{"record":{"id":"7c1e484404af65c6","repo":"apache/iceberg","slug":"failed-to-get-hadoop-user","errorCode":null,"errorMessage":"Failed to get Hadoop user","messagePattern":"Failed to get Hadoop user","errorType":"console","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"hive-metastore/src/main/java/org/apache/iceberg/hive/HiveHadoopUtil.java","lineNumber":37,"sourceCode":"package org.apache.iceberg.hive;\n\nimport java.io.IOException;\nimport org.apache.hadoop.security.UserGroupInformation;\nimport org.slf4j.Logger;\nimport org.slf4j.LoggerFactory;\n\npublic class HiveHadoopUtil {\n\n  private static final Logger LOG = LoggerFactory.getLogger(HiveHadoopUtil.class);\n\n  private HiveHadoopUtil() {}\n\n  public static String currentUser() {\n    String username = null;\n    try {\n      username = UserGroupInformation.getCurrentUser().getShortUserName();\n    } catch (IOException e) {\n      LOG.warn(\"Failed to get Hadoop user\", e);\n    }\n\n    if (username != null) {\n      return username;\n    } else {\n      LOG.warn(\"Hadoop user is null, defaulting to user.name\");\n      return System.getProperty(\"user.name\");\n    }\n  }\n}\n","sourceCodeStart":19,"sourceCodeEnd":48,"githubUrl":"https://github.com/apache/iceberg/blob/86d9c8fc543e7c56c9f624eb725f76c9baff9570/hive-metastore/src/main/java/org/apache/iceberg/hive/HiveHadoopUtil.java#L19-L48","documentation":"HiveHadoopUtil.currentUser resolves the Hadoop user via UserGroupInformation.getCurrentUser(). If Hadoop's UGI initialization fails (IOException), the library logs this warning and falls through to alternate resolution (user.name system property). It is a degradation, not a thrown error.","triggerScenarios":"Calling code that relies on HiveHadoopUtil.currentUser() (e.g. HiveTableOperations for ownership/lock metadata) when UserGroupInformation cannot determine the current user — UGI not initialized, no Kerberos/login context, or Hadoop config missing.","commonSituations":"Running outside a Hadoop-configured environment (no core-site.xml on classpath); using the hive-metastore catalog from a non-Hadoop runtime; missing hadoop-auth setup in containers.","solutions":["Ensure Hadoop configuration (core-site.xml / hdfs-site.xml) is on the classpath so UGI initializes","Set the 'user.name' system property so the fallback returns a sensible identity","Call UserGroupInformation.setConfiguration(conf) and/or ugi.loginUserFromKeytab before catalog operations","If Kerberos, verify keytab/principal settings and that the login succeeds"],"exampleFix":"// before\nString user = HiveHadoopUtil.currentUser(); // null-ish / warns\n// after\nUserGroupInformation.setConfiguration(new Configuration());\nUserGroupInformation.loginUserFromKeytab(principal, keytabPath);\nString user = HiveHadoopUtil.currentUser();","handlingStrategy":"fallback","validationCode":"try { UserGroupInformation.getCurrentUser(); } catch (IOException e) { /* UGI not usable — initialize before catalog use */ }","typeGuard":null,"tryCatchPattern":"try { UserGroupInformation.getCurrentUser().getShortUserName(); } catch (IOException e) { UserGroupInformation.setConfiguration(new Configuration()); /* retry */ }","preventionTips":["Initialize UserGroupInformation with Hadoop conf before catalog operations","Login via keytab for Kerberos environments","Set user.name system property as a safety net"],"tags":["hadoop","security","ugi","user"],"backgroundTag":"missing-credentials","analyzedSha":"86d9c8fc543e7c56c9f624eb725f76c9baff9570","analyzedAt":"2026-09-12T00:46:39.097Z","contentChangedAt":"2026-09-12T00:46:39.097Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}