{"record":{"id":"ee8b4050d27d7a5d","repo":"apache/iceberg","slug":"hadoop-user-is-null-defaulting-to-user-name","errorCode":null,"errorMessage":"Hadoop user is null, defaulting to user.name","messagePattern":"Hadoop user is null, defaulting to user\\.name","errorType":"console","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"hive-metastore/src/main/java/org/apache/iceberg/hive/HiveHadoopUtil.java","lineNumber":43,"sourceCode":"\npublic class HiveHadoopUtil {\n\n  private static final Logger LOG = LoggerFactory.getLogger(HiveHadoopUtil.class);\n\n  private HiveHadoopUtil() {}\n\n  public static String currentUser() {\n    String username = null;\n    try {\n      username = UserGroupInformation.getCurrentUser().getShortUserName();\n    } catch (IOException e) {\n      LOG.warn(\"Failed to get Hadoop user\", e);\n    }\n\n    if (username != null) {\n      return username;\n    } else {\n      LOG.warn(\"Hadoop user is null, defaulting to user.name\");\n      return System.getProperty(\"user.name\");\n    }\n  }\n}\n","sourceCodeStart":25,"sourceCodeEnd":48,"githubUrl":"https://github.com/apache/iceberg/blob/86d9c8fc543e7c56c9f624eb725f76c9baff9570/hive-metastore/src/main/java/org/apache/iceberg/hive/HiveHadoopUtil.java#L25-L48","documentation":"Companion fallback of currentUser(): after a failed UGI lookup, the short username is still null, so the code logs this warning and returns the JVM 'user.name' system property instead. Identity comes from the OS/JVM rather than Hadoop, which may not match the intended metastore user.","triggerScenarios":"UserGroupInformation.getCurrentUser() throws IOException AND the caught path leaves username null, so the else branch reads System.getProperty(\"user.name\").","commonSituations":"Containers where the OS user (e.g. 'root' or a UID) differs from the Kerberos/Hadoop identity expected by HMS; entitlement or ownership checks then record the wrong user.","solutions":["Pass -Duser.name=<hadoop-user> as a JVM argument to align the fallback identity","Fix the root cause: put Hadoop config on the classpath or initialize UGI so getCurrentUser works","Verify which user HMS sees (e.g. in metastore logs) and align configuration accordingly"],"exampleFix":"// before\njava -jar app.jar\n// after\njava -Duser.name=iceberg_svc -jar app.jar","handlingStrategy":"validation","validationCode":"String user = System.getProperty(\"user.name\"); if (user == null || user.equals(\"root\")) { /* fix -Duser.name before running */ }","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Set -Duser.name to the intended service identity in container/launch scripts","Verify HMS-side principal alignment when using Kerberos","Log the resolved identity at startup and compare against expected"],"tags":["hadoop","user","fallback","configuration"],"backgroundTag":"missing-credentials","analyzedSha":"86d9c8fc543e7c56c9f624eb725f76c9baff9570","analyzedAt":"2026-09-12T00:46:39.097Z","contentChangedAt":"2026-09-12T00:46:39.097Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}