summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | tor-rtmock: Avoid misleading task dumps by careful drop sequencingIan Jackson2025-01-151-9/+34
| | |
| * | tor-rtmock: Add some more tracing / debug outputIan Jackson2025-01-151-1/+9
| | |
| * | tor-rtmock: Explain a difficulty with test trace outputIan Jackson2025-01-151-0/+5
| | |
| * | tor-proto: Add traced_test to test casesIan Jackson2025-01-153-0/+23
|/ / | | | | | | (We don't add it to the handful of unit tests that don't use an executor.)
* | Merge branch 'mistrust-fileaccess' into 'main'Nick Mathewson2025-01-143-92/+518
|\ \ | |/ |/| | | | | | | | | fs-mistrust: Facilities for file access Closes #1746 See merge request tpo/core/arti!2707
| * file_access: Refactor APIs to consume self.Nick Mathewson2025-01-141-7/+16
| | | | | | | | | | This approach makes it even less likely for people to store a FileAccess for repeated use.
| * file_access: Make link-following behavior explicitly controlled.Nick Mathewson2025-01-141-8/+38
| |
| * Documentation fixes from GabiNick Mathewson2025-01-141-5/+3
| |
| * fs-mistrust: Try more to explain what FileAccess is for.Nick Mathewson2025-01-141-3/+7
| |
| * fs-mistrust: Follow symlinks when using file-access outside a CheckedDir.Nick Mathewson2025-01-141-9/+98
| | | | | | | | | | | | When we're not bound to a CheckedDir, it doesn't make sense to forbid following symlinks, so long as their targets are also sensible.
| * fs-mistrust: Add FileAccess for Verifier (and Mistrust).Nick Mathewson2025-01-142-9/+42
| |
| * fs-mistrust: Have Verifier check methods take self by reference.Nick Mathewson2025-01-141-2/+2
| | | | | | | | There is no reason for these to consume self.
| * fs-mistrust: Add ability to create files with chosen mode.Nick Mathewson2025-01-141-10/+117
| |
| * fs-mistrust: Clean up documentation.Nick Mathewson2025-01-141-15/+13
| |
| * fs-mistrust: Move file access methods on CheckedDir to FileAccess.Nick Mathewson2025-01-142-69/+168
| | | | | | | | | | These are the methods which we'd like to give new options in #1746; we can move other methods later if we want to.
| * fs-mistrust: Define a (stub) FileAccess type.Nick Mathewson2025-01-143-0/+38
| | | | | | | | | | We're going to move functionality and configuration functions here to implement #1746.
| * fs-mistrust::CheckedDir: Refactor some common code.Nick Mathewson2025-01-141-22/+32
| |
| * fs-mistrust: Add test for (not) opening symlink from CheckedDir.Nick Mathewson2025-01-141-1/+10
| |
| * fs-mistrust: clarify doc for a private function.Nick Mathewson2025-01-141-0/+2
| |
* | Merge branch 'relay-bin-3' into 'main'opara2025-01-144-4/+105
|\ \ | |/ |/| | | | | arti-relay: add lints See merge request tpo/core/arti!2708
| * arti-relay: fix rust/clippy lintsSteven Engler2025-01-144-4/+34
| |
| * arti-relay: add rust/clippy lintsSteven Engler2025-01-143-0/+71
|/
* Merge branch 'parse-unparsed-cert-2' into 'main'David Goulet2025-01-1319-97/+480
|\ | | | | | | | | | | | | tor-relay-crypto Add high-level cert types implementing ToEncodableCert Closes #1777 See merge request tpo/core/arti!2672
| * tor-key-forge: Add missing semver.md entries.Gabriela Moldovan2025-01-131-0/+3
| |
| * tor-relay-crypto: Remove TODO about validating cert extensions.Gabriela Moldovan2025-01-131-2/+0
| | | | | | | | | | | | | | There is no need for validation here. If any validation is required, it will be handled by the calling code. Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2672?commit_id=10845d5e6a06d4d9548d536846eb470128d8a7d4#note_3147517
| * tor-key-forge: Remove no longer needed ItemType impl for KeyUnknownCert.Gabriela Moldovan2025-01-131-9/+0
| | | | | | | | | | No longer used, because we're now using `ParsedEd25519Cert` instead of `KeyUnknownCert` to represent parsed but not yet validated certs.
| * tor-keymgr: Use ParsedEd25519Cert when decoding certs.Gabriela Moldovan2025-01-133-12/+13
| | | | | | | | | | | | | | This helps us get rid of our uses of `KeyUnknownCert`. Needed because `KeyUnknownCert` can't readily be converted back to `EncodedEd25519Cert` (while `ParsedEd25519Cert` *can* -- see the `certs` module from `tor-relay-crypto`).
| * tor-relay-crypto: Use the new cert_type() function to get the cert type.Gabriela Moldovan2025-01-131-2/+8
| |
| * tor-relay-crypto: Use the high-level cert types instead of EncodedEd25519Cert.Gabriela Moldovan2025-01-131-2/+4
| | | | | | | | | | | | | | This will come in handy later on, when we start using these function in conjunction with `KeyMgr::get_or_generate_key_and_cert`, which expects the `make_certificate` callback to return a type that implements `ToEncodableCert`.
| * tor-relay-crypto: Implement ToEncodableCert for the relay cert types.Gabriela Moldovan2025-01-133-0/+94
| | | | | | | | Closes #1777
| * tor-relay-crypto: Add high-level cert types.Gabriela Moldovan2025-01-132-1/+41
| | | | | | | | | | | | These will be the `ToEncodableCert`s we write to the keystore. Part of #1777
| * tor-key-forge: Implement ItemType for ParsedEd25519Cert.Gabriela Moldovan2025-01-131-0/+9
| | | | | | | | | | This will enable us to retrieve it from the keystore as an `ErasedKey` (side note, we should rename `ErasedKey` to `ErasedItem`).
| * tor-key-forge: Add wrappers for various cert types.Gabriela Moldovan2025-01-132-3/+115
| |
| * tor-key-forge: Fill out the InvalidCertError type.Gabriela Moldovan2025-01-133-1/+21
| | | | | | | | We'll soon use this.
| * tor-cert: Add experimental API for building EncodedEd25519Certs.Gabriela Moldovan2025-01-131-0/+17
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This will enable us to deserialize byte slices as `EncodedEd25519Certs`. Needed because this type will be used to representing a parsed + validated cert retrieved from the keystore. Technically, we *could* do without this function by defining a separate newtype wrapper over `Vec<u8>` to represent the validated cert data, but IMO adding a second encoded ed25519 cert type in another crate might be confusing later down the line (because the two types will be nearly identical, and are bound to eventually diverge in terms of API and implementation). Part of #1137
| * tor-keymgr: Fix cert handling tests.Gabriela Moldovan2025-01-134-25/+66
| | | | | | | | | | | | This updates and reenables the cert management tests. Part of #1768
| * tor-key-forge: Fix typo in doc comment.Gabriela Moldovan2025-01-131-1/+1
| |
| * tor-cert: Remove no-longer-needed experimental API.Gabriela Moldovan2025-01-131-12/+0
| | | | | | | | Part of #1768
| * tor-keymgr: Use Ed25519Cert::decode to parse the certs.Gabriela Moldovan2025-01-134-4/+18
| |
| * tor-keymgr: Add cert parse error variant.Gabriela Moldovan2025-01-135-2/+22
| | | | | | | | | | | | | | This will soon be used, when we modify the `ArtiNativeKeystore` cert lookup code to actually parse certificates before returning them. Part of #1768
| * tor-key-forge: Add ItemType impl for KeyUnknownCert.Gabriela Moldovan2025-01-131-0/+9
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | `KeyUnknownCert` will soon be used as the `ToEncodableCert::ParsedCert` type for Tor ed25519 certs. For example, the `ToEncodableCert` impl for `RelaySigningKeyCert` will look like this: ```rust pub struct RelaySigningKeyCert(EncodedEd25519Cert); impl ToEncodableCert<RelaySigningKeypair> for RelaySigningKeyCert { type ParsedCert = KeyUnknownCert; type EncodableCert = EncodedEd25519Cert; type SigningKey = RelayIdentityKeypair; fn validate( cert: Self::ParsedCert, subject: &RelaySigningKeypair, signed_with: &Self::SigningKey, ) -> Result<Self, InvalidCertError> { // TODO: validate `KeyUnknownCert` // and convert it to an EncodedEd25519Cert // (we don't yet an easy way to perform this conversion) } fn to_encodable_cert(self) -> Self::EncodableCert { self.0 } } ```
| * tor-key-forge: Split out ItemType as a separate trait.Gabriela Moldovan2025-01-137-28/+57
| | | | | | | | | | | | | | | | This is necessary because `ParsedCert`s will not be `EncodableItem`s. This is because we cannot (and don't want to) write certificates that have not yet been validated to the keystore. They do need to be retrievable from the keystore though, so we also change `ErasedKey` to be `Box<dyn ItemType>` instead.
| * tor-key-forge: Distinguish between parsed certs and encodable certs.Gabriela Moldovan2025-01-132-12/+16
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We need two different types to represent * certs that have been parsed, but not yet validated (`KeyUnknownCert`) * newly generated encodable certs (`EncodedEd25519Cert`) Currently, we don't use `KeyUnknownCert` anywhere, and instead use `EncodedEd25519Cert` to represent "parsed" but not-yet-validated certs. This approach is wrong and relies on a broken (no-op) `EncodedEd25519Cert::from_bytes` implementation. A future commit will address this problem by replacing `EncodedEd25519Cert::from_bytes` with `Ed25519Cert::decode` to actually parse the cert upon retrieving it from the keystore.
| * tor-keymgr: Replace from_encodable_cert with validation function.Gabriela Moldovan2025-01-132-22/+7
| | | | | | | | | | | | | | | | In practice, we won't be able to obtain an `ToEncodableCert` type from an `EncodableItem` cert without validating it first, so we need to collapse `validate` into `from_encodable_cert`. Part of #1768
| * tor-key-forge: Export some additional tor-cert types.Gabriela Moldovan2025-01-131-3/+3
|/ | | | This will soon be used.
* Merge branch 'relay-bin-3' into 'main'opara2025-01-137-149/+465
|\ | | | | | | | | arti-relay: improve cli and add config loading See merge request tpo/core/arti!2699
| * arti-relay: don't use environment var in `Mistrust`Steven Engler2025-01-132-26/+4
| |
| * arti-relay: remove `TorRelayConfigBuilder::from_directories`Steven Engler2025-01-131-27/+0
| | | | | | | | | | I don't think we'll ever need this. Users will set the directories through the config file.
| * arti-relay: add basic placeholder loggerSteven Engler2025-01-131-4/+61
| | | | | | | | | | This is probably not what the final logger would look like, but it's a fine placeholder for now.
| * arti-relay: add config loadingSteven Engler2025-01-132-13/+47
| |