<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Ranger policies on HDFS (READ/WRITE/EXECUTE) in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Ranger-policies-on-HDFS-READ-WRITE-EXECUTE/m-p/214462#M176374</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;With a regular filesystem, if I create a directory '/data/dir1/dir2/', a user without the 'execute' permission on '/data/dir1' is denied access to '/data/dir1/dir2/' even if he's granted access to '/data/dir1/dir2/' itself, i.e. he has not the right to traverse the tree. &lt;/P&gt;&lt;P&gt;But not with Ranger. If my filesystem permissions are set to '000' for all the directories and I have a policy granting access to  '/data/dir1/dir2/' to my user, this user should not be able to see '/data/dir1/dir2/' since he has no access to '/data/dir1/'. But he can!&lt;/P&gt;&lt;P&gt;1. Is this the expected behavior?&lt;/P&gt;&lt;P&gt;2. If so, what is the meaning of the 'execute' permission in Ranger?&lt;/P&gt;&lt;P&gt;3. How to get my expected behavior?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EDITED&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;All the 
directories have their permissions set to '000' in my filesystem, so 
without 
Ranger, no user has access to any of them. Then I create a
 policy in Ranger for '/dir1/dir2/' with 'rwx' permissions for user A. 
User A has now access to this directory, contrary to what I was 
expecting. Because since there is no policy with the 'execute' 
permission for '/dir1/', I 
was expecting that user A couldn't access '/dir1/dir2' (because on a 
regular filesystem, one need to traverse all the hierarchy of 
directories and so to have the 'execute' permission on all the parents).&lt;/P&gt;</description>
    <pubDate>Mon, 09 Apr 2018 16:59:14 GMT</pubDate>
    <dc:creator>c_inconnu1</dc:creator>
    <dc:date>2018-04-09T16:59:14Z</dc:date>
  </channel>
</rss>

