Both confirmed and fixed in dev.

1. The four backup cp calls (KEYFILE/CERTFILE/CAFILE/FULLCHAIN) ran
   unguarded. With USE_SCP=yes MULTI_CALL is implicit, so each cp is its
   own ssh call and a missing source aborted the deploy. In batched mode
   it was masked because the exit code is that of the last command.
   Each cp is now wrapped in a remote [ -f ] test.
2. deploy/ssh.sh tested DEPLOY_SSH_FULLCHAIN = "yes" instead of
   DEPLOY_SSH_MULTI_CALL (since 2017). Effect was only that the
   fullchain backup got deferred to the next batch. Fixed as well.

Please upgrade with acme.sh --upgrade -b dev and retest.
This commit is contained in:
neil
2026-09-11 11:51:07 +08:00 Unverified
parent 2074493c7c
commit 9249c89221
+5 -5
View File
@@ -247,7 +247,7 @@ then rm -rf \"\$fn\"; echo \"Backup \$fn deleted as older than 180 days\"; fi; d
if [ -n "$DEPLOY_SSH_KEYFILE" ]; then
if [ "$DEPLOY_SSH_BACKUP" = "yes" ]; then
# backup file we are about to overwrite.
_cmdstr="$_cmdstr cp $DEPLOY_SSH_KEYFILE $_backupdir >/dev/null;"
_cmdstr="$_cmdstr if [ -f $DEPLOY_SSH_KEYFILE ]; then cp $DEPLOY_SSH_KEYFILE $_backupdir >/dev/null; fi;"
if [ "$DEPLOY_SSH_MULTI_CALL" = "yes" ]; then
if ! _ssh_remote_cmd "$_cmdstr"; then
return $_err_code
@@ -284,7 +284,7 @@ then rm -rf \"\$fn\"; echo \"Backup \$fn deleted as older than 180 days\"; fi; d
_pipe=">>"
elif [ "$DEPLOY_SSH_BACKUP" = "yes" ]; then
# backup file we are about to overwrite.
_cmdstr="$_cmdstr cp $DEPLOY_SSH_CERTFILE $_backupdir >/dev/null;"
_cmdstr="$_cmdstr if [ -f $DEPLOY_SSH_CERTFILE ]; then cp $DEPLOY_SSH_CERTFILE $_backupdir >/dev/null; fi;"
if [ "$DEPLOY_SSH_MULTI_CALL" = "yes" ]; then
if ! _ssh_remote_cmd "$_cmdstr"; then
return $_err_code
@@ -325,7 +325,7 @@ then rm -rf \"\$fn\"; echo \"Backup \$fn deleted as older than 180 days\"; fi; d
_pipe=">>"
elif [ "$DEPLOY_SSH_BACKUP" = "yes" ]; then
# backup file we are about to overwrite.
_cmdstr="$_cmdstr cp $DEPLOY_SSH_CAFILE $_backupdir >/dev/null;"
_cmdstr="$_cmdstr if [ -f $DEPLOY_SSH_CAFILE ]; then cp $DEPLOY_SSH_CAFILE $_backupdir >/dev/null; fi;"
if [ "$DEPLOY_SSH_MULTI_CALL" = "yes" ]; then
if ! _ssh_remote_cmd "$_cmdstr"; then
return $_err_code
@@ -370,8 +370,8 @@ then rm -rf \"\$fn\"; echo \"Backup \$fn deleted as older than 180 days\"; fi; d
_pipe=">>"
elif [ "$DEPLOY_SSH_BACKUP" = "yes" ]; then
# backup file we are about to overwrite.
_cmdstr="$_cmdstr cp $DEPLOY_SSH_FULLCHAIN $_backupdir >/dev/null;"
if [ "$DEPLOY_SSH_FULLCHAIN" = "yes" ]; then
_cmdstr="$_cmdstr if [ -f $DEPLOY_SSH_FULLCHAIN ]; then cp $DEPLOY_SSH_FULLCHAIN $_backupdir >/dev/null; fi;"
if [ "$DEPLOY_SSH_MULTI_CALL" = "yes" ]; then
if ! _ssh_remote_cmd "$_cmdstr"; then
return $_err_code
fi