Commit Graph

2121 Commits

Author SHA1 Message Date
cloudhead 6dcfbfcdee
build: Separate release from upload 2024-11-01 12:28:39 +01:00
cloudhead 09f796234d
radicle: Compute root OID for older remotes
For older clients, `refs/rad/root` won't be set. In that case, compute
it locally based on `refs/rad/id`.
2024-10-31 17:34:03 +01:00
Johannes Kuehlewindt 0c9a7419dc
cli: Add config modification sub-commands
Adds `set`, `add`, `remove`, `delete` to `rad config`.

Note that the changes will affect the configuration file, but not the
running instances. For changes to be reflected in the running instances
the node would need to be restarted.
2024-10-23 17:19:27 +02:00
cloudhead a838c3ea01
fmt: Run `cargo fmt` 2024-10-23 16:17:24 +02:00
Fintan Halpenny b4f2614d6c cob: chronological ordering of concurrent values
The underlying `Dag` for a COB will use the `Ord` implementation of
whatever is provided as the key. This means that the lexicographical
ordering of the `Oid` SHA will be used, which in turn means that if
the SHAs change in our tests, then the ordering will be broken for
concurrent updates.

To prevent this from happening, a variant of the `prune` method is
introduced that takes an ordering of the keys and values – this method
being called `prune_by`.

This allows `prune` to be replaced with `prune_by` in the
`ChangeGraph::evaluate` method. The ordering used is first comparing
the `Entry::timestamp` and then the `EntryId` (`Oid`).
2024-10-23 13:02:55 +01:00
Fintan Halpenny de1958fab0 radicle: refactor doc
The aim of this change is to make the `Doc` type more safe to use by approaching
the design via [Parse don't validate][[0]] approach.

The problem with the previous approach was that all field were `pub` and thus a
`Doc<Verified>` could easily be mutated and serialized. Granted, the code that
used the serialization would tend to verify the `Doc` first, however, this
approach *ensures* that only a verified `Doc` can be serialized. It also meant
that trying to add new data that would follow the parse approach would require
more generic parameters on top of the existing `PhantomData` parameter, i.e. we
need to do something like: `Doc<RawField, V> -> Doc<ValidField, V>`.

The new approach splits the type into two separate types: `RawDoc` and `Doc`.
The former is allowed to be mutated at will, and uses types that are less
strict. The latter is the valid type that can only be constructed by validating
a `RawDoc` (or the `initial` constructor). The `Doc` type's fields can then only
be accessed by read-only methods.

Solves the problems above by only allowing mutations to `RawDoc`, as well as,
new fields being added to `RawDoc` which are then validated via
`RawDoc::verified`.

[0]: https://lexi-lambda.github.io/blog/2019/11/05/parse-don-t-validate/
2024-10-22 14:58:12 +01:00
cloudhead f83c116742
radicle: Fix clippy warnings around `unwrap`
The policy should be that we don't use unwraps outside of test code,
unless we have a good reason to.
2024-10-21 16:42:06 +02:00
cloudhead 989edacd56
Include new `rad/root` in signed refs
We ensure that a `rad/root` ref is included in the signed refs file
under `rad/sigrefs` for all remotes. This prevents a certain kind of
"grafting" attack where signed refs can be copied between repositories,
by having the peer sign over the identity root together with the data refs.

When verifying signed refs, we ensure that the ref is present and points
to an identity branch root that matches the repository identity containing
the signed refs.

Alternatives: lots of alternatives were considered, but this one doesn't
introduce any changes to the signing. The `rad/id/root` name was
considered but is invalid due to `rad/id`.
2024-10-21 16:32:49 +02:00
cloudhead 24066c2600
radicle: Test the signed refs grafting attack 2024-10-21 16:32:49 +02:00
Fintan Halpenny 46c2637f77
radicle: add tags fetch refspec
Add a fetch refspec to fetch tags from a Radicle remote. The
`--no-tag` option is also included. This is to ensure that it is easy
to collaborate by having tags placed in the remote namespace of
another peer. However, if the namespace is the default `rad` remote,
then tags are expected to be allowed -- this is to pave way for the
feature of canonical tags.

In the tests, the `--tags` option is removed -- and is generally
recommended that it is not used. This is to ensure that it does not
override the `--no-tag` option.
2024-10-21 14:30:37 +02:00
cloudhead 6763bf31e1
helper: Don't require `GIT_DIR` for listing refs 2024-10-21 13:07:36 +02:00
cloudhead 855327d303
cob: Change APIs to take URIs for embeds
To facilitate edit actions, take URIs instead of the actual blobs. This
means API callers don't have to load all the blobs just for them to be
re-hashed when an edit action is submitted.

There are some peculiarities when dealing with the `Identity` COB since
the embed is the identity document itself. We handle that special case.
2024-10-14 12:51:36 +02:00
cloudhead 034eb41860
node: Ensure private RIDs don't leak in gossip
Though refs of private repositories are not announced publicly, they can
sometimes be relayed to nodes that are not in the allow list.

We fix this by always checking the visibility of a repository before
sending a refs announcement of it to a peer.

Discovered-by: Adrian Duke <adrian.duke@gmail.com>
2024-10-08 13:28:09 +02:00
cloudhead 3acdb17b86
cob: Fix patch review editing
Due to the way review editing was implemented, we were losing comments
on previous review edits.

Here, we add a new `review.edit` action that is specifically for
editing, and make the existing `review` action fail silently (for
backwards compatibility) in case it is used when there is already a
review.

We also simplify the review data structure by only keeping track of one
review per author per revision, instead of all edits. Later, if needed,
it will be possible to keep track of all review edits.
2024-10-04 17:44:45 +02:00
Alexis Sellier 729a6e057e
cobs: Fix COB drafts to work correctly 2024-10-01 15:59:23 +02:00
Fintan Halpenny e130b4dc06
radicle: custom upstream remote for patches
When creating a new upstream for the patch workflow, the remote name is always
assumed to be `rad`.

It's possible for users to use another remote name but still use a `rad://` URL
for pushing. To allow for this, the function that creates the upstream entry now
takes a remote name. In the remote helper, `rad patch checkout`, and `rad patch
set` the remote can be optionally specified and fall back to the `rad` remote
name as a default.

Signed-off-by: Fintan Halpenny <fintan.halpenny@gmail.com>
X-Clacks-Overhead: GNU Terry Pratchett
2024-09-12 17:59:57 +02:00
Lars Wirzenius 00639182a7
docs: Add a note on running isolated nodes
Signed-off-by: Lars Wirzenius <liw@liw.fi>
2024-09-12 17:56:21 +02:00
Lorenz Leutgeb 47842a81e3
man: Mention `rad patch review` 2024-09-12 17:51:42 +02:00
Lorenz Leutgeb 4b955fff15
nix: Fix macOS build 2024-09-12 17:50:06 +02:00
Fintan Halpenny f244d89e56
node: check policy before visibility
In the `is_authorized` helper, the logic checks the policy and the visibility of
the repository.

If the policy is set to block, the function can return before getting the
repository and the identity document. This improves the check, since the
repository and identity document may be missing if the repository is blocked, so
it would return a different error other than the expected unauthorized error.
2024-09-12 17:47:55 +02:00
Lorenz Leutgeb 1d57778f6b
profile: Treat empty passphrase as no passphrase 2024-09-11 13:34:41 +02:00
cloudhead d39ba83cfc
Update `Cargo.lock` 2024-09-03 12:42:10 +02:00
cloudhead b77bea8e09
Update `radicle-systemd` Cargo.toml 2024-09-03 12:40:22 +02:00
cloudhead 1c620a2819
Update `radicle-node` crate to 0.10.0 2024-09-03 12:37:47 +02:00
cloudhead 57a0c8c46c
Update `radicle-fetch` crate to 0.10.0 2024-09-03 12:36:24 +02:00
cloudhead c8b33a4fba
Update `radicle-remote-helper` crate to 0.10.0 2024-09-03 12:34:27 +02:00
cloudhead bde68ac76c
Update `radicle-cli` crate to 0.11.0 2024-09-03 12:33:02 +02:00
cloudhead bbc79a7e30
Update `radicle-term` crate to 0.11.0 2024-09-03 12:31:07 +02:00
cloudhead 73467bde83
Update `radicle-signals` crate to 0.10.0 2024-09-03 12:31:07 +02:00
cloudhead bc14229639
scripts: Small improvement to `cache-cobs` 2024-09-02 16:20:17 +02:00
cloudhead 4e112aaeaa
Update `radicle` crate to 0.13.0 2024-08-28 13:01:35 +02:00
cloudhead 2d241e5f7d
Update `radicle-crypto` crate to 0.11.0 2024-08-28 13:01:35 +02:00
cloudhead c112f3fbc9
Update `radicle-cob` crate to 0.12.0 2024-08-28 12:55:30 +02:00
cloudhead c8fbcf2a7a
helper: Revert patches correctly
When pushing to the default branch and updating the canonical head,
check to see if any merged patches are reverted due to this change.

If so, make sure the COB cache reflects this.
2024-08-23 15:59:59 +02:00
Lorenz Leutgeb 0dd06b91c1
nix: Correctly set `RUST_SRC_DIR` 2024-08-22 11:12:10 +01:00
Lorenz Leutgeb 621c5a4563
rust: Migrate to `rust-toolchain.toml`
See
 - https://rust-lang.github.io/rustup/overrides.html#the-toolchain-file
2024-08-22 11:12:10 +01:00
Lorenz Leutgeb b398e54b83
nix: Update flake to get to reach Rust 1.80 2024-08-22 11:12:09 +01:00
cloudhead 757483f351
radicle: Fix patch COB `review` action
When two `review` actions were posted by the same author, for the same
revision, an error was returned, cancelling evaluation for that author.
This caused certain patches to for eg. lose their merge status.

To remedy this, we *allow* multiple `review` actions per revision, but
simply take the last one as the "current" review. Since this makes the
`review.edit` action redundant, we remove that action completely. This
is safe, as none of the tools created review edits.
2024-08-21 17:37:58 +02:00
cloudhead 8922388caa
scripts: Add install command in changelog 2024-08-20 17:39:04 +02:00
Sebastian Martinez c0aecbac3a
Relax version requirement for `radicle` dependencies
Since a few crates rely on the `radicle` crate, dependency updates that
affect multiple crates like `git2` are not able to resolve the
dependencies and fail, if the version is fixed to e.g. `0.12.0`
2024-08-20 16:35:04 +02:00
Sebastian Martinez beac367056
Update `radicle-surf` to 0.22.0 2024-08-20 16:35:04 +02:00
Sebastian Martinez cae66b6168
Update `radicle-git-ext` to 0.8.0 2024-08-20 16:35:04 +02:00
Sebastian Martinez f71da0ee95
Update `git2` to 0.19.0 2024-08-20 16:35:04 +02:00
Fintan Halpenny eb432b9bc1
cli: announce on issue edit and comment
The `rad issue edit` and `rad issue comment` subcommands were not included in
the announce check. Since these are considered write commands, they should also
announce when executed.
2024-08-20 16:32:02 +02:00
cloudhead ab6ca14c88
tools: Add optional revision to `rad-merge` 2024-08-20 16:23:32 +02:00
Fintan Halpenny 86a0443916
crdt: run cargo fmt 2024-08-09 12:41:01 +02:00
Fintan Halpenny e1470fccd7
fetch: update gix-pack and gix-odb
The `gix-fs` crate was flagged as vulnerable[^0]. To update it to `>=0.11.0`, it
was necessary to update the `gix-pack` and `gix-odb` crate versions to `0.51`
and `0.61`, respectively.

This in turn updated `fastrand` which changed its algorithm[^1], which meant
that some test outputs were reordered or matched new values.

[0]: https://rustsec.org/advisories/RUSTSEC-2024-0350
[1]: https://github.com/smol-rs/fastrand/blob/master/CHANGELOG.md#version-210
2024-08-09 12:41:01 +02:00
cloudhead a61affa9fb
node: Don't fail if we can't load a COB to cache
This change simply logs an error if there is a problem loading a COB
from storage, instead of bailing on the cache update process.

We also ensure that objects that can't be loaded from storage are
removed from the cache.
2024-08-09 11:59:53 +02:00
cloudhead 1d1b9c3d49
radicle: Don't use transactions in cache
The `transaction` method was being used for single queries. This
was unnecessary.
2024-08-09 10:54:04 +02:00
cloudhead 9db69a40a6
radicle: Remove cache entries before caching
In case of a bug or failed cache update, there may be objects in the
cache that are no longer in storage.

When doing a full re-cache, remove all existing entries from the repo
first.
2024-08-09 10:48:46 +02:00