summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | arti-client: Update docs to reflect KeystoreSelector renaming.Gabriela Moldovan2024-09-231-3/+3
| | | | |
| * | | | tor-keymgr: Rename the primary keystore for clarity.Gabriela Moldovan2024-09-2310-44/+46
|/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, arti's primary keystore was referred to as its "default" keystore. However, "default" is inaccurate here: there is no way to meaningfully override this "default" (the "default" store acts as the main keystore). Throughout the codebase, we query all keystores for keys (including the secondary ones), but only ever write to the default/primary keystore. This is OK for now, because it enables us to have one mutable keystore, and multiple secondary, read-only stores.
* | | | Merge branch 'bug_1610' into 'main'gabi-2502024-09-2312-50/+170
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bug 1610: Add support for constructing ArtiEphemeralKeystore to InertTorClient::create_keymgr() Closes #1610 See merge request tpo/core/arti!2394
| * | | | arti-client: added support for constructing ArtiEphemeralKeystore to ↵Morgan2024-09-201-22/+37
| | | | | | | | | | | | | | | | | | | | InertTorClient::create_keymgr()
| * | | | tor-keymgr: added dummy implementation of ArtiEphemeralKeyStoreMorgan2024-09-201-0/+14
| | | | |
| * | | | tor-keymgr: added support for specifying keystore kind to ArtiKeystoreConfigMorgan2024-09-205-18/+103
| | | | |
| * | | | tor-keymgr: renamed ArtiNativeKeystoreConfig to ArtiKeystoreConfigMorgan2024-09-206-11/+14
| | | | |
| * | | | arti-client: expose key-mgr/ephemeral-keystore feature in arti-clientMorgan2024-09-201-0/+3
| |/ / /
* | | | Merge branch 'shadow-chutney2' into 'main'gabi-2502024-09-235-35/+232
|\ \ \ \ | |/ / / |/| | | | | | | | | | | Add CI job integration-chutney-shadow See merge request tpo/core/arti!2427
| * | | CI: Only build shadow onceJim Newsome2024-09-181-51/+43
| | | |
| * | | Add ci job `integration-chutney-shadow`Jim Newsome2024-09-181-0/+56
| | | |
| * | | CI: Set up ~/src and ~/.local in before_scriptJim Newsome2024-09-181-5/+6
| | | | | | | | | | | | | | | | | | | | We'll want this in the shadow-chutney test too. No harm in just doing it for all jobs.
| * | | Add `tests/chutney/integration-e2e-shadow`Jim Newsome2024-09-182-0/+102
| | | | | | | | | | | | | | | | | | | | This is a wrapper script for running `tests/chutney/integration-e2e` under shadow.
| * | | chutney test: rework installation and tracking of chutney itselfJim Newsome2024-09-183-1/+25
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously `tests/chutney/setup` would locate *or install* chutney and set `CHUTNEY_PATH` for itself. However that `CHUTNEY_PATH` wasn't propagated to other steps or "up" to the new `integration-e2e` wrapper script. Tracking it in the arti.run along with other dynamic info lets us ensure we consistently use the same chutney across steps, and in the higher level `integration-e2e` script.
| * | | chutney test: add option to skip tests incompatible with shadowJim Newsome2024-09-181-5/+17
| | | |
| * | | chutney: don't hard-code expected IP address for example.comJim Newsome2024-09-181-2/+6
| | | | | | | | | | | | | | | | | | | | | | | | It looks like it changed at some point. Rather than hard-coding, just do the lookup locally and compare the tor-lookup result against that.
| * | | chutney test: move logic from .gitlab-ci.yml to integration-e2eJim Newsome2024-09-182-5/+11
| |/ / | | | | | | | | | | | | | | | | | | Having this in a script is a step towards being able to run exactly the same test under shadow without duplicating this high-level logic. It's also convenient for running the ci test locally.
* | | Merge branch 'rotate-keys' into 'main'gabi-2502024-09-2012-22/+323
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | arti: Add hsc subcommands for key rotation and deletion Closes #1475 See merge request tpo/core/arti!2435
| * | | arti: Tolerate lowercase "no" in confirmation prompt.Gabriela Moldovan2024-09-191-3/+7
| | | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2435#note_3080452
| * | | arti: Fix typo in display_service_discovery_key function name.Gabriela Moldovan2024-09-191-3/+3
| | | |
| * | | arti: Clarify what the client is supposed to do with the hsc key output.Gabriela Moldovan2024-09-191-0/+8
| | | |
| * | | arti: Document that "arti hsc" is experimental.Gabriela Moldovan2024-09-191-0/+3
| | | |
| * | | arti: Gate the arti hsc subcommand behind a new "hsc" feature (fmt).Gabriela Moldovan2024-09-191-4/+1
| | | |
| * | | arti: Gate the arti hsc subcommand behind a new "hsc" feature.Gabriela Moldovan2024-09-195-17/+9
| | | | | | | | | | | | | | | | This new feature is experimental.
| * | | arti: Omit the optional --key-type argument from the docs.Gabriela Moldovan2024-09-191-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | By default `--key-type` is set to `restricted-discovery` so it can omitted from these examples (omitting it makes the usage a bit clearer IMO).
