/* Licensed to the Apache Software Foundation (ASF) under one or more *contributorlicenseagreements.SeetheNOTICEfiledistributedwith *thisworkforadditionalinformationregardingcopyrightownership. *TheASFlicensesthisfiletoYouundertheApacheLicense,Version2.0 *(the"License");youmaynotusethisfileexceptincompliancewith *theLicense.YoumayobtainacopyoftheLicenseat * *http://www.apache.org/licenses/LICENSE-2.0 * *Unlessrequiredbyapplicablelaworagreedtoinwriting,software *distributedundertheLicenseisdistributedonan"ASIS"BASIS, *WITHOUTWARRANTIESORCONDITIONSOFANYKIND,eitherexpressorimplied. *SeetheLicenseforthespecificlanguagegoverningpermissionsand *limitationsundertheLicense.
*/
md_job_load(job); /* Evaluate again on loaded value. Values will change when watchdog switches child process */ if (apr_time_now() < job->next_run) return;
job->next_run = 0; if (job->finished && job->notified_renewed) { /* finished and notification handled, nothing to do. */ goto leave;
}
result = md_result_md_make(ptemp, md->name); if (job->last_result) md_result_assign(result, job->last_result);
if (md->state == MD_S_MISSING_INFORMATION) { /* Missing information, this will not change until configuration
* is changed and server reloaded. */
job->fatal_error = 1;
job->next_run = 0; goto leave;
}
if (md_will_renew_cert(md)) { /* Renew the MDs credentials in a STAGING area. Might be invoked repeatedly *withoutdiscardingprevious/intermediateresults. *OnlyreturnsSUCCESSwhentherenewaliscomplete,e.g.STAGINGhasa *completesetofnewcredentials.
*/
ap_log_error( APLOG_MARK, APLOG_DEBUG, 0, dctx->s, APLOGNO(10052) "md(%s): state=%d, driving", job->mdomain, md->state);
if (md->stapling && dctx->mc->ocsp &&
md_reg_has_revoked_certs(dctx->mc->reg, dctx->mc->ocsp, md, dctx->p)) {
ap_log_error( APLOG_MARK, APLOG_DEBUG, 0, dctx->s, APLOGNO(10500) "md(%s): has revoked certificates", job->mdomain);
} elseif (!md_reg_should_renew(dctx->mc->reg, md, dctx->p)) {
ap_log_error( APLOG_MARK, APLOG_DEBUG, 0, dctx->s, APLOGNO(10053) "md(%s): no need to renew", job->mdomain); goto expiry;
}
/* The (possibly configured) event handler may veto renewals. This
* is used in cluster installtations, see #233. */
rv = md_event_raise("renewing", md->name, job, result, ptemp); if (APR_SUCCESS != rv) {
ap_log_error(APLOG_MARK, APLOG_INFO, 0, dctx->s, APLOGNO(10060) "%s: event-handler for 'renewing' returned %d, preventing renewal to proceed.",
job->mdomain, rv); goto leave;
}
if (APR_SUCCESS == result->status) { /* Finished jobs might take a while before the results become valid.
* If that is in the future, request to run then */ if (apr_time_now() < result->ready_at) {
md_job_retry_at(job, result->ready_at); goto leave;
}
if (!job->notified_renewed) {
md_job_save(job, result, ptemp);
md_job_notify(job, "renewed", result);
}
} else {
ap_log_error( APLOG_MARK, APLOG_ERR, result->status, dctx->s, APLOGNO(10056) "processing %s: %s", job->mdomain, result->detail);
md_job_log_append(job, "renewal-error", result->problem, result->detail);
md_event_holler("errored", job->mdomain, job, result, ptemp);
ap_log_error(APLOG_MARK, APLOG_INFO, 0, dctx->s, APLOGNO(10057) "%s: encountered error for the %d. time, next run in %s",
job->mdomain, job->error_runs,
md_duration_print(ptemp, job->next_run - apr_time_now()));
}
}
/* mod_watchdog invoked us as a single thread inside the whole server (on this machine). *Thismightbearepeatedruninsidethesamechild(mod_watchdogkeepsaffinityas *longasthechildlives)oranother/newchild.
