| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | |/ / / / / |
|
| |\ \ \ \ \ \
| |/ / / / /
|/| | | | |
| | | | | |
| | | | | | |
Utilize ItemPresent in RouterDesc
See merge request tpo/core/arti!4080
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
Adds RouterDesc::hidden_service_dir as well as an accompanying ZST
token.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
No functional change.
|
| |/ / / / /
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This commit modifies RouterDesc to replace all occurrences of `bool`
with `Option<ItemPresent<T>>` while adding respective ZST tokens for the
respective items.
In this case, it adjusts caches_extra_info and tunnelled_dir_server.
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
Add Ed25519NtorCrossCert
See merge request tpo/core/arti!4022
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This commit adds an argument to the generic test specifying whether the
type requires the respective extension or not, in order to replace a
clumsy std::any solution.
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
Accidentially made a mistake here, will merge them into a single test as
a follow-up.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
We will not need it for Ed25519NtorCrossCert so let's remove it, as
discussed in IRC.
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This commit removes the old .verify() method and replaces it with
.verify_inner() plus the logic to actually verify the signatures and
expiration dates using tor-checkable.
The verification logic is purposely different as the new one was taken
from the legacy one.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This commit changes the legacy parser to make use of the just added
.verify_inner() method.
For this, we replace the part that extracts crosscert_cert to only
extract the inner signature and expiry timestamp, because this is what
will be used ultimately. Inside this extraction, we change the parser
to only obtain the KeyUnknownCert without any further checks, after
which we will pass it to .verify_inner() to store the signatures and
expiry date.
Following this change, we now only change the places where the previous
crosscert_cert was used to extract signatures and expiration dates to
use the just extracted cc_sig and cc_expiry instead.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This commit creates a new method, Ed25519NtorCrossCert::verify_inner(),
which in essence represents a copying of the verification logic for ntor
cross certificates from the legacy parser into parse2 logic, with the
eventual goal to unify these two.
Unfortunately, a 1:1 move using --color-moved was not possible, because
the legacy parser uses edcert::UnvalidatedEdCert for this, which is a
very legacy parser specific type, as it contains a Pos in its inner
items.
Instead, I encourage reviewers to review the functional equality between
these two implementations using the following approach:
1. Open the .verify_inner() in one pane.
2. Open routerdesc.rs below the position where this commit introduces
the "XXX" comment in another pane next to it; this is the lion's
share of the legacy implementation of it.
3. Ensure that the properties that the legacy implementation achieves is
also achieved by .verify_inner(). This may require you to take a
look at UnvalidatedEdCert::check_cert_type() and similar methods and
verify that the if statements in .verify_inner() are equivalent.
As outlined above, we cannot make use of these methods directly
ourselves inside .verify_inner().
Keep in mind that the legacy parser only returns a
tor_cert::UncheckedCert, whereas .verify_inner() returns a gated type.
This is okay because UncheckedCert contains these gated types inside it
anyways.
|
| | | | | | |
| | | | | |
| | | | | | |
Co-authored-by: Ian Jackson
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This commit adds the tests for Ed25519NtorCrossCert by implementing
Ed25519CertTest for it and executing the respective generic test
functions for it.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This commit changes the invalid ed25519 cert unit test violation of a
missing signed-with extension if the generic type is not
Ed25519NtorCrossCertificate, as this type does not use this extension.
Instead, we change the test vector to a `mut Vec<_>` and push the
missing signed-with test if the generic parameter IS NOT of type
Ed25519NtorCrossCert.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
Switches the invalid/out-of-place CertType away from ntor cross-cert
because we will add a test for this soon.
Instead, we now just an RSA certificate, should not collide with any
edcert.
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This commit extends .verify() and .new_signed() in Ed25519CertTest to
accept the signing key next to the certified key in order to also
support Ed25519 certificates not containing the signed-with extension,
such as ntor certificates.
|
| | |/ / / /
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This commit adds the Ed25519NtorCrossCert type for use with
EmbeddedCert.
So far, this certificate may not be used directly tet, because of the
non-trivial X25519 -> Ed25519 conversion which is explained in a doc
comment.
The next commits will add more parse2-like types for actually parsing
it, by honoring the `bit` found in `ntor-onion-key-crosscert` items.
A unit test will be added in the immediate next commit.
|
| |\ \ \ \ \
| |/ / / /
|/| | | |
| | | | |
| | | | | |
tor-netdoc: ns preamble: break out validity_time_range
See merge request tpo/core/arti!4054
|
| | | | | | |
|
| | | | | |
| | | | |
| | | | |
| | | | | |
Remove the otiose `preamble` and `timebound_range` bindings again.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
We are going to want to use this when we implement verification for
network statuses from parse2.
Review with --color-moved.
|
| | | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Introduce and use bindings `preamble` and `timebound_range` that will
make the next change easier to review.
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
Make all Timebound implementation inclusive
See merge request tpo/core/arti!4094
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This commit updates Timebound's rustdoc to require inclusiveness when
checking the timeliness of a given object.
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | | |
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This commit replaces a call to .duration_since(...).expect() with
.saturating_duration_since() for defensive programming. We will change
code related to it in the next commit.
|
| |/ / / / /
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
This commit fixes the ed25519_invalid_cert unit test to not use `now` as
the expiration date when generating a certificate in order to test the
failed verification of it.
The reason for this is that we want to change the verification function
to be *inclusive* of the expiry date. If we were to use `now` as the
expiry date while also being at `now`, we would no longer get an error.
We will do the actual change in the next commits.
|
| |\ \ \ \ \
| |_|_|/ /
|/| | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Mark "counter-galois-onion" as stable
Closes #2550
See merge request tpo/core/arti!4069
|
| | | | | | |
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
tor-netdoc: Remove accidential TODO left-over
See merge request tpo/core/arti!4081
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This commit removes an accidential TODO left-over related to eventdns,
which now appears as it would refer to caches-extra-info.
I must have forgotten to rebase this out after we decided to not include
eventdns in arti!4006, but looking at torspec!498, it is obvious that
the comment refers to eventdns and not caches-extra-info.
|
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
CI: Bump docker images
See merge request tpo/core/arti!4078
|
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
Part of #2559
|
| |\ \ \ \ \ \ \
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
Add the "dep:" prefix to rpc-related dependencies in Cargo.toml
See merge request tpo/core/arti!4090
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This is technically a breaking change since it removes the
tor-rpc-connect, tor-rpcbase, and arti-rpcserver features from arti. But
I think these implicit features should not be expected to be stable.
|
| |/ / / / / / / |
|
| |\ \ \ \ \ \ \
| |_|_|_|_|/ /
|/| | | | | |
| | | | | | |
| | | | | | | |
make TimerangeBound:is_valid treat bounds as inclusive; use it for parse2's AuthCert
See merge request tpo/core/arti!4070
|
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
I want to call this in one of tor-netdoc's parse2 derives, which *do*
support generics.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
If we move this let into the item impl, it will have access to the
generics we're about to add to the `impl $rule`.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
Previously we were relying on the macro_rules pattern being in the
rustdoc. But it's about to get more complex.
Document it manually.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
Usually Rust doesn't put a space after `:` in trait bounds. But it
does when calling a macro with { } syntax.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This bit of the doc contains both succeeding and failing examples,
each marked with an appropriate comment.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
I want this in tor-netdoc (which doesn't use tor-config and probably
shouldn't).
Almost entirely code motion. Review with --color-moved.
|