summaryrefslogtreecommitdiff
path: root/crates/tor-keymgr/src
Commit message (Collapse)AuthorAgeFilesLines
* Merge branch 'patch-1' into 'main'David Goulet2026-05-282-1/+5
|\ | | | | | | | | feat: Make KeystoreEntry::new() public See merge request tpo/core/arti!3288
| * feat: Make KeystoreEntry::new() publicAaron Dewes2025-09-292-1/+5
| | | | | | | | | | | | | | | | | | | | | | Commit 6958b6c8 changed the way the `Keystore` trait works. The `list` method must now return a `KeystoreEntry`. Before this change, it was essentially impossible to implement keystores outside of `tor-keymgr`. For 3rd party users of the Arti API that want to implement a custom keystore, it became essentially impossible to do so. To make this work again, this commit makes KeystoreEntry::new() public, if the experimental-api feature is enabled.
* | keymgr: Add a TODO about possibly removing RawEntryId::EphemeralGabriela Moldovan2026-05-181-0/+11
| |
* | keymgr: Rephrase the remove_unchecked docs for clarityGabriela Moldovan2026-05-181-5/+5
| |
* | keymgr: Clarify that not all keystores support stringly-typed entry IDsGabriela Moldovan2026-05-181-0/+12
| |
* | keymgr: Remove a couple unused From<> implsGabriela Moldovan2026-05-182-20/+0
| | | | | | | | | | These are unused, and I don't think they're needed by our API users either, since `KeystoreEntryResult` is just a type alias for `Result`.
* | keymgr: Update tests to stop using RawKeystoreEntry (fmt)Gabriela Moldovan2026-05-181-3/+1
| |
* | keymgr: Update tests to stop using RawKeystoreEntryGabriela Moldovan2026-05-182-15/+15
| | | | | | | | `RawKeystoreEntry` no longer exists, so these tests need to be updated.
* | keymgr: Remove RawKeystoreEntry (fmt)Gabriela Moldovan2026-05-184-6/+6
| |
* | keymgr: Remove RawKeystoreEntryGabriela Moldovan2026-05-187-76/+32
| | | | | | | | | | | | | | | | | | | | | | | | I think this adds unnecessary indirection, and it's a bit confusing to have two separate keystore entry types (we have `KeystoreEntry` too). This type exists just to server as a wrapper over the `RawEntryId` of an unrecognized keystore entry, and the `KeystoreId` of the keystore it was found in. This commit folds `RawKeystoreEntry` into `UnrecognizedEntry`, which was previously a thin wrapper over `RawKeystoreEntry`.
* | tor-cert: Ed25519CertBuilder: do builder fn renameIan Jackson2026-04-292-2/+2
| | | | | | | | | | | | Change all call sites. This completes the rename.
* | keymgr: Remove outdated references to derive-adhocGabriela Moldovan2026-04-161-3/+3
| | | | | | | | | | This updates some outdated references from back when `derive-deftly` was called `derive-adhoc`.
* | keymgr: Use CAPS for metasyntactic variables in macroGabriela Moldovan2026-04-161-6/+6
| | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3891#note_3395849
* | keymgr: Don't require ctor_path attr to be quotedGabriela Moldovan2026-04-162-2/+2
| | | | | | | | This updates a doc and the corresponding test.
* | keymgr: Use unquoted keypair_specifier in testsGabriela Moldovan2026-04-161-1/+1
| |
* | keymgr: Make KeySpecifier take an unquoted keypair_specifierGabriela Moldovan2026-04-161-2/+2
| | | | | | | | This also makes the macro `beta_deftly`.
* | keymgr: Require keypair_specifier to be a typeGabriela Moldovan2026-04-161-1/+1
| | | | | | | | | | | | I want to make all uses of `keypair_specifier` unquoted, so this can't be a `token_stream` (and in fact, `keypair_specifier` was always meant to be a type).
* | keymgr: Update outdated KeySpecifier docGabriela Moldovan2026-04-161-1/+1
| | | | | | | | This attribute is called `keypair_specifier`, not `key_specifier`.
