summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | | | tor-netdoc: routerstatus: r item: add blank lines to structIan Jackson2026-06-111-0/+5
| |/ / / / /
* | | | | | Merge branch 'rd-item-present' into 'main'Clara Engler2026-06-112-4/+33
|\ \ \ \ \ \ | |/ / / / / |/| | | | | | | | | | | | | | | | | Utilize ItemPresent in RouterDesc See merge request tpo/core/arti!4080
| * | | | | tor-netdoc: Add RouterDesc::hidden_serive_dirClara Engler2026-06-112-0/+14
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Adds RouterDesc::hidden_service_dir as well as an accompanying ZST token.
| * | | | | tor-netdoc: Replace bool with ItemPresent in RouterDesc (fmt)Clara Engler2026-06-111-1/+2
| | | | | | | | | | | | | | | | | | | | | | | | No functional change.
| * | | | | tor-netdoc: Replace bool with ItemPresent in RouterDescClara Engler2026-06-112-4/+18
|/ / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit modifies RouterDesc to replace all occurrences of `bool` with `Option<ItemPresent<T>>` while adding respective ZST tokens for the respective items. In this case, it adjusts caches_extra_info and tunnelled_dir_server.
* | | | | Merge branch 'ntor-crosscert' into 'main'Clara Engler2026-06-114-40/+279
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Add Ed25519NtorCrossCert See merge request tpo/core/arti!4022
| * | | | | tor-netdoc: Specify requires_signed_with_ext in ed25519_cert_invalidClara Engler2026-06-111-6/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds an argument to the generic test specifying whether the type requires the respective extension or not, in order to replace a clumsy std::any solution.
| * | | | | tor-netdoc: Add TODO for merging generic test functionsClara Engler2026-06-111-0/+2
| | | | | |
| * | | | | tor-netdoc: Actually call ed25519_cert_invalid for Ed25519NtorCrossCertClara Engler2026-06-111-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Accidentially made a mistake here, will merge them into a single test as a follow-up.
| * | | | | tor-netdoc: Remove "both keys must be different" testClara Engler2026-06-111-9/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We will not need it for Ed25519NtorCrossCert so let's remove it, as discussed in IRC.
| * | | | | tor-netdoc: Remove #[allow(unused)]Clara Engler2026-06-111-1/+0
| | | | | |
| * | | | | tor-netdoc: Use .verify_inner() in .verify()Clara Engler2026-06-111-42/+15
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit removes the old .verify() method and replaces it with .verify_inner() plus the logic to actually verify the signatures and expiration dates using tor-checkable. The verification logic is purposely different as the new one was taken from the legacy one.
| * | | | | tor-netdoc: Use .verify_inner() in legacy parserClara Engler2026-06-111-15/+10
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit changes the legacy parser to make use of the just added .verify_inner() method. For this, we replace the part that extracts crosscert_cert to only extract the inner signature and expiry timestamp, because this is what will be used ultimately. Inside this extraction, we change the parser to only obtain the KeyUnknownCert without any further checks, after which we will pass it to .verify_inner() to store the signatures and expiry date. Following this change, we now only change the places where the previous crosscert_cert was used to extract signatures and expiration dates to use the just extracted cc_sig and cc_expiry instead.
| * | | | | tor-netdoc: Ed25519NtorCrossCert::verify_inner()Clara Engler2026-06-112-1/+93
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit creates a new method, Ed25519NtorCrossCert::verify_inner(), which in essence represents a copying of the verification logic for ntor cross certificates from the legacy parser into parse2 logic, with the eventual goal to unify these two. Unfortunately, a 1:1 move using --color-moved was not possible, because the legacy parser uses edcert::UnvalidatedEdCert for this, which is a very legacy parser specific type, as it contains a Pos in its inner items. Instead, I encourage reviewers to review the functional equality between these two implementations using the following approach: 1. Open the .verify_inner() in one pane. 2. Open routerdesc.rs below the position where this commit introduces the "XXX" comment in another pane next to it; this is the lion's share of the legacy implementation of it. 3. Ensure that the properties that the legacy implementation achieves is also achieved by .verify_inner(). This may require you to take a look at UnvalidatedEdCert::check_cert_type() and similar methods and verify that the if statements in .verify_inner() are equivalent. As outlined above, we cannot make use of these methods directly ourselves inside .verify_inner(). Keep in mind that the legacy parser only returns a tor_cert::UncheckedCert, whereas .verify_inner() returns a gated type. This is okay because UncheckedCert contains these gated types inside it anyways.
| * | | | | tor-netdoc: Documentation improvements for Ed25519NtorCrossCertClara Engler2026-06-111-4/+6
| | | | | | | | | | | | | | | | | | Co-authored-by: Ian Jackson
| * | | | | tor-netdoc: Add test for Ed25519NtorCrossCertClara Engler2026-06-111-0/+55
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds the tests for Ed25519NtorCrossCert by implementing Ed25519CertTest for it and executing the respective generic test functions for it.
| * | | | | tor-netdoc: Dynamically add signed-with violationClara Engler2026-06-111-11/+15
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit changes the invalid ed25519 cert unit test violation of a missing signed-with extension if the generic type is not Ed25519NtorCrossCertificate, as this type does not use this extension. Instead, we change the test vector to a `mut Vec<_>` and push the missing signed-with test if the generic parameter IS NOT of type Ed25519NtorCrossCert.
| * | | | | tor-netdoc: Switch invalid CertType in unit testClara Engler2026-06-111-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Switches the invalid/out-of-place CertType away from ntor cross-cert because we will add a test for this soon. Instead, we now just an RSA certificate, should not collide with any edcert.
| * | | | | tor-netdoc: Provide signing key in Ed25519CertTestClara Engler2026-06-111-0/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit extends .verify() and .new_signed() in Ed25519CertTest to accept the signing key next to the certified key in order to also support Ed25519 certificates not containing the signed-with extension, such as ntor certificates.
| * | | | | tor-netdoc: Add Ed25519NtorCrossCertClara Engler2026-06-113-2/+123
| |/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds the Ed25519NtorCrossCert type for use with EmbeddedCert. So far, this certificate may not be used directly tet, because of the non-trivial X25519 -> Ed25519 conversion which is explained in a doc comment. The next commits will add more parse2-like types for actually parsing it, by honoring the `bit` found in `ntor-onion-key-crosscert` items. A unit test will be added in the immediate next commit.
* | | | | Merge branch 'validity-time-range' into 'main'Clara Engler2026-06-113-6/+16
|\ \ \ \ \ | |/ / / / |/| | | | | | | | | | | | | | tor-netdoc: ns preamble: break out validity_time_range See merge request tpo/core/arti!4054
| * | | | tor-netdoc: netstatus preamble: use saturating sub for starting_timeIan Jackson2026-06-102-1/+2
| | | | |
| * | | | tor-netdoc: ns preamble: break out validity_time_range (tidy)Ian Jackson2026-06-031-5/+3
| | | | | | | | | | | | | | | | | | | | Remove the otiose `preamble` and `timebound_range` bindings again.
| * | | | tor-netdoc: ns preamble: break out validity_time_rangeIan Jackson2026-06-033-7/+16
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We are going to want to use this when we implement verification for network statuses from parse2. Review with --color-moved.
| * | | | tor-netdoc: ns preamble: break out validity_time_range (prep)Ian Jackson2026-06-031-3/+5
| | | | | | | | | | | | | | | | | | | | | | | | | Introduce and use bindings `preamble` and `timebound_range` that will make the next change easier to review.
* | | | | Merge branch 'inclusive-timerange' into 'main'Ian Jackson2026-06-115-7/+15
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | Make all Timebound implementation inclusive See merge request tpo/core/arti!4094
| * | | | | tor-checkable: Specify Timebound inclusiveness in rustdocClara Engler2026-06-111-0/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit updates Timebound's rustdoc to require inclusiveness when checking the timeliness of a given object.
| * | | | | tor-cert: Document expiry inclusiveness for Ed25519CertClara Engler2026-06-111-0/+2
| | | | | |
| * | | | | tor-cert: Make Ed25519Cert time bound inclusiveClara Engler2026-06-111-1/+1
| | | | | |
| * | | | | tor-cert: Replace duration_since with saturation (fmt)Clara Engler2026-06-111-4/+2
| | | | | |
| * | | | | tor-cert: Replace duration_since with saturationClara Engler2026-06-113-2/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit replaces a call to .duration_since(...).expect() with .saturating_duration_since() for defensive programming. We will change code related to it in the next commit.
| * | | | | tor-netdoc: Fix ed25519_invalid_cert unit testClara Engler2026-06-111-2/+2
|/ / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit fixes the ed25519_invalid_cert unit test to not use `now` as the expiration date when generating a certificate in order to test the failed verification of it. The reason for this is that we want to change the verification function to be *inclusive* of the expiry date. If we were to use `now` as the expiry date while also being at `now`, we would no longer get an error. We will do the actual change in the next commits.
