Skip to content

Rebuild - #69

Merged
qianmoQ merged 22 commits into
devfrom
rebuild
Oct 5, 2026
Merged

qianmoQ merged 22 commits into
devfrom
rebuild

Conversation

@qianmoQ

@qianmoQ qianmoQ commented Oct 5, 2026

Copy link
Copy Markdown
Member

Changelog category (leave one)

  • New Feature
  • Bug Fix
  • Documentation (changelog entry is not required)
  • Other

Changelog entry (Details of this change)

If there is an issue connection, write it to the end of the question
e.g: issue-7
Please delete this information when submitting

  • e.g: Support XXXXX

Affected version

  • e.g: latest version

grantforge-agent-core runs on Java 8 inside the systems GrantForge protects. GrantForgeAgent
sends heartbeats, downloads the service's snapshot when the policy version changes, checks
its Ed25519 signature with Bouncy Castle, builds a policy engine from it with Jackson 2 and
keeps the last good snapshot on disk for starts without the server. Decisions add the roles
and groups the snapshot gives the user; access events go out in batches and are spooled to
disk while the server is away.
At a million accounts every user list page sorted the whole tenant and counted it again. An
index on tenant, creation time and id lets the database walk the newest accounts, and the
search first reads up to 1000 matches unordered: that many or fewer are ordered in memory and
counted for free, so a rare match no longer runs the ordered scan through the whole table.
The console application's id is kept per catalog version, which application changes now
raise, removing a query from every API call.
A search for accounts whose name, display name or address contains the text scanned every
account; at a million that took 250-400 ms. On PostgreSQL the migration enables pg_trgm where
the database allows it and adds trigram indexes matching the search's expressions, which
brings the search to a few tens of milliseconds. Without the extension, and on the other
databases, nothing changes.
The hdfs service type declares paths, matched as paths and optionally with everything below
them, with read, write and execute. Testing a connection and looking up paths go through
WebHDFS or HttpFS with the JDK's HTTP client, so no Hadoop client is needed and any Hadoop
version works; several NameNode addresses are tried in turn, skipping standby ones. The plugin
is packaged with its own Jackson and the release unpacks it into plugins/hdfs.
@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ❌ 1 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 6 package(s) with unknown licenses.
See the Details below.

License Issues

pom.xml

PackageVersionLicenseIssue Type
org.apache.maven.plugins:maven-javadoc-plugin3.12.0Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause AND LicenseRef-scancode-public-domain AND MITIncompatible License
org.devlive.grantforge:grantforge-agent-core2026.0.0NullUnknown License

core/grantforge-agent-core/pom.xml

PackageVersionLicenseIssue Type
org.devlive.grantforge:grantforge-policy-engineNullUnknown License
org.devlive.grantforge:grantforge-test-supportNullUnknown License

core/grantforge-plugin-host/pom.xml

PackageVersionLicenseIssue Type
org.devlive.grantforge:grantforge-plugin-hdfs2026.0.0NullUnknown License

plugins/grantforge-agent-hdfs/pom.xml

PackageVersionLicenseIssue Type
org.devlive.grantforge:grantforge-agent-coreNullUnknown License

plugins/grantforge-plugin-hdfs/pom.xml

PackageVersionLicenseIssue Type
org.devlive.grantforge:grantforge-plugin-apiNullUnknown License
Allowed Licenses: MIT, MIT-0, Apache-2.0, BSD-2-Clause, BSD-3-Clause, ISC, 0BSD, CC0-1.0, CC-BY-4.0, Unlicense, BlueOak-1.0.0, Python-2.0, EPL-1.0, EPL-2.0, MPL-2.0, LGPL-2.1-only, LGPL-2.1-or-later
Excluded from license check: pkg:maven/com.oracle.database.jdbc/ojdbc11, pkg:maven/com.oracle.database.jdbc/ucp11, pkg:maven/com.mysql/mysql-connector-j, pkg:npm/robust-predicates, pkg:npm/uri-js, pkg:maven/org.bouncycastle/bcprov-jdk18on, pkg:maven/org.apache.hadoop.thirdparty/hadoop-shaded-protobuf_3_25

