aboutsummaryrefslogtreecommitdiff
path: root/crates/tor-netdoc/src
Commit message (Collapse)AuthorAgeFilesLines
...
| * tor-netdoc: Expose whole input string (rustfmt)Ian Jackson2026-01-151-2/+1
| |
| * tor-netdoc: Expose whole input stringIan Jackson2026-01-151-8/+17
| | | | | | | | | | | | | | | | The string so far is exposed already via whole_for_signatures. It is unusual for a doc parser to need this, but embedded documents can use this plus byte_position to get the original input text for their part of the outer document.
| * tor-netdoc: parse2: Provide NetdocParseable::is_structural_keyword (rustfmt)Ian Jackson2026-01-152-5/+3
| |
| * tor-netdoc: parse2: Provide NetdocParseable::is_structural_keywordIan Jackson2026-01-156-2/+87
| | | | | | | | Roughly as per the proposal in `doc/dev/notes/authcert-in-consensus.md`.
| * tor-netdoc: Abolish poc's AuthCert (rustfmt)Ian Jackson2026-01-152-8/+3
| |
| * tor-netdoc: Abolish poc's AuthCertIan Jackson2026-01-154-109/+13
| | | | | | | | | | | | | | | | | | | | | | We can use the real AuthCert now that it implements the parse2 traits. The verification function is still used by poc's netstatus code and by a test case. We must change the field names in a few places, because the real AuthCert's struct field names are the keywords, whereas the poc's are the key names. (A shame that they're different!)
| * tor-netdoc: Prepare poc's DirAuthKeyCertSigned::verify_selfcertIan Jackson2026-01-151-7/+8
| | | | | | | | | | | | | | Use accessors for the body. (Eventually this function will replace, be replaced by, or merge with, the existing signature code outside poc.)
| * tor-netdoc: Add an error variant we'll need for parsing embedded docsIan Jackson2026-01-151-0/+3
| |
| * tor-netdoc: Improve Keyword API slightlyIan Jackson2026-01-151-1/+12
| |
* | Merge branch 'dirmirror-authcert' into 'main'Clara Engler2026-01-154-23/+37
|\ \ | | | | | | | | | | | | Implement authority certificate management See merge request tpo/core/arti!3561
| * | tor-netdoc: Change error variantsClara Engler2026-01-153-18/+18
| | | | | | | | | | | | | | | | | | | | | This commit changes `ErrorProblem::Other` to `ErrorProblem::OtherBadDocument` while adding two new variants: * `ErrorProblem::Internal` * `ErrorProblem::BadApiUsage`
| * | parse2: OOB check for parse_netdoc_multiple_with_offsetsClara Engler2026-01-151-5/+15
| | | | | | | | | | | | | | | | | | | | | This commit adds an out-of-bounds memory check to parse2::parse_netdoc_multiple_with_offsets while adding the guarantee that interfacing applications do not need to validate the returned usize values to be in-range.
| * | tor-netdoc: Make ConsensusFlavor exhaustiveClara Engler2026-01-151-1/+5
| |/ | | | | | | | | | | | | | | | | | | This commit marks the ConsensusFlavor struct exhaustive because handling it in a non-exhaustive fashion would cause lots of redundant error handling in tor-dirserver. Besides, a change in the list of consensus flavors should indeed be breaking for applications making use of this struct, as it is quite a heavy change, from a netdoc point of view.
* / tor-netdoc: Rename Version and expose it as netstatus::SoftwareVersionIan Jackson2026-01-154-9/+9
|/ | | | | | | This struct is still a bit odd, and there's a todo saying we may change it again, but at least now it's now available. While we're here, rename the variant Tor to CTor.
* tor-netdoc: Fix typoIan Jackson2026-01-141-1/+1
| | | | | As per https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3571#note_3325449
* tor-netdoc: constructors: Use manual non exhaustiveIan Jackson2026-01-143-3/+14
| | | | With `#[non_exhaustive]`, you're not allowed to write even `Thing { ..base }`.
* tor-netdoc: derives: New `skip` document field optionIan Jackson2026-01-144-10/+37
| | | | | This lets us having document items that are "manually non exhaustive" which is necessary for struct literal constructors.
* tor-netdoc: Improve docs for derived constructorsClara Engler2026-01-131-2/+12
|
* tor-netdoc: Remove TODO re AuthCert constructionIan Jackson2026-01-131-2/+0
|
* tor-netdoc: Deprecate AuthCertBuilderIan Jackson2026-01-132-0/+5
|
* tor-netdoc: improve derived Constructor docs with a kind-of exampleIan Jackson2026-01-131-0/+11
| | | | Let's not ask users to refer to the Constructor derive macro docs.
* tor-netdoc: Provide AuthCertConstructorIan Jackson2026-01-132-1/+10
|
* tor-netdoc: Fix an attribute position in AuthCertIan Jackson2026-01-131-1/+1
| | | | The compiler doesn't notice this, but it's odd.
* tor-netdoc: implement Constructor deriveIan Jackson2026-01-131-3/+54
|
* tor-netdoc: constructor derive: APIIan Jackson2026-01-131-1/+93
| | | | This doesn't actually work of course.
* tor-netdoc: authcert: Fix wrong linkIan Jackson2026-01-061-1/+1
|
* tor-netdoc: authcert: Add TODO about constructorsIan Jackson2026-01-061-0/+2
|
* tor-netdoc: authcert: rustfmtIan Jackson2026-01-061-5/+5
|
* tor-netdoc: authcert: Delete syntax info from rustdocsIan Jackson2026-01-061-37/+2
| | | | | This is in the spec. I don't think it is a great idea to duplicate it here.
* tor-netdoc: authcert: Fix remaining old names/paths in docsIan Jackson2026-01-061-8/+8
| | | | | These names came from tmp, and we renamed things as we went, but didn't change the docs everywhere.
* tor-netdoc: authcert: Improve docs for CrossCertIan Jackson2026-01-061-13/+12
| | | | Fix the type names while we're here.
* tor-netdoc: authcert: rename tmp test moduleIan Jackson2026-01-061-1/+1
| | | | This module is now the "proper" tests for the parse2 impl on AuthCert.
* tor-netdoc: authcert: abolish tmp module (reindent)Ian Jackson2026-01-061-50/+50
|
* tor-netdoc: authcert: abolish tmp moduleIan Jackson2026-01-061-140/+14
| | | | | | | | | | | tmp's version of AuthCert is gone. Each of its fields is already in AuthCert, including the docs links. I've decided not to transfer the syntax snippets. The remaining function in that module is now an inherent method on AuthCert, not on tmp's version. This needs reformatting since verify_self_signed is now at the wrong level!
* tor-netdoc: authcert: derive PartialEq and Eq in testsIan Jackson2026-01-061-0/+1
| | | | | It's not clear that we want to expose these impls, but our existing tests (in test::tmp) want them.
* tor-netdoc: authcert: Transfer spec links into AuthCert from tmpIan Jackson2026-01-061-28/+14
|
* tor-netdoc: authcert: derive parse2Ian Jackson2026-01-062-1/+13
|
* tor-netdoc: authcert: Add CrossCert to AuthCertIan Jackson2026-01-062-2/+19
| | | | This will enable parse2 to process it.
* tor-netdoc: authcert: Move signatures out of tmp (fmt)Ian Jackson2026-01-061-2/+2
|
* tor-netdoc: authcert: Move signatures out of tmpIan Jackson2026-01-061-68/+79
|
* tor-netdoc: authcert: Move CrossCert out of tmpIan Jackson2026-01-062-86/+99
| | | | | | | | We can call this type authcert::CrossCert. The names in the docs are getting rather wrong, and right now the docs build produces warnings. We'll tidy all that at the end after we're done moving and renaming.
* tor-netdoc: authcert: Rename verify_selfcert to verify_self_signedIan Jackson2026-01-061-14/+14
| | | | | | The distinction is: `verify_selfcert` sounds like it only verifies the self certificate. `veriify_self_signed` completely verifies a document, albeit one that is expected to be self-signed.
* tor-netdoc: authcert: Move AuthCertVersion out of tmpIan Jackson2026-01-062-20/+31
| | | | | Let's keep the existing name `AuthCert` in authcert.rs, so we want to rename this from DirKeyCertificateVersion, while we move it.
* tor-netdoc: authcert: Make all fields pubIan Jackson2026-01-061-7/+7
| | | | This is our new style. Now there's no known-dead code.
* tor-netdoc: authcert: Use Iso8601TimeSp for time fieldsIan Jackson2026-01-062-11/+11
| | | | This will let the parse2 derive work properly.
* tor-netdoc: authcert: Shuffle fingerprint values aboutIan Jackson2026-01-062-19/+11
| | | | | | | | | Make AuthCert look like the network document. This means removing its stored copy of H(KP_auth_sign_rsa), which it previously had via the embedded AuthCertKeyIds. We reculculate it as needed in AuthCert::key_ids().
* tor-netdoc: authcert: Abolish AuthCert::sk_fingerprintIan Jackson2026-01-061-6/+1
| | | | There are no in-tree callers.
* tor-netdoc: authcert: Make key_ids return owned AuthCertKeyIdsIan Jackson2026-01-062-5/+5
| | | | | AuthCert is about to lose its copy of H(KP_auth_sign_rsa) so it needs to return an owned value.
* tor-netdoc: RSA: check exponent and min size in parse2Ian Jackson2026-01-062-1/+24
| | | | | | | | | | | | | | | According to the spec we always use this fixed exponent, and we have a minimum size of 1024. This is checked adhoc in the old parser with some slight assistance from what is now `RsaPublicParse1Helper`. It's not clear to me that checking the exponent is actually a good idea. I think checking the size is probably a bad idea, and if it is a good idea then 1024 is clearly too short. But rather than revisit these questions, let's reproduce the old behaviour in parse2. In parse2 these checks should be features of the type.
* tor-netdoc: RSA: rename helper type to RsaPublicParse1HelperIan Jackson2026-01-064-15/+18
| | | | | | This is used by the old parsing code, apparently as a thing to hang the checking methods off. It is confusing to have so many different RSA types! Let's at least rename this one.