mirror of
https://github.com/MariaDB/server.git
synced 2025-01-27 17:33:44 +01:00
180c44e0f6
Folloup: Made encryption rules too strict (and incorrect). Allow creating table with ENCRYPTED=OFF with all values of ENCRYPTION_KEY_ID but create warning that nondefault values are ignored. Allow creating table with ENCRYPTED=DEFAULT if used key_id is found from key file (there was bug on this) and give error if key_id is not found.
98 lines
2.8 KiB
Text
98 lines
2.8 KiB
Text
-- source include/have_innodb.inc
|
|
-- source include/have_file_key_management_plugin.inc
|
|
|
|
#
|
|
# MDEV-8817: Failing assertion: new_state->key_version != ENCRYPTION_KEY_VERSION_INVALID
|
|
#
|
|
|
|
--disable_query_log
|
|
let $innodb_file_format_orig = `SELECT @@innodb_file_format`;
|
|
let $innodb_file_per_table_orig = `SELECT @@innodb_file_per_table`;
|
|
let $encrypt_tables = `SELECT @@innodb_encrypt_tables`;
|
|
let $threads = `SELECT @@innodb_encryption_threads`;
|
|
--enable_query_log
|
|
|
|
SET GLOBAL innodb_file_format = `Barracuda`;
|
|
SET GLOBAL innodb_file_per_table = ON;
|
|
SET GLOBAL innodb_encrypt_tables = ON;
|
|
SET GLOBAL innodb_encryption_threads = 4;
|
|
|
|
CREATE TABLE t1 (pk INT PRIMARY KEY AUTO_INCREMENT, c VARCHAR(256)) ENGINE=INNODB ENCRYPTED=NO ENCRYPTION_KEY_ID=4;
|
|
DROP TABLE t1;
|
|
set innodb_default_encryption_key_id = 99;
|
|
--error 1005
|
|
CREATE TABLE t1 (pk INT PRIMARY KEY AUTO_INCREMENT, c VARCHAR(256)) ENGINE=INNODB;
|
|
SHOW WARNINGS;
|
|
--error 1005
|
|
CREATE TABLE t1 (pk INT PRIMARY KEY AUTO_INCREMENT, c VARCHAR(256)) ENGINE=INNODB ENCRYPTED=YES;
|
|
SHOW WARNINGS;
|
|
set innodb_default_encryption_key_id = 4;
|
|
CREATE TABLE t1 (pk INT PRIMARY KEY AUTO_INCREMENT, c VARCHAR(256)) ENGINE=INNODB ENCRYPTED=YES;
|
|
SHOW CREATE TABLE t1;
|
|
DROP TABLE t1;
|
|
CREATE TABLE t1 (pk INT PRIMARY KEY AUTO_INCREMENT, c VARCHAR(256)) ENGINE=INNODB;
|
|
SHOW CREATE TABLE t1;
|
|
CREATE TABLE t2 (pk INT PRIMARY KEY AUTO_INCREMENT, c VARCHAR(256)) ENGINE=INNODB ENCRYPTED=NO ENCRYPTION_KEY_ID=1;
|
|
--replace_regex /#sql-[0-9a-f_]*/#sql-temporary/
|
|
--error 1005
|
|
ALTER TABLE t1 ENCRYPTION_KEY_ID=99;
|
|
--replace_regex /#sql-[0-9a-f_]*/#sql-temporary/
|
|
SHOW WARNINGS;
|
|
set innodb_default_encryption_key_id = 1;
|
|
|
|
|
|
--disable_warnings
|
|
--disable_query_log
|
|
let $i = 400;
|
|
while ($i)
|
|
{
|
|
INSERT INTO t1 values(NULL, substring(MD5(RAND()), -128));
|
|
dec $i;
|
|
}
|
|
commit;
|
|
INSERT INTO t2 select * from t1;
|
|
|
|
--disable_abort_on_error
|
|
|
|
--connect (con1,localhost,root,,test)
|
|
--connect (con2,localhost,root,,test)
|
|
|
|
let $i = 50;
|
|
while ($i)
|
|
{
|
|
connection con1;
|
|
send ALTER TABLE t1 ENCRYPTED=NO ENCRYPTION_KEY_ID=1;
|
|
connection con2;
|
|
send ALTER TABLE t1 ENCRYPTED=YES ENCRYPTION_KEY_ID=4;
|
|
connection default;
|
|
send ALTER TABLE t2 ENCRYPTED=NO ENCRYPTION_KEY_ID=1;
|
|
connection con1;
|
|
--reap;
|
|
ALTER TABLE t1 ENCRYPTED=NO ENCRYPTION_KEY_ID=1;
|
|
connection con2;
|
|
--reap
|
|
ALTER TABLE t1 ENCRYPTED=YES ENCRYPTION_KEY_ID=4;
|
|
connection default;
|
|
--reap
|
|
ALTER TABLE t2 ENCRYPTED=YES ENCRYPTION_KEY_ID=1;
|
|
ALTER TABLE t1 ENCRYPTED=NO ENCRYPTION_KEY_ID=1;
|
|
dec $i;
|
|
}
|
|
|
|
connection default;
|
|
--disconnect con1
|
|
--disconnect con2
|
|
|
|
--enable_abort_on_error
|
|
--enable_warnings
|
|
--enable_query_log
|
|
|
|
drop table t1,t2;
|
|
|
|
# reset system
|
|
--disable_query_log
|
|
EVAL SET GLOBAL innodb_file_per_table = $innodb_file_per_table_orig;
|
|
EVAL SET GLOBAL innodb_file_format = $innodb_file_format_orig;
|
|
EVAL SET GLOBAL innodb_encrypt_tables = $encrypt_tables;
|
|
EVAL SET GLOBAL innodb_encryption_threads = $threads;
|
|
--enable_query_log
|