OpenSSF Scorecard

Scorecard details
PackageVersionScoreDetails
maven/com.fasterxml.jackson.core:jackson-databind UnknownUnknown
maven/org.bouncycastle:bcprov-jdk18on UnknownUnknown
maven/org.devlive.grantforge:grantforge-policy-engine UnknownUnknown
maven/org.devlive.grantforge:grantforge-test-support UnknownUnknown
maven/org.jspecify:jspecify UnknownUnknown
maven/org.springframework.boot:spring-boot-starter-test UnknownUnknown
maven/org.devlive.grantforge:grantforge-plugin-hdfs 2026.0.0 UnknownUnknown
maven/org.apache.maven.plugins:maven-dependency-plugin 2026.0.0 UnknownUnknown
maven/commons-cli:commons-cli 1.9.0 UnknownUnknown
maven/org.apache.hadoop.thirdparty:hadoop-shaded-guava 1.5.0 UnknownUnknown
maven/org.apache.hadoop.thirdparty:hadoop-shaded-protobuf_3_25 1.5.0 UnknownUnknown
maven/org.apache.hadoop:hadoop-client-api UnknownUnknown
maven/org.apache.hadoop:hadoop-client-runtime UnknownUnknown
maven/org.apache.hadoop:hadoop-hdfs UnknownUnknown
maven/org.apache.maven.plugins:maven-dependency-plugin UnknownUnknown
maven/org.apache.maven.plugins:maven-shade-plugin 3.6.1 🟢 5.2
Details
CheckScoreReason
Code-Review🟢 4Found 7/17 approved changesets -- score normalized to 4
Security-Policy🟢 10security policy file detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Maintained🟢 1030 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Packaging⚠️ -1packaging workflow not detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Binary-Artifacts🟢 8binaries present in source code
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
maven/org.apache.maven.plugins:maven-surefire-plugin UnknownUnknown
maven/org.devlive.grantforge:grantforge-agent-core UnknownUnknown
maven/org.jspecify:jspecify UnknownUnknown
maven/org.springframework.boot:spring-boot-starter-test UnknownUnknown
maven/org.apache.hadoop:hadoop-client-api UnknownUnknown
maven/org.apache.hadoop:hadoop-client-runtime UnknownUnknown
maven/org.apache.kerby:kerb-simplekdc UnknownUnknown
maven/org.apache.maven.plugins:maven-assembly-plugin UnknownUnknown
maven/org.apache.maven.plugins:maven-dependency-plugin UnknownUnknown
maven/org.apache.maven.plugins:maven-surefire-plugin UnknownUnknown
maven/org.devlive.grantforge:grantforge-plugin-api UnknownUnknown
maven/org.jspecify:jspecify UnknownUnknown
maven/org.springframework.boot:spring-boot-starter-test UnknownUnknown
maven/org.apache.hadoop:hadoop-client-api 3.5.0 UnknownUnknown
maven/org.apache.hadoop:hadoop-client-runtime 3.5.0 UnknownUnknown
maven/org.apache.kerby:kerb-simplekdc 2.1.2 🟢 7.7
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Security-Policy🟢 9security policy file detected
Packaging⚠️ -1packaging workflow not detected
Code-Review⚠️ 0Found 0/2 approved changesets -- score normalized to 0
Dependency-Update-Tool🟢 10update tool detected
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies🟢 10all dependencies are pinned
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Branch-Protection🟢 3branch protection is not maximal on development and all release branches
Signed-Releases⚠️ -1no releases found
Vulnerabilities🟢 100 existing vulnerabilities detected
SAST🟢 10SAST tool is run on all commits
CI-Tests🟢 914 out of 15 merged PRs checked by a CI test -- score normalized to 9
Contributors🟢 10project has 7 contributing companies or organizations
maven/org.apache.maven.plugins:maven-dependency-plugin 3.7.0 UnknownUnknown
maven/org.apache.maven.plugins:maven-gpg-plugin 3.2.8 🟢 3.8
Details
CheckScoreReason
Code-Review⚠️ 0Found 1/12 approved changesets -- score normalized to 0
Packaging⚠️ -1packaging workflow not detected
Maintained🟢 1023 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts⚠️ 0binaries present in source code
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 10security policy file detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
maven/org.apache.maven.plugins:maven-javadoc-plugin 3.12.0 🟢 5.1
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Code-Review⚠️ 2Found 4/20 approved changesets -- score normalized to 2
Security-Policy🟢 10security policy file detected
Maintained🟢 1030 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Binary-Artifacts🟢 9binaries present in source code
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
maven/org.apache.maven.plugins:maven-source-plugin 3.3.1 UnknownUnknown
maven/org.devlive.grantforge:grantforge-agent-core 2026.0.0 UnknownUnknown
maven/org.sonatype.central:central-publishing-maven-plugin 0.11.0 UnknownUnknown

