Huang Kuan Hao created HDDS-16660:
-------------------------------------

             Summary: Validate S3 trailing checksums against uploaded payloads
                 Key: HDDS-16660
                 URL: https://issues.apache.org/jira/browse/HDDS-16660
             Project: Apache Ozone
          Issue Type: Improvement
          Components: S3
            Reporter: Huang Kuan Hao
            Assignee: Huang Kuan Hao


HDDS-15142 verifies the signed trailer's HMAC, but does not calculate the 
declared checksum over the uploaded payload. A correctly signed trailer can 
therefore contain a checksum that does not match the data.

Calculate the selected checksum while streaming and compare it with the decoded 
trailer value before committing the object or multipart part. Validate checksum 
encoding and decoded length, and reject mismatches with the appropriate S3 
error.

Cover valid uploads, empty objects, malformed checksum values, and a correctly 
authenticated trailer containing an incorrect checksum. Exercise both PutObject 
and UploadPart and verify that rejected uploads are not committed. Keep memory 
usage bounded.

Specify coverage for the trailer algorithms already recognized by S3 Gateway 
(CRC32, CRC32C, CRC64NVME, SHA1, SHA256). Reuse existing CRC32/CRC32C 
facilities where applicable; CRC64NVME calculation needs a separate 
implementation/dependency assessment. Do not silently accept an algorithm 
without validating it. Coordinate unsigned-upload coverage with the unsigned 
trailer framing task. Checksum persistence and retrieval are separate work.

https://github.com/apache/ozone/pull/11222#pullrequestreview-5344295815



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to