emitted
address being bracketed, which the bracketed input still covers.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants