summaryrefslogtreecommitdiff
path: root/crates/tor-dirserver/src
Commit message (Collapse)AuthorAgeFilesLines
* tor-dirserver: Fix for missing_extra_infos() for NULLClara Engler2026-04-281-0/+1
| | | | | | | | | | If extra-infos is set to NULL, which might be the case for micro descriptors or even router descriptors because the field is optional there, this SQL query fails because it cannot LEFT JOIN server.extra_unsigned_sha1 when this field is NULL. To fix this, we simply add an additional clause to the WHERE statement that filters such rows out.
* tor-dirserver: Make fingerprint optional in router_descriptorClara Engler2026-04-281-2/+2
| | | | | | | | This commit changes the schema to make the fingerprint optional. Reason for this is, that microdescriptors are also stored in this table and microdescriptors only contain an OPTIONAL onion-key, meaning it may not always be possible to determine this value from a microdescriptor, thereby making it silly to require it here.
* tor-dirserver: Make use of only one descriptor hash in missing selectionClara Engler2026-04-271-0/+2
| | | | | | | | | | | | | | | This commit makes use of the presence of only one descriptor hash inside consensus_router_descriptor_member by adding a respective AND clause to the select statements of missing descriptors to only select the rows with a non-null SHA-1 (or SHA-2 for the sake of microdescs) in the consensus_router_descriptor_member table. This is defensive programming and should not be required in practice because the docid as well as the "XOR" CHECK should already ensure that this value is always non-NULL. However, if it still happens and slips through, the statement would return NULL rows, which is not what we want and was previously prevented by ensuring this field was never NULL in the first place.
* tor-dirserver: Store precisely one descriptor hash in schemaClara Engler2026-04-273-24/+16
| | | | | | | | | | | | | | | | | | This commit modifies the consensus_router_descriptor_member table in the database schema, removing the NOT NULL constraint on unsigned_sha1 and unsigned_sha2 by replacing it with a new CHECK constraint that checks that either one of them is set but not both. The reason for this is as follows: We are going to use this table to compute the queue of missing descriptors, which means that we can only populate this table with the data we know from the consensus. The consensus however tells us only one of those hashes, namely sha1 in the case of a consensus-ns and sha2 in the case of a consensus-md. In other words: This commit can also be seen as an effort to change the design of the operation in such a way that the queue is obtained directly from the database and not computed at the start during state transition.
* dirserver: Skip warnings re SaturatingTime::saturating_duration_sinceNick Mathewson2026-04-211-0/+2
| | | | | Rust 1.95 warns us that this is an experimental API that could be stabilized in the future.
* tor-netdoc: Rename `AuthCertUnverified::verify_self_signed`Ian Jackson2026-03-311-1/+1
| | | | | | | | | | | This method verifies all the signatures, and checks that the signing authority is in the provided list. Anyway, authcerts aren't really self-signed: they're a signature by KS_auth_id_rsa on KP_auth_sign_rsa. Note that there is also a `verify_selfcert` method which does only some of the checks, and has some code duplication. That will be cleaned up later.
* Merge branch 'weak_table_explicit_hasher' into 'main'David Goulet2026-03-241-0/+5
|\ | | | | | | | | | | | | Force use of standard hasher with weak_tables. Closes #2418 See merge request tpo/core/arti!3801
| * Force use of standard hasher with weak_tables.Nick Mathewson2026-03-241-0/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | Closes #2418. Fixes TROVE-2026-005, where we would use a less cryptographically secure (and probably less DoS resistant) hash function for these tables if: - We are built alongside another crate that uses `weak-table` - That crate enables the `weak-table/ahash` feature. - We are running on a system without hardware AES. Severity: Low
* | Fix typosTobias Stoeckmann2026-03-247-23/+23
|/ | | | Typos found with codespell
* tor-dirserver: Avoid using NetdocParseable for consensusesIan Jackson2026-03-191-4/+8
| | | | | | | | | | | | We want to stop deriving NetdocParseable directly for body structs. Doing so reveals a call site here in tor-dirmirror where a consensus is parsed and the body data used, but without verifying the signatures. Do this explicitly with the hoop-jumping which is going to become deliberately unavoidable. Add a TODO comment because I'm not sure we have decided explicitloy that this is OK.
* tor-dirserver: Avoid using NetdocParseable for consensuses (prep)Ian Jackson2026-03-191-4/+10
| | | | Formatting changes which make the next commit more readable.
* tor-netdoc: parse2: Introduce SignatureData structIan Jackson2026-03-191-2/+2
| | | | This is going to contain body information, and the hashes, too.
* tor-dirserver: Require AuthCerts to make progressClara Engler2026-03-091-37/+54
| | | | | | This commit changes the functionality of the AuthCerts state to only report a success when at least a single certificate was included in the response.
* tor-dirserver: Add retry logic POC TODOClara Engler2026-03-091-0/+4
| | | | | Adds a small TODO with regard to a potentially broken retry logic in the proof-of-concept.
* tor-dirserver: SQL comment for unsigned hashesClara Engler2026-03-091-0/+11
| | | | | This commit documents why and how we use the `unsigned_` fields in the `consensus_router_descriptor_member` table alongside SQL limitations.
* tor-dirserver: Move POC to own moduleClara Engler2026-03-092-73/+91
| | | | | This commit moves dirserver POC code to an own module to semantically indicate it is not production ready.
* tor-dirserver: Document stream dropClara Engler2026-03-091-1/+2
| | | | | | This commit documents why we drop the HTTP TCP stream and why this is fine, namely because this is compliant HTTP/1.0 behavior where there is no connection reuse.
* tor-dirserver: Link to discussion regarding TODOClara Engler2026-03-091-0/+3
| | | | | This commit links the discussion for the TODO for the dirmirror's handling of forward compatibility with netdocs.
* tor-dirserver: Use collect instead of mutable forClara Engler2026-03-091-18/+9
|
* tor-dirserver: Remove fiddly SQL CHECKClara Engler2026-03-091-5/+1
|
* tor-dirserver: Use tor-llcrypto for digestsClara Engler2026-03-091-4/+4
| | | | | | | | This commit replaces the uses of sha1, sha2, and sha3 with their respective pedants from tor-llcrypto for better consistency. Internally, they still use the same logic and underlying crates but let's use this encapsulation nonetheless.
* tor-dirserver: Improve hash wrapper macro docsClara Engler2026-03-091-0/+19
|
* tor-dirserver: Move schema to own fileClara Engler2026-03-092-170/+167
| | | | | | | | This commit moves the database schema into schema_v1.sql and uses include_str to include it. For now, the schema lives in the `src/` directory. If this becomes a problem because we get more schemas and schema upgrades, we can move it into another sub directory, but let's not overengineer the hierarchy there.
* tor-dirserver: PoC for FSM main loopClara Engler2026-03-091-2/+73
| | | | | This commit implements a PoC serving as the main loop for the FSM, demonstrating how invocation and error handling works.
* tor-dirserver: TODO a torspec DoS issueClara Engler2026-03-091-0/+9
| | | | Discussed with nickm on IRC, there will be a torspec issue soon.
* tor-dirserver: Implement `State::AuthCerts`Clara Engler2026-03-092-7/+229
| | | | | | | | | | | | | | This commit implements the logic required for retrieving, validating, and storing authority certificates. The implementation determines the missing certificates by looking at the signatories of the unvalidated consensus and checking them in the db. Afterwards, they will be queried and individually filtered and verified before being inserted into the database. A return of this implementation notably DOES NOT imply all missing certificates have been downloaded. This was chosen for a simplified retry logic.
* tor-dirserver: Add `StaticEngine::send_request()`Clara Engler2026-03-092-47/+104
| | | | | | | | | | | | | This commit adds a new method to static engine that serves as a convenience wrapper around `tor_dirclient::send_request`. The reason for that is, that fetch_consensus is not the only method that requires performing download requests, so it makes sense to generalize it. Besides, it also adds support for parsing multiple netdocs alongside storing their raw variant, which is required for inserting them into the database at one point eventually.
* tor-dirserver: Add IsFatal traitClara Engler2026-03-092-19/+24
| | | | | This commit adds the IsFatal trait to the err module for having a generic signature for the fatality of certain error variants.
* tor-dirservert: Implement FetchConsensus stateClara Engler2026-03-092-2/+167
| | | | | | | | | | | | This commit implements the `FetchConsensus` state by adding a method to `StaticEngine` called `fetch_consensus`, which retrieves the consensus from an upstream directory authority. Likewise, it also implements a new error type called `AuthorityRequestError`. The retry logic is handled externally which will be done in later commits.
* tor-dirserver: Derive PartialEq and Eq for StateClara Engler2026-03-091-2/+2
| | | | Required to test state transitions properly.
* tor-dirserver: PreferredRuntime in StaticEngineClara Engler2026-03-091-2/+9
| | | | This is required for compatibility with other crates in arti.
* tor-dirserver: Remove unused error variantsClara Engler2026-03-091-62/+0
|
* tor-dirserver: Remove download moduleClara Engler2026-03-092-367/+0
| | | | | This commit removes the download manager module because it does not fit well into the mental model of our current finite state machine anymore.
* tor-dirserver: Remove `preferred` from dataClara Engler2026-03-091-9/+1
| | | | | | | | | | This commit removes the `preferred` member field from the `Unverified` and `Verified` variant in `ConsensusBoundData` while adding it as a parameter to `StaticEngine::execute`, with the idea being that the retry logic is handled by the caller anyways, involving the selection of authorities. Right now, I am still a bit unsure how this will play out.
