| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | |
| |
| |
| |
| | |
If the Arti keystore is disabled, we have nothing to initialize the
`KeyMgr` with, so we might as well make it optional.
|
| |\ \
| | |
| | |
| | |
| | | |
Add getters to a couple of config builders
See merge request tpo/core/arti!1425
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
It's a bit of a wart that tor-ptmgr calls these "protocols" and
tor-guardmgr calls these "transport names".
|
| | | |
| | |
| | |
| | |
| | | |
BridgeConfigBuilder is Serialize so this isn't making any new API
promises. Ideally we'd have getters like this everywhere.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
cargo doc --locked --document-private-items --workspace --all-features
warning: unclosed HTML tag `CountryCode`
--> crates/tor-geoip/src/lib.rs:90:54
|
90 | /// We store these as NonZeroU8 so that an Option<CountryCode> only has to
| ^^^^^^^^^^^^^
|
= note: `#[warn(rustdoc::invalid_html_tags)]` on by default
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
tor-linkspec: impl AsRef<str> for PtTransportName
See merge request tpo/core/arti!1426
|
| | |/ / |
|
| |\ \ \
| | | |
| | | |
| | | |
| | | | |
Update pwd-grp to 0.1.1 to fix MacOS build etc.
See merge request tpo/core/arti!1427
|
| | |/ /
| | |
| | |
| | | |
This also gets rid of a duplicate copy of derive-adhoc.
|
| |\ \ \
| |_|/
|/| |
| | |
| | | |
Bump requirement to rlimit 0.10.1
See merge request tpo/core/arti!1423
|
| | | |
| | |
| | |
| | |
| | |
| | | |
There was a bug in 0.10.0 that broke MacOS.
Part of #963.
|
| |\ \ \
| |/ /
|/| |
| | |
| | | |
geoip: Enable the niche optimization for CountryCode.
See merge request tpo/core/arti!1384
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Since we're going to be using `Option<CountryCode>` all over, let's
save the extra byte.
Sadly this required std::mem::transmute(), which is unsafe, so maybe
we should think twice.
|
| | | | |
|
| |\ \ \
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
geoip: Allow ASNs as zeros when creating NetDefn
Closes #961
See merge request tpo/core/arti!1417
|
| | | | |
| | | |
| | | |
| | | | |
to be able to debug it, for instance.
|
| | | |/
| |/|
| | |
| | |
| | |
| | |
| | | |
so that GeoipDb can be created from files including ASNs generated with
tor/scripts/maint/geoip/geoip-db-tool.
Closes #961
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
This would be a break in higher-layer crates which incorproate this
error but:
1. That's just arti-client which hides it behind the detailed errors
cargo feature
2. I'm hoping cargo-semver-checks would spot it, anyway.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
The effect is that everywhere a RetryError is used, the error sources
for the contained errors will be Display'd.
In tor-hsclient we no longer need to explicitly wrap things up in
tor_error::Report.
|
| | | |
| | |
| | |
| | |
| | | |
We're going to require that a RetryError contains things that are
AsRef<dyn Error> and ParseIntError isn't so we need a newtype.
|
| | | |
| | |
| | |
| | |
| | | |
This code came from tor-error. So now tor-error depends on
retry-error.
|
| |/ /
| |
| |
| | |
We're about to want this.
|
| |\ \
| | |
| | |
| | |
| | | |
Mid-month dependency upgrades
See merge request tpo/core/arti!1412
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | | |
(Everything else is already on 0.11.0.)
|
| |\ \ \
| |/ /
|/| |
| | |
| | |
| | |
| | | |
Replace use of unmaintained users crate with homegrown pwd-grp
Closes #877
See merge request tpo/core/arti!1410
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
We don't use OsString now except where it appears in our public API,
or where we get it from std::env.
Moving the `use` statements into the use sites enabled me to see
that I had found all the places I wanted to change.
|
| | | |
| | |
| | |
| | | |
This function is actually (properly) fallible now.
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
MockPwdGrpProvider has internal mutability and is Sync, so its add
functions take &self.
|
| | | |
| | |
| | |
| | |
| | | |
This gets rid of some unsafe code here, with doubtful error handling,
in favour of the unit-tested version in pwd-grp.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
users is unmaintained. pwd-grp is the crate I have just written to
replace it. In this commit:
Change the cargo dependency and imports.
Replace the cacheing arrangements. users has a built-in cache;
pwd-grp doesn't. Now, instead of cashing individual lookups, we cache
the trusted user and trusted gid calculation results.
This saves on some syscalls, and is also more convenient to write.
(Mocking is still done via the dependency.)
Many systematic consequential changes of details:
* The entrypoint names to the library are different:
pwd-grp uses the names of the corresponding Unix functions.
* pwd-grp's returned structs are transparent, so we don't
call accessors for .uid(), .name(), etc.
* pwd-grp's methods are much more often fallible
(returning io::Result<Option<...>)
* We're using the non-UTF-8 pwd-grp API, which means we must
use turbofish syntax in some places.
* The mocking API is a bit different.
|
| | | |
| | |
| | |
| | |
| | | |
This allows us to change a number of trait bounds in advance, reducing
noise in the next commit.
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Add some wrapper functions for convenience.
The pwd-grp crate has a richer and more faithful, but not so
convenient, way of creating dummy user/group entries. Also the type
names are all going to change.
Doing this now reduces churn.
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
The actual underlying operations here *are* fallible.
The `users` crate hides those errors in several cases.
(Failures are very rare (at least unless NIS is involved), so this is
not of much practical import, but it's going to be necessary when we
use the more careful pwd-grp crate.
|
| |\ \ \
| |/ /
|/| |
| | |
| | |
| | |
| | | |
tor-keymgr config updates
Closes #939
See merge request tpo/core/arti!1404
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | | |
`ItemOrBool` is currently not used anywhere (it was previously used by
the keymgr config).
|
| | | |
| | |
| | |
| | | |
Closes #939
|
| | | | |
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
Previously, the keystore config consisted of a single field in
`StorageConfig`, which encoded 2 bits of information: whether the
keystore is enabled, and its root directory:
```
[storage]
# use this path, fail if compiled out
# keystore = "/path/to/arti/keystore"
#
# use default path, fail if compiled out
# keystore = true
#
# disable
# keystore = false
```
This commit adds `ArtiNativeKeystoreConfig`, which will replace the
multi-purpose `keystore` field. The new config will look like this:
```
#[storage.keystore]
# Whether the keystore is enabled.
#
# If the `keymgr` feature is enabled and this option is:
# * set to false, we will ignore the configured keystore path.
# * set to "auto", the configured keystore, or the default keystore, if the
# keystore path is not specified, will be used
# * set to true, the configured keystore, or the default keystore, if the
# keystore path is not specified, will be used
#
# If the `keymgr` feature is disabled and this option is:
# * set to false, we will ignore the configured keystore path.
# * set to "auto", we will ignore the configured keystore path.
#
# Setting this option to true when the `keymgr` feature is disabled is a
# configuration error.
#enabled = "auto"
# The root directory of the arti keystore
#path = "${ARTI_LOCAL_DATA}/keystore"
```
While `ArtiNativeKeystoreConfig` currently only has 2 fields, `enabled`
and `path`, future versions of the keystore might require additional
config options.
|