Huang Kuan Hao created HDDS-16661:
-------------------------------------

             Summary: Validate unsigned S3 checksum trailer completion and 
framing
                 Key: HDDS-16661
                 URL: https://issues.apache.org/jira/browse/HDDS-16661
             Project: Apache Ozone
          Issue Type: Improvement
          Components: S3
            Reporter: Huang Kuan Hao
            Assignee: Huang Kuan Hao


{{UnsignedChunksInputStream}} stops at the zero-length completion chunk without 
parsing the checksum trailer. It cannot check that the trailer declared by 
{{x-amz-trailer}} is present or complete.

The write guard reads only the decoded payload length and explicitly completes 
signed streams. Extend completion for unsigned trailer uploads so validation 
runs before commit, even when the payload length has already been satisfied.

For {{STREAMING-UNSIGNED-PAYLOAD-TRAILER}}, parse the declared trailer, require 
a matching header name, validate checksum encoding and length, and require the 
final terminator. Make the parsed checksum available to payload checksum 
verification.

Cover missing trailers, mismatched names, malformed values, truncated input, 
and valid AWS SDK uploads through PutObject and UploadPart. Preserve explicitly 
supported modes that do not require a trailer.

Payload checksum comparison is tracked separately; unsigned uploads do not 
require a trailer signature.

https://github.com/apache/ozone/pull/11222#pullrequestreview-5344295815



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to