From: Mathias Bartmann <mathias.bartmann@gmail.com>
To: pve-devel@lists.proxmox.com
Subject: [PATCH proxmox-acme 1/3] fix #7851: acme: add missing _mktemp and restore _dbase64 default
Date: Fri, 25 Sep 2026 14:47:35 +0200 [thread overview]
Message-ID: <20260925124737.42866-2-mathias.bartmann@gmail.com> (raw)
In-Reply-To: <20260925124737.42866-1-mathias.bartmann@gmail.com>
The dns_oci.sh plugin cannot complete a DNS-01 challenge, because of two
helpers in the proxmox-acme shim that differ from upstream acme.sh:
_dbase64() only implements upstream's multiline branch and ignores its
argument. Upstream decodes with '-A' by default and only drops it when
called as '_dbase64 multiline'. dns_oci.sh calls it without argument to
decode the single-line base64 private key, so the key decodes to an
empty string ("Usage: _fingerprint privkey"). Restore the upstream
conditional; dns_cyon.sh, dns_nic.sh and dns_yc.sh pass 'multiline' and
keep their current behaviour.
_mktemp() is not defined at all. dns_oci.sh writes the key to a
temporary file to sign its requests, so every request goes out
unsigned, and OCI's 404 then surfaces as the misleading
"DNS Zone not found". dns_transip.sh uses _mktemp the same way.
Add a test that runs these helpers through the shim and compares them
with upstream semantics.
Signed-off-by: Mathias Bartmann <mathias.bartmann@gmail.com>
---
src/proxmox-acme | 11 ++++++++++-
src/test/Makefile | 2 +-
src/test/test-shim-helpers | 34 ++++++++++++++++++++++++++++++++++
3 files changed, 45 insertions(+), 2 deletions(-)
create mode 100755 src/test/test-shim-helpers
diff --git a/src/proxmox-acme b/src/proxmox-acme
index 705f7df..00f4c06 100644
--- a/src/proxmox-acme
+++ b/src/proxmox-acme
@@ -15,8 +15,17 @@ _base64() {
openssl base64 -e | tr -d '\r\n'
}
+#Usage: multiline
_dbase64() {
- openssl base64 -d
+ if [ "$1" ]; then
+ openssl base64 -d
+ else
+ openssl base64 -d -A
+ fi
+}
+
+_mktemp() {
+ mktemp
}
# Usage: hashalg [outputhex]
diff --git a/src/test/Makefile b/src/test/Makefile
index bfa8991..b6044c6 100644
--- a/src/test/Makefile
+++ b/src/test/Makefile
@@ -1,6 +1,6 @@
.PHONY: test test-missing-functions
-test: verify-dnsapi-plugins-in-schema.pl.t verify-acme-sources-in-makefile.pl.t test-missing-functions
+test: verify-dnsapi-plugins-in-schema.pl.t verify-acme-sources-in-makefile.pl.t test-shim-helpers.t test-missing-functions
%.t: %
./$<
diff --git a/src/test/test-shim-helpers b/src/test/test-shim-helpers
new file mode 100755
index 0000000..b625a53
--- /dev/null
+++ b/src/test/test-shim-helpers
@@ -0,0 +1,34 @@
+#!/bin/sh
+
+# Check that helpers in src/proxmox-acme behave like their acme.sh upstream
+# counterparts, as the dnsapi plugins are synced unmodified from there.
+
+SHIM="bash ../proxmox-acme"
+FAILED=0
+
+fail() {
+ echo "FAIL: $1" >&2
+ FAILED=1
+}
+
+# a single base64 line longer than openssl's 64 character line limit, like
+# the base64-encoded private key dns_oci.sh decodes with a plain _dbase64
+PLAIN=$(head -c 1500 /dev/zero | tr '\0' 'x')
+SINGLE_LINE=$(printf '%s' "$PLAIN" | openssl base64 -e | tr -d '\n')
+WRAPPED=$(printf '%s' "$PLAIN" | openssl base64 -e)
+
+[ "$(printf '%s' "$SINGLE_LINE" | $SHIM _dbase64)" = "$PLAIN" ] ||
+ fail "_dbase64 without argument does not decode a single long line"
+
+[ "$(printf '%s\n' "$WRAPPED" | $SHIM _dbase64 multiline)" = "$PLAIN" ] ||
+ fail "_dbase64 multiline does not decode line-wrapped input"
+
+TMP_FILE=$($SHIM _mktemp)
+if [ -f "$TMP_FILE" ] && [ -w "$TMP_FILE" ]; then
+ rm -f "$TMP_FILE"
+else
+ fail "_mktemp does not create a writable temporary file"
+fi
+
+[ "$FAILED" -eq 0 ] || exit 1
+echo "OK: proxmox-acme helpers behave like upstream acme.sh."
--
2.55.0
next prev parent reply other threads:[~2026-09-28 7:16 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-25 12:47 [PATCH proxmox-acme 0/3] acme: fix missing/diverging shim helpers, tighten missing-function check Mathias Bartmann
2026-09-25 12:47 ` Mathias Bartmann [this message]
2026-09-25 12:47 ` [PATCH proxmox-acme 2/3] acme: add missing _url_replace function Mathias Bartmann
2026-09-25 12:47 ` [PATCH proxmox-acme 3/3] tests: rewrite check-missing-functions to catch calls in substitutions Mathias Bartmann
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260925124737.42866-2-mathias.bartmann@gmail.com \
--to=mathias.bartmann@gmail.com \
--cc=pve-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.