[
https://issues.apache.org/jira/browse/HDDS-16657?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Prince Raj updated HDDS-16657:
------------------------------
Description:
*Description*
Ozone S3 Gateway currently accepts a bucket lifecycle configuration containing
a {{Transition}} action to a storage class that is not supported by Ozone.
The {{PutBucketLifecycleConfiguration}} request returns HTTP 200 even though
Ozone does not support S3 lifecycle transition actions for the specified
storage class.
This allows users to successfully configure a lifecycle rule that Ozone cannot
enforce.
h3. Reproduction
Create a lifecycle configuration containing a {{Transition}} action:
h3. {{}}
{code:java}
EXPIRE_DATE="2026-10-01T00:00:00Z" ozones3api
put-bucket-lifecycle-configuration \ --bucket "$BUCKET" \
--lifecycle-configuration '{ "Rules": [ { "ID": "unsupported-transition",
"Status": "Enabled", "Filter": { "Prefix": "" }, "Expiration": { "Date":
"'"$EXPIRE_DATE"'" }, "Transitions": [ { "Days": 1, "StorageClass": "EC" } ] }
] }' \ --debug{code}
The lifecycle request contains:
h3. {{}}
{code:java}
<Transition> <Days>1</Days> <StorageClass>EC</StorageClass> </Transition>{code}
h3. {{{}{}}}Actual Result
The {{PutBucketLifecycleConfiguration}} request succeeds with HTTP 200:
h3. {{}}
{code:java}
PUT ...?lifecycle HTTP/1.1" 200 0{code}
h3. {{}}
No validation error is returned to indicate that the lifecycle {{Transition}}
action is unsupported.
h3. Expected Result
The {{PutBucketLifecycleConfiguration}} API should reject lifecycle
configurations containing unsupported {{Transition}} actions.
The request should return an appropriate 4xx error, such as:
* {{InvalidRequest}}
* {{InvalidArgument}}
* {{NotImplemented}}
The response should clearly indicate that the requested lifecycle
{{Transition}} action or storage class is not supported.
For example:
h3. {{}}
{code:java}
Invalid lifecycle configuration: Transition actions are not supported.
or:
Invalid lifecycle configuration: storage class 'EC' is not supported for
lifecycle transitions{code}
h3. Impact
Users can successfully configure lifecycle rules containing unsupported
transition actions and receive HTTP 200, which incorrectly indicates that the
configuration was accepted and is enforceable.
This can result in lifecycle rules being stored without the corresponding
transition action being executable, potentially causing the configured
lifecycle policy to be silently ineffective.
h3. Expected Behavior Summary
* Validate lifecycle {{Transition}} actions during
{{{}PutBucketLifecycleConfiguration{}}}.
* Reject unsupported transition actions or storage classes at configuration
time.
* Return an appropriate 4xx error with a clear and actionable error message.
* Do not return HTTP 200 for a lifecycle configuration containing an
unsupported transition action.
h3.
was:
Ozone S3 Gateway currently accepts a bucket lifecycle configuration containing
a {{Transition}} action to a storage class that is not supported by Ozone.
The {{PutBucketLifecycleConfiguration}} request returns HTTP 200 even though
Ozone does not support S3 lifecycle transition actions for the specified
storage class.
This allows users to successfully configure a lifecycle rule that Ozone cannot
enforce.
h3.
> Ozone S3: PutBucketLifecycleConfiguration accepts unsupported lifecycle
> Transition actions
> ------------------------------------------------------------------------------------------
>
> Key: HDDS-16657
> URL: https://issues.apache.org/jira/browse/HDDS-16657
> Project: Apache Ozone
> Issue Type: Bug
> Reporter: Prince Raj
> Assignee: Priyesh Karatha
> Priority: Major
>
> *Description*
> Ozone S3 Gateway currently accepts a bucket lifecycle configuration
> containing a {{Transition}} action to a storage class that is not supported
> by Ozone.
> The {{PutBucketLifecycleConfiguration}} request returns HTTP 200 even though
> Ozone does not support S3 lifecycle transition actions for the specified
> storage class.
> This allows users to successfully configure a lifecycle rule that Ozone
> cannot enforce.
> h3. Reproduction
> Create a lifecycle configuration containing a {{Transition}} action:
> h3. {{}}
> {code:java}
> EXPIRE_DATE="2026-10-01T00:00:00Z" ozones3api
> put-bucket-lifecycle-configuration \ --bucket "$BUCKET" \
> --lifecycle-configuration '{ "Rules": [ { "ID": "unsupported-transition",
> "Status": "Enabled", "Filter": { "Prefix": "" }, "Expiration": { "Date":
> "'"$EXPIRE_DATE"'" }, "Transitions": [ { "Days": 1, "StorageClass": "EC" } ]
> } ] }' \ --debug{code}
> The lifecycle request contains:
> h3. {{}}
> {code:java}
> <Transition> <Days>1</Days> <StorageClass>EC</StorageClass>
> </Transition>{code}
> h3. {{{}{}}}Actual Result
> The {{PutBucketLifecycleConfiguration}} request succeeds with HTTP 200:
> h3. {{}}
> {code:java}
> PUT ...?lifecycle HTTP/1.1" 200 0{code}
> h3. {{}}
> No validation error is returned to indicate that the lifecycle {{Transition}}
> action is unsupported.
> h3. Expected Result
> The {{PutBucketLifecycleConfiguration}} API should reject lifecycle
> configurations containing unsupported {{Transition}} actions.
> The request should return an appropriate 4xx error, such as:
> * {{InvalidRequest}}
> * {{InvalidArgument}}
> * {{NotImplemented}}
> The response should clearly indicate that the requested lifecycle
> {{Transition}} action or storage class is not supported.
> For example:
> h3. {{}}
> {code:java}
> Invalid lifecycle configuration: Transition actions are not supported.
> or:
> Invalid lifecycle configuration: storage class 'EC' is not supported for
> lifecycle transitions{code}
> h3. Impact
> Users can successfully configure lifecycle rules containing unsupported
> transition actions and receive HTTP 200, which incorrectly indicates that the
> configuration was accepted and is enforceable.
> This can result in lifecycle rules being stored without the corresponding
> transition action being executable, potentially causing the configured
> lifecycle policy to be silently ineffective.
> h3. Expected Behavior Summary
> * Validate lifecycle {{Transition}} actions during
> {{{}PutBucketLifecycleConfiguration{}}}.
> * Reject unsupported transition actions or storage classes at configuration
> time.
> * Return an appropriate 4xx error with a clear and actionable error message.
> * Do not return HTTP 200 for a lifecycle configuration containing an
> unsupported transition action.
> h3.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]