)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":39146,"name":"Nathaniel Martes","display_name":"Nate Martes","email":"natemartes09@gmail.com","username":"nmartes"},"change_message_id":"aff1b814f01686233f41eaee16d30bde206ef692","unresolved":true,"context_lines":[{"line_number":29,"context_line":"Objects written before this change keep their plaintext sysmeta and are"},{"line_number":30,"context_line":"still read correctly."},{"line_number":31,"context_line":""},{"line_number":32,"context_line":"Related-Change: Ie957413640289c458db35c6e65dbdc0e71652322"},{"line_number":33,"context_line":""},{"line_number":34,"context_line":"Co-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e"},{"line_number":35,"context_line":"Change-Id: I8b126d54e34f74d3cdb08cae626811caa3daba82"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"f94da68e_a6b9eb48","line":32,"range":{"start_line":32,"start_character":0,"end_line":32,"end_character":57},"updated":"2026-09-01 13:01:26.000000000","message":"Might be good to add `SecurityImpact` too","commit_id":"a3f1007c6c9198d290985c4e21c0f27b4baa6b29"},{"author":{"_account_id":39146,"name":"Nathaniel Martes","display_name":"Nate Martes","email":"natemartes09@gmail.com","username":"nmartes"},"change_message_id":"1983c98182143778e6c913ce74fded0db85f4814","unresolved":true,"context_lines":[{"line_number":29,"context_line":"Objects written before this change keep their plaintext sysmeta and are"},{"line_number":30,"context_line":"still read correctly."},{"line_number":31,"context_line":""},{"line_number":32,"context_line":"Related-Change: Ie957413640289c458db35c6e65dbdc0e71652322"},{"line_number":33,"context_line":""},{"line_number":34,"context_line":"Co-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e"},{"line_number":35,"context_line":"Change-Id: I8b126d54e34f74d3cdb08cae626811caa3daba82"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":1,"id":"9fb97a0c_a8d5048b","line":32,"range":{"start_line":32,"start_character":0,"end_line":32,"end_character":57},"in_reply_to":"f94da68e_a6b9eb48","updated":"2026-09-01 15:31:28.000000000","message":"Actually if we are squashing this does not matter...","commit_id":"a3f1007c6c9198d290985c4e21c0f27b4baa6b29"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":39146,"name":"Nathaniel Martes","display_name":"Nate Martes","email":"natemartes09@gmail.com","username":"nmartes"},"change_message_id":"aff1b814f01686233f41eaee16d30bde206ef692","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"b6d964a3_72eadaab","updated":"2026-09-01 13:01:26.000000000","message":"I am good with +1-ing this. I think we have to diverge from AWS here an encrypt the checksum always to save us from punching a hole that will become a problem.\n\nJust some small nits, but if this merges I am cool with it!\nThough how we merge it is the better question, that might just mean to sq? this down, but then checksum on full objects gets bigger... but it we could introduce this patch before it as prep (for a header that is not being used yet...)\n\nEhhh I think squashing it down would be best since the header is only added by this patch (currently) and we probably won\u0027t be getting any more digest headers like this one","commit_id":"a3f1007c6c9198d290985c4e21c0f27b4baa6b29"},{"author":{"_account_id":39146,"name":"Nathaniel Martes","display_name":"Nate Martes","email":"natemartes09@gmail.com","username":"nmartes"},"change_message_id":"f67e74a56acdcf074cc9db8cd346b35e63ff95ba","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"a7c0d6db_d355b2eb","updated":"2026-08-31 23:54:09.000000000","message":"The big question I have about this patch is, S3 only encrypts metadata if a user asks for it, with aws:kms. Swift does not support this, but I think this is important enough to diverge from what AWS does because it would make Swift worse on quite an important piece","commit_id":"a3f1007c6c9198d290985c4e21c0f27b4baa6b29"},{"author":{"_account_id":39146,"name":"Nathaniel Martes","display_name":"Nate Martes","email":"natemartes09@gmail.com","username":"nmartes"},"change_message_id":"612fff87c1df835f6645d350ad1ed945e6fdd7f2","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"445567eb_90446c81","updated":"2026-09-02 13:57:53.000000000","message":"I am going to do more on this in a bit, but this patch will probably change once we merged 1003424: crypto: Encrypt object sysmeta declared sensitive | https://review.opendev.org/c/openstack/swift/+/1003424","commit_id":"8b202da411b88d4743c34b85271389c9e7f5afda"}],"swift/common/middleware/crypto/crypto_utils.py":[{"author":{"_account_id":39146,"name":"Nathaniel Martes","display_name":"Nate Martes","email":"natemartes09@gmail.com","username":"nmartes"},"change_message_id":"aff1b814f01686233f41eaee16d30bde206ef692","unresolved":true,"context_lines":[{"line_number":34,"context_line":"# that persists such a digest as sysmeta should add its header name here."},{"line_number":35,"context_line":"BODY_DIGEST_SYSMETA_HEADERS \u003d ("},{"line_number":36,"context_line":"    # written by the s3api middleware for checksummed object PUTs"},{"line_number":37,"context_line":"    get_sys_meta_prefix(\u0027object\u0027) + \u0027s3api-checksum-value\u0027,"},{"line_number":38,"context_line":")"},{"line_number":39,"context_line":""},{"line_number":40,"context_line":"# Namespace in which the encrypted values of BODY_DIGEST_SYSMETA_HEADERS are"}],"source_content_type":"text/x-python","patch_set":1,"id":"1cedc5b1_bce28142","line":37,"range":{"start_line":37,"start_character":0,"end_line":37,"end_character":59},"updated":"2026-09-01 13:01:26.000000000","message":"Yea I think we have to refer to the s3api middleware here.. or perhaps we add like some prefix to the object sysmeta name after the \u003cmiddleware\u003e name inside of the sysmeta header, maybe like\n\n`X-Sysmeta-Object-\u003cMiddleware\u003e-Encrypt-\u003cMy\u003e-\u003cSysmeta\u003e-\u003cKey`\n\nThough I could see this being an issue and we only have 1 use case (and probably won\u0027t have another use case of checksum metadata being asked by the user)","commit_id":"a3f1007c6c9198d290985c4e21c0f27b4baa6b29"},{"author":{"_account_id":39146,"name":"Nathaniel Martes","display_name":"Nate Martes","email":"natemartes09@gmail.com","username":"nmartes"},"change_message_id":"aff1b814f01686233f41eaee16d30bde206ef692","unresolved":true,"context_lines":[{"line_number":39,"context_line":""},{"line_number":40,"context_line":"# Namespace in which the encrypted values of BODY_DIGEST_SYSMETA_HEADERS are"},{"line_number":41,"context_line":"# persisted. It is inside the x-object-sysmeta-crypto- namespace that"},{"line_number":42,"context_line":"# decrypter.purge_crypto_sysmeta_headers already strips from responses."},{"line_number":43,"context_line":"ENCRYPTED_SYSMETA_PREFIX \u003d get_sys_meta_prefix(\u0027object\u0027) + \u0027crypto-meta-\u0027"},{"line_number":44,"context_line":""},{"line_number":45,"context_line":""}],"source_content_type":"text/x-python","patch_set":1,"id":"5a3bdbf9_b9a21dd4","line":42,"range":{"start_line":42,"start_character":12,"end_line":42,"end_character":40},"updated":"2026-09-01 13:01:26.000000000","message":"nit: `decrypter. purge_crypto_sysmeta_header`\nneed space","commit_id":"a3f1007c6c9198d290985c4e21c0f27b4baa6b29"}],"swift/common/middleware/crypto/decrypter.py":[{"author":{"_account_id":39146,"name":"Nathaniel Martes","display_name":"Nate Martes","email":"natemartes09@gmail.com","username":"nmartes"},"change_message_id":"aff1b814f01686233f41eaee16d30bde206ef692","unresolved":false,"context_lines":[{"line_number":197,"context_line":"                result.append((new_prefix + short_name, decrypted_value))"},{"line_number":198,"context_line":"        return result"},{"line_number":199,"context_line":""},{"line_number":200,"context_line":"    def decrypt_body_digest_sysmeta(self, keys):"},{"line_number":201,"context_line":"        \"\"\""},{"line_number":202,"context_line":"        Decrypt object sysmeta that was encrypted at PUT time because it is a"},{"line_number":203,"context_line":"        digest of the object body. Encrypted values are stored in the"}],"source_content_type":"text/x-python","patch_set":1,"id":"47637959_d47afd71","line":200,"range":{"start_line":200,"start_character":0,"end_line":200,"end_character":48},"updated":"2026-09-01 13:01:26.000000000","message":"I like this function, pretty straightforward","commit_id":"a3f1007c6c9198d290985c4e21c0f27b4baa6b29"}],"swift/common/middleware/s3api/s3checksum.py":[{"author":{"_account_id":39146,"name":"Nathaniel