* tor-dirserver: Fix rustdoc commentsClara Engler2026-03-092-5/+5
|
* tor-dirserver: Implement consensus loadingClara Engler2026-03-091-16/+205
| | | | | | This commit implements the consensus loading mechanism by glueing together the logic from the database module with regard to querying missing descriptors.
* tor-dirserver: Query missing descriptor logicClara Engler2026-03-091-1/+394
| | | | | | | | | | | | | | | | | | | This commit implements the logic for querying missing descriptors by adding three new methods to ConsensusMeta: * missing_servers * missing_extras * missing_micros All of them essentially work the same, namely by querying the consensus_router_descriptor_member database table alongside the docid of the current consensus, left joining the respective router_descriptor and returning the digests on all rows where the left join resulteed in a NULL. A small exception are extra-info descriptors. There, we can only return the ones where we have an accompanying server descriptor, hence why we perform an inner join with the server descriptors between the from and the left join.
* tor-dirserver: Rename `md` to `microdesc`Clara Engler2026-03-091-2/+2
| | | | | This is better because it is returned by `ConsensusFlavor::Microdesc::name()`.
* tor-dirserver: Fix extra info schemaClara Engler2026-03-091-7/+10
| | | | | | | | | | | | This commit fixes some parts in the extra-info related part of the database schema. Most notably, it changes the semantic to indicate that the sha1 represents the unsigned part of the extra-info document. Likewise, it also ensures that the reference to an extra-info document must not be null with a plain consensus but null with a microdescriptor consensus.
* tor-dirserver: Store unsigned SHA for descsClara Engler2026-03-091-12/+13
| | | | | | | | | | | This commit modifies the database schema to rename `sha1` and `sha2` to `unsigned_sha1` and `unsigned_sha2`. Network status consensuses refer to server descriptors by their unsigned sha1. Microdescriptor consensuses refer to microdescriptors by their sha2, which is always unsigned, so we adapt that name for consistency.
* tor-dirserver: Remove foreign key from descriptor memberClara Engler2026-03-091-4/+8
| | | | | | | | | | | This commit removes the foreign key constraints from the `consensus_router_descriptor_member` in order to allow the insertion of the router descriptors contained in a consensus before the respective descriptors were fetched. This also allows to directly compute the missing descriptors in SQL, using a left join on this table on `router_descriptor` and obtaining the entries that are NULL.
* tor-dirserver: Store sha1 for extra-infoClara Engler2026-03-091-2/+6
| | | | | | | | | | | This commit modifies the database schema by tracking the sha1 of the extra-info instead of the rowid. This makes generating queues and other things easier. It also removes the foreign key constraint in order to allow for an asynchronous retrieval and storage. Otherwise it would not be possible to store a router descriptor without having obtained the extra info first.
* tor-dirserver: Use getters for meta structsClara Engler2026-03-091-13/+16
| | | | | | This approach is better in order to guarantee that invariants are not violated, such that the expiry timestamp not being earlier than the valid after one for example.
* tor-dirserver: Derive Copy on database meta structsClara Engler2026-03-091-2/+2
|
* tor-dirserver: Implement Sha1Clara Engler2026-03-091-4/+11
| | | | | This commit implements Sha1 for the database in order to use it for the fingerprints in authority key certificates.
* tor-dirserver: Implement Sha3_256Clara Engler2026-03-091-8/+5
| | | | | This commit implements Sha3_256 as a database type and uses it for stroing `ConsensusMeta::unsigned_sha3_256`.
* tor-dirserver: Generic database hash implementationClara Engler2026-03-091-65/+69
| | | | | | | | | | | | | | | This commit moves the `DocumentId` implementation into a macro called `impl_hash_wrapper` that implements a hash type in a database compatible fashion. In our case, we implement this for `sha2::Sha256` and then type alias `DocumentId` to this new hash. Yes, we originally moved away from a type alias here, but I think this is fine because for the foreseeable future, we will continue to use a hash here, just maybe not Sha2, but the flexibility remains. The motivation for this is to support other hash algorithms similarly too.
* tor-dirserver: pub(crate) for ConsensusMeta::lifetimeClara Engler2026-03-091-1/+1
|
* tor-dirserver: Move AuthCert to databaseClara Engler2026-03-092-573/+263
| | | | | | | | | This commit moves get_recent_auth_certs from operation to database by introducing a new struct called `AuthCertMeta` containing the database metadata alongside an accompanying data method returning the raw data. For now, it leaves out the download, verify, and insert logic. We will add that back later once we will need it.
* tor-dirserver: Rename Consensus to ConsensusMetaClara Engler2026-03-092-27/+35
| | | | | | | This commit renames the database `Consensus` to `ConsensusMeta` in order to not collide with the naming from tor-netdoc and to clearly indicate that this data is just metadata about such a document, but not the document itself.