* | keymgr: Fix ephemeral keystore cert encoding bug (fmt)Gabriela Moldovan2026-04-081-6/+3
| |
* | keymgr: Fix ephemeral keystore cert encoding bugGabriela Moldovan2026-04-081-4/+25
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This fixes a bug that was causing the ephemeral keystore to retrieve certs in a format that couldn't be handled by the `KeyMgr`. This caused all certificate retrievals from `EphemeralKeystore` done via the `KeyMgr` to fail with an internal error. For context, the only supported cert type is `TorEd25519Cert`, which is a pre-encoded certificate (i.e. a type wrapper over a `Vec<u8>`). These certificates are stored as-is by the Arti native keystore (the bytes are written to a file on disk). When retrieving a `TorEd25519Cert`, the Arti keystore uses `parse_certificate_erased()` to parse the cert into a `ParsedEd25519Cert` before returning it as a type-erased `ErasedKey`. This works as intended with the `KeyMgr` retrieval and downcasting logic, which expects the certificate to be returned in the `ParsedCert` format specified in the `ToEncodableCert` implementation. Before this change, the ephemeral keystore, on the other hand, did not play well with the `KeyMgr` when it came to cert retrieval: it would incorrectly store the `KeystoreItem` as-is, and retrieve it as an `ErasedKey` using the `ErasedKey::into_erased()` implementation. This would then cause the `KeyMgr` to fail to downcast the `ErasedKey` to the correct type (because the returned erased item was of a different type than `ParsedCert`). This commit also removes `KeystoreItem::into_erased()`, which was a footgun (because certificates are not actually supposed to be retrieved in the format returned by `CertData::into_erased()`).
* | tor-keymgr: migrate to web-time-compat.Nick Mathewson2026-03-262-3/+3
| |
* | Fix typosTobias Stoeckmann2026-03-241-2/+4
| | | | | | | | Typos found with codespell
* | keymgr: Remove now-addressed XXXGabriela Moldovan2026-03-171-3/+0
| |
* | keymgr: Fix feature-gating in testsGabriela Moldovan2026-03-171-4/+3
| |
* | keymgr: Lower get() logic into get_from_store()Gabriela Moldovan2026-03-171-13/+15
| | | | | | | | | | | | | | | | | | This moves the logic for retrieving a public key from its corresponding keypair into `get_from_store()`. Fixes a bug which made it impossible to retrieve a public key using the key specifier of its keypair type with any function other than `KeyMgr::get()`.
* | keymgr: Add more tests to reveal the get_*() bug for public keysGabriela Moldovan2026-03-171-1/+65
| | | | | | | | This will be fixed in the next commit.
* | keymgr: Pass the item type to entry_descriptor() (fmt)Gabriela Moldovan2026-03-171-1/+5
| |
* | keymgr: Pass the item type to entry_descriptor()Gabriela Moldovan2026-03-171-4/+4
| | | | | | | | I am about to repurpose this test helper for other item types too.
* | keymgr: Preserve item metadata when converting to TestPublicKey (fmt)Gabriela Moldovan2026-03-171-1/+4
| |
* | keymgr: Preserve item metadata when converting to TestPublicKeyGabriela Moldovan2026-03-171-1/+3
| | | | | | | | This will enable us to test the provenance of public keys.
* | keymgr: Update cert testsGabriela Moldovan2026-03-171-1/+16
| | | | | | | | | | | | | | | | | | | | | | | | | | | | This is needed now that `get_or_generate_key_and_cert()` uses the keypair specifier when generating the subject key. Without this the cert retrieval tests fail because `get_or_generate_key_and_cert()` now requires the subject key specifier to have an associated keypair specifier ("KeyCertificateSpecifier has no keypair specifier for the subject key?"). Note that even with this patch, the `get_cert_entry()` test still fails because of a bug in the `get_*()` family of functions. This will be fixed in a future commit.
* | keymgr: Use the keypair specifier when generating keys.Gabriela Moldovan2026-03-171-1/+9
| | | | | | | | | | | | | | When generating a new keypair, we want to use the keypair specifier of the subject key. Fixes a bug where this code was incorrectly generating a keypair using the specifier of the public key type (the resulting generated key had a `kp_` prefix instead of `ks_`).
* | keymgr: Add test retrieving an expired certGabriela Moldovan2026-03-121-1/+77
| | | | | | | | | | This tests that the `KeyMgr` returns an error if you try to retrieve an invalid cert.
* | keymgr: Introduce a new TestCert typeGabriela Moldovan2026-03-121-4/+28
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is a bit of a hack, but we need it to make the tests pass. The issue is that our test keystore stores `TestItem`s, and all our other test used `TestItem` as their key types. Now that we have certs, we have this concept of a `ToEncodableCert::ParsedCert`, which is what the keymgr downcasts the retrieved certs to before validating them and returning the final cert result (which is usually going to be of a different type than `ParsedCert`). This wrapper ensures that the keystore returns the expected `ParsedCert` type, so that validation doesn't fail. Before this change, we were hackily returning `TestItem` in the tests, even for certificates, but that doesn't work anymore, because the `ItemType` impl of `TestItem` returns `KeyType::Ed25519Keypair`, which is obviously not a `CertType`. Using it resulted in an error because there is a mismatch between the cert `ItemType` (`Ed25519Keypair`) and the `ItemType` of the `KeystoreItem::Cert` entry (`Ed25519TorCert`). Normally this wouldn't happen, but the whole test keystore implementation is funky and inconsistent.
* | keymgr: Add tests for the new get_cert() APIGabriela Moldovan2026-03-121-1/+89
| |
* | keymgr: Generate test cert specifiers using d-dGabriela Moldovan2026-03-122-24/+26
| | | | | | | | | | | | This will enable us to test against other keymgr APIs (e.g. `list_matching()`), which require some extra trait impls that get generated for free by our new `CertSpecifier` macro.
* | keymgr: Reexport the d-d helpersGabriela Moldovan2026-03-121-0/+5
| |
* | keymgr: Make make_certificate() a top-level functionGabriela Moldovan2026-03-121-31/+32
| | | | | | | | This will soon be used by other tests too.
* | keymgr: Add test for the auto-generated cert patternsGabriela Moldovan2026-03-121-0/+34
| |
* | keymgr: Add new KeyMgr::get_cert_entry() APIGabriela Moldovan2026-03-121-1/+70
| | | | | | | | | | | | This will enable us to retrieve a cert given its `KeystoreEntry`. This is useful for retrieving certificates listed with `KeyMgr::list_matching()`.
* | keymgr: Remove old has_certificate() optionGabriela Moldovan2026-03-121-52/+0
| | | | | | | | This was replaced by the new `CertSpecifier` d-d macro.
* | keymgr: Add a new experimental CertSpecifier macroGabriela Moldovan2026-03-121-0/+303
| | | | | | | | | | This will replace the `has_certificate()` attr from the `KeySpecifier` d-d macro.
* | keymgr: Move extract() out of parse_arti_path()Gabriela Moldovan2026-03-121-41/+41
| | | | | | | | This will soon be used for parsing the denotators of cert paths too.
* | keymgr: Abolish KeyCertificateSpecifier::signing_key_specifier() (fmt)Gabriela Moldovan2026-03-121-3/+1
| |
* | keymgr: Abolish KeyCertificateSpecifier::signing_key_specifier()Gabriela Moldovan2026-03-124-49/+12
| | | | | | | | | | | | | | We need to be able to parse KeyPaths into KeyCertificateSpecifier, and we can't do that if the signing key is part of the cert specifier (because the signing key doesn't get encoded in the key path, unlike the subject key, which does)
* | keymgr: Add a new trait for cert specifier patternsGabriela Moldovan2026-03-122-0/+31
| | | | | | | | | | These are significantly different from `KeySpecifierPattern`s, so it's best to have a separate trait.
* | Merge branch 'cert-denotators2' into 'main'Ian Jackson2026-03-114-30/+143
|\ \ | | | | | | | | | | | | | | | | | | keymgr: Update cert ArtiPath building to use denotator sets Closes #2377 See merge request tpo/core/arti!3754
| * | keymgr: Do not elide leading empty denotator groupsGabriela Moldovan2026-03-051-2/+5
| | | | | | | | | | | | Addresses https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3754#note_3361904
| * | keymgr: Replace literal value with constantGabriela Moldovan2026-03-051-1/+1
| | |
| * | keymgr: Add test for paths with empty denotator groups (fmt)Gabriela Moldovan2026-03-051-1/+4
| | |