)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"f28af65d7b1dc107ea28a1d23062afb4ac37def4","unresolved":true,"context_lines":[{"line_number":31,"context_line":""},{"line_number":32,"context_line":"The encrypter encrypts sensitive sysmeta also for a zero-byte object."},{"line_number":33,"context_line":"The plaintext Etag of such an object is always the same value, but a"},{"line_number":34,"context_line":"sensitive value does not always come from the body. Each encrypted value"},{"line_number":35,"context_line":"holds its own key id. Because of this, the decrypter can decrypt the"},{"line_number":36,"context_line":"value when there is no body crypto meta, and after an operator changes"},{"line_number":37,"context_line":"the root secret."},{"line_number":38,"context_line":""},{"line_number":39,"context_line":"Only a PUT can set object sysmeta. Object versioning keeps sensitive"},{"line_number":40,"context_line":"sysmeta on the version object, and removes it from the zero-byte"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":6,"id":"8cfde3d5_0171168c","line":37,"range":{"start_line":34,"start_character":52,"end_line":37,"end_character":16},"updated":"2026-09-07 18:23:44.000000000","message":"This is a different pattern to how we store the key_id of user metadata that can also be encrypted when there is no body. For user metadata we persist a \"companion\" header that has the key_id for all user metadata. IMHO we should replicate this pattern for the sensitive sysmeta.","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"2287b5b3164335794c8ba9e90afbc0a89fce6a25","unresolved":false,"context_lines":[{"line_number":31,"context_line":""},{"line_number":32,"context_line":"The encrypter encrypts sensitive sysmeta also for a zero-byte object."},{"line_number":33,"context_line":"The plaintext Etag of such an object is always the same value, but a"},{"line_number":34,"context_line":"sensitive value does not always come from the body. Each encrypted value"},{"line_number":35,"context_line":"holds its own key id. Because of this, the decrypter can decrypt the"},{"line_number":36,"context_line":"value when there is no body crypto meta, and after an operator changes"},{"line_number":37,"context_line":"the root secret."},{"line_number":38,"context_line":""},{"line_number":39,"context_line":"Only a PUT can set object sysmeta. Object versioning keeps sensitive"},{"line_number":40,"context_line":"sysmeta on the version object, and removes it from the zero-byte"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":6,"id":"38018abc_dfc0009f","line":37,"range":{"start_line":34,"start_character":52,"end_line":37,"end_character":16},"in_reply_to":"8cfde3d5_0171168c","updated":"2026-09-08 17:53:39.000000000","message":"Done","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":1179,"name":"Clay Gerrard","email":"clay.gerrard@gmail.com","username":"clay-gerrard"},"change_message_id":"cc4d0fe8e33aefbef04559d084037ced5944d65d","unresolved":true,"context_lines":[{"line_number":44,"context_line":"change adds the first consumer of this namespace in the s3api"},{"line_number":45,"context_line":"middleware."},{"line_number":46,"context_line":""},{"line_number":47,"context_line":"SecurityImpact"},{"line_number":48,"context_line":""},{"line_number":49,"context_line":"Related-Change-Id: I8b126d54e34f74d3cdb08cae626811caa3daba82"},{"line_number":50,"context_line":"Co-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":6,"id":"8610e3de_1a36d095","line":47,"updated":"2026-09-02 23:11:25.000000000","message":"I think it\u0027s worth some extra eyeballs\n\nhttps://docs.openstack.org/contributors/es_MX/common/git.html#footers\n\nthe risk is not \"we\u0027re doing sensitive-sysmeta wrong\" - it\u0027s more like \"oh our mw uses sysmeta, we migth want to opt-in to this collaboration with crypto going forward for new clusters\"\n\nCOPY is a decent migration path FWIW","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":6968,"name":"Christian Schwede","email":"cschwede@nvidia.com","username":"cschwede"},"change_message_id":"78b5f029a9e799af1a02fe1ae9ccf99f90e86ea3","unresolved":true,"context_lines":[{"line_number":44,"context_line":"change adds the first consumer of this namespace in the s3api"},{"line_number":45,"context_line":"middleware."},{"line_number":46,"context_line":""},{"line_number":47,"context_line":"SecurityImpact"},{"line_number":48,"context_line":""},{"line_number":49,"context_line":"Related-Change-Id: I8b126d54e34f74d3cdb08cae626811caa3daba82"},{"line_number":50,"context_line":"Co-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":6,"id":"e9054ab7_c053ad12","line":47,"in_reply_to":"8610e3de_1a36d095","updated":"2026-09-03 05:43:24.000000000","message":"Like the idea to have more eyes on it.","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":6968,"name":"Christian Schwede","email":"cschwede@nvidia.com","username":"cschwede"},"change_message_id":"78b5f029a9e799af1a02fe1ae9ccf99f90e86ea3","unresolved":true,"context_lines":[{"line_number":46,"context_line":""},{"line_number":47,"context_line":"SecurityImpact"},{"line_number":48,"context_line":""},{"line_number":49,"context_line":"Related-Change-Id: I8b126d54e34f74d3cdb08cae626811caa3daba82"},{"line_number":50,"context_line":"Co-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e"},{"line_number":51,"context_line":"Change-Id: If9d53f4f1e548dc735813ed9adbc33088037272c"},{"line_number":52,"context_line":"Signed-off-by: Christian Schwede \u003ccschwede@mailbox.org\u003e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":6,"id":"582eaaf0_c5f3811b","line":49,"updated":"2026-09-03 05:43:24.000000000","message":"We need to replace this with Ie957413640289c458db35c6e65dbdc0e71652322 - the former is the \"sq?\"-patch, and Ie95... is the one that will be the first consumer patch.","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"2287b5b3164335794c8ba9e90afbc0a89fce6a25","unresolved":false,"context_lines":[{"line_number":46,"context_line":""},{"line_number":47,"context_line":"SecurityImpact"},{"line_number":48,"context_line":""},{"line_number":49,"context_line":"Related-Change-Id: I8b126d54e34f74d3cdb08cae626811caa3daba82"},{"line_number":50,"context_line":"Co-Authored-By: Claude Opus 5 \u003cnoreply@anthropic.com\u003e"},{"line_number":51,"context_line":"Change-Id: If9d53f4f1e548dc735813ed9adbc33088037272c"},{"line_number":52,"context_line":"Signed-off-by: Christian Schwede \u003ccschwede@mailbox.org\u003e"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":6,"id":"c8f00fc6_b1f190aa","line":49,"in_reply_to":"582eaaf0_c5f3811b","updated":"2026-09-08 17:53:39.000000000","message":"Done","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":34930,"name":"Jianjian Huo","email":"jhuo@nvidia.com","username":"jhuo"},"change_message_id":"fa43733d5d50add790110899902714a4a5e8a569","unresolved":true,"context_lines":[{"line_number":31,"context_line":"the middleware that set the value. The encrypter at the destination then"},{"line_number":32,"context_line":"encrypts the value again with the key of the destination object."},{"line_number":33,"context_line":""},{"line_number":34,"context_line":"The encrypter encrypts sensitive sysmeta even for a zero-byte object,"},{"line_number":35,"context_line":"because a sensitive value does not always come from the body. Such an"},{"line_number":36,"context_line":"object has no body crypto meta. The encrypter therefore stores the key"},{"line_number":37,"context_line":"id and the cipher in X-Object-Sysmeta-Crypto-Meta, one header for all"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":18,"id":"ab5d23c3_0ac2e2dd","line":34,"updated":"2026-09-14 04:46:54.000000000","message":"\u003e The encrypter encrypts sensitive sysmeta even for a zero-byte object, because a sensitive value does not always come from the body\n\nif sensitive sysmeta only has checksum of data, then we can skip encryption for zero-byte object, since unencrypted Content-Length discloses object is empty already, and then sensitive sysmeta can also reuse ``X-Object-Sysmeta-Crypto-Body-Meta``?\n\nfor etag under encryption, the encrypter deliberately leaves an empty-body ETag unencrypted rather than encrypting the empty-string MD5. however sensitive sysmeta for a zero-byte object will be encrypted, maybe sensitive sysmeta will contain other sensitive info in additional to checksum in future?","commit_id":"4d36f9e79587fcc807a511b933d097fdfac2eedd"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"8483599d200fe33a5851c6a8c274531fbc6a31f3","unresolved":true,"context_lines":[{"line_number":31,"context_line":"the middleware that set the value. The encrypter at the destination then"},{"line_number":32,"context_line":"encrypts the value again with the key of the destination object."},{"line_number":33,"context_line":""},{"line_number":34,"context_line":"The encrypter encrypts sensitive sysmeta even for a zero-byte object,"},{"line_number":35,"context_line":"because a sensitive value does not always come from the body. Such an"},{"line_number":36,"context_line":"object has no body crypto meta. The encrypter therefore stores the key"},{"line_number":37,"context_line":"id and the cipher in X-Object-Sysmeta-Crypto-Meta, one header for all"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":18,"id":"e49d8664_75db169e","line":34,"in_reply_to":"ab5d23c3_0ac2e2dd","updated":"2026-09-14 08:17:52.000000000","message":"IMHO since we are going to the trouble of adding a general namespace, we should allow for future use cases where the sensitive metadata may not be a digest of the content.","commit_id":"4d36f9e79587fcc807a511b933d097fdfac2eedd"},{"author":{"_account_id":34930,"name":"Jianjian Huo","email":"jhuo@nvidia.com","username":"jhuo"},"change_message_id":"fa43733d5d50add790110899902714a4a5e8a569","unresolved":true,"context_lines":[{"line_number":39,"context_line":"after an operator changes the root secret."},{"line_number":40,"context_line":""},{"line_number":41,"context_line":"Only a PUT can set object sysmeta. Object versioning keeps sensitive"},{"line_number":42,"context_line":"sysmeta on the version object, and removes it from the zero-byte"},{"line_number":43,"context_line":"symlink."},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"No middleware in this patch writes to the namespace. The s3api"}],"source_content_type":"text/x-gerrit-commit-message","patch_set":18,"id":"00aaa3f4_98bf35d1","line":42,"updated":"2026-09-14 04:46:54.000000000","message":"\u003e removes it from the zero-byte symlink.\n\nthis is not the case anymore, zero-byte symlink also keeps it.","commit_id":"4d36f9e79587fcc807a511b933d097fdfac2eedd"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":1179,"name":"Clay Gerrard","email":"clay.gerrard@gmail.com","username":"clay-gerrard"},"change_message_id":"cc4d0fe8e33aefbef04559d084037ced5944d65d","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"3433ac04_b5340565","updated":"2026-09-02 23:11:25.000000000","message":"I didn\u0027t quite understand intuatively how this worked with encryption disabled, it\u0027s a little hard to review on it\u0027s own without an immediate consumer.  I found this probetest (optional) helpful:\n\n1003620: crypto: test sensitive sysmeta storage | https://review.opendev.org/c/openstack/swift/+/1003620\n\n... essentially `X-Object-Sysmeta-Sensitive` is a new reserved sysmeta namesapce - presumably Swift is implicitly agreeing to stay out of it for any future metadata and we\u0027re ~hoping that no out-of-tree-middleware happeend to use this namespace\n\nIt is *normal* sysmeta - ALL sysmeta is \"sensitive\" (impossible for users to write, and removed from responses via gatekeeper) - the \"object-sysmeta-sensitive\" namespace only a \"best effort hint\" for WHEN crypto is in the pipeline (and your mw sits left of crypto) any sysmeta in this new sysmeta sub-namespace WILL get encrypted IFF encryption is enabled\n\notherwise - it\u0027s just *normal* plaintext sysmeta the same way the mw sent it down the pipeline just like mw can already write whatever it wants into sysmeta\n\nThis is more of that - but with an extra hint that really has more to do with the operator choice to install crypto than anything about a \"requirement\" the mw itself can make on if data \"must\" be encrypted (mw wouldn\u0027t know if encryption is enabled).  IFF an operator chooses to install and enable crypto mw then future writes into the sysmeta-senstive namespace will be encrypted and decrypted trasparently to the middleware so that sysmeta-senstiive feels like any other \"internal to the cluster only\" sysmeta.\n\nThere is no expectation that out-of-tree mw does or should use this capability - if your mw writes sysmeta and you\u0027re realizing some of probably should be encrypted it is probably not - but it could be if you start using the new sensitive sysmeta namesapce.  GLHF!","commit_id":"fa71c232c898519d8b045a84717b22de0c675cb4"},{"author":{"_account_id":39146,"name":"Nathaniel Martes","display_name":"Nate Martes","email":"natemartes09@gmail.com","username":"nmartes"},"change_message_id":"01dfecce2526e1d9b91e53127752be3e16b539f7","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":5,"id":"517dbe1d_65eef752","updated":"2026-09-02 15:44:31.000000000","message":"This looks good to me to merge into master, and then we can probably rebase 991516: s3api: Checksum Persistence for Full Object Upload PUTs | https://review.opendev.org/c/openstack/swift/+/991516 and update 1003079: sq? s3api: Store the checksum value as sensitive sysmeta | https://review.opendev.org/c/openstack/swift/+/1003079 a tad bit","commit_id":"fa71c232c898519d8b045a84717b22de0c675cb4"},{"author":{"_account_id":6968,"name":"Christian Schwede","email":"cschwede@nvidia.com","username":"cschwede"},"change_message_id":"78b5f029a9e799af1a02fe1ae9ccf99f90e86ea3","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":5,"id":"bd31ce78_dd4fd687","in_reply_to":"3433ac04_b5340565","updated":"2026-09-03 05:43:24.000000000","message":"\u003e I didn\u0027t quite understand intuatively how this worked with encryption disabled, it\u0027s a little hard to review on it\u0027s own without an immediate consumer.\n\nDo you think there is anything we could add to this patch to make it easier to understand? Or is the probetest and consumer in the s3api patches sufficient enough?\n\n\u003e I found this probetest (optional) helpful: 1003620: crypto: test sensitive sysmeta storage | https://review.opendev.org/c/openstack/swift/+/1003620\n\nThat\u0027s helpful, thanks!\n\n\u003e ... essentially X-Object-Sysmeta-Sensitive is a new reserved sysmeta namesapce\n\u003e It is normal sysmeta - ALL sysmeta is \"sensitive\" (impossible for users to write, and removed from responses via gatekeeper) - the \"object-sysmeta-sensitive\" namespace only a \"best effort hint\" for WHEN crypto is in the pipeline (and your mw sits left of crypto) any sysmeta in this new sysmeta sub-namespace WILL get encrypted IFF encryption is enabled\n\nRight, sysmeta is always sensitive - the \"Sensitive\" suffix is the one I came up with, but there might be a better one? \"Confidential\" maybe?","commit_id":"fa71c232c898519d8b045a84717b22de0c675cb4"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"f28af65d7b1dc107ea28a1d23062afb4ac37def4","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":6,"id":"762de035_185ef4b1","updated":"2026-09-07 18:23:44.000000000","message":"I suggest an alternative pattern for persisting the sysmeta key_id, the same as user meta, in 1004470: crypto: store sensitive sysmeta key_id separately | https://review.opendev.org/c/openstack/swift/+/1004470","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":6968,"name":"Christian Schwede","email":"cschwede@nvidia.com","username":"cschwede"},"change_message_id":"f1a8770ede377e45ea5c99c14a98b31528b37ecc","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":9,"id":"a0224296_216b0e11","updated":"2026-09-08 10:42:37.000000000","message":"Patchset 7 includes Clays probetests: 1003620: crypto: test sensitive sysmeta storage | https://review.opendev.org/c/openstack/swift/+/1003620\n\nPatchset 8 includes Alistairs improvements: 1004470: crypto: store sensitive sysmeta key_id separately | https://review.opendev.org/c/openstack/swift/+/1004470\n\nPatchset 9 addresses a few other comments.","commit_id":"1bb5ce42c338c849b1e2ddca353b24d014b34072"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"2287b5b3164335794c8ba9e90afbc0a89fce6a25","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":11,"id":"3a3bb9ae_7e5070de","updated":"2026-09-08 17:53:39.000000000","message":"I\u0027ve suggested some doc edits as a follow-on here 1004680: sensitive sysmeta: improve docs | https://review.opendev.org/c/openstack/swift/+/1004680\n\nI have one remaining query re. object versioning","commit_id":"33e5aeb2ee1b8e746996e75906ac4772c04e8f08"},{"author":{"_account_id":34930,"name":"Jianjian Huo","email":"jhuo@nvidia.com","username":"jhuo"},"change_message_id":"fa43733d5d50add790110899902714a4a5e8a569","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":18,"id":"d50438c9_80a2a89d","updated":"2026-09-14 04:46:54.000000000","message":"Compared to reusing the original header name, a new dedicated ``X-Object-Sysmeta-Crypto-Sensitive-*`` header provides one rolling-upgrade safety: if ciphertext were stored under the original ``Sensitive-*`` name, an old proxy would regard it as an ordinary plaintext sysmeta value, middleware to the left of the decrypter could then consume ciphertext as though it were a real checksum value.","commit_id":"4d36f9e79587fcc807a511b933d097fdfac2eedd"},{"author":{"_account_id":15343,"name":"Tim Burke","email":"tburke@nvidia.com","username":"tburke"},"change_message_id":"4fed9be7cae936e44dd5196144823187601aa6a0","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":18,"id":"9e689548_31187354","updated":"2026-09-16 22:58:57.000000000","message":"Straw man, because I want to see the arguments against:\n\nWe should have the proxy app reject object PUTs with headers in the `X-Object-Sysmeta-Sensitive-*` namespace.","commit_id":"4d36f9e79587fcc807a511b933d097fdfac2eedd"},{"author":{"_account_id":34930,"name":"Jianjian Huo","email":"jhuo@nvidia.com","username":"jhuo"},"change_message_id":"1f499d10286a7b0a07b2990597ba0cabee22e10c","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":18,"id":"d34b74a9_6fab869e","in_reply_to":"9e689548_31187354","updated":"2026-09-17 04:12:14.000000000","message":"oh, then on a cluster without encryption enabled, users would see their S3 PUTs with checksum be rejected. ☹️","commit_id":"4d36f9e79587fcc807a511b933d097fdfac2eedd"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"aaa96a1d4e999c9823f0c47fcc7e40045efc4654","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":18,"id":"fbfe0f86_5394a1f1","in_reply_to":"d34b74a9_6fab869e","updated":"2026-09-17 09:03:04.000000000","message":"hehe, IMHO that would be equivalent to saying that the proxy app should reject requests with headers in the ``x-object-meta-*`` namespace, because we have already implicitly declared those to be \"sensitive\" *in the context of encryption being enabled*.","commit_id":"4d36f9e79587fcc807a511b933d097fdfac2eedd"}],"doc/source/development_middleware.rst":[{"author":{"_account_id":1179,"name":"Clay Gerrard","email":"clay.gerrard@gmail.com","username":"clay-gerrard"},"change_message_id":"cc4d0fe8e33aefbef04559d084037ced5944d65d","unresolved":true,"context_lines":[{"line_number":409,"context_line":""},{"line_number":410,"context_line":"Middleware that is not part of Swift must not write to this namespace before"},{"line_number":411,"context_line":"every proxy in the cluster runs a version of Swift that has the encrypter"},{"line_number":412,"context_line":"support for it. A proxy without the support stores the value in the clear."}],"source_content_type":"text/x-rst","patch_set":5,"id":"098b0c7f_257ba944","line":412,"updated":"2026-09-02 23:11:25.000000000","message":"this is a good call out!","commit_id":"fa71c232c898519d8b045a84717b22de0c675cb4"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"2287b5b3164335794c8ba9e90afbc0a89fce6a25","unresolved":true,"context_lines":[{"line_number":388,"context_line":"Object Sensitive Sysmeta"},{"line_number":389,"context_line":"************************"},{"line_number":390,"context_line":""},{"line_number":391,"context_line":"If middleware stores object system metadata that gives information about the"},{"line_number":392,"context_line":"plaintext object body, it must use headers of the form"},{"line_number":393,"context_line":"``X-Object-Sysmeta-Sensitive-\u003ckey\u003e: \u003cvalue\u003e``. An example is a checksum of the"},{"line_number":394,"context_line":"object body."},{"line_number":395,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"106ed099_4a3a7083","line":392,"range":{"start_line":391,"start_character":44,"end_line":392,"end_character":21},"updated":"2026-09-08 17:53:39.000000000","message":"nit: \"or any other sensitive information\"","commit_id":"1bb5ce42c338c849b1e2ddca353b24d014b34072"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"8483599d200fe33a5851c6a8c274531fbc6a31f3","unresolved":false,"context_lines":[{"line_number":388,"context_line":"Object Sensitive Sysmeta"},{"line_number":389,"context_line":"************************"},{"line_number":390,"context_line":""},{"line_number":391,"context_line":"If middleware stores object system metadata that gives information about the"},{"line_number":392,"context_line":"plaintext object body, it must use headers of the form"},{"line_number":393,"context_line":"``X-Object-Sysmeta-Sensitive-\u003ckey\u003e: \u003cvalue\u003e``. An example is a checksum of the"},{"line_number":394,"context_line":"object body."},{"line_number":395,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"22c943c2_c261fd34","line":392,"range":{"start_line":391,"start_character":44,"end_line":392,"end_character":21},"in_reply_to":"106ed099_4a3a7083","updated":"2026-09-14 08:17:52.000000000","message":"Done","commit_id":"1bb5ce42c338c849b1e2ddca353b24d014b34072"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"2287b5b3164335794c8ba9e90afbc0a89fce6a25","unresolved":true,"context_lines":[{"line_number":395,"context_line":""},{"line_number":396,"context_line":"Sensitive sysmeta is object system metadata, so only a PUT can set it (see"},{"line_number":397,"context_line":":ref:`sysmeta`). Middleware sets the header in the request headers, or in the"},{"line_number":398,"context_line":"footers of the PUT. An empty value tells nothing about the plaintext, so the"},{"line_number":399,"context_line":"encrypter stores an empty value in the clear."},{"line_number":400,"context_line":""},{"line_number":401,"context_line":"If the pipeline contains the encryption middleware, the encrypter encrypts"},{"line_number":402,"context_line":"each value in this namespace with the object key. It then stores the value as"}],"source_content_type":"text/x-rst","patch_set":9,"id":"4709fb80_e8e7f1ed","line":399,"range":{"start_line":398,"start_character":20,"end_line":399,"end_character":45},"updated":"2026-09-08 17:53:39.000000000","message":"nit: IMHO this sentence should be near the end of the next paragraph, after the concept of encrypting the headers has been introduced.","commit_id":"1bb5ce42c338c849b1e2ddca353b24d014b34072"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"8483599d200fe33a5851c6a8c274531fbc6a31f3","unresolved":false,"context_lines":[{"line_number":395,"context_line":""},{"line_number":396,"context_line":"Sensitive sysmeta is object system metadata, so only a PUT can set it (see"},{"line_number":397,"context_line":":ref:`sysmeta`). Middleware sets the header in the request headers, or in the"},{"line_number":398,"context_line":"footers of the PUT. An empty value tells nothing about the plaintext, so the"},{"line_number":399,"context_line":"encrypter stores an empty value in the clear."},{"line_number":400,"context_line":""},{"line_number":401,"context_line":"If the pipeline contains the encryption middleware, the encrypter encrypts"},{"line_number":402,"context_line":"each value in this namespace with the object key. It then stores the value as"}],"source_content_type":"text/x-rst","patch_set":9,"id":"b637e880_28ace2da","line":399,"range":{"start_line":398,"start_character":20,"end_line":399,"end_character":45},"in_reply_to":"4709fb80_e8e7f1ed","updated":"2026-09-14 08:17:52.000000000","message":"Done","commit_id":"1bb5ce42c338c849b1e2ddca353b24d014b34072"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"2287b5b3164335794c8ba9e90afbc0a89fce6a25","unresolved":true,"context_lines":[{"line_number":408,"context_line":"Object versioning removes these headers from the zero-byte symlink that it"},{"line_number":409,"context_line":"writes for a versioned object, because the values describe the version object."},{"line_number":410,"context_line":""},{"line_number":411,"context_line":"Middleware that is not part of Swift must not write to this namespace before"},{"line_number":412,"context_line":"every proxy in the cluster runs a version of Swift that has the encrypter"},{"line_number":413,"context_line":"support for it. A proxy without the support stores the value in the clear."},{"line_number":414,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"b4530dcf_6b994a6e","line":411,"range":{"start_line":411,"start_character":0,"end_line":411,"end_character":36},"updated":"2026-09-08 17:53:39.000000000","message":"any middleware, not just third-party","commit_id":"1bb5ce42c338c849b1e2ddca353b24d014b34072"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"2287b5b3164335794c8ba9e90afbc0a89fce6a25","unresolved":true,"context_lines":[{"line_number":408,"context_line":"Object versioning removes these headers from the zero-byte symlink that it"},{"line_number":409,"context_line":"writes for a versioned object, because the values describe the version object."},{"line_number":410,"context_line":""},{"line_number":411,"context_line":"Middleware that is not part of Swift must not write to this namespace before"},{"line_number":412,"context_line":"every proxy in the cluster runs a version of Swift that has the encrypter"},{"line_number":413,"context_line":"support for it. A proxy without the support stores the value in the clear."},{"line_number":414,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"43eeef5e_7959e595","line":411,"range":{"start_line":411,"start_character":37,"end_line":411,"end_character":51},"updated":"2026-09-08 17:53:39.000000000","message":"this seems too harsh: \"must not\" implies something will blow up. IIUC it\u0027s fine to use the namespace if *this* proxy supports it, so long as your middleware can tolerate not getting the value back, which is what the next paragraph says.\n\nAlso, cluster may run without encryption in which case it\u0027s fine to use the namespace. We\u0027re not requiring that clusters have encryption enabled before a middleware uses the sensitive namespace.","commit_id":"1bb5ce42c338c849b1e2ddca353b24d014b34072"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"8483599d200fe33a5851c6a8c274531fbc6a31f3","unresolved":false,"context_lines":[{"line_number":408,"context_line":"Object versioning removes these headers from the zero-byte symlink that it"},{"line_number":409,"context_line":"writes for a versioned object, because the values describe the version object."},{"line_number":410,"context_line":""},{"line_number":411,"context_line":"Middleware that is not part of Swift must not write to this namespace before"},{"line_number":412,"context_line":"every proxy in the cluster runs a version of Swift that has the encrypter"},{"line_number":413,"context_line":"support for it. A proxy without the support stores the value in the clear."},{"line_number":414,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"870e479e_364e9630","line":411,"range":{"start_line":411,"start_character":37,"end_line":411,"end_character":51},"in_reply_to":"43eeef5e_7959e595","updated":"2026-09-14 08:17:52.000000000","message":"Done","commit_id":"1bb5ce42c338c849b1e2ddca353b24d014b34072"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"8483599d200fe33a5851c6a8c274531fbc6a31f3","unresolved":false,"context_lines":[{"line_number":408,"context_line":"Object versioning removes these headers from the zero-byte symlink that it"},{"line_number":409,"context_line":"writes for a versioned object, because the values describe the version object."},{"line_number":410,"context_line":""},{"line_number":411,"context_line":"Middleware that is not part of Swift must not write to this namespace before"},{"line_number":412,"context_line":"every proxy in the cluster runs a version of Swift that has the encrypter"},{"line_number":413,"context_line":"support for it. A proxy without the support stores the value in the clear."},{"line_number":414,"context_line":""}],"source_content_type":"text/x-rst","patch_set":9,"id":"f85a1c9e_ad9cf356","line":411,"range":{"start_line":411,"start_character":0,"end_line":411,"end_character":36},"in_reply_to":"b4530dcf_6b994a6e","updated":"2026-09-14 08:17:52.000000000","message":"Done","commit_id":"1bb5ce42c338c849b1e2ddca353b24d014b34072"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"2287b5b3164335794c8ba9e90afbc0a89fce6a25","unresolved":true,"context_lines":[{"line_number":412,"context_line":"every proxy in the cluster runs a version of Swift that has the encrypter"},{"line_number":413,"context_line":"support for it. A proxy without the support stores the value in the clear."