*/ switch (state) { case AP_WATCHDOG_STATE_STARTING:
ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, dctx->s, APLOGNO(10054) "md watchdog start, auto drive %d mds", dctx->jobs->nelts); break;
case AP_WATCHDOG_STATE_RUNNING:
ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, dctx->s, APLOGNO(10055) "md watchdog run, auto drive %d mds", dctx->jobs->nelts);
/* Process all drive jobs. They will update their next_run property *andwescheduleourselfattheearliestofall.Ajobmayspecify0 *asnext_runtoindicatethatitwantstoparticipateinthenormal
* regular runs. */
next_run = next_run_default(dctx); for (i = 0; i < dctx->jobs->nelts; ++i) {
job = APR_ARRAY_IDX(dctx->jobs, i, md_job_t *);
if (apr_time_now() >= job->next_run) {
process_drive_job(dctx, job, ptemp);
}
/* We use mod_watchdog to run a single thread in one of the child processes *tomonitortheMDsmarkedaswatched,usingtheconstdatainthelist *mc->mdsofourMDstructures. * *Thedatainmccannotbechanged,aswemayspawncopiesinnewchildprocesses *oftheoriginaldataatanytime.Thechildwhichhoststhewatchdogthread *mayalsodieorberecycled,whichcausesanewwatchdogthreadtorun *inanotherprocesswiththeoriginaldata. * *Instead,weuseourstoretopersistchangesingroupSTAGING.Thisis *keptwritabletochildprocesses,butthedatastoredthereisnotlive. *However,mod_watchdogmakessurethatweonlyeverhaveasinglethreadin *ourserver(onthismachine)thatwritesthere.Otherprocesses,e.g.informing *theuseraboutprogress,onlyreadfromthere. * *AllchangesduringdrivinganMDarestoredasfilesinMG_SG_STAGING/<MD.name>. *Allwillhave"md.json"and"job.json".Theremaybearangeofotherfilesused *bytheprotocolobtainingthecertificate/keys. * *
*/
wd_get_instance = APR_RETRIEVE_OPTIONAL_FN(ap_watchdog_get_instance);
wd_register_callback = APR_RETRIEVE_OPTIONAL_FN(ap_watchdog_register_callback);
wd_set_interval = APR_RETRIEVE_OPTIONAL_FN(ap_watchdog_set_callback_interval);
if (!wd_get_instance || !wd_register_callback || !wd_set_interval) {
ap_log_error(APLOG_MARK, APLOG_CRIT, 0, s, APLOGNO(10061) "mod_watchdog is required"); return !OK;
}
/* We want our own pool with own allocator to keep data across watchdog invocations. *Sincewe'llruninasinglewatchdogthread,usingourownallocatorwillprevent
* any confusion in the parent pool. */
apr_allocator_create(&allocator);
apr_allocator_max_free_set(allocator, 1);
rv = apr_pool_create_ex(&dctxp, p, NULL, allocator); if (rv != APR_SUCCESS) {
ap_log_error(APLOG_MARK, APLOG_ERR, rv, s, APLOGNO(10062) "md_renew_watchdog: create pool"); return rv;
}
apr_allocator_owner_set(allocator, dctxp);
apr_pool_tag(dctxp, "md_renew_watchdog");
dctx->jobs = apr_array_make(dctx->p, mc->mds->nelts, sizeof(md_job_t *)); for (i = 0; i < mc->mds->nelts; ++i) {
md = APR_ARRAY_IDX(mc->mds, i, md_t*); if (!md || !md->watched) continue;
md_job_load(job); if (job->error_runs) { /* Server has just restarted. If we encounter an MD job with errors *onapreviousdriving,wepurgeitsSTAGINGarea. *ThiswillresetthedrivingfortheMD.Itmayrunintothesame *erroragain,orincaseofrace/confusion/ourerror/CAerror,it *mightallowtheMDtosucceedbyafreshstart.
*/
ap_log_error( APLOG_MARK, APLOG_NOTICE, 0, dctx->s, APLOGNO(10064) "md(%s): previous drive job showed %d errors, purging STAGING " "area to reset.", md->name, job->error_runs);
md_store_purge(md_reg_store_get(dctx->mc->reg), p, MD_SG_STAGING, md->name);
md_store_purge(md_reg_store_get(dctx->mc->reg), p, MD_SG_CHALLENGES, md->name);
job->error_runs = 0;
}
}
if (!dctx->jobs->nelts) {
ap_log_error(APLOG_MARK, APLOG_DEBUG, 0, s, APLOGNO(10065) "no managed domain to drive, no watchdog needed.");
apr_pool_destroy(dctx->p); return APR_SUCCESS;
}
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.