/* Cached L or key for given key_version */ struct key_struct
{
uint key_version; /*!< Version of the key */
uint key_length; /*!< Key length */ unsignedchar key[MY_AES_MAX_KEY_LENGTH]; /*!< Cached key
(that is L in CRYPT_SCHEME_1) */
};
/** is encryption enabled */ extern ulong srv_encrypt_tables;
/** Mutex helper for crypt_data->scheme @param[in,out]schemeencryptionscheme
@param[in] exit should we exit or enter mutex ? */ void
crypt_data_scheme_locker(
st_encryption_scheme* scheme, intexit);
struct fil_space_rotate_state_t
{
time_t start_time; /*!< time when rotation started */
ulint active_threads; /*!< active threads in space */
uint32_t next_offset; /*!< next "free" offset */
uint32_t max_offset; /*!< max offset needing to be rotated */
uint min_key_version_found; /*!< min key version found but not
rotated */ bool starting; /*!< initial write of IV */ bool flushing; /*!< space is being flushed at end of rotate */ bool aborted; /*!< a rotation thread bailed out of its claimedbatch(e.g.,onIOPSexhaustionor
shutdown). */
lsn_t end_lsn; /*!< max lsn created when rotating this
space */
};
#ifndef UNIV_INNOCHECKSUM
struct fil_space_crypt_t : st_encryption_scheme
{ public: /** Constructor. Does not initialize the members! Theobjectisexpectedtobeplacedinabufferthat
has been zero-initialized. */
fil_space_crypt_t(
uint new_type,
uint new_min_key_version,
uint new_key_id,
fil_encryption_t new_encryption)
: st_encryption_scheme(),
min_key_version(new_min_key_version),
encryption(new_encryption),
key_found(0),
rotate_state()
{
key_id = new_key_id;
my_random_bytes(iv, sizeof(iv));
mysql_mutex_init(0, &mutex, nullptr);
locker = crypt_data_scheme_locker;
type = new_type;
if (new_encryption == FIL_ENCRYPTION_OFF ||
(!srv_encrypt_tables &&
new_encryption == FIL_ENCRYPTION_DEFAULT)) {
type = CRYPT_SCHEME_UNENCRYPTED;
} else {
type = CRYPT_SCHEME_1;
min_key_version = key_get_latest_version();
}
/** Get latest key version from encryption plugin @retvalkey_versionor @retvalENCRYPTION_KEY_VERSION_INVALIDifusedkey_id
is not found from encryption plugin. */
uint key_get_latest_version(void);
/** Returns true if key was found from encryption plugin
and false if not. */ bool is_key_found() const { return key_found != ENCRYPTION_KEY_VERSION_INVALID;
}
/** Returns true if tablespace should be encrypted */ bool should_encrypt() const { return ((encryption == FIL_ENCRYPTION_ON) ||
(srv_encrypt_tables &&
encryption == FIL_ENCRYPTION_DEFAULT));
}
/** Return true if tablespace is encrypted. */ bool is_encrypted() const { return (encryption != FIL_ENCRYPTION_OFF);
}
/** Return true if default tablespace encryption is used, */ bool is_default_encryption() const { return (encryption == FIL_ENCRYPTION_DEFAULT);
}
/** Return true if tablespace is not encrypted. */ bool not_encrypted() const { return (encryption == FIL_ENCRYPTION_OFF);
}
/** Write encryption metadata to the first page. @param[in,out]blockfirstpageofthetablespace
@param[in,out] mtr mini-transaction */ void write_page0(buf_block_t* block, mtr_t* mtr);
uint min_key_version; // min key version for this space
fil_encryption_t encryption; // Encryption setup
mysql_mutex_t mutex; // mutex protecting following variables
/** Return code from encryption_key_get_latest_version. IfENCRYPTION_KEY_VERSION_INVALIDencryptionplugin couldnotfindthekeyandthereisnoneedtocall get_latest_key_versionagainaskeysarereadonly
at startup. */
uint key_found;
fil_space_rotate_state_t rotate_state;
};
/** Status info about encryption */ struct fil_space_crypt_status_t {
ulint space; /*!< tablespace id */
ulint scheme; /*!< encryption scheme */
uint min_key_version; /*!< min key version */
uint current_key_version;/*!< current key version */
