[
https://issues.apache.org/jira/browse/HDDS-16657?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Priyesh Karatha updated HDDS-16657:
-----------------------------------
Parent: HDDS-8342
Issue Type: Sub-task (was: Bug)
> Ozone S3: PutBucketLifecycleConfiguration accepts unsupported lifecycle
> Transition actions
> ------------------------------------------------------------------------------------------
>
> Key: HDDS-16657
> URL: https://issues.apache.org/jira/browse/HDDS-16657
> Project: Apache Ozone
> Issue Type: Sub-task
> Reporter: Prince Raj
> Assignee: Priyesh Karatha
> Priority: Major
>
> *Description*
> Ozone S3 Gateway currently accepts a bucket lifecycle configuration
> containing a {{Transition}} action to a storage class that is not supported
> by Ozone.
> The {{PutBucketLifecycleConfiguration}} request returns HTTP 200 even though
> Ozone does not support S3 lifecycle transition actions for the specified
> storage class.
> This allows users to successfully configure a lifecycle rule that Ozone
> cannot enforce.
> h3. Reproduction
> Create a lifecycle configuration containing a {{Transition}} action:
> h3. {{}}
> {code:java}
> EXPIRE_DATE="2026-10-01T00:00:00Z" ozones3api
> put-bucket-lifecycle-configuration \ --bucket "$BUCKET" \
> --lifecycle-configuration '{ "Rules": [ { "ID": "unsupported-transition",
> "Status": "Enabled", "Filter": { "Prefix": "" }, "Expiration": { "Date":
> "'"$EXPIRE_DATE"'" }, "Transitions": [ { "Days": 1, "StorageClass": "EC" } ]
> } ] }' \ --debug{code}
> The lifecycle request contains:
> h3. {{}}
> {code:java}
> <Transition> <Days>1</Days> <StorageClass>EC</StorageClass>
> </Transition>{code}
> h3. {{{}{}}}Actual Result
> The {{PutBucketLifecycleConfiguration}} request succeeds with HTTP 200:
> h3. {{}}
> {code:java}
> PUT ...?lifecycle HTTP/1.1" 200 0{code}
> h3. {{}}
> No validation error is returned to indicate that the lifecycle {{Transition}}
> action is unsupported.
> h3. Expected Result
> The {{PutBucketLifecycleConfiguration}} API should reject lifecycle
> configurations containing unsupported {{Transition}} actions.
> The request should return an appropriate 4xx error, such as:
> * {{InvalidRequest}}
> * {{InvalidArgument}}
> * {{NotImplemented}}
> The response should clearly indicate that the requested lifecycle
> {{Transition}} action or storage class is not supported.
> For example:
> h3. {{}}
> {code:java}
> Invalid lifecycle configuration: Transition actions are not supported.
> or:
> Invalid lifecycle configuration: storage class 'EC' is not supported for
> lifecycle transitions{code}
> h3. Impact
> Users can successfully configure lifecycle rules containing unsupported
> transition actions and receive HTTP 200, which incorrectly indicates that the
> configuration was accepted and is enforceable.
> This can result in lifecycle rules being stored without the corresponding
> transition action being executable, potentially causing the configured
> lifecycle policy to be silently ineffective.
> h3. Expected Behavior Summary
> * Validate lifecycle {{Transition}} actions during
> {{{}PutBucketLifecycleConfiguration{}}}.
> * Reject unsupported transition actions or storage classes at configuration
> time.
> * Return an appropriate 4xx error with a clear and actionable error message.
> * Do not return HTTP 200 for a lifecycle configuration containing an
> unsupported transition action.
> h3.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]