summaryrefslogtreecommitdiff
path: root/crates/tor-dirmgr/src
Commit message (Collapse)AuthorAgeFilesLines
* squash! Upgrade rand dependency to 0.9.Nick Mathewson2025-03-182-6/+6
| | | | - The Rng::gen() functions have been renamed to Rng::random().
* squash! Upgrade rand dependency to 0.9.Nick Mathewson2025-03-184-4/+4
| | | | - `rand::thread_rng()` has been deprecated and renamed to `rand::rng()`
* netdoc: Make some parsing init functions fallible.Nick Mathewson2025-03-171-2/+7
| | | | | | | I'm about to make our parsers reject some strings at construction time, so it makes sense to have these functions become fallible. This is a breaking change.
* tor-rtmock: allow-Decorate every use of MockSleepProviderIan Jackson2025-03-061-0/+2
| | | | | | | MockSleepProvider and MockSleepRuntime have been declared deprecated by the docs for some time. We're about to mark them `#[deprecated]`. This commit has been split out for clarity of review.
* tor-dirmgr: remove `dbg!`Steven Engler2025-03-051-1/+0
|
* sqlite: Handle vanished blobs during consensus loadingNick Mathewson2025-03-051-16/+38
| | | | | | | | | Here we move the responsibility for removing ExtDoc entries for vanished blobs into the _caller_ of read_blob(): we want to tidy all such entries in one go. Unlike a (reverted) previous approach, this time we don't need a retry loop.
* sqlite: add a method to tidy extdocs for vanished blobsNick Mathewson2025-03-051-1/+93
|
* sqlite.rs: Let read_blob signal whether it cleaned up.Nick Mathewson2025-03-051-8/+28
| | | | We'll want to use this information to tell us whether to retry.
* sqlite: Extract body of latest_consensus into a new methodNick Mathewson2025-03-051-23/+33
| | | | I'm about to add a retry mechanism.
* sqlite: Stop ignoring any errors.Nick Mathewson2025-03-051-3/+22
| | | | | We've already stopped ignoring any DB errors, so we may as well make sure that any FS errors we encounter are also reported.
* sqlite: Add a comment about O(n) query.Nick Mathewson2025-03-051-0/+2
|
* sqlite.rs: Rustfmt.Nick Mathewson2025-03-051-86/+87
|
* sqlite.rs: Put SavedBlobHandle into its own moduleNick Mathewson2025-03-051-13/+30
| | | | | | | This will help us keep its members private from the rest of sqlite.rs, and ensure that things are kept consistent. (This violates rust formatting for clarity. I'll reindent after.)
* sqlite.rs: More comments about blob rollback.Nick Mathewson2025-03-051-1/+7
|
* sqlite.rs: Give SavedBlobHandle more methods.Nick Mathewson2025-03-051-24/+47
| | | | | This is in preparation for making it opaque from the rest of the code, so that we can more easily reason about it.
* sqlite.rs: add comments about consistencyNick Mathewson2025-03-051-2/+14
|
* sqlite.rs: Add a note on blob consistency (or lack thereof)Nick Mathewson2025-03-051-0/+77
|
* sqlite.rs: Rename dtype to digest_type to avoid further confusion.Nick Mathewson2025-03-051-6/+6
|
* dirmgr: Propagate row-conversion failure from expire_all.Nick Mathewson2025-03-051-5/+4
| | | | | This can only happen because of a bug or because of db corruption, and we probably shouldn't ignore it.
* dirmgr: When expiring a consensus, remove its blob.Nick Mathewson2025-03-051-2/+68
| | | | | | | Previously, we would leave the ExtDocs blob to expire on its own, and it would hang out for up to a week. Closes #1655.
* dirmgr: Store the correct value in ExtDocs.typeNick Mathewson2025-03-051-2/+5
| | | | | | | | | | | | | Also, document that old values will be kicking around for a little while. Fortunately: - Nothing actually looked at these values before. - All elements in this table have an expiration date, so once a new version of Arti has been running for a week or two, the old erroneous values will go away.
* clippy: deny `mod_module_files`Steven Engler2025-01-061-0/+1
| | | | | | Denies 'mod.rs' files for consistency. https://rust-lang.github.io/rust-clippy/master/index.html#mod_module_files
* add_warnings, *: Allow clippy::needless_lifetimesNick Mathewson2024-12-031-0/+1
| | | | | | | | In 1.83, this warning triggers on many of our crates. We're thinking of fixing them all, but for now, we're going to disable the warning. This is part of #1765.
* TimerangeBound: Stop using std::ops::Bound.Wesley Aptekar-Cassels2024-11-252-7/+5
| | | | Fixes: #1691
* tor-dirmgr: don't support changing `DirMgrConfig::cache_trust`Steven Engler2024-11-052-0/+5
| | | | | `DirMgrConfig::update_from_config` uses the old value and not the new value, so it should be reported using `Reconfigure::cannot_change`.
* Replace _ => panic!() elsewhereIan Jackson2024-10-151-1/+1
|
* Upgrade to derive_more version 1.0.0Nick Mathewson2024-09-252-5/+5
| | | | | | The `derive_more` crate broke backward compatibility with this version, so this change involved quite a few manual fixups. With luck, they'll keep compatibility for some while in the future.
* rtcompat: Add an extension trait for building modified RuntimesNick Mathewson2024-09-241-2/+3
| | | | | | | With this extension trait, we no longer need to construct `CompoundRuntime` directly outside of tor-rtcompat. This in turn will make it a little less painful when we have to add more generics to CompoundRuntime.
* Fix typosDimitris Apostolou2024-09-031-1/+1
|
* extract tor_async_utils::oneshot into ::oneshot-fused-workaroundJim Newsome2024-08-282-2/+2
| | | | | | | | | | | | | | Having this in the `tor-async-utils` crate prevents us from doing both of the following without introducing a circular dependency: * using it in `tor-rtmock` (which we currently do, particularly in tests). * using `tor-rtmock` to test things in `tor-async-utils`. We don't do this yet, but it is generally sensible to do so. In particular we want to move the `stream_peak` module there, which is currently tested with `tor-rtmock`. Moving this into its own crate avoids this circular dependency.
* Merge branch 'sqlite-race' into 'main'gabi-2502024-07-312-9/+62
|\ | | | | | | | | | | | | tor-dirmgr: Return an error if storage is readonly and DB is missing/incompatbile. Closes #1497 See merge request tpo/core/arti!2283
| * tor-dirmgr: Replace from_conn impl with a call to from_conn_internal helper.Gabriela Moldovan2024-07-301-7/+16
| |
| * tor-dirmgr: Return an error if storage is readonly and DB is ↵Gabriela Moldovan2024-07-302-14/+58
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | missing/incompatbile. This fixes a bug in `SqliteStore`'s constructor: previously, it would unconditionally try to create the missing database, even if it didn't have write access. As a result, it was impossible to reliably start multiple concurrent arti processes configured with the same (empty or nonexistent) cache_dir, because many of them would fail with errors such as ``` attempt to write a readonly database: Error code 8: Attempt to write a readonly database ``` Returning a `LocalResourceAlreadyInUse` error kind here enables us to leverage the retry loop from `TorClientBuilder::create_unbootstrapped` (which retries on local resource errors if `local_resource_timeout` is set). Closes #1497
* | tor-dirmgr: Use Path::try_exists() instead of Path::exists().Gabriela Moldovan2024-07-301-1/+1
|/
* tor-dirmgr: Deprecate Error::CachePermissions, use CacheAccessIan Jackson2024-07-101-1/+12
|
* tor-dirmgr: Correct message and description for mistrust errorIan Jackson2024-07-101-2/+4
|
* tor-dirmgr: Add some duplicate dead code allowsIan Jackson2024-07-082-2/+4
| | | | Sadly, rustc seems to want us to mark this allow in several places.
* Merge branch 'tolerate_missing_blob' into 'main'Nick Mathewson2024-06-181-23/+161
|\ | | | | | | | | | | | | dirmgr::storage: Treat a missing blob file as an absent object. Closes #1466 See merge request tpo/core/arti!2200
| * sqlite: (style) Use consistent casing on "ExtDocs"Nick Mathewson2024-06-181-2/+2
| | | | | | | | SQL is case-insensitive, but it is still nice to be consistent.
| * storage: Remove orphaned files from dir_blobsNick Mathewson2024-06-121-0/+117
| | | | | | | | | | | | | | | | | | | | This patch removes files from dir_blobs if they are not referenced from the database, or if their filenames are not valid UTF-8. (If they were not valid UTF-8, we wouldn't have put them in our database.) To ensure that there can't be any race conditions, we only do this when the file is a bit old.
| * dirmgr: create temporary testing stores with correct paths.Nick Mathewson2024-06-121-3/+3
| | | | | | | | | | Previously, we were putting an (optional) db.sql file and our blobs into the same path, which is not what we do outside of our tests.
| * dirmgr::storage: Enable foreign keys on our sqlite connections.Nick Mathewson2024-06-121-0/+4
| | | | | | | | | | | | Without this, "ON DELETE CASCADE" will do nothing. Part of fixing #1466.
| * dirmgr::storage: Treat a missing blob file as an absent object.Nick Mathewson2024-06-121-19/+36
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously it was counted as a hard error, which would cause an absolute failure to start if a blob file had been deleted improperly -- for example, by a renegade cache-cleaner that had decided to remove the largest files it could find. Upon encountering a missing blob, we remove it from the database as well: if we did not, then unavailable consensuses could still cause us to try to fetch consensus diffs, because their rows would still be present. Fixes #1466.
* | dirmgr: Limit the number of mds that we will fetch from sqlite at once.Nick Mathewson2024-06-121-6/+14
| | | | | | | | | | | | This should help limit our memory usage when restarting from cache. Possible (imperfect) solution for #1027.
* | dirmgr: split out the loading part of load_once into a new function.Nick Mathewson2024-06-121-6/+17
|/
* dirauth: Add new faravahar authorityDavid Goulet2024-05-301-1/+2
| | | | | | | Related to C-tor MR: https://gitlab.torproject.org/tpo/core/tor/-/merge_requests/819 Signed-off-by: David Goulet <[email protected]>
* DirMgr: Clarify dead_code status on storage methods.Nick Mathewson2024-05-141-2/+5
| | | | | | | | | Per comments on #1383, we're keeping these methods. This commit replaces the "TODO" comments with comments explaining why it's okay that this methods are unused. Part of #1383.
* Use the right feature name for an allow(dead_code).Nick Mathewson2024-05-071-1/+1
|
* Re-run maint/add_warning.Nick Mathewson2024-05-061-2/+2
| | | | This commit is automatically generated.
* properly report bootstrap readiness without cachetrinity-1686a2024-04-291-0/+3
|