ggershinsky commented on code in PR #18220:
URL: https://github.com/apache/iceberg/pull/18220#discussion_r4215818144
##########
aws/src/main/java/org/apache/iceberg/aws/glue/GlueTableOperations.java:
##########
@@ -125,10 +195,20 @@ protected String tableName() {
@Override
protected void doRefresh() {
String metadataLocation = null;
+ String tableKeyIdFromGlue = null;
+ String dekLengthFromGlue = null;
+ String metadataHashFromGlue = null;
Table table = getGlueTable();
if (table != null) {
checkIfTableIsIceberg(table, tableName());
metadataLocation = table.parameters().get(METADATA_LOCATION_PROP);
+ /* Table key ID must be retrieved from a catalog service, and not from
untrusted storage
+ (e.g. metadata json file) that can be tampered with. For example, an
attacker can remove
+ the table key parameter (along with existing snapshots) in the file,
making the writers
+ produce unencrypted files. Table key ID is taken directly from the Glue
catalog */
+ tableKeyIdFromGlue =
table.parameters().get(TableProperties.ENCRYPTION_TABLE_KEY);
Review Comment:
The reasons are mostly historical - we started with a parameter fetch from a
trusted catalog; the hash check was added later.
However, the functional overlap is not full. If there is a random byte
corruption in the stored metadata, the hash check makes the table unsuitable
for future writes and reads (since we can't be sure about the key and other
encr parameters). But, if the key etc are kept in the catalog, theoretically
the table can be recovered in certain situations.
In the cost-benefit analysis of keeping both props and hash in the catalog,
I think the benefit part is not large. But the cost part is even smaller, since
it doesn't cost much to send a few strings to the catalog.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]