summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | Tweak documentation for wait_for_stop slightly.Nick Mathewson2024-07-231-1/+7
|/ /
* | Merge branch 'expose-annotated' into 'main'Nick Mathewson2024-07-221-0/+15
|\ \ | | | | | | | | | | | | | | | | | | tor-netdoc: Dangerously expose annotation fields Closes #1469 See merge request tpo/core/arti!2213
| * | tor-netdoc: Dangerously expose annotation fieldsClara Engler2024-06-211-0/+15
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit exposes the fields of `routerdesc::AnnotatedRouterDesc` and `routerdesc::RouterAnnotation` with the enabled feature `dangerous-expose-struct-fields`. On one side, it achieves a greater consistency among the other structures found within this module; On the other side it makes the already public API (assuming the feature above is enabled) useable. Fixes #1469
* | | Merge branch 'openssl-bump' into 'main'Nick Mathewson2024-07-221-4/+4
|\ \ \ | | | | | | | | | | | | | | | | Bump openssl to 0.10.66 to satisfy cargo-audit. See merge request tpo/core/arti!2276
| * | | Bump openssl to 0.10.66 to satisfy cargo-audit.Gabriela Moldovan2024-07-221-4/+4
|/ / / | | | | | | | | | See RUSTSEC-2024-0357.
* | | Merge branch 'fix-keystore-contains' into 'main'gabi-2502024-07-221-16/+27
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-keymgr: Fix bug in ArtiNativeKeystore::contains Closes #1492 See merge request tpo/core/arti!2274
| * | | tor-keymgr: Fix ArtiNativeKeystore::contains() bug.Gabriela Moldovan2024-07-171-1/+9
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This fixes a bug in `ArtiNativeKeystore`'s `Keystore::contains()` implementation: previously, it called Path::exists() on the relative path (built by concatenating the key specifier and the extension), so unless your current directory happened to be the root of the keystore, `contains()` would always return `false`. `KeyMgr::generate` uses `Keystore::contains()` under the hood, so it was affected by this bug too: if called `overwrite = false`, it would misbehave and overwrite any existing keys. Internally, we call `KeyMgr::generate` in a couple of places: * `tor-hsservice/src/lib.rs`, to generate the `hsid` if it doesn't already exist. This callsite is not affected by the bug, because `KeyMgr::generate` is only called if `KeyMgr::get` returns `None` * `tor-hsservice/src/ipt_mgr.rs`, to generate `KS_hss_ntor` and `KS_hs_ipt_sid` keys for intro point establishment. This callsite is also not affected (because it too calls `get()` before attempting to `generate()`) The bug affects any downstream users that use `KeyMgr::generate` with a key manager backed by `ArtiNativeKeystore`. ------ `KeyMgr::get_or_generate` is not affected, even though it calls `Keymgr::generate` (it performs a separate extra check before calling `generate()`). (Both suffer from a known TOCTOU race, but that's a separate matter.) As an aside, I'd like to somehow unify `KeyMgr::get_or_generate` and `KeyMgr::get` (I've had some attempts in the past but ended up abandoning them because the result was more unergonomic than the existing APIs). Part of #1492
| * | | tor-keymgr: Rename function to clarify it returns a relative path (fmt).Gabriela Moldovan2024-07-171-1/+2
| | | |
| * | | tor-keymgr: Rename function to clarify it returns a relative path.Gabriela Moldovan2024-07-171-15/+15
| | | |
| * | | tor-keymgr: Add test for ArtiNativeKeystore::contains.Gabriela Moldovan2024-07-171-0/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This new assertion fails, because the implementation of `ArtiNativeKeystore::contains()` is buggy: it calls Path::exists() on the relative path built by concatenating the key specifier and the extension (so unless your current directory happens to be the root of the keystore, contains() is always going to return false). Part of #1492
* | | | Merge branch 'common' into 'main'Ian Jackson2024-07-1726-77/+721
|\ \ \ \ | |/ / / |/| | | | | | | | | | | | | | | | | | | Switch many scripts to rust-maint-common Closes #1300 and #1 See merge request tpo/core/arti!2267
| * | | maint/rust-maint-common/forbid-absolute-shebang: Fix error messageIan Jackson2024-07-171-1/+1
| | | |
| * | | Run update-shell-includes, to forbid cwd-dependent script includesIan Jackson2024-07-161-0/+1
| | | |
| * | | maint/common/update-shell-includes: Tolerate includes with a `$`Ian Jackson2024-07-161-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | These are not hardcoded, whatever they are, so they're not the principal thing we're trying to prevent. Previously, this would trip on this in arti.git:maint/cargo-publish: maint="$(dirname "$0")" ... # shellcheck source=maint/crates-io-utils.sh source "$maint/crates-io-utils.sh" Ideally we'd teach this script to be able to check and maintain includes for scripts that aren't in common/, but I think that's a task for another day.
| * | | Switch to maint/common/forbid-script-extensionsIan Jackson2024-07-162-39/+1
| | | |
| * | | Switch to maint/common/forbid-absolute-shebangsIan Jackson2024-07-162-11/+1
| | | |
| * | | maint/common/forbid-absolute-shebansg: Fix error handlingIan Jackson2024-07-161-4/+15
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | set -o pipefail is defused by the if. And we should properly check the expected statuses from git. If git isn't found, this script would otherwise spuriously think everything is fine.
| * | | CI: maint-checks job: Install gitIan Jackson2024-07-161-1/+1
| | | | | | | | | | | | | | | | Without this, maint/shebang is broken.
