Files
MicrOBU/microbu-esp32c5/external/vanetza-idf/tools/pki/prune_command.hpp
T
Ashin Walpola 0e9525162d Keep the colleague's microbu-esp32c5 tree in this repository
obu-firmware builds against vanetza-idf from microbu-esp32c5/external, but
that tree was gitignored, so a clone of this repository could not build the
firmware it ships. It is now committed here as ordinary files in its own
folder, microbu-esp32c5/: the colleague's commit cf4b99f plus the V2X2MAP
bridge's signature verification (--trust) used on the bench. Nothing is
fetched from or pushed to the colleague's repository; this repository and
its remotes carry everything. The folder's own .gitignore keeps build output,
downloaded components and private key material out, as it did there; the
committed file set is identical to that repository's tracked files.

The ESP32-C5 is still flashed from obu-firmware/, which only takes
vanetza-idf from microbu-esp32c5/, so the two stay separate folders.
FLASHING.md says how to take a newer version of the colleague's tree (copy
it over the folder, rebuild, test, commit).
2026-09-23 17:46:40 +02:00

111 lines
3.3 KiB
C++

#pragma once
#include "certificate.hpp"
#include "certificate_storage.hpp"
#include "hashed_id8.hpp"
#include "main.hpp"
#include <vanetza/common/clock.hpp>
#include <CLI/CLI.hpp>
#include <memory>
#include <string>
namespace vanetza
{
namespace pki
{
/**
* Visitor that observes expired certificates streamed by `prune_expired`.
* Methods are called once per certificate as it is encountered. The driver
* performs no per-cert buffering.
*/
class PruneExpiredVisitor
{
public:
virtual ~PruneExpiredVisitor() = default;
/**
* An expired certificate eligible for deletion.
*
* \param store backing store holding the cert; the visitor erases from it if needed
* \param label short role tag ("Root CA", "EC", "AT", "TLM") for output
* \param pubkey_hex canonical-hex name of the corresponding credential
*/
virtual void on_deletable(CertificateStorage& store, const std::string& label, const HashedId8&, const Certificate&,
const std::string& pubkey_hex)
{
}
/**
* An expired certificate that is being skipped because it is referenced
* by station configuration and `--force` was not specified.
*/
virtual void on_skipped(const std::string& label, const HashedId8&, const Certificate&)
{
}
/// Called once after all stores have been fully iterated.
virtual void on_summary()
{
}
};
/**
* Stream every expired certificate in the cert and ticket stores through the
* visitor. Memory is constant — no per-cert state is retained.
*
* \param now cutoff for expiry: `cert.valid_until() < now` ⇒ expired
* \param force if true, station-referenced certs go to `on_deletable` instead
* of `on_skipped`
*/
void prune_expired(const MainConfig& cfg, Clock::time_point now, bool force, PruneExpiredVisitor& visitor);
/**
* Prune expired authorization tickets and their credentials.
* `dry_run` lists without deleting.
*/
void prune_expired_tickets(const MainConfig& cfg, Clock::time_point now, bool dry_run);
/// Visitor for `prune_orphans`. Same streaming pattern.
class PruneOrphansVisitor
{
public:
virtual ~PruneOrphansVisitor() = default;
/// An orphan credential eligible for deletion, by canonical-hex name.
virtual void on_orphan(const std::string& canonical_hex)
{
}
/// A credential retained because a certificate still references it.
virtual void on_keep(const std::string& canonical_hex)
{
}
/// Called once after all credentials have been iterated.
virtual void on_summary()
{
}
};
/**
* Stream every orphan credential through the visitor.
* A credential is orphan when its canonical-hex name does not match any public key
* referenced by a certificate in either store.
*/
void prune_orphans(const MainConfig& cfg, PruneOrphansVisitor& visitor);
/**
* Reconcile the exported AA/EA issuer certificates against the currently stored
* CTLs: remove any `.aa`/`.ea` cert whose HashedId8 is not present in the latest
* stored CTL of any trusted Root CA. Prevents issuer certs orphaned by CTL
* rotation from accumulating. `dry_run` lists without deleting.
*/
void prune_ctl(const MainConfig& cfg, bool dry_run);
// CLI subcommand tree.
std::shared_ptr<CLI::App> build_prune_command(const MainConfig&);
} // namespace pki
} // namespace vanetza