From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id 139841FF09B for ; Mon, 28 Sep 2026 09:16:36 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id B555E21891; Mon, 28 Sep 2026 09:15:01 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790340458; x=1790945258; darn=lists.proxmox.com; h=content-transfer-encoding:mime-version:message-id:date:subject:to :from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=vx2opGSMYEVD9A+cif8a5ia7pQpy11eJFkPpZlBzhGg=; b=ai1ruwv+YTsNW2wG0bgz1iq4Fu7dwj/920teytyRgTs3mfbaNcu5GXtK+erekkimb3 IbnsPYVVUmT/Isy2SwVs1tph0EQjSzDcMUWUeTJ5Z9x1Ccb1RIsjheZ/JDuV355+W+kw IoslPHYQ6ZcezgzIZOrJJZs2FOsw1Rti+/39v0chxxpxjLIsbf6WzvSI1Oo0kVOx82rL wYFCfdhfYA2KT+ztQ3F+9V6LvUHFhQNwvOirYdY+5KGG80ywJEMrzFppKKu39o3f9hyl wnUcT5RGsNXAp5/nqq81pcHyWd8yC2j9y01Q/hk27qumLs2hJCo9O2ZYCLOC/kdPtGAe HiaA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790340458; x=1790945258; h=content-transfer-encoding:mime-version:message-id:date:subject:to :from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=vx2opGSMYEVD9A+cif8a5ia7pQpy11eJFkPpZlBzhGg=; b=fIPCTe1rkoYBkVhQebjdSLWTQOjia2X1Hll9F88PN70tiqJpqW2vf76Rao1GjJWiEm IVHbu9x+Xgj6PEBvVT1Ei4oAlEBLFG+oj8GLyi9jOWQWGqT6GeyOmMl4mIh2v3KfvK61 +SzbSaIUHzkcM1TcPJSPIpPU0nwbbxOW9LXl97OpMRutp4OiGB1Nb+d9pc7J4AxaIt0p vcyjlMuu+Mj1EelfTEYj5rg3SrQQDgCUkOxE6Ms3xhQER0DD9qUwrB6irmNEDqQzgESM B+WGKqywpmTAj3G9RoWIVPTQHV2XgfZJKe+OsNvEIjJw8BKC2RHhnv5pU+9jB+HQ9aXu 5GVw== X-Gm-Message-State: AFuF++nZd5KJugGBxPFvL1o4kQLobX1qZvrUulRBtfT6LqxOxaHmYMtX BGQicxx0vvW0yshHuSMIXohik4aNevMjF4WtWSTrZbz3vS7xkvZ6UDN/+ONUG9jb X-Gm-Gg: AYBFou0xCoNup/HIR8lQ847k/hWj+r/KoMrtgw+Bfj02e0eljVneHZiiBZUyvOVHS9U NTZ33AldUs4t4TXVh9as9CEvX5jo1Zx9V8TbxfHtwCRbhqS8iOTnOyPKXFNMSi8kCuXihe/ezQF B5VFyHS9g/HPuZafPk1EZfLdA2tDBNfj4KLAK2NGt+gES3v/an9rpWuKVxPZA+Tg0XBONXG9GwN bpy9lQdTGm9D3CCXSYwO/KUOdsJUQQ6yyiSZOiiDbm15Y9w5R65lA7yN7U+3FTtxyFy82kJMgzG IDMdGPZ4+0Ha5NGrEk/RxHP5bFXpkama39xpOBDirHc87uKauhv6GXrR0h/pmDuYqGw9s3a7oLF HIL2l7IegmFqCQ12dBoEK6BCDkO1fHKyVK1ltmbq2re6doudveGtiIetoc0MgmjkUbOOFvqBHBu DvXsOreF3Dcs4U7/XoTduo1gsHCbpA/lL2X/m2jCeW9DwY2r1IeLl1VLLbuYhclp0wm6esDyRFw SYB2qAgeCQ4Kqx/MmqnefZifM2mvKc1COB51nX98dOhH+dhHw== X-Received: by 2002:a05:600c:198b:b0:49c:edd8:ba35 with SMTP id 5b1f17b1804b1-49fe66ca13dmr98801105e9.6.1790340458389; Fri, 25 Sep 2026 05:47:38 -0700 (PDT) From: Mathias Bartmann To: pve-devel@lists.proxmox.com Subject: [PATCH proxmox-acme 0/3] acme: fix missing/diverging shim helpers, tighten missing-function check Date: Fri, 25 Sep 2026 14:47:34 +0200 Message-ID: <20260925124737.42866-1-mathias.bartmann@gmail.com> X-Mailer: git-send-email 2.55.0 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-SPAM-LEVEL: Spam detection results: 0 DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DKIM_VALID_AU -0.1 Message has a valid DKIM or DK signature from author's domain DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain DMARC_PASS -0.1 DMARC pass policy FREEMAIL_FROM 0.001 Sender email is commonly abused enduser mail provider SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record X-MailFrom: mathias.bartmann@gmail.com X-Mailman-Rule-Hits: nonmember-moderation X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation Message-ID-Hash: XGKN3A5AAT3BWB5YJM3LTXIFS7FRRB4C X-Message-ID-Hash: XGKN3A5AAT3BWB5YJM3LTXIFS7FRRB4C X-Mailman-Approved-At: Mon, 28 Sep 2026 09:14:43 +0200 X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: dns_oci.sh (Oracle Cloud DNS) cannot complete a DNS-01 challenge, see bug #7851 for the full analysis. Patch 1 fixes the two shim helpers behind it and adds a test running them through the shim. While looking at why this was not caught at build time, it turned out that check-missing-functions misses calls at the end of a command substitution or pipe, and drops any line that also has an assignment. With that fixed (patch 3) it finds a third missing helper, _url_replace used by dns_yc.sh, added in patch 2 so the series passes at every commit. A minimal fix within the existing grep pipeline is possible, but it still drops any line that also calls a known helper, so it would not catch _url_replace, and it needs ten more false-positive entries for variables after export, unset and read. The rewrite checks each called name individually, so the expected list shrinks to the one real upstream issue (dns_aws.sh: _error). Happy to send the minimal variant instead if you prefer. Patch 1 was verified end to end on PVE 9.2 with an OCI-hosted zone: certificate ordered and installed on pveproxy. Patch 2 is a verbatim copy of the upstream helper, but I could not test it against Yandex Cloud. Mathias Bartmann (3): fix #7851: acme: add missing _mktemp and restore _dbase64 default acme: add missing _url_replace function tests: rewrite check-missing-functions to catch calls in substitutions src/proxmox-acme | 15 +++++++- src/test/Makefile | 2 +- src/test/check-missing-functions | 59 ++++++++++++++++++++++++----- src/test/missing-functions.expected | 8 +--- src/test/test-shim-helpers | 37 ++++++++++++++++++ 5 files changed, 102 insertions(+), 19 deletions(-) create mode 100755 src/test/test-shim-helpers -- 2.55.0