aboutsummaryrefslogtreecommitdiff
path: root/crates/tor-dirserver/src
Commit message (Collapse)AuthorAgeFilesLines
...
* tor-dirserver: Move schema to own fileClara Engler2026-03-092-170/+167
| | | | | | | | This commit moves the database schema into schema_v1.sql and uses include_str to include it. For now, the schema lives in the `src/` directory. If this becomes a problem because we get more schemas and schema upgrades, we can move it into another sub directory, but let's not overengineer the hierarchy there.
* tor-dirserver: PoC for FSM main loopClara Engler2026-03-091-2/+73
| | | | | This commit implements a PoC serving as the main loop for the FSM, demonstrating how invocation and error handling works.
* tor-dirserver: TODO a torspec DoS issueClara Engler2026-03-091-0/+9
| | | | Discussed with nickm on IRC, there will be a torspec issue soon.
* tor-dirserver: Implement `State::AuthCerts`Clara Engler2026-03-092-7/+229
| | | | | | | | | | | | | | This commit implements the logic required for retrieving, validating, and storing authority certificates. The implementation determines the missing certificates by looking at the signatories of the unvalidated consensus and checking them in the db. Afterwards, they will be queried and individually filtered and verified before being inserted into the database. A return of this implementation notably DOES NOT imply all missing certificates have been downloaded. This was chosen for a simplified retry logic.
* tor-dirserver: Add `StaticEngine::send_request()`Clara Engler2026-03-092-47/+104
| | | | | | | | | | | | | This commit adds a new method to static engine that serves as a convenience wrapper around `tor_dirclient::send_request`. The reason for that is, that fetch_consensus is not the only method that requires performing download requests, so it makes sense to generalize it. Besides, it also adds support for parsing multiple netdocs alongside storing their raw variant, which is required for inserting them into the database at one point eventually.
* tor-dirserver: Add IsFatal traitClara Engler2026-03-092-19/+24
| | | | | This commit adds the IsFatal trait to the err module for having a generic signature for the fatality of certain error variants.
* tor-dirservert: Implement FetchConsensus stateClara Engler2026-03-092-2/+167
| | | | | | | | | | | | This commit implements the `FetchConsensus` state by adding a method to `StaticEngine` called `fetch_consensus`, which retrieves the consensus from an upstream directory authority. Likewise, it also implements a new error type called `AuthorityRequestError`. The retry logic is handled externally which will be done in later commits.
* tor-dirserver: Derive PartialEq and Eq for StateClara Engler2026-03-091-2/+2
| | | | Required to test state transitions properly.
* tor-dirserver: PreferredRuntime in StaticEngineClara Engler2026-03-091-2/+9
| | | | This is required for compatibility with other crates in arti.
* tor-dirserver: Remove unused error variantsClara Engler2026-03-091-62/+0
|
* tor-dirserver: Remove download moduleClara Engler2026-03-092-367/+0
| | | | | This commit removes the download manager module because it does not fit well into the mental model of our current finite state machine anymore.
* tor-dirserver: Remove `preferred` from dataClara Engler2026-03-091-9/+1
| | | | | | | | | | This commit removes the `preferred` member field from the `Unverified` and `Verified` variant in `ConsensusBoundData` while adding it as a parameter to `StaticEngine::execute`, with the idea being that the retry logic is handled by the caller anyways, involving the selection of authorities. Right now, I am still a bit unsure how this will play out.
* tor-dirserver: Fix rustdoc commentsClara Engler2026-03-092-5/+5
|
* tor-dirserver: Implement consensus loadingClara Engler2026-03-091-16/+205
| | | | | | This commit implements the consensus loading mechanism by glueing together the logic from the database module with regard to querying missing descriptors.
* tor-dirserver: Query missing descriptor logicClara Engler2026-03-091-1/+394
| | | | | | | | | | | | | | | | | | | This commit implements the logic for querying missing descriptors by adding three new methods to ConsensusMeta: * missing_servers * missing_extras * missing_micros All of them essentially work the same, namely by querying the consensus_router_descriptor_member database table alongside the docid of the current consensus, left joining the respective router_descriptor and returning the digests on all rows where the left join resulteed in a NULL. A small exception are extra-info descriptors. There, we can only return the ones where we have an accompanying server descriptor, hence why we perform an inner join with the server descriptors between the from and the left join.
* tor-dirserver: Rename `md` to `microdesc`Clara Engler2026-03-091-2/+2
| | | | | This is better because it is returned by `ConsensusFlavor::Microdesc::name()`.
