| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| |
|
|
|
|
|
|
| |
As per
https://gitlab.torproject.org/tpo/core/arti/-/issues/2436#note_3384773
Made with
cargo set-version --offline --bump minor -p retry-error
|
| |\
| |
| |
| |
| |
| |
| | |
Force use of standard hasher with weak_tables.
Closes #2418
See merge request tpo/core/arti!3801
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
Closes #2418.
Fixes TROVE-2026-005, where we would use a less cryptographically
secure (and probably less DoS resistant) hash function for these
tables if:
- We are built alongside another crate that uses `weak-table`
- That crate enables the `weak-table/ahash` feature.
- We are running on a system without hardware AES.
Severity: Low
|
| |/
|
|
| |
Typos found with codespell
|
| |
|
|
|
|
|
|
|
|
|
|
| |
We want to stop deriving NetdocParseable directly for body structs.
Doing so reveals a call site here in tor-dirmirror where a consensus
is parsed and the body data used, but without verifying the
signatures.
Do this explicitly with the hoop-jumping which is going to become
deliberately unavoidable. Add a TODO comment because I'm not sure we
have decided explicitloy that this is OK.
|
| |
|
|
| |
Formatting changes which make the next commit more readable.
|
| |
|
|
| |
This is going to contain body information, and the hashes, too.
|
| |
|
|
|
|
| |
This commit changes the functionality of the AuthCerts state to only
report a success when at least a single certificate was included in the
response.
|
| |
|
|
|
| |
Adds a small TODO with regard to a potentially broken retry logic in the
proof-of-concept.
|
| |
|
|
|
| |
This commit documents why and how we use the `unsigned_` fields in the
`consensus_router_descriptor_member` table alongside SQL limitations.
|
| |
|
|
|
| |
This commit moves dirserver POC code to an own module to semantically
indicate it is not production ready.
|
| |
|
|
|
|
| |
This commit documents why we drop the HTTP TCP stream and why this is
fine, namely because this is compliant HTTP/1.0 behavior where there is
no connection reuse.
|
| |
|
|
|
| |
This commit links the discussion for the TODO for the dirmirror's
handling of forward compatibility with netdocs.
|
| | |
|
| | |
|
| |
|
|
|
|
|
|
| |
This commit replaces the uses of sha1, sha2, and sha3 with their
respective pedants from tor-llcrypto for better consistency.
Internally, they still use the same logic and underlying crates but
let's use this encapsulation nonetheless.
|
| | |
|
| |
|
|
|
|
|
|
| |
This commit moves the database schema into schema_v1.sql and uses
include_str to include it. For now, the schema lives in the `src/`
directory. If this becomes a problem because we get more schemas and
schema upgrades, we can move it into another sub directory, but let's
not overengineer the hierarchy there.
|
| |
|
|
|
| |
This commit implements a PoC serving as the main loop for the FSM,
demonstrating how invocation and error handling works.
|
| |
|
|
| |
Discussed with nickm on IRC, there will be a torspec issue soon.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
| |
This commit implements the logic required for retrieving, validating,
and storing authority certificates.
The implementation determines the missing certificates by looking at the
signatories of the unvalidated consensus and checking them in the db.
Afterwards, they will be queried and individually filtered and verified
before being inserted into the database.
A return of this implementation notably DOES NOT imply all missing
certificates have been downloaded. This was chosen for a simplified
retry logic.
|
| |
|
|
|
|
|
|
|
|
|
|
|
| |
This commit adds a new method to static engine that serves as a
convenience wrapper around `tor_dirclient::send_request`.
The reason for that is, that fetch_consensus is not the only method that
requires performing download requests, so it makes sense to generalize
it.
Besides, it also adds support for parsing multiple netdocs alongside
storing their raw variant, which is required for inserting them into the
database at one point eventually.
|
| |
|
|
|
| |
This commit adds the IsFatal trait to the err module for having a
generic signature for the fatality of certain error variants.
|
| |
|
|
|
|
|
|
|
|
|
|
| |
This commit implements the `FetchConsensus` state by adding a method to
`StaticEngine` called `fetch_consensus`, which retrieves the consensus
from an upstream directory authority.
Likewise, it also implements a new error type called
`AuthorityRequestError`.
The retry logic is handled externally which will be done in later
commits.
|
| |
|
|
| |
Required to test state transitions properly.
|
| |
|
|
| |
This is required for compatibility with other crates in arti.
|
| | |
|
| |
|
|
|
| |
This commit removes the download manager module because it does not fit
well into the mental model of our current finite state machine anymore.
|
| |
|
|
|
|
|
|
|
|
| |
This commit removes the `preferred` member field from the `Unverified`
and `Verified` variant in `ConsensusBoundData` while adding it as a
parameter to `StaticEngine::execute`, with the idea being that the retry
logic is handled by the caller anyways, involving the selection of
authorities.
Right now, I am still a bit unsure how this will play out.
|
| | |
|
| |
|
|
|
|
| |
This commit implements the consensus loading mechanism by glueing
together the logic from the database module with regard to querying
missing descriptors.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
This commit implements the logic for querying missing descriptors by
adding three new methods to ConsensusMeta:
* missing_servers
* missing_extras
* missing_micros
All of them essentially work the same, namely by querying the
consensus_router_descriptor_member database table alongside the docid of
the current consensus, left joining the respective router_descriptor and
returning the digests on all rows where the left join resulteed in a
NULL.
A small exception are extra-info descriptors. There, we can only return
the ones where we have an accompanying server descriptor, hence why we
perform an inner join with the server descriptors between the from and
the left join.
|
| |
|
|
|
| |
This is better because it is returned by
`ConsensusFlavor::Microdesc::name()`.
|
| |
|
|
|
|
|
|
|
|
|
|
| |
This commit fixes some parts in the extra-info related part of the
database schema.
Most notably, it changes the semantic to indicate that the sha1
represents the unsigned part of the extra-info document.
Likewise, it also ensures that the reference to an extra-info document
must not be null with a plain consensus but null with a microdescriptor
consensus.
|
| |
|
|
|
|
|
|
|
|
|
| |
This commit modifies the database schema to rename `sha1` and `sha2` to
`unsigned_sha1` and `unsigned_sha2`.
Network status consensuses refer to server descriptors by their unsigned
sha1.
Microdescriptor consensuses refer to microdescriptors by their sha2,
which is always unsigned, so we adapt that name for consistency.
|
| |
|
|
|
|
|
|
|
|
|
| |
This commit removes the foreign key constraints from the
`consensus_router_descriptor_member` in order to allow the insertion of
the router descriptors contained in a consensus before the respective
descriptors were fetched.
This also allows to directly compute the missing descriptors in SQL,
using a left join on this table on `router_descriptor` and obtaining the
entries that are NULL.
|
| |
|
|
|
|
|
|
|
|
|
| |
This commit modifies the database schema by tracking the sha1 of the
extra-info instead of the rowid. This makes generating queues and other
things easier.
It also removes the foreign key constraint in order to allow for an
asynchronous retrieval and storage. Otherwise it would not be possible
to store a router descriptor without having obtained the extra info
first.
|
| |
|
|
|
|
| |
This approach is better in order to guarantee that invariants are not
violated, such that the expiry timestamp not being earlier than the
valid after one for example.
|
| | |
|
| |
|
|
|
| |
This commit implements Sha1 for the database in order to use it for the
fingerprints in authority key certificates.
|
| |
|
|
|
| |
This commit implements Sha3_256 as a database type and uses it for
stroing `ConsensusMeta::unsigned_sha3_256`.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
This commit moves the `DocumentId` implementation into a macro called
`impl_hash_wrapper` that implements a hash type in a database compatible
fashion.
In our case, we implement this for `sha2::Sha256` and then type alias
`DocumentId` to this new hash. Yes, we originally moved away from a
type alias here, but I think this is fine because for the foreseeable
future, we will continue to use a hash here, just maybe not Sha2, but
the flexibility remains.
The motivation for this is to support other hash algorithms similarly
too.
|
| | |
|
| |
|
|
|
|
|
|
|
| |
This commit moves get_recent_auth_certs from operation to database by
introducing a new struct called `AuthCertMeta` containing the database
metadata alongside an accompanying data method returning the raw data.
For now, it leaves out the download, verify, and insert logic.
We will add that back later once we will need it.
|
| |
|
|
|
|
|
| |
This commit renames the database `Consensus` to `ConsensusMeta` in order
to not collide with the naming from tor-netdoc and to clearly indicate
that this data is just metadata about such a document, but not the
document itself.
|
| |
|
|
| |
Makes things more handy to write.
|
| |
|
|
|
| |
If is annoying to use, especially if we can avoid it by just avoid name
conflicts.
|
| | |
|
| |
|
|
|
|
|
| |
Right now, it is a bit unfortunate that we have the very long schema
string between two code blocks. It is probably better to either have it
at the top or the bottom of the file, hence why this commit moves it to
the top.
|
| |
|
|
|
| |
This commit moves calculate_sync_timeout into the Consensus struct in
the database module, as it fits better there.
|