summaryrefslogtreecommitdiff
path: root/crates/tor-cert/src
Commit message (Collapse)AuthorAgeFilesLines
* Re-run maint/add_warning.Nick Mathewson2024-05-061-2/+2
| | | | This commit is automatically generated.
* Run maint/add_warning.Nick Mathewson2024-03-132-0/+2
|
* deny clippy::unchecked_duration_subtractiontrinity-1686a2024-02-291-0/+1
|
* Remove RngCompatExt.Nick Mathewson2023-11-291-2/+1
| | | | | | | | | | This code was needed with the old version of dalek-cryptography, which wasn't compatible with up-to-date versions of the `rand` crate(s). But now that we've upgraded, we can drop this. (We could have left it around and deprecated it, but we are already making a breaking change to tor-llcrypto by upgrading dalek-cryptography.)
* Convert to the latest versions of dalek-cryptographyNick Mathewson2023-11-292-5/+5
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The main changes that we have to adjust for are as follows: * In x25519-dalek: * `StaticSecret` is now behind a feature. * `StaticSecret::new` is deprecated in favor of `StaticSecret::random_from_rng`. * StaticSecret no longer does its own clamping. * In ed25519-dalek: * `SecretKey` has (in effect) been renamed to `SigningKey`. The name `SecretKey` is now an alias for `[u8; 32]`. * `SigningKey` is effectively a keypair, since it contains a public key as well. * `PublicKey` has been renamed to `VerifyingKey`. * The functions to extract a signing key and verifying key have been renamed as you might expect. * `ExpandedSecretKey` has been moved to `hasmat` and no longer implements `sign`. * `ExpanededSecretKey` now has as its elements a scalar and a hash prefix. * Various functions that took `&[u8]` now take `&[u8; N]`. * We no longer need a wrapper for older versions of rand. There is a single test in tor-keymgr that does not pass. I've marked it as ignore for now, in hopes that @gabi-250 can help me figure it out. This closes #808. There are several changes I want to make before we merge, however. They are marked with TODO DALEK.
* tor-cert, tor-netdoc: Use EncodedEd25519Cert instead of Vec<u8>.Gabriela Moldovan2023-10-251-2/+2
|
* tor-cert: Add EncodedEd25519Cert type.Gabriela Moldovan2023-10-252-0/+15
|
* tor-netdoc: Update outdated doc string.Gabriela Moldovan2023-10-251-1/+1
|
* Run maint/add_warning to add lint block everywhereIan Jackson2023-08-232-0/+2
|
* Merge branch 'dangerously_assume_timely' into 'main'Ian Jackson2023-08-161-1/+1
|\ | | | | | | | | tor-cert: actually use dangerously_assume_timely See merge request tpo/core/arti!1497
| * tor-cert: actually use dangerously_assume_timelyEmil Engler2023-08-101-1/+1
| | | | | | | | | | | | This commit makes a trait function use another currently unused trait function, thereby increasing the test coverage, as well as being potentially more correct from a semantic point of view.
* | doc: note unreachable codeEmil Engler2023-08-101-0/+1
| |
* | test: encode unrecognized `tor_cert::CertExt`Emil Engler2023-08-101-0/+14
|/ | | | | This commit introduces a test for unrecognized `tor_cert::CertExt` fields.
* Run add_warnings on all files.Nick Mathewson2023-08-041-2/+2
|
* Run maint/add_warning to actually apply new lint allowsIan Jackson2023-07-102-0/+3
|
* Run add_warning to remove `missing_panics_doc` deny.Nick Mathewson2023-07-061-1/+0
| | | | Closes #950.
* Remove spurious todo-hs items in tor-cert.Nick Mathewson2023-06-281-6/+0
| | | | | | | I am not sure why we wrote these comments, but they are incorrect: I've investigated the C code and found only 3 key types. The "unimplemented" types that the TODO comment here complains about are in fact certificate types.
* lints: Run maint/add_warning to actually apply new lintsIan Jackson2023-06-211-0/+2
|
* Deprecate check_key, and refactor its logic into the new functions.Nick Mathewson2023-05-161-16/+33
| | | | Closes #759
* Replace usage of KeyUnknownCert::check_key.Nick Mathewson2023-05-161-1/+1
|
* tor-cert: Add new functions to replace KeyUnknownCert::check_key.Nick Mathewson2023-05-161-0/+30
| | | | | | | These should have a cleaner API than check_key, and be easier to understand. Part of #759
* fix a couple clippy lintstrinity-1686a2023-05-081-3/+3
|
* Use the type system to enforce use of blinded keys.Gabriela Moldovan2023-03-271-4/+6
| | | | | | | | | | | | | | | Hidden services use blinded singing keys derived from the identity key to sign descriptor signing keys. Before this patch, the hidden descriptor builder represented its blinded signing keys (`blinded_id`) as plain `ed25519::Keypair`s. This was not ideal, as there was nothing preventing the caller from accidentally initializing `blinded_id` with an unblinded keypair. This introduces a new `HsBlindKeypair` type to represent blinded keypairs. Signed-off-by: Gabriela Moldovan <[email protected]>
* Merge branch 'ticket_525_part2' into 'main'Nick Mathewson2023-02-092-8/+14
|\ | | | | | | | | Apply restricted_msg to ChanMsg parts of tor-proto See merge request tpo/core/arti!1013
| * Change tor_bytes::Error::BadMessage to a Cow.Nick Mathewson2023-02-092-8/+14
| | | | | | | | | | | | | | | | | | | | Actually, to avoid making a breaking change, I'm deprecating BadMessage and creating a new InvalidMessage variant that takes a Cow. This way I don't need to track every crate that re-exposes tor_bytes::Error and call this a breaking change in those. Making this change will allow tor_bytes errors to be much more helpful.
