summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * keymgr: Split out ArtiPathError from KeyPathErrorGabriela Moldovan2026-01-065-27/+44
| | | | | | | | | | This makes the error handling around `KeyPath`s a bit more sensible, IMO, and it will make it easier to extend it for `CTorPath` errors.
| * keymgr: Make describe_via_components() return BugGabriela Moldovan2026-01-061-1/+1
| | | | | | | | This never returns any other type of error.
| * keymgr: Move Unrecognized errors out of KeyPathError (fmt)Gabriela Moldovan2026-01-061-3/+3
| |
| * keymgr: Move Unrecognized errors out of KeyPathErrorGabriela Moldovan2026-01-066-20/+18
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Out of all the variants in `KeyPathError`, `Unrecognized` is the odd one out, because unlike the others, which are mainly just lower level parsing errors, `Unrecognized` is a higher level error constructed in `KeyMgr::describe()`. `KeyMgr::describe()` now returns an `Option`, because * the failure to describe a user provided `KeyPath` may or may not be an error * previously, `describe()` would only ever return `Ok` or `Err(KeyPathError::Unrecognized)`, which essentially a binary result. Also, `describe()` would never return any of the other `KeyPathError` kinds, which further suggests `Unrecognized` doesn't belong there The `Unrecognized` variant still exists, but is now part of `KeystoreCorruptionError`, (returned from `KeyMgr::validate_entry_integrity()`).
| * keymgr: Fix clippy warning when KeySpecifier is used in tor-keymgrGabriela Moldovan2026-01-061-0/+1
| | | | | | | | | | | | | | | | | | If you try to use this macro within `tor-keymgr` (as we do in the tests), clippy complains about the unreachable catch-all branch for `KeyPath`s (we can't get rid of the catch-all, because outside of `tor-keymgr` KeyPath` is non-exhaustive; but we should probably just go ahead and make `KeyPath` exhaustive at this point, because it's very unlikely it will ever grow new variants).
| * proto: Use describe() unconditionally in validate_entry_integrity()Gabriela Moldovan2026-01-061-12/+5
| | | | | | | | | | `KeyMgr::describe()` now works for `CTorPath`s too, so the key path validation can be the same as for `ArtiPath`s.
| * keymgr: Update expected output in integration testsGabriela Moldovan2026-01-061-6/+6
| | | | | | | | | | C Tor keystore entries now use the same output format as the non-C Tor entries.
| * keymgr: Update test d-d macro with new ctor_path functionsGabriela Moldovan2026-01-061-17/+24
| |
| * arti: Remove no-longer needed helper functionGabriela Moldovan2026-01-061-23/+18
| | | | | | | | This folds `display_arti_entry()` into `display_entry()`.
| * arti: Remove special handling for C Tor keys (fmt)Gabriela Moldovan2026-01-061-4/+1
| |
| * arti: Remove special handling for C Tor keysGabriela Moldovan2026-01-061-40/+2
| | | | | | | | | | | | | | | | | | | | This is no longer needed now that `KeyMgr::describe()` works on `CTorPath`s. Removing this special handling has the added bonus that the keymgr CLI output is now uniform for all keystores (before this change, `keys list` used a slightly different output format for displaying C Tor entries). The corresponding tests will be updated in a future commit.
| * keymgr: Specify ctor conversion functions as moduleGabriela Moldovan2026-01-063-71/+78
| | | | | | | | | | | | | | This is similar to `#[serde(with = "...")]`, and feels a bit nicer than having to specify two separate functions for the conversions (because with two separate functions, you *can* technically only specify one of them, which shouldn't be allowed).
| * keymgr: Extend KeySpecifier macro to support CTorPath conversionsGabriela Moldovan2026-01-063-5/+78
| | | | | | | | | | This enables us to implement `KeyMgr::describe()`, which relies on the ability to extract the key specifier of the key from its `KeyPath`.
| * keymgr: Make parse_key_path() only parse ArtiPathsGabriela Moldovan2026-01-061-18/+23
|/ | | | | | Unlike `ArtiPath`s, C Tor paths don't need to be parsed, because we have a predefined list of allowed C Tor paths (`CTorPath` is an enum with variants for each supported key type).
* Merge branch 'authcert' into 'main'Ian Jackson2026-01-0612-478/+391
|\ | | | | | | | | tor-netdoc: Replace AuthCert with the version from tmp See merge request tpo/core/arti!3555
| * tor-netdoc: authcert: Fix wrong linkIan Jackson2026-01-061-1/+1
| |
| * tor-netdoc: authcert: Add TODO about constructorsIan Jackson2026-01-061-0/+2
| |
| * tor-netdoc: authcert: rustfmtIan Jackson2026-01-061-5/+5
| |
| * tor-netdoc: authcert: Delete syntax info from rustdocsIan Jackson2026-01-061-37/+2
| | | | | | | | | | This is in the spec. I don't think it is a great idea to duplicate it here.
| * tor-netdoc: authcert: Fix remaining old names/paths in docsIan Jackson2026-01-061-8/+8
| | | | | | | | | | These names came from tmp, and we renamed things as we went, but didn't change the docs everywhere.
| * tor-netdoc: authcert: Improve docs for CrossCertIan Jackson2026-01-061-13/+12
| | | | | | | | Fix the type names while we're here.
| * tor-netdoc: authcert: rename tmp test moduleIan Jackson2026-01-061-1/+1
| | | | | | | | This module is now the "proper" tests for the parse2 impl on AuthCert.
| * tor-netdoc: authcert: abolish tmp module (reindent)Ian Jackson2026-01-061-50/+50
| |
| * tor-netdoc: authcert: abolish tmp moduleIan Jackson2026-01-061-140/+14
| | | | | | | | | | | | | | | | | | | | | | tmp's version of AuthCert is gone. Each of its fields is already in AuthCert, including the docs links. I've decided not to transfer the syntax snippets. The remaining function in that module is now an inherent method on AuthCert, not on tmp's version. This needs reformatting since verify_self_signed is now at the wrong level!
| * tor-netdoc: authcert: derive PartialEq and Eq in testsIan Jackson2026-01-061-0/+1
| | | | | | | | | | It's not clear that we want to expose these impls, but our existing tests (in test::tmp) want them.
| * tor-netdoc: authcert: Transfer spec links into AuthCert from tmpIan Jackson2026-01-061-28/+14
| |
| * tor-netdoc: authcert: derive parse2Ian Jackson2026-01-062-1/+13
| |
| * tor-netdoc: authcert: Add CrossCert to AuthCertIan Jackson2026-01-062-2/+19
| | | | | | | | This will enable parse2 to process it.
| * tor-netdoc: authcert: Move signatures out of tmp (fmt)Ian Jackson2026-01-061-2/+2
| |
| * tor-netdoc: authcert: Move signatures out of tmpIan Jackson2026-01-061-68/+79
| |
| * tor-netdoc: authcert: Move CrossCert out of tmpIan Jackson2026-01-062-86/+99
| | | | | | | | | | | | | | | | We can call this type authcert::CrossCert. The names in the docs are getting rather wrong, and right now the docs build produces warnings. We'll tidy all that at the end after we're done moving and renaming.
| * tor-netdoc: authcert: Rename verify_selfcert to verify_self_signedIan Jackson2026-01-061-14/+14
| | | | | | | | | | | | The distinction is: `verify_selfcert` sounds like it only verifies the self certificate. `veriify_self_signed` completely verifies a document, albeit one that is expected to be self-signed.
| * tor-netdoc: authcert: Move AuthCertVersion out of tmpIan Jackson2026-01-062-20/+31
| | | | | | | | | | Let's keep the existing name `AuthCert` in authcert.rs, so we want to rename this from DirKeyCertificateVersion, while we move it.
| * tor-netdoc: authcert: Make all fields pubIan Jackson2026-01-061-7/+7
| | | | | | | | This is our new style. Now there's no known-dead code.
| * tor-netdoc: authcert: Use Iso8601TimeSp for time fieldsIan Jackson2026-01-062-11/+11
| | | | | | | | This will let the parse2 derive work properly.
| * tor-netdoc: authcert: Shuffle fingerprint values aboutIan Jackson2026-01-062-19/+11
| | | | | | | | | | | | | | | | | | Make AuthCert look like the network document. This means removing its stored copy of H(KP_auth_sign_rsa), which it previously had via the embedded AuthCertKeyIds. We reculculate it as needed in AuthCert::key_ids().
| * tor-netdoc: authcert: Abolish AuthCert::sk_fingerprintIan Jackson2026-01-062-6/+2
| | | | | | | | There are no in-tree callers.
| * tor-netdoc: authcert: Make key_ids return owned AuthCertKeyIdsIan Jackson2026-01-065-10/+11
| | | | | | | | | | AuthCert is about to lose its copy of H(KP_auth_sign_rsa) so it needs to return an owned value.
| * tor-netdoc: RSA: check exponent and min size in parse2Ian Jackson2026-01-062-1/+24
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | According to the spec we always use this fixed exponent, and we have a minimum size of 1024. This is checked adhoc in the old parser with some slight assistance from what is now `RsaPublicParse1Helper`. It's not clear to me that checking the exponent is actually a good idea. I think checking the size is probably a bad idea, and if it is a good idea then 1024 is clearly too short. But rather than revisit these questions, let's reproduce the old behaviour in parse2. In parse2 these checks should be features of the type.
| * tor-netdoc: RSA: rename helper type to RsaPublicParse1HelperIan Jackson2026-01-064-15/+18
| | | | | | | | | | | | This is used by the old parsing code, apparently as a thing to hang the checking methods off. It is confusing to have so many different RSA types! Let's at least rename this one.
| * tor-netdoc: authcert: Improve docs a bitIan Jackson2026-01-061-5/+12
| | | | | | | | Spec links from the tmp module will be added later.
| * tor-netdoc: authcert: Rename fields in AuthCert to match the specIan Jackson2026-01-062-39/+39
| |
| * tor-netdoc: authcert: Reorder fields in AuthCert to match the specIan Jackson2026-01-061-4/+4
|/
* Merge branch 'web-docs' into 'main'Alexander Hansen Færøy2026-01-056-16/+27
|\ | | | | | | | | web: Miscallaneous improvements See merge request tpo/core/arti!3559
| * web: add warning about `--no-default-features`Steven Engler2026-01-051-0/+8
| |
| * web: fixed typoSteven Engler2026-01-051-1/+1
| |
| * web: move `--` in commandSteven Engler2026-01-051-1/+1
| | | | | | | | | | I think that the `--` separator should go before any arti-specific args, which includes the arti subcommand.
| * web: don't recommend `--all-features`Steven Engler2026-01-051-1/+1
| | | | | | | | This enables experimental features.
| * web: reword some textSteven Engler2026-01-051-9/+8
| | | | | | | | | | | | Opinionated changes trying to make it more accurate and less cheesy. Further changes would be nice, but I'm trying not to go overboard here.
| * web: try to update some things that are out of dateSteven Engler2026-01-053-5/+9
| |