mirror of
https://github.com/NLnetLabs/krill.git
synced 2026-10-01 22:04:54 +02:00
Mark types that are used for storing state. (#1286)
This PR sticks a warning on all types that are used when serializing Krill’s state. This hopefully will serve as a reminder that they cannot be changed without considering migrations.
This commit is contained in:
+26
-10
@@ -163,6 +163,8 @@ pub struct PublishedFile {
|
||||
//------------ PublicationServerInfo -----------------------------------------
|
||||
|
||||
/// Details of a publication server.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct PublicationServerInfo {
|
||||
/// The public key used by the publication server.
|
||||
@@ -189,6 +191,8 @@ pub struct ApiRepositoryContact {
|
||||
//------------ RepositoryContact ---------------------------------------------
|
||||
|
||||
/// A contact with a remote repository.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Serialize)]
|
||||
pub struct RepositoryContact {
|
||||
/// Information about the remote repository.
|
||||
@@ -269,6 +273,8 @@ impl fmt::Display for ParentCaReq {
|
||||
//------------ ParentServerInfo ----------------------------------------------
|
||||
|
||||
/// Information about the server of the parent CA.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct ParentServerInfo {
|
||||
/// The URI where the CA needs to send its RFC6492 messages
|
||||
@@ -310,6 +316,8 @@ impl fmt::Display for ParentServerInfo {
|
||||
/// a data migration of past events, and because theoretically we may
|
||||
/// need other options in future if there is an alternative to RFC 6492
|
||||
/// one day.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
#[allow(clippy::large_enum_variant)]
|
||||
#[serde(rename_all = "snake_case")]
|
||||
@@ -368,6 +376,8 @@ impl fmt::Display for ParentCaContact {
|
||||
/// The protocol to use when contacting a parent.
|
||||
///
|
||||
/// This type is used when saving and presenting the command history.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
#[serde(rename_all = "snake_case")]
|
||||
pub enum StorableParentContact {
|
||||
@@ -410,6 +420,8 @@ impl fmt::Display for CertAuthInit {
|
||||
//------------ AddChildRequest -----------------------------------------------
|
||||
|
||||
/// Information necessary to request adding a child CA.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct AddChildRequest {
|
||||
/// The handle to identify the child with.
|
||||
@@ -451,16 +463,6 @@ pub struct UpdateChildRequest {
|
||||
pub resource_class_name_mapping: Option<ResourceClassNameMapping>,
|
||||
}
|
||||
|
||||
/// A mapping from the name of a resource class in parent and child.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct ResourceClassNameMapping {
|
||||
/// The name of the resource class at the parent.
|
||||
pub name_in_parent: ResourceClassName,
|
||||
|
||||
/// The name of the resource class at the child.
|
||||
pub name_for_child: ResourceClassName,
|
||||
}
|
||||
|
||||
impl UpdateChildRequest {
|
||||
/// Creates a child update request that only changes the ID certificate.
|
||||
pub fn id_cert(id_cert: IdCert) -> Self {
|
||||
@@ -530,6 +532,20 @@ impl fmt::Display for UpdateChildRequest {
|
||||
}
|
||||
}
|
||||
|
||||
//------------ ResourceClassNameMapping --------------------------------------
|
||||
|
||||
/// A mapping from the name of a resource class in parent and child.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct ResourceClassNameMapping {
|
||||
/// The name of the resource class at the parent.
|
||||
pub name_in_parent: ResourceClassName,
|
||||
|
||||
/// The name of the resource class at the child.
|
||||
pub name_for_child: ResourceClassName,
|
||||
}
|
||||
|
||||
|
||||
//------------ ServerInfo ----------------------------------------------------
|
||||
|
||||
|
||||
@@ -14,15 +14,21 @@ use serde::{Deserialize, Serialize};
|
||||
//------------- Type Aliases -------------------------------------------------
|
||||
|
||||
/// The type of a customer ASN.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
pub type CustomerAsn = Asn;
|
||||
|
||||
/// The type of a provider ASN.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
pub type ProviderAsn = Asn;
|
||||
|
||||
|
||||
//------------ AspaDefinitionUpdates -----------------------------------------
|
||||
|
||||
/// Information for an ASPA definition update.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct AspaDefinitionUpdates {
|
||||
/// Definitions to add or replace.
|
||||
@@ -87,6 +93,8 @@ impl fmt::Display for AspaDefinitionList {
|
||||
//------------ AspaDefinition ------------------------------------------------
|
||||
|
||||
/// The definition of an ASPA record.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct AspaDefinition {
|
||||
/// The customer ASN.
