| Commit message (Collapse) | Author | Age | Files | Lines |
| |
|
|
|
|
|
|
| |
Done with
```
cargo set-version --bump patch -p arti
```
|
| |
|
|
|
|
|
|
|
|
| |
This is the result of:
```
for crate in $( ./maint/list_crates |grep '^\(tor\|arti-\)' ); do
cargo set-version -p $crate 0.21.0
done
```
|
| | |
|
| |
|
|
|
|
|
|
| |
No updates on their dependents, because:
fslock-guard (only tests have changed)
equix (only change is removal of a private constant)
fs-mistrust (documentation, formatting, and use of Path::try_exists in tests)
|
| | |
|
| |
|
|
|
| |
Rust 1.70 (our MSRV) will not allow us to use a trait from a private
module in this way, unfortunately.
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
|
|
| |
Except for *error_out, they are always set to NULL on error.
|
| | |
|
| | |
|
| |
|
|
|
|
|
| |
Additionally, inline the related conversion functions.
This should reduce the total amount of unsafe code that somebody
would need to look at.
|
| | |
|
| | |
|
| |
|
|
| |
(Documentation movement still needed.)
|
| | |
|
| | |
|
| | |
|
| |
|
|
|
|
|
| |
I got this by reading over all the relevant Rust stdlib safety
documentation (now linked to in the macro definitions),
and making sure that the C no-UB text is sufficient to guarantee
that those requirements are met.
|
| |
|
|
|
|
|
|
|
| |
Previously, some of our conversion macros tried to exit early with
`?`. This is undesirable, since the OutPtr conversion has the side
effect of writing NULL to a pointer (if it is present).
Now, every conversion runs, and _then_ we exit with an error if
any of them fails.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
These macros do the only part of our FFI functions that needs to be
`unsafe`: converting input pointers into types that can be used in
safe rust. I've added documentation about what requirements each of
these conversions puts onto out inputs: both informally, and via a
reference to the relevant parts of the Rust library documentation.
While doing this I found a safety bug in `OutPtr::from_opt_ptr`:
it should have been using `MaybeUninit`.
These macros should allow us to build a "proof sketch" for the
safety of our FFI code. We need to show, for each input parameter:
- That the documented requirements for its conversion method
are also documented requirements for that kind of input, in our
header file.
- That the documented requirements for how it can be used
after conversion are in fact followed in the code.
|
| |
|
|
| |
(and to what extent)
|
| | |
|
| | |
|
| | |
|
| |
|
|
| |
In brief: Everything now starts with ARTI_RPC, arti_rpc, or ArtiRpc.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
These documents are no longer called "safety". They are now mostly
collected as a big list of "correctness requirements" at the start
of the cbindgen header. Because of these requirements, most
functions no longer need their own "safety" sections.
I am explicitly using `#[allow(clippy::missing_safety_doc)]` on each
function, rather than adding a blanket exception:
- There are other unsafe functions in this code, to which we
wouldn't want an exception to apply.
- Documenting the safety^W correctness requirements of a function
is important enough to make sure that we aren't skipping out on
it unintentionally.
|
| | |
|
| |
|
|
|
|
|
|
| |
Per discussion, we'd rather have an optional output parameter for error
objects rather than mess with thread-local variables.
This is possibly less convenient for direct usage from C,
but likely more convenient for wrapper functions in other languages.
|
| |
|
|
|
|
|
|
|
|
|
|
|
| |
In this API, borrowed strings are `const char *`, and owned strings
are `ArtiRpcStr *`. You can get the former from the latter with
`arti_rpc_str_get()`, which returns a `const char *` in hopes that
you will neither modify nor free() that `const char *`
(Note that there are no places where string ownership needs to be
passed into this library; and at present, there is only one case
where it is passed out. I do not anticipate that we will need to do
intake of owned strings. We will probably need to return these in a
few more cases as we add more API surface.)
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
|
|
|
|
|
|
|
|
| |
This is a bit complicated since:
- Using cbindgen with macro expansion requires a nightly rust:
so, we have to look for one.
- There are some cbindgen warnings which I cannot find any way to
suppress, so instead of giving all warnings, it seems better to
give a diff from the old list of warnings to the new list.
|
| |
|
|
|
|
|
|
|
| |
This only covers the absolute minimal API in order to launch a
connection and run simple requests, and it doesn't document anything
nearly well enough. Nonetheless I think it's good enough for an
initial review, to make sure that we've got the basics right (as
well as a general consensus on the error handling API, naming, and
so forth).
|
| |
|
|
| |
(Internally, it is a boxed CStr that is always UTF-8.)
|
| |\
| |
| |
| |
| |
| |
| | |
tor-dirmgr: Return an error if storage is readonly and DB is missing/incompatbile.
Closes #1497
See merge request tpo/core/arti!2283
|
| | | |
|
| | |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
missing/incompatbile.
This fixes a bug in `SqliteStore`'s constructor: previously, it would
unconditionally try to create the missing database, even if it didn't
have write access. As a result, it was impossible to reliably start
multiple concurrent arti processes configured with the same (empty or
nonexistent) cache_dir, because many of them would fail with errors such
as
```
attempt to write a readonly database: Error code 8: Attempt to write a readonly database
```
Returning a `LocalResourceAlreadyInUse` error kind here enables us to
leverage the retry loop from `TorClientBuilder::create_unbootstrapped`
(which retries on local resource errors if `local_resource_timeout` is
set).
Closes #1497
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
arti: Add tests for the hss/hsc subcomands
Closes #1250
See merge request tpo/core/arti!2275
|
| | | | |
|
| | |/
| |
| |
| | |
Closes #1250
|
| |\ \
| | |
| | |
| | |
| | | |
tor-rtmock docs: Improve discussions of mocked time
See merge request tpo/core/arti!2286
|
| | | | |
|
| | |/
| |
| |
| | |
Improve/replace some out-of-date notes in the docs.
|