uint keyserver_requests;/*!< no of key requests to key server */
uint key_id; /*!< current key_id */ bool rotating; /*!< is key rotation ongoing */ bool flushing; /*!< is flush at end of rotation ongoing */
ulint rotate_next_page_number; /*!< next page if key rotating */
ulint rotate_max_page_number; /*!< max page if key rotating */
};
/** Initialize encryption parameters from a tablespace header page. @param[in]zip_sizeROW_FORMAT=COMPRESSEDpagesize,or0 @param[in]pagefirstpageofthetablespace @returncryptdatafrompage0
@retval NULL if not present or not valid */
fil_space_crypt_t* fil_space_read_crypt_data(ulint zip_size, const byte* page)
MY_ATTRIBUTE((nonnull, warn_unused_result));
/** Freeacryptdataobject
@param[in,out] crypt_data crypt data to be freed */ void fil_space_destroy_crypt_data(fil_space_crypt_t **crypt_data);
/** Amend encryption information from redo log. @param[in]spacetablespace
@param[in] data encryption metadata */ void fil_crypt_parse(fil_space_t* space, const byte* data);
/********************************************************************* Adjustthreadcountforkeyrotation
@param[in] enw_cnt Number of threads to be used */ void fil_crypt_set_thread_cnt(const uint new_cnt);
/********************************************************************* Adjustmaxkeyage
@param[in] val New max key age */ void fil_crypt_set_rotate_key_age(uint val);
/********************************************************************* Adjustrotationiops
@param[in] val New max roation iops */ void fil_crypt_set_rotation_iops(uint val);
/** Add the import tablespace to default_encrypt list ifnecessaryandsignalfil_crypt_threads
@param space imported tablespace */ void fil_crypt_add_imported_space(fil_space_t *space);
/********************************************************************* Adjustencrypttables
@param[in] val New setting for innodb-encrypt-tables */ void fil_crypt_set_encrypt_tables(ulong val);
/*********************************************************************
Init threads for key rotation */ void fil_crypt_threads_init();
/*********************************************************************
Clean up key rotation threads resources */ void fil_crypt_threads_cleanup();
/********************************************************************* Waitforcryptthreadstostopaccessingspace
@param[in] space Tablespace */ void fil_space_crypt_close_tablespace(const fil_space_t *space);
/********************************************************************* Getcryptstatusforaspace(usedbyinformation_schema) @param[in]spaceTablespace @param[out]statusCryptstatus
return 0 if crypt data present */ void
fil_space_crypt_get_status( const fil_space_t* space, struct fil_space_crypt_status_t* status);
/********************************************************************* Returncryptstatistics
@param[out] stat Crypt statistics */ void fil_crypt_total_stat(fil_crypt_stat_t *stat);
@param[in,out]pagepageframe(checksumistemporarilymodified) @param[in]zip_sizeROW_FORMAT=COMPRESSEDpagesize,or0
@return true if page is encrypted AND OK, false otherwise */ bool fil_space_verify_crypt_checksum(const byte* page, ulint zip_size)
MY_ATTRIBUTE((warn_unused_result));
/** Add the tablespace to the rotation list if innodb_encrypt_rotate_key_ageis0orencryptionplugindoes notdokeyversionrotation
@return whether the tablespace should be added to rotation list */ bool fil_crypt_must_default_encrypt();
#endif/* fil0crypt_h */
Messung V0.5 in Prozent
¤ Diese beiden folgenden Angebotsgruppen bietet das Unternehmen0.13Angebot
(Wie Sie bei der Firma Beratungs- und Dienstleistungen beauftragen können 2026-10-08)
¤
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.