* | Rename key identifiers that have changed in the specNick Mathewson2023-02-081-2/+2
|/ | | | | | | | | Generated with perl: s/K([PS])_hs_intro_tid/K$1_hs_ipt_sid/g; s/K([PS])_onion_ntor/K$1_ntor/g; s/K([PS])_hs_intro_ntor/K$1_hss_ntor/g; s/K([PS])_hs_desc_ephem/K$1_hss_desc_enc/g;
* tor-cert: document hs-related certificate types.Nick Mathewson2023-02-071-4/+25
| | | | | Also, explain why a few of these certificates aren't actually useful as certificates. (This issue is also documented in torspec!110)
* tor-cert: Implement Timebound for Ed25519CertNick Mathewson2023-02-071-4/+16
| | | | | This allows us to run `is_valid_at` and friends on the certificate itself, which we will use soon in hsdesc validity checks.
* Allow clippy::unchecked_duration_subtraction in testsNick Mathewson2023-01-272-0/+2
| | | | | This panics on error, and we're fine with a panic on misbehavior in tests.
* Disable clippy::unlinlined-format-argsNick Mathewson2023-01-271-0/+1
| | | | | | | | This warning kind of snuck up on us! (See #748) For now, let's disable it. (I've cleaned it up in a couple of examples, since those are meant to be more idiomatic and user-facing.) Closes #748.
* tor-cert: add a few hs TODOsNick Mathewson2023-01-061-0/+3
|
* test lint blocks: Add many many automaticallyIan Jackson2022-12-122-0/+17
| | | | | This is precisely the result of running the rune in maint/adhoc-add-lint-blocks.
* Run add_warnings.Nick Mathewson2022-11-031-0/+1
|
* cargo fmt to remove blank linesIan Jackson2022-10-121-1/+0
| | | | | | | Apparently cargo fmt doesn't like these, which my perl rune didn't delete. This commit is precisely the result of `cargo fmt`.
* Replace all README copies in src/lib.rs with includesIan Jackson2022-10-121-51/+1
| | | | | | | | The feature we want is `#[doc = include_str!("README.md")]`, which is stable since 1.54 and our MSRV is now 1.56. This commit is precisely the result of the following Perl rune: perl -i~ -0777 -pe 's{(^//!(?!.*\@\@).*\n)+}{#![doc = include_str!("../README.md")]\n}m' crates/*/src/lib.rs
* Work around a new nightly clippy warningNick Mathewson2022-09-301-1/+1
| | | | | | | | | | | | | | The warning `clippy::bool_to_int_with_if` is meant to shout at you when you say `if x { 1 } else { 0 }` and instead suggest that you say `inttype::from(x)`. I agreed with this for the case in tor-cert, where we are literally converting a boolean into a flag. I don't agree with this in tor-netdoc, where we are using a boolean to decide how many fields to skip in a given document format. So for this case, I decided to clean up the code a little by renaming "skip" to "n_skip", and changing the boolean to use an enum instead.
* add feature annotation not added by doc_auto_cfgtrinity-1686a2022-08-241-0/+1
|
* enable doc_auto_cfg feature on every crate when documenting for docs.rstrinity-1686a2022-08-241-0/+1
|
* Fix typosDimitris Apostolou2022-08-011-1/+1
|
* use Ed25519 identity instead of PublicKey in tor-cert::rsatrinity-1686a2022-07-251-2/+2
|
* change usage of PublicKey to Ed25519 in tor-certtrinity-1686a2022-07-233-24/+23
| | | | and propagate to other affected crates
* change check_key to take a Option<&_> instead of &Option<_>trinity-1686a2022-07-232-3/+3
|
* tor-cert: Remove all usage of infallible writers.Nick Mathewson2022-07-111-1/+1
|
* tor-cert: Encoding now uses Writeable trait.Nick Mathewson2022-07-113-25/+26
| | | | This lets us remove a few TODOs.
* Rename "write" methods on tor-bytes to "write_infallible".Nick Mathewson2022-07-111-1/+1
| | | | | | | | | | | | | | | This comprises four renames: ``` write_onto -> write_onto_infallible write_into -> write_into_infallible write -> write_infallible writer_and_consume -> write_and_consume_infallible. ``` The rest of this branch will be concerned with replacing these `_infallible` methods with ones that return a `Result`. This is part of #513.
* Implement functionality to construct signed Ed25519 certs.Nick Mathewson2022-07-063-79/+239
| | | | | | | | | | | | | | This is behind a feature flag, since it isn't needed for pure clients: only onion services and relays need this. I've named the object that constructs these certs `Ed25519CertConstructor` because it doesn't follow the builder pattern exactly: mainly because you can't get an Ed25519Cert out of it. _That_ part is necessary because we require that an Ed25519Cert should only exist if the certificate was found to be well-signed with the right public key. Closes #511.
* Merge branch 'clippy' into 'main'Ian Jackson2022-06-241-0/+3
|\ | | | | | | | | Fix clippy nightly again See merge request tpo/core/arti!603
| * Run maint/add_warning crates/*/src/{lib,main}.rsIan Jackson2022-06-231-0/+3
| | | | | | | | Update all lint blocks
* | tor-proto: split and elaborate tor_bytes::Error instancesNick Mathewson2022-06-232-27/+51
|/ | | | | | | | | Some of these were for decoding particular objects (we now say what kind of objects), and some were unrelated tor_cert errors that for some reason we had shoved into a tor_bytes::Error. There is now a separate tor_cert::CertError type, independent from tor_cert's use of `tor_bytes::Error` for parsing errors.
* tor-cert: Make more types Clone and Debug.Nick Mathewson2022-06-071-0/+8
| | | | | (Not sure how we missed this before. This is part of making more of tor-netdoc tested.)