summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | keymgr: Do not expect x25519 keys to be stored as ed25519 ssh keys.Gabriela Moldovan2023-08-163-19/+54
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, the Arti key store would store x25519 secret keys as ed25519 OpenSSH keys, which it would convert to x25519 upon loading (using the conversion function added in !1297 (merged)). This approach isn't good enough though: most people will probably want to bring their existing x25519 keys, and in order to store those in OpenSSH format, we'd need convert them to ed25519, which is impossible (because the secret part of an x25519 key contains a SHA512'd secret, whereas the corresponding, "un-expanded", ed25519 secret key contains the secret itself rather than the SHA). Now that `ssh-key` has support for ssh keys with [custom algorithm names], we can store x25519 in OpenSSH format directly. This commit changes the storage format used by the keymgr for x25519 client auth keys (from ed25519-ssh to our own custom key type with an algorithm name of `"[email protected]"`). Closes #936 [custom algorithm names]: https://github.com/RustCrypto/SSH/pull/136
| * | | keymgr: Bump ssh-key to 0.6.0.Gabriela Moldovan2023-08-163-122/+79
|/ / / | | | | | | | | | This brings in the changes from #936.
* | | Merge branch 'bump-backtrace' into 'main'Nick Mathewson2023-08-152-2/+2
|\ \ \ | |_|/ |/| | | | | | | | tor-error, arti: Bump backtrace to 0.3.68. See merge request tpo/core/arti!1509
| * | tor-error, arti: Bump backtrace to 0.3.68.Gabriela Moldovan2023-08-152-2/+2
|/ / | | | | | | | | | | | | | | Previously we were using backtrace 0.3.39, which has a [bug] that causes it to segault in some circumstances. I experienced this bug while trying to fix the minimal-versions build in !1508. [bug]: https://github.com/rust-lang/backtrace-rs/issues/267
* | Merge branch 'cargo_audit_2022_0093' into 'main'Nick Mathewson2023-08-141-0/+8
|\ \ | | | | | | | | | | | | cargo_audit: Add an exception for RUSTSEC-2022-0093. See merge request tpo/core/arti!1506
| * | cargo_audit: Add an exception for RUSTSEC-2022-0093.Nick Mathewson2023-08-141-0/+8
| | | | | | | | | | | | | | | | | | | | | This is the API deficiency in ed25519-dalek v1 that allows you to mismatch public and private keys, leading to a (fatal) double-signing attack. We have worked around this in our current design, so it's appropriate to suppress this warning for now.
* | | Merge branch 'establish_intro_v2' into 'main'Nick Mathewson2023-08-1418-53/+468
|\ \ \ | |/ / |/| | | | | | | | | | | | | | Implement circuit binding and start on intro-point establisher logic Closes #953 and #993 See merge request tpo/core/arti!1472
| * | Start working on the backend for an IptEstablisher.Nick Mathewson2023-08-143-8/+249
| | | | | | | | | | | | | | | | | | | | | | | | This should be enough now to establish real introduction points, though there is still a lot of work to do. Part of #976. This has been rebased and edited to incorporate discussions from !1465.
| * | proto: Fix a type-complexity warning.Nick Mathewson2023-08-142-9/+21
| | |
| * | proto: API to expose the `CircuitBinding` type.Nick Mathewson2023-08-144-5/+40
| | | | | | | | | | | | Closes #993
| * | proto: Take CircuitBinding one step forward into Reactor::add_hop.Nick Mathewson2023-08-144-10/+26
| | |
| * | proto: Add (not-yet-exposed) code to remember and use KH valuesNick Mathewson2023-08-145-16/+82
| | | | | | | | | | | | | | | | | | | | | | | | These values are computed as part of the circuit extension handshake, and are used as MAC keys to bind `ESTABLISH_INTRO` messages to a particular circuit so that they can't be replayed. Part of #993.
| * | cell: make establish_intro accept impl<Into<HsMacKey>>Nick Mathewson2023-08-142-15/+15
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This allows us to allow passing in opaque HsMacKey objects, rather than untyped byte slices. Additionally, we now check both MAC and signature unconditionally, to avoid the large timing side-channel. The small timing side-channel of combining booleans with `&` is considered safe. Part of #993.
