public inbox for pbs-devel@lists.proxmox.com
 help / color / mirror / Atom feed
From: Robert Obkircher <r.obkircher@proxmox.com>
To: Christian Ebner <c.ebner@proxmox.com>, pbs-devel@lists.proxmox.com
Subject: Re: [PATCH v1 proxmox-backup 2/2] datastore: rephrase error messages for failed chunk insert
Date: Wed, 12 Aug 2026 11:52:14 +0200	[thread overview]
Message-ID: <90d3d067-1db9-4b7d-b8d3-0b42da6686df@proxmox.com> (raw)
In-Reply-To: <a0f31b2e-8159-4e83-8ce0-e9ab0a067b9b@proxmox.com>


On 07.08.26 14:43, Christian Ebner wrote:
> On 8/7/26 11:58 AM, Robert Obkircher wrote:
>> The "not allowed" phrasing sounds like an access-right problem, when
>> the actual problem is likely file corruption.
>>
>> Link: https://forum.proxmox.com/threads/184140
>> Signed-off-by: Robert Obkircher <r.obkircher@proxmox.com>
>> ---
>>   pbs-datastore/src/chunk_store.rs | 4 ++--
>>   1 file changed, 2 insertions(+), 2 deletions(-)
>>
>> diff --git a/pbs-datastore/src/chunk_store.rs
>> b/pbs-datastore/src/chunk_store.rs
>> index 3f637730c..d9d0c9a26 100644
>> --- a/pbs-datastore/src/chunk_store.rs
>> +++ b/pbs-datastore/src/chunk_store.rs
>> @@ -718,7 +718,7 @@ impl ChunkStore {
>>                   // includes data derived from the encryption key
>>                   if magic == UNCOMPRESSED_BLOB_MAGIC_1_0 || magic
>> == COMPRESSED_BLOB_MAGIC_1_0 {
>>                       bail!(
>> -                        "Overwriting unencrypted chunk
>> '{digest_str}' on store '{name}' with encrypted chunk with same
>> digest not allowed!"
>> +                        "Cannot overwrite existing unencrypted
>> chunk '{digest_str}' on store '{name}' with encrypted chunk."
>>                       );
>>                   }
>>   @@ -726,7 +726,7 @@ impl ChunkStore {
>>                   // their sizes are different, one of them *must*
>> be invalid
>>                   if magic == ENCRYPTED_BLOB_MAGIC_1_0 &&
>> !chunk.is_compressed() {
>>                       bail!(
>> -                        "Overwriting existing (encrypted) chunk
>> '{digest_str}' on store '{name}' is not allowed!"
>> +                        "Found existing encrypted chunk
>> '{digest_str}' of different size on store '{name}'. Consider
>> running verification and garbage-collection because it may be
>> corrupted.",
>
> question: pre-existing but since one of the chunks must be the
> corrupt one here, and the server checks the CRC sum on upload, the
> new chunk is most likely to be the fine one. Might be worth to
> decode the full on-disk chunk then and double check its CRC? An only
> bail if both are fine, which is very unlikely? 

It is not necessarily the case that one chunk must be corrupt here. It
could also be an attack from a malicious client that learned about an
existing digest and is trying to override it. So, especially if both
CRCs were valid, we must keep the older one.

I do agree that decoding to find out more details makes sense, because
this should be extremely rare in practice.

But this is also the critical section of the most heavily contended
lock, so removing the magic read entirely might be worth it. Fabian
seemed convinced that this would be safe.


>
> anyways, I suggest to modify the error message to be a bit more
> concise:
>
> "Unexpected encrypted chunk {} with different size already present
> on store {}. Run verification to detect possibly corrupt chunks." 

I think verification alone wouldn't be sufficient for unreferenced chunks.

The user on the forum post mentioned being unable to verify the backup
as it has been deleted via the gui.


>
>>                       )
>>                   }
>>   
>




  reply	other threads:[~2026-08-12  9:52 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-07  9:57 [PATCH v1 proxmox-backup 0/2] minor chunk insert improvements Robert Obkircher
2026-08-07  9:57 ` [PATCH v1 proxmox-backup 1/2] datastore: prefer standard library over custom unsafe code Robert Obkircher
2026-08-07 12:43   ` Christian Ebner
2026-08-07  9:58 ` [PATCH v1 proxmox-backup 2/2] datastore: rephrase error messages for failed chunk insert Robert Obkircher
2026-08-07 12:43   ` Christian Ebner
2026-08-12  9:52     ` Robert Obkircher [this message]
2026-08-12 10:03       ` Christian Ebner

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=90d3d067-1db9-4b7d-b8d3-0b42da6686df@proxmox.com \
    --to=r.obkircher@proxmox.com \
    --cc=c.ebner@proxmox.com \
    --cc=pbs-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal