Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
This project is now read‑only. Starting Monday, February 2, please use https://ibm-ceph.atlassian.net/ for all bug tracking management.

Bug 2302541

Summary: [rgw][sts]: Deny AbortMultipartUpload is not respected if Allow PutObject permission is also present in the session policy
Product: [Red Hat Storage] Red Hat Ceph Storage Reporter: Hemanth Sai <hmaheswa>
Component: RGWAssignee: Pritha Srivastava <prsrivas>
Status: CLOSED ERRATA QA Contact: Hemanth Sai <hmaheswa>
Severity: high Docs Contact: Rivka Pollack <rpollack>
Priority: unspecified    
Version: 7.1CC: ceph-eng-bugs, cephqe-warriors, jcaratza, mbenjamin, prsrivas, rpollack
Target Milestone: ---Keywords: Automation
Target Release: 9.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: ceph-20.1.0-80 Doc Type: Bug Fix
Doc Text:
.IAM policy now recognizes `AbortMultipartUpload` `Deny` requests Previously, a session policy incorrectly used the `AbortMultipartUpload` action. As a result, a `Deny` statement for `AbortMultipartUpload` in the IAM policy was not respected when `PutObject` was allowed. With this fix, the action in the IAM policy was corrected. The `Deny` for `AbortMultipartUpload` in the IAM policy is now properly enforced.
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-01-29 06:48:38 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2388233    

Description Hemanth Sai 2024-08-02 18:17:54 UTC
Description of problem:
Deny AbortMultipartUpload is not respected if Allow PutObject permission is also present in the session policy

manual testing fail log: https://docs.google.com/document/d/1ZGE7HrCUkXUngyE8snejZRe6vGBh3CHvXJmuHGU_tjM/edit#heading=h.fxl9j7n1cfvk
automation fail log: http://magna002.ceph.redhat.com/cephci-jenkins/hsm/sts_session_policy_deny_abort_multipart/test_sts_using_boto_verify_session_policy_allow_put_object_and_deny_abort_multipart_upload.console.log


if Allow PutObject permission is not present in the session policy, then Deny AbortMultipartUpload is denied as expected
pass logs: https://docs.google.com/document/d/1ZGE7HrCUkXUngyE8snejZRe6vGBh3CHvXJmuHGU_tjM/edit#heading=h.774oihid864k


Without session policy, Deny AbortMultipartUpload is denied as expected even if Allow PutObject permission is present in the role policy:
pass logs: https://docs.google.com/document/d/1ZGE7HrCUkXUngyE8snejZRe6vGBh3CHvXJmuHGU_tjM/edit#heading=h.la990ffflm13



Version-Release number of selected component (if applicable):
ceph version 18.2.1-228.el9cp

How reproducible:
always

Steps to Reproduce:
1.create a user 
2.create a role and attach a role policy to allow all s3 actions

[root@magna016 ~]# radosgw-admin role create --role-name hsm-xyz1-role2 --assume-role-policy-doc "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Principal\":{\"AWS\":[\"arn:aws:iam:::user/hsm-xyz1\"]},\"Action\":[\"sts:AssumeRole\"]}]}"
{
    "RoleId": "31a445dc-a80c-43e4-96c6-6e6170bf07e3",
    "RoleName": "hsm-xyz1-role2",
    "Path": "/",
    "Arn": "arn:aws:iam:::role/hsm-xyz1-role2",
    "CreateDate": "2024-08-02T14:56:18.269Z",
    "MaxSessionDuration": 3600,
    "AssumeRolePolicyDocument": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Principal\":{\"AWS\":[\"arn:aws:iam:::user/hsm-xyz1\"]},\"Action\":[\"sts:AssumeRole\"]}]}"
}
[root@magna016 ~]# 
[root@magna016 ~]# radosgw-admin role policy put --role-name hsm-xyz1-role2 --policy-name hsm-xyz1-role2-policy1 --policy-doc "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Action\":[\"s3:*\"],\"Resource\":[\"arn:aws:s3:::*\"]}]}" --debug-rgw 0
Permission policy attached successfully
[root@magna016 ~]# 



3.Perform the assume role API call and obtain sts creds

[root@magna016 ~]# aws --endpoint-url http://10.8.128.16:80 --profile xyz1 sts assume-role --role-arn arn:aws:iam:::role/hsm-xyz1-role2 --role-session-name session1001 --policy "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Action\":[\"s3:PutObject\"],\"Resource\":[\"arn:aws:s3:::*\"]},{\"Effect\":\"Deny\",\"Action\":[\"s3:AbortMultipartUpload\"],\"Resource\":[\"arn:aws:s3:::*\"]}]}"
{
    "Credentials": {
        "AccessKeyId": "06QJi40zxziZJSfhgzf",
        "SecretAccessKey": "P6IX4TM4L3OSF7LJG3DEU6OR143HON9IZVMR63R",
        "SessionToken": "hGXiWEJyalTsNBgJWsYOqVA8NKW7U+1XqH1EvENT/fsxk3uMyUxcfjvf4iBjgSwzGmiuCneKOzlZ6ClD1vXjOq9MM/wGgM67JJnWqYgFdKLX+tR5YDgnBoF7Tcqw5z+Mvi6bMaE9d2qNT4GDx8VTiAu6JxZKKydEx3nK+YUddnn7/iP1KgyXZEh99s5MP9wPCOoNpMBjnfj6sL3Q1l1wMtfuPdYoVo/vDJTmvT1+pP/JZOslvzBlCcg2n085iLYRM4g3bQ18T2TmfYlNn3jsLWf05Qt0bX3ZKF1Ea6h01uEMOk44npYa6AIuKhwYv4i/CNOYyx8rcUrjyjMyz/PiGE7eIr7DlmTAAJEeTF9cWAd9tNRK6UwnRs29ZYV1P03Kpd23EI56urqemY934/ydJqQZKqvLl0ofNhPAnSmd0lC1lVvNg9Jjzu/zBOcj3XnhJa/3vt4xrQQzJIalINQLoULjU151mtEFKGPtlYGd56LluyNVLS4nSuei5CspaP7i82A8CZSunyrVebbu+AGM5LNdjyR+BeT86dwpFs7K7452f7RBLOpebkcBQ8swWAdfD32UjsdRy8Ymhy6hSAtqaw==",
        "Expiration": "2024-08-02T16:00:50.969164386Z"
    },
    "AssumedRoleUser": {
        "Arn": "arn:aws:sts:::assumed-role/hsm-xyz1-role2/session1001"
    },
    "PackedPolicySize": 0
}
[root@magna016 ~]# 
[root@magna016 ~]# cat ~/.aws/credentials
[xyz1]
aws_access_key_id = xyz1
aws_secret_access_key = xyz1

