Siyao Meng created HDDS-16436:
---------------------------------

             Summary: LEGACY bucket lifecycle move to trash with a stale 
updateID can destructively trash a live key
                 Key: HDDS-16436
                 URL: https://issues.apache.org/jira/browse/HDDS-16436
             Project: Apache Ozone
          Issue Type: Bug
            Reporter: Siyao Meng


h3. Finding
The LEGACY (non-FSO) rename handler lacks the per-key updateID guard that the 
delete and FSO-rename paths enforce, so a lifecycle move-to-trash carrying a 
scan-captured stale updateID destructively moves the client's live, overwritten 
(or delete+recreated) key into trash where reads return not-found and retention 
eventually purges it; the move is durably committed with no automatic recovery. 
Reachable in the default configuration (move-to-trash enabled by default) on a 
LEGACY bucket with a lifecycle rule and a post-scan overwrite. This is silent 
client-visible data loss.

h3. Classification
* Verdict: REPRODUCED
* Severity: Critical
* Source: Specula TLA+ model checking and confirmation debate, finding CR-4

h3. Reproduce
{noformat}
Ozone commit: 9fbf9ee0cb1bd2f5f5d437b6719ebbe5309351fb
Specula:      v1.1.0 (commit c6aa3dfa)
Target:       om-key-lifecycle
Guidance:     
campaigns/ozone-9fbf9ee/targets/006-om-key-lifecycle/.prompt-extra.md
{noformat}
{code:none}
specula run --agent=claude-code --effort=high --keep-original --max-parallel=2 \
  --enable-reviews --confirm-debate --tlc-memory-limit=28G --tlc-worker-limit=8 
\
  "om-key-lifecycle|apache/ozone|Java|Use the target-specific .prompt-extra.md"
{code}
Discovered under HDDS-16429 (Specula TLA+ verification effort). The TLA+ 
specification, counterexample, and confirmation debate live in the Specula run 
artifacts.

Generated with Specula (Claude Opus 4.8).



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to