| * | | maint scripts: Fix some absolute shebangsIan Jackson2024-07-162-2/+2
| | | |
| * | | Use maint/common/apt-install instead of open-coding (multiline)Ian Jackson2024-07-161-10/+8
| | | |
| * | | Use maint/common/apt-install instead of open-coding (apt-get)Ian Jackson2024-07-161-8/+8
| | | |
| * | | maint/common/apt-install: Don't repeat apt-get updateIan Jackson2024-07-161-1/+9
| | | |
| * | | maint/common/apt-install: Use `apt-get install`Ian Jackson2024-07-161-1/+1
| | | | | | | | | | | | | | | | | | | | This changes from `apt install` (which is not supposed to be used in scripts) to `apt-get install`.
| * | | Use maint/common/apt-install instead of open-coding (apt)Ian Jackson2024-07-161-3/+3
| | | |
| * | | Switch to maint/common/via-cargo-install-in-ciIan Jackson2024-07-162-24/+4
| | | | | | | | | | | | | | | | And delete our old version of the script.
| * | | Aet maint/via-cargo-install-in-ci.cache-idIan Jackson2024-07-161-0/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | See docs in maint/common/via-cargo-install-in-ci This is not the same id as in our maint/via-cargo-install-in-ci, which is deliberate. Let's flush this cache, just in case.
| * | | via-cargo-install-in-ci: Split a multi-package invocationIan Jackson2024-07-161-1/+2
| | | | | | | | | | | | | | | | We're about to switch to a version that doesn't support this.
| * | | Replace maint/shellcheck_all with maint/common/shellcheck-allIan Jackson2024-07-164-12/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * Change all in-tree reference * Delete our copy of script, which now lives in the rust-maint-common subtree. * Leave a symlink behind, so that old git hooks that people (IMO possibly unwisely) installed, still work.
| * | | Add symlink to rust-maint-commonIan Jackson2024-07-161-0/+1
| | | | | | | | | | | | | | | | As recommended by the README there
| * | | Add 'maint/rust-maint-common/' from commit ↵Ian Jackson2024-07-1616-0/+698
| |\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | 'be8ec72c0b0ced653c618af564387079d9ea8e5f' git-subtree-dir: maint/rust-maint-common git-subtree-mainline: c05af7edf8f715b31d90d128ba6078a8094f440c git-subtree-split: be8ec72c0b0ced653c618af564387079d9ea8e5f
| | * \ \ Merge branch 'for-every-commit' into 'main'Nick Mathewson2024-07-157-0/+230
| | |\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | for-every-commit: Copy from derive-deftly See merge request tpo/core/rust-maint-common!5
| | | * | | apt-install: Use new include stanzaIan Jackson2024-07-151-1/+6
| | | | | |
| | | * | | for-every-commit: Make test project publish = falseIan Jackson2024-07-151-0/+1
| | | | | |
| | | * | | for-every-commit: Use new stanza for bash-utils includeIan Jackson2024-07-151-1/+6
| | | | | | | | | | | | | | | | | | | | | | | | Resolves semantic conflict with !7
| | | * | | for-every-commit: Fix shellcheck complaintsIan Jackson2024-07-151-7/+6
| | | | | |
| | | * | | for-every-commit: use env-based shebangIan Jackson2024-07-151-1/+1
| | | | | |
| | | * | | for-every-commit: Test in CIIan Jackson2024-07-151-0/+6
| | | | | |
| | | * | | for-every-commit: Document need for libtoml-perlIan Jackson2024-07-151-0/+3
| | | | | |
| | | * | | apt-install: New scriptIan Jackson2024-07-152-0/+19
| | | | | | | | | | | | | | | | | | | | | | | | This rune appears *so much*!
| | | * | | test-project: Add maint/Ian Jackson2024-07-151-0/+1
| | | | | |
| | | * | | test-project: Add url to Cargo.tomlIan Jackson2024-07-151-0/+1
| | | | | |
| | | * | | test-project: Add, by running cargo initIan Jackson2024-07-152-0/+9
| | | | | |
| | | * | | for-every-commit: Reject attempts at passing optionsIan Jackson2024-07-152-1/+12
| | | | | |
| | | * | | for-every-commit: Write a correct head commentIan Jackson2024-07-151-3/+16
| | | | | |
| | | * | | for-every-commit: Copy from derive-deftlyIan Jackson2024-07-151-0/+157
| | |/ / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is definitely the most sophisticated version of this script, which also exists in rust-pwd-grp and maybe elsewhere. The head comment is garbage. Copied from derive-deftly.git#f71bf71c913acc23286a828a8ea51c708b4c88ed
| | * | | Merge branch 'include-nuggets' into 'main'Nick Mathewson2024-07-157-6/+153
| | |\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Use non-cwd-relative $0-based includes in shell scripts Closes #1 See merge request tpo/core/rust-maint-common!7
| | | * | | Placate shellcheckIan Jackson2024-07-151-0/+1
| | | | | |
| | | * | | Do not use -- on $0. (update all scripts)Ian Jackson2024-07-154-8/+8
| | | | | |
| | | * | | Do not use -- on $0.Ian Jackson2024-07-151-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Apparently Alpine's realpath(1) (and presumably its dirname(1)) don't understand it. In 2024!
| | | * | | Run update-shell-includes in CIIan Jackson2024-07-151-0/+1
| | | | | |