[ 
https://issues.apache.org/jira/browse/HDDS-16657?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Prince Raj updated HDDS-16657:
------------------------------
    Description: 
*Description* 
Ozone S3 Gateway currently accepts a bucket lifecycle configuration containing 
a {{Transition}} action to a storage class that is not supported by Ozone.

The {{PutBucketLifecycleConfiguration}} request returns HTTP 200 even though 
Ozone does not support S3 lifecycle transition actions for the specified 
storage class.

This allows users to successfully configure a lifecycle rule that Ozone cannot 
enforce.
h3. Reproduction

Create a lifecycle configuration containing a {{Transition}} action:
h3. {{}}
{code:java}
EXPIRE_DATE="2026-10-01T00:00:00Z" ozones3api 
put-bucket-lifecycle-configuration \ --bucket "$BUCKET" \ 
--lifecycle-configuration '{ "Rules": [ { "ID": "unsupported-transition", 
"Status": "Enabled", "Filter": { "Prefix": "" }, "Expiration": { "Date": 
"'"$EXPIRE_DATE"'" }, "Transitions": [ { "Days": 1, "StorageClass": "EC" } ] } 
] }' \ --debug{code}
The lifecycle request contains:
h3. {{}}
{code:java}
<Transition> <Days>1</Days> <StorageClass>EC</StorageClass> </Transition>{code}
h3. {{{}{}}}Actual Result

The {{PutBucketLifecycleConfiguration}} request succeeds with HTTP 200:
h3. {{}}
{code:java}
PUT ...?lifecycle HTTP/1.1" 200 0{code}
h3. {{}}

No validation error is returned to indicate that the lifecycle {{Transition}} 
action is unsupported.
h3. Expected Result

The {{PutBucketLifecycleConfiguration}} API should reject lifecycle 
configurations containing unsupported {{Transition}} actions.

The request should return an appropriate 4xx error, such as:
 * {{InvalidRequest}}
 * {{InvalidArgument}}
 * {{NotImplemented}}

The response should clearly indicate that the requested lifecycle 
{{Transition}} action or storage class is not supported.

For example:
h3. {{}}
{code:java}
Invalid lifecycle configuration: Transition actions are not supported.
or:

Invalid lifecycle configuration: storage class 'EC' is not supported for 
lifecycle transitions{code}
h3. Impact

Users can successfully configure lifecycle rules containing unsupported 
transition actions and receive HTTP 200, which incorrectly indicates that the 
configuration was accepted and is enforceable.

This can result in lifecycle rules being stored without the corresponding 
transition action being executable, potentially causing the configured 
lifecycle policy to be silently ineffective.
h3. Expected Behavior Summary
 * Validate lifecycle {{Transition}} actions during 
{{{}PutBucketLifecycleConfiguration{}}}.
 * Reject unsupported transition actions or storage classes at configuration 
time.
 * Return an appropriate 4xx error with a clear and actionable error message.
 * Do not return HTTP 200 for a lifecycle configuration containing an 
unsupported transition action.

h3.  

  was:
Ozone S3 Gateway currently accepts a bucket lifecycle configuration containing 
a {{Transition}} action to a storage class that is not supported by Ozone.

The {{PutBucketLifecycleConfiguration}} request returns HTTP 200 even though 
Ozone does not support S3 lifecycle transition actions for the specified 
storage class.

This allows users to successfully configure a lifecycle rule that Ozone cannot 
enforce.
h3.  


> Ozone S3: PutBucketLifecycleConfiguration accepts unsupported lifecycle 
> Transition actions
> ------------------------------------------------------------------------------------------
>
>                 Key: HDDS-16657
>                 URL: https://issues.apache.org/jira/browse/HDDS-16657
>             Project: Apache Ozone
>          Issue Type: Bug
>            Reporter: Prince Raj
>            Assignee: Priyesh Karatha
>            Priority: Major
>
> *Description* 
> Ozone S3 Gateway currently accepts a bucket lifecycle configuration 
> containing a {{Transition}} action to a storage class that is not supported 
> by Ozone.
> The {{PutBucketLifecycleConfiguration}} request returns HTTP 200 even though 
> Ozone does not support S3 lifecycle transition actions for the specified 
> storage class.
> This allows users to successfully configure a lifecycle rule that Ozone 
> cannot enforce.
> h3. Reproduction
> Create a lifecycle configuration containing a {{Transition}} action:
> h3. {{}}
> {code:java}
> EXPIRE_DATE="2026-10-01T00:00:00Z" ozones3api 
> put-bucket-lifecycle-configuration \ --bucket "$BUCKET" \ 
> --lifecycle-configuration '{ "Rules": [ { "ID": "unsupported-transition", 
> "Status": "Enabled", "Filter": { "Prefix": "" }, "Expiration": { "Date": 
> "'"$EXPIRE_DATE"'" }, "Transitions": [ { "Days": 1, "StorageClass": "EC" } ] 
> } ] }' \ --debug{code}
> The lifecycle request contains:
> h3. {{}}
> {code:java}
> <Transition> <Days>1</Days> <StorageClass>EC</StorageClass> 
> </Transition>{code}
> h3. {{{}{}}}Actual Result
> The {{PutBucketLifecycleConfiguration}} request succeeds with HTTP 200:
> h3. {{}}
> {code:java}
> PUT ...?lifecycle HTTP/1.1" 200 0{code}
> h3. {{}}
> No validation error is returned to indicate that the lifecycle {{Transition}} 
> action is unsupported.
> h3. Expected Result
> The {{PutBucketLifecycleConfiguration}} API should reject lifecycle 
> configurations containing unsupported {{Transition}} actions.
> The request should return an appropriate 4xx error, such as:
>  * {{InvalidRequest}}
>  * {{InvalidArgument}}
>  * {{NotImplemented}}
> The response should clearly indicate that the requested lifecycle 
> {{Transition}} action or storage class is not supported.
> For example:
> h3. {{}}
> {code:java}
> Invalid lifecycle configuration: Transition actions are not supported.
> or:
> Invalid lifecycle configuration: storage class 'EC' is not supported for 
> lifecycle transitions{code}
> h3. Impact
> Users can successfully configure lifecycle rules containing unsupported 
> transition actions and receive HTTP 200, which incorrectly indicates that the 
> configuration was accepted and is enforceable.
> This can result in lifecycle rules being stored without the corresponding 
> transition action being executable, potentially causing the configured 
> lifecycle policy to be silently ineffective.
> h3. Expected Behavior Summary
>  * Validate lifecycle {{Transition}} actions during 
> {{{}PutBucketLifecycleConfiguration{}}}.
>  * Reject unsupported transition actions or storage classes at configuration 
> time.
>  * Return an appropriate 4xx error with a clear and actionable error message.
>  * Do not return HTTP 200 for a lifecycle configuration containing an 
> unsupported transition action.
> h3.  



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to