1
0
mirror of https://github.com/MariaDB/server.git synced 2025-08-01 03:47:19 +03:00

MDEV-8238: Tables with encryption=yes using file_key_management plugin are not encrypted

Analysis: Problem was that encryption was skipped.

Fixed by making sure that tables with ENCRYPTED=YES are encrypted.
This commit is contained in:
Jan Lindström
2015-05-27 15:37:13 +03:00
parent 2bea4bd9ed
commit a25ccd4f83
12 changed files with 259 additions and 79 deletions

View File

@ -0,0 +1,143 @@
# Restart mysqld --loose-file-key-management-filename=/home/jan/mysql/10.1-bugs/mysql-test/std_data/keys2.txt
SET GLOBAL innodb_file_format = `Barracuda`;
SET GLOBAL innodb_file_per_table = ON;
create table innodb_normal(c1 bigint not null, b char(200)) engine=innodb;
create table innodb_compact(c1 bigint not null, b char(200)) engine=innodb row_format=compact encrypted=yes encryption_key_id=2;
create table innodb_compressed(c1 bigint not null, b char(200)) engine=innodb row_format=compressed encrypted=yes encryption_key_id=3;
create table innodb_dynamic(c1 bigint not null, b char(200)) engine=innodb row_format=dynamic encrypted=yes encryption_key_id=4;
create table innodb_redundant(c1 bigint not null, b char(200)) engine=innodb row_format=redundant encrypted=yes encryption_key_id=5;
insert into innodb_normal values (1,'test1'),(2,'foo'),(3,'bar'),(4,'mariadb');
insert into innodb_compact select * from innodb_normal;
insert into innodb_compressed select * from innodb_normal;
insert into innodb_dynamic select * from innodb_normal;
insert into innodb_redundant select * from innodb_normal;
SELECT variable_value >= 0 FROM information_schema.global_status WHERE LOWER(variable_name) = 'innodb_num_pages_encrypted';
variable_value >= 0
1
SELECT variable_value >= 0 FROM information_schema.global_status WHERE LOWER(variable_name) = 'innodb_num_pages_decrypted';
variable_value >= 0
1
alter table innodb_compact engine=innodb encryption_key_id = 6;
alter table innodb_compressed engine=innodb encryption_key_id = 6;
alter table innodb_dynamic engine=innodb encryption_key_id = 6;
alter table innodb_redundant engine=innodb encryption_key_id = 6;
select * from innodb_normal;
c1 b
1 test1
2 foo
3 bar
4 mariadb
select * from innodb_compact;
c1 b
1 test1
2 foo
3 bar
4 mariadb
select * from innodb_compressed;
c1 b
1 test1
2 foo
3 bar
4 mariadb
select * from innodb_dynamic;
c1 b
1 test1
2 foo
3 bar
4 mariadb
select * from innodb_redundant;
c1 b
1 test1
2 foo
3 bar
4 mariadb
SELECT variable_value >= 0 FROM information_schema.global_status WHERE LOWER(variable_name) = 'innodb_num_pages_encrypted';
variable_value >= 0
1
SELECT variable_value >= 0 FROM information_schema.global_status WHERE LOWER(variable_name) = 'innodb_num_pages_decrypted';
variable_value >= 0
1
# Restart mysqld --loose-file-key-management-filename=/home/jan/mysql/10.1-bugs/mysql-test/std_data/keys3.txt
select * from innodb_normal;
c1 b
1 test1
2 foo
3 bar
4 mariadb
select * from innodb_compact;
c1 b
1 test1
2 foo
3 bar
4 mariadb
select * from innodb_compressed;
c1 b
1 test1
2 foo
3 bar
4 mariadb
select * from innodb_dynamic;
c1 b
1 test1
2 foo
3 bar
4 mariadb
select * from innodb_redundant;
c1 b
1 test1
2 foo
3 bar
4 mariadb
SELECT variable_value >= 0 FROM information_schema.global_status WHERE LOWER(variable_name) = 'innodb_num_pages_encrypted';
variable_value >= 0
1
SELECT variable_value >= 0 FROM information_schema.global_status WHERE LOWER(variable_name) = 'innodb_num_pages_decrypted';
variable_value >= 0
1
SET GLOBAL innodb_file_format = `Barracuda`;
SET GLOBAL innodb_file_per_table = ON;
alter table innodb_compact engine=innodb encryption_key_id = 2;
alter table innodb_compressed engine=innodb encryption_key_id = 3;
alter table innodb_dynamic engine=innodb encryption_key_id = 4;
alter table innodb_redundant engine=innodb encryption_key_id = 5;
select * from innodb_normal;
c1 b
1 test1
2 foo
3 bar
4 mariadb
select * from innodb_compact;
c1 b
1 test1
2 foo
3 bar
4 mariadb
select * from innodb_compressed;
c1 b
1 test1
2 foo
3 bar
4 mariadb
select * from innodb_dynamic;
c1 b
1 test1
2 foo
3 bar
4 mariadb
select * from innodb_redundant;
c1 b
1 test1
2 foo
3 bar
4 mariadb
SELECT variable_value >= 0 FROM information_schema.global_status WHERE LOWER(variable_name) = 'innodb_num_pages_encrypted';
variable_value >= 0
1
SELECT variable_value >= 0 FROM information_schema.global_status WHERE LOWER(variable_name) = 'innodb_num_pages_decrypted';
variable_value >= 0
1
drop table innodb_normal;
drop table innodb_compact;
drop table innodb_compressed;
drop table innodb_dynamic;
drop table innodb_redundant;