summaryrefslogtreecommitdiff
path: root/crates/tor-keymgr
Commit message (Collapse)AuthorAgeFilesLines
...
| * Revert "tor-keymgr: Fix now-failing test."Gabriela Moldovan2024-05-081-0/+16
| | | | | | | | This reverts commit 9ea35caeb1ed23fd029627d04819debc41d85c77.
| * tor-keymgr: Validate the KeyType when inserting into the ephemeral keystore.Gabriela Moldovan2024-05-081-0/+20
| | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2131#note_3028014
| * tor-keymgr: Add function for extracting the KeyType of an ssh key.Gabriela Moldovan2024-05-082-0/+50
| |
| * tor-keymgr: Fix newly failing tests (fmt).Gabriela Moldovan2024-05-081-33/+62
| |
| * tor-keymgr: Fix newly failing tests.Gabriela Moldovan2024-05-082-59/+109
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This updates the keymgr tests to be slightly more robust. These tests attach some metadata to each key, such as the "nickname" of the key (which only exists for testing purposes), whether the key was auto-generated, and the keystore ID of the keystore from which the key was retrieved. Previously, the metadata was encoded in the key "material" itself (the test "keys" were actually just `String`s with a hacky `EncodableKey` implementation that abused the "encrypted" variant of `KeypairData`). This was only possible because we had access to the key internals (through `SshKeyData::Public`/`SshKeyData::Private`), but since the internals are inaccessible now, the tests need to be updated.
| * tor-keymgr: Make SshKeyData an opaque type.Gabriela Moldovan2024-05-073-87/+75
| | | | | | | | | | | | This helps prevent external users from creating `SshKeyData` out of unsupported types of `ssh_key::public::KeyData` and `ssh_key::private::KeypairData`.
| * tor-keymgr: Do not make SshKeyData infallibly convertible from ↵Gabriela Moldovan2024-05-072-11/+49
| | | | | | | | KeyData/KeypairData.
| * tor-keymgr: Seal the EncodableKey trait.Gabriela Moldovan2024-05-072-1/+33
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | As explained in the docs, this trait should not be implementable outside of the `tor-keymgr` crate. The `SshKeyData::into_erased` and `UnparsedOpensshKey::parse_ssh_format_erased` impls assume the types implementing `EncodableKey` form a statically known closed set. If we later decide to make the supported key types an open set, we should make this trait implementable outside of `tor-keymgr` too. External types wanting to create custom "key types" for use in the keymgr should use the non-sealed `ToEncodableKey` trait, which specifies the `EncodableKey` type to use. This trait is mainly used to create `SshKeyData` IMO, we should make `SshKeyData` opaque, since it's not meant to be constructed through other means (`SshKeyData` is currently a public enum, so its variants and the `ssh_key` types they wrap are public). A future commit will make it opaque.
| * tor-keymgr: Update ephemeral keystore docs.Gabriela Moldovan2024-05-071-2/+2
| |
| * tor-keymgr: Dedupe all the convert functions.Gabriela Moldovan2024-05-073-143/+17
| |
| * tor-keymgr: Make an ArtiNativeKeystore-specific function private.Gabriela Moldovan2024-05-071-20/+16
| | | | | | | | | | | | | | The `ssh_algorithm()` function was only meant for use in the ArtiNativeKeystore, for extracting the `KeyType` given the `SshAlgorithm` of a key read from disk, so it really shouldn't be crate-public.
| * tor-keymgr: Move arti-specific ssh code to arti module.Gabriela Moldovan2024-05-078-70/+75
| | | | | | | | | | | | | | | | | | Some of the types and impls from `key_type/ssh.rs` (such as `UnparsedOpenSshKey`) have nothing to do with `KeyType`, and are only used by the `ArtiNativeKeystore`, so I'm moving them to the `arti` keystore module. The shared ssh-related stuff now lives in the top-level `ssh.rs`.
| * tor-keymgr: Test that the ephemeral store returns the correct type.Gabriela Moldovan2024-05-071-2/+6
| |
| * tor-keymgr: Fix now-failing test.Gabriela Moldovan2024-05-071-16/+0
| | | | | | | | | | | | Inserting a key that has the wrong key type no longer fails, because we now store the `KeyData` as-is, without attempting to parse it as a specific kind of SSH key.
| * tor-keymgr: Simplify ephemeral keystore impl.Gabriela Moldovan2024-05-071-31/+6
| | | | | | | | Closes #1362 #1367
| * tor-keymgr: Make SshKeyData convertible to ErasedKey.Gabriela Moldovan2024-05-071-3/+151
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This adds an `SshKeyData::into_erased` function that returns the `SshKeyData` as a type-erased concrete key type (e.g. a type-erased `ed25519::Keypair`). This commit duplicates all of the `convert_*` functions from `key_type/ssh.rs`. A future commit will rewrite the code from `key_type/ssh.rs` to use `SshKeyData::into_erased`, and to remove the duplicate functions. Previously, `EncodableKey` returned an encoded `SshKeyData`, which doesn't implement `EncodableKey`. This was rather inconvenient for `Keystore` implementers. For instance, for the in-memory keystore we ended up working around this limitation by serializing and deserializing `EncodableKey`s to and from `String`. For the full context, see https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2076#note_3016460 Needed for #1362 #1367
| * tor-keymgr: Add an error type for unsupported keys.Gabriela Moldovan2024-05-071-0/+6
| |
| * tor-keymgr: Move parse_ssh_format_erased to UnparsedOpenSshKey.Gabriela Moldovan2024-05-073-39/+37
| | | | | | | | | | I think it makes more sense for parse_ssh_format_erased to be a function of the key than of `KeyType`.
| * tor-keymgr: Move parse_openssh! macro to the top of the file.Gabriela Moldovan2024-05-071-58/+58
| | | | | | | | | | | | We're about to need it in the `UnparsedOpenSshKey` impl. This commit is just code motion and has no functional changes.
| * tor-keymgr: Avoid using UnparsedOpenSshKey.Gabriela Moldovan2024-05-071-5/+6
| | | | | | | | | | | | | | | | | | | | `UnparsedOpenSshKey` was originally only meant to be used for the `ArtiNativeKeystore`. I am about to make it private to the arti module, so I'm updating the ephemeral keystore tests to not use it. Part of #1362
* | Merge branch 'new_ci_cfg_strategy' into 'main'Nick Mathewson2024-05-071-2/+2
|\ \ | |/ |/| | | | | | | | | add_warning/CI: New strategy to avoid "unexpected-cfgs" warning Closes #1395 See merge request tpo/core/arti!2129
| * Re-run maint/add_warning.Nick Mathewson2024-05-061-2/+2
| | | | | | | | This commit is automatically generated.
* | tor-keymgr: Make test module private again.Gabriela Moldovan2024-05-071-1/+1
| | | | | | | | | | | | | | This doesn't need to be public anymore now that the test keys are exported from `test_utils`. Addresses https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2076#note_3016577
* | tor-keymgr: Move TestSpecifier to test_utils.Gabriela Moldovan2024-05-073-26/+49
| | | | | | | | | | | | | | This is used by `ArtiNativeKeystore` and the `EphemeralKeystore`. Moving it to test_utils means `EphemeralKeystore` no longer needs to import test helpers from the arti module.
* | tor-keymgr: Move test constants to test_utils.Gabriela Moldovan2024-05-074-23/+55
|/ | | | | Closes #1363 and addresses a handful of TODOs about `include_str!`ing the same key multiple times from various test modules.
* Bump versions of 0.x tor-* and arti-* cratesIan Jackson2024-04-301-8/+8
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | for p in `cat ../u`; do cargo set-version --locked --offline -p $p; done where u contains tor-basic-utils tor-async-utils tor-error tor-config tor-units tor-geoip tor-rtcompat tor-rtmock tor-log-ratelim tor-rpcbase tor-memquota tor-llcrypto tor-protover tor-bytes tor-hscrypto tor-socksproto tor-checkable tor-cert tor-linkspec tor-cell tor-proto tor-netdoc tor-consdiff tor-netdir tor-relay-selection tor-persist tor-chanmgr tor-ptmgr tor-guardmgr tor-circmgr tor-dirclient tor-dirmgr tor-keymgr tor-hsclient tor-hsservice tor-hsrproxy arti-client arti-rpcserver arti-hyper
* Delete duplicate KeySpecifierComponentPrettyHelperIan Jackson2024-04-251-9/+0
| | | | This had somehow got duplicated; remove the one in derive.rs.
* Merge branch 'rpc_deftly' into 'main'Ian Jackson2024-04-111-1/+1
|\ | | | | | | | | Refactor RPC system to use derive_deftly; add generic-object support See merge request tpo/core/arti!2079
| * Upgrade derive-deftly requirement to 0.10.3Nick Mathewson2024-04-111-1/+1
| | | | | | | | We're taking this for the fix to derive-deftly#52.
* | tor-keymgr: added initial implementation for in-memory ArtiEphemeralKeystoreRichard Pospesel2024-04-105-4/+324
| |
* | tor-keymgr: Export KeyMgrBuilderError.Gabriela Moldovan2024-04-081-1/+1
|/ | | | | | `KeyMgrBuilderError` is used in `KeyMgrBuilder`'s public API. See https://gitlab.torproject.org/tpo/core/arti/-/issues/1358#note_3016025
* Merge branch 'deftly' into 'main'Ian Jackson2024-04-036-76/+78
|\ | | | | | | | | Switch to derive-deftly See merge request tpo/core/arti!2066
| * derive-deftly: Call pub_template_semver_checkIan Jackson2024-04-031-0/+2
| | | | | | | | | | | | | | This is a new feature in d-d 0.10.0. Our currrent semver policy doesn't care about this, but let's not encode that property in the tree and leave ourselves a booby-trap.
| * Switch to derive-deftlyIan Jackson2024-04-036-76/+76
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is the combination of a number of separate commits, many of which were generated by seddery, and then rebased and squashed. Cargo.toml perl -i~ -pe 's{^derive-adhoc}{derive-deftly = "0.10"}' crates/*/Cargo.toml (not regenerated during rebase) update Cargo.lock `cargo fetch` without --locked (regenerated during rebase) seddery git-ls-files | grep '\.rs$' | xargs perl -i~ -pe 's{^use derive_adhoc}{use derive_deftly}' git-ls-files | grep '\.rs$' | xargs perl -i~ -pe 's{\bdefine_derive_adhoc\b}{define_derive_deftly}g' git-ls-files | grep '\.rs$' | xargs perl -i~ -pe 's{\bAdhoc\b}{Deftly}g if m{derive}' git-ls-files | grep '\.rs$' | xargs perl -i~ -pe 's{\#\[derive_adhoc\b}{#[derive_deftly}g' git-ls-files | grep '\.rs$' | xargs perl -i~ -pe 's{use derive_adhoc}{use derive_deftly}' git-ls-files | grep '\.rs$' | xargs perl -i~ -pe 's{\bderive_adhoc\b}{derive_deftly_adhoc} if m{use.*deftly}' git-ls-files | grep '\.rs$' | xargs perl -i~ -pe 's{\bderive_adhoc!}{derive_deftly_adhoc!}' (not regenerated during rebase) Manually add `#[derive_deftly_adhoc]` where needed. seddery git-ls-files | grep '\.rs$' | xargs perl -i~ -pe 's{\#\[adhoc\b}{#[deftly}g' git-ls-files | grep '\.rs$' | xargs perl -i~ -pe 's{\bderive_adhoc_template}{derive_deftly_template}' (not regenerated during rebase) Manually fix up an import Manually update some builder attrs Manually fix up tor_rtmock::time_core This was missed in my seddery, due to me rebasing the branch and not redoing the seddery.
* | remove unused dependenciestrinity-1686a2024-04-021-1/+0
|/ | | | Edited-by: Nick Mathewson <[email protected]>
* Update unstable `tor/arti-*` crates to 0.17.0.Nick Mathewson2024-04-021-8/+8
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Done with: ``` CRATES=" tor-basic-utils tor-async-utils tor-error tor-config tor-events tor-units tor-geoip tor-rtcompat tor-rtmock tor-log-ratelim tor-rpcbase tor-llcrypto tor-protover tor-bytes tor-hscrypto tor-hspow tor-socksproto tor-checkable tor-cert tor-linkspec tor-cell tor-proto tor-netdoc tor-consdiff tor-netdir tor-relay-selection tor-congestion tor-persist tor-chanmgr tor-ptmgr tor-guardmgr tor-circmgr tor-dirclient tor-dirmgr tor-keymgr tor-hsclient tor-hsservice tor-hsrproxy arti-client arti-rpcserver arti-config arti-hyper arti-bench arti-testing " for crate in $CRATES; do cargo set-version -p "$crate" 0.17.0 done ```
* Bump patchlevel versions on non-{tor/arti} crates.Nick Mathewson2024-04-021-1/+1
| | | | | | | | | | | | | | | | These have all had backward-compatible changes. Generated with: ``` cargo set-version --bump patch -p fs-mistrust cargo set-version --bump patch -p test-temp-dir cargo set-version --bump patch -p fslock-guard cargo set-version --bump patch -p hashx cargo set-version --bump patch -p equix cargo set-version --bump patch -p caret cargo set-version --bump patch -p safelog cargo set-version --bump patch -p retry-error ```
* Run "fixup-features" in preparation for next release.Nick Mathewson2024-03-281-1/+1
|
* Run maint/add_warning.Nick Mathewson2024-03-137-0/+7
|
* fix: fix typosDimitris Apostolou2024-03-092-5/+5
|
* Fix typos in doc commentsTobias Stoeckmann2024-03-062-4/+4
|
* Use tor_basic_utils::PathExt::display_lossyIan Jackson2024-03-052-4/+7
| | | | | Change Path::display to this new function, in call sites where it's being used for a diagnostic.
* Merge branch 'remove-semver' into 'main'Ian Jackson2024-03-051-16/+0
|\ | | | | | | | | Remove semver.md files from arti 1.2.0 release. See merge request tpo/core/arti!2022
| * Remove semver.md files from arti 1.2.0 release.Gabriela Moldovan2024-03-041-16/+0
| |
* | Merge branch 'deny-unchecked-duration-substraction' into 'main'Ian Jackson2024-03-051-0/+1
|\ \ | |/ |/| | | | | | | | | deny clippy::unchecked_duration_subtraction Closes #1304 See merge request tpo/core/arti!2008
| * deny clippy::unchecked_duration_subtractiontrinity-1686a2024-02-291-0/+1
| |
* | Bump the minor version, for crates with breaking changes.Gabriela Moldovan2024-03-041-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | APIs were broken in these pre-1.0.0 crates: ``` tor-keymgr tor-config tor-checkable tor-circmgr tor-dirmgr tor-hsclient tor-hsservice tor-hsrproxy ``` Done with: ``` cargo set-version --bump minor -p tor-keymgr cargo set-version --bump minor -p tor-config cargo set-version --bump minor -p tor-checkable cargo set-version --bump minor -p tor-circmgr cargo set-version --bump minor -p tor-dirmgr cargo set-version --bump minor -p tor-hsclient cargo set-version --bump minor -p tor-hsservice cargo set-version --bump minor -p tor-hsrproxy ```
* | Bump patchlevel of crates with functional changes.Gabriela Moldovan2024-03-041-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Functional changes were made, but no APIs were added or broken: ``` tor-events (async_broadcast 0.6.0 -> 0.7.0) tor-netdoc (signature 1 -> 2) tor-guardmgr arti-testing (config 0.13.4 -> 0.14.0) tor-persist (breaking changes gated behind experimental feature) fslock-guard (fix lockfile_has_path compilation on Windows) ``` Done with: ``` cargo set-version --bump patch -p tor-events cargo set-version --bump patch -p tor-netdoc cargo set-version --bump patch -p tor-guardmgr cargo set-version --bump patch -p arti-testing cargo set-version --bump patch -p tor-persist cargo set-version --bump patch -p fslock-guard ```
* | Merge branch 'analyzer_windows_problems' into 'main'gabi-2502024-03-041-0/+1
|\ \ | | | | | | | | | | | | Fix rust-analyzer problems seen with default features on Windows See merge request tpo/core/arti!2009
| * | tor-keymgr: Fix compilation on WindowsTobias Stoeckmann2024-02-291-0/+1
| |/ | | | | | | | | The PermissionsExt::from_mode function is not available on Windows and disabled in all other places of the file. Do so here as well.