summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | Add KeyedFuturesUnorderedJim Newsome2024-08-012-0/+367
| | | | |
* | | | | Remove semver.md files post-release.Nick Mathewson2024-08-013-3/+0
|/ / / /
* | | | Merge branch 'changelog-1.2.6' into 'main'arti-v1.2.6Nick Mathewson2024-08-011-0/+187
|\ \ \ \ | |/ / / |/| | | | | | | | | | | Initial Changelog for 1.2.6 See merge request tpo/core/arti!2302
| * | | Re-run update-md-links.Nick Mathewson2024-08-011-1/+0
| | | |
| * | | Final (?) 1.2.6 changelog tweaksNick Mathewson2024-08-011-8/+5
| | | |
| * | | Apply 1 suggestion(s) to 1 file(s)Nick Mathewson2024-08-011-2/+2
| | | | | | | | | | | | Co-authored-by: gabi-250 <[email protected]>
| * | | Apply 1 suggestion(s) to 1 file(s)Nick Mathewson2024-08-011-1/+1
| | | | | | | | | | | | Co-authored-by: Ian Jackson <[email protected]>
| * | | changelog: add links.Nick Mathewson2024-08-011-6/+66
| | | |
| * | | Initial changelog for 1.2.6Nick Mathewson2024-08-011-0/+131
| | | |
* | | | Merge branch 'version-bumps-arti-v1.2.6' into 'main'Nick Mathewson2024-08-0151-570/+618
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | Version bumps for Arti 1.2.6 See merge request tpo/core/arti!2303
| * | | | Bump "arti" crate to 1.2.6Nick Mathewson2024-08-014-4/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Done with ``` cargo set-version --bump patch -p arti ```
| * | | | Bump versions for tor- and arti- crates to 0.21.0Nick Mathewson2024-08-0146-398/+398
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is the result of: ``` for crate in $( ./maint/list_crates |grep '^\(tor\|arti-\)' ); do cargo set-version -p $crate 0.21.0 done ```
| * | | | Run "cargo update" for crates/{equix/hashx}/bench.Nick Mathewson2024-08-012-162/+210
| | | | |
| * | | | Minor bumps on fslock-guard, fs-mistrust, equixNick Mathewson2024-08-014-6/+6
| |/ / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | No updates on their dependents, because: fslock-guard (only tests have changed) equix (only change is removal of a private constant) fs-mistrust (documentation, formatting, and use of Path::try_exists in tests)
* | | | Merge branch 'updates-20240801' into 'main'Nick Mathewson2024-08-011-251/+297
|\ \ \ \ | |/ / / |/| | | | | | | | | | | Run "cargo update" in preparation for release. See merge request tpo/core/arti!2300
| * | | Unpin ccIan Jackson2024-08-012-2/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | The previous commit added a pinned dep on cc 1.0.93, which we don't want. See also !2231
| * | | Cargo.lock: Downgrade cc againIan Jackson2024-08-012-10/+12
| | | | | | | | | | | | | | | | | | | | | | | | Roughly the same as 32a45edb84a210eb9fa692f7f339b2a0b20cb1c6. Add the line to arti's Cargo.toml for convenience for next time.
| * | | Run "cargo update" in preparation for release.Nick Mathewson2024-08-011-261/+307
|/ / /
* | | Merge branch 'fixup-features' into 'main'Nick Mathewson2024-08-013-3/+3
|\ \ \ | |/ / |/| | | | | | | | Run "fixup-features". See merge request tpo/core/arti!2299
| * | Run "fixup-features".Nick Mathewson2024-08-013-3/+3
|/ /
* | Merge branch 'rpc_ffi_beginnings' into 'main'Nick Mathewson2024-07-3116-31/+2137
|\ \ | | | | | | | | | | | | rpc: Initial core of an FFI interface. See merge request tpo/core/arti!2273
| * | ffi: Make "sealed" a little less effective.Nick Mathewson2024-07-311-7/+7
| | | | | | | | | | | | | | | Rust 1.70 (our MSRV) will not allow us to use a trait from a private module in this way, unfortunately.
| * | ffi: Re-run cbindgen.Nick Mathewson2024-07-312-23/+55
| | |
| * | ffi: Add some explicit ()s to prove they are there.Nick Mathewson2024-07-312-2/+6
| | |
| * | ffi: Document safety for each function using ffi_body_raw.Nick Mathewson2024-07-312-3/+17
| | |
| * | ffi: rename ffi_body_simple to ffi_body_rawNick Mathewson2024-07-313-18/+18
| | |
| * | ffi: Document rules for ensuring return valuesNick Mathewson2024-07-311-0/+13
| | |
| * | ffi: Clean up long lines and confusing expressions.Nick Mathewson2024-07-313-9/+18
| | |
| * | ffi: Clarify rules for *out pointers.Nick Mathewson2024-07-311-3/+5
| | | | | | | | | | | | Except for *error_out, they are always set to NULL on error.