* tor-dirserver: Fix extra info schemaClara Engler2026-03-091-7/+10
| | | | | | | | | | | | This commit fixes some parts in the extra-info related part of the database schema. Most notably, it changes the semantic to indicate that the sha1 represents the unsigned part of the extra-info document. Likewise, it also ensures that the reference to an extra-info document must not be null with a plain consensus but null with a microdescriptor consensus.
* tor-dirserver: Store unsigned SHA for descsClara Engler2026-03-091-12/+13
| | | | | | | | | | | This commit modifies the database schema to rename `sha1` and `sha2` to `unsigned_sha1` and `unsigned_sha2`. Network status consensuses refer to server descriptors by their unsigned sha1. Microdescriptor consensuses refer to microdescriptors by their sha2, which is always unsigned, so we adapt that name for consistency.
* tor-dirserver: Remove foreign key from descriptor memberClara Engler2026-03-091-4/+8
| | | | | | | | | | | This commit removes the foreign key constraints from the `consensus_router_descriptor_member` in order to allow the insertion of the router descriptors contained in a consensus before the respective descriptors were fetched. This also allows to directly compute the missing descriptors in SQL, using a left join on this table on `router_descriptor` and obtaining the entries that are NULL.
* tor-dirserver: Store sha1 for extra-infoClara Engler2026-03-091-2/+6
| | | | | | | | | | | This commit modifies the database schema by tracking the sha1 of the extra-info instead of the rowid. This makes generating queues and other things easier. It also removes the foreign key constraint in order to allow for an asynchronous retrieval and storage. Otherwise it would not be possible to store a router descriptor without having obtained the extra info first.
* tor-dirserver: Use getters for meta structsClara Engler2026-03-091-13/+16
| | | | | | This approach is better in order to guarantee that invariants are not violated, such that the expiry timestamp not being earlier than the valid after one for example.
* tor-dirserver: Derive Copy on database meta structsClara Engler2026-03-091-2/+2
|
* tor-dirserver: Implement Sha1Clara Engler2026-03-091-4/+11
| | | | | This commit implements Sha1 for the database in order to use it for the fingerprints in authority key certificates.
* tor-dirserver: Implement Sha3_256Clara Engler2026-03-091-8/+5
| | | | | This commit implements Sha3_256 as a database type and uses it for stroing `ConsensusMeta::unsigned_sha3_256`.
* tor-dirserver: Generic database hash implementationClara Engler2026-03-091-65/+69
| | | | | | | | | | | | | | | This commit moves the `DocumentId` implementation into a macro called `impl_hash_wrapper` that implements a hash type in a database compatible fashion. In our case, we implement this for `sha2::Sha256` and then type alias `DocumentId` to this new hash. Yes, we originally moved away from a type alias here, but I think this is fine because for the foreseeable future, we will continue to use a hash here, just maybe not Sha2, but the flexibility remains. The motivation for this is to support other hash algorithms similarly too.
* tor-dirserver: pub(crate) for ConsensusMeta::lifetimeClara Engler2026-03-091-1/+1
|
* tor-dirserver: Move AuthCert to databaseClara Engler2026-03-092-573/+263
| | | | | | | | | This commit moves get_recent_auth_certs from operation to database by introducing a new struct called `AuthCertMeta` containing the database metadata alongside an accompanying data method returning the raw data. For now, it leaves out the download, verify, and insert logic. We will add that back later once we will need it.
* tor-dirserver: Rename Consensus to ConsensusMetaClara Engler2026-03-092-27/+35
| | | | | | | This commit renames the database `Consensus` to `ConsensusMeta` in order to not collide with the naming from tor-netdoc and to clearly indicate that this data is just metadata about such a document, but not the document itself.
* tor-dirserver: Use database as dbClara Engler2026-03-091-4/+4
| | | | Makes things more handy to write.
* tor-dirserver: Avoid super in testsClara Engler2026-03-091-54/+44
| | | | | If is annoying to use, especially if we can avoid it by just avoid name conflicts.
* tor-dirserver: `use crate::database::Consensus`Clara Engler2026-03-091-3/+3
|
* tor-dirserver: Move db constants to the topClara Engler2026-03-091-172/+172
| | | | | | | Right now, it is a bit unfortunate that we have the very long schema string between two code blocks. It is probably better to either have it at the top or the bottom of the file, hence why this commit moves it to the top.
* tor-dirserver: Move sync timeout to databaseClara Engler2026-03-092-55/+38
| | | | | This commit moves calculate_sync_timeout into the Consensus struct in the database module, as it fits better there.
* tor-dirserver: Remove serve functionClara Engler2026-03-092-129/+2
| | | | | This commit removes the operation serve function because it no longer fits into the new model of operation using a FSM.
* tor-dirserver: Refactor consensus retrieval logicClara Engler2026-03-092-260/+324
| | | | | | | | This commit moves the get_recent_consensus logic to the database module, which also introduces a struct querying all fields in it. This not only simplifies the return type but also makes working with this type more comfortable to work with.
* tor-dirserver: docid as consistent foreign keyClara Engler2026-03-091-10/+10
| | | | | | This commit replaces occurrences of rowid with docid, particularly in tables for N:M cardinalities. Purpose of this is, to achieve a greater consistency with the overall database schema.
* tor-dirserver: Return Timestamp in consensus queryingClara Engler2026-03-091-17/+10
| | | | | This is more useful and less boilerplate, removing a parameter for a conversion we can do ourselves if required.
* tor-dirserver: Scratch out the FSMClara Engler2026-03-092-5/+493
| | | | | | | This commit scratches out the FSM for the dirmirror operation. Right now, there are still lots of TODO, lots of code warnigns, and such. It should model the rough concept.
* tor-netdoc: Rename *Signed to *UnverifiedIan Jackson2026-03-031-9/+9
| | | | | | | | | | This was a weird name, and while working in this area it all seemed to make the docs strange. Rename it. This is quite invasive! In theory we could have the macros generate compatibility aliases, but that seems quite complex.
* Allow clippy::collapsible_if to triggerGabriela Moldovan2026-02-161-0/+1
| | | | | | | | | `clippy::collapsible_if` started triggering after bumping the MSRV to 1.88. Since this triggers from a lot of places, and since there even are a couple of instances where we explicitly allow `clippy::collapsible_ifs`, I've opened #2342 for deciding what to do about it.
* dirserver: Allow clippy::unused_asyncGabriela Moldovan2026-01-272-0/+2
| | | | This code is still WIP, no need to address the lint yet.
* maint/add_warning: Run script to add new warningGabriela Moldovan2026-01-271-0/+1
| | | | This adds the lint to all our crates.
* tor-dirserver: Add comment on compression bugClara Engler2026-01-221-0/+4
| | | | | This commit adds a comment explaining why we treat compression errors as a bug.
* tor-dirserver: Make compression failures a bugClara Engler2026-01-222-5/+2
| | | | | | | | | | | | | | This commit removes `DatabaseError::Compression` because it does not fit in. Right now, this single variant makes the error to be call-site oriented which is not nice for error handling. Instead, this error should indicate that something was truly wrong with the database in itself, such as an invalid schema, a low-level SQLite bug, etc. Instead, we now map a compression error to `DatabaseError::Bug` because there is no good reason on why it should fail, given that we compress memory data to memory data. Probably because it uses the `std::io::Writer` interface which itself demands use of `std::io::Result`.
* Merge branch 'database-refactoring' into 'main'Clara Engler2026-01-224-197/+245
|\ | | | | | | | | tor-dirserver: Refactorings in the database.rs module See merge request tpo/core/arti!3599
| * tor-dirserver: Remove FromStr for DocumentIdClara Engler2026-01-223-39/+15
| | | | | | | | | | | | | | | | | | | | | | This commit removes FromStr for DocumentId because it was only used in testing anyways. Instead, it replaces it with a simple From<[u8; 32]> only enabled in test builds, which is sufficient for what we are trying to do. An alternative would be to make the inner field pub, but this seems to aggressive for a testing only thing.
| * tor-dirserver: Add `sha2` to `router_descriptor`Clara Engler2026-01-191-0/+2
| | | | | | | | | | | | | | | | | | | | This comit adds a `sha2` column to `router_descriptor` alongside a `CHECK` to see whether it equals `docid`. The reason for this is simple: Microdescriptors are the only kind of documents that are queriable with a SHA2 hash. Previously, we would have simply used the `docid` column for this, but in order to abstract it better, a distinct column with this hash is better.
| * tor-dirserver: Rename `doc_id` to `docid`Clara Engler2026-01-194-76/+75
| | | | | | | | | | Because we went with `docid` in the database (due to `rowid`), it is only natural to call the code variables `docid` too.
| * tor-dirserver: Rename sha256 to docid in schemaClara Engler2026-01-194-51/+51
| | | | | | | | | | | | This commit renames the sha256 column to docid for the reason that we agreed upon making the schema visible to all modules, so if we were to encapsulate docid properly, this change is only natural.
| * tor-dirserver: Rename database meta tableClara Engler2026-01-191-16/+13
| | | | | | | | | | This commit renames arti_dirmirror_schema_version to arti_dirserver_schema_version.