Skip to content

[fix][broker] Align partitioned topic truncate checks with non-partitioned topics - #26776

Merged
nodece merged 1 commit into
apache:masterfrom
lhotari:improve-partitioned-truncate-checks
Sep 30, 2026
Merged

nodece merged 1 commit into
apache:masterfrom
lhotari:improve-partitioned-truncate-checks

Conversation

@lhotari

@lhotari lhotari commented Sep 30, 2026

Copy link
Copy Markdown
Member

Motivation

Truncating a non-partitioned topic or a single partition validates tenant admin access before the topic is truncated. When a partitioned topic is truncated by its parent name, internalTruncateTopicAsync did not run that check itself. It read the partitioned topic metadata and then sent the truncate request to each partition through the broker's internal admin client. As a result, a partitioned topic was not checked the same way as a non-partitioned topic.

Modifications

  • PersistentTopicsBase#internalTruncateTopicAsync now calls validateAdminAccessForTenantAsync once at the start, before the partitioned topic metadata is read and before any partition is truncated. Partitioned topics, non-partitioned topics and single partitions now all use the same check.
  • Renamed internalTruncateNonPartitionedTopicAsync to the private helper truncateNonPartitionedTopicWithoutAccessCheckAsync. It now only checks topic ownership and truncates the topic, because the caller has already validated tenant admin access.

Verifying this change

  • Make sure that the change passes the CI checks.

This change added tests and can be verified as follows:

  • Added TopicAuthZTest#testTruncate, which runs for both partitioned and non-partitioned topics. It creates a subscription, publishes messages and then checks that:
    • a role with no permissions, a role with any single topic-level AuthAction, and a role with produce + consume all get NotAuthorizedException, and the subscription backlog is unchanged;
    • a tenant admin can truncate the topic, which clears the backlog;
    • a super user can truncate the topic.
  • The existing AdminApiTest truncate tests continue to pass.

Does this pull request potentially affect one of the following parts:

If the box was checked, please highlight the changes

  • Dependencies (add or upgrade a dependency)
  • The public API
  • The schema
  • The default values of configurations
  • The threading model
  • The binary protocol
  • The REST endpoints (truncating a partitioned topic now requires tenant admin access, the same as truncating a non-partitioned topic)
  • The admin CLI options
  • The metrics
  • Anything that affects deployment

…ioned topics

Truncating a non-partitioned topic or a single partition validates tenant
admin access, but truncating a partitioned topic by its parent name read the
partitioned topic metadata and sent the truncate request to each partition
through the broker's internal admin client without running that check itself.

Validate tenant admin access once at the start of internalTruncateTopicAsync,
before the partitioned topic metadata is read or any partition is truncated,
so that partitioned topics, non-partitioned topics and single partitions use
the same check. Rename internalTruncateNonPartitionedTopicAsync to the private
helper truncateNonPartitionedTopicWithoutAccessCheckAsync, which now only
checks topic ownership and truncates the topic.

Truncating a partitioned topic now requires tenant admin access, the same as
truncating a non-partitioned topic.

Add TopicAuthZTest#testTruncate for partitioned and non-partitioned topics:
roles holding only topic level permissions are rejected and the subscription
backlog is left intact, while tenant admins and super users can truncate.

Assisted-by: Claude Code
@nodece
nodece merged commit b8b5769 into apache:master Sep 30, 2026
44 checks passed
ascentstream-bot pushed a commit to ascentstream/pulsar that referenced this pull request Oct 1, 2026
ascentstream-bot pushed a commit to ascentstream/pulsar that referenced this pull request Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants