Skip to content

chore: replace aws-sdk-go v1 with aws-sdk-go-v2 - #7

Merged
locle2302 merged 1 commit into
masterfrom
chore/aws-sdk-go-v2
Sep 11, 2026
Merged

locle2302 merged 1 commit into
masterfrom
chore/aws-sdk-go-v2

Conversation

@locle2302

@locle2302 locle2302 commented Sep 11, 2026 •

Copy link
Copy Markdown
Collaborator

What

Ports the S3 and GCS backends, the credential providers and the V2 signer from aws-sdk-go v1 to aws-sdk-go-v2, removing the v1 module from the dependency graph.

Why

close https://github.com/parallelworks/core/issues/19809

aws-sdk-go v1 is flagged for CVE-2020-8911 and CVE-2020-8912. Both live in service/s3/s3crypto, which goofys never imports, and no v1 release fixes them. Scanners match at module level, so every binary embedding goofys is flagged, including all six pw CLI binaries in the ACTIVATE ingress image. Dropping the module is the only way to clear it. Tracked as CORE-7555.

Notable decisions

RequestChecksumCalculation and ResponseChecksumValidation are set to WhenRequired. The v2 default of WhenSupported adds CRC32 to every request and breaks S3-compatible stores.

The GCS resumable upload path moved from mutating request objects to smithy middleware, since v2 has no request object to mutate. The deserialize middleware still translates Google's 308 into a successful PutObjectOutput.

release.yml now uploads to an existing release instead of failing when the tag already has one.

Testing

Unit tests added for the ported surfaces: error mapping, V2 signatures, multipart, delete MD5, bucket detection and region, SSE-over-TLS, and GCS resumable.

Verified live on two ACTIVATE clusters with the rebuilt CLI, confirmed by binary hash, against a real AWS bucket and a real GCS bucket mounted through the interop endpoint. Both passed: small and 50MB writes with md5 verified byte-identical, ranged reads, file and directory renames, 50MB rename with md5 rechecked, listing 1200 objects past the pagination boundary, single and bulk deletes, and missing-file mapping to ENOENT.

Not covered: credential rotation, non-AWS S3 endpoints, and UploadPartCopy above the 5GB copy limit.

aws-sdk-go v1 is flagged for CVE-2020-8911 and CVE-2020-8912, which live in
the s3crypto package. No v1 release fixes them, so scanners flag every binary
that embeds this module even though goofys never imports s3crypto.

Port the S3 and GCS backends, the credential providers and the V2 signer to
aws-sdk-go-v2 so the module drops out entirely.

Request and response checksums are set to WhenRequired rather than the v2
default of WhenSupported, which would add CRC32 to every request and break
S3-compatible stores.

The GCS resumable upload path moves from mutating request objects to smithy
middleware, since v2 has no request object to mutate.
@locle2302 locle2302 self-assigned this Sep 11, 2026
@locle2302
locle2302 marked this pull request as ready for review September 11, 2026 20:56
@locle2302
locle2302 merged commit d2cf3dd into master Sep 11, 2026
1 check passed
@locle2302
locle2302 deleted the chore/aws-sdk-go-v2 branch September 11, 2026 21:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants