mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-07 05:43:14 +00:00
d7b19131d8
fix(ecstore): read the persisted SSE-C nonce in the GET decrypt resolver #4576 moved SSE-C encryption to a random per-encryption nonce persisted in object metadata and taught the rustfs-layer decrypt resolver to read it back — but the byte-level GET decryption resolves its material in crates/ecstore object_api/readers.rs, a duplicated twin that still recomputed the deterministic legacy nonce. Encrypt with the random nonce, decrypt with the deterministic one: the first AEAD block fails and every SSE-C GET aborts its body after the response headers (IncompleteRead(0 bytes) on clients; all 8 SSE-C cases in the implemented s3-tests whitelist), which is what has been driving the "S3 Implemented Tests" CI job into its 60-minute timeout since 2026-07-09. Resolve the base nonce like the encrypt side: prefer the persisted IV (x-rustfs-encryption-iv, then the case-insensitive MinIO interop key), fall back to the deterministic nonce only for legacy objects with no stored IV or an undecodable value. Full implemented s3-tests whitelist is back to 451 passed / 0 failed against the fixed binary.
RustFS ECStore - Erasure Coding Storage
High-performance erasure coding storage engine for RustFS distributed object storage
📖 Documentation
· 🐛 Bug Reports
· 💬 Discussions
📖 Overview
RustFS ECStore provides erasure coding storage capabilities for the RustFS distributed object storage system. For the complete RustFS experience, please visit the main RustFS repository.
✨ Features
- Reed-Solomon erasure coding implementation
- Configurable redundancy levels (N+K schemes)
- Automatic data healing and reconstruction
- Multi-drive support with intelligent placement
- Parallel encoding/decoding for performance
- Efficient disk space utilization
📚 Documentation
For comprehensive documentation, examples, and usage guides, please visit the main RustFS repository.
📄 License
This project is licensed under the Apache License 2.0 - see the LICENSE file for details.
Copyright 2024 RustFS Team
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
RustFS is a trademark of RustFS, Inc.
All other trademarks are the property of their respective owners.
Made with ❤️ by the RustFS Storage Team
