summaryrefslogtreecommitdiff
path: root/crates/tor-proto/src/crypto
Commit message (Collapse)AuthorAgeFilesLines
* proto: remove bench pub wrappersLionel Goffaux2025-05-226-285/+85
|
* proto: use consts for bench throuputsLionel Goffaux2025-05-142-0/+6
|
* proto: fix doc typosLionel Goffaux2025-05-143-4/+4
|
* proto: fix name mismatch in the bench utils docLionel Goffaux2025-05-083-10/+10
|
* proto: fix typo s(t)ateLionel Goffaux2025-05-081-3/+3
|
* proto: extend benchmarksLionel Goffaux2025-05-085-147/+303
|
* Use simpler way to refer to last byte of tag.Nick Mathewson2025-05-071-1/+1
|
* proto: Clear low 6 bits of counter in CGO PRF.Nick Mathewson2025-05-071-3/+4
| | | | See torspec#332.
* cell,proto: Split request/response extensions into seprate typesNick Mathewson2025-05-071-9/+9
| | | | Implements part of proposal 358.
* cell: Use ExtList to implement CircRequestExt.Nick Mathewson2025-05-071-3/+4
| | | | This required some renaming, so that the types and their codes matched.
* Rename NtorV3Extension to CircRequestExtNick Mathewson2025-05-071-16/+16
| | | | | | | This type will, because of prop358, be shared by ntorv3, hs-ntor, and probably other future handshakes. There will also be a CircResponseExt type.
* tor_proto: name fields in bench_utils.Nick Mathewson2025-05-061-7/+10
|
* proto: Apply type-specific wrappers for tor1 cryptoNick Mathewson2025-05-063-61/+65
| | | | | | | | | | | | | Now instead of using CryptState for everything, we have specific types for each role and direction of crypto. This turned up a harmless-so-far bug in our onion service code: as an onion service, we were using _client_ crypto layers to respond to a client request. That's not correct, and wouldn't have worked with CGO. Instead, we need to use relay crypto layers, wrapped as client layers. Closes #1975.
* proto, cell: Remove RelayCellFormatTrait.Nick Mathewson2025-05-063-136/+76
| | | | | | | | | | | | | | | | The purpose of the trait was to parameterize the tor1 cell crypto on the different possible relay cell layouts. It made sense to have this trait when we thought we would implement the new cell layout for prop340 (packed-and-fragmented) well before we implemented CGO. But it now appears all but certain that CGO will land long before we make any more headway on prop340. Therefore, it doesn't make sense to carry the ability to customize `tor1` for other relay cell layouts. Removing this trait saves a fair bit of complexity.
* tor-proto: Rename some no-longer-apt tor1 members.Nick Mathewson2025-05-061-14/+13
|
* tor-proto: remove some now-unneeded accessors.Nick Mathewson2025-05-061-35/+15
|
* Emit SendmeTag directly from cell crypto.Nick Mathewson2025-05-063-79/+70
| | | | | | | | | | | | | | | | | | | | This changes the code to copy a SendmeTag rather than returning a slice. This isn't actually a big change: sending a slice already required 16 bytes (on 64-bit platforms), so sending a SendmeTag around isn't a big deal. We rely extensively on the compiler's ability to optimize away all the checking in code like this: ``` let slice: &[u8]; let a: [u8;N] = slice[0..N].try_into().expect("Nope"); ``` I've spot-checked it somewhat with "cargo-show-asm", but it could use more thorough checking. Closes #1956.
* proto: Split out CGO BlkCipher trait for Encryption/DecryptionNick Mathewson2025-05-062-57/+172
| | | | | | This lets us use `Aes128Dec` and `Aes128Enc` in place of plain old `Aes128`, which can be less space-efficient depending on the back-end.
* tor-proto: use RelayCellFormat rather than u8 in tests.Nick Mathewson2025-04-291-14/+14
| | | | (The u8 code was written before RelayCellFormat::V1 was introduced.)
* Rename feature cgo => counter-galois-onion.Nick Mathewson2025-04-291-3/+3
|
* CGO: Fix authenticated-sendme tag handling.Nick Mathewson2025-04-291-5/+20
| | | | | | See discussion at torspec#328: it's important that our SENDME authentication tag always be taken based on the _encrypted_ cell.
* CGO: Note another possible performance improvement.Nick Mathewson2025-04-291-0/+3
|
* proto: Implement and test CGO cryptography.Nick Mathewson2025-04-292-13/+316
| | | | | | | | This provides all the operations from proposal 359, along with the necessary integration and unit tests to make sure that they are behaving properly. Closes #1943
* proto: Implement UIV+, the wide-block RPRP used for CGO.Nick Mathewson2025-04-291-1/+174
|
* proto: Implement CGO functions ET and PRFNick Mathewson2025-04-291-3/+321
| | | | | | | These are a tweakable block cipher, and a pseudorandom byte stream. This commit includes test vectors, which were generated from the Python reference implementation and confirmed with a less optimized Rust implementation.