| * | hscrypto: Expose hs_mac as a SimpleMac.Nick Mathewson2023-08-144-1/+19
| | |
| * | llcrypto: New SimpleMac traitNick Mathewson2023-08-143-0/+20
| | | | | | | | | | | | | | | | | | | | | | | | | | | This will be useful in preference to the regular Mac trait for the places where we need to pass a Mac key around, but we don't need to support incremental operation. Part of arti#993, where we want to expose a MAC object without exposing sensitive data.
| * | Wrap a long line in hscrypto/Cargo.toml.Nick Mathewson2023-08-141-1/+8
|/ /
* | Merge branch 'readme_timeline' into 'main'Nick Mathewson2023-08-131-2/+6
|\ \ | |/ |/| | | | | README: Note more details about upcoming milestones See merge request tpo/core/arti!1471
| * README: Note more details about upcoming milestonesNick Mathewson2023-08-041-2/+6
| |
* | Merge branch 'nogit' into 'main'gabi-2502023-08-091-1/+1
|\ \ | | | | | | | | | | | | CI: Remove unneeded install of git in maint-checks See merge request tpo/core/arti!1492
| * | CI: Remove unneeded install of git in maint-checksIan Jackson2023-08-091-1/+1
|/ / | | | | | | | | | | | | This was added in 9357a8fd6b22 "ci: add shebang to the GitLab CI" as part of !990 to the `maint-checks` job; but the actual additional check was added to the `doc-features` job (by mistake, fixed in !1490); and, that shebang check script doesn't need git anyway.
* | Merge branch 'shebang-ci' into 'main'Ian Jackson2023-08-091-1/+1
|\ \ | | | | | | | | | | | | ci: move shebang check into proper CI test See merge request tpo/core/arti!1490
| * | ci: move shebang check into proper CI testEmil Engler2023-08-091-1/+1
|/ / | | | | | | | | | | | | Currently, the shebang check CI is not executed, as it would need to fail then. See !1489
* | Merge branch 'relative-shebang-nodep' into 'main'gabi-2502023-08-091-1/+1
|\ \ | | | | | | | | | | | | maint: use relative shebang in `maint/bump_nodep` See merge request tpo/core/arti!1489
| * | maint: use relative shebang in `maint/bump_nodep`Emil Engler2023-08-091-1/+1
| | |
* | | Merge branch 'chutney' into 'main'Ian Jackson2023-08-091-0/+3
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Disable chutney test again Closes #810 See merge request tpo/core/arti!1488
| * | | Disable chutney test againIan Jackson2023-08-091-0/+3
| | | |
* | | | Merge branch 'tor-proto-incoming-discard' into 'main'Ian Jackson2023-08-092-21/+61
|\ \ \ \ | |_|/ / |/| | | | | | | | | | | tor-proto: Implement IncomingStream::discard() See merge request tpo/core/arti!1484
| * | | tor-proto: Make update_state() and discard() return Result<(), Bug>.Gabriela Moldovan2023-08-092-6/+6
| | | | | | | | | | | | | | | | These functions only ever return `Bug` errors.
| * | | tor-proto: Implement IncomingStream::discard().Gabriela Moldovan2023-08-082-2/+4
| | | |
| * | | tor-proto: Replace boolean flags with an IncomingStreamState enum.Gabriela Moldovan2023-08-081-18/+56
| |/ / | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit introduces an `IncomingStreamState` enum, which indicates whether the stream was accepted, discarded, or rejected, or if it is still pending. The `is_rejected`/`is_accepted` boolean flags are no longer needed. Without this change, we'd need to introduce yet another boolean flag when we implement `discard()` (for the "discarded" state).
* | | Merge branch 'key-uses' into 'main'Ian Jackson2023-08-091-0/+144
|\ \ \ | | | | | | | | | | | | | | | | key-management.md: Use scenarios See merge request tpo/core/arti!1445
| * | | key-management.md: Fix typosgabi-2502023-08-081-3/+3
| | | |
| * | | key-management.md: Use scenariosIan Jackson2023-07-281-0/+143
| | | |
| * | | key-management.md: Fix pandoc formattingIan Jackson2023-07-281-0/+1
| | | | | | | | | | | | | | | | Add a missing blank line.
* | | | Merge branch 'remove-keystore-fs-perm-variant' into 'main'Ian Jackson2023-08-092-13/+1
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | tor-error: Remove KeystoreFsPermissions variant. See merge request tpo/core/arti!1487
| * | | | tor-error: Remove KeystoreFsPermissions variant.Gabriela Moldovan2023-08-082-13/+1
| | |/ / | |/| | | | | | | | | | | | | | | | | | | | | | | | | | According to the `ErrorKind` lumping guidelines, `KeystoreFsPermissions` should be lumped with `FsPermissions`: they represent the same type of error, and their "location" is the same ("Host"). Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1315#note_2916455
* | | | Merge branch 'with_coverage-no-list' into 'main'Ian Jackson2023-08-091-2/+2
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | maint: provide no list of grcov formats See merge request tpo/core/arti!1482
| * | | | maint: provide no list of grcov formatsEmil Engler2023-08-081-2/+2
| |/ / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit removes a list we provide for the supported grcov formats. In my opinion, this is a practice of bad software engineering, as we would then have to maintain this list by ourselves. Therefore, this commit removes this list from the `maint/with_coverage` script and replaces it with a references to the accompanying grcov command.
* | | | Merge branch 'bridge-disabled' into 'main'Ian Jackson2023-08-081-3/+52
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | arti-client config: Fix bridge handling and test it Closes #1000 See merge request tpo/core/arti!1481
| * | | | bridge config: Fix an error message slightlyIan Jackson2023-08-081-1/+1
| | | | |
| * | | | arti-client config test: partially un-degrade formattingIan Jackson2023-08-081-10/+10
| | | | |
| * | | | arti-client config test: degrade formattingIan Jackson2023-08-081-12/+18
| | | | | | | | | | | | | | | | | | | | As demanded by rustfmt
| * | | | arti-client config: Add an extra test case for bridgesIan Jackson2023-08-081-0/+45
| | | | | | | | | | | | | | | | | | | | This complements the new `check_bridge_pt` test.
| * | | | bridge config: reject bridges=true when there are no bridgesIan Jackson2023-08-081-2/+0
| |/ / / | | | | | | | | | | | | This is a bugfix. Perhaps it is a security fix?
* | | | Merge branch 'coverage-fixes' into 'main'gabi-2502023-08-081-1/+2
|\ \ \ \ | |/ / / |/| | | | | | | | | | | maint: list the HTML dependencies in coverage See merge request tpo/core/arti!1485
| * | | maint: remove useless optargEmil Engler2023-08-081-1/+1
| | | | | | | | | | | | | | | | | | | | The `maint/coverage` script has a useless option `c`. This commit removes it.
| * | | maint: list the HTML dependencies in coverageEmil Engler2023-08-081-0/+1
|/ / / | | | | | | | | | | | | | | | | | | | | | Currently, the `maint/coverage` script does not inform about the dependencies required for generating the HTML output, those are, the Python packages `bs4` and `lxml`. This commit fixes that, by updating the help section accordingly.
* | | Merge branch 'tor-proto-incoming-todo' into 'main'gabi-2502023-08-081-18/+15
|\ \ \ | | | | | | | | | | | | | | | | tor-proto: Replace IncomingStreamMsg with IncomingStreamRequest. See merge request tpo/core/arti!1477
| * | | tor-proto: Replace IncomingStreamMsg with IncomingStreamRequest.Gabriela Moldovan2023-08-071-18/+15
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The two enums essentially serve the same purpose, so we don't need both of them. This also addresses the TODO that says we should return an error if `accept_data` is called for a RESOLVE stream.
* | | | Merge branch 'tor-proto-incoming-drop' into 'main'Ian Jackson2023-08-082-15/+77
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | tor-proto: Implement `Drop` for `IncomingStream`. See merge request tpo/core/arti!1476