ggershinsky commented on code in PR #18220:
URL: https://github.com/apache/iceberg/pull/18220#discussion_r4215997325
##########
aws/src/main/java/org/apache/iceberg/aws/glue/GlueTableOperations.java:
##########
@@ -125,10 +195,20 @@ protected String tableName() {
@Override
protected void doRefresh() {
String metadataLocation = null;
+ String tableKeyIdFromGlue = null;
+ String dekLengthFromGlue = null;
+ String metadataHashFromGlue = null;
Table table = getGlueTable();
if (table != null) {
checkIfTableIsIceberg(table, tableName());
metadataLocation = table.parameters().get(METADATA_LOCATION_PROP);
+ /* Table key ID must be retrieved from a catalog service, and not from
untrusted storage
+ (e.g. metadata json file) that can be tampered with. For example, an
attacker can remove
+ the table key parameter (along with existing snapshots) in the file,
making the writers
+ produce unencrypted files. Table key ID is taken directly from the Glue
catalog */
+ tableKeyIdFromGlue =
table.parameters().get(TableProperties.ENCRYPTION_TABLE_KEY);
Review Comment:
btw, it might also help in the post-mortem analysis. If the table security
params (key etc) differ between catalog and metadata.json, it's likely an
attack. If these parameters are the same, it's likely a storage corruption.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]