summaryrefslogtreecommitdiff
path: root/crates/fs-mistrust/src
Commit message (Collapse)AuthorAgeFilesLines
* fix compiling fs-misstrust on tvOSyaucp2025-03-263-11/+27
|
* fix: fix typosDimitris Apostolou2025-01-301-1/+1
|
* fs-mistrust: document that follow_final_links is not insecureNick Mathewson2025-01-281-0/+4
| | | | | Since it makes an exception, we need to be clear about the exceptions that it _doesn't_ make.
* fs-mistrust: link to documentation about "obeying constraints"Nick Mathewson2025-01-281-5/+5
| | | | | | Since "obeying the constraints of a FileAccess" is a term of art, this commit introduces links from the places where it is used to the place where it is defined.
* fs-mistrust: Fix test compilation on windows.Nick Mathewson2025-01-161-1/+2
| | | | | | | | | `std::os::unix::fs::MetadataExt` was indeed the right trait to import, but it doesn't exist on non-unix platforms. This is another bugfix on !2707. It should retain the fix of !2717. I've confirmed that it builds on Windows and passes tests on Linux and Mac.
* Fix: Tests fails to run on macoshhamud2025-01-161-5/+5
|
* file_access: Refactor APIs to consume self.Nick Mathewson2025-01-141-7/+16
| | | | | This approach makes it even less likely for people to store a FileAccess for repeated use.
* file_access: Make link-following behavior explicitly controlled.Nick Mathewson2025-01-141-8/+38
|
* Documentation fixes from GabiNick Mathewson2025-01-141-5/+3
|
* fs-mistrust: Try more to explain what FileAccess is for.Nick Mathewson2025-01-141-3/+7
|
* fs-mistrust: Follow symlinks when using file-access outside a CheckedDir.Nick Mathewson2025-01-141-9/+98
| | | | | | When we're not bound to a CheckedDir, it doesn't make sense to forbid following symlinks, so long as their targets are also sensible.
* fs-mistrust: Add FileAccess for Verifier (and Mistrust).Nick Mathewson2025-01-142-9/+42
|
* fs-mistrust: Have Verifier check methods take self by reference.Nick Mathewson2025-01-141-2/+2
| | | | There is no reason for these to consume self.
* fs-mistrust: Add ability to create files with chosen mode.Nick Mathewson2025-01-141-10/+117
|
* fs-mistrust: Clean up documentation.Nick Mathewson2025-01-141-15/+13
|
* fs-mistrust: Move file access methods on CheckedDir to FileAccess.Nick Mathewson2025-01-142-69/+168
| | | | | These are the methods which we'd like to give new options in #1746; we can move other methods later if we want to.
* fs-mistrust: Define a (stub) FileAccess type.Nick Mathewson2025-01-143-0/+38
| | | | | We're going to move functionality and configuration functions here to implement #1746.
* fs-mistrust::CheckedDir: Refactor some common code.Nick Mathewson2025-01-141-22/+32
|
* fs-mistrust: Add test for (not) opening symlink from CheckedDir.Nick Mathewson2025-01-141-1/+10
|
* fs-mistrust: clarify doc for a private function.Nick Mathewson2025-01-141-0/+2
|
* clippy: deny `mod_module_files`Steven Engler2025-01-061-0/+1
| | | | | | Denies 'mod.rs' files for consistency. https://rust-lang.github.io/rust-clippy/master/index.html#mod_module_files
* fs-mistrust: trim whitespace in env var valuesSteven Engler2024-12-182-4/+8
|
* fs-mistrust: commit to stable env var handlingSteven Engler2024-12-182-4/+43
| | | | | | | | Since these environment variables become part of the stable API for applications that use fs-mistrust, we should be explicit about how these environment variables are interpreted so that applications can show the values in their documentation or help text, and so that we don't accidentally change the behaviour and break applications.
* fs-mistrust: (docs) fix incomplete list of env variable valuesSteven Engler2024-12-181-2/+2
|
* Resolve clippy::empty_line_after_doc_comments warnings.Nick Mathewson2024-12-031-1/+0
| | | | These are new in Rust 1.83.
* add_warnings, *: Allow clippy::needless_lifetimesNick Mathewson2024-12-031-0/+1
| | | | | | | | In 1.83, this warning triggers on many of our crates. We're thinking of fixing them all, but for now, we're going to disable the warning. This is part of #1765.
* fs-mistrust: Remove outdated thiserror syntaxClara Engler2024-11-121-1/+1
| | | | | | This commit removes an outdated syntax in a `thiserror` macro which will be removed in `thiserror` version 2. The change this commit makes is backwards compatible in itself.
* Replace _ => panic!() elsewhereIan Jackson2024-10-151-1/+1
|
* Fix a couple of lifetime warnings from nightly.Nick Mathewson2024-10-011-1/+1
| | | | | | | | | Nightly rustdoc, under some circumstances, issues a warning when you have an elided lifetime that matches a lifetime with a name. (It would prefer that you name the lifetime explicitly.) This does not change the actual lifetime of anything; it only makes some formerly elided lifetimes explicit.
* fs-mistrust: Make fake PathExt return impl DisplayIan Jackson2024-08-191-3/+4
| | | | Otherwise it doesn't compile when actually used.
* fs-mistrust: Make a comment into a docIan Jackson2024-08-191-2/+2
| | | | Placates clippy.
* fs-mistrust: Decorate some items with missing walkdir cfgIan Jackson2024-08-192-1/+5
|
* fs-mistrust: Make CheckedDir::metadata() return an error if path is symlink.Gabriela Moldovan2024-08-121-2/+45
|
* fs-mistrust: Avoid opening the file in CheckedDir::metadata().Gabriela Moldovan2024-08-081-5/+19
| | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2291#note_3057232
* fs-mistrust: Add a TODO about refactoring CheckedDir::metadata().Gabriela Moldovan2024-08-081-0/+1
|
* fs-mistrust: Note that metadata() can return Error::NotFound.Gabriela Moldovan2024-08-081-0/+2
|
* fs-mistrust: Apply deferred cargo fmt.Gabriela Moldovan2024-08-081-1/+4
|
* fs-mistrust: Add a CheckedDir::metadata function.Gabriela Moldovan2024-08-081-1/+28
|
* fs-mistrust: Use Path::try_exists() instead of Path::exists().Gabriela Moldovan2024-07-301-2/+2
|
* fs-mistrust: Explain that Error might not be a permissions errorIan Jackson2024-07-101-0/+7
|
* fs-mistrust: Fix a formatting botchIan Jackson2024-07-101-2/+3
| | | | rustfmt didn't want to fix this, for some reason.
* Fix a footnote reference that Nightly complains aboutIan Jackson2024-07-081-1/+1
|
* Re-run maint/add_warning.Nick Mathewson2024-05-061-2/+2
| | | | This commit is automatically generated.
* Run maint/add_warning.Nick Mathewson2024-03-138-0/+8
|
* Fix typos in doc commentsTobias Stoeckmann2024-03-062-2/+2
|
* Fix typos in commentsTobias Stoeckmann2024-03-061-1/+1
|
* fs-mistrust: Introduce a fn display_lossyIan Jackson2024-03-051-2/+9
| | | | | We're going to tell clippy to forbid Path::display. But we can't have the PathExt from tor-basic-utils, here.
* deny clippy::unchecked_duration_subtractiontrinity-1686a2024-02-291-0/+1
|
* educe: Use std's default for enums where default variant is unitIan Jackson2024-02-122-10/+6
| | | | | | | | | | | | | Since Rust 1.66, std's default works properly for enums, provided that the default variant is a unit. Review all uses of `#[educe(default)]` on enums and replace them with std where possible, which is most of them. In 1.66 and later, std's `#[derive(Default)]` doesn't infer any generic bounds on the derived impl, where it's an enum - since the unit variant can always be constructed. So this change doesn't add any generic bounds and is not API-visible.
* fs_mistrust: Provide CheckedDir::make_secure_dirIan Jackson2024-01-291-0/+18
| | | | | | state_dir wants this, to descend into subdirectories. I think the implementation could be improved - see the TODO.