summaryrefslogtreecommitdiff
path: root/crates/tor-bytes/src
Commit message (Collapse)AuthorAgeFilesLines
* Convert to the latest versions of dalek-cryptographyNick Mathewson2023-11-291-17/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The main changes that we have to adjust for are as follows: * In x25519-dalek: * `StaticSecret` is now behind a feature. * `StaticSecret::new` is deprecated in favor of `StaticSecret::random_from_rng`. * StaticSecret no longer does its own clamping. * In ed25519-dalek: * `SecretKey` has (in effect) been renamed to `SigningKey`. The name `SecretKey` is now an alias for `[u8; 32]`. * `SigningKey` is effectively a keypair, since it contains a public key as well. * `PublicKey` has been renamed to `VerifyingKey`. * The functions to extract a signing key and verifying key have been renamed as you might expect. * `ExpandedSecretKey` has been moved to `hasmat` and no longer implements `sign`. * `ExpanededSecretKey` now has as its elements a scalar and a hash prefix. * Various functions that took `&[u8]` now take `&[u8; N]`. * We no longer need a wrapper for older versions of rand. There is a single test in tor-keymgr that does not pass. I've marked it as ignore for now, in hopes that @gabi-250 can help me figure it out. This closes #808. There are several changes I want to make before we merge, however. They are marked with TODO DALEK.
* Remove direct dependency on generic-arrayNick Mathewson2023-09-281-13/+8
| | | | | | | | | | Instead of tying ourselves to a particular version of the generic-array crate, we now always use the version re-exported by our RustCrypto crates. This lets us avoid the possibility of version mismatch. (Originally I had planned to upgrade to generic-array 1.0, but then I found that we were not actually using it.)
* Run maint/add_warning to add lint block everywhereIan Jackson2023-08-232-0/+2
|
* tor-bytes: deprecate always_bug with From traitEmil Engler2023-08-171-0/+11
| | | | | | This commit deprecates the `EncodeError::always_bug` function with a `From<EncodeError> for Bug` trait, which is a more semantically correct way to perform this action.
* Run add_warnings on all files.Nick Mathewson2023-08-041-2/+2
|
* Run maint/add_warning to actually apply new lint allowsIan Jackson2023-07-102-0/+3
|
* Run add_warning to remove `missing_panics_doc` deny.Nick Mathewson2023-07-061-1/+0
| | | | Closes #950.
* lints: Run maint/add_warning to actually apply new lintsIan Jackson2023-06-211-0/+2
|
* tor-bytes: Remove use of arrayrefNick Mathewson2023-05-253-19/+16
| | | | | Part of #872: Now that const generics are in, we have better ways to express converting slices into array-references.
* Serval rustdoc link fixes.Nick Mathewson2023-03-081-1/+1
|
* tor-bytes: defend against misuse of extract_n().Nick Mathewson2023-03-061-1/+14
| | | | | | | | | | | | | | | | | | | | | | | | Previously, if somebody wrote this code, an attacker could easily use it to cause an OOM panic: ``` let n = r.take_u64(); let items: Vec<Foo> = r.extract_n(n as usize)?; ``` The first line of defense here is not to write protocols like that: we don't actually _have_ any 32-bit counters in our protocol AFAICT. The second line of defense is to pre-check `n` for reasonableness before calling `extract_n`. Here we add a third line of defense: whereas previously we would do `Vec::with_capacity(n)` in `extract_n`, we now allocate an initial capacity of `min(n, r.remaining())`. This ensures that the size of the allocation can't exceed the remaining length of the message, which (for our cell types at least) should prevent it from overflowing or running OOM.
* tor-bytes: Clarify that Cursor is not a good thing, and could be neater.Nick Mathewson2023-03-011-2/+11
|
* clarify results of misusing cursorsIan Jackson2023-03-011-2/+2
|
* tor-bytes: impl Readable and Writeable for CtByteArray.Nick Mathewson2023-02-281-0/+18
|
* tor-bytes: Add cursor functionality to ReaderNick Mathewson2023-02-281-0/+61
| | | | | We'll use this to implement signature and MAC checking for EstablishIntro cells.
* Change tor_bytes::Error::BadMessage to a Cow.Nick Mathewson2023-02-092-2/+11
| | | | | | | | | | Actually, to avoid making a breaking change, I'm deprecating BadMessage and creating a new InvalidMessage variant that takes a Cow. This way I don't need to track every crate that re-exposes tor_bytes::Error and call this a breaking change in those. Making this change will allow tor_bytes errors to be much more helpful.
* Allow clippy::unchecked_duration_subtraction in testsNick Mathewson2023-01-272-0/+2
| | | | | This panics on error, and we're fine with a panic on misbehavior in tests.
* Disable clippy::unlinlined-format-argsNick Mathewson2023-01-271-0/+1
| | | | | | | | This warning kind of snuck up on us! (See #748) For now, let's disable it. (I've cleaned it up in a couple of examples, since those are meant to be more idiomatic and user-facing.) Closes #748.
* tor-bytes: impl Writeable for &impl WriteableIan Jackson2023-01-241-0/+6
|
* tor-bytes: Implement conversion from EncodeError to BugIan Jackson2023-01-241-1/+16
|
* test lint blocks: Add many many automaticallyIan Jackson2022-12-122-0/+18
| | | | | This is precisely the result of running the rune in maint/adhoc-add-lint-blocks.
* Run add_warnings.Nick Mathewson2022-11-031-0/+1
|
* tor-bytes: Avoid redundant allocationEmil Engler2022-10-251-1/+1
| | | | See c489e1d9118edd842f80b76a636037524a45ee45
* Fix some rustdoc errors.Nick Mathewson2022-10-133-9/+6
| | | | | | In addition to the usual "You named that method wrong!" errors, we have a new rustdoc error that complains about bogus "HTML tags" that are actually unquoted usage of types like `Result<Foo>`.
* cargo fmt to remove blank linesIan Jackson2022-10-121-1/+0
| | | | | | | Apparently cargo fmt doesn't like these, which my perl rune didn't delete. This commit is precisely the result of `cargo fmt`.
* Replace all README copies in src/lib.rs with includesIan Jackson2022-10-121-48/+1
| | | | | | | | The feature we want is `#[doc = include_str!("README.md")]`, which is stable since 1.54 and our MSRV is now 1.56. This commit is precisely the result of the following Perl rune: perl -i~ -0777 -pe 's{(^//!(?!.*\@\@).*\n)+}{#![doc = include_str!("../README.md")]\n}m' crates/*/src/lib.rs
* enable doc_auto_cfg feature on every crate when documenting for docs.rstrinity-1686a2022-08-241-0/+1
|
* New SecretBuf type in tor-bytesNick Mathewson2022-08-012-0/+125
| | | | | | | | | This Writer is a simple wrapper around `Vec<u8>` that makes sure that its contents are cleared whenever they are dropped _or reallocated_. The reallocation is the important part here: without that, we risk not zeroizing the first allocation of the buffer.
* Apply 1 suggestion(s) to 1 file(s)eta2022-07-191-1/+1
|
* Remove the last vestiges of write_infallible.Nick Mathewson2022-07-112-41/+6
| | | | | Now that everything has been converted to fallible writers, we get to finally remove write_infallible() from tor_bytes.
* tor-bytes::impls: Remove usage of infallible writers.Nick Mathewson2022-07-111-2/+2
|
* Remove "write_and_consume_infallible".Nick Mathewson2022-07-111-9/+3
| | | | | | There were only a few of these. Removing it required porting everything to use `write_and_consume` instead, and handling its (potential) errors.
* Convert each write_onto_infallible implementation into write_onto.Nick Mathewson2022-07-112-15/+29
|
* Convert each write_into_infallible implementation into write_into.Nick Mathewson2022-07-111-1/+2
| | | | (There was only one.)
* Define new write_into and write_onto methods with correct APIs.Nick Mathewson2022-07-112-6/+56
|
* Rename "write" methods on tor-bytes to "write_infallible".Nick Mathewson2022-07-113-31/+31
| | | | | | | | | | | | | | | This comprises four renames: ``` write_onto -> write_onto_infallible write_into -> write_into_infallible write -> write_infallible writer_and_consume -> write_and_consume_infallible. ``` The rest of this branch will be concerned with replacing these `_infallible` methods with ones that return a `Result`. This is part of #513.
* Add a Bug variant to tor-bytes::EncodeError.Nick Mathewson2022-07-112-2/+11
| | | | This will help down the line as we make more writers fallible.
* Merge branch 'clippy' into 'main'Ian Jackson2022-06-241-0/+3
|\ | | | | | | | | Fix clippy nightly again See merge request tpo/core/arti!603
| * Run maint/add_warning crates/*/src/{lib,main}.rsIan Jackson2022-06-231-0/+3
| | | | | | | | Update all lint blocks
* | tor-bytes: Split EncodeError from ErrorNick Mathewson2022-06-233-8/+18
|/ | | | | | | | | | | Since there is currently only one error type that can occur when encoding, it doesn't make sense to use the full Error type here. This split will help us downstream, as we no longer need to categorize tor_bytes::Error as "an error in encoding or decoding". I considered renaming Error to DecodeError, but that had pretty huge downstream effects, and didn't seem to be worth it.
* Style fixes to tor-bytes errors.Nick Mathewson2022-06-221-5/+9
| | | | | Also note an issue with the design of tor-bytes::Error that should probably go in a separate MR.
* tor-bytes: read_nested_*: rustfmtIan Jackson2022-06-101-13/+23
| | | | I disagree with almost all of these layout decisions...
* tor-bytes: read_nested_*: Take a closureIan Jackson2022-06-101-25/+40
| | | | | | | | | | This eliminates the possibility of writing the bug of failing to call `should_be_exhausted`. As per this discussion https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/572#note_2811464 Fixes #498
* Fix typos in docs and commentsNick Mathewson2022-06-091-2/+2
|
* tor-bytes: Provide nested writersIan Jackson2022-06-091-1/+116
|
* tor-bytes: Provide nested readersIan Jackson2022-06-092-0/+70
|
* tor-bytes: Reader: Provide take_restIan Jackson2022-06-092-0/+20
| | | | We'll want this in a moment.
* tor-bytes: Prepare errors for nested reader/writerIan Jackson2022-06-091-1/+5
| | | | Writing is going to be able to give errors too.
* lints: Add let_unit_value allow to all cratesIan Jackson2022-05-311-0/+1
| | | | | From running add_warning, with manual picking of the right hunks/lines.
* lints: Add lint block delimiters to every crateIan Jackson2022-05-311-0/+2
| | | | | | This was the result of: maint/add_warning crates/*/src/{lib,main}.rs and then manually curating the results.