From e94631de44e08a826c569e149ed45f7edc70e720 Mon Sep 17 00:00:00 2001 From: neil Date: Sun, 12 Jul 2026 11:20:53 +0800 Subject: [PATCH] dns_pdns: probe zones with the server-side name filter in _get_root The unfiltered GET /zones lists every zone on the server; with large installations (100k zones) root-zone detection took minutes per domain. Probe each walk-up candidate with ?zone= instead (exact match per the PowerDNS API docs); servers that ignore the parameter return the full list, which the existing check still handles. https://github.com/acmesh-official/acme.sh/issues/6382 --- dnsapi/dns_pdns.sh | 22 +++++++++++++--------- 1 file changed, 13 insertions(+), 9 deletions(-) diff --git a/dnsapi/dns_pdns.sh b/dnsapi/dns_pdns.sh index 847a1af1..72a58af0 100755 --- a/dnsapi/dns_pdns.sh +++ b/dnsapi/dns_pdns.sh @@ -189,19 +189,23 @@ _get_root() { domain=$1 i=1 - if _pdns_rest "GET" "/api/v1/servers/$PDNS_ServerId/zones"; then - _zones_response=$(echo "$response" | _normalizeJson) - fi - while true; do h=$(printf "%s" "$domain" | cut -d . -f "$i"-100) - if _contains "$_zones_response" "\"name\":\"$h.\""; then - _domain="$h." - if [ -z "$h" ]; then - _domain="=2E" + # Probe each candidate zone with the server-side name filter instead of + # listing every zone: with large installations (100k zones) the + # unfiltered list takes minutes. Servers that ignore the parameter + # return the full list, which the check below still handles. + # https://doc.powerdns.com/authoritative/http-api/zone.html + if _pdns_rest "GET" "/api/v1/servers/$PDNS_ServerId/zones?zone=$h."; then + _zones_response=$(echo "$response" | _normalizeJson) + if _contains "$_zones_response" "\"name\":\"$h.\""; then + _domain="$h." + if [ -z "$h" ]; then + _domain="=2E" + fi + return 0 fi - return 0 fi if [ -z "$h" ]; then