2015-12-22 14:48:03 +08:00
|
|
|
<!DOCTYPE import-control PUBLIC
|
|
|
|
"-//Puppy Crawl//DTD Import Control 1.1//EN"
|
|
|
|
"http://www.puppycrawl.com/dtds/import_control_1_1.dtd">
|
|
|
|
<!--
|
2022-02-17 14:35:36 +08:00
|
|
|
Licensed to the Apache Software Foundation (ASF) under one or more
|
|
|
|
contributor license agreements. See the NOTICE file distributed with
|
|
|
|
this work for additional information regarding copyright ownership.
|
|
|
|
The ASF licenses this file to You under the Apache License, Version 2.0
|
|
|
|
(the "License"); you may not use this file except in compliance with
|
|
|
|
the License. You may obtain a copy of the License at
|
|
|
|
|
|
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
See the License for the specific language governing permissions and
|
|
|
|
limitations under the License.
|
2015-12-22 14:48:03 +08:00
|
|
|
-->
|
|
|
|
|
|
|
|
<import-control pkg="kafka">
|
|
|
|
|
|
|
|
<!-- THINK HARD ABOUT THE LAYERING OF THE PROJECT BEFORE CHANGING THIS FILE -->
|
|
|
|
|
|
|
|
<!-- common library dependencies -->
|
|
|
|
<allow pkg="java" />
|
|
|
|
<allow pkg="scala" />
|
|
|
|
<allow pkg="javax.management" />
|
|
|
|
<allow pkg="org.slf4j" />
|
|
|
|
<allow pkg="org.junit" />
|
|
|
|
<allow pkg="java.security" />
|
|
|
|
<allow pkg="javax.net.ssl" />
|
|
|
|
<allow pkg="javax.security" />
|
|
|
|
|
|
|
|
<allow pkg="kafka.common" />
|
|
|
|
<allow pkg="kafka.utils" />
|
|
|
|
<allow pkg="kafka.serializer" />
|
|
|
|
<allow pkg="org.apache.kafka.common" />
|
|
|
|
|
2020-02-14 02:21:14 +08:00
|
|
|
<!-- see KIP-544 for why KafkaYammerMetrics should be used instead of the global default yammer metrics registry
|
|
|
|
https://cwiki.apache.org/confluence/display/KAFKA/KIP-544%3A+Make+metrics+exposed+via+JMX+configurable -->
|
|
|
|
<disallow class="com.yammer.metrics.Metrics" />
|
|
|
|
<allow pkg="com.yammer.metrics"/>
|
|
|
|
|
2021-03-22 23:45:56 +08:00
|
|
|
<subpackage name="testkit">
|
|
|
|
<allow pkg="kafka.metrics"/>
|
|
|
|
<allow pkg="kafka.raft"/>
|
|
|
|
<allow pkg="kafka.server"/>
|
|
|
|
<allow pkg="kafka.tools"/>
|
|
|
|
<allow pkg="org.apache.kafka.clients"/>
|
|
|
|
<allow pkg="org.apache.kafka.controller"/>
|
|
|
|
<allow pkg="org.apache.kafka.raft"/>
|
|
|
|
<allow pkg="org.apache.kafka.test"/>
|
|
|
|
<allow pkg="org.apache.kafka.metadata" />
|
|
|
|
<allow pkg="org.apache.kafka.metalog" />
|
2021-05-12 00:58:28 +08:00
|
|
|
<allow pkg="org.apache.kafka.server.common" />
|
2021-03-22 23:45:56 +08:00
|
|
|
</subpackage>
|
|
|
|
|
2015-12-22 14:48:03 +08:00
|
|
|
<subpackage name="tools">
|
2017-09-23 12:05:16 +08:00
|
|
|
<allow pkg="org.apache.kafka.clients.admin" />
|
2016-08-02 11:12:22 +08:00
|
|
|
<allow pkg="kafka.admin" />
|
2015-12-22 14:48:03 +08:00
|
|
|
<allow pkg="joptsimple" />
|
2016-08-02 11:12:22 +08:00
|
|
|
<allow pkg="org.apache.kafka.clients.consumer" />
|
2015-12-22 14:48:03 +08:00
|
|
|
</subpackage>
|
|
|
|
|
2017-04-27 05:10:38 +08:00
|
|
|
<subpackage name="coordinator">
|
|
|
|
<allow class="kafka.server.MetadataCache" />
|
|
|
|
</subpackage>
|
|
|
|
|
2015-12-22 14:48:03 +08:00
|
|
|
<subpackage name="examples">
|
|
|
|
<allow pkg="org.apache.kafka.clients" />
|
|
|
|
</subpackage>
|
|
|
|
|
MINOR: Make ReplicaManager, LogManager, KafkaApis easier to construct (#11320)
The ReplicaManager, LogManager, and KafkaApis class all have many
constructor parameters. It is often difficult to add or remove a
parameter, since there are so many locations that need to be updated. In
order to address this problem, we should use named parameters when
constructing these objects from Scala code. This will make it easy to
add new optional parameters without modifying many test cases. It will
also make it easier to read git diffs and PRs, since the parameters will
have names next to them. Since Java does not support named paramters,
this PR adds several Builder classes which can be used to achieve the
same effect.