Martes","display_name":"Nate Martes","email":"natemartes09@gmail.com","username":"nmartes"},"change_message_id":"612fff87c1df835f6645d350ad1ed945e6fdd7f2","unresolved":false,"context_lines":[{"line_number":90,"context_line":"        s3api_sysmeta_header(\u0027object\u0027, \u0027checksum-algorithm\u0027):"},{"line_number":91,"context_line":"            normalize_checksum_algorithm(checksum_algorithm),"},{"line_number":92,"context_line":"        # a digest of the body, so the encrypter must encrypt this value"},{"line_number":93,"context_line":"        s3api_sensitive_sysmeta_header(\u0027object\u0027, \u0027checksum-value\u0027):"},{"line_number":94,"context_line":"            checksum_value,"},{"line_number":95,"context_line":"        s3api_sysmeta_header(\u0027object\u0027, \u0027checksum-type\u0027): checksum_type,"},{"line_number":96,"context_line":"    }"}],"source_content_type":"text/x-python","patch_set":2,"id":"9d0f08f3_b9cb80c1","line":93,"range":{"start_line":93,"start_character":0,"end_line":93,"end_character":67},"updated":"2026-09-02 13:57:53.000000000","message":"I\u0027m really glad we abstracted away the actual sysmeta headers for s3 checksums, it makes these changes much eaiser","commit_id":"8b202da411b88d4743c34b85271389c9e7f5afda"}],"swift/common/middleware/versioned_writes/object_versioning.py":[{"author":{"_account_id":39146,"name":"Nathaniel Martes","display_name":"Nate Martes","email":"natemartes09@gmail.com","username":"nmartes"},"change_message_id":"612fff87c1df835f6645d350ad1ed945e6fdd7f2","unresolved":true,"context_lines":[{"line_number":462,"context_line":"            \u0027X-Object-Manifest\u0027, \u0027X-Static-Large-Object\u0027,"},{"line_number":463,"context_line":"            \u0027X-Object-Sysmeta-Slo-Etag\u0027, \u0027X-Object-Sysmeta-Slo-Size\u0027,"},{"line_number":464,"context_line":"            # a checksum describes the target\u0027s body, not this empty symlink"},{"line_number":465,"context_line":"            \u0027X-Object-Sysmeta-S3Api-Checksum-Algorithm\u0027,"},{"line_number":466,"context_line":"            \u0027X-Object-Sysmeta-S3Api-Checksum-Type\u0027,"},{"line_number":467,"context_line":"        )"},{"line_number":468,"context_line":"        for header in not_for_symlink_headers:"}],"source_content_type":"text/x-python","patch_set":2,"id":"fc8be24c_964e042d","line":465,"range":{"start_line":465,"start_character":0,"end_line":465,"end_character":56},"updated":"2026-09-02 13:57:53.000000000","message":"Pretty sure these need to be the `X-Object-System-Sensistive-S3Api-Checksum-Algorithm` ones since those are the ones written down from s3checksum.\n\nThis also means we probably won\u0027t need this once 1003424: crypto: Encrypt object sysmeta declared sensitive | https://review.opendev.org/c/openstack/swift/+/1003424\nis merged... because it checks for sensistvie sysmeta on L470","commit_id":"8b202da411b88d4743c34b85271389c9e7f5afda"}],"test/unit/common/middleware/test_object_versioning.py":[{"author":{"_account_id":39146,"name":"Nathaniel Martes","display_name":"Nate Martes","email":"natemartes09@gmail.com","username":"nmartes"},"change_message_id":"aff1b814f01686233f41eaee16d30bde206ef692","unresolved":true,"context_lines":[{"line_number":702,"context_line":"        # the original PUT no longer has the callback"},{"line_number":703,"context_line":"        self.assertNotIn(\u0027swift.callback.update_footers\u0027, req.environ)"},{"line_number":704,"context_line":""},{"line_number":705,"context_line":"    def test_PUT_checksum_headers_not_on_symlink(self):"},{"line_number":706,"context_line":"        # a checksum arriving in headers, as the copy middleware propagates it"},{"line_number":707,"context_line":"        # from the source of a COPY, describes the version object\u0027s body and"},{"line_number":708,"context_line":"        # must not be written to the zero-byte symlink"}],"source_content_type":"text/x-python","patch_set":1,"id":"bbae5994_63229cae","line":705,"range":{"start_line":705,"start_character":0,"end_line":705,"end_character":55},"updated":"2026-09-01 13:01:26.000000000","message":"Might be good to bring in this test into the encryption pipeline test cases","commit_id":"a3f1007c6c9198d290985c4e21c0f27b4baa6b29"}]}
