certbot: shutdown cancels an in-flight ACME order and skips DNS-01 TXT cleanup
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 52/100
Direzione di ricerca
Leggere dstack/certbot/cli/src/main.rs e dstack/certbot/src/acme_client.rs, in particolare il shutdown select, il flusso di renew_inner e la pulizia di DNS-01 vicino alla riga 185. Tracciare il comportamento esistente di renew_timeout ed eseguire i test di certbot o i controlli relativi a shutdown. Il lavoro è completato quando shutdown gestisce sia i rinnovi inattivi sia quelli in corso entro una scadenza delimitata, senza lasciare il record TXT o lo stato di autorizzazione.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Follow-up to #924.
The shutdown path added in #924 cancels the daemon future rather than letting it unwind:
// dstack/certbot/cli/src/main.rs
tokio::select! {
_ = bot.run() => unreachable!("certbot daemon returned"),
result = shutdown_signal() => result?,
}
If the signal lands while renew_inner is mid-ACME-order, bot.run() is dropped at its current await point and the cleanup at the end of the DNS-01 flow never runs:
// dstack/certbot/src/acme_client.rs:185
if let Err(err) = self.dns01_client.remove_record(&challenge.id).await {
error!("failed to remove dns record {}: {err}", challenge.id);
}
Result: a stale _acme-challenge TXT record left in the DNS zone, plus a pending authorization at the CA.
This is not a regression — before #924 the default SIGTERM disposition killed the process at the same point with the same effect — and it is self-healing, because set_txt_records calls remove_txt_records(&acme_domain) before publishing new ones on the next attempt. But "stop the daemon cleanly" currently means "stop promptly", not "stop without leaving state behind", and the gap is worth closing.
Proposal
Give the loop a cancellation token instead of dropping the future:
- check the token at the top of each iteration and in the interval wait (
select!betweensleep(renew_interval)and cancellation) — this covers the idle case, which is the overwhelmingly common one and is already instant today; - for the in-flight case, either let the current renewal run to completion under a bounded grace period before exiting, or make the DNS-01 challenge cleanup drop-safe (scope guard) so cancellation at any await point still removes the TXT record.
The grace period must stay bounded — renew_timeout already caps a single renewal, so reusing it as the shutdown deadline is a reasonable ceiling.
- Lingua principale
- Rust
- Stelle
- 551
- Fork
- 97
- Merge medio
- 1g 8h
- PR unite (30g)
- 182
Preparare l'ambiente
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di Dstack-TEE/dstack
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
Dstack-TEE/dstack#1384 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 30/100
Dstack-TEE/dstack#1301 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 55/100
Dstack-TEE/dstack#1300 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
Dstack-TEE/dstack#1299 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
Dstack-TEE/dstack#1298 ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di Dstack-TEE/dstack
Issue simili
-
`categorize_command` has no `uv` arm, so every `rtk uv …` row counts as `other` in the ecosystem mixApertaarea:api bug good first issue priority:low
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 92/100
rtk-ai/rtk#4316 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 92/100
I maintainer di solito rispondono entro 1 giorno
-
area/cli kind/bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 90/100
I maintainer di solito rispondono entro 1 giorno
-
enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
-
good first issue open-endedness: low type: new feature
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100