},{"line_number":414,"context_line":""},{"line_number":415,"context_line":"During a rolling upgrade, middleware must also accept that the header is"},{"line_number":416,"context_line":"absent, even when the object has a value. An old proxy removes every"},{"line_number":417,"context_line":"``X-Object-Sysmeta-Crypto-`` header from a response. It does not know how to"},{"line_number":418,"context_line":"restore ``X-Object-Sysmeta-Crypto-Sensitive-\u003ckey\u003e``. Middleware to the left of"}],"source_content_type":"text/x-rst","patch_set":9,"id":"7b6650ec_8784fb00","line":415,"range":{"start_line":415,"start_character":0,"end_line":415,"end_character":24},"updated":"2026-09-08 17:53:39.000000000","message":"I\u0027m confused: during an upgrade, each proxy either has new middleware that is setting sensitive sysmeta AND new encrypter/decrypter, or neither?\n\nOr are we anticipating that a middleware might start using the namespace before upgrading swift? But that seems like a very bad idea because we\u0027re saying that at some point in the future, during an upgrade, you\u0027ll then temporarily stop seeing some of your sysmeta in responses (because they start to be encrypted in the PUT but not decrypted in the GET path during upgrade). So...\"only use the sensitive namespace for stuff you can tolerate going missing from responses\".\n\nPerhaps what we should be saying is:\n\n\"It is strongly recommended that all swift proxy-servers are upgraded to support the sensitive sysmeta namespace before any middleware starts to use the namespace. If this is not possible then the following should be noted:\n\n* Prior to all proxy-servers supporting the sensitive sysmeta namespace, headers in that namespace may be persisted unencrypted.\n* During a rolling upgrade that introduces support for the sensitive namespace, some proxies may start to encrypt sensitive namespace headers in PUT requests before other proxies are capable of decrypting them in the GET or HEAD responses, resulting in the sensitive sysmeta namespace headers being absent from some GET or HEAD requests.\n\nThe same applies during a rolling enablement of encryption in a cluster that has support for the sensitive sysmeta namespace.\"","commit_id":"1bb5ce42c338c849b1e2ddca353b24d014b34072"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"2287b5b3164335794c8ba9e90afbc0a89fce6a25","unresolved":true,"context_lines":[{"line_number":412,"context_line":"every proxy in the cluster runs a version of Swift that has the encrypter"},{"line_number":413,"context_line":"support for it. A proxy without the support stores the value in the clear."},{"line_number":414,"context_line":""},{"line_number":415,"context_line":"During a rolling upgrade, middleware must also accept that the header is"},{"line_number":416,"context_line":"absent, even when the object has a value. An old proxy removes every"},{"line_number":417,"context_line":"``X-Object-Sysmeta-Crypto-`` header from a response. It does not know how to"},{"line_number":418,"context_line":"restore ``X-Object-Sysmeta-Crypto-Sensitive-\u003ckey\u003e``. Middleware to the left of"}],"source_content_type":"text/x-rst","patch_set":9,"id":"d4bfee3f_cd0cdfa4","line":415,"range":{"start_line":415,"start_character":70,"end_line":415,"end_character":72},"updated":"2026-09-08 17:53:39.000000000","message":"s/the header is absent/headers in the sensitive sysmeta namespace may be absent from GET and HEAD response headers/","commit_id":"1bb5ce42c338c849b1e2ddca353b24d014b34072"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"8483599d200fe33a5851c6a8c274531fbc6a31f3","unresolved":false,"context_lines":[{"line_number":412,"context_line":"every proxy in the cluster runs a version of Swift that has the encrypter"},{"line_number":413,"context_line":"support for it. A proxy without the support stores the value in the clear."},{"line_number":414,"context_line":""},{"line_number":415,"context_line":"During a rolling upgrade, middleware must also accept that the header is"},{"line_number":416,"context_line":"absent, even when the object has a value. An old proxy removes every"},{"line_number":417,"context_line":"``X-Object-Sysmeta-Crypto-`` header from a response. It does not know how to"},{"line_number":418,"context_line":"restore ``X-Object-Sysmeta-Crypto-Sensitive-\u003ckey\u003e``. Middleware to the left of"}],"source_content_type":"text/x-rst","patch_set":9,"id":"cace6a94_95cffd04","line":415,"range":{"start_line":415,"start_character":0,"end_line":415,"end_character":24},"in_reply_to":"7b6650ec_8784fb00","updated":"2026-09-14 08:17:52.000000000","message":"Done","commit_id":"1bb5ce42c338c849b1e2ddca353b24d014b34072"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"8483599d200fe33a5851c6a8c274531fbc6a31f3","unresolved":false,"context_lines":[{"line_number":412,"context_line":"every proxy in the cluster runs a version of Swift that has the encrypter"},{"line_number":413,"context_line":"support for it. A proxy without the support stores the value in the clear."},{"line_number":414,"context_line":""},{"line_number":415,"context_line":"During a rolling upgrade, middleware must also accept that the header is"},{"line_number":416,"context_line":"absent, even when the object has a value. An old proxy removes every"},{"line_number":417,"context_line":"``X-Object-Sysmeta-Crypto-`` header from a response. It does not know how to"},{"line_number":418,"context_line":"restore ``X-Object-Sysmeta-Crypto-Sensitive-\u003ckey\u003e``. Middleware to the left of"}],"source_content_type":"text/x-rst","patch_set":9,"id":"70b205d3_fa4e9534","line":415,"range":{"start_line":415,"start_character":70,"end_line":415,"end_character":72},"in_reply_to":"d4bfee3f_cd0cdfa4","updated":"2026-09-14 08:17:52.000000000","message":"Done","commit_id":"1bb5ce42c338c849b1e2ddca353b24d014b34072"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"2287b5b3164335794c8ba9e90afbc0a89fce6a25","unresolved":true,"context_lines":[{"line_number":413,"context_line":"support for it. A proxy without the support stores the value in the clear."},{"line_number":414,"context_line":""},{"line_number":415,"context_line":"During a rolling upgrade, middleware must also accept that the header is"},{"line_number":416,"context_line":"absent, even when the object has a value. An old proxy removes every"},{"line_number":417,"context_line":"``X-Object-Sysmeta-Crypto-`` header from a response. It does not know how to"},{"line_number":418,"context_line":"restore ``X-Object-Sysmeta-Crypto-Sensitive-\u003ckey\u003e``. Middleware to the left of"},{"line_number":419,"context_line":"the decrypter therefore sees no value until the upgrade is complete."}],"source_content_type":"text/x-rst","patch_set":9,"id":"ced33739_fe054933","line":416,"range":{"start_line":416,"start_character":22,"end_line":416,"end_character":40},"updated":"2026-09-08 17:53:39.000000000","message":"is this meant to mean the object has a non-empty body? AFAIK we haven\u0027t previously described objects as having \"values\" and its confusing w.r.t. header values.","commit_id":"1bb5ce42c338c849b1e2ddca353b24d014b34072"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"8483599d200fe33a5851c6a8c274531fbc6a31f3","unresolved":false,"context_lines":[{"line_number":413,"context_line":"support for it. A proxy without the support stores the value in the clear."},{"line_number":414,"context_line":""},{"line_number":415,"context_line":"During a rolling upgrade, middleware must also accept that the header is"},{"line_number":416,"context_line":"absent, even when the object has a value. An old proxy removes every"},{"line_number":417,"context_line":"``X-Object-Sysmeta-Crypto-`` header from a response. It does not know how to"},{"line_number":418,"context_line":"restore ``X-Object-Sysmeta-Crypto-Sensitive-\u003ckey\u003e``. Middleware to the left of"},{"line_number":419,"context_line":"the decrypter therefore sees no value until the upgrade is complete."}],"source_content_type":"text/x-rst","patch_set":9,"id":"182fd526_a318c575","line":416,"range":{"start_line":416,"start_character":22,"end_line":416,"end_character":40},"in_reply_to":"ced33739_fe054933","updated":"2026-09-14 08:17:52.000000000","message":"Done","commit_id":"1bb5ce42c338c849b1e2ddca353b24d014b34072"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"2287b5b3164335794c8ba9e90afbc0a89fce6a25","unresolved":true,"context_lines":[{"line_number":416,"context_line":"absent, even when the object has a value. An old proxy removes every"},{"line_number":417,"context_line":"``X-Object-Sysmeta-Crypto-`` header from a response. It does not know how to"},{"line_number":418,"context_line":"restore ``X-Object-Sysmeta-Crypto-Sensitive-\u003ckey\u003e``. Middleware to the left of"},{"line_number":419,"context_line":"the decrypter therefore sees no value until the upgrade is complete."}],"source_content_type":"text/x-rst","patch_set":9,"id":"0f38cfe6_cc0cd918","line":419,"range":{"start_line":419,"start_character":24,"end_line":419,"end_character":29},"updated":"2026-09-08 17:53:39.000000000","message":"s/sees no value/may not receive sensitive sysmeta headers/\n\n\"sees no value\" could imply that it gets the header, but without a value.","commit_id":"1bb5ce42c338c849b1e2ddca353b24d014b34072"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"8483599d200fe33a5851c6a8c274531fbc6a31f3","unresolved":false,"context_lines":[{"line_number":416,"context_line":"absent, even when the object has a value. An old proxy removes every"},{"line_number":417,"context_line":"``X-Object-Sysmeta-Crypto-`` header from a response. It does not know how to"},{"line_number":418,"context_line":"restore ``X-Object-Sysmeta-Crypto-Sensitive-\u003ckey\u003e``. Middleware to the left of"},{"line_number":419,"context_line":"the decrypter therefore sees no value until the upgrade is complete."}],"source_content_type":"text/x-rst","patch_set":9,"id":"06e54c0c_667d4985","line":419,"range":{"start_line":419,"start_character":24,"end_line":419,"end_character":29},"in_reply_to":"0f38cfe6_cc0cd918","updated":"2026-09-14 08:17:52.000000000","message":"Done","commit_id":"1bb5ce42c338c849b1e2ddca353b24d014b34072"},{"author":{"_account_id":15343,"name":"Tim Burke","email":"tburke@nvidia.com","username":"tburke"},"change_message_id":"1b5b757a6dc3a4c156060d836bc418f861b5d066","unresolved":true,"context_lines":[{"line_number":416,"context_line":"* Middleware should only add sensitive sysmeta headers to PUT requests on"},{"line_number":417,"context_line":"  proxy-servers that have been upgraded to support the namespace. Sensitive"},{"line_number":418,"context_line":"  sysmeta headers set on a PUT request on a proxy-server that does not support"},{"line_number":419,"context_line":"  the namespace will not be encrypted."},{"line_number":420,"context_line":"* During a rolling upgrade that introduces support for the sensitive namespace,"},{"line_number":421,"context_line":"  some proxies may start to encrypt sensitive namespace headers in PUT requests"},{"line_number":422,"context_line":"  before other proxies are capable of decrypting them in GET or HEAD"}],"source_content_type":"text/x-rst","patch_set":16,"id":"4c2aa951_396f099e","line":419,"updated":"2026-09-10 19:52:37.000000000","message":"But they *will* be stored, right? Would the middleware be able to tell the difference?\n\nWhat do we expect middlewares to do if the proxy hasn\u0027t been upgraded yet? 500? Or just skip trying to write anything in the sensitive namespace? Does the situation change any if the middleware is trying to support both old and new Swift?","commit_id":"d73d0b3fb00013404fd436c70c746693b6d52271"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"36c867c231daa7f117a1671ffbf7f30f88b3434a","unresolved":true,"context_lines":[{"line_number":416,"context_line":"* Middleware should only add sensitive sysmeta headers to PUT requests on"},{"line_number":417,"context_line":"  proxy-servers that have been upgraded to support the namespace. Sensitive"},{"line_number":418,"context_line":"  sysmeta headers set on a PUT request on a proxy-server that does not support"},{"line_number":419,"context_line":"  the namespace will not be encrypted."},{"line_number":420,"context_line":"* During a rolling upgrade that introduces support for the sensitive namespace,"},{"line_number":421,"context_line":"  some proxies may start to encrypt sensitive namespace headers in PUT requests"},{"line_number":422,"context_line":"  before other proxies are capable of decrypting them in GET or HEAD"}],"source_content_type":"text/x-rst","patch_set":16,"id":"ab94e317_53712519","line":419,"in_reply_to":"4c2aa951_396f099e","updated":"2026-09-11 10:32:14.000000000","message":"\u003e But they will be stored, right? \nyes and we should make that clear.\n\n\u003e What do we expect middlewares to do if the proxy hasn\u0027t been upgraded yet?\nI think the implication is \"don\u0027t upgrade middleware before upgrading swift\", and we should make that more obvious.","commit_id":"d73d0b3fb00013404fd436c70c746693b6d52271"},{"author":{"_account_id":15343,"name":"Tim Burke","email":"tburke@nvidia.com","username":"tburke"},"change_message_id":"4fed9be7cae936e44dd5196144823187601aa6a0","unresolved":false,"context_lines":[{"line_number":416,"context_line":"* Middleware should only add sensitive sysmeta headers to PUT requests on"},{"line_number":417,"context_line":"  proxy-servers that have been upgraded to support the namespace. Sensitive"},{"line_number":418,"context_line":"  sysmeta headers set on a PUT request on a proxy-server that does not support"},{"line_number":419,"context_line":"  the namespace will not be encrypted."},{"line_number":420,"context_line":"* During a rolling upgrade that introduces support for the sensitive namespace,"},{"line_number":421,"context_line":"  some proxies may start to encrypt sensitive namespace headers in PUT requests"},{"line_number":422,"context_line":"  before other proxies are capable of decrypting them in GET or HEAD"}],"source_content_type":"text/x-rst","patch_set":16,"id":"9d21504f_29cfd280","line":419,"in_reply_to":"ab94e317_53712519","updated":"2026-09-16 22:58:57.000000000","message":"\u003e yes and we should make that clear.\n\nDone:\n\n\u003e If the pipeline does not contain the encryption middleware, no values are encrypted.\n\nand\n\n\u003e Sensitive sysmeta headers will *not* be encrypted and their plaintext values will be stored if they are added to a PUT request on a proxy-server that has not been upgraded to support the sensitive sysmeta namespace.\n\n---\n\n\u003e I think the implication is \"don\u0027t upgrade middleware before upgrading swift\", and we should make that more obvious.\n\nI guess this is the idea behind\n\n\u003e When a cluster has encryption enabled, it is strongly recommended that *all* swift proxy-servers are upgraded to support the sensitive sysmeta namespace before any middleware starts to use the namespace.\n\n? But see my comment around there.","commit_id":"d73d0b3fb00013404fd436c70c746693b6d52271"},{"author":{"_account_id":15343,"name":"Tim Burke","email":"tburke@nvidia.com","username":"tburke"},"change_message_id":"1b5b757a6dc3a4c156060d836bc418f861b5d066","unresolved":true,"context_lines":[{"line_number":426,"context_line":""},{"line_number":427,"context_line":"Similar cautions apply if encryption is to be enabled by a rolling"},{"line_number":428,"context_line":"configuration change in a cluster that has support for the sensitive sysmeta"},{"line_number":429,"context_line":"namespace."}],"source_content_type":"text/x-rst","patch_set":16,"id":"83bb3605_a52f9bdf","line":429,"updated":"2026-09-10 19:52:37.000000000","message":"This is part of what the `disable_encryption` option is for, yeah? Start a rolling config change to include encryption with `disable_encryption \u003d True`, wait until that finishes, then do another one to set `disable_encryption \u003d False` (or just remove the option).","commit_id":"d73d0b3fb00013404fd436c70c746693b6d52271"},{"author":{"_account_id":15343,"name":"Tim Burke","email":"tburke@nvidia.com","username":"tburke"},"change_message_id":"4fed9be7cae936e44dd5196144823187601aa6a0","unresolved":true,"context_lines":[{"line_number":426,"context_line":""},{"line_number":427,"context_line":"Similar cautions apply if encryption is to be enabled by a rolling"},{"line_number":428,"context_line":"configuration change in a cluster that has support for the sensitive sysmeta"},{"line_number":429,"context_line":"namespace."}],"source_content_type":"text/x-rst","patch_set":16,"id":"aa5ec27d_b86d4496","line":429,"in_reply_to":"0b49d920_949c64cb","updated":"2026-09-16 22:58:57.000000000","message":"Yes, there will be a window where some proxies are encrypting sensitive sysmeta and others aren\u0027t, but there will *also* be some proxies encrypting etags and user meta while others aren\u0027t. I think that\u0027s just a necessary part of turning on encryption.\n\nIncluding this feels inconsistent. We say\n\n\u003e Middleware must store sensitive object system metadata in the sensitive sysmeta namespace, by using a header of the form `X-Object-Sysmeta-Sensitive-\u003ckey\u003e: \u003cvalue\u003e`.\n\nwith no reference to encryption, then\n\n\u003e If the pipeline contains the encryption middleware, the encrypter encrypts each non-empty value in the sensitive sysmeta namespace with the object key. ... If the pipeline does not contain the encryption middleware, no values are encrypted.\n\nso we\u0027re already taking the stance that sensitive sysmeta *may* be stored unencrypted; there\u0027s no guarantee that it will be encrypted. As long as it gets encrypted if and only if all the *other* metadata we might encrypt gets encrypted, I feel like the general enabling-encryption docs are enough.\n\n---\n\nOr maybe we\u0027re looking for a caveat like\n\n\u003e If introducing a middleware that **requires** sensitive sysmeta be encrypted, be sure to enable encryption throughout the cluster *before* enabling the new middleware.\n\n?","commit_id":"d73d0b3fb00013404fd436c70c746693b6d52271"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"36c867c231daa7f117a1671ffbf7f30f88b3434a","unresolved":true,"context_lines":[{"line_number":426,"context_line":""},{"line_number":427,"context_line":"Similar cautions apply if encryption is to be enabled by a rolling"},{"line_number":428,"context_line":"configuration change in a cluster that has support for the sensitive sysmeta"},{"line_number":429,"context_line":"namespace."}],"source_content_type":"text/x-rst","patch_set":16,"id":"0b49d920_949c64cb","line":429,"in_reply_to":"83bb3605_a52f9bdf","updated":"2026-09-11 10:32:14.000000000","message":"when you roll out ``disable_encryption \u003d True`` there\u0027s still going to be a window of time in which some proxies are not encrypting sensitive sysmeta and some are, so the first caution applies but maybe not the second.","commit_id":"d73d0b3fb00013404fd436c70c746693b6d52271"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"aaa96a1d4e999c9823f0c47fcc7e40045efc4654","unresolved":true,"context_lines":[{"line_number":426,"context_line":""},{"line_number":427,"context_line":"Similar cautions apply if encryption is to be enabled by a rolling"},{"line_number":428,"context_line":"configuration change in a cluster that has support for the sensitive sysmeta"},{"line_number":429,"context_line":"namespace."}],"source_content_type":"text/x-rst","patch_set":16,"id":"61452926_f282f656","line":429,"in_reply_to":"aa5ec27d_b86d4496","updated":"2026-09-17 09:03:04.000000000","message":"Re: \n\u003e we\u0027re already taking the stance that sensitive sysmeta may be stored unencrypted;\n\n1. The section should start by establishing the precondition, perhaps something like:\n\n\"When a cluster has encryption enabled then sysmeta values that are considered to be sensitive can be encrypted.\"\n\nand then proceed to say:\n\n\"Middleware developers can identify sensitive sysmeta by \u003cinsert chosen mechanism: naming, registry etc\u003e. The encrypter middleware encrypts each\nnon-empty sensitive sysmeta value with the object key. It then\nreplaces the original ``X-Object-Sysmeta-\u003ckey\u003e`` header with an\n``X-Object-Sysmeta-Crypto-\u003ckey\u003e: \u003cencrypted value\u003e`` header. Empty values\nare not encrypted and those headers are not replaced. The decrypter puts back\nthe original header name and decrypted value before other middleware reads the\nresponse.\n\nNote: Sensitive sysmeta will only be encrypted when the encryption middleware is in the pipeline and encryption is enabled.\".\n\nAs for the mechanism, one reason I am leaning towards using a registry of sensitive sysmeta keys is because embedding ``-Sensitive-`` in the name is a distraction/deception if you don\u0027t have crypto enabled. (cf. Tim\u0027s strawman). Whereas registering a \"hint\" to crypto is a little less so.\n\nThe other reasons I prefer a registry approach are:\n\n* it avoids any possible collision with existing third party sysmeta names\n\n* it is consistent with the pattern for a registry of sensitive headers\n\n* it allows existing sysmeta keys to be later registered for encryption\n\n-----\n\nRe: encryption enablement:\n\nI agree that perhaps we should just simplify to a caveat/cross-reference such as:\n\n\u003e If introducing a middleware that requires sensitive sysmeta be encrypted, be sure to enable encryption throughout the cluster before enabling the new middleware.\n\nOne other nit though: this statement is ops guidance, but this is a development document.\n\nI felt when I drafted this that I was slipping down a slope into too many ifs and buts!","commit_id":"d73d0b3fb00013404fd436c70c746693b6d52271"},{"author":{"_account_id":34930,"name":"Jianjian Huo","email":"jhuo@nvidia.com","username":"jhuo"},"change_message_id":"fa43733d5d50add790110899902714a4a5e8a569","unresolved":true,"context_lines":[{"line_number":409,"context_line":"Upgrading to use the sensitive sysmeta namespace"},{"line_number":410,"context_line":"------------------------------------------------"},{"line_number":411,"context_line":""},{"line_number":412,"context_line":"When a cluster has encryption enabled, it is strongly recommended that *all*"},{"line_number":413,"context_line":"swift proxy-servers are upgraded to support the sensitive sysmeta namespace"},{"line_number":414,"context_line":"before any middleware starts to use the namespace. If this is not possible then"},{"line_number":415,"context_line":"the following should be noted:"}],"source_content_type":"text/x-rst","patch_set":18,"id":"9d3fcca1_0738d5c6","line":412,"updated":"2026-09-14 04:46:54.000000000","message":"sounds like we are going to need a checkpoint release before putting ``991516: s3api: Checksum Persistence for Full Object Upload PUTs | https://review.opendev.org/c/openstack/swift/+/991516`` in a release; but how to handle upstream releases?","commit_id":"4d36f9e79587fcc807a511b933d097fdfac2eedd"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"8483599d200fe33a5851c6a8c274531fbc6a31f3","unresolved":true,"context_lines":[{"line_number":409,"context_line":"Upgrading to use the sensitive sysmeta namespace"},{"line_number":410,"context_line":"------------------------------------------------"},{"line_number":411,"context_line":""},{"line_number":412,"context_line":"When a cluster has encryption enabled, it is strongly recommended that *all*"},{"line_number":413,"context_line":"swift proxy-servers are upgraded to support the sensitive sysmeta namespace"},{"line_number":414,"context_line":"before any middleware starts to use the namespace. If this is not possible then"},{"line_number":415,"context_line":"the following should be noted:"}],"source_content_type":"text/x-rst","patch_set":18,"id":"6961cb3d_76310446","line":412,"in_reply_to":"9d3fcca1_0738d5c6","updated":"2026-09-14 08:17:52.000000000","message":"I\u0027m not sure we do. During a rolling upgrade that ships both sensitive sysmeta support and checksum persistence, upgraded proxies will start to persist checksums AND encrypt them, older proxies will not return the persisted checksum which is the same as before upgrade. i.e. we are addressing both of the following notes.","commit_id":"4d36f9e79587fcc807a511b933d097fdfac2eedd"},{"author":{"_account_id":15343,"name":"Tim Burke","email":"tburke@nvidia.com","username":"tburke"},"change_message_id":"4fed9be7cae936e44dd5196144823187601aa6a0","unresolved":true,"context_lines":[{"line_number":411,"context_line":""},{"line_number":412,"context_line":"When a cluster has encryption enabled, it is strongly recommended that *all*"},{"line_number":413,"context_line":"swift proxy-servers are upgraded to support the sensitive sysmeta namespace"},{"line_number":414,"context_line":"before any middleware starts to use the namespace. If this is not possible then"},{"line_number":415,"context_line":"the following should be noted:"},{"line_number":416,"context_line":""},{"line_number":417,"context_line":"* Middleware should only add sensitive sysmeta headers to PUT requests on"}],"source_content_type":"text/x-rst","patch_set":18,"id":"d6942004_02927ffd","line":414,"updated":"2026-09-16 22:58:57.000000000","message":"This guidance feels weird to me; I think it\u0027s something about making the upgrade and package-management requirements contingent on the current config.\n\nLike, suppose I\u0027m on old Swift and I *don\u0027t* have encryption enabled. I find some cool 3rd party middleware that uses the sensitive namespace -- from these docs, I can go ahead and turn it on immediately, right? While if I had encryption enabled, I should wait -- upgrade Swift first, *then* I get to turn on my middleware.\n\nBut what happens if there\u0027s some nebulous plan to enable encryption? Do I have to upgrade Swift before I get my new feature? Otherwise, I can\u0027t ensure\n\n\u003e Middleware should only add sensitive sysmeta headers to PUT requests on proxy-servers that have been upgraded to support the sensitive sysmeta namespace.\n\n*later*, if I enable both encryption and the new middleware on old Swift *now*.\n\nWhat if both Swift upgrades and encryption enablement have a history of being low priority work? Which do you wait for before getting your feature? Or do you try to use the feature as leverage to force higher prioritization of both the other two?","commit_id":"4d36f9e79587fcc807a511b933d097fdfac2eedd"},{"author":{"_account_id":34930,"name":"Jianjian Huo","email":"jhuo@nvidia.com","username":"jhuo"},"change_message_id":"fa43733d5d50add790110899902714a4a5e8a569","unresolved":true,"context_lines":[{"line_number":429,"context_line":"* During a rolling upgrade that introduces support for the sensitive namespace,"},{"line_number":430,"context_line":"  some proxies may start to encrypt sensitive namespace headers in PUT requests"},{"line_number":431,"context_line":"  before other proxies are capable of decrypting them in GET or HEAD"},{"line_number":432,"context_line":"  responses. This may result in sensitive sysmeta namespace headers being"},{"line_number":433,"context_line":"  absent from some GET or HEAD responses, until all proxy-servers support the"},{"line_number":434,"context_line":"  sensitive sysmeta namespace. Middleware should be designed to tolerate this."},{"line_number":435,"context_line":""}],"source_content_type":"text/x-rst","patch_set":18,"id":"7f19d215_6062a395","line":432,"updated":"2026-09-14 04:46:54.000000000","message":"yes, GET or HEAD responses is an concern here.","commit_id":"4d36f9e79587fcc807a511b933d097fdfac2eedd"}],"swift/common/middleware/crypto/crypto_utils.py":[{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"f28af65d7b1dc107ea28a1d23062afb4ac37def4","unresolved":true,"context_lines":[{"line_number":32,"context_line":"# The encrypter stores encrypted sensitive sysmeta here. The name is inside"},{"line_number":33,"context_line":"# x-object-sysmeta-crypto-, which the decrypter removes from responses."},{"line_number":34,"context_line":"ENCRYPTED_SENSITIVE_SYSMETA_PREFIX \u003d \\"},{"line_number":35,"context_line":"    get_sys_meta_prefix(\u0027object\u0027) + \u0027crypto-sensitive-\u0027"},{"line_number":36,"context_line":""},{"line_number":37,"context_line":""},{"line_number":38,"context_line":"class Crypto(object):"}],"source_content_type":"text/x-python","patch_set":6,"id":"af5ebcad_ee293da8","line":35,"updated":"2026-09-07 18:23:44.000000000","message":"ok, so this IS the pattern I prefer i.e. using ``get_sys_meta_prefix``","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"2287b5b3164335794c8ba9e90afbc0a89fce6a25","unresolved":false,"context_lines":[{"line_number":32,"context_line":"# The encrypter stores encrypted sensitive sysmeta here. The name is inside"},{"line_number":33,"context_line":"# x-object-sysmeta-crypto-, which the decrypter removes from responses."},{"line_number":34,"context_line":"ENCRYPTED_SENSITIVE_SYSMETA_PREFIX \u003d \\"},{"line_number":35,"context_line":"    get_sys_meta_prefix(\u0027object\u0027) + \u0027crypto-sensitive-\u0027"},{"line_number":36,"context_line":""},{"line_number":37,"context_line":""},{"line_number":38,"context_line":"class Crypto(object):"}],"source_content_type":"text/x-python","patch_set":6,"id":"891386af_05cdceb8","line":35,"in_reply_to":"af5ebcad_ee293da8","updated":"2026-09-08 17:53:39.000000000","message":"Acknowledged","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"}],"swift/common/middleware/crypto/decrypter.py":[{"author":{"_account_id":1179,"name":"Clay Gerrard","email":"clay.gerrard@gmail.com","username":"clay-gerrard"},"change_message_id":"cc4d0fe8e33aefbef04559d084037ced5944d65d","unresolved":true,"context_lines":[{"line_number":39,"context_line":"    return [h for h in headers if not"},{"line_number":40,"context_line":"            h[0].lower().startswith("},{"line_number":41,"context_line":"                (get_object_transient_sysmeta(\u0027crypto-\u0027),"},{"line_number":42,"context_line":"                 get_sys_meta_prefix(\u0027object\u0027) + \u0027crypto-\u0027))]"},{"line_number":43,"context_line":""},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"class BaseDecrypterContext(CryptoWSGIContext):"}],"source_content_type":"text/x-python","patch_set":5,"id":"759a8985_cbfa20fa","line":42,"updated":"2026-09-02 23:11:25.000000000","message":"this exisiting helper will cause old proxies to strip the entire crypto[-sensitive] namespace from replies \n\nduring rolling upgrades old mw code to the left of decrypter will not see the encrypted sensitive crypto sysmeta","commit_id":"fa71c232c898519d8b045a84717b22de0c675cb4"},{"author":{"_account_id":15343,"name":"Tim Burke","email":"tburke@nvidia.com","username":"tburke"},"change_message_id":"091f2d3a752166e4db10fc3ebc9fea4fab8ba3e0","unresolved":true,"context_lines":[{"line_number":39,"context_line":"    return [h for h in headers if not"},{"line_number":40,"context_line":"            h[0].lower().startswith("},{"line_number":41,"context_line":"                (get_object_transient_sysmeta(\u0027crypto-\u0027),"},{"line_number":42,"context_line":"                 get_sys_meta_prefix(\u0027object\u0027) + \u0027crypto-\u0027))]"},{"line_number":43,"context_line":""},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"class BaseDecrypterContext(CryptoWSGIContext):"}],"source_content_type":"text/x-python","patch_set":5,"id":"a790b479_328e3d42","line":42,"in_reply_to":"759a8985_cbfa20fa","updated":"2026-09-04 20:09:58.000000000","message":"Might also be worth calling out in over in https://review.opendev.org/c/openstack/swift/+/1003424/6/doc/source/development_middleware.rst where we\u0027ve already started to gather some rolling upgrade notes at the end.","commit_id":"fa71c232c898519d8b045a84717b22de0c675cb4"},{"author":{"_account_id":6968,"name":"Christian Schwede","email":"cschwede@nvidia.com","username":"cschwede"},"change_message_id":"f1a8770ede377e45ea5c99c14a98b31528b37ecc","unresolved":false,"context_lines":[{"line_number":39,"context_line":"    return [h for h in headers if not"},{"line_number":40,"context_line":"            h[0].lower().startswith("},{"line_number":41,"context_line":"                (get_object_transient_sysmeta(\u0027crypto-\u0027),"},{"line_number":42,"context_line":"                 get_sys_meta_prefix(\u0027object\u0027) + \u0027crypto-\u0027))]"},{"line_number":43,"context_line":""},{"line_number":44,"context_line":""},{"line_number":45,"context_line":"class BaseDecrypterContext(CryptoWSGIContext):"}],"source_content_type":"text/x-python","patch_set":5,"id":"61a6cb3f_93dd786a","line":42,"in_reply_to":"a790b479_328e3d42","updated":"2026-09-08 10:42:37.000000000","message":"Ack, done in latest patchset.","commit_id":"fa71c232c898519d8b045a84717b22de0c675cb4"},{"author":{"_account_id":15343,"name":"Tim Burke","email":"tburke@nvidia.com","username":"tburke"},"change_message_id":"091f2d3a752166e4db10fc3ebc9fea4fab8ba3e0","unresolved":true,"context_lines":[{"line_number":202,"context_line":"        \"\"\""},{"line_number":203,"context_line":"        Decrypt sensitive sysmeta and move it back to the"},{"line_number":204,"context_line":"        x-object-sysmeta-sensitive- namespace. Each value holds its own key"},{"line_number":205,"context_line":"        id, because an object with no body has no body crypto meta."},{"line_number":206,"context_line":""},{"line_number":207,"context_line":"        :param req: a Request object."},{"line_number":208,"context_line":"        :return: a list of (header, value) pairs of decrypted sysmeta."}],"source_content_type":"text/x-python","patch_set":6,"id":"5846279b_b0a89b11","line":205,"range":{"start_line":205,"start_character":47,"end_line":205,"end_character":66},"updated":"2026-09-04 20:09:58.000000000","message":"But we don\u0027t use that for user meta on zero-byte objects, right? Why can\u0027t we use the object key (not the body key) directly?","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":15343,"name":"Tim Burke","email":"tburke@nvidia.com","username":"tburke"},"change_message_id":"1b5b757a6dc3a4c156060d836bc418f861b5d066","unresolved":false,"context_lines":[{"line_number":202,"context_line":"        \"\"\""},{"line_number":203,"context_line":"        Decrypt sensitive sysmeta and move it back to the"},{"line_number":204,"context_line":"        x-object-sysmeta-sensitive- namespace. Each value holds its own key"},{"line_number":205,"context_line":"        id, because an object with no body has no body crypto meta."},{"line_number":206,"context_line":""},{"line_number":207,"context_line":"        :param req: a Request object."},{"line_number":208,"context_line":"        :return: a list of (header, value) pairs of decrypted sysmeta."}],"source_content_type":"text/x-python","patch_set":6,"id":"e80f8245_f7bf99ee","line":205,"range":{"start_line":205,"start_character":47,"end_line":205,"end_character":66},"in_reply_to":"31d2ab60_c8e5d9a1","updated":"2026-09-10 19:52:37.000000000","message":"Acknowledged","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":6968,"name":"Christian Schwede","email":"cschwede@nvidia.com","username":"cschwede"},"change_message_id":"7ea7a641cea9d070c75d6fd02e609fb300478481","unresolved":true,"context_lines":[{"line_number":202,"context_line":"        \"\"\""},{"line_number":203,"context_line":"        Decrypt sensitive sysmeta and move it back to the"},{"line_number":204,"context_line":"        x-object-sysmeta-sensitive- namespace. Each value holds its own key"},{"line_number":205,"context_line":"        id, because an object with no body has no body crypto meta."},{"line_number":206,"context_line":""},{"line_number":207,"context_line":"        :param req: a Request object."},{"line_number":208,"context_line":"        :return: a list of (header, value) pairs of decrypted sysmeta."}],"source_content_type":"text/x-python","patch_set":6,"id":"31d2ab60_c8e5d9a1","line":205,"range":{"start_line":205,"start_character":47,"end_line":205,"end_character":66},"in_reply_to":"5846279b_b0a89b11","updated":"2026-09-08 13:20:44.000000000","message":"We do use the object key. The per-value key fetch is now gone.","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"f28af65d7b1dc107ea28a1d23062afb4ac37def4","unresolved":true,"context_lines":[{"line_number":216,"context_line":"                short_name \u003d name[prefix_len:]"},{"line_number":217,"context_line":"                try:"},{"line_number":218,"context_line":"                    _junk, crypto_meta \u003d extract_crypto_meta(val)"},{"line_number":219,"context_line":"                    keys \u003d self.get_decryption_keys(req, crypto_meta)"},{"line_number":220,"context_line":"                except EncryptionException as err:"},{"line_number":221,"context_line":"                    self.logger.error("},{"line_number":222,"context_line":"                        \"Error decrypting header %(header)s: %(error)s\","}],"source_content_type":"text/x-python","patch_set":6,"id":"494b8820_46f5e4cc","line":219,"updated":"2026-09-07 18:23:44.000000000","message":"So ``put_keys`` and ``post_keys`` that are passed to ``decrypt_resp_headers`` are not relevant and we fetch keys again for *each* sensitive sysmeta.\n\nThe pattern for sensitive sysmeta is different that user metadata. For user metadata, we persist the key_id in crypto meta in a separate item of transient sysmeta, then fetch the ``post_keys`` once to decrypt all user meta items. For sensitive sysmeta we are storing the key_id with every item and fetching the key for every item. That may not be too \"expensive\" because IIUC keys are cached in the keymaster, but it is confusing, and leads to the dubious gating of sensitive sysmeta decryption on irrelevant keys.\n\nI\u0027d like us to consider replicating the pattern for user metadata i.e. persist the crypto meta and key_id  used for sensitive sysmeta under ``x-object-sysmeta-crypto-meta``, and use that to fetch \"sysmeta_keys\" once during decryption.","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":6968,"name":"Christian Schwede","email":"cschwede@nvidia.com","username":"cschwede"},"change_message_id":"7ea7a641cea9d070c75d6fd02e609fb300478481","unresolved":false,"context_lines":[{"line_number":216,"context_line":"                short_name \u003d name[prefix_len:]"},{"line_number":217,"context_line":"                try:"},{"line_number":218,"context_line":"                    _junk, crypto_meta \u003d extract_crypto_meta(val)"},{"line_number":219,"context_line":"                    keys \u003d self.get_decryption_keys(req, crypto_meta)"},{"line_number":220,"context_line":"                except EncryptionException as err:"},{"line_number":221,"context_line":"                    self.logger.error("},{"line_number":222,"context_line":"                        \"Error decrypting header %(header)s: %(error)s\","}],"source_content_type":"text/x-python","patch_set":6,"id":"5f5eae84_c2501882","line":219,"in_reply_to":"494b8820_46f5e4cc","updated":"2026-09-08 13:20:44.000000000","message":"Done, changes are now squashed in.","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"f28af65d7b1dc107ea28a1d23062afb4ac37def4","unresolved":true,"context_lines":[{"line_number":229,"context_line":"                result.append((new_prefix + short_name, decrypted_value))"},{"line_number":230,"context_line":"        return result"},{"line_number":231,"context_line":""},{"line_number":232,"context_line":"    def decrypt_resp_headers(self, req, put_keys, post_keys,"},{"line_number":233,"context_line":"                             update_cors_exposed):"},{"line_number":234,"context_line":"        \"\"\""},{"line_number":235,"context_line":"        Find encrypted headers and replace with the decrypted versions."}],"source_content_type":"text/x-python","patch_set":6,"id":"9108ebe3_2d0490ea","line":232,"range":{"start_line":232,"start_character":40,"end_line":232,"end_character":59},"updated":"2026-09-07 18:23:44.000000000","message":"these would be better named \"body_keys\" and \"user_meta_keys\"\n\n``put_keys`` is NOT necessarily the keys used for sensitive sysmeta encryption: if there was no body, and the keymaster has rotated keys since the object PUT, then ``put_keys`` is whatever the current keymaster keys are and not what was used to encrypt the sensitive sysmeta.","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"fe29e52c04aee4a0645c4897674224216506a216","unresolved":true,"context_lines":[{"line_number":229,"context_line":"                result.append((new_prefix + short_name, decrypted_value))"},{"line_number":230,"context_line":"        return result"},{"line_number":231,"context_line":""},{"line_number":232,"context_line":"    def decrypt_resp_headers(self, req, put_keys, post_keys,"},{"line_number":233,"context_line":"                             update_cors_exposed):"},{"line_number":234,"context_line":"        \"\"\""},{"line_number":235,"context_line":"        Find encrypted headers and replace with the decrypted versions."}],"source_content_type":"text/x-python","patch_set":6,"id":"3a8016cd_71c3ec62","line":232,"range":{"start_line":232,"start_character":40,"end_line":232,"end_character":59},"in_reply_to":"9108ebe3_2d0490ea","updated":"2026-09-08 08:22:41.000000000","message":"note: this comment is off-topic","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"f28af65d7b1dc107ea28a1d23062afb4ac37def4","unresolved":true,"context_lines":[{"line_number":262,"context_line":"                    etag_header, encrypted_etag, put_keys[\u0027container\u0027])"},{"line_number":263,"context_line":"                mod_hdr_pairs.append((etag_header, decrypted_etag))"},{"line_number":264,"context_line":""},{"line_number":265,"context_line":"            mod_hdr_pairs.extend(self.decrypt_sensitive_sysmeta(req))"},{"line_number":266,"context_line":""},{"line_number":267,"context_line":"        # Decrypt all user metadata. Encrypted user metadata values are stored"},{"line_number":268,"context_line":"        # in the x-object-transient-sysmeta-crypto-meta- namespace. Those are"}],"source_content_type":"text/x-python","patch_set":6,"id":"a268ec0f_14c44515","line":265,"updated":"2026-09-07 18:23:44.000000000","message":"this is conditional on ``put_keys`` and yet it does not use ``put_keys``, which is pretty confusing. It turns out (I think) that even for an empty body, with no Crypto-Body-Meta, there are still put_keys (whatever the keymaster current default keys are), so we\u0027ll get here even for an empty body, but it\u0027s really not clear why decrypting sensitive metadata should depend on ``put_keys`` when the ``decrypt_sensitive_sysmeta`` method then *fetches* keys again.","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"f28af65d7b1dc107ea28a1d23062afb4ac37def4","unresolved":true,"context_lines":[{"line_number":373,"context_line":"                content_type\u003d\u0027text/plain\u0027)"},{"line_number":374,"context_line":""},{"line_number":375,"context_line":"        if put_keys is None and post_keys is None:"},{"line_number":376,"context_line":"            # skip decryption"},{"line_number":377,"context_line":"            start_response(self._response_status, self._response_headers,"},{"line_number":378,"context_line":"                           self._response_exc_info)"},{"line_number":379,"context_line":"            return app_resp"}],"source_content_type":"text/x-python","patch_set":6,"id":"94ff12c7_83e7b2e4","line":376,"updated":"2026-09-07 18:23:44.000000000","message":"``decrypt_sensitive_sysmeta`` does not depend on these keys...but we might return early here before decrypting sensitive sysmeta. That is not *obviously* correct.","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"}],"swift/common/middleware/crypto/encrypter.py":[{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"f28af65d7b1dc107ea28a1d23062afb4ac37def4","unresolved":true,"context_lines":[{"line_number":96,"context_line":"            self.plaintext_md5 \u003d md5(usedforsecurity\u003dFalse)"},{"line_number":97,"context_line":"            self.ciphertext_md5 \u003d md5(usedforsecurity\u003dFalse)"},{"line_number":98,"context_line":""},{"line_number":99,"context_line":"    def install_footers_callback(self, req):"},{"line_number":100,"context_line":"        # the proxy controller will call back for footer metadata after"},{"line_number":101,"context_line":"        # body has been sent"},{"line_number":102,"context_line":"        inner_callback \u003d req.environ.get(\u0027swift.callback.update_footers\u0027)"}],"source_content_type":"text/x-python","patch_set":6,"id":"32ace092_2bf596ba","line":99,"range":{"start_line":99,"start_character":8,"end_line":99,"end_character":32},"updated":"2026-09-07 18:23:44.000000000","message":"nit: this method already does a more than install a callback, and now more functionality is being added. There is one instance of the class per PUT request, so we could filter out sensitive headers and hold them as an instance variable. I guess it\u0027s convenient to just hold them in the closure.