summaryrefslogtreecommitdiff
path: root/crates/tor-keymgr
Commit message (Collapse)AuthorAgeFilesLines
* Bump all the unstable tor- and arti- crates to 0.19.Gabriela Moldovan2024-06-051-8/+8
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The unstable crates are: - tor-error - tor-config - tor-units - tor-geoip - tor-rtcompat - tor-rtmock - tor-log-ratelim - tor-rpcbase - tor-memquota - tor-llcrypto - tor-protover - tor-bytes - tor-hscrypto - tor-socksproto - tor-checkable - tor-cert - tor-linkspec - tor-cell - tor-proto - tor-netdoc - tor-consdiff - tor-netdir - tor-relay-selection - tor-persist - tor-chanmgr - tor-ptmgr - tor-guardmgr - tor-circmgr - tor-dirclient - tor-dirmgr - tor-keymgr - tor-hsclient - tor-hsservice - tor-hsrproxy - arti-client - arti-rpcserver - arti-hyper - tor-basic-utils - tor-async-utils Done using ``` for p in "${unstable[@]}"; do cargo set-version -p $p 0.19; done ``` where `unstable` contains the list above
* tor-keymgr: Regenerate the keys.Gabriela Moldovan2024-05-1612-48/+48
| | | | | The keys generated in this commit are reproducible using the `maint/keygen-openssh-test/generate` script.
* tor-keymgr: Regenerate the test keys.Gabriela Moldovan2024-05-1512-51/+53
| | | | | | | This commit contains a new set of `tor-keymgr/testdata` keys, generated using ./maint/keygen-openssh-test/generate.sh`. Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2121#note_3025369
* tor-keymgr: Move keygen script to maint.Gabriela Moldovan2024-05-156-306/+0
|
* tor-keymgr: Make keygen crate part of the workspace.Gabriela Moldovan2024-05-152-2475/+0
|
* tor-keymgr: Add script for generating test key files.Gabriela Moldovan2024-05-158-0/+2787
| | | | | | | | | | | `tor-keymgr/testdata` contains a bunch of OpenSSH keys used for testing. I meant to share the script I generated them with, but somehow never got around to it. Note: the OpenSSH keys generated by this script are going to look slightly different than the ones that are checked into the repo. This is because some of those original key files were generated ad-hoc (I manually modified them a while ago, but I forgot exactly how
* tor-keymgr: Fix nightly warnings.Gabriela Moldovan2024-05-091-6/+6
| | | | This is a follow-up from !2131
* Merge branch 'keymgr-ephemeral-refactor' into 'main'gabi-2502024-05-0911-616/+830
|\ | | | | | | | | | | | | tor-keymgr: Refactor code shared between ArtiNativeKeystore and ArtiEphemeralKeystore Closes #1362 and #1367 See merge request tpo/core/arti!2131
| * Revert "tor-keymgr: Fix now-failing test."Gabriela Moldovan2024-05-081-0/+16
| | | | | | | | This reverts commit 9ea35caeb1ed23fd029627d04819debc41d85c77.
| * tor-keymgr: Validate the KeyType when inserting into the ephemeral keystore.Gabriela Moldovan2024-05-081-0/+20
| | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2131#note_3028014
| * tor-keymgr: Add function for extracting the KeyType of an ssh key.Gabriela Moldovan2024-05-082-0/+50
| |
| * tor-keymgr: Fix newly failing tests (fmt).Gabriela Moldovan2024-05-081-33/+62
| |
| * tor-keymgr: Fix newly failing tests.Gabriela Moldovan2024-05-082-59/+109
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This updates the keymgr tests to be slightly more robust. These tests attach some metadata to each key, such as the "nickname" of the key (which only exists for testing purposes), whether the key was auto-generated, and the keystore ID of the keystore from which the key was retrieved. Previously, the metadata was encoded in the key "material" itself (the test "keys" were actually just `String`s with a hacky `EncodableKey` implementation that abused the "encrypted" variant of `KeypairData`). This was only possible because we had access to the key internals (through `SshKeyData::Public`/`SshKeyData::Private`), but since the internals are inaccessible now, the tests need to be updated.