|
||||
@@ -225,6 +233,8 @@ impl FromStr for AspaDefinition {
|
||||
//------------ AspaProvidersUpdate -------------------------------------------
|
||||
|
||||
/// An update to the provider ASN list of an ASPA definition.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Default, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct AspaProvidersUpdate {
|
||||
/// A list of ASNs to be added to the provider ASNs.
|
||||
|
||||
@@ -38,6 +38,8 @@ impl Eq for BgpSecDefinition {}
|
||||
//------------ BgpSecAsnKey ------------------------------------------------
|
||||
|
||||
/// A BGPsec router key for a specific ASN.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Copy, Debug, Eq, Hash, PartialEq)]
|
||||
pub struct BgpSecAsnKey {
|
||||
/// The autonomous system that uses the router key.
|
||||
|
||||
+21
-1
@@ -42,7 +42,9 @@ use super::roa::{RoaPayload, RoaPayloadJsonMapKey};
|
||||
|
||||
//------------ IdCertInfo ----------------------------------------------------
|
||||
|
||||
/// A encoded ID certificate and SHA256 hash of the encoding.
|
||||
/// An encoded ID certificate and SHA256 hash of the encoding.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct IdCertInfo {
|
||||
/// The public key of the ID certificate.
|
||||
@@ -130,6 +132,8 @@ impl fmt::Display for IdCertPem<'_> {
|
||||
//------------ ChildState ----------------------------------------------------
|
||||
|
||||
/// The suspension status of a child CA.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(
|
||||
Clone, Copy, Debug, Default, Deserialize, Eq, PartialEq, Serialize,
|
||||
)]
|
||||
@@ -197,6 +201,8 @@ impl fmt::Display for ChildCaInfo {
|
||||
pub struct Received;
|
||||
|
||||
/// A certificate that was received from a parent CA.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
pub type ReceivedCert = CertInfo<Received>;
|
||||
|
||||
|
||||
@@ -207,6 +213,8 @@ pub type ReceivedCert = CertInfo<Received>;
|
||||
pub struct Issued;
|
||||
|
||||
/// A certificate which has been issued to a child CA.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
pub type IssuedCertificate = CertInfo<Issued>;
|
||||
|
||||
|
||||
@@ -217,6 +225,8 @@ pub type IssuedCertificate = CertInfo<Issued>;
|
||||
pub struct Suspended;
|
||||
|
||||
/// An certificate which has been suspended because the child is inactive.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
pub type SuspendedCert = CertInfo<Suspended>;
|
||||
|
||||
|
||||
@@ -227,6 +237,8 @@ pub type SuspendedCert = CertInfo<Suspended>;
|
||||
pub struct Unsuspended;
|
||||
|
||||
/// A certificate that has been unsuspended and needs to be re-activated.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
pub type UnsuspendedCert = CertInfo<Unsuspended>;
|
||||
|
||||
|
||||
@@ -239,6 +251,8 @@ pub type UnsuspendedCert = CertInfo<Unsuspended>;
|
||||
///
|
||||
/// This type is generic over a marker type `T` indicating the status of the
|
||||
/// certificate.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct CertInfo<T> {
|
||||
/// Where this certificate is published by the parent
|
||||
@@ -615,6 +629,8 @@ impl fmt::Display for ObjectName {
|
||||
//------------ Revocation ----------------------------------------------------
|
||||
|
||||
/// Information for an entry on a CRL.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Copy, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct Revocation {
|
||||
/// The serial number of the certificate to be revoked.
|
||||
@@ -675,6 +691,8 @@ impl From<&Aspa> for Revocation {
|
||||
//------------ Revocations ---------------------------------------------------
|
||||
|
||||
/// The list of revocation entries of a CRL.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Default, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct Revocations(Vec<Revocation>);
|
||||
|
||||
@@ -2093,6 +2111,8 @@ pub struct BgpStats {
|
||||
//------------ RtaName -------------------------------------------------------
|
||||
|
||||
/// The name of an RTA.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
pub type RtaName = String;
|
||||
|
||||
|
||||
|
||||
@@ -41,6 +41,8 @@ use super::ca::Revocation;
|
||||
/// accordance with best practices (avoid fate sharing in case a prefix is
|
||||
/// suddenly no longer held), but aggregation will be done if a
|
||||
/// (configurable) threshold is exceeded.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Copy, Deserialize, Eq, Hash, PartialEq, Serialize)]
|
||||
pub struct RoaPayload {
|
||||
/// The autonomous system authorized to originate routes.
