| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| |
|
|
|
|
|
|
|
|
|
|
| |
This commit implements the `FetchConsensus` state by adding a method to
`StaticEngine` called `fetch_consensus`, which retrieves the consensus
from an upstream directory authority.
Likewise, it also implements a new error type called
`AuthorityRequestError`.
The retry logic is handled externally which will be done in later
commits.
|
| |
|
|
| |
Required to test state transitions properly.
|
| |
|
|
| |
This is required for compatibility with other crates in arti.
|
| | |
|
| |
|
|
|
| |
This commit removes the download manager module because it does not fit
well into the mental model of our current finite state machine anymore.
|
| |
|
|
|
|
|
|
|
|
| |
This commit removes the `preferred` member field from the `Unverified`
and `Verified` variant in `ConsensusBoundData` while adding it as a
parameter to `StaticEngine::execute`, with the idea being that the retry
logic is handled by the caller anyways, involving the selection of
authorities.
Right now, I am still a bit unsure how this will play out.
|
| | |
|
| |
|
|
|
|
| |
This commit implements the consensus loading mechanism by glueing
together the logic from the database module with regard to querying
missing descriptors.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
This commit implements the logic for querying missing descriptors by
adding three new methods to ConsensusMeta:
* missing_servers
* missing_extras
* missing_micros
All of them essentially work the same, namely by querying the
consensus_router_descriptor_member database table alongside the docid of
the current consensus, left joining the respective router_descriptor and
returning the digests on all rows where the left join resulteed in a
NULL.
A small exception are extra-info descriptors. There, we can only return
the ones where we have an accompanying server descriptor, hence why we
perform an inner join with the server descriptors between the from and
the left join.
|
| |
|
|
|
| |
This is better because it is returned by
`ConsensusFlavor::Microdesc::name()`.
|
| |
|
|
|
|
|
|
|
|
|
|
| |
This commit fixes some parts in the extra-info related part of the
database schema.
Most notably, it changes the semantic to indicate that the sha1
represents the unsigned part of the extra-info document.
Likewise, it also ensures that the reference to an extra-info document
must not be null with a plain consensus but null with a microdescriptor
consensus.
|
| |
|
|
|
|
|
|
|
|
|
| |
This commit modifies the database schema to rename `sha1` and `sha2` to
`unsigned_sha1` and `unsigned_sha2`.
Network status consensuses refer to server descriptors by their unsigned
sha1.
Microdescriptor consensuses refer to microdescriptors by their sha2,
which is always unsigned, so we adapt that name for consistency.
|
| |
|
|
|
|
|
|
|
|
|
| |
This commit removes the foreign key constraints from the
`consensus_router_descriptor_member` in order to allow the insertion of
the router descriptors contained in a consensus before the respective
descriptors were fetched.
This also allows to directly compute the missing descriptors in SQL,
using a left join on this table on `router_descriptor` and obtaining the
entries that are NULL.
|
| |
|
|
|
|
|
|
|
|
|
| |
This commit modifies the database schema by tracking the sha1 of the
extra-info instead of the rowid. This makes generating queues and other
things easier.
It also removes the foreign key constraint in order to allow for an
asynchronous retrieval and storage. Otherwise it would not be possible
to store a router descriptor without having obtained the extra info
first.
|
| |
|
|
|
|
| |
This approach is better in order to guarantee that invariants are not
violated, such that the expiry timestamp not being earlier than the
valid after one for example.
|
| | |
|
| |
|
|
|
| |
This commit implements Sha1 for the database in order to use it for the
fingerprints in authority key certificates.
|
| |
|
|
|
| |
This commit implements Sha3_256 as a database type and uses it for
stroing `ConsensusMeta::unsigned_sha3_256`.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
This commit moves the `DocumentId` implementation into a macro called
`impl_hash_wrapper` that implements a hash type in a database compatible
fashion.
In our case, we implement this for `sha2::Sha256` and then type alias
`DocumentId` to this new hash. Yes, we originally moved away from a
type alias here, but I think this is fine because for the foreseeable
future, we will continue to use a hash here, just maybe not Sha2, but
the flexibility remains.
The motivation for this is to support other hash algorithms similarly
too.
|
| | |
|
| |
|
|
|
|
|
|
|
| |
This commit moves get_recent_auth_certs from operation to database by
introducing a new struct called `AuthCertMeta` containing the database
metadata alongside an accompanying data method returning the raw data.
For now, it leaves out the download, verify, and insert logic.
We will add that back later once we will need it.
|
| |
|
|
|
|
|
| |
This commit renames the database `Consensus` to `ConsensusMeta` in order
to not collide with the naming from tor-netdoc and to clearly indicate
that this data is just metadata about such a document, but not the
document itself.
|
| |
|
|
| |
Makes things more handy to write.
|
| |
|
|
|
| |
If is annoying to use, especially if we can avoid it by just avoid name
conflicts.
|
| | |
|
| |
|
|
|
|
|
| |
Right now, it is a bit unfortunate that we have the very long schema
string between two code blocks. It is probably better to either have it
at the top or the bottom of the file, hence why this commit moves it to
the top.
|
| |
|
|
|
| |
This commit moves calculate_sync_timeout into the Consensus struct in
the database module, as it fits better there.
|
| |
|
|
|
| |
This commit removes the operation serve function because it no longer
fits into the new model of operation using a FSM.
|
| |
|
|
|
|
|
|
| |
This commit moves the get_recent_consensus logic to the database module,
which also introduces a struct querying all fields in it.
