fix(engine): aws-chunked uploads stored the SigV4 framing as object content - #108
Merged
Merged
Conversation
# Conflicts: # CHANGELOG.md
# Conflicts: # CONFORMANCE.md # adapters/aws-s3-style/README.md # conformance/matrix.json # conformance/matrix.yaml
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #102.
A default
PutObjectfrom AWSSDK.S3 4.0.102.4 sendsSTREAMING-AWS4-HMAC-SHA256-PAYLOADframing withContent-Encoding: aws-chunked. The engine stored that framing as object content, so the chunk-size lines, the;chunk-signature=extensions, the terminal zero chunk, and any trailers all landed in the object. Five bytes in, 298 bytes out.UseChunkEncoding=falseon an otherwise identical request round-tripped correctly, which points away from the adapter and toward an SDK version difference.Found by @jeremydixon22 driving the
aws-s3-styleadapter with the AWS .NET SDK.internal/engine/engine.goread the body withio.ReadAll(http.MaxBytesReader(...)). Go's HTTP server stripsTransfer-Encoding: chunked, butContent-Encoding: aws-chunkedis framing inside the payload itself, and no decoder existed in Go or Starlark. The request authenticated before it stored the framed bytes, becauseadapters/aws-s3-style/scripts/lib.star:457-467already accepted theSTREAMING-*content hash verbatim.What changed
internal/engine/chunked_aws.godecodes the framing after the body read and before the profile layer, so rules, profiles, and handlers all observe decoded bytes.Content-Encodingandx-amz-content-sha256pass through untouched, since SigV4 signs them; deleting either would break signature verification on any SDK that includes them in its signed set.Decoding is triggered by an
aws-chunkedtoken inContent-Encoding(comma-split, case-folded, multi-value aware) or by aSTREAMING-*content hash without that header. The read limit for the still-framed body ismax_body_bytesplus 2 MiB of framing headroom, so chunk signatures and trailers do not cause a spurious413.Malformed, truncated, or over-limit framing returns
400 IncompleteBodywithout echoing request bytes. Limits: 4 KiB per chunk or trailer line, 10,000 data chunks, 32 trailers totalling 8 KiB, and decoded output bounded bymax_body_bytes.x-amz-decoded-content-lengthis verified when exactly one valid value is present and ignored otherwise, never pre-allocated from. The parser accepts uppercase hex, treats bytes after the first;as an opaque extension, and reads exactlysizebytes then CRLF, so binary payloads containing CRLF are safe.Deviations
Per-chunk signatures are not verified; the header signature is. Streaming checksum trailers are discarded. Both are recorded in
conformance/matrix.yaml:157-158.Verification
TestAWSChunkedParsercovers single and multi-chunk bodies, binary payloads containing CRLF and NUL, uppercase hex, OWS around the chunk line, bothSTREAMING-*tokens, trailers, the count and size caps, decoded-over-max_body_bytes, and malformed input including bare LF, a+-prefixed size, and a trailer with no colon.Round-trip through AWSSDK.S3 4.0.102.4, 5 bytes in and 5 bytes out:
stunt adapter lint adapters/aws-s3-styleis clean andjust conformance-matrixregenerates with no drift.