1 Commits
  • dns_yc: fix TXT record removal failing with "Unknown key file format" (#7150)
    * dns_yc: restore YC_SA_Key_File in dns_yc_rm before signing the JWT
    
    dns_yc_rm() never rebuilt YC_SA_Key_File from YC_SA_Key_File_PEM_b64 /
    YC_SA_Key_File_Path like dns_yc_add() does. Per the DNS API dev guide,
    add()/rm() run in separate subshells, so rm() must repeat add()'s setup
    steps rather than rely on variables set during add().
    
    Without it, when _yc_login() needs a fresh JWT during removal (the IAM
    token from the add phase isn't available), it signs with an empty/unset
    key path, and openssl fails with "Unknown key file format". The
    resulting auth failure then surfaces misleadingly as "invalid domain" in
    _get_root, and the TXT record is never deleted.
    
    Verified against a real Yandex Cloud account/zone with --staging: before
    the fix, removal failed with the same errors reported in the issue;
    after adding the missing key-restoration block, add + remove both
    succeed and the TXT record is actually deleted.
    
    * dns_yc: preserve other TXT values when removing one at the same name
    
    dns_yc_rm previously sent the full current data array (all existing
    TXT values at the name) to the deletions API, wiping out the whole
    rrset instead of only the value being removed. This breaks wildcard +
    base domain issuance, where both share the same _acme-challenge name
    with two different values: removing the first one deleted both,
    leaving nothing for the second removal to find.
    
    * dns_yc: read persisted config from domain conf before account conf
    
    YC_Zone_ID, YC_Folder_ID, YC_SA_ID, YC_SA_Key_ID (zone-ID mode) and
    YC_SA_Key_File_PEM_b64/Path were always saved via _savedomainconf
    (domain.conf), but only ever read back via _readaccountconf_mutable
    (account.conf). Once the env vars were unset, none of these could be
    recovered from the saved config, so dns_yc_add/dns_yc_rm failed with
    "You didn't specify a YC_SA_ID or YC_SA_Key_ID or YC_SA_Key_File."
    even though the values had been persisted correctly on the prior run.
    
    * dns_yc: replace grep -Fxv/sed with a portable loop in dns_yc_rm
    
    Solaris's /usr/bin/grep supports neither -F nor -x, so
    _remaining_txtvalue was always empty there and the preserve-other-
    values logic silently fell back to deleting the whole rrset (with a
    grep usage error on stderr on every rm). The sed trailing-comma strip
    had a matching issue on Solaris, whose sed drops an unterminated last
    line. CI didn't catch this because the fallback path also returns
    "done: true". Use a plain for-loop with word splitting instead.
    
    * dns_yc: use upsertRecordSets.deletions to remove a single TXT value
    
    updateRecordSets has no "merges" field (only deletions/additions), so
    the previous preserve-other-values logic silently did nothing -- the
    TXT record was never actually removed, a regression from before that
    change (which at least deleted the whole rrset). CI didn't catch it
    because _clearupdns runs dns_yc_rm in a subshell and ignores its exit
    code.
    
    upsertRecordSets.deletions removes only the specified value from the
    rrset directly, so the getRecordSet read and the remaining-value
    recomputation are no longer needed at all.
    
    Verified against a real zone (base + wildcard domain sharing one
    _acme-challenge name): adding both values then removing one leaves
    the other in place, and removing the second cleans up fully.
    
    * dns_yc: don't delete the user's own key file in YC_SA_Key_File_Path mode
    
    _yc_login unconditionally rm'd $YC_SA_Key_File after signing. That's
    fine for the PEM_b64 path, where it's a decoded temp file, but in
    YC_SA_Key_File_Path mode it's the user's own persistent key file --
    the first successful login permanently deleted it, so every
    subsequent dns_yc_rm/renewal hit "Unknown key file format" (the exact
    symptom this PR is about, just from a different cause). Track whether
    the key file is our own temp copy and only delete it in that case.
    
    Verified with a stubbed _yc_login: a temp-mode key gets removed after
    login, a path-mode key survives.
    
    * dns_yc: clear both domain and account conf on invalid config
    
    The failure branch in dns_yc_add only ever called _clearaccountconf,
    but YC_Zone_ID/YC_Folder_ID/YC_SA_Key_File_PEM_b64/Path are persisted
    via _savedomainconf, and YC_SA_ID/YC_SA_Key_ID may have been saved via
    _saveaccountconf_mutable (Folder_ID mode, which stores under a
    SAVED_ prefix read back by _readaccountconf_mutable). Clearing only
    one store left stale values behind in whichever one wasn't touched.
    
    Verified by seeding both domain.conf and account.conf with leftover
    values, then triggering this branch and confirming both config files
    end up empty.