mirror of
https://github.com/MariaDB/server.git
synced 2025-08-01 03:47:19 +03:00
MDEV-8238: Tables with encryption=yes using file_key_management plugin are not encrypted
Analysis: Problem was that encryption was skipped. Fixed by making sure that tables with ENCRYPTED=YES are encrypted.
This commit is contained in:
@ -0,0 +1,143 @@
|
||||
# Restart mysqld --loose-file-key-management-filename=/home/jan/mysql/10.1-bugs/mysql-test/std_data/keys2.txt
|
||||
SET GLOBAL innodb_file_format = `Barracuda`;
|
||||
SET GLOBAL innodb_file_per_table = ON;
|
||||
create table innodb_normal(c1 bigint not null, b char(200)) engine=innodb;
|
||||
create table innodb_compact(c1 bigint not null, b char(200)) engine=innodb row_format=compact encrypted=yes encryption_key_id=2;
|
||||
create table innodb_compressed(c1 bigint not null, b char(200)) engine=innodb row_format=compressed encrypted=yes encryption_key_id=3;
|
||||
create table innodb_dynamic(c1 bigint not null, b char(200)) engine=innodb row_format=dynamic encrypted=yes encryption_key_id=4;
|
||||
create table innodb_redundant(c1 bigint not null, b char(200)) engine=innodb row_format=redundant encrypted=yes encryption_key_id=5;
|
||||
insert into innodb_normal values (1,'test1'),(2,'foo'),(3,'bar'),(4,'mariadb');
|
||||
insert into innodb_compact select * from innodb_normal;
|
||||
insert into innodb_compressed select * from innodb_normal;
|
||||
insert into innodb_dynamic select * from innodb_normal;
|
||||
insert into innodb_redundant select * from innodb_normal;
|
||||
SELECT variable_value >= 0 FROM information_schema.global_status WHERE LOWER(variable_name) = 'innodb_num_pages_encrypted';
|
||||
variable_value >= 0
|
||||
1
|
||||
SELECT variable_value >= 0 FROM information_schema.global_status WHERE LOWER(variable_name) = 'innodb_num_pages_decrypted';
|
||||
variable_value >= 0
|
||||
1
|
||||
alter table innodb_compact engine=innodb encryption_key_id = 6;
|
||||
alter table innodb_compressed engine=innodb encryption_key_id = 6;
|
||||
alter table innodb_dynamic engine=innodb encryption_key_id = 6;
|
||||
alter table innodb_redundant engine=innodb encryption_key_id = 6;
|
||||
select * from innodb_normal;
|
||||
c1 b
|
||||
1 test1
|
||||
2 foo
|
||||
3 bar
|
||||
4 mariadb
|
||||
select * from innodb_compact;
|
||||
c1 b
|
||||
1 test1
|
||||
2 foo
|
||||
3 bar
|
||||
4 mariadb
|
||||
select * from innodb_compressed;
|
||||
c1 b
|
||||
1 test1
|
||||
2 foo
|
||||
3 bar
|
||||
4 mariadb
|
||||
select * from innodb_dynamic;
|
||||
c1 b
|
||||
1 test1
|
||||
2 foo
|
||||
3 bar
|
||||
4 mariadb
|
||||
select * from innodb_redundant;
|
||||
c1 b
|
||||
1 test1
|
||||
2 foo
|
||||
3 bar
|
||||
4 mariadb
|
||||
SELECT variable_value >= 0 FROM information_schema.global_status WHERE LOWER(variable_name) = 'innodb_num_pages_encrypted';
|
||||
variable_value >= 0
|
||||
1
|
||||
SELECT variable_value >= 0 FROM information_schema.global_status WHERE LOWER(variable_name) = 'innodb_num_pages_decrypted';
|
||||
variable_value >= 0
|
||||
1
|
||||
# Restart mysqld --loose-file-key-management-filename=/home/jan/mysql/10.1-bugs/mysql-test/std_data/keys3.txt
|
||||
select * from innodb_normal;
|
||||
c1 b
|
||||
1 test1
|
||||
2 foo
|
||||
3 bar
|
||||
4 mariadb
|
||||
select * from innodb_compact;
|
||||
c1 b
|
||||
1 test1
|
||||
2 foo
|
||||
3 bar
|
||||
4 mariadb
|
||||
select * from innodb_compressed;
|
||||
c1 b
|
||||
1 test1
|
||||
2 foo
|
||||
3 bar
|
||||
4 mariadb
|
||||
select * from innodb_dynamic;
|
||||
c1 b
|
||||
1 test1
|
||||
2 foo
|
||||
3 bar
|
||||
4 mariadb
|
||||
select * from innodb_redundant;
|
||||
c1 b
|
||||
1 test1
|
||||
2 foo
|
||||
3 bar
|
||||
4 mariadb
|
||||
SELECT variable_value >= 0 FROM information_schema.global_status WHERE LOWER(variable_name) = 'innodb_num_pages_encrypted';
|
||||
variable_value >= 0
|
||||
1
|
||||
SELECT variable_value >= 0 FROM information_schema.global_status WHERE LOWER(variable_name) = 'innodb_num_pages_decrypted';
|
||||
variable_value >= 0
|
||||
1
|
||||
SET GLOBAL innodb_file_format = `Barracuda`;
|
||||
SET GLOBAL innodb_file_per_table = ON;
|
||||
alter table innodb_compact engine=innodb encryption_key_id = 2;
|
||||
alter table innodb_compressed engine=innodb encryption_key_id = 3;
|
||||
alter table innodb_dynamic engine=innodb encryption_key_id = 4;
|
||||
alter table innodb_redundant engine=innodb encryption_key_id = 5;
|
||||
select * from innodb_normal;
|
||||
c1 b
|
||||
1 test1
|
||||
2 foo
|
||||
3 bar
|
||||
4 mariadb
|
||||
select * from innodb_compact;
|
||||
c1 b
|
||||
1 test1
|
||||
2 foo
|
||||
3 bar
|
||||
4 mariadb
|
||||
select * from innodb_compressed;
|
||||
c1 b
|
||||
1 test1
|
||||
2 foo
|
||||
3 bar
|
||||
4 mariadb
|
||||
select * from innodb_dynamic;
|
||||
c1 b
|
||||
1 test1
|
||||
2 foo
|
||||
3 bar
|
||||
4 mariadb
|
||||
select * from innodb_redundant;
|
||||
c1 b
|
||||
1 test1
|
||||
2 foo
|
||||
3 bar
|
||||
4 mariadb
|
||||
SELECT variable_value >= 0 FROM information_schema.global_status WHERE LOWER(variable_name) = 'innodb_num_pages_encrypted';
|
||||
variable_value >= 0
|
||||
1
|
||||
SELECT variable_value >= 0 FROM information_schema.global_status WHERE LOWER(variable_name) = 'innodb_num_pages_decrypted';
|
||||
variable_value >= 0
|
||||
1
|
||||
drop table innodb_normal;
|
||||
drop table innodb_compact;
|
||||
drop table innodb_compressed;
|
||||
drop table innodb_dynamic;
|
||||
drop table innodb_redundant;
|
Reference in New Issue
Block a user