From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id 966B41FF0AD for ; Sun, 04 Oct 2026 14:59:41 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 7C6D3215F7; Sun, 04 Oct 2026 14:59:37 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dualfroz.com; s=dkim; t=1791118771; h=from:subject:date:message-id:to:mime-version: content-transfer-encoding; bh=16/dh7Dsafcvg/4335uGqRvXE5uN3y5cOW8SJgljcvU=; b=soG/5N3ia74tUo6eptNbqNImIJi0UL6eb/VcPCrCfWCAkyI6K2e/o8dKdRa1P14qXufFKp gIVHLmC3PzZg014YQls0muDG8yFD97KLGvxuJsQ0NjuOrg0OGqXralWEoMhUeK6tZ+GPEA wRB8Oj99ATBccR67J+v0N27SVg+n90ahVxVGfbco9QjgFhPuevrkqKnUZUVCL6PNyWLe0D juXQhW3bfNieGLMhbluCujwg5wJxvEPAQKaoRg4q+0OuekqEYuraNk61Om/cJ+hMWNesNv T/PUPUzHSBG64ATQrzPGjyRJ79lbLC20OeVdDo56OVyJFLMpbB3HNqeqXXOq0g== From: Michal Fox To: pve-devel@lists.proxmox.com Subject: [PATCH proxmox-acme] fix #7155: proxmox-acme: support upper-hex mode of _url_encode Date: Sun, 4 Oct 2026 12:59:25 +0000 Message-ID: <20261004125925.7-1-me@dualfroz.com> X-Mailer: git-send-email 2.47.3 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Last-TLS-Session-Version: TLSv1.3 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.204 Adjusted score from AWL reputation of From: address DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DKIM_VALID_AU -0.1 Message has a valid DKIM or DK signature from author's domain DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain DMARC_PASS -0.1 DMARC pass policy SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: F6GWHNMTZX3PAX24LKDN27FODT7XGYEG X-Message-ID-Hash: F6GWHNMTZX3PAX24LKDN27FODT7XGYEG X-MailFrom: me@dualfroz.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: The _url_encode function of acme.sh takes an optional 'upper-hex' argument, which makes it output the percent-encoded characters with upper-case hex digits. Our copy of the function in proxmox-acme lacks it and always outputs lower-case hex. The Aliyun DNS plugin of the bundled acme.sh version uses this argument for the signature of its API requests, as the Aliyun API requires upper-case hex there. So the signature never matched, and adding the TXT record always failed with "SignatureDoesNotMatch". Add the argument the same way acme.sh implements it, as suggested in the bug. Upstream changed the Aliyun plugin in the meantime to not rely on the argument anymore, because of bundled copies like ours, but newer plugins, like dns_baidu.sh and dns_hw.sh, use it too. Signed-off-by: Michal Fox --- Notes: tested by sourcing proxmox-acme and the bundled dns_ali.sh, and building the request URL of _ali_rest for a fixed query with a mocked _get. with this patch the signature matches the one of a reference implementation in Python, which encodes with upper-case hex as Aliyun requires, without it it does not. the default lower-case output of _url_encode is unchanged. 'make test' in src passes. src/proxmox-acme | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/src/proxmox-acme b/src/proxmox-acme index 705f7df..18cbf20 100644 --- a/src/proxmox-acme +++ b/src/proxmox-acme @@ -510,7 +510,9 @@ _hex_dump() { } # stdin stdout +#_url_encode [upper-hex] the encoded hex will be upper-case if the argument upper-hex is followed _url_encode() { + _upper_hex=$1 _hex_str=$(_hex_dump) for _hex_code in $_hex_str; do #upper case @@ -720,6 +722,9 @@ _url_encode() { #other hex *) + if [ "$_upper_hex" = "upper-hex" ]; then + _hex_code=$(printf "%s" "$_hex_code" | _upper_case) + fi printf '%%%s' "$_hex_code" ;; esac -- 2.43.0