| Commit message (Collapse) | Author | Age | Files | Lines |
| |
|
|
|
|
|
| |
I find these names confusing. To my mind "check" implies a function
returning `Result<(), _>`.
Some other APIs use `unwrap` here but I think `if` is good.
|
| |
|
|
|
| |
It wouldn't make much sense for one concrete type to be unwrappable
variously as different inner types.
|
| |
|
|
|
|
|
|
|
|
|
| |
Now that we have `bounds()`, we can centralise this implementation and
delete the implementations.
I don't think it's necessary to provide an engineered safeguard
against downstreams overriding this method. Any existing implementors
of this trait will break because they must provide `.bounds()` now,
which is an opportunity to notice that the `is_valid_at` can be
deleted. But, if it is not deleted, nothing goes wrong.
|
| |
|
|
|
| |
This was always TimeValidityError. And we want to rely on that so we
can do the validity checking more centrally.
|
| |
|
|
|
|
|
| |
This makes a `TimeBound` much more convenient to work with, will allow
more centralisation.
This replaces temporary `bound` inherent method on `TimeRangeBound`.
|
| | |
|
| | |
|
| | |
|
| |
|
|
| |
Removed unnecessary lint
|
| |
|
|
|
|
|
|
| |
This commit derives PartialEq and Eq on the "core" certificate types in
lib.rs, i.e. the Ed25519 certificates and its adjacent data types.
We will need this for proper PartialEq and Eq handling in tor-netdoc at
one point.
|
| | |
|
| | |
|
| | |
|
| |
|
|
|
|
| |
This commit replaces a call to .duration_since(...).expect() with
.saturating_duration_since() for defensive programming. We will change
code related to it in the next commit.
|
| |
|
|
|
|
|
|
|
|
|
|
| |
This commit executes maint/add_warning with the just added change to
deny string slices except in tests.
I recommend auditing this by checking out the previous commit followed
by running the script yourself and then verifying that the diff is
identical to this commit.
This commit makes cargo clippy fail. We will add exceptions in the next
commit.
|
| |
|
|
|
|
| |
This commit derives PartialEq and Eq on CertifiedKey and UnrecognizedKey
in tor-cert. We will need this later for ntor cross certificates in
tor-netdoc.
|
| | |
|
| |
|
|
|
|
|
|
|
|
|
|
|
| |
This is widely used in-tree already. I don't think it makes sense to
feature-gate it.
There are some (perhaps rather thin) tests for both the Ed25519Builder
and EncodedRsaCrosscert.
It is possible we might want to change the API further, but this is
still a 0.x crate so that's not going to be a problem.
We'll remove the actual cargo feature in the next commit.
|
| |
|
|
|
|
| |
Change all call sites.
This completes the rename.
|
| |
|
|
| |
Abolish the type alias and change call references.
|
| |
|
|
|
|
|
|
|
|
| |
This is a perfectly ordinary builder type. There isn't any reason why
it ought to be called "constructor". And, nowadays, we have things in
tor-netdoc called Constructor that take a different approach.
Briefly, leave a temporary compat alias, to make diffs more comprehensible.
Currently this experimental, so no semver implications.
|
| |
|
|
| |
This reverts commit 68caf324a320fff1a4f0e9b0f5014a34d0e3729f.
|
| |
|
|
|
| |
This is more sensible and will make the code in tor-netdoc less strange.
We'll revert the TryFrom in a moment.
|
| |
|
|
|
|
|
|
| |
Implement the Writeable trait.
Explain why this approach is correct and leave a comment near the
decoder (to avoid future changes making this implementation buggy) and
a test case.
|
| |
|
|
| |
Otherwise we can't implement trait-based decoding in tor-netdoc.
|
| | |
|
| |
|
|
|
| |
Most other certificate types do so too and we will need it in
tor-netdoc.
|
| | |
|
| |
|
|
|
|
|
|
| |
Formerly we required the caller for push_cert_body to specify the
type of the cert that they were pushing. But in nearly every case,
the certificate object that the caller is holding knows what its
own type is! This makes the tor_proto build_certs_cell function
a bit less error-prone, since we don't have to worry about mismatch.
|
| |
|
|
|
|
|
|
|
|
|
|
| |
We documented our SystemTime-to-expiry conversion as always rounding
_up_, but we did not account for fractional seconds when doing so.
Therefore, if the requested expiration was set partway through the
first second of an hour, the conversion would round down.
This patch fixes that, and adds a regression test. I've confirmed
that the test fails without this patch.
Closes #2407
|
| |
|
|
|
|
|
| |
These certificates use a weird expiration format: counting hours
since the unix epoch. Previously we had it implemented in two
different places. This patch centralizes it, since we are about to
become slightly more complicated.
|
| | |
|
| |
|
|
|
|
|
|
|
| |
`clippy::collapsible_if` started triggering after bumping the MSRV to
1.88.
Since this triggers from a lot of places, and since there even are a
couple of instances where we explicitly allow `clippy::collapsible_ifs`,
I've opened #2342 for deciding what to do about it.
|
| | |
|
| |
|
|
| |
This adds the lint to all our crates.
|
| |
|
|
|
|
| |
It is always the same type for this specific certificate.
Signed-off-by: David Goulet <[email protected]>
|
| |
|
|
|
|
|
|
|
| |
Fixes part of #2193.
(Edits from nickm: I selected the cases here that I could verify
were correct from immediate context.)
Edited-by: Nick Mathewson <[email protected]>
|
| | |
|
| | |
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Although we never need to actually check the signature on the other
party's x509 certificate, A relay does need a certificate and a
private key in order to be a proper TLS server.
In this function, I've added support for making an ersatz P-256
certificate certifying a P-256 key. See the code for info about the
rationale here. (Tor supports this, since it doesn't look at the
key at all: only the TLS layer cares about that.)
native_tls and rustls expect to get their keys and certs in
different forms, so this code provides them.
(Note that we don't expect to use native_tls with relays in the
first place, but it might be useful for lower-level interop
testing.)
Closes #2205.
|
| | |
|
| | |
|
| |
|
|
|
| |
This doesn't give precisely the same results as before for leap
years, but that should be okay.
|
| |
|
|
| |
Run maint/add_warning
|
| |
|
|
| |
Signed-off-by: David Goulet <[email protected]>
|
| |
|
|
| |
Closes #2197.
|
| |
|
|
| |
This feature has been removed from nightly, in favor of doc_cfg.
|
| |
|
|
|
|
|
|
|
|
| |
```text
warning: duplicated attribute
--> crates/tor-hsservice/src/timeout_track.rs:630:14
|
630 | #![allow(clippy::needless_pass_by_value)] // TODO hoist into standard lint block
| ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
```
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
| |
First, run
```
git grep -l "^edition =" |
xargs perl -i -pe 's/^edition *=.*/edition = "2024"/;'
```
Second, manually verify that all Cargo.toml files have changed,
and nothing else has changed.
Third, run cargo fmt again.
|
| |
|
|
| |
See #2060.
|