public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
* [PATCH proxmox-acme v2] fix #7749: always serialize in same order
@ 2026-07-27  7:29 Thomas Ellmenreich
  0 siblings, 0 replies; only message in thread
From: Thomas Ellmenreich @ 2026-07-27  7:29 UTC (permalink / raw)
  To: pve-devel; +Cc: Thomas Ellmenreich, Elias Huhsovitz

All objects are now serialized with "canonical => 1" so that the
resulting bytes are directly comparable. Perls randomized hash key
orders lead to different serialization outputs even with the same input.

The 'tojs' function also now explicitly overrides the utf8 and canonical
options to make sure that they are always set.

Signed-off-by: Thomas Ellmenreich <t.ellmenreich@proxmox.com>
Reviewed-by: Elias Huhsovitz <e.huhsovitz@proxmox.com>
---
Serializing acme responses to json, because of perls randomized hash key order,
would lead to unequal serialized responses if they were compared as bytes. By
setting "canonical => 1" the serializations now always have the same order and
can thus be compared bytewise.

I have tested the patch against a local instance of HashiCorp Vault PKI and the
EAB registration works.

It seems that "canonical" can have performance implications when serialising
larger objects, but since the objects produced in our acme client are
relatively small, I consider this acceptable.


 src/PVE/ACME.pm | 14 +++++++++-----
 1 file changed, 9 insertions(+), 5 deletions(-)

diff --git a/src/PVE/ACME.pm b/src/PVE/ACME.pm
index e6fb9c2..fb93eca 100644
--- a/src/PVE/ACME.pm
+++ b/src/PVE/ACME.pm
@@ -64,9 +64,13 @@ sub encode($) { # acme requires 'base64url' encoding
     return encode_base64url($_[0]);
 }
 
-sub tojs($;%) { # shortcut for to_json with utf8=>1
-    my ($data, %data) = @_;
-    return to_json($data, { utf8 => 1, %data });
+sub tojs($;%) { # shortcut for to_json with utf8=>1 and canonical=>1
+    my ($data, %opts) = @_;
+
+    $opts{utf8} = 1;
+    $opts{canonical} = 1;
+
+    return to_json($data, %opts);
 }
 
 sub fromjs($) {
@@ -155,7 +159,7 @@ sub save {
     }
     # pretty => 1 for readability
     # canonical => 1 to reduce churn
-    file_set_contents($self->{path}, tojs($o, pretty => 1, canonical => 1));
+    file_set_contents($self->{path}, tojs($o, pretty => 1));
 }
 
 # Load serialized account JSON file into $self
@@ -196,7 +200,7 @@ sub jwk {
 sub jwk_thumbprint {
     my ($self) = @_;
     my $jwk = $self->jwk(1); # $pure = 1
-    return encode(sha256(tojs($jwk, canonical => 1))); # canonical sorts
+    return encode(sha256(tojs($jwk)));
 }
 
 # A key authorization string in acme is a challenge token dot-connected with
-- 
2.47.3





^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-07-27  7:30 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-27  7:29 [PATCH proxmox-acme v2] fix #7749: always serialize in same order Thomas Ellmenreich

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal