mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-28 07:57:01 +00:00
feat(kms): add master key version to data key envelope contract (#5480)
* fix(kms): restore vault backend test compilation after timeout parameter PR #5472 added an attempt_timeout parameter to VaultKmsClient::new while PR #5474 landed tests still using the one-argument form, leaving 'cargo test -p rustfs-kms' unable to compile on main. Pass the same 30-second timeout the surrounding integration tests already use. * feat(kms): add master key version to data key envelope contract DataKeyEnvelope gains an optional master_key_version field recording which KEK version wrapped the DEK, so rotation-aware backends can load the matching historical material on decrypt. The field is skipped when None, keeping envelopes from non-rotating backends byte-identical to the historical seven-field JSON shape, and legacy envelopes without the field deserialize to None. The envelope discriminator marker is untouched, so mixed-format routing is unchanged in both directions. Adds the KeyVersionNotFound typed error for version-addressed material lookups that must fail closed instead of falling back to the current version. Refs rustfs/backlog#1565
This commit is contained in:
@@ -120,6 +120,10 @@ pub enum KmsError {
|
||||
/// Persisted key record uses a format version unknown to this build
|
||||
#[error("Unsupported key format version {version:?} for key {key_id}")]
|
||||
UnsupportedFormatVersion { key_id: String, version: String },
|
||||
|
||||
/// Requested master key version has no persisted material for the key
|
||||
#[error("Key version {version} not found for key {key_id}")]
|
||||
KeyVersionNotFound { key_id: String, version: u32 },
|
||||
}
|
||||
|
||||
impl KmsError {
|
||||
@@ -253,6 +257,14 @@ impl KmsError {
|
||||
version: version.into(),
|
||||
}
|
||||
}
|
||||
|
||||
/// Create a key version not found error
|
||||
pub fn key_version_not_found<S: Into<String>>(key_id: S, version: u32) -> Self {
|
||||
Self::KeyVersionNotFound {
|
||||
key_id: key_id.into(),
|
||||
version,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Convert from standard library errors
|
||||
|
||||
Reference in New Issue
Block a user