This not only simplifies the return type but also makes working with
this type more comfortable to work with.
|
| |
|
|
|
|
| |
This commit replaces occurrences of rowid with docid, particularly in
tables for N:M cardinalities. Purpose of this is, to achieve a greater
consistency with the overall database schema.
|
| |
|
|
|
| |
This is more useful and less boilerplate, removing a parameter for a
conversion we can do ourselves if required.
|
| |
|
|
|
|
|
| |
This commit scratches out the FSM for the dirmirror operation.
Right now, there are still lots of TODO, lots of code warnigns, and
such. It should model the rough concept.
|
| |\
| |
| |
| |
| | |
tor-netdoc parse2: Rename *Signed to *Unverified
See merge request tpo/core/arti!3742
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
This was a weird name, and while working in this area it all seemed to
make the docs strange.
Rename it. This is quite invasive!
In theory we could have the macros generate compatibility aliases, but
that seems quite complex.
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
The issue concerns `libsqlite3-sys` linking to a native library. Cargo
cannot handle multiple versions/crates linking to the same native
library. This affects both the `tor-dirmgr` and `tor-dirserver` crates,
which depend on `rusqlite`.
Relaxing the version requirement gives downstream projects flexibility so
cargo can select an appropriate `libsqlite3-sys` version without a high
chance of conflicts caused by pinning a specific version.
The proposed supported version range was determined by testing until
encountering a version lacking a feature currently in use (breaking
unchange?).
Regarding testing, the current CI with minimum-version test only
validates the maximum and minimum versions, so breaking changes
introduced between them can pass unnoticed. Tools like
[Cargo-Bounds](https://github.com/vivax3794/cargo_bounds) can help, but
this is out of scope for this MR. Also, supported versions of `rusqlite`
for `tor-dirmgr` and `tor-dirserver` differ, so running tests for the
whole project (same workspace) causes cargo to pick only overlapping
versions, which hides parts of each crate’s supported range.
Referencing #754, after this MR, increasing the maximum version or
decreasing the minimum version of `rusqlite` shouldn't be a breaking
change, but increasing the minimum version could be.
Resolves: #1740
|
| |/ |
|
| |
|
|
|
|
|
|
|
| |
Done using:
```
for crate in $(./maint/list_crates | rg '^(tor|arti-)'); do
cargo set-version -p $crate 0.40.0
done
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
The non-{arti-,tor-} crates are:
```
./maint/list-crates | rg -v '^(tor|arti)'
oneshot-fused-workaround
slotmap-careful
test-temp-dir
fslock-guard
hashx
equix
caret
fs-mistrust
safelog
retry-error
futures-copy
```
Because this release bumps the MSRV, I am bumping the minor version of all of
them.
MINOR="
oneshot-fused-workaround
slotmap-careful
test-temp-dir
fslock-guard
hashx
equix
caret
fs-mistrust
safelog
retry-error
futures-copy
"
for crate in $MINOR; do
cargo set-version --bump minor -p $crate;
done
```
|
| |
|
|
|
|
|
|
|
| |
`clippy::collapsible_if` started triggering after bumping the MSRV to
1.88.
Since this triggers from a lot of places, and since there even are a
couple of instances where we explicitly allow `clippy::collapsible_ifs`,
I've opened #2342 for deciding what to do about it.
|
| |
|
|
|
|
|
| |
As agreed at our last team meeting.
See
https://gitlab.torproject.org/tpo/core/arti/#minimum-supported-rust-version
|
| |
|
|
| |
Makes docs.rs also document types behind optional feature flags.
|
| |
|
|
|
|
|
|
|
|
| |
Done via:
```
for crate in $(./maint/list-crates | rg '^(tor|arti-)'); do
cargo set-version -p $crate 0.39.0
done
```
|
| | |
|
| |
|
|
| |
This code is still WIP, no need to address the lint yet.
|
| |
|
|
| |
This adds the lint to all our crates.
|
| |
|
|
|
| |
This commit adds a comment explaining why we treat compression errors as
a bug.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
| |
This commit removes `DatabaseError::Compression` because it does not fit
in. Right now, this single variant makes the error to be call-site
oriented which is not nice for error handling. Instead, this error
should indicate that something was truly wrong with the database in
itself, such as an invalid schema, a low-level SQLite bug, etc.
Instead, we now map a compression error to `DatabaseError::Bug` because
there is no good reason on why it should fail, given that we compress
memory data to memory data. Probably because it uses the
`std::io::Writer` interface which itself demands use of
`std::io::Result`.
|
| |\
| |
| |
| |
| | |
tor-dirserver: Refactorings in the database.rs module
See merge request tpo/core/arti!3599
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
This commit removes FromStr for DocumentId because it was only used in
testing anyways.
Instead, it replaces it with a simple From<[u8; 32]> only enabled in
test builds, which is sufficient for what we are trying to do.
An alternative would be to make the inner field pub, but this seems to
aggressive for a testing only thing.
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
This comit adds a `sha2` column to `router_descriptor` alongside a
`CHECK` to see whether it equals `docid`.
The reason for this is simple: Microdescriptors are the only kind of
documents that are queriable with a SHA2 hash. Previously, we would
have simply used the `docid` column for this, but in order to abstract
it better, a distinct column with this hash is better.
|