Files
rustfs/docs
唐小鸭 3e69654f91 fix(kms): refuse key ids that leave the key prefix on the Vault backends (#7727)
Only the Local backend refused a key identifier containing a path
separator. On Vault KV2 a create with the name bad/name succeeded and
produced a nested KV2 path that the listing then reported as a
directory rather than a key, and an identifier containing .. addressed
a record outside the configured key prefix once the HTTP client
normalised the URL; Vault Transit built its transit key name and its
metadata path from the same unchecked identifier.

Lift the Local backend's containment rule into a shared segment check
(empty, /, backslash, NUL, . and ..) and apply it at the single point
where each backend turns the identifier into a path or a Transit key
name, so create, describe, encrypt, delete and the metadata writes all
refuse with InvalidKey before any request reaches Vault. The admin API
already maps that to 400. The AWS backend is untouched: it addresses
keys by ARN and alias, both of which contain /.

Refs rustfs/backlog#2474 (KMS-213 CreateNegatives on vault-kv2).

Co-authored-by: Hauser <housemecn@gmail.com>
(cherry picked from commit 2f2e775655)
2026-09-14 23:18:32 +08:00
..

Documentation

Use the focused indexes rather than treating this directory as an unordered collection:

Operations

Operational runbooks live under operations/. Replication operators should start with:

Runbook Use it for
Site replication operations Health fields, pending operations, outage recovery, re-pair admission, IAM/SSE boundaries, and upgrades.
Replication target check Validating an S3 destination and version fidelity before enabling replication.
Replication object size limits Multipart routing, large-object limits, and retry characteristics.
Replication outbound transport Integrity headers, generic target behavior, and transport knobs.

For persisted administrator bucket tasks and bucket recreation, see Bucket heal recovery.

For disk replacement across VM restarts and schema 5/6 maintenance migration, see Replacement generation recovery.

For historical GET timeouts during PUT or Heal, see Object lock contention diagnostics.

Other runbooks remain grouped by filename in operations/; architecture pages link to the relevant runbook where a cross-boundary procedure is required.

For storage dashboards, see Storage metrics and observer selection: drive ownership, snapshot freshness, counter queries, and rolling upgrades.

For optional shard commitments, see Independent shard integrity rollout: activation, legacy repair results, multipart mode changes, and rollback limits.