From: Michal Fox <me@dualfroz.com>
To: pve-devel@lists.proxmox.com
Subject: [PATCH proxmox-acme] fix #7155: proxmox-acme: support upper-hex mode of _url_encode
Date: Sun, 4 Oct 2026 12:59:25 +0000 [thread overview]
Message-ID: <20261004125925.7-1-me@dualfroz.com> (raw)
The _url_encode function of acme.sh takes an optional 'upper-hex'
argument, which makes it output the percent-encoded characters with
upper-case hex digits. Our copy of the function in proxmox-acme lacks
it and always outputs lower-case hex.
The Aliyun DNS plugin of the bundled acme.sh version uses this argument
for the signature of its API requests, as the Aliyun API requires
upper-case hex there. So the signature never matched, and adding the
TXT record always failed with "SignatureDoesNotMatch".
Add the argument the same way acme.sh implements it, as suggested in
the bug. Upstream changed the Aliyun plugin in the meantime to not rely
on the argument anymore, because of bundled copies like ours, but newer
plugins, like dns_baidu.sh and dns_hw.sh, use it too.
Signed-off-by: Michal Fox <me@dualfroz.com>
---
Notes:
tested by sourcing proxmox-acme and the bundled dns_ali.sh, and building
the request URL of _ali_rest for a fixed query with a mocked _get. with
this patch the signature matches the one of a reference implementation
in Python, which encodes with upper-case hex as Aliyun requires, without
it it does not. the default lower-case output of _url_encode is
unchanged. 'make test' in src passes.
src/proxmox-acme | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/src/proxmox-acme b/src/proxmox-acme
index 705f7df..18cbf20 100644
--- a/src/proxmox-acme
+++ b/src/proxmox-acme
@@ -510,7 +510,9 @@ _hex_dump() {
}
# stdin stdout
+#_url_encode [upper-hex] the encoded hex will be upper-case if the argument upper-hex is followed
_url_encode() {
+ _upper_hex=$1
_hex_str=$(_hex_dump)
for _hex_code in $_hex_str; do
#upper case
@@ -720,6 +722,9 @@ _url_encode() {
#other hex
*)
+ if [ "$_upper_hex" = "upper-hex" ]; then
+ _hex_code=$(printf "%s" "$_hex_code" | _upper_case)
+ fi
printf '%%%s' "$_hex_code"
;;
esac
--
2.43.0
reply other threads:[~2026-10-04 12:59 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261004125925.7-1-me@dualfroz.com \
--to=me@dualfroz.com \
--cc=pve-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox