aboutsummaryrefslogtreecommitdiff
path: root/crates/tor-llcrypto/src/pk/ed25519.rs
Commit message (Collapse)AuthorAgeFilesLines
* tor-llcrypto: Implement Ed25519PublicKey for ExpandedKeypairClara Engler2026-06-251-0/+6
| | | | | ExpandedKeypair already implements Ed25519SigningKey, so there is no reason to not implement Ed25519PublicKey on it.
* hscrypto, linkspec, llcrypto: Use new redaction helpersNick Mathewson2026-06-101-6/+2
| | | | This eliminates some string slicing.
* everywhere: Add #[allow(clippy::string_slice)]Clara Engler2026-06-091-0/+1
| | | | | | | | This commit adds #[allow(clippy::string_slice)] to all functions in the code where string slices are used, alongside a TODO comment. We do this add the function header to have it consistent, as things like expression based allow's are still experimental.
* maint: Run maint/add_warning to deny string slicesClara Engler2026-06-091-0/+1
| | | | | | | | | | | | This commit executes maint/add_warning with the just added change to deny string slices except in tests. I recommend auditing this by checking out the previous commit followed by running the script yourself and then verifying that the diff is identical to this commit. This commit makes cargo clippy fail. We will add exceptions in the next commit.
* Upgrade rand crates to 0.10.Wesley Aptekar-Cassels2026-05-121-1/+1
| | | | | | | | | | | When the circ-padding feature is enabled, we use maybenot, which does not yet support rand 0.10. In the meantime, enabling this feature pulls in rand 0.9. This is not ideal, but should be okay as a temporary situation. This also replaces the use of ReseedingRng (which was removed in 0.10) with the reseeding_rng crate. This is somewhat less performant, but it should be okay.
* tor-llcrypto: add `Ed25519Identity::from_base64()`Steven Engler2026-02-101-0/+42
| | | | | | | | This is intended to be analogous to `RsaIdentity::from_hex()`. I've found myself wanting this a few times, and it makes it easy to grab a `master-key-ed25519` from the consensus and paste it into the code without needing to do extra conversions.
* llcrypto: Depend on tor-memquota-cost, not tor-memquota.Nick Mathewson2026-02-021-1/+1
|
* tor-llcrypto: unconditionally use derive_deftlyhashcatHitman2025-09-231-1/+2
| | | | | | | I didn't even realize I was still conditionally using it on a feature. That's what I get for always testing with all-features. Signed-off-by: hashcatHitman <[email protected]>
* tor-(hs|ll)crypto: deftly derive ConstantTimeEqhashcatHitman2025-09-231-3/+19
| | | | | | | | | | | | | | | | | This is my initial attempt at deriving ConstantTimeEq and PartialEq. This includes the previously missed HsSvcNtorKeypair and HsClientDescEncKeypair types. In tor-llcrypto, a few implementations still had to be done by hand, and some types which previously derived normal PartialEq now derive it with ConstantTimeEq. I could not figure out how to properly set up the macros such that they could be used both in the current crate and in others, so for the moment they are duplicated. Just so I can get feedback. Ideally, this will be replaced with a better solution before merge. Signed-off-by: hashcatHitman <[email protected]>
* tor-llcrypto: fix typotcyrus2025-07-231-1/+1
| | | | | `tor_llcrypto::pk::ed25519::PublicKey` is based on `ed25519_dalek::VerifyingKey` and not `ed25519_dalek::SigningKey`.
* llcrypto: add an rng compatibility shim for dalek-cryptoNick Mathewson2025-03-181-2/+4
| | | | | | | | | dalek-cryptography is still on rand 0.8, so we need a compatibility shim for the Rng. Fortunately, since we merged interface-abstraction-of-the-daleks (!2868), we no longer need to propagate this compatibility layer throughout our codebase.
* Wrap ed25519-dalek types.Nick Mathewson2025-03-181-14/+140
| | | | | | | | | | | With this change, we'll no longer need to expose the types from dalek-cryptography as part of our API, and we'll have more freedom to switch ed25519 implementations, or to upgrade to a newer `rand` ahead of their schedule. Unlike with x25519-dalek, I had to tweak the API a bit: There's no way to get a &PublicKey out of a Keypair now, and implementing the old ed25519-dalek traits seemed unnecessary.
* Rename "memquota" feature to "memquota-memcost" when it's just HasMemoryCost ↵Ian Jackson2024-10-161-2/+10
| | | | (fmt)
* Rename "memquota" feature to "memquota-memcost" when it's just HasMemoryCostIan Jackson2024-10-161-5/+5
| | | | It's not documented anywhere ATM. I will do that in a followup MR.
* Some HasMemoryCost impls in tor-llcryptoIan Jackson2024-10-021-0/+7
|
* tor_hsservice: add `impl From<&FooPublicKeySpecifier> for ↵Adam Joseph F0B74D717CDE8412A3E0D4D5F29AC8080DA8E1E02024-09-091-0/+6
| | | | | | | | | | | | | FooKeypairSpecifier` instances This adds the following trivial `From` instances: - tor_hsservice: impl From<&HsIdPublicKeySpecifier> for HsIdKeypairSpecifier - tor_hsservice: impl From<&BlindIdPublicKeySpecifier> for BlindIdKeypairSpecifier - tor_hscrypto::pk: impl From<HsBlindIdKeypair> for HsBlindIdKey - tor_llcrypto::pk::ed25519: impl From<ExpandedKeypair> for PublicKey - tor_keymgr::mgr: impl From<TestKey> for TestPublicKey - tor::hscrypto::pk: impl From<HsIdKeypair> for HsIdKey
* Resolve an unfinished sentenceNick Mathewson2023-11-291-1/+2
|
* grammar fix in commentgabi-2502023-11-291-1/+1
|
* llcrypto: remove a comment suggesting a grand renaming.Nick Mathewson2023-11-291-3/+3
|
* llcrypto: Hide the members of ExpandedKeypair.Nick Mathewson2023-11-291-5/+15
| | | | | With this change, we no longer expose the ExpandedSecretKey unescorted, which makes it harder to misuse the API.
