1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
//! The periodic CRL prune, as a job.
//!
//! RFC 5280 §3.3 permits dropping a revocation entry once the certificate
//! itself has expired, and [`crl::prune_expired`](super::crl::prune_expired) is
//! what decides which. Doing it only on revocation would be proportional to the
//! wrong thing: a CA that revokes a batch and then goes quiet never sheds
//! anything, and it is precisely the quiet CA whose CRL nobody notices growing.
//!
//! Deliberately **not** in [`crate::jobs::sweep`], whose `SweepTarget` is four
//! `DELETE`s over four tables and needs nothing but a
//! [`Database`](crate::sqlite::db::Database). This one holds signer state, signs
//! with the CA key, and touches no database at all.
//!
//! Two shapes it borrows from that module and one it does not:
//!
//! - [`JobOutcome::Reschedule`] is how periodic work is spelled here, and
//! - `run` **never returns [`JobOutcome::Failed`]** — a retired periodic job
//! does not re-enqueue itself, so one unwritable directory would stop the
//! prune for the life of the process rather than for one day.
//! - But there is **one handler over every CA**, not one per CA. See
//! [`SignerBackend::crl_pruner`](crate::signer::SignerBackend::crl_pruner):
//! [`JobRegistry::register`](crate::jobs::JobRegistry::register) refuses two
//! handlers for one `kind`, and two profiles with different
//! `[signer.local_ca]` sections are two backends, so the alternative would
//! make a supported configuration a startup error.
use Arc;
use Duration;
use async_trait;
use ;
use crate;
use crateCrlPruner;
use crateJob;
/// The `jobs.kind` the CRL prune runs under.
pub const CRL_SWEEP_KIND: &str = "local_ca_crl_sweep";
/// The one row's `dedup_key`. A constant, like the table sweeps': there is one
/// occurrence, and it walks every CA rather than there being one row each.
///
/// That is not only tidiness. A per-CA row would outlive the profile that named
/// it — unmount a profile and its row keeps being claimed, by a handler that no
/// longer has anything to hand it.
const SWEEP_KEY: &str = "all";
/// How often the prune runs.
///
/// A certificate's `notAfter` has a resolution of seconds but its *lifetime* is
/// measured in days, so an entry lingering a few hours past the point it could
/// have gone is nobody's problem — and this signs a CRL per CA that had
/// something to drop, which is not work to do hourly.
const DAILY: Duration = from_secs;
/// Prunes every local CA's revocation ledger, once a day.