public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
From: Michal Fox <me@dualfroz.com>
To: pve-devel@lists.proxmox.com
Subject: [PATCH proxmox-acme] fix #7155: proxmox-acme: support upper-hex mode of _url_encode
Date: Sun,  4 Oct 2026 12:59:25 +0000	[thread overview]
Message-ID: <20261004125925.7-1-me@dualfroz.com> (raw)

The _url_encode function of acme.sh takes an optional 'upper-hex'
argument, which makes it output the percent-encoded characters with
upper-case hex digits. Our copy of the function in proxmox-acme lacks
it and always outputs lower-case hex.

The Aliyun DNS plugin of the bundled acme.sh version uses this argument
for the signature of its API requests, as the Aliyun API requires
upper-case hex there. So the signature never matched, and adding the
TXT record always failed with "SignatureDoesNotMatch".

Add the argument the same way acme.sh implements it, as suggested in
the bug. Upstream changed the Aliyun plugin in the meantime to not rely
on the argument anymore, because of bundled copies like ours, but newer
plugins, like dns_baidu.sh and dns_hw.sh, use it too.

Signed-off-by: Michal Fox <me@dualfroz.com>
---

Notes:
    tested by sourcing proxmox-acme and the bundled dns_ali.sh, and building
    the request URL of _ali_rest for a fixed query with a mocked _get. with
    this patch the signature matches the one of a reference implementation
    in Python, which encodes with upper-case hex as Aliyun requires, without
    it it does not. the default lower-case output of _url_encode is
    unchanged. 'make test' in src passes.

 src/proxmox-acme | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/src/proxmox-acme b/src/proxmox-acme
index 705f7df..18cbf20 100644
--- a/src/proxmox-acme
+++ b/src/proxmox-acme
@@ -510,7 +510,9 @@ _hex_dump() {
 }
 
 # stdin stdout
+#_url_encode [upper-hex]  the encoded hex will be upper-case if the argument upper-hex is followed
 _url_encode() {
+  _upper_hex=$1
   _hex_str=$(_hex_dump)
   for _hex_code in $_hex_str; do
     #upper case
@@ -720,6 +722,9 @@ _url_encode() {
 
       #other hex
       *)
+        if [ "$_upper_hex" = "upper-hex" ]; then
+          _hex_code=$(printf "%s" "$_hex_code" | _upper_case)
+        fi
         printf '%%%s' "$_hex_code"
         ;;
     esac
-- 
2.43.0




                 reply	other threads:[~2026-10-04 12:59 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261004125925.7-1-me@dualfroz.com \
    --to=me@dualfroz.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal