Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,10 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/), and this

## [Unreleased]

### Fixed

- **Large-object SigV4 signing** — Sign S3 requests with payload lengths above 2 GiB without rejecting their 64-bit `Content-Length` values.

## [5.15.1] - 2026-09-16

### Fixed
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2122,7 +2122,7 @@ protected final void applyAuthHeaders(

// Set payload header
final String contentLengthHeader = httpHeaders.get(HttpHeaderNames.CONTENT_LENGTH);
final int contentLength = contentLengthHeader == null ? 0 : Integer.parseInt(contentLengthHeader);
final long contentLength = contentLengthHeader == null ? 0 : Long.parseLong(contentLengthHeader);
if (contentLength > 0) {
httpHeaders.set(S3Api.AMZ_PAYLOAD_HEADER, S3Api.AMZ_UNSIGNED_PAYLOAD);
} else {
Expand Down Expand Up @@ -2259,7 +2259,7 @@ protected String getCanonicalV4(final HttpHeaders httpHeaders, final Map<String,
final String payloadHashHeader = httpHeaders.get(S3Api.AMZ_PAYLOAD_HEADER);
if (payloadHashHeader != null && !payloadHashHeader.isEmpty()) {
buffCanonical.append(payloadHashHeader);
} else if (Integer.parseInt(httpHeaders.get(HttpHeaderNames.CONTENT_LENGTH)) > 0) {
} else if (Long.parseLong(httpHeaders.get(HttpHeaderNames.CONTENT_LENGTH)) > 0) {
buffCanonical.append(S3Api.AMZ_UNSIGNED_PAYLOAD);
} else {
buffCanonical.append(S3Api.AMZ_EMPTY_BODY_SHA256);
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -547,6 +547,39 @@ void applyAuthHeaders_v4_setsUnsignedPayloadForBodies() throws Exception {
assertEquals(S3Api.AMZ_UNSIGNED_PAYLOAD, headers.get(S3Api.AMZ_PAYLOAD_HEADER));
}

@Test
void applyAuthHeaders_v4_acceptsContentLengthAboveIntegerRange() throws Exception {
Config cfg = baseConfig(false, 4, false, null, "s3.us-east-1.amazonaws.com:443");
TestS3Driver drv = new TestS3Driver(cfg);
HttpHeaders headers = new DefaultHttpHeaders();
headers.set(HttpHeaderNames.HOST, "s3.us-east-1.amazonaws.com:443");
headers.set(HttpHeaderNames.CONTENT_LENGTH, (long) Integer.MAX_VALUE + 1);

Method m = S3StorageDriver.class.getDeclaredMethod(
"applyAuthHeaders", HttpHeaders.class, HttpMethod.class, String.class, Credential.class);
m.setAccessible(true);
m.invoke(drv, headers, HttpMethod.PUT, "/bucket/obj", TEST_CRED);

assertEquals(S3Api.AMZ_UNSIGNED_PAYLOAD, headers.get(S3Api.AMZ_PAYLOAD_HEADER));
assertNotNull(headers.get(HttpHeaderNames.AUTHORIZATION));
}

@Test
void canonicalV4_acceptsContentLengthAboveIntegerRange() throws Exception {
S3StorageDriver<Item, Operation<Item>> drv = newDriverMock();
HttpHeaders headers = new DefaultHttpHeaders();
headers.set(HttpHeaderNames.HOST, "s3.test:443");
headers.set(HttpHeaderNames.CONTENT_LENGTH, (long) Integer.MAX_VALUE + 1);

Method m = S3StorageDriver.class.getDeclaredMethod(
"getCanonicalV4", HttpHeaders.class, Map.class, HttpMethod.class, String.class);
m.setAccessible(true);
String canonical = (String) m.invoke(
drv, headers, new TreeMap<String, String>(), HttpMethod.PUT, "/bucket/object");

assertTrue(canonical.endsWith(S3Api.AMZ_UNSIGNED_PAYLOAD));
}

@Test
void canonicalV4_insertsEmptyQueryLineWhenAbsent() throws Exception {
Config cfg = baseConfig(false, 4, false, null, "127.0.0.1:9020");
Expand Down
Loading