From: Jakob Klocker <j.klocker@proxmox.com>
To: pbs-devel@lists.proxmox.com
Cc: Jakob Klocker <j.klocker@proxmox.com>
Subject: [PATCH proxmox-backup v2 2/3] fix #6990: server: drop verify state on push job
Date: Fri, 21 Aug 2026 13:18:25 +0200 [thread overview]
Message-ID: <20260821111826.299588-3-j.klocker@proxmox.com> (raw)
In-Reply-To: <20260821111826.299588-1-j.klocker@proxmox.com>
When pushing a snapshot the target manifest is recreated from the source
manifest, copying its verify_state. As with pull, this makes the pushed
snapshot appear verified on the remote without its stored copy having
been checked there.
Strip verify_state after copying the unprotected section so the pushed
snapshot is verified independently on the target.
Link: https://bugzilla.proxmox.com/show_bug.cgi?id=6990
Signed-off-by: Jakob Klocker <j.klocker@proxmox.com>
---
src/server/push.rs | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/src/server/push.rs b/src/server/push.rs
index 9a69f5ce8..456b025fd 100644
--- a/src/server/push.rs
+++ b/src/server/push.rs
@@ -1416,6 +1416,13 @@ pub(crate) async fn push_snapshot(
} else {
target_manifest.signature = source_manifest.signature.clone();
};
+
+ if let Some(unprotected) = target_manifest.unprotected.as_object_mut() {
+ unprotected.remove("verify_state");
+ } else {
+ bail!("Encountered unexpected manifest without 'unprotected' section.");
+ }
+
// FIXME: replace me with to_data_blob once there is an upload_blob
let manifest_string =
target_manifest.to_string(encrypt_using_key.map(|(_, config)| config).as_deref())?;
--
2.47.3
next prev parent reply other threads:[~2026-08-21 11:18 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-21 11:18 [PATCH proxmox-backup v2 0/3] fix #6990: server: drop verify state on push & pull job Jakob Klocker
2026-08-21 11:18 ` [PATCH proxmox-backup v2 1/3] server: pull: run blocking file operations on the blocking pool Jakob Klocker
2026-08-21 11:18 ` Jakob Klocker [this message]
2026-08-21 11:18 ` [PATCH proxmox-backup v2 3/3] fix #6990: server: drop verify state on non-decrypt pull job Jakob Klocker
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260821111826.299588-3-j.klocker@proxmox.com \
--to=j.klocker@proxmox.com \
--cc=pbs-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.