mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-10-11 16:57:45 +02:00
* s3api: resolve volume data encryption in CopyObject SSE flows (#11646) * s3api: honor bucket-default KMS key on copy and fix transformed-upload metadata - Synthesize the destination bucket's default encryption as request headers before any SSE evaluation, so the configured KMS key ID and bucket-key setting reach the copy paths instead of only a boolean. - uploadTransformedChunkData returns the upload result so callers record the uploader's cipher key AND compression decision; a wrongly cleared IsCompressed made transformed copies unreadable. - decompressChunkVolumeCipher fails loudly when a compressed chunk does not decompress, instead of uploading still-compressed bytes marked uncompressed. - copyMultipartSSECChunk now strips the volume cipher and re-encrypts on upload like the other transform paths. - The ciphered inner upload now uses the caller's private BytesBuffer. * s3api: extract copy bucket-default header synthesis for coverage Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * s3api: test bucket-default encryption header synthesis on copy Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * s3api: validate copy encryption headers before bucket defaults and resolve empty KMS key * s3api: name the AWS-managed SSE-KMS default key once --------- Co-authored-by: Chris Lu <chrislusf@users.noreply.github.com> Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
37 lines
1.4 KiB
Go
37 lines
1.4 KiB
Go
package s3_constants
|
|
|
|
// Cryptographic constants
|
|
const (
|
|
// AES block and key sizes
|
|
AESBlockSize = 16 // 128 bits for AES block size (IV length)
|
|
AESKeySize = 32 // 256 bits for AES-256 keys
|
|
|
|
// SSE algorithm identifiers
|
|
SSEAlgorithmAES256 = "AES256"
|
|
SSEAlgorithmKMS = "aws:kms"
|
|
|
|
// SSEKMSDefaultKeyID is the AWS-managed key SSE-KMS requests resolve to
|
|
// when no key ID is given, matching AWS's aws/s3 managed key alias.
|
|
SSEKMSDefaultKeyID = "alias/aws/s3"
|
|
|
|
// SSE type identifiers for response headers and internal processing
|
|
SSETypeC = "SSE-C"
|
|
SSETypeKMS = "SSE-KMS"
|
|
SSETypeS3 = "SSE-S3"
|
|
|
|
// S3 multipart upload limits and offsets
|
|
S3MaxPartSize = 5 * 1024 * 1024 * 1024 // 5GB - AWS S3 maximum part size limit
|
|
|
|
// Multipart offset calculation for unique IV generation
|
|
// Using 8GB offset between parts (larger than max part size) to prevent IV collisions
|
|
// Critical for CTR mode encryption security in multipart uploads
|
|
PartOffsetMultiplier = int64(1) << 33 // 8GB per part offset
|
|
|
|
// KMS validation limits based on AWS KMS service constraints
|
|
MaxKMSEncryptionContextPairs = 10 // Maximum number of encryption context key-value pairs
|
|
MaxKMSKeyIDLength = 500 // Maximum length for KMS key identifiers
|
|
|
|
// S3 multipart upload limits based on AWS S3 service constraints
|
|
MaxS3MultipartParts = 10000 // Maximum number of parts in a multipart upload (1-10,000)
|
|
)
|