ReplicaManager also had a secondary constructor, which this PR removes.
The function of the secondary constructor was just to provide some
default parameters for the main constructor. However, it is simpler just
to actually use default parameters.
Reviewers: David Arthur <mumrah@gmail.com>
2021-09-18 05:12:31 +08:00
|
|
|
<subpackage name="server">
|
|
|
|
<subpackage name="builders">
|
|
|
|
<allow pkg="kafka" />
|
|
|
|
<allow pkg="org.apache.kafka" />
|
|
|
|
</subpackage>
|
|
|
|
</subpackage>
|
|
|
|
|
2021-02-10 00:49:33 +08:00
|
|
|
<subpackage name="test">
|
2021-03-05 03:28:20 +08:00
|
|
|
<allow pkg="org.apache.kafka.controller"/>
|
|
|
|
<allow pkg="org.apache.kafka.metadata"/>
|
KAFKA-13646; Implement KIP-801: KRaft authorizer (#11649)
Currently, when using KRaft mode, users still have to have an Apache ZooKeeper instance if they want to use AclAuthorizer. We should have a built-in Authorizer for KRaft mode that does not depend on ZooKeeper. This PR introduces such an authorizer, called StandardAuthorizer. See KIP-801 for a full description of the new Authorizer design.
Authorizer.java: add aclCount API as described in KIP-801. StandardAuthorizer is currently the only authorizer that implements it, but eventually we may implement it for AclAuthorizer and others as well.
ControllerApis.scala: fix a bug where createPartitions was authorized using CREATE on the topic resource rather than ALTER on the topic resource as it should have been.
QuorumTestHarness: rename the controller endpoint to CONTROLLER for consistency (the brokers already called it that). This is relevant in AuthorizerIntegrationTest where we are examining endpoint names. Also add the controllerServers call.
TestUtils.scala: adapt the ACL functions to be usable from KRaft, by ensuring that they use the Authorizer from the current active controller.
BrokerMetadataPublisher.scala: add broker-side ACL application logic.
Controller.java: add ACL APIs. Also add a findAllTopicIds API in order to make junit tests that use KafkaServerTestHarness#getTopicNames and KafkaServerTestHarness#getTopicIds work smoothly.
AuthorizerIntegrationTest.scala: convert over testAuthorizationWithTopicExisting (more to come soon)
QuorumController.java: add logic for replaying ACL-based records. This means storing them in the new AclControlManager object, and integrating them into controller snapshots. It also means applying the changes in the Authorizer, if one is configured. In renounce, when reverting to a snapshot, also set newBytesSinceLastSnapshot to 0.
Reviewers: YeonCheol Jang <YeonCheolGit@users.noreply.github.com>, Jason Gustafson <jason@confluent.io>
2022-02-10 02:38:52 +08:00
|
|
|
<allow pkg="org.apache.kafka.server.authorizer"/>
|
2021-02-10 00:49:33 +08:00
|
|
|
<allow pkg="kafka.test.annotation"/>
|
|
|
|
<allow pkg="kafka.test.junit"/>
|
|
|
|
<allow pkg="kafka.network"/>
|
|
|
|
<allow pkg="kafka.api"/>
|
|
|
|
<allow pkg="kafka.server"/>
|
|
|
|
<allow pkg="org.apache.kafka.clients.admin"/>
|
|
|
|
<allow pkg="integration.kafka.server" class="IntegrationTestHelper"/>
|
|
|
|
<subpackage name="annotation">
|
|
|
|
<allow pkg="kafka.test"/>
|
|
|
|
</subpackage>
|
|
|
|
<subpackage name="junit">
|
|
|
|
<allow pkg="kafka.test"/>
|
2021-03-22 23:45:56 +08:00
|
|
|
<allow pkg="kafka.testkit"/>
|
|
|
|
<allow pkg="org.apache.kafka.clients"/>
|
|
|
|
<allow pkg="org.apache.kafka.metadata" />
|
2021-02-10 00:49:33 +08:00
|
|
|
</subpackage>
|
|
|
|
</subpackage>
|
2015-12-22 14:48:03 +08:00
|
|
|
</import-control>
|