From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id C9E951FF125 for ; Mon, 03 Aug 2026 12:25:20 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 6406A21353; Mon, 03 Aug 2026 12:25:20 +0200 (CEST) From: Christian Ebner To: pbs-devel@lists.proxmox.com Subject: [PATCH proxmox-backup] fix #7878: reuse manifest on non-encrypting push with matching key Date: Mon, 3 Aug 2026 12:24:57 +0200 Message-ID: <20260803102458.371169-1-c.ebner@proxmox.com> X-Mailer: git-send-email 2.47.3 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1785752704084 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.127 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_LOW -0.7 Sender listed at https://www.dnswl.org/, low trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: XIEAICDOX36ILZ2L2TAEEHLPXKEYHR3B X-Message-ID-Hash: XIEAICDOX36ILZ2L2TAEEHLPXKEYHR3B X-MailFrom: c.ebner@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox Backup Server development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: This fixes a regression for push sync jobs with pre-encrypted snapshots no longer reusing chunks, even if the previous backup snapshot was encrypted using the same key. Previous to commit bb3a5fdfc ("sync: push: gracefully handle previous manifest signature mismatches") the it was possible to reuse the manifest of a previous backup snapshot even if not matched by the key fingerprint. The newly introduced check restricted this, did however not take into account that for pre-encrypted snapshots the crypt config on the push is not present, therefore acting like a regular (non-encrypting) push. In that case, there is no encryption key with matching fingerprint to check, so the job did not allow to reuse chunks from that manifest, resulting in prolonged sync runs. Fix this by also checking the source manifest fingerprint against the previous snapshot manifest if no server side key is being used and allow re-using chunks if they did match. Fixes: bb3a5fdfc ("sync: push: gracefully handle previous manifest signature mismatches") Signed-off-by: Christian Ebner --- src/server/push.rs | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/src/server/push.rs b/src/server/push.rs index 5cc794a68..18f8a6f0f 100644 --- a/src/server/push.rs +++ b/src/server/push.rs @@ -1144,6 +1144,18 @@ pub(crate) async fn push_snapshot( if signed_only { return Ok(Arc::new(manifest)); } + + // allow reuse for client side encrypted snapshots with matching key + if let Some(source_key_fp) = source_manifest + .fingerprint() + .context("failed getting fingerprint on source")? + { + if manifest_key_fp == source_key_fp { + return Ok(Arc::new(manifest)); + } + bail!("previous snapshot encrypted using different key"); + }; + bail!("previous snapshot encrypted but no encryption key configured"); }; -- 2.47.3