summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | Bump openssl-src to 1.1.1t.Nick Mathewson2023-02-071-2/+2
|/ /
* | Merge branch 'shadykaty-error-hint-v2' into 'main'eta2023-02-077-8/+155
|\ \ | | | | | | | | | | | | | | | | | | Create and use an ErrorHint type to report how to fix a problem. Closes #579 and #578 See merge request tpo/core/arti!994
| * | ErrorHint: Report hints for arti_client errors.Nick Mathewson2023-01-271-4/+11
| | |
| * | ErrorHint: Add a note about lowering the permissions hintNick Mathewson2023-01-271-0/+4
| | |
| * | ErrorHint: use anonymize_homeNick Mathewson2023-01-271-2/+4
| | |
| * | ErrorHint: Implement tryfrom_torpersistNick Mathewson2023-01-273-3/+8
| | |
| * | ErrorHint: refactor API (part 2)Nick Mathewson2023-01-271-75/+60
| | | | | | | | | | | | | | | | | | | | | Change ErrorHint so that, internally, it just holds an enum with a lightweight reference to whatever parts of the error it needs to generate a hint. Then we can move the formatting logic into a Display function for ErrorHint, and do away with ErrorDetail entirely.
| * | ErrorHint: refactor API (part 1)Nick Mathewson2023-01-271-13/+19
| | | | | | | | | | | | | | | | | | | | | Move the "hint" function into Error, and use Option rather than Result. (I'm using Option here because it's not really an error case not to have a hint; we just either have a hint, or we don't.)
| * | add opaque ErrorHint API, impl ErrorHint from BadPermissionsShady Katy2023-01-274-3/+141
| | |
* | | Merge branch 'env-check' into 'main'eta2023-02-072-1/+12
|\ \ \ | | | | | | | | | | | | | | | | maint: add shebang See merge request tpo/core/arti!990
| * | | ci: add shebang to the GitLab CIEmil Engler2023-01-261-1/+2
| | | |
| * | | maint: add shebangEmil Engler2023-01-261-0/+10
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds a test called `shebang`, which checks if all shebangs in scripts use relative paths through `#/usr/bin/env`, rather than absolute paths, such as `#/bin/bash`. See 833b10575bbb18200ae9e6ba4f0a1dd858417020.
* | | | Merge branch 'authcert_bug' into 'main'eta2023-02-075-41/+90
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Fix AuthCert behavior on unrecognized tokens, and prevent bug from recurring elsewhere. Closes #752 See merge request tpo/core/arti!1006
| * | | | netdoc: Require that unrecognized tokens be handled explicitly.Nick Mathewson2023-02-033-5/+39
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Now we require that, for all `SectionRules`, either the caller say how to handle unrecognized tokens (using `.add(UNRECOGNIZED...)`), or that they explicitly reject unrecognized tokens (using `reject_unrecognized`()`.) This solution uses an assert!() rather than an Error to indicate failure. I say that's fine, since 1. This is a crate-internal API. 2. We never dynamically construct SectionRules according to different behavior: they are always prefabricated in a fixed code block. Thus, if we test a parser at all, we will make sure that its SectionRules are well-formed. I considered and explicitly rejected a solution where the builder had to be finalized with separate methods `build_strict()` or `build_tolerant()`: It's too easy IMO for the caller to forget what these call means. Prevents further recurrences of #752. Closes #752.
| * | | | netdoc: Switch SectionRules building to use a Buidler pattern.Nick Mathewson2023-02-035-41/+55
| | | | | | | | | | | | | | | | | | | | No new behavior yet.
| * | | | Add a rule to handle UNRECOGNIZED in AuthCert.Nick Mathewson2023-02-031-0/+1
| | |_|/ | |/| | | | | | | | | | | | | | | | | | This fixes an instance of bug#752. Previously, we would reject any AuthCert that contained an unexpected keyword. (Fortunately, this data format does not change very often.)
* | | | Merge branch 'parse_hsdesc' into 'main'Nick Mathewson2023-02-0719-66/+1778
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | Onion service descriptor parsing and decoding, first cut. See merge request tpo/core/arti!999
| * | | | netdoc: Add a comment about renaming layer to document.Nick Mathewson2023-02-071-0/+9
| | | | |
| * | | | netdoc::hsdesc: rename Passwd to Password.Nick Mathewson2023-02-072-2/+2
| | | | |
| * | | | netdoc: Rename/comment objects from hsdesc.Nick Mathewson2023-02-071-9/+15
| | | | |
| * | | | netdoc: Rename/comment objects from inner_layer.Nick Mathewson2023-02-072-23/+47
| | | | |
| * | | | netdoc: Rename/comment objects from middle_layer.Nick Mathewson2023-02-074-19/+28
| | | | |
| * | | | netdoc: Rename/comment objects from desc_encNick Mathewson2023-02-073-21/+36
| | | | |
| * | | | netdoc: Renaming and comments in outer_layer.Nick Mathewson2023-02-071-8/+13
| | | | |
| * | | | netdoc: Use Itertools::exactly_once in hsdesc parsingNick Mathewson2023-02-072-4/+8
| | | | |
| * | | | netdoc: Remove useless should_be_exhausted calls.Nick Mathewson2023-02-073-3/+0
| | | | |
| * | | | Remove a needless line.Nick Mathewson2023-02-071-1/+0
| | | | |
| * | | | Even more clarifying comments.Nick Mathewson2023-02-073-8/+14
| | | | |
| * | | | netdoc: Try to add a bunch of clarifying documentation.Nick Mathewson2023-02-075-28/+87
| | | | | | | | | | | | | | | | | | | | | | | | | In the process I found a couple of keys without identifiers in the spec.
| * | | | netdoc: Use Signature::from to construct ed25519 sigs.Nick Mathewson2023-02-072-5/+10
| | | | |
| * | | | netdoc: Clear up a few typos in hsdesc comments and strings.Nick Mathewson2023-02-072-6/+6
| | | | |
| * | | | netdoc: Implement onion service descriptor parsers.Nick Mathewson2023-02-072-45/+183
| | | | |
| * | | | tor-checkable: Add dangerously_map() functions.Nick Mathewson2023-02-072-1/+60
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | These functions consume a checkable wrapper, and return a new checkable wrapper with mapped contents but the same not-yet-checked constraints. As documented, They are "dangerous" because the provided function gets access to the contents before they are checked; the caller has to make sure that the provided function doesn't expose their contents inappropriately.
| * | | | netdoc: Parse the inner layer of an onion service descriptor.Nick Mathewson2023-02-074-0/+354
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | There are some places where I note certificates which are not currently validated, because there is no cryptographic point in doing so. We should either document that this is okay, or validate the certificates anyway. This code might benefit from refactoring to make it prettier.
| * | | | netdoc: Add a workaround for C Tor's lack of mid-layer NLNick Mathewson2023-02-072-2/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | It turns out that C Tor doesn't add a newline at the end of the middle layer of an onion service descriptor. I've made a spec MR (torspec!109) to document this: here, it's time to work around the issue.
| * | | | netdoc: Parse the middle layer of a hsdesc, and decrypt it.Nick Mathewson2023-02-073-0/+259
| | | | |
| * | | | netdoc: Use correct size for descriptor encryption cookieNick Mathewson2023-02-071-2/+2
| | | | |
| * | | | netdoc: move test descriptor to a higher level test moduleNick Mathewson2023-02-072-6/+12
| | | | | | | | | | | | | | | | | | | | | | | | | We're going to make use of it in all of our tests, so we may as well expose it to them from hsdesc::test.
| * | | | netdoc: implement onion service descryptor encryptionNick Mathewson2023-02-074-10/+231
| | | | | | | | | | | | | | | | | | | | | | | | | This is tested via a round-trip check, and via a successful decryption of our example descriptor's outer layer.
| * | | | netdoc: Parser for outer layer of onion service descriptors.Nick Mathewson2023-02-072-0/+255
| | | | |
| * | | | netdoc: Add an example onion service descriptor to test our parsing.Nick Mathewson2023-02-071-0/+223
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I generated this using C tor (latest main) and a Chutney network about a week ago. The subcredential is: 78210A0D2C72BB7A0CAF606BCD938B9A3696894FDDDBC3B87D424753A7E3DF37 The HS_blind_id is: 43CC0D62FC6252F578705CA645A46109E265290343B1137E90189744B20B3F2D
| * | | | netdoc: Derive Debug and Clone on HsDesc and its kin.Nick Mathewson2023-02-071-0/+3
| | | | |
| * | | | hscrypto: Impl From<Ed25519Identity> for BlindedOnionId.Nick Mathewson2023-02-071-0/+6
| | | | |
| * | | | hscrypto: add From/Into between RevisionCounter and u64.Nick Mathewson2023-02-071-1/+3
| | | | |
| * | | | tor-cert: document hs-related certificate types.Nick Mathewson2023-02-071-4/+25
| | | | | | | | | | | | | | | | | | | | | | | | | Also, explain why a few of these certificates aren't actually useful as certificates. (This issue is also documented in torspec!110)
| * | | | tor-cert: Implement Timebound for Ed25519CertNick Mathewson2023-02-072-4/+18
| | | | | | | | | | | | | | | | | | | | | | | | | This allows us to run `is_valid_at` and friends on the certificate itself, which we will use soon in hsdesc validity checks.
| * | | | llcrypto: Implement `Into<[u8;32]>` for Ed25519IdentityNick Mathewson2023-02-072-0/+7
| | | | |
| * | | | llcrypto: Derive zeroize for CtByteArray.Nick Mathewson2023-02-072-1/+3
| | | | |
* | | | | Merge branch 'warning' into 'main'Nick Mathewson2023-02-070-0/+0
|\ \ \ \ \ | |/ / / / |/| | | | | | | | | | | | | | tor-netdoc: Suppress a cfg-dependent dead code warning See merge request tpo/core/arti!998
| * | | | tor-netdoc: Suppress a cfg-dependent dead code warningIan Jackson2023-01-311-0/+1
| | | | | | | | | | | | | | | | | | | | | | | | | This is dead code when cargo +stable clippy -p tor-netdir --all-features --all-targets