KMIP server doesn't return encryption key in time when mongod shuts down

XMLWordPrintableJSON

    • Type: Bug
    • Resolution: Unresolved
    • Priority: Major - P3
    • None
    • Affects Version/s: None
    • Component/s: None
    • Server Security
    • ALL
    • Server Security 2025-07-04, Server Security 2025-07-20, Server Security 2025-08-01
    • 200
    • None
    • 3
    • TBD
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      BF-37960 is an issue where an invariant is hit on wiredtiger_kv_engine.cpp when a mongod tries to shut down. It happens on KMIP server doesn't respond to the request to fetch the encryption key in time when wiredtiger_open is called. 

      This issue likely occurs in v8.0-s8 branch due to Straight to 8 exposing different FCV pathways that could enable a downgrade to happen. It could possibly happen in this check in shouldDowngrade(), since right now the FCV is being started on 7.0 (the kLastContinuous and kLastLTS but the mongod starts on 8.0-s8, whereas on master, both the FCV and mongod are 8.0. 

              Assignee:
              Adam Rayner
              Reporter:
              David Chen
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: