Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
This project is now read‑only. Starting Monday, February 2, please use https://ibm-ceph.atlassian.net/ for all bug tracking management.

Bug 2350732

Summary: [IBM Support] [RGW] Conditional write doesn't work in certain scenarios
Product: [Red Hat Storage] Red Hat Ceph Storage Reporter: Mike Hackett <mhackett>
Component: RGWAssignee: Ali Masarwa <Ali.Masarwa>
Status: CLOSED ERRATA QA Contact: Manisha <mreddem>
Severity: high Docs Contact: Rivka Pollack <rpollack>
Priority: high    
Version: 5.3CC: amasarwa, ceph-eng-bugs, cephqe-warriors, ckulal, mbenjamin, mkasturi, mreddem, racpatel, rpollack, shabhard, tserlin
Target Milestone: ---   
Target Release: 9.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: ceph-20.1.0-18 Doc Type: Enhancement
Doc Text:
.Enhanced conditional operations This enhancement introduces support for conditional `PUT` and `DELETE` operations, including bulk and multi-delete requests. These conditional operations improve data consistency for some workloads. NOTE: The conditional `InitMultipartUpload` is not implemented in this release.
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-01-29 06:54:07 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2388233    

Description Mike Hackett 2025-03-07 21:15:03 UTC
Description of problem:

Perform a conditional PUT operation on an versioned or multipart object in your IBM Ceph S3 setup using the If-Match header, ensuring the operation proceeds only if the object's ETag matches the specified value.

The GET operation with If-Match works successfully, confirming that the ETag condition is processed correctly for reads.

The PUT operation with If-Match fails consistently with a 412 PreconditionFailed error, even when the correct ETag is provided.


ETag Verification:
For example :
[root@esg4stl304 ~]# aws --no-verify-ssl --endpoint-url=https://stl.dev.s3.mastercard.int:443 s3api put-object --bucket test-bucket --key test-object --body 5mb-file.bin
/usr/lib/python3.6/site-packages/botocore/vendored/requests/packages/urllib3/connectionpool.py:768: InsecureRequestWarning: Unverified HTTPS request is being made. Adding certificate verification is strongly advised. See: https://urllib3.readthedocs.org/en/latest/security.html
  InsecureRequestWarning)
{
    "ETag": "\"fa5f892d298b2b850f3263688cc51887\""
}
The object's ETag is confirmed as "fa5f892d298b2b850f3263688cc51887", which matches the value used in the If-Match header.
The ETag remains consistent across operations, indicating no changes to the object.
[root@esg4stl304 ~]# /usr/local/bin/aws --no-verify-ssl --endpoint-url=https://stl.dev.s3.mastercard.int:443 s3api get-object --bucket test-bucket --key test-object --if-match '"fa5f892d298b2b850f3263688cc51887"' d        ownloaded-file.bin
urllib3/connectionpool.py:1064: InsecureRequestWarning: Unverified HTTPS request is being made to host 'stl.dev.s3.mastercard.int'. Adding certificate verification is strongly advised. See: https://urllib3.readthed        ocs.io/en/1.26.x/advanced-usage.html#ssl-warnings
{
    "AcceptRanges": "bytes",
    "LastModified": "2024-12-03T13:17:44+00:00",
    "ContentLength": 5242880,
    "ETag": "\"fa5f892d298b2b850f3263688cc51887\"",
    "ContentType": "binary/octet-stream",
    "Metadata": {}
}
[root@esg4stl304 ~]#
[root@esg4stl304 ~]# s3cmd put updated-5mb-file.bin s3://test-bucket/test-object --add-header="If-Match: \"fa5f892d298b2b850f3263688cc51887\""
upload: 'updated-5mb-file.bin' -> 's3://test-bucket/test-object'  [1 of 1]
5242880 of 5242880   100% in    0s   112.34 MB/s  done
ERROR: S3 error: 412 (PreconditionFailed)
[root@esg4stl304 ~]#


Upstream Tracker for issue: https://tracker.ceph.com/issues/68183


Version-Release number of selected component (if applicable):
5.3

How reproducible:
Consistent.

Steps to Reproduce:
1.
2.
3.

Actual results:
Conditional writes (PUT with If-Match) are not functioning as expected, preventing applications from enforcing write conditions based on ETag when using multipart or versioned objects.

Expected results:
Should function.

Additional info:
https://tracker.ceph.com/issues/68183

Comment 12 errata-xmlrpc 2026-01-29 06:54:07 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Moderate: Red Hat Ceph Storage 9.0 Security and Enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2026:1536