|
||||
@@ -229,6 +231,8 @@ impl fmt::Debug for RoaPayload {
|
||||
//------------ RoaPayloadJsonMapKey ------------------------------------------
|
||||
|
||||
/// A [`RoaPayload`] that serializes as a string.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Copy, Debug, Eq, Hash, Ord, PartialOrd, PartialEq)]
|
||||
pub struct RoaPayloadJsonMapKey(RoaPayload);
|
||||
|
||||
@@ -302,6 +306,8 @@ impl<'de> Deserialize<'de> for RoaPayloadJsonMapKey {
|
||||
/// Existing ROAs may contain other information that the Krill system is
|
||||
/// responsible for, rather than the API (update) user. For example: which ROA
|
||||
/// object(s) the intended configuration appears on.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, Hash, PartialEq, Serialize)]
|
||||
pub struct RoaConfiguration {
|
||||
/// The ROA payload definition.
|
||||
@@ -390,6 +396,8 @@ impl fmt::Display for RoaConfiguration {
|
||||
//------------ RoaInfo -------------------------------------------------------
|
||||
|
||||
/// Information about a ROA *object.*
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct RoaInfo {
|
||||
/// The route or routes authorized by this ROA
|
||||
@@ -507,6 +515,8 @@ impl fmt::Display for ConfiguredRoas {
|
||||
/// Multiple updates are sent as a single delta, because it's important that
|
||||
/// all authorizations for a given prefix are published together in order to
|
||||
/// avoid invalidating announcements.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Default, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct RoaConfigurationUpdates {
|
||||
/// The ROA configurations to be added.
|
||||
@@ -630,6 +640,8 @@ impl fmt::Display for RoaConfigurationUpdates {
|
||||
/// A prefix that knows which family it belongs to.
|
||||
///
|
||||
/// This type serializes into the string representation of the prefix.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Copy, Eq, Hash, PartialEq)]
|
||||
pub enum TypedPrefix {
|
||||
/// An IPv4 prefix.
|
||||
@@ -808,6 +820,8 @@ impl Serialize for TypedPrefix {
|
||||
//------------ Ipv4Prefix ----------------------------------------------------
|
||||
|
||||
/// An IPv4 prefix.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Copy, Eq, Hash, PartialEq)]
|
||||
pub struct Ipv4Prefix(Prefix);
|
||||
|
||||
@@ -844,6 +858,8 @@ impl From<Ipv4Prefix> for Prefix {
|
||||
//------------ Ipv6Prefix ----------------------------------------------------
|
||||
|
||||
/// An IPv6 prefix.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Copy, Eq, Hash, PartialEq)]
|
||||
pub struct Ipv6Prefix(Prefix);
|
||||
|
||||
|
||||
@@ -67,6 +67,8 @@ impl fmt::Display for RtaContentRequest {
|
||||
/// Resource Tagged Attestations
|
||||
///
|
||||
/// See: <https://tools.ietf.org/id/draft-michaelson-rpki-rta-01.html>
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, Serialize, PartialEq)]
|
||||
pub struct ResourceTaggedAttestation {
|
||||
#[serde(
|
||||
|
||||
+20
-15
@@ -12,7 +12,6 @@ use rpki::{
|
||||
ca::{
|
||||
idexchange::{ChildHandle, RecipientHandle, SenderHandle},
|
||||
provisioning,
|
||||
provisioning::ResourceClassName,
|
||||
publication::Base64,
|
||||
sigmsg::SignedMessage,
|
||||
},
|
||||
@@ -33,6 +32,7 @@ use crate::api::admin::PublishedFile;
|
||||
use crate::api::ca::{
|
||||
IdCertInfo, IssuedCertificate, ObjectName, ReceivedCert, Revocations,
|
||||
};
|
||||
use crate::server::ca::UsedKeyState;
|
||||
use crate::server::ca::publishing::{
|
||||
ManifestBuilder, ObjectSetRevision, PublishedCrl,
|
||||
PublishedManifest, PublishedObject,
|
||||
@@ -50,6 +50,8 @@ use crate::server::ca::publishing::{
|
||||
/// The Trust Anchor Signer can make changes to this set based on the
|
||||
/// requests it gets from the proxy. It can then return a response to the
|
||||
/// proxy that allow it to update the state with that same change.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct TrustAnchorObjects {
|
||||
// The revision of the set, meaning its number and the
|
||||
@@ -273,6 +275,7 @@ impl fmt::Display for TrustAnchorObjects {
|
||||
|
||||
//------------ TaCertDetails -------------------------------------------------
|
||||
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct TaCertDetails {
|
||||
pub cert: ReceivedCert,
|
||||
@@ -342,6 +345,7 @@ impl std::fmt::Display for TrustAnchorLocator {
|
||||
|
||||
//------------ TrustAnchorSignerInfo ---------------------------------------
|
||||
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct TrustAnchorSignerInfo {
|
||||
// The ID of the associated signer.
|
||||
@@ -396,6 +400,7 @@ impl fmt::Display for TrustAnchorSignerInfo {
|
||||
|
||||
//------------ Nonce -------------------------------------------------------
|
||||
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct Nonce(Arc<str>);
|
||||
|
||||
@@ -419,6 +424,7 @@ impl std::fmt::Display for Nonce {
|
||||
|
||||
//------------ TrustAnchorProxySignerExchange ------------------------------
|
||||
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct TrustAnchorProxySignerExchange {
|
||||
pub time: Time,
|
||||
@@ -428,6 +434,7 @@ pub struct TrustAnchorProxySignerExchange {
|
||||
|
||||
//------------ TrustAnchorSignedMessage ------------------------------------
|
||||
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct TrustAnchorSignedMessage {
|
||||
message: Base64,
|
||||
@@ -544,6 +551,8 @@ impl fmt::Display for ApiTrustAnchorSignedRequest {
|
||||
|
||||
/// A [`TrustAnchorSignerRequest`] and its signed message as base64 for
|
||||
/// (re-)validation.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct TrustAnchorSignedRequest {
|
||||
pub signed: TrustAnchorSignedMessage,
|
||||
@@ -603,6 +612,8 @@ impl fmt::Display for TrustAnchorSignedRequest {
|
||||
/// a key. If there are no requests for a child, then it is
|
||||
/// assumed that the current issued certificate(s) to the child
|
||||
/// should not change.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct TrustAnchorSignerRequest {
|
||||
pub nonce: Nonce, // should be matched in response (replay protection)
|
||||
@@ -663,6 +674,8 @@ impl fmt::Display for TrustAnchorSignerRequest {
|
||||
//------------ TrustAnchorChildRequests ------------------------------------
|
||||
|
||||
/// Requests for Trust Anchor Child.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct TrustAnchorChildRequests {
|
||||
pub child: ChildHandle,
|
||||
@@ -674,6 +687,8 @@ pub struct TrustAnchorChildRequests {
|
||||
|
||||
/// A [`TrustAnchorSignerResponse`] and its signed message as base64 for
|
||||
/// (re-)validation.
|
||||
//
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct TrustAnchorSignedResponse {
|
||||
signed: TrustAnchorSignedMessage,
|
||||
@@ -721,6 +736,7 @@ impl fmt::Display for TrustAnchorSignedResponse {
|
||||
|
||||
//------------ TrustAnchorSignerResponse -----------------------------------
|
||||
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct TrustAnchorSignerResponse {
|
||||
pub nonce: Nonce, // should match the request (replay protection)
|
||||
@@ -785,6 +801,7 @@ impl fmt::Display for TrustAnchorSignerResponse {
|
||||
|
||||
//------------ TrustAnchorChild --------------------------------------------
|
||||
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
pub struct TrustAnchorChild {
|
||||
pub handle: ChildHandle,
|
||||
@@ -813,22 +830,9 @@ impl TrustAnchorChild {
|
||||
}
|
||||
|
||||
|
||||
//------------ UsedKeyState ------------------------------------------------
|
||||
|
||||
/// Tracks the state of a key used by a child CA. This is needed because
|
||||
/// RFC 6492 dictates that keys cannot be re-used across resource classes.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
#[allow(clippy::large_enum_variant)]
|
||||
#[serde(rename_all = "snake_case")]
|
||||
pub enum UsedKeyState {
|
||||
#[serde(alias = "current")]
|
||||
InUse(ResourceClassName), /* Multiple keys are possible during a key
|
||||
* rollover. */
|
||||
Revoked,
|
||||
}
|
||||
|
||||
//------------ ProvisioningRequest -----------------------------------------
|
||||
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
#[allow(clippy::large_enum_variant)]
|
||||
pub enum ProvisioningRequest {
|
||||
@@ -877,6 +881,7 @@ impl std::fmt::Display for ProvisioningRequest {
|
||||
|
||||
//------------ ProvisioningResponse ----------------------------------------
|
||||
|
||||
// *Warning:* This type is used in stored state.
|
||||
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
|
||||
#[allow(clippy::large_enum_variant)]
|
||||
pub enum ProvisioningResponse {
|
||||
|
||||
Reference in New Issue
Block a user