| * tor-keymgr: Make SshKeyData an opaque type.Gabriela Moldovan2024-05-073-87/+75
| | | | | | | | | | | | This helps prevent external users from creating `SshKeyData` out of unsupported types of `ssh_key::public::KeyData` and `ssh_key::private::KeypairData`.
| * tor-keymgr: Do not make SshKeyData infallibly convertible from ↵Gabriela Moldovan2024-05-072-11/+49
| | | | | | | | KeyData/KeypairData.
| * tor-keymgr: Seal the EncodableKey trait.Gabriela Moldovan2024-05-072-1/+33
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | As explained in the docs, this trait should not be implementable outside of the `tor-keymgr` crate. The `SshKeyData::into_erased` and `UnparsedOpensshKey::parse_ssh_format_erased` impls assume the types implementing `EncodableKey` form a statically known closed set. If we later decide to make the supported key types an open set, we should make this trait implementable outside of `tor-keymgr` too. External types wanting to create custom "key types" for use in the keymgr should use the non-sealed `ToEncodableKey` trait, which specifies the `EncodableKey` type to use. This trait is mainly used to create `SshKeyData` IMO, we should make `SshKeyData` opaque, since it's not meant to be constructed through other means (`SshKeyData` is currently a public enum, so its variants and the `ssh_key` types they wrap are public). A future commit will make it opaque.
| * tor-keymgr: Update ephemeral keystore docs.Gabriela Moldovan2024-05-071-2/+2
| |
| * tor-keymgr: Dedupe all the convert functions.Gabriela Moldovan2024-05-073-143/+17
| |
| * tor-keymgr: Make an ArtiNativeKeystore-specific function private.Gabriela Moldovan2024-05-071-20/+16
| | | | | | | | | | | | | | The `ssh_algorithm()` function was only meant for use in the ArtiNativeKeystore, for extracting the `KeyType` given the `SshAlgorithm` of a key read from disk, so it really shouldn't be crate-public.
| * tor-keymgr: Move arti-specific ssh code to arti module.Gabriela Moldovan2024-05-078-70/+75
| | | | | | | | | | | | | | | | | | Some of the types and impls from `key_type/ssh.rs` (such as `UnparsedOpenSshKey`) have nothing to do with `KeyType`, and are only used by the `ArtiNativeKeystore`, so I'm moving them to the `arti` keystore module. The shared ssh-related stuff now lives in the top-level `ssh.rs`.
| * tor-keymgr: Test that the ephemeral store returns the correct type.Gabriela Moldovan2024-05-071-2/+6
| |
| * tor-keymgr: Fix now-failing test.Gabriela Moldovan2024-05-071-16/+0
| | | | | | | | | | | | Inserting a key that has the wrong key type no longer fails, because we now store the `KeyData` as-is, without attempting to parse it as a specific kind of SSH key.
| * tor-keymgr: Simplify ephemeral keystore impl.Gabriela Moldovan2024-05-071-31/+6
| | | | | | | | Closes #1362 #1367
| * tor-keymgr: Make SshKeyData convertible to ErasedKey.Gabriela Moldovan2024-05-071-3/+151
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This adds an `SshKeyData::into_erased` function that returns the `SshKeyData` as a type-erased concrete key type (e.g. a type-erased `ed25519::Keypair`). This commit duplicates all of the `convert_*` functions from `key_type/ssh.rs`. A future commit will rewrite the code from `key_type/ssh.rs` to use `SshKeyData::into_erased`, and to remove the duplicate functions. Previously, `EncodableKey` returned an encoded `SshKeyData`, which doesn't implement `EncodableKey`. This was rather inconvenient for `Keystore` implementers. For instance, for the in-memory keystore we ended up working around this limitation by serializing and deserializing `EncodableKey`s to and from `String`. For the full context, see https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2076#note_3016460 Needed for #1362 #1367
| * tor-keymgr: Add an error type for unsupported keys.Gabriela Moldovan2024-05-071-0/+6
| |
| * tor-keymgr: Move parse_ssh_format_erased to UnparsedOpenSshKey.Gabriela Moldovan2024-05-073-39/+37
| | | | | | | | | | I think it makes more sense for parse_ssh_format_erased to be a function of the key than of `KeyType`.
| * tor-keymgr: Move parse_openssh! macro to the top of the file.Gabriela Moldovan2024-05-071-58/+58
| | | | | | | | | | | | We're about to need it in the `UnparsedOpenSshKey` impl. This commit is just code motion and has no functional changes.
| * tor-keymgr: Avoid using UnparsedOpenSshKey.Gabriela Moldovan2024-05-071-5/+6
| | | | | | | | | | | | | | | | | | | | `UnparsedOpenSshKey` was originally only meant to be used for the `ArtiNativeKeystore`. I am about to make it private to the arti module, so I'm updating the ephemeral keystore tests to not use it. Part of #1362
* | Merge branch 'new_ci_cfg_strategy' into 'main'Nick Mathewson2024-05-071-2/+2
|\ \ | |/ |/| | | | | | | | | add_warning/CI: New strategy to avoid "unexpected-cfgs" warning Closes #1395 See merge request tpo/core/arti!2129
| * Re-run maint/add_warning.Nick Mathewson2024-05-061-2/+2
| | | | | | | | This commit is automatically generated.
* | tor-keymgr: Make test module private again.Gabriela Moldovan2024-05-071-1/+1
| | | | | | | | | | | | | | This doesn't need to be public anymore now that the test keys are exported from `test_utils`. Addresses https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2076#note_3016577
* | tor-keymgr: Move TestSpecifier to test_utils.Gabriela Moldovan2024-05-073-26/+49
| | | | | | | | | | | | | | This is used by `ArtiNativeKeystore` and the `EphemeralKeystore`. Moving it to test_utils means `EphemeralKeystore` no longer needs to import test helpers from the arti module.
* | tor-keymgr: Move test constants to test_utils.Gabriela Moldovan2024-05-074-23/+55
|/ | | | | Closes #1363 and addresses a handful of TODOs about `include_str!`ing the same key multiple times from various test modules.
* Bump versions of 0.x tor-* and arti-* cratesIan Jackson2024-04-301-8/+8
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | for p in `cat ../u`; do cargo set-version --locked --offline -p $p; done where u contains tor-basic-utils tor-async-utils tor-error tor-config tor-units tor-geoip tor-rtcompat tor-rtmock tor-log-ratelim tor-rpcbase tor-memquota tor-llcrypto tor-protover tor-bytes tor-hscrypto tor-socksproto tor-checkable tor-cert tor-linkspec tor-cell tor-proto tor-netdoc tor-consdiff tor-netdir tor-relay-selection tor-persist tor-chanmgr tor-ptmgr tor-guardmgr tor-circmgr tor-dirclient tor-dirmgr tor-keymgr tor-hsclient tor-hsservice tor-hsrproxy arti-client arti-rpcserver arti-hyper
* Delete duplicate KeySpecifierComponentPrettyHelperIan Jackson2024-04-251-9/+0
| | | | This had somehow got duplicated; remove the one in derive.rs.
* Merge branch 'rpc_deftly' into 'main'Ian Jackson2024-04-111-1/+1
|\ | | | | | | | | Refactor RPC system to use derive_deftly; add generic-object support See merge request tpo/core/arti!2079
| * Upgrade derive-deftly requirement to 0.10.3Nick Mathewson2024-04-111-1/+1
| | | | | | | | We're taking this for the fix to derive-deftly#52.
* | tor-keymgr: added initial implementation for in-memory ArtiEphemeralKeystoreRichard Pospesel2024-04-105-4/+324
| |
* | tor-keymgr: Export KeyMgrBuilderError.Gabriela Moldovan2024-04-081-1/+1
|/ | | | | | `KeyMgrBuilderError` is used in `KeyMgrBuilder`'s public API. See https://gitlab.torproject.org/tpo/core/arti/-/issues/1358#note_3016025
* Merge branch 'deftly' into 'main'Ian Jackson2024-04-036-76/+78
|\ | | | | | | | | Switch to derive-deftly See merge request tpo/core/arti!2066
| * derive-deftly: Call pub_template_semver_checkIan Jackson2024-04-031-0/+2
| | | | | | | | | | | | | | This is a new feature in d-d 0.10.0. Our currrent semver policy doesn't care about this, but let's not encode that property in the tree and leave ourselves a booby-trap.
