| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | |
| | |
| | |
| | |
| | |
| | |
| | | |
This commit changes `ErrorProblem::Other` to
`ErrorProblem::OtherBadDocument` while adding two new variants:
* `ErrorProblem::Internal`
* `ErrorProblem::BadApiUsage`
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | | |
This commit adds an out-of-bounds memory check to
parse2::parse_netdoc_multiple_with_offsets while adding the guarantee
that interfacing applications do not need to validate the returned usize
values to be in-range.
|
| | |/
| |
| |
| |
| |
| |
| |
| |
| |
| | |
This commit marks the ConsensusFlavor struct exhaustive because handling
it in a non-exhaustive fashion would cause lots of redundant error
handling in tor-dirserver.
Besides, a change in the list of consensus flavors should indeed be
breaking for applications making use of this struct, as it is quite a
heavy change, from a netdoc point of view.
|
| |/
|
|
|
|
|
| |
This struct is still a bit odd, and there's a todo saying we may
change it again, but at least now it's now available.
While we're here, rename the variant Tor to CTor.
|
| |
|
|
|
| |
As per
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3571#note_3325449
|
| |
|
|
| |
With `#[non_exhaustive]`, you're not allowed to write even `Thing { ..base }`.
|
| |
|
|
|
| |
This lets us having document items that are "manually non exhaustive"
which is necessary for struct literal constructors.
|
| |
|
|
|
| |
Fix the conflict in tor-netdoc/semver.md by hand, including the new
entries already landed since v1.9.0.
|
| |\
| |
| |
| |
| | |
tor-netdoc: constructor derive
See merge request tpo/core/arti!3560
|
| | | |
|
| | | |
|
| | | |
|
| | |
| |
| |
| | |
Let's not ask users to refer to the Constructor derive macro docs.
|
| | | |
|
| | |
| |
| |
| | |
The compiler doesn't notice this, but it's odd.
|
| | | |
|
| | |
| |
| |
| | |
This doesn't actually work of course.
|
| |/
|
|
|
|
|
|
|
| |
Done using the following:
```bash
for crate in $(./maint/list_crates | rg '^(tor|arti-)'); do
cargo set-version -p $crate 0.38.0
done
```
|
| | |
|
| | |
|
| | |
|
| |
|
|
|
| |
This is in the spec. I don't think it is a great idea to duplicate it
here.
|
| |
|
|
|
| |
These names came from tmp, and we renamed things as we went, but
didn't change the docs everywhere.
|
| |
|
|
| |
Fix the type names while we're here.
|
| |
|
|
| |
This module is now the "proper" tests for the parse2 impl on AuthCert.
|
| | |
|
| |
|
|
|
|
|
|
|
|
|
| |
tmp's version of AuthCert is gone. Each of its fields is already in
AuthCert, including the docs links. I've decided not to transfer the
syntax snippets.
The remaining function in that module is now an inherent method on
AuthCert, not on tmp's version.
This needs reformatting since verify_self_signed is now at the wrong level!
|
| |
|
|
|
| |
It's not clear that we want to expose these impls, but our existing
tests (in test::tmp) want them.
|
| | |
|
| | |
|
| |
|
|
| |
This will enable parse2 to process it.
|
| | |
|
| | |
|
| |
|
|
|
|
|
|
| |
We can call this type authcert::CrossCert.
The names in the docs are getting rather wrong, and right now the docs
build produces warnings. We'll tidy all that at the end after we're
done moving and renaming.
|
| |
|
|
|
|
| |
The distinction is: `verify_selfcert` sounds like it only verifies the
self certificate. `veriify_self_signed` completely verifies a
document, albeit one that is expected to be self-signed.
|
| |
|
|
|
| |
Let's keep the existing name `AuthCert` in authcert.rs, so we want to
rename this from DirKeyCertificateVersion, while we move it.
|
| |
|
|
| |
This is our new style. Now there's no known-dead code.
|
| |
|
|
| |
This will let the parse2 derive work properly.
|
| |
|
|
|
|
|
|
|
| |
Make AuthCert look like the network document.
This means removing its stored copy of H(KP_auth_sign_rsa), which it
previously had via the embedded AuthCertKeyIds.
We reculculate it as needed in AuthCert::key_ids().
|
| |
|
|
| |
There are no in-tree callers.
|
| |
|
|
|
| |
AuthCert is about to lose its copy of H(KP_auth_sign_rsa) so it needs
to return an owned value.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
According to the spec we always use this fixed exponent, and we have a
minimum size of 1024. This is checked adhoc in the old parser with
some slight assistance from what is now `RsaPublicParse1Helper`.
It's not clear to me that checking the exponent is actually a good
idea. I think checking the size is probably a bad idea, and if it is
a good idea then 1024 is clearly too short.
But rather than revisit these questions, let's reproduce the old
behaviour in parse2.
In parse2 these checks should be features of the type.
|
| |
|
|
|
|
| |
This is used by the old parsing code, apparently as a thing to hang
the checking methods off. It is confusing to have so many different
RSA types! Let's at least rename this one.
|
| |
|
|
| |
Spec links from the tmp module will be added later.
|
| | |
|
| | |
|
| |
|
|
|
| |
Prompted by
https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/3554#note_3313768
|
| | |
|
| |
|
|
|
|
| |
* Make a fancy version of t_ok, t_ok_multi, that takes the expected boundary byte offsets.
* t_ok is now just for single-document files and is implemented in terms of t_ok_multi.
* Use t_ok_multi for the one test case with multiple documents.
|
| | |
|