\n\nPerhaps the comment could be expanded (or made a docstring):\n\n```\nGather state that will be needed to construct footer metadata,\nand install a callback that the proxy controller will call for\nfooter metadata after the body has been sent.\n```","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":6968,"name":"Christian Schwede","email":"cschwede@nvidia.com","username":"cschwede"},"change_message_id":"f1a8770ede377e45ea5c99c14a98b31528b37ecc","unresolved":false,"context_lines":[{"line_number":96,"context_line":"            self.plaintext_md5 \u003d md5(usedforsecurity\u003dFalse)"},{"line_number":97,"context_line":"            self.ciphertext_md5 \u003d md5(usedforsecurity\u003dFalse)"},{"line_number":98,"context_line":""},{"line_number":99,"context_line":"    def install_footers_callback(self, req):"},{"line_number":100,"context_line":"        # the proxy controller will call back for footer metadata after"},{"line_number":101,"context_line":"        # body has been sent"},{"line_number":102,"context_line":"        inner_callback \u003d req.environ.get(\u0027swift.callback.update_footers\u0027)"}],"source_content_type":"text/x-python","patch_set":6,"id":"02f6efe4_bb67ccaa","line":99,"range":{"start_line":99,"start_character":8,"end_line":99,"end_character":32},"in_reply_to":"32ace092_2bf596ba","updated":"2026-09-08 10:42:37.000000000","message":"Acknowledged","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":15343,"name":"Tim Burke","email":"tburke@nvidia.com","username":"tburke"},"change_message_id":"091f2d3a752166e4db10fc3ebc9fea4fab8ba3e0","unresolved":true,"context_lines":[{"line_number":105,"context_line":"        client_etag \u003d req.headers.pop(\u0027etag\u0027, None)"},{"line_number":106,"context_line":"        override_header \u003d get_container_update_override_key(\u0027etag\u0027)"},{"line_number":107,"context_line":"        container_listing_etag_header \u003d req.headers.get(override_header)"},{"line_number":108,"context_line":"        # Remove sensitive sysmeta from the headers, for example a value"},{"line_number":109,"context_line":"        # from the source of a COPY. The footers callback puts it back."},{"line_number":110,"context_line":"        header_sensitive_sysmeta \u003d {}"},{"line_number":111,"context_line":"        for name in list(req.headers):"},{"line_number":112,"context_line":"            if is_object_sensitive_sysmeta(name) and req.headers[name]:"}],"source_content_type":"text/x-python","patch_set":6,"id":"5ebd04fe_dce4a2a8","line":109,"range":{"start_line":108,"start_character":53,"end_line":109,"end_character":35},"updated":"2026-09-04 20:09:58.000000000","message":"I guess this is trying to explain why we\u0027d be looking for it in headers at all, when the main example we\u0027ve got is wanting to write down a CRC which requires reading the whole body, so it\u0027s gotta be passed as a footer?\n\nAnother fun use for this namespace might be something like an auth middleware annotating who the uploader is for an object. That could always go in headers, and I could see wanting to keep the value secret...","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"f28af65d7b1dc107ea28a1d23062afb4ac37def4","unresolved":true,"context_lines":[{"line_number":105,"context_line":"        client_etag \u003d req.headers.pop(\u0027etag\u0027, None)"},{"line_number":106,"context_line":"        override_header \u003d get_container_update_override_key(\u0027etag\u0027)"},{"line_number":107,"context_line":"        container_listing_etag_header \u003d req.headers.get(override_header)"},{"line_number":108,"context_line":"        # Remove sensitive sysmeta from the headers, for example a value"},{"line_number":109,"context_line":"        # from the source of a COPY. The footers callback puts it back."},{"line_number":110,"context_line":"        header_sensitive_sysmeta \u003d {}"},{"line_number":111,"context_line":"        for name in list(req.headers):"},{"line_number":112,"context_line":"            if is_object_sensitive_sysmeta(name) and req.headers[name]:"}],"source_content_type":"text/x-python","patch_set":6,"id":"67d4b7d6_2480cec9","line":109,"range":{"start_line":108,"start_character":53,"end_line":109,"end_character":35},"in_reply_to":"5ebd04fe_dce4a2a8","updated":"2026-09-07 18:23:44.000000000","message":"We have recently had a separate discussion about whether copy middleware should be copying *any* sysmeta at all.","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"f28af65d7b1dc107ea28a1d23062afb4ac37def4","unresolved":true,"context_lines":[{"line_number":109,"context_line":"        # from the source of a COPY. The footers callback puts it back."},{"line_number":110,"context_line":"        header_sensitive_sysmeta \u003d {}"},{"line_number":111,"context_line":"        for name in list(req.headers):"},{"line_number":112,"context_line":"            if is_object_sensitive_sysmeta(name) and req.headers[name]:"},{"line_number":113,"context_line":"                header_sensitive_sysmeta[name] \u003d req.headers.pop(name)"},{"line_number":114,"context_line":""},{"line_number":115,"context_line":"        def footers_callback(footers):"}],"source_content_type":"text/x-python","patch_set":6,"id":"8e1c3f0d_8b4c8401","line":112,"range":{"start_line":112,"start_character":53,"end_line":112,"end_character":70},"updated":"2026-09-07 18:23:44.000000000","message":"this presumes that ``\u0027x-object-sysmeta-sensitive-my-mw-secret\u0027: \u0027\u0027`` is *not* sensitive, which doesn\u0027t seem like a necessary restriction on the sensitive namespace.","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":6968,"name":"Christian Schwede","email":"cschwede@nvidia.com","username":"cschwede"},"change_message_id":"f1a8770ede377e45ea5c99c14a98b31528b37ecc","unresolved":false,"context_lines":[{"line_number":109,"context_line":"        # from the source of a COPY. The footers callback puts it back."},{"line_number":110,"context_line":"        header_sensitive_sysmeta \u003d {}"},{"line_number":111,"context_line":"        for name in list(req.headers):"},{"line_number":112,"context_line":"            if is_object_sensitive_sysmeta(name) and req.headers[name]:"},{"line_number":113,"context_line":"                header_sensitive_sysmeta[name] \u003d req.headers.pop(name)"},{"line_number":114,"context_line":""},{"line_number":115,"context_line":"        def footers_callback(footers):"}],"source_content_type":"text/x-python","patch_set":6,"id":"13b56942_34964687","line":112,"range":{"start_line":112,"start_character":53,"end_line":112,"end_character":70},"in_reply_to":"8e1c3f0d_8b4c8401","updated":"2026-09-08 10:42:37.000000000","message":"Ack, removed.","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"fe29e52c04aee4a0645c4897674224216506a216","unresolved":true,"context_lines":[{"line_number":109,"context_line":"        # from the source of a COPY. The footers callback puts it back."},{"line_number":110,"context_line":"        header_sensitive_sysmeta \u003d {}"},{"line_number":111,"context_line":"        for name in list(req.headers):"},{"line_number":112,"context_line":"            if is_object_sensitive_sysmeta(name) and req.headers[name]:"},{"line_number":113,"context_line":"                header_sensitive_sysmeta[name] \u003d req.headers.pop(name)"},{"line_number":114,"context_line":""},{"line_number":115,"context_line":"        def footers_callback(footers):"}],"source_content_type":"text/x-python","patch_set":6,"id":"e676d0df_5fdbdd25","line":112,"range":{"start_line":112,"start_character":53,"end_line":112,"end_character":70},"in_reply_to":"8e1c3f0d_8b4c8401","updated":"2026-09-08 08:22:41.000000000","message":"Ignore this comment, I was being dumb. Encrypted empty string is the empty string, although our encrypter will raise a ValueError if you try to encrypt an empty header:\n\n```\n../../../../../swift/common/middleware/crypto/encrypter.py:115: in encrypt_sensitive_sysmeta\n    enc_val, crypto_meta \u003d encrypt_header_val(\n../../../../../swift/common/middleware/crypto/encrypter.py:48: in encrypt_header_val\n    raise ValueError(\u0027empty value is not acceptable\u0027)\nE   ValueError: empty value is not acceptable\n```","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"f28af65d7b1dc107ea28a1d23062afb4ac37def4","unresolved":true,"context_lines":[{"line_number":120,"context_line":"                inner_callback(footers)"},{"line_number":121,"context_line":""},{"line_number":122,"context_line":"            # a value in the footers replaces a value in the headers"},{"line_number":123,"context_line":"            sensitive_sysmeta \u003d dict(header_sensitive_sysmeta)"},{"line_number":124,"context_line":"            for name in list(footers):"},{"line_number":125,"context_line":"                if is_object_sensitive_sysmeta(name) and footers[name]:"},{"line_number":126,"context_line":"                    sensitive_sysmeta[name] \u003d footers.pop(name)"}],"source_content_type":"text/x-python","patch_set":6,"id":"9b7e34fa_73bfe7f9","line":123,"updated":"2026-09-07 18:23:44.000000000","message":"why the copy? do we ever expect (and support) footers_callback to be called more than once?","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":6968,"name":"Christian Schwede","email":"cschwede@nvidia.com","username":"cschwede"},"change_message_id":"7ea7a641cea9d070c75d6fd02e609fb300478481","unresolved":true,"context_lines":[{"line_number":120,"context_line":"                inner_callback(footers)"},{"line_number":121,"context_line":""},{"line_number":122,"context_line":"            # a value in the footers replaces a value in the headers"},{"line_number":123,"context_line":"            sensitive_sysmeta \u003d dict(header_sensitive_sysmeta)"},{"line_number":124,"context_line":"            for name in list(footers):"},{"line_number":125,"context_line":"                if is_object_sensitive_sysmeta(name) and footers[name]:"},{"line_number":126,"context_line":"                    sensitive_sysmeta[name] \u003d footers.pop(name)"}],"source_content_type":"text/x-python","patch_set":6,"id":"0a66365b_218c934d","line":123,"in_reply_to":"9b7e34fa_73bfe7f9","updated":"2026-09-08 13:20:44.000000000","message":"Right, this is no longer needed. Dropped.","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":15343,"name":"Tim Burke","email":"tburke@nvidia.com","username":"tburke"},"change_message_id":"091f2d3a752166e4db10fc3ebc9fea4fab8ba3e0","unresolved":false,"context_lines":[{"line_number":121,"context_line":""},{"line_number":122,"context_line":"            # a value in the footers replaces a value in the headers"},{"line_number":123,"context_line":"            sensitive_sysmeta \u003d dict(header_sensitive_sysmeta)"},{"line_number":124,"context_line":"            for name in list(footers):"},{"line_number":125,"context_line":"                if is_object_sensitive_sysmeta(name) and footers[name]:"},{"line_number":126,"context_line":"                    sensitive_sysmeta[name] \u003d footers.pop(name)"},{"line_number":127,"context_line":""}],"source_content_type":"text/x-python","patch_set":6,"id":"591bd830_eb6e7602","line":124,"range":{"start_line":124,"start_character":24,"end_line":124,"end_character":28},"updated":"2026-09-04 20:09:58.000000000","message":"Right: make a copy since we\u0027ll be `pop()`ping.","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":15343,"name":"Tim Burke","email":"tburke@nvidia.com","username":"tburke"},"change_message_id":"091f2d3a752166e4db10fc3ebc9fea4fab8ba3e0","unresolved":true,"context_lines":[{"line_number":122,"context_line":"            # a value in the footers replaces a value in the headers"},{"line_number":123,"context_line":"            sensitive_sysmeta \u003d dict(header_sensitive_sysmeta)"},{"line_number":124,"context_line":"            for name in list(footers):"},{"line_number":125,"context_line":"                if is_object_sensitive_sysmeta(name) and footers[name]:"},{"line_number":126,"context_line":"                    sensitive_sysmeta[name] \u003d footers.pop(name)"},{"line_number":127,"context_line":""},{"line_number":128,"context_line":"            # Encrypt also when there is no body: unlike the Etag, a"}],"source_content_type":"text/x-python","patch_set":6,"id":"54eff0bb_5aad9d0f","line":125,"range":{"start_line":125,"start_character":53,"end_line":125,"end_character":70},"updated":"2026-09-04 20:09:58.000000000","message":"Why this requirement? Object server doesn\u0027t do that [when it merges footers to headers](https://github.com/openstack/swift/blob/2.38.1/swift/obj/server.py#L1012-L1014).","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"f28af65d7b1dc107ea28a1d23062afb4ac37def4","unresolved":true,"context_lines":[{"line_number":122,"context_line":"            # a value in the footers replaces a value in the headers"},{"line_number":123,"context_line":"            sensitive_sysmeta \u003d dict(header_sensitive_sysmeta)"},{"line_number":124,"context_line":"            for name in list(footers):"},{"line_number":125,"context_line":"                if is_object_sensitive_sysmeta(name) and footers[name]:"},{"line_number":126,"context_line":"                    sensitive_sysmeta[name] \u003d footers.pop(name)"},{"line_number":127,"context_line":""},{"line_number":128,"context_line":"            # Encrypt also when there is no body: unlike the Etag, a"}],"source_content_type":"text/x-python","patch_set":6,"id":"a1917732_302f17a7","line":125,"range":{"start_line":125,"start_character":53,"end_line":125,"end_character":70},"in_reply_to":"54eff0bb_5aad9d0f","updated":"2026-09-07 18:23:44.000000000","message":"Also note that footers is a HeaderKeyDict which cannot have ``None`` values\n\nThis condition contradicts the comment \"a value in the footers replaces a value in the headers\" because an empty string will not replace a value in the headers","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":6968,"name":"Christian Schwede","email":"cschwede@nvidia.com","username":"cschwede"},"change_message_id":"7ea7a641cea9d070c75d6fd02e609fb300478481","unresolved":true,"context_lines":[{"line_number":122,"context_line":"            # a value in the footers replaces a value in the headers"},{"line_number":123,"context_line":"            sensitive_sysmeta \u003d dict(header_sensitive_sysmeta)"},{"line_number":124,"context_line":"            for name in list(footers):"},{"line_number":125,"context_line":"                if is_object_sensitive_sysmeta(name) and footers[name]:"},{"line_number":126,"context_line":"                    sensitive_sysmeta[name] \u003d footers.pop(name)"},{"line_number":127,"context_line":""},{"line_number":128,"context_line":"            # Encrypt also when there is no body: unlike the Etag, a"}],"source_content_type":"text/x-python","patch_set":6,"id":"04813b48_0f686ecf","line":125,"range":{"start_line":125,"start_character":53,"end_line":125,"end_character":70},"in_reply_to":"a1917732_302f17a7","updated":"2026-09-08 13:20:44.000000000","message":"\u003e Why this requirement? Object server doesn\u0027t do that when it merges footers to headers.