1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210
|
#############################################################
# TEST 1 : NORMAL ALTER ENCRYPT mysql TABLESPACE.
#############################################################
#########################################################################
# RESTART 1 : WITH KEYRING PLUGIN
#########################################################################
SET debug='+d,skip_dd_table_access_check';
# Initially, mysql should be unencrypted by default
SELECT NAME, ENCRYPTION FROM INFORMATION_SCHEMA.INNODB_TABLESPACES WHERE NAME='mysql';
NAME ENCRYPTION
mysql N
SELECT NAME,OPTIONS FROM mysql.tablespaces WHERE NAME='mysql';
NAME OPTIONS
mysql encryption=N;
ALTER TABLESPACE mysql ENCRYPTION='Y';
SELECT NAME, ENCRYPTION FROM INFORMATION_SCHEMA.INNODB_TABLESPACES WHERE NAME='mysql';
NAME ENCRYPTION
mysql Y
SELECT NAME,OPTIONS FROM mysql.tablespaces WHERE NAME='mysql';
NAME OPTIONS
mysql encryption=Y;
ALTER TABLESPACE mysql ENCRYPTION='N';
SELECT NAME, ENCRYPTION FROM INFORMATION_SCHEMA.INNODB_TABLESPACES WHERE NAME='mysql';
NAME ENCRYPTION
mysql N
SELECT NAME,OPTIONS FROM mysql.tablespaces WHERE NAME='mysql';
NAME OPTIONS
mysql encryption=N;
#############################################################
# TEST 2 : CRASH DURING ALTER ENCRYPT mysql TABLESPACE.
#############################################################
############################################################
# ALTER TABLESPACE 1 : Unencrypted => Encrypted #
# (crash at page 10) #
############################################################
# Set Encryption process to crash at page 10
SET SESSION debug= '+d,alter_encrypt_tablespace_page_10';
# Encrypt the tablespace. It will cause crash.
ALTER TABLESPACE mysql ENCRYPTION='Y';
# Restart after crash
SET debug='+d,skip_dd_table_access_check';
# Wait for Encryption processing to finish in background thread
set global innodb_buf_flush_list_now = 1;
# After restart/recovery, check that Encryption was roll-forward
SELECT NAME, ENCRYPTION FROM INFORMATION_SCHEMA.INNODB_TABLESPACES WHERE NAME='mysql';
NAME ENCRYPTION
mysql Y
SELECT NAME,OPTIONS FROM mysql.tablespaces WHERE NAME='mysql';
NAME OPTIONS
mysql encryption=Y;
ALTER TABLESPACE mysql ENCRYPTION='Y';
SELECT NAME, ENCRYPTION FROM INFORMATION_SCHEMA.INNODB_TABLESPACES WHERE NAME='mysql';
NAME ENCRYPTION
mysql Y
SELECT NAME,OPTIONS FROM mysql.tablespaces WHERE NAME='mysql';
NAME OPTIONS
mysql encryption=Y;
#########################################################################
# RESTART 2 : WITH KEYRING PLUGIN
#########################################################################
SET debug='+d,skip_dd_table_access_check';
SELECT NAME, ENCRYPTION FROM INFORMATION_SCHEMA.INNODB_TABLESPACES WHERE NAME='mysql';
NAME ENCRYPTION
mysql Y
SELECT NAME,OPTIONS FROM mysql.tablespaces WHERE NAME='mysql';
NAME OPTIONS
mysql encryption=Y;
############################################################
# ALTER TABLESPACE 2 : Encrypted => Unencrypted #
# (crash at page 10) #
############################################################
# Set Unencryption process to crash at page 10
SET SESSION debug= '+d,alter_encrypt_tablespace_page_10';
# Unencrypt the tablespace. It will cause crash.
ALTER TABLESPACE mysql ENCRYPTION='N';
# Restart after crash
SET debug='+d,skip_dd_table_access_check';
# Wait for Unencryption processing to finish in background thread
set global innodb_buf_flush_list_now = 1;
# After restart/recovery, check that Unencryption was roll-forward
SELECT NAME, ENCRYPTION FROM INFORMATION_SCHEMA.INNODB_TABLESPACES WHERE NAME='mysql';
NAME ENCRYPTION
mysql N
SELECT NAME,OPTIONS FROM mysql.tablespaces WHERE NAME='mysql';
NAME OPTIONS
mysql encryption=N;
ALTER TABLESPACE mysql ENCRYPTION='N';
SELECT NAME, ENCRYPTION FROM INFORMATION_SCHEMA.INNODB_TABLESPACES WHERE NAME='mysql';
NAME ENCRYPTION
mysql N
SELECT NAME,OPTIONS FROM mysql.tablespaces WHERE NAME='mysql';
NAME OPTIONS
mysql encryption=N;
#########################################################################
# RESTART 3 : WITHOUT KEYRING PLUGIN
#########################################################################
SET debug='+d,skip_dd_table_access_check';
SELECT NAME, ENCRYPTION FROM INFORMATION_SCHEMA.INNODB_TABLESPACES WHERE NAME='mysql';
NAME ENCRYPTION
mysql N
SELECT NAME,OPTIONS FROM mysql.tablespaces WHERE NAME='mysql';
NAME OPTIONS
mysql encryption=N;
#############################################################
# TEST 3 : CRASH BEFORE/AFTER ENCRYPTION PROCESSING.
#############################################################
#########################################################################
# RESTART 4 : WITH KEYRING PLUGIN
#########################################################################
SET debug='+d,skip_dd_table_access_check';
ALTER TABLESPACE mysql ENCRYPTION='Y';
SELECT NAME,OPTIONS FROM mysql.tablespaces WHERE NAME='mysql';
NAME OPTIONS
mysql encryption=Y;
# Set server to crash just before encryption processing starts
SET SESSION debug="+d,alter_encrypt_tablespace_crash_before_processing";
# Unencrypt the tablespace. It will cause crash.
ALTER TABLESPACE mysql ENCRYPTION='N';
# Restart after crash
SET debug='+d,skip_dd_table_access_check';
# Wait for Unencryption processing to finish in background thread
SELECT NAME, ENCRYPTION FROM INFORMATION_SCHEMA.INNODB_TABLESPACES WHERE NAME='mysql';
NAME ENCRYPTION
mysql Y
SELECT NAME,OPTIONS FROM mysql.tablespaces WHERE NAME='mysql';
NAME OPTIONS
mysql encryption=Y;
# Set server to crash just after encryption processing finishes
SET SESSION debug="-d,alter_encrypt_tablespace_crash_before_processing";
SET SESSION debug="+d,alter_encrypt_tablespace_crash_after_processing";
# Unencrypt the tablespace. It will cause crash.
ALTER TABLESPACE mysql ENCRYPTION='N';
# Restart after crash
SET debug='+d,skip_dd_table_access_check';
# Wait for Unencryption processing to finish in background thread
SELECT NAME, ENCRYPTION FROM INFORMATION_SCHEMA.INNODB_TABLESPACES WHERE NAME='mysql';
NAME ENCRYPTION
mysql N
SELECT NAME,OPTIONS FROM mysql.tablespaces WHERE NAME='mysql';
NAME OPTIONS
mysql encryption=N;
#############################################################
# TEST 4 : CRASH DURING KEY ROTATION.
#############################################################
#########################################################################
# RESTART 5 : WITH KEYRING PLUGIN
#########################################################################
SET debug='+d,skip_dd_table_access_check';
ALTER TABLESPACE mysql ENCRYPTION='Y';
SELECT NAME,OPTIONS FROM mysql.tablespaces WHERE NAME='mysql';
NAME OPTIONS
mysql encryption=Y;
# Set server to crash while rotating encryption
SET SESSION debug="+d,ib_crash_during_rotation_for_encryption";
ALTER INSTANCE ROTATE INNODB MASTER KEY;
# Restart after crash
SET debug='+d,skip_dd_table_access_check';
SELECT NAME,OPTIONS FROM mysql.tablespaces WHERE NAME='mysql';
NAME OPTIONS
mysql encryption=Y;
SET SESSION debug="-d,ib_crash_during_rotation_for_encryption";
ALTER INSTANCE ROTATE INNODB MASTER KEY;
SELECT NAME,OPTIONS FROM mysql.tablespaces WHERE NAME='mysql';
NAME OPTIONS
mysql encryption=Y;
#############################################################
# TEST 5 : PRIVILEGE CHECK.
#############################################################
CREATE DATABASE priv_test;
CREATE USER myuser@'localhost';
GRANT ALL ON priv_test.* TO myuser@'localhost';
#connection con1
ALTER TABLESPACE mysql ENCRYPTION='Y';
ERROR 42000: Access denied; you need (at least one of) the CREATE TABLESPACE privilege(s) for this operation
#connection default
GRANT CREATE TABLESPACE ON mysql.* TO myuser@'localhost';
ERROR HY000: Incorrect usage of DB GRANT and GLOBAL PRIVILEGES
GRANT CREATE TABLESPACE ON *.* TO myuser@'localhost';
#connection con1
ALTER TABLESPACE mysql ENCRYPTION='N';
#connection default
SELECT NAME,OPTIONS FROM mysql.tablespaces WHERE NAME='mysql';
NAME OPTIONS
mysql encryption=N;
#connection con1
ALTER TABLESPACE mysql ENCRYPTION='Y';
#connection default
SELECT NAME,OPTIONS FROM mysql.tablespaces WHERE NAME='mysql';
NAME OPTIONS
mysql encryption=Y;
DROP DATABASE priv_test;
DROP USER myuser@localhost;
###########
# Cleanup #
###########
ALTER TABLESPACE mysql ENCRYPTION='N';
SELECT NAME,OPTIONS FROM mysql.tablespaces WHERE NAME='mysql';
NAME OPTIONS
mysql encryption=N;
#########################################################################
# RESTART 6 : WITHOUT KEYRING PLUGIN
#########################################################################
# restart:
|