| * | | arti: Document the commands for key removal and rotation.Gabriela Moldovan2024-09-191-1/+41
| | | |
| * | | arti: Add a test for the "hsc key" subcommand help output.Gabriela Moldovan2024-09-193-0/+19
| | | |
| * | | arti: Add a subcommand for removing a client discovery key.Gabriela Moldovan2024-09-191-0/+35
| | | | | | | | | | | | | | | | Closes #1475
| * | | arti: Add an hsc subcommand for rotating client keys.Gabriela Moldovan2024-09-193-0/+114
| | | | | | | | | | | | | | | | Part of #1475
| * | | arti: Move public key output logic to a separate function.Gabriela Moldovan2024-09-191-4/+13
| | | | | | | | | | | | | | | | | | | | This will be reused for `arti hsc key rotate`, which also outputs the public key.
| * | | arti-client: Add APIs for rotating service discovery keys.Gabriela Moldovan2024-09-191-0/+80
| | | |
* | | | Merge branch 'ticket1619_01' into 'main'gabi-2502024-09-191-8/+161
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | key-forge: Add curve25519 key wrapper macro Closes #1619 See merge request tpo/core/arti!2430
| * | | | key-forge: Add curve25519 key wrapper macroDavid Goulet2024-09-191-8/+161
|/ / / / | | | | | | | | | | | | | | | | | | | | Closes #1619 Signed-off-by: David Goulet <[email protected]>
* | | | Merge branch 'forge-macros' into 'main'David Goulet2024-09-195-48/+44
|\ \ \ \ | |/ / / |/| | | | | | | | | | | tor-key-forge: encapsulate `define_ed25519_keypair` macro dependencies See merge request tpo/core/arti!2433
| * | | tor-key-forge: encapsulate `define_ed25519_keypair` macro depsSteven Engler2024-09-185-48/+44
| |/ / | | | | | | | | | | | | | | | | | | | | | | | | This re-exports the types/traits needed by the `define_ed25519_keypair` macro so that the macro caller doesn't need to import a bunch of extra packages in its Cargo.toml that it doesn't use, and so that the caller doesn't need a `use prelude::*` before invoking the macro. This makes the macro nicer to use for the caller, and should prevent the macro from causing "cannot find ... in this scope" errors.
* | | Merge branch 'hsc-get-key' into 'main'Alexander Hansen Færøy2024-09-194-43/+88
|\ \ \ | |/ / |/| | | | | | | | arti: Add hsc key subcommand, deprecate hsc get-key. See merge request tpo/core/arti!2432
| * | arti: Satisfy clippy.Gabriela Moldovan2024-09-181-4/+4
| | |
| * | arti: Add hsc key subcommand, deprecate hsc get-key.Gabriela Moldovan2024-09-184-10/+39
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I am deprecating the old `hsc get-key` subcommand in favor of the new `hsc key get` subcommand. This is because I plan to implement the rest of the key management functionality (key deletion, rotation, etc.) as subcommands of the `hsc key` command. The alternative would be to add a new distinct top-level `hsc rotate-key`, `hsc remove-key`, etc. subcommand alongside the existing `hsc get-key` command (which IMO is less nice than the alternative I'm proposing).
| * | arti: Move the keygen-related args to a separate struct.Gabriela Moldovan2024-09-181-9/+17
| | | | | | | | | | | | These will be reused by a future `key rotate` subcommand.
| * | arti: Make sure we check the KeyType before running the command.Gabriela Moldovan2024-09-181-1/+5
| | | | | | | | | | | | | | | Otherwise, if/when we add support for other `KeyType`s we risk forgetting to update the rest of the implementation.
| * | arti: Move the shared arti hsc args to CommonArgs (fmt).Gabriela Moldovan2024-09-181-2/+4
| | |
| * | arti: Move the shared arti hsc args to CommonArgs.Gabriela Moldovan2024-09-181-16/+22
| | |
| * | arti: Move TorClient creation to the top-level (fmt).Gabriela Moldovan2024-09-181-4/+1
| | |
| * | arti: Move TorClient creation to the top-level.Gabriela Moldovan2024-09-181-8/+7
|/ / | | | | | | | | The client will be used by future subcommands too, not just `prepare_service_discovery_key`.
* | Merge branch 'ticket1604_01' into 'main'David Goulet2024-09-1815-22/+353
|\ \ | | | | | | | | | | | | | | | | | | relay: Declare keys and add a KeyMgr to TorRelay Closes #1604 See merge request tpo/core/arti!2411
| * | relay: Require keymgr feature from tor-keymgrDavid Goulet2024-09-181-1/+1
| | | | | | | | | | | | | | | | | | | | | A relay can't operate without a KeyMgr so enable it by default from the tor-keymgr crate. Signed-off-by: David Goulet <[email protected]>
| * | key-forge: Fix a comment with the wrong nameDavid Goulet2024-09-181-2/+2
| | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
| * | key-forge: Support extra docs and attributes to ed25519 keypairDavid Goulet2024-09-182-9/+19
| | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
| * | tor-keymgr: Set KeySpecifier deftly exported struct non_exhaustiveDavid Goulet2024-09-181-0/+1
| | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
| * | relay: Try to generate long-term identity keyDavid Goulet2024-09-183-5/+33
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | When creating the KeyMgr, attempt to create the long-term identity key if none are found in the KeyMgr. Until the KeyMgr has certificate support, we can't create the certificate. Add a TODO comment item about future work needed there. Related to #1604 Signed-off-by: David Goulet <[email protected]>