| * Switch to derive-deftlyIan Jackson2024-04-036-76/+76
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is the combination of a number of separate commits, many of which were generated by seddery, and then rebased and squashed. Cargo.toml perl -i~ -pe 's{^derive-adhoc}{derive-deftly = "0.10"}' crates/*/Cargo.toml (not regenerated during rebase) update Cargo.lock `cargo fetch` without --locked (regenerated during rebase) seddery git-ls-files | grep '\.rs$' | xargs perl -i~ -pe 's{^use derive_adhoc}{use derive_deftly}' git-ls-files | grep '\.rs$' | xargs perl -i~ -pe 's{\bdefine_derive_adhoc\b}{define_derive_deftly}g' git-ls-files | grep '\.rs$' | xargs perl -i~ -pe 's{\bAdhoc\b}{Deftly}g if m{derive}' git-ls-files | grep '\.rs$' | xargs perl -i~ -pe 's{\#\[derive_adhoc\b}{#[derive_deftly}g' git-ls-files | grep '\.rs$' | xargs perl -i~ -pe 's{use derive_adhoc}{use derive_deftly}' git-ls-files | grep '\.rs$' | xargs perl -i~ -pe 's{\bderive_adhoc\b}{derive_deftly_adhoc} if m{use.*deftly}' git-ls-files | grep '\.rs$' | xargs perl -i~ -pe 's{\bderive_adhoc!}{derive_deftly_adhoc!}' (not regenerated during rebase) Manually add `#[derive_deftly_adhoc]` where needed. seddery git-ls-files | grep '\.rs$' | xargs perl -i~ -pe 's{\#\[adhoc\b}{#[deftly}g' git-ls-files | grep '\.rs$' | xargs perl -i~ -pe 's{\bderive_adhoc_template}{derive_deftly_template}' (not regenerated during rebase) Manually fix up an import Manually update some builder attrs Manually fix up tor_rtmock::time_core This was missed in my seddery, due to me rebasing the branch and not redoing the seddery.
* | remove unused dependenciestrinity-1686a2024-04-021-1/+0
|/ | | | Edited-by: Nick Mathewson <[email protected]>
* Update unstable `tor/arti-*` crates to 0.17.0.Nick Mathewson2024-04-021-8/+8
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Done with: ``` CRATES=" tor-basic-utils tor-async-utils tor-error tor-config tor-events tor-units tor-geoip tor-rtcompat tor-rtmock tor-log-ratelim tor-rpcbase tor-llcrypto tor-protover tor-bytes tor-hscrypto tor-hspow tor-socksproto tor-checkable tor-cert tor-linkspec tor-cell tor-proto tor-netdoc tor-consdiff tor-netdir tor-relay-selection tor-congestion tor-persist tor-chanmgr tor-ptmgr tor-guardmgr tor-circmgr tor-dirclient tor-dirmgr tor-keymgr tor-hsclient tor-hsservice tor-hsrproxy arti-client arti-rpcserver arti-config arti-hyper arti-bench arti-testing " for crate in $CRATES; do cargo set-version -p "$crate" 0.17.0 done ```
* Bump patchlevel versions on non-{tor/arti} crates.Nick Mathewson2024-04-021-1/+1
| | | | | | | | | | | | | | | | These have all had backward-compatible changes. Generated with: ``` cargo set-version --bump patch -p fs-mistrust cargo set-version --bump patch -p test-temp-dir cargo set-version --bump patch -p fslock-guard cargo set-version --bump patch -p hashx cargo set-version --bump patch -p equix cargo set-version --bump patch -p caret cargo set-version --bump patch -p safelog cargo set-version --bump patch -p retry-error ```
* Run "fixup-features" in preparation for next release.Nick Mathewson2024-03-281-1/+1
|
* Run maint/add_warning.Nick Mathewson2024-03-137-0/+7
|
* fix: fix typosDimitris Apostolou2024-03-092-5/+5
|
* Fix typos in doc commentsTobias Stoeckmann2024-03-062-4/+4
|
* Use tor_basic_utils::PathExt::display_lossyIan Jackson2024-03-052-4/+7
| | | | | Change Path::display to this new function, in call sites where it's being used for a diagnostic.