Mark types that are used for storing state. (#1286)

This PR sticks a warning on all types that are used when serializing
Krill’s state. This hopefully will serve as a reminder that they cannot
be changed without considering migrations.
This commit is contained in:
Martin Hoffmann
2025-06-12 14:15:12 +02:00
committed by GitHub
parent c445fece1a
commit 7b66408dc6
31 changed files with 1081 additions and 786 deletions
+26 -10
View File
@@ -163,6 +163,8 @@ pub struct PublishedFile {
//------------ PublicationServerInfo -----------------------------------------
/// Details of a publication server.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct PublicationServerInfo {
/// The public key used by the publication server.
@@ -189,6 +191,8 @@ pub struct ApiRepositoryContact {
//------------ RepositoryContact ---------------------------------------------
/// A contact with a remote repository.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Serialize)]
pub struct RepositoryContact {
/// Information about the remote repository.
@@ -269,6 +273,8 @@ impl fmt::Display for ParentCaReq {
//------------ ParentServerInfo ----------------------------------------------
/// Information about the server of the parent CA.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct ParentServerInfo {
/// The URI where the CA needs to send its RFC6492 messages
@@ -310,6 +316,8 @@ impl fmt::Display for ParentServerInfo {
/// a data migration of past events, and because theoretically we may
/// need other options in future if there is an alternative to RFC 6492
/// one day.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
#[allow(clippy::large_enum_variant)]
#[serde(rename_all = "snake_case")]
@@ -368,6 +376,8 @@ impl fmt::Display for ParentCaContact {
/// The protocol to use when contacting a parent.
///
/// This type is used when saving and presenting the command history.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
#[serde(rename_all = "snake_case")]
pub enum StorableParentContact {
@@ -410,6 +420,8 @@ impl fmt::Display for CertAuthInit {
//------------ AddChildRequest -----------------------------------------------
/// Information necessary to request adding a child CA.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct AddChildRequest {
/// The handle to identify the child with.
@@ -451,16 +463,6 @@ pub struct UpdateChildRequest {
pub resource_class_name_mapping: Option<ResourceClassNameMapping>,
}
/// A mapping from the name of a resource class in parent and child.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct ResourceClassNameMapping {
/// The name of the resource class at the parent.
pub name_in_parent: ResourceClassName,
/// The name of the resource class at the child.
pub name_for_child: ResourceClassName,
}
impl UpdateChildRequest {
/// Creates a child update request that only changes the ID certificate.
pub fn id_cert(id_cert: IdCert) -> Self {
@@ -530,6 +532,20 @@ impl fmt::Display for UpdateChildRequest {
}
}
//------------ ResourceClassNameMapping --------------------------------------
/// A mapping from the name of a resource class in parent and child.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct ResourceClassNameMapping {
/// The name of the resource class at the parent.
pub name_in_parent: ResourceClassName,
/// The name of the resource class at the child.
pub name_for_child: ResourceClassName,
}
//------------ ServerInfo ----------------------------------------------------
+10
View File
@@ -14,15 +14,21 @@ use serde::{Deserialize, Serialize};
//------------- Type Aliases -------------------------------------------------
/// The type of a customer ASN.
//
// *Warning:* This type is used in stored state.
pub type CustomerAsn = Asn;
/// The type of a provider ASN.
//
// *Warning:* This type is used in stored state.
pub type ProviderAsn = Asn;
//------------ AspaDefinitionUpdates -----------------------------------------
/// Information for an ASPA definition update.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct AspaDefinitionUpdates {
/// Definitions to add or replace.
@@ -87,6 +93,8 @@ impl fmt::Display for AspaDefinitionList {
//------------ AspaDefinition ------------------------------------------------
/// The definition of an ASPA record.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct AspaDefinition {
/// The customer ASN.
@@ -225,6 +233,8 @@ impl FromStr for AspaDefinition {
//------------ AspaProvidersUpdate -------------------------------------------
/// An update to the provider ASN list of an ASPA definition.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Default, Deserialize, Eq, PartialEq, Serialize)]
pub struct AspaProvidersUpdate {
/// A list of ASNs to be added to the provider ASNs.
+2
View File
@@ -38,6 +38,8 @@ impl Eq for BgpSecDefinition {}
//------------ BgpSecAsnKey ------------------------------------------------
/// A BGPsec router key for a specific ASN.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Copy, Debug, Eq, Hash, PartialEq)]
pub struct BgpSecAsnKey {
/// The autonomous system that uses the router key.
+21 -1
View File
@@ -42,7 +42,9 @@ use super::roa::{RoaPayload, RoaPayloadJsonMapKey};
//------------ IdCertInfo ----------------------------------------------------
/// A encoded ID certificate and SHA256 hash of the encoding.
/// An encoded ID certificate and SHA256 hash of the encoding.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct IdCertInfo {
/// The public key of the ID certificate.
@@ -130,6 +132,8 @@ impl fmt::Display for IdCertPem<'_> {
//------------ ChildState ----------------------------------------------------
/// The suspension status of a child CA.
//
// *Warning:* This type is used in stored state.
#[derive(
Clone, Copy, Debug, Default, Deserialize, Eq, PartialEq, Serialize,
)]
@@ -197,6 +201,8 @@ impl fmt::Display for ChildCaInfo {
pub struct Received;
/// A certificate that was received from a parent CA.
//
// *Warning:* This type is used in stored state.
pub type ReceivedCert = CertInfo<Received>;
@@ -207,6 +213,8 @@ pub type ReceivedCert = CertInfo<Received>;
pub struct Issued;
/// A certificate which has been issued to a child CA.
//
// *Warning:* This type is used in stored state.
pub type IssuedCertificate = CertInfo<Issued>;
@@ -217,6 +225,8 @@ pub type IssuedCertificate = CertInfo<Issued>;
pub struct Suspended;
/// An certificate which has been suspended because the child is inactive.
//
// *Warning:* This type is used in stored state.
pub type SuspendedCert = CertInfo<Suspended>;
@@ -227,6 +237,8 @@ pub type SuspendedCert = CertInfo<Suspended>;
pub struct Unsuspended;
/// A certificate that has been unsuspended and needs to be re-activated.
//
// *Warning:* This type is used in stored state.
pub type UnsuspendedCert = CertInfo<Unsuspended>;
@@ -239,6 +251,8 @@ pub type UnsuspendedCert = CertInfo<Unsuspended>;
///
/// This type is generic over a marker type `T` indicating the status of the
/// certificate.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct CertInfo<T> {
/// Where this certificate is published by the parent
@@ -615,6 +629,8 @@ impl fmt::Display for ObjectName {
//------------ Revocation ----------------------------------------------------
/// Information for an entry on a CRL.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Copy, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct Revocation {
/// The serial number of the certificate to be revoked.
@@ -675,6 +691,8 @@ impl From<&Aspa> for Revocation {
//------------ Revocations ---------------------------------------------------
/// The list of revocation entries of a CRL.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Default, Deserialize, Eq, PartialEq, Serialize)]
pub struct Revocations(Vec<Revocation>);
@@ -2093,6 +2111,8 @@ pub struct BgpStats {
//------------ RtaName -------------------------------------------------------
/// The name of an RTA.
//
// *Warning:* This type is used in stored state.
pub type RtaName = String;
+16
View File
@@ -41,6 +41,8 @@ use super::ca::Revocation;
/// accordance with best practices (avoid fate sharing in case a prefix is
/// suddenly no longer held), but aggregation will be done if a
/// (configurable) threshold is exceeded.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Copy, Deserialize, Eq, Hash, PartialEq, Serialize)]
pub struct RoaPayload {
/// The autonomous system authorized to originate routes.
@@ -229,6 +231,8 @@ impl fmt::Debug for RoaPayload {
//------------ RoaPayloadJsonMapKey ------------------------------------------
/// A [`RoaPayload`] that serializes as a string.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Copy, Debug, Eq, Hash, Ord, PartialOrd, PartialEq)]
pub struct RoaPayloadJsonMapKey(RoaPayload);
@@ -302,6 +306,8 @@ impl<'de> Deserialize<'de> for RoaPayloadJsonMapKey {
/// Existing ROAs may contain other information that the Krill system is
/// responsible for, rather than the API (update) user. For example: which ROA
/// object(s) the intended configuration appears on.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, Hash, PartialEq, Serialize)]
pub struct RoaConfiguration {
/// The ROA payload definition.
@@ -390,6 +396,8 @@ impl fmt::Display for RoaConfiguration {
//------------ RoaInfo -------------------------------------------------------
/// Information about a ROA *object.*
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct RoaInfo {
/// The route or routes authorized by this ROA
@@ -507,6 +515,8 @@ impl fmt::Display for ConfiguredRoas {
/// Multiple updates are sent as a single delta, because it's important that
/// all authorizations for a given prefix are published together in order to
/// avoid invalidating announcements.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Default, Deserialize, Eq, PartialEq, Serialize)]
pub struct RoaConfigurationUpdates {
/// The ROA configurations to be added.
@@ -630,6 +640,8 @@ impl fmt::Display for RoaConfigurationUpdates {
/// A prefix that knows which family it belongs to.
///
/// This type serializes into the string representation of the prefix.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Copy, Eq, Hash, PartialEq)]
pub enum TypedPrefix {
/// An IPv4 prefix.
