Addresses CodeRabbit review on PR #9228: in
createMultipartSSEKMSDecryptedReaderDirect the per-chunk SSE-KMS metadata
was deserialized in the prep loop but the IV length was only validated
later, inside CreateSSEKMSDecryptedReader, which runs from the wrap
closure -- AFTER the chunk's volume-server fetch has already started.
That weakens the new "reject malformed chunks before any fetch" contract
for SSE-KMS specifically: a chunk with a missing/short/long IV would
fire its HTTP GET, then fail mid-stream during decrypt.
The fix moves the existing ValidateIV check into the prep loop, matching
the SSE-S3 and SSE-C paths.
Drive-by: extract the SSE-KMS prep loop into a free
buildMultipartSSEKMSReader helper that mirrors buildMultipartSSES3Reader,
so the new contract is unit-testable without an S3ApiServer. The
exported method (createMultipartSSEKMSDecryptedReaderDirect) stays a
thin caller, so behavior for production callers is unchanged.
New tests in weed/s3api/s3api_multipart_ssekms_test.go pin the contract:
- TestBuildMultipartSSEKMSReader_RejectsBadIVBeforeAnyFetch covers
missing IV, empty IV, short IV, long IV. Each case asserts both
that an error is returned AND that the fetch callback is never
invoked.
- TestBuildMultipartSSEKMSReader_RejectsMissingMetadataBeforeAnyFetch
pins the analogous behavior when SseMetadata is nil on a chunk in
position N: chunks 0..N-1 must not be fetched (the earlier eager
implementation depended on a closeAppendedReaders cleanup path; the
new contract is stronger -- nothing is opened in the first place).
- TestBuildMultipartSSEKMSReader_RejectsUnparseableMetadataBeforeAnyFetch
covers the JSON-unmarshal failure branch.
- TestBuildMultipartSSEKMSReader_SortsByOffset smoke-tests the
documented sort-by-offset contract by recording the order in which
fetch is invoked.
All four pass under `go test ./weed/s3api/`. Existing weed/s3api unit
suite + the SSE integration suite (with the local KMS provider enabled
via s3-config-template.json) continue to pass.
see https://blog.aqwari.net/xml-schema-go/
1. go get aqwari.net/xml/cmd/xsdgen
2. Add EncodingType element for ListBucketResult in AmazonS3.xsd
3. xsdgen -o s3api_xsd_generated.go -pkg s3api AmazonS3.xsd
4. Remove empty Grantee struct in s3api_xsd_generated.go
5. Remove xmlns: sed s'/http:\/\/s3.amazonaws.com\/doc\/2006-03-01\/\ //' s3api_xsd_generated.go