[xyz1-sts-user]
aws_access_key_id = 06QJi40zxziZJSfhgzf
aws_secret_access_key = P6IX4TM4L3OSF7LJG3DEU6OR143HON9IZVMR63R
aws_session_token = hGXiWEJyalTsNBgJWsYOqVA8NKW7U+1XqH1EvENT/fsxk3uMyUxcfjvf4iBjgSwzGmiuCneKOzlZ6ClD1vXjOq9MM/wGgM67JJnWqYgFdKLX+tR5YDgnBoF7Tcqw5z+Mvi6bMaE9d2qNT4GDx8VTiAu6JxZKKydEx3nK+YUddnn7/iP1KgyXZEh99s5MP9wPCOoNpMBjnfj6sL3Q1l1wMtfuPdYoVo/vDJTmvT1+pP/JZOslvzBlCcg2n085iLYRM4g3bQ18T2TmfYlNn3jsLWf05Qt0bX3ZKF1Ea6h01uEMOk44npYa6AIuKhwYv4i/CNOYyx8rcUrjyjMyz/PiGE7eIr7DlmTAAJEeTF9cWAd9tNRK6UwnRs29ZYV1P03Kpd23EI56urqemY934/ydJqQZKqvLl0ofNhPAnSmd0lC1lVvNg9Jjzu/zBOcj3XnhJa/3vt4xrQQzJIalINQLoULjU151mtEFKGPtlYGd56LluyNVLS4nSuei5CspaP7i82A8CZSunyrVebbu+AGM5LNdjyR+BeT86dwpFs7K7452f7RBLOpebkcBQ8swWAdfD32UjsdRy8Ymhy6hSAtqaw==
region = us-east-1
[root@magna016 ~]# 


4.create multipart upload using bucket owner creds or sts creds

[root@magna016 ~]# aws --endpoint-url http://10.8.128.16:80 --profile xyz1-sts-user s3api create-multipart-upload --bucket abort-multipart-bkt1 --key sts-user-obj100
{
    "Bucket": "abort-multipart-bkt1",
    "Key": "sts-user-obj100",
    "UploadId": "2~NyI-j-FG4WRPHyA6YuU0q0WCJixxbZF"
}
[root@magna016 ~]# 

[root@magna016 ~]# aws --endpoint-url http://10.8.128.16:80 --profile xyz1 s3api create-multipart-upload --bucket abort-multipart-bkt1 --key bucket-owner-obj100
{
    "Bucket": "abort-multipart-bkt1",
    "Key": "bucket-owner-obj100",
    "UploadId": "2~-ShpT9wx8Fr6su4GvOyyzwY2Us_NGOY"
}
[root@magna016 ~]# 
[root@magna016 ~]# 
[root@magna016 ~]# aws --endpoint-url http://10.8.128.16:80 --profile xyz1 s3api upload-part --bucket abort-multipart-bkt1 --key bucket-owner-obj100 --part-number 1 --upload-id 2~-ShpT9wx8Fr6su4GvOyyzwY2Us_NGOY --body obj20MB
{
    "ETag": "\"10e4462c9d0b08e7f0b304c4fbfeafa3\""
}
[root@magna016 ~]# 
 


5.with sts user, abort the multipart uploads, it should deny actually, but it allows the operation

[root@magna016 ~]# aws --endpoint-url http://10.8.128.16:80 --profile xyz1-sts-user s3api abort-multipart-upload --bucket abort-multipart-bkt1 --key sts-user-obj100 --upload-id 2~NyI-j-FG4WRPHyA6YuU0q0WCJixxbZF
[root@magna016 ~]# 

[root@magna016 ~]# aws --endpoint-url http://10.8.128.16:80 --profile xyz1-sts-user s3api abort-multipart-upload --bucket abort-multipart-bkt1 --key bucket-owner-obj100 --upload-id 2~-ShpT9wx8Fr6su4GvOyyzwY2Us_NGOY
[root@magna016 ~]# 




Actual results:
Deny AbortMultipartUpload is not respected if Allow PutObject permission is also present in the session policy

Expected results:
Deny AbortMultipartUpload should be denied even if Allow PutObject permission is also present in the session policy

Additional info:

Comment 9 errata-xmlrpc 2026-01-29 06:48:38 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Moderate: Red Hat Ceph Storage 9.0 Security and Enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2026:1536