@@ -808,6 +820,8 @@ impl Serialize for TypedPrefix {
//------------ Ipv4Prefix ----------------------------------------------------
/// An IPv4 prefix.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Copy, Eq, Hash, PartialEq)]
pub struct Ipv4Prefix(Prefix);
@@ -844,6 +858,8 @@ impl From<Ipv4Prefix> for Prefix {
//------------ Ipv6Prefix ----------------------------------------------------
/// An IPv6 prefix.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Copy, Eq, Hash, PartialEq)]
pub struct Ipv6Prefix(Prefix);
+2
View File
@@ -67,6 +67,8 @@ impl fmt::Display for RtaContentRequest {
/// Resource Tagged Attestations
///
/// See: <https://tools.ietf.org/id/draft-michaelson-rpki-rta-01.html>
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, Serialize, PartialEq)]
pub struct ResourceTaggedAttestation {
#[serde(
+20 -15
View File
@@ -12,7 +12,6 @@ use rpki::{
ca::{
idexchange::{ChildHandle, RecipientHandle, SenderHandle},
provisioning,
provisioning::ResourceClassName,
publication::Base64,
sigmsg::SignedMessage,
},
@@ -33,6 +32,7 @@ use crate::api::admin::PublishedFile;
use crate::api::ca::{
IdCertInfo, IssuedCertificate, ObjectName, ReceivedCert, Revocations,
};
use crate::server::ca::UsedKeyState;
use crate::server::ca::publishing::{
ManifestBuilder, ObjectSetRevision, PublishedCrl,
PublishedManifest, PublishedObject,
@@ -50,6 +50,8 @@ use crate::server::ca::publishing::{
/// The Trust Anchor Signer can make changes to this set based on the
/// requests it gets from the proxy. It can then return a response to the
/// proxy that allow it to update the state with that same change.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct TrustAnchorObjects {
// The revision of the set, meaning its number and the
@@ -273,6 +275,7 @@ impl fmt::Display for TrustAnchorObjects {
//------------ TaCertDetails -------------------------------------------------
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct TaCertDetails {
pub cert: ReceivedCert,
@@ -342,6 +345,7 @@ impl std::fmt::Display for TrustAnchorLocator {
//------------ TrustAnchorSignerInfo ---------------------------------------
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct TrustAnchorSignerInfo {
// The ID of the associated signer.
@@ -396,6 +400,7 @@ impl fmt::Display for TrustAnchorSignerInfo {
//------------ Nonce -------------------------------------------------------
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct Nonce(Arc<str>);
@@ -419,6 +424,7 @@ impl std::fmt::Display for Nonce {
//------------ TrustAnchorProxySignerExchange ------------------------------
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct TrustAnchorProxySignerExchange {
pub time: Time,
@@ -428,6 +434,7 @@ pub struct TrustAnchorProxySignerExchange {
//------------ TrustAnchorSignedMessage ------------------------------------
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct TrustAnchorSignedMessage {
message: Base64,
@@ -544,6 +551,8 @@ impl fmt::Display for ApiTrustAnchorSignedRequest {
/// A [`TrustAnchorSignerRequest`] and its signed message as base64 for
/// (re-)validation.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct TrustAnchorSignedRequest {
pub signed: TrustAnchorSignedMessage,
@@ -603,6 +612,8 @@ impl fmt::Display for TrustAnchorSignedRequest {
/// a key. If there are no requests for a child, then it is
/// assumed that the current issued certificate(s) to the child
/// should not change.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct TrustAnchorSignerRequest {
pub nonce: Nonce, // should be matched in response (replay protection)
@@ -663,6 +674,8 @@ impl fmt::Display for TrustAnchorSignerRequest {
//------------ TrustAnchorChildRequests ------------------------------------
/// Requests for Trust Anchor Child.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct TrustAnchorChildRequests {
pub child: ChildHandle,
@@ -674,6 +687,8 @@ pub struct TrustAnchorChildRequests {
/// A [`TrustAnchorSignerResponse`] and its signed message as base64 for
/// (re-)validation.
//
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct TrustAnchorSignedResponse {
signed: TrustAnchorSignedMessage,
@@ -721,6 +736,7 @@ impl fmt::Display for TrustAnchorSignedResponse {
//------------ TrustAnchorSignerResponse -----------------------------------
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct TrustAnchorSignerResponse {
pub nonce: Nonce, // should match the request (replay protection)
@@ -785,6 +801,7 @@ impl fmt::Display for TrustAnchorSignerResponse {
//------------ TrustAnchorChild --------------------------------------------
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
pub struct TrustAnchorChild {
pub handle: ChildHandle,
@@ -813,22 +830,9 @@ impl TrustAnchorChild {
}
//------------ UsedKeyState ------------------------------------------------
/// Tracks the state of a key used by a child CA. This is needed because
/// RFC 6492 dictates that keys cannot be re-used across resource classes.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
#[allow(clippy::large_enum_variant)]
#[serde(rename_all = "snake_case")]
pub enum UsedKeyState {
#[serde(alias = "current")]
InUse(ResourceClassName), /* Multiple keys are possible during a key
* rollover. */
Revoked,
}
//------------ ProvisioningRequest -----------------------------------------
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
#[allow(clippy::large_enum_variant)]
pub enum ProvisioningRequest {
@@ -877,6 +881,7 @@ impl std::fmt::Display for ProvisioningRequest {
//------------ ProvisioningResponse ----------------------------------------
// *Warning:* This type is used in stored state.
#[derive(Clone, Debug, Deserialize, Eq, PartialEq, Serialize)]
#[allow(clippy::large_enum_variant)]
pub enum ProvisioningResponse {