aboutsummaryrefslogtreecommitdiff
path: root/crates/tor-dirserver/src/mirror
Commit message (Collapse)AuthorAgeFilesLines
* tor-dirserver: fix tests on OpenBSDAndrew Kloet2026-08-051-2/+2
| | | | | | Use an IPv6 loopback address instead of the unspecified address when creating test servers. The address returned by binding to [::]:0 is not valid as a connection target on OpenBSD.
* tor-checkable: Rename `TimeBound::check_valid_*` to `if_valid_*`Ian Jackson2026-07-231-1/+1
| | | | | | | I find these names confusing. To my mind "check" implies a function returning `Result<(), _>`. Some other APIs use `unwrap` here but I think `if` is good.
* Much formatting churn for 2024 editionIan Jackson2026-07-222-3/+3
|
* Use new TimeBound name throughout the treeIan Jackson2026-07-161-1/+1
|
* tor-dirserver: Use "plain" consensus terminology rather than "ns" (fmt)Ian Jackson2026-07-151-1/+4
|
* tor-dirserver: Use "plain" consensus terminology rather than "ns"Ian Jackson2026-07-151-12/+12
| | | | | | | | It doesn't make sense to say that a plain consensus is an "ns" consensus, because "ns" stands for "network status" and all consensus flavours, and indeed votes, are network statusus. That's why tor-netdoc now uses "plain". Use that here too.
* tor-dirserver: Use real consensus types, not poc (fmt)Ian Jackson2026-07-151-4/+1
|
* tor-dirserver: Use real consensus types, not pocIan Jackson2026-07-151-3/+2
|
* tor-netdoc: authcert: use TimerangeBound for UnverifiedAuthCert::verify (fmt)Ian Jackson2026-06-101-8/+8
| | | | Precisely the result of rustfmt.
* tor-netdoc: authcert: use TimerangeBound for UnverifiedAuthCert::verifyIan Jackson2026-06-101-2/+5
| | | | | | | | | | | | | | TimerangeBound is reasonably nice and this will fit in better when we want to verify votes. Adjust the one non-test call site (in tor-dirserver) using .and_then. In the tests: * Where we expected success, call .check_valid_at and add another .unwrap(). * Where we expected signature verification failure, delete the time parameters. * Where we expected timeliness failure, call .check_valid_at and map the error. * With nontrivial tolerance, add calls to `extend_[pre_]tolerance`.
* everywhere: Add #[allow(clippy::string_slice)]Clara Engler2026-06-091-0/+2
| | | | | | | | This commit adds #[allow(clippy::string_slice)] to all functions in the code where string slices are used, alongside a TODO comment. We do this add the function header to have it consistent, as things like expression based allow's are still experimental.
* maint: Run maint/add_warning to deny string slicesClara Engler2026-06-091-0/+1
| | | | | | | | | | | | This commit executes maint/add_warning with the just added change to deny string slices except in tests. I recommend auditing this by checking out the previous commit followed by running the script yourself and then verifying that the diff is identical to this commit. This commit makes cargo clippy fail. We will add exceptions in the next commit.
* tor-netdoc: Rename NetdocUnverified trait to NetdocParseableUnverifiedIan Jackson2026-06-021-2/+2
| | | | | | | | | | | | The NetdocParseableUnverified derive macro implements this trait (amongst other things). Traits and derive macros should have aligned names. This is only used for parsing, so let's keep the "Parseable" part of the name. I don't think the effort of deprecated alias, for downstream compatibility, is worth it, our compatibility policy notwithstanding.
* tor-netdoc: Apply deferred rustfmt churnIan Jackson2026-04-291-3/+1
|
* tor-netdoc: Abolish poc's netstatus signature typeIan Jackson2026-04-291-14/+2
| | | | | | | | | | | | | | Use prod's Signature instead. This gets rid of: * The old parsing code. We have a new approach based on ItemValueParseable, KeywordOrString and and DigestAlgoInSignature. * The duplicate DirectorySignaturesHashesAccu and its temporary conversions. poc's verify_timeless function needs a little adjustment for the new struct layout.
* tor-dirserver: Store precisely one descriptor hash in schemaClara Engler2026-04-271-4/+2
| | | | | | | | | | | | | | | | | | This commit modifies the consensus_router_descriptor_member table in the database schema, removing the NOT NULL constraint on unsigned_sha1 and unsigned_sha2 by replacing it with a new CHECK constraint that checks that either one of them is set but not both. The reason for this is as follows: We are going to use this table to compute the queue of missing descriptors, which means that we can only populate this table with the data we know from the consensus. The consensus however tells us only one of those hashes, namely sha1 in the case of a consensus-ns and sha2 in the case of a consensus-md. In other words: This commit can also be seen as an effort to change the design of the operation in such a way that the queue is obtained directly from the database and not computed at the start during state transition.
* tor-netdoc: Rename `AuthCertUnverified::verify_self_signed`Ian Jackson2026-03-311-1/+1
| | | | | | | | | | | This method verifies all the signatures, and checks that the signing authority is in the provided list. Anyway, authcerts aren't really self-signed: they're a signature by KS_auth_id_rsa on KP_auth_sign_rsa. Note that there is also a `verify_selfcert` method which does only some of the checks, and has some code duplication. That will be cleaned up later.
* Fix typosTobias Stoeckmann2026-03-241-4/+4
| | | | Typos found with codespell
* tor-dirserver: Avoid using NetdocParseable for consensusesIan Jackson2026-03-191-4/+8
| | | | | | | | | | | | We want to stop deriving NetdocParseable directly for body structs. Doing so reveals a call site here in tor-dirmirror where a consensus is parsed and the body data used, but without verifying the signatures. Do this explicitly with the hoop-jumping which is going to become deliberately unavoidable. Add a TODO comment because I'm not sure we have decided explicitloy that this is OK.
* tor-dirserver: Avoid using NetdocParseable for consensuses (prep)Ian Jackson2026-03-191-4/+10
| | | | Formatting changes which make the next commit more readable.
* tor-netdoc: parse2: Introduce SignatureData structIan Jackson2026-03-191-2/+2
| | | | This is going to contain body information, and the hashes, too.
* tor-dirserver: Require AuthCerts to make progressClara Engler2026-03-091-37/+54
| | | | | | This commit changes the functionality of the AuthCerts state to only report a success when at least a single certificate was included in the response.
* tor-dirserver: Add retry logic POC TODOClara Engler2026-03-091-0/+4
| | | | | Adds a small TODO with regard to a potentially broken retry logic in the proof-of-concept.
* tor-dirserver: Move POC to own moduleClara Engler2026-03-092-73/+91
| | | | | This commit moves dirserver POC code to an own module to semantically indicate it is not production ready.
* tor-dirserver: Document stream dropClara Engler2026-03-091-1/+2
| | | | | | This commit documents why we drop the HTTP TCP stream and why this is fine, namely because this is compliant HTTP/1.0 behavior where there is no connection reuse.
* tor-dirserver: Link to discussion regarding TODOClara Engler2026-03-091-0/+3
| | | | | This commit links the discussion for the TODO for the dirmirror's handling of forward compatibility with netdocs.
* tor-dirserver: PoC for FSM main loopClara Engler2026-03-091-2/+73
| | | | | This commit implements a PoC serving as the main loop for the FSM, demonstrating how invocation and error handling works.
* tor-dirserver: TODO a torspec DoS issueClara Engler2026-03-091-0/+9
| | | | Discussed with nickm on IRC, there will be a torspec issue soon.
* tor-dirserver: Implement `State::AuthCerts`Clara Engler2026-03-091-6/+184
| | | | | | | | | | | | | | This commit implements the logic required for retrieving, validating, and storing authority certificates. The implementation determines the missing certificates by looking at the signatories of the unvalidated consensus and checking them in the db. Afterwards, they will be queried and individually filtered and verified before being inserted into the database. A return of this implementation notably DOES NOT imply all missing certificates have been downloaded. This was chosen for a simplified retry logic.
* tor-dirserver: Add `StaticEngine::send_request()`Clara Engler2026-03-091-47/+97
| | | | | | | | | | | | | This commit adds a new method to static engine that serves as a convenience wrapper around `tor_dirclient::send_request`. The reason for that is, that fetch_consensus is not the only method that requires performing download requests, so it makes sense to generalize it. Besides, it also adds support for parsing multiple netdocs alongside storing their raw variant, which is required for inserting them into the database at one point eventually.
* tor-dirserver: Add IsFatal traitClara Engler2026-03-091-2/+2
| | | | | This commit adds the IsFatal trait to the err module for having a generic signature for the fatality of certain error variants.
* tor-dirservert: Implement FetchConsensus stateClara Engler2026-03-091-2/+115
| | | | | | | | | | | | This commit implements the `FetchConsensus` state by adding a method to `StaticEngine` called `fetch_consensus`, which retrieves the consensus from an upstream directory authority. Likewise, it also implements a new error type called `AuthorityRequestError`. The retry logic is handled externally which will be done in later commits.
* tor-dirserver: Derive PartialEq and Eq for StateClara Engler2026-03-091-2/+2
| | | | Required to test state transitions properly.
* tor-dirserver: PreferredRuntime in StaticEngineClara Engler2026-03-091-2/+9
| | | | This is required for compatibility with other crates in arti.
* tor-dirserver: Remove download moduleClara Engler2026-03-092-367/+0
| | | | | This commit removes the download manager module because it does not fit well into the mental model of our current finite state machine anymore.
* tor-dirserver: Remove `preferred` from dataClara Engler2026-03-091-9/+1
| | | | | | | | | | This commit removes the `preferred` member field from the `Unverified` and `Verified` variant in `ConsensusBoundData` while adding it as a parameter to `StaticEngine::execute`, with the idea being that the retry logic is handled by the caller anyways, involving the selection of authorities. Right now, I am still a bit unsure how this will play out.
* tor-dirserver: Fix rustdoc commentsClara Engler2026-03-091-1/+1
|
* tor-dirserver: Implement consensus loadingClara Engler2026-03-091-16/+205
| | | | | | This commit implements the consensus loading mechanism by glueing together the logic from the database module with regard to querying missing descriptors.
* tor-dirserver: Move AuthCert to databaseClara Engler2026-03-091-572/+7
| | | | | | | | | This commit moves get_recent_auth_certs from operation to database by introducing a new struct called `AuthCertMeta` containing the database metadata alongside an accompanying data method returning the raw data. For now, it leaves out the download, verify, and insert logic. We will add that back later once we will need it.
* tor-dirserver: Rename Consensus to ConsensusMetaClara Engler2026-03-091-4/+4
| | | | | | | This commit renames the database `Consensus` to `ConsensusMeta` in order to not collide with the naming from tor-netdoc and to clearly indicate that this data is just metadata about such a document, but not the document itself.
* tor-dirserver: Use database as dbClara Engler2026-03-091-4/+4
| | | | Makes things more handy to write.
* tor-dirserver: `use crate::database::Consensus`Clara Engler2026-03-091-3/+3
|
* tor-dirserver: Move sync timeout to databaseClara Engler2026-03-091-55/+2
| | | | | This commit moves calculate_sync_timeout into the Consensus struct in the database module, as it fits better there.
* tor-dirserver: Remove serve functionClara Engler2026-03-091-112/+2
| | | | | This commit removes the operation serve function because it no longer fits into the new model of operation using a FSM.
* tor-dirserver: Refactor consensus retrieval logicClara Engler2026-03-091-259/+33
| | | | | | | | This commit moves the get_recent_consensus logic to the database module, which also introduces a struct querying all fields in it. This not only simplifies the return type but also makes working with this type more comfortable to work with.
* tor-dirserver: Return Timestamp in consensus queryingClara Engler2026-03-091-17/+10
| | | | | This is more useful and less boilerplate, removing a parameter for a conversion we can do ourselves if required.
* tor-dirserver: Scratch out the FSMClara Engler2026-03-091-5/+457
| | | | | | | This commit scratches out the FSM for the dirmirror operation. Right now, there are still lots of TODO, lots of code warnigns, and such. It should model the rough concept.
* tor-netdoc: Rename *Signed to *UnverifiedIan Jackson2026-03-031-9/+9
| | | | | | | | | | This was a weird name, and while working in this area it all seemed to make the docs strange. Rename it. This is quite invasive! In theory we could have the macros generate compatibility aliases, but that seems quite complex.
* Merge branch 'database-refactoring' into 'main'Clara Engler2026-01-221-26/+27
|\ | | | | | | | | tor-dirserver: Refactorings in the database.rs module See merge request tpo/core/arti!3599
| * tor-dirserver: Rename `doc_id` to `docid`Clara Engler2026-01-191-10/+10
| | | | | | | | | | Because we went with `docid` in the database (due to `rowid`), it is only natural to call the code variables `docid` too.