s3: disable signing Accept-Encoding for Ceph and Linode - fixes #8206

Ceph RGW (and Linode Object Storage, which is Ceph-backed) can break
SigV4 when Accept-Encoding is included in the signature, especially
when a reverse proxy rewrites that header. GCS already sets this quirk;
apply the same default for Ceph and Linode as suggested in #8206.
This commit is contained in:
Aditya
2026-09-09 10:21:07 +01:00
committed by Nick Craig-Wood
parent 39b487d7f7
commit ea589de941
3 changed files with 19 additions and 0 deletions
+4
View File
@@ -19,3 +19,7 @@ quirks:
force_path_style: true force_path_style: true
list_url_encode: false list_url_encode: false
use_already_exists: false use_already_exists: false
# Ceph RGW (and reverse proxies such as Cloudflare in front of it) can
# mutate Accept-Encoding and break SigV4 when that header is signed.
# See: https://github.com/rclone/rclone/issues/8206
sign_accept_encoding: false
+5
View File
@@ -24,3 +24,8 @@ endpoint:
us-iad-10.linodeobjects.com: Washington, DC, US (us-iad-10) us-iad-10.linodeobjects.com: Washington, DC, US (us-iad-10)
acl: {} acl: {}
bucket_acl: true bucket_acl: true
quirks:
# Linode Object Storage is Ceph-backed; signing Accept-Encoding causes
# SignatureDoesNotMatch with rclone 1.68+. Match the Ceph quirk.
# See: https://github.com/rclone/rclone/issues/8206
sign_accept_encoding: false
+10
View File
@@ -5159,6 +5159,12 @@ parameter `--s3-upload-cutoff 0` or put this in the config file as
`upload_cutoff 0` to work around a bug which causes uploading of small `upload_cutoff 0` to work around a bug which causes uploading of small
files to fail. files to fail.
Rclone defaults `sign_accept_encoding` to false for the Ceph provider.
That avoids `SignatureDoesNotMatch` errors when a reverse proxy (for
example Cloudflare) rewrites the `Accept-Encoding` request header. You
can override this with `--s3-sign-accept-encoding` / `sign_accept_encoding`
if needed.
Note also that Ceph sometimes puts `/` in the passwords it gives Note also that Ceph sometimes puts `/` in the passwords it gives
users. If you read the secret access key using the command line tools users. If you read the secret access key using the command line tools
you will get a JSON blob with the `/` escaped as `\/`. Make sure you you will get a JSON blob with the `/` escaped as `\/`. Make sure you
@@ -7477,6 +7483,10 @@ secret_access_key = SECRET_ACCESS_KEY
endpoint = eu-central-1.linodeobjects.com endpoint = eu-central-1.linodeobjects.com
``` ```
Linode Object Storage is Ceph-backed. Rclone defaults
`sign_accept_encoding` to false for this provider so SigV4 requests do
not fail with `SignatureDoesNotMatch` (see the [Ceph](#ceph) section).
### Magalu {#magalu} ### Magalu {#magalu}
Here is an example of making a [Magalu Object Storage](https://magalu.cloud/object-storage/) Here is an example of making a [Magalu Object Storage](https://magalu.cloud/object-storage/)