* llcrypto: Remove ExpandedSecretKey export.Nick Mathewson2023-11-291-5/+2
| | | | | | | This type was part of `hazmat`, and was no longer necessary anywhere in our codebase. (It had one remaining user, which was easy enough to remove.) By removing it, we remove the opportunity for using an unescorted ed25519 private key.
* Convert to the latest versions of dalek-cryptographyNick Mathewson2023-11-291-7/+61
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The main changes that we have to adjust for are as follows: * In x25519-dalek: * `StaticSecret` is now behind a feature. * `StaticSecret::new` is deprecated in favor of `StaticSecret::random_from_rng`. * StaticSecret no longer does its own clamping. * In ed25519-dalek: * `SecretKey` has (in effect) been renamed to `SigningKey`. The name `SecretKey` is now an alias for `[u8; 32]`. * `SigningKey` is effectively a keypair, since it contains a public key as well. * `PublicKey` has been renamed to `VerifyingKey`. * The functions to extract a signing key and verifying key have been renamed as you might expect. * `ExpandedSecretKey` has been moved to `hasmat` and no longer implements `sign`. * `ExpanededSecretKey` now has as its elements a scalar and a hash prefix. * Various functions that took `&[u8]` now take `&[u8; N]`. * We no longer need a wrapper for older versions of rand. There is a single test in tor-keymgr that does not pass. I've marked it as ignore for now, in hopes that @gabi-250 can help me figure it out. This closes #808. There are several changes I want to make before we merge, however. They are marked with TODO DALEK.
* tor-llcrypto: remove use of arrayrefNick Mathewson2023-06-011-6/+1
|
* llcrypto: Add an `ed25519::ExpandedKeypair` type.Nick Mathewson2023-05-181-0/+25
| | | | | | | | This is like an `ed25519::Keypair`, except that instead of a `SecretKey` it contains an `ExpandedSecretKey`. We'll be using this to implement #798, where we impose a rule that there must be no "unescorted" ed25519 secret keys.
* Use the type system to enforce use of blinded keys.Gabriela Moldovan2023-03-271-0/+12
| | | | | | | | | | | | | | | Hidden services use blinded singing keys derived from the identity key to sign descriptor signing keys. Before this patch, the hidden descriptor builder represented its blinded signing keys (`blinded_id`) as plain `ed25519::Keypair`s. This was not ideal, as there was nothing preventing the caller from accidentally initializing `blinded_id` with an unblinded keypair. This introduces a new `HsBlindKeypair` type to represent blinded keypairs. Signed-off-by: Gabriela Moldovan <[email protected]>
* Expose a little new functionality from tor-llcrypto.Nick Mathewson2023-02-281-0/+9
| | | | | Expose ED25519 signature length; make ValidatableEd25519Signature implement Debug and Clone.
* llcrypto: Implement `Into<[u8;32]>` for Ed25519IdentityNick Mathewson2023-02-071-0/+6
|
* Complete our migration to base64ct.Nick Mathewson2023-01-201-12/+5
| | | | | | | | | This is in lieu of upgrading to the latest base64 crate, which has a different API from the old one. Since we have to migrate either way, we might as well use base64ct everywhere. I don't think that most of these cases _require_ constant-time base64, but it won't hurt.
* llcrypto: clarify meaning of "Identity".Nick Mathewson2023-01-061-3/+7
| | | | | | | | | | The `Ed25519Identity` and `RsaIdentity` types are not precisely always used as relay identifiers: they are more generally used as _key_ identifiers. This will become relevant as `RsaIdentity` is used for authority keys (as in authorities' VoterInfo blocks), and as `Ed25519Identity` is used as the identifier behind an onion service key.
* Add a new "CtByteArray" type, and use it in Id types.Nick Mathewson2023-01-051-18/+14
| | | | | | This type provides a common implementation for types that are implemented as arrays of bytes that should only be compared with constant-time comparisons.
* llcrypto: Make key id types Redactable.Nick Mathewson2022-11-281-0/+16
|
* Define a constant for ED25519 identity length.Nick Mathewson2022-08-101-3/+6
|
* tor-llcrypto: expose the Signer API from ed25519-dalekNick Mathewson2022-07-061-1/+1
|
* squash! Bump every crate's edition to 2021.Nick Mathewson2022-04-251-2/+0
| | | | | Remove all `use` statements for `TryFrom` and `TryInto`. These are now redundant in Rust 2021.
* Implement Ord for Ed25519Identity.Nick Mathewson2022-03-301-1/+1
|
* Implement ConstantTimeEq for key ids.Nick Mathewson2021-10-011-2/+8
|
* Move all crates into a `crates` subdirectory.Nick Mathewson2021-08-271-0/+265
This will cause some pain for now, but now is really the best time to do this kind of thing.