Skip to content

feat(client): add a file system backend for the certificate chain cache - #3562

Merged
jpraynaud merged 3 commits into
mainfrom
jpraynaud/3522-fs-certificate-chain-cache
Sep 28, 2026
Merged

jpraynaud merged 3 commits into
mainfrom
jpraynaud/3522-fs-certificate-chain-cache

Conversation

@jpraynaud

@jpraynaud jpraynaud commented Sep 23, 2026 •

Copy link
Copy Markdown
Member

Content

This PR includes the file system backend of the certificate chain cache of mithril-client, so that the certificates verified by one CLI run are reused by the next ones:

  • Added FileCertificateVerifierCache, available with the fs and unstable features, storing one JSON file per committed certificate with its expiration date under committed/<space>/, where the space is the fingerprint of the genesis verification key that validated it.
  • Staged the certificates of a chain validation in progress under staged/<certificate chain validation id>/, with the creation date of the batch in a created_at file.
  • Committed a validation by writing each certificate with its expiration date to a separate file, then moving it to the committed directory with an atomic rename, so that no cross process lock is needed and a failed move leaves the staged certificate intact.
  • Aligned the expiration semantics on the memory backend: the expiration date of a certificate is set at commit, and a staged batch expires after the staging expiration delay from its creation.
  • Swept the expired committed certificates and the expired staged batches when a new batch is staged and at commit, as a best effort that never fails a stage or a commit and only touches batch directories and certificate files.
  • Invalidated a committed file that cannot be parsed by deleting it and reporting an error, which the verifier already logs before falling back to the aggregator.
  • Restricted the certificate hashes and validation ids used as file names to alphanumeric characters, - and _, since the previous hash of a downloaded certificate could otherwise make the client read and delete files outside the cache.
  • Added the fs feature of tokio to the fs feature of the crate.

Pre-submit checklist

  • Branch
    • Tests are provided (if possible)
    • Crates versions are updated (if relevant)
    • CHANGELOG file is updated (if relevant)
    • Commit sequence broadly makes sense
    • Key commits have useful messages
  • PR
    • All check jobs of the CI have succeeded
    • Self-reviewed the diff
    • Useful pull request description
    • Reviewer requested
  • Documentation
    • No new TODOs introduced

Comments

  • The backend is gated on the fs feature rather than on non-WASM targets.
  • The files are not synced to disk: a committed file truncated by a power loss is detected, deleted and fetched again from the aggregator.
  • A staged batch without a readable created_at file (interrupted creation) expires from the last modification of its directory.

Issue(s)

Closes #3522

@jpraynaud jpraynaud self-assigned this Sep 23, 2026
@jpraynaud
jpraynaud added this pull request to stack #3563 September 23, 2026 16:52
@jpraynaud
jpraynaud requested a lite review from Copilot September 23, 2026 16:52

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved cache publication and integration issues can compromise correctness and prevent the advertised CLI reuse behavior.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Adds a filesystem-backed certificate verification cache for reuse across client runs.

Changes:

  • Implements staged and committed certificate storage with expiration and cleanup.
  • Exposes the backend behind fs and unstable features.
  • Adds filename validation, Tokio filesystem support, tests, and changelog documentation.
File Summary
mithril-client/​src/​certificate_client/​verify_cache/​mod.rs Registers and exports the filesystem cache backend.
mithril-client/​src/​certificate_client/​verify_cache/​file_cache.rs Implements the filesystem cache; unresolved concerns remain around partial commits and publishing incomplete files.
mithril-client/​src/​certificate_client/​mod.rs Exports the cache, but the CLI does not yet configure or use it.
mithril-client/​Cargo.toml Adds filesystem support; the fs feature documentation should also mention certificate caching.
CHANGELOG.md Documents the new backend.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread mithril-client/src/certificate_client/verify_cache/file_cache.rs Outdated
@jpraynaud
jpraynaud marked this pull request as ready for review September 23, 2026 16:58
@jpraynaud
jpraynaud requested a review from damrobi September 23, 2026 16:58
@github-actions

github-actions Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Test Results

     5 files  ±  0     221 suites  ±0   47m 36s ⏱️ - 16m 38s
 3 807 tests + 51   3 807 ✅ + 51  0 💤 ±0  0 ❌ ±0 
12 288 runs  +202  12 288 ✅ +202  0 💤 ±0  0 ❌ ±0 

Results for commit faf3736. ± Comparison against base commit bc0bb01.

♻️ This comment has been updated with latest results.

@jpraynaud
jpraynaud deployed to testing-preview September 23, 2026 17:33 — with GitHub Actions Active
@jpraynaud
jpraynaud deployed to testing-2-preview September 23, 2026 17:33 — with GitHub Actions Active
@jpraynaud
jpraynaud force-pushed the jpraynaud/3522-fs-certificate-chain-cache branch 2 times, most recently from 7fc6b90 to 2ee72b7 Compare September 24, 2026 16:12
@jpraynaud
jpraynaud deployed to testing-preview September 24, 2026 16:49 — with GitHub Actions Active
@jpraynaud
jpraynaud deployed to testing-2-preview September 24, 2026 16:49 — with GitHub Actions Active
@jpraynaud
jpraynaud force-pushed the jpraynaud/3522-fs-certificate-chain-cache branch from 2ee72b7 to c4a9eec Compare September 25, 2026 15:59
@jpraynaud
jpraynaud deployed to testing-preview September 25, 2026 16:29 — with GitHub Actions Active
@jpraynaud
jpraynaud deployed to testing-2-preview September 25, 2026 16:29 — with GitHub Actions Active

@turmelclem turmelclem left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 👍

@damrobi damrobi left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 👍

Base automatically changed from jpraynaud/3521-early-stop-certificate-chain-cache to main September 28, 2026 16:07
…cache

Certificates are staged per chain validation id and committed with atomic renames,
unparsable files are invalidated and expired entries and batches are swept.
* mithril-client from `0.14.26` to `0.14.27`
@jpraynaud
jpraynaud force-pushed the jpraynaud/3522-fs-certificate-chain-cache branch from c4a9eec to faf3736 Compare September 28, 2026 16:21
@jpraynaud
jpraynaud deployed to testing-preview September 28, 2026 16:38 — with GitHub Actions Active
@jpraynaud
jpraynaud deployed to testing-2-preview September 28, 2026 16:38 — with GitHub Actions Active
@jpraynaud
jpraynaud merged commit 6b60db6 into main Sep 28, 2026
53 checks passed
@jpraynaud
jpraynaud deleted the jpraynaud/3522-fs-certificate-chain-cache branch September 28, 2026 16:40

This branch was successfully deployed

2 active deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add a file-system backend for the certificate chain cache

4 participants