summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
* | | Merge branch 'ticket_759' into 'main'Nick Mathewson2023-05-169-17/+66
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-cert: Replace the KeyUnknownCert::check_key API Closes #759 See merge request tpo/core/arti!1184
| * | | Deprecate check_key, and refactor its logic into the new functions.Nick Mathewson2023-05-161-16/+33
| | | | | | | | | | | | | | | | Closes #759
| * | | Replace usage of KeyUnknownCert::check_key.Nick Mathewson2023-05-167-11/+11
| | | |
| * | | tor-cert: Add new functions to replace KeyUnknownCert::check_key.Nick Mathewson2023-05-162-0/+32
| | |/ | |/| | | | | | | | | | | | | | | | These should have a cleaner API than check_key, and be easier to understand. Part of #759
* | | Merge branch 'resolve_relay' into 'main'Nick Mathewson2023-05-161-0/+142
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | netdir: New function to check consistency of a HasRelayIds Closes #855 See merge request tpo/core/arti!1186
| * | | netdir: New function to check consistency of a HasRelayIdsNick Mathewson2023-05-161-0/+142
| |/ / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This function will be used to look up a relay by a set of LinkSpecs given from an incoming HsDesc or INTRODUCE2 message. It differs from other "lookup relay by IDs" functions in that it needs to be able to return "here's a relay", "couldn't found a relay", or "learned that this relay is impossible." Closes #855: This is the only new API needed for ChanTarget validation, I think.
* | | Merge branch 'key-mgmt-api-updates-v2' into 'main'gabi-2502023-05-161-81/+208
|\ \ \ | | | | | | | | | | | | | | | | dev docs: key-management.md updates and clarifications See merge request tpo/core/arti!1185
| * | | dev docs: The key store version file should specify a minimum supported version.Gabriela Moldovan2023-05-161-2/+10
| | | | | | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | dev docs: Remove unused arguments.Gabriela Moldovan2023-05-161-12/+9
| | | | | | | | | | | | | | | | | | | | | | | | There are several places where he `KeyType` isn't needed anymore. Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | dev docs: Clarify how C Tor key store loads keys from multiple different key ↵Gabriela Moldovan2023-05-161-26/+66
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | dirs. This also moves the `extension` function out of `KeyType` because for the C Tor key store, a key's file extension depends on the role/user of the key, which isn't known by `KeyType` (`KeyType` is a tor-agnostic key type such as `Ed25519Private`). Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | dev docs: Distinguish between arti_extension and ctor_extension.Gabriela Moldovan2023-05-161-2/+7
| | | | | | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | dev docs: Clarify that ArtiPath/CTorPath are relative to the key store root.Gabriela Moldovan2023-05-161-1/+9
| | | | | | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | dev docs: Add note about key store versioning.Gabriela Moldovan2023-05-161-0/+9
| | | | | | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | dev docs: Add note about C Tor store configuration.Gabriela Moldovan2023-05-161-1/+49
| | | | | | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | dev docs: Move the key passphrases subsection to the Arti store section.Gabriela Moldovan2023-05-161-6/+6
| | | | | | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | dev docs: Create a separate section for the C tor key store discussion.Gabriela Moldovan2023-05-161-5/+17
| | | | | | | | | | | | | | | | Signed-off-by: Gabriela Moldovan <[email protected]>
| * | | dev docs: Rename {Key, HsClient}Identity.Gabriela Moldovan2023-05-161-45/+45
| |/ / | | | | | | | | | | | | | | | | | | | | | This renames `KeyIdentity` to `KeySpecifier` so it doesn't get confused with the concept of an "identity key". `HsClientIdentity` is also renamed for consistency. Signed-off-by: Gabriela Moldovan <[email protected]>
* | | Merge branch 'rpc-objectmap' into 'main'Nick Mathewson2023-05-165-231/+214
|\ \ \ | |_|/ |/| | | | | | | | | | | | | | RPC: revise semantics for weak references and object IDs Closes #848 See merge request tpo/core/arti!1183
| * | rpc: Clarify how authentication works.Nick Mathewson2023-05-161-10/+5
| | |
| * | rpc: Clarify some object ID docs and remove impl details.Nick Mathewson2023-05-161-37/+4
| | |
| * | rpc: Revise example in documentationNick Mathewson2023-05-161-4/+4
| | |
| * | rpc: Split the generational index into two.Nick Mathewson2023-05-161-113/+92
| | | | | | | | | | | | This lets us simplify our logic a bit for strong references.
| * | rpc: Change the formatting of object IDsNick Mathewson2023-05-153-22/+79
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We want each ID to have a unique form every time it is given out, so that you can't use ID==ID to check whether Object==Object. (See discussions leading to #848.) We'd also like the form of object IDs to be a little annoying to analyze, to discourage people from writing programs that depends on their particular format. (We are reserving the right to change the format whenever we want.) We _don't_ want to use any cryptography here (yet), lest somebody think that this is an actual security mechanism. (This isn't for security; it's for encouraging developers to treat IDs as opaque.) With that in mind, we now lightly obfuscate our generational indices before returning them.
