A library that provides an embeddable, persistent key-value store for fast storage.
Go to file
Ewout Prangsma 51778612c9 Encryption at rest support
Summary:
This PR adds support for encrypting data stored by RocksDB when written to disk.

It adds an `EncryptedEnv` override of the `Env` class with matching overrides for sequential&random access files.
The encryption itself is done through a configurable `EncryptionProvider`. This class creates is asked to create `BlockAccessCipherStream` for a file. This is where the actual encryption/decryption is being done.
Currently there is a Counter mode implementation of `BlockAccessCipherStream` with a `ROT13` block cipher (NOTE the `ROT13` is for demo purposes only!!).

The Counter operation mode uses an initial counter & random initialization vector (IV).
Both are created randomly for each file and stored in a 4K (default size) block that is prefixed to that file. The `EncryptedEnv` implementation is such that clients of the `Env` class do not see this prefix (nor data, nor in filesize).
The largest part of the prefix block is also encrypted, and there is room left for implementation specific settings/values/keys in there.

To test the encryption, the `DBTestBase` class has been extended to consider a new environment variable called `ENCRYPTED_ENV`. If set, the test will setup a encrypted instance of the `Env` class to use for all tests.
Typically you would run it like this:

```
ENCRYPTED_ENV=1 make check_some
```

There is also an added test that checks that some data inserted into the database is or is not "visible" on disk. With `ENCRYPTED_ENV` active it must not find plain text strings, with `ENCRYPTED_ENV` unset, it must find the plain text strings.
Closes https://github.com/facebook/rocksdb/pull/2424

Differential Revision: D5322178

Pulled By: sdwilsh

fbshipit-source-id: 253b0a9c2c498cc98f580df7f2623cbf7678a27f
2017-06-26 16:56:24 -07:00
arcanist_util Fix arc setting for Facebook internal tools 2017-02-02 13:24:16 -08:00
buckifier update buckifer/TARGETS 2017-05-24 11:56:57 -07:00
build_tools fixed typo 2017-06-05 11:27:34 -07:00
cache Add GPLv2 as an alternative license. 2017-04-27 18:06:12 -07:00
cmake/modules CMake: more MinGW fixes 2017-04-06 14:09:13 -07:00
coverage Fix coverage script 2014-11-03 14:53:00 -08:00
db Encryption at rest support 2017-06-26 16:56:24 -07:00
docs Intra-L0 blog post 2017-06-26 13:11:41 -07:00
env Encryption at rest support 2017-06-26 16:56:24 -07:00
examples CMake: more MinGW fixes 2017-04-06 14:09:13 -07:00
hdfs New API for background work in single thread pool 2017-05-23 11:12:27 -07:00
include/rocksdb Encryption at rest support 2017-06-26 16:56:24 -07:00
java Fix jni WriteBatchThreadedTest 2017-06-26 15:27:17 -07:00
memtable WriteBufferManager will not trigger flush if much data is already being flushed 2017-06-21 10:41:37 -07:00
monitoring revert perf_context and io_stats to __thread 2017-06-26 15:27:17 -07:00
options Optimize for serial commits in 2PC 2017-06-24 14:11:29 -07:00
port Implement ReopenWritibaleFile on Windows and other fixes 2017-06-20 10:31:13 -07:00
table Unit Tests for sync, range sync and file close failures 2017-06-26 13:27:58 -07:00
third-party fixed typo 2017-06-13 16:58:01 -07:00
tools Remove pin_slice option by making it the default 2017-06-15 16:14:08 -07:00
util revert perf_context and io_stats to __thread 2017-06-26 15:27:17 -07:00
utilities Optimize for serial commits in 2PC 2017-06-24 14:11:29 -07:00
.clang-format A script that automatically reformat affected lines 2014-01-14 12:21:24 -08:00
.deprecated_arcconfig Update ShipIt to honor TARGETS updates 2017-04-13 16:12:03 -07:00
.gitignore Simple blob file dumper 2017-05-23 10:42:59 -07:00
.travis.yml Force travis to build with clang on MacOS 2017-06-05 15:41:57 -07:00
appveyor.yml Rework test running script. 2017-04-05 11:39:20 -07:00
AUTHORS Add AUTHORS file. Fix #203 2014-09-29 10:52:18 -07:00
CMakeLists.txt Encryption at rest support 2017-06-26 16:56:24 -07:00
CONTRIBUTING.md facebook accounts are not required for CLA signers 2014-07-08 05:57:54 -04:00
COPYING Add GPLv2 as an alternative license. 2017-04-27 18:06:12 -07:00
DEFAULT_OPTIONS_HISTORY.md options.delayed_write_rate use the rate of rate_limiter by default. 2017-05-24 09:58:24 -07:00
DUMP_FORMAT.md First version of rocksdb_dump and rocksdb_undump. 2015-06-19 16:24:36 -07:00
HISTORY.md Trivial typo in HISTORY.md 2017-06-26 15:57:08 -07:00
INSTALL.md cross-platform compatibility improvements 2017-05-15 16:15:38 -07:00
LANGUAGE-BINDINGS.md Adding Dlang to the list 2017-02-16 17:24:10 -08:00
LICENSE Updated all copyright headers to the new format. 2016-02-09 15:12:00 -08:00
Makefile Encryption at rest support 2017-06-26 16:56:24 -07:00
PATENTS Update Patent Grant. 2015-04-13 10:33:43 +01:00
README.md Appveyor badge to show master branch 2016-07-26 13:54:08 -07:00
ROCKSDB_LITE.md Optimistic Transactions 2015-05-29 14:36:35 -07:00
src.mk Encryption at rest support 2017-06-26 16:56:24 -07:00
TARGETS Encryption at rest support 2017-06-26 16:56:24 -07:00
thirdparty.inc Introduce XPRESS compresssion on Windows. (#1081) 2016-04-19 22:54:24 -07:00
USERS.md fixed typo 2017-06-13 16:58:01 -07:00
Vagrantfile Update Vagrant file (test internal phabricator workflow) 2016-10-28 15:39:19 -07:00
WINDOWS_PORT.md Commit both PR and internal code review changes 2015-07-07 16:58:20 -07:00

RocksDB: A Persistent Key-Value Store for Flash and RAM Storage

Build Status Build status

RocksDB is developed and maintained by Facebook Database Engineering Team. It is built on earlier work on LevelDB by Sanjay Ghemawat (sanjay@google.com) and Jeff Dean (jeff@google.com)

This code is a library that forms the core building block for a fast key value server, especially suited for storing data on flash drives. It has a Log-Structured-Merge-Database (LSM) design with flexible tradeoffs between Write-Amplification-Factor (WAF), Read-Amplification-Factor (RAF) and Space-Amplification-Factor (SAF). It has multi-threaded compactions, making it specially suitable for storing multiple terabytes of data in a single database.

Start with example usage here: https://github.com/facebook/rocksdb/tree/master/examples

See the github wiki for more explanation.

The public interface is in include/. Callers should not include or rely on the details of any other header files in this package. Those internal APIs may be changed without warning.

Design discussions are conducted in https://www.facebook.com/groups/rocksdb.dev/