* New empty CGO module.Nick Mathewson2025-04-291-0/+23
|
* proto: Unified integration tests for relay crypto.Nick Mathewson2025-04-291-3/+210
|
* proto: Make relay-side cell crypto traits return tags.Nick Mathewson2025-04-292-15/+20
| | | | | | (We'll need these tags both to implement authenticated SENDMES at the relay side, and also to make sure that cgo is generating them correctly.)
* proto: Make crypt layers take a ChanCmd argumentNick Mathewson2025-04-293-42/+52
| | | | | | CGO will need this argument so that it can authenticate the command as part of its crypto operations. (Trying to meddle with RELAY vs RELAY_EARLY will no longer work!)
* proto: refactor RelayCrypt trait into separate traitsNick Mathewson2025-04-293-19/+78
| | | | | | It seems very likely that, as with client crypto, we'll want relay crypto to separable into "forward" and "reverse" objects, so that the two can be used more or less independently.
* proto: Tweak semantics of RelayCrypt::originate.Nick Mathewson2025-04-293-3/+5
| | | | | | | | | | This makes the behavior of "originate" match the behavior of OutboundClientLayer::originate_for, which creates the message _and_ encrypts it. This will be necessary for CGO, where "originate" and "encrypt" are not easily separated operations. (Nothing uses this trait yet, since relay circuits aren't yet a thing, so it's a good time to get it right.)
* proto: move tor1 testvector test into tor1 module.Nick Mathewson2025-04-292-54/+79
|
* proto: Clean up imports in tor1.rs.Nick Mathewson2025-04-292-6/+8
|
* proto: Move tor1 relay crypto to a separate file.Nick Mathewson2025-04-292-312/+312
| | | | | | | Since we're about to have a second kind of relay cell crypto, it makes sense to move this module. This change is pure code movement.
* Note some places where we need updates for #1944.Nick Mathewson2025-04-161-0/+5
| | | | (Also note a couple of other CGO-related issues)
* tor-proto: removed "ntor_v3" feature flagSteven Engler2025-04-011-1/+0
| | | | ntor v3 is now always enabled.
* squash! Upgrade rand dependency to 0.9.Nick Mathewson2025-03-181-4/+0
| | | | - `try_fill_bytes()` is no longer a member of RngCore.
* squash! Upgrade rand dependency to 0.9.Nick Mathewson2025-03-181-3/+3
| | | | - `rand::thread_rng()` has been deprecated and renamed to `rand::rng()`
* tor-proto: Split out send_relay_cell().Gabriela Moldovan2025-01-281-1/+1
|
* tor-proto: put every bench_utils mod behind the bench featureLionel Goffaux2024-11-062-3/+2
|
* tor-proto: change the visibility of the RelayBody inner structLionel Goffaux2024-11-061-1/+1
|
* tor-proto: remove inlines attributesLionel Goffaux2024-11-062-4/+0
|
* tor-proto: Add benchmarks for cell encryption and decryptionLionel Goffaux2024-11-042-0/+175
|
* Some HasMemoryCost impls in tor-protoIan Jackson2024-10-021-1/+4
|
* tor-proto: Use Reader::take_all_but().Nick Mathewson2024-09-161-8/+1
|
* tor-bytes: Error: provide and call Error::incomplete_errorIan Jackson2024-09-111-1/+1
| | | | | | | | | | | | | | | | | | | We introduce the new constructor and call it at the error generation sites. But there is still not yet any functional change. Change the type of Truncated's field to be Sensitive. The original reason for not doing this no longer applies, since we don't generally want to open-code construction of this variant. Conveniently, changing the type means we get to find all the sites where one *is* constructed and adjust them. In reader.rs and tor-proto we can just call incomplete_error. In tor-cell, there's a call site where we previously provided an underestimate, and where the Reader isn't available. We adjust that ad-hoc but this is fine because the error variant will change. (relaycell is using a Reader from from_slice.)
* tor-bytes: Add a deficit field to Error::Truncated (fmt)Ian Jackson2024-09-101-1/+3
|
* tor-bytes: Add a deficit field to Error::TruncatedIan Jackson2024-09-101-1/+2
| | | | This will allow us to fix #1592, but it doesn't do so yet.
* Add allows for many dead code warnings in tor-protoIan Jackson2024-07-082-0/+5
| | | | | | | I'm not sure how to resolve these. See #1467. We ought to fix them before they propagate to +stable, particularly since after !2242 they'll break CI.
* Add temporary allows for some dead code warningsIan Jackson2024-04-252-0/+2
|