certbot: shutdown cancels an in-flight ACME order and skips DNS-01 TXT cleanup
Mantenedores costumam responder em até 1 dia
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 4/5
- Tempo estimado
- 3-5 dias
- Facilidade para iniciantes
- 52/100
Direção de pesquisa
Leia dstack/certbot/cli/src/main.rs e dstack/certbot/src/acme_client.rs, especialmente o shutdown select, o fluxo de renew_inner e a limpeza de DNS-01 próxima à linha 185. Rastreie o comportamento existente de renew_timeout e execute os testes do certbot ou as verificações relacionadas a shutdown. Está concluído quando shutdown lidar tanto com renovações ociosas quanto com renovações em andamento dentro de um prazo limitado, sem deixar o registro TXT ou o estado de autorização para trás.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Follow-up to #924.
The shutdown path added in #924 cancels the daemon future rather than letting it unwind:
// dstack/certbot/cli/src/main.rs
tokio::select! {
_ = bot.run() => unreachable!("certbot daemon returned"),
result = shutdown_signal() => result?,
}
If the signal lands while renew_inner is mid-ACME-order, bot.run() is dropped at its current await point and the cleanup at the end of the DNS-01 flow never runs:
// dstack/certbot/src/acme_client.rs:185
if let Err(err) = self.dns01_client.remove_record(&challenge.id).await {
error!("failed to remove dns record {}: {err}", challenge.id);
}
Result: a stale _acme-challenge TXT record left in the DNS zone, plus a pending authorization at the CA.
This is not a regression — before #924 the default SIGTERM disposition killed the process at the same point with the same effect — and it is self-healing, because set_txt_records calls remove_txt_records(&acme_domain) before publishing new ones on the next attempt. But "stop the daemon cleanly" currently means "stop promptly", not "stop without leaving state behind", and the gap is worth closing.
Proposal
Give the loop a cancellation token instead of dropping the future:
- check the token at the top of each iteration and in the interval wait (
select!betweensleep(renew_interval)and cancellation) — this covers the idle case, which is the overwhelmingly common one and is already instant today; - for the in-flight case, either let the current renewal run to completion under a bounded grace period before exiting, or make the DNS-01 challenge cleanup drop-safe (scope guard) so cancellation at any await point still removes the TXT record.
The grace period must stay bounded — renew_timeout already caps a single renewal, so reusing it as the shutdown deadline is a reasonable ceiling.
- Linguagem predominante
- Rust
- Estrelas
- 551
- Forks
- 97
- Merge médio
- 1d 3h
- PRs com merge (30d)
- 199
Preparar o ambiente
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de Dstack-TEE/dstack
-
Dificuldade 5/5 Mais de uma semana Facilidade para iniciantes 35/100
Dstack-TEE/dstack#1384 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 5/5 Mais de uma semana Facilidade para iniciantes 30/100
Dstack-TEE/dstack#1301 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 3/5 1-2 dias Facilidade para iniciantes 55/100
Dstack-TEE/dstack#1300 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 4/5 3-5 dias Facilidade para iniciantes 48/100
Dstack-TEE/dstack#1299 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 4/5 3-5 dias Facilidade para iniciantes 48/100
Dstack-TEE/dstack#1298 ·
Mantenedores costumam responder em até 1 dia
Todas as issues de Dstack-TEE/dstack
Issues semelhantes
-
`sysknife history --help` says --since takes ISO-8601, and the parser refuses offsets and bare datesAbertabug easy good first issue help wanted
Dificuldade 1/5 1-3 horas Facilidade para iniciantes 94/100
lacs-project/sysknife#519 ·
Mantenedores costumam responder em até 1 dia
-
enhancement
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 72/100
-
area:breg bug criticality:p3 triage:needs-implementation
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
registrystack/registry-stack#1699 ·
Mantenedores costumam responder em até 1 dia
-
documentation
Dificuldade 1/5 1-3 horas Facilidade para iniciantes 84/100
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 88/100
lbjlaq/Antigravity-Manager#3539 · 2 comentários ·
Mantenedores costumam responder em até 1 dia