\n\nChanged in latest patchset, `filter_sensitive_sysmeta` now removes an empty value too, so a value in the footers replaces a value in the headers, as the object server does.","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":15343,"name":"Tim Burke","email":"tburke@nvidia.com","username":"tburke"},"change_message_id":"091f2d3a752166e4db10fc3ebc9fea4fab8ba3e0","unresolved":true,"context_lines":[{"line_number":125,"context_line":"                if is_object_sensitive_sysmeta(name) and footers[name]:"},{"line_number":126,"context_line":"                    sensitive_sysmeta[name] \u003d footers.pop(name)"},{"line_number":127,"context_line":""},{"line_number":128,"context_line":"            # Encrypt also when there is no body: unlike the Etag, a"},{"line_number":129,"context_line":"            # sensitive value can be secret when the body is empty. Keep the"},{"line_number":130,"context_line":"            # key id, because a zero byte object has no body crypto meta."},{"line_number":131,"context_line":"            for name, val in sensitive_sysmeta.items():"}],"source_content_type":"text/x-python","patch_set":6,"id":"30f7c5da_200ab876","line":128,"range":{"start_line":128,"start_character":22,"end_line":128,"end_character":31},"updated":"2026-09-04 20:09:58.000000000","message":"\"even when\" reads better to me.","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":6968,"name":"Christian Schwede","email":"cschwede@nvidia.com","username":"cschwede"},"change_message_id":"7ea7a641cea9d070c75d6fd02e609fb300478481","unresolved":false,"context_lines":[{"line_number":125,"context_line":"                if is_object_sensitive_sysmeta(name) and footers[name]:"},{"line_number":126,"context_line":"                    sensitive_sysmeta[name] \u003d footers.pop(name)"},{"line_number":127,"context_line":""},{"line_number":128,"context_line":"            # Encrypt also when there is no body: unlike the Etag, a"},{"line_number":129,"context_line":"            # sensitive value can be secret when the body is empty. Keep the"},{"line_number":130,"context_line":"            # key id, because a zero byte object has no body crypto meta."},{"line_number":131,"context_line":"            for name, val in sensitive_sysmeta.items():"}],"source_content_type":"text/x-python","patch_set":6,"id":"8b75e6a6_7c035ebd","line":128,"range":{"start_line":128,"start_character":22,"end_line":128,"end_character":31},"in_reply_to":"30f7c5da_200ab876","updated":"2026-09-08 13:20:44.000000000","message":"Done","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"f28af65d7b1dc107ea28a1d23062afb4ac37def4","unresolved":true,"context_lines":[{"line_number":126,"context_line":"                    sensitive_sysmeta[name] \u003d footers.pop(name)"},{"line_number":127,"context_line":""},{"line_number":128,"context_line":"            # Encrypt also when there is no body: unlike the Etag, a"},{"line_number":129,"context_line":"            # sensitive value can be secret when the body is empty. Keep the"},{"line_number":130,"context_line":"            # key id, because a zero byte object has no body crypto meta."},{"line_number":131,"context_line":"            for name, val in sensitive_sysmeta.items():"},{"line_number":132,"context_line":"                new_name \u003d ENCRYPTED_SENSITIVE_SYSMETA_PREFIX + \\"},{"line_number":133,"context_line":"                    strip_object_sensitive_sysmeta_prefix(name)"}],"source_content_type":"text/x-python","patch_set":6,"id":"32adca5b_4b4988bb","line":130,"range":{"start_line":129,"start_character":68,"end_line":130,"end_character":72},"updated":"2026-09-07 18:23:44.000000000","message":"\"Keep\" implies it\u0027s already there and we\u0027re not popping it. I\u0027d suggest:\n\n\"Include the key_id in the val_crypto_meta because it won\u0027t be persisted with body_crypto_meta when there is no body\".\n\n(note also use the actual underscored variable names)","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"f28af65d7b1dc107ea28a1d23062afb4ac37def4","unresolved":true,"context_lines":[{"line_number":130,"context_line":"            # key id, because a zero byte object has no body crypto meta."},{"line_number":131,"context_line":"            for name, val in sensitive_sysmeta.items():"},{"line_number":132,"context_line":"                new_name \u003d ENCRYPTED_SENSITIVE_SYSMETA_PREFIX + \\"},{"line_number":133,"context_line":"                    strip_object_sensitive_sysmeta_prefix(name)"},{"line_number":134,"context_line":"                enc_val, val_crypto_meta \u003d encrypt_header_val("},{"line_number":135,"context_line":"                    self.crypto, val, self.keys[\u0027object\u0027])"},{"line_number":136,"context_line":"                val_crypto_meta[\u0027key_id\u0027] \u003d self.keys[\u0027id\u0027]"}],"source_content_type":"text/x-python","patch_set":6,"id":"9c8757b1_5cdbb543","line":133,"updated":"2026-09-07 18:23:44.000000000","message":"nit: it seemed a little odd that we strip the ``-sensitive-`` part of the name only to then replace with the same:\n\ni.e. from the tests module\n```\nSENSITIVE_HEADER \u003d \u0027X-Object-Sysmeta-Sensitive-Test-Digest\u0027\nENC_SENSITIVE_HEADER \u003d \\\n    \u0027X-Object-Sysmeta-Crypto-Sensitive-Test-Digest\u0027\n```\n\nthe prefix that actually *changes is* ``X-Object-Sysmeta-`` to ``X-Object-Sysmeta-Crypto-``","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"f28af65d7b1dc107ea28a1d23062afb4ac37def4","unresolved":true,"context_lines":[{"line_number":133,"context_line":"                    strip_object_sensitive_sysmeta_prefix(name)"},{"line_number":134,"context_line":"                enc_val, val_crypto_meta \u003d encrypt_header_val("},{"line_number":135,"context_line":"                    self.crypto, val, self.keys[\u0027object\u0027])"},{"line_number":136,"context_line":"                val_crypto_meta[\u0027key_id\u0027] \u003d self.keys[\u0027id\u0027]"},{"line_number":137,"context_line":"                footers[new_name] \u003d append_crypto_meta("},{"line_number":138,"context_line":"                    enc_val, val_crypto_meta)"},{"line_number":139,"context_line":""}],"source_content_type":"text/x-python","patch_set":6,"id":"d08373de_2001ea55","line":136,"updated":"2026-09-07 18:23:44.000000000","message":"ok, unlike the Etag case below, we need to include this key_id in the per-header crypto_meta. For Etag, we also persist X-Object-Sysmeta-Crypto-Body-Meta which has the key_id, but we can\u0027t rely on that for these sensitive headers.","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"f28af65d7b1dc107ea28a1d23062afb4ac37def4","unresolved":true,"context_lines":[{"line_number":154,"context_line":"                # as sysmeta along with the crypto parameters that were used."},{"line_number":155,"context_line":"                encrypted_etag, etag_crypto_meta \u003d encrypt_header_val("},{"line_number":156,"context_line":"                    self.crypto, plaintext_etag, self.keys[\u0027object\u0027])"},{"line_number":157,"context_line":"                footers[\u0027X-Object-Sysmeta-Crypto-Etag\u0027] \u003d \\"},{"line_number":158,"context_line":"                    append_crypto_meta(encrypted_etag, etag_crypto_meta)"},{"line_number":159,"context_line":"                footers[\u0027X-Object-Sysmeta-Crypto-Body-Meta\u0027] \u003d \\"},{"line_number":160,"context_line":"                    dump_crypto_meta(self.body_crypto_meta)"}],"source_content_type":"text/x-python","patch_set":6,"id":"561dab21_28ef370c","line":157,"range":{"start_line":157,"start_character":25,"end_line":157,"end_character":49},"updated":"2026-09-07 18:23:44.000000000","message":"it\u0027s unfortunate that it\u0027s not obvious that this is the same namespace that the ``-sensitive-*`` sysmeta lives in. We could perhaps (as a follow on) introduce a ``crypto_sysmeta_header(name)`` helper.","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":6968,"name":"Christian Schwede","email":"cschwede@nvidia.com","username":"cschwede"},"change_message_id":"f1a8770ede377e45ea5c99c14a98b31528b37ecc","unresolved":true,"context_lines":[{"line_number":154,"context_line":"                # as sysmeta along with the crypto parameters that were used."},{"line_number":155,"context_line":"                encrypted_etag, etag_crypto_meta \u003d encrypt_header_val("},{"line_number":156,"context_line":"                    self.crypto, plaintext_etag, self.keys[\u0027object\u0027])"},{"line_number":157,"context_line":"                footers[\u0027X-Object-Sysmeta-Crypto-Etag\u0027] \u003d \\"},{"line_number":158,"context_line":"                    append_crypto_meta(encrypted_etag, etag_crypto_meta)"},{"line_number":159,"context_line":"                footers[\u0027X-Object-Sysmeta-Crypto-Body-Meta\u0027] \u003d \\"},{"line_number":160,"context_line":"                    dump_crypto_meta(self.body_crypto_meta)"}],"source_content_type":"text/x-python","patch_set":6,"id":"f40f7ef7_a1e4ce9e","line":157,"range":{"start_line":157,"start_character":25,"end_line":157,"end_character":49},"in_reply_to":"561dab21_28ef370c","updated":"2026-09-08 10:42:37.000000000","message":"Good idea, let\u0027s do that as a follow on.","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"f28af65d7b1dc107ea28a1d23062afb4ac37def4","unresolved":true,"context_lines":[{"line_number":252,"context_line":"            req.headers.pop(name)"},{"line_number":253,"context_line":"        # store a single copy of the crypto meta items that are common to all"},{"line_number":254,"context_line":"        # encrypted user metadata independently of any such meta that is stored"},{"line_number":255,"context_line":"        # with the object body because it might change on a POST. This is done"},{"line_number":256,"context_line":"        # for future-proofing - the meta stored here is not currently used"},{"line_number":257,"context_line":"        # during decryption."},{"line_number":258,"context_line":"        if crypto_meta:"},{"line_number":259,"context_line":"            meta \u003d dump_crypto_meta({\u0027cipher\u0027: crypto_meta[\u0027cipher\u0027],"},{"line_number":260,"context_line":"                                     \u0027key_id\u0027: keys[\u0027id\u0027]})"}],"source_content_type":"text/x-python","patch_set":6,"id":"85599868_8b74d3f6","line":257,"range":{"start_line":255,"start_character":66,"end_line":257,"end_character":28},"updated":"2026-09-07 18:23:44.000000000","message":"I think this is stale - we do now read the user meta crypto meta from the companion header","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":6968,"name":"Christian Schwede","email":"cschwede@nvidia.com","username":"cschwede"},"change_message_id":"f1a8770ede377e45ea5c99c14a98b31528b37ecc","unresolved":false,"context_lines":[{"line_number":252,"context_line":"            req.headers.pop(name)"},{"line_number":253,"context_line":"        # store a single copy of the crypto meta items that are common to all"},{"line_number":254,"context_line":"        # encrypted user metadata independently of any such meta that is stored"},{"line_number":255,"context_line":"        # with the object body because it might change on a POST. This is done"},{"line_number":256,"context_line":"        # for future-proofing - the meta stored here is not currently used"},{"line_number":257,"context_line":"        # during decryption."},{"line_number":258,"context_line":"        if crypto_meta:"},{"line_number":259,"context_line":"            meta \u003d dump_crypto_meta({\u0027cipher\u0027: crypto_meta[\u0027cipher\u0027],"},{"line_number":260,"context_line":"                                     \u0027key_id\u0027: keys[\u0027id\u0027]})"}],"source_content_type":"text/x-python","patch_set":6,"id":"7af70ed3_041025a6","line":257,"range":{"start_line":255,"start_character":66,"end_line":257,"end_character":28},"in_reply_to":"85599868_8b74d3f6","updated":"2026-09-08 10:42:37.000000000","message":"Done","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"fe29e52c04aee4a0645c4897674224216506a216","unresolved":true,"context_lines":[{"line_number":252,"context_line":"            req.headers.pop(name)"},{"line_number":253,"context_line":"        # store a single copy of the crypto meta items that are common to all"},{"line_number":254,"context_line":"        # encrypted user metadata independently of any such meta that is stored"},{"line_number":255,"context_line":"        # with the object body because it might change on a POST. This is done"},{"line_number":256,"context_line":"        # for future-proofing - the meta stored here is not currently used"},{"line_number":257,"context_line":"        # during decryption."},{"line_number":258,"context_line":"        if crypto_meta:"},{"line_number":259,"context_line":"            meta \u003d dump_crypto_meta({\u0027cipher\u0027: crypto_meta[\u0027cipher\u0027],"},{"line_number":260,"context_line":"                                     \u0027key_id\u0027: keys[\u0027id\u0027]})"}],"source_content_type":"text/x-python","patch_set":6,"id":"5f75619d_e8c0733d","line":257,"range":{"start_line":255,"start_character":66,"end_line":257,"end_character":28},"in_reply_to":"85599868_8b74d3f6","updated":"2026-09-08 08:22:41.000000000","message":"note: off-topic","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":15343,"name":"Tim Burke","email":"tburke@nvidia.com","username":"tburke"},"change_message_id":"091f2d3a752166e4db10fc3ebc9fea4fab8ba3e0","unresolved":true,"context_lines":[{"line_number":263,"context_line":"    def handle_put(self, req, start_response):"},{"line_number":264,"context_line":"        self._check_headers(req)"},{"line_number":265,"context_line":"        keys \u003d self.get_keys(req.environ, required\u003d[\u0027object\u0027, \u0027container\u0027])"},{"line_number":266,"context_line":"        self.encrypt_user_metadata(req, keys)"},{"line_number":267,"context_line":""},{"line_number":268,"context_line":"        enc_input_proxy \u003d EncInputWrapper(self.crypto, keys, req, self.logger)"},{"line_number":269,"context_line":"        req.environ[\u0027wsgi.input\u0027] \u003d enc_input_proxy"}],"source_content_type":"text/x-python","patch_set":6,"id":"ac94deee_257ff5c9","line":266,"updated":"2026-09-04 20:09:58.000000000","message":"Off-topic: I just realized -- we don\u0027t encrypt user meta that turns up in footers. I feel like Timur had some middleware that would do that, maybe pulling EXIF tags from images as they\u0027re uploaded or something...","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"}],"swift/common/middleware/versioned_writes/object_versioning.py":[{"author":{"_account_id":39146,"name":"Nathaniel Martes","display_name":"Nate Martes","email":"natemartes09@gmail.com","username":"nmartes"},"change_message_id":"01dfecce2526e1d9b91e53127752be3e16b539f7","unresolved":false,"context_lines":[{"line_number":464,"context_line":"        )"},{"line_number":465,"context_line":"        for header in not_for_symlink_headers:"},{"line_number":466,"context_line":"            req.headers.pop(header, None)"},{"line_number":467,"context_line":"        # sensitive sysmeta describes the version object, not this symlink"},{"line_number":468,"context_line":"        for header in [h for h in req.headers"},{"line_number":469,"context_line":"                       if is_object_sensitive_sysmeta(h)]:"},{"line_number":470,"context_line":"            req.headers.pop(header)"}],"source_content_type":"text/x-python","patch_set":4,"id":"8d78180f_466cda48","line":467,"range":{"start_line":467,"start_character":0,"end_line":467,"end_character":74},"updated":"2026-09-02 15:44:31.000000000","message":"Yes seems reasonable","commit_id":"28eefcf1e1a502ab477b352d53c3519d0ef31fea"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"2287b5b3164335794c8ba9e90afbc0a89fce6a25","unresolved":true,"context_lines":[{"line_number":467,"context_line":"        # sensitive sysmeta describes the version object, not this symlink"},{"line_number":468,"context_line":"        for header in [h for h in req.headers"},{"line_number":469,"context_line":"                       if is_object_sensitive_sysmeta(h)]:"},{"line_number":470,"context_line":"            req.headers.pop(header)"},{"line_number":471,"context_line":""},{"line_number":472,"context_line":"        # *do* set swift_source here; this PUT is an implementation detail"},{"line_number":473,"context_line":"        req.environ[\u0027swift.source\u0027] \u003d \u0027OV\u0027"}],"source_content_type":"text/x-python","patch_set":9,"id":"1a511533_3c487f08","line":470,"updated":"2026-09-08 17:53:39.000000000","message":"hmmm, why is sensitive sysmeta treated differently from other sysmeta w.r.t. the symlink? IIUC the symlink will still get the checksum type and algorithm sysmeta, but the checksum value sysmeta will be stripped...which seems confusing?