summaryrefslogtreecommitdiff
path: root/crates/tor-bytes/src
Commit message (Collapse)AuthorAgeFilesLines
* lints: Run maint/add_warning to actually apply new lintsIan Jackson2023-06-211-0/+2
|
* tor-bytes: Remove use of arrayrefNick Mathewson2023-05-253-19/+16
| | | | | Part of #872: Now that const generics are in, we have better ways to express converting slices into array-references.
* Serval rustdoc link fixes.Nick Mathewson2023-03-081-1/+1
|
* tor-bytes: defend against misuse of extract_n().Nick Mathewson2023-03-061-1/+14
| | | | | | | | | | | | | | | | | | | | | | | | Previously, if somebody wrote this code, an attacker could easily use it to cause an OOM panic: ``` let n = r.take_u64(); let items: Vec<Foo> = r.extract_n(n as usize)?; ``` The first line of defense here is not to write protocols like that: we don't actually _have_ any 32-bit counters in our protocol AFAICT. The second line of defense is to pre-check `n` for reasonableness before calling `extract_n`. Here we add a third line of defense: whereas previously we would do `Vec::with_capacity(n)` in `extract_n`, we now allocate an initial capacity of `min(n, r.remaining())`. This ensures that the size of the allocation can't exceed the remaining length of the message, which (for our cell types at least) should prevent it from overflowing or running OOM.
* tor-bytes: Clarify that Cursor is not a good thing, and could be neater.Nick Mathewson2023-03-011-2/+11
|
* clarify results of misusing cursorsIan Jackson2023-03-011-2/+2
|
* tor-bytes: impl Readable and Writeable for CtByteArray.Nick Mathewson2023-02-281-0/+18
|
* tor-bytes: Add cursor functionality to ReaderNick Mathewson2023-02-281-0/+61
| | | | | We'll use this to implement signature and MAC checking for EstablishIntro cells.
* Change tor_bytes::Error::BadMessage to a Cow.Nick Mathewson2023-02-092-2/+11
| | | | | | | | | | Actually, to avoid making a breaking change, I'm deprecating BadMessage and creating a new InvalidMessage variant that takes a Cow. This way I don't need to track every crate that re-exposes tor_bytes::Error and call this a breaking change in those. Making this change will allow tor_bytes errors to be much more helpful.
* Allow clippy::unchecked_duration_subtraction in testsNick Mathewson2023-01-272-0/+2
| | | | | This panics on error, and we're fine with a panic on misbehavior in tests.
* Disable clippy::unlinlined-format-argsNick Mathewson2023-01-271-0/+1
| | | | | | | | This warning kind of snuck up on us! (See #748) For now, let's disable it. (I've cleaned it up in a couple of examples, since those are meant to be more idiomatic and user-facing.) Closes #748.
* tor-bytes: impl Writeable for &impl WriteableIan Jackson2023-01-241-0/+6
|
* tor-bytes: Implement conversion from EncodeError to BugIan Jackson2023-01-241-1/+16
|
* test lint blocks: Add many many automaticallyIan Jackson2022-12-122-0/+18
| | | | | This is precisely the result of running the rune in maint/adhoc-add-lint-blocks.
* Run add_warnings.Nick Mathewson2022-11-031-0/+1
|
* tor-bytes: Avoid redundant allocationEmil Engler2022-10-251-1/+1
| | | | See c489e1d9118edd842f80b76a636037524a45ee45
* Fix some rustdoc errors.Nick Mathewson2022-10-133-9/+6
| | | | | | In addition to the usual "You named that method wrong!" errors, we have a new rustdoc error that complains about bogus "HTML tags" that are actually unquoted usage of types like `Result<Foo>`.
* cargo fmt to remove blank linesIan Jackson2022-10-121-1/+0
| | | | | | | Apparently cargo fmt doesn't like these, which my perl rune didn't delete. This commit is precisely the result of `cargo fmt`.
* Replace all README copies in src/lib.rs with includesIan Jackson2022-10-121-48/+1
| | | | | | | | The feature we want is `#[doc = include_str!("README.md")]`, which is stable since 1.54 and our MSRV is now 1.56. This commit is precisely the result of the following Perl rune: perl -i~ -0777 -pe 's{(^//!(?!.*\@\@).*\n)+}{#![doc = include_str!("../README.md")]\n}m' crates/*/src/lib.rs
* enable doc_auto_cfg feature on every crate when documenting for docs.rstrinity-1686a2022-08-241-0/+1
|
* New SecretBuf type in tor-bytesNick Mathewson2022-08-012-0/+125
| | | | | | | | | This Writer is a simple wrapper around `Vec<u8>` that makes sure that its contents are cleared whenever they are dropped _or reallocated_. The reallocation is the important part here: without that, we risk not zeroizing the first allocation of the buffer.
* Apply 1 suggestion(s) to 1 file(s)eta2022-07-191-1/+1
|
* Remove the last vestiges of write_infallible.Nick Mathewson2022-07-112-41/+6
| | | | | Now that everything has been converted to fallible writers, we get to finally remove write_infallible() from tor_bytes.
* tor-bytes::impls: Remove usage of infallible writers.Nick Mathewson2022-07-111-2/+2
|
* Remove "write_and_consume_infallible".Nick Mathewson2022-07-111-9/+3
| | | | | | There were only a few of these. Removing it required porting everything to use `write_and_consume` instead, and handling its (potential) errors.
* Convert each write_onto_infallible implementation into write_onto.Nick Mathewson2022-07-112-15/+29
|
* Convert each write_into_infallible implementation into write_into.Nick Mathewson2022-07-111-1/+2
| | | | (There was only one.)
