mirror of
https://github.com/tailscale/tailscale.git
synced 2026-07-20 21:23:07 +08:00
The ACME serialization mutex (acmeMu) was a package-level global, and
several ACME-related fields lived on LocalBackend even though the
cert code is conditional and not linked into every binary. With
multiple tsnet.Servers in one process (each its own LocalBackend),
a process-wide acmeMu also serialized unrelated backends.
Introduce a new feature/acme extension that owns the per-LocalBackend
ACME/cert state in an ipnlocal.CertState value:
- acmeMu, renewMu, renewCertAt (previously package globals)
- pendingACMETLSALPNCerts, pendingCertDomains{,Mu},
getCertForTest, certRefreshCancel (previously LocalBackend
fields, only meaningful when ACME was compiled in)
ipnlocal/cert.go now reaches the state through b.certState(), which
is routed by a feature.Hook installed at init by feature/acme. The
CertState type lives in ipnlocal so cert.go can access its fields
directly without a method explosion; the extension in feature/acme
constructs and owns it.
This is a baby step. The end goal is for the entire cert/ACME code
to live in feature/acme, with ipnlocal only retaining whatever thin
hooks the rest of LocalBackend needs to call into it. The current
split (CertState and most of cert.go in ipnlocal, extension wrapper
in feature/acme) is a deliberately temporary middle ground that
keeps this PR small while making the next moves mechanical.
The package is named feature/acme to match the existing HasACME /
ts_omit_acme naming. condregister/maybe_acme.go wires it in for
non-js builds.
Updates #12614
Updates #20248
Updates #20249
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
Change-Id: I520909f24ad11a9622ef33c2290fe36ad44d6f71
|
||
|---|---|---|
| .. | ||
| childproc | ||
| tailscaledhooks | ||
| debug_forcereflect.go | ||
| debug.go | ||
| depaware-min.txt | ||
| depaware-minbox.txt | ||
| depaware.txt | ||
| deps_test.go | ||
| flag.go | ||
| generate.go | ||
| install_darwin.go | ||
| install_windows.go | ||
| manifest_windows_386.syso | ||
| manifest_windows_amd64.syso | ||
| manifest_windows_arm64.syso | ||
| netstack.go | ||
| proxy.go | ||
| required_version.go | ||
| sigpipe.go | ||
| ssh.go | ||
| tailscale-online.target | ||
| tailscale-wait-online.service | ||
| tailscaled_bird.go | ||
| tailscaled_drive.go | ||
| tailscaled_notwindows.go | ||
| tailscaled_test.go | ||
| tailscaled_windows.go | ||
| tailscaled.defaults | ||
| tailscaled.go | ||
| tailscaled.openrc | ||
| tailscaled.service | ||
| webclient.go | ||
| windows-manifest.xml | ||
| with_cli.go | ||