Skip to content

fix: trim whitespace-only Region in error responses before header fallback - #2308

Open
cipherprofessor wants to merge 1 commit into
minio:masterfrom
cipherprofessor:fix/trim-whitespace-region-error-response
Open

cipherprofessor wants to merge 1 commit into
minio:masterfrom
cipherprofessor:fix/trim-whitespace-region-error-response

Conversation

@cipherprofessor

@cipherprofessor cipherprofessor commented Sep 20, 2026 •

Copy link
Copy Markdown

Problem

httpRespToErrorResponse() only falls back to the x-amz-bucket-region header when the XML error body's <Region> is exactly "". A whitespace-only value (e.g. a single space) isn't caught by that check, so it gets used verbatim as the SigV4 signing region — corrupting the Authorization header on every subsequent request to that bucket with net/http: invalid header field value.

This is the error-response-path sibling of the whitespace-region bug already being fixed on the success-response path by #2274. While reviewing that PR, @allanrogerr pointed out the identical issue exists on this path too and asked for it to be handled in its own PR, since #2274 doesn't touch httpRespToErrorResponse(). This fix has no issue number of its own — it was found via that review comment, not filed as a separate issue.

Fix

One line: errResp.Region = strings.TrimSpace(errResp.Region) immediately before the existing empty-string check, so a whitespace-only region is treated the same as a genuinely empty one and correctly falls back to the header.

Scoped to Region only — not RequestID/HostID just above it, which are populated by the identical "if empty, fall back to header" pattern. A stray space in a diagnostic ID field has no functional consequence, while a corrupted Region breaks every subsequent signed request to the bucket. Happy to extend to those two as well if maintainers would rather have all three handled consistently.

Testing

  • Added TestHttpRespToErrorResponseWhitespaceRegion, modeling a whitespace-only <Region> in the XML body alongside a real x-amz-bucket-region header, confirming the result now falls back to the header value instead of using the whitespace verbatim. Confirmed this test fails against the pre-fix code and passes after the fix (TDD red/green).
  • go build ./..., go vet ./..., gofmt -l all clean.
  • go test -short -race ./... (full repo) green.
  • golangci-lint run --config ./.golangci.yml currently fails locally with unknown linters: 'gomodguard_v2' — verified this is pre-existing and unrelated to this change (identical failure on a clean checkout with this diff stashed out).

Summary by CodeRabbit

  • Bug Fixes
    • Improved error response handling by ignoring whitespace-only region values and using the region provided in the response header instead.
    • Region comparisons now consistently use trimmed values.

…lback

httpRespToErrorResponse() only falls back to the x-amz-bucket-region
header when the XML body's <Region> is exactly "". A whitespace-only
value (e.g. a single space) is not caught by that check, so it gets
used verbatim as the SigV4 signing region -- corrupting the
Authorization header on every subsequent request to that bucket with
"net/http: invalid header field value".

This is the error-response-path sibling of the whitespace-region bug
being fixed on the success-response path by minio#2274: reviewing that PR,
@allanrogerr pointed out the identical issue exists here too and asked
for it to be handled in its own PR, since minio#2274 doesn't touch this
code path. This has no issue number of its own -- it was found via
that review comment, not filed separately.

Scoped to Region only, not RequestID/HostID just above it (populated
by the identical "if empty, fall back to header" pattern): a stray
space in a diagnostic ID field has no functional consequence, while a
corrupted Region breaks every subsequent signed request to the bucket.

Added a regression test modeling a whitespace-only <Region> in the XML
body confirming it now correctly falls back to the
x-amz-bucket-region header.

go build, go vet, gofmt, and go test -short -race ./... all clean.
@coderabbitai

coderabbitai Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 76fc4561-fead-4a36-a8c2-a1f0273af61c

📥 Commits

Reviewing files that changed from the base of the PR and between 32e1f32 and 7debd58.

📒 Files selected for processing (2)
  • api-error-response.go
  • api-error-response_test.go

Included review availability: Your plan provides up to 8 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

The error response parser trims the XML Region value before checking for an empty value. A new test confirms that whitespace-only XML content falls back to the x-amz-bucket-region header.

Changes

Region normalization

Layer / File(s) Summary
Normalize region and validate fallback
api-error-response.go, api-error-response_test.go
httpRespToErrorResponse trims the parsed region. The new test verifies header fallback for a whitespace-only <Region> value.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Bug fix

Suggested reviewers: klauspost

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: trimming whitespace-only Region values before falling back to the header.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 2 files.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit trims the region neat
Whitespace hops away from sight
The header points the parser right
Tests thump softly, green and bright
One small fix makes errors fleet

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants