mirror of
https://github.com/versity/versitygw.git
synced 2026-07-19 22:42:20 +00:00
fix: prevent index-out-of-range panic in s3proxy GetBucketOwnershipControls
Add nil and length checks before accessing
resp.OwnershipControls.Rules[0]. If the upstream S3 backend returns
a response with nil OwnershipControls or empty Rules, the server
panics with an index-out-of-range error. Return
OwnershipControlsNotFoundError instead, matching the behavior of
the posix and azure backends.
This bug was introduced in commit 7545e623 (2024-06-28) when bucket
ownership controls were first implemented for the s3proxy backend.
Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
This commit is contained in:
@@ -258,6 +258,9 @@ func (s *S3Proxy) GetBucketOwnershipControls(ctx context.Context, bucket string)
|
||||
if err != nil {
|
||||
return ownship, handleError(err)
|
||||
}
|
||||
if resp.OwnershipControls == nil || len(resp.OwnershipControls.Rules) == 0 {
|
||||
return ownship, s3err.GetBucketErr(s3err.ErrOwnershipControlsNotFound, bucket)
|
||||
}
|
||||
return resp.OwnershipControls.Rules[0].ObjectOwnership, nil
|
||||
}
|
||||
func (s *S3Proxy) DeleteBucketOwnershipControls(ctx context.Context, bucket string) error {
|
||||
|
||||
Reference in New Issue
Block a user