* Define new write_into and write_onto methods with correct APIs.Nick Mathewson2022-07-112-6/+56
|
* Rename "write" methods on tor-bytes to "write_infallible".Nick Mathewson2022-07-113-31/+31
| | | | | | | | | | | | | | | This comprises four renames: ``` write_onto -> write_onto_infallible write_into -> write_into_infallible write -> write_infallible writer_and_consume -> write_and_consume_infallible. ``` The rest of this branch will be concerned with replacing these `_infallible` methods with ones that return a `Result`. This is part of #513.
* Add a Bug variant to tor-bytes::EncodeError.Nick Mathewson2022-07-112-2/+11
| | | | This will help down the line as we make more writers fallible.
* Merge branch 'clippy' into 'main'Ian Jackson2022-06-241-0/+3
|\ | | | | | | | | Fix clippy nightly again See merge request tpo/core/arti!603
| * Run maint/add_warning crates/*/src/{lib,main}.rsIan Jackson2022-06-231-0/+3
| | | | | | | | Update all lint blocks
* | tor-bytes: Split EncodeError from ErrorNick Mathewson2022-06-233-8/+18
|/ | | | | | | | | | | Since there is currently only one error type that can occur when encoding, it doesn't make sense to use the full Error type here. This split will help us downstream, as we no longer need to categorize tor_bytes::Error as "an error in encoding or decoding". I considered renaming Error to DecodeError, but that had pretty huge downstream effects, and didn't seem to be worth it.
* Style fixes to tor-bytes errors.Nick Mathewson2022-06-221-5/+9
| | | | | Also note an issue with the design of tor-bytes::Error that should probably go in a separate MR.
* tor-bytes: read_nested_*: rustfmtIan Jackson2022-06-101-13/+23
| | | | I disagree with almost all of these layout decisions...
* tor-bytes: read_nested_*: Take a closureIan Jackson2022-06-101-25/+40
| | | | | | | | | | This eliminates the possibility of writing the bug of failing to call `should_be_exhausted`. As per this discussion https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/572#note_2811464 Fixes #498
* Fix typos in docs and commentsNick Mathewson2022-06-091-2/+2
|
* tor-bytes: Provide nested writersIan Jackson2022-06-091-1/+116
|
* tor-bytes: Provide nested readersIan Jackson2022-06-092-0/+70
|
* tor-bytes: Reader: Provide take_restIan Jackson2022-06-092-0/+20
| | | | We'll want this in a moment.
* tor-bytes: Prepare errors for nested reader/writerIan Jackson2022-06-091-1/+5
| | | | Writing is going to be able to give errors too.
* lints: Add let_unit_value allow to all cratesIan Jackson2022-05-311-0/+1
| | | | | From running add_warning, with manual picking of the right hunks/lines.
* lints: Add lint block delimiters to every crateIan Jackson2022-05-311-0/+2
| | | | | | This was the result of: maint/add_warning crates/*/src/{lib,main}.rs and then manually curating the results.
* clippy: Drop an unused lifetimeIan Jackson2022-05-111-1/+1
|
* Fix grammar and typosSamanta Navarro2022-04-271-1/+1
|
* Disable clippy::clone_on_ref_ptrIan Jackson2022-02-241-1/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This lint is IMO inherently ill-conceived. I have looked for the reasons why this might be thought to be a good idea and there were basically two (and they are sort of contradictory): I. "Calling ‘.clone()` on an Rc, Arc, or Weak can obscure the fact that only the pointer is being cloned, not the underlying data." This is the wording from https://rust-lang.github.io/rust-clippy/v0.0.212/#clone_on_ref_ptr It is a bit terse; we are left to infer why it is a bad idea to obscure this fact. It seems to me that if it is bad to obscure some fact, that must be because the fact is a hazard. But why would it be a hazard to not copy the underlying data ? In other languages, faliing to copy the underlying data is a serious correctness hazard. There is a whose class of bugs where things were not copied, and then mutated and/or reused in multiple places in ways that were not what the programmer intended. In my experience, this is a very common bug when writing Python and Javascript. I'm told it's common in golang too. But in Rust this bug is much much harder to write. The data inside an Arc is immutable. To have this bug you'd have use interior mutability - ie mess around with Mutex or RefCell. That provides a good barrier to these kind of accidents. II. "The reason for writing Rc::clone and Arc::clone [is] to make it clear that only the pointer is being cloned, as opposed to the underlying data. The former is always fast, while the latter can be very expensive depending on what is being cloned." This is the reasoning found here https://github.com/rust-lang/rust-clippy/issues/2048 This is saying that *not* using Arc::clone is hazardous. Specifically, that a deep clone is a performance hazard. But for this argument, the lint is precisely backwards. It's linting the "good" case and asking for it to be written in a more explicit way; while the supposedly bad case can be written conveniently. Also, many objects (in our codebase, and in all the libraries we use) that are Clone are in fact simply handles. They contain Arc(s) (or similar) and are cheap to clone. Indeed, that is the usual case. It does not make sense to distinguish in the syntax we use to clone such a handle, whether the handle is a transparent Arc, or an opaque struct containing one or more other handles. Forcing Arc::clone to be written as such makes for code churn when a type is changed from Arc<Something> to Something: Clone, or vice versa.
* Make Bug from InternalError, add bad_api_usage! and into_bad_api_usage!Ian Jackson2022-02-151-2/+2
| | | | Including supporting machinery, new kind field, etc.
* Change deny(clippy::all) to warn(clippy::all).Nick Mathewson2022-02-141-1/+1
| | | | Closes #338.
* tor-bytes: Use InternalError.Nick Mathewson2022-02-092-3/+17
| | | | | | This crate's Error type is too low-level to have an ErrorKind, but it does make sense to use InternalError for the internal errors here.
* extend lints to include 'clippy::all'Daniel Eades2021-12-281-0/+1
|