From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id 9B7E61FF0AB for ; Wed, 07 Oct 2026 14:34:32 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 1692E20BCB; Wed, 07 Oct 2026 14:34:32 +0200 (CEST) From: Christian Ebner To: pbs-devel@lists.proxmox.com Subject: [PATCH proxmox 0/3] s3-client: fix request signing and update request time on retry Date: Wed, 7 Oct 2026 14:34:03 +0200 Message-ID: <20261007123406.429342-1-c.ebner@proxmox.com> X-Mailer: git-send-email 2.47.3 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1791376468140 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.579 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: ECMOZMI2HSL2H5RS4FS5SOPWQXHSOONE X-Message-ID-Hash: ECMOZMI2HSL2H5RS4FS5SOPWQXHSOONE X-MailFrom: c.ebner@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox Backup Server development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: This patch series fixes 2 issues with the current s3-client implementation. In particular: - Patch 1 fixes an issue with s3-client request signing, encountered during development. The canonical request headers and query parameters were incorrectly sorted by key+value strings instead of key only, which could lead to sorting mismatches with the API server, resulting in signature mismatches and therefore rejected requests. In particular, this might be encountered if one header name is a prefix to another header name. Fixed by sorting headers and queries via their respective key only. - Patches 2+3 fix a not updated request time for requests being retried. This could potentially lead to `RequestTimeTooSkewed` errors when the time in-between retried requests is very large and might explain such errors observed as reported in the community forum [0]. Fixed by setting the current request time and updating the request signature each time before sending the request via the client. [0] https://forum.proxmox.com/threads/186881/ proxmox: Christian Ebner (3): s3-client: fix header and query parameter sorting during aws sign v4 s3-client: factor out request signing and related header updates s3-client: update request time and signature on retries proxmox-s3-client/src/aws_sign_v4.rs | 30 ++++++--- proxmox-s3-client/src/client.rs | 95 ++++++++++++++-------------- 2 files changed, 67 insertions(+), 58 deletions(-) Summary over all repositories: 2 files changed, 67 insertions(+), 58 deletions(-) -- Generated by murpp 0.11.0