| Commit message (Collapse) | Author | Age | Files | Lines |
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
This crate is new, and gets a bump to 0.1.0.
tor-log-ratelim
This crate had a breaking change:
tor-persist
tor-llcrypto had a breaking change. These crates _are_
tor-llcrypto, or (transitively) depend on it. I am assuming that
they all re-expose something from it in a way that matters:
tor-llcrypto
tor-bytes
tor-hscrypto
tor-socksproto
tor-checkable
tor-cert
tor-linkspec
tor-cell
tor-proto
tor-netdoc
tor-consdiff
tor-netdir
tor-chanmgr
tor-ptmgr
tor-guardmgr
tor-circmgr
tor-dirclient
tor-dirmgr
tor-keymgr
tor-hsclient
tor-hsservice
tor-hsrproxy
arti-client
arti-rpcserver
arti-hyper
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
These crates had backward-compatible changes, and get a patchlevel
bump only:
fs-mistrust
tor-error
tor-config
tor-rtcompat
tor-rtmock
This crate exposes no non-CLI APIs, and gets a patchlevel bump only:
arti
|
| |\
| |
| |
| |
| | |
tor-keymgr: Remove unnecessary impls for KeystoreCorruptionError.
See merge request tpo/core/arti!1779
|
| | |
| |
| |
| |
| |
| |
| | |
These impl only exist because they were needed back when we didn't
have the `tor_keymgr::Error` enum and all errors _had_ to implement
`KeystoreError`. They are not used or required anymore, so let's remove
them.
|
| |\ \
| | |
| | |
| | |
| | | |
Increase our MSRV to 1.70
See merge request tpo/core/arti!1773
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
With this change, we no longer expose the ExpandedSecretKey
unescorted, which makes it harder to misuse the API.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
This code was needed with the old version of dalek-cryptography,
which wasn't compatible with up-to-date versions of the `rand`
crate(s). But now that we've upgraded, we can drop this.
(We could have left it around and deprecated it, but we are already
making a breaking change to tor-llcrypto by upgrading
dalek-cryptography.)
|
| | |/
|/|
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
The main changes that we have to adjust for are as follows:
* In x25519-dalek:
* `StaticSecret` is now behind a feature.
* `StaticSecret::new` is deprecated in favor of
`StaticSecret::random_from_rng`.
* StaticSecret no longer does its own clamping.
* In ed25519-dalek:
* `SecretKey` has (in effect) been renamed to `SigningKey`. The name
`SecretKey` is now an alias for `[u8; 32]`.
* `SigningKey` is effectively a keypair, since it contains a
public key as well.
* `PublicKey` has been renamed to `VerifyingKey`.
* The functions to extract a signing key and verifying key have
been renamed as you might expect.
* `ExpandedSecretKey` has been moved to `hasmat` and no longer
implements `sign`.
* `ExpanededSecretKey` now has as its elements a scalar and a hash
prefix.
* Various functions that took `&[u8]` now take `&[u8; N]`.
* We no longer need a wrapper for older versions of rand.
There is a single test in tor-keymgr that does not pass. I've
marked it as ignore for now, in hopes that @gabi-250 can help me
figure it out.
This closes #808. There are several changes I want to make before
we merge, however. They are marked with TODO DALEK.
|
| | |
| |
| |
| |
| |
| |
| | |
`ArtiNativeKeystore::list` now returns an error if the parent directory
of any of its keys doesn't pass the `CheckedDir::read_dir` validation.
Part of #1117
|
| |/
|
|
|
|
|
| |
This updates `ArtiNativeKeystore` to use the new `remove_file` API from
arti!1759.
Part of #1117
|
| | |
|
| |\
| |
| |
| |
| |
| |
| | |
tor-keymgr: Derive Builder for KeyMgr.
Closes #1114
See merge request tpo/core/arti!1760
|
| | |
| |
| |
| |
| |
| |
| | |
Eventually these will need to be auto-generated, but that is not
possible right now.
Context: https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1760#note_2969841
|
| | |
| |
| |
| | |
We don't use this now that we have a `KeyMgrBuilder`.
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| | |
`KeyMgr` is soon going to have more fields, so now is a good time to
derive `Builder` for it.
Closes #1114
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
tor-keymgr: Add a top-level Error enum
Closes #1113
See merge request tpo/core/arti!1751
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
We were previously returning `internal!`, which is incorrect: this is a
type of Arti keystore corruption error, not an internal error.
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | | |
`KeystoreCorruptionError` is now part of `tor_keymgr::Error` and no
longer implements `KeystoreError` (the `KeystoreError` trait is now only
for keystore-specific errors).
|
| | | |
| | |
| | |
| | | |
We don't use this anymore.
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Previously, the `tor_keymgr::Error` type was `Box<dyn KeystoreError>`.
This forced us to impl `KeystoreError` for any error returned by the
keymgr (including those that were not coming from a `Keystore` impl).
Now, `tor_keymgr::Error` is an non-exhaustive enum and the `Box<dyn
KeystoreError>` opaque error type is only returned from `Keystore` impls
The reason we're keeping the `dyn KeystoreError` error type is because
it enables `Keystore` implementors to use their own error types. Without
it, they would have to choose from our (closed) set of error variants,
which may not be suitable for their keystore. See #901.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
We are about to add a top-level `tor_keymgr::Error` enum that has a
variant that contains a `KeyType`. The error enum needs to be `Clone`,
so we need `KeyType` (both the dummy version and the "real" one, because
the `err` module is not cfg'd behind the `keymgr` feature) to be
`Clone`.
|
| | | |
| | |
| | |
| | |
| | |
| | | |
KeystoreCorruptionError is about to become a variant of the top-level
keymgr Error enum (which doesn't exist yet but will be introduced in a
future commit).
|
| | |/
| |
| |
| | |
An `SshKeyError` *is* an Arti keystore error, so let's unify the two.
|
| |/ |
|
| |\
| |
| |
| |
| |
| |
| | |
tor-keymgr: Support encoding more than one denotator in an ArtiPath.
Closes #1093 and #1112
See merge request tpo/core/arti!1747
|
| | | |
|
| | | |
|
| | |
| |
| |
| | |
Closes arti#1112
|
| |\ \
| |/
|/|
| |
| |
| |
| | |
tor-hscrypto: Deprecate HsClientIntroAuth{Key, Keypair}.
Closes #1037
See merge request tpo/core/arti!1749
|
| | |
| |
| |
| |
| | |
`HsClientIntroAuthKeypair` is deprecated and no longer used as an
"encodable key".
|
| | |
| |
| |
| | |
(fmt).
|
| | | |
|
| | | |
|
| | | |
|
| | |
| |
| |
| | |
We don't use this anymore.
|
| | | |
|
| | | |
|
| | | |
|
| | | |
|
| | |
| |
| |
| | |
This also fixes a clippy warning about a needless borrow.
|
| | |
| |
| |
| |
| |
| |
| | |
Clippy is wrong here: it's complaining about us not using `$crate`, when
we _are_ using `$crate`.
See https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1733#note_2965924
|
| | | |
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| |
| | |
For the most part, this is just code movement. The implementation was
copied over to `define_derive_adhoc` from `define_key_specifier`, with
some minor adjustments that were needed to make it compile.
Closes #1093
|
| | | |
|