aboutsummaryrefslogtreecommitdiff
path: root/crates/tor-cert/src/lib.rs
Commit message (Collapse)AuthorAgeFilesLines
* tor-checkable: TimeBound: Make wrapped type an associated typeIan Jackson2026-07-231-2/+6
| | | | | It wouldn't make much sense for one concrete type to be unwrappable variously as different inner types.
* tor-checkable: TimeBound: Make is_valid_at a provided methodIan Jackson2026-07-231-16/+1
| | | | | | | | | | | Now that we have `bounds()`, we can centralise this implementation and delete the implementations. I don't think it's necessary to provide an engineered safeguard against downstreams overriding this method. Any existing implementors of this trait will break because they must provide `.bounds()` now, which is an opportunity to notice that the `is_valid_at` can be deleted. But, if it is not deleted, nothing goes wrong.
* tor-checkable: TimeBound: remove Error associated typeIan Jackson2026-07-231-8/+4
| | | | | This was always TimeValidityError. And we want to rely on that so we can do the validity checking more centrally.
* tor-checkable: TimeBound: Add bounds accessorIan Jackson2026-07-231-0/+10
| | | | | | | This makes a `TimeBound` much more convenient to work with, will allow more centralisation. This replaces temporary `bound` inherent method on `TimeRangeBound`.
* Use new TimeBound name throughout the treeIan Jackson2026-07-161-2/+2
|
* add_warning: add reference to arti#2556Jim Newsome2026-07-151-1/+1
|
* Removed unnecessary lintpryty262026-07-151-1/+1
| | | | Removed unnecessary lint
* tor-cert: Derive PartialEq and Eq on core typesClara Engler2026-06-291-8/+8
| | | | | | | | This commit derives PartialEq and Eq on the "core" certificate types in lib.rs, i.e. the Ed25519 certificates and its adjacent data types. We will need this for proper PartialEq and Eq handling in tor-netdoc at one point.
* tor-cert: Document expiry inclusiveness for Ed25519CertClara Engler2026-06-111-0/+2
|
* tor-cert: Make Ed25519Cert time bound inclusiveClara Engler2026-06-111-1/+1
|
* tor-cert: Replace duration_since with saturation (fmt)Clara Engler2026-06-111-4/+2
|
* tor-cert: Replace duration_since with saturationClara Engler2026-06-111-2/+3
| | | | | | This commit replaces a call to .duration_since(...).expect() with .saturating_duration_since() for defensive programming. We will change code related to it in the next commit.
* maint: Run maint/add_warning to deny string slicesClara Engler2026-06-091-0/+2
| | | | | | | | | | | | This commit executes maint/add_warning with the just added change to deny string slices except in tests. I recommend auditing this by checking out the previous commit followed by running the script yourself and then verifying that the diff is identical to this commit. This commit makes cargo clippy fail. We will add exceptions in the next commit.
* tor-cert: Derive Eq on CertifiedKeyClara Engler2026-05-261-2/+2
| | | | | | This commit derives PartialEq and Eq on CertifiedKey and UnrecognizedKey in tor-cert. We will need this later for ntor cross certificates in tor-netdoc.
* tor-cert: Stabilise everything gated by feature = "encode" (fmt)Ian Jackson2026-04-291-2/+1
|
* tor-cert: Stabilise everything gated by feature = "encode"Ian Jackson2026-04-291-14/+6
| | | | | | | | | | | | | This is widely used in-tree already. I don't think it makes sense to feature-gate it. There are some (perhaps rather thin) tests for both the Ed25519Builder and EncodedRsaCrosscert. It is possible we might want to change the API further, but this is still a 0.x crate so that's not going to be a problem. We'll remove the actual cargo feature in the next commit.
* tor-cert: Ed25519CertBuilder: do type rename everywhereIan Jackson2026-04-291-4/+0
| | | | Abolish the type alias and change call references.
* tor-cert: Ed25519CertBuilder: rename from Ed25519CertConstructorIan Jackson2026-04-291-1/+5
| | | | | | | | | | This is a perfectly ordinary builder type. There isn't any reason why it ought to be called "constructor". And, nowadays, we have things in tor-netdoc called Constructor that take a different approach. Briefly, leave a temporary compat alias, to make diffs more comprehensible. Currently this experimental, so no semver implications.
* Revert "tor-cert: Provide ed25519 cert decoding via TryFrom trait"Ian Jackson2026-04-271-7/+0
| | | | This reverts commit 68caf324a320fff1a4f0e9b0f5014a34d0e3729f.
* tor-cert: Provide ed25519 cert decoding via tor-bytesIan Jackson2026-04-271-0/+7
| | | | | This is more sensible and will make the code in tor-netdoc less strange. We'll revert the TryFrom in a moment.
* tor-cert: Provide ed25519 cert encoding via tor-bytesIan Jackson2026-04-231-1/+27
| | | | | | | | Implement the Writeable trait. Explain why this approach is correct and leave a comment near the decoder (to avoid future changes making this implementation buggy) and a test case.
* tor-cert: Provide ed25519 cert decoding via TryFrom traitIan Jackson2026-04-231-0/+7
| | | | Otherwise we can't implement trait-based decoding in tor-netdoc.
* tor-cert: impl From<Ed25519Identity> for CertifiedKeyIan Jackson2026-04-231-1/+4
|
* tor-cert: Derive Debug, Clone for SigCheckedCertClara Engler2026-04-221-0/+1
| | | | | Most other certificate types do so too and we will need it in tor-netdoc.
* tor-cert: Port to web-time-compatNick Mathewson2026-03-261-5/+6
|
* cell, proto, cert: Simplify CERTS cell building.Nick Mathewson2026-03-191-1/+1
| | | | | | | | Formerly we required the caller for push_cert_body to specify the type of the cert that they were pushing. But in nearly every case, the certificate object that the caller is holding knows what its own type is! This makes the tor_proto build_certs_cell function a bit less error-prone, since we don't have to worry about mismatch.
* cert: Fix minor but annoying bug in cert expiry calculationNick Mathewson2026-03-171-2/+18
| | | | | | | | | | | | We documented our SystemTime-to-expiry conversion as always rounding _up_, but we did not account for fractional seconds when doing so. Therefore, if the requested expiration was set partway through the first second of an hour, the conversion would round down. This patch fixes that, and adds a regression test. I've confirmed that the test fails without this patch. Closes #2407
* cert: Deduplicate expiry-in-hours logicNick Mathewson2026-03-171-4/+52
| | | | | | | These certificates use a weird expiration format: counting hours since the unix epoch. Previously we had it implemented in two different places. This patch centralizes it, since we are about to become slightly more complicated.
* Allow clippy::collapsible_if to triggerGabriela Moldovan2026-02-161-0/+1
| | | | | | | | | `clippy::collapsible_if` started triggering after bumping the MSRV to 1.88. Since this triggers from a lot of places, and since there even are a couple of instances where we explicitly allow `clippy::collapsible_ifs`, I've opened #2342 for deciding what to do about it.
* cert: Extract x509 code into new tor-cert-x509 crate.Nick Mathewson2026-02-021-1/+2
|
* maint/add_warning: Run script to add new warningGabriela Moldovan2026-01-271-0/+1
| | | | This adds the lint to all our crates.
* Fix name of clippy lint to unchecked_time_subtraction (2)Ian Jackson2025-11-061-2/+2
| | | | Run maint/add_warning
* tor-cert: Generate x509 identity certificates for CERT cellsNick Mathewson2025-10-071-0/+2
| | | | Closes #2197.
* Remove "doc_auto_cfg" incantation from all crates.Nick Mathewson2025-09-291-1/+1
| | | | This feature has been removed from nightly, in favor of doc_cfg.
* Temporarily suppress mismatched_lifetime_syntaxes.Gabriela Moldovan2025-07-071-0/+1
| | | | See #2060.
* Wrap ed25519-dalek types.Nick Mathewson2025-03-181-1/+0
| | | | | | | | | | | With this change, we'll no longer need to expose the types from dalek-cryptography as part of our API, and we'll have more freedom to switch ed25519 implementations, or to upgrade to a newer `rand` ahead of their schedule. Unlike with x25519-dalek, I had to tweak the API a bit: There's no way to get a &PublicKey out of a Keypair now, and implementing the old ed25519-dalek traits seemed unnecessary.
* cert: reserve 0x0C for FAMILY_V_IDENTITY (happy families) certs.Nick Mathewson2025-02-111-0/+4
|
* clippy: deny `mod_module_files`Steven Engler2025-01-061-0/+1
| | | | | | Denies 'mod.rs' files for consistency. https://rust-lang.github.io/rust-clippy/master/index.html#mod_module_files
* add_warnings, *: Allow clippy::needless_lifetimesNick Mathewson2024-12-031-0/+1
| | | | | | | | In 1.83, this warning triggers on many of our crates. We're thinking of fixing them all, but for now, we're going to disable the warning. This is part of #1765.
* Re-run maint/add_warning.Nick Mathewson2024-05-061-2/+2
| | | | This commit is automatically generated.
* Run maint/add_warning.Nick Mathewson2024-03-131-0/+1
|
* deny clippy::unchecked_duration_subtractiontrinity-1686a2024-02-291-0/+1
|
* Convert to the latest versions of dalek-cryptographyNick Mathewson2023-11-291-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The main changes that we have to adjust for are as follows: * In x25519-dalek: * `StaticSecret` is now behind a feature. * `StaticSecret::new` is deprecated in favor of `StaticSecret::random_from_rng`. * StaticSecret no longer does its own clamping. * In ed25519-dalek: * `SecretKey` has (in effect) been renamed to `SigningKey`. The name `SecretKey` is now an alias for `[u8; 32]`. * `SigningKey` is effectively a keypair, since it contains a public key as well. * `PublicKey` has been renamed to `VerifyingKey`. * The functions to extract a signing key and verifying key have been renamed as you might expect. * `ExpandedSecretKey` has been moved to `hasmat` and no longer implements `sign`. * `ExpanededSecretKey` now has as its elements a scalar and a hash prefix. * Various functions that took `&[u8]` now take `&[u8; N]`. * We no longer need a wrapper for older versions of rand. There is a single test in tor-keymgr that does not pass. I've marked it as ignore for now, in hopes that @gabi-250 can help me figure it out. This closes #808. There are several changes I want to make before we merge, however. They are marked with TODO DALEK.
* tor-cert: Add EncodedEd25519Cert type.Gabriela Moldovan2023-10-251-0/+2
|
* Run maint/add_warning to add lint block everywhereIan Jackson2023-08-231-0/+1
|
* tor-cert: actually use dangerously_assume_timelyEmil Engler2023-08-101-1/+1
| | | | | | This commit makes a trait function use another currently unused trait function, thereby increasing the test coverage, as well as being potentially more correct from a semantic point of view.
* Run add_warnings on all files.Nick Mathewson2023-08-041-2/+2
|
* Run maint/add_warning to actually apply new lint allowsIan Jackson2023-07-101-0/+2
|
* Run add_warning to remove `missing_panics_doc` deny.Nick Mathewson2023-07-061-1/+0
| | | | Closes #950.
* Remove spurious todo-hs items in tor-cert.Nick Mathewson2023-06-281-6/+0
| | | | | | | I am not sure why we wrote these comments, but they are incorrect: I've investigated the C code and found only 3 key types. The "unimplemented" types that the TODO comment here complains about are in fact certificate types.