mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-02 11:29:17 +00:00
105af08a10
* test(kms): cover KV2 decrypt of pre-rotation envelopes offline The forward half of the rotation contract - an envelope written before a rotation still decrypts after it - was only exercised by the #[ignore] live-Vault tests, so CI never verified it. The offline layer only had the negative cases (a regressed version pointer must fail closed). Drive encrypt -> rotate -> decrypt over the scripted Vault responder, folding what each rotation writes back into the served state so the material the decrypt resolves is the material the rotation persisted. Also cover two consecutive rotations and pin that new envelopes carry the rotated version. * test(kms): cover Transit decrypt of pre-rotation data keys offline Vault owns the transit crypto, so the offline responder cannot prove the round trip - that stays in the #[ignore] live test. What it can pin is the client-side wiring: after a rotation records the version bump, decrypting a data key generated before it must forward the historical vault:v1: ciphertext to Vault byte for byte and return the material Vault hands back.