| * | rpc: rename GenIdx::into/try_from implementationsNick Mathewson2023-05-152-11/+9
| | | | | | | | | | | | | | | These are about to become nondeterministic-ish and probably shouldn't use the Into/TryFrom traits.
| * | rpc: do not deduplicate strong object idsNick Mathewson2023-05-151-52/+39
| | | | | | | | | | | | | | | | | | | | | | | | Per discussion referenced at #848, we want each operation that returns a strong object ID to return a new, distinct strong ID. Note that we no longer need to put strong and weak references in the same arena; we can clean this code up a lot down the road.
| * | rpc: Repair an error in our ObjectId encoding.Nick Mathewson2023-05-151-1/+1
| |/ | | | | | | | | | | Now we generate object IDs that we can parse. This is about to be obsolete once we change how we generate objects and their IDs for #848, but we may as well start from a working state.
* | Merge branch 'run-fixup-features' into 'main'gabi-2502023-05-1643-117/+412
|\ \ | |/ |/| | | | | | | | | Run fixup-features on our Cargo.tomls, and handle its warnings Closes #856 and #795 See merge request tpo/core/arti!1182
| * Revise all XXXXs from fixup-featuresNick Mathewson2023-05-1519-89/+79
| |
| * Run fixup-features _with_ annotations.Nick Mathewson2023-05-1519-0/+70
| | | | | | | | | | This litters our Cargo.toml files with "XXX" entries that we should fix.
| * Reformat Cargo.toml files.Nick Mathewson2023-05-1520-69/+230
| |
| * Run fixup-features --no-annotate for initial Cargo.toml fixes.Nick Mathewson2023-05-1542-44/+118
|/ | | | | | | | | This does the following: - Gives every crate a `full`. - Cause every `full` to depend on `full` from the lower-level crates. - Makes every feature listed _directly_ in `experimental` depend on `__is_experimental`.
* Merge branch 'better-fixup-features' into 'main'Nick Mathewson2023-05-159-146/+416
|\ | | | | | | | | Revise fixup-features to be closer to something we can use See merge request tpo/core/arti!1180
| * fixup-features: minor doc fix.Nick Mathewson2023-05-151-5/+5
| |
| * Mark an initial set of non-additive features.Nick Mathewson2023-05-155-14/+24
| |
| * fixup-features: Do not annotate non-features.Nick Mathewson2023-05-152-3/+7
| |
| * fixup-features: Do not add edges from non-features.Nick Mathewson2023-05-152-2/+7
| |
| * fixup-features: distinguish internal and external edgesNick Mathewson2023-05-152-3/+8
| | | | | | | | An external edge does not cause its target to be created as a feature.
| * fixup-features: Add an option to not annotate.Nick Mathewson2023-05-153-6/+25
| |
| * fixup-features: ability to add annotations for everything.Nick Mathewson2023-05-151-7/+13
| |
| * fixup-features: fix off-by-one in argument reading.Nick Mathewson2023-05-151-1/+1
| |
| * fixup-features: Implement remaining rules.Nick Mathewson2023-05-151-34/+64
| |
| * fixup-features: Enforce __is_experimental tagging rule.Nick Mathewson2023-05-151-0/+19
| |
| * fixup-features: Revise our rule 2 enforcement to use newer APIs.Nick Mathewson2023-05-151-14/+14
| |
| * fixup-features: Refactor "apply a list of changes" code into a new module.Nick Mathewson2023-05-152-25/+88
| |
| * fixup-features: Make a feature graph type in a submoduleNick Mathewson2023-05-153-60/+149
| | | | | | | | | | I tried to use petgraph, but it was optimized for performance over usability, and the usability was beyond me.
| * fixup-features: minor spelling and comment fixes.Nick Mathewson2023-05-151-1/+1
| |
| * fixup-features: Describe the semantics we actually wantNick Mathewson2023-05-151-6/+26
| | | | | | | | | | | | | | | | | | The problem with our old rules is that "reachable from __nonadditive" and "reachable from experimental" were not themselves sensible definitions of nonadditive and experimental. See https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1068#note_2887939
* | Merge branch 'x25519-dalek-upgrade' into 'main'gabi-2502023-05-158-28/+72
|\ \ | | | | | | | | | | | | llcrypto: upgrade x25519-dalek. See merge request tpo/core/arti!1181
| * | Use non-deprecated *Secret::random_from_rng.Nick Mathewson2023-05-136-20/+21
| | | | | | | | | | | | The `new` function is deprecated in x25519-dalek 2.0.0-rc.2
| * | llcrypto: upgrade x25519-dalek.Nick Mathewson2023-05-132-8/+51
|/ / | | | | | | | | | | | | | | This upgrades us to 2.0.0-rc.2, which is the latest in the not-quite-done-yet 2.0 series. The only code change that's absolutely needed is opting into the static_secrets feature.