| * | ffi: use void to omit unreachable "on invalid" blocksNick Mathewson2024-07-315-26/+60
| | |
| * | RPC: Re-wrap some macro definitions and usages.Nick Mathewson2024-07-311-14/+41
| | |
| * | ffi: Remove all non-opt conversionsNick Mathewson2024-07-313-206/+120
| | | | | | | | | | | | | | | | | | | | | Additionally, inline the related conversion functions. This should reduce the total amount of unsafe code that somebody would need to look at.
| * | ffi: Always abort on panic.Nick Mathewson2024-07-313-42/+13
| | |
| * | ffi: Document on-error behavior of consuming and setting.Nick Mathewson2024-07-311-0/+5
| | |
| * | ffi: Refactor @init macro expansions into new functions.Nick Mathewson2024-07-311-23/+102
| | | | | | | | | | | | (Documentation movement still needed.)
| * | ffi: Document internal ffi_initialize macro.Nick Mathewson2024-07-311-0/+14
| | |
| * | Apply suggestions about macro behavior, design, and usageNick Mathewson2024-07-311-0/+18
| | |
| * | Apply safety-related suggestions from DizietNick Mathewson2024-07-313-5/+18
| | |
| * | RPC FFI: Write a bit more text for the C no-UB requirements.Nick Mathewson2024-07-312-11/+26
| | | | | | | | | | | | | | | | | | | | | I got this by reading over all the relevant Rust stdlib safety documentation (now linked to in the macro definitions), and making sure that the C no-UB text is sufficient to guarantee that those requirements are met.
| * | ffi: Ensures every converter tries to run.Nick Mathewson2024-07-311-30/+55
| | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, some of our conversion macros tried to exit early with `?`. This is undesirable, since the OutPtr conversion has the side effect of writing NULL to a pointer (if it is present). Now, every conversion runs, and _then_ we exit with an error if any of them fails.
| * | Use macros to make FFI functions simpler to read and check.Nick Mathewson2024-07-313-145/+406
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | These macros do the only part of our FFI functions that needs to be `unsafe`: converting input pointers into types that can be used in safe rust. I've added documentation about what requirements each of these conversions puts onto out inputs: both informally, and via a reference to the relevant parts of the Rust library documentation. While doing this I found a safety bug in `OutPtr::from_opt_ptr`: it should have been using `MaybeUninit`. These macros should allow us to build a "proof sketch" for the safety of our FFI code. We need to show, for each input parameter: - That the documented requirements for its conversion method are also documented requirements for that kind of input, in our header file. - That the documented requirements for how it can be used after conversion are in fact followed in the code.
| * | rpc: Explain _why_ utf-8 in Utf8CString is a safety requirement.Nick Mathewson2024-07-311-0/+6
| | | | | | | | | | | | (and to what extent)
| * | Rename Utf8CStr=>Utf8CStringNick Mathewson2024-07-315-18/+18
| | |
| * | Copy suggestions from .h file to cbindgen.tomlNick Mathewson2024-07-311-7/+9
| | |
| * | Add a missing "-".Nick Mathewson2024-07-311-1/+1
| | |
| * | rpclib: Suggestions from @diziet for improving safety docs.Nick Mathewson2024-07-312-8/+11
| | |
| * | rpclib ffi: Grand identifier renamingNick Mathewson2024-07-315-71/+92
| | | | | | | | | | | | In brief: Everything now starts with ARTI_RPC, arti_rpc, or ArtiRpc.
| * | rpclib: Revise/condense "safety" docs for C functionsNick Mathewson2024-07-314-98/+78
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | These documents are no longer called "safety". They are now mostly collected as a big list of "correctness requirements" at the start of the cbindgen header. Because of these requirements, most functions no longer need their own "safety" sections. I am explicitly using `#[allow(clippy::missing_safety_doc)]` on each function, rather than adding a blanket exception: - There are other unsafe functions in this code, to which we wouldn't want an exception to apply. - Documenting the safety^W correctness requirements of a function is important enough to make sure that we aren't skipping out on it unintentionally.
| * | rpc: Rename OutPtr functions for clarityNick Mathewson2024-07-313-13/+13
| | |
| * | rpclib: Grand error refactoring: outparam, not thread-localNick Mathewson2024-07-316-155/+138
| | | | | | | | | | | | | | | | | | | | | | | | Per discussion, we'd rather have an optional output parameter for error objects rather than mess with thread-local variables. This is possibly less convenient for direct usage from C, but likely more convenient for wrapper functions in other languages.