aboutsummaryrefslogtreecommitdiff
path: root/crates/tor-keymgr/src
Commit message (Collapse)AuthorAgeFilesLines
...
* | keymgr: Abolish KeyCertificateSpecifier::signing_key_specifier() (fmt)Gabriela Moldovan2026-03-121-3/+1
| |
* | keymgr: Abolish KeyCertificateSpecifier::signing_key_specifier()Gabriela Moldovan2026-03-124-49/+12
| | | | | | | | | | | | | | We need to be able to parse KeyPaths into KeyCertificateSpecifier, and we can't do that if the signing key is part of the cert specifier (because the signing key doesn't get encoded in the key path, unlike the subject key, which does)
* | keymgr: Add a new trait for cert specifier patternsGabriela Moldovan2026-03-122-0/+31
| | | | | | | | | | These are significantly different from `KeySpecifierPattern`s, so it's best to have a separate trait.
* | Merge branch 'cert-denotators2' into 'main'Ian Jackson2026-03-114-30/+143
|\ \ | | | | | | | | | | | | | | | | | | keymgr: Update cert ArtiPath building to use denotator sets Closes #2377 See merge request tpo/core/arti!3754
| * | keymgr: Do not elide leading empty denotator groupsGabriela Moldovan2026-03-051-2/+5
| | | | | | | | | | | | Addresses https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3754#note_3361904
| * | keymgr: Replace literal value with constantGabriela Moldovan2026-03-051-1/+1
| | |
| * | keymgr: Add test for paths with empty denotator groups (fmt)Gabriela Moldovan2026-03-051-1/+4
| | |
| * | keymgr: Add test for paths with empty denotator groupsGabriela Moldovan2026-03-051-0/+12
| | |
| * | keymgr: Add more tests for cert ArtiPath construction (fmt)Gabriela Moldovan2026-03-052-9/+9
| | |
| * | keymgr: Add more tests for cert ArtiPath constructionGabriela Moldovan2026-03-051-2/+17
| | | | | | | | | | | | | | | This commit is intentionally misindented to make reviewing the diff a bit easier.
| * | keymgr: Update cert ArtiPath building to use denotator groupsGabriela Moldovan2026-03-051-7/+18
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | In a certificate's `ArtiPath`, the `ArtiPath` of the subject key is now separated from the certificate denotators by `@`. This will enable us to derive the subject key `ArtiPath` from the `ArtiPath` of its certificate. In practice, this change is a no-op for the relay implementation, because none of our certificates have certificate denotators. For instance, the `ArtiPath` of the for the `KP_relaysign_ed` certificate (`KP_relaysign_ed` signed with `KS_relayid_ed`) is of the form `relay/relaysign_ed+<valid_until>` (the only denotators here are the denotators of the subject key). It's important to note that the certifying key is not encoded in the `ArtiPath` of the certificate. The implication is that if we'll ever need to have multiple certs for the same subject key, signed with different with different certifying keys, those certificates will be distinguished by their certificate denotator group. So if we ever need a second certificate for `KP_relaysign_ed`, certified with something other than `KP_relaysign_ed`, it will need to be of the form `relay/relaysign_ed+<valid_until>@<CERT_DENOS>`, where `<CERT_DENOS>` is a list of `+`-separated certificate denotators. Closes #2377
| * | keymgr: Support having multiple denotator groups within an ArtiPathGabriela Moldovan2026-03-052-4/+14
| | | | | | | | | | | | | | | | | | This will enable us to parse certificate paths that consist of the `ArtiPath` of the subject key, followed by the denotator group of the certificate.
| * | keymgr: Move denotator group validation to a separate functionGabriela Moldovan2026-03-051-3/+10
| | |
| * | keymgr: Update ArtiPath docs with the new denotator rulesGabriela Moldovan2026-03-051-3/+21
| | | | | | | | | | | | | | | | | | | | | This introduces the concept of a "denotator group", and new syntax for separating denotator groups within an ArtiPath. The implementation will follow in a separate commit.
| * | keymgr: Implement KeySpecifier for KeyCertificateSpecifiersGabriela Moldovan2026-03-052-5/+39
| | | | | | | | | | | | | | | | | | | | | | | | | | | `KeyCertificateSpecifiers` have an `ArtiPath`, so it's only natural to retrieve it via this new `KeySpecifier` implementation. This replaces the old, ad-hoc `ArtiPath` building from the `KeyMgr` implementation: IMO, the `KeyMgr` impl is the wrong place to build these `ArtiPath`s (ideally they should remain opaque to the `KeyMgr`).
* | | keymgr: Remove unnecessary TestItem building (fmt)Gabriela Moldovan2026-03-101-1/+4
| | |
* | | keymgr: Remove unnecessary TestItem buildingGabriela Moldovan2026-03-101-4/+1
| | |
* | | keymgr: Remove unnecessary parenthesesGabriela Moldovan2026-03-101-1/+1
| | | | | | | | | | | | Resolves a clippy warning.
* | | keymgr: Replace .find(...).is_some() with .any() (fmt)Gabriela Moldovan2026-03-101-9/+4
| | |
* | | keymgr: Replace .find(...).is_some() with .any()Gabriela Moldovan2026-03-101-3/+2
| | | | | | | | | | | | Resolves a clippy warning.
* | | keymgr: Replace Result<> with type alias (fmt)Gabriela Moldovan2026-03-101-5/+5
| | |
* | | keymgr: Replace match with if letGabriela Moldovan2026-03-101-4/+1
| | | | | | | | | | | | As suggested by clippy
* | | keymgr: Replace Result<> with type alias (fmt)Gabriela Moldovan2026-03-101-3/+5
| | |
* | | keymgr: Replace Result<> with type aliasGabriela Moldovan2026-03-101-1/+1
| | |
* | | keymgr: Remove unnecessary type annotationGabriela Moldovan2026-03-101-4/+1
| | |
* | | keymgr: Replace macro-generated Keystore impls with a single Keystore type (fmt)Gabriela Moldovan2026-03-101-162/+156
| | |
* | | keymgr: Replace macro-generated Keystore impls with a single Keystore typeGabriela Moldovan2026-03-101-33/+22
| | | | | | | | | | | | | | | | | | | | | | | | This doesn't really need to be macro-generated, because these impls only differ in the `KeystoreId`. The code is intentionally misindented to make reviewing the diff a bit easier. A future commit will reformat it all.
* | | keymgr: Move unrecognized entry building logic out of macro (fmt)Gabriela Moldovan2026-03-101-22/+14
| | |
* | | keymgr: Move unrecognized entry building logic out of macroGabriela Moldovan2026-03-101-29/+34
|/ / | | | | | | | | I am about to remove this macro altogether and simplify the keystore impls, so I am preemptively moving this into a separate function.
* | keymgr: Port to derive_deftly(TorConfig)Nick Mathewson2026-02-241-44/+33
| | | | | | | | | | As with previous modules, I've left some thing less conformant with our "standard" APIs in order to keep backward compat (for now).
* | keymgr: Extend d-d helper to derive KeyCertificateSpecifiersGabriela Moldovan2026-02-171-0/+71
| | | | | | | | Closes #2360
* | Allow clippy::collapsible_if to triggerGabriela Moldovan2026-02-161-0/+1
| | | | | | | | | | | | | | | | | | `clippy::collapsible_if` started triggering after bumping the MSRV to 1.88. Since this triggers from a lot of places, and since there even are a couple of instances where we explicitly allow `clippy::collapsible_ifs`, I've opened #2342 for deciding what to do about it.
* | maint/add_warning: Run script to add new warningGabriela Moldovan2026-01-271-0/+1
| | | | | | | | This adds the lint to all our crates.
* | keymgr: Remove redundant field name in struct initGabriela Moldovan2026-01-061-1/+1
| | | | | | | | Fixes a clippy warning.
* | keymgr: Add tests for the unhappy path of from_ctor_path()Gabriela Moldovan2026-01-061-2/+34
| |
* | keymgr: Derive PartialEq for CTorPathErrorGabriela Moldovan2026-01-061-1/+1
| |
* | keymgr: Update tests to use the new d-d macro annotation for CTorPaths (fmt)Gabriela Moldovan2026-01-061-1/+3
| |
* | keymgr: Update tests to use the new d-d macro annotation for CTorPathsGabriela Moldovan2026-01-061-28/+14
| |
* | keymgr: Use d-d to generate CTorPath<->KeySpecifier conversionsGabriela Moldovan2026-01-061-26/+54
| |
* | keymgr: Add a CTorKeySpecifier trait (fmt)Gabriela Moldovan2026-01-061-4/+4
| |
* | keymgr: Add a CTorKeySpecifier traitGabriela Moldovan2026-01-062-1/+18
| |
* | keymgr: Make CTorPath more like the client/service specifiers (fmt)Gabriela Moldovan2026-01-064-12/+21
| |
* | keymgr: Make CTorPath more like the client/service specifiersGabriela Moldovan2026-01-064-74/+50
| | | | | | | | | | | | | | | | | | | | | | | | | | This will make it easier to see the correspondence between CTorPaths and the HS client/service key specifiers. Initially, I was hoping this would make it easier to write a d-d macro that automatically derives a `CTorPath` variant (e.g. `HsClientDescEncKeypair`) from the KeySpecifier type name (`HsClientDescEncKeypairSpecifier`), but alas, I don't think d-d can "chop off" name suffixes ("Specifier", in this case). `from_ctor_path()`/`ctor_path()` implementations for converting `CTorPath`s to and from key specifiers.
* | keymgr: Fix some recently broken doc linksGabriela Moldovan2026-01-063-6/+6
| |
* | keymgr: Resolve a handful of clippy warnings (fmt)Gabriela Moldovan2026-01-061-2/+1
| |
* | keymgr: Resolve a handful of clippy warningsGabriela Moldovan2026-01-062-4/+4
| |
* | keymgr: Push error handling into the from_ctor_path() functionsGabriela Moldovan2026-01-062-16/+9
| |
* | keymgr: Replace placeholder errors with CTorPathError (fmt)Gabriela Moldovan2026-01-061-4/+4
| |
* | keymgr: Replace placeholder errors with CTorPathErrorGabriela Moldovan2026-01-063-10/+35
| |
* | keymgr: Remove unused argument in helper function (fmt)Gabriela Moldovan2026-01-061-6/+1
| |