Huang Kuan Hao created HDDS-16660:
-------------------------------------
Summary: Validate S3 trailing checksums against uploaded payloads
Key: HDDS-16660
URL: https://issues.apache.org/jira/browse/HDDS-16660
Project: Apache Ozone
Issue Type: Improvement
Components: S3
Reporter: Huang Kuan Hao
Assignee: Huang Kuan Hao
HDDS-15142 verifies the signed trailer's HMAC, but does not calculate the
declared checksum over the uploaded payload. A correctly signed trailer can
therefore contain a checksum that does not match the data.
Calculate the selected checksum while streaming and compare it with the decoded
trailer value before committing the object or multipart part. Validate checksum
encoding and decoded length, and reject mismatches with the appropriate S3
error.
Cover valid uploads, empty objects, malformed checksum values, and a correctly
authenticated trailer containing an incorrect checksum. Exercise both PutObject
and UploadPart and verify that rejected uploads are not committed. Keep memory
usage bounded.
Specify coverage for the trailer algorithms already recognized by S3 Gateway
(CRC32, CRC32C, CRC64NVME, SHA1, SHA256). Reuse existing CRC32/CRC32C
facilities where applicable; CRC64NVME calculation needs a separate
implementation/dependency assessment. Do not silently accept an algorithm
without validating it. Coordinate unsigned-upload coverage with the unsigned
trailer framing task. Checksum persistence and retrieval are separate work.
https://github.com/apache/ozone/pull/11222#pullrequestreview-5344295815
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]