Scanned Files

  • core/grantforge-agent-core/pom.xml
  • core/grantforge-plugin-host/pom.xml
  • core/grantforge-server/pom.xml
  • plugins/grantforge-agent-hdfs/pom.xml
  • plugins/grantforge-plugin-hdfs/pom.xml
  • pom.xml

The architecture rules forbid Optional.get, which the account page used, so every test job
failed on the identity module's architecture test.
Every API call reads the console snapshot; the evaluator only reads, so its transactions skip
flushing and dirty checking. The cached path's p99 was 1.014 ms against a 1 ms limit.
A server started from an IDE runs from build output folders and has no plugins folder, so no
plugin loaded. Without an explicit grantforge.plugins.directory and without a plugins folder
in the working directory, the host now uses the plugins folder of the repository its classes
were built in, and a built plugin module loads from target/classes with the dependencies its
build copied to target/plugin-lib. Server and service tests keep an empty plugins folder.
The HDFS service type used WebHDFS only. It now uses Hadoop's shaded client, so a service
names its cluster as Hadoop does (hdfs:// with HA nameservices, webhdfs://, swebhdfs://,
viewfs://), takes Ranger's settings under their names, and signs the lookup user in with
simple authentication or Kerberos by keytab or password. A real KDC tests the Kerberos logins.
The example plugin, a test fixture, showed up as a service type in IDE runs and was picked by
mistake. A module now loads as a plugin only when its build copied its libraries to
target/plugin-lib, as installable plugins do.
The server declared the plugin's zip as a dependency, which exists only from the package phase
on, so every CI job that stops at test failed to resolve it. The root pom now builds the plugin
before the server, which unpacks the zip at prepare-package for the release.
The Bouncy Castle Licence is the MIT license under its own name; the review reported it as
non-standard.
A push reports the branch's previous tip as the range start; after a force push that commit is
gone from the clone, and the check crashed on an invalid range. It now checks the branch from
where it left the default branch, as for a pull request, or the head alone without one.
Lookups can start from a configured directory (lookup.path) for users who may not list the root,
and stop with an error above lookup.max.entries instead of scanning huge folders. Cluster URIs,
authentication and the additional properties are validated as Hadoop will use them, and the
whole call is serialized because UGI keeps its security settings in static state. Lookup input
may be as long as a policy resource value.
An agent that denies access without a matching policy still enforces GrantForge's rules, so its
access events say so. The undetermined decision before a snapshot is now public for agents to
use.
grantforge-agent-hdfs authorizes HDFS access inside the NameNode with the signed local policies
of the agent core and ships access events; snapshot paths are also checked against the paths
they copy. The release carries it in agents/hdfs, and the documentation has a page on deploying
it.
// Lock the whole call: serializing just the login allows another service to change UGI's static
// authentication and auth-to-local settings before this service opens its own file system.
// Waiting is interruptible so the host's call timeout can cancel a queued lookup.
LOGIN.lockInterruptibly();
script/release/tag.sh checks the tree and the branch, sets the version everywhere, tags
v<version> and pushes it, and can move the branch on to the next version; --dry-run only
previews. The GitHub release notes are now every commit since the previous release, grouped by
type with links, instead of a changelog page; AuthX's bare version tags such as 1.0.6 count as
releases, marker tags do not.
The release profile adds sources, Javadoc and GPG signatures; the release workflow deploys them
to GitHub Packages and, when the Central Portal token and the GPG key are set as secrets, to
Maven Central through the central profile. That profile publishes only with
-Dcentral.skip=false, so a local build with Central credentials in settings.xml uploads nothing.
The example plugin, a test fixture, is never published.
The database jobs build a few modules with -pl, which leaves out the HDFS agent, so the server's
prepare-package could not copy it and every database job failed. grantforge.bundle.skip turns the
plugin and agent bundling off; the database tests set it, full builds keep bundling.
The HDFS agent brings hadoop-shaded-protobuf_3_25, licensed under Apache-2.0, BSD-3-Clause, MIT
and protobuf's BSD-style licence, all permissive; dependency review rejected the combination.
The README describes the rebuilt platform in English, with the same content in README.zh-CN.md,
and links the documentation at grantforge.devlive.org, where the site is now published.
maven-javadoc-plugin, which writes the release's Javadoc jars and is never shipped, combines
Apache-2.0 with BSD, MIT and public domain parts, which dependency review rejected.
@qianmoQ
qianmoQ merged commit 1980841 into dev Oct 5, 2026
80 of 81 checks passed
@qianmoQ
qianmoQ deleted the rebuild branch October 5, 2026 12:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants