aboutsummaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * | | | | | | relay: Use same wallclock() time when generating keysDavid Goulet2026-03-171-8/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
| * | | | | | | relay: Make the crypto tasks use the runtime wallclockDavid Goulet2026-03-172-25/+42
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This way we can unit tests properly. Signed-off-by: David Goulet <[email protected]>
| * | | | | | | relay: Rewrite the rotation key logic in the crypto taskDavid Goulet2026-03-172-163/+252
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is almost a full rewrite of the crypto task which was needed in order to support our relay signing certificate to be put in the keystore which will be needed for the offline key feature. Instead of having rotate_key() do all the things, we now instead do two pass: 1. Remove all expired keys and certs. 2. Generate any missing keys. This still results in using the minimum valid_until of all our keys for the task sleep time. We can know cleanup the local trait used for this gymnastic and trade it for some more KeyMgr gymnastic. Fixes #2404 Signed-off-by: David Goulet <[email protected]>
| * | | | | | | relay: Don't log warn if key already exists when generating oneDavid Goulet2026-03-171-4/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
| * | | | | | | relay: Remove leftover comment from previous code iterationDavid Goulet2026-03-171-4/+0
|/ / / / / / / | | | | | | | | | | | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
* | | | | | | Merge branch 'expiry_hours' into 'main'David Goulet2026-03-174-34/+86
|\ \ \ \ \ \ \ | |_|_|/ / / / |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | cert: Fix minor rounding bug in systemtime-to-expiry conversion Closes #2407 See merge request tpo/core/arti!3787
| * | | | | | cert: Fix minor but annoying bug in cert expiry calculationNick Mathewson2026-03-171-2/+18
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | We documented our SystemTime-to-expiry conversion as always rounding _up_, but we did not account for fractional seconds when doing so. Therefore, if the requested expiration was set partway through the first second of an hour, the conversion would round down. This patch fixes that, and adds a regression test. I've confirmed that the test fails without this patch. Closes #2407
| * | | | | | cert: Deduplicate expiry-in-hours logicNick Mathewson2026-03-174-34/+70
|/ / / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | These certificates use a weird expiration format: counting hours since the unix epoch. Previously we had it implemented in two different places. This patch centralizes it, since we are about to become slightly more complicated.
* | | | | | Merge branch 'keymgr-cert-fixes2' into 'main'gabi-2502026-03-172-21/+115
|\ \ \ \ \ \ | |_|_|/ / / |/| | | | | | | | | | | | | | | | | keymgr: Use the keypair specifier when generating keys. See merge request tpo/core/arti!3785
| * | | | | keymgr: Remove now-addressed XXXGabriela Moldovan2026-03-171-3/+0
| | | | | |
| * | | | | keymgr: Fix feature-gating in testsGabriela Moldovan2026-03-171-4/+3
| | | | | |
| * | | | | keymgr: Lower get() logic into get_from_store()Gabriela Moldovan2026-03-171-13/+15
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This moves the logic for retrieving a public key from its corresponding keypair into `get_from_store()`. Fixes a bug which made it impossible to retrieve a public key using the key specifier of its keypair type with any function other than `KeyMgr::get()`.
| * | | | | keymgr: Add more tests to reveal the get_*() bug for public keysGabriela Moldovan2026-03-171-1/+65
| | | | | | | | | | | | | | | | | | | | | | | | This will be fixed in the next commit.
| * | | | | keymgr: Pass the item type to entry_descriptor() (fmt)Gabriela Moldovan2026-03-171-1/+5
| | | | | |
| * | | | | keymgr: Pass the item type to entry_descriptor()Gabriela Moldovan2026-03-171-4/+4
| | | | | | | | | | | | | | | | | | | | | | | | I am about to repurpose this test helper for other item types too.
| * | | | | keymgr: Preserve item metadata when converting to TestPublicKey (fmt)Gabriela Moldovan2026-03-171-1/+4
| | | | | |
| * | | | | keymgr: Preserve item metadata when converting to TestPublicKeyGabriela Moldovan2026-03-171-1/+3
| | | | | | | | | | | | | | | | | | | | | | | | This will enable us to test the provenance of public keys.
| * | | | | keymgr: Update cert testsGabriela Moldovan2026-03-171-1/+16
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is needed now that `get_or_generate_key_and_cert()` uses the keypair specifier when generating the subject key. Without this the cert retrieval tests fail because `get_or_generate_key_and_cert()` now requires the subject key specifier to have an associated keypair specifier ("KeyCertificateSpecifier has no keypair specifier for the subject key?"). Note that even with this patch, the `get_cert_entry()` test still fails because of a bug in the `get_*()` family of functions. This will be fixed in a future commit.
| * | | | | keymgr: Use the keypair specifier when generating keys.Gabriela Moldovan2026-03-171-1/+9
|/ / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | When generating a new keypair, we want to use the keypair specifier of the subject key. Fixes a bug where this code was incorrectly generating a keypair using the specifier of the public key type (the resulting generated key had a `kp_` prefix instead of `ks_`).
* | | | | Merge branch 'ssh-fork' into 'main'gabi-2502026-03-164-15/+15
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | keymgr, key-forge: Use our ssh-* forks See merge request tpo/core/arti!3783
| * | | | | keymgr, key-forge: Use our ssh-* forksGabriela Moldovan2026-03-164-15/+15
|/ / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Upstream `ssh-key` is missing some important features we need for arti-relay: * a bug fix without which we can't convert deserialized RSA keys to their rsa counterparts: https://github.com/RustCrypto/SSH/pull/318 * @wesleyac 's patch https://github.com/RustCrypto/SSH/pull/412 for allowing insecure (1024 bits long) RSA keys (needed because the relay KS_relayid_rsa identity keys are 1024 bits long) We plan to switch back to mainline `ssh-key` when `ssh-key 0.7.0` comes out. See the discussion in #2398 for more details.
* | | | | Merge branch 'circ-react-logs' into 'main'David Goulet2026-03-162-2/+44
|\ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | proto: Add more logging to the new circuit reactors See merge request tpo/core/arti!3776
| * | | | | proto: Add more logging to the new circuit reactorsGabriela Moldovan2026-03-122-2/+44
| | | | | |
* | | | | | Merge branch 'typos' into 'main'opara2026-03-1646-58/+58
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | Fix various typos See merge request tpo/core/arti!3781
| * | | | | | Fix grammar typosTobias Stoeckmann2026-03-156-9/+9
| | | | | | |
| * | | | | | Fix word duplicate typosTobias Stoeckmann2026-03-1544-50/+50
| | | | | | |
* | | | | | | Merge branch 'rpc-su-v2' into 'main'Nick Mathewson2026-03-1623-74/+543
|\ \ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | RPC: Provide superuser mode Closes #2285 See merge request tpo/core/arti!3743
| * | | | | | | rpc test: python integration tests for su mode.Nick Mathewson2026-03-164-1/+73
| | | | | | | |
| * | | | | | | python rpc: Add wrapper for prefer-superuser method.Nick Mathewson2026-03-162-0/+22
| | | | | | | |
| * | | | | | | rpc-client: Run cbindgen to regenerate C header.Nick Mathewson2026-03-161-0/+20
| | | | | | | |
| * | | | | | | rpc-client: add support to prefer/require su permissionNick Mathewson2026-03-165-2/+114
| | | | | | | |
| * | | | | | | rpc: Add support for set_dormant.Nick Mathewson2026-03-163-7/+60
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is not exactly the most _urgent_ superuser functionality, but it is probably the easiest to implement.
| * | | | | | | rpc: Implement superuser mode.Nick Mathewson2026-03-164-7/+50
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | When connection point provides superuser support, provide a (currently inert) RpcSuperuser object to the RPC session.
| * | | | | | | rpc: add a "superuser" element to connect points.Nick Mathewson2026-03-163-0/+49
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Currently does nothing.
| * | | | | | | rpc: Do not allow a connection to be authenticated twiceNick Mathewson2026-03-164-10/+24
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This makes it a little easier to drop unwanted capabilities.
| * | | | | | | rpc: Move responsibility for Session creation to ConnectionNick Mathewson2026-03-165-64/+42
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The Connection will know the options that the listener was created with, as opposed to RpcMgr, which is the same for every listener.
| * | | | | | | rpc: Add su capability to RpcSession, and methods to get/drop itNick Mathewson2026-03-161-2/+108
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | (For now, the su capability doesn't actually do anything, and there is no ability to actually have a session start with one.)
* | | | | | | | Merge branch 'windows_build_typo' into 'main'Nick Mathewson2026-03-163-2/+5
|\ \ \ \ \ \ \ \ | |_|/ / / / / / |/| | | | | | | | | | | | | | | | | | | | | | | arti-rpc-client-core: Fix windows build See merge request tpo/core/arti!3780
| * | | | | | | Fix windows cargo warningsTobias Stoeckmann2026-03-152-1/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Disable use-statements which are only needed for unix.
| * | | | | | | arti-rpc-client-core: Fix windows buildTobias Stoeckmann2026-03-151-1/+1
|/ / / / / / / | | | | | | | | | | | | | | | | | | | | | Fix a typo in use-statement for windows.
* | | | | | | Merge branch 'bug2366' into 'main'Nick Mathewson2026-03-141-1/+1
|\ \ \ \ \ \ \ | |/ / / / / / |/| | | | | | | | | | | | | | | | | | | | proto: Move criterion-cycles-per-byte to dev-dependencies See merge request tpo/core/arti!3778
| * | | | | | proto: Move criterion-cycles-per-byte to dev-dependenciesNick Mathewson2026-03-131-1/+1
|/ / / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This may help fix our CI cross compilation tests on platforms without a C compiler install. In any case, it may speed up non-test builds by a tiny bit. Possible solution for #2366.
* | | | | | Merge branch 'shadow-keep-going' into 'main'Alexander Hansen Færøy2026-03-121-10/+14
|\ \ \ \ \ \ | |/ / / / / |/| | | | | | | | | | | | | | | | | shadow ci: keep going after first failure See merge request tpo/core/arti!3766
| * | | | | shadow ci: keep going after first failureJim Newsome2026-03-111-10/+14
| | | | | | | | | | | | | | | | | | | | | | | | It can be useful to see the outcome of the other tests/analysis.
* | | | | | Merge branch 'relay-log-idents' into 'main'opara2026-03-122-0/+33
|\ \ \ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | arti-relay: Log relay identities See merge request tpo/core/arti!3773
| * | | | | | arti-relay: Log relay identitiesSteven Engler2026-03-122-0/+33
| | | | | | |
* | | | | | | Merge branch 'cert-entry2' into 'main'David Goulet2026-03-128-209/+755
|\ \ \ \ \ \ \ | |/ / / / / / |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | keymgr: New `CertSpecifier` macro and cert APIs Closes #2376 See merge request tpo/core/arti!3770
| * | | | | | keymgr: Add test retrieving an expired certGabriela Moldovan2026-03-121-1/+77
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This tests that the `KeyMgr` returns an error if you try to retrieve an invalid cert.
| * | | | | | keymgr: Introduce a new TestCert typeGabriela Moldovan2026-03-121-4/+28
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is a bit of a hack, but we need it to make the tests pass. The issue is that our test keystore stores `TestItem`s, and all our other test used `TestItem` as their key types. Now that we have certs, we have this concept of a `ToEncodableCert::ParsedCert`, which is what the keymgr downcasts the retrieved certs to before validating them and returning the final cert result (which is usually going to be of a different type than `ParsedCert`). This wrapper ensures that the keystore returns the expected `ParsedCert` type, so that validation doesn't fail. Before this change, we were hackily returning `TestItem` in the tests, even for certificates, but that doesn't work anymore, because the `ItemType` impl of `TestItem` returns `KeyType::Ed25519Keypair`, which is obviously not a `CertType`. Using it resulted in an error because there is a mismatch between the cert `ItemType` (`Ed25519Keypair`) and the `ItemType` of the `KeystoreItem::Cert` entry (`Ed25519TorCert`). Normally this wouldn't happen, but the whole test keystore implementation is funky and inconsistent.
| * | | | | | keymgr: Add tests for the new get_cert() APIGabriela Moldovan2026-03-121-1/+89
| | | | | | |