From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id 186B91FF0AA for ; Tue, 06 Oct 2026 16:47:13 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 894242141B; Tue, 06 Oct 2026 16:47:09 +0200 (CEST) From: Christian Ebner To: pbs-devel@lists.proxmox.com Subject: [PATCH proxmox-backup v5 03/14] api: config: unlocked s3 bucket access check for datastore creation Date: Tue, 6 Oct 2026 16:46:33 +0200 Message-ID: <20261006144644.744818-4-c.ebner@proxmox.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20261006144644.744818-1-c.ebner@proxmox.com> References: <20261006144644.744818-1-c.ebner@proxmox.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1791298024996 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.608 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: K6R34ETYIL5EP4J7TDESG3QWE53WGZGM X-Message-ID-Hash: K6R34ETYIL5EP4J7TDESG3QWE53WGZGM X-MailFrom: c.ebner@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox Backup Server development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: The bucket access check performed when creating a new datastore with s3 backend can theoretically block up to the set s3 client request timeout of 30 min. It is not acceptable to hold the config lock for this long, effectively blocking configuration access for unrelated datastores. Move the check to the start so it is performed before even locking the config. Signed-off-by: Christian Ebner --- src/api2/config/datastore.rs | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/src/api2/config/datastore.rs b/src/api2/config/datastore.rs index 76e784e5a..808422a36 100644 --- a/src/api2/config/datastore.rs +++ b/src/api2/config/datastore.rs @@ -284,6 +284,13 @@ pub fn create_datastore( user_info.check_privs(&auth_id, &["system", "disks"], PRIV_SYS_MODIFY, false)?; } + let (backend, s3_client) = DataStore::s3_client_and_backend_from_datastore_config(&config)?; + if let Some(s3_client) = s3_client { + proxmox_async::runtime::block_on(s3_client.head_bucket()) + .context("failed to access bucket") + .map_err(|err| format_err!("{err:#}"))?; + } + let lock = pbs_config::datastore::lock_config()?; let (section_config, _digest) = pbs_config::datastore::config()?; @@ -340,13 +347,6 @@ pub fn create_datastore( let store_name = config.name.to_string(); - let (backend, s3_client) = DataStore::s3_client_and_backend_from_datastore_config(&config)?; - if let Some(s3_client) = s3_client { - proxmox_async::runtime::block_on(s3_client.head_bucket()) - .context("failed to access bucket") - .map_err(|err| format_err!("{err:#}"))?; - } - WorkerTask::new_thread( "create-datastore", Some(store_name.clone()), -- 2.47.3