summaryrefslogtreecommitdiff
path: root/crates/tor-netdoc/src/doc
Commit message (Collapse)AuthorAgeFilesLines
* llcrypto: Hide the members of ExpandedKeypair.Nick Mathewson2023-11-291-3/+3
| | | | | With this change, we no longer expose the ExpandedSecretKey unescorted, which makes it harder to misuse the API.
* llcrypto: Remove redundant re-exports in keymanip.Nick Mathewson2023-11-292-3/+2
| | | | (These types were all already re-exported from pk::ed25519.)
* Remove RngCompatExt.Nick Mathewson2023-11-294-15/+8
| | | | | | | | | | This code was needed with the old version of dalek-cryptography, which wasn't compatible with up-to-date versions of the `rand` crate(s). But now that we've upgraded, we can drop this. (We could have left it around and deprecated it, but we are already making a breaking change to tor-llcrypto by upgrading dalek-cryptography.)
* Convert to the latest versions of dalek-cryptographyNick Mathewson2023-11-294-15/+16
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The main changes that we have to adjust for are as follows: * In x25519-dalek: * `StaticSecret` is now behind a feature. * `StaticSecret::new` is deprecated in favor of `StaticSecret::random_from_rng`. * StaticSecret no longer does its own clamping. * In ed25519-dalek: * `SecretKey` has (in effect) been renamed to `SigningKey`. The name `SecretKey` is now an alias for `[u8; 32]`. * `SigningKey` is effectively a keypair, since it contains a public key as well. * `PublicKey` has been renamed to `VerifyingKey`. * The functions to extract a signing key and verifying key have been renamed as you might expect. * `ExpandedSecretKey` has been moved to `hasmat` and no longer implements `sign`. * `ExpanededSecretKey` now has as its elements a scalar and a hash prefix. * Various functions that took `&[u8]` now take `&[u8; N]`. * We no longer need a wrapper for older versions of rand. There is a single test in tor-keymgr that does not pass. I've marked it as ignore for now, in hopes that @gabi-250 can help me figure it out. This closes #808. There are several changes I want to make before we merge, however. They are marked with TODO DALEK.
* tor-netdoc: Use the new HandshakeType enum to represent CREATE2 HTYPEs (fmt).Gabriela Moldovan2023-10-301-17/+21
|
* tor-netdoc: Use the new HandshakeType enum to represent CREATE2 HTYPEs.Gabriela Moldovan2023-10-302-15/+16
| | | | | | | | | | | Representing the supported HTYPEs as `HandshakeType`s instead of `u32`s makes it more difficult to pass in wrong/invalid values to `HsDescBuilder::create2_formats`. This also fixes a descriptor publisher bug spotted by @jnewsome, where the advertised CREATE2 HTYPEs included HTYPE `1`, which is actually supposed to be a reserved value. The publisher now only advertises the `NTOR` HTYPE (just like C Tor).
* Remove a broken rustdoc link and fix a typo.Nick Mathewson2023-10-271-3/+0
|
* tor-cert, tor-netdoc: Use EncodedEd25519Cert instead of Vec<u8>.Gabriela Moldovan2023-10-253-11/+8
|
* tor-netdoc: Change return type of create_desc_sign_key_cert.Gabriela Moldovan2023-10-251-6/+3
| | | | | | `Bug` wasn't necessarily the right error type here. Plus, with the new error type adding new errors (i.e. `CertEncodeError` variants), is not a breaking change.
* tor-netdoc: Building a descriptor now only requires the public part of ↵Gabriela Moldovan2023-10-251-8/+10
| | | | blinded_id.
* tor-netdoc: Remove now-unused blinded_id field.Gabriela Moldovan2023-10-252-7/+0
|
* tor-netdoc: Update HsDesc, HsDescOuter to accept the hs_desc_sign cert as an ↵Gabriela Moldovan2023-10-252-21/+32
| | | | | | | | | | argument. This will enable us to (eventually) the load the descriptor signing key cert from the keystore (as opposed to always recomputing it when building the `HsDesc`). Part of #1048
* tor-netdoc: Add helper function for computing the descriptor signing key cert.Gabriela Moldovan2023-10-253-15/+34
|
* tor-dirclient, tor-netdoc: Add TODO SPECs.Gabriela Moldovan2023-10-241-0/+3
|
* tor-netdoc: Use an unpadded base64 encoding for the signature.Gabriela Moldovan2023-10-241-3/+3
| | | | This is what the C Tor HsDirs want.
* Explain why we are sorting intro points.Nick Mathewson2023-10-161-0/+7
|
* Sort introduction point lists by ntor public key.Neel Chauhan2023-10-161-16/+18
| | | | Closes #1039
* tor-netdoc: Remove outdated note.Gabriela Moldovan2023-09-251-4/+0
|
* tor-hsclient, arti-client, tor-keymgr, tor-netdoc: Use a keypair instead of ↵Gabriela Moldovan2023-09-253-6/+6
| | | | StaticSecret (fmt).
* tor-hsclient, arti-client, tor-keymgr, tor-netdoc: Use a keypair instead of ↵Gabriela Moldovan2023-09-253-13/+12
| | | | | | | | | | | | | StaticSecret. Previously, when retrieving `KS_hsc_desc_enc` keys (or any other x25519 keys) from the keystore, the keymgr would discard the public part of the key (SSH private keys contain the public part of the key too). Instead of discarding the public key and returning just the `StaticSecret`, the keymgr now returns a `StaticKeypair`. This makes the x25519 `EncodableKey`/`ToEncodableKey` implementation consistent with the ed25519 one (which retrieves key pairs rather than "unescorted" secrets).
* tor-netdoc: "testing" feature: Provide test_parsed_hsdescIan Jackson2023-09-181-12/+20
| | | | | | This is actually just the start of an existing test case. tor-hsservice tests will want this in a moment.
* tor-netdoc: tests: Hoist out TEST_DATA_HS_BLIND_ID (fmt)Ian Jackson2023-09-181-4/+1
|
* tor-netdoc: tests: Hoist out TEST_DATA_HS_BLIND_IDIan Jackson2023-09-181-3/+9
|
* tor-netdoc: provide a IntroPointDescBuilder (fmt)Ian Jackson2023-08-291-2/+1
|
* tor-netdoc: provide a IntroPointDescBuilderIan Jackson2023-08-291-0/+13
| | | | | | | | | | | Previously there was no way to construct one of these during descriptor generation, other than parsing. A fairly simple builder seems right. I felt the builder's setter functions for setting keys should be named precisely after official key names. But the fields weren't, so for now I have done some builder-level renaming.
* Merge branch 'clippy' into 'main'Ian Jackson2023-08-2316-0/+16
|\ | | | | | | | | clippy: Suppress needless_pass_by_value in tests See merge request tpo/core/arti!1535
| * Run maint/add_warning to add lint block everywhereIan Jackson2023-08-2316-0/+16
| |
* | tor-netdoc: Fix clippy lints.Gabriela Moldovan2023-08-232-6/+6
| |
* | tor-netdoc: Remove redundant `IntroPointDesc` struct.Gabriela Moldovan2023-08-232-33/+13
|/ | | | | | | | | | | | This commit replaces `tor_netdoc::hsdesc::inner::IntroPointDesc` with the (almost identical) `tor_netdoc::hsdesc::IntroPointDesc`. The only difference between the two structs is that `inner::IntroPointDesc` wraps a `Vec<LinkSpec>` instead of a `Vec<EncodedLinkSpec>`. Since `EncodedLinkSpec` can be derived from `LinkSpec` (and vice-versa), and since `hsdesc::inner::IntroPointDesc` never made it in our public API, this commit also removes `hsdesc::inner::IntroPointDesc` in favour of `hsdesc::IntroPointDesc`.
* Merge branch 'explain_952_fix' into 'main'Nick Mathewson2023-07-111-0/+3
|\ | | | | | | | | Explain the code for the #952 fix. See merge request tpo/core/arti!1391
| * Explain the code for the #952 fix.Nick Mathewson2023-07-101-0/+3
| | | | | | | | | | Let's explain what Trinity did in its fix for #952, so that we know why this code is here the next time we find it.
* | Run maint/add_warning to actually apply new lint allowsIan Jackson2023-07-1016-0/+16
|/
* be more lenient while parsing inner hs desctrinity-1686a2023-07-071-1/+6
|
* Fix a rustdoc link.Nick Mathewson2023-06-291-1/+1
|
* Merge branch 'maxintro3' into 'main'Ian Jackson2023-06-292-6/+74
|\ | | | | | | | | tor-netdoc: Handle anomalous numbers of introduction points See merge request tpo/core/arti!1332
| * tor-netdoc: Placate clippy (fmt)Ian Jackson2023-06-281-2/+1
| |
| * tor-netdoc: Placate clippyIan Jackson2023-06-281-2/+1
| |
| * tor-netdoc: Test hsdescs inners with a variety of IPT counts (fmt)Ian Jackson2023-06-281-9/+18
| |
| * tor-netdoc: Test hsdescs inners with a variety of IPT countsIan Jackson2023-06-281-0/+33
| |
| * tor-netdoc: hsdesc: Disregard intro points after the MAX'thIan Jackson2023-06-282-7/+19
| |
| * tor-netdoc: Reject hsdescs with no intro pointsIan Jackson2023-06-282-0/+16
| | | | | | | | None of the existing NetdocErrorKinds seemed right.
* | netdir: Move voting_period() to netdoc::LifetimeNick Mathewson2023-06-291-0/+12
|/ | | | | I was going to add a comment about "doing this if we need the voting period anywhere else" but it turns out that we also use it in dirmgr.
* Conditionalise an importIan Jackson2023-06-281-0/+1
| | | | | Fixes a warning with cargo clippy --locked --offline --workspace --all-targets
* Back down x25519-dalek to 2.0.0-pre.1 from 2.0.0-rc.2pinkforest2023-06-272-7/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | ========================= Notes from nickm: (This differs from pinkforest's original MR: It removes the Cargo.lock changes and the version bump on tor-llcrypto.) Minimal Cargo.lock changes from downgrade. (These are exactly those changes generated by running "build" and "test".) There are several reasons to do this: * It's best to bump all of our dalek dependencies at once to rc.3 or later, rather than the piecemeal approach we've been stuck with so far. * We don't want to do this bump right now, since there are some tricky questions about clamping we need to figure out (see #808), and we need to make sure we get them right, and we're in a distracted this week. * We _do_ need to move away from 2.0.0-rc.2 right now, since it was causing a failure in `cargo install arti`, and then it got yanked. Thanks to pinkforest for helping us out here and explaining all of this! Fixes #926. Commit-edited-by: Nick Mathewson <[email protected]>
* netdoc: remove final TODO HSNick Mathewson2023-06-261-1/+0
| | | | Although this Errorkind is not perfect, it is good enough.
* netdoc: Downgrade TODO on EncryptedHsDesc::decryptNick Mathewson2023-06-261-2/+5
|
* netdoc: Remove "decrypted_with_id" as meaninglessNick Mathewson2023-06-261-26/+9
| | | | | | Actually, never mind about adding an accessor here: this value was set incorrectly and didn't match its documentation. As such it's basically useless, and we might as well throw it out.
* netdoc: Remove dead_code exception; add accessors.Nick Mathewson2023-06-262-5/+36
| | | | | | | | | | | | This commit removes some actual dead code and additionally adds some minimal accessors to HsDesc to expose some of its properties. (I'm trying to keep these minimal since it's not yet clear whether we want to expose more detail here.) Here we also make StoredHsDescMeta a conditional type that's only present when the new "hs-dir" feature is enabled. Neither relays nor clients need this: Only HsDirs will need it, when we finally implement relays.
* netdoc: change a TODO HS about a distinguisher to a NOTE.Nick Mathewson2023-06-261-4/+7
| | | | (We explicitly do not care if Arti can be distinguished from C tor.)
* netdoc: replace a test TODO with a reference to other testsNick Mathewson2023-06-261-1/+8
| | | | The tests called for here already existed.