\n\nwould it matter if we persisted (encrypted) sensitive sysmeta with symlinks?","commit_id":"1bb5ce42c338c849b1e2ddca353b24d014b34072"},{"author":{"_account_id":6968,"name":"Christian Schwede","email":"cschwede@nvidia.com","username":"cschwede"},"change_message_id":"6d9a3b7c4dd73a655e4210b4152b711f80971b9b","unresolved":true,"context_lines":[{"line_number":467,"context_line":"        # sensitive sysmeta describes the version object, not this symlink"},{"line_number":468,"context_line":"        for header in [h for h in req.headers"},{"line_number":469,"context_line":"                       if is_object_sensitive_sysmeta(h)]:"},{"line_number":470,"context_line":"            req.headers.pop(header)"},{"line_number":471,"context_line":""},{"line_number":472,"context_line":"        # *do* set swift_source here; this PUT is an implementation detail"},{"line_number":473,"context_line":"        req.environ[\u0027swift.source\u0027] \u003d \u0027OV\u0027"}],"source_content_type":"text/x-python","patch_set":9,"id":"cc91ac3b_58f47cf8","line":470,"in_reply_to":"1a511533_3c487f08","updated":"2026-09-09 09:54:45.000000000","message":"It would not matter today. There might be a theoretical issue if we don\u0027t drop this header:\n\n1. Upload with a S3 checksum\n2. Client copies object into a versioned container\n3. The copy middleware will use the checksum persistence headers in the PUT request\n4. The versioning middleware creates a symlink with all checksum headers\n5. Middleware or internal client sends a GET using `symlink\u003dget` and gets a checksum of a 0-byte object.","commit_id":"1bb5ce42c338c849b1e2ddca353b24d014b34072"},{"author":{"_account_id":6968,"name":"Christian Schwede","email":"cschwede@nvidia.com","username":"cschwede"},"change_message_id":"25e8d8347faddafa9beed926d8f2a344b82855a4","unresolved":true,"context_lines":[{"line_number":467,"context_line":"        # sensitive sysmeta describes the version object, not this symlink"},{"line_number":468,"context_line":"        for header in [h for h in req.headers"},{"line_number":469,"context_line":"                       if is_object_sensitive_sysmeta(h)]:"},{"line_number":470,"context_line":"            req.headers.pop(header)"},{"line_number":471,"context_line":""},{"line_number":472,"context_line":"        # *do* set swift_source here; this PUT is an implementation detail"},{"line_number":473,"context_line":"        req.environ[\u0027swift.source\u0027] \u003d \u0027OV\u0027"}],"source_content_type":"text/x-python","patch_set":9,"id":"2b066354_68f0be83","line":470,"in_reply_to":"cc91ac3b_58f47cf8","updated":"2026-09-09 10:56:21.000000000","message":"Alistair reminded me that this is no longer an issue because we merged 1001706: s3api: don\u0027t copy all s3api sysmeta when copying objects | https://review.opendev.org/c/openstack/swift/+/1001706 two weeks ago.","commit_id":"1bb5ce42c338c849b1e2ddca353b24d014b34072"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"675de47200ec712c735f90ed9b772a2d57541abf","unresolved":true,"context_lines":[{"line_number":464,"context_line":"        )"},{"line_number":465,"context_line":"        for header in not_for_symlink_headers:"},{"line_number":466,"context_line":"            req.headers.pop(header, None)"},{"line_number":467,"context_line":"        # sensitive sysmeta describes the version object, not this symlink"},{"line_number":468,"context_line":"        for header in [h for h in req.headers"},{"line_number":469,"context_line":"                       if is_object_sensitive_sysmeta(h)]:"},{"line_number":470,"context_line":"            req.headers.pop(header)"}],"source_content_type":"text/x-python","patch_set":11,"id":"01715271_0517497d","line":467,"updated":"2026-09-09 08:22:06.000000000","message":"if this stays then we should say why we are only dropping the sensitive sysmeta, given that *all* sysmeta relates to the version object (apart from the symlink sysmeta of course)","commit_id":"33e5aeb2ee1b8e746996e75906ac4772c04e8f08"},{"author":{"_account_id":22348,"name":"Zuul","username":"zuul","tags":["SERVICE_USER"]},"tag":"autogenerated:zuul:check","change_message_id":"b83c6a13c8d8144e63b9551b5549f361d91b3a95","unresolved":false,"context_lines":[{"line_number":151,"context_line":"    ACCOUNT_LISTING_LIMIT, CONTAINER_LISTING_LIMIT"},{"line_number":152,"context_line":"from swift.common.http import is_success, is_client_error, HTTP_NOT_FOUND, \\"},{"line_number":153,"context_line":"    HTTP_CONFLICT"},{"line_number":154,"context_line":"from swift.common.request_helpers import get_sys_meta_prefix, \\"},{"line_number":155,"context_line":"    copy_header_subset, get_reserved_name, split_reserved_name, \\"},{"line_number":156,"context_line":"    constrain_req_limit, is_object_sensitive_sysmeta"},{"line_number":157,"context_line":"from swift.common.middleware import app_property"}],"source_content_type":"text/x-python","patch_set":15,"id":"d9061b05_b9c7b652","line":154,"updated":"2026-09-09 16:49:28.000000000","message":"pep8: F401 \u0027swift.common.request_helpers.is_object_sensitive_sysmeta\u0027 imported but unused","commit_id":"a0aac4c34ea337b3707a1625fde96b75af531969"}],"swift/common/request_helpers.py":[{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"f28af65d7b1dc107ea28a1d23062afb4ac37def4","unresolved":true,"context_lines":[{"line_number":47,"context_line":"OBJECT_TRANSIENT_SYSMETA_PREFIX \u003d \u0027x-object-transient-sysmeta-\u0027"},{"line_number":48,"context_line":"OBJECT_SYSMETA_CONTAINER_UPDATE_OVERRIDE_PREFIX \u003d \\"},{"line_number":49,"context_line":"    \u0027x-object-sysmeta-container-update-override-\u0027"},{"line_number":50,"context_line":"OBJECT_SENSITIVE_SYSMETA_PREFIX \u003d \u0027x-object-sysmeta-sensitive-\u0027"},{"line_number":51,"context_line":"USE_REPLICATION_NETWORK_HEADER \u003d \u0027x-backend-use-replication-network\u0027"},{"line_number":52,"context_line":"MISPLACED_OBJECTS_ACCOUNT \u003d \u0027.misplaced_objects\u0027"},{"line_number":53,"context_line":""}],"source_content_type":"text/x-python","patch_set":6,"id":"ba9ed3a5_215f3fe9","line":50,"updated":"2026-09-07 18:23:44.000000000","message":"I\u0027d prefer to stick to ``get_sys_meta_prefix`` being the single point of truth for the ``x-object-sysmeta-`` part of the prefix, rather than hardcoding it in ``OBJECT_SENSITIVE_SYSMETA_PREFIX``, but I can see that  ``OBJECT_SYSMETA_CONTAINER_UPDATE_OVERRIDE_PREFIX`` has already broken that principle.","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":15343,"name":"Tim Burke","email":"tburke@nvidia.com","username":"tburke"},"change_message_id":"091f2d3a752166e4db10fc3ebc9fea4fab8ba3e0","unresolved":true,"context_lines":[{"line_number":377,"context_line":"    if not is_object_transient_sysmeta(key):"},{"line_number":378,"context_line":"        raise ValueError(\u0027Key is not object transient sysmeta\u0027)"},{"line_number":379,"context_line":"    return key[len(OBJECT_TRANSIENT_SYSMETA_PREFIX):]"},{"line_number":380,"context_line":""},{"line_number":381,"context_line":""},{"line_number":382,"context_line":"def get_user_meta_prefix(server_type):"},{"line_number":383,"context_line":"    \"\"\""}],"source_content_type":"text/x-python","patch_set":6,"id":"cc34ac05_405484fa","line":380,"updated":"2026-09-04 20:09:58.000000000","message":"Better to have `strip_object_sensitive_sysmeta_prefix` around here?","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":15343,"name":"Tim Burke","email":"tburke@nvidia.com","username":"tburke"},"change_message_id":"091f2d3a752166e4db10fc3ebc9fea4fab8ba3e0","unresolved":true,"context_lines":[{"line_number":417,"context_line":"    :returns: the entire object transient system metadata header for key"},{"line_number":418,"context_line":"    \"\"\""},{"line_number":419,"context_line":"    return \u0027%s%s\u0027 % (OBJECT_TRANSIENT_SYSMETA_PREFIX, key)"},{"line_number":420,"context_line":""},{"line_number":421,"context_line":""},{"line_number":422,"context_line":"def get_container_update_override_key(key):"},{"line_number":423,"context_line":"    \"\"\""}],"source_content_type":"text/x-python","patch_set":6,"id":"5929da7f_e14c203c","line":420,"updated":"2026-09-04 20:09:58.000000000","message":"Should `get_object_sensitive_sysmeta` be down here or so?","commit_id":"9941a3b9a4f7019dfeaefdd77d75bb6bda21741d"},{"author":{"_account_id":34930,"name":"Jianjian Huo","email":"jhuo@nvidia.com","username":"jhuo"},"change_message_id":"fa43733d5d50add790110899902714a4a5e8a569","unresolved":true,"context_lines":[{"line_number":44,"context_line":"from swift.common.wsgi import make_subrequest"},{"line_number":45,"context_line":""},{"line_number":46,"context_line":""},{"line_number":47,"context_line":"OBJECT_TRANSIENT_SYSMETA_PREFIX \u003d \u0027x-object-transient-sysmeta-\u0027"},{"line_number":48,"context_line":"OBJECT_SYSMETA_CONTAINER_UPDATE_OVERRIDE_PREFIX \u003d \\"},{"line_number":49,"context_line":"    \u0027x-object-sysmeta-container-update-override-\u0027"},{"line_number":50,"context_line":"OBJECT_SENSITIVE_SYSMETA_PREFIX \u003d \u0027x-object-sysmeta-sensitive-\u0027"}],"source_content_type":"text/x-python","patch_set":18,"id":"fbcde00a_6932e81f","line":47,"updated":"2026-09-14 04:46:54.000000000","message":"it\u0027s ``transient-sysmeta`` while the new one is ``sysmeta-sensitive``, how about ``sensitive-sysmeta``?","commit_id":"4d36f9e79587fcc807a511b933d097fdfac2eedd"},{"author":{"_account_id":7847,"name":"Alistair Coles","email":"alistairncoles@gmail.com","username":"acoles"},"change_message_id":"8483599d200fe33a5851c6a8c274531fbc6a31f3","unresolved":true,"context_lines":[{"line_number":44,"context_line":"from swift.common.wsgi import make_subrequest"},{"line_number":45,"context_line":""},{"line_number":46,"context_line":""},{"line_number":47,"context_line":"OBJECT_TRANSIENT_SYSMETA_PREFIX \u003d \u0027x-object-transient-sysmeta-\u0027"},{"line_number":48,"context_line":"OBJECT_SYSMETA_CONTAINER_UPDATE_OVERRIDE_PREFIX \u003d \\"},{"line_number":49,"context_line":"    \u0027x-object-sysmeta-container-update-override-\u0027"},{"line_number":50,"context_line":"OBJECT_SENSITIVE_SYSMETA_PREFIX \u003d \u0027x-object-sysmeta-sensitive-\u0027"}],"source_content_type":"text/x-python","patch_set":18,"id":"a5872c39_6b0185b1","line":47,"in_reply_to":"fbcde00a_6932e81f","updated":"2026-09-14 08:17:52.000000000","message":"That would require us to add support for a whole new namespace \u0027x-object-sensitive-sysmeta-*\u0027 in the object servers too (and other places like gatekeeper)","commit_id":"4d36f9e79587fcc807a511b933d097fdfac2eedd"}],"test/unit/common/middleware/crypto/test_decrypter.py":[{"author":{"_account_id":1179,"name":"Clay Gerrard","email":"clay.gerrard@gmail.com","username":"clay-gerrard"},"change_message_id":"cc4d0fe8e33aefbef04559d084037ced5944d65d","unresolved":true,"context_lines":[{"line_number":292,"context_line":"        enc_body \u003d encrypt(body, body_key, FAKE_IV)"},{"line_number":293,"context_line":"        hdrs \u003d self._make_response_headers("},{"line_number":294,"context_line":"            len(enc_body), md5hex(body), fetch_crypto_keys(), body_key)"},{"line_number":295,"context_line":"        hdrs[\u0027x-object-sysmeta-sensitive-other-digest\u0027] \u003d \u0027AAAAAA\u003d\u003d\u0027"},{"line_number":296,"context_line":"        self.app.register(\u0027GET\u0027, \u0027/v1/a/c/o\u0027, HTTPOk, body\u003denc_body,"},{"line_number":297,"context_line":"                          headers\u003dhdrs)"},{"line_number":298,"context_line":"        resp \u003d req.get_response(self.decrypter)"}],"source_content_type":"text/x-python","patch_set":5,"id":"d4c41e43_879aa5d1","line":295,"updated":"2026-09-02 23:11:25.000000000","message":"right, the registered proxy response has the plaintext sensitive sysmeta","commit_id":"fa71c232c898519d8b045a84717b22de0c675cb4"}],"test/unit/common/middleware/crypto/test_encryption.py":[{"author":{"_account_id":1179,"name":"Clay Gerrard","email":"clay.gerrard@gmail.com","username":"clay-gerrard"},"change_message_id":"cc4d0fe8e33aefbef04559d084037ced5944d65d","unresolved":true,"context_lines":[{"line_number":639,"context_line":"        self._check_match_requests("},{"line_number":640,"context_line":"            \u0027HEAD\u0027, self.proxy_app, object_path\u003ddest_obj_path)"},{"line_number":641,"context_line":""},{"line_number":642,"context_line":"        # the destination has no encrypter, so the value is in the clear"},{"line_number":643,"context_line":"        req \u003d Request.blank(dest_obj_path, method\u003d\u0027GET\u0027)"},{"line_number":644,"context_line":"        resp \u003d req.get_response(self.proxy_app)"},{"line_number":645,"context_line":"        self.assertEqual(\u0027200 OK\u0027, resp.status)"}],"source_content_type":"text/x-python","patch_set":5,"id":"1c825459_b37fceeb","line":642,"updated":"2026-09-02 23:11:25.000000000","message":"this is a good call out!","commit_id":"fa71c232c898519d8b045a84717b22de0c675cb4"}]}
