Huang Kuan Hao created HDDS-16661:
-------------------------------------
Summary: Validate unsigned S3 checksum trailer completion and
framing
Key: HDDS-16661
URL: https://issues.apache.org/jira/browse/HDDS-16661
Project: Apache Ozone
Issue Type: Improvement
Components: S3
Reporter: Huang Kuan Hao
Assignee: Huang Kuan Hao
{{UnsignedChunksInputStream}} stops at the zero-length completion chunk without
parsing the checksum trailer. It cannot check that the trailer declared by
{{x-amz-trailer}} is present or complete.
The write guard reads only the decoded payload length and explicitly completes
signed streams. Extend completion for unsigned trailer uploads so validation
runs before commit, even when the payload length has already been satisfied.
For {{STREAMING-UNSIGNED-PAYLOAD-TRAILER}}, parse the declared trailer, require
a matching header name, validate checksum encoding and length, and require the
final terminator. Make the parsed checksum available to payload checksum
verification.
Cover missing trailers, mismatched names, malformed values, truncated input,
and valid AWS SDK uploads through PutObject and UploadPart. Preserve explicitly
supported modes that do not require a trailer.
Payload checksum comparison is tracked separately; unsigned uploads do not
require a trailer signature.
https://github.com/apache/ozone/pull/11222#pullrequestreview-5344295815
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]