Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

certbot: shutdown cancels an in-flight ACME order and skips DNS-01 TXT cleanup

Aperta
#1,013 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
52/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Tranquilla
Stack tecnologico
rust
Ambito
backend, cli, security

Direzione di ricerca

Leggere dstack/certbot/cli/src/main.rs e dstack/certbot/src/acme_client.rs, in particolare il shutdown select, il flusso di renew_inner e la pulizia di DNS-01 vicino alla riga 185. Tracciare il comportamento esistente di renew_timeout ed eseguire i test di certbot o i controlli relativi a shutdown. Il lavoro è completato quando shutdown gestisce sia i rinnovi inattivi sia quelli in corso entro una scadenza delimitata, senza lasciare il record TXT o lo stato di autorizzazione.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

rust

Follow-up to #924.

The shutdown path added in #924 cancels the daemon future rather than letting it unwind:

// dstack/certbot/cli/src/main.rs
tokio::select! {
    _ = bot.run() => unreachable!("certbot daemon returned"),
    result = shutdown_signal() => result?,
}

If the signal lands while renew_inner is mid-ACME-order, bot.run() is dropped at its current await point and the cleanup at the end of the DNS-01 flow never runs:

// dstack/certbot/src/acme_client.rs:185
if let Err(err) = self.dns01_client.remove_record(&challenge.id).await {
    error!("failed to remove dns record {}: {err}", challenge.id);
}

Result: a stale _acme-challenge TXT record left in the DNS zone, plus a pending authorization at the CA.

This is not a regression — before #924 the default SIGTERM disposition killed the process at the same point with the same effect — and it is self-healing, because set_txt_records calls remove_txt_records(&acme_domain) before publishing new ones on the next attempt. But "stop the daemon cleanly" currently means "stop promptly", not "stop without leaving state behind", and the gap is worth closing.

Proposal

Give the loop a cancellation token instead of dropping the future:

  • check the token at the top of each iteration and in the interval wait (select! between sleep(renew_interval) and cancellation) — this covers the idle case, which is the overwhelmingly common one and is already instant today;
  • for the in-flight case, either let the current renewal run to completion under a bounded grace period before exiting, or make the DNS-01 challenge cleanup drop-safe (scope guard) so cancellation at any await point still removes the TXT record.

The grace period must stay bounded — renew_timeout already caps a single renewal, so reusing it as the shutdown deadline is a reasonable ceiling.

Lingua principale
Rust
Stelle
551
Fork
97
Merge medio
1g 8h
PR unite (30g)
182

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di Dstack-TEE/dstack

Tutte le issue di Dstack-TEE/dstack

Issue simili

Altre issue su Rust

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.