* | | | | Merge branch 'cgo-stable' into 'main'Nick Mathewson2026-06-103-6/+6
|\ \ \ \ \ | |_|_|/ / |/| | | | | | | | | | | | | | | | | | | | | | | | Mark "counter-galois-onion" as stable Closes #2550 See merge request tpo/core/arti!4069
| * | | | Mark "counter-galois-onion" as stableNick Mathewson2026-06-043-6/+6
| | | | |
* | | | | Merge branch 'fix-eventdns-todo' into 'main'Ian Jackson2026-06-101-1/+0
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | tor-netdoc: Remove accidential TODO left-over See merge request tpo/core/arti!4081
| * | | | | tor-netdoc: Remove accidential TODO left-overClara Engler2026-06-091-1/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit removes an accidential TODO left-over related to eventdns, which now appears as it would refer to caches-extra-info. I must have forgotten to rebase this out after we decided to not include eventdns in arti!4006, but looking at torspec!498, it is obvious that the comment refers to eventdns and not caches-extra-info.
* | | | | | Merge branch 'bump-docker-imgs' into 'main'Ian Jackson2026-06-102-3/+3
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | CI: Bump docker images See merge request tpo/core/arti!4078
| * | | | | | CI: Update RECENT_RUST_IMAGE to 1.96Gabriela Moldovan2026-06-081-1/+1
| | | | | | |
| * | | | | | CI: Bump build-repro docker images to rust 1.96Gabriela Moldovan2026-06-082-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Part of #2559
* | | | | | | Merge branch 'dep' into 'main'Ian Jackson2026-06-102-2/+2
|\ \ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Add the "dep:" prefix to rpc-related dependencies in Cargo.toml See merge request tpo/core/arti!4090
| * | | | | | | arti: add "dep:" prefix to 'rpc' feature dependenciesSteven Engler2026-06-101-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is technically a breaking change since it removes the tor-rpc-connect, tor-rpcbase, and arti-rpcserver features from arti. But I think these implicit features should not be expected to be stable.
| * | | | | | | arti-client: add "dep:" prefix to "tor-rpcbase"Steven Engler2026-06-101-1/+1
|/ / / / / / /
* | | | | | | Merge branch 'authcert-timebound' into 'main'Ian Jackson2026-06-1014-156/+224
|\ \ \ \ \ \ \ | |_|_|_|_|/ / |/| | | | | | | | | | | | | | | | | | | | make TimerangeBound:is_valid treat bounds as inclusive; use it for parse2's AuthCert See merge request tpo/core/arti!4070
| * | | | | | tor-netcoc: NetdocParseableUnverified derive: forbid NetdocParseableIan Jackson2026-06-102-0/+12
| | | | | | |
| * | | | | | assert_not_impl: Support genericsIan Jackson2026-06-101-5/+22
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I want to call this in one of tor-netdoc's parse2 derives, which *do* support generics.
| * | | | | | assert_not_impl: Support generics - prepIan Jackson2026-06-101-2/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | If we move this let into the item impl, it will have access to the generics we're about to add to the `impl $rule`.
| * | | | | | assert_not_impl: Formally document input syntaxIan Jackson2026-06-101-1/+15
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously we were relying on the macro_rules pattern being in the rustdoc. But it's about to get more complex. Document it manually.
| * | | | | | assert_not_impl: Regularise example syntaxIan Jackson2026-06-101-4/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Usually Rust doesn't put a space after `:` in trait bounds. But it does when calling a macro with { } syntax.
| * | | | | | assert_not_impl: Fix a mendacious headingIan Jackson2026-06-101-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This bit of the doc contains both succeeding and failing examples, each marked with an appropriate comment.
| * | | | | | assert_not_impl: Promote to tor-basic-utilsIan Jackson2026-06-104-42/+46
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I want this in tor-netdoc (which doesn't use tor-config and probably shouldn't). Almost entirely code motion. Review with --color-moved.