summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | ffi: Document safety for each function using ffi_body_raw.Nick Mathewson2024-07-312-3/+17
| | |
| * | ffi: rename ffi_body_simple to ffi_body_rawNick Mathewson2024-07-313-18/+18
| | |
| * | ffi: Document rules for ensuring return valuesNick Mathewson2024-07-311-0/+13
| | |
| * | ffi: Clean up long lines and confusing expressions.Nick Mathewson2024-07-313-9/+18
| | |
| * | ffi: Clarify rules for *out pointers.Nick Mathewson2024-07-311-3/+5
| | | | | | | | | | | | Except for *error_out, they are always set to NULL on error.
| * | ffi: use void to omit unreachable "on invalid" blocksNick Mathewson2024-07-315-26/+60
| | |
| * | RPC: Re-wrap some macro definitions and usages.Nick Mathewson2024-07-311-14/+41
| | |
| * | ffi: Remove all non-opt conversionsNick Mathewson2024-07-313-206/+120
| | | | | | | | | | | | | | | | | | | | | Additionally, inline the related conversion functions. This should reduce the total amount of unsafe code that somebody would need to look at.
| * | ffi: Always abort on panic.Nick Mathewson2024-07-313-42/+13
| | |
| * | ffi: Document on-error behavior of consuming and setting.Nick Mathewson2024-07-311-0/+5
| | |
| * | ffi: Refactor @init macro expansions into new functions.Nick Mathewson2024-07-311-23/+102
| | | | | | | | | | | | (Documentation movement still needed.)
| * | ffi: Document internal ffi_initialize macro.Nick Mathewson2024-07-311-0/+14
| | |
| * | Apply suggestions about macro behavior, design, and usageNick Mathewson2024-07-311-0/+18
| | |
| * | Apply safety-related suggestions from DizietNick Mathewson2024-07-313-5/+18
| | |
| * | RPC FFI: Write a bit more text for the C no-UB requirements.Nick Mathewson2024-07-312-11/+26
| | | | | | | | | | | | | | | | | | | | | I got this by reading over all the relevant Rust stdlib safety documentation (now linked to in the macro definitions), and making sure that the C no-UB text is sufficient to guarantee that those requirements are met.
| * | ffi: Ensures every converter tries to run.Nick Mathewson2024-07-311-30/+55
| | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, some of our conversion macros tried to exit early with `?`. This is undesirable, since the OutPtr conversion has the side effect of writing NULL to a pointer (if it is present). Now, every conversion runs, and _then_ we exit with an error if any of them fails.
| * | Use macros to make FFI functions simpler to read and check.Nick Mathewson2024-07-313-145/+406
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | These macros do the only part of our FFI functions that needs to be `unsafe`: converting input pointers into types that can be used in safe rust. I've added documentation about what requirements each of these conversions puts onto out inputs: both informally, and via a reference to the relevant parts of the Rust library documentation. While doing this I found a safety bug in `OutPtr::from_opt_ptr`: it should have been using `MaybeUninit`. These macros should allow us to build a "proof sketch" for the safety of our FFI code. We need to show, for each input parameter: - That the documented requirements for its conversion method are also documented requirements for that kind of input, in our header file. - That the documented requirements for how it can be used after conversion are in fact followed in the code.
| * | rpc: Explain _why_ utf-8 in Utf8CString is a safety requirement.Nick Mathewson2024-07-311-0/+6
| | | | | | | | | | | | (and to what extent)
| * | Rename Utf8CStr=>Utf8CStringNick Mathewson2024-07-315-18/+18
| | |
| * | Copy suggestions from .h file to cbindgen.tomlNick Mathewson2024-07-311-7/+9
| | |
| * | Add a missing "-".Nick Mathewson2024-07-311-1/+1
| | |
| * | rpclib: Suggestions from @diziet for improving safety docs.Nick Mathewson2024-07-312-8/+11
| | |
| * | rpclib ffi: Grand identifier renamingNick Mathewson2024-07-315-71/+92
| | | | | | | | | | | | In brief: Everything now starts with ARTI_RPC, arti_rpc, or ArtiRpc.
| * | rpclib: Revise/condense "safety" docs for C functionsNick Mathewson2024-07-314-98/+78
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | These documents are no longer called "safety". They are now mostly collected as a big list of "correctness requirements" at the start of the cbindgen header. Because of these requirements, most functions no longer need their own "safety" sections. I am explicitly using `#[allow(clippy::missing_safety_doc)]` on each function, rather than adding a blanket exception: - There are other unsafe functions in this code, to which we wouldn't want an exception to apply. - Documenting the safety^W correctness requirements of a function is important enough to make sure that we aren't skipping out on it unintentionally.
| * | rpc: Rename OutPtr functions for clarityNick Mathewson2024-07-313-13/+13
| | |
| * | rpclib: Grand error refactoring: outparam, not thread-localNick Mathewson2024-07-316-155/+138
| | | | | | | | | | | | | | | | | | | | | | | | Per discussion, we'd rather have an optional output parameter for error objects rather than mess with thread-local variables. This is possibly less convenient for direct usage from C, but likely more convenient for wrapper functions in other languages.
| * | rpclib: _Sketch_ of string API.Nick Mathewson2024-07-316-40/+66
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | In this API, borrowed strings are `const char *`, and owned strings are `ArtiRpcStr *`. You can get the former from the latter with `arti_rpc_str_get()`, which returns a `const char *` in hopes that you will neither modify nor free() that `const char *` (Note that there are no places where string ownership needs to be passed into this library; and at present, there is only one case where it is passed out. I do not anticipate that we will need to do intake of owned strings. We will probably need to return these in a few more cases as we add more API surface.)
| * | rpclib: Add "STATUS" to status codes.Nick Mathewson2024-07-312-16/+16
| | |
| * | rpc: Improve documentation and strings for FFI status codes.Nick Mathewson2024-07-312-6/+54
| | |
| * | rpclib: Tweaks from review to header documentation.Nick Mathewson2024-07-312-6/+12
| | |
| * | rpc ffi: Try a more reference-driven approach to pointer handling.Nick Mathewson2024-07-315-31/+198
| | |
| * | Add a script to run cbindgen and check its outputs.Nick Mathewson2024-07-315-3/+550
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is a bit complicated since: - Using cbindgen with macro expansion requires a nightly rust: so, we have to look for one. - There are some cbindgen warnings which I cannot find any way to suppress, so instead of giving all warnings, it seems better to give a diff from the old list of warnings to the new list.
| * | rpc: Initial core of an FFI interface.Nick Mathewson2024-07-3110-6/+830
| | | | | | | | | | | | | | | | | | | | | | | | | | | This only covers the absolute minimal API in order to launch a connection and run simple requests, and it doesn't document anything nearly well enough. Nonetheless I think it's good enough for an initial review, to make sure that we've got the basics right (as well as a general consensus on the error handling API, naming, and so forth).
| * | RPC: Make message types able to be CStr or str.Nick Mathewson2024-07-313-22/+65
| | | | | | | | | | | | (Internally, it is a boxed CStr that is always UTF-8.)
* | | Merge branch 'ci-bis' into 'main'Nick Mathewson2024-07-311-11/+17
|\ \ \ | |/ / |/| | | | | | | | CI: Fix file overlap errors on main See merge request tpo/core/arti!2297
| * | CI: Only preserve rust-recent artifacts, don't process rust-latest onesIan Jackson2024-07-311-5/+5
| | | | | | | | | | | | | | | | | | | | | | | | The -latest jobs don't actually have artifacts. But: In the -latest jobs this can cause errors due to duplication: the artifacts from the -recent jobs in the same pipeline result in EEXIST errors.
| * | CI: Use YAML anchors rather than .extends for rust-recent/rust-latestIan Jackson2024-07-311-6/+12
|/ / | | | | | | | | This will let us make the artifact processing only happen when we want to save artifacts.
* | Merge branch 'bytemuck-update' into 'main'Ian Jackson2024-07-311-2/+2
|\ \ | | | | | | | | | | | | Update bytemuck to 1.16.3; previous version was yanked. See merge request tpo/core/arti!2294
| * | Update bytemuck to 1.16.3; previous version was yanked.Nick Mathewson2024-07-311-2/+2
|/ /
* | Merge branch 'sqlite-race' into 'main'gabi-2502024-07-312-9/+62
|\ \ | | | | | | | | | | | | | | | | | | tor-dirmgr: Return an error if storage is readonly and DB is missing/incompatbile. Closes #1497 See merge request tpo/core/arti!2283
| * | tor-dirmgr: Replace from_conn impl with a call to from_conn_internal helper.Gabriela Moldovan2024-07-301-7/+16
| | |
| * | tor-dirmgr: Return an error if storage is readonly and DB is ↵Gabriela Moldovan2024-07-302-14/+58
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | missing/incompatbile. This fixes a bug in `SqliteStore`'s constructor: previously, it would unconditionally try to create the missing database, even if it didn't have write access. As a result, it was impossible to reliably start multiple concurrent arti processes configured with the same (empty or nonexistent) cache_dir, because many of them would fail with errors such as ``` attempt to write a readonly database: Error code 8: Attempt to write a readonly database ``` Returning a `LocalResourceAlreadyInUse` error kind here enables us to leverage the retry loop from `TorClientBuilder::create_unbootstrapped` (which retries on local resource errors if `local_resource_timeout` is set). Closes #1497
* | | Merge branch 'cli-tests' into 'main'gabi-2502024-07-3134-0/+491
|\ \ \ | | | | | | | | | | | | | | | | | | | | | | | | arti: Add tests for the hss/hsc subcomands Closes #1250 See merge request tpo/core/arti!2275
| * | | CI: Add TODOs about rethinking matrix_test.Gabriela Moldovan2024-07-301-0/+9
| | | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2275#note_3054040
| * | | editorconfig: Ignore the files from the test state dirs.Gabriela Moldovan2024-07-301-0/+8
| | | |
| * | | arti: Add tests for the arti hsc subcommand.Gabriela Moldovan2024-07-3020-0/+146
| | | |
| * | | CI: Add cli-test job.Gabriela Moldovan2024-07-301-0/+11
| | | |
| * | | arti: Add tests for the arti hss subcommand.Gabriela Moldovan2024-07-3013-0/+317
| |/ / | | | | | | | | | Closes #1250
* | | Merge branch 'rtmock-doc' into 'main'Ian Jackson2024-07-301-3/+20
|\ \ \ | | | | | | | | | | | | | | | | tor-rtmock docs: Improve discussions of mocked time See merge request tpo/core/arti!2286
| * | | tor-rtmock docs: Add some more discussion of the simulated timeIan Jackson2024-07-301-1/+17
| | | |