mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-30 08:49:26 +00:00
db57fabcbd
WarmBackendS3::new already rejects loopback, private, link-local, and cloud metadata-service endpoints via validate_outbound_url, but the Aliyun, Azure, Huaweicloud, Tencent, MinIO, R2, RustFS, and GCS warm backend constructors built their transition clients directly from conf.endpoint without the same check. The endpoint comes from the AddTier admin API, gated only by SetTierAction, which can be a narrower IAM grant than root. Any principal holding it could point one of these eight tier types at an internal address (loopback, RFC1918, link-local, or a cloud metadata IP) and have the server issue authenticated outbound requests to it, a server-side SSRF vector that the S3 and Wasabi tier types were already closed against. Apply the same validate_outbound_url check at construction time for all eight providers, before any credentials or network client are built, mirroring the existing WarmBackendS3 pattern. GCS keeps its default-endpoint behavior when conf.endpoint is empty and only validates an explicitly configured endpoint. Add a regression test per provider asserting that a loopback endpoint is rejected before any backend/network setup, matching the existing WarmBackendS3 coverage. Update the error(format!) ratchet baseline: these are one-shot admin tier-configuration validation errors returned once per AddTier call, not per-disk I/O errors that flow through reduce_errs quorum aggregation (backlog#1845), so the new ::other(format!) call sites do not introduce a quorum-bucketing hazard. They mirror the pre-existing, already-baselined warm_backend_s3.rs call site.
RustFS ECStore - Erasure Coding Storage
High-performance erasure coding storage engine for RustFS distributed object storage
📖 Documentation
· 🐛 Bug Reports
· 💬 Discussions
📖 Overview
RustFS ECStore provides erasure coding storage capabilities for the RustFS distributed object storage system. For the complete RustFS experience, please visit the main RustFS repository.
✨ Features
- Reed-Solomon erasure coding implementation
- Configurable redundancy levels (N+K schemes)
- Automatic data healing and reconstruction
- Multi-drive support with intelligent placement
- Parallel encoding/decoding for performance
- Efficient disk space utilization
📚 Documentation
For comprehensive documentation, examples, and usage guides, please visit the main RustFS repository.
📄 License
This project is licensed under the Apache License 2.0 - see the LICENSE file for details.
Copyright 2024 RustFS Team
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
RustFS is a trademark of RustFS, Inc.
All other trademarks are the property of their